WO2006116931A1 - Methode garantissant la securite des donnees d'un reseau de stockage et systeme pour celle-ci - Google Patents

Methode garantissant la securite des donnees d'un reseau de stockage et systeme pour celle-ci Download PDF

Info

Publication number
WO2006116931A1
WO2006116931A1 PCT/CN2006/000850 CN2006000850W WO2006116931A1 WO 2006116931 A1 WO2006116931 A1 WO 2006116931A1 CN 2006000850 W CN2006000850 W CN 2006000850W WO 2006116931 A1 WO2006116931 A1 WO 2006116931A1
Authority
WO
WIPO (PCT)
Prior art keywords
storage
data
server
cluster
encryption
Prior art date
Application number
PCT/CN2006/000850
Other languages
English (en)
Chinese (zh)
Inventor
Yaolong Zhu
Hui Xiong
Jie Yan
Original Assignee
Zhang, Jinkui
Zhou, Feng
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhang, Jinkui, Zhou, Feng filed Critical Zhang, Jinkui
Publication of WO2006116931A1 publication Critical patent/WO2006116931A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general

Definitions

  • the method of the present invention provides a security management device for isolating commands and data between a server cluster and a storage device cluster, and the security management device performs data between the two.
  • Processing and security management is equivalent to setting up an intelligent security administrator for the data flow between the server cluster and the storage device cluster.
  • it can realize normal data processing between the server cluster and the storage device cluster.
  • Security measures can be taken in the security management device. For all data flows or special: security measures such as encryption processing, permission management restrictions, etc., data storage and user access under the condition of sharing storage devices for multiple users Provides security measures and safeguards.
  • the security management device simulates the working mode of the storage device and the server respectively, and the security management device can be set by using ordinary server hardware or embedded hardware platform, which can make the method of the invention simple and convenient. Access authorization and/or data encryption/decryption at the storage protocol layer for data processing and security management is fully compatible with existing storage systems, ie compatible with any hardware, operating system and applications.
  • Figure 3 is a flow chart of the user login of the present invention.
  • Figure 6 is a flow chart of the disconnection of the user of the present invention.
  • 1 invention storage network data security management device 2—storage device cluster; 3—server cluster; 4—storage network; 10—security platform of security management device; 20—software platform of security management device; 100—device-side hardware Protocol processing port; 110-server hardware protocol processing port; 120-hard encryption module; 130-key hardware interface; 200-device storage protocol module; 210-server storage protocol module; 220-encryption management module; Software encryption module; 240 - password management module; 250 - rights management module; 260 - encryption algorithm management module; m - key management module; 280 - configuration database.
  • the storage network data security management apparatus 1 is a schematic structural diagram of a storage network data security device of the present invention.
  • the storage network data security management apparatus 1 of the present invention connects the storage device cluster 2 and the server cluster 3 through the storage network 4, and is disposed on the command and data channels between the two to isolate data and commands.
  • the storage network data security management apparatus 1 includes a hardware platform 10 and a software platform 20, and performs data processing and data security management on data transmitted between the server cluster 3 and the storage device cluster 2.
  • the hardware platform 10 includes a device side hardware protocol processing port 100, a server side hardware protocol processing port 110, and a hard encryption module 120.
  • the server side hardware protocol processing port 110 is connected to the server cluster 3, and the device side hardware protocol processing port 100 is connected to the storage device cluster 2.
  • the device-side hardware protocol processing port 100 and the server-side hardware protocol processing port 110 are composed of an underlying hardware system and a processing storage protocol layer.
  • the device-side hardware protocol processing port 100 and the server-side hardware protocol processing port 110 can adopt the most commonly used Ethernet port and the Fibre Channel port.
  • the actual application can adopt the flexible software and hardware configuration mode to implement the functions of each protocol layer, or Take other types of hardware ports.
  • the key hardware interface 130 is responsible for reading the hard key, and may be any method such as the USB interface reading the USB key or the IC card reader interface reading the IC card.
  • Figure 6 is a flow chart of the disconnection of the user of the present invention. As shown in FIG. 6, to ensure data security, the present invention deletes the key from the configuration database 280 when the user disconnects. If the user has further requirements, the password for the user login can also be cleared.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)

