System for storing data and method for operating a storage system

By switching the storage device to read-only mode and reallocating stripes and drive identifiers, the inoperability of the storage device in the event of an internal failure is resolved, achieving stable operation and data reliability of the fail-resilient storage device.

CN114003167BActive Publication Date: 2026-07-21SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2021-06-02
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing storage devices and systems are prone to becoming inoperable when they encounter internal failures, lacking fault resilience and unable to maintain partial capabilities or restore full functionality in various resilience modes.

Method used

A method for operating a fail-safe storage device is achieved by switching the storage device to read-only mode and reallocating stripes and drive identifiers, and using a second storage device for write and read operations. This includes reallocating stripes in a RAID-0 storage system to accommodate write operations.

Benefits of technology

When a storage device encounters an internal failure, it can maintain partial capability or restore full functionality in various resilience modes, ensuring data reliability and system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114003167B_ABST
    Figure CN114003167B_ABST
Patent Text Reader

Abstract

A system for storing data and a method for operating a storage system are disclosed. In some embodiments, the system includes a first storage device and a second storage device, and the method includes: determining that the first storage device is in a read-only state and the second storage device is in a read-write state; performing a write operation of a first stripe on the storage system; performing a first read operation of a second stripe from the storage system; and performing a second read operation of the first stripe from the storage system, wherein the step of performing the write operation includes: writing a portion of the first stripe to the second storage device, and making an entry for the first stripe in a mapping table.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more aspects of embodiments of this disclosure relate to data storage systems, and more specifically, to data storage systems and apparatus configured to exhibit resiliency in the presence of internal failure conditions. Background Technology

[0002] This background section is intended to provide context only, and the disclosure of any embodiments or concepts in this section does not constitute an admission that the embodiments or concepts are prior art.

[0003] Storage devices and systems are widely applicable in a variety of data processing systems. Storage devices are complex enough to encounter a wide range of internal failure conditions, including, for example, temperature sensor failure or bit flips caused by radiation. If these failure conditions are not considered in the design of the storage device or the system using such a storage device (e.g., a redundant array of independent disks (RAID)), a single failure in the storage device can render the entire storage device, and perhaps even a larger system including the storage device (such as a RAID), inoperable.

[0004] Therefore, there is a need for a system and method for the flexible operation of storage devices and systems including storage devices.

[0005] Technical issues

[0006] The purpose of this invention is to provide a RAID system with fault-tolerant storage, which can operate in various resilience modes while maintaining partial capability or recovering full functionality regardless of internal failures. Summary of the Invention

[0007] In some embodiments, a fail-resilient storage device can operate in various resilience modes while maintaining partial capability or recovering full functionality regardless of internal failures. In some cases, one way a storage device can maintain partial capability is by operating in read-only mode, in which the storage device responds to read requests from the host and returns an error message if it receives a write request from the host. In a RAID-0 storage system, the possibility of a storage device switching to read-only mode can be accommodated by reallocating the stripes constituting the stripes for any write operations performed after the storage device has switched to read-only mode.

[0008] According to an embodiment of the present invention, a method for operating a storage system including a first storage device and a second storage device is provided. The method includes: determining that the first storage device is in a read-only state and the second storage device is in a read-write state; performing a write operation on a first stripe of the storage system; performing a first read operation on a second stripe of the storage system; and performing a second read operation on the first stripe of the storage system. The step of performing the write operation includes: writing a portion of the first stripe to the second storage device and creating an entry for the first stripe in a mapping table. The step of performing the first read operation includes: reading a portion of the second stripe from the first storage device and the second storage device. The step of performing the second read operation includes: determining that the mapping table includes an entry for the first stripe and reading a portion of the first stripe from the second storage device.

[0009] In some embodiments, the storage system includes a plurality of storage devices including a first storage device and a second storage device, and the step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, the remaining storage devices including the second storage device, and the step of performing a write operation includes: writing a first stripe to the remaining storage devices.

[0010] In some embodiments, the step of performing the first read operation includes: determining that the second stripe is open-mapped within the plurality of storage devices, and reading the second stripe from the plurality of storage devices.

[0011] In some embodiments, the method further includes: reassigning drive identifiers to the remaining storage devices, wherein each of the plurality of storage devices has an original drive identifier, and the reassignment step includes: assigning a corresponding original drive identifier to each storage device having an identifier number less than the original drive identifier number of the first storage device; and subtracting from the corresponding original drive identifier number an identifier number assigned to each storage device having an identifier number greater than the original drive identifier number of the first storage device.

[0012] In some embodiments, the step of performing the second read operation includes: reading a first stripe from the remaining storage device, and reading a stripe of the first stripe from the storage device at an address based on a mapping table.

[0013] In some embodiments, the method further includes: reassigning drive identifiers to the remaining storage devices, wherein each of the plurality of storage devices has an original drive identifier, and the reassignment step includes: assigning a corresponding original drive identifier to each storage device having an identifier that is less than the original drive identifier of the first storage device.

[0014] In some embodiments, the reallocation step further includes: subtracting an identifier assigned to each storage device that has an original drive identifier greater than the original drive identifier of the first storage device from the corresponding original drive identifier.

[0015] In some embodiments, the original drive identifier of the first storage device is n, and the step of reading a strip of the first strip includes: reading a strip from the storage device having a reassigned identifier n.

[0016] According to an embodiment of the present invention, a system for storing data is provided, the system comprising: a first storage device; a second storage device; and a processing circuit connected to the first storage device and the second storage device, the processing circuit being configured to: determine that the first storage device is in a read-only state and the second storage device is in a read-write state; perform a write operation on a first stripe; perform a first read operation on a second stripe; and perform a second read operation on the first stripe, wherein the step of performing the write operation includes: writing a portion of the first stripe to the second storage device and creating an entry for the first stripe in a mapping table, the step of performing the first read operation includes: reading a portion of the second stripe from the first storage device and the second storage device, and the step of performing the second read operation includes: determining that the mapping table includes an entry for the first stripe, and reading a portion of the first stripe from the second storage device.

[0017] In some embodiments, the system includes a plurality of storage devices including a first storage device and a second storage device, wherein the step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, the remaining storage devices including the second storage device, and the step of performing a write operation includes: writing a first stripe to the remaining storage devices.

[0018] In some embodiments, the step of performing the first read operation includes: determining that the second stripe is open-mapped within the plurality of storage devices, and reading the second stripe from the plurality of storage devices.

