Tenant-Specific Node Authorization in NAS Clusters
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches for isolating different tenants in NAS clusters do not scale effectively, particularly in large clusters with many NAS data nodes, and fail to provide sufficient isolation and quality of service.
Innovation Solution
A management database tracks tenant-specific lists of authorized NAS data nodes for each tenant, limiting the scope of NAS data nodes on which tenant-owned NAS servers can operate, enabling computational isolation and improving quality of service by managing activities like provisioning, load balancing, and failover.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional approaches for isolating different tenants are used in NAS clusters, then tenant isolation is provided at basic levels, but the system does not scale effectively to large clusters with many NAS data nodes
Solution Approach 1:
The patent segments tenant isolation to the per-NAS-data-node level by introducing tenant-specific lists that track which NAS data nodes are authorized to run NAS servers for each tenant. This fine-grained segmentation enables the system to scale to large clusters while maintaining effective tenant isolation, as each tenant's computational activities are confined to specific authorized nodes rather than being isolated at coarser system levels.
2Reliability
If conventional approaches for isolating different tenants are used in NAS clusters, then basic tenant separation is achieved, but computational isolation and quality of service are insufficient
Solution Approach 1:
The patent applies local quality by implementing tenant-specific lists that provide differentiated authorization levels for each tenant. Instead of uniform isolation across all tenants, the system allows customized control where each tenant can be assigned specific NAS data nodes based on their computational isolation requirements. This enables varying degrees of computational isolation and quality of service for different tenants while maintaining reliable separation.
3Ease of operation
If tenant-specific lists of authorized NAS data nodes are tracked, then computational isolation and quality of service improve, but system complexity increases
Solution Approach 1:
The patent introduces a management database as an intermediary component that handles the complexity of tracking tenant-specific lists of authorized NAS data nodes. This intermediary abstracts the complexity from the core NAS operations, providing computational isolation and quality of service control through a centralized management layer. The management database systematically organizes tenant-authorizations and NAS data node mappings, making the complexity manageable and controllable.
Data Source
AI summary
A technique for supporting multi-tenancy in a NAS cluster provides a management database which tracks, for each tenant of the NAS cluster, a tenant-specific list of identifiers of NAS data nodes that are authorized to run NAS servers owned by respective tenants. In response to a request to run a NAS server owned by a particular tenant of the NAS cluster, the technique limits the scope of NAS data nodes on which the NAS server may be run to the ones identified in the tenant-specific list for that tenant in the management database. The management database thus determines where each tenant's NAS servers may be run, and participates in driving NAS cluster activities, such as NAS server provisioning, load balancing, and failover.


