A storage method, system, device and readable storage medium

By setting namespaces for different tenants and binding them to storage pool groups in the storage system, and using file metadata for data writing and reading, the problem of data isolation in a multi-tenant environment is solved, achieving the effect of physical isolation and clear data ownership.

CN120724496BActive Publication Date: 2025-12-05JINAN INSPUR DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511172594.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-12-05
Estimated Expiration
2045-08-21

AI Technical Summary

Technical Problem

Traditional data storage methods cannot provide sufficient security and performance in a multi-tenant environment, and existing technologies mainly rely on logical isolation, which cannot meet the data isolation requirements.

Method used

In the storage system, different namespaces are set up for different tenants and uniquely bound to storage pool groups. The target storage pool is determined by the storage pool group information of the namespace to achieve physical isolation, and data is written and read using file metadata.

Benefits of technology

It achieves physical isolation of data for different tenants, ensures clear data ownership, facilitates data access, and improves data security and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120724496B_ABST
    Figure CN120724496B_ABST
Patent Text Reader

Abstract

The application discloses a storage method, a storage system, a storage device and a readable storage medium in the technical field of storage, and supports a storage system supporting multiple tenants to receive a file creation request sent by a client and determine a namespace corresponding to a tenant to which the client belongs; wherein different tenants correspond to different namespaces in the storage system; target storage pools are determined from a storage pool group corresponding to the namespace by using storage pool group information of the namespace; a target file is created in the target storage pool, and file metadata of the target file is stored; in the case that the client requests to write data to the target file, the file metadata is used to write to-be-written data into the target storage pool. The application can realize physical isolation of data of different tenants in the storage system supporting multiple tenants, and can guarantee clear data ownership and facilitate data access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of storage technology, and in particular to a storage method, system, device, and readable storage medium. Background Technology

[0002] With the rapid development of cloud computing and big data technologies, the storage and management of distributed unstructured data resources have become increasingly important. However, traditional data storage and management methods cannot meet the data security and performance requirements of multi-tenant environments. Specifically, current data isolation methods mainly rely on logical isolation, which cannot provide sufficient security and performance.

[0003] In conclusion, how to effectively solve the problems of data isolation in storage systems is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] The purpose of this invention is to provide a storage method, system, device, and readable storage medium to achieve physically isolated data in a multi-tenant storage system.

[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution.

[0006] A storage method, applied to a multi-tenant storage system, includes:

[0007] The system receives a file creation request from a client and determines the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces.

[0008] Using the storage pool group information of the namespace, the target storage pool is determined from the storage pool group corresponding to the namespace; wherein, a storage pool belongs to only one storage pool group;

[0009] Create a target file in the target storage pool and store the file metadata of the target file;

[0010] When the client requests to write data to the target file, the data to be written is written to the target storage pool using the file metadata.

[0011] Preferably, determining the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace includes:

[0012] Determine the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different levels of popularity;

[0013] Using the storage pool group information of the namespace, the target storage pool located in the target layer is determined from the storage pool group corresponding to the namespace.

[0014] Preferably, determining the target layer corresponding to the file creation request includes:

[0015] Obtain the popularity information corresponding to the target file from the file creation request;

[0016] Using the aforementioned heat information, the target layer is determined from several heat layers corresponding to the layering strategy.

[0017] Preferably, determining the target storage pool located in the target hierarchy from the storage pool group corresponding to the namespace includes:

[0018] Determine whether there is a candidate storage pool located in the target tier within the storage pool group;

[0019] If so, the target storage pool is determined from the candidate storage pools;

[0020] If not, the target storage pool is determined from the candidate storage pools located in the default tier within the storage pool group.

[0021] Preferably, the process of dividing storage into tiers includes:

[0022] In response to the layering request from the management interface, determine the storage layer corresponding to different levels of popularity;

[0023] Establish the binding relationship between storage pools and storage tiers, and record the binding relationship information.

[0024] Preferably, in response to a tiering request from the management interface, the storage tiers corresponding to different levels of popularity are determined, including:

[0025] In response to the layering request, obtain the layering strategy;

[0026] The hot layer, warm layer, and cold layer are divided according to the layering strategy described above.

[0027] Preferably, the process of creating the storage pool group includes:

[0028] In response to a storage pool group creation request from the management interface, determine a unique storage pool group name for the system;

[0029] Select a storage pool from the ungrouped storage pools and add the selected storage pool as a member of the storage pool group;

[0030] Write the storage pool group information of the newly created storage pool group into the database.

[0031] Preferably, the process of creating the namespace includes:

[0032] In response to a command space creation request from the management interface, create a namespace;

[0033] The newly created command space is bound to an unbound storage pool group, and the binding information is recorded in the database.

[0034] Preferably, writing the data to be written to the target storage pool using the file metadata includes:

[0035] The target storage pool where the target file is located is determined using the file metadata;

[0036] The data to be written is written to the target storage pool.

[0037] Preferably, determining the namespace corresponding to the tenant to which the client belongs includes:

[0038] Based on the user's affiliation with the tenant, determine the target tenant to which the client belongs;

[0039] Using the mapping relationship between tenants and namespaces, query the database for the namespace corresponding to the target tenant.

[0040] Preferably, after writing the data to be written to the target storage pool using the file metadata, the method further includes:

[0041] Receive data and write traceability request;

[0042] Obtain the file metadata corresponding to the data write traceability request;

[0043] Output the file metadata.

[0044] Preferably, it further includes:

[0045] Receive the data read request sent by the client;

[0046] The specified storage pool where the data to be read is located is determined using the file metadata; wherein, the specified storage pool is located in the namespace;

[0047] Data is read from the designated storage pool and fed back to the client.

