A docking storage method, device and system for a bare machine

By building a storage network and adopting MUX-VLAN and ACL technology, combining IP address automatic configuration and CHAP authentication, data leakage problems during the docking process of bare metal and storage devices are solved, secure data transmission and isolation are achieved, and security in a multi-tenant environment is improved.

CN114362976BActive Publication Date: 2025-07-11HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011034957.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-27
Publication Date
2025-07-11
Estimated Expiration
2040-09-27

AI Technical Summary

Technical Problem

In the cloud platform, during the docking process between bare metal and storage devices, other bare metals may intercept data, resulting in data leakage, and it is difficult for the existing technology to achieve secure data transmission and isolation.

Method used

By building a storage network, using composite virtual LAN MUX-VLAN and access control list ACL technology, the isolation between bare metal and interoperability with storage devices is achieved, combining automatic IP address configuration and CHAP authentication to ensure data security.

Benefits of technology

It effectively avoids malicious data interception between bare metal, improves security and data transmission reliability in multi-tenant scenarios, and ensures secure docking between bare metal and storage devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114362976B_ABST
    Figure CN114362976B_ABST
Patent Text Reader

Abstract

The present application discloses a docking storage method, device and system for bare machines. The method includes: establishing a storage network, which includes multiple bare machines, access switches, core switches and storage devices; connecting the multiple bare machines to the access switches, connecting the multiple access switches to the core switches, and connecting the core switches to the storage devices; configuring the storage network so that each of the multiple bare machines can communicate with the storage device and any two of the multiple bare machines are isolated from each other. Implementing the present application can isolate multiple bare machines from each other in a multi-tenant scenario, improving the security when bare machines dock with storage devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a bare metal docking storage method, device and system. Background Art

[0002] Cloud platforms usually include a storage network. The storage network includes multiple bare metal machines and storage devices. Each of the multiple bare metal machines can access the storage device, and the multiple bare metal machines can communicate with each other. Therefore, when a bare metal machine sends data to the storage device, other bare metal machines can intercept the data, resulting in the data being leaked.

[0003] Therefore, how to achieve the secure connection of bare metal to storage devices, that is, when a bare metal sends data to the storage device, other bare metals cannot intercept the data is still a technical challenge. Summary of the invention

[0004] The embodiments of the present application disclose a bare metal storage docking method, device and system, which can achieve isolation between multiple bare metals in a multi-tenant scenario, thereby improving the security of bare metal docking storage devices.

[0005] In a first aspect, an embodiment of the present application provides a bare metal docking storage method, which is applied to a cloud management platform, and the method includes: establishing a storage network, the storage network includes multiple bare metals, access switches, core switches and storage devices; connecting multiple bare metals to access switches, multiple access switches to core switches, and core switches to storage devices; configuring the storage network so that each bare metal among the multiple bare metals can communicate with the storage device and any two bare metals among the multiple bare metals are isolated from each other.

[0006] In the above method, a storage network including multiple bare metal machines, access switches, core switches and storage devices is formed. By configuring the storage network, different bare metal machines are isolated from each other and each bare metal machine in the storage network communicates only with the storage device. This effectively avoids the bare metal machine maliciously intercepting messages sent by other bare metal machines, and also prevents data leakage in the storage device, thereby improving the security performance of bare metal machines and storage devices in multi-tenant scenarios.

[0007] In a possible implementation of the first aspect, the multiple bare metal machines include a first bare metal machine and a second bare metal machine, and configuring the storage network may be: using a composite virtual local area network MUX-VLAN on an access switch to isolate the first bare metal machine and the second bare metal machine, the first bare metal machine and the second bare metal machine are respectively connected to the access switch, and the first bare metal machine and the second bare metal machine are located in the same VLAN and the same subnet.

[0008] Implementing the above implementation method, the first bare machine and the second bare machine are any two of multiple bare machines. When the first bare machine and the second bare machine are connected to the same access switch, and the VLAN and subnet where the first bare machine is located are the same as those where the second bare machine is located respectively, MUX-VLAN can be used to isolate the first bare machine and the second bare machine, realizing layer-2 traffic isolation between bare machines in the same VLAN and the same subnet, effectively avoiding the event of malicious message interception between bare machines, and improving the security of bare machines.

[0009] In a possible implementation of the first aspect, the above multiple bare machines include a first bare machine and a second bare machine. The configured storage network can be: setting a first access control list on the access switch to isolate the first bare machine and the second bare machine. The first bare machine and the second bare machine are respectively connected to the access switch, and the first bare machine and the second bare machine are in the same VLAN and the same subnet.

[0010] Implementing the above implementation method, the first bare machine and the second bare machine are any two of multiple bare machines. When the first bare machine and the second bare machine are connected to the same access switch, and the VLAN and subnet where the first bare machine is located are the same as those where the second bare machine is located respectively, setting an access control list (ACL) on the access switch to make the first bare machine and the second bare machine non-interoperable realizes layer-2 traffic isolation between bare machines in the same VLAN and the same subnet, effectively avoiding the event of malicious message interception between bare machines, and improving the security performance of bare machines.

[0011] In a possible implementation of the first aspect, the multiple bare machines further include a third bare machine and a fourth bare machine. The configured storage network can be: setting a second access control list on the core switch to isolate the third bare machine and the fourth bare machine. The third bare machine and the fourth bare machine are respectively connected to the core switch through different access switches, and the third bare machine and the fourth bare machine are in different subnets.

[0012] Implementing the above implementation method, the third bare machine and the fourth bare machine are any two of multiple bare machines. When the access switch connected to the third bare machine is different from the access switch connected to the fourth bare machine, and the subnet where the third bare machine is located is different from the subnet where the fourth bare machine is located, setting an ACL on the core switch to prohibit communication between the third bare machine and the fourth bare machine realizes layer-3 traffic isolation between bare machines across subnets, effectively avoiding the event of malicious message interception between bare machines, and improving the security performance of bare machines in the case of multiple tenants.

[0013] In a possible implementation of the first aspect, configuring the storage network includes: setting a third access control list on the core switch to enable each of the multiple bare machines to communicate with the storage device. Each bare machine and the storage device are in different VLANs and different subnets.

[0014] Implementing the above implementation, the bare metal in the storage network and the storage device are in different VLANs and different subnets. By setting up ACL on the core switch to enable each bare metal to communicate with the storage device, three-layer traffic intercommunication between the bare metal and the storage device across VLANs and subnets is achieved.

[0015] In a possible implementation of the first aspect, when the storage network further includes computing nodes, configuring the storage network further includes: setting up a fourth access control list on the core switch to isolate each of the multiple bare metals from the computing nodes, and each bare metal and the computing nodes are in different VLANs and different subnets.

[0016] When there are also computing nodes in the storage network, the computing nodes and the bare metals are in different VLANs and different subnets. By setting up ACL on the core switch to prevent each of the multiple bare metals from communicating with the computing nodes, three-layer traffic isolation between the bare metals and the computing nodes across VLANs and subnets is achieved, avoiding malicious interception of messages sent by the bare metals by the computing nodes and improving the security performance of the bare metals.

[0017] In a possible implementation of the first aspect, the IP address of each of the multiple bare metals is automatically configured based on the subnet of the access switch to which each bare metal is connected and the MAC address of each bare metal.

[0018] Combining the subnet of the access switch connected to the bare metal and the MAC address of the bare metal to assign an IP address to the target bare metal, that is, determining the subnet where the target bare metal is located according to the access switch, and determining the host number of the target bare metal within the subnet according to the MAC address of the target bare metal, thus realizing the automatic assignment of the IP address of the target bare metal, avoiding configuration errors or repetitions that occur in manually configuring the IP address of the bare metal, and improving the efficiency and accuracy of the IP address configuration of the bare metal.

[0019] In a possible implementation of the first aspect, after each of the multiple bare metals communicates with the storage device, before each bare metal accesses the storage device, each bare metal passes the CHAP authentication initiated by the storage device.

[0020] The bare metal and the storage device can communicate with each other. In the case where the bare metal passes the CHAP authentication initiated by the storage device, the bare metal has the right to use the storage device, that is, the bare metal passes the CHAP authentication to enable the storage device to determine that the identity of the bare metal is legal, so the storage device can be used by the bare metal, effectively preventing brute force cracking of the bare metal and improving the security during the docking of the bare metal to the storage device in a multi-tenant scenario.

[0021] In a possible implementation of the first aspect, each of the multiple bare machines corresponds to a set of user names and user passwords for CHAP authentication, and the user names and user passwords corresponding to different bare machines are different.

[0022] Each bare machine in the storage network is assigned a set of user names and user passwords for CHAP authentication, and the user names and user passwords for CHAP authentication of each bare machine are unique. The user names and user passwords are both randomly generated, effectively preventing the bare machines from being counterfeited to obtain data in the storage device, and improving the security during the process of the bare machines docking with the storage device in a multi-tenant scenario.

[0023] In a possible implementation of the first aspect, configuring the storage network means: using an access control list, or using an access control list and a composite virtual local area network MUX-VLAN to configure the storage network.

[0024] In a second aspect, the present application provides a device, which includes a building unit for building a storage network. The storage network includes multiple bare machines, an access switch, a core switch, and a storage device; the multiple bare machines are connected to the access switch, the multiple access switches are connected to the core switch, and the core switch is connected to the storage device; a configuration unit for configuring the storage network so that each of the multiple bare machines can communicate with the storage device and any two of the multiple bare machines are isolated from each other.

[0025] In a possible implementation of the second aspect, the multiple bare machines include a first bare machine and a second bare machine. The configuration unit is specifically used for: isolating the first bare machine and the second bare machine on the access switch by using a composite virtual local area network MUX-VLAN. The first bare machine and the second bare machine are respectively connected to the access switch, and the first bare machine and the second bare machine are in the same VLAN and the same subnet.

[0026] In a possible implementation of the second aspect, the multiple bare machines include a first bare machine and a second bare machine. The configuration unit is specifically used for: setting a first access control list on the access switch to isolate the first bare machine and the second bare machine. The first bare machine and the second bare machine are respectively connected to the access switch, and the first bare machine and the second bare machine are in the same VLAN and the same subnet.

