DATA PROTECTION IN A STORAGE SYSTEM USING EXTERNAL SECRETS

    公开(公告)号:EP3066610B1

    公开(公告)日:2018-06-20

    申请号:EP14796637.8

    申请日:2014-10-27

    IPC分类号: G06F21/62 G06F17/30 H04L9/08

    摘要: A system, method, and computer-readable storage medium for protecting a set of storage devices using a secret sharing scheme in combination with an external secret. An initial master secret is generated and then transformed into a final master secret using an external secret. A plurality of shares are generated from the initial master secret and distributed to the storage devices. The data of each storage device is encrypted with a device-specific key, and this key is encrypted using the final master secret. In order to read the data on a given storage device, the initial master secret reconstructed from a threshold number of shares and the external secret is retrieved. Next, the initial master secret is transformed into the final master secret using the external secret, and then the final master secret is used to decrypt the encrypted key of a given storage device.

    POINT TO POINT BASED BACKEND COMMUNICATION LAYER FOR STORAGE PROCESSING
    5.
    发明公开
    POINT TO POINT BASED BACKEND COMMUNICATION LAYER FOR STORAGE PROCESSING 审中-公开
    点对点存储处理的后端通信层

    公开(公告)号:EP3281129A1

    公开(公告)日:2018-02-14

    申请号:EP16777315.9

    申请日:2016-04-07

    摘要: A storage system is provided. The storage system includes a plurality of storage nodes, each of the plurality of storage nodes having a plurality of storage units with storage memory. The system includes a first network coupling the plurality of storage nodes and a second network coupled to at least a subset of the plurality of storage units of each of the plurality of storage nodes such that one of the plurality of storage units of a first one of the plurality of storage nodes can initiate or relay a command to one of the plurality of storage units of a second one of the plurality of storage nodes via the second network without the command passing through the first network.

    SCHEDULING OF RECONSTRUCTIVE I/O READ OPERATIONS IN A STORAGE ENVIRONMENT
    6.
    发明公开
    SCHEDULING OF RECONSTRUCTIVE I/O READ OPERATIONS IN A STORAGE ENVIRONMENT 审中-公开
    存储环境中重构I / O读操作的调度

    公开(公告)号:EP3206118A1

    公开(公告)日:2017-08-16

    申请号:EP17154034.7

    申请日:2011-09-15

    摘要: A system and method for effectively scheduling read and write operations among a plurality of solid-state storage devices. A computer system comprises client computers and data storage arrays coupled to one another via a network. A data storage array utilizes solid-state drives and Flash memory cells for data storage. A storage controller within a data storage array comprises an I/O scheduler. The storage controller is configured to receive a read request targeted to the data storage medium, and identify at least a first storage device of the plurality of storage devices which contains data targeted by the read request. In response to either detecting or predicting the first storage device will exhibit variable performance, the controller is configured to generate a reconstruct read request configured to obtain the data from one or more devices of the plurality of storage devices other than the first storage device.

    摘要翻译: 一种用于有效地调度多个固态存储设备之间的读取和写入操作的系统和方法。 计算机系统包括经由网络彼此耦合的客户端计算机和数据存储阵列。 数据存储阵列利用固态驱动器和闪存单元进行数据存储。 数据存储阵列内的存储控制器包括I / O调度器。 存储控制器被配置为接收以数据存储介质为目标的读取请求,并且识别包含读取请求的目标数据的多个存储设备中的至少第一存储设备。 响应于检测或预测第一存储设备将呈现可变性能,控制器被配置为生成重建读取请求,该重建读取请求被配置为从除第一存储设备以外的多个存储设备中的一个或多个设备获取数据。

    MECHANISM FOR PERSISTING MESSAGES IN A STORAGE SYSTEM
    7.
    发明公开
    MECHANISM FOR PERSISTING MESSAGES IN A STORAGE SYSTEM 审中-公开
    机构中的机械感应器

