Storage system and path management method

The storage system addresses performance issues in SDS by dynamically managing remote copy paths during node additions or removals, ensuring efficient remote copy operations and preventing performance degradation.

JP2025133228APending Publication Date: 2025-09-11HITACHI VANTARA LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024031047
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-01
Publication Date
2025-09-11

AI Technical Summary

Technical Problem

Existing storage systems with Software Defined Storage (SDS) face performance degradation during scale-out or scale-in operations due to the lack of clear methods for resetting remote copy paths when storage nodes are added or removed, as described in Patent Document 1.

Method used

A storage system and path management method that involves establishing a new remote copy path and deleting the original path when storage nodes are added or removed, using a first management device to collect information and manage the creation or deletion of paths between storage nodes, ensuring seamless remote copy operations.

Benefits of technology

Prevents performance degradation in remote copy processing by efficiently managing remote copy paths during storage node additions or removals, maintaining system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025133228000001_ABST
    Figure 2025133228000001_ABST
Patent Text Reader

Abstract

To provide a storage system and a method for managing a path, which can prevent performance degradation of remote copy processing after increase or decrease of storage nodes.SOLUTION: A first management apparatus is provided to set a new remote copy path between a first storage node, in which a primary volume associated with a secondary volume moved due to addition or removal of a second storage node is provided, and the second storage node to which the secondary volume has been moved, and to delete an original remote copy path that has been set between the first storage node and the second storage node from which the secondary volume has been moved, when addition or removal of the second storage node is performed at a secondary site.SELECTED DRAWING: Figure 15
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a storage system and a path management method, and is suitable for application to a storage system that protects data by remote copying between multiple sites, for example. [Background technology]

[0002] 2. Description of the Related Art Conventionally, a storage system configured with a plurality of storage nodes is known, and the storage system is provided by, for example, executing predetermined software on each storage node.

[0003] Furthermore, to ensure business continuity even in the event of a disaster, remote copy technology is available for replicating storage systems between multiple geographically separated data centers. In a storage system that is configured with multiple nodes and is equipped with remote copy functionality, the site that normally processes business applications is called the primary site, and the site that takes over from the primary site when a site-wide failure occurs on the primary site and causes the storage system to stop is called the secondary site.

[0004] For example, Patent Document 1 discloses a technology for constructing a pair by selecting a storage device on the secondary site that satisfies the performance and capacity requirements of the primary site when forming a remote copy pair between the primary site and the secondary site in a configuration in which the secondary site is made up of multiple storage devices. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] US Patent Application Publication No. 2018 / 0032254 Summary of the Invention [Problem to be solved by the invention]

[0006] In storage systems that use Software Defined Storage (SDS), scaling out is achieved by adding storage nodes that implement SDS when performance or capacity becomes insufficient. To improve performance and reliability, the software that functions as the storage controller for SDS (hereafter referred to as storage control software) and the logical volumes owned by the storage control software, which were previously located on other storage nodes, are relocated to the newly added storage node (hereafter referred to as an additional storage node). The "ownership" of a logical volume refers to the right to manage that logical volume and perform I / O processing on that logical volume. Only the storage control node that owns the logical volume can perform I / O processing on that logical volume.

[0007] For this reason, when a secondary volume of a copy source logical volume (hereinafter referred to as a primary volume) and a copy destination logical volume (hereinafter referred to as a secondary volume) in a remote copy configuration is moved to an additional storage node due to scale-out at the secondary site, it is necessary to reset a path for remote copy (hereinafter referred to as a remote copy path) between the storage node on the primary site where the primary volume is created and the additional storage node to which the secondary volume is moved, but Patent Document 1 does not disclose how to reset the remote copy path in such a situation. However, if the remote copy path is not reset in such a situation, there is a problem in that the performance of the remote copy process decreases, the specific reasons for which will be described later.

[0008] Furthermore, when scaling in a storage system that uses SDS, the storage control software that was located on the storage node being removed and the logical volumes that the storage control software owns must be relocated to other storage nodes.

[0009] For this reason, if the secondary volume of the primary and secondary volumes in a remote copy configuration is located on a removed storage node, it is necessary to reset the remote copy path between the storage node to which the secondary volume is moved and the storage node on the primary site where the primary volume corresponding to that secondary volume is created, but Patent Document 1 does not disclose how to reset the remote copy path in such a situation. Even in such a situation, if the remote copy path is not reset, there is a problem in that the performance of the remote copy process decreases.

[0010] The present invention has been made in consideration of the above points, and aims to propose a storage system and a path management method that can prevent a performance degradation in remote copy processing after adding or removing storage nodes. [Means for solving the problem]

[0011] In order to solve this problem, the present invention provides a storage system having one or more first storage nodes installed at a primary site and a plurality of second storage nodes installed at a secondary site, wherein the first storage node is provided with a primary volume provided to a higher-level device as a storage area for reading and writing data, and the second storage node is provided with a secondary volume as a storage area for backing up the data written to the corresponding primary volume, and a remote copy path is established between the first storage node and the second storage node in which the secondary volume corresponding to the primary volume installed on the first storage node is installed, for remotely copying the data written to the primary volume to the secondary volume, and a first management device is provided that, when the second storage node is added or removed at the secondary site, establishes a new remote copy path between the first storage node in which the primary volume associated with the secondary volume moved due to the addition or removal is installed and deletes the original remote copy path that was established between the second storage node and the second storage that is the source of the secondary volume moved due to the addition or removal.

[0012] Also, in the present invention, there is provided a path management method executed in a storage system having one or more first storage nodes installed at a primary site and a plurality of second storage nodes installed at a secondary site, wherein the first storage node is provided with a primary volume provided to a host device as a storage area for reading and writing data, the second storage node is provided with a secondary volume as a storage area for backing up the data written in the corresponding primary volume, and a remote copy path is set between the first storage node and the second storage node in which the secondary volume corresponding to the primary volume installed in the first storage node is provided, for remotely copying the data written in the primary volume to the secondary volume, and the storage system comprises a first management device and a storage node arranged at the primary site and configured to manage the primary volume. and a third management device that is arranged at the secondary site and manages each of the second storage nodes installed at the secondary site, wherein the system includes a first step in which the first management device collects necessary information from the second and / or third management devices when the second storage node is expanded or reduced at the secondary site, and a second step in which the first management device, based on the collected information, sets a new remote copy path between the secondary volume that has been moved due to the expansion or reduction and the first storage node in which the primary volume associated with the secondary volume is installed, and instructs the second and third management devices to delete the original remote copy path that was set between the second storage that is the source of the secondary volume that has been moved due to the expansion or reduction and the first storage node.

[0013] According to the storage system and path management method of the present invention, even after the number of second storage nodes is increased or decreased, remote copy can be performed between the second storage node to which a secondary volume that has been moved due to the increase or decrease in the number of second storage nodes is moved and the first storage node in which the primary volume associated with that secondary volume exists, via a newly created remote copy path. [Effects of the Invention]

[0014] According to the present invention, it is possible to realize a storage system and a path management method that can prevent a decrease in performance of remote copy processing after adding or removing storage nodes. [Brief explanation of the drawings]

[0015] [Figure 1] 1 is a block diagram showing a schematic overall configuration of a storage system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing the logical configuration of a storage system. [Figure 3] FIG. 10 is a block diagram showing the flow of data copying from a primary volume to a secondary volume. [Figure 4] FIG. 2 is a block diagram illustrating an outline of a pair management function according to the present embodiment. [Figure 5] FIG. 2 is a block diagram illustrating an outline of a path management function according to the present embodiment. [Figure 6] FIG. 2 is a block diagram illustrating an outline of a path management function according to the present embodiment. [Figure 7] FIG. 2 is a block diagram showing various programs and tables stored in the memories of the first and second storage nodes, the primary site management device, and the secondary site management device. [Figure 8] 10 is a diagram illustrating an example of the configuration of a system configuration management table. [Figure 9] 10 is a diagram showing an example of the configuration of a storage device management table. [Figure 10] 10 is a diagram illustrating an example of the configuration of a port management table. [Figure 11] 10 is a diagram showing an example of the configuration of a volume management table. [Figure 12] 10 is a diagram showing an example of the configuration of a volume pair management table. [Figure 13] 10 is a diagram showing an example of the configuration of a path management table; [Figure 14]10 is a flowchart showing the processing steps of storage node addition processing on the secondary site management software side. [Figure 15] 10 is a flowchart showing the processing steps of a storage node addition process on the pair management software side. [Figure 16] 10 is a flowchart showing the processing steps of storage node reduction processing on the secondary site management software side. [Figure 17A] 10 is a flowchart showing the processing steps of a storage node removal process on the pair management software side. [Figure 17B] 10 is a flowchart showing the processing steps of a storage node removal process on the pair management software side. DETAILED DESCRIPTION OF THE INVENTION

[0016] An embodiment of the present invention will be described in detail below with reference to the drawings.

[0017] In the following description, an "interface apparatus" may refer to one or more communication interface devices. The one or more communication interface devices may be one or more homogeneous communication interface devices (e.g., one or more NICs (Network Interface Cards)) or two or more heterogeneous communication interface devices (e.g., a NIC and an HBA (Host Bus Adapter)).

[0018] In the following description, "memory" refers to one or more memory devices, which are an example of one or more storage devices, and may typically be a primary storage device. At least one memory device in the memory may be a volatile memory device or a non-volatile memory device.

[0019] In the following description, a "storage device" may refer to one or more persistent storage devices, which are an example of one or more storage devices. A persistent storage device may typically be a non-volatile storage device (e.g., an auxiliary storage device), and specifically may be, for example, a hard disk drive (HDD), a solid state drive (SSD), or a non-volatile memory express (NVMe) drive.

[0020] Furthermore, in the following description, a "processor" may refer to one or more processor devices. The at least one processor device may typically be a microprocessor device such as a CPU (Central Processing Unit), but may also be another type of processor device such as a GPU (Graphics Processing Unit). The at least one processor device may be a single-core or multi-core. The at least one processor device may also be a processor core. The at least one processor device may also be a processor device in a broader sense, such as a hardware circuit that performs part or all of the processing (e.g., an FPGA (Field-Programmable Gate Array), a CPLD (Complex Programmable Logic Device), or an ASIC (Application Specific Integrated Circuit)).

[0021] In the following description, information that provides an output for an input may be described using expressions such as "xxx table," but this information may be data of any structure (for example, structured data or unstructured data), or may be a neural network that generates an output for an input, or a learning model such as a genetic algorithm or random forest. Therefore, the "xxx table" may be referred to as "xxx information." In the following description, the structure of each table is an example, and one table may be divided into two or more tables, or all or part of two or more tables may be one table.

[0022] In the following description, processing may be described using a "program" as the subject. However, because a program is executed by a processor to perform a predetermined process using a storage device and / or an interface device, etc., as appropriate, the subject of the process may also be the processor (or a device such as a controller having the processor). A program may be installed in a device such as a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable (e.g., non-transitory) recording medium. In the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs.

[0023] Furthermore, in the following description, when describing elements of the same type without distinguishing between them, the common portion (the portion excluding the branch number) of the reference code including the branch number may be used, and when describing elements of the same type while distinguishing between them, the reference code including the branch number may be used. For example, when describing nodes without distinguishing between them, they may be written as "Node XX" (XX is an integer equal to or greater than 0), and when describing individual nodes while distinguishing between them, they may be written as "Node XX A" and "Node XX B". Furthermore, as another method of description when describing elements of the same type while distinguishing between them, the ID of the element (for example, an identification number) may be used. Specifically, for example, the above-mentioned "Node XX A" and "Node XX B" may be written as "Node 1" and "Node 2".

[0024] (1) Configuration of the storage system according to this embodiment 1, the reference numeral 1 denotes the storage system according to this embodiment as a whole. This storage system 1 is configured such that a primary site 2 and a secondary site 3 are connected via a first network 4 that is made up of a WAN (Wide Area Network) such as the Internet, and a pair management device 5 installed in a location other than the primary site 2 and the secondary site 3 is connected to the first network 4.

[0025] The primary site 2 is equipped with one or more host devices 10, one or more first storage nodes 11, and a primary site management device 12, which are interconnected via a second network 13 such as Ethernet.

