A system and method for securely mounting a distributed file system

By introducing the VFS layer, driver layer and virtual machine monitor layer in the virtualized environment, blocking the authentication information of the distributed cluster, and dynamically mount and uninstalling the file system through the dynamic management module, the problem of low security risks and integration when using the CephFS file system in the virtualized environment is solved, and a distributed file system with high security and simple structure is realized.

CN114675932BActive Publication Date: 2025-05-30SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210318379.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2025-05-30
Estimated Expiration
2042-03-29

AI Technical Summary

Technical Problem

When using CephFS file system in a virtualized environment, the prior art poses huge security risks, complex network topology and low integration problems, making it difficult to provide a securely mounted distributed file system with a simple structure and high security.

Method used

By introducing the VFS layer, driver layer and virtual machine monitor layer in the virtualization environment, communication connection is established between the front-end driver and the back-end driver. The virtual machine monitor layer blocks the authentication information of the distributed cluster and realizes dynamic mount and uninstall of the file system through the dynamic management module.

Benefits of technology

It realizes a secure mount distributed file system with high security and simple structure, which can realize data reading and writing functions with fewer resources, facilitate management and maintenance, and reduce operation and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114675932B_ABST
    Figure CN114675932B_ABST
Patent Text Reader

Abstract

The present invention discloses a system for securely mounting a distributed file system, which includes a VFS layer, a driver layer, and a virtual machine monitor layer; the driver layer includes a front-end driver and a back-end driver that communicate with each other, and a client is established in the virtual machine monitor layer; the VFS layer and the front-end driver are located on the guest side, the VFS layer mounts the file system of the distributed cluster corresponding to the client, and the front-end driver is used to drive the VFS layer; the back-end driver and the virtual machine monitor layer are located on the host side, the back-end driver is used to drive the client, the client is directly communicatively connected to the distributed cluster, and the virtual machine monitor layer shields the authentication information of the distributed cluster from the client on the guest side. It has high security, and at the same time, its structure is simple, and it can implement the data reading and writing functions with only less resources, which is convenient for management and maintenance. The present invention also provides a method, which also has the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, and particularly to a system for securely mounting a distributed file system and a method for securely mounting a distributed file system. Background Art

[0002] Hypervisor is an intermediate software layer running between a basic physical server and an operating system, which allows multiple operating systems and applications to share hardware. It can also be called VMM (virtual machine monitor), that is, virtual machine monitor. Hypervisor is the core of all virtualization technologies. According to different Hypervisors, virtualization is divided into type I virtualization and type II virtualization. Among them, type I virtualization means that virtual machines directly run on system hardware to create full hardware emulation instances, which is called the "bare metal" type; type II virtualization means that virtual machines run on a traditional operating system to create full hardware emulation instances, which is called the "hosted" type. The hosted / host type Hypervisor runs on the basic operating system to build a complete set of virtual hardware platforms, including CPUs, memory, and peripherals such as network cards and hard disks. Users can install Guest operating systems and application software as needed. The operating systems at the Host bottom layer and the Guest layer can be completely independent, such as running the Linux operating system on Windows. Currently, the mainstream type II virtualization Hypervisors include KVM+QEMU, Virtual PC, etc.

[0003] CephFS is a file system that supports the POSIX (Portable Operating System Interface) interface. It uses a Ceph storage cluster to store data and separates the management and storage of the metadata and data of the file system. CephFS is built on top of RADOS, inherits the fault tolerance and scalability of RADOS, and supports redundant copies and high data reliability. Currently, the methods for virtual machines in a virtualized environment to use the CephFS file system either have huge security risks, complex network topologies, or low integration levels, making it inconvenient for management and maintenance. Therefore, how to provide a technical solution for securely mounting a distributed file system with a simple structure and high security is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0004] The object of the present invention is to provide a system for securely mounting a distributed file system, which has a simple structure and high security; another object of the present invention is to provide a method for securely mounting a distributed file system, the system structure of which is simple and secure.