Abstract

L'invention concerne une méthode et un système garantissant la sécurité des données d'un réseau de stockage et comportant un dispositif de gestion de la sécurité disposé dans le canal de données entre le cluster serveur et le cluster de dispositifs de stockage du réseau de stockage. Le dispositif de gestion de la sécurité isole les commandes et données échangées entre le cluster serveur et le cluster de dispositifs de stockage et traite et gère entre eux de façon sécurisée les commandes et les données qu'ils échangent. La méthode peut appliquer un processus normal aux données, d'une part, et peut appliquer différentes mesures de sécurité pour traiter de façon sécurisée tous les flux de données ou les flux spéciaux de données, d'autre part, de façon à appliquer des mesures de sécurité et sécuriser le stockage de données partagées multi-utilisateur et les accès utilisateur.
PCT/CN2006/000850 2005-04-29 2006-04-29 Methode garantissant la securite des donnees d'un reseau de stockage et systeme pour celle-ci WO2006116931A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200510011667.2 2005-04-29
CNB2005100116672A CN100385860C (zh) 2005-04-29 2005-04-29 一种保障存储网络数据安全的方法及装置

Publications (1)

Publication Number Publication Date
WO2006116931A1 true WO2006116931A1 (fr) 2006-11-09

Family

ID=35353226

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2006/000850 WO2006116931A1 (fr) 2005-04-29 2006-04-29 Methode garantissant la securite des donnees d'un reseau de stockage et systeme pour celle-ci

Country Status (2)

Country Link
CN (1) CN100385860C (fr)
WO (1) WO2006116931A1 (fr)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102025503A (zh) * 2010-11-04 2011-04-20 北京曙光天演信息技术有限公司 一种集群环境下数据安全实现方法和一种高安全性的集群
CN115378646A (zh) * 2022-07-14 2022-11-22 刘书凯 一种计算机通信的网络安全监测系统

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101877783B (zh) * 2009-11-06 2012-01-25 北京邦诺存储科技有限公司 网络视频存储器集群化视频监控系统和方法
CN102244649B (zh) * 2010-05-12 2015-06-10 杭州华三通信技术有限公司 一种安全网络间传输数据的方法和资料处理机
CN102420820B (zh) 2011-11-28 2016-06-08 杭州华三通信技术有限公司 一种集群系统中的隔离方法和装置
CN102761538B (zh) * 2012-04-27 2014-10-22 南大傲拓科技江苏有限公司 应用于多种通讯接口网关的通信共享数据区设计管理方法
CN104243510B (zh) * 2013-06-07 2018-08-14 中国科学院声学研究所 一种安全网络存储系统与方法
CN104579689B (zh) * 2015-01-20 2018-02-13 中城智慧科技有限公司 一种软密钥系统及实现方法
CN108667867B (zh) * 2017-03-29 2021-05-18 华为技术有限公司 数据存储方法及装置
CN111259227B (zh) * 2020-01-16 2023-11-10 北京旷视科技有限公司 用于在多个检索集群之间共享目标检索服务的方法和装置
CN112348513A (zh) * 2020-09-09 2021-02-09 中诚区块链研究院(南京)有限公司 一种能够提供多种加密方式交易区块链

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003158538A (ja) * 2001-11-22 2003-05-30 Anritsu Corp ゲートウェイ装置及び該装置を用いたアクセス方法
US20040078599A1 (en) * 2001-03-01 2004-04-22 Storeage Networking Technologies Storage area network (san) security
US20040088574A1 (en) * 2002-10-31 2004-05-06 Brocade Communications Systems, Inc. Method and apparatus for encryption or compression devices inside a storage area network fabric

