IP Library Granted Patent US 9,888,013
Granted Patent B2
US 9,888,013 · App. 15/154,232 · Granted Feb 6, 2018

Determining virtual adapter access controls in a computing environment

Inventors: Ralph Friedrich (Sindelfingen, DE); Raymond M. Higgs (Poughkeepsie, NY); George P. Kuch (Poughkeepsie, NY); Elizabeth A. Moore (Sunnyvale, CA); Johnathon R. Pandich (Owego, NY); Richard M. Sczepczenski (Hyde Park, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/102G06F9/45545G06F9/45558H04L41/28H04L49/3054H04L49/354G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,888,013
App. No.
15/154,232
Granted
Feb 6, 2018
Kind
B2
Abstract

A control component of a computing environment initiates sending of request(s) over a network of the computing environment by an activated virtual adapter. The activated virtual adapter is hosted on a physical adapter of a host system coupled to the network, and is for use by a guest, hosted by the host system, in performing data input and output. The request(s) retrieve access control information from the network indicative of access control(s) enforced in controlling access by the activated virtual adapter to network component(s). The initiating provides indication(s) to the physical adapter, absent involvement of the guest, that the request(s) be sent by the virtual adapter. Based on the initiating, the control component obtains the access control information from the physical adapter, and determines, based on that information, the access control(s) being enforced by the network in controlling access by the activated virtual adapter to the network component(s).

Claims (18)

1. A computer-implemented method comprising:

initiating, by a control component of a computing environment, sending of one or more requests over a network of the computing environment by an activated virtual adapter, the activated virtual adapter being hosted on a physical adapter of a host system coupled to the network, the activated virtual adapter for use by a guest, hosted by the host system, in performing data input and output, wherein the one or more requests retrieve, via responses provided to and received by the virtual adapter in response to the one or more requests, access control information from the network, the access control information indicative of one or more access controls enforced by the network in controlling access by the activated virtual adapter to one or more network components of the network, and wherein the initiating comprises the control component providing one or more indications to the physical adapter, absent involvement of the guest, that the one or more requests be sent by the virtual adapter;

based on the initiating, obtaining, by the control component, the access control information from the physical adapter, wherein the initiating, the sending of the one or more requests by the activated virtual adapter, and the obtaining occur absent involvement of the guest;

determining, by the control component, based on the obtained access control information, the one or more access controls being enforced by the network in controlling access by the activated virtual adapter to the one or more network components; and

initiating return of the virtual adapter to a state of the virtual adapter prior to the activating.

2. The method of claim 1 , wherein the initiating and the obtaining by the activated virtual adapter is non-disruptive of use of the activated virtual adapter by the guest in performing data input and output, and wherein use of the activated virtual adapter in performing data input and output by the guest is non-disruptive of the initiating and the obtaining by the control component.

3. The method of claim 1 , wherein the initiating, obtaining, and determining occur prior to an initial program load of the guest.

4. The method of claim 1 , wherein the host system is a separate system from the control component, wherein the host system executes on a first set of one or more processors and the control component executes on a second set of one or more processors different from the first set of one or more processors.

5. The method of claim 1 , wherein the initiating initiates sending of a request, of the one or more requests, to log the activated virtual adapter into the network.

6. The method of claim 1 , wherein the initiating initiates sending a request, of the one or more requests, to determine remote ports of the network that are accessible to the activated virtual adapter, wherein the retrieved access control information comprises an indication of one or more remote ports of the network that are accessible to the activated virtual adapter.

7. The method of claim 1 , wherein the initiating initiates sending a request, of the one or more requests, to log into a remote port accessible to the activated virtual adapter.

8. The method of claim 1 , wherein a remote port accessible to the activated virtual adapter is a remote port of a storage device hosting a storage array, wherein a logical unit of the storage array is indicated by a logical unit number, and wherein a request of the one or more requests comprises a logical unit number interrogation request.

9. The method of claim 1 , wherein the one or more network components comprise a storage area network, and wherein the retrieved access control information comprises logical unit number masking data or zoning configuration data for controlling zones of the storage area network, wherein the determining determines one or more storage arrays to which the activated virtual adapter has access.

10. The method of claim 1 , wherein the one or more network components comprise a storage area network, and wherein the retrieved access control information comprises logical unit number masking data or zoning configuration data for controlling zones of the storage area network, wherein the determining determines one or more zones of which the activated virtual adapter is a member.

11. The method of claim 1 , wherein the determined one or more access controls comprise an access control preventing access by the activated virtual adapter to a network component of the one or more network components.

12. The method of claim 1 , further comprising determining, based on at least some of the obtained access control information, whether an access control of the determined one or more access controls is appropriate for controlling access by the activated virtual adapter to the one or more network components, wherein the determining is performed while the guest remains inactive.

13. The method of claim 12 , further comprising, based on determining that the access control is not appropriate for controlling access by the activated virtual adapter to the one or more network components, reconfiguring the activated virtual adapter or a network component of the network prior to activating the guest.

14. The method of claim 1 , wherein the guest comprises a guest virtual machine hosted by the host system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 13, 2016
From: FRIEDRICH, RALPH; HIGGS, RAYMOND M.; KUCH, GEORGE P.; MOORE, ELIZABETH A.; PANDICH, JOHNATHON R.; SCZEPCZENSKI, RICHARD M.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038589/0836 →
Continuity (2)
Continuation 14212255 · Mar 14, 2014
Related Publication 20160255020A1 · Sep 1, 2016