[0027] In a possible implementation of the second aspect, the multiple bare machines further include a third bare machine and a fourth bare machine. The configuration unit is specifically used for: setting a second access control list on the core switch to isolate the third bare machine and the fourth bare machine. The third bare machine and the fourth bare machine are respectively connected to the core switch through different access switches, and the third bare machine and the fourth bare machine are in different subnets.

[0028] In a possible implementation of the second aspect, the configuration unit is specifically configured to: set a third access control list on the core switch to enable each of the multiple bare machines to communicate with the storage device, where each bare machine and the storage device are in different VLANs and different subnets.

[0029] In a possible implementation of the second aspect, when the storage network further includes computing nodes, the configuration unit is further configured to: set a fourth access control list on the core switch to isolate each of the multiple bare machines from the computing nodes, where each bare machine and the computing nodes are in different VLANs and different subnets.

[0030] In a possible implementation of the second aspect, the IP address of each of the multiple bare machines is automatically configured based on the subnet of the access switch to which each bare machine is connected and the MAC address of each bare machine.

[0031] In a possible implementation of the second aspect, after each of the multiple bare machines communicates with the storage device, before each bare machine accesses the storage device, each bare machine passes the CHAP authentication initiated by the storage device.

[0032] In a possible implementation of the second aspect, each of the multiple bare machines corresponds to a set of username and user password for CHAP authentication, and the usernames and user passwords corresponding to different bare machines are different.

[0033] In a possible implementation of the second aspect, the configuration unit is specifically configured to: configure the storage network by using an access control list, or an access control list and a composite virtual local area network MUX-VLAN.

[0034] In a third aspect, the present application provides a storage system for bare machines, the storage system including: multiple bare machines, access switches, a core switch, and a storage device; the multiple bare machines are connected to the access switches, the multiple access switches are connected to the core switch, and the core switch is connected to the storage device; each of the multiple bare machines communicates with the storage device, and any two of the multiple bare machines are isolated from each other.

[0035] In a possible implementation of the third aspect, the multiple bare machines include a first bare machine and a second bare machine.

[0036] A composite virtual local area network MUX-VLAN is set on the access switch, and the MUX-VLAN isolates the first bare machine from the second bare machine. The first bare machine and the second bare machine are respectively connected to the access switch, and the first bare machine and the second bare machine are in the same VLAN and the same subnet.

[0037] In a possible implementation of the third aspect, the multiple bare machines include a first bare machine and a second bare machine.

[0038] A first access control list is set on the access switch, and the first access control list isolates the first bare machine from the second bare machine. The first bare machine and the second bare machine are respectively connected to the access switch, and the first bare machine and the second bare machine are in the same VLAN and the same subnet.

[0039] In a possible implementation manner of the third aspect, the multiple bare machines further include a third bare machine and a fourth bare machine. A second access control list is set on the core switch, and the second access control list isolates the third bare machine from the fourth bare machine. The third bare machine and the fourth bare machine are respectively connected to the core switch through different access switches, and the third bare machine and the fourth bare machine are in different subnets.

[0040] In a possible implementation manner of the third aspect, a third access control list is set on the core switch, and the third access control list enables each of the multiple bare machines to communicate with the storage device. Each bare machine and the storage device are in different VLANs and different subnets.

[0041] In a possible implementation manner of the third aspect, when the storage system further includes a computing node, a fourth access control list is further set on the core switch, and the fourth access control list isolates each of the multiple bare machines from the computing node. Each bare machine and the computing node are in different VLANs and different subnets.

[0042] In a possible implementation manner of the third aspect, the IP address of each of the multiple bare machines is automatically configured based on the subnet of the access switch to which each bare machine is connected and the MAC address of each bare machine.

[0043] In a possible implementation manner of the third aspect, after each of the multiple bare machines communicates with the storage device, before each bare machine accesses the storage device, each bare machine passes the CHAP authentication initiated by the storage device.

[0044] In a possible implementation manner of the third aspect, each of the multiple bare machines corresponds to a set of user names and user passwords for CHAP authentication, and the user names and user passwords corresponding to different bare machines are different.

[0045] In a fourth aspect, an embodiment of the present application provides a device, which includes a processor and a memory. The processor and the memory are connected or coupled together through a bus. Among them, the memory is used to store program instructions; the processor calls the program instructions in the memory to execute the method in the first aspect or any possible implementation manner of the first aspect.

[0046] Fifth aspect, an embodiment of the present application provides a computer-readable storage medium, and the computer-readable medium stores program code for a device to execute, and the program code includes instructions for executing the method in the first aspect or any possible implementation manner of the first aspect.

[0047] Sixth aspect, an embodiment of the present application provides a computer software product, and the computer program software product includes program instructions. When the computer software product is executed by a device, the device executes the method in the foregoing first aspect or any possible embodiment of the first aspect. The computer software product can be a software installation package. In the case where it is necessary to use the method provided by any possible design of the first aspect, the computer software product can be downloaded and executed on the device to implement the method in the first aspect or any possible embodiment of the first aspect. Description of the Drawings

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for description in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0049] Figure 1 is a schematic diagram of the architecture of a system provided by an embodiment of the present application;

[0050] Figure 2 is a schematic diagram of the specific structure of a system provided by an embodiment of the present application;

[0051] Figure 3 is a schematic diagram of the network connection of a bare machine provided by an embodiment of the present application;

[0052] Figure 4 is another schematic diagram of the network connection of a bare machine provided by an embodiment of the present application;

[0053] Figure 5 is another schematic diagram of the network connection of a bare machine provided by an embodiment of the present application;

[0054] Figure 6 is a flowchart of a method for automatically configuring the IP address of a bare machine provided by an embodiment of the present application;

[0055] Figure 7 is a flowchart of a method for configuring CHAP authentication information of a bare machine provided by an embodiment of the present application;

[0056] Figure 8 is a flowchart of a method for CHAP authentication between a bare machine and a storage device provided by an embodiment of the present application;

[0057] Figure 9 It is a schematic structural diagram of a device provided in this embodiment of the present application;

[0058] Figure 10 It is a schematic functional structure diagram of a device provided in an embodiment of the present application;

[0059] Figure 11 It is a schematic functional structure diagram of another device provided in an embodiment of the present application;

[0060] Figure 12 It is a schematic functional structure diagram of another device provided in an embodiment of the present application. Detailed implementation manners

[0061] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The terms "first", "second", etc. in the specification and claims of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order.

[0062] For ease of understanding, the following first introduces the relevant terms that may be involved in the embodiments of the present application.

[0063] (1) Internet Small Computer System Interface iSCSI

[0064] The Internet Small Computer System Interface (iSCSI), also known as the IP Storage Area Network (SAN). It is an industry standard for transmitting SCSI block commands over an existing IP network based on the TCP / IP protocol. It is a storage technology that can transmit messages and block data simultaneously over an existing IP network without the need to install a separate fiber optic network. iSCSI is based on the TCP / IP protocol, encapsulates SCSI commands / data blocks into iSCSI packets, then encapsulates them into TCP messages, and then into IP packets, and can be transmitted through routing or switches on standard Ethernet devices.

[0065] iSCSI is a typical client / server (C / S) architecture. Among them, the host device accessing the storage system is called an iSCSI client or host, and can also be called an iSCSI initiator, while the storage device providing storage services is called the server side, and the server side can also be called a target. The main function of iSCSI is to perform a large amount of data encapsulation and reliable transmission processes between the host device (initiator) and the storage device (target) using the TCP / IP network.

[0066] (2) Challenge Handshake Authentication Protocol (CHAP)

[0067] CHAP stands for Challenge Handshake Authentication Protocol in PPP (Point-to-Point Protocol). This protocol can periodically verify the identity of the peer through three-way handshake, which can be performed at the initial link establishment, completion, and repeated after the link is established. By incrementally changing the identifier and variable challenge value, replay attacks from endpoints can be prevented, and the use of repeated verification can limit the exposure time to a single attack. It is commonly used in the remote access environment of enterprise networks.

[0068] Specifically, the first step: after the link establishment phase ends, the authenticator sends a "challenge" message to the peer endpoint; the second step: the peer endpoint responds with the value calculated by the one-way hash function; the third step: the authenticator checks the response based on the hash value it calculates itself. If the values match, the authentication is acknowledged; otherwise, the connection should be terminated; the fourth step: after a certain random interval, the authenticator sends a new "challenge" message to the endpoint, repeating the first to the third steps. The authenticator can control the verification frequency and time.

[0069] See Figure 1 , Figure 1 which is a schematic structural diagram of an application system provided by an embodiment of the present application. As Figure 1 shown, the application system of the present application includes: a cloud management platform 110, multiple bare machines 120, and a storage device 130. Among them, each of the multiple bare machines 120 is connected to the cloud management platform 110 through a network, and the storage device 130 is connected to the cloud management platform 110 through a network. It should be noted that any two of the multiple bare machines 120 cannot communicate with each other, and each of the multiple bare machines 120 can communicate with the storage device 130.

[0070] The cloud management platform 110 includes an operating system 111 and hardware 112. The cloud management platform 110 can be AWS (Amazon Web Service), OpenStack, CloudStack, etc. for providing IAAS services. The operating system 111 can be an embedded operating system, a Unix-like operating system, etc. For example, the embedded operating system can be VxWorks, eCos, SymbianOS, and Palm OS, the graphical operating system can be Microsoft Windows and MacOS X, etc., and the Unix-like operating system can be System V, BSD, and Linux, etc. The hardware 112 can include a processor, memory, and physical network cards, etc.

[0071] The storage device 130 supports the iSCSI technology, that is, it provides storage space for multiple bare machines 120 through a network. This type of storage device provides a bare, file system-free logical volume to multiple bare machines 120, and each logical volume has a unique Logical Unit Number (LUN).

