EP1513042A2

Coordinated network initiator management that avoids security conflicts

Abstract

An abstraction module that facilitates security configuration amongst a number of initiators in a manner that there are no conflicts in the security information across all initiators. The abstraction module exposes a common interface that may be used to configure any of the initiators, receives through this common interface an indication that a selected one of the initiators is to be configured to communicate with a selected target device, and retrieves security information from a common database, the database including information that is relevant to configuring security for any of the plurality of initiators. The abstraction module identifies a security configuration for the selected initiator using the retrieved security information and, if the settings would not cause a conflict with any of the other of the initiators, uses the identified security configuration to configure the selected initiator.

EP1513042A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 10 August 2024, 2.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

34 claims: 34 independent, 0 dependent

  1. 1
    A method in a computer system that includes a plurality of initiators, each for initiating communication with target devices over a network, the method for configuring the computer system to securely communicate with a target device over the network, the method comprising the following performed by an abstraction module that configures each of the plurality of initiators in a manner that security conflicts between the plurality of initiators is avoided:an act of exposing a common interface that may be used to configure any of the plurality of initiators;an act of receiving an indication through the common interface that a selected initiator from among the plurality of initiators is to be configured to communicate with a selected target device;an act of retrieving security information from a database that includes information that is relevant to configuring security for any of the plurality of initiators;an act of identifying a security configuration of the selected initiator using the retrieved security information;an act of determining that the identified security configuration would not cause the selected initiator to conflict with any of the other of the plurality of initiators;andan act of configuring the selected initiator using the identified security configuration.
  2. 2
    A method in accordance with Claim 1, wherein the identified security configuration is different than the retrieved security information.
  3. 3
    A method in accordance with Claim 1, wherein the identified security configuration is the same as the retrieved security information.
  4. 4
    A method in accordance with Claim 1, wherein the retrieved security information comprises IPSec configuration information.
  5. 5
    A method in accordance with Claim 1, wherein the retrieved security information comprising CHAP configuration information
  6. 6
    A method in accordance with Claim 1, wherein the selected initiator is configured to cause communication to occur with the target device using iSCSI.
  7. 7
    A method in accordance with Claim 1, wherein the act of retrieving security information from a database comprises an act of retrieving the security information from an Active Directory.
  8. 8
    A method in accordance with Claim 1, wherein the selected initiator is a hardware initiator.
  9. 9
    A method in accordance with Claim 1, wherein the selected initiator is a software initiator.
  10. 10
    A method in accordance with Claim 1, wherein the act of retrieving security information occurs in response to the act of the abstraction module receiving the indication.
  11. 11
    A method in accordance with Claim 1, wherein the indication through the common interface is received in response to a request to communicate with the selected target device.
  12. 12
    A method in accordance with Claim 1, wherein the indication through the common interface is received in advance of any express request to communicate with the selected target device.
  13. 13
    A method in accordance with Claim 12, wherein the indication through the common interface is received in response to initializing the computer system.
  14. 14
    A method in a computer system that includes a plurality of initiators, each for initiating communication with target devices over a network, the method for configuring the computer system to securely communicate with a target device over the network, the method comprising the following performed by an abstraction module that configures each of the plurality of initiators in a manner that security conflicts between the plurality of initiators is avoided:an act of exposing a common interface that may be used to configure any of the plurality of initiators;an act of receiving an indication through the common interface that a selected initiator from among the plurality of initiators is to be configured to communicate with a selected target device;a step for causing the selected initiator to communicate with the selected target device such that the security configuration of the selected initiator does not conflict with others of the plurality of initiators.
  15. 15
    A method in accordance with Claim 14, wherein the step for causing the selected initiator to communicate with the selected target device comprises the following:an act of retrieving security information from a database that includes information that is relevant to configuring security for any of the plurality of initiators;an act of identifying a security configuration of the selected initiator using the retrieved security information;an act of determining that the identified security configuration would not cause the selected initiator to conflict with any of the other of the plurality of initiators;andan act of configuring the selected initiator using the identified security configuration.