[0019] In some embodiments, the processing circuitry is further configured to: reallocate drive identifiers to the remaining storage devices, wherein each of the plurality of storage devices has an original drive identifier, and the reallocation step includes: assigning a corresponding original drive identifier to each storage device having an identifier number less than the original drive identifier number of the first storage device; and subtracting from the corresponding original drive identifier number an identifier number assigned to each storage device having an identifier number greater than the original drive identifier number of the first storage device.

[0020] In some embodiments, the step of performing the second read operation includes: reading a first stripe from the remaining storage device, and reading a stripe of the first stripe from the storage device at an address based on a mapping table.

[0021] In some embodiments, the processing circuitry is further configured to: reassign drive identifiers to the remaining storage devices, wherein each of the plurality of storage devices has an original drive identifier, and the reassignment step includes: assigning a corresponding original drive identifier to each storage device having an identifier that is less than the original drive identifier of the first storage device.

[0022] In some embodiments, the processing circuitry is further configured to subtract an identifier assigned to each storage device having an identifier greater than the original drive identifier of the first storage device from the corresponding original drive identifier.

[0023] In some embodiments, the original drive identifier of the first storage device is n, and the step of reading a strip of the first strip includes: reading a strip from the storage device having a reassigned identifier n.

[0024] According to an embodiment of the present invention, a system for storing data is provided, the system comprising: a first storage device; a second storage device; and a processing device connected to the first storage device and the second storage device, the processing device being configured to: determine that the first storage device is in a read-only state and the second storage device is in a read-write state; perform a write operation on a first stripe; perform a first read operation on a second stripe; and perform a second read operation on the first stripe, wherein the step of performing the write operation comprises: writing a portion of the first stripe to the second storage device, and creating an entry for the first stripe in a mapping table; the step of performing the first read operation comprises: reading a portion of the second stripe from the first storage device and the second storage device; and the step of performing the second read operation comprises: determining that the mapping table includes an entry for the first stripe, and reading a portion of the first stripe from the second storage device.

[0025] In some embodiments, the system includes a plurality of storage devices including a first storage device and a second storage device, wherein the step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, the remaining storage devices including the second storage device, and the step of performing a write operation includes: writing a first stripe to the remaining storage devices.

[0026] In some embodiments, the step of performing the first read operation includes: determining that the second stripe is open-mapped within the plurality of storage devices, and reading the second stripe from the plurality of storage devices.

[0027] In some embodiments, the means for processing is further configured to: reallocate drive identifiers to the remaining storage devices, wherein each of the plurality of storage devices has an original drive identifier, and the reallocation step includes: assigning a corresponding original drive identifier to each storage device having an identifier number less than the original drive identifier number of the first storage device; and subtracting from the corresponding original drive identifier number an identifier number assigned to each storage device having an identifier number greater than the original drive identifier number of the first storage device.

[0028] According to embodiments of this disclosure, a RAID system with fail-resilient storage is provided for operating in various resilience modes while maintaining partial capability or restoring full functionality regardless of internal failures. Attached Figure Description

[0029] The accompanying drawings provided herein are for illustrative purposes only; other embodiments, which may not be explicitly described, are not excluded from the scope of this disclosure.

[0030] These and other features and advantages of this disclosure will be appreciated and understood by referring to the specification, claims and drawings, wherein:

[0031] Figure 1 This is a block diagram of a data storage system according to an embodiment of the present disclosure;

[0032] Figure 2A This is a table of fault states of a storage device according to embodiments of the present disclosure;

[0033] Figure 2B This is a table of operating modes of a storage device according to embodiments of the present disclosure;

[0034] Figure 2C It is a table of commands sent from a host to a storage device according to embodiments of the present disclosure;

[0035] Figure 2D This is a table illustrating the hierarchy of flexible modes according to embodiments of this disclosure;

[0036] Figure 3A This is a flowchart of a first operation method of a fault-tolerant storage device according to an embodiment of the present disclosure;

[0037] Figure 3B This is a flowchart of a second operation method of a fault-tolerant storage device according to an embodiment of the present disclosure;

[0038] Figure 4 This is a schematic data layout diagram of a storage device according to an embodiment of the present disclosure;

[0039] Figure 5AThis is a flowchart of a first operation method of a storage device in fail-resilient read-only mode according to an embodiment of the present disclosure;

[0040] Figure 5B This is a flowchart of a second operation method for a storage device in fail-resilient read-only mode according to an embodiment of the present disclosure;

[0041] Figure 6A This is a schematic data layout diagram of a RAID-0 system performing write operations according to an embodiment of the present invention;

[0042] Figure 6B This is a schematic data layout diagram of a RAID-0 system performing a read operation according to an embodiment of the present disclosure;

[0043] Figure 6C This is a schematic data layout diagram of a RAID-0 system performing remapping and write operations according to embodiments of the present disclosure;

[0044] Figure 7A This is a flowchart of a first operating method of a RAID-0 storage system according to an embodiment of the present disclosure; and

[0045] Figure 7B This is a flowchart of a second operating method of a RAID-0 storage system according to an embodiment of the present disclosure. Detailed Implementation

[0046] The detailed description set forth below in conjunction with the accompanying drawings is intended as a description of exemplary embodiments of systems and methods for resilient operation of storage devices and systems including storage devices provided in this disclosure, and is not intended to represent the only forms in which this disclosure may be constructed or utilized. This description, in conjunction with the illustrated embodiments, illustrates the features of this disclosure. However, it should be understood that the same or equivalent functions and structures may be implemented by different embodiments, which are also intended to be included within the scope of the disclosure. As indicated elsewhere herein, the same element reference numerals are intended to indicate the same elements or features.

[0047] In some embodiments, a fail-resilient storage device may be able to operate in various resilience modes regardless of internal failures and may retain partial capability or restore full functionality. For example, in response to a temperature sensor failure, the storage device may operate at a reduced rate, or at a reduced rate for write operations, or it may completely cease write operations. In response to a transient failure that may have damaged the storage medium, the storage device may reformat the storage medium. In response to a transient failure that has not damaged the storage medium, the storage device may cycle power. In some cases, one way the storage device can maintain partial capability is by operating in read-only mode, in which the storage device responds to read requests from the host, and returns an error message if the storage device receives a write request from the host. It may also move data that is about to expire to a rescue area so that the data is not lost due to expiration. In a RAID-0 storage system, the possibility of the storage device switching to read-only mode can be accommodated by reallocating the stripes that make up the stripes for any write operations performed after the storage device has switched to read-only mode.

