Storage Cluster Tenant Communication Isolation via Virtual Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Datacenters face security concerns and resource challenges in managing communications between storage tenants and storage cluster systems, as existing solutions require installing third-party communication components that can be difficult to control and maintain, leading to potential data collisions and communication errors.
Innovation Solution
The storage cluster system hosts tenant communication components, establishing dedicated virtual networks to ensure secure and isolated communication between storage tenants and the storage cluster, reducing the need for additional hardware or software at the datacenter and allowing for controlled updates and error prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate communication components are installed at the datacenter for each storage tenant, then secure isolated communication is achieved, but device complexity and maintenance resources increase tremendously
Solution Approach 1:
The patent merges multiple tenant communication components into a single shared communication component at the datacenter. This single component services multiple storage tenants by establishing separate virtual network connections for each tenant, thereby reducing device complexity while maintaining secure isolated communication through logical separation rather than physical separation.
Solution Approach 2:
The shared communication component is designed to perform multiple functions by serving different storage tenants through a single instance. It can establish multiple virtual network connections, handle different tenant data streams, and provide isolated communication channels for multiple tenants simultaneously, making the component universal and multi-functional.
2Ease of operation
If third party communication components are installed at the datacenter, then communication between datacenter and storage system is enabled, but security control becomes difficult
Solution Approach 1:
The patent introduces a broker as an intermediary component that sits between the shared communication component and the storage tenants. The broker acts as a mediator that controls and regulates data access, ensuring that communication capabilities are provided while security is maintained through the broker's mediation and validation of data exchanges.
Solution Approach 2:
The shared communication component and broker are deployed and managed by the storage system provider rather than requiring third-party components at the datacenter. This self-service approach allows the provider to maintain full control over security policies, access rights, and communication protocols, eliminating the security control issues associated with third-party components.
3Reliability
If communication components are maintained by the storage system entity, then communication problems from datacenter updates can occur, but maintaining components requires tremendous time and resources
Solution Approach 1:
By merging multiple tenant communication functions into a single shared communication component, the patent reduces the total number of components that need maintenance. This consolidation means fewer patches and updates are required compared to maintaining separate components for each tenant, thereby reducing maintenance time and resources while maintaining communication stability.
Data Source
AI summary
A response communication that includes one or more data packets is received at a broker associated with a storage node of a plurality of storage nodes via a virtual network associated with the plurality of storage nodes of a storage system. The one or more data packets are provided, via the virtual network associated with the storage nodes, to a tenant communication component associated with an intended destination. A connection between the broker and the tenant communication component associated with the intended destination is terminated. A new connection between the intended destination and the tenant communication component associated with the intended destination is established. The new connection is associated with a virtual network associated with a storage tenant. The one or more data packets are sent to the intended destination via the virtual network associated with the storage tenant.


