Storage management system, storage management method, and storage management program

The storage management system addresses inefficiencies by managing volumes with placement labels, ensuring regulatory compliance and optimizing storage through risk detection and alert mechanisms.

JP2026001344APending Publication Date: 2026-01-07HITACHI VANTARA LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024098588
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-19
Publication Date
2026-01-07

Smart Images

  • Figure 2026001344000001_ABST
    Figure 2026001344000001_ABST
Patent Text Reader

Abstract

To appropriately manage a volume.SOLUTION: In a storage management system 11 for managing a plurality of volumes, each volume can be managed by assigning a data protection type label that defines an arrangement area of data related to the volume, and a CPU22 of the storage management system 11 determines whether or not an arrangement position of data related to a predetermined volume is appropriate based on the data protection type label assigned to the predetermined volume, and outputs an alert indicating that the arrangement area of the data is not appropriate when it is determined that the arrangement area of the data related to the predetermined volume is not appropriate.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technique for managing the allocation of data relating to volumes in a storage. [Background technology]

[0002] In storage operations, from the perspective of data protection, it is necessary to pay attention to the management of volumes and the transfer destination of volume data depending on the type of data, etc.

[0003] For example, in areas where legal regulations, such as the General Data Protection Regulation (GDPR), restrict the storage location of data containing sensitive information such as personal information, violations of the storage location of data containing sensitive information such as personal information can result in penalties such as fines. Furthermore, for example, in cloud services, if the remote copy destination region is set incorrectly due to a configuration error on the part of the cloud service or the user, there is a risk of violating legal regulations. Furthermore, from the perspective of disaster recovery, if the remote copy destination of data is located in a nearby region, there is a risk that disaster recovery will not function properly.

[0004] For example, Patent Document 1 discloses a technology for determining legal or contractual risks in the migration of applications and data between data centers. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] International Publication No. 2014 / 041761 Summary of the Invention [Problem to be solved by the invention]

[0006] In storage operations, it may be preferable to manage data storage locations in smaller data units rather than in units of applications. For example, if only a small portion of the data used by an application is sensitive information, storing all of the data used by the application in a location that satisfies legal regulations may reduce storage utilization efficiency or be cost-inefficient.

[0007] The present invention has been made in view of the above circumstances, and its object is to provide a technique that can appropriately manage volumes. [Means for solving the problem]

[0008] In order to achieve the above object, a storage management system according to one aspect is a storage management system that manages multiple volumes, and is capable of managing each volume by assigning a placement specification label that specifies the placement area of ​​data related to the volume, and a processor of the storage management system determines whether the placement location of data related to a specified volume is appropriate based on the placement specification label assigned to the specified volume, and if it determines that the placement area of ​​data related to the specified volume is not appropriate, outputs an alert indicating that the placement area of ​​the data is not appropriate. [Effects of the Invention]

[0009] According to the present invention, volumes can be managed appropriately. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram showing the overall configuration of a computer system according to one embodiment. [Figure 2] FIG. 2 is a hardware configuration diagram of a storage system according to an embodiment. [Figure 3] FIG. 3 is a functional configuration diagram relating to volume risk management in a computer system according to one embodiment. [Figure 4] FIG. 4 is a configuration diagram of a combination management table according to an embodiment. [Figure 5] FIG. 5 is a diagram illustrating the configuration of a risk table according to an embodiment. [Figure 6] FIG. 6 is a diagram showing the configuration of a distance table according to an embodiment. [Figure 7] FIG. 7 is a diagram illustrating the configuration of a requirement fulfilling region table according to one embodiment. [Figure 8] FIG. 8 is a diagram showing the structure of a price table according to an embodiment. [Figure 9] FIG. 9 is a functional configuration diagram relating to copy risk management in a computer system according to one embodiment. [Figure 10] FIG. 10 is a diagram illustrating an overview of the volume risk management process according to one embodiment. [Figure 11] FIG. 11 is a diagram illustrating an outline of a first processing operation after volume risk detection according to one embodiment. [Figure 12] FIG. 12 is a diagram illustrating an outline of a second processing operation after volume risk detection according to one embodiment. [Figure 13] FIG. 13 is a diagram illustrating an outline of the processing operation of copy risk evaluation according to one embodiment. [Figure 14] FIG. 14 is a diagram illustrating an outline of a first processing operation after a copy risk is detected according to an embodiment. [Figure 15] FIG. 15 is a diagram illustrating an outline of a second processing operation after a copy risk is detected according to an embodiment. [Figure 16] FIG. 16 is a flowchart of a volume setting process according to an embodiment. [Figure 17] FIG. 17 is a flowchart of a volume risk assessment process according to one embodiment. [Figure 18] FIG. 18 is a flowchart of a recommended area estimation process according to an embodiment. [Figure 19] FIG. 19 is a flowchart of a volume risk alert handling process according to an embodiment. [Figure 20] FIG. 20 is a flowchart of a copy setting process according to an embodiment. [Figure 21] FIG. 21 is a flowchart of a copy risk assessment process according to one embodiment. [Figure 22] FIG. 22 is a flowchart of a copy risk alert handling process according to an embodiment. [Figure 23] FIG. 23 is a flowchart of a pre-copy process according to one embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] The following description of the embodiments will be given with reference to the drawings. Note that the embodiments described below do not limit the scope of the invention as claimed, and not all of the elements and combinations thereof described in the embodiments are necessarily essential to the solution of the invention.