[0005] To solve the above technical problems, the present invention provides a system for securely mounting a distributed file system, including a VFS layer, a driver layer, and a virtual machine monitor layer; the driver layer includes a front-end driver and a back-end driver that communicate with each other, and a client is established in the virtual machine monitor layer;

[0006] The VFS layer and the front-end driver are located at the guest side. The VFS layer mounts the file system corresponding to the distributed cluster of the client, and the front-end driver is used to drive the VFS layer;

[0007] The back-end driver and the virtual machine monitor layer are located at the host side. The back-end driver is used to drive the client, and the client is directly communicatively connected to the distributed cluster. The virtual machine monitor layer shields the authentication information of the distributed cluster from the guest side.

[0008] Optionally, it further includes a dynamic management module located at the host side, and the dynamic management module mounts or unmounts the file system dynamically.

[0009] Optionally, the distributed cluster is a Ceph cluster, the client is a Cephfs client, the back-end driver is a virtio-cephfs back-end driver, the front-end driver is a virtio-cephfs front-end driver, and the file system is a Cephfs file system.

[0010] Optionally, the file system is the file system mounted by the VFS layer according to the mount point reported by the virtual machine monitor layer.

[0011] Optionally, the mount point is a CephFS file system identification label.

[0012] Optionally, the dynamic management module is used for:

[0013] When dynamically mounting the file system, trigger the client to access the distributed cluster, enable the back-end driver to initiate a registration interrupt of the mount point, and complete the dynamic mounting of the file system.

[0014] Optionally, the dynamic management module is used for:

[0015] When dynamically unmounting the file system, trigger the client to close the communication connection with the distributed cluster, enable the back-end driver to initiate a release interrupt of the mount point, and complete the dynamic unmounting of the file system.

[0016] Optionally, the front-end driver and the back-end driver use the same shared memory.

[0017] The present invention also provides a method for securely mounting a distributed file system, including:

[0018] Establish a client in the virtual machine monitor on the host side, so that the client is directly communicatively connected to the distributed cluster;

[0019] Mount the file system of the distributed cluster in the VFS layer on the guest side;

[0020] Establish a communication connection between the file system and the client through the front-end driver and the back-end driver; the driver layer includes a front-end driver and a back-end driver that are communicatively connected to each other. The front-end driver is located on the guest side and is used to drive the VFS layer; the back-end driver is located on the host side and is used to drive the client. The virtual machine monitor layer shields the authentication information of the distributed cluster from the guest.

[0021] Optionally, it further includes:

[0022] Dynamically mount or unmount the file system through the dynamic management module.

[0023] A system for securely mounting a distributed file system provided by the present invention includes a VFS layer, a driver layer, and a virtual machine monitor layer; the driver layer includes a front-end driver and a back-end driver that are communicatively connected to each other. A client is established in the virtual machine monitor layer; the VFS layer and the front-end driver are located on the guest side. The VFS layer mounts the file system of the distributed cluster corresponding to the client, and the front-end driver is used to drive the VFS layer; the back-end driver and the virtual machine monitor layer are located on the host side. The back-end driver is used to drive the client, and the client is directly communicatively connected to the distributed cluster. The virtual machine monitor layer shields the authentication information of the distributed cluster from the guest-side client.

[0024] By transforming the virtual machine monitor in type-II virtualization into a user-mode client, directly establishing network communication with the distributed cluster, dynamically registering the file system in the VFS layer in the Guest side, and shielding the authentication information of the distributed cluster in the virtual machine monitor layer, it has high security. At the same time, its structure is simple, and it can implement the data reading and writing functions with only less resources, which is convenient for management and maintenance.

