RDMA Control Service for Cloud Instance Access Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Access isolation for different users accessing an RDMA network node is traditionally problematic in RoCE-based RDMA communication systems, particularly in public cloud instances, due to the reliance on TCP/IP for routing and the shared nature of the infrastructure.
Innovation Solution
An RDMA control service assigns an address segment to instances based on user information and connection relationships, builds an access control list to manage access between instances, and sends this list to a switch control service for configuration, ensuring access control between different instances defined by the same user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If RoCE-based RDMA communication is used on public cloud instances, then data transmission efficiency is improved, but access isolation between different users deteriorates
Solution Approach 1:
The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.
Solution Approach 2:
The patent introduces an RDMA control service as an intermediary between users and the RDMA network infrastructure. This service manages address segment assignments, maintains mapping relationships, and controls access permissions. By placing this intermediary layer, the system enables efficient RoCE communication while enforcing user-specific access isolation policies.
2Adaptability or versatility
If TCP/IP protocol is used for routing, then network compatibility is improved, but access isolation control deteriorates
Solution Approach 1:
The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.
Solution Approach 2:
The patent implements local quality control by applying different access control policies to different address segments. Each user's address segment has its own access control list (ACL) with specific permissions, allowing the system to maintain TCP/IP compatibility for routing while enforcing user-specific isolation policies at the local segment level.
3Productivity
If shared infrastructure is used, then resource utilization is improved, but access security deteriorates
Solution Approach 1:
The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.
Solution Approach 2:
The patent introduces an RDMA control service as an intermediary between users and the RDMA network infrastructure. This service manages address segment assignments, maintains mapping relationships, and controls access permissions. By placing this intermediary layer, the system enables efficient RoCE communication while enforcing user-specific access isolation policies.
Data Source
AI summary
Embodiments of this application relate to the data access field, including data access methods systems that enable efficient and effective data access. In one embodiment, a method includes: assigning, by an RDMA control service based on user information and a corresponding connection relationship between a switch and a first instance defined by a user, an address segment to the first instance; building, by the RDMA control service, an access control list based on the address segment assigned to the first instance, where the access control list is used for controlling access between different first instances defined by the user; and sending, by the RDMA control service, the access control list to a switch control service, such that the switch control service configures the access control list for the switch. In one embodiment, access between different instances defined by a same user can be effectively controlled, thereby effectively resolving an issue of access isolation for different users accessing an RDMA network node.