[0048] A multi-tenant storage system includes:

[0049] The namespace determination module is used to receive a file creation request sent by the client and determine the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces;

[0050] The storage pool determination module is used to determine the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace;

[0051] The file creation module is used to create target files in the target storage pool and store the file metadata of the target files;

[0052] The data writing module is used to write the data to be written to the target storage pool using the file metadata when the client requests to write data to the target file.

[0053] An electronic device, comprising:

[0054] Memory, used to store computer programs;

[0055] A processor is used to implement the above-described storage method when executing the computer program.

[0056] A readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the above-described storage method.

[0057] In a multi-tenant storage system, the method provided in this embodiment of the invention is applied to receive a file creation request sent by a client and determine the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces; using the storage pool group information of the namespace, a target storage pool is determined from the storage pool group corresponding to the namespace; a target file is created in the target storage pool and the file metadata of the target file is stored; when the client requests to write data to the target file, the data to be written is written to the target storage pool using the file metadata.

[0058] In this invention, to achieve data isolation, different namespaces are set up for different tenants in the storage system, and each namespace is uniquely bound to a storage pool group. When a client initiates a file creation request, the namespace corresponding to the client's tenant is first determined. Then, using the storage pool group information corresponding to that namespace, the target storage pool is identified from the storage pools corresponding to that namespace, and the target file is created in that target storage pool, saving the file metadata of the target file. Thus, when a client requests to write data to the target file, the data to be written can be written to the target storage pool using the file metadata. Since different storage pools are physically isolated from each other, and namespaces correspond to different storage pool groups, and a storage pool belongs to only one storage pool group, creating a file restricts users to selecting a pool from the storage pool group bound to their namespace, thereby achieving physical data isolation between different tenants. Furthermore, by controlling storage paths in conjunction with file metadata, clear data ownership can also be ensured.

[0059] In other words, the present invention can physically isolate the data of different tenants in a multi-tenant storage system, and can also ensure clear data ownership and facilitate data access.

[0060] Accordingly, embodiments of the present invention also provide a multi-tenant supporting storage system, device, and readable storage medium corresponding to the above-described storage method, which have the above-described technical effects, and will not be elaborated further here. Attached Figure Description

[0061] To more clearly illustrate the technical solutions in the embodiments of the present invention or related technologies, the drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0062] Figure 1 This is a flowchart illustrating an implementation of a storage method according to an embodiment of the present invention;

[0063] Figure 2 This is a schematic diagram illustrating the creation of a storage pool group in an embodiment of the present invention;

[0064] Figure 3 This is a schematic diagram of a storage pool group in an embodiment of the present invention;

[0065] Figure 4 This is a schematic diagram of a file creation process in an embodiment of the present invention;

[0066] Figure 5 This is a schematic diagram of the structure of a multi-tenant storage system according to an embodiment of the present invention;

[0067] Figure 6 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention;

[0068] Figure 7 This is a schematic diagram of the specific structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0069] To enable those skilled in the art to better understand the present invention, the invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0070] Please refer to Figure 1 , Figure 1 This is a flowchart of a storage method according to an embodiment of the present invention, which can be applied to a storage system that supports multi-tenancy.

[0071] This storage system can specifically be a system with a multi-tenant architecture. Multi-tenant architecture is a software architecture design that allows multiple users (tenants) to share the same set of software instances and infrastructure resources. Each tenant uses the system as if it were an independent system, but in reality, they share the same underlying resources. This architecture is widely used in cloud computing environments; for example, SaaS (Software as a Service) cloud applications typically employ multi-tenant architecture to provide services to multiple enterprises.

[0072] In this embodiment, the storage system can be divided into storage pool groups, and each storage pool group can be bound to a uniquely defined namespace. A namespace refers to a file system, corresponding to a bucket in an object protocol. Different tenants are associated with different namespaces, thereby achieving physical data isolation between different tenants.

[0073] The method includes the following steps.

[0074] S101. Receive the file creation request sent by the client and determine the namespace corresponding to the tenant to which the client belongs.

[0075] In the storage system, different tenants correspond to different namespaces.

[0076] The client can be any user belonging to any tenant within a multi-tenant environment supported by the storage system. This embodiment does not specifically limit which service or business this client corresponds to.

[0077] After receiving a file creation request from a client, you can first determine the command space corresponding to the tenant to which the client belongs.

[0078] It should be noted that in this invention, different tenants correspond to different namespaces, and there are several users under one tenant, with each user belonging to a specific tenant. Therefore, upon receiving a file creation request, the tenant to which the client belongs, and the tenant's namespace, can be uniquely identified.

[0079] In one specific embodiment of this invention, determining the namespace corresponding to the tenant to which the client belongs includes: determining the target tenant to which the client belongs based on the user's affiliation with the tenant; and querying the namespace corresponding to the target tenant from the database using the mapping relationship between tenants and namespaces. Since there is an affiliation relationship between users and tenants, the target tenant to which the client belongs can be determined first. Because there is a mapping relationship between tenants and namespaces, the namespace corresponding to the target tenant can be queried from the database. Thus, since the client and the user are corresponding, a unique namespace can be assigned to the client.

[0080] S102. Using the storage pool group information of the namespace, determine the target storage pool from the storage pool group corresponding to the namespace.

[0081] Each storage pool belongs to only one storage pool group.

[0082] Each tenant corresponds one-to-one with a namespace, and each namespace domain storage pool group corresponds one-to-one with another. Each storage pool uniquely belongs to one storage pool group. In other words, for each tenant, the corresponding storage space is a fixed number of storage pools.