[0025] The present invention also provides a method for securely mounting a distributed file system, which also has the above beneficial effects and will not be elaborated here. Brief Description of the Drawings

[0026] To more clearly illustrate the technical solutions of the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0027] Figure 1 It is the system architecture diagram of a system for securely mounting a distributed file system provided by an embodiment of the present invention;

[0028] Figure 2 It is the deployment architecture diagram of a system for securely mounting a distributed file system provided by an embodiment of the present invention;

[0029] Figure 3 It is the flowchart of a method for securely mounting a distributed file system provided by an embodiment of the present invention.

[0030] In the figure: 1. VFS layer, 2. Driver layer, 3. Client. Detailed implementation manners

[0031] The core of the present invention is to provide a system for securely mounting a distributed file system. In the prior art, currently, there are mainly three methods for virtual machines in a virtualized environment to use the CephFS file system: First, the direct usage method. The Guest system acts as a client of the CephFS and can directly access the CephFS cluster through Ceph-fuse or the Ceph kernel module. In this usage method, the underlying Ceph cluster authentication information is directly exposed to tenant access, and it is required that the tenant virtual machine is interconnected with the Ceph network, which poses a huge security risk. Therefore, cloud platform manufacturers cannot use this method. Second, the indirect usage method through NFS protocol conversion. NFS-Ganesha is an open-source file server based on NFS and supports multiple storage backends. CephFS is exported as NFS through NFS-ganesha, and the NFS client inside the virtual machine mounts the NFS exported by NFS-ganesha to indirectly use CephFS. This method is the current mainstream method. In this method, the virtual machine accesses the NFS-ganesha service, and the NFS-ganesha service then connects to the CephFS cluster. The existence of the intermediate medium, the NFS-ganesha server, increases the software stack, resource consumption, and operation and maintenance costs; the network path is long, and it is required that the virtual machine network and the NFS-ganesha service network are reachable, and the network topology is complex, which does not increase the operation and maintenance costs; there are problems such as a long network path and NFS-ganesha protocol conversion consumption, which affect data read and write performance. Third, the indirect usage method through host directory mounting. The host mounts the CephFS file system to a local directory in a kernel manner, and the virtual machine uses protocols such as 9pfs and virtiofs to access the local directory to indirectly use the CephFS file system; this method only supports mounting the file system when the Guest starts and does not support dynamic mounting and unloading; moreover, the 9pfs protocol involved in this method has very low conversion efficiency and insufficient file system read and write performance; the virtiofs protocol requires the host to deploy the virtio-fsd program, and the Guest installs the virtio-fs file system and the virtio-fs driver program, with many dependencies and low integration, which is not convenient for management and maintenance.

[0032] A system for securely mounting a distributed file system provided by the present invention includes a VFS layer, a driver layer, and a virtual machine monitor layer; the driver layer includes a front-end driver and a back-end driver that communicate with each other, and a client is established in the virtual machine monitor layer; the VFS layer and the front-end driver are located at the guest end, the VFS layer mounts the file system of the distributed cluster corresponding to the client, and the front-end driver is used to drive the VFS layer; the back-end driver and the virtual machine monitor layer are located at the host end, the back-end driver is used to drive the client, the client is directly communicatively connected to the distributed cluster, and the virtual machine monitor layer shields the authentication information of the distributed cluster from the client at the guest end.

[0033] By transforming the virtual machine monitor in type II virtualization into a user-mode client, directly establishing network communication with the distributed cluster, dynamically registering the file system in the VFS layer on the Guest side, and shielding the authentication information of the distributed cluster in the virtual machine monitor layer, it has high security. At the same time, its structure is simple, and it can implement the read and write functions of data with only less resources, which is convenient for management and maintenance.

