Storage system management system and storage system management method
Patent Information
- Application Number
- JP2025025660
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2026-09-01
AI Technical Summary
【0020】 本開示によれば、テナント毎の独立したユーザ管理に対応しつつユーザビリティを向上できる。なお、ここに記載された効果は必ずしも限定されるものではなく、本開示中に記載された何れかの効果であってもよい。
Smart Images

Figure 2026139181000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a storage system management system and a storage system management method. Background Art
[0002] In recent years, in large-scale storage-intensive environments, a physical storage apparatus is shared and used by a plurality of companies, a plurality of departments, and the like. In such a large-scale storage-intensive environment, a multi-tenant configuration storage system enables resources of one storage to be distributed or shared among a plurality of tenants (companies or departments).
[0003] A multi-tenant configuration storage system builds a virtual storage system by managing a large number of physical storage apparatuses with software and defining the whole as a large storage apparatus, and provides each tenant with a virtual storage resource obtained by logically partitioning the storage system for each tenant (see Patent Document 2).
[0004] In a multi-tenant configuration storage system, in order to reduce the management load of the entire storage system, multi-tenant management is performed in which storage resources are allocated for each tenant (each company or each department), a storage resource administrator is appointed, and the allocated storage resources are managed individually.
[0005] In a multi-tenant configuration storage system, security mechanisms are required to prevent accidental damage to volumes belonging to another tenant, prevent data leakage to other tenants, and avoid impacting operations by other storage resource administrators, among other security requirements.
[0006] Patent Document 1 discloses a multi-tenant management system that ensures independence between tenants while allowing users to access resources in multiple tenants without separate authentication for each namespace. This multi-tenant management system selects a namespace corresponding to a user from among multiple namespaces and uses the user management information of that namespace to determine if the user is a legitimate user. If the result of this determination is true, the system determines, based on global scope management information common to all tenants (information that associates tenant scopes with resource access ranges), whether the resource to be accessed in accordance with the resource access request from the user belongs to a resource access range corresponding to one of the tenant scopes (labels for the resource access range of each tenant) represented by the user management information of the selected namespace. If the result of this determination is true, the system executes the resource access request. [Prior art documents] [Patent Documents]
[0007] [Patent Document 1] Japanese Patent Publication No. 2024-102743 [Patent Document 2] International Publication No. 2014 / 184893 [Overview of the project] [Problems that the invention aims to solve]
[0008] In multi-tenancy management, roles (permissions) are granted to storage resource administrators at the user group level. The storage resources (sets of storage resources) that can be managed by these roles are then assigned to user groups as resource groups. Storage resource administrators are then granted permissions to perform user management operations and storage resource management operations on the storage resources (sets of storage resources) assigned to the user group to which they belong. Furthermore, in multi-tenancy management, storage users are granted permissions to use the storage resources (sets of storage resources) assigned to the user group to which they belong. Hereafter, storage resource administrators and storage users will be referred to simply as "users" unless there is a specific need to distinguish between them.
[0009] In multi-tenancy management, the storage system's authentication infrastructure authenticates users, authorizes the groups to which authenticated users belong, grants authenticated users permissions to the storage resources assigned to the authorized groups, and enables the operation and use of storage resources within the scope of those permissions, thereby realizing the management of storage resources on a per-tenant basis.
[0010] Multi-tenancy management includes soft multi-tenancy management methods and hard multi-tenancy management methods. Hard multi-tenancy management methods require stricter security and other requirements compared to soft multi-tenancy management methods.
[0011] While soft multi-tenancy management methods manage users on a per-tenant basis, hard multi-tenancy management methods require each tenant to manage users independently (including user IDs and related authentication / authorization information) from the perspective of preventing data leakage to other tenants and ensuring security.
[0012] Soft multi-tenancy management is applicable, for example, when users belonging to each tenant belong to the same common organization and it is acceptable to manage users on a per-tenant basis (such as when a company's storage system is shared by multiple departments within the same company). Hard multi-tenancy management is applicable, for example, when users belonging to each tenant belong to separate organizations and it is necessary to manage users independently in each tenant from the standpoint of preventing data leakage to other tenants and for security reasons (such as when a storage system is shared by multiple organizations on a public cloud).
[0013] One example of a conventional multi-tenancy storage system is a configuration in which all tenants use a common namespace to manage user IDs and other information for identifying users (see paragraphs
[0092] to
[0095] of Patent Document 1 and Figure 8, etc.). However, if this configuration is adopted, it is not possible to assign user IDs with the same name to different tenants. Therefore, since all tenants must use user IDs with different names, usability deteriorates as the number of tenants increases.
[0014] In contrast, other examples of conventional multi-tenancy storage systems can adopt a configuration in which each tenant uses an independent namespace to manage user IDs and other information for identifying users (see paragraphs
[0096] to
[0126] of Patent Document 1 and Figure 9, etc.). In other examples of conventional multi-tenancy storage systems, the namespace selection unit selects a namespace assigned to a tenant based on tenant information obtained from the tenant acquisition unit of the user terminal, and performs user authentication using the user management table assigned to the selected namespace.
[0015] Conventional multi-tenancy storage systems can adopt a configuration that uses an external system (external server) for user authentication from the perspective of improving security and reducing costs. For example, paragraph
[0074] of Patent Document 1 states that it is also possible to entrust the authentication process to an external authentication system.
[0016] However, conventional multi-tenancy storage systems employ a configuration that uses an external system (external server) for user authentication, and when a hardware multi-tenancy management method is applied, they cannot support the independent user management for each tenant required by the hardware multi-tenancy management method (managing user authentication and authorization information, including user IDs), because they do not provide an independent external server for authentication and authorization for each tenant. Furthermore, if an independent external server for authentication and authorization were provided for each tenant, a configuration would be needed in which user authentication requests from each tenant to the storage system are processed by an independent external server corresponding to each tenant, but this configuration is not described in Patent Document 1. In addition, even when adopting a configuration that uses an external system (external server) for user authentication, there is a need to improve usability by enabling the assignment of user IDs with the same name across different tenants.
