Resource Fencing via Network Aliases in Multi-Tenant Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant data systems, ensuring data access restrictions are maintained during failover to a site with a different network topology is challenging, as traditional methods rely on mirroring the primary site's network topology, which is impractical and can render tenants inaccessible due to topology mismatches.
Innovation Solution
The system employs a mechanism to map access restrictions from the primary site to a replica site using network aliases, allowing flexible enforcement of access controls even when the replica site has a sparser network topology, by binding each capability to a specific IP network and using destination IP address filtering to grant or deny access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the replica site mirrors the network topology of the primary site to maintain access restrictions, then data access security is improved, but device complexity and ease of operation deteriorate due to the impracticality of maintaining identical topologies
Solution Approach 1:
The patent introduces network aliases as an intermediary layer between the replica site's actual network topology and the access restriction requirements. Instead of requiring identical network topologies, the system uses alias entries to map destination IP addresses to available networks at the replica site, allowing access restrictions to be maintained through this intermediary mapping mechanism rather than through direct topology mirroring
Solution Approach 2:
The system changes the parameter of network identification from requiring exact topology matches to using flexible IP address-to-network mappings. By allowing the destination network IP address binding to be decoupled from the physical network topology through alias entries, the system transforms the rigid parameter of topology identity into a flexible parameter of logical address mapping
2Device complexity
If the replica site uses a sparser network topology to reduce device complexity, then ease of operation is improved, but data access security deteriorates due to inability to maintain access restrictions
Solution Approach 1:
Network aliases serve as the intermediary that bridges the gap between the simplified replica network topology and the security requirements. The alias mechanism allows the system to maintain access restrictions through logical IP address mappings rather than requiring the physical network structure to match security zone requirements
Solution Approach 2:
The patent segments the network identification function into two independent parts: the actual physical network topology and the logical access restriction mapping. This segmentation allows the replica site to use a simplified physical topology while maintaining security through the separate logical mapping layer provided by network aliases
3Reliability
If traditional firewall-based packet rejection is used to enforce access restrictions, then data access security is improved, but device complexity worsens due to the need for complex firewall configurations across multiple networks
Solution Approach 1:
The patent extracts the access restriction enforcement mechanism from the network layer (firewall) and moves it to the application layer. Instead of using firewall rules to enforce security, the system binds capabilities to specific destination IP addresses and enforces restrictions at the application level by checking whether the requesting network matches the bound destination address, thereby removing the need for complex firewall configurations
Data Source
AI summary
A storage system has a plurality of nodes which are grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants. A node in the cluster system comprises: a memory, and a controller operable to bind each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and has a destination IP address of the IP network to which the capability is bound. It is permissible for one or more capabilities to be bound to the same IP network. Each IP network has one corresponding network interface.