[0026] The host device 10 is a general-purpose computer device that functions as a higher-level device for the first storage node 11. However, the host device 10 may also be a virtual computer device such as a virtual machine. The host device 10 reads and writes data from and to the first storage node 11 via the second network 13 in response to a request from a user operation or an installed application program 10A (FIG. 3).

[0027] The first storage node 11 is a server device that provides a storage area for reading and writing data to the host device 10, and is configured with a control unit 21, multiple storage devices 22, and one or more ports 23 interconnected via an internal bus 20.

[0028] The control unit 21 is configured to include one or more processors 24 and one or more memories 25. The processor 24 is a device having a function of controlling the operation of the entire first storage node 11, and is configured from a CPU (Central Processing Unit), an MPU (Micro Processing Unit), etc.

[0029] The memory 25 is composed of a volatile semiconductor memory or a nonvolatile semiconductor memory such as an SRAM (Static Random Access Memory) or a DRAM (Dynamic Random Access Memory), and is used to temporarily store various programs and necessary data. The processor 24 executes the programs stored in the memory 25, thereby executing various processes of the first storage node 11 as a whole, as described below.

[0030] The storage device 22 is configured from a large-capacity nonvolatile storage device such as an HDD, SSD, or NVMe. The storage device 22 provides a physical storage area for reading and writing data from and to the host device 10. The port 23 is interface hardware for connecting the first storage node 11 to the second network 13.

[0031] The primary site management device 12 is configured from a general-purpose computer device equipped with information processing resources such as a processor and memory. The primary site management device 12 manages each of the first storage nodes 11 arranged at the primary site 2 based on the installed primary site management software (hereinafter referred to as primary site management software) 26.

[0032] The secondary site 3 is equipped with a plurality of second storage nodes 30 and a secondary site management device 31, which are interconnected via a third network 32 such as Ethernet. The second storage node 30 is a server device that provides a storage area for backing up data written to the first storage node 11. The second storage node 30 has a similar configuration to the first storage node 11, and therefore a detailed description thereof will be omitted here.

[0033] The second storage node 30 of the secondary site 3 is managed together with one or more other second storage nodes 30 in a group called a cluster 33. The example in Fig. 1 illustrates a case where only one cluster 33 is set in the secondary site 3, but multiple clusters 33 can also be set in the secondary site 3.

[0034] The secondary site management device 31 is configured with a general-purpose computer device equipped with information processing resources such as a processor and memory. The secondary site management device 31 manages each of the second storage nodes 30 arranged at the secondary site 3 based on the secondary site management software (hereinafter referred to as secondary site management software) 34 installed on it.

[0035] The pair management device 5 is also configured from a general-purpose computer equipped with information processing resources such as a processor and memory. The pair management device 5 performs processes such as setting and deleting a remote copy path 7 (FIG. 2) between a first storage node 11 in the primary site 2 and a second storage node 30 in the secondary site 3 based on the installed pair management software (hereinafter referred to as the pair management software) 6.

[0036] Fig. 2 shows the logical configuration of the storage system 1. As shown in Fig. 2, one or more primary volumes PVOL are created in each first storage node 11 of the primary site 2 to be provided to the host device 10 (Fig. 1) as a storage area for reading and writing data. In addition, each first storage node 11 also has one or more storage control software 35 (described below) that manages these primary volumes PVOL.

[0037] On the other hand, one or more storage control software 35 is arranged in each second storage node 30 of the secondary site 3. As described above, the storage control software 35 is software that functions as a storage controller of the SDS. Each storage control software 35 is managed as one group for redundancy (hereinafter referred to as a redundancy group) together with storage control software 35 arranged in one or more other second storage nodes 30 that are different from each other.

[0038] In a redundancy group, one storage control software 35 is set to a state in which it can accept I / O (Input / Output) requests from the first storage node 11 at the primary site 2 (the active system state, hereinafter referred to as active mode), and the remaining storage control software 35 is set to a state in which it cannot accept I / O requests from the first storage node 11 (the standby system state, hereinafter referred to as standby mode).

[0039] For example, Figure 2 shows an example in which a redundancy group is formed by a storage control software 35 called "SCS#M" placed in a second storage node 30 called "Node1" and a storage control software 35 called "SCS#M" placed in a second storage node 11 called "NodeM", and one of these storage control software 35 placed in the second storage node 11 called "NodeM" is set to active mode ("Active"), and the other placed in the second storage node 11 called "Node1" is set to standby mode ("Standby").

[0040] In other drawings, each storage control software 35 labeled "SCS#X" placed on a different second storage node 30 is storage control software 35 that constitutes the same redundancy group "X," and among them, storage control software 35 labeled "Active" represents storage control software 35 in active mode, and storage control software 35 labeled "Standby" represents storage control software 35 in standby mode.

[0041] In a redundant group, if a failure occurs in the storage control software 35 in active mode or in the second storage node 30 on which that storage control software 35 is running, the state of the storage control software 35 that had been set to standby mode until then is switched to active mode. As a result, if the storage control software 35 that had been set to active mode becomes unable to operate, the I / O processing that had been executed by that storage control software 35 can be taken over by the storage control software 35 that had been set to standby mode until then (failover function).

[0042] To realize such a failover function, the storage control software 35 belonging to the same redundancy group always holds the same configuration information. The configuration information is information necessary for the storage control software 35 to execute processes related to various functions, such as mapping information that associates the storage area of ​​the secondary volume SVOL with the storage area of ​​the storage device 22 (FIG. 1), a remote copy function that copies data to a remote location synchronously or asynchronously for disaster prevention, a capacity virtualization function that virtualizes the storage capacity of each storage device 22 (FIG. 1) mounted on the second storage node 30, a hierarchical storage control function that moves frequently accessed data to a storage area with a faster response speed, a deduplication function that deletes duplicate data from stored data, a data compression function that compresses and stores data, and a snapshot function that preserves the state of data at a certain point in time.

[0043] When the configuration information of a storage control software 35 in active mode that constitutes a redundancy group is updated, the difference between the configuration information before and after the update is transferred as differential data to the other storage control software 35 that constitutes the redundancy group, and the other storage control software 35 updates the configuration information held by that storage control software 35 based on this differential data. This ensures that the configuration information held by each storage control software 35 that constitutes the redundancy group is always kept synchronized.

[0044] In this way, all storage control software 35 that make up a redundancy group always maintain the same configuration information, so that even if a failure occurs in a storage control software 35 set to active mode or in the second storage node 30 on which that storage control software 35 is located, or if that second storage node 30 is removed, the processing that had been performed by that storage control software 35 can be immediately taken over by another storage control software 35 that makes up the same redundancy group as that storage control software 35.

[0045] On the other hand, at the secondary site 3, secondary volumes SVOL are created in the second storage node 30 in correspondence with each primary volume PVOL created at the primary site 2. The secondary volumes SVOL are logical volumes for backing up data stored in the corresponding primary volumes PVOL.

[0046] Each secondary volume SVOL corresponding to one primary volume PVOL is associated with each storage control software 35 constituting the same redundancy group, and is created in the second storage node 30 in which the storage control software 35 is located.

[0047] Therefore, when a redundancy group is composed of two storage control software 35 as shown in Figure 2, two secondary volumes SVOL are created for one primary volume PVOL in different second storage nodes 30 within the secondary site 3, and these secondary volumes SVOL are each associated with the storage control software 35 that constitutes the same redundancy group.

[0048] Furthermore, a remote copy path 7 is established between the first storage node 11 of the primary site 2 in which the primary volume PVOL is provided and each second storage node 30 in which a secondary volume SVOL is created corresponding to the primary volume PVOL.

[0049] The data written to the primary volume PVOL is then transferred to the second storage node 30 via one of these remote copy paths 7, which connects the first storage node 11 on which the primary volume PVOL was created with the second storage node 30 on which the secondary volume SVOL associated with the storage control software 35 in active mode of the corresponding secondary volume SVOL was created.

[0050] Furthermore, the data transferred to the second storage node 30 is then stored in a secondary volume SVOL created in association with the primary volume PVOL in the second storage node 30 under the control of the storage control software 35 in active mode.

[0051] Furthermore, the data is transferred from the second storage node 30 in which the storage control software 35 in active mode is located to each second storage node 30 in which each storage control software 35 in standby mode that is part of the same redundancy group as the storage control software 35 is located, via the third network 32 (FIG. 1). Then, the data is also stored in the secondary volume SVOL created in correspondence with the primary volume PVOL under the control of the storage control software 35 in the second storage node 30.

[0052] In the following, the storage control software 35 in active mode will be referred to as the active storage control software 35, and the storage control software 35 in standby mode will be referred to as the standby storage control software 35. The secondary volume SVOL managed by the active storage control software 35 will be referred to as the active secondary volume SVOL, and the secondary volume SVOL managed by the standby storage control software 35 will be referred to as the standby secondary volume SVOL.

[0053] Furthermore, hereinafter, a combination of a primary volume PVOL and a secondary volume SVOL created corresponding to the primary volume PVOL will be referred to as a volume pair. When multiple secondary volumes SVOL are created for redundancy for a primary volume PVOL, each combination of the primary volume PVOL and these secondary volumes SVOL is a volume pair.

[0054] 3 shows a specific flow of remote copying of data from the primary volume PVOL to each corresponding secondary volume SVOL as described above. In the case of the storage system 1 of this embodiment, remote copying between the primary volume PVOL and the secondary volume SVOL is performed asynchronously with the timing at which the host device 10 writes data to the primary volume PVOL.

[0055] In practice, in the case of this storage system 1, a logical volume called a journal volume PJVOL is created in each first storage node 11 in which a primary volume PVOL to be backed up at the primary site 2 is created, corresponding to that primary volume PVOL. Hereinafter, this journal volume PJVOL will be referred to as the primary journal volume PJVOL. One primary journal volume PJVOL may be created for one primary volume PVOL, or one primary journal volume PJVOL may be created for multiple primary volumes PVOL.

[0056] Furthermore, in each second storage node 30 of the secondary site 3 where each secondary volume SVOL created in correspondence with the primary volume PVOL has been created, a journal volume SJVOL is created in correspondence with each of these secondary volumes SVOL. Hereinafter, this journal volume SJVOL will be referred to as a secondary journal volume SJVOL. One secondary journal volume SJVOL may be created for one secondary volume SVOL, or one for multiple secondary volumes SVOL.

[0057] The secondary journal volume SJVOL and secondary volume SVOL are created by carving out a storage area called a pool PL, which is a collection of storage areas provided by each storage device 22 mounted on the second storage node. The same is true for the primary journal volume PJVOL and primary volume PVOL.

[0058] When the host device 10 writes data ("A" and "B" in Figure 3) to the primary volume PVOL, metadata such as the location in the primary volume PVOL where the data is written, the data length of the data, and a sequence number are added to the data to generate journal data JNL, and the generated journal data JNL is written to the primary journal volume PJVOL associated with the primary volume PVOL.

[0059] In addition, the journal data JNL written to the primary journal volume PJVOL is sent to the second storage node 30 in which an active secondary volume SVOL corresponding to the primary volume PVOL has been created at a predetermined timing, for example, when the load on the first storage node 11 is low, and then stored in the secondary journal volume SJVOL created in the second storage node 30 in correspondence with the active secondary volume SVOL.

[0060] The journal data JNL stored in this secondary journal volume SJVOL is then read from that secondary journal volume SJVOL by the active storage control software 35 that has ownership of that active secondary volume SVOL. The active storage control software 35 then removes the metadata from the read journal data JNL to extract only the data written to the corresponding primary volume PVOL, and stores the extracted data in that active secondary volume SVOL.

[0061] Specifically, the active storage control software 35 obtains the position in the corresponding primary volume PVOL where the data was written, which is included in the metadata removed from the journal data JNL. The active storage control software 35 also identifies the storage device 22 that provides a storage area at that position in the active secondary volume SVOL that forms a volume pair with the primary volume PVOL, and writes the data to that storage device 22.