[0017] This disclosure was made in view of the above issues. Specifically, one of the purposes of this disclosure is to provide a storage system management system and a storage system management method that can improve usability while supporting independent user management for each tenant. [Means for solving the problem]
[0018] To solve the above problems, the storage system management system of the present disclosure is a multi-tenancy storage system management system that includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, and has an authentication external server corresponding to each of the multiple tenants, the authentication unit has a plurality of tenant namespaces corresponding to each of the multiple tenants and applied to user identification information for identifying the user, each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant, and the authentication unit receives authentication information including the user identification information from a host belonging to the tenant and performs user authentication using the external server corresponding to the tenant.
[0019] The storage system management method of this disclosure is a method for managing a multi-tenancy storage system that includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, wherein an external server for authentication corresponding to each of the multiple tenants is used, the authentication unit has a plurality of tenant namespaces corresponding to each of the multiple tenants and applied to user identification information for identifying the user, each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant, and the authentication unit receives authentication information including the user identification information from a host belonging to the tenant and performs user authentication using the external server corresponding to the tenant. [Effects of the Invention]
[0020] This disclosure enables improved usability while supporting independent user management for each tenant. The effects described herein are not necessarily limited to those described herein and may include any of the effects described herein. [Brief explanation of the drawing]
[0021] [Figure 1] FIG. 1 is a diagram illustrating an example system configuration of a management system for a storage system according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram illustrating an example hardware configuration of a storage system. [Figure 3] FIG. 3 is a diagram for explaining a multi-tenancy function of a storage system. [Figure 4] FIG. 4 is a diagram illustrating an example hardware configuration of a storage node. [Figure 5] FIG. 5 is a diagram illustrating an example hardware configuration of a computer applied to a management terminal. [Figure 6] FIG. 6 is a functional block diagram of an authentication infrastructure. [Figure 7] FIG. 7 is a functional block diagram of an external server for a system administrator, an external server for tenant A, an external server for tenant B, and an external server for tenant C. [Figure 8A] FIG. 8A is a diagram for explaining an authentication infrastructure management table. [Figure 8B] FIG. 8B is a diagram for explaining a management table for a system administrator. [Figure 9] FIG. 9 is a diagram for explaining a management table for tenant A. [Figure 10] FIG. 10 is a diagram for explaining a management table for tenant B. [Figure 11] FIG. 11 is a diagram for explaining a management table for tenant C. [Figure 12] FIG. 12 is a diagram for explaining an authentication and authorization information table for a system administrator stored in an external server for a system administrator. [Figure 13] FIG. 13 is a diagram for explaining an authentication and authorization information table for tenant A stored in an external server for tenant A. [Figure 14] FIG. 14 is a diagram for explaining an authentication and authorization information table for tenant B stored in an external server for tenant B. [Figure 15]Figure 15 is a diagram illustrating the authentication and authorization information table for Tenant C held by the external server for Tenant C. [Figure 16] Figure 16 is a diagram illustrating the configuration information DB management table 1600. [Figure 17] Figure 17 is a sequence diagram illustrating the operation of the system. [Figure 18] Figure 18 is a flowchart illustrating the processes performed by the authentication and authorization execution unit of the authentication infrastructure. [Figure 19] Figure 19 shows an example of a modified system configuration of the storage system management system. [Figure 20] Figure 20 shows an example of a modified system configuration of the storage system management system. [Modes for carrying out the invention]
[0022] The embodiments of this disclosure will be described below with reference to the drawings. In all the drawings of the embodiments, the same or corresponding parts may be denoted by the same reference numerals.
[0023] In the following explanation, various types of information may be described using terms such as "table," "record," "row," "column," and "section," but these types of information may also be represented using other data structures. When describing identification information, terms such as "ID" and "name" will be used, but these are interchangeable and can also be replaced with other expressions of identification information.
[0024] In the following explanation, the processing may be described using a functional block as the subject, but the subject of the processing may also be the processor or device (management terminal or external server) instead of the functional block.
[0025] <<Embodiment>> Figure 1 shows an example of the configuration of a management system for a storage system according to an embodiment of this disclosure.
[0026] The management system includes a storage system 100, a host 200a belonging to tenant A (for example, a customer), a host 200b belonging to tenant B (for example, a customer), a host 200c belonging to tenant C (for example, a customer), an external server 300s for the system administrator, an external server 300a for tenant A, an external server 300b for tenant B, and an external server 300c for tenant C. Hereafter, hosts 200a through 200c may be referred to as "host 200" when there is no need to distinguish between them. The external server 300s for the system administrator, external server 300a for tenant A, external server 300b for tenant B, and external server 300c for tenant C may be referred to as "external server 300" when there is no need to distinguish between them. The management system does not necessarily include hosts 200.
[0027] The host 200 and the storage system 100 are connected to each other via a network, enabling them to communicate with one another. The storage system 100 and the external server 300 are also connected to each other via a network, enabling them to communicate with one another.
[0028] The storage system 100 includes a management terminal 110 and a storage cluster 120. The management terminal 110 is a computer for managing and operating the entire storage system 100. The management terminal 110 includes a management processing unit 111 and an authentication infrastructure 112. The authentication infrastructure may be referred to as the "authentication unit." Details of these functions will be described later.
[0029] As shown in Figure 2, the storage cluster 120 is a virtual storage system constructed from multiple storage nodes 121. The storage system 100 has multi-tenancy capabilities (multi-tenancy configuration).
