MULTI-TENANT SECURITY IN THE CLOUD
    501.
    发明申请
    MULTI-TENANT SECURITY IN THE CLOUD 审中-公开
    云中的多重安全

    公开(公告)号:US20160173500A1

    公开(公告)日:2016-06-16

    申请号:US14572443

    申请日:2014-12-16

    Applicant: NetApp, Inc.

    CPC classification number: H04L63/105 G06F21/6218 H04L63/08

    Abstract: A cloud asset manager can securely provide multi-tenant access to remote assets while preserving isolation across tenants. The remote asset manager defines various roles for legitimate users of the remote asset manager. The roles are associated with credentials that provide access to the remote assets and/or information about the remote assets maintained by a service provider. And the users map to roles based on attempted actions that access the service provider. Thus, a user's requested action is attempted with credentials associated with a role that maps to the requested action.

    Abstract translation: 云资产管理器可以安全地提供多租户访问远程资产,同时保护租户之间的隔离。 远程资产管理器为远程资产管理器的合法用户定义各种角色。 这些角色与提供对远程资产的访问的凭据和/或关于由服务提供商维护的远程资产的信息相关联。 并且用户根据访问服务提供商的尝试操作映射到角色。 因此,尝试使用与映射到请求的操作的角色相关联的凭据的用户请求的动作。

    Decoupled reliability groups
    502.
    发明授权
    Decoupled reliability groups 有权
    解耦可靠性组

    公开(公告)号:US09367394B2

    公开(公告)日:2016-06-14

    申请号:US13708784

    申请日:2012-12-07

    Applicant: NetApp, Inc.

    Abstract: Methods and apparatuses for updating members of a data storage reliability group are provided. In one exemplary method, a reliability group includes a data zone in a first storage node and a checksum zone in a second data storage node. The method includes updating a version counter associated with the data zone in response to destaging a data object from a staging area of the data zone to a store area of the data zone without synchronizing the destaging with the state of the checksum zone. The method further includes transmitting, from the data zone to the checksum zone, an update message indicating completion of the destaging of the data object, wherein the update message includes a current value of the version counter.

    Abstract translation: 提供了更新数据存储可靠性组的成员的方法和装置。 在一个示例性方法中,可靠性组包括第一存储节点中的数据区和第二数据存储节点中的校验和区。 该方法包括更新与数据区域相关联的版本计数器,以响应于将数据对象从数据区域的暂存区域降级到数据区域的存储区域,而不使分级与校验和区域的状态同步。 所述方法还包括从所述数据区向所述校验和区发送指示所述数据对象的分级的完成的更新消息,其中所述更新消息包括所述版本计数器的当前值。

    Clustered RAID assimilation management
    503.
    发明授权
    Clustered RAID assimilation management 有权
    集群RAID同化管理

    公开(公告)号:US09367241B2

    公开(公告)日:2016-06-14

    申请号:US14854850

    申请日:2015-09-15

    Applicant: NetApp, Inc.

    Abstract: In one embodiment, a node of a cluster is coupled to a storage array of storage devices. The node executes a storage input/output (I/O) stack having a redundant array of independent disks (RAID) layer that organizes the storage devices within the storage array as a plurality of RAID groups. Configuration information is stored as a cluster database. The configuration information identifies the RAID groups associated with the storage devices. Each RAID group is associated with a plurality of segments and each segment has a different RAID configuration.

    Abstract translation: 在一个实施例中,集群的节点耦合到存储设备的存储阵列。 节点执行具有独立磁盘(RAID)层的冗余阵列的存储输入/输出(I / O)堆栈,其将存储阵列内的存储设备组织为多个RAID组。 配置信息存储为集群数据库。 配置信息标识与存储设备关联的RAID组。 每个RAID组与多个段相关联,并且每个段具有不同的RAID配置。

    Accelerating internet small computer system interface (iSCSI) proxy input/output (I/O)
    504.
    发明授权
    Accelerating internet small computer system interface (iSCSI) proxy input/output (I/O) 有权
    加速互联网小型计算机系统接口(iSCSI)代理输入/输出(I / O)

    公开(公告)号:US09361042B2

    公开(公告)日:2016-06-07

    申请号:US14519966

    申请日:2014-10-21

    Applicant: NetApp, Inc.