[0034] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0035] Please refer to Figure 1 and Figure 2 , Figure 1 FIG. Figure 2 is a system architecture diagram of a system for securely mounting a distributed file system provided by an embodiment of the present invention;

[0036] See Figure 1 and Figure 2 In the embodiment of the present invention, the system for securely mounting a distributed file system includes a VFS layer 1, a driver layer 2, and a virtual machine monitor layer; the driver layer 2 includes a front-end driver and a back-end driver that communicate with each other, and a client 3 is established in the virtual machine monitor layer; the VFS layer 1 and the front-end driver are located on the Guest side, the VFS layer 1 mounts the file system corresponding to the distributed cluster of the client 3, and the front-end driver is used to drive the VFS layer 1; the back-end driver and the virtual machine monitor layer are located on the Host side, the back-end driver is used to drive the client 3, the client 3 is directly communicatively connected to the distributed cluster, and the virtual machine monitor layer shields the authentication information of the distributed cluster from the Guest.

[0037] In the physical structure, in the embodiments of the present invention, virtual machines will be virtualized in each host machine, as well as the virtual machine monitor layer of type-II virtualization corresponding to each virtual machine, that is, the II hypervisor. Then, a corresponding client 3 will be established in this virtual machine monitor layer, and it will communicate directly with the distributed cluster through the network card of its corresponding host machine. For the system architecture, a system for securely mounting a distributed file system provided in the embodiments of the present invention is divided into three layers, namely the VFS layer 1, the driver layer 2, and the virtual machine monitor layer. Among them, the driver layer 2 includes a front-end driver and a back-end driver that communicate with each other, which are respectively arranged on the guest side and the host side to implement the driving function; and a client 3 is established in the virtual machine monitor layer.

[0038] In the VFS layer 1 of the operating system on the guest side, that is, virtio-cephfs, the file system of the distributed cluster corresponding to the above-mentioned client 3 is mounted, such as the CephFS file system, so as to facilitate users to operate on the guest side. Specifically, in the embodiments of the present invention, a virtio-cephfs file system type needs to be added to the Guest kernel, and the remote CephFS file system is mapped to the virtio-cephfs file system in the guest side for users to use. The above-mentioned front-end driver is usually located in the Guest operating system kernel module, and it mainly provides the underlying driver for the file system in the VFS layer 1, that is, provides the underlying interface support to implement operations such as data reading and writing.

[0039] On the host side, usually specifically in the virtual machine monitor layer, that is, in the Hypervisor, the back-end driver is implemented. This back-end driver first needs to perform data interaction with the above-mentioned front-end driver located on the guest side. Specifically, when the above-mentioned front-end driver responds to the data reading and writing requests of the VFS layer 1, it will transfer the requests to the above-mentioned back-end driver for subsequent data reading and writing operations.

[0040] The client 3 established in the hypervisor will communicate directly with the distributed cluster. The above-mentioned back-end driver also needs to interact with the client 3 established in the virtual machine monitor layer. After receiving the read-write request sent by the front-end driver, it needs to be converted into a corresponding interface for invocation, such as being converted into a libcephfs library interface for invocation, so as to send this request to the client 3 established in the virtual machine monitor layer, enabling it to communicate directly with the distributed cluster to complete this request.

[0041] In the embodiments of the present invention, the virtual machine monitor layer will shield the authentication information of the distributed cluster from the guest side. This authentication information includes the IP address and port number of the distributed cluster, as well as information such as the user name and keyring (similar to a secret key) used for authentication, to achieve secure access on the guest side.

[0042] Specifically, in the embodiment of the present invention, the distributed cluster is a Ceph cluster, the client 3 is a Cephfs client 3, the backend driver is a virtio-cephfs backend driver, the front-end driver is a virtio-cephfs front-end driver, and the file system is a Cephfs file system. That is, the system provided by the embodiment of the present invention is specifically a system established for CephFS. CephFS is a file system that supports the POSIX interface. It uses a Ceph storage cluster to store data, and separates the management and storage of the metadata and data of the file system, thereby facilitating the mounting of the Cephfs file system at the VFS layer 1.

[0043] Specifically, in the embodiment of the present invention, the file system is a file system mounted by the VFS layer 1 according to the mount point reported by the virtual machine monitor layer. In actual operation, the virtual machine monitor layer will first report a mount point, and this mount point will correspond to a file system. Through the data transmission of the above-mentioned driver layer 2, the mount point can be uploaded to the VFS layer 1, thereby mapping the corresponding file system. At this time, the mapping basis of the VFS layer 1 is the mount point reported by the virtual machine monitor layer.