[0012] In the following explanation, information may be described using the expression "AAA table", but the information may be expressed in any data structure. In other words, to show that the information does not depend on the data structure, the "AAA table" can be called "AAA information".

[0013] In the following description, processing may be described with a "program" as the operating entity. However, since a program is executed by a processor to perform a predetermined process using at least one of a storage unit and an interface unit as appropriate, the subject of the process may also be the processor (or a computer or computer system having a processor). A program may be installed on a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. In the following description, two or more programs may be realized as one program, or one program may be realized as two or more programs. At least a portion of the processing realized by executing a program may be realized by a hardware circuit (for example, an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array)).

[0014] FIG. 1 is a diagram showing the overall configuration of a computer system according to one embodiment.

[0015] The computer system 1 comprises a management terminal 2 and a plurality of storage systems 10 (10A, 10B, etc.). The management terminal 2 and the storage systems 10 are connected via a network 5. The network 5 is, for example, a communication path such as a wired LAN (Local Area Network), a wireless LAN, or a WAN (Wide Area Network).

[0016] The management terminal 2 is configured by a computer such as a PC (Personal Computer), and is a terminal operated by a user (administrator) to manage the volumes stored in the storage system 10.

[0017] A storage system 10 (10A, 10B) is configured with one or more physical or virtual servers. The storage system 10 includes a storage management system 11 and a storage node 12. The storage management system 11 and the storage node 12 may each be configured with a physical server or a virtual server.

[0018] The storage node 12 has a storage device that stores a volume, and performs processing to write volume data to the storage device and read volume data from the storage device. In this embodiment, a data protection type label (an example of a placement specification label) that is information that specifies the area where data is to be placed can be associated with the volume. The information that specifies the area where data is to be placed may be information that specifies the area where data may be placed, or may be information that specifies the area where data may not be placed. Data protection type labels include "No Concerns" (e.g., a numeric value of 0), indicating that there are no protection concerns for the region where the data is deployed; "GDPR" (e.g., a numeric value of 1), indicating that the data is subject to the GDPR (a legal regulation); "CCPA" (California Consumer Privacy Act) (e.g., a numeric value of 2), indicating that the data is subject to the Japan Personal Information Protection Act (a legal regulation); "Disaster Protection (Country)" (e.g., a numeric value of 4), indicating that the data is subject to disaster protection by setting the destination country to a country different from the source country for disaster protection purposes; and "Disaster Protection (Distance)" (e.g., a numeric value of 5), indicating that the data is subject to disaster protection by setting the destination country to a specified distance or more from the source country for disaster protection purposes. Multiple data protection type labels can be selected and set as long as there are no contradictions in the protection targets.

[0019] The storage management system 11 performs management processing for volumes stored in the storage node 12. In this embodiment, the storage management system 11 can set a data protection type label for a volume in accordance with an instruction from a user.

[0020] FIG. 2 is a hardware configuration diagram of a storage system according to an embodiment.

[0021] The storage system 10 is configured by a computer such as a PC (Personal Computer) or a general-purpose server, for example. The storage system 10 includes a communication interface (I / F) 21, a CPU (Central Processing Unit) 22, an input device 23, a storage device 24, a memory 25, and a display device 26. The communication I / F 21, the CPU 22, the input device 23, the storage device 24, the memory 25, and the display device 26 are connected via a bus 27.

[0022] The communication I / F 21 is, for example, an interface such as a wired LAN card or a wireless LAN card, and communicates with other devices (for example, the management terminal 2 or other storage systems 10) via the network 5.

[0023] The CPU 22 is an example of a processor, and executes various processes according to programs stored in the memory 25 and / or the storage device 24 .

[0024] The memory 25 is, for example, a RAM (RANDOM ACCESS MEMORY), and stores programs executed by the CPU 22 and necessary information.

[0025] The storage device 24 is, for example, a hard disk or flash memory, and stores programs executed by the CPU 22, data used by the CPU 22, volumes of user data used by users, etc. In this embodiment, the storage device 24 stores a risk analysis program 24a as a program, and stores a combination management table 41, a risk table 42, a distance table 43, a requirement fulfillment area table 44, a price table 45, time zone setting information 46, etc., which will be described later, as information.