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6172988B1 (en) * 1996-01-31 2001-01-09 Tiernan Communications, Inc. Method for universal messaging and multiplexing of video, audio, and data streams
US6292657B1 (en) * 1998-07-13 2001-09-18 Openwave Systems Inc. Method and architecture for managing a fleet of mobile stations over wireless data networks
US7546360B2 (en) * 2002-06-06 2009-06-09 Cadence Design Systems, Inc. Isolated working chamber associated with a secure inter-company collaboration environment

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040078599A1 (en) * 2001-03-01 2004-04-22 Storeage Networking Technologies Storage area network (san) security
JP2003158538A (ja) * 2001-11-22 2003-05-30 Anritsu Corp ゲートウェイ装置及び該装置を用いたアクセス方法
US20040088574A1 (en) * 2002-10-31 2004-05-06 Brocade Communications Systems, Inc. Method and apparatus for encryption or compression devices inside a storage area network fabric

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102025503A (zh) * 2010-11-04 2011-04-20 北京曙光天演信息技术有限公司 一种集群环境下数据安全实现方法和一种高安全性的集群
CN115378646A (zh) * 2022-07-14 2022-11-22 刘书凯 一种计算机通信的网络安全监测系统

Also Published As

Publication number Publication date
CN1694415A (zh) 2005-11-09
CN100385860C (zh) 2008-04-30

Similar Documents

Publication Publication Date Title
WO2006116931A1 (fr) Methode garantissant la securite des donnees d'un reseau de stockage et systeme pour celle-ci
CN110176987B (zh) 一种设备认证的方法、装置、设备和计算机存储介质
CN106549750B (zh) 以计算机实施的方法与使用其的系统、及计算机程序产品
US9578034B2 (en) Trusted peripheral device for a host in a shared electronic environment
US6907457B2 (en) Architecture for access to embedded files using a SAN intermediate device
US8335915B2 (en) Encryption based security system for network storage
US6971016B1 (en) Authenticated access to storage area network
US7320071B1 (en) Secure universal serial bus
US7917751B2 (en) Distributed filesystem network security extension
JP3922886B2 (ja) 基本パスワードをリモートで復元するデータ処理のシステム及び方法
US20080022120A1 (en) System, Method and Computer Program Product for Secure Access Control to a Storage Device
TWI620093B (zh) 用於保全電腦大容量儲存資料的方法和裝置
US20100153703A1 (en) Storage security using cryptographic splitting
US8719923B1 (en) Method and system for managing security operations of a storage server using an authenticated storage module
US20150244778A1 (en) Assembling of Isolated Remote Data
WO2015196890A1 (fr) Procédé de commande d'accès de sécurité pour disque dur et disque dur
CN1551003A (zh) 用于正在处理中的加密/解密usb数据的动态置换
US7461135B2 (en) Computer and access control method in a computer
JP4087149B2 (ja) ディスク装置共有システム、及び計算機
WO2002093314A2 (fr) Systeme de protection fonde sur le cryptage pour le stockage des donnees de reseaux
CN105279453A (zh) 一种支持分离存储管理的文件分区隐藏系统及其方法
US7493429B2 (en) Communication of information via a side-band channel, and use of same to verify positional relationship
US8291176B2 (en) Protection domain groups to isolate access to memory windows
KR101115358B1 (ko) 방송장치 감시장치를 포함하는 스마트워크 컴퓨터
CN102665055A (zh) 一种io远程映射设备及方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application
NENP Non-entry into the national phase

Ref country code: DE

WWW Wipo information: withdrawn in national office

Country of ref document: DE

NENP Non-entry into the national phase

Ref country code: RU

WWW Wipo information: withdrawn in national office

Country of ref document: RU

122 Ep: pct application non-entry in european phase

Ref document number: 06722423

Country of ref document: EP

Kind code of ref document: A1

WWW Wipo information: withdrawn in national office

Ref document number: 6722423

Country of ref document: EP