Serverless Storage Domain Management via Multiple Master Approach
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage system environments face challenges in managing secure communications connections, particularly as the number of data storage systems increases, leading to a burden on administrators for credential renewal and introducing single points of failure with domain management servers.
Innovation Solution
Implementing a multiple master approach where each data storage system can function as an owner of its domain, allowing for authentication, addition/removal of members, and modification of domain credentials without a central domain management server, distributing domain definitions and membership information among members.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a domain management server is used to manage credentials for multiple storage systems, then the administrative burden of credential renewal is reduced, but a single point of failure is introduced and system complexity increases
Solution Approach 1:
The patent introduces a domain management server as an intermediary that centralizes credential management. This server acts as a mediator between storage systems, handling authentication and credential distribution. By centralizing these functions, the system reduces administrative burden while maintaining security through controlled credential renewal without requiring direct peer-to-peer credential management between storage systems.
Solution Approach 2:
The domain management server performs multiple functions including credential storage, authentication verification, credential renewal coordination, and domain membership management. This multi-functional approach consolidates what would otherwise require separate mechanisms in each storage system, reducing overall system complexity while improving ease of operation.
2Device complexity
If peer-to-peer authentication is implemented between storage systems, then system complexity is reduced, but the administrative burden of credential management increases significantly
Solution Approach 1:
The patent extracts the credential management functionality from individual storage systems and consolidates it into a dedicated domain management server. This separation allows storage systems to maintain simpler peer-to-peer authentication mechanisms while the domain management server handles the complex tasks of credential storage, renewal, and distribution, thereby reducing administrative burden without significantly increasing overall system complexity.
3Ease of operation
If a domain management server is implemented, then credential management is simplified, but cost and system complexity increase
Solution Approach 1:
The domain management server is designed to autonomously handle credential renewal processes without requiring manual administrative intervention. It automatically monitors credential expiration, initiates renewal procedures, and distributes updated credentials to relevant storage systems. This self-service capability simplifies credential management while minimizing the need for additional administrative infrastructure.
Data Source
AI summary
Techniques for managing data mobility domains in storage system environments. The techniques employ a multiple master approach, in which each storage system in a storage system domain can function as an owner of the domain. Each domain owner has privileges pertaining to addition of new members to the domain, removal of members from the domain, and modification of domain credentials. When a new storage system is added as a member of the domain, the domain credentials are provided from the domain owner to the new storage system, resulting in the domain credentials being shared among all members of the domain. Domain membership information is also shared among all members of the domain. In this way, the management of storage system domains can be achieved without the need of a domain management server, avoiding a single point of failure or latency and reducing the complexity/cost associated with the domain management server.