[0026] The input device 23 is, for example, a mouse, a keyboard, etc., and accepts information input by a user. The display device 26 is, for example, a display, and displays and outputs a user interface including various types of information.

[0027] 3 is a functional configuration diagram relating to volume risk management in a computer system according to one embodiment. Here, volume risk refers to the risk of the location of the volume itself, relating to data protection requirements.

[0028] The storage management system 11 of the storage system 10 includes a notification unit 31, a recommendation processing unit 32, a risk analysis processing unit 33, a volume management unit 34, a combination management table 41, a risk table 42, a distance table 43, a requirement fulfillment area table 44, a price table 45, and time zone setting information 46. The notification unit 31, the recommendation processing unit 32, the risk analysis processing unit 33, and the volume management unit 34 are configured by the CPU 22 executing the risk analysis program 24a.

[0029] FIG. 4 is a configuration diagram of a combination management table according to an embodiment.

[0030] The combination management table 41 is a table for managing information on whether or not a combination of data protection type labels set for a volume is permitted.

[0031] The combination management table 41 stores each data protection type that can be set as a data protection type label on both the vertical and horizontal axes, and the field at the intersection of the data protection type on the vertical axis and the data protection type on the horizontal axis indicates whether the combination of two corresponding data protection types is allowed (Allowed) or not allowed (Not Allowed).

[0032] According to the combination management table 41 in Figure 4, for example, the data protection type labels GDPR and CCPR are not permitted to be set in combination, but the data protection type labels GDPR and disaster protection (country) are permitted to be set in combination.

[0033] FIG. 5 is a diagram illustrating the configuration of a risk table according to an embodiment.

[0034] The risk table 42 is a table for managing information on whether or not a region is at risk when placing a volume to be protected, which is assigned a data protection type.

[0035] In the risk table 42, the vertical axis stores each settable data protection type, and the horizontal axis stores multiple regions, and the field at the intersection of the data protection type on the vertical axis and the region on the horizontal axis stores whether or not there is a risk in placing a volume of the corresponding data protection type in the storage system 10 in the corresponding region. Note that for disaster protection (country) and disaster protection (distance), whether or not there is a risk is determined by the relationship between the copy source and the copy destination, so whether or not there is a risk is not set for each region.

[0036] According to the risk table 42 in Figure 5, for example, it can be seen that there is no risk in placing volumes protected by the GDPR in storage systems 10 in Berlin, Germany (DE / Berlin), Tokyo, Japan (JP / Tokyo), and Chicago, USA (US / Chicago).

[0037] FIG. 6 is a diagram showing the configuration of a distance table according to an embodiment.

[0038] The distance table 43 is a table that manages information about the distance between regions. In the distance table 43, multiple regions are stored on the vertical and horizontal axes, and the distance between these regions is stored in the field that is the intersection of the region on the vertical axis and the region on the horizontal axis.

[0039] According to the distance table 43 in FIG. 6, for example, it can be seen that the distance between Shanghai, China (CN / Shanghai) and Berlin, Germany (DE / Berlin) is 8392 km.

[0040] FIG. 7 is a diagram illustrating the configuration of a requirement fulfilling region table according to one embodiment.

[0041] The requirement satisfying region table 44 is a table for managing regions that satisfy (fulfill) the requirements of a data protection type. The requirement satisfying region table 44 stores an entry for each data protection type. An entry in the requirement satisfying region table 44 includes fields for a data protection type 44a and a requirement satisfying region 44b. The data protection type 44a stores the data protection type corresponding to the entry. The requirement satisfying region 44b stores the name of a region that satisfies the requirements for data of the data protection type corresponding to the entry. Here, if the storage system 10 is provided by AWS (Amazon Web Service: AWS is a registered trademark), the name of the region can be used as the region name.

[0042] FIG. 8 is a diagram showing the structure of a price table according to an embodiment.

[0043] The price table 45 stores the price of the storage system 10 usage fee in the region where the storage system 10 is located. The price table 45 stores an entry for each region. An entry in the price table 45 includes fields for region 45a and price 45b. The region 45a stores the name of the region corresponding to the entry. The price 45b stores the price (deployment cost) of the storage system 10 usage fee in the region corresponding to the entry.

[0044] The time zone setting information 46 includes information on the time zone ID and country code of the region where the storage system 10, including the storage node 12 managed by the storage management system 11, is located. The time zone ID and country code may be values ​​that conform to the time zone database of the IANA (International Assigned Numbers Authority), for example.

[0045] Returning to the explanation of Figure 3, the volume management unit 34 receives a designation of a data protection type to be stored in the storage node 12 or assigned to a volume that has been stored therein, based on an instruction from the administrator via the management terminal 2, and performs processing to associate a data protection type label with the volume. When receiving a combination of multiple data protection types, the volume management unit 34 refers to the combination management table 41 so that only combinations of multiple data protection types that are permitted can be specified. The volume management unit 34 receives a volume (target volume) that is to be subjected to risk assessment related to the volume's location area from the risk analysis processing unit 33, obtains a data protection type label associated with the target volume, and notifies the risk analysis processing unit 33 of this.