    Inventor: Andrew J. Spry

    CPC classification number: G06F3/0655 G06F3/0608 G06F3/067 H04L67/1097

    Abstract: The present invention is a method for accelerating proxy Input/Output (proxyI/O). The method includes the step of receiving a command at a primary target storage system. The primary target storage system may be part of a clustered storage array. The command may be a command which was transmitted by an initiator system via a storage area network, and may include a request for data. The method further includes the step of forwarding the command to a session layer of the primary target storage system. Further, when a virtualization layer of the primary target storage system determines that a portion of the data requested in the data request is not stored by the primary target storage system, but is stored by a proxy target storage system included in the plurality of storage systems, the method further includes providing a proxyIO request to a proxy initiator of the primary target storage system. Further, the method may further include, based on the proxyIO request, generating a proxyDataIn request and providing the proxyDataIn request to an I/O controller for the primary target storage system.

    Abstract translation: 本发明是一种加速代理输入/输出(proxyI / O)的方法。 该方法包括在主要目标存储系统处接收命令的步骤。 主要目标存储系统可以是集群存储阵列的一部分。 该命令可以是由发起者系统经由存储区域网络发送的命令,并且可以包括对数据的请求。 该方法还包括将命令转发到主目标存储系统的会话层的步骤。 此外,当主要目标存储系统的虚拟化层确定数据请求中请求的数据的一部分未被主要目标存储系统存储时,而是被包括在多个存储系统中的代理目标存储系统存储 该方法还包括向主目标存储系统的代理启动器提供代理服务器请求。 此外,该方法还可以基于proxyIO请求生成proxyDataIn请求,并向主目标存储系统的I / O控制器提供proxyDataIn请求。

    Systems and methods for managing files in a content storage system
    505.
    发明授权
    Systems and methods for managing files in a content storage system 有权
    用于管理内容存储系统中的文件的系统和方法

    公开(公告)号:US09355120B1

    公开(公告)日:2016-05-31

    申请号:US13782056

    申请日:2013-03-01

    Applicant: NetApp, Inc.

    CPC classification number: G06F17/30203 G06F17/30221 H04L67/1097

    Abstract: Systems and methods that allow operators to configure how files and directories are placed within file system views into a storage system, and how these configured file placements are performed by the distributed system. Possible features include a mechanism by which the desired placement of files and directories can be specified, a mechanism by which the placement goals can be realized in a given topology of a distributed system, and a mechanism by which changes to the placement of objects can applied retroactively. The disclosed embodiments may be able to scale to managing hundreds of billions of files spanning thousands of file system views, especially in the presence of disconnected operation.

    Abstract translation: 允许操作员配置如何将文件系统视图中的文件和目录放置到存储系统中的系统和方法,以及这些配置的文件展示位置由分布式系统执行的方式。 可能的特征包括可以指定文件和目录的期望布置的机制,可以在分布式系统的给定拓扑中实现放置目标的机制,以及可以应用对对象布置的改变的机制 具追溯力 所公开的实施例可能能够扩展到管理数千亿个文件,跨越数千个文件系统视图,特别是在存在断开连接的操作的情况下。

    TRANSACTING ACROSS MULTIPLE TRANSACTIONAL DOMAINS
    506.
    发明申请
    TRANSACTING ACROSS MULTIPLE TRANSACTIONAL DOMAINS 审中-公开
    交易多个交互域

    公开(公告)号:US20160132841A1

    公开(公告)日:2016-05-12

    申请号:US14539052

    申请日:2014-11-12

    Applicant: NetApp Inc.

    CPC classification number: G06Q20/027 G06Q20/08 G06Q20/12 G06Q20/3829

    Abstract: One or more techniques and/or systems are provided for facilitating transactions across multiple transactional domains. For example, a first committer stores first data according to a first transactional domain (e.g., communication protocol data of a smart television) and a second committer stores second data according to a second transactional domain (e.g., communication protocol data of a mobile device). The first committer may commit to updating the first data from an old data state to a new data state (e.g., update from an unauthenticated protocol to an authenticated protocol). The first committer may instruct the second committer to perform a second commit of the second data to the new data state. If the second commit succeeds, then the first committer may utilize the new data state (e.g., utilize the authenticated protocol for communication) otherwise the first committer may utilize the old data state (e.g., utilize the unauthenticated protocol for communication).