[0048] Figure 1 A computing system is illustrated, comprising a host 105 connected to one or more storage devices 110 (or “drives”). The storage devices 110 may be connected to the host 105 via a volume manager 115 (discussed in further detail below), or they may be directly connected to the host 105. In some embodiments, the storage devices 110 may experience internal failure conditions, and the storage devices may exhibit various resilient behaviors to mitigate the system-level impact of failure conditions, as discussed in further detail below. Each storage device 110 may be a solid-state drive (SSD), and it may include a controller 120 (or “control circuitry”) and a storage medium 125 (e.g., NAND flash memory). The smallest erasable unit in the storage device 110 may be referred to as a “block,” and the smallest writable unit in the storage device 110 may be referred to as a “page.” Each storage device 110 may have a form factor suitable for any one of a plurality of form factors for persistent storage devices, including but not limited to 2.5”, 1.8”, MO-297, MO-300, M.2, and Enterprise and Data Center SSD form factor (EDSFF), and may have an electrical interface through which it can connect to host 105, which is any one of a plurality of interfaces suitable for persistent storage devices, including Peripheral Component Interconnect (PCI), PCIe, Ethernet, Small Computer System Interface (SCSI), Serial AT Accessory (SATA), and Serial Attached SCSI (SAS).

[0049] Storage medium 125 may have a retention period (which may depend on the usage history of storage medium 125 and therefore may vary within storage medium 125); data that has been stored longer than the retention period (i.e., data with a lifespan exceeding the retention period) may become unreliable and can be said to have expired. Error-correcting codes may be used to store data in storage medium 125; these error-correcting codes may be block codes. When data is read from storage medium 125, a certain amount of raw data, referred to as a code block, can be read from storage medium 125, and an attempt can be made to decode it. If the attempt fails, additional attempts (read retry) can be made. During use, a portion of storage medium 125 (e.g., a block) may deteriorate to the point that the retention period becomes unacceptably short, and that block may be classified as a "bad block". To prevent this situation from rendering the entire storage medium 125 inoperable, a reserved space known as a "bad block management reserve" may exist (e.g., included in each flash die or in each flash plane), and the controller 120 or another controller inside the flash die or flash plane may start using the reserved blocks and stop using the bad blocks.

[0050] Figure 2A This is a table of fault conditions (or "fault states"), each marked with a condition identifier ("condition ID"). Condition 1 is any fault condition in which storage device 110 is no longer able to perform read or write operations and cannot be resolved by power-on or reformatting the storage medium. The state of storage device 110 in this manner may have various sub-states, where, for example, each sub-state corresponds to a different fault mechanism. Such a state or fault condition (storage device 110 is no longer able to perform read or write operations and cannot be resolved by power-on or reformatting the storage medium) may be caused, for example, by a corrupted portion of the controller's firmware (in which case the controller may be rebooted into a safe mode where corrupted instructions are not executed) or by a failure of the processing circuitry in storage device 110 (e.g., a failure of the processing circuitry that manages interaction with the storage medium but is not responsible for communication with host 105). When this type of fault condition occurs, storage device 110 may respond to any read or write commands from host 105 using error messages.

[0051] Case 2 is any of the following failure conditions: (i) a failure condition in which the storage device 110 is no longer able to perform read or write operations, and (ii) a failure condition that can be recovered by powering on the storage device 110 or by reformatting the storage medium. Such a failure condition may be caused, for example, by a program execution error in the controller 120 of the storage device 110 (e.g., an out-of-range pointer due to a bit flip in the random access memory (RAM) of the controller 120, or an incorrect instruction due to a bit flip). If the program execution error has not yet caused the controller 120 to write incorrect data to the storage medium 125 (e.g., if the program execution error has occurred since the controller's most recent write to the storage medium), powering on the storage device may be sufficient to restore the storage device 110 to normal operation; if the program execution error has caused the controller 120 to write erroneous data to the storage medium 125, reformatting the storage medium 125 may be sufficient to restore the storage device 110 to normal operation.

[0052] Case 3 can be mitigated by operating storage device 110 in read-only mode, and reformatting storage medium 125 will not restore all the functions targeted by any fault conditions. Examples of such faults include (i) a temperature sensor failure, and (ii) a portion of storage medium 125 has been converted to read-only mode. In the case of a temperature sensor failure, the fault can be detected by determining that the temperature sensor reading is out of range (e.g., has exceeded a threshold temperature), and in such a case, the risk of overheating of storage device 110 can be reduced by avoiding write operations, which can dissipate more power than read operations. For example, if the flash memory plane or die runs out of bad block management reserve space used for runtime bad block management, a portion of storage medium 125 may be converted to read-only mode. For example, storage device 110 may make an unsuccessful attempt to decode a data item while attempting to perform a read operation, determine that the block storing the data is a bad block, and determine that the remaining bad block management reserve space is less than a threshold size and therefore insufficient to ensure the reliability of the plane or die when moving the data from the bad block to the bad block management reserve space. Then, storage device 110 can determine that bad block management is no longer being performed and switch to read-only mode. The operation of read-only mode is discussed in further detail below. As used herein, a "data item" is any amount of data processed in an operation; for example, data resulting from decoding a block of code can be a data item.

[0053] Case 4 is any failure condition that can be mitigated by operating storage device 110 in write-through mode. For example, if the power backup capacitor in storage device 110 fails, the device can complete the write to storage medium 125 before sending a completion command to host 105 in response to any write command received from the host, so that if the power supply fails before the write to storage medium 125 has been completed, the host will not be incorrectly notified that the write has been successfully completed. Operating in write-through mode can result in performance degradation (in terms of throughput and latency).

[0054] Case 5 is any failure condition that can be mitigated by operating the storage device 110 in a manner that reduces power dissipation. For example, in the event of a temperature sensor failure, the storage device 110 may operate in read-only mode as described above, or it may reduce the rate at which operations are performed (e.g., write operations, which may dissipate more power than read operations) to reduce power dissipation in the storage device 110. For example, the storage device 110 may perform a first write to the storage medium, then wait for an interval corresponding to reduced performance (the waiting period results in a reduction in the rate at which write operations are performed), and then perform another (e.g., a second) write to the storage medium.

[0055] Case 6 is that any fault condition can be mitigated by operating storage device 110 in read-only mode and reformatting storage medium 125 will restore full functionality. For each case, Figure 2A The third column of the table indicates whether valid user data is still available, and whether storage device 110 can be restored to full functionality, for example, by reformatting storage medium 125.

[0056] like Figure 2A As illustrated in the examples listed, in some embodiments, storage device 110 can implement three levels of fault resilience (full resilience mode, partial resilience mode, and vulnerable mode). In full resilience mode, storage device 110 can operate with a "self-recovery" feature, and (although user data in the device may be lost) storage device 110 can be able to recover full functionality by resetting operations such as power restart or formatting storage medium 125.