[0072] Each of the multiple bare machines 120 refers to a physical server that can automatically complete the installation of the operating system and configure storage and networks. For example, a Bare Metal Service (BMS). As Figure 1 shown, each of the multiple bare machines 120 corresponds to a tenant, that is, the mapping relationship between the tenant and the bare machine is one-to-one, and the operating system of the bare machine can be custom-installed by the tenant. In some possible embodiments, the corresponding relationship between the tenant and the bare machine in the application system can also be one-to-many, that is, a tenant can rent multiple bare machines. For example, bare machine 1 and bare machine 2 correspond to the same tenant. In this case, it is still set that the different bare machines cannot communicate with each other, but each bare machine can communicate with the storage device 10 to improve the security of the bare machine docking the storage device. Optionally, when the security requirements for the system are not so high, it is also possible to enable the bare machines belonging to the same tenant to communicate with each other, but the bare machines corresponding to different tenants cannot communicate with each other.

[0073] Based on the above Figure 1 described system architecture, combined with Figure 2 to further illustrate the process of multiple bare machines 120 docking with the storage device 130. Refer to Figure 2 , Figure 2 is a schematic diagram of the specific structure of a system provided by this application. The bare machine management module and the storage management module both belong to Figure 1 the cloud management platform 110 in. In some possible embodiments, the bare machine management module can be a component of the cloud management platform 110 for providing computing services. For example, the Nova component, etc. The storage management module can be a component of the cloud management platform 110 for providing storage. For example, the Cinder component, etc. In Figure 2 , bare machine A and bare machine B do not communicate with each other. Bare machine A can communicate with the storage device, and bare machine B can communicate with the storage device. The storage device supports the iSCSI protocol. Therefore, an iSCSI target is integrated in the storage device. Correspondingly, iSCSI initiators are integrated in bare machine A and bare machine B respectively. In this application, when bare machine A (or bare machine B) passes the security authentication (such as CHAP authentication) initiated by the storage device, the iSCSI initiator in bare machine A (or bare machine B) can communicate with the iSCSI target of the storage device. It should be noted that Figure 2 in, bare machine A and bare machine B are only examples of multiple bare machines, and do not limit the number of multiple bare machines to only 2.

[0074] See Figure 2 As shown, taking the docking of bare machine A with a storage device as an example for exemplary elaboration, the basic process of the docking of bare machine A with a storage device is as follows: A tenant sends a request to create a "volume (or called a flash device)" for bare machine A to the storage management module of the cloud management platform. The storage management module creates a "volume" in the storage device and records the corresponding relationship between the created "volume" and bare machine A. The tenant sends a request to mount the "volume" to the bare machine management module of the cloud management platform. After receiving the request to mount the "volume", the bare machine management module obtains the metadata of the "volume" corresponding to bare machine A from the storage management module, and the bare machine management module transfers the metadata of the "volume" to the storage agent module in bare machine A, thus realizing the mounting of the "volume" for bare machine A. When bare machine A and the storage device can communicate with each other, when bare machine A wants to access the volume in the iSCSI storage device, under the condition that bare machine A passes authentication, the storage agent module in bare machine A calls the iSCSI initiator in the bare machine based on the original data of the "volume" to access and use the "volume".

[0075] In the related art, the process of docking a bare machine with a storage device can refer to the description of the docking of bare machine A with a storage device above. However, the difference is that in the related art, when multiple bare machines are docked with a storage device, since the storage network is an ordinary virtual local area network (VLAN), the bare machines connected to the same storage device can communicate with each other through the storage network and have no isolation ability, which is extremely likely to cause high-risk events such as data leakage and transmission packet interception in a multi-tenant scenario, and there are great security risks. In addition, in the related art, it is not restricted that the bare machine can access the storage device only when the bare machine passes authentication. Therefore, the tenant of another bare machine can forge the iSCSI initiator in its own bare machine into the iSCSI initiator of a known bare machine by brute force cracking, and then can access the volume in the storage device corresponding to the known bare machine, thereby reading private data or writing destructive data. For example, taking the growth of the simulation identification number as an example, assume that the corresponding relationship between bare machine A (the identification number of the iSCSI initiator is 1) and LUN1, LUN2 and the corresponding relationship between bare machine B (the identification number of the iSCSI initiator is 2) and LUN3, LUN4 have been established on the storage management module, but the relevant mapping information of bare machine C has not been established on the storage management module. Assume that bare machine C pre-accesses the storage device, and bare machine C brute force cracks the iSCSI initiator by simulating the growth of the identification number. For example, testing the identification number 2 (simulating the iSCSI initiator of bare machine B), then it can access LUN3 and LUN4 in the storage device, resulting in the leakage of data information in the storage device and low security. In addition, the IPs on the bare machine nodes are mostly manually configured, with poor usability and low security.

[0076] The present application provides a method for docking storage of bare - metal tenants, which can not only achieve isolation between bare - metal machines of multiple tenants, but also effectively prevent brute - force cracking of iSCSI initiators in the bare - metal machines and automatically configure the IP addresses of the bare - metal machines, greatly improving the security during the process of docking the bare - metal machines with storage devices and the security of the entire system.

[0077] Based on the system architecture described above, there are three goals:

[0078] (1) If we want to achieve secure docking between a bare - metal machine and a storage device, we need to pre - set the isolation between bare - metal machines and the inter - communication between bare - metal machines and storage devices in various networking forms in the storage network. For example, taking the bare - metal machine A, bare - metal machine B, and storage device in Figure 2 as an example, to achieve isolation between bare - metal machine A and bare - metal machine B, that is, when bare - metal machine A sends a message outward, bare - metal machine B cannot intercept the message. Similarly, when bare - metal machine B sends a message outward, bare - metal machine B cannot intercept the message; in addition, to achieve inter - communication between bare - metal machine A and the storage device, that is, bare - metal machine A can send a message to the storage device, and the storage device can also send a message to bare - metal machine A, and to achieve inter - communication between bare - metal machine B and the storage device, similar to the inter - communication between bare - metal machine A and the storage device, which will not be elaborated here.

[0079] (2) Automatically configure the IP address of the bare - metal machine. The bare - metal management module automatically configures the IP address of the bare - metal machine based on the subnet where the target switch connected to the bare - metal machine is located and the Media Access Control (MAC) address of the storage network card in the bare - metal machine.

[0080] (3) Prevent brute - force cracking of the iSCSI initiator in the bare - metal machine. Taking the bare - metal machine A and the storage device in Figure 2 as an example, before the bare - metal machine A reads data from the storage device or writes data to the storage device, the bare - metal machine A also needs to perform a security authentication with the storage device. After the bare - metal machine A passes the authentication, the bare - metal machine A has the permission to read data from the storage device or write data to the storage device. Optionally, the security authentication between the bare - metal machine and the storage device can adopt CHAP authentication.

[0081] Next, the specific implementation processes of the above three goals will be introduced in turn.

[0082] First, introduce the implementation of the above - mentioned goal (1), that is, set the isolation and inter - communication of bare - metal machines in various networking forms in the storage network. Among them, the so - called inter - communication means that the bare - metal machine can only communicate with the storage device, and the so - called isolation means that the bare - metal machines cannot communicate with each other. In some possible embodiments, if there are also computing nodes in the network, the so - called isolation also means that the bare - metal machine cannot communicate with the computing nodes.

[0083] In the embodiments of the present application, in a multi-tenant environment, isolation and intercommunication of bare machines in various networking forms can be controlled based on at least one of Multiplex VLAN (MUX-VLAN) technology and Access Control List (ACL) technology. Among them, MUX-VLAN technology is used to implement isolation between bare machines located in the same VLAN and the same subnet. In other words, MUX-VLAN technology can achieve layer-2 traffic isolation; ACL technology can be used to implement isolation between bare machines located in the same VLAN and the same subnet (i.e., layer-2 traffic isolation), and can also be used to implement isolation between bare machines located in the same VLAN and different subnets, as well as isolation between bare machines located in different VLANs and different subnets (i.e., layer-3 traffic isolation). In addition, ACL technology is also used to implement intercommunication between a bare machine and a storage device, where the bare machine and the storage device are located in different VLANs and different subnets.

[0084] In some possible embodiments, if there are computing nodes (e.g., virtual machines) in addition to bare machines in the networking of the storage network, when the bare machine and the computing node are located in the same VLAN and different subnets or in different VLANs and different subnets, ACL technology can also implement isolation between the bare machine and the computing node. It should be noted that to determine whether the subnets of bare machine A and bare machine B are the same, the IP address of the bare machine is AND-operated with its corresponding subnet mask to obtain the subnet address, and then the subnet address of bare machine A is compared with the subnet address of bare machine B. If they are the same, it means that bare machine A and bare machine B are in the same subnet.

[0085] MUX-VLAN provides a mechanism for controlling network resources through VLAN. MUX-VLAN is divided into a Principal VLAN and a Subordinate VLAN. Among them, the Subordinate VLAN is further divided into a Separate VLAN and a Group VLAN (also known as a group VLAN). The Subordinate VLAN needs to be bound to the Principal VLAN, and each Principal VLAN only supports one Separate VLAN but supports multiple Group VLANs. The interface of the Principal VLAN can communicate with all interfaces within the MUX VLAN. The interface of the Separate VLAN can only communicate with the interface of the Principal VLAN and is completely isolated from other types of interfaces. The interface of the Group VLAN can communicate with the interface of the Principal VLAN, and the interfaces within the same group can also communicate with each other, but cannot communicate with interfaces in other groups or Separate ports.

[0086] The ACL technology is a flow control technology based on packet filtering. ACL can define a series of different rules. The device classifies data packets according to these rules and processes different packets, so as to control network access behavior, limit network traffic, improve network performance, prevent network attacks, etc. ACL can effectively control network users' access to network resources, which can be specific to the network applications of two network devices or can be used for large-scale access control management based on subnets, that is, to achieve communication and isolation between network devices, providing an effective means for network applications.

