RDMA Control Service for Cloud Instance Access Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Access isolation for different users accessing an RDMA network node is traditionally problematic in RoCE-based RDMA communication systems, particularly in public cloud instances, due to the reliance on TCP/IP for routing and the shared nature of the infrastructure.

Innovation Solution

An RDMA control service assigns an address segment to instances based on user information and connection relationships, builds an access control list to manage access between instances, and sends this list to a switch control service for configuration, ensuring access control between different instances defined by the same user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If RoCE-based RDMA communication is used on public cloud instances, then data transmission efficiency is improved, but access isolation between different users deteriorates

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidaccess isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an RDMA control service as an intermediary between users and the RDMA network infrastructure. This service manages address segment assignments, maintains mapping relationships, and controls access permissions. By placing this intermediary layer, the system enables efficient RoCE communication while enforcing user-specific access isolation policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If TCP/IP protocol is used for routing, then network compatibility is improved, but access isolation control deteriorates

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidaccess isolation control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality control by applying different access control policies to different address segments. Each user's address segment has its own access control list (ACL) with specific permissions, allowing the system to maintain TCP/IP compatibility for routing while enforcing user-specific isolation policies at the local segment level.

Inventive Principle:
Principle #3Local quality

3Productivity

If shared infrastructure is used, then resource utilization is improved, but access security deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidaccess security
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the address space by assigning unique address segments to different users and instances. The RDMA control service maintains an address segment mapping relationship that divides the overall address space into isolated segments, ensuring that each user's instances can only access resources within their assigned segment, thereby achieving access isolation while maintaining RoCE-based high-speed communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an RDMA control service as an intermediary between users and the RDMA network infrastructure. This service manages address segment assignments, maintains mapping relationships, and controls access permissions. By placing this intermediary layer, the system enables efficient RoCE communication while enforcing user-specific access isolation policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11863520B2Data access methods and systems
Publication Date: 2024.01.02 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US11863520B2 patent drawing
  • US11863520B2 patent drawing
  • US11863520B2 patent drawing

AI summary

Embodiments of this application relate to the data access field, including data access methods systems that enable efficient and effective data access. In one embodiment, a method includes: assigning, by an RDMA control service based on user information and a corresponding connection relationship between a switch and a first instance defined by a user, an address segment to the first instance; building, by the RDMA control service, an access control list based on the address segment assigned to the first instance, where the access control list is used for controlling access between different first instances defined by the user; and sending, by the RDMA control service, the access control list to a switch control service, such that the switch control service configures the access control list for the switch. In one embodiment, access between different instances defined by a same user can be effectively controlled, thereby effectively resolving an issue of access isolation for different users accessing an RDMA network node.