[0046] The volume management unit 34 also acquires snapshots of volumes stored in the storage node 12, i.e., creates snapshot volumes in the storage node 12. The timing for acquiring a snapshot may be, for example, one or more of the following: when the volume is created, when the setting of the data protection type label for the volume is changed, when remote copy is set, or periodically (for example, once an hour). The volume for which a snapshot is acquired may be a volume for which a data protection type other than "no concern" is set in the data protection type label. The snapshot includes information about the data protection type label associated with the volume when the snapshot is acquired.

[0047] The risk analysis processing unit 33 receives the designation of the target volume from the administrator via the management terminal 2, and notifies the volume management unit 34 of an instruction to obtain the data protection type of the target volume. The risk analysis processing unit 33 receives the data protection type of the target volume from the volume management unit 34. The risk analysis processing unit 33 refers to the time zone setting information 46 and the risk table 42, and performs analysis processing to analyze whether there is a risk (volume risk) in the location area (location) of the target volume regarding the data protection type indicated by the data protection type label for the target volume, and notifies the recommendation processing unit 32 and the notification unit 31 of the risk analysis result.

[0048] The recommendation processing unit 32 receives from the risk analysis processing unit 33 information on whether there is a volume risk and information on the area where the volume is located, and if it receives information on the existence of a volume risk, it refers to the requirement fulfillment area table 44 to obtain information on areas that satisfy the requirements of the data protection type for the target volume, refers to the price table 45 to obtain information on areas with low usage fees from among the obtained areas, and passes the obtained area information to the notification unit 31 as a recommendation estimation result.

[0049] The notification unit 31 receives a risk analysis result 47 including the presence or absence of a volume risk and the time of risk analysis execution from the risk analysis processing unit 33, and if there is a volume risk, notifies an alert to the management terminal 2. At this time, the notification unit 31 may also notify the management terminal 2 of the recommendation estimation result received from the recommendation processing unit 32.

[0050] 9 is a functional configuration diagram relating to copy risk management in a computer system according to one embodiment. Here, copy risk refers to the risk of the location of the copy destination volume with respect to the requirements of the data protection type.

[0051] 3, the storage management system 11A includes a remote copy setting management unit 35. The remote copy setting management unit 35 is configured by the CPU 22 executing the risk analysis program 24a. Furthermore, the storage management system 11B of the storage system 10B stores time zone setting information 46.

[0052] The remote copy setting management unit 35 receives designation of source and destination volumes for remote copying based on instructions from the administrator from the management terminal 2, and stores copy pair information relating to the source and destination volumes in the storage node 12. Furthermore, based on instructions from the administrator from the management terminal 2, the remote copy setting management unit 35 receives designation of a data protection type to be assigned to the source volume, and performs processing to associate a data protection type label with the volume.

[0053] The remote copy setting management unit 35 receives from the risk analysis processing unit 33 the volume (target volume) of the remote copy source that is the target of copy risk judgment, acquires the data protection type label associated with the target volume, and notifies the risk analysis processing unit 33.

[0054] The remote copy setting management unit 35 receives a restoration instruction for the copy source of the remote copy that is the target of copy risk judgment from the risk analysis processing unit 33, and executes restoration processing for the copy source volume. The remote copy setting management unit 35 receives a shredding instruction for the copy destination of the remote copy that is the target of copy risk judgment from the risk analysis processing unit 33, deletes the copy destination volume, and deletes the copy pair information of the target remote copy.

[0055] The risk analysis processor 33 receives a designation of a copy source volume (target volume) from the administrator via the management terminal 2 and notifies the remote copy setting manager 35 of an instruction to obtain the data protection type of the target volume. The risk analysis processor 33 receives the data protection type of the target volume from the remote copy setting manager 35. The risk analysis processor 33 obtains time zone setting information 46 of the copy destination storage system 10 from the copy destination storage management system 11B. The time zone setting information 46 may be obtained from the copy destination storage management system 11B via HTTPS communication, or may be obtained using a unique protocol when creating a copy pair. The risk analysis processor 33 refers to the time zone setting information 46, the risk table 42, and the distance table 43, and performs an analysis process to analyze whether there is a risk (copy risk) in the location area of ​​the target volume that is the copy destination, with respect to the data protection requirements indicated by the data protection type of the target volume, and notifies the recommendation processor 32 and the notification unit 31 of the risk analysis result.

[0056] Next, an overview of various processes in the computer system 1 will be explained.

[0057] FIG. 10 is a diagram illustrating an overview of the volume risk management process according to one embodiment.