[0062] Furthermore, the active storage control software 35 transfers the journal data JNL stored in the secondary journal volume SJVOL to the standby storage control software 35 associated with the standby secondary volume SVOL created in correspondence with the primary volume PVOL in each second storage node 30. Then, upon receiving this journal data, the standby storage control software 35 stores the received journal data in the secondary journal volume SJVOL associated with the standby secondary volume SVOL.

[0063] In addition, the active storage control software 35 transfers the data stored in the active secondary volume SVOL (data written to the corresponding primary volume PVOL) as described above to the standby storage control software 35 associated with the standby secondary volume SVOL in each second storage node 30 where the corresponding standby secondary volume SVOL exists. At this time, the active storage control software 35 associated with the active secondary volume SVOL also notifies the location in the active secondary volume SVOL where the data has been written.

[0064] Thus, the standby storage control software 35 that receives this data stores the received data in the standby secondary volume SVOL. Specifically, the standby storage control software 35 identifies the storage device 22 that provides a storage area for the position on the standby secondary volume SVOL notified by the active storage control software 35 that is associated with the active secondary volume SVOL (the position where the data was written in the corresponding primary volume PVOL), and writes the data to that storage device 22. This makes the data redundant on the secondary site 3 side.

[0065] (2) Path management function according to this embodiment (2-1) Overview of the Path Management Function According to This Embodiment Next, we will explain the path management function of this storage system 1. When a second storage node 30 is added or removed within the secondary site 3, this path management function re-establishes a new remote copy path 7 in the second storage node 30 that is the relocation destination between the relocated storage control software 35 and the secondary volume SVOL for which the storage control software 35 has ownership, and deletes the corresponding original remote copy path 7 that was previously established in the relocation source second storage node 30.

[0066] In the following, the transfer of the storage control software 35 or the secondary volume SVOL from one second storage node 30 to another second storage node 30 will be referred to as "relocation" or "migration." In the following, "relocation" and "migration" will be used interchangeably.

[0067] For example, if a second storage node 30 called "M+1" is added to the cluster 33 (FIG. 1) of the secondary site 3 having the configuration shown in FIG. 2 as shown in FIG. 4, an active storage control software 35 ("SCS#M+1 Active" in FIG. 4) is placed in the added second storage node (additional storage node) 30.

[0068] Incidentally, if the number of storage control software 35 constituting a redundancy group in such a cluster 33 is "2" (if the redundancy level in that cluster 33 is "2"), the active storage control software 35 placed in the expanded storage node 30 and one standby storage control software 35 constituting the redundancy group must be placed in any second storage node 30 other than the expanded storage node 30 in the cluster 33.

[0069] In this case, in consideration of load balancing among the second storage nodes 30 at the secondary site 3, it is preferable that the number of storage control software 35 placed on each second storage node 30 be the same among these second storage nodes 30.

[0070] Therefore, in this embodiment, when the active storage control software 35 placed on the additional storage node 30 and one or more standby storage control software 35 that constitute the redundancy group are placed on another second storage node 30, as shown in Figure 5, the existing standby storage control software 35 placed on one of the second storage nodes 30 ("SCS#M Standby" in Figure 5), the standby secondary volume SVOL for which that standby storage control software 35 has ownership, and its configuration information are relocated to the additional storage node 30, and then the active storage control software 35 placed on the additional storage node 30 and the standby storage control software 35 that constitutes the redundancy group ("SCS#M+1 Standby" in Figure 5) are placed on that second storage node 30.

[0071] In this state, if a failure occurs in the active storage control software 35 that is part of the same redundancy group as the standby storage control software 35 that has been relocated to the additional storage node 30 (hereinafter referred to as the relocated standby storage control software 35), or in the second storage node 30 on which the active storage control software 35 is located, the corresponding first storage node 11 at the primary site 2 will then begin sending journal data JNL to the second storage node 30 ("Node 1" in Figure 5) that was the source of the relocation and where the secondary volume SVOL, for which the relocated standby storage control software 35 has ownership, was located before the relocation.

[0072] However, since the second storage node 30, which is the source of the relocation, no longer has the relocation standby storage control software 35 and the secondary volume SVOL for which the relocation standby storage control software 35 has ownership, the journal data JNL is transferred via the third network 32 (Figure 1) to the additional storage node 30, which is the relocation destination of the relocation standby storage control software 35.

[0073] However, when such a transfer occurs, the response of the secondary site 3 to the remote copy between the primary site 2 and the secondary site 3 becomes slow, and furthermore, there is a problem that an extra load is generated on the second storage node 30, which is the relocation source of the relocation standby storage control software 35, due to the transfer of the journal data JNL.

[0074] On the other hand, for example, as shown in Figure 6, when a second storage node 30 called "M" is removed from the cluster 33 of the secondary site 3 having the configuration shown in Figure 2, it is necessary to relocate each storage control software 35 ("SCS#M Active" and "SCS#M-1 Standby" in Figure 6) existing in the second storage node (removed storage node) 30 to another second storage node 30, and move the secondary volume SVOL managed by that storage control software 35 to that second storage node 30.

[0075] Therefore, in this embodiment, the active secondary volume SVOL for which the active storage control software 35 located in the removed storage node 30 holds ownership is moved to another second storage node 30, and ownership of the active secondary volume SVOL is transferred from the active storage control software 35 of the removed storage node 30 to the active storage control software 35 in the second storage node 30 to which the active secondary volume SVOL has been moved. Also, with regard to the standby storage control software 35 located in the removed storage node 30, the standby storage control software 35, the standby secondary volume SVOL for which the standby storage control software 35 holds ownership, and its configuration information are relocated to any other second storage node 30.

[0076] In this state, when the removed storage node 30 is actually removed, the first storage node 11 in which the primary volume PVOL corresponding to the active secondary volume SVOL for which the active storage control software 35 in the removed storage node 30 had ownership is located will recognize that a failure has occurred in the removed storage node 30. Then, the journal data JNL of the data written to the primary volume PVOL, which had been sent to the removed storage node 30 until then, will be sent to the second storage node 30 ("Node 1" in FIG. 6) in which the standby storage control software 35 ("SCS#M Standby" in FIG. 6) that constitutes the same redundancy group as the active storage control software 35 is located.

[0077] Therefore, the second storage node 30 that receives the journal data JNL will transfer the journal data JNL to the second storage node 30 ("Node M-1" in Figure 6) to which the active storage control software 35 is to be relocated.

[0078] However, when such a transfer occurs, the response of the secondary site 3 to the remote copy between the primary site 2 and the secondary site 3 becomes slow, and furthermore, there is a problem that the second storage node 30 that transfers such journal data JNL is placed under an extra load due to the transfer.

[0079] Therefore, in the storage system 1 of this embodiment, when the second storage node 30 is added or removed at the secondary site 3, a new remote copy path 7 is re-established in the second storage node 30 to which the relocated storage control software 35 and the secondary volume SVOL for which the storage control software 35 has ownership are relocated, and the original remote copy path 7 that was set in the second storage node 30 from which the relocation is made is deleted, thereby preventing the transfer of journal data JNL within the secondary site 3 as described above.

[0080] In practice, in this storage system 1, when an additional storage node 30 is newly installed on the secondary site 3 side, the secondary site management device 31 instructs the second storage node 30 from which the standby storage control software 35 was relocated and the additional storage node 30 to relocate (copy) the standby storage control software 35 that was located on any of the second storage nodes 30, the standby secondary volume SVOL for which the standby storage control software 35 has ownership, and its configuration information to the additional storage node 30.

[0081] In addition, when copying a secondary volume SVOL between second storage nodes 30, it may be necessary to copy or create a corresponding secondary journal volume SJVOL in the destination second storage node 30, but for ease of explanation and understanding, all explanations of copying or creating such secondary journal volumes SJVOL will be omitted below.

[0082] When the relocation of the standby storage control software 35 and the standby secondary volume SVOL is completed, the secondary site management device 31 transmits relocation information to the pair management device 5, including information such as the storage control software ID of the standby storage control software 35 of each relocated standby storage control software 35, the volume ID of each standby secondary volume SVOL for which each standby storage control software 35 has ownership, the node ID of the second storage node 30 from which each standby storage control software 35 was relocated, and the node ID of the second storage node (additional storage node) 30 to which each standby storage control software 35 is to be relocated.

[0083] The pair management device 5 that has received this rearrangement information acquires from the primary site management device 12, for each rearranged standby storage control software 35, the primary volume PVOL corresponding to the standby secondary volume SVOL for which the standby storage control software 35 has ownership, the IP addresses of each port 23 provided on the first storage node 11 on which the storage control software 35 having ownership of the primary volume PVOL is located, and the IP addresses of each port 23 provided on the additional storage node 30.

[0084] Then, based on the acquired information, the pair management device 5 re-establishes a remote copy path 7 between the first storage node 11 and the additional storage node 30 to which the standby storage control software 35 has been relocated, for performing remote copying between the standby secondary volume SVOL for which the relocated standby storage control software 35 has ownership and the primary volume PVOL associated with the standby secondary volume SVOL.

[0085] The pair management device 5 also deletes the remote copy path 7 for performing remote copying between the primary volume PVOL and the standby secondary volume SVOL, which was set between the first storage node 11 and the second storage node 30 from which each standby storage control software 35 was relocated to the additional storage node 30.

[0086] In response to this, when the secondary site management device 31 receives information from the user indicating that any of the second storage nodes 30 within the secondary site 3 will be removed, it moves the active secondary volume SVOL, for which the active storage control software 35 in that second storage node (the storage node to be removed) 30 has ownership, and its configuration information to a second storage node 30 selected by the secondary site management device 31 other than the storage node 30 to be removed, and instructs the second storage node 30 and the storage node 30 to transfer the ownership of the active secondary volume SVOL to the active storage control software 35 in that second storage node 30.

[0087] The secondary site management device 31 also instructs the second storage node 30 and the reduced storage node 30 to relocate the standby storage control software 35 located in the reduced storage node 30, the standby secondary volume SVOL for which the standby control software 35 has ownership, and its configuration information to one or more second storage nodes 30 selected by the secondary site management device 31 other than the reduced storage node 30.

[0088] Then, when the relocation of each secondary volume SVOL and each storage control software 35 that was located on the removed storage node 30 is completed, the secondary site management device 31 sends to the pair management device 5 relocation information including information such as the storage control software ID of each relocated storage control software 35 (including the active storage control software 35 that has transferred ownership of the active secondary volume SVOL), the volume ID of each secondary volume SVOL for which each of these storage control software 35 has or had ownership, the node ID of the second storage node (removed storage node) 30 from which each of these storage control software 35 is to be relocated, and the node ID of the second storage node 30 to which each of these storage control software 35 is to be relocated (including the transfer of ownership of the active secondary volume SVOL).

[0089] The pair management device 5 that has received this relocation information acquires from the primary site management device 12, for each relocated storage control software 35, the primary volume PVOL corresponding to the secondary volume SVOL for which that storage control software 35 has ownership, the IP addresses of each port 23 provided on the first storage node 11 on which the storage control software 35 that has ownership of that primary volume PVOL is located, and the IP addresses of each port 23 provided on the second storage node 30 to which the relocated storage control software 35 is to be relocated.

[0090] Then, based on the acquired information, the pair management device 5 re-establishes a remote copy path 7 for performing remote copying between the active secondary volume SVOL moved from the removed storage node 30 and the primary volume PVOL corresponding to the active secondary volume SVOL, between each second storage node 30 to which the active secondary volume SVOL is moved and the first storage node 11 where the primary volume PVOL is located.

[0091] The pair management device 5 also resets the remote copy paths 7 for performing remote copying between each standby secondary volume SVOL moved from the removed storage node 30 and each primary volume PVOL corresponding to these standby secondary volumes SVOL, between the second storage node 30 to which each storage control software 35 is relocated and the first storage node 11 on which the corresponding primary volume PVOL is located.

[0092] Furthermore, the pair management device 5 deletes the remote copy path 7, which was set between the first storage node 11 on which the primary volume PVOL associated with the active secondary volume SVOL for which the active storage control software 35 in the removed storage node 30 has ownership, is located, and the removed storage node 30, for performing remote copying between the primary volume PVOL and the active secondary volume SVOL.

