Metadata Server Virtual Machine Grouping for Distributed Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed storage systems deployed in virtualization environments face security and stability risks due to the need to disclose physical server positions and virtual machine distribution statuses, compromising the security and stability of both physical servers and the virtualization environment.
Innovation Solution
A data storage method where a metadata server determines identifiers of virtual machines based on grouping information, allowing data storage without revealing physical server addresses or virtual machine distribution statuses, by using anti-affinity or affinity groups to ensure secure and stable data storage across multiple virtual machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the distributed storage system uses physical server addresses and virtual machine distribution status for data storage, then data storage functionality is achieved, but security and stability of physical servers and virtualization environment are compromised
Solution Approach 1:
The patent introduces an intermediary mapping mechanism where the metadata server acts as a mediator between the client and physical storage resources. Instead of directly exposing physical server addresses, the system uses virtual machine identifiers and mapping relationships stored in the metadata server to route data operations. This intermediary layer prevents direct exposure of physical infrastructure details while maintaining full data storage and retrieval functionality.
Solution Approach 2:
The patent creates an abstracted copy of the storage system topology through virtual machine identifiers and logical mapping relationships. Rather than using real physical server addresses, the system maintains a virtual representation of the storage network where VM IDs serve as proxies for actual physical locations. This copying approach allows the system to function with virtual addresses that do not reveal sensitive physical infrastructure information.
2Productivity
If the system discloses virtual machine distribution status for data storage routing, then data storage efficiency is improved, but security risks to physical servers increase
Solution Approach 1:
The metadata server serves as an intermediary that holds the mapping information between virtual machine identifiers and physical storage locations. When data storage operations are needed, the client queries the metadata server which returns routing information without exposing the complete virtual machine distribution status. This intermediary approach maintains storage efficiency by enabling proper data routing while limiting the exposure of sensitive distribution information.
Solution Approach 2:
The patent applies local quality by providing different levels of information access to different components. The metadata server stores complete mapping relationships for internal routing purposes, but only exposes necessary routing information to clients. This selective information disclosure maintains data storage efficiency while reducing security risks by not uniformly exposing all distribution status information.
3Ease of operation
If the distributed storage system queries physical server addresses through virtual machine manager, then data storage routing is enabled, but stability of physical servers and virtualization environment is reduced
Solution Approach 1:
The system maintains a copied or abstracted view of the storage topology through virtual machine identifiers rather than directly querying and exposing physical server addresses. The metadata server stores mapping relationships that replicate the necessary routing information in a virtualized form, enabling data storage routing without direct dependence on physical server address queries through the virtual machine manager.
Solution Approach 2:
The patent segments the information access into multiple layers: the virtual machine manager manages virtual machine lifecycle, the metadata server manages mapping relationships, and clients access only necessary routing information. This segmentation reduces the stability impact by isolating queries to specific components rather than requiring broad information exchange across the entire virtualization environment.
Data Source
AI summary
A data storage method and a physical server are provided. M virtual machines are deployed on a plurality of physical servers. The M virtual machines are respectively deployed as M data nodes in a distributed storage system. A metadata node in the distributed storage system receives a data storage request of a client, and determines identifiers of N virtual machines from the M virtual machines based on stored grouping information. The grouping information records a mapping relationship between a plurality of anti-affinity groups and identifiers of the M virtual machines.