[0057] In partial resilience mode, storage device 110 may operate with lower performance, smaller capacity, or reduced capability in the event of a failure condition. For example, as described above, if the power backup capacitor fails, all writes can be completed (i.e., command completion can be sent to host 105) only after data is written to storage medium 125 (i.e., only synchronous writes can be performed), thus slowing down the operation of storage device 110 and reducing its performance. In this case, user data can be preserved. If the reserved space for runtime bad blocks (RTBB) used for bad block management is exhausted, storage device 110 may operate with a smaller capacity. In this case, affected dies in storage device 110 can be excluded from disk space, and the overall disk capacity can be reduced. User data on lost space may be lost. For example, if a set in IO determinism or a region in a partition namespace can no longer accept new data writes, the set or region can be excluded from disk space, but the remaining disk space can remain available for read and write operations. User data on a region or set may be lost.

[0058] If storage device 110 disallows write operations and switches to read-only mode, storage device 110 can operate with reduced capabilities. Storage device 110 may be able to operate in two types of read-only modes: persistent read-only mode and non-persistent read-only mode. In persistent read-only mode, storage device 110 can continue to serve read requests outside the retention period of storage medium 125. In non-persistent read-only mode, storage device 110 can continue to serve read requests during the retention period of storage medium 125, and if storage device 110 encounters a data integrity problem (e.g., detected by one or more unsuccessful attempts to decode data during a read operation), storage device 110 can report invalid data areas. As described above, storage device 110 operating in vulnerable mode may be unable to perform read or write operations and may gracefully exit, continuing to receive commands from the host and returning errors.

[0059] In some embodiments, five logical block address (LBA) space types may be defined, referred to as (i) execution space (P), (ii) poor performance space (UP), (iii) read-only space (RO), (iv) volatile read-only space (VRO), and (v) inaccessible space (IA). An execution (P) space may be an LBA space containing valid data that can be read and written normally without sacrificing performance. A poor performance (UP) space may be an LBA space containing valid data that can be read and written normally, but with reduced performance (e.g., reduced write performance). A read-only (RO) space may be an LBA space containing only read-only valid data. Storage device 110 may respond to write commands from the host to this type of LBA space using error messages. Data in a read-only space may remain valid for a period exceeding the retention period. A volatile read-only (VRO) space may be read-only, and storage device 110 may respond to write commands from the host to this type of LBA space using error messages. Data in this type of LBA space may be temporarily valid and may become invalid upon its expiration (i.e., when the lifetime of the data in storage medium 125 reaches the retention period of storage medium 125). Inaccessible (IA) space may be an LBA space containing invalid data that is inaccessible to the host. Figure 2B The table represents the combination of LBA space types that may exist in storage device 110 for each fault condition identified in the first column. Patterns identified by an asterisk (*) allow the host to obtain detailed information about the LBA space using the get feature command. Figure 2C The arguments for the “Get Features” command are shown. The “Get Features” command can be passed to storage device 110 to query storage device 110 for values ​​of its state and associated parameters (“IOPS” stands for Input and Output Operations per Second).

[0060] Figure 2D The representation indicates that the host 105 can use to query the storage device 110 for non-volatile memory fast (NVMe) commands about its status, and the hierarchy of enumerated constants that the storage device 110 can use to respond.

[0061] Figure 3AThis is a flowchart of a method for operating in a fail-resilient mode in some embodiments. At 305, host 105 sends data to and / or receives data from storage device; at 310, host 105 determines whether an error has occurred in storage device; at 315, storage device 110 performs internal diagnostics and determines its fail-resilient state (e.g., fully resilient, partially resilient, or vulnerable); at 320, storage device 110 modifies its performance, capacity, or capability based on the diagnostics (e.g., switches to read-only mode); at 325, storage device 110 publishes its state based on an application programming interface (API) upon request from host 105; and at 330, host 105 routes data of a given type to storage device 110 or a different storage device 110 with a given bandwidth based on the state. Figure 3B This is a flowchart illustrating details of a method for operating in a fail-resilient mode. The method includes: at 335, determining that the storage device is in a first failure state, wherein recovery from the first failure state is feasible by powering on the storage device or by formatting the storage medium; at 340, determining that the storage device is in a second failure state, wherein partial recovery from the second failure state is feasible by operating the storage device with reduced performance, reduced capacity, or read-only mode; and at 345, operating the storage device with reduced performance, reduced capacity, or read-only mode.

[0062] Multiple embodiments and variations of the embodiments disclosed herein can also be constructed. A field-programmable gate array (FPGA) or embedded processor can perform internal block checks and send asynchronous updates about the status of storage device 110 to host 105. Events can occur and be sent to host 105 (e.g., temperature or other parameters within the device). If no device driver feature is available to provide notification, host 105 can poll storage device 110 according to a predetermined schedule. The FPGA or embedded processor can monitor the historical performance of storage device 110 and use machine learning to provide predictive analytics (e.g., the probability of being in a given fault-resistant state). Commands can be introduced in the NVMe specification; for example, telemetry information from the NVMe specification can be extended (to report the status of storage device 110). Some embodiments can be implemented in, for example, Ethernet storage devices or key-value (KV) storage devices.

[0063] In some embodiments, the host may (i) send different data types (e.g., file types such as images, videos, text, or high-priority or low-priority data) based on the state of storage device 110 (e.g., high-priority data or real-time data may not be written to devices considered to be in a partially vulnerable mode); (ii) reduce the transfer rate if storage device 110 is in a partially vulnerable state and in a low-performance state; (iii) send a reduced total amount of data if storage device 110 is in a partially vulnerable and low-capacity state; (iv) read data at the maximum possible rate and store the data elsewhere if storage device 110 is in a partially vulnerable unsustainable read-only mode to avoid exceeding the hold period (in which case the host may calculate the required data rate based on the amount of data to be copied and the hold period); (v) ignore data that is “read” from vulnerable storage device 110 because it is erroneous and simply delete the data when the host 105 receives the data; and (vi) temporarily reroute read / write inputs and outputs to a cache in a fully resilient storage device 110 that is being power-rebooted or formatted, based on messages that control the timing of such events between the host and storage device 110. An FPGA on a partially vulnerable SSD with reduced capacity can filter incoming data writes and write only a portion of that data to storage device 110. In some cases, filtering may include compression. Such an FPGA can receive various types of data (e.g., file types such as images, videos, text, or high-priority or low-priority data) from host 105 and filter based on the state of storage device 110. For example, the FPGA can determine that high-priority data should not be written to storage device 110 in a partially vulnerable mode. The FPGA can send a rejection message to host 105 and give the reason for the rejection. Optionally, the FPGA can filter out specific types of data (e.g., image data) to be written to storage device 110 in a partially resilient, lower-capacity state. For example, if storage device 110 loses performance (e.g., operates at a reduced write rate), latency-sensitive reads and writes can be rejected.