[0030] Figure 3 is a diagram illustrating the multi-tenancy function (multi-tenancy configuration) of the storage system 100. Note that the management terminal 110 is not shown in Figure 3. As shown in Figure 3, the storage cluster 120 provided by the storage system 100 includes a storage pool 130. The multi-tenancy function is a function in the storage system 100 that allows the storage pool 130, which is a storage resource, to be distributed or shared by multiple tenants.
[0031] The storage pool 130 is a logical user data storage area that combines multiple drives from multiple storage nodes 121. Multiple volumes 131 can be created from the storage pool 130, provided that the total capacity is less than or equal to the capacity of the storage pool 130. The created volumes 131 are connected to the host 200 of each tenant. The host 200 can read and write data to the connected volumes 131.
[0032] Each distributed storage system becomes a virtual private storage (VPS) which is a storage resource provided to each tenant. In this example, VPS132a is provided (allocated) to tenant A, VPS132b is provided (allocated) to tenant B, and VPS132c is provided (allocated) to tenant C. VPS132a, VPS132b, and VPS132c may be referred to as VPS132 when there is no need to distinguish between them.
[0033] Figure 4 shows an example of the hardware configuration of storage node 121. As shown in Figure 4, storage node 121 includes a controller 410 and a drive box 420. The controller 410 includes a host interface 411, a management interface 412, a drive interface 413, memory 414, and a processor 415 connected to them. The number of these components is arbitrary.
[0034] The host interface 411 is an interface device for communication with the host 200. The management interface 412 is an interface device for communication with the management terminal 110. The drive interface 413 is an interface device for communication with the drive box 420.
[0035] The drive box 420 houses multiple drives 421, which are one or more non-volatile storage devices capable of reading and writing data to store various types of data. The drive box 420 is connected to the drive interface 413 of the controller 410. The drives 421 are, for example, hard disk drives (HDDs), solid-state drives (SSDs) 139, etc.
[0036] The processor 415 is a control device that manages the operation of the entire storage node 121 and performs various processes by executing various programs stored in the memory 414. The memory 414 stores, for example, control information used by the storage node 121, programs executed by the processor 415, data accessed by the host 200, and various tables. The memory 414 is generally composed of DRAM (Dynamic RAM (Random Access Memory)), but it may also be composed of other storage media such as MRAM (Magneto-resistive RAM), ReRAM (Resistive RAM), PCM (Phase Change Memory), or NAND.
[0037] Figure 5 shows an example of the hardware configuration of a computer 500 applied to a management terminal 110. As shown in Figure 5, the computer 500 includes a non-volatile storage device 510 that can read and write data, memory 520 (e.g., RAM), a processor CPU 530, an input / output interface 540, a network interface 550, and a bus 560. The computer may be a virtual computer built on the cloud.
[0038] The storage device 510 stores various programs, data, etc. The CPU 530 loads the programs stored in the storage device 510 into the memory 520. The CPU 530 then executes the programs loaded into the memory 520 to perform various functions.
[0039] As mentioned above, memory 520 is loaded with the program that the CPU 530 will execute, and it temporarily stores the data that the CPU 530 will use when executing the program.
[0040] The input / output interface 540 is an interface for connecting operating devices such as a keyboard and mouse, as well as a display. The network interface 550 is an interface for connecting the computer 500 to a network.
[0041] The external server 300 is comprised of the computer 500 shown in Figure 5. The external server 300 may be a virtual computer built on the cloud, or it may be comprised of multiple computers.
[0042] Figure 6 is a functional block diagram illustrating the details of the functions of the management terminal 110. As previously described, the management terminal 110 includes a management processing unit 111 and an authentication infrastructure 112. The management processing unit 111 and the authentication infrastructure 112 correspond to the programs and / or data stored in the storage device 510 of the computer 500 applied to the management terminal 110.
[0043] The management processing unit 111 provides an interface for the storage system 100 to communicate with the host 200. The host 200 can perform operations such as data retrieval, storage, updating, and deletion through APIs provided by the storage system 100, as enabled by the management processing unit 111. The management processing unit 111 receives requests from the host 200, performs appropriate processing according to the request, and then returns a response to the host 200. For example, in response to a data retrieval request from the host 200, it returns the specified data.
[0044] The authentication infrastructure 112 includes an authentication and authorization execution unit 601, a tenant identification unit 602, an external authentication and authorization namespace 603, a system administrator namespace 604s, a namespace for tenant A 604a, a namespace for tenant B 604b, a namespace for tenant C 604c, and a database management system (DBMS) 605.
[0045] The authentication and authorization execution unit 601 receives the request from the management processing unit 111 each time the management processing unit 111 receives a request from a user on the host 200, obtains the information necessary for authentication and authorization contained in the request, and performs user authentication and authorization using the external server 300. The tenant identification unit 602 identifies the tenant to which the host 200 that sent the request belongs.
[0046] The external authentication and authorization namespace 603 includes the authentication infrastructure management table 800 (see Figure 8A). The system administrator namespace 604s includes the system administrator management table 810 (see Figure 8B). The tenant A namespace 604a includes the tenant A management table 900 (see Figure 9). The tenant B namespace 604b includes the tenant B management table 1000 (see Figure 10). The tenant C namespace 604c includes the tenant C management table 1100 (see Figure 11). The storage system 100 employs a configuration in which each tenant uses an independent namespace to manage user IDs and other information for identifying users.
[0047] DBMS605 is software for managing databases (DBs), and it includes tools and functions for creating, managing, and operating databases. DBMS605 manages and operates databases (DBs) that are created and maintained (stored, stored). One example of DBMS605 is PostgreSQL.
[0048] Figure 7 is a functional block diagram of the external server 300s for the system administrator, the external server 300a for tenant A, the external server 300b for tenant B, and the external server 300c for tenant C.