[0083] After a namespace is created, its storage pool group information can be used to identify the corresponding storage pool group and the storage pools that make up that group. Therefore, based on the storage pool group information, the target storage pool can be determined from the storage pool group corresponding to the namespace.

[0084] That is, the selection pool for file creation is strictly controlled within the command space, and physical isolation between different tenants is achieved based on the storage pool.

[0085] In one specific embodiment of this invention, the process of creating a storage pool group includes: responding to a storage pool group creation request from the management interface, determining a unique storage pool group name for the system; selecting a storage pool from ungrouped storage pools and adding the selected storage pool as a member of the storage pool group; and writing the storage pool group information of the newly created storage pool group into a database. In this embodiment, a storage pool group creation interface can be provided in the management interface of the storage system. In response to a storage pool group creation request from this management interface, a storage pool group can be created, such as determining a unique storage pool group name for the system and selecting a storage pool from ungrouped storage pools, thereby adding the selected storage pool as a member of the current storage pool group. For example, if a technician makes a storage pool group creation request in the management interface, in response to this request, the name of the requested storage pool group can be determined. Then, ungrouped storage pools are output in the management interface for the technician to select. The multiple storage pools selected by the technician are then added as members of the currently created storage pool group, and the storage pool group information is written into the database, thus completing the creation of the storage pool group.

[0086] In one specific embodiment of this invention, when creating storage pool groups, multiple storage pool groups of different specifications are created. When creating namespaces, a suitable target storage pool group is selected from the multiple different storage pool groups and bound to it according to the business requirements corresponding to the namespace. This allows the storage pool group to better adapt to the business requirements corresponding to the bound namespace, that is, different tenants can be supported with different services within a single storage system. For example, when creating storage pool groups, storage pool groups with different numbers of storage pools can be created, such as some storage pool groups having only one storage pool, while others have multiple storage pools with different storage media, in order to store data with varying frequency.

[0087] S103. Create the target file in the target storage pool and store the target file's file metadata.

[0088] Once the target storage pool is identified, the target file can be created within that pool. In other words, the physical address of the target file corresponds to the target storage pool within the corresponding storage pool group under the namespace.

[0089] To facilitate subsequent tracking and storage path management, the target file's metadata is stored after the target file is created. This metadata can include data describing the file's basic information, attributes, status, and context. Although file metadata does not contain the actual content of the file, it is crucial for the file's management, retrieval, use, and maintenance.

[0090] For example, component metadata can include basic identification information (fundamental attributes used to uniquely identify files), such as filename (a user-assigned identifier, which may include an extension (to indicate the file format)), file path (the file's location in the storage system), and file unique identifier (a unique identifier assigned internally by the system, used for underlying indexing and management, unaffected by changes in filename or path); storage and system attributes (describing the file's physical characteristics and system status on the storage medium), such as file size (actual size, disk space occupied), storage location (partition, disk, storage device identifier (e.g., hard drive serial number, cloud storage bucket name)), file type (e.g., text, image, video, executable file), specific format (e.g., .txt, .jpg, .mp4, .exe, identified by extension or file header information), file attributes (operating system-marked status (e.g., read-only, hidden, system file, archive file, etc.)); and time-related information (recording key time points in the file's lifecycle), such as creation time (the time the file was created (accurate to the second or millisecond)) and modification time (…). Time (the last time the file content was modified (updated when the content changes)), Access Time (the last time the file was read or accessed), Change Time; Permissions and security information (data related to controlling file access permissions), such as Owner, Permissions, encryption status, digital signature information (such as signature data used to verify file integrity and origin); Content descriptive metadata is information used to describe the file content (varies depending on the file type), etc.

[0091] In this embodiment, file metadata can be stored in a database for access.

[0092] S104. When a client requests to write data to a target file, the data to be written is written to the target storage pool using the file metadata.

[0093] When a client requests to write data to a target file, the file's metadata can be used for addressing, and the data to be written can be written to the target storage pool. Specifically, in practical applications, users can transfer the data to be written when creating the file and write the data immediately after the target file is created, or they can write the data gradually later according to actual usage needs after the file is created.

[0094] As can be seen, when the client writes data, the data is written to the corresponding storage pool, which avoids data interference between different tenants and achieves physical isolation.

[0095] In one specific embodiment of this invention, writing data to be written to a target storage pool using file metadata includes: determining the target storage pool where the target file is located using file metadata; and writing the data to be written to the target storage pool. The file metadata records information such as the address of the target file, thus the target storage pool where the target file is located can be determined based on the file metadata. Therefore, when writing data to be written, the data can be written to the target storage pool.

[0096] In one specific embodiment of this invention, after writing the data to be written to the target storage pool using file metadata, the method further includes: receiving a data write traceability request; obtaining the file metadata corresponding to the data write traceability request; and outputting the file metadata. Since file metadata records information covering multiple dimensions from basic identification and storage status to content description and security controls, file retrieval efficiency can be improved, data security can be ensured, and more granular file lifecycle management can be supported based on this file metadata. For example, when a data write traceability request is received, data write traceability can be achieved directly by reading the corresponding file metadata and providing feedback, facilitating management.

[0097] In one specific embodiment of this invention, a data read request sent by a client can also be received; the specified storage pool where the data to be read is located can be determined using file metadata; wherein the specified storage pool is located in a namespace; data is read from the specified storage pool and fed back to the client. That is, firstly, the specified storage pool where the data to be read is located is determined based on file metadata, and this specified storage pool is located in a namespace. Then, by reading data from the specified storage pool, the data required by the client can be fed back. Since the file metadata is stored after the file creation is restricted to a namespace and a pool is selected, data reading is also restricted to the storage pool corresponding to the namespace. This ensures that users can only access / read the namespace corresponding to their tenant, achieving physical data isolation between different tenants.