[0064] In some embodiments, as described above, storage device 110 may operate in one of two read-only modes, which may be referred to as "persistent" (or "first") read-only mode and "non-persistent" (or "second") read-only mode. In non-persistent read-only mode, storage device 110 may simply reject any write command that can be received from host 105, and it may (i) attempt to execute a read command for unexpired data or (ii) attempt to execute all read commands, returning the data and error code (an indication that the data item could not be read (e.g., zero)) generated by any successful decoding attempt if decoding is unsuccessful.

[0065] In persistent read-only mode, storage device 110 may be able to serve external read requests beyond the retention period of storage medium 125. As described below, although storage device 110 may perform writes to storage medium 125 for internal purposes, in response to any write command from host 105, storage device 110 may take no action other than returning an error message. To enable data retention beyond the retention period, storage device 110 may allocate a space called a “rescue space”, to which storage device 110 moves data that is about to expire (e.g., data with a lifespan exceeding a threshold lifetime based on the retention period of storage medium 125 (e.g., 80% of the retention period of storage medium 125)) such that the expiration of the data is subsequently postponed by the retention period of the rescue space. If data in the rescue space is about to expire, it may be moved back into the rescue space as needed to prevent data loss. In some embodiments, storage device 110 moves data well before it expires, thereby utilizing periods of low load to perform such movements, for example. As described above, the transition to persistent read-only mode can be triggered by the exhaustion of bad block management retention space. In this case, the affected plane or die can be made read-only, and once all the data stored on the affected plane or die has been relocated to the rescue space, the affected plane or die can be excluded from the physical address space of the storage device 110.

[0066] Storage device 110 can respond to read commands from host 105 across the entire LBA space. Because the physical space of storage device 110 can be reduced (e.g., because a portion of storage medium 125 has become read-only and its data is being moved (or has been moved) to rescue space), but the logical space of the device remains unchanged, storage device 110 can return zero if host 105 sends a read command within an LBA space that cannot be mapped to the Physical Block Address (PBA) space.

[0067] Rescue space can be allocated from overprovisioning space or from any unused space on storage device 110. If a region in a set or partition namespace in I / O determinism is not writable, the set or region can become read-only and be excluded from the physical address space once all data has been relocated. Rescue space can be dynamically created using namespaces. One or more namespaces can be used for user data, and additional namespaces can be created for rescue space. When storage device 110 transitions to persistent read-only mode, one or more namespaces used for user data can be reduced in size, and the size of the namespace used for rescue space can be increased.

[0068] If the size of the area of ​​the storage medium 125 affected by the failure (e.g., an area within an area where bad block management reserve space has been exhausted) exceeds the size of the available rescue space, the storage device 110 may move only the data that will expire soonest (e.g., the oldest data), or only the data marked as important or related to a given file type (e.g., image, video, or document), or move data of consecutive types (e.g., all data related to a file), leaving the other data behind. The set of file types considered important can be user-configurable. In some embodiments employing the KV storage device 110, key-value pairs may be used to compress or encode data importance.

[0069] In some embodiments, storage device 110 may determine that the amount of available rescue space is less than a threshold size and therefore insufficient to support operation in persistent read-only mode, and thus storage device 110 may switch to non-persistent read-only mode. This determination may be made upon initial detection of a fault, or storage device 110 may initially switch to persistent read-only mode upon initial detection of a fault, and after a period of time, as rescue space (e.g., due to the continued expiration of data in the faulty portion of storage medium 125) is consumed to the point that available rescue space decreases to less than a threshold size, storage device 110 may then switch from persistent read-only mode to non-persistent read-only mode. Upon switching from persistent read-only mode to non-persistent read-only mode, storage device 110 may notify host 105 of the switch, and host 105 may then attempt to copy as much data as possible from storage device 110 to another storage device before the data expires.

[0070] In some cases, data may be lost over a period of time, such as a day or an hour. Thus, the FPGA in storage device 110 can monitor the nature of the data on the drive (e.g., old, tagged, sequential, or file-type) to facilitate transfer when storage device 110 switches to a sustainable read-only mode. The FPGA can queue the data, or prioritize data to be transferred to the rescue space, and compress the data as it is moved to the rescue space. Some embodiments may be implemented in, for example, Ethernet storage devices or key-value (KV) storage devices.

[0071] Figure 4This is a schematic data layout diagram of storage device 110 in some embodiments. Block lifetime table 405 lists the retention period for each block in storage device 110, and mapping table 410 lists the mapping from logical block addresses to physical block addresses. When storage device 110 transitions to persistent read-only mode, storage device 110 copies data from fault-used space 415 (physical space affected by a fault condition) to rescue space 420. Data in normal-used space 425 is processed as it would be in normal operating mode (rather than persistent read-only mode). Because the fault condition results in the loss of physical space, there is a corresponding reduction in the size of used LBA space 430, where some of the previously available LBA space becomes unused LBA space 435. As described above, firmware 440 executed by controller 120 enables data movement and table updates.

[0072] Figure 5A This is a flowchart of a method for switching to a sustainable read-only mode in some embodiments. At 505, host 105 sends data to and / or receives data from storage device; at 510, host 105 determines whether an error has occurred in storage device; at 515, storage device 110 performs internal diagnostics and switches to sustainable read-only mode; at 520, the FPGA may optionally (e.g., based on data type or lifetime) monitor the nature of valid data on storage device 110; at 525, when the lifetime of data is nearing its retention period, storage device 110 relocates valid data to a rescue space; and at 530, storage device 110 may optionally send information about the status and contents of the rescue space to host 105 that refreshes the data. Figure 5B This is a flowchart illustrating details of a method for operating in a sustained read-only mode. The method includes: at 535, determining that the storage device is in a fault state, and that partial recovery from the fault state is feasible by operating the storage device in a first read-only mode; and at 540, operating the storage device in the first read-only mode by determining that the lifetime of a first data item stored in a page of the storage device has exceeded a threshold lifetime, and copying the first data item to a rescue space in the storage device.