[0049] As shown in Figure 7, the external server 300s for the system administrator includes a system administrator authentication execution unit 701s, a system administrator authorization execution unit 702s, and a system administrator authentication and authorization information table 703s (see Figure 12).
[0050] The system administrator authentication execution unit 701s and the system administrator authorization execution unit 702s correspond to programs stored in the storage device 510 of the computer 500 applied to the external server 300s for the system administrator. The system administrator authentication authorization information table 703s corresponds to data stored in the storage device 510 of the computer 500 applied to the external server 300s for the system administrator.
[0051] The system administrator authentication execution unit 701s performs authentication of the system administrator in response to a request from the authentication infrastructure 112 and returns the authentication result to the authentication infrastructure 112. If the authentication of the system administrator is successful, the system administrator authorization execution unit 702s assigns (authorizes) an external user group ID to the system administrator and returns it to the authentication infrastructure 112. The external user group ID is sometimes referred to as "identification information" for identifying roles. The system administrator authentication authorization information table 703s is the information (authentication information) used for the authentication of the system administrator. The system administrator authentication authorization information table 703s will be described in detail later with reference to Figure 12.
[0052] The external server 300a for tenant A includes a tenant A authentication execution unit 701a, a tenant A authorization execution unit 702a, and a tenant A authentication and authorization information table 703a (see Figure 13).
[0053] The Tenant A authentication execution unit 701a and the Tenant A authorization execution unit 702a correspond to programs stored in the storage device 510 of the computer 500 applied to the external server 300a for Tenant A. The Tenant A authentication and authorization information table 703a corresponds to data stored in the storage device 510 of the computer 500 applied to the external server 300a for Tenant A.
[0054] The Tenant A authentication execution unit 701a performs authentication of users belonging to Tenant A in response to a request from the authentication infrastructure 112 and returns the authentication result to the authentication infrastructure 112. If the authentication of the system administrator is successful, the Tenant A authorization execution unit 702a assigns (authorizes) an external user group ID to the system administrator and returns it to the authentication infrastructure 112. The Tenant A authentication and authorization information table 703a is information (authentication information) used to authenticate users belonging to Tenant A, created using the namespace for Tenant A. The Tenant A authentication and authorization information table 703a will be described in detail later with reference to Figure 13.
[0055] The external server 300b for tenant B includes a tenant B authentication execution unit 701b, a tenant B authorization execution unit 702b, and a tenant B authentication and authorization information table 703b (see Figure 14). The tenant B authentication execution unit 701b performs authentication of users belonging to tenant B in response to a request from the authentication infrastructure 112 and returns the authentication result to the authentication infrastructure 112.
[0056] The Tenant B authentication execution unit 701b and the Tenant B authorization execution unit 702b correspond to programs stored in the storage device 510 of the computer 500 applied to the external server 300b for Tenant B. The Tenant B authentication and authorization information table 703b corresponds to data stored in the storage device 510 of the computer 500 applied to the external server 300b for Tenant B.
[0057] If the authentication of the system administrator is successful, the Tenant B authorization execution unit 702b assigns (authorizes) the external user group ID to the system administrator and sends a reply to the authentication infrastructure 112. The Tenant B authentication authorization information table 703b is information (authentication information) used to authenticate users belonging to Tenant B, created using the Tenant B namespace. The Tenant B authentication authorization information table 703b will be described in detail later with reference to Figure 14.
[0058] The external server 300c for tenant C includes a tenant C authentication execution unit 701c, a tenant C authorization execution unit 702c, and a tenant C authentication and authorization information table 703c (see Figure 15).
[0059] The Tenant C authentication execution unit 701c and the Tenant C authorization execution unit 702c correspond to programs stored in the storage device 510 of the computer 500 applied to the external server 300c for Tenant C. The Tenant C authentication and authorization information table 703c corresponds to data stored in the storage device 510 of the computer 500 applied to the external server 300c for Tenant C.
[0060] The Tenant C authentication execution unit 701c performs authentication of users belonging to Tenant C in response to a request from the authentication infrastructure 112 and returns the authentication result to the authentication infrastructure 112. If the authentication of the system administrator is successful, the Tenant C authorization execution unit 702c assigns (authorizes) an external user group ID to the system administrator and returns it to the authentication infrastructure 112. The Tenant C authentication and authorization information table 703c is information (authentication information) used for authenticating users belonging to Tenant C, created using the namespace for Tenant C. The Tenant C authentication and authorization information table 703c will be described in detail later with reference to Figure 15.
[0061] The management system of this disclosure has an external authentication and authorization server 300 corresponding to each of several tenants, and each external server 300 has authentication and authorization information (authentication and authorization information table 703a for tenant A, authentication and authorization information table 703b for tenant B, and authentication and authorization information table 703c for tenant C) for authenticating and authorizing users defined in the tenant namespace of the corresponding tenant.
[0062] The management system disclosed herein adopts a configuration in which user authentication and authorization are performed using an external server 300, by independently providing an external server 300 for authentication and authorization for each tenant. When a hardware multi-tenancy type management method is applied, it can accommodate the independent user management for each tenant required by the hardware multi-tenancy type management method.
[0063] Furthermore, the management system disclosed herein improves usability by allowing the assignment of user IDs and other information across different tenants, even when using an external server 300 for user authentication, by using an independent namespace for each tenant to manage user IDs and the like.
[0064] Figure 8A is a diagram illustrating the authentication infrastructure management table 800. As shown in Figure 8A, the authentication infrastructure management table 800 includes user group ID 801, external user group ID 802, tenant name 803, and role information 804 as columns for storing information (values). In the authentication infrastructure management table 800, the information corresponding to each column related to user management is associated with each other and stored as row-level information (records).
