Resource Fencing via Network Aliases in Multi-Tenant Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-tenant data systems, ensuring data access restrictions are maintained during failover to a site with a different network topology is challenging, as traditional methods rely on mirroring the primary site's network topology, which is impractical and can render tenants inaccessible due to topology mismatches.

Innovation Solution

The system employs a mechanism to map access restrictions from the primary site to a replica site using network aliases, allowing flexible enforcement of access controls even when the replica site has a sparser network topology, by binding each capability to a specific IP network and using destination IP address filtering to grant or deny access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the replica site mirrors the network topology of the primary site to maintain access restrictions, then data access security is improved, but device complexity and ease of operation deteriorate due to the impracticality of maintaining identical topologies

Engineering Contradiction:
Improvedata access securityVSAvoidnetwork topology configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces network aliases as an intermediary layer between the replica site's actual network topology and the access restriction requirements. Instead of requiring identical network topologies, the system uses alias entries to map destination IP addresses to available networks at the replica site, allowing access restrictions to be maintained through this intermediary mapping mechanism rather than through direct topology mirroring

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of network identification from requiring exact topology matches to using flexible IP address-to-network mappings. By allowing the destination network IP address binding to be decoupled from the physical network topology through alias entries, the system transforms the rigid parameter of topology identity into a flexible parameter of logical address mapping

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If the replica site uses a sparser network topology to reduce device complexity, then ease of operation is improved, but data access security deteriorates due to inability to maintain access restrictions

Engineering Contradiction:
Improvenetwork topology configurationVSAvoiddata access security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Network aliases serve as the intermediary that bridges the gap between the simplified replica network topology and the security requirements. The alias mechanism allows the system to maintain access restrictions through logical IP address mappings rather than requiring the physical network structure to match security zone requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network identification function into two independent parts: the actual physical network topology and the logical access restriction mapping. This segmentation allows the replica site to use a simplified physical topology while maintaining security through the separate logical mapping layer provided by network aliases

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional firewall-based packet rejection is used to enforce access restrictions, then data access security is improved, but device complexity worsens due to the need for complex firewall configurations across multiple networks

Engineering Contradiction:
Improvedata access securityVSAvoidfirewall configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the access restriction enforcement mechanism from the network layer (firewall) and moves it to the application layer. Instead of using firewall rules to enforce security, the system binds capabilities to specific destination IP addresses and enforces restrictions at the application level by checking whether the requesting network matches the bound destination address, thereby removing the need for complex firewall configurations

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9954947B2Resource fencing for vLAN multi-tenant systems
Publication Date: 2018.04.24 HITACHI VANTARA LLC
  • US9954947B2 patent drawing
  • US9954947B2 patent drawing
  • US9954947B2 patent drawing

AI summary

A storage system has a plurality of nodes which are grouped into a plurality of cluster systems each having multiple nodes, each cluster system being logically partitioned into a plurality of namespaces, each namespace including a collection of data objects, each cluster system having multiple tenants, each tenant being a grouping of namespaces, each cluster system having a plurality of capabilities, at least some of the capabilities being bound to the tenants. A node in the cluster system comprises: a memory, and a controller operable to bind each capability to one of a plurality of IP networks so that each capability is bound to only one of the IP networks and has a destination IP address of the IP network to which the capability is bound. It is permissible for one or more capabilities to be bound to the same IP network. Each IP network has one corresponding network interface.