[0093] Similarly, the pair management device 5 deletes the remote copy paths 7 that were set between the removed storage node 30 and each first storage node 11 on which each primary volume PVOL corresponding to each standby secondary volume SVOL in the removed storage node 30 is located, for performing remote copying between each primary volume PVOL and each standby secondary volume SVOL.

[0094] (2-2) Configuration of tables and programs related to the path management function according to this embodiment As a means for realizing the path management function according to the present embodiment as described above, the memory 25 (FIG. 1) of each of the first and second storage nodes 11, 30 stores a system configuration management table 40, a storage device management table 41, a port management table 42, a volume management table 43, a volume pair management table 44, and a path management table 45, as well as an I / O processing unit 50, a node addition processing unit 51, and a node removal processing unit 52, as shown in FIG.

[0095] In addition, the primary site management device 12 and the secondary site management device 31 also store a similar system configuration management table 40, a storage device management table 41, a port management table 42, a volume management table 43, a volume pair management table 44, and a path management table 45 other than the I / O processing unit 50, as well as a node addition processing unit 51 and a node removal processing unit 52.

[0096] The system configuration management table 40 is a table for managing all of the first and second storage nodes 11, 30 present in the storage system 1, and is configured with a node ID column 40A, a status column 40B, a storage device ID list column 40C, and a port ID list column 40D, as shown in Fig. 8. In the system configuration management table 40, one record (row) corresponds to any one of the first or second storage nodes 11, 30 present in the storage system 1.

[0097] The node ID column 40A stores an identifier (node ​​ID) that is assigned to the corresponding first or second storage node 11, 30 and is unique to that first or second storage node 11, 30 within the storage system 1. The status column 40B stores the current status of that first or second storage node 11, 30. The status of the first or second storage node 11, 30 can be "Failure," which means that a failure has occurred, or "Normal," which means that no failure has occurred and the node is in a normal state.

[0098] The storage device ID list column 40C stores all of the identifiers (storage device IDs) that are assigned to each storage device 22 (FIG. 1) installed in the corresponding first or second storage node 11, 30 and that are unique to that storage device 22 within the storage system 1. The port ID list column 40D stores all of the identifiers (port IDs) that are assigned to each port 23 (FIG. 1) that the corresponding first or second storage node 11, 30 has and that are unique to that port 23 within the storage system 1.

[0099] 8, for example, the current state of the first or second storage node 11, 30 assigned a node ID of "0" is normal ("Normal"), and the first or second storage node 11, 30 is shown to be equipped with a storage device 22 assigned a storage device ID of "0," "1," or "2," respectively. Fig. 8 also shows that the first or second storage node 11, 30 has a port 23 assigned a port ID of "0" and a port 23 assigned a port ID of "1."

[0100] The storage device management table 41 is a table used to manage the storage devices 22 mounted on each of the first and second storage nodes 11 present in the storage system 1, and is configured with a storage device ID column 41A, a status column 41B, and a size column 41C, as shown in Fig. 9. In the storage device management table 41, one record corresponds to one storage device 22 mounted on either the first or second storage node 11, 30.

[0101] The storage device ID column 41A stores the storage device ID of the corresponding storage device 22, and the status column 41B stores the current status of that storage device 22. The status of the storage device 22 can be "Failure," which means that a failure has occurred, or "Normal," which means that no failure has occurred and the device is in a normal state. The size column 41C stores the capacity of that storage device 22.

[0102] Therefore, in the example of FIG. 9, for example, the current status of the storage device 22 assigned the storage device ID "0" is normal ("Normal"), and its capacity is "1400 GB."

[0103] The port management table 42 is a table used to manage the ports 23 provided in each of the first and second storage nodes 11 present in the storage system 1, and is configured with a port ID column 42A, a status column 42B, and an IP address column 42C, as shown in Fig. 10. In the port management table 42, one record corresponds to one port 23 provided in either the first or second storage node 11, 30.

[0104] The port ID column 42A stores the port ID of the corresponding port 23, and the status column 42B stores the current status of that port 23. The status of the port 23 can be "Failure," which means that a failure has occurred, or "Normal," which means that no failure has occurred and the port is in a normal state. The IP address column 42C stores the IP address of that port 23.

[0105] Therefore, in the example of FIG. 10, for example, the current state of port 23 assigned the port ID "0" is normal ("Normal"), and the IP address of port 23 is "172.12.16.200."

[0106] The volume management table 43 is a table used to manage each logical volume created in the storage system 1, and as shown in Fig. 11, is configured with a volume ID column 43A, an owner ID column 43B, a retreat destination ID column 43C, a size column 43D, an attribute column 43E, and a node ID column 43F. In the volume management table 43, one record corresponds to one logical volume created in the storage system 1.

[0107] The volume ID column 43A stores an identifier (volume ID) that is assigned to the corresponding logical volume and is unique to that logical volume within the storage system 1, and the node ID column 43F stores the node ID of the first or second storage node 11, 30 in which the logical volume was created.

[0108] In addition, the owner ID column 43B stores the identifier (storage control software ID) of the storage control software 35 that has ownership of the logical volume, and stores the storage control software ID of the storage control software 35 that is the target of the fallback and that forms the same redundancy group as the storage control software 35.

[0109] Furthermore, the size column 43D stores the capacity of the corresponding logical volume, and the attribute column 43E stores the attribute of that logical volume. The attributes of a logical volume include "normal VOL", which means that the logical volume is not set for remote copy with any other logical volume, "PVOL", which means that the logical volume is the primary volume PVOL of the volume pair, "SVOL", which means that the logical volume is the secondary volume SVOL of the volume pair, and "JNLVOL", which means that the logical volume is a journal volume.

[0110] Therefore, in the example of Figure 11, for example, the logical volume assigned the volume ID "0" is a logical volume created within the first or second storage node 11, 30 assigned the node ID "0", and its capacity is "500 GB" and its attribute is "normal VOL".

[0111] Figure 11 also shows that this logical volume is owned by storage control software 35 with storage control software ID "0", and that storage control software 3 is in the same redundancy group as storage control software 35 with storage control software ID "0".

[0112] The volume pair management table 44 is a table used to manage each volume pair defined in the storage system 1, and as shown in Fig. 12, is configured with a volume pair ID column 44A, a primary volume ID column 44B, a primary journal volume ID column 44C, a secondary journal volume ID column 44D, a secondary volume ID column 44E, a path ID column 44F, a status column 44G, and an attribute column 44H. In the volume pair management table 44, one record corresponds to one volume pair defined in the storage system 1.

[0113] The volume pair ID column 44A stores an identifier (volume pair ID) that is assigned to the corresponding volume pair and is unique to that volume pair within the storage system 1.

[0114] The primary volume ID column 44B stores the volume ID of the primary volume PVOL in the volume pair, and the primary journal volume ID column 44C stores the volume ID of the primary journal volume PJVOL associated with the primary volume PVOL (where journal data JNL (Figure 3) for the data stored in the primary volume PVOL is stored).

[0115] Furthermore, the secondary journal volume column 44D stores the volume ID of the secondary journal volume SJVOL to which the journal data JNL stored in the primary journal volume PJVOL is transferred, and the secondary volume ID column 44E stores the volume ID of the secondary volume SVOL in the corresponding volume pair.

[0116] Furthermore, the path ID column 44F stores an identifier (path ID) unique to the remote copy path 7 that is assigned to the remote copy path 7 used for remote copying data from the primary volume PVOL, whose volume ID is stored in the primary volume ID column 44B, to the secondary volume SVOL, whose volume ID is stored in the secondary volume ID column 44E.

[0117] Furthermore, the status column 44G stores the current status of the corresponding volume pair. The volume pair status can be "Copying," which means that remote copying is in progress, "Suspend," which means that remote copying is temporarily suspended, or "Normal," which means that the status is normal but remote copying is not occurring.

[0118] Furthermore, the attribute column 44H stores the attribute of the secondary volume SVOL in that copy pair. These attributes include "Active," which means that the corresponding secondary volume SVOL is an active secondary volume SVOL, and "Standby," which means that the secondary volume SVOL is a standby secondary volume SVOL. The first storage node 11 references this volume pair management table 44 and transmits journal data JNL to the corresponding second storage node 30 using the remote copy path 7 connected to the secondary volume SVOL whose attribute is "Active."

[0119] Therefore, in the example of Figure 12, for example, a volume pair assigned a volume pair ID of "0" is shown to be a volume pair in which the logical volume assigned a volume ID of "1" is the primary volume PVOL and the logical volume assigned a volume ID of "101" is the secondary volume SVOL.

[0120] Figure 12 also shows that the data stored in this primary volume PVOL is sent from the primary volume PVOL to the secondary volume SVOL, sequentially passing through the primary journal volume PJVOL, which has a volume ID of "2" at the primary site 2, and the secondary journal volume SJVOL, which has a volume ID of "102" at the secondary site 3.

[0121] Furthermore, FIG. 12 also shows that the path ID of the remote copy path 7 connecting the primary volume PVOL and secondary volume SVOL of the volume pair is "0" and that the current status is normal ("Normal").

[0122] In addition, Figure 12 shows that the secondary volume SVOL of the volume pair assigned the volume pair ID "0" and the secondary volume SVOL of the volume pair assigned the volume pair ID "1" are redundant logical volumes because the primary volume PVOL of these volume pairs is the same (the volume ID of both primary volumes PVOL is "1"), and that the secondary volume SVOL of the volume pair assigned the volume pair ID "0" is the active secondary volume SVOL (the attribute of the secondary volume SVOL is "Active").

[0123] The path management table 45 is a table used to manage all remote copy paths 7 set within the storage system 1. In the following, it is assumed that all remote copy paths are duplicated. As shown in FIG. 13, the path management table 45 is configured with a path ID column 45A, a protocol information column 45B, an IP address column 45C, an access policy column 45D, and a preferred path column 45E. In the path management table 45, one record corresponds to one remote copy path 7 set within the storage system 1.

[0124] The path ID column 45A stores the path ID of the corresponding remote copy path 7, and the protocol information column 45B stores the protocol that the remote copy path 7 complies with.

[0125] The IP address column 45C is divided into a first path column 45CA and a second path column 45CB, which correspond to the two paths (hereinafter referred to as the first and second paths) that make up the corresponding remote copy path 7. The first path column 45CA and the second path column 45CB store the IP address of the port 23 of the first storage node 11 at the primary site 2 (the IP address represented by "P:" in FIG. 13) and the IP address of the port 23 of the second storage node 30 at the secondary site 3 (the IP address represented by "S:" in the figure), respectively, to which the corresponding first or second path is connected.

[0126] Furthermore, the access policy column 45D stores information indicating how to use the first and second paths that make up the corresponding remote copy path 7. In this case, the first and second paths can be used in a "symmetric" manner, where both the first and second paths are used while switching between them using a method such as round robin, or in an "asymmetric" manner, where only one of the first or second paths is used. Furthermore, the preferred path column 45E stores the IP address of the port 23 on the first storage node 11 side of the first or second path to be used when the access policy is "asymmetric," and the IP address of the port 23 of the second storage node 30.

[0127] 13, for example, the remote copy path 7 assigned a path ID of "0" is shown to be composed of a first path connecting a port 23 assigned an IP address of "172.12.16.202" of a first storage node 11 installed at the primary site 2 and a port 23 assigned an IP address of "172.12.16.203" of a second storage node 30 installed at the secondary site 3, and a second path connecting a port 23 assigned an IP address of "172.12.16.302" of the first storage node 11 and a port 23 assigned an IP address of "172.12.16.303" of the second storage node. Figure 13 also shows that this remote copy path 7 is an "iSCSI" compliant path, the access policy is "asymmetric", and the first path is the preferred path.

[0128] Since the first and second storage nodes 11 and 30 recognize the communication destination by referring to the path management table 45 they hold, the remote copy path 7 can be set by registering the necessary information in the path management table 45 (creating a record corresponding to the remote copy path 7), and the remote copy path 7 can be deleted by deleting the information about the remote copy path 7 stored in the path management table 45 (deleting the record corresponding to the remote copy path 7).

