IP Library Granted Patent US 10,102,356
Granted Patent B1
US 10,102,356 · App. 15/064,829 · Granted Oct 16, 2018

Securing storage control path against unauthorized access

Inventors: Adnan Sahin (Needham, MA); Michael Specht (Acton, MA)
Assignee: EMC IP Holding Company LLC
G06F21/31G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,102,356
App. No.
15/064,829
Filed
Mar 9, 2016
Granted
Oct 16, 2018
Kind
B1
Art Unit
2434
USPC
726/1
Abstract

Techniques are described providing secure authentication of control commands executed on a data storage system. A pass code may be generated in accordance with criteria in response to successful two-factor authentication of a user identifier. Providing a valid generated passcode may be required with a control command in order for a data storage system to execute the control command. The control command may be one of a subset of possible control command that may be performed with respect to storage entities, such as logical devices and snapshots thereof. In another embodiment, rather than providing a pass code, the two factor authentication information and user identifier may be provided with the control command whereby successful completion of two-factor authentication of the user identifier and two factor authentication information may be required in order to execute the control command.

Claims (42)

1. A method of processing control commands comprising:

receiving first information identifying a first portion of one or more control commands for a second portion of one or more data storage entities, wherein each of the control commands in the first portion is an allowable control command for each of the data storage entities of the second portion;

providing a user identifier and authentication information to a pass code provider;

authenticating the user identifier using the authentication information;

in response to successfully completing said authenticating, generating, by the pass code provider, a pass code used with issuing control commands to at least a first data storage entity of the second portion, wherein said generating uses one or more criteria to generate the pass code and the one or more criteria includes at least one attribute of the first data storage entity;

sending a request to a data storage system over a control path, the request including the pass code and a control command of the first portion;

performing first processing on the data storage system that validates the pass code for use with the control command; and

responsive to successfully validating the pass code, executing the control command.

2. The method of claim 1 , wherein the first portion identifies a subset of allowable control commands.

3. The method of claim 2 , wherein the second portion identifies a subset of one or more data storage entities defined in a data storage system configuration.

4. The method of claim 3 , wherein the second portion identifies a subset of defined logical devices and associated snapshots, and wherein the first portion identifies one or more control commands issued to modify a state associated with any logical device or any snapshot of the second portion.

5. The method of claim 3 , wherein the second portion identifies a subset of defined logical devices and associated snapshots, and wherein the first portion identifies one or more control commands issued to delete any logical device or any snapshot of the second portion.

6. The method of claim 1 , further comprising:

defining one or more policies each identifying a first subset of control commands;

defining a second subset of data storage system entities; and

associating the second subset of data storage system entities with a first of the one or more policies, wherein said associating indicates that each control command identified in said first policy requires a valid pass code to be provided in order for said each control command to be executed by the data storage system.

7. The method of claim 1 , wherein the one or more criteria includes any one or more of: an identifier or serial number of the data storage system, a logical device identifier, a snapshot identifier, a string denoting a date and time, and a network location of the data storage system.

8. The method of claim 7 , wherein the first processing performed by the data storage system that validates the pass code comprises:

determining a computed pass code in accordance with the one or more criteria;

comparing the computed pass code to the pass code received over the control path in the request;

if the computed pass code matches the pass code received, determining that the pass code received has been successfully validated; and

if the computed pass code does not match the pass code received, determining that the pass code received has not been successfully validated.

9. The method of claim 1 , wherein the authentication information is two-factor authentication information and said authentication performs two-factor authentication processing to authenticate the user identifier.

10. The method of claim 9 , wherein the two-factor authentication information includes a user password and a random number generated as part of a random number sequence having a seed value associated with the user identifier.

11. The method of claim 10 , wherein a hardware token or fob generates random numbers of the random number sequence at various points in time and displays each of the generated random numbers on the hardware token or fob at a different one of the various points in time.

12. The method of claim 11 , wherein the hardware token or fob generates a new random number at each occurrence of a fixed time interval.

13. The method of claim 1 , wherein the pass code is valid for any of: performing a specified number of control commands of the first portion, performing any number of control commands of the first portion in a defined time period, and performing any number of control commands before a defined expiration time.

14. The method of claim 1 , wherein the pass code is a hash value generated using a cryptographic hash function having one or more inputs determined in accordance with the one or more criteria.

15. A system comprising:

a processor; and

a memory comprising code stored thereon that, when executed, performs a method of processing control commands comprising:

receiving first information identifying a first portion of one or more control commands for a second portion of one or more data storage entities, wherein each of the control commands in the first portion is an allowable control command for each of the data storage entities of the second portion;

providing a user identifier and authentication information to a pass code provider;

authenticating the user identifier using the authentication information;

in response to successfully completing said authenticating, generating, by the pass code provider, a pass code used with issuing control commands to at least a first data storage entity of the second portion, wherein said generating uses one or more criteria to generate the pass code and the one or more criteria includes at least one attribute of the first data storage entity;

sending a request to a data storage system over a control path, the request including the pass code and a control command of the first portion;

performing first processing on the data storage system that validates the pass code for use with the control command; and

responsive to successfully validating the pass code, executing the control command.

16. The system of claim 15 , wherein the first portion identifies a subset of allowable control commands.

17. The system of claim 16 , wherein the second portion identifies a subset of one or more data storage entities defined in a data storage system configuration.

18. The system of claim 17 , wherein the second portion identifies a subset of defined logical devices and associated snapshots, and wherein the first portion identifies one or more control commands issued to modify a state associated with any logical device or any snapshot of the second portion.

19. A non-transitory computer readable medium comprising code stored thereon that, when executed, performs a method of processing control commands comprising: receiving first information identifying a first portion of one or more control commands for a second portion of one or more data storage entities, wherein each of the control commands in the first portion is an allowable control command for each of the data storage entities of the second portion; providing a user identifier and authentication information to a pass code provider; authenticating the user identifier using the authentication information; in response to successfully completing said authenticating, generating, by the pass code provider, a pass code used with issuing control commands to at least a first data storage entity of the second portion, wherein said generating uses one or more criteria to generate the pass code and the one or more criteria includes at least one attribute of the first data storage entity; sending a request to a data storage system over a control path, the request including the pass code and a control command of the first portion; performing first processing on the data storage system that validates the pass code for use with the control command; and responsive to successfully validating the pass code, executing the control command.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2016
From: SAHIN, ADNAN; SPECHT, MICHAEL
To: EMC CORPORATION
Reel/Frame 037931/0226 →
Cited By (44)
US 12,197,274 US 12,204,657 US 12,204,778 US 12,216,615 US 12,229,402 US 12,235,807 US 12,235,954 US 12,236,121 US 12,236,122 US 12,242,425 US 12,248,566 US 12,254,123 US 12,271,264 US 12,271,359 US 12,287,990 US 12,314,131 US 12,323,437 US 12,339,750 US 12,367,178 US 12,386,782 US 12,399,908 US 12,411,962 US 12,422,984 US 12,430,059 US 12,450,126 US 12,457,214 US 12,481,531 US 12,499,085 US 12,505,079 US 12,511,239 US 12,541,313 US 12,561,125 US 12,561,428 US 12,578,858 US 12,578,971 US 12,585,621 US 12,609,934 US 12,615,251 US 12,639,172 US 12,639,176 US 12,645,576 US 12,650,784 US 12,675,368 US 12,717,689