[0065] Specifically, User Group ID 801 stores an ID used to identify a user group. A user group is a grouping of user accounts. By associating user groups with external user groups, VPS132, and roles, access to managed items can be controlled. External User Group ID 802 stores an ID used to identify an external user group. An external user group is a grouping of user accounts and corresponds to a user group. Tenant Name 803 stores the name of the VPS132 assigned to the tenant that the user can operate. VPS132 is associated with a user group, and the VPS132 that a user can operate is determined by which user group the user belongs to. Note that if the name of a specific VPS132 is not stored in Tenant Name 803 (i.e., "null"), it means that there are no restrictions on which VPS can be operated, and all VPS can be operated. Note that the name of VPS132 also functions as identification information for identifying the tenant, so it is sometimes referred to as "tenant identification information".
[0066] Role information 804 stores role information (sometimes referred to as "roles"). Roles define the items (permissions) that a user can operate on the storage system 100. Roles are associated with user groups (IDs that indicate user groups), and the items (permissions) that a user can operate on are determined by which user group the user belongs to.
[0067] The roles are explained in detail as follows: Audit indicates the administrator of all audit logs and is capable of performing the operations specified for this role (e.g., auditing all VPS). Security indicates the administrator of all security and is capable of performing the operations specified for this role. Storage indicates the administrator of all storage and is capable of performing the operations specified for this role. RemoteCopy indicates the administrator of all remote copy and is capable of performing the operations specified for this role. Monitor indicates the monitor of all storage and is capable of performing the operations specified for this role (e.g., as an administrator, referencing volumes within the VPS to detect volume failures). Service indicates the maintenance administrator of all storage and is capable of performing the operations specified for this role. Resource indicates the administrator who allocates resources to VPS and is capable of performing the operations specified for this role (e.g., viewing, creating, editing, and deleting VPS).
[0068] VpsSecurity indicates the VPS security administrator and is authorized to perform the operations specified for that role (e.g., user management operations within the VPS they are responsible for, and operations necessary for managing users, user groups, and sessions as a security administrator). VpsStorage indicates the VPS storage administrator and is authorized to perform the operations specified for that role (resource management operations necessary for a storage administrator). VpsMonitor indicates the VPS monitor and is authorized to perform the operations specified for that role (referencing the following resources within the VPS they are responsible for).
[0069] Figure 8B is a diagram illustrating the system administrator management table 810. As shown in Figure 8B, the system administrator management table 810 includes the tenant name 811, the user group ID 812, and the external user group ID 813 as columns for storing information (values). In the system administrator management table 810, information corresponding to each column related to system administrator management is associated with each other and stored as row-level information (records).
[0070] Specifically, tenant name 811 is "null," meaning no information is stored there. User group ID 812 contains an ID (user group ID) to identify the user group. External user group ID 903 contains an ID (external user group ID) to identify the external user group.
[0071] Figure 9 is a diagram illustrating the management table 900 for tenant A. As shown in Figure 9, the management table 900 for tenant A includes the tenant name 901, the user group ID 902, and the external user group ID 903 as columns for storing information (values). In the management table 900 for tenant A, information corresponding to each column regarding the management of users belonging to tenant A is associated with each other and stored as row-level information (records).
[0072] Specifically, tenant name 901 stores the name of VPS132 assigned to the tenant. User group ID 902 stores the ID used to identify the user group (user group ID). External user group ID 903 stores the ID used to identify the external user group (external user group ID).
[0073] Figure 10 is a diagram illustrating the management table 1000 for tenant B. As shown in Figure 10, the management table 1000 for tenant B includes the tenant name 1001, the user group ID 1002, and the external user group ID 1003 as columns for storing information (values). In the management table 1000 for tenant B, information corresponding to each column regarding the management of users belonging to tenant B is associated with each other and stored as row-level information (records).
[0074] Specifically, tenant name 1001 stores the name of VPS132 assigned to the tenant. User group ID 1002 stores the ID used to identify the user group (user group ID). External user group ID 1003 stores the ID used to identify the external user group (external user group ID).
[0075] Figure 11 is a diagram illustrating the management table 1100 for tenant C. As shown in Figure 11, the management table 1100 for tenant C includes the tenant name 1101, the user group ID 1102, and the external user group ID 1103 as columns for storing information (values). In the management table 1100 for tenant C, the information corresponding to each column regarding users belonging to tenant C is associated with each other and stored as row-level information (records).
[0076] Specifically, tenant name 1101 stores the name of VPS 132 assigned to the tenant. User group ID 1102 stores the ID used to identify the user group (user group ID). External user group ID 1103 stores the ID used to identify the external user group (external user group ID).
[0077] Figure 12 is a diagram illustrating the system administrator authentication and authorization information table 1200 held by the external server 300s for system administrators. As shown in Figure 12, the system administrator authentication and authorization information table 1200 includes user ID 1201, password 1202, and external user group ID 1203 as columns for storing information (values). In the system administrator authentication and authorization information table 1200, the information corresponding to each column regarding the information used for system administrator authentication is associated with each other and stored as row-level information (records).
[0078] Specifically, User ID 1201 stores an ID to identify the user. Password 1202 stores the password. External User Group ID 1203 stores an ID (External User Group ID) to identify the external user group.
[0079] Figure 13 is a diagram illustrating the authentication and authorization information table 1300 for Tenant A, which is held by the external server 300a for Tenant A. As shown in Figure 13, the authentication and authorization information table 1300 for Tenant A includes User ID 1301, Password 1302, and External User Group ID 1303 as columns for storing information (values). In the authentication and authorization information table 1300 for Tenant A, the information corresponding to each column regarding the information used for authenticating users belonging to Tenant A is associated with each other and stored as row-level information (records).