[0073] In some embodiments, as described above, a RAID-0 system including an array of storage devices 110 and a volume manager 115 can be configured to adapt to the conversion of any storage device 110 of the RAID-0 system to read-only mode (e.g., to a sustained read-only mode). During normal operation, the volume manager 115 may be responsible for striping data across the array of storage devices 110 (e.g., writing one stripe from each stripe to the corresponding storage device 110 of the array of storage devices 110 (each stripe consists of such stripes)). In such a system, when any one of the arrays of storage devices 110 is converted to read-only mode (or “read-only state”), the RAID-0 system converts to an operating mode (which may be referred to as “emergency mode”), and the volume manager 115 for the array of storage devices 110 (i) allocates rescue space for metadata from the failed storage device 110 and rescued user data on each of the remaining unaffected storage devices 110 (storage devices 110 that remain in read-write state), and (ii) maintains a mapping table (which may be referred to as a “emergency mapping table”). The rescue space on each storage device 110 may be capable of storing n stripes, where n = R / (strip size), R = C / M, and C is the capacity of each storage device in the array of storage devices 110, and M is the number of storage devices 110 in the array of storage devices 110. The volume manager 115 may be implemented (e.g., in hardware, in software or firmware, or a combination of hardware, software, and firmware) in the host or in the RAID controller of the RAID-0 system (which may be housed, for example, in a separate rack from the host). In some embodiments, the volume manager 115 is implemented in an FPGA. The RAID-0 system may be self-contained and may virtualize the array of storage devices 110 such that, from the host's perspective, the RAID-0 system operates as a single storage device 110. Typically, the volume manager may be (e.g., via suitable software or firmware) a processing circuit configured to perform the operations described herein performed by the volume manager (discussed in further detail below).

[0074] When the RAID-0 system is operating in emergency mode and a write command is received from host 105 requiring stripes to be written to the array of storage device 110, volume manager 115 checks the emergency mapping table to determine if the stripe is "registered" (i.e., if an entry has been created for the stripe). If no entry has been created (i.e., if the stripe is "open-mapped," i.e., not registered), volume manager 115 creates an entry in the emergency mapping table to indicate where the stripe, which would normally have been written to the failed storage device 110 (the storage device 110 that has been converted to read-only mode), will be written. If the emergency mapping table already includes an entry for the stripe, that entry is used to determine where the stripe, which would normally have been written to the failed storage device 110, will be written. In either case, volume manager 115 then proceeds as follows: Figure 6A The array shown writes each strip to the storage device 110, and writes strips 605 that would normally have been written to the faulty storage device 110 to the rescue space in another storage device 110.

[0075] When the host 105 receives a read command requesting the reading of a stripe from the array of storage device 110, the volume manager 115 checks the emergency mapping table to determine if an entry has already been created for the stripe. If no entry has been created, then... Figure 6B As shown, volume manager 115 reads stripes as it would in a normal operation of reading stripes from each storage device 110 (including failed storage device 110). If the emergency mapping table includes entries for stripes, those entries are used to determine where to read stripes that would normally have been read from failed storage device 110.

[0076] For example, remapping of stripes that would normally have been written to faulty storage device 110 can be achieved as follows: Each storage device 110 in the array of storage devices 110 may have a drive identifier (or "drive ID"), which can be a number between zero and M-1, where M is the number of storage devices 110 in the array of storage devices 110. Volume manager 115 can reallocate drive identifiers, for example, assigning each storage device 110 in the array of storage devices 110 a replacement drive identifier to be used for performing read or write operations on registered stripes (read operations on unregistered stripes can continue to use the original drive identifier). Replacement drive identifiers can be generated using the following formula:

[0077] If drive ID < faulty drive ID

[0078] New drive ID = drive ID,

[0079] otherwise,

[0080] New drive ID = ((drive ID-1)+(M-1))mod(M-1).

[0081] The effect of this can be: (i) assigning the corresponding original drive identifier to each storage device with an identifier number that is less than the original drive identifier of the faulty storage device, and (ii) assigning the identifier number obtained by subtracting one from the corresponding original drive identifier to each storage device with an identifier number that is greater than the original drive identifier of the faulty storage device.

[0082] Using an alternate drive number, the target drive can be identified by the formula Target Drive ID = sid%(M-1), where the strip that has been written to the faulty storage device 110 can be written to the target drive, where Target Drive ID is the alternate drive identifier of the target drive, sid is the strip identifier of the strip that has been written to the faulty storage device 110, and "%" is the modulo operator.

[0083] Figure 6C This is a schematic diagram of a RAID-0 system with four storage devices 110 (i.e., M=4), where drive 1 has been switched to read-only mode. When writing to stripe 1, the target drive ID is implicitly determined by the following formula:

[0084] Target driver ID = ID%(M-1) = 1.

[0085] That is, the target drive is a storage device 110 with alternative drive identifier 1 (i.e., drive 2). Within the drive, the rescue space can be divided into strips of the same size as the strip (referred to as "rescue strips" or "R-Strips"). The emergency mapping table can include an entry (1,0) (whose first element is the strip ID (strip 1), and its second element is the R-Strip ID on the target drive). Therefore, an entry (1,0) in the emergency mapping table indicates that strip (1,1) is mapped to R-Strip (1,0).

[0086] A RAID-0 system can be configured to adapt to the conversion of one or more of the array of storage devices 110 to a sustainable read-only mode or a non-sustainable read-only mode. In the case of conversion to non-sustainable read-only mode, the registration record of the failed storage device 110 can be permanently written to the rescue space of another device. In the case of conversion to non-sustainable read-only mode, the volume manager 115 can migrate data from the failed storage device 110 to the unaffected storage device 110 at a rate sufficient to move all data from the failed storage device 110 before the data expires. The server can calculate this rate based on the remaining time before expiration and the amount of data.

[0087] Figure 7AThis is a flowchart of a method for operating a RAID-0 system. At 705, storage device 110 in the RAID-0 system experiences a failure and transitions to read-only mode; at 710, the affected storage device 110 performs internal diagnostics and determines its failure resilience state is partially resilient and read-only; at 715, volume manager 115 determines that the affected storage device 110 is in read-only mode and reallocates (“live”) the IDs of the unaffected storage devices; at 720, volume manager 115 receives a write operation, adds an entry to the emergency mapping table indicating that the stripe of the affected device is redirected to the target (unaffected) storage device 110, and the entire stripe is written to the rescue space of the target (unaffected) storage device based on the new drive ID of the unaffected storage device; and at 725, volume manager 115 receives a read command from host 105, and while reading the stripe of the affected storage device from the rescue space of the target (unaffected) storage device, reads all stripes of the stripe from the live unaffected storage device 110 of the RAID system.