[0044] Furthermore, in the embodiment of the present invention, the mount point is a CephFS file system identification label. At this time, the only information about the file system used in the guest end is this mount point or its identification label, which realizes the secure access of the guest. Generally, the CephFS file system is similar to ext4, virtio-fs, etc., supports the POSIX protocol, and supports functions such as CephFS file system snapshots and quotas.

[0045] Correspondingly, in the embodiment of the present invention, the virtual machine monitor layer hypervisor can use the libcephfs library and the Ceph cluster authentication information to establish network communication and data interaction with the CephFS cluster, and maintain a one-to-one mapping relationship between the CephFS file system and the corresponding identification label of this file system in the Guest end. Since the above-mentioned CephFS client 3 is located outside the Guest end, the virtual machine monitor layer can shield the Ceph cluster authentication information and has a natural security attribute.

[0046] The CephFS client 3 receives the data read and write requests of the virtio-cephfs backend driver, and uses the libcephfs library interface to communicate with the CephFS, thereby completing the real read and write operations of the CephFS file system.

[0047] A system for securely mounting a distributed file system provided by an embodiment of the present invention transforms the virtual machine monitor in type II virtualization into a user-mode client 3, directly establishes network communication with the distributed cluster, dynamically registers the file system in the VFS layer 1 in the Guest end, and shields the authentication information of the distributed cluster in the virtual machine monitor layer, having high security. At the same time, its structure is simple, and it can implement the read and write functions of data with only less resources, which is convenient for management and maintenance.

[0048] The specific content of a system for securely mounting a distributed file system provided by the present invention will be introduced in detail in the following embodiments of the invention.

[0049] Different from the above embodiments of the invention, the embodiments of the present invention further limit the relevant content of the mount point on the basis of the above embodiments of the invention. The rest of the content has been introduced in detail in the above embodiments of the invention and will not be repeated here.

[0050] See Figure 1 , in the embodiment of the present invention, the system for securely mounting a distributed file system further includes a dynamic management module located at the host end, and the dynamic management module mounts or unmounts the file system dynamically.

[0051] The above dynamic management module is usually set in the virtual machine monitor layer. This dynamic management module is mainly used to implement the dynamic mounting and dynamic unmounting of the above file system. In the embodiment of the present invention, the dynamic management module usually needs to communicate with the above client 3 and the backend driver to implement the above dynamic mounting and dynamic unmounting functions. Usually, the above dynamic management module needs to be responsible for the connection life cycle management between the above client 3 and the distributed cluster, such as the connection between the CephFS client 3 and the CephFS cluster, including creating a connection, closing a connection, etc. It is responsible for the file system, including the dynamic mounting and unmounting of the CephFS file system.

[0052] Specifically, in the embodiment of the present invention, the dynamic management module is used for:

[0053] When dynamically mounting the file system, trigger the client 3 to access the distributed cluster, enable the backend driver to initiate a registration interrupt of the mount point, and complete the dynamic mounting of the file system.

[0054] That is, when a dynamic file system mount is required, the dynamic management module first needs to trigger an operation for the client 3 to access the distributed cluster, enabling the dynamic management module to control the back-end driver to initiate a registration interruption of the mount point. That is, when running on the guest side, an interruption signal for dynamic registration of the mount point is sent to the front-end driver through the interruption mechanism. At this time, the front-end driver can respond to the interruption request of the back-end driver to perform dynamic registration of the mount point, realizing the dynamic mount function of the file system, including the CephFS file system.

[0055] Specifically, in the embodiment of the present invention, the dynamic management module can also be used for:

[0056] When dynamically unmounting the file system, trigger the client 3 to close the communication connection with the distributed cluster, enable the back-end driver to initiate a release interruption of the mount point, and complete the dynamic unmounting of the file system.