[0087] See Figure 3 , Figure 3 which is a networking schematic diagram of a bare machine provided by an embodiment of the present application. As Figure 3 shown, in this scenario, there are bare machine 1, bare machine 2, bare machine 3, bare machine 4, two access switches (access switch 1 and access switch 2), a core switch, and a storage device. Before describing the connections of each component, for the convenience of description, for each switch, the interfaces of the switch are sequentially represented as the first interface, the second interface, etc. in the order from left to right, but the present application does not limit the naming of each interface of the switch. Specifically, bare machine 1 is connected to the first interface of access switch 1, bare machine 2 is connected to the second interface of access switch 1, bare machine 3 is connected to the first interface of access switch 2, bare machine 4 is connected to the second interface of access switch 2, the third interface of access switch 1 is connected to the first interface of the core switch, the fourth interface of access switch 2 is connected to the second interface of the core switch, and the third interface of the core switch is connected to the storage device.

[0088] In the core switch, the VLAN IDs of the first interface and the second interface are both set to 2124, and the VLAN ID of the third interface is set to 2126; in access switch 1, the VLAN ID of the third interface is set to 2124, and the VLAN 2124 of the third interface is configured as the primary VLAN of the MUX-VLAN. The VLAN IDs of the first interface and the second interface are both set to 2200, and VLAN 2200 is configured as an isolated slave VLAN in the slave VLAN, and the isolated slave VLAN 2200 is bound to the primary VLAN 2124; in access switch 2, the VLAN ID of the fourth interface is set to 2124, and the VLAN 2124 of the fourth interface is configured as the primary VLAN of the MUX-VLAN. The VLAN IDs of the first interface and the second interface are set to 2200, and VLAN 2200 is configured as an isolated slave VLAN in the slave VLAN, and the isolated slave VLAN 2200 is bound to the primary VLAN 2124. In addition, in Figure 3 , it is assumed that the subnet mask defaults to 255.255.255.0.

[0089] In this networking form, the isolation and intercommunication of bare metals are achieved through MUX-VLAN technology and ACL technology. That is, MUX-VLAN is used to isolate the Layer 2 traffic between bare metals, and ACL rules are set to isolate the Layer 3 traffic between bare metals and between bare metals and computing nodes, as well as the intercommunication between bare metals and storage devices. The specific implementation is as follows:

[0090] (1) Isolation of bare metal devices under the same access switch: Bare metal devices under the same access switch use the same VLAN and the same subnet, such as Figure 3 As shown in the figure, bare metal 1 and bare metal 2 are in the same subnet, and bare metal 3 and bare metal 4 are in the same subnet. Set the interface of the access switch connected to the bare metal to use the isolation type secondary VLAN in MUX-VLAN to isolate the interconnection between bare metals under the same access switch and implement Layer 2 traffic isolation. Figure 3 It can be seen that in access switch 1, the first interface connected to bare metal 1 and the second interface connected to bare metal 2 are both added to the isolated slave VLAN 2200, so that bare metal 1 and bare metal 2 cannot communicate with each other. Similarly, in access switch 2, bare metal 3 and bare metal 4 both correspond to the isolated slave VLAN 2200, so that bare metal 3 and bare metal 4 cannot communicate with each other.

[0091] (2) Isolation between bare metal devices under different access switches: Bare metal devices under different access switches can use the same VLAN (including primary VLAN and secondary VLAN), but they need to use different subnets. The isolation between bare metal devices under different subnets is achieved by setting ACL rules on the core switch. Figure 3Taking the bare machine 1 under the access switch 1 and the bare machine 3 under the access switch 2 as examples, the VLANs used by the interfaces of the access switches corresponding to the bare machine 1 and the bare machine 3 are the same, but the subnets used by the bare machine 1 and the bare machine 3 are different. If the bare machine 1 and the bare machine 3 are not to communicate with each other, ACL rules need to be set on the core switch for three-layer traffic isolation, that is, an ACL rule for prohibiting the subnet where the bare machine 1 is located from accessing the subnet where the bare machine 3 is located and an ACL rule for prohibiting the subnet where the bare machine 3 is located from accessing the subnet where the bare machine 1 is located are established, so that the bare machine 1 and the bare machine 3 cannot communicate with each other. Since the subnets where the bare machine 1 and the bare machine 2 are located are the same, and the subnets where the bare machine 3 and the bare machine 4 are located are the same, therefore, setting ACL rules according to the above steps can also control that the bare machine 1 and the bare machine 4 cannot communicate with each other, and the bare machine 2 cannot communicate with the bare machine 3 and the bare machine 4 respectively. For example, the ACL rule set on the core switch can be "rule 1 deny ip source 88.98.100.0 0.0.0.255 destination 88.98.104.0 0.0.0.255", so that any two of the bare machine 1, the bare machine 2, the bare machine 3 and the bare machine 4 cannot communicate with each other. In some possible embodiments, when the IP addresses of the bare machine 1 and the bare machine 3 are known, an ACL rule for prohibiting the IP address of the bare machine 1 from accessing the IP address of the bare machine 3 can also be established on the core switch to achieve three-layer traffic isolation between the bare machine 1 and the bare machine 3.

[0092] (3) Intercommunication between the bare machine and the storage device: The bare machine and the storage device use different VLANs and different subnets. The intercommunication between the bare machine and the storage device can be achieved by setting ACL rules on the core switch. For example, the VLAN ID of the storage device is 2126, different from the VLAN IDs of bare machine 1, bare machine 2, bare machine 3, and bare machine 4 which are 2200. The subnet corresponding to the storage device is 88.98.103.0, the subnets corresponding to bare machine 1 and bare machine 2 are 88.98.100.0, and the subnets corresponding to bare machine 3 and bare machine 4 are 88.98.104.0. In other words, the network segment used by the storage device is 103, different from the network segment 100 used by bare machine 1 and bare machine 2, and also different from the network segment 104 used by bare machine 3 and bare machine 4. Take the intercommunication between bare machine 1 and the storage device as an example: Bare machine 1 and the storage device are in different subnets, and the ACL rule allowing the subnet of bare machine 1 to communicate with the subnet of the storage device can be set on the core switch. For example, "rule 2 permit 88.98.100.0 0.0.0.255 destination 88.98.103.0 0.0.0.255" can achieve the intercommunication between bare machine 1 and the storage device. Since bare machine 2 and bare machine 1 are in the same subnet, this ACL rule can also achieve the intercommunication between bare machine 2 and the storage device. Referring to the above steps, ACL rules can be set to achieve the intercommunication between bare machine 3, bare machine 4 and the storage device respectively, which will not be elaborated here.

[0093] It should be noted that, in Figure 3 the network configuration shown, the gateway is not set on the switch using MUX-VLAN, but on the core switch.

[0094] After the above settings, combined with MUX-VLAN and ACL rules, finally, bare machine 1 and bare machine 2 cannot communicate with each other, bare machine 3 and bare machine 4 cannot communicate with each other, the storage device can communicate with bare machine 1, bare machine 2, bare machine 3, and bare machine 4 respectively, bare machine 1 cannot communicate with bare machine 3 and bare machine 4 respectively, and bare machine 2 cannot communicate with bare machine 3 and bare machine 4 respectively.

[0095] In some possible embodiments, Figure 3The network shown also includes computing nodes, such as: virtual machine 1, virtual machine 2, virtual machine 3, and virtual machine 4. When the network also includes virtual machines, in addition to implementing isolation between bare machines and interoperability between bare machines and storage devices, it is also necessary to control non-interoperability between bare machines and virtual machines. Among them, virtual machine 1 and virtual machine 2 are respectively connected to the fourth interface and the fifth interface of access switch 1, and the VLAN IDs of the fourth interface and the fifth interface of access switch 1 are set to 2125. Virtual machine 3 and virtual machine 4 are respectively connected to the third interface and the fifth interface of access switch 2, and the VLAN IDs of the third interface and the fifth interface of access switch 2 are set to 2125. In this case, it is required that virtual machines, bare machines, and storage devices use different VLANs and different subnets. From Figure 3 it can be seen that the VLANs used by virtual machines, bare machines, and storage devices are all different. The subnets of virtual machines 1 / 2 are the same and different from the subnets of bare machines and storage devices; the subnets of virtual machines 3 / 4 are the same and different from the subnets of virtual machines 1 / 2, bare machines, and storage devices. Since bare machines and virtual machines are in different VLANs and different subnets, corresponding ACL rules can be set on the core switch to isolate bare machines and virtual machines, so that bare machine 1 and bare machine 2 are not interoperable with any one of virtual machines 1, 2, 3, and 4 respectively, and bare machine 3 and bare machine 4 are not interoperable with any one of virtual machines 1, 2, 3, and 4 respectively. As for whether virtual machines communicate with each other and whether virtual machines communicate with storage devices, the present application does not make specific limitations.

[0096] It should be noted that when setting the isolation and interoperability of bare machines in this network form, when using the MUX-VLAN technology, the same or a small number of VLAN IDs should be used as much as possible. Only one isolated slave VLAN can be bound to the same master VLAN. Therefore, the VLAN IDs corresponding to bare machines 1 / 2 and bare machines 3 / 4 are the same.

[0097] See Figure 4 , Figure 4 is another network diagram of bare machines provided by the embodiment of the present application. As shown in Figure 4 , this scenario includes multiple bare machines, multiple access switches, a core switch, and a storage device. Among them, the storage device is connected to the core switch through access switch 5, and bare machines 1 and 2 are connected to the core switch through access switch 2, and bare machines 3 and 4 are connected to the core switch through access switch 4. In some possible embodiments, Figure 4 the network shown also includes computing nodes, for example, virtual machine 1 and virtual machine 2, and virtual machine 1 and virtual machine 2 are connected to the core switch through access switch 3. It can be seen that virtual machines and bare machines do not share access switches. It should be noted that bare machines, storage devices, and virtual machines use different subnets. In addition, inFigure 4 In this case, it is assumed that the subnet mask is defaulted to 255.255.255.0.

