Storage System Quorum Verification for Data Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing information system cannot maintain a duplex configuration when a failure occurs in the quorum apparatus, leading to potential data mismatch and improper data being provided to the host computer.
Innovation Solution
The system includes two storage apparatuses and two quorum apparatuses, with each storage apparatus determining its execution feasibility based on survival information stored and checked through the quorum apparatuses, allowing one to execute I/O requests while the other does not, even in the absence of failures in the communication paths, thus maintaining data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one storage apparatus is set to I/O request non-executable when quorum apparatus fails, then data integrity is maintained, but duplex configuration cannot be maintained
Solution Approach 1:
The system segments the quorum verification function by introducing multiple quorum apparatuses (first quorum apparatus and second quorum apparatus). Each storage apparatus can verify survival information through different quorum apparatuses, allowing independent verification paths that prevent total system lockdown when one quorum apparatus fails.
Solution Approach 2:
The system changes the parameter of quorum verification by allowing storage apparatuses to check survival information through alternative quorum apparatuses. When the first quorum apparatus fails, the system transitions to using the second quorum apparatus for verification, maintaining the quorum mechanism's integrity while adapting to the failure condition.
2Productivity
If both storage apparatuses can be accessed by host computer, then availability is improved, but data mismatch and improper data provision may occur
Solution Approach 1:
The system implements feedback through survival information stored in quorum apparatuses. Each storage apparatus continuously checks survival information of the counterpart storage apparatus through the quorum apparatuses. This feedback mechanism allows the system to dynamically determine I/O request executability based on real-time survival status, ensuring data consistency while maintaining availability.
Solution Approach 2:
The system performs preliminary verification by checking survival information in quorum apparatuses before allowing I/O requests to proceed. Storage apparatuses determine executability of I/O requests based on pre-checked survival information, preventing improper data operations before they can occur.
3Reliability
If I/O request executability is restricted to prevent data mismatch, then data integrity is maintained, but system productivity decreases
Solution Approach 1:
The system makes I/O request executability dynamic rather than static. Storage apparatuses continuously update their executability status based on current survival information checks. When the counterpart storage apparatus is confirmed surviving through quorum verification, I/O requests are permitted; when survival cannot be confirmed, executability is restricted. This dynamic adjustment optimizes productivity while maintaining data integrity.
Data Source
AI summary
In an information system including: first and second storage apparatuses executing synchronous copying of data to a counterpart storage device; a first quorum apparatus coupled to the first and the second storage apparatuses; and a second quorum apparatus coupled to the first and the second storage apparatuses, wherein the first and the second storage apparatuses are each configured to perform control to determine whether to execute the I/O request in accordance with an execution feasibility setting, and in health check processing that is repeatedly executed, the first and the second storage apparatuses are each configured to store survival information thereof in the first and the second quorum apparatuses, check whether the survival information of the counterpart storage apparatus is able to be checked from any one of the first and the second quorum apparatuses, and set the execution feasibility setting of the storage apparatus.