[0098] In a multi-tenant storage system, the method provided in this embodiment of the invention is applied to receive a file creation request sent by a client and determine the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces; using the storage pool group information of the namespace, a target storage pool is determined from the storage pool group corresponding to the namespace; a target file is created in the target storage pool and the file metadata of the target file is stored; when the client requests to write data to the target file, the data to be written is written to the target storage pool using the file metadata.

[0099] In this invention, to achieve data isolation, different namespaces are set up for different tenants in the storage system, and each namespace is uniquely bound to a storage pool group. When a client initiates a file creation request, the namespace corresponding to the client's tenant is first determined. Then, using the storage pool group information corresponding to that namespace, the target storage pool is identified from the storage pools corresponding to that namespace, and the target file is created in that target storage pool, saving the file metadata of the target file. Thus, when a client requests to write data to the target file, the data to be written can be written to the target storage pool using the file metadata. Since different storage pools are physically isolated from each other, and namespaces correspond to different storage pool groups, and a storage pool belongs to only one storage pool group, creating a file restricts users to selecting a pool from the storage pool group bound to their namespace, thereby achieving physical data isolation between different tenants. Furthermore, by controlling storage paths in conjunction with file metadata, clear data ownership can also be ensured.

[0100] In other words, the present invention can physically isolate the data of different tenants in a multi-tenant storage system, and can also ensure clear data ownership and facilitate data access.

[0101] It should be noted that, based on the above embodiments, the present invention also provides corresponding improvements. In the preferred / improved embodiments, steps that are the same as or corresponding to those in the above embodiments can be referred to each other, and the corresponding beneficial effects can also be referred to each other; however, these will not be elaborated upon in the preferred / improved embodiments herein.

[0102] In one specific embodiment of this invention, the process of creating a namespace includes: creating a namespace in response to a namespace creation request from the management interface; establishing a binding relationship between the newly created namespace and an unbound storage pool group, and recording the binding relationship information in the database. In this embodiment, tenants correspond to namespaces, and namespaces and storage pool groups have a binding relationship. Therefore, when creating a namespace, that is, in response to a namespace creation request from the management interface, the namespace is created, and a binding relationship is established between the namespace and an unbound storage pool group. By recording the binding relationship between the namespace and the storage pool group, the creation of the namespace can be completed.

[0103] In one specific embodiment of the present invention, the storage system can be divided into storage layers with different levels of popularity so that a corresponding storage pool can be selected to create a file according to storage needs. Accordingly, the target storage pool is determined from the storage pool group corresponding to the namespace using the storage pool group information of the namespace, including: determining the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different levels of popularity; and the target storage pool located in the target layer is determined from the storage pool group corresponding to the namespace using the storage pool group information of the namespace.

[0104] In other words, during the creation of a target file, when selecting the target storage pool, the target tier corresponding to the file creation request can be determined first. For example, the storage tier of the target file to be created can be specified in the file creation request, and the target tier can be directly selected based on this request. Then, based on the storage pool group information, it is first determined which storage pools are in the storage pool group corresponding to the namespace, and which storage pools are located in the target tier, and the target storage pool is selected only from the storage pools located in the target tier.

[0105] In one specific embodiment of this invention, determining the target layer corresponding to a file creation request includes: obtaining popularity information corresponding to the target file from the file creation request; and using the popularity information to determine the target layer from several popularity layers corresponding to the tiering strategy. Since the storage system divides storage layers according to popularity, in this embodiment, the file creation request can carry popularity information corresponding to the target file to be created, such as hot, warm, or cold. Then, combining the tiering strategy and the popularity information, the target layer is determined from several popularity layers. For example, if the tiering strategy divides storage layers into three popularity layers, such as a hot layer, a warm layer, and a cold layer, and the popularity information carried in the file creation request is hot data, then the hot layer can be determined as the target layer. That is, the target storage pool is then selected from the hot layer.

[0106] In one specific embodiment of this invention, determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace includes: determining whether there is a candidate storage pool located in the target layer in the storage pool group; if so, determining the target storage pool from the candidate storage pools; if not, determining the target storage pool from the candidate storage pools located in the default layer within the storage pool group. In this embodiment, during the process of determining the target storage pool, it can be first determined whether there is a candidate storage pool located in the target layer in the storage pool group bound to the namespace of the corresponding tenant. If so, the target storage pool can be directly determined from the candidate storage pools in the target layer; if there is no candidate storage pool located in the target layer in the storage pool group, the target storage pool can be determined from the candidate storage pools located in the default layer within the storage pool group. That is, if the storage pool group has a target layer, the target storage pool is directly selected within the target layer; if the storage pool group does not have a target layer, the target storage pool can be selected within the default layer, thereby ensuring the fault tolerance and standardization of the pool selection process.

[0107] In one specific embodiment of this invention, the process of dividing storage into tiers includes: responding to a tiering request from the management interface, determining storage tiers corresponding to different levels of popularity; establishing a binding relationship between storage pools and storage tiers, and recording the binding relationship information. In this embodiment, storage tiers corresponding to different levels of popularity can be determined through a tiering request from the management interface, then a binding relationship can be established between storage pools and storage tiers, and the binding relationship information can be recorded. In this way, storage tiering can be completed.

[0108] In one specific embodiment of the present invention, in response to a tiering request from the management interface, determining storage tiers corresponding to different levels of popularity includes: in response to the tiering request, obtaining a tiering strategy; and dividing the storage into hot, warm, and cold tiers according to the tiering strategy. That is, the tiering strategy can be transmitted through the tiering request, and then the storage tiers can be divided into hot, warm, and cold tiers based on the tiering strategy, so as to select the target storage pool where the target file is located according to different levels of popularity.