[0057] That is, when a dynamic file system unmount is required, the dynamic management module first needs to trigger an operation for the client 3 to close the communication connection with the distributed cluster, enabling the dynamic management module to control the back-end driver to initiate a release interruption of the mount point. That is, when running on the guest side, an interruption signal for dynamic release of the mount point is sent to the front-end driver through the interruption mechanism. At this time, the front-end driver can respond to the interruption request of the back-end driver to perform dynamic release of the mount point, realizing the dynamic unmount function of the file system, including the CephFS file system.

[0058] When the guest side is started for the first time, the front-end driver is responsible for scanning and registering the mount points of the remote file system during the startup of the guest side; correspondingly, the back-end driver is responsible for responding to the scanning signal of the front-end driver during the startup of the guest side and reporting the mount point information. In the embodiment of the present invention, the front-end driver and the back-end driver can use the same shared memory. That is, in the embodiment of the present invention, a shared memory mechanism is specifically used to achieve efficient data transmission between the front-end driver and the back-end driver, improving the read and write performance of the file system.

[0059] In the embodiment of the present invention, the guest side can specifically use the mount–t virtio-cephfs src-tagdest command to mount the remote file system for internal use. Among them, src-tag is the mount point scanned and registered by the front-end driver, which is a user-defined mount point string.

[0060] The system provided by the embodiments of the present invention transforms the type-II Hypervisor into a user-mode CephFS client 3, which directly establishes network communication with CephFS. The CephFS clients 3 are distributed among different Hypervisor host machines, without a single point of failure problem. For network requirements, it only requires the network interoperability between the Hypervisor host machines and the Ceph cluster, and has no requirements for the virtual machine network. Therefore, it only involves the physical network, and the network topology is simple. The network path does not involve the virtual network, and the network path is short, reducing the impact of network latency and jitter on data read and write performance.

[0061] Next, a method for securely mounting a distributed file system provided by the embodiments of the present invention will be introduced. The method for securely mounting a distributed file system described below can be correspondingly referred to the system for securely mounting a distributed file system described above.

[0062] Please refer to Figure 3 , Figure 3 which is a flowchart of a method for securely mounting a distributed file system provided by the embodiments of the present invention.

[0063] Referring to Figure 3 , in the embodiments of the present invention, the method for securely mounting a distributed file system includes:

[0064] S101: Establish a client in the virtual machine monitor at the host end, so that the client directly communicates and connects with the distributed cluster.

[0065] S102: Mount the file system of the distributed cluster in the VFS layer at the guest end.

[0066] S103: Establish a communication connection between the file system and the client through the front-end driver and the back-end driver.

[0067] In the embodiments of the present invention, the driver layer 2 includes a front-end driver and a back-end driver that communicate with each other. The front-end driver is located at the guest end and is used to drive the VFS layer 1; the back-end driver is located at the host end and is used to drive the client 3. The virtual machine monitor layer shields the authentication information of the distributed cluster from the guest. The specific contents of the above VFS layer 1, driver layer 2, and virtual machine monitor layer have been introduced in detail in the above embodiments of the invention, and will not be elaborated here.

[0068] In the embodiments of the present invention, a client 3 and a backend driver are established respectively at the virtual machine monitor layer on the host side, a front-end driver is set in the guest side, and a file system is mounted at the VFS layer 1 in the guest side. By transforming the virtual machine monitor in type II virtualization into a user-mode client 3, direct network communication with the distributed cluster is established, the file system is dynamically registered at the VFS layer 1 in the guest side, and the authentication information of the distributed cluster is shielded at the virtual machine monitor layer, which has high security. At the same time, its structure is simple, and the read and write functions of data can be realized with only less resources, which is convenient for management and maintenance.

[0069] Specifically, in the embodiments of the present invention, a method for securely mounting a distributed file system may further include:

[0070] S104: Dynamically mount or unmount the file system through a dynamic management module.