    Abstract translation: 提供一个或多个技术和/或系统以促进跨多个事务域的事务。 例如,第一提交者根据第一事务域(例如,智能电视的通信协议数据)存储第一数据,而第二提交者根据第二事务域(例如,移动设备的通信协议数据)存储第二数据, 。 第一提交者可以承诺将第一数据从旧的数据状态更新到新的数据状态(例如,从未认证的协议更新为认证的协议)。 第一提交者可以指示第二提交者执行第二数据的第二次提交到新的数据状态。 如果第二次提交成功,则第一提交者可以利用新的数据状态(例如,利用经认证的协议进行通信),否则第一提交者可以利用旧的数据状态(例如,利用未经认证的协议进行通信)。

    Distributed file system snapshot
    507.
    发明授权
    Distributed file system snapshot 有权
    分布式文件系统快照

    公开(公告)号:US09336219B2

    公开(公告)日:2016-05-10

    申请号:US14195752

    申请日:2014-03-03

    Applicant: NetApp, Inc.

    Abstract: Technology is disclosed for managing data in a distributed file system (“the technology”). The technology can gather metadata information associated with the data stored within the distributed file system, create a secondary namespace within a local file system of a local host using the gathered metadata information and store the gathered metadata information as files within the secondary namespace. Further, when a request to create a PPI of the distributed file system is received, the technology can create a PPI of the secondary namespace using a PPI creation feature of the local file system.

    Abstract translation: 公开了用于管理分布式文件系统(“技术”)中的数据的技术。 该技术可以收集与分布式文件系统中存储的数据相关联的元数据信息,使用收集的元数据信息在本地主机的本地文件系统内创建辅助命名空间,并将收集的元数据信息作为文件存储在辅助命名空间中。 此外,当接收到创建分布式文件系统的PPI的请求时,该技术可以使用本地文件系统的PPI创建特征来创建二级命名空间的PPI。

    TECHNIQUES FOR CONTROLLING CLIENT TRAFFIC ON A CLUSTERED SYSTEM
    508.
    发明申请
    TECHNIQUES FOR CONTROLLING CLIENT TRAFFIC ON A CLUSTERED SYSTEM 审中-公开
    控制集群系统客户端流量的技术

    公开(公告)号:US20160127462A1

    公开(公告)日:2016-05-05

    申请号:US14526760

    申请日:2014-10-29

    Applicant: NETAPP, INC.

    CPC classification number: H04L67/1095 H04L67/1097

    Abstract: Various embodiments are generally directed an apparatus and method to receive client traffic comprising information at a primary cluster of a clustered system over a communications link, perform, a replication operation on the clustered system to replicate the information on a secondary cluster of the clustered system, and determine a client traffic throughput for the client traffic and a replication throughput for the replication operation. In some embodiments, the apparatus and method may include buffering one or more write operations to control the client traffic such that the client traffic throughput is less than or equal to the replication throughput for the replication operation.

    Abstract translation: 各种实施例通常涉及一种装置和方法,用于通过通信链路在集群系统的主集群处接收包括信息的客户端业务,执行集群系统上的复制操作以在集群系统的辅助集群上复制信息, 并确定客户端流量的客户端流量吞吐量和复制操作的复制吞吐量。 在一些实施例中,装置和方法可以包括缓冲一个或多个写入操作以控制客户端流量,使得客户端流量吞吐量小于或等于复制操作的复制吞吐量。

    SYSTEM AND METHOD FOR DETERMINING OCCURRENCES OF DATA CORRUPTION IN A FILE SYSTEM UNDER ACTIVE USE
    509.
    发明申请
    SYSTEM AND METHOD FOR DETERMINING OCCURRENCES OF DATA CORRUPTION IN A FILE SYSTEM UNDER ACTIVE USE 审中-公开
    用于确定主动使用的文件系统中的数据损坏的系统和方法

    公开(公告)号:US20160124990A1

    公开(公告)日:2016-05-05

    申请号:US14534039

    申请日:2014-11-05

    Applicant: NetApp, Inc.

    CPC classification number: G06F16/1844

    Abstract: A client system is provided for a test environment in which resources of a network file system are under test. A resource under test can correspond to an appliance (such as a cache or data migration appliance), or alternatively, to a file system. The client system can replicate operations specified for the file system on a control data set. The control data set can represent a copy of the file system that is handling the client specified file system operations during a test session. A comparison of the control data set to data stores which hold data for the resource under test can identify when temporary or permanent corruption issues occur.

    Abstract translation: 为网络文件系统的资源进行测试的测试环境提供了客户端系统。 被测资源可对应于设备(例如缓存或数据迁移设备),或者替代文件系统。 客户端系统可以在控制数据集上复制为文件系统指定的操作。 控制数据集可以表示在测试会话期间处理客户端指定的文件系统操作的文件系统的副本。 将控制数据集与保存被测资源数据的数据存储区进行比较,可以识别发生临时或永久性腐败问题的时间。

Patent Agency Ranking