Metadata Server Virtual Machine Grouping for Distributed Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed storage systems deployed in virtualization environments face security and stability risks due to the need to disclose physical server positions and virtual machine distribution statuses, compromising the security and stability of both physical servers and the virtualization environment.

Innovation Solution

A data storage method where a metadata server determines identifiers of virtual machines based on grouping information, allowing data storage without revealing physical server addresses or virtual machine distribution statuses, by using anti-affinity or affinity groups to ensure secure and stable data storage across multiple virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the distributed storage system uses physical server addresses and virtual machine distribution status for data storage, then data storage functionality is achieved, but security and stability of physical servers and virtualization environment are compromised

Engineering Contradiction:
Improvesecurity and stabilityVSAvoidphysical server address leakage
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary mapping mechanism where the metadata server acts as a mediator between the client and physical storage resources. Instead of directly exposing physical server addresses, the system uses virtual machine identifiers and mapping relationships stored in the metadata server to route data operations. This intermediary layer prevents direct exposure of physical infrastructure details while maintaining full data storage and retrieval functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates an abstracted copy of the storage system topology through virtual machine identifiers and logical mapping relationships. Rather than using real physical server addresses, the system maintains a virtual representation of the storage network where VM IDs serve as proxies for actual physical locations. This copying approach allows the system to function with virtual addresses that do not reveal sensitive physical infrastructure information.

Inventive Principle:
Principle #26Copying

2Productivity

If the system discloses virtual machine distribution status for data storage routing, then data storage efficiency is improved, but security risks to physical servers increase

Engineering Contradiction:
Improvedata storage efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The metadata server serves as an intermediary that holds the mapping information between virtual machine identifiers and physical storage locations. When data storage operations are needed, the client queries the metadata server which returns routing information without exposing the complete virtual machine distribution status. This intermediary approach maintains storage efficiency by enabling proper data routing while limiting the exposure of sensitive distribution information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by providing different levels of information access to different components. The metadata server stores complete mapping relationships for internal routing purposes, but only exposes necessary routing information to clients. This selective information disclosure maintains data storage efficiency while reducing security risks by not uniformly exposing all distribution status information.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the distributed storage system queries physical server addresses through virtual machine manager, then data storage routing is enabled, but stability of physical servers and virtualization environment is reduced

Engineering Contradiction:
Improvedata storage routing capabilityVSAvoidvirtualization environment stability
Core Design Contradiction:
Ease of operationVSStability of the object's composition

Solution Approach 1:

The system maintains a copied or abstracted view of the storage topology through virtual machine identifiers rather than directly querying and exposing physical server addresses. The metadata server stores mapping relationships that replicate the necessary routing information in a virtualized form, enabling data storage routing without direct dependence on physical server address queries through the virtual machine manager.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent segments the information access into multiple layers: the virtual machine manager manages virtual machine lifecycle, the metadata server manages mapping relationships, and clients access only necessary routing information. This segmentation reduces the stability impact by isolating queries to specific components rather than requiring broad information exchange across the entire virtualization environment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11036535B2Data storage method and apparatus
Publication Date: 2021.06.15 HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
  • US11036535B2 patent drawing
  • US11036535B2 patent drawing
  • US11036535B2 patent drawing

AI summary

A data storage method and a physical server are provided. M virtual machines are deployed on a plurality of physical servers. The M virtual machines are respectively deployed as M data nodes in a distributed storage system. A metadata node in the distributed storage system receives a data storage request of a client, and determines identifiers of N virtual machines from the M virtual machines based on stored grouping information. The grouping information records a mapping relationship between a plurality of anti-affinity groups and identifiers of the M virtual machines.