I/o authorization control in shared storage systems

US2019324924A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2019324924-A1
Application numberUS-201815959185-A
CountryUS
Kind codeA1
Filing dateApr 21, 2018
Priority dateApr 21, 2018
Publication dateOct 24, 2019
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for limiting I/O access in shared storage systems is disclosed. In one embodiment, such a method includes establishing, for a volume, a list of address spaces that are authorized to access the volume. The method further receives an I/O request to access the volume and determines whether the I/O request originates from one of the address spaces identified in the list. If the I/O request originates from one of the address spaces in the list, the method passes the I/O request to the volume. If, on the other hand, the I/O request does not originate from one of the address spaces in the list, the method blocks the I/O request. A corresponding system and computer program product are also disclosed.

First claim

Opening claim text (preview).

1 . A method for limiting I/O access in a shared storage system, the method comprising: establishing, for a volume, a list of address spaces that are authorized to access the volume; receiving an I/O request to access the volume; determining whether the I/O request originates from one of the address spaces identified in the list; if the I/O request originates from one of the address spaces in the list, passing the I/O request to the volume; and if the I/O request does not originate from one of the address spaces in the list, blocking the I/O request. 2 . The method of claim 1 , further comprising passing the I/O request to the volume if the I/O request is a system-level I/O request, regardless of whether the I/O request originates from one of the address spaces identified in the list, wherein the system-level I/O request is an I/O request that is associated with operating system or system recovery operations. 3 . The method of claim 1 , wherein the volume is one of a logical volume and a physical volume. 4 . The method of claim 1 , further comprising setting an error code in the event the I/O request is blocked. 5 . The method of claim 1 , wherein the list of address spaces is implemented as a hash table. 6 . The method of claim 1 , wherein each address space is associated with a particular job name. 7 . The method of claim 1 , wherein the list is maintained at the host-system level. 8 . A computer program product for limiting I/O access in a shared storage system, the computer program product comprising a non-transitory computer-readable storage medium having computer-usable program code embodied therein, the computer-usable program code configured to perform the following when executed by at least one processor: establish, for a volume, a list of address spaces that are authorized to access the volume; receive an I/O request to access the volume; determine whether the I/O request originates from one of the address spaces identified in the list; if the I/O request originates from one of the address spaces in the list, pass the I/O request to the volume; and if the I/O request does not originate from one of the address spaces in the list, block the I/O request. 9 . The computer program product of claim 8 , wherein the computer-usable program code is further configured to pass the I/O request to the volume if the I/O request is a system-level I/O request, regardless of whether the I/O request originates from one of the address spaces identified in the list, wherein the system-level I/O request is an I/O request that is associated with operating system or system recovery operations. 10 . The computer program product of claim 8 , wherein the volume is one of a logical volume and a physical volume. 11 . The computer program product of claim 8 , wherein the computer-usable program code is further configured to set an error code in the event the I/O request is blocked. 12 . The computer program product of claim 8 , wherein the list of address spaces is implemented as a hash table. 13 . The computer program product of claim 8 , wherein each address space is associated with a particular job name. 14 . The computer program product of claim 8 , wherein the list is maintained at the host-system level. 15 . A system for limiting I/O access in a shared storage system, the system comprising: at least one processor; at least one memory device operably coupled to the at least one processor and storing instructions for execution on the at least one processor, the instructions causing the at least one processor to: establish, for a volume, a list of address spaces that are authorized to access the volume; receive an I/O request to access the volume; determine whether the I/O request originates from one of the address spaces identified in the list; if the I/O request originates from one of the address spaces in the list, pass the I/O request to the volume; and if the I/O request does not originate from one of the address spaces in the list, block the I/O request. 16 . The system of claim 15 , wherein the instructions further cause the at least one processor to pass the I/O request to the volume if the I/O request is a system-level I/O request, regardless of whether the I/O request originates from one of the address spaces identified in the list, wherein the system-level I/O request is an I/O request that is associated with operating system or system recovery operations. 17 . The system of claim 15 , wherein the volume is one of a logical volume and a physical volume. 18 . The system of claim 15 , wherein the instructions further cause the at least one processor to set an error code in the event the I/O request is blocked. 19 . The system of claim 15 , wherein the list of address spaces is implemented as a hash table. 20 . The system of claim 15 , wherein each address space is associated with a particular job name.

Assignees

Inventors

Classifications

  • Permissions · CPC title

  • in relation to access · CPC title

  • G06F3/067Primary

    Distributed or networked storage systems, e.g. storage area networks [SAN], network attached storage [NAS] · CPC title

  • at device level, e.g. emulation of a storage device or system · CPC title

  • Security improvement · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2019324924A1 cover?
A method for limiting I/O access in shared storage systems is disclosed. In one embodiment, such a method includes establishing, for a volume, a list of address spaces that are authorized to access the volume. The method further receives an I/O request to access the volume and determines whether the I/O request originates from one of the address spaces identified in the list. If the I/O request…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification G06F3/067. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Oct 24 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).