Distributed Storage Management Tunnels to Reduce Public IP Use

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed data storage systems require a large number of public IP addresses for mesh connectivity between geographically separated clusters, leading to usability issues and operational burdens due to frequent subnet or allocation changes.

Innovation Solution

Implementing inter-cluster tunnels, such as IPSEC tunnels, using pre-provisioned private network addresses and employing routing rules with dummy namespace addresses to maintain seamless connectivity and security without requiring additional public addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mesh connectivity is implemented between geographically separated clusters, then seamless communication is achieved, but the number of public IP addresses required increases significantly

Engineering Contradiction:
ImproveconnectivityVSAvoidpublic IP addresses
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent introduces a gateway as an intermediary component that terminates tunnel connections between clusters. The gateway acts as a mediator that receives management traffic from local SP nodes, performs routing checks, and forwards the traffic through encrypted tunnels to remote clusters. This intermediary approach allows mesh connectivity to be maintained while significantly reducing the number of public IP addresses required, as the gateway consolidates the tunnel termination function rather than requiring direct public IP addresses for each SP node pair.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If public IP addresses are allocated for mesh connectivity, then cluster communication is enabled, but operational burden increases due to frequent subnet or allocation changes

Engineering Contradiction:
Improvecommunication capabilityVSAvoidoperational burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a virtual dimension through encrypted tunnels that overlay the physical network infrastructure. Instead of managing public IP addresses in the traditional network dimension, the system creates a virtual communication dimension where SP nodes can communicate using private addresses through the tunnel gateway infrastructure. This dimensional shift allows the system to maintain communication adaptability while eliminating the operational burden of managing public IP address allocations and subnet changes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Quantity of substance

If tunneling is implemented using private network addresses, then the number of public IP addresses is reduced, but routing complexity increases

Engineering Contradiction:
Improvepublic IP addressesVSAvoidrouting configuration
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The gateway implements self-service routing functionality by automatically performing routing checks on incoming management traffic. When the gateway receives traffic from a local SP node destined for a remote SP node, it autonomously checks the routing rule associating the destination address with the appropriate tunnel, applies the tunnel configuration rule, and forwards the traffic through the correct tunnel. This self-service approach reduces routing complexity compared to manual configuration, as the gateway automatically manages the routing decisions based on pre-configured rules.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12438809B2Distributed data storage system with tunneling of management requests among scale-out clusters
Publication Date: 2025.10.07 DELL PROD LP
  • US12438809B2 patent drawing
  • US12438809B2 patent drawing
  • US12438809B2 patent drawing

AI summary

A distributed data storage system includes clusters of data storage appliances interconnected by an inter-cluster (IC) network having an IC namespace. Storage processing (SP) nodes exchange management traffic using mesh network (MN) addresses of a separate MN namespace. Gateways provide IC tunnels for routing management traffic among the clusters using IC network addresses. Operation includes, in each gateway for traffic from a local SP node destined for a remote SP node of another cluster, (1) performing a routing check based on a routing rule associating an MN destination address with a dummy MN address further associated with a respective IC tunnel, (2) applying a tunnel configuration rule of the IC tunnel associating the MN destination address with the IC network address of a remote gateway for the remote SP, and (3) forwarding the traffic on the respective IC tunnel using the IC network address of the remote gateway.