[0129] On the other hand, the I / O processing unit 50 is part of the storage control software 35 implemented in the first and second storage nodes 11 and 30, and has the function of executing I / O processing corresponding to an I / O request when an I / O request (read request or write request) is given from the host device 10 (Figure 1) in the first storage node 11, or when a write request for data to be remotely copied is given from the first storage node 11 in the second storage node 30.

[0130] In practice, when a data read request is given from the host device 10 (Figure 1), the I / O processing unit 50 of the first storage node 11 reads the data from the location where the data to be read specified in the read request is stored in the primary volume PVOL where the data to be read specified in the read request is stored, and sends the data to the host device 10.

[0131] Furthermore, when a data write request is given from the host device 10, the I / O processing unit 50 of the first storage node 11 writes the write target data specified in the write request to the location specified in the write request in the primary volume PVOL where the write target data is to be written, generates journal data JNL for the data, stores the generated journal data JNL in the corresponding primary journal volume PJVOL, and further transfers the journal data JNL to the corresponding second storage node 30.

[0132] The processing content (I / O processing) of the I / O processor 50 of the second storage node 30 has already been explained, so the explanation will be omitted here.

[0133] In the first and second storage nodes 11, 30, the node addition processing unit 51 is part of the storage control software 35 installed in the first and second storage nodes 11, 30, and in the primary site management device 12 and secondary site management device 31, it is part of the primary site management software 26 (FIG. 1) or secondary site management software 34 (FIG. 1) installed in the primary site management device 12 and secondary site management device 31. When a second storage node 30 is installed in the secondary site 3, the node addition processing unit 51 executes necessary processing out of the series of processing performed in the storage system 1 described above.

[0134] In the first and second storage nodes 11, 30, the node removal processing unit 52 is also part of the storage control software 35 installed in the first and second storage nodes 11, 30, and in the primary site management device 12 and secondary site management device 31, it is part of the primary site management software 26 (FIG. 1) or secondary site management software 34 (FIG. 1) installed in the primary site management device 12 and secondary site management device 31. When the second storage node 30 is removed from the secondary site 3, the node removal processing unit 52 executes necessary processing out of the series of processing performed in the storage system 1 as described above.

[0135] (3) Various processes related to the path management function of this embodiment Next, the specific processing contents of the various processes executed in relation to the path management function of this embodiment will be explained. Note that, in the following, the processing entities of the various processes will be explained as "programs," but it goes without saying that in reality, the processor 24 (FIG. 1) in the second storage node 30 or a processor (not shown) of the primary site management device 12 or secondary site management device 31 executes the processes based on the programs.

[0136] (3-1) Storage node expansion process on the secondary site management software FIG. 14 shows the flow of a series of processes (hereinafter referred to as the secondary site management software side storage node addition process) executed by the secondary site management software 34 of the secondary site management device 31 when a new second storage node 30 is added to the cluster 33 at the secondary site 3.

[0137] In the following description, it is assumed that active storage control software 35 and an active secondary volume SVOL, the ownership of which is held by the active storage control software 35, have already been placed in the additional storage node 30 by prior user operation or the like, and that the necessary information regarding the additional storage node 30, the active storage control software 35, and the active secondary volume SVOL has already been registered in the system configuration management table 40, storage device management table 41, port management table 42, and volume management table 43.

[0138] When the secondary site management software 34 receives information from the user indicating that a second storage node 30 has been added to the cluster 33, for example, by the user performing a predetermined operation on the secondary site management device 31, the secondary site management software 34 starts the storage node addition process on the secondary site management software side shown in FIG. 14.

[0139] The secondary site management software 34 then first registers the added storage node 30 in the cluster 33 to which the storage node 30 is to be added (S1). Specifically, the secondary site management software 34 registers and manages information about which second storage node 30 belongs to which cluster 33 in a management table (not shown) (hereinafter referred to as the cluster management table), and registers information that the second storage node 30 has been added to that cluster 33 in the cluster management table.

[0140] Next, the secondary site management software 34 selects a second storage node (hereinafter referred to as a relocation source storage node) 30 as the relocation source of the standby storage control software 35 (and standby secondary volume SVOL) to be relocated to the added storage node 30 (S2). For example, the secondary site management software 34 refers to the volume management table 43 it holds, and determines the standby storage control software 35 that manages the fewest number of secondary volumes SVOL as the standby storage control software 35 to be relocated, and selects the second storage node 30 on which that standby storage control software 35 is located as the relocation source storage node 30.

[0141] At this time, the secondary site management software 34 selects the number of relocation source storage nodes 30 according to the redundancy of the secondary volume SVOL (the number of storage control software 35 constituting the redundancy group). For example, if the redundancy of the secondary volume SVOL is "N", the secondary site management software 34 selects N relocation source storage nodes 30.

[0142] Next, the secondary site management software 34 relocates the standby storage control software 35 to be relocated in each of the relocation source storage nodes 30 selected as described above to the additional storage node 30, and moves all standby secondary volumes SVOL for which the relocated standby storage control software 35 has ownership in the second storage node 30 that is the relocation source, and their configuration information, to the additional storage node 30 (S3).

[0143] Specifically, the secondary site management software 34 first instructs the second storage nodes 30 on which the standby storage control software 35 to be relocated is located and the additional storage node 30 to copy all of the data of each standby storage control software 35 to be relocated, the volume data of all standby secondary volumes SVOL for which the standby storage control software 35 has ownership, and the configuration information of these standby secondary volumes SVOL to the additional storage node 30.

[0144] The secondary site management software 34 also rewrites the value in the node ID column 43F (FIG. 11) of the record in the volume management table 43 (FIG. 11) held by itself, which corresponds to each active secondary volume SVOL that has been moved to the additional storage node 30 as described above, to the node ID of the additional storage node 30.

[0145] The secondary site management software 34 then transmits differential data indicating the difference between the updated volume management table 43 before and after the update to each second storage node 30 in the secondary site 3. As a result, based on this differential data, the contents of the volume management table 43 held by each second storage node 30 are updated in the same way as the volume management table 43 held by the secondary site management software 34.

[0146] The secondary site management software 34 also transmits this differential data to the primary site management software 26 of the primary site 2. Then, upon receiving this differential data, the primary site management software 26 updates its own volume management table 43 based on this differential data in the same way as the volume management table 43 held by the secondary site management software 34.

[0147] The secondary site management software 34 also transmits differential data indicating the difference before and after the update in the volume management table 43 updated in this manner to each first storage node 11 in the primary site 2. As a result, based on this differential data, the contents of the volume management table 43 held by each first storage node 11 are updated in the same way as the volume management table 43 held by the primary site management software 26.

[0148] Next, the secondary site management software 34 instructs each second storage node 30, which is the relocation source of each relocated standby storage control software 35, to create standby storage control software 35 that will form a redundancy group together with the active storage control software 35 created in the added storage node 30 (S4). As a result, standby storage control software 35 that will form the same redundancy group together with the active storage control software 35 created in the added storage node 30 is created in each of these second storage nodes 30.

[0149] Thereafter, the secondary site management software 34 transmits the storage control software ID of each standby storage control software 35 relocated to the additional storage node 30 as described above, the volume IDs of all standby secondary volumes SVOL for which these standby storage control software 35 have ownership, the node IDs of the storage nodes 30 from which these standby storage control software 35 are relocated, and the node ID of the second storage node (additional storage node) to which these standby storage control software 35 are relocated as relocation information to the pair management software 6 in the pair management device 5 (S5).

[0150] Then, the secondary site management software 34 thereafter ends the storage node addition processing on the secondary site management software side.

[0151] (3-2) Processing of pair management software when adding storage nodes FIG. 15 shows the flow of a series of processes (hereinafter referred to as pair management software side storage node addition process) executed by the pair management software 6 of the pair management device 5 that has received the above-mentioned rearrangement information.

[0152] When the pair management software 6 receives the rearrangement information, it starts the storage node addition process on the pair management software side shown in FIG. 15, and first acquires (receives) the rearrangement information that has been sent (S10).

[0153] Next, the pair management software 6 selects one standby secondary volume SVOL that has not been processed in step S12 and after from among the standby secondary volumes SVOL that have been moved to the additional storage node 30 and that are recognized based on the acquired rearrangement information (S11).

[0154] Next, the pair management software 6 collects from the primary site management device 12 information required to set up a remote copy path 7 for performing remote copying between the standby secondary volume SVOL selected in step S11 (hereinafter referred to as the selected standby secondary volume) and the primary volume PVOL corresponding to the selected standby secondary volume SVOL, between the first storage node 11 (hereinafter referred to as the specific storage node in the explanation of Figure 15) on which the primary volume PVOL was created and the additional storage node 30 (S12).

[0155] Specifically, the pair management software 6 specifies the volume ID of the selected standby secondary volume SVOL, and queries the primary site management software 26 of the primary site management device 12 for the volume ID of the primary volume PVOL corresponding to that selected standby secondary volume SVOL and the storage control software ID of the storage control software 35 that has ownership of that primary volume PVOL. The pair management software 6 also queries the primary site management software 26 of the primary site management device 12 for the IP addresses of each port 23 provided in the specific storage node 11 where that storage control software 35 is located, and the IP addresses of each port 23 provided in the additional storage node 30.

[0156] Upon receiving this inquiry, the primary site management software 26 obtains the volume ID of the primary volume PVOL corresponding to the selected standby secondary volume SVOL from its own volume pair management table 44 (FIG. 9). The primary site management software 26 also obtains from its own volume management table 43 the storage control software ID of the storage control software 35 that has ownership of that primary volume PVOL and the node ID of the specific storage node 11 in which that primary volume PVOL is created.

[0157] Furthermore, the main site management software 26 acquires the port ID of each port 23 provided in the specified storage node 11 and the port ID of each port 23 provided in the additional storage node 30 from the system configuration table 40 (FIG. 5) held by itself. Then, the main site management software 26 acquires the IP addresses of each port 23 of the specified storage node 11 and the additional storage node 30, whose port IDs have been acquired as described above, from the port management table 42 (FIG. 7) held by itself. Then, the main site management software 26 transmits this information acquired in this manner to the pair management software 6.

[0158] Next, the pair management software 6 instructs the primary site management software 26 and the secondary site management software 34 to create a remote copy path 7 between the specified storage node 11 and the additional storage node 30, connecting the primary volume PVOL, whose volume ID was obtained in step S12, and the selected standby secondary volume SVOL (S13).

[0159] Specifically, the pair management software 6 creates two combinations of the IP address of each port 23 of the specific storage node 11 obtained in step S12 and the IP address of each port 23 of the additional storage node 30, and instructs the primary site management software 26 and the secondary site management software 34 to create a path connecting these IP addresses for each combination.

[0160] Thus, the primary site management software 26 and secondary site management software 34 that have received this instruction store this IP address combination in the first and second path columns 45CA, 45CB of an unused record in their own path management table 45 (FIG. 13) as a combination of IP addresses on both ends of the first path and second path, respectively, and store necessary information (for example, information determined by default) in the protocol information column 45B, access policy column 45D, and preferred path column 45E of that record. The primary site management software 26 and secondary site management software 34 also store the same path ID assigned to that remote copy path 7 in the path ID column 45A of the path management table 45.

[0161] Furthermore, the primary site management software 26 and the secondary site management software 34 update the value of the path ID column 44F of the record in which the selected standby secondary volume SVOL is stored in the secondary volume ID column 44E (Figure 12) in the volume pair management table 44 that they each hold, to the same path ID assigned to the remote copy path 7.

[0162] The primary site management software 26 then transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each first storage node 11 in the primary site 2, thereby similarly updating the path management table 45 and volume pair management table 44 held by each first storage node 11. The secondary site management software 34 also transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each second storage node 30 in the secondary site 3, thereby similarly updating the path management table 45 and volume pair management table 44 held by each second storage node 30.

[0163] As a result of the above, a remote path 7 is established between the specified storage node 11 and the additional storage node 30. The primary site management software 26 and the secondary site management software 34 may further cooperate to create an iSCSI initiator in the specified storage node 11 that corresponds to the primary volume PVOL corresponding to the selected standby secondary volume SVOL, and to create an iSCSI target in the additional storage node 30 that corresponds to the selected standby secondary volume SVOL, and to perform processing up to establishing a session between these iSCSI initiators and iSCSI targets.