[0109] In one specific embodiment of this invention, in response to a storage pool group creation request from the management interface, a unique storage pool group name is determined; ungrouped storage pools are selected from several storage tiers, and the selected storage pools are added as members of the current storage pool group; the default tier for the current storage pool group is determined, and the storage pool group information of the currently created storage pool group is written to the database. That is, when creating a storage pool group, if the storage system is divided into different storage tiers, when selecting storage pools for the storage pool group, ungrouped storage pools can be selected from different storage tiers according to requirements, and a default storage tier can be set to ensure the fault tolerance and standardization of the pool selection process. Writing the storage pool group information to the database confirms the completion of storage pool group creation. The storage pool group information may include the name of the storage pool group, the identifiers of the storage pools within the storage pool group, and the correspondence between storage pools and storage tiers.

[0110] To help those skilled in the art better understand and implement the storage method provided in the embodiments of the present invention, the following describes in detail how to achieve physical isolation for multiple tenants, taking an application to a distributed file storage system as an example.

[0111] In a distributed file storage system, specifically for a distributed unstructured multi-tenant storage system, the storage method provided in this embodiment of the invention is based on the physical isolation of distributed unstructured multi-tenant data resources.

[0112] First, a tiered storage architecture can be adopted, vertically dividing storage pool groups and establishing a globally unique default tier as a fundamental guarantee. Pool selection strategies are customized for each tier, with a single storage pool group supporting up to 16 storage pools, enabling flexible planning of storage resources. Then, a unique storage pool group name is configured, allowing for flexible selection of storage pools across tiers within the group, breaking tier boundary limitations and adapting to diverse data storage needs. When creating a namespace, the storage pool group is bound, leveraging physical isolation mechanisms to ensure that different tenants' or business data do not interfere with each other from the underlying architecture, building a robust data security defense. When writing file data under a namespace, pool selection is strictly limited to the bound storage pool group. Through storage path control, clear data ownership is ensured while optimizing read / write performance using tiered features. Furthermore, when creating a file, the target tier can be selected first according to the tiered strategy, and then verified by associating the namespace with the storage pool group information: if the tier exists within the group, it is used directly; otherwise, it automatically falls back to the default tier, ensuring the fault tolerance and standardization of the pool selection process. Within the selected tier, storage pools are matched according to the tier selection pool strategy. The mapping relationship between file metadata and storage pools is persisted to disk. Subsequent data writing is precisely directed to the storage pool, realizing full traceability and controllability of data storage. From architecture design to execution chain, data security and performance standards are guaranteed.

[0113] For details, please refer to Figure 2The management interface begins creating a storage pool group. Set the storage pool group name, which must be unique system-wide. Select storage pools from the hot, warm, and cold tiers, up to 16 in total. Set the default tier for the storage pool group; the default tier must be unique. Storage pool group information is written to the database. The created storage pool group looks like this. Figure 3 As shown. In Figure 3 The system has namespaces A and B, where namespace A is bound to storage pool group A, and namespace B is bound to storage pool group B. The storage system is divided into hot, warm, and cold layers.

[0114] For storage pool group A, its default layer is the hot layer. Its storage pool members include hot storage pool 1 (hot_pool1) and hot storage pool 2 (hot_pool2) located in the hot layer, warm storage pool 1 (warm_pool1) and warm storage pool 2 (warm_pool2) located in the warm layer, and cold storage pool 1 (cold_pool1) and cold storage pool 2 (cold_pool2) located in the cold layer.

[0115] For storage pool group B, its default layer is the cold layer. Its storage pool members include hot storage pool 3 and hot storage pool 4 located in the hot layer, warm storage pool 3 and warm storage pool 4 located in the warm layer, and cold storage pool 3 and cold storage pool 4 located in the cold layer.

[0116] Regarding namespace creation, it can be initiated through the management interface, where namespaces can be bound to storage pool groups, and the binding relationship between storage pool groups and namespaces can be persisted. For example... Figure 3 As shown, namespace A is bound to storage pool group A.

[0117] like Figure 4 As shown, the process involves: creating a file; determining the tier based on hierarchical strategies; retrieving storage pool group information based on namespaces; checking if the storage pool group contains the tier defined by the strategy; if not, selecting the default tier within the storage pool group and choosing a storage pool from among the default tiers; if it does contain the tier, selecting a storage pool from among the determined tiers. Specifically, the storage pool can be determined based on a pre-set tier selection strategy, such as random selection, or by matching the required file size with the remaining storage pool capacity. After determining the storage pool, the file metadata is persisted. Subsequent file data writing is based on the file metadata and written to the selected storage pool.

[0118] In distributed file storage systems, specifically for distributed unstructured multi-tenant storage systems, the method provided in this invention can achieve physical or logical isolation of tenant data through namespace-level data isolation and a hierarchical storage pool binding mechanism, flexibly meeting the diverse data security and performance needs of different customers. That is, physical data isolation and performance optimization are achieved through hierarchical storage and storage pool groups. Hierarchical storage enables categorized data storage, while storage pool groups achieve both physical data isolation and performance optimization.

[0119] Corresponding to the above method embodiments, this invention also provides a storage system that supports multi-tenancy. The storage system that supports multi-tenancy described below can be referred to in correspondence with the storage method described above.

[0120] See Figure 5 As shown, the multi-tenant storage system includes the following modules.

[0121] The namespace determination module 101 is used to receive a file creation request sent by the client and determine the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces;

[0122] The storage pool determination module 102 is used to determine the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace;

[0123] The file creation module 103 is used to create target files in the target storage pool and store the file metadata of the target files;

[0124] The data writing module 104 is used to write the data to be written to the target storage pool using file metadata when the client requests to write data to the target file.