[0098] Under this networking mode, the isolation and interconnection of bare machines are only achieved through the ACL technology, that is, by setting ACL rules to achieve layer-2 traffic isolation and layer-3 traffic isolation between bare machines, layer-3 traffic isolation between bare machines and computing nodes, and interconnection between bare machines and storage devices. The specific implementation is as follows:

[0099] (1) Isolation of bare machines under the same access switch: Bare machines under the same access switch use the same subnet. ACL rules are set on this access switch to prevent interconnection between bare machines under the same access switch, achieving layer-2 traffic isolation. For example, taking the Figure 4 bare machines 3 and 4 as an example, ACL rules are set on access switch 4 to prohibit mutual access between the subnets where bare machine 3 and bare machine 4 are located. For example, "rule 1 deny ip source 88.98.103.0 0.0.0.255 destination 88.98.103.0 0.0.0.255". In addition, referring to the above steps, ACL rules can be set to achieve Figure 4 the non-interconnection between bare machines 1 and 2 under access switch 2 in , which will not be elaborated here. The layer-2 traffic isolation between bare machines under the same access switch can refer to the above operations.

[0100] (2) Isolation between bare machines under different access switches: The subnets of bare machines under different access switches are different. ACL rules are set on the core switch corresponding to the bare machines to achieve isolation between subnets of bare machines, that is, to achieve layer-3 traffic isolation. For example, taking the bare machine 1 under access switch 2 and the bare machine 3 under access switch 4 in Figure 4 as an example, the VLANs used by the interfaces of the access switches corresponding to bare machine 1 and bare machine 3 are different, and the subnets used by bare machine 1 and bare machine 3 are different. If you want bare machine 1 and bare machine 3 to be unable to communicate with each other, set ACL rules on the core switch to prohibit mutual access between the subnets where bare machine 1 and bare machine 3 are located. For example, "rule 1 deny ip source 88.98.100.0 0.0.0.255 destination 88.98.103.0 0.0.0.255" (this ACL rule can prohibit bare machine 1 from accessing bare machine 3) and "rule 2 deny ip source 88.98.103.0 0.0.0.255 destination 88.98.100.0 0.0.0.255" (this ACL rule can prohibit bare machine 3 from accessing bare machine 1). Therefore, it can be achieved that bare machine 1 and bare machine 3 cannot communicate with each other. Since bare machine 1 and bare machine 2 are in the same subnet, and bare machine 3 and bare machine 4 are in the same subnet, the two ACL rules set above can also achieveFigure 4 The bare machines 1 and 4 are not interconnected, and the bare machine 2 is not interconnected with the bare machines 3 and 4 respectively. The isolation between bare machines under different access switches can refer to the above operations.

[0101] (3) Interconnection between the bare machine and the storage device: The bare machine and the storage device use different VLANs and different subnets. The interconnection between the bare machine and the storage device can be achieved by setting ACL rules on the core switch. For example, Figure 4 taking the interconnection setting between the bare machine 3 and the storage device in

[0102] In some possible embodiments, Figure 4 the networking environment shown also includes computing nodes, such as virtual machines 1 and 2. In addition to implementing the isolation between the bare machines as described above, it is also necessary to implement the isolation between the bare machine and the virtual machine. Since the bare machine and the virtual machine use different subnets, therefore, it is necessary to set ACL rules on the core switch to prohibit the bare machine and the virtual machine from accessing each other so that the bare machine and the virtual machine are not interconnected, and the three-layer traffic isolation between the bare machine and the virtual machine is achieved.

[0103] In some possible embodiments, the bare machine and the virtual machine may also share the access switch. If the bare machine and the virtual machine use the same VLAN and the same subnet, for the same access switch, it is necessary to control the Layer 2 traffic isolation between bare machines and the Layer 2 traffic isolation between the bare machine and the virtual machine by setting ACL rules on the access switch; for the same access switch, if the bare machine and the virtual machine use different VLANs and different subnets, for the same access switch, it is necessary to control the Layer 2 traffic isolation between bare machines and the Layer 3 traffic isolation between the bare machine and the virtual machine by setting ACL rules on the access switch. As for the isolation between bare machine subnets and the isolation between the bare machine and the virtual machine under different access switches, it can be set on the core switch with reference to the relevant descriptions above, and this application does not make any limitations.

[0104] It should be noted that in Figure 4 the network architecture shown, it is necessary to configure a gateway for each access switch.

[0105] In some possible embodiments, access switches can be stacked to provide as many interfaces as possible in a limited space, such as Figure 4As shown in the figure, access switch 1 and access switch 2 are stacked. Then, the configurations of access switch 1 and access switch 2 are the same. That is, the VLAN ID of access switch 1 is the same as that of access switch 2, both being 2124, and the gateway of access switch 1 is the same as that of access switch 2, both being 88.98.100.2. Additionally, bare machines 5 and 6 are connected to access switch 1, and bare machines 5 / 6 and bare machines 1 / 2 under access switch 2 are in the same subnet. In this case, to isolate any two of bare machines 1 / 2 and bare machines 5 / 6 from each other, in addition to setting ACL rules on access switch 2 to prohibit bare machines 1 and 2 from communicating with each other, it is also necessary to set ACL rules on access switch 2 to prohibit bare machine 1 from communicating with bare machines 5 and 6 respectively, and to prohibit bare machine 2 from communicating with bare machines 5 and 6 respectively. Similarly, on access switch 1, ACL rules need to be set to prohibit bare machines 5 and 6 from communicating with each other, and to prohibit bare machines 5 and 6 from communicating with bare machines 1 and 5 respectively. Since bare machines 1, 2, 5, and 6 are in the same VLAN and the same subnet, setting ACL rules on access switch 2 to prohibit inter-bare machine access between the same network segments can achieve isolation between any two of bare machines 1, 2, 3, and 4. For example, "rule 1 deny ip source 88.98.100.0 0.0.0.255 destination 88.98.100.0 0.0.0.255". The same ACL rule is also set on access switch 1 to achieve isolation between any two of bare machines 1, 2, 3, and 4. Additionally, the implementation of isolation between bare machines 5, 6 and bare machines 3, 4 respectively can refer to the above rules to make corresponding settings on access switch 1 and access switch 2, which will not be elaborated here.

[0106] Compare Figure 3 and Figure 4 There are mainly two differences. First, for the isolation between bare machines in the same VLAN and the same subnet under the same access switch, Figure 3 uses the isolation VLAN in MUX-VLAN on this access switch to achieve layer-2 traffic isolation between bare machines, while Figure 4 sets ACL rules on this access switch to prohibit communication between bare machines, thereby achieving layer-2 traffic isolation between bare machines. Second, Figure 3 bare machines and virtual machines share the access switch, while Figure 4 bare machines and virtual machines do not share the access switch. In a large-scale networking environment, Figure 4 's networking method can reduce the impact of unexpected events on the whole, with higher security.

[0107] It should be noted that in Figure 3 and Figure 4In the present application, the correspondence between each bare machine and the tenant is not limited, but the bare machines cannot communicate with each other. That is, in Figure 3 and Figure 4 , the relationship between the bare machine and the tenant can be one-to-one, or the bare machine and the tenant can be one-to-many. However, regardless of whether the tenants corresponding to each bare machine are the same or different, the bare machines cannot communicate with each other, and each bare machine can only communicate with the storage device.

[0108] In addition to Figure 3 and Figure 4 shown in the networking mode, refer to Figure 5 , the present application provides another networking mode for the bare machine. In Figure 5 , the correspondence between the tenant and the bare machine is introduced. When the security isolation requirements for the bare machine in the networking are not high, for the isolation between the bare machines, it can be the isolation between the bare machines of different tenants, and the bare machines of the same tenant can communicate with each other, and the bare machine is isolated from the computing node, and the bare machine communicates with the storage device. Figure 5 The networking mode shown can be independent of Figure 3 and Figure 4 , or it can be a supplement to Figure 3 and Figure 5 , and the present application does not make specific limitations.

[0109] In Figure 5 , the storage device and the bare machine use different VLANs and different subnets. The storage device is connected to the core switch through the access switch 3, the bare machine 1 and the bare machine 2 are connected to the core switch through the access switch 1, and the bare machine 3 and the bare machine 4 are connected to the core switch through the access switch 2. The bare machine 1 corresponds to tenant A, and the bare machine 2 corresponds to tenant B, that is, the bare machine 1 and the bare machine 2 correspond to different tenants, and the bare machine 3 and the bare machine 4 both correspond to tenant C.

[0110] Since the bare machine 1 and the bare machine 2 use the same VLAN and the same subnet, the isolation type slave VLAN of MUX-VLAN is used on the access switch 1 to realize the layer 2 traffic isolation between the bare machine 1 and the bare machine 2; the bare machine 3 and the bare machine 4 use the same VLAN and the same subnet, and the bare machine 3 and the bare machine 4 corresponding to the same tenant can communicate with each other. In addition, the bare machine 1 / 2 and the bare machine 3 / 4 use different VLANs and different subnets. ACL rules are set on the core switch to prohibit the bare machine 1 from communicating with the bare machine 3 and the bare machine 4 respectively, and ACL rules are set to prohibit the bare machine 2 from communicating with the bare machine 3 and the bare machine 4 respectively, so as to realize the isolation between the bare machines corresponding to different tenants. For the communication between each bare machine and the storage device, ACL rules can be set on the core switch to allow each bare machine to access the storage device. For the specific settings, reference can be made to Figure 3 or Figure 4 for the relevant description, which will not be elaborated here.

[0111] In some possible embodiments, if Figure 5 When there are computing nodes in the network shown, the computing nodes and bare metal use different subnets. In this case, it is also necessary to control the isolation between bare metal and computing nodes, that is, to set ACL rules on the core switch to prohibit the bare metal and computing nodes from communicating with each other, so as to achieve three-layer traffic isolation. For the specific process, please refer to Figure 3 or Figure 4 The relevant descriptions in will not be repeated here.

[0112] The above networking method is used to control the isolation between bare metals in the networking form and the intercommunication between bare metals and storage devices, thereby obtaining the configuration information of each switch in the networking form where the bare metal is located. In addition, the IP address of the bare metal itself needs to be configured, that is, to achieve the above goal (2). The embodiment of the present application proposes a bare metal IP address automatic configuration method, which can replace the manual configuration of the bare metal IP, and improve the accuracy and configuration efficiency of the bare metal IP configuration. See Figure 6 , Figure 6 The present invention provides a method for automatically configuring a bare metal IP address, which includes but is not limited to the following steps:

[0113] S101. A bare metal management module obtains configuration information of an access switch connected to the bare metal.