[0164] Next, the pair management software 6 collects from the primary site management device 12 information required to delete the remote copy path 7 connecting the second storage node 30 (hereinafter referred to as the source storage node) that is the source of the selected standby secondary volume SVOL and the specific storage node 11 (S14). Specifically, the pair management software 6 extracts the node ID of the source storage node 30 from the relocation information notified by the secondary site management software 34, and queries the primary site management software 26 for the IP addresses of each port 23 provided in the source storage node 30 to which the node ID is assigned.

[0165] Upon receiving this inquiry, the primary site management software 26 acquires the port IDs of the ports 23 of the source storage node 30 from the record corresponding to the source storage node 30 in the system configuration table 40 (FIG. 5) held by itself. The primary site management software 26 then acquires the IP addresses of the ports 23 of the source storage node 30, whose port IDs have been acquired as described above, from the port management table 42 (FIG. 7) held by itself. The primary site management software 26 then transmits the acquired IP addresses of the ports 23 of the source storage node 30 to the pair management software 6.

[0166] Then, based on the IP addresses of the ports 23 of the source storage node 30 thus obtained and the IP addresses of the ports 23 of the specified storage node 11 obtained in step S12, the pair management software 26 instructs the primary site management software 26 and the secondary site management software 34 to delete the remote copy path 7 connecting the specified storage node 11 and the source storage node 30 (S15). This instruction includes information on the IP addresses of the ports 23 of the specified storage node 11 and the IP addresses of the ports 23 of the source storage node 30.

[0167] Thus, the primary site management software 26 and secondary site management software 34 that receive this instruction identify, from the records of the path management table 45 that they hold, records in which at least one combination of the IP address of each port 23 provided on the specified storage node 11 and the IP address of each port 23 provided on the source storage node 30 is stored in the first or second path column 45CA, 45CB, and deletes that record from the path management table 45.

[0168] The primary site management software 26 also transmits differential data before and after the above-mentioned update of the path management table 45 held by itself to each first storage node 11 in the primary site 2, thereby causing each first storage node 11 to similarly update its own path management table 45. The secondary site management software 34 also transmits differential data before and after the above-mentioned update of the path management table 45 held by itself to each second storage node 30 in the secondary site 3, thereby causing each second storage node 30 to similarly update its own path management table 45. As a result of the above, the remote path 7 set between the specified storage node 11 and the source storage node 30 is deleted.

[0169] Thereafter, the pair management software 26 determines (S16) whether or not the processing from step S12 onwards has been completed for all standby secondary volumes SVOL that have been moved to the additional storage node 30 that are recognized from the relocation information notified by the secondary site management software 34. If the pair management software 6 obtains a negative result in this determination, it returns to step S11, and thereafter repeats the processing from step S11 to step S16 while sequentially switching the standby secondary volume SVOL selected in step S11 to another corresponding standby secondary volume SVOL that has not yet been processed from step S12 onwards.

[0170] By this repeated processing, a remote copy path 7 connecting each standby secondary volume SVOL moved to the additional storage node 30 and the primary volume PVOL corresponding to that standby secondary volume SVOL is sequentially established between the corresponding first storage node 11 and the additional storage node 30, and the remote copy path 7 established between the source storage node 30 of that standby secondary volume SVOL and the specified storage node 11 is sequentially deleted.

[0171] Then, when the pair management software 6 obtains a positive result in step S16 by completing the processing of steps S12 to S15 for each standby secondary volume SVOL that has been moved to the added storage node 30, it terminates the storage node addition processing on the pair management software side.

[0172] (3-3) Processing of the secondary site management software when removing a storage node Figure 16 shows the flow of a series of processes (hereinafter referred to as the secondary site management software side storage node removal process) executed by the secondary site management software 34 of the secondary site management device 31 when removing a second storage node 30 from a cluster 33 at the secondary site 3.

[0173] When the secondary site management software 34 receives information from the user indicating that a specific second storage node 30 is to be removed from the cluster 33, for example, by the user performing a predetermined operation on the secondary site management device 31, the secondary site management software 34 starts the storage node removal process on the secondary site management software side shown in Figure 13.

[0174] The secondary site management software 34 first selects, from among the active storage control software 35 located in second storage nodes 30 other than the second storage node 30 to be removed (removed storage node) 30 in the same cluster 33 as the second storage node 30 to be removed, the active storage control software 35 to which the ownership of all active secondary volumes SVOL for which the active storage control software 35 located in the removed storage node 30 has ownership (S20).

[0175] For example, the secondary site management software 34 selects the active storage control software 35 so as to balance the loads on the second storage nodes 30 other than the removed storage node 30 in the cluster 33 to which the removed storage node 30 belongs. Hereinafter, the active storage control software 35 selected at this time will be referred to as the transferee active storage control software 35.

[0176] Next, the secondary site management software 34 moves all active secondary volumes SVOLs for which the active storage control software 35 located in the removed storage node 30 has ownership to the second storage node 30 in which the destination active storage control software 35 selected in step S20 is located, and moves the ownership of each of these moved active secondary volumes SVOLs to the destination active storage control software 35 (S21).

[0177] Specifically, the secondary site management software 34 instructs the second storage node 30 and the removed storage node 30 to copy the data of each active secondary volume SVOL for which the active storage control software 35 located in the removed storage node 30 has ownership and the configuration information of that active secondary volume SVOL to the second storage node 30 on which the transferee active storage control software 35 is located.

[0178] The secondary site management software 34 also rewrites the storage control software ID stored in the owner ID column 43B (FIG. 11) of the record corresponding to each active secondary volume SVOL moved as described above to the second storage node 30 where the transfer destination active storage control software 35 is located in the volume management table 43 (FIG. 11) held by itself, to the storage control software ID of the transfer destination active storage control software 35. The secondary site management software 34 also rewrites the value in the node ID column 43F of that record to the node ID of the second storage node 30 where the transfer destination active storage control software 35 is located.

[0179] The secondary site management software 34 then transmits differential data indicating the difference between before and after the update in the volume management table 43 thus updated to each second storage node 30 in the secondary site 3. As a result, based on this differential data, the contents of the volume management table 43 held by each second storage node 30 are updated in the same way as the volume management table 43 held by the secondary site management software 34. As a result, the ownership of each active secondary volume SVOL is handed over to the migration destination active storage control software 35.

[0180] The secondary site management software 34 also transmits this differential data to the primary site management software 26 of the primary site 2. Then, upon receiving this differential data, the primary site management software 26 updates its own volume management table 43 based on this differential data in the same way as the volume management table 43 held by the secondary site management software 34.

[0181] Furthermore, the secondary site management software 34 transmits difference data indicating the difference before and after the update in the volume management table 43 updated in this manner to each first storage node 11 in the primary site 2. As a result, based on this difference data, the contents of the volume management table 43 held by each first storage node 11 are updated in the same way as the volume management table 43 held by the primary site management software 26.

[0182] Next, the secondary site management software 34 moves each standby secondary volume SVOL and its configuration information, which is owned by the standby storage control software 35 that is in the same redundancy group as the active storage control software 35 that was located on the removed storage node 30, to the second storage node 30 on which the standby storage control software 35 that is in the same redundancy group as the transferee active storage control software 35 is located (S22).

[0183] Specifically, the secondary site management software 34 copies each of the standby secondary volumes SVOL and their configuration information to the second storage node 30 in which the standby storage control software 35 that constitutes the same redundancy group as the transferee active storage control software 35 is located, in the same manner as in step S21.

[0184] The secondary site management software 34 then transfers the ownership of these standby secondary volumes SVOL to the standby storage control software 35 in the destination second storage node 30 (the corresponding standby storage control software 35 that constitutes the same redundancy group as the transfer destination active storage control software 35) in the same manner as described above. In response to this, the secondary site management software 34 also updates the volume management tables 43 held by the secondary site management device 31, the second storage node 30, the primary site management device 12, and each first storage node 11 in the same manner as in step S21.

[0185] Next, the secondary site management software 34 deletes the active storage control software 35 that was placed on the reduced storage node 30 from the reduced storage node 30, and also deletes the standby storage control software 35 that constitutes the same redundancy group as the active storage control software 35 from the second storage node 30 on which the standby storage control software 35 is placed (S23).

[0186] Specifically, the secondary site management software 34 instructs the reduced storage node 30 to delete the data of the active storage control software 35, and also instructs the second storage node 30 on which the standby storage control software 35 is located to delete the data of the standby storage control software 35 that constitutes the same redundancy group as the active storage control software 35.

[0187] Next, the secondary site management software 34 moves all the standby storage control software 35 located on the removed storage node 30, the standby secondary volumes SVOLs for which the standby storage control software 35 has ownership, and the configuration information of the standby secondary volumes SVOLs to any second storage node 30 other than the removed storage node 30 within the same cluster 33 (S24).

[0188] Specifically, the secondary site management software 34 first determines the second storage node 30 to which each standby storage control software 35 located on the removed storage node 30 is to be relocated. The relocation destination is determined so as to balance the load on each second storage node 30 within the same cluster 33. The secondary site management software 34 then instructs each determined second storage node 30 and the removed storage node 30 to copy the standby storage control software 35, the standby secondary volume SVOL, and the data of its configuration information.

[0189] Thereafter, in response to the movement of the standby secondary volume SVOL, the secondary site management software 34 rewrites the value stored in the node ID column 43F corresponding to the standby secondary volume SVOL in the volume management table 43 held by the secondary site management device 31, the second storage node 30, the primary site management device 12, and each first storage node 11, in the same manner as in step S21, to the node ID of the second storage node 30 to which the standby secondary volume SVOL has been moved.

[0190] The secondary site management software 34 then transmits the storage control software ID of the storage control software 35 that has been relocated (including the transfer of ownership) from the reduced storage node 30 to another second storage node 30 as described above, the volume IDs of each secondary volume SVOL that has been moved from the reduced storage node 30 to another second storage node 30 as a result, the node IDs of the second storage nodes 30 to which each relocated storage control software 35 has been relocated, and the node ID of the reduced storage node 30 to the pair management software 6 of the pair management device 5 as relocation information (S25).

[0191] Then, the secondary site management software 34 thereafter ends the storage node reduction processing on the secondary site management software side.

[0192] (3-4) Processing of pair management software when removing a storage node 17A and 17B show the flow of a series of processes (hereinafter referred to as pair management software side storage node removal process) executed by the pair management software 6 of the pair management device 5 that has received the above-mentioned rearrangement information.

[0193] When the pair management software 6 receives the rearrangement information, it starts the storage node removal process on the pair management software side shown in Figures 17A and 17B, and first receives and acquires the rearrangement information that has been sent (S30).

[0194] Next, the pair management software 6 selects one active secondary volume SVOL that has not been processed in steps S32 and after from among the active secondary volumes SVOL that have been moved from the removed storage node 30 to another second storage node 30 and that are recognized based on the acquired rearrangement information (S31).

[0195] Next, the pair management software 6 collects from the primary site management device 12 information required to set up a remote copy path 7 for performing remote copying between the active secondary volume SVOL selected in step S31 (hereinafter referred to as the selected active secondary volume) and the primary volume PVOL corresponding to the selected active secondary volume SVOL, between the first storage node 11 where the primary volume PVOL was created (hereinafter referred to as the active specified storage node) and the second storage node 30 to which the selected active secondary volume is to be moved (hereinafter referred to as the active destination storage node) (S32).

[0196] Specifically, the pair management software 6 specifies the volume ID of the selected active secondary volume SVOL, and queries the primary site management software 26 of the primary site management device 12 for the volume ID of the primary volume PVOL corresponding to the selected active secondary volume SVOL and the storage control software ID of the storage control software 35 that has ownership of the primary volume PVOL. The pair management software 6 also queries the primary site management software 26 of the primary site management device 12 for the IP addresses of the ports 23 provided in the active specified storage node 11 where the storage control software 35 is located, and the IP addresses of the ports 23 provided in the active destination storage node 30.

[0197] Upon receiving this inquiry, the primary site management software 26 obtains the volume ID of the primary volume PVOL corresponding to the selected active secondary volume SVOL from its own volume pair management table 44 (FIG. 9). The primary site management software 26 also obtains from its own volume management table 43 the storage control software ID of the storage control software 35 that has ownership of that primary volume PVOL and the node ID of the active specified storage node 11 in which that primary volume PVOL has been created.