    公开(公告)号:EP3152662A1

    公开(公告)日:2017-04-12

    申请号:EP15802652.6

    申请日:2015-06-04

    IPC分类号: G06F11/07 G06F3/06

    摘要: A plurality of storage nodes in a single chassis is provided. The plurality of storage nodes in the single chassis is configured to communicate together as a storage cluster. Each of the plurality of storage nodes includes nonvolatile solid-state memory for user data storage. The plurality of storage nodes is configured to distribute user data and metadata associated with the user data throughout the plurality of storage nodes such that the plurality of storage nodes maintain the ability to read the user data, using erasure coding, despite a loss of two of the plurality of storage nodes. The plurality of storage nodes configured to initiate an action based on the redundant copies of the metadata, responsive to achieving a level of redundancy for the redundant copies of the metadata. A method for accessing user data in a plurality of storage nodes having nonvolatile solid-state memory is also provided.

    摘要翻译: 提供了单个机箱中的多个存储节点。 单个机箱中的多个存储节点被配置为一起作为存储集群通信。 多个存储节点中的每一个包括用于用户数据存储的非易失性固态存储器。 多个存储节点被配置为在整个多个存储节点中分配与用户数据相关联的用户数据和元数据,使得多个存储节点使用擦除编码保持读取用户数据的能力,尽管丢失了两个 多个存储节点。 所述多个存储节点经配置以基于元数据的冗余副本来发起动作,响应于实现元数据的冗余副本的冗余级别。 还提供了一种用于访问具有非易失性固态存储器的多个存储节点中的用户数据的方法。

    AUTOMATICALLY RECONFIGURING A STORAGE MEMORY TOPOLOGY
    8.
    发明公开
    AUTOMATICALLY RECONFIGURING A STORAGE MEMORY TOPOLOGY 审中-公开
    澳大利亚自动化设备有限公司AUFZEICHNUNGSSPEICHERTOPOLOGIE

    公开(公告)号:EP3152648A1

    公开(公告)日:2017-04-12

    申请号:EP15803264.9

    申请日:2015-06-04

    IPC分类号: G06F3/06 G06F12/02

    摘要: A storage cluster is provided. The storage cluster includes a plurality of storage nodes within a single chassis. Each of the plurality of storage nodes has nonvolatile solid-state memory for storage of user data. The plurality of storage nodes are configured to distribute the user data and metadata throughout the plurality of storage nodes with erasure coding of the user data such that the plurality of storage nodes can access the user data, via the erasure coding, with a failure of two of the plurality of storage nodes. The plurality of storage nodes are configured to employ the erasure coding to reconfigure redundancy of the user data responsive to one of adding or removing a storage node.

    摘要翻译: 提供了一个存储集群。 存储集群在单个机箱内包括多个存储节点。 多个存储节点中的每一个具有用于存储用户数据的非易失性固态存储器。 多个存储节点被配置为在用户数据的擦除编码的情况下在整个多个存储节点中分发用户数据和元数据,使得多个存储节点可以经由擦除编码访问用户数据,其中两个 的多个存储节点。 多个存储节点被配置为响应于添加或移除存储节点之一而采用擦除编码来重新配置用户数据的冗余。

    MULTI-DRIVE COOPERATION TO GENERATE AN ENCRYPTION KEY
    9.
    发明公开
    MULTI-DRIVE COOPERATION TO GENERATE AN ENCRYPTION KEY 有权
    合作在多个驱动器,用于生成密钥加密

    公开(公告)号:EP2901357A1

    公开(公告)日:2015-08-05

    申请号:EP13776624.2

    申请日:2013-09-25

    IPC分类号: G06F21/60 H04L9/08

    摘要: A system, method, and computer-readable storage medium for protecting a set of storage devices using a secret sharing scheme. The data of each storage device is encrypted with a key, and the key is encrypted based on a shared secret and a device-specific value. Each storage device stores a share and its encrypted key, and if a number of storage devices above a threshold are available, then the shared secret can be reconstructed from the shares and used to decrypt the encrypted keys. Otherwise, the secret cannot be reconstructed if less than the threshold number of storage devices are accessible, and then data on the storage devices will be unreadable.