[0080] Specifically, User ID 1301 stores an ID to identify the user. Password 1302 stores the password. External User Group ID 1303 stores an ID to identify the external user group (External User Group ID).
[0081] Figure 14 is a diagram illustrating the authentication and authorization information table 1400 for Tenant B, which is maintained by the external server 300b for Tenant B. As shown in Figure 14, the authentication and authorization information table 1400 for Tenant B includes User ID 1401, Password 1402, and External User Group ID 1403 as columns for storing information (values). In the authentication and authorization information table 1400 for Tenant B, the information corresponding to each column regarding the information used for authenticating users belonging to Tenant B is associated with each other and stored as row-level information (records).
[0082] Specifically, User ID 1401 stores an ID to identify the user. Password 1402 stores the password. External User Group ID 1403 stores an ID to identify the external user group (External User Group ID).
[0083] Figure 15 is a diagram illustrating the authentication and authorization information table 1500 for Tenant C, which is held by the external server 300c for Tenant C. As shown in Figure 15, the authentication and authorization information table 1500 for Tenant C includes User ID 1501, Password 1502, and External User Group ID 1503 as columns for storing information (values). In the authentication and authorization information table 1500 for Tenant C, the information corresponding to each column regarding the information used for authentication of users belonging to Tenant C is associated with each other and stored as row-level information (records).
[0084] Specifically, User ID 1501 stores an ID to identify the user. Password 1502 stores the password. External User Group ID 1503 stores an ID (External User Group ID) to identify the external user group.
[0085] Figure 16 is a diagram illustrating the configuration information DB management table 1600. As shown in Figure 16, the configuration information DB management table 1600 includes the tenant name 1601 and the host information 1602 of the external server 300 as columns for storing information (values). In the configuration information DB management table 1600, the information corresponding to each column related to the management of the tenant and the external server 300 is associated with each other and stored as row-level information (records). Specifically, the tenant name 1601 stores the name used to identify the VPS 132 assigned to the tenant. The host information 1602 of the external server 300 stores the IP address of the external server 300.
[0086] Figure 17 is a sequence diagram illustrating the operation of the system.
[0087] S1711: The authentication infrastructure 112, at a certain time, uses tenant identification information to name (set (register)) the hostname to which requests to the tenant will be sent. This certain time is, for example, when a user creates a tenant namespace. The user uses tenant identification information to identify the tenant to which they belong and creates an FQDN (Fully Qualified Domain Name) that includes the tenant identification information as the hostname to which requests will be sent. For example, if the tenant identification information is VPS-A, which is the name of VPS132a, the FQDN will be "VPS-A.sds-block.hitachi.com".
[0088] S1712: Based on user operations, host 200 sends a user request to the management processing unit 111 (not shown in Figure 17) which includes a user ID and password as authentication information, and a request to perform operations such as data retrieval, storage, updating, and deletion on the storage system 100. The authentication infrastructure 112 receives the user request via the management processing unit 111 (not shown in Figure 17).
[0089] The request is created by the software on host 200 so that it includes a Fully Qualified Domain Name (FQDN) that contains tenant identification information as the hostname to which the request is sent, in order to identify the tenant to which the user belongs. For example, if a request sent from host 200 used by a user belonging to tenant A is a GET request, then "https: / / VPS-A.sds-block.hitachi.com / ConfigurationManager / simple / v1 / objects / volumes" is created. In this GET request, the tenant identification information "VPS-A" is included in the FQDN as the hostname to which the request is sent.
[0090] S1713: The authentication infrastructure 112, using the tenant identification unit 602, extracts tenant identification information included as a hostname from the FQDN included in the request, and identifies which tenant the user belongs to based on the extracted tenant identification information.
[0091] S1714: The authentication infrastructure 112, using the authentication authorization execution unit 601, refers to the configuration information DB management table 1600 in Figure 16, which is contained in the database managed by the DBMS 605, using the tenant identification information extracted in S1713, and obtains the host information (IP address) of the external server 300.
[0092] S1715: The authentication infrastructure 112, via the authentication authorization execution unit 601, sends the user ID, password, and authentication authorization request to the external server 300 identified in S1714 (hereinafter sometimes referred to as "the relevant external server 300").
[0093] S1716: When the external server 300 receives a user ID, password, and authentication authorization request from the authentication infrastructure 112, it compares the received user ID and password with the corresponding information (authentication authorization information table) within the external server 300 and performs authentication. If the received user ID and password exist in the authentication authorization information table and are associated with each other, authentication is successful.
[0094] S1717: When authentication is successful, the relevant external server 300 identifies an ID indicating the corresponding external user group from the user ID and password in the authentication authorization information table (assigns it to the user (authorizes them)).
[0095] S1718: The external server 300 transmits the identified external user group ID and the result of successful authentication to the authentication infrastructure 112.
[0096] S1719: The authentication infrastructure 112, using the authentication authorization execution unit 601, identifies the user group ID and tenant identification information to be used within the storage cluster 120 from the external user group ID, based on the tenant management table (the table corresponding to the tenant identified in S1713 among the tenant A management table 900 to the tenant C management table 1100 (the system administrator table 810 if the tenant is not identified)). Specifically, the authentication infrastructure 112, using the authentication authorization execution unit 601, identifies the user group ID and tenant identification information associated with the external user group ID in the tenant management table. Note that if the user is a system administrator, only the user group ID is identified.
[0097] S1720: The authentication infrastructure 112, via the authentication authorization execution unit 601, assigns a role corresponding to the user group ID and tenant identification information (or, if the user is a system administrator, the role corresponding to the user group ID) to the user who operated the host 200 that sent the request, based on the authentication infrastructure management table 800 (authorizing the role to the user).
[0098] S1721: The authentication infrastructure 112 transmits the authentication and authorization result to the host 200 via the authentication and authorization execution unit 601.