[0198] Furthermore, the primary site management software 26 acquires the port ID of each port 23 provided in the specified active storage node 11 and the port ID of each port 23 provided in the active destination storage node 30 from a system configuration table 40 (FIG. 5) held by itself. Then, the primary site management software 26 acquires the IP addresses of each port 23 of the specified active storage node 11 and the active destination storage node 30, whose port IDs have been acquired as described above, from a port management table 42 (FIG. 7) held by itself. Then, the primary site management software 26 transmits this information acquired in this manner to the pair management software 6.

[0199] Next, the pair management software 6 instructs the primary site management software 26 and the secondary site management software 34 to create a remote copy path 7 between the active specified storage node 11 and the active destination storage node 30, connecting the primary volume PVOL, whose volume ID was obtained in step S32, and the selected active secondary volume SVOL (S33).

[0200] Specifically, the pair management software 6 creates two combinations of the IP address of each port 23 of the active specified storage node 11 obtained in step S32 and the IP address of each port 23 of the active destination storage node 30, and instructs the primary site management software 26 and the secondary site management software 34 to create a path connecting these IP addresses for each combination.

[0201] Thus, the primary site management software 26 and secondary site management software 34 that have received this instruction store this IP address combination in the first and second path columns 45CA, 45CB of an unused record in their own path management table 45 (FIG. 13) as a combination of IP addresses on both ends of the first path and second path, respectively, and store necessary information (for example, information determined by default) in the protocol information column 45B, access policy column 45D, and preferred path column 45E of that record. The primary site management software 26 and secondary site management software 34 also store the same path ID assigned to that remote copy path 7 in the path ID column 45A of the path management table 45.

[0202] Furthermore, the primary site management software 26 and the secondary site management software 34 update the value of the path ID column 44F of the record in which the selected active secondary volume SVOL is stored in the secondary volume ID column 44E (Figure 12) in the volume pair management table 44 that they each hold, to the same path ID assigned to the remote copy path 7.

[0203] The primary site management software 26 then transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each first storage node 11 in the primary site 2, thereby similarly updating the path management table 45 and volume pair management table 44 held by each first storage node 11. The secondary site management software 34 also transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each second storage node 30 in the secondary site 3, thereby similarly updating the path management table 45 and volume pair management table 44 held by each second storage node 30.

[0204] As a result of the above, a remote path 7 is established between the specified active storage node 11 and the active destination storage node 30. The primary site management software 26 and the secondary site management software 34 may further cooperate to create an iSCSI initiator in the specified active storage node 11 that corresponds to the primary volume PVOL corresponding to the selected active secondary volume SVOL, and to create an iSCSI target in the active destination storage node 30 that corresponds to the selected active secondary volume SVOL, and to perform processing up to establishing a session between these iSCSI initiators and iSCSI targets.

[0205] Next, the pair management software 6 collects from the primary site management device 12 information required to delete the remote copy path 7 connecting the removed storage node 30, which is the migration source of the selected active secondary volume SVOL, and the specified active storage node 11 (S34). Specifically, the pair management software 6 extracts the node ID of the removed storage node 30 from the relocation information notified by the secondary site management software 34, and queries the primary site management software 26 for the IP addresses of each port 23 provided in the removed storage node 30 to which the node ID has been assigned.

[0206] Upon receiving this inquiry, the primary site management software 26 acquires the port IDs of the ports 23 of the reduced storage node 30 from the record corresponding to the reduced storage node 30 in the system configuration table 40 (FIG. 5) held by itself. The primary site management software 26 then acquires the IP addresses of the ports 23 of the reduced storage node 30, whose port IDs have been acquired as described above, from the port management table 42 (FIG. 7) held by itself. The primary site management software 26 then transmits the acquired IP addresses of the ports 23 of the reduced storage node 30 to the pair management software 6.

[0207] Then, based on the IP addresses of the ports 23 of the removed storage node 30 thus obtained and the IP addresses of the ports 23 of the specified active storage node 11 obtained in step S32, the pair management software 26 instructs the primary site management software 26 and the secondary site management software 34 to delete the remote copy path 7 connecting the specified active storage node 11 and the removed storage node 30 (S35). This instruction includes information on the IP addresses of the ports 23 of the specified active storage node 11 and the IP addresses of the ports 23 of the removed storage node 30.

[0208] Thus, upon receiving this instruction, the primary site management software 26 and secondary site management software 34 identify from the records of the path management table 45 they hold, a record in which at least one combination of the IP address of each port 23 of the active specified storage node 11 and the IP address of each port 23 of the removed storage node 30 is stored in the first or second path column 45CA, 45CB, and deletes that record from the path management table 45.

[0209] The primary site management software 26 also transmits differential data before and after the above-described update of the path management table 45 held by itself to each first storage node 11 in the primary site 2, thereby causing each first storage node 11 to similarly update its own path management table 45. The secondary site management software 34 also transmits differential data before and after the above-described update of the path management table 45 held by itself to each second storage node 30 in the secondary site 3, thereby causing each second storage node 30 to similarly update its own path management table 45. As a result of the above, the remote path 7 set between the active specified storage node 11 and the removed storage node 30 is deleted.

[0210] Thereafter, the pair management software 26 determines (S36) whether or not the processing from step S32 onwards has been completed for all active secondary volumes SVOL that have been moved from the removed storage node 30 to other second storage nodes 30, which is recognized from the relocation information notified from the secondary site management software 34. If the pair management software 26 obtains a negative result in this determination, it returns to step S31, and thereafter repeats the processing from step S31 to step S36 while sequentially switching the active secondary volume SVOL selected in step S31 to other corresponding active secondary volumes SVOL for which step S32 onwards has not been processed.

[0211] By this repeated process, remote copy paths 7 connecting each active secondary volume SVOL moved from the reduced storage node 30 to another second storage node 30 to the primary volume PVOL corresponding to that active secondary volume SVOL are sequentially set between the corresponding active specified storage node 11 and the active destination storage node 30, and the original remote copy paths 7 set between the reduced storage node 30, which is the migration source of that active secondary volume SVOL, and the active specified storage node 11 are sequentially deleted.

[0212] When the pair management software 6 eventually obtains a positive result in step S36 by completing the processing of steps S32 to S35 for each standby secondary volume SVOL that has been moved to the additional storage node 30, it selects one standby secondary volume SVOL that has not yet been processed in steps S38 and after from among the standby secondary volumes SVOL that have been moved from the reduced storage node 30 to another second storage node 30 and that were managed by each standby storage control software 35 that was located on the reduced storage node 30 (S37).

[0213] Next, the pair management software collects from the primary site management device 12 information required to set up a remote copy path 7 for performing remote copying between the active secondary volume (hereinafter referred to as the selected standby secondary volume) SVOL selected in step S37 and the primary volume PVOL corresponding to the selected standby secondary volume SVOL, between the first storage node (hereinafter referred to as the standby specified storage node) 11 where the primary volume PVOL was created and the second storage node (hereinafter referred to as the standby destination storage node) 30 to which the selected standby secondary volume is to be moved (S38).

[0214] Specifically, the pair management software 6 specifies the volume ID of the selected standby secondary volume SVOL, and queries the primary site management software 26 of the primary site management device 12 for the volume ID of the primary volume PVOL corresponding to that selected standby secondary volume SVOL and the storage control software ID of the storage control software 35 that has ownership of that primary volume PVOL. The pair management software 6 also queries the primary site management software 26 of the primary site management device 12 for the IP addresses of each port 23 provided in the standby specified storage node 11 where that storage control software 35 is located, and the IP addresses of each port 23 provided in the standby destination storage node 30.

[0215] Upon receiving this inquiry, the primary site management software 26 obtains the volume ID of the primary volume PVOL corresponding to the selected standby secondary volume SVOL from its own volume pair management table 44 (FIG. 9). The primary site management software 26 also obtains from its own volume management table 43 the storage control software ID of the storage control software 35 that has ownership of the primary volume PVOL and the node ID of the standby specified storage node 11 in which the primary volume PVOL is created.

[0216] Furthermore, the primary site management software 26 acquires the port ID of each port 23 provided in the standby specified storage node 11 and the port ID of each port 23 provided in the standby destination storage node 30 from the system configuration table 40 (FIG. 5) held by itself. Then, the primary site management software 26 acquires the IP addresses of each port 23 of the standby specified storage node 11 and the standby destination storage node 30, whose port IDs have been acquired as described above, from the port management table 42 (FIG. 7) held by itself. Then, the primary site management software 26 transmits this information acquired in this manner to the pair management software 6.

[0217] Next, the pair management software 6 instructs the primary site management software 26 and the secondary site management software 34 to create a remote copy path 7 between the standby specified storage node 11 and the standby destination storage node 30, connecting the primary volume PVOL, whose volume ID was obtained in step S38, and the selected standby secondary volume SVOL (S39).

[0218] Specifically, the pair management software 6 creates two combinations of the IP address of each port 23 of the standby specified storage node 11 obtained in step S38 and the IP address of each port 23 of the standby destination storage node 30, and instructs the primary site management software 26 and the secondary site management software 34 to create a path connecting these IP addresses for each combination.

[0219] Thus, the primary site management software 26 and secondary site management software 34 that have received this instruction store this IP address combination in the first and second path columns 45CA, 45CB of an unused record in their own path management table 45 (FIG. 13) as a combination of IP addresses on both ends of the first path and second path, respectively, and store necessary information (for example, information determined by default) in the protocol information column 45B, access policy column 45D, and preferred path column 45E of that record. The primary site management software 26 and secondary site management software 34 also store the same path ID assigned to that remote copy path 7 in the path ID column 45A of the path management table 45.

[0220] Furthermore, the primary site management software 26 and the secondary site management software 34 update the value of the path ID column 44F of the record in which the selected standby secondary volume SVOL is stored in the secondary volume ID column 44E (Figure 12) in the volume pair management table 44 that they each hold, to the same path ID assigned to the remote copy path 7.

[0221] The primary site management software 26 then transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each first storage node 11 in the primary site 2, thereby similarly updating the path management table 45 and volume pair management table 44 held by each first storage node 11. The secondary site management software 34 also transmits differential data before and after the above-described update of the path management table 45 and volume pair management table 44 held by itself to each second storage node 30 in the secondary site 3, thereby similarly updating the path management table 45 and volume pair management table 44 held by each second storage node 30.

[0222] As a result of the above, a remote path 7 is established between the standby specified storage node 11 and the standby destination storage node 30. The primary site management software 26 and the secondary site management software 34 may further cooperate to create an iSCSI initiator in the standby specified storage node 11 that is associated with the primary volume PVOL corresponding to the selected standby secondary volume SVOL, and to create an iSCSI target in the standby destination storage node 30 that is associated with the selected standby secondary volume SVOL, and to perform processing up to establishing a session between these iSCSI initiators and iSCSI targets.

[0223] Next, the pair management software 6 collects from the primary site management device 12 information required to delete the remote copy path 7 connecting the removed storage node 30, which is the migration source of the selected standby secondary volume SVOL, and the specified standby storage node 11 (S40). Specifically, the pair management software 6 extracts the node ID of the removed storage node 30 from the relocation information notified by the secondary site management software 34, and queries the primary site management software 26 for the IP addresses of each port 23 provided in the removed storage node 30 to which the node ID has been assigned.

[0224] The primary site management software 26, which has received this inquiry, acquires the port ID of each port 23 of the reduced storage node 30 from the record corresponding to the reduced storage node 30 in the system configuration table 40 (FIG. 5) held by itself. The primary site management software 26 then acquires the IP address of each port 23 of the reduced storage node 30, whose port ID has been acquired as described above, from the port management table 42 (FIG. 7) held by itself. The primary site management software 26 then transmits the acquired IP addresses of each port 23 of the reduced storage node 30 to the pair management software 6.

