Serverless Storage Domain Management via Multiple Master Approach

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage system environments face challenges in managing secure communications connections, particularly as the number of data storage systems increases, leading to a burden on administrators for credential renewal and introducing single points of failure with domain management servers.

Innovation Solution

Implementing a multiple master approach where each data storage system can function as an owner of its domain, allowing for authentication, addition/removal of members, and modification of domain credentials without a central domain management server, distributing domain definitions and membership information among members.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a domain management server is used to manage credentials for multiple storage systems, then the administrative burden of credential renewal is reduced, but a single point of failure is introduced and system complexity increases

Engineering Contradiction:
Improveadministrative burdenVSAvoidsingle point of failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a domain management server as an intermediary that centralizes credential management. This server acts as a mediator between storage systems, handling authentication and credential distribution. By centralizing these functions, the system reduces administrative burden while maintaining security through controlled credential renewal without requiring direct peer-to-peer credential management between storage systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The domain management server performs multiple functions including credential storage, authentication verification, credential renewal coordination, and domain membership management. This multi-functional approach consolidates what would otherwise require separate mechanisms in each storage system, reducing overall system complexity while improving ease of operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If peer-to-peer authentication is implemented between storage systems, then system complexity is reduced, but the administrative burden of credential management increases significantly

Engineering Contradiction:
Improvesystem complexityVSAvoidadministrative burden
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent extracts the credential management functionality from individual storage systems and consolidates it into a dedicated domain management server. This separation allows storage systems to maintain simpler peer-to-peer authentication mechanisms while the domain management server handles the complex tasks of credential storage, renewal, and distribution, thereby reducing administrative burden without significantly increasing overall system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If a domain management server is implemented, then credential management is simplified, but cost and system complexity increase

Engineering Contradiction:
Improvecredential managementVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The domain management server is designed to autonomously handle credential renewal processes without requiring manual administrative intervention. It automatically monitors credential expiration, initiates renewal procedures, and distributes updated credentials to relevant storage systems. This self-service capability simplifies credential management while minimizing the need for additional administrative infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10986091B2Systems and methods of serverless management of data mobility domains
Publication Date: 2021.04.20 EMC IP HLDG CO LLC
  • US10986091B2 patent drawing
  • US10986091B2 patent drawing
  • US10986091B2 patent drawing

AI summary

Techniques for managing data mobility domains in storage system environments. The techniques employ a multiple master approach, in which each storage system in a storage system domain can function as an owner of the domain. Each domain owner has privileges pertaining to addition of new members to the domain, removal of members from the domain, and modification of domain credentials. When a new storage system is added as a member of the domain, the domain credentials are provided from the domain owner to the new storage system, resulting in the domain credentials being shared among all members of the domain. Domain membership information is also shared among all members of the domain. In this way, the management of storage system domains can be achieved without the need of a domain management server, avoiding a single point of failure or latency and reducing the complexity/cost associated with the domain management server.