[0071] The specific content of the dynamic management module has been introduced in detail in the above-mentioned embodiments of the invention, and will not be elaborated here.

[0072] The method of this embodiment is used to implement the foregoing system. Therefore, the specific implementation manners in the above method can be seen in the embodiment part of the system in the previous text. Therefore, its specific implementation manners can be referred to the descriptions of the corresponding parts of each embodiment, and will not be elaborated here.

[0073] In this specification, each embodiment is described in a progressive manner. The key points of each embodiment are the differences from other embodiments. The same or similar parts between each embodiment can be referred to each other.

[0074] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0075] The steps of the method or algorithm described in combination with the embodiments disclosed in this article can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.

[0076] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.

[0077] The above has introduced in detail a system for securely mounting a distributed file system and a method for securely mounting a distributed file system provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the protection scope of the claims of the present invention.

Claims

1. A system for securely mounting a distributed file system, characterized in that, it includes a VFS layer, a driver layer, and a virtual machine monitor layer; the driver layer includes a front-end driver and a back-end driver that communicate with each other, and a client is established in the virtual machine monitor layer; the VFS layer and the front-end driver are located at the guest end, the VFS layer mounts the file system of the corresponding distributed cluster of the client, and the front-end driver is used to drive the VFS layer; the back-end driver and the virtual machine monitor layer are located at the host end, the back-end driver is used to drive the client, the client is directly communicatively connected to the distributed cluster, and the virtual machine monitor layer shields the authentication information of the distributed cluster from the guest end; it further includes a dynamic management module located at the host end, and the dynamic management module mounts or unmounts the file system dynamically; the file system is the file system mounted by the VFS layer according to the mount point reported by the virtual machine monitor layer; the dynamic management module is used for: when dynamically mounting the file system, triggering the client to access the distributed cluster, enabling the back-end driver to initiate a registration interrupt of the mount point, and completing the dynamic mounting of the file system; when dynamically unmounting the file system, triggering the client to close the communication connection with the distributed cluster, enabling the back-end driver to initiate a release interrupt of the mount point, and completing the dynamic unmounting of the file system.

2. The system according to claim 1, characterized in that, the distributed cluster is a Ceph cluster, the client is a Cephfs client, the back-end driver is a virtio-cephfs back-end driver, the front-end driver is a virtio-cephfs front-end driver, and the file system is a Cephfs file system.

3. The system according to claim 2, characterized in that, the mount point is a CephFS file system identification label.

4. The system according to claim 1, characterized in that, the front-end driver and the back-end driver use the same shared memory.

5. A method for securely mounting a distributed file system, characterized in that, it includes: establishing a client in the virtual machine monitor at the host end, enabling the client to be directly communicatively connected to the distributed cluster; mounting the file system of the distributed cluster in the VFS layer at the guest end; establishing a communication connection between the file system and the client through the front-end driver and the back-end driver; the driver layer includes a front-end driver and a back-end driver that communicate with each other, the front-end driver is located at the guest end, and the front-end driver is used to drive the VFS layer; the back-end driver is located at the host end, and the back-end driver is used to drive the client, and the virtual machine monitor layer shields the authentication information of the distributed cluster from the guest; it further includes: dynamically mounting or unmounting the file system through the dynamic management module; the file system is the file system mounted by the VFS layer according to the mount point reported by the virtual machine monitor layer; the dynamic management module is used for: When the file system is dynamically mounted, it triggers the client to access the distributed cluster, enables the backend driver to initiate a registration interruption of the mount point, and completes the dynamic mounting of the file system; When the file system is dynamically unmounted, it triggers the client to close the communication connection with the distributed cluster, enables the backend driver to initiate a release interruption of the mount point, and completes the dynamic unmounting of the file system.

Citation Information

Patent Citations

  • Shared access system and method for remotely mounting local disk into cloud desktop virtual machine

    CN111782318A