[0058] The risk analysis program 24a acquires region information from the time zone setting information 46, estimates the region of the storage node 12, and evaluates the volume risk based on the data protection type of the target volume.

[0059] If there is a volume risk, the risk analysis program 24a outputs an alert 51 indicating, for example, that the region of the storage system in which the volume is located is not appropriate for the data protection type to the management terminal 2. The risk analysis program 24a may include in the alert 51 recommendation information recommending a storage system 10 in a region with no risk.

[0060] The risk analysis program 24a performs processing to acquire a snapshot of the volume protected by GDPR in the storage node 12 at a predetermined point in time.

[0061] FIG. 11 is a diagram illustrating an outline of a first processing operation after volume risk detection according to one embodiment.

[0062] After outputting an alert 51 to the management terminal 2 indicating that there is a volume risk, the risk analysis program 24a can receive an instruction (rollback instruction) to restore the volume to a predetermined point in time (for example, a point in time when there was no volume risk) from the administrator via the management terminal 2. When an instruction to restore the volume to a predetermined point in time is received from the management terminal 2, the risk analysis program 24a restores the volume based on a snapshot at the predetermined point in time, and restores the volume's volume protection type label to the label at that point in time. This makes it possible to restore the volume to a state where there is no volume risk.

[0063] FIG. 12 is a diagram illustrating an outline of a second processing operation after volume risk detection according to one embodiment.

[0064] The risk analysis program 24a outputs an alert 51 to the management terminal 2 indicating that there is a volume risk, and can then receive a volume shredding instruction (deletion instruction) from the administrator via the management terminal 2 to delete the volume at volume risk. When a volume shredding instruction is received from the management terminal 2, the risk analysis program 24a deletes the volume at volume risk and a snapshot of that volume. This allows the volume at volume risk to be appropriately deleted from the storage node 12 in the region where the risk exists.

[0065] FIG. 13 is a diagram illustrating an outline of the processing operation of copy risk evaluation according to one embodiment.

[0066] The risk analysis program 24a obtains regional information from the time zone setting information 46 of its own storage management system 11 (11A in the example shown in the figure) which is the source of the copy, and obtains regional information from the time zone setting information 46 of the storage management system 11 (11B in the example shown in the figure) of the storage system 10 (10B in the example shown in the figure) which is the destination of the copy, estimates the regions of the storage nodes 12 of the source and destination of the copy, and evaluates the copy risk based on the data protection type of the target volume of the source of the copy.

[0067] If there is a copy risk, the risk analysis program 24a outputs an alert 52 indicating, for example, that the region of the storage system to which the volume is to be copied is not appropriate for the data protection type to the management terminal 2. The risk analysis program 24a may include in the alert 52 recommendation information that recommends a storage system 10 in a region that is a copy destination with no risk.

[0068] FIG. 14 is a diagram illustrating an outline of a first processing operation after a copy risk is detected according to an embodiment.

[0069] After outputting an alert 52 to the management terminal 2 indicating that there is a copy risk, the risk analysis program 24a can receive an instruction from the administrator via the management terminal 2 to restore a volume to a predetermined point in time (for example, a point in time when there is no copy risk). When an instruction to restore a volume to a predetermined point in time is received from the management terminal 2, the risk analysis program 24a restores the volume based on a snapshot taken at the predetermined point in time and restores the volume's volume protection type label to the label at that point in time, and also instructs the copy-destination storage management system 11 to restore the copy-destination volume based on the snapshot taken at the corresponding point in time. As a result, the copy-destination storage management system 11 restores the copy-destination volume based on the snapshot and restores the volume's volume protection type label to the label at the time of the snapshot. This makes it possible to restore the copy-source and copy-destination volumes to a state where there is no copy risk.

[0070] FIG. 15 is a diagram illustrating an outline of a second processing operation after a copy risk is detected according to an embodiment.

[0071] After outputting an alert 52 to the management terminal 2 indicating that there is a copy risk, the risk analysis program 24a can receive a volume shredding instruction from the administrator via the management terminal 2 to delete a copy-risk destination volume. When a volume shredding instruction is received from the management terminal 2, the risk analysis program 24a deletes the copy pair information and sends a volume shredding instruction for the copy-destination volume to the copy-destination storage management system 11. The copy-destination storage management system 11 deletes the copy-destination volume and deletes snapshots for this volume in accordance with the volume shredding instruction. This allows copy-risk destination volumes to be appropriately deleted from storage nodes 12 in risky areas.

[0072] Next, various processes in the computer system 1 will be described in detail.

[0073] First, the volume setting process for setting a volume in the storage system 10 will be described.

[0074] FIG. 16 is a flowchart of a volume setting process according to an embodiment.

[0075] When the risk analysis program 24a of the storage management system 11 receives an instruction to display a volume setting screen from the management terminal 2, it causes the management terminal 2 to display the volume setting screen (S11). The volume setting screen receives an instruction to create a volume from the administrator of the management terminal 2 and a designation of the data protection type for the volume.