[0114] In an embodiment of the present application, the bare metal management module obtains the configuration information of the access switch connected to the bare metal, and the configuration information includes the identifier (or name, number, etc.) of the access switch, the subnet of the access switch, and the mapping relationship between the identifier of the access switch and the subnet of the access switch. In some possible embodiments, the configuration information also includes the VLAN ID of each interface of the access switch, the VLAN attributes of the access switch (i.e., the primary VLAN, isolated slave VLAN, ordinary VLAN, etc.), and the subnet mask and other information. In some possible embodiments, that is, if an ACL is set on the access switch to isolate the Layer 2 traffic between bare metals, the configuration information also includes the gateway of the access switch.

[0115] Specifically, the network administrator pre-configures the Figures 3 - 4 At least one of the networking methods described in the foregoing configures the access switches, core switches and storage devices in the storage network, and stores the configuration information of the access switches, core switches and storage devices. When the bare metal management module needs to automatically configure the IP address of each bare metal, the bare metal management module can obtain the configuration information of the access switch connected to the bare metal from the cloud management platform.

[0116] S102: The bare metal management module obtains the hardware connection information of the bare metal.

[0117] The hardware connection information indicates the connection status between the bare machine and the access switch. The hardware connection information includes the MAC address of the storage network card of the bare machine, the identifier (or name, number, etc.) of the access switch, and the connection mapping relationship between the MAC address of the storage network card of the bare machine and the identifier of the access switch.

[0118] In the embodiment of the present application, after the bare machine custom-installs the operating system according to the tenant, when the bare machine, the access switch, etc. are powered on, the bare machine management module issues a command to update the node information to the bare machine. After receiving the command, the bare machine sends its own link layer discovery protocol (LLDP) information to the bare machine management module. The bare machine management module obtains the hardware connection information of the bare machine from the LLDP information of the bare machine.

[0119] S103. The bare machine management module assigns an IP address to the bare machine according to the configuration information and the hardware connection information.

[0120] In the embodiment of the present application, the bare machine management module determines the identifier of the bare machine and the target access switch connected to the bare machine according to the hardware connection information, and searches for the subnet corresponding to the identifier of the target access switch in the configuration information, thereby determining the network number of the subnet where the bare machine is located; the bare machine management module also determines the MAC address of the storage network card of the bare machine according to the hardware connection information, and assigns a host number to the bare machine according to the MAC address. Thus, the network number and the host number of the bare machine are determined. The network number and the host number constitute the IP address of the bare machine. Therefore, the bare machine management module completes the assignment of the IP address of the bare machine.

[0121] In the case of multiple bare machines, the bare machine management module can sequentially assign host numbers to each bare machine in the corresponding subnet according to the reading order of the MAC addresses of the storage network cards of the multiple bare machines, thereby avoiding duplicate assignment of the IP addresses of the bare machines.

[0122] In some possible embodiments, the bare machine management module can also determine the bare machine, the target access switch connected to the bare machine, and the target interface according to the hardware connection information, search for the VLAN ID and the corresponding subnet corresponding to the target interface of the target access switch in the configuration information, thereby determining the network number of the subnet where the bare machine is located, and then assign host numbers to each bare machine according to the order of reading the MAC addresses of the storage network cards of each bare machine from the hardware connection information.

[0123] For example, assume that the hardware connection information shows that bare machine 1 and bare machine 2 are respectively connected to access switch 1. The bare machine management module pre-assigns IP addresses to bare machine 1 and bare machine 2. Looking up in the configuration information, access switch 1 corresponds to VLAN 2124 and the subnet where it is located is 88.98.100.0. Therefore, the bare machine management module can determine to assign IP addresses to bare machine 1 and bare machine 2 within the subnet 88.98.100.0; further, in the hardware connection information, host numbers are assigned to bare machine 1 and bare machine 2 in sequence according to the reading order of the MAC addresses of bare machine 1 and bare machine 2 to prevent duplicate assignment of host numbers. Finally, the IP address assigned to bare machine 1 is 88.98.100.10, and the IP address assigned to bare machine 2 is 88.98.100.11.

[0124] It should be noted that after the IP addresses of the bare machines are assigned, the bare machine management module stores the IP addresses of the bare machines and the MAC addresses of the storage network cards of the bare machines in the metadata.

[0125] It should be noted that if VLANs are divided based on the interfaces of the switch, the subnet where the bare machine is located can be determined according to the interface of the target switch connected to the bare machine. In some possible embodiments, if VLANs are divided based on MAC addresses, the hardware connection information obtained by the storage device includes the mapping relationship between the bare machine and the MAC address of the switch connected to the bare machine. The subnet where the bare machine is located can be determined according to the MAC address of the switch corresponding to the bare machine.

[0126] S104. The bare machine obtains the assigned IP address from the bare machine management module and sets the IP address of the bare machine to the assigned IP address.

[0127] In the embodiments of the present application, the bare machine obtains the assigned IP address from the bare machine management module and sets the IP address of the bare machine to the assigned IP address. Specifically, the bare machine receives the startup command of the tenant, and the storage Agent module in the bare machine starts automatically. The storage Agent module obtains the assigned IP address from the metadata of the bare machine management module. The assigned IP address corresponds to the MAC address of the storage network card of the bare machine. The storage Agent module uses the assigned IP address as the IP address of the bare machine, thus completing the automatic assignment of the IP address of the bare machine.

[0128] In some possible embodiments, the Dynamic Host Configuration Protocol (DHCP) can also be used to automatically assign IP addresses to the bare machines, and the present application does not make specific limitations.

[0129] It can be seen that by implementing the embodiments of the present application, the IP address of the bare machine is automatically configured based on the networking configuration information of the bare machine and the hardware connection information of the bare machine, which improves the accuracy and efficiency of the IP address configuration of the bare machine and enhances the security of the bare machine's connection to the storage device.

[0130] After the networking configuration of the bare machine and the automatic configuration of the bare machine's IP address are completed, communication can be carried out between the bare machine and the storage device. To further improve the security of communication between the bare machine and the storage device, when the bare machine sends a read operation or write operation command to the storage device, CHAP authentication between the bare machine and the storage device is required, that is, to achieve the above-mentioned objective (3). Before performing CHAP authentication, the user name and user password for CHAP authentication of the bare machine need to be configured first. Refer to Figure 7 , Figure 7 is a flowchart of a method for configuring the user name and user password for CHAP authentication provided by the embodiments of the present application. The method includes but is not limited to the following steps:

[0131] S201. The storage management module receives a first request sent by the tenant.

[0132] In the embodiments of the present application, the storage management module of the cloud management platform receives a first request sent by the tenant. The first request includes tenant information, the size of the volume, and the number of the target bare machine, and the first request is used to instruct the storage management module to create a volume for the target bare machine rented by the tenant.

[0133] S202. The storage management module sets the CHAP authentication information of the tenant and establishes a mapping relationship between the target bare machine and the volume.

[0134] In the embodiments of the present application, after the storage management module of the cloud management platform receives the first request sent by the tenant, it sets the corresponding CHAP authentication information of the tenant. Among them, the CHAP authentication information includes at least one set of user name and user password, and the user name and user password are used for CHAP authentication between the target bare machine rented by the tenant and the storage device. In addition, the storage device allocates a corresponding volume for the target bare machine according to the size of the volume in the first request. Each volume has a unique logical unit number LUN, and a mapping relationship between the target bare machine and the volume is established.

[0135] It should be noted that when the number of target bare machines in the first request is one, there is only one set of user name and user password in the CHAP authentication information; when the number of target bare machines in the first request is multiple, the CHAP authentication information includes multiple sets of user name and user password, that is, the storage management module creates multiple sets of user name and user password for the tenant, that is, each target bare machine corresponds to a set of user name and user password, and the user name and user password corresponding to different target bare machines are different. In other words, the storage management module uses the target bare machine as the basis for creating the user name and user password to improve the security of the target bare machine's connection to the storage device.

[0136] In some possible embodiments, when the number of target bare machines in the first request is multiple, the storage management module may also create only one set of username and user password for the tenant. That is to say, the multiple target bare machines leased by the tenant share this set of username and user password, and the present application does not make specific limitations.

[0137] S203. The storage management module sends CHAP authentication information to the storage device.

[0138] In the embodiments of the present application, the storage management module sends the username and user password for CHAP authentication to the storage device. Correspondingly, the storage device receives the username and user password for CHAP authentication sent by the storage management module.

[0139] S204. The bare machine management module receives a second request sent by the tenant.

[0140] In the embodiments of the present application, the bare machine management module receives a second request sent by the tenant. The second request includes the number of the target bare machine, and the second request is used to instruct the bare machine management module to mount a volume to the target bare machine.

[0141] S205. The bare machine management module obtains the CHAP authentication information of the tenant and the mapping relationship between the target bare machine and the volume from the storage management module.

[0142] In the embodiments of the present application, after receiving the second request, the bare machine management module obtains the CHAP authentication information of the tenant and the mapping relationship between the target bare machine and the volume from the storage management module, and mounts a volume to the target bare machine according to the mapping relationship between the target bare machine and the volume.

[0143] In addition, the bare machine management module sends the metadata of the volume corresponding to the target bare machine to the target bare machine. Correspondingly, the storage Agent module in the target bare machine receives the metadata of the volume.

[0144] It should be noted that whether it is the CHAP authentication information sent by the storage management module to the storage device in S203 or the CHAP authentication information obtained by the bare machine management module in S204, they are all encrypted. The encryption algorithm used in the encryption process may be a symmetric encryption algorithm (such as the DES algorithm), an asymmetric encryption algorithm (such as the RSA algorithm), etc., or a hash algorithm (such as the MD5 algorithm), etc. The present application does not make specific limitations.

