Distributed Storage Management Tunnels to Reduce Public IP Use
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing distributed data storage systems require a large number of public IP addresses for mesh connectivity between geographically separated clusters, leading to usability issues and operational burdens due to frequent subnet or allocation changes.
Innovation Solution
Implementing inter-cluster tunnels, such as IPSEC tunnels, using pre-provisioned private network addresses and employing routing rules with dummy namespace addresses to maintain seamless connectivity and security without requiring additional public addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mesh connectivity is implemented between geographically separated clusters, then seamless communication is achieved, but the number of public IP addresses required increases significantly
Solution Approach 1:
The patent introduces a gateway as an intermediary component that terminates tunnel connections between clusters. The gateway acts as a mediator that receives management traffic from local SP nodes, performs routing checks, and forwards the traffic through encrypted tunnels to remote clusters. This intermediary approach allows mesh connectivity to be maintained while significantly reducing the number of public IP addresses required, as the gateway consolidates the tunnel termination function rather than requiring direct public IP addresses for each SP node pair.
2Adaptability or versatility
If public IP addresses are allocated for mesh connectivity, then cluster communication is enabled, but operational burden increases due to frequent subnet or allocation changes
Solution Approach 1:
The patent introduces a virtual dimension through encrypted tunnels that overlay the physical network infrastructure. Instead of managing public IP addresses in the traditional network dimension, the system creates a virtual communication dimension where SP nodes can communicate using private addresses through the tunnel gateway infrastructure. This dimensional shift allows the system to maintain communication adaptability while eliminating the operational burden of managing public IP address allocations and subnet changes.
3Quantity of substance
If tunneling is implemented using private network addresses, then the number of public IP addresses is reduced, but routing complexity increases
Solution Approach 1:
The gateway implements self-service routing functionality by automatically performing routing checks on incoming management traffic. When the gateway receives traffic from a local SP node destined for a remote SP node, it autonomously checks the routing rule associating the destination address with the appropriate tunnel, applies the tunnel configuration rule, and forwards the traffic through the correct tunnel. This self-service approach reduces routing complexity compared to manual configuration, as the gateway automatically manages the routing decisions based on pre-configured rules.
Data Source
AI summary
A distributed data storage system includes clusters of data storage appliances interconnected by an inter-cluster (IC) network having an IC namespace. Storage processing (SP) nodes exchange management traffic using mesh network (MN) addresses of a separate MN namespace. Gateways provide IC tunnels for routing management traffic among the clusters using IC network addresses. Operation includes, in each gateway for traffic from a local SP node destined for a remote SP node of another cluster, (1) performing a routing check based on a routing rule associating an MN destination address with a dummy MN address further associated with a respective IC tunnel, (2) applying a tunnel configuration rule of the IC tunnel associating the MN destination address with the IC network address of a remote gateway for the remote SP, and (3) forwarding the traffic on the respective IC tunnel using the IC network address of the remote gateway.