[0076] The risk analysis program 24a receives the data protection type designated for the volume by the administrator from the management terminal 2, and sets a data protection type label for the volume (S12).

[0077] The risk analysis program 24a determines whether or not a data protection type label other than "no concern" has been assigned to the target volume (S13).

[0078] As a result, if it is determined that no data protection type label other than "no concern" has been assigned, that is, that a data protection type label of "no concern" has been assigned (S13: No), the risk analysis program 24a terminates the volume setting process.

[0079] On the other hand, if it is determined that a data protection type label other than "no concern" has been assigned (S13: Yes), the risk analysis program 24a creates a snapshot of the target volume (S14) and executes a volume risk assessment process (see Figure 17) to evaluate whether or not there is a volume risk for the target volume (S15).

[0080] Next, the risk analysis program 24a determines whether or not there is a volume risk in the target volume as a result of the volume risk evaluation process (S16).

[0081] As a result, if it is determined that there is no volume risk in the target volume (S16: No), the risk analysis program 24a ends the volume setting process.

[0082] On the other hand, if it is determined that the target volume has a volume risk (S16: Yes), the risk analysis program 24a executes a recommended area estimation process (see FIG. 18) to estimate an area of ​​the storage system 10 that has no volume risk (S17).

[0083] Next, the risk analysis program 24a causes the management terminal 2 to output an alert calling attention to the presence of a volume risk and a recommendation recommending an area with no volume risk (S18). This allows the administrator to properly understand that there is a volume risk, and to identify a storage system 10 with no risk.

[0084] Next, the risk analysis program 24a executes a volume risk alert handling process (see FIG. 19) (S19), and ends the volume setting process.

[0085] Next, the volume risk assessment process executed in step S15 will be described.

[0086] FIG. 17 is a flowchart of a volume risk assessment process according to one embodiment.

[0087] The risk analysis program 24a references the time zone setting information 46, acquires regional information for the storage system 10, and estimates the location region of the storage system 10 (S21). Next, the risk analysis program 24a acquires the data protection type label for the target volume (S22).

[0088] Next, based on the location area of ​​the storage system 10 and the data protection type label of the target volume, the risk table 42 is referenced to determine whether there is a risk (S23), and if it is determined that there is a risk (S23: Yes), the risk analysis result is determined to be risk present (S24) and the volume risk assessment process is terminated, whereas if it is determined that there is no risk (S23: No), the risk analysis result is determined to be no risk (S25) and the volume risk assessment process is terminated.

[0089] Next, the recommended area estimation process executed in step S17 will be described.

[0090] FIG. 18 is a flowchart of a recommended area estimation process according to an embodiment.

[0091] The risk analysis program 24a refers to the requirement fulfilling region table 44 and acquires the region name of the region that fulfills the requirements based on the data protection type label of the target volume (S31).

[0092] Next, the risk analysis program 24a refers to the price table 45, acquires the area with the lowest price among the areas that satisfy the requirements as a recommended area (S32), and ends the recommended area estimation process.

[0093] Next, the volume risk alert handling process executed in step S19 will be described.

[0094] FIG. 19 is a flowchart of a volume risk alert handling process according to an embodiment.

[0095] The risk analysis program 24a judges whether or not an instruction to roll back the target volume has been received from the management terminal 2 (S41).

[0096] As a result, if an instruction to roll back the target volume has been received (S41: Yes), the risk analysis program 24a selects the snapshot specified in the instruction to roll back, rolls back the target volume using the selected snapshot (S42), and terminates the volume risk alert handling process.

[0097] On the other hand, if an instruction to roll back the target volume has not been received (S41: No), the risk analysis program 24a determines whether an instruction to shred the target volume has been received from the management terminal 2 (S43).

[0098] As a result, if an instruction to shred the target volume has been received (S43: Yes), the risk analysis program 24a shreds the target volume (S44) and ends the volume risk alert handling process. On the other hand, if an instruction to shred the target volume has not been received (S43: No), the risk analysis program 24a ends the volume risk alert handling process.

[0099] According to this volume risk alert handling process, if there is a volume risk, the target volume can be restored to the state it was in at a predetermined point in time, or the target volume can be deleted.

[0100] Next, a copy setting process for setting up remote copying of a volume of the storage system 10 to another storage system 10 will be described.

[0101] FIG. 20 is a flowchart of a copy setting process according to an embodiment.

[0102] The risk analysis program 24a receives a remote copy setting instruction from the administrator via the management terminal 2 (S51). Here, the remote copy setting instruction includes, for example, the specification of the copy source volume and the copy destination storage system 10.

[0103] The risk analysis program 24a determines whether or not a data protection type label other than "no concern" has been assigned to the copy source volume (copy source volume) (S52).