  16. 16
    A method in accordance with Claim 15, wherein the identified security configuration is different than the retrieved security information.
  17. 17
    A method in accordance with Claim 15, wherein the identified security configuration is the same as the retrieved security information.
  18. 18
    A method in accordance with Claim 15, wherein the retrieved security information comprises IPSec configuration information.
  19. 19
    A method in accordance with Claim 15, wherein the retrieved security information comprising CHAP configuration information
  20. 20
    A method in accordance with Claim 15, wherein the selected initiator is configured to cause communication to occur with the target device using iSCSI.
  21. 21
    A method in accordance with Claim 15, wherein the act of retrieving security information from a database comprises an act of retrieving the security information from an Active Directory.
  22. 22
    A method in accordance with Claim 15, wherein the selected initiator is a hardware initiator.
  23. 23
    A method in accordance with Claim 15, wherein the selected initiator is a software initiator.
  24. 24
    A computer program product for use in a computer system that including a plurality of initiators, each for initiating communication with target devices over a network, the computer program product for implementing a method for configuring the computer system to securely communicate with a target device over the network, the computer program product comprising one or more computer-readable media having thereon computer-executable instructions that, when executed by one or more processors of the computing system, cause the computing system to perform the following:an act of instantiating an abstraction module and causes the abstraction module to perform the following: an act of exposing a common interface that may be used to configure any of the plurality of initiators;an act of receiving an indication through the common interface that a selected initiator from among the plurality of initiators is to be configured to communicate with a selected target device;an act of retrieving security information from a database that includes information that is relevant to configuring security for any of the plurality of initiators;an act of identifying a security configuration of the selected initiator using the retrieved security information;an act of determining that the identified security configuration would not cause the selected initiator to conflict with any of the other of the plurality of initiators;andan act of configuring the selected initiator using the identified security configuration.
  25. 25
    A computer program product in accordance with Claim 24, wherein the one or more computer-readable media are physical memory media.
  26. 26
    A computer program product in accordance with Claim 25, wherein the one or more computer-readable media is persistent memory.
  27. 27
    A computer program product in accordance with Claim 25, wherein the one or more computer-readable media is volatile system memory.
  28. 28
    A computer program product in accordance with Claim 24, wherein the retrieved security information comprises IPSec configuration information.
  29. 29
    A computer program product in accordance with Claim 24, wherein the retrieved security information comprising CHAP configuration information.
  30. 30
    A computer program product for use in a computer system that including a plurality of initiators, each for initiating communication with target devices over a network, the computer program product for implementing a method for configuring the computer system to securely communicate with a target device over the network, the computer program product comprising one or more computer-readable media having thereon computer-executable instructions that, when executed by one or more processors of the computing system, cause the computing system to instantiate the following:a plurality of initiators, each capable of communicating with at least one of the plurality of target devices;an abstraction module configured to expose a common interface that may be used to configure any of the plurality of initiators, receive an indication through the common interface that a selected initiator from among the plurality of initiators is to be configured to communicate with a selected target device, retrieve security information from a database that includes information that is relevant to configuring security for any of the plurality of initiators, identify a security configuration of the selected initiator using the retrieved security information in response to receiving the indication, and configure the selected indicator using the identified security configuration if the identified security information would not cause the selected initiator to conflict with any of the other of the plurality of initiators.
  31. 31
    A computer program product in accordance with Claim 30, wherein the one or more computer-readable media further have thereon computer-executable instructions that, when executed by one or more processors of the computing system, cause the computing system to instantiate the following:a software module configured to submit the indication to the common interface.
  32. 32
    A computer program product in accordance with Claim 30, wherein the one or more computer-readable media are physical memory media.
  33. 33
    A computer program product in accordance with Claim 32, wherein the one or more computer-readable media is persistent memory.
  34. 34
    A computer program product in accordance with Claim 32, wherein the one or more computer-readable media is volatile system memory.
Independent claims34