[0125] The multi-tenant storage system provided in this embodiment of the invention receives a file creation request sent by a client and determines the namespace corresponding to the tenant to which the client belongs; wherein, different tenants correspond to different namespaces in the storage system; using the storage pool group information of the namespace, the target storage pool is determined from the storage pool group corresponding to the namespace; a target file is created in the target storage pool and the file metadata of the target file is stored; when the client requests to write data to the target file, the data to be written is written to the target storage pool using the file metadata.

[0126] In this invention, to achieve data isolation, different namespaces are set up for different tenants in the storage system, and each namespace is uniquely bound to a storage pool group. When a client initiates a file creation request, the namespace corresponding to the client's tenant is first determined. Then, using the storage pool group information corresponding to that namespace, the target storage pool is identified from the storage pools corresponding to that namespace, and the target file is created in that target storage pool, saving the file metadata of the target file. Thus, when a client requests to write data to the target file, the data to be written can be written to the target storage pool using the file metadata. Since different storage pools are physically isolated from each other, and namespaces correspond to different storage pool groups, and a storage pool belongs to only one storage pool group, creating a file restricts users to selecting a pool from the storage pool group bound to their namespace, thereby achieving physical data isolation between different tenants. Furthermore, by controlling storage paths in conjunction with file metadata, clear data ownership can also be ensured.

[0127] In other words, the present invention can physically isolate the data of different tenants in a multi-tenant storage system, and can also ensure clear data ownership and facilitate data access.

[0128] In one specific embodiment of the present invention, the storage pool determination module determines the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different popularity; using the storage pool group information of the namespace, the target storage pool located in the target layer is determined from the storage pool group corresponding to the namespace.

[0129] In one specific embodiment of the present invention, the storage pool determination module is specifically used to obtain the popularity information corresponding to the target file from the file creation request; and to determine the target layer from several popularity layers corresponding to the layering strategy using the popularity information.

[0130] In one specific embodiment of the present invention, the storage pool determination module is specifically used to determine whether there is a candidate storage pool located in the target layer in the storage pool group; if so, the target storage pool is determined from the candidate storage pool; if not, the target storage pool is determined from the candidate storage pool located in the default layer in the storage pool group.

[0131] In one specific embodiment of the present invention, a storage tiering module is further included, which is used to divide the storage tiers process, including: responding to the tiering request of the management interface, determining the storage tiers corresponding to different popularity; establishing the binding relationship between the storage pool and the storage tier, and recording the binding relationship information.

[0132] In one specific embodiment of the present invention, a storage layering module is specifically used to respond to a layering request, obtain a layering strategy, and divide the layer into a hot layer, a warm layer, and a cold layer according to the layering strategy.

[0133] In one specific embodiment of the present invention, a storage pool group creation module is further included, which is used to implement the process of creating a storage pool group, including: responding to a storage pool group creation request from the management interface, determining a unique storage pool group name in the system; selecting a storage pool from ungrouped storage pools and adding the selected storage pool as a member of the storage pool group; and writing the storage pool group information of the newly created storage pool group into the database.

[0134] In one specific embodiment of the present invention, a namespace creation module is further included, which is used to implement the process of creating a namespace, including: creating a namespace in response to a command space creation request from the management interface; establishing a binding relationship between the newly created commandspace and an unbound storage pool group, and recording the binding relationship information in the database.

[0135] In one specific embodiment of the present invention, the data writing module is specifically used to determine the target storage pool where the target file is located using file metadata; and to write the data to be written into the target storage pool.

[0136] In one specific embodiment of the present invention, the namespace determination module is specifically used to determine the target tenant to which the client belongs based on the user's affiliation with the tenant; and to query the namespace corresponding to the target tenant from the database using the mapping relationship between the tenant and the namespace.

[0137] In one specific embodiment of the present invention, a storage traceability module is further included, which is used to receive a data write traceability request after writing the data to be written to the target storage pool using file metadata; obtain the file metadata corresponding to the data write traceability request; and output the file metadata.

[0138] In one specific embodiment of the present invention, it further includes: a data reading module, used to receive a data reading request sent by the client; determine the specified storage pool where the data to be read is located using file metadata; wherein the specified storage pool is located in a namespace; read data from the specified storage pool and feed it back to the client.

[0139] Corresponding to the above method embodiments, this invention also provides an electronic device. The electronic device described below and the storage method described above can be referred to in correspondence.

[0140] See Figure 6 As shown, the electronic device includes:

[0141] Memory 332 is used to store computer programs;

[0142] The processor 322 is used to implement the storage method steps of the above method embodiments when executing a computer program.

[0143] For details, please refer to Figure 7 , Figure 7 This is a schematic diagram of the specific structure of an electronic device provided in this embodiment. The electronic device can vary significantly due to differences in configuration or performance. It may include one or more central processing units (CPUs) (e.g., one or more processors) and a memory 332. The memory 332 stores one or more computer programs 342 or data 344. The memory 332 can be temporary or permanent storage. The program stored in the memory 332 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the data processing device. Furthermore, the processor 322 may be configured to communicate with the memory 332 and execute the series of instruction operations stored in the memory 332 on the electronic device 301.

[0144] Electronic device 301 may also include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341.

[0145] The steps in the storage method described above can be implemented by the structure of an electronic device.