[0104] As a result, if it is determined that no data protection type label other than "no concern" has been assigned, i.e., that a data protection type label of "no concern" has been assigned (S52: No), the risk analysis program 24a terminates the copy setting processing.

[0105] On the other hand, if it is determined that a data protection type label other than "no concern" has been assigned (S52: Yes), the risk analysis program 24a executes a copy risk evaluation process (see FIG. 21) to evaluate whether or not there is a risk (copy risk) for the remote copy to be set (target remote copy) (S53).

[0106] Next, the risk analysis program 24a determines whether or not there is a copy risk in the target remote copy as a result of the copy risk evaluation process (S54).

[0107] As a result, if it is determined that there is no copy risk in the target remote copy (S54: No), the risk analysis program 24a ends the copy setting process.

[0108] On the other hand, if it is determined that there is a copy risk in the target remote copy (S54: Yes), the risk analysis program 24a executes a recommended region estimation process (see FIG. 18) to estimate the region of the copy-destination storage system 10 that has no copy risk (S55). In the recommended region estimation process, in step S31, the risk analysis program 24a references the requirement fulfilling region table 44 and acquires the region name of a region that fulfills the requirements based on the data protection type of the copy-source volume and the region information of the copy-destination volume.

[0109] Next, the risk analysis program 24a causes the management terminal 2 to output an alert that warns of the existence of a copy risk and a recommendation for an area with no copy risk (S56). This allows the administrator to properly understand that there is a copy risk, and to identify a copy destination storage system 10 with no risk.

[0110] Next, the risk analysis program 24a executes the copy risk alert handling process (see FIG. 22) (S57), and ends the copy setting process.

[0111] Next, the copy risk evaluation process executed in step S53 will be described.

[0112] FIG. 21 is a flowchart of a copy risk assessment process according to one embodiment.

[0113] The risk analysis program 24a acquires the time zone setting information 46 from the copy destination storage system 10, and estimates the location region of the copy destination storage system 10 (S61). Next, the risk analysis program 24a references the time zone setting information 46 of the copy source storage system 10, acquires the location information of the storage system 10, and estimates the location region of the storage system 10 (S62). Next, the risk analysis program 24a acquires the data protection type label of the copy source (S63).

[0114] Next, the risk analysis program 24a refers to the risk table 42 based on the locations of the source and destination storage systems 10 and the data protection type of the target volume, and determines whether or not there is a risk (S64). For example, if the data protection type is disaster protection (country), if the country to which the source storage system 10 belongs and the country to which the destination storage system 10 belongs are the same country, it is determined that there is a risk, and if they are not the same country, it is determined that there is no risk. Furthermore, if the data protection type label is disaster protection (distance), it specifies the distance between the region of the source storage system 10 and the region of the destination storage system 10 by referring to the distance table 43, and if the specified distance is less than a predetermined distance (for example, 500 km) taking disaster protection into consideration, it is determined that there is a risk, and if it is 500 km or more, it is determined that there is no risk.

[0115] If it is determined in step S64 that there is a risk (S64: Yes), the risk analysis program 24a determines the risk analysis result to be risky (S65) and terminates the copy risk assessment process, whereas if it is determined that there is no risk (S64: No), it determines the risk analysis result to be no risk (S66) and terminates the copy risk assessment process.

[0116] Next, the copy risk alert handling process executed in step S57 will be described.

[0117] FIG. 22 is a flowchart of a copy risk alert handling process according to an embodiment.

[0118] The risk analysis program 24a judges whether or not an instruction to roll back the volume that is the target of remote copying has been received from the management terminal 2 (S71).

[0119] As a result, if an instruction to roll back the volume has been received (S71: Yes), the risk analysis program 24a selects the destination snapshot specified in the rollback instruction and rolls back the destination volume using the selected snapshot (S72), then selects the source snapshot specified in the rollback instruction and rolls back the source volume using the selected snapshot (S73), and terminates the copy alert handling process.

[0120] On the other hand, if an instruction to roll back the volume to be remote copied has not been received (S71: No), the risk analysis program 24a determines whether an instruction to delete the copy pair information to be remote copied has been received from the management terminal 2 (S74).

[0121] As a result, if an instruction to delete the copy pair information has been received (S74: Yes), the risk analysis program 24a shreds the copy destination volume (S75), deletes the copy destination snapshot (S76), deletes the instructed copy pair information (S77), and ends the copy risk alert handling process.On the other hand, if an instruction to delete the copy pair information has not been received (S74: No), the risk analysis program 24a ends the copy risk alert handling process.

[0122] According to this copy risk alert handling process, if there is a copy risk, the source and destination volumes can be restored to their state at a specified point in time, or the destination volume, snapshot, and copy pair information can be deleted.

[0123] Next, a copy pre-execution process for analyzing copy risks, which is executed before actually performing a remote copy, will be described.