[0145] S206. The target bare machine starts up automatically, and the target bare machine obtains the corresponding username and user password from the bare machine management module.

[0146] In the embodiment of the present application, the target bare machine starts up automatically upon receiving the startup command sent by the tenant, and the storage Agent module in the target bare machine obtains the username and user password of the target bare machine from the bare machine management module.

[0147] It should be noted that if the obtained username and user password of the target bare machine are encrypted, correspondingly, the target bare machine also needs to decrypt the obtained username and user password, and send the decrypted username and user password to the iSCSI initiator in the target bare machine, so that when the target bare machine sends read / write operation commands to the storage device, the iSCSI initiator in the bare machine performs CHAP authentication with the storage device based on the username and user password. If the CHAP authentication of the target bare machine is successful, the target bare machine can normally use the corresponding volume in the storage device according to the metadata of the volume. The specific process of CHAP authentication can refer to the following related descriptions. For the sake of simplicity of the specification, it will not be elaborated here.

[0148] In some possible embodiments, if the tenant wants to change the username and user password corresponding to the bare machine, the tenant sends a third request to the storage management module. The third request includes the identifier of the target bare machine, and is used to instruct the storage management module to change the username and user password corresponding to the target bare machine in the CHAP authentication information. The storage management module resends the changed CHAP authentication information to the storage device and the bare machine management module. The tenant restarts the target bare machine, and after the target bare machine starts up automatically, it obtains the corresponding changed username and user password from the bare machine management module, thus completing the update of the username and user password of the bare machine for CHAP authentication.

[0149] It can be seen that by implementing the embodiment of the present application, before the bare machine accesses the storage device, the username and user password of the bare machine for CHAP authentication are configured, so that subsequent CHAP authentication is performed between the bare machine and the storage device, improving the security of the bare machine docking with the storage device, and helping to realize the docking of the bare machine with the storage device based on the iSCSI protocol in a safe and trustworthy manner.

[0150] After the username and user password of the bare machine for CHAP authentication are completed, when the bare machine sends a read operation or write operation command to the storage device, the storage device initiates CHAP authentication to the bare machine that issues the access request to verify whether the bare machine has access rights. Only when the verification is successful can the bare machine perform a read operation or write operation on the storage device. See Figure 8 , Figure 8 is a flowchart of a CHAP authentication method when a bare machine docks with a storage device provided by an embodiment of the present application. The method includes but is not limited to the following steps:

[0151] S301. The storage device sends challenge information to the bare machine.

[0152] Specifically, the storage device sends challenge information to the bare machine. The challenge information includes random data and a CHAP ID. The random data is randomly generated by the storage device, and the CHAP ID is also generated by the storage device. It should be noted that the CHAP ID not only corresponds to the random data, but also corresponds to the bare machine. Accordingly, the bare machine receives the challenge information sent by the storage device.

[0153] It should be noted that the interaction of messages between the bare machine and the storage device during the CHAP authentication process is actually the interaction between the iSCSI initiator of the bare machine and the iSCSI target of the storage device.

[0154] S302. The bare machine processes the first user password and the challenge information to obtain a first hash value.

[0155] Specifically, after receiving the challenge information sent by the storage device, which includes random data and a CHAP ID, the bare machine obtains its own first user password from the storage space, and calculates the first hash value based on the Message-Digest Algorithm 5 (MD5) for the first user password, random data, and CHAP ID.

[0156] The MD5 algorithm is a widely used cryptographic hash function. For any length of input information, after being processed by the MD5 algorithm, a 128-bit (16-byte) hash value can be generated, which can also be called a hash value. Different inputs result in different hash values. Therefore, the MD5 algorithm can be used to ensure the exact consistency of information transmission. The process of obtaining the first hash value by processing the input data with MD5 can refer to the prior art and will not be elaborated here.

[0157] It should be noted that before the storage device sends the challenge information to the bare machine, the bare machine pre-gets the first user password and the first user name from the bare machine management module, and the first user password corresponds to the first user name. When the bare machine is created, the bare machine management module obtains the corresponding first user name and first user password of the bare machine from the storage management module of the storage device.

[0158] S303. The bare machine sends a response message to the storage device.

[0159] Specifically, after obtaining the first hash value, the bare machine sends a response message to the storage device to enable the storage device to authenticate the identity of the bare machine based on the response message. The response message includes the first hash value, the first user name of the bare machine, and the CHAP ID, where the CHAP ID is the one sent by the storage device to this bare machine in S1. Accordingly, the storage device receives the response message sent by the bare machine.

[0160] S304. The storage device processes the second user password and the response information to obtain a second hash value.

[0161] Specifically, after receiving the response information, the storage device looks up the mapping information according to the first user name in the response information to obtain the second user password corresponding to the first user name. The mapping information includes the corresponding relationship between the first user name and the second user password, and the mapping information is stored in the storage device. The storage device also obtains the random data corresponding to the CHAP ID according to the CHAP ID in the response information, and processes the second user password, the random data, and the CHAP ID using the MD5 algorithm to obtain the second hash value.

[0162] S305. The storage device compares whether the first hash value and the second hash value are the same to obtain the CHAP authentication result.

[0163] Specifically, the storage device compares whether the first hash value and the second hash value are the same to obtain the CHAP authentication result. Specifically, if the first hash value is the same as the second hash value, the CHAP authentication result is authentication success, which means the identity of the bare machine is legal; if the first hash value is different from the second hash value, the CHAP authentication result is authentication failure, which means the identity of the bare machine is illegal.

[0164] S306. The storage device sends the CHAP authentication result to the bare machine.

[0165] Specifically, the storage device sends the CHAP authentication result to the bare machine. Correspondingly, the bare machine receives the CHAP authentication result sent by the storage device. When the received CHAP authentication result indicates authentication success, it means the identity of the bare machine is legal and there is a volume mapped to the bare machine in the storage device, and the bare machine has the right to use the volume mapped to the storage device; when the received CHAP authentication result indicates authentication failure, it means the identity of the bare machine is illegal and the bare machine has no right to use the storage space of the storage device.

[0166] It can be seen that before the bare machine accesses the storage device, adding a CHAP authentication process for the bare machine and the storage device to determine whether the bare machine has the right to use the storage space of the storage device improves the security in the process of the bare machine docking the storage device in a multi-tenant scenario and effectively prevents brute force cracking of the iSCSI initiator of the bare machine.

[0167] See Figure 9 , Figure 9 is a schematic structural diagram of a device provided by the present application. The device 21 includes at least one or more processing units 210, an external memory 220, a communication interface 230, and a bus 240. The processing unit 210, the external memory 220, and the communication interface 230 are connected through the bus 240. The device 21 can be Figure 1 the cloud management platform in

[0168] The bus 240 can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus 240 can be divided into an address bus, a data bus, a control bus, etc.

[0169] The communication interface 230 can be a wired interface or a wireless interface for communicating with other modules or devices. The wired interface can be an Ethernet interface, a Controller Area Network (CAN) interface, a Local Interconnect Network (LIN), and a FlexRay interface. The wireless interface can be a cellular network interface or a Wireless Local Area Network (WLAN) interface, etc. In an embodiment of the present application, the communication interface 230 can be respectively used to implement interactions with the bare machine and the storage device.

[0170] The external memory 220 can include volatile memory, such as random access memory (RAM); the memory 220 can also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the memory 220 can further include a combination of the above types. The external memory can be used to store executable program codes and program data. The stored codes include: a bare machine IP address configuration program, configuration programs of each switch, a storage device IP configuration program, a volume creation instruction, a volume mounting instruction, and other application programs; the stored data includes: configuration data of each switch, allocation information of the bare machine IP address, hardware connection information of the bare machine, CHAP authentication information of the bare machine, etc.

[0171] The processing unit 210 can call and execute program codes and data in the external memory 220 to implement specific operations such as forming a storage network, configuring switches and storage devices of the storage network, and allocating IP addresses for bare machines. The processing unit 210 includes a processor 211. For example, it can be a Central Processing Unit (CPU). The CPU can adopt a Complex Instruction Set Computer (CISC) architecture (such as the x86 architecture), a Reduced Instruction Set Computing (RISC) architecture (such as the MIPS (Microprocessor without Interlocked Piped Stages) architecture), and so on.

[0172] The processing unit 210 may also include an internal memory 212, a chipset, registers, and so on.

[0173] The internal memory 212 is used to save instructions or data that the processor 211 has just used or recycled, such as a cache memory, and so on. If the processor 211 needs to use the instruction or data again, it can directly call it from the internal memory 212, reducing the waiting time of the processor 211, and thus improving the efficiency of the system. When the content of the memory data page in the internal memory 212 is inconsistent with the content of the data page in the memory 231, this memory data page can be called a dirty page; when the content of the memory data page in the internal memory 212 is consistent with the content of the data page in the memory 231, this memory data page can be called a clean page.

[0174] The chipset may include a north bridge chip 214, which is responsible for data transmission between the processor 211 and the internal memory 212. Optionally, the chipset may further include a south bridge chip 213. One end of the south bridge chip 213 is connected to the processor 211 through the north bridge chip 210, and the other end is connected to the interfaces of various external devices. In some specific embodiments, the north bridge chip 214 may be integrated into the processor 211, or part of the functions of the south bridge chip 213 may be integrated into the north bridge chip 214, or the south bridge chip 213 may be integrated into the processor 211, or the south bridge chip 213 may be integrated into the north bridge chip 214, and so on.

[0175] Registers are high-speed storage components with limited storage capacity. They can be used to temporarily store instruction, data, address, and other OS status data, such as an Instruction Register (IR), a Program Counter (PC), and an Accumulator (ACC), and so on.

[0176] See Figure 10 , Figure 10It is a schematic functional structure diagram of a device provided by the present application. The device 30 includes a building unit 310 and a configuration unit 311. The device 30 can be implemented by hardware, software, or a combination of both.