[0146] That is, the electronic device can achieve the following: receiving a file creation request sent by a client and determining the namespace corresponding to the client's tenant; wherein, different tenants correspond to different namespaces in the storage system; using the storage pool group information of the namespace, determining the target storage pool from the storage pool group corresponding to the namespace; wherein, a storage pool belongs to only one storage pool group; creating a target file in the target storage pool and storing the file metadata of the target file; and when the client requests to write data to the target file, using the file metadata to write the data to be written to the target storage pool.

[0147] In one specific embodiment of the present invention, determining a target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace includes: determining the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different levels of popularity; and determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace using the storage pool group information of the namespace.

[0148] In one specific embodiment of the present invention, determining the target layer corresponding to a file creation request includes: obtaining popularity information corresponding to the target file from the file creation request; and using the popularity information to determine the target layer from several popularity layers corresponding to the layering strategy.

[0149] In one specific embodiment of the present invention, determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace includes: determining whether there is a candidate storage pool located in the target layer in the storage pool group; if so, determining the target storage pool from the candidate storage pool; if not, determining the target storage pool from the candidate storage pool located in the default layer within the storage pool group.

[0150] In one specific embodiment of the present invention, the process of dividing storage into layers includes: responding to a layering request from the management interface, determining storage layers corresponding to different levels of popularity; establishing a binding relationship between storage pools and storage layers, and recording the binding relationship information.

[0151] In one specific embodiment of the present invention, in response to a layering request from the management interface, determining storage layers corresponding to different levels of heat includes: in response to a layering request, obtaining a layering strategy; and dividing the storage into hot, warm, and cold layers according to the layering strategy.

[0152] In one specific embodiment of the present invention, the process of creating a storage pool group includes: responding to a storage pool group creation request in the management interface, determining a unique storage pool group name in the system; selecting a storage pool from ungrouped storage pools and adding the selected storage pool as a member of the storage pool group; and writing the storage pool group information of the newly created storage pool group into the database.

[0153] In one specific embodiment of the present invention, the process of creating a namespace includes: creating a namespace in response to a command space creation request from the management interface; establishing a binding relationship between the newly created commandspace and an unbound storage pool group, and recording the binding relationship information in the database.

[0154] In one specific embodiment of the present invention, writing data to be written to a target storage pool using file metadata includes: determining the target storage pool where the target file is located using file metadata; and writing the data to be written to the target storage pool.

[0155] In one specific embodiment of the present invention, determining the namespace corresponding to the tenant to which the client belongs includes: determining the target tenant to which the client belongs based on the user's affiliation with the tenant; and querying the namespace corresponding to the target tenant from the database using the mapping relationship between tenants and namespaces. In another specific embodiment of the present invention, after writing the data to be written to the target storage pool using file metadata, the method further includes: receiving a data write traceability request; obtaining the file metadata corresponding to the data write traceability request; and outputting the file metadata.

[0156] In one specific embodiment of the present invention, the method further includes: receiving a data read request sent by a client; determining the specified storage pool where the data to be read is located using file metadata; wherein the specified storage pool is located in a namespace; reading the data from the specified storage pool and feeding it back to the client.

[0157] Corresponding to the above method embodiments, this invention also provides a readable storage medium. The readable storage medium described below corresponds to and can be referred to in relation to the storage method described above.

[0158] A readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the storage method described in the above method embodiments.

[0159] The readable storage medium can specifically be a USB flash drive, external hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, or any other readable storage medium capable of storing program code.

[0160] That is, when the computer program stored in the readable storage medium is executed, it can: receive a file creation request sent by a client and determine the namespace corresponding to the client's tenant; wherein, different tenants correspond to different namespaces in the storage system; determine the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace; wherein, a storage pool belongs to only one storage pool group; create a target file in the target storage pool and store the file metadata of the target file; and write the data to be written to the target storage pool using the file metadata when the client requests to write data to the target file.

[0161] In one specific embodiment of the present invention, determining a target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace includes: determining the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different levels of popularity; and determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace using the storage pool group information of the namespace.

[0162] In one specific embodiment of the present invention, determining the target layer corresponding to a file creation request includes: obtaining popularity information corresponding to the target file from the file creation request; and using the popularity information to determine the target layer from several popularity layers corresponding to the layering strategy.

[0163] In one specific embodiment of the present invention, determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace includes: determining whether there is a candidate storage pool located in the target layer in the storage pool group; if so, determining the target storage pool from the candidate storage pool; if not, determining the target storage pool from the candidate storage pool located in the default layer within the storage pool group.

[0164] In one specific embodiment of the present invention, the process of dividing storage into layers includes: responding to a layering request from the management interface, determining storage layers corresponding to different levels of popularity; establishing a binding relationship between storage pools and storage layers, and recording the binding relationship information.

[0165] In one specific embodiment of the present invention, in response to a layering request from the management interface, determining storage layers corresponding to different levels of heat includes: in response to a layering request, obtaining a layering strategy; and dividing the storage into hot, warm, and cold layers according to the layering strategy.

[0166] In one specific embodiment of the present invention, the process of creating a storage pool group includes: responding to a storage pool group creation request in the management interface, determining a unique storage pool group name in the system; selecting a storage pool from ungrouped storage pools and adding the selected storage pool as a member of the storage pool group; and writing the storage pool group information of the newly created storage pool group into the database.

[0167] In one specific embodiment of the present invention, the process of creating a namespace includes: creating a namespace in response to a command space creation request from the management interface; establishing a binding relationship between the newly created commandspace and an unbound storage pool group, and recording the binding relationship information in the database.

[0168] In one specific embodiment of the present invention, writing data to be written to a target storage pool using file metadata includes: determining the target storage pool where the target file is located using file metadata; and writing the data to be written to the target storage pool.