[0124] FIG. 23 is a flowchart of a pre-copy process according to one embodiment.

[0125] The risk analysis program 24a determines whether or not a data protection type label other than "no concern" has been assigned to the copy source volume (S81).

[0126] As a result, if it is determined that no data protection type label other than "no concern" has been assigned, i.e., that a data protection type label of "no concern" has been assigned (S81: No), the risk analysis program 24a terminates the pre-copy processing.

[0127] On the other hand, if it is determined that a data protection type label other than "no concern" has been assigned (S81: Yes), the risk analysis program 24a creates snapshots of the source and destination volumes (S82) and executes a copy risk evaluation process (see Figure 21) to evaluate whether there is a copy risk for the remote copy (S83).

[0128] Next, the risk analysis program 24a determines whether or not there is a copy risk in the remote copy as a result of the copy risk evaluation process (S84).

[0129] As a result, if it is determined that there is no copy risk (S84: No), the risk analysis program 24a ends the copy pre-execution processing.

[0130] On the other hand, if it is determined that there is a copy risk (S84: Yes), the risk analysis program 24a executes a recommended region estimation process (see FIG. 18) to estimate the region of the copy-destination storage system 10 that has no copy risk (S85). In the recommended region estimation process, in step S31, the risk analysis program 24a refers to the requirement-satisfying region table 44 and acquires the region name of a region that satisfies the requirements based on the data protection type of the copy-source volume and the region information of the copy-destination volume.

[0131] Next, the risk analysis program 24a outputs to the management terminal 2 an alert that warns of the existence of a copy risk and a recommendation of a copy destination region that has no copy risk (S86), and ends the processing. This allows the administrator to properly understand that there is a copy risk before performing the copy, and to identify a copy destination storage system 10 that has no copy risk.

[0132] The present invention is not limited to the above-described embodiment, and can be modified appropriately without departing from the spirit of the present invention.

[0133] For example, in the above embodiment, the areas that satisfy the requirements were identified by referring to the requirement-satisfying area table 44, but the present invention is not limited to this, and the areas that satisfy the requirements may also be identified by referring to the risk table 42. [Explanation of symbols]

[0134] 1...computer system, 2...management terminal, 5...network, 10, 10A, 10B...storage system, 11, 11A, 11B...storage management system, 12, 12A, 12B...storage node, 21...communication I / F, 22...CPU, 23...input device, 24...storage device, 24a...risk analysis program, 25...memory, 26...display device

Claims

1. A storage management system for managing a plurality of volumes, Each volume can be managed by assigning a placement specification label that specifies the placement area of ​​data related to the volume, The processor of the storage management system determining whether the location of data related to a predetermined volume is appropriate based on the location definition label assigned to the predetermined volume; When it is determined that the location of the data relating to the predetermined volume is inappropriate, an alert is output indicating that the location of the data is inappropriate. Storage management system.

2. The placement regulation label includes at least one of information on legal regulations that regulate the placement area for data related to the volume and information that regulates the placement area from the viewpoint of disaster protection. The storage management system according to claim 1 .

3. The processor: If it is determined that the location of the data relating to the predetermined volume is not appropriate, a location appropriate for the data is identified, and the identified location is recommended. The storage management system according to claim 1 .

4. The processor: If there are multiple suitable areas as the identified placement area, the most suitable area is identified based on placement cost. The storage management system according to claim 3 .

5. The data relating to the volume is the data of the volume itself. The storage management system according to claim 3 .

6. The data relating to the volume is data of a volume to which the data of the volume is copied. The storage management system according to claim 3 .

7. The processor: A deletion instruction for the data for which the location area is inappropriate is received from the user, and the data is deleted based on the deletion instruction. The storage management system according to claim 3 .

8. The processor: A rollback instruction is received from the user for returning the data in the inappropriate location to a state at a predetermined time, and the data is returned to the state at the predetermined time based on the rollback instruction. The storage management system according to claim 1 .

9. A storage management method for a storage management system that manages multiple volumes, comprising: Each volume can be managed by assigning a placement specification label that specifies the placement location of data related to the volume, The storage management system includes: determining whether the location of data related to a predetermined volume is appropriate based on the location definition label assigned to the predetermined volume; When it is determined that the location of the data related to the predetermined volume is inappropriate, an alert is output indicating that the location of the data is inappropriate. Storage management methods.

10. A storage management program that allows a computer that manages multiple volumes to manage storage, Each volume can be managed by assigning a placement specification label that specifies the placement location of data related to the volume, The computer, determining whether or not the placement position of data related to a predetermined volume is appropriate based on the placement definition label assigned to the predetermined volume; When it is determined that the location of the data related to the predetermined volume is inappropriate, an alert indicating that the location of the data is inappropriate is output. Storage management program.

Citation Information

Patent Citations

  • Risk analysis device, risk analysis method and program

    WO2014041761A1