Tenant-Specific Node Authorization in NAS Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches for isolating different tenants in NAS clusters do not scale effectively, particularly in large clusters with many NAS data nodes, and fail to provide sufficient isolation and quality of service.

Innovation Solution

A management database tracks tenant-specific lists of authorized NAS data nodes for each tenant, limiting the scope of NAS data nodes on which tenant-owned NAS servers can operate, enabling computational isolation and improving quality of service by managing activities like provisioning, load balancing, and failover.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional approaches for isolating different tenants are used in NAS clusters, then tenant isolation is provided at basic levels, but the system does not scale effectively to large clusters with many NAS data nodes

Engineering Contradiction:
Improvetenant isolation capabilityVSAvoidsystem scalability
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments tenant isolation to the per-NAS-data-node level by introducing tenant-specific lists that track which NAS data nodes are authorized to run NAS servers for each tenant. This fine-grained segmentation enables the system to scale to large clusters while maintaining effective tenant isolation, as each tenant's computational activities are confined to specific authorized nodes rather than being isolated at coarser system levels.

Inventive Principle:
Principle #1Segmentation

2Reliability

If conventional approaches for isolating different tenants are used in NAS clusters, then basic tenant separation is achieved, but computational isolation and quality of service are insufficient

Engineering Contradiction:
Improvetenant separationVSAvoidcomputational isolation quality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing tenant-specific lists that provide differentiated authorization levels for each tenant. Instead of uniform isolation across all tenants, the system allows customized control where each tenant can be assigned specific NAS data nodes based on their computational isolation requirements. This enables varying degrees of computational isolation and quality of service for different tenants while maintaining reliable separation.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If tenant-specific lists of authorized NAS data nodes are tracked, then computational isolation and quality of service improve, but system complexity increases

Engineering Contradiction:
Improvecomputational isolationVSAvoidmanagement database structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a management database as an intermediary component that handles the complexity of tracking tenant-specific lists of authorized NAS data nodes. This intermediary abstracts the complexity from the core NAS operations, providing computational isolation and quality of service control through a centralized management layer. The management database systematically organizes tenant-authorizations and NAS data node mappings, making the complexity manageable and controllable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10289325B1Managing multiple tenants in NAS (network attached storage) clusters
Publication Date: 2019.05.14 EMC IP HLDG CO LLC
  • US10289325B1 patent drawing
  • US10289325B1 patent drawing
  • US10289325B1 patent drawing

AI summary

A technique for supporting multi-tenancy in a NAS cluster provides a management database which tracks, for each tenant of the NAS cluster, a tenant-specific list of identifiers of NAS data nodes that are authorized to run NAS servers owned by respective tenants. In response to a request to run a NAS server owned by a particular tenant of the NAS cluster, the technique limits the scope of NAS data nodes on which the NAS server may be run to the ones identified in the tenant-specific list for that tenant in the management database. The management database thus determines where each tenant's NAS servers may be run, and participates in driving NAS cluster activities, such as NAS server provisioning, load balancing, and failover.