Storage Resource Group Allocation for Multi-User Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a multi-tenancy storage system environment, there is an imbalance in resource allocation and insecurity between users when multiple management users manage shared resources, leading to inefficiencies and security risks.
Innovation Solution
A computer system that includes a storage system and a management device, where resources are grouped into user-defined groups, and access permissions are granted based on user group affiliations, allowing balanced resource allocation and enhanced security through logical partitioning and user-specific authority management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple management users are provided to manage shared storage resources, then resource utilization efficiency is improved, but information security between users deteriorates
Solution Approach 1:
The patent segments storage resources into distinct storage resource groups (RSGs) that can be independently allocated to different user groups. Each RSG acts as an isolated unit with its own access control list (ACL), preventing users from accessing resources belonging to other groups while maintaining efficient shared resource utilization across authorized users.
Solution Approach 2:
The patent introduces storage resource group (RSG) as an intermediary layer between individual users and physical storage devices. The RSG structure with ACLs serves as a mediator that enforces access control policies, allowing multiple users to share storage resources efficiently while maintaining security boundaries through group-based permission management.
2Reliability
If storage resources are logically partitioned into resource groups, then security between host computers is improved, but device complexity increases
Solution Approach 1:
The patent implements storage resource groups that serve multiple functions simultaneously: they provide logical partitioning for security isolation, enable efficient resource allocation and sharing, support access control through ACLs, and facilitate dynamic resource management. This multi-functionality reduces the need for separate mechanisms, thereby limiting the increase in device complexity.
Solution Approach 2:
The patent employs a nested structure where storage resource groups contain storage resources, and user groups are associated with RSGs through allocation relationships. This nested organization (users → user groups → RSGs → storage resources) provides hierarchical access control while maintaining a unified management structure that simplifies the overall system architecture.
3Reliability
If access permissions are granted based on user group affiliations, then information security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges access control functionality into the existing user group management framework. By combining permission granting with user group affiliation, the system eliminates the need for separate complex permission assignment mechanisms. Users inherit access rights automatically through their group memberships, simplifying operation while maintaining strong security.
Solution Approach 2:
The patent implements self-service access control where users automatically receive appropriate permissions based on their group affiliations without requiring manual permission assignment. The system autonomously manages access rights by evaluating user-group-RSG relationships, reducing operational complexity while ensuring consistent security enforcement.
Data Source
AI summary
A computer system and its control method capable of allocating resources to a plurality of users in a balanced manner and ensuring information security between the users even when the plurality of users are made to extensively manage a storage system are provided.The storage system includes: a plurality of resource groups defined by grouping of a plurality of resources; a storage area for storing management information of the plurality of resource groups and association information between the plurality of resources and the plurality of resource groups; and a plurality of user groups defined by grouping of the plurality of users, each of the user groups being allocated to at least one of the plurality of resource groups; wherein based on login of at least one user from among the plurality of users, a management device has the storage system execute operation permitted by an authority granted to the user group, to which the relevant user belongs, on the resource group allocated to the user group.