[0088] Figure 7B This is a flowchart illustrating details of a method for operating a RAID-0 storage system. The method includes: at 730, determining that a first storage device is in a read-only state and a second storage device is in a read-write state; at 735, performing a write operation on the storage system for the first stripe by writing a portion of the first stripe to the second storage device and creating an entry for the first stripe in a mapping table; at 740, performing a first read operation on the second stripe from the storage system by reading a portion of the second stripe from the first and second storage devices; and at 745, performing a second read operation on the first stripe from the storage system by determining that the mapping table includes an entry for the first stripe and reading a portion of the first stripe from the second storage device.

[0089] The various elements described herein (such as host 105 or controller 120) may be or may include processing circuitry. The term "processing circuitry" or "means for processing" is used herein to refer to any combination of hardware, firmware, and software for processing data or digital signals. Processing circuitry hardware may include, for example, application-specific integrated circuits (ASICs), general-purpose or special-purpose central processing units (CPUs), digital signal processors (DSPs), graphics processing units (GPUs), and programmable logic devices (such as field-programmable gate arrays (FPGAs)). In processing circuitry, as used herein, each function is performed by hardware configured (i.e., hardwired) to perform said function, or by more general-purpose hardware (such as a CPU) configured to execute instructions stored in a non-transitory storage medium. Processing circuitry may be fabricated on a single printed circuit board (PCB) or distributed across several interconnected PCBs. Processing circuitry may include other processing circuitry (e.g., processing circuitry may include two processing circuits, an FPGA and a CPU, interconnected on a PCB).

[0090] As used herein, “part” means “at least some” of that thing, and therefore can mean less than or all of that thing. Thus, “part” as a special case includes the whole thing (i.e., an example where the whole thing is a part of the thing). As used herein, the term “or” should be interpreted as “and / or”, such that, for example, “A or B” means either “A” or “B” or “A and B”.

[0091] The background art provided in the Background section of this disclosure is included only to set forth the context, and the content of that section is not to be acknowledged as prior art. Any component or combination of components described (e.g., in any system diagram included herein) may be used to perform one or more operations of any flowchart included herein. Furthermore, (i) the operations are example operations and may involve various additional steps not explicitly covered, and (ii) the temporal order of the operations may be changed.

[0092] As used herein, when a method (e.g., adjustment) or a first quantity (e.g., a first variable) is referred to as “based on” a second quantity (e.g., a second variable), this means that the second quantity is an input to the method or affects the first quantity (e.g., the second quantity may be an input to a function that calculates the first quantity (e.g., a unique input or one of several inputs), or the first quantity may be equal to the second quantity, or the first quantity may be the same as the second quantity (e.g., stored in the same one or more locations in memory)).

[0093] It will be understood that although the terms “first,” “second,” “third,” etc., may be used herein to describe various elements, components, regions, layers, and / or portions, these elements, components, regions, layers, and / or portions should not be limited by these terms. These terms are used only to distinguish one element, component, region, layer, or portion from another. Therefore, without departing from the spirit and scope of the inventive concept, the first element, first component, first region, first layer, or first portion discussed herein may be referred to as a second element, second component, second region, second layer, or second portion.

[0094] For ease of description, spatial relative terms (such as "below," "under," "below," "below," "below," "above," and "above") are used herein to describe the relationship of one element or feature as shown in the accompanying drawings to one or more other elements or features. It will be understood that, in addition to the orientations depicted in the drawings, such spatial relative terms are intended to include different orientations of the device in use or operation. For example, if the device in the drawings is flipped, an element described as "below," "below," or "below" another element or feature will be "above" said other element or feature. Thus, the example terms "below" and "below" can include both above and below orientations. The device may also be otherwise oriented (e.g., rotated 90 degrees or in other orientations), and the spatial relative descriptors used herein should be interpreted accordingly. Furthermore, it will be understood that when a layer is referred to as being "between" two layers, it can be the only layer between the two layers, or one or more intermediate layers may exist.

[0095] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the inventive concept. As used herein, the terms “substantially,” “about,” and similar terms are used as approximate terms rather than terms of degree and are intended to take into account the inherent biases of measured or calculated values ​​that will be recognized by one of ordinary skill in the art.

[0096] As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “including” are used in this specification, they indicate the presence of the stated features, integrals, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items. Expressions such as “at least one of…” modify the entire list of elements when following a list, without modifying any individual element in the list. Furthermore, the use of “may” in describing embodiments of the inventive concept means “one or more embodiments of this disclosure.” Additionally, the term “exemplary” is intended to indicate an example or illustration. As used herein, the term “use” may be considered synonymous with the term “utilize.”

[0097] It will be understood that when a component or layer is referred to as being "on" another component or layer, "connected to", "bonded to", or "adjacent to" another component or layer, it may be directly on, connected to, bonded to, or adjacent to the other component or layer, or one or more intermediate components or layers may be present. Conversely, when a component or layer is referred to as being "directly on" another component or layer, "directly connected to", "directly bonded to", or "immediately adjacent to" another component or layer, no intermediate components or layers are present.

[0098] Any numerical range stated herein is intended to include all subranges of the same numerical precision contained within the stated range. For example, the range “1.0 to 10.0” or “between 1.0 and 10.0” is intended to include all subranges between the stated minimum value 1.0 and the stated maximum value 10.0 (and includes both the stated minimum value 1.0 and the stated maximum value 10.0, i.e., a minimum value equal to or greater than 1.0 and a maximum value equal to or less than 10.0) (e.g., 2.4 to 7.6). Any maximum numerical limit stated herein is intended to include all lower numerical limits included therein, and any minimum numerical limit stated in this specification is intended to include all higher numerical limits included therein.

[0099] Although exemplary embodiments of systems and methods for resilient operation of storage devices and systems including storage devices have been specifically described and illustrated herein, many modifications and variations will be apparent to those skilled in the art. Therefore, it should be understood that systems and methods for resilient operation of storage devices and systems including storage devices constructed in accordance with the principles of this disclosure may be implemented in ways different from those specifically described herein. The invention is also defined in the appended claims and their equivalents.

Claims

1. A method for operating a storage system including a first storage device and a second storage device, the method comprising: It is determined that the first storage device is in a read-only state and the second storage device is in a read-write state, wherein the first storage device has a first driver identifier and the second storage device has a second driver identifier; Reassign the third drive identifier to the second storage device; Perform the first stripe write operation on the storage system; Perform the first read operation of the second stripe from the storage system; and Perform the second read operation on the first stripe from the storage system. in, The steps to perform a write operation include: An entry is created in the mapping table for the first stripe to indicate that the stripe of the first stripe, which is to be written to the first storage device, is redirected to the second storage device. Based on the third drive identifier of the second storage device, the strip of the first strip is written into the rescue space of the second storage device. The steps of performing the first read operation include: reading a portion of the second strip from the first storage device and the second storage device, and The steps of performing the second read operation include: determining that the mapping table includes entries of the first stripe, and reading a portion of the first stripe from the second storage device.