[0177] Among them, the building unit 310 is used to build a storage network. The storage network includes multiple bare machines, access switches, core switches, and storage devices; the multiple bare machines are connected to the access switches, the multiple access switches are connected to the core switches, and the core switches are connected to the storage devices; the configuration unit 311 is used to configure the storage network so that each of the multiple bare machines can communicate with the storage device and any two of the multiple bare machines are isolated from each other. In some possible embodiments, the device 30 further includes an allocation unit 312, and the allocation unit 312 is used for automatic configuration of bare machine IPs.

[0178] Each functional module of the device 30 can be used to implement Figures 3 - 7 the method described in the embodiment. The building unit 310 can be used to implement Figures 3 - 5 the networking of the storage network shown in any one of the Figures 3 - 5 embodiments, and the configuration unit 311 can be used to implement Figure 6 the configuration of the storage network shown in any one of the Figure 7 embodiments. In the

[0179] embodiment, the allocation unit 312 can be used to execute S101 - S103. Each functional module of the device 30 can also be used to execute Figure 7 the method described in the embodiment. For the sake of simplicity of the specification, it will not be elaborated here.

[0179] Refer to Figure 11 , Figure 11 It is a schematic functional structure diagram of a device provided by the present application. The device 40 includes: the device 40 includes a sending unit 410, a receiving unit 411, and an authentication unit 412. The device 40 can be implemented by hardware, software, or a combination of both.

[0180] Among them, the sending unit 410 is used to send a challenge message to the device 50, the receiving unit 411 is used to receive the response message sent by the device 50, the authentication unit 412 is used to perform CHAP authentication on the identity of the device 50 according to the response message to obtain a CHAP authentication result, and the sending unit 410 is further used to send the CHAP authentication result to the device 50.

[0181] Each functional module of the device 40 can be used to implement Figure 8 the method described in the Figure 8 embodiment. In the Figure 8 embodiment, the sending unit 410 can be used to execute S301 and S306, the receiving unit 411 can be used to execute S303, and the authentication unit 412 is used to execute S304 and S305. Each functional module of the device 40 can also be used to execute Figure 7The method described in the embodiment will not be elaborated here for the sake of the simplicity of the specification.

[0182] See Figure 12 , Figure 12 which is a schematic functional structure diagram of a device provided by the present application. The device 50 includes a receiving unit 510, a processing unit 511, and a transmitting unit 512. The device 50 can be implemented by means of hardware, software, or a combination of both.

[0183] Among them, the receiving unit 510 is used to send challenge information sent by the receiving device 40, the processing unit 511 is used to process the challenge information to obtain a first hash value, the transmitting unit 512 is used to send response information to the device 40, and the receiving unit 510 is further used to receive the CHAP authentication result sent by the device 40.

[0184] Each functional module of the device 50 can be used to implement Figure 8 the method described in the embodiment. In Figure 8 the embodiment, the receiving unit 510 can be used to execute S301 and S306, the processing unit 511 can be used to execute S302, and the transmitting unit 512 is used to execute S303. Each functional module of the device 50 can also be used to execute Figure 7 the method described in the embodiment. For the sake of the simplicity of the specification, it will not be elaborated here.

[0185] In the above embodiments of this article, the descriptions of the respective embodiments have their own emphases. For the parts not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0186] It should be noted that those of ordinary skill in the art can see that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program, and this program can be stored in a computer-readable storage medium. The storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disc memories, tape memories, or any other computer-readable medium capable of carrying or storing data.

[0187] Essentially, or in terms of the part that contributes to the prior art, or all or part of the technical solution of this application can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a device (which can be a personal computer, server, or network device, robot, single-chip microcomputer, chip, robot, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.

Claims

1. A docking storage method for a bare machine, characterized in that, The method is applied to a cloud management platform, and the method includes: Construct a storage network, where the storage network includes multiple bare machines, access switches, core switches, and storage devices; the multiple bare machines are connected to the access switches, the access switches are connected to the core switches, and the core switches are connected to the storage devices; Configure the storage network through at least one of a composite virtual local area network MUX-VLAN and an access control list, so that each of the multiple bare machines can communicate with the storage device and any two of the multiple bare machines are isolated from each other. The multiple bare machines include bare machines in the same VLAN; where, when the multiple bare machines include a first bare machine and a second bare machine in different subnets, the core switch is provided with a first access control list for isolating the first bare machine and the second bare machine; when the multiple bare machines include a third bare machine and a fourth bare machine in the same VLAN and the same subnet, the access switch to which the third bare machine and the fourth bare machine are connected is provided with the MUX-VLAN or a second access control list to isolate the third bare machine and the fourth bare machine; the first access control list and the second access control list belong to the access control list, and the first bare machine and the second bare machine are respectively connected to the core switch through different access switches.

2. The method according to claim 1, wherein The access control list includes a third access control list, and configuring the storage network through at least one of a composite virtual local area network MUX-VLAN and an access control list includes: Set the third access control list on the core switch so that each of the multiple bare machines can communicate with the storage device, and each bare machine and the storage device are in different VLANs and different subnets.

3. The method according to claim 2, characterized in that, When the storage network further includes computing nodes, the access control list includes a fourth access control list, and configuring the storage network through at least one of a composite virtual local area network MUX-VLAN and an access control list further includes: Set the fourth access control list on the core switch so that each of the multiple bare machines is isolated from the computing nodes, and each bare machine and the computing nodes are in different VLANs and different subnets.

4. The method according to claim 1, characterized in that, The IP address of each of the multiple bare machines is automatically configured based on the subnet of the access switch to which each bare machine is connected and the MAC address of each bare machine.

5. The method according to claim 1, wherein After each of the multiple bare machines communicates with the storage device, before each bare machine accesses the storage device, each bare machine passes the CHAP authentication initiated by the storage device.

6. The method according to claim 5, wherein Each of the multiple bare machines corresponds to a set of user names and user passwords for the CHAP authentication, and the user names and user passwords corresponding to different bare machines are different.

7. A device, characterized in that, The device includes: A building unit for building a storage network, the storage network including multiple bare machines, access switches, core switches, and storage devices; the multiple bare machines are connected to the access switches, the access switches are connected to the core switches, and the core switches are connected to the storage devices; A configuration unit for configuring the storage network through at least one of a composite virtual local area network MUX-VLAN and an access control list, so that each of the multiple bare machines can communicate with the storage device and any two of the multiple bare machines are isolated from each other, and the multiple bare machines include bare machines in the same VLAN; wherein, when the multiple bare machines include a first bare machine and a second bare machine in different subnets, the core switch is provided with a first access control list for isolating the first bare machine and the second bare machine; when the multiple bare machines include a third bare machine and a fourth bare machine in the same VLAN and the same subnet, the access switch to which the third bare machine and the fourth bare machine are connected is provided with the MUX-VLAN or a second access control list to isolate the third bare machine and the fourth bare machine; the first access control list and the second access control list; the first access control list and the second access control list belong to the access control list, and the first bare machine and the second bare machine are respectively connected to the core switch through different access switches.

8. The device according to claim 7, characterized in that, The access control list includes a third access control list, and the configuration unit is specifically used for: Setting the third access control list on the core switch so that each of the multiple bare machines can communicate with the storage device, and each of the bare machines and the storage device are in different VLANs and different subnets.

9. The device according to claim 8, characterized in that, When the storage network further includes computing nodes, the access control list includes a fourth access control list, and the configuration unit is further used for: Setting the fourth access control list on the core switch so that each of the multiple bare machines is isolated from the computing nodes, and each of the bare machines and the computing nodes are in different VLANs and different subnets.

10. The device according to claim 7, characterized in that, The IP address of each of the multiple bare machines is automatically configured based on the subnet of the access switch to which each of the bare machines is connected and the MAC address of each of the bare machines.

11. The device according to claim 7, characterized in that After each of the multiple bare machines communicates with the storage device, before each of the bare machines accesses the storage device, each of the bare machines passes the CHAP authentication initiated by the storage device.

12. The device according to claim 11, wherein Each of the multiple bare machines corresponds to a set of user names and user passwords for the CHAP authentication, and the user names and user passwords corresponding to different bare machines are different.

13. A storage system for a bare machine, characterized in that, The storage system includes multiple bare machines, access switches, core switches, and storage devices; the multiple bare machines are connected to the access switches, the access switches are connected to the core switches, and the core switches are connected to the storage devices; Each of the multiple bare machines communicates with the storage device, and any two of the multiple bare machines are isolated from each other. The multiple bare machines include bare machines in the same VLAN. The storage system is configured by at least one of a composite virtual local area network MUX-VLAN and an access control list. When the multiple bare machines include a first bare machine and a second bare machine in different subnets, a first access control list for isolating the first bare machine from the second bare machine is set on the core switch. When the multiple bare machines include a third bare machine and a fourth bare machine in the same VLAN and the same subnet, the MUX-VLAN or a second access control list is set on the access switch to which the third bare machine and the fourth bare machine are connected to isolate the third bare machine from the fourth bare machine. The first access control list and the second access control list belong to the access control list. The first bare machine and the second bare machine are respectively connected to the core switch through different access switches.

14. The system according to claim 13, wherein a third access control list is set on the core switch. The third access control list enables each of the multiple bare machines to communicate with the storage device. Each of the bare machines and the storage device are in different VLANs and different subnets. The third access control list belongs to the access control list.

15. The system according to claim 14, wherein When the storage system further includes a computing node, a fourth access control list is further set on the core switch. The fourth access control list enables each of the multiple bare machines to be isolated from the computing node. Each of the bare machines and the computing node are in different VLANs and different subnets. The fourth access control list belongs to the access control list.

16. The system according to claim 13, wherein The IP address of each of the multiple bare machines is automatically configured based on the subnet of the access switch to which each of the bare machines is connected and the MAC address of each of the bare machines.

17. The system according to claim 13, wherein After each of the multiple bare machines communicates with the storage device, before each of the bare machines accesses the storage device, each of the bare machines passes the CHAP authentication initiated by the storage device.

18. The system according to claim 17, wherein Each of the multiple bare machines corresponds to a set of user names and user passwords for the CHAP authentication, and the user names and user passwords corresponding to different bare machines are different.

Citation Information

Patent Citations

  • Data processing method, related device and computer storage medium

    CN109302466A