Storage Cluster Tenant Communication Isolation via Virtual Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Datacenters face security concerns and resource challenges in managing communications between storage tenants and storage cluster systems, as existing solutions require installing third-party communication components that can be difficult to control and maintain, leading to potential data collisions and communication errors.

Innovation Solution

The storage cluster system hosts tenant communication components, establishing dedicated virtual networks to ensure secure and isolated communication between storage tenants and the storage cluster, reducing the need for additional hardware or software at the datacenter and allowing for controlled updates and error prevention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate communication components are installed at the datacenter for each storage tenant, then secure isolated communication is achieved, but device complexity and maintenance resources increase tremendously

Engineering Contradiction:
Improvesecure isolated communicationVSAvoidnumber of communication components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple tenant communication components into a single shared communication component at the datacenter. This single component services multiple storage tenants by establishing separate virtual network connections for each tenant, thereby reducing device complexity while maintaining secure isolated communication through logical separation rather than physical separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared communication component is designed to perform multiple functions by serving different storage tenants through a single instance. It can establish multiple virtual network connections, handle different tenant data streams, and provide isolated communication channels for multiple tenants simultaneously, making the component universal and multi-functional.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If third party communication components are installed at the datacenter, then communication between datacenter and storage system is enabled, but security control becomes difficult

Engineering Contradiction:
Improvecommunication capabilityVSAvoiduncontrolled data access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a broker as an intermediary component that sits between the shared communication component and the storage tenants. The broker acts as a mediator that controls and regulates data access, ensuring that communication capabilities are provided while security is maintained through the broker's mediation and validation of data exchanges.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The shared communication component and broker are deployed and managed by the storage system provider rather than requiring third-party components at the datacenter. This self-service approach allows the provider to maintain full control over security policies, access rights, and communication protocols, eliminating the security control issues associated with third-party components.

Inventive Principle:
Principle #25Self-service

3Reliability

If communication components are maintained by the storage system entity, then communication problems from datacenter updates can occur, but maintaining components requires tremendous time and resources

Engineering Contradiction:
Improvecommunication stabilityVSAvoidmaintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By merging multiple tenant communication functions into a single shared communication component, the patent reduces the total number of components that need maintenance. This consolidation means fewer patches and updates are required compared to maintaining separate components for each tenant, thereby reducing maintenance time and resources while maintaining communication stability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12160475B2Secure communications of storage tenants that share a storage cluster system
Publication Date: 2024.12.03 COHESITY INC
  • US12160475B2 patent drawing
  • US12160475B2 patent drawing
  • US12160475B2 patent drawing

AI summary

A response communication that includes one or more data packets is received at a broker associated with a storage node of a plurality of storage nodes via a virtual network associated with the plurality of storage nodes of a storage system. The one or more data packets are provided, via the virtual network associated with the storage nodes, to a tenant communication component associated with an intended destination. A connection between the broker and the tenant communication component associated with the intended destination is terminated. A new connection between the intended destination and the tenant communication component associated with the intended destination is established. The new connection is associated with a virtual network associated with a storage tenant. The one or more data packets are sent to the intended destination via the virtual network associated with the storage tenant.