[0099] The above describes the operation of the management system. The management system disclosed herein provides an external server 300 for authentication and authorization independently for each tenant. In this case, it becomes difficult for the authentication infrastructure 112 to identify the external server 300 corresponding to the tenant that sent the authentication information and to identify the external server 300 that requests authentication and authorization. In response to this, this system uses tenant identification information to create and configure an FQDN that includes the tenant identification information as the hostname to which the request is sent.
[0100] The authentication infrastructure 112 uses the tenant identification unit 602 to extract tenant identification information included as the hostname of the destination of the request from the FQDN included in the request, and the authentication authorization execution unit 601 uses the extracted tenant identification information to identify the host information of the external server 300. As a result, the management system of this disclosure can identify the external server 300 that requests authentication authorization and request authentication authorization from the appropriate external server 300 corresponding to each tenant.
[0101] Figure 18 is a flowchart illustrating the process performed by the authentication and authorization execution unit 601 of the authentication infrastructure 112.
[0102] The authentication and authorization execution unit 601 starts processing from step 1800, and after sequentially executing the processes from steps 1805 to 1820 described below, proceeds to step 1825.
[0103] Step 1805: The authentication and authorization execution unit 601 receives a user request from the host 200 via the management processing unit 111.
[0104] Step 1810: As previously described, the authentication and authorization execution unit 601 extracts tenant identification information included as a hostname from the FQDN included in the request by the tenant identification unit 602, and identifies which tenant the user belongs to based on the extracted tenant identification information.
[0105] Step 1815: As previously described, the authentication and authorization execution unit 601 uses the identified tenant identification information to refer to the configuration information DB management table 1600 in Figure 16 contained in the database and obtains the host information (IP address) of the external server 300.
[0106] Step 1820: The authentication and authorization execution unit 601 sends the user ID, password, and authentication and authorization request to the external server 300 indicated by the identified IP address, causing the external server 300 to perform user authentication and receive the authentication result. If authentication is successful, the authentication and authorization execution unit 601 also receives the external user group ID.
[0107] When the authentication authorization execution unit 601 proceeds to step 1825, it determines whether the user of the authentication result received from the external server 300 is legitimate or not (i.e., whether the authentication result is successful or not).
[0108] If the authenticated user is not legitimate (authentication fails), the authentication authorization execution unit 601 determines "NO" in step 1825 and proceeds to step 1830, outputting an error message indicating authentication rejection to the host 200 via the management processing unit 111. Subsequently, the authentication authorization execution unit 601 proceeds to step 1895 and terminates this processing flow.
[0109] If the authenticated user is legitimate (in the case of successful authentication), the authentication authorization execution unit 601 determines "YES" in step 1825 and proceeds to step 1845 after sequentially executing the processes in steps 1835 and 1840 described below.
[0110] Step 1835: The authentication and authorization execution unit 601 identifies the user group ID and tenant identification information from the external user group ID based on the tenant management table (the table corresponding to the tenant identified in step 1810, from the tenant management table 900 to the tenant management table 1100).
[0111] Step 1840: The authentication and authorization execution unit 601 assigns a role to the user (i.e., authorizes) that corresponds to the user group ID and tenant identification information identified based on the authentication infrastructure management table 800 (if the user is a system administrator, the role corresponding to the user group ID).
[0112] When the authentication and authorization execution unit 601 proceeds to step 1845, it determines whether the command execution is within the scope of role privileges. That is, it determines whether the user has the role necessary for the operation requested by the request.
[0113] If the command execution is outside the scope of role privileges, the authentication and authorization execution unit 601 determines "NO" in step 1845 and proceeds to step 1850, outputting an error message to the host 200 via the management processing unit 111. After that, the authentication and authorization execution unit 601 proceeds to step 1895 and terminates this processing flow.
[0114] If the command execution falls within the scope of role privileges, the authentication and authorization execution unit 601 determines "YES" in step 1845 and proceeds to step 1855, outputting the access rights to the target resource and the right to execute the operation to the management processing unit 111. This grants access to the requested target resource and permits operations on the target resource. Subsequently, the authentication and authorization execution unit 601 proceeds to step 1895 and terminates this processing flow.
[0115] <Effects> As described above, the management system of the storage system 100 according to the embodiment of this disclosure can improve usability while supporting independent user management for each tenant.
[0116] <<Variation>> This disclosure is not limited to the embodiments described above, and various modifications can be taken within the scope of this disclosure. Furthermore, the embodiments described above can be combined with each other, as long as they do not deviate from the scope of this disclosure.
[0117] In the above embodiment, as shown in Figure 19, the external server 300s for the system administrator may consist of an authentication server 301s for the system administrator and an authorization server 302s for the system administrator. The external server 300a for tenant A may consist of an authentication server 301a for tenant A and an authorization server 302a for tenant A. The external server 300b for tenant B may consist of an authentication server 301b for tenant B and an authorization server 302b for tenant B. The external server 300c for tenant C may consist of an authentication server 301c for tenant C and an authorization server 302c for tenant C.
[0118] In this case, the authentication server 301s for the system administrator has an authentication execution unit 701s for the system administrator and an authentication authorization information table 703s for the system administrator. The authorization server 302s for the system administrator has an authorization execution unit 702s for the system administrator and an authentication authorization information table 703s for the system administrator. The authentication server 301a for tenant A has an authentication execution unit 701a for tenant A and an authentication authorization information table 703a for tenant A. The authorization server 302a for tenant A has an authorization execution unit 702a for tenant A and an authentication authorization information table 703a for tenant A.