[0225] Then, based on the IP addresses of the ports 23 of the reduced storage node 30 thus obtained and the IP addresses of the ports 23 of the specified standby storage node 11 obtained in step S32, the pair management software 26 instructs the primary site management software 26 and the secondary site management software 34 to delete the remote copy path 7 connecting the specified standby storage node 11 and the reduced storage node 30 (S41). This instruction includes information on the IP addresses of the ports 23 of the specified standby storage node 11 and the IP addresses of the ports 23 of the reduced storage node 30.

[0226] Thus, the primary site management software 26 and secondary site management software 34 that receive this instruction identify, from among the records of the path management table 45 that they hold, a record in which at least one combination of the IP address of each port 23 of the standby specified storage node 11 and the IP address of each port 23 of the removed storage node 30 is stored in the first or second path column 45CA, 45CB, and deletes that record from the path management table 45.

[0227] The primary site management software 26 also transmits differential data before and after the above-described update of the path management table 45 held by itself to each first storage node 11 in the primary site 2, thereby causing each first storage node 11 to similarly update its own path management table 45. The secondary site management software 34 also transmits differential data before and after the above-described update of the path management table 45 held by itself to each second storage node 30 in the secondary site 3, thereby causing each second storage node 30 to similarly update its own path management table 45. As a result of the above, the remote path 7 set between the specified standby storage node 11 and the removed storage node 30 is deleted.

[0228] Thereafter, the pair management software 26 determines (S42) whether or not the processing from step S38 onwards has been completed for all standby secondary volumes SVOL that have been moved from the removed storage node 30 to other second storage nodes 30, which is recognized from the relocation information notified from the secondary site management software 34. If the pair management software 26 obtains a negative result in this determination, it returns to step S37, and thereafter repeats the processing from step S37 to step S42 while sequentially switching the standby secondary volume SVOL selected in step S37 to other corresponding standby secondary volumes SVOL for which step S38 onwards has not been processed.

[0229] By this repeated process, remote copy paths 7 connecting each standby secondary volume SVOL moved from the reduced storage node 30 to another second storage node 30 to the primary volume PVOL corresponding to that standby secondary volume SVOL are sequentially established between the corresponding standby specified storage node 11 and the standby destination storage node 30, and the original remote copy paths 7 established between the reduced storage node 30, which is the migration source of that standby secondary volume SVOL, and the standby specified storage node 11 are sequentially deleted.

[0230] Then, when the pair management software 6 eventually completes the processing of steps S38 to S41 for each standby secondary volume SVOL that has been moved from the removed storage node 30 to another second storage node 30 and obtains a positive result in step S42, it terminates the storage node removal processing on the pair management software side.

[0231] (4) Effects of this embodiment As described above, in the storage system 1 of this embodiment, when a second storage node 30 is added or removed within the site 3, under the control of the pair management device 5, a new remote copy path 7 is re-established on the second storage node 30 to which the storage control software 35 that was relocated in conjunction with the addition or removal of the second storage node 30 and the secondary volume SVOL for which the storage control software 35 has ownership are relocated, and the corresponding original remote copy path 7 that had been set on the second storage node 30 from which the second storage node 30 was relocated is deleted.

[0232] Therefore, in this storage system 1, even after the number of second storage nodes 30 is increased or decreased, remote copy can be performed between the second storage node 30 to which the relocated storage control software 35 and the secondary volume SVOL for which the storage control software 35 has ownership are relocated, and the first storage node 11 in which the primary volume PVOL associated with the secondary volume SVOL is located, via the newly created remote copy path 7.

[0233] Therefore, according to this storage system 1, even if a failure occurs in the active storage control software 35 or the second storage node 30 on which the active storage control software 35 is located and a failover is executed, the transfer of journal data JNL within the secondary site 3 caused by the addition or removal of the second storage node 30 can be suppressed, thereby preventing a decrease in performance of the remote copy process.

[0234] (5) Other embodiments In the above embodiment, the primary site management device 12 is provided separately from the first storage node 11 at the primary site 2, but the present invention is not limited to this. The functions of the primary site management device 12 may be implemented in any of the first storage nodes 11, and the primary site management device 12 may be omitted.

[0235] Similarly, in the above embodiment, the secondary site management device 31 is provided separately from the second storage node 30 at the secondary site 3, but the present invention is not limited to this. The functions of the secondary site management device 31 may be implemented in any of the second storage nodes 30, and the secondary site management device 31 may be omitted.

[0236] Furthermore, in the above embodiment, the present invention has been described as being applied to adding or removing a second storage node 30 at the secondary site 3, but the present invention is not limited to this and can be similarly applied to adding or removing a first storage node 11 at the primary site 2.

[0237] Furthermore, in the above embodiment, in steps S12 and S14 of the storage node addition processing on the pair management software side, and in steps S32 and S34 of the storage node removal processing on the pair management software side, the pair management software 6 has been described as acquiring the necessary information from the primary site management device 5, but the present invention is not limited to this, and the information may be acquired from the secondary site management device 31 or the first or second storage node 11, 30. Furthermore, the information on the primary site 2 may be acquired from the primary site management device 5, and the information on the secondary site 3 may be acquired from the secondary site management device 31.

[0238] Furthermore, in the above-described embodiment, the pair management device 5 is configured from one computer device, but the present invention is not limited to this, and the pair management device 5 may also be configured from a distributed computing system made up of multiple computer devices. [Industrial Applicability]

[0239] The present invention can be applied to a storage system having one or more first storage nodes installed at a primary site and a plurality of second storage nodes installed at a secondary site. [Explanation of symbols]

[0240] 1...storage system, 2...primary site, 3...secondary site, 5...pair management device, 6...pair management software, 7...remote copy path, 10...host device, 11...first storage node, 12...primary site management device, 21...control unit, 22...storage device, 23...port, 24...processor, 25...memory, 30...second storage node (additional storage node), reduced storage node, 31 secondary site management device, 33...cluster, 34...secondary site management software, 35...storage control software, PVOL...primary volume, SVOL...secondary volume.

Claims

1. In a storage system having one or more first storage nodes installed at a primary site and a plurality of second storage nodes installed at a secondary site, a primary volume provided to a host device as a storage area for reading and writing data is provided in the first storage node; a secondary volume is provided in the second storage node as a storage area for backing up the data written in the corresponding primary volume; a remote copy path is established between the first storage node and the second storage node in which the secondary volume corresponding to the primary volume provided in the first storage node is provided, for remotely copying the data written in the primary volume to the secondary volume; a first management device that, when the second storage node is added or removed at the secondary site, establishes a new remote copy path between the secondary volume moved in accordance with the addition or removal and the first storage node in which the primary volume associated with the secondary volume is provided, and deletes the original remote copy path that was established between the second storage node that is the source of the secondary volume moved in accordance with the addition or removal and the first storage node. A storage system comprising:

2. The first management device is installed in a location separate from the primary site and the secondary site.

2. The storage system according to claim 1.

3. a second management device that is disposed at the primary site and manages each of the first storage nodes installed at the primary site; a third management device that is arranged at the secondary site and manages each of the second storage nodes installed at the secondary site; Furthermore, the first management device, collecting necessary information from the second and / or third management devices when the second storage node is added or removed at the secondary site; Instructing the second and third management devices to set a new remote copy path and delete the original remote copy path based on the collected information.

2. The storage system according to claim 1.

4. the first management device, When the second storage node is added, information on the secondary volume moved to the added second storage node, information on the second storage node from which the secondary volume is relocated, and information on the added second storage node are obtained from the third management device; acquiring, from the second or third management device, an address of the first storage node in which the primary volume corresponding to the secondary volume moved to the added second storage node exists, and an address of the added second storage node, based on each of the acquired information; Instructing the second and third management devices to set a new remote copy path between the first storage node and the added second storage node based on each of the acquired addresses.

4. The storage system according to claim 3.

5. the first management device, acquiring, from the second or third management device, an address of the second storage node that is the source of the secondary volume that has been moved to the added second storage node, based on the information acquired from the third management device; Based on the acquired address, instruct the second and third management devices to delete the original remote copy path between the first storage node where the primary volume corresponding to the moved secondary volume exists and the second storage node from which the secondary volume has been moved.

5. The storage system according to claim 4.

6. the first management device, When the second storage node is removed, information on the secondary volume moved from the removed second storage node to another second storage node, information on the second storage node to which the secondary volume has been moved, and information on the removed second storage node are obtained from the third management device; acquires from the second or third management device, based on the acquired information, an address of the first storage node in which the primary volume associated with the secondary volume moved from the removed second storage node to another second storage node exists, and an address of the second storage node to which the secondary volume has been moved from the removed second storage node; Instruct the second and third management devices to set a new remote copy path between the first storage node where the primary volume corresponding to the moved secondary volume exists and the second storage node to which the secondary volume is to be moved, based on each of the acquired addresses.

4. The storage system according to claim 3.

7. the first management device, acquiring an address of the removed second storage node from the second or third management device based on the information acquired from the third management device; Based on the acquired address, the second and third management devices are instructed to delete the original remote copy path between the first storage node in which the primary volume corresponding to the moved secondary volume exists and the removed second storage node.

7. The storage system according to claim 6.

8. 1. A path management method executed in a storage system having one or more first storage nodes installed at a primary site and a plurality of second storage nodes installed at a secondary site, comprising: a primary volume provided to a host device as a storage area for reading and writing data is provided in the first storage node; a secondary volume is provided in the second storage node as a storage area for backing up the data written in the corresponding primary volume; a remote copy path is established between the first storage node and the second storage node in which the secondary volume corresponding to the primary volume provided in the first storage node is provided, for remotely copying the data written in the primary volume to the secondary volume; the storage system includes a first management device, a second management device that is arranged at the primary site and manages each of the first storage nodes installed at the primary site, and a third management device that is arranged at the secondary site and manages each of the second storage nodes installed at the secondary site; a first step in which the first management device collects necessary information from the second and / or third management device when the second storage node is added or removed at the secondary site; a second step in which the first management device, based on the collected information, establishes a new remote copy path between the secondary volume moved due to the expansion / reduction and the first storage node in which the primary volume associated with the secondary volume is provided, and instructs the second and third management devices to delete the original remote copy path that was established between the second storage node that is the migration source of the secondary volume moved due to the expansion / reduction and the first storage node. A path management method comprising:

9. In the first step, the first management device When the second storage node is added, information on the secondary volume moved to the added second storage node, information on the second storage node from which the secondary volume is relocated, and information on the added second storage node are obtained from the third management device; acquiring, from the second or third management device, an address of the first storage node in which the primary volume corresponding to the secondary volume moved to the added second storage node exists, and an address of the added second storage node, based on each of the acquired information; In the second step, the first management device Instructing the second and third management devices to set a new remote copy path between the first storage node and the added second storage node based on each of the acquired addresses.

9. The path management method according to claim 8.

10. In the first step, the first management device acquiring, from the second or third management device, an address of the second storage node that is the source of the secondary volume that has been moved to the added second storage node, based on the information acquired from the third management device; In the second step, the first management device Based on the acquired address, instruct the second and third management devices to delete the original remote copy path between the first storage node where the primary volume corresponding to the moved secondary volume exists and the second storage node from which the secondary volume has been moved.

10. The path management method according to claim 9.

11. In the first step, the first management device When the second storage node is removed, information on the secondary volume moved from the removed second storage node to another second storage node, information on the second storage node to which the secondary volume has been moved, and information on the removed second storage node are obtained from the third management device; acquires from the second or third management device, based on the acquired information, an address of the first storage node in which the primary volume associated with the secondary volume moved from the removed second storage node to another second storage node exists, and an address of the second storage node to which the secondary volume has been moved from the removed second storage node; In the second step, the first management device Instruct the second and third management devices to set a new remote copy path between the first storage node where the primary volume corresponding to the moved secondary volume exists and the second storage node to which the secondary volume is to be moved, based on each of the acquired addresses.

9. The path management method according to claim 8.

12. In the first step, the first management device acquiring an address of the removed second storage node from the second or third management device based on the information acquired from the third management device; In the second step, the first management device Based on the acquired address, the second and third management devices are instructed to delete the original remote copy path between the first storage node in which the primary volume corresponding to the moved secondary volume exists and the removed second storage node.

12. The path management method according to claim 11.

Citation Information

Patent Citations

  • Computer system and management method for computer

    US20180032254A1