Storage Cluster Synchronization With Edge VDL Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face vulnerabilities due to lingering exposure of deleted data, particularly in multi-tenant scenarios, where reallocated storage clusters can reveal sensitive information unless fully initialized, which is computationally expensive and impacts performance.
Innovation Solution
Implementing valid data length (VDL) controls on a per-cluster basis, with metadata stored and managed at edge data volume nodes, and utilizing sequence controls synchronized by a master metadata node to control access without comprehensive initialization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive initialization of storage clusters is performed during deallocation and reallocation, then data security is improved by preventing exposure of deleted data, but computational cost and processing time increase significantly
Solution Approach 1:
The patent applies partial action by implementing VDL controls only when necessary - specifically when storage clusters are reallocated from decommissioned virtual machines or when security policies require it. Instead of universally initializing all storage clusters during every reallocation, the system selectively applies initialization based on the source of the storage and security requirements, thereby reducing unnecessary computational overhead while maintaining data security where needed
2Device complexity
If VDL controls are managed centrally at a single node, then centralized coordination is simplified, but network bandwidth consumption increases due to frequent synchronization requirements
Solution Approach 1:
The patent implements local quality by distributing VDL indicator storage and management to edge data volume nodes throughout the storage network. Each edge node maintains its own VDL indicators locally rather than requiring all VDL data to be centralized at a single node. This distributed approach allows local decision-making regarding VDL enforcement while reducing the network synchronization burden, as each node independently manages its local VDL indicators without requiring constant centralized coordination
Solution Approach 2:
The patent segments the VDL management system into multiple independent components distributed across different nodes. Instead of a monolithic centralized VDL manager, the system divides VDL indicator storage, management, and enforcement functions across multiple edge data volume nodes. Each segment operates semi-independently, managing its own VDL indicators and only coordinating with the master metadata node when necessary for synchronization, thereby reducing overall network bandwidth consumption
3Reliability
If VDL indicators are synchronized at the master metadata node, then data access control consistency is maintained, but network traffic and processing overhead increase
Solution Approach 1:
The patent applies preliminary action by pre-calculating and pre-distributing VDL indicator values to edge data volume nodes before they are needed for access control decisions. The master metadata node generates VDL indicators in advance and distributes them to relevant edge nodes proactively, rather than waiting for access requests to trigger synchronization. This preliminary distribution reduces the frequency and volume of network traffic during actual data access operations, as edge nodes can independently enforce VDL controls using pre-received indicators
Data Source
AI summary
Some storage systems are configured with VDL (valid data length) type controls that are implemented on a per cluster basis and, in some instances, on a sub-cluster basis, rather than simply a per file basis. In some instances, per-cluster VDL metadata for the storage clusters is stored and referenced at the edge data volume nodes of a distributed network for the storage system rather than, and/or without, storing or synchronizing the per-cluster VDL metadata at a master node that manages the corresponding storage clusters for the different data volume nodes. Sequence controls are also provided and managed by the master node and synchronized with the edge data volume nodes to further control access to data contained in the storage clusters.