[0119] The authentication server 301b for tenant B has a tenant B authentication execution unit 701b and a tenant B authentication authorization information table 703b. The authorization server 302b for tenant B has a tenant B authorization execution unit 702b and a tenant B authentication authorization information table 703b. The authentication server 301c for tenant C has a tenant C authentication execution unit 701c and a tenant C authentication authorization information table 703c. The authorization server 302c for tenant C has a tenant C authorization execution unit 702c and a tenant C authentication authorization information table 703c. In the above embodiment, as shown in Figure 20, the management processing unit 111 and the authentication infrastructure 112 may be included in the storage cluster 120 instead of the management terminal 110. Similarly, in the modified example shown in Figure 19, the management processing unit 111 and the authentication infrastructure 112 may also be included in the storage cluster 120 instead of the management terminal 110.
[0120] This disclosure may also take the following configuration.
[0121] [1] A management system for a multi-tenancy storage system, which includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, Each of the aforementioned tenants has an external authentication server, The authentication unit has a plurality of tenant namespaces, each corresponding to one of the plurality of tenants, and applied to user identification information for identifying the user. Each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant. The authentication unit receives authentication information, including the user identification information, from a host belonging to the tenant, and performs user authentication using the external server corresponding to the tenant. A management system for storage systems.
[0122] [2] A method for managing a multi-tenancy storage system, which includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, Using an external authentication server corresponding to each of the multiple tenants, The authentication unit has a plurality of tenant namespaces, each corresponding to one of the plurality of tenants, and applied to user identification information for identifying the user. Each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant. The authentication unit receives authentication information, including the user identification information, from a host belonging to the tenant, and performs user authentication using the external server corresponding to the tenant. How to manage a storage system. [Explanation of Symbols]
[0123] 100...Storage system, 110...Management terminal, 111...Management processing unit, 112...Authentication infrastructure, 120...Storage cluster, 121...Storage node, 130...Storage pool, 131...Volume, 200a...Host, 200b...Host, 200c...Host, 300a...External server for Tenant A, 300b...External server for Tenant B, 300c...External server for Tenant C, 300s...External server for system administrator, 301a...Authentication server for Tenant A, 301b...Authentication server for Tenant B, 301c...Authentication server for Tenant C, 301s...Authentication server for system administrator, 302a...Authorization server for Tenant A, 302b...Authorization server for Tenant B, 302c...Authorization server for Tenant C, 302s...Authorization server for system administrator
Claims
1. A management system for a multi-tenancy storage system, which includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, Each of the aforementioned tenants has an external authentication server, The authentication unit has a plurality of tenant namespaces, each corresponding to one of the plurality of tenants, and applied to user identification information for identifying the user. Each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant. The authentication unit receives authentication information, including the user identification information, from a host belonging to the tenant, and performs user authentication using the external server corresponding to the tenant. A management system for storage systems.
2. In the storage system management system according to claim 1, The authentication unit uses the external server corresponding to the tenant to perform authorization to identify the user group to which the user belongs. A management system for storage systems.
3. In the storage system management system according to claim 2, The authentication unit identifies the external server corresponding to the tenant that sent the authentication information, transmits the authentication information to the identified external server, causes the external server to perform user authentication and authorization based on the authentication information and authentication information, receives identification information from the external server for identifying the role information including the authentication result, identifies the role information based on the identification information, and assigns the identified role information to the user. A management system for storage systems.
4. In the storage system management system according to claim 3, The authentication unit receives a request from the host for an operation on the storage resource, which includes the authentication information and tenant identification information for identifying the tenant. Extract the tenant identification information from the request, and identify the external server corresponding to the tenant based on the tenant identification information. A management system for storage systems.
5. In the storage system management system according to claim 4, The authentication unit has information relating the tenant identification information to the host information of the external server, and identifies the external server corresponding to the tenant by identifying the host information based on the information and the extracted tenant identification information. A management system for storage systems.
6. In the storage system management system according to claim 4, The authentication information includes information relating the user identification information and external user group identification information for identifying the user group, The external server identifies the external user group identification information from the user identification information of the authenticated user based on the authentication information, and transmits the identified external user group identification information to the authentication unit as the identified information. A management system for storage systems.
7. In the storage system management system according to claim 6, The authentication unit has tenant management information, The tenant management information is defined in the tenant namespace and is information to which the tenant identification information, user group identification information for identifying the user group, and external user group identification information are associated. The authentication unit identifies the tenant identification information and the user group identification information from the external user group identification information identified by the external server, based on the tenant management information. A management system for storage systems.
8. In the storage system management system according to claim 7, The authentication unit is a namespace separate from the multiple tenant namespaces, and includes an external authentication and authorization namespace applied to the user group identification information, the tenant identification information, and the role information, and authentication infrastructure management information defined in the external authentication and authorization namespace. The authentication infrastructure management information is information to which the tenant identification information, the user group identification information, and the role information are associated. The authentication unit identifies the role information from the tenant identification information and the user group identification information based on the authentication infrastructure management information. A management system for storage systems.
9. In the storage system management system according to claim 1, The external server authenticates the user based on the authentication information and the authentication information. A management system for storage systems.
10. In the storage system management system according to claim 9, The authentication information is the user identification information and password. A management system for storage systems.
11. A method for managing a multi-tenancy storage system, which includes an authentication unit that provides storage resources to multiple tenants, authenticates users, and grants users role information that defines the rights to operate the storage resources, Using an external authentication server corresponding to each of the multiple tenants, The authentication unit has a plurality of tenant namespaces, each corresponding to one of the plurality of tenants, and applied to user identification information for identifying the user. Each of the external servers has authentication information for authenticating the user defined in the tenant namespace of the corresponding tenant. The authentication unit receives authentication information, including the user identification information, from a host belonging to the tenant, and performs user authentication using the external server corresponding to the tenant. How to manage a storage system.
Citation Information
Patent Citations
Multitenant management system and method
JP2024102743A
Computer system, and resource management method
WO2014184893A1