Storage Cluster VDL Controls for Secure Tenant Reallocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage systems face vulnerabilities due to lingering exposure of deleted data, particularly in multi-tenant scenarios, where reallocated storage clusters can reveal sensitive information unless fully initialized, which is computationally expensive and burdens network bandwidth.
Innovation Solution
Implementing valid data length (VDL) controls on a per-cluster basis, with VDL indicators maintained at edge data volume nodes and sequence numbers centrally managed by a master metadata node, reducing the need for synchronization with a centralized management node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive initialization of storage clusters is performed when deallocated and reallocated, then data security is improved by preventing exposure of deleted data, but computational cost and impact on system performance increase
Solution Approach 1:
The patent applies partial action by implementing VDL controls only when necessary - specifically when storage clusters are reallocated between different tenants or files. Instead of initializing all storage clusters comprehensively, the system selectively applies security controls to prevent exposure of deleted data while avoiding unnecessary initialization operations that would impact performance.
Solution Approach 2:
The system performs preliminary action by setting VDL indicators to an initialized state when storage clusters are deallocated, before they are reallocated to new files or tenants. This preliminary marking prevents potential data exposure without requiring actual initialization of the storage bits, thus maintaining security while reducing computational overhead.
2Reliability
If per-file VDL controls are managed from a centralized node, then data access control is improved, but network bandwidth consumption increases due to synchronization requirements
Solution Approach 1:
The patent segments the VDL management functionality by implementing it at the edge data volume nodes rather than requiring centralized management. Each edge node independently manages its own VDL indicators for local storage clusters, eliminating the need for continuous synchronization with a centralized node and reducing network bandwidth consumption while maintaining data access control.
3Productivity
If storage clusters are reallocated without initialization in a multi-tenant scenario, then system responsiveness is improved, but data vulnerability increases allowing new tenants to access previous tenant's data
Solution Approach 1:
The patent introduces VDL indicators as an intermediary control mechanism between storage cluster reallocation and data access. When storage clusters are reallocated, the VDL indicator is set to an initialized state, acting as a mediator that prevents new tenants from accessing previous data without requiring actual initialization of the storage bits. This maintains system responsiveness while eliminating data vulnerability.
Data Source
AI summary
Some storage systems are configured with VDL (valid data length) type controls that are implemented on a per cluster basis and, in some instances, on a sub-cluster basis, rather than simply a per file basis. In some instances, per-cluster VDL metadata for the storage clusters is stored and referenced at the edge data volume nodes of a distributed network for the storage system rather than, and/or without, storing or synchronizing the per-cluster VDL metadata at a master node that manages the corresponding storage clusters for the different data volume nodes. Sequence controls are also provided and managed by the master node and synchronized with the edge data volume nodes to further control access to data contained in the storage clusters.