[0169] In one specific embodiment of the present invention, determining the namespace corresponding to the tenant to which the client belongs includes: determining the target tenant to which the client belongs based on the user's affiliation with the tenant; and querying the namespace corresponding to the target tenant from the database using the mapping relationship between tenants and namespaces. In another specific embodiment of the present invention, after writing the data to be written to the target storage pool using file metadata, the method further includes: receiving a data write traceability request; obtaining the file metadata corresponding to the data write traceability request; and outputting the file metadata.

[0170] In one specific embodiment of the present invention, the method further includes: receiving a data read request sent by a client; determining the specified storage pool where the data to be read is located using file metadata; wherein the specified storage pool is located in a namespace; reading the data from the specified storage pool and feeding it back to the client.

[0171] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple; relevant parts can be referred to the method section.

[0172] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.

[0173] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0174] Finally, it should be noted that in this document, relationships such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "include," "contain," or any other variations are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.

[0175] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A storage method, characterized in that, Applications include storage systems that support multi-tenancy, including: The system receives a file creation request from a client and determines the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces; the client is the client used by any user corresponding to any tenant under the multi-tenancy supported by the storage system; Using the storage pool group information of the namespace, the target storage pool is determined from the storage pool group corresponding to the namespace; wherein, a storage pool belongs to only one storage pool group; Create a target file in the target storage pool and store the file metadata of the target file; When the client requests to write data to the target file, the data to be written is written to the target storage pool using the file metadata; Specifically, determining the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace includes: Determine the target layer corresponding to the file creation request; wherein, the storage system has storage layers with different levels of popularity; Using the storage pool group information of the namespace, determine the target storage pool located in the target layer from the storage pool group corresponding to the namespace; The process of determining the target storage pool located in the target hierarchy from the storage pool group corresponding to the namespace includes: Determine whether there is a candidate storage pool located in the target tier within the storage pool group; If so, the target storage pool is determined from the candidate storage pools; If not, the target storage pool is determined from the candidate storage pools located in the default tier within the storage pool group.

2. The method according to claim 1, characterized in that, Determining the target layer corresponding to the file creation request includes: Obtain the popularity information corresponding to the target file from the file creation request; Using the aforementioned heat information, the target layer is determined from several heat layers corresponding to the layering strategy.

3. The method according to claim 1, characterized in that, The process of dividing storage into tiers includes: In response to the layering request from the management interface, determine the storage layer corresponding to different levels of popularity; Establish the binding relationship between storage pools and storage tiers, and record the binding relationship information.

4. The method according to claim 3, characterized in that, In response to tiering requests from the management interface, determine the storage tiers corresponding to different levels of activity, including: In response to the layering request, obtain the layering strategy; The hot layer, warm layer, and cold layer are divided according to the layering strategy described above.

5. The method according to claim 1, characterized in that, The process of creating the storage pool group includes: In response to a storage pool group creation request from the management interface, determine a unique storage pool group name for the system; Select a storage pool from the ungrouped storage pools and add the selected storage pool as a member of the storage pool group; Write the storage pool group information of the newly created storage pool group into the database.

6. The method according to claim 1, characterized in that, The process of creating the namespace includes: In response to a command space creation request from the management interface, create a namespace; The newly created command space is bound to an unbound storage pool group, and the binding information is recorded in the database.

7. The method according to claim 1, characterized in that, Using the file metadata to write the data to be written to the target storage pool includes: The target storage pool where the target file is located is determined using the file metadata; The data to be written is written to the target storage pool.

8. The method according to claim 1, characterized in that, Determining the namespace corresponding to the tenant to which the client belongs includes: Based on the user's affiliation with the tenant, determine the target tenant to which the client belongs; Using the mapping relationship between tenants and namespaces, query the database for the namespace corresponding to the target tenant.

9. The method according to claim 1, characterized in that, After writing the data to be written to the target storage pool using the file metadata, the method further includes: Receive data and write traceability request; Obtain the file metadata corresponding to the data write traceability request; Output the file metadata.

10. The method according to any one of claims 1 to 9, characterized in that, Also includes: Receive the data read request sent by the client; The specified storage pool where the data to be read is located is determined using the file metadata; wherein, the specified storage pool is located in the namespace; Data is read from the designated storage pool and fed back to the client.

11. A storage system supporting multi-tenancy, characterized in that, include: The namespace determination module is used to receive a file creation request sent by the client and determine the namespace corresponding to the tenant to which the client belongs; wherein, different tenants in the storage system correspond to different namespaces; the client is the client used by any user corresponding to any tenant under the multi-tenancy supported by the storage system; The storage pool determination module is used to determine the target storage pool from the storage pool group corresponding to the namespace using the storage pool group information of the namespace; The file creation module is used to create target files in the target storage pool and store the file metadata of the target files; The data writing module is used to write the data to be written to the target storage pool using the file metadata when the client requests to write data to the target file. The storage pool determination module is specifically used to determine the target layer corresponding to the file creation request; wherein the storage system has storage layers with different popularity; using the storage pool group information of the namespace, determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace; wherein determining the target storage pool located in the target layer from the storage pool group corresponding to the namespace includes: determining whether there is a candidate storage pool located in the target layer in the storage pool group; if so, determining the target storage pool from the candidate storage pool; if not, determining the target storage pool from the candidate storage pool located in the default layer in the storage pool group.

12. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the storage method as described in any one of claims 1 to 10 when executing the computer program.

13. A readable storage medium, characterized in that, The readable storage medium stores a computer program that, when executed by a processor, implements the steps of the storage method as described in any one of claims 1 to 10.

Citation Information

Patent Citations

  • Data processing method and device, equipment and storage medium

    CN117235009A

  • Distributed multi-tenant data security isolation system and method

    CN119402233A