2. The method according to claim 1, wherein, The storage system includes multiple storage devices, including a first storage device and a second storage device. The step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, wherein the one or more remaining storage devices include the second storage device, and The steps of performing a write operation include: writing a first stripe to the one or more remaining storage devices.

3. The method of claim 2, wherein, The steps for performing the first read operation include: Determine that the second stripe is open-mapped across the plurality of storage devices, and Read the second strip from the plurality of storage devices.

4. The method according to claim 2, further comprising: Reassign drive identifiers to the one or more remaining storage devices, wherein... Each of the plurality of storage devices has an original drive identifier number, and the reallocation step includes: Assign the corresponding original drive identifier to each storage device with an identifier number that is less than the original drive identifier number of the first storage device; and The identifier obtained by subtracting one from the corresponding original drive identifier is assigned to each storage device that has an identifier greater than the original drive identifier of the first storage device.

5. The method according to claim 2, wherein, The steps for performing the second read operation include: Read the first strip from the one or more remaining storage devices, and Read the first stripe from the rescue space of the storage device at the address based on the mapping table.

6. The method according to claim 5, further comprising: The drive identifier is reassigned to the remaining storage device, wherein... Each of the plurality of storage devices has an original drive identifier, and the reallocation step includes: assigning the corresponding original drive identifier to each storage device having an identifier number that is less than the original drive identifier of the first storage device.

7. The method according to claim 6, wherein, The reallocation step further includes: assigning an identifier obtained by subtracting one from the corresponding original drive identifier to each storage device having an identifier that is greater than the original drive identifier of the first storage device.

8. The method according to claim 6, wherein, The original drive identifier of the first storage device is n, and the step of reading a strip of the first strip includes: reading a strip from the storage device having a reassigned identifier n, where n is an integer not less than 0.

9. A system for storing data, the system comprising: A first storage device having a first drive identifier; A second storage device having a second drive identifier; as well as The processing circuit is connected to the first storage device and the second storage device. The processing circuit is configured to: determine that the first storage device is in a read-only state and the second storage device is in a read-write state; reallocate a third driver identifier to the second storage device; and perform a write operation on the first stripe. Perform the first read operation on the second stripe; And perform the second read operation on the first stripe. in, The steps to perform a write operation include: An entry is created in the mapping table for the first stripe to indicate that the stripe of the first stripe, which is to be written to the first storage device, is redirected to the second storage device. Based on the third drive identifier of the second storage device, the strip of the first strip is written into the rescue space of the second storage device. The steps of performing the first read operation include: reading a portion of the second strip from the first storage device and the second storage device, and The steps of performing the second read operation include: determining that the mapping table includes entries of the first stripe, and reading a portion of the first stripe from the second storage device.

10. The system of claim 9, comprising a plurality of storage devices including a first storage device and a second storage device, wherein, The step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, wherein the one or more remaining storage devices include the second storage device, and The steps of performing a write operation include: writing a first stripe to the one or more remaining storage devices.

11. The system according to claim 10, wherein, The steps for performing the first read operation include: Determine that the second stripe is open-mapped across the plurality of storage devices, and Read the second strip from the plurality of storage devices.

12. The system according to claim 10, wherein, The processing circuitry is also configured to reassign drive identifiers to the one or more remaining storage devices, wherein, Each of the plurality of storage devices has an original drive identifier number, and the reallocation step includes: Assign the corresponding original drive identifier to each storage device with an identifier number that is less than the original drive identifier number of the first storage device; and The identifier obtained by subtracting one from the corresponding original drive identifier is assigned to each storage device that has an identifier greater than the original drive identifier of the first storage device.

13. The system according to claim 10, wherein, The steps for performing the second read operation include: Read the first strip from the one or more remaining storage devices, and Read the first stripe from the rescue space of the storage device at the address based on the mapping table.

14. The system according to claim 13, wherein, The processing circuitry is also configured to: reassign the driver identifier to the remaining storage device, wherein, Each of the plurality of storage devices has an original drive identifier, and the reallocation step includes: assigning the corresponding original drive identifier to each storage device having an identifier number that is less than the original drive identifier of the first storage device.

15. The system according to claim 14, wherein, The processing circuit is also configured to assign an identifier obtained by subtracting one from the corresponding original driver identifier to each storage device having an identifier greater than the original driver identifier of the first storage device.

16. The system according to claim 14, wherein, The original drive identifier of the first storage device is n, and the step of reading a strip of the first strip includes: reading a strip from the storage device having a reassigned identifier n, where n is an integer not less than 0.

17. A system for storing data, the system comprising: A first storage device having a first drive identifier; A second storage device having a second drive identifier; as well as The processing apparatus is configured to: determine the state of the first storage device and the state of the second storage device; In response to the first storage device being in a read-only state and the second storage device being in a read-write state, a third drive identifier is reallocated to the second storage device, a write operation on the first stripe is performed, a first read operation on the second stripe is performed, and a second read operation on the first stripe is performed. in, The steps to perform a write operation include: An entry is created in the mapping table for the first stripe to indicate that the stripe of the first stripe, which is to be written to the first storage device, is redirected to the second storage device. Based on the third drive identifier of the second storage device, the strip of the first strip is written into the rescue space of the second storage device; The steps of performing the first read operation include: reading a portion of the second stripe from the first storage device and the second storage device, and the steps of performing the second read operation include: determining that the mapping table includes entries of the first stripe, and reading a portion of the first stripe from the second storage device.

18. The system of claim 17, comprising a plurality of storage devices including a first storage device and a second storage device, wherein, The step of determining that the second storage device is in a read / write state includes: determining that one or more remaining storage devices other than the first storage device are in a read / write state, wherein the one or more remaining storage devices include the second storage device, and The steps of performing a write operation include: writing a first stripe to the one or more remaining storage devices.

19. The system according to claim 18, wherein, The steps for performing the first read operation include: Determine that the second stripe is open-mapped across the plurality of storage devices, and Read the second strip from the plurality of storage devices.

20. The system according to claim 18, wherein, The processing apparatus is further configured to: reassign drive identifiers to the one or more remaining storage devices, wherein... Each of the plurality of storage devices has an original drive identifier number, and the reallocation step includes: Assign the corresponding original drive identifier to each storage device with an identifier number that is less than the original drive identifier number of the first storage device; and The identifier obtained by subtracting one from the corresponding original drive identifier is assigned to each storage device that has an identifier greater than the original drive identifier of the first storage device.