Cluster Shared Volumes
    7.
    发明申请
    Cluster Shared Volumes 有权
    群集共享卷

    公开(公告)号:US20090327798A1

    公开(公告)日:2009-12-31

    申请号:US12147956

    申请日:2008-06-27

    IPC分类号: G06F17/30 G06F13/14 G06F11/16

    摘要: Described is a technology by which a storage volume is shared by cluster nodes of a server cluster. In one implementation, each node includes a redirector that provides shared access to the volume from that node. The redirector routes file system metadata requests from applications and the like through a first (e.g., SMB) communications path to the owning node, and routes file system read and write data to the storage device through a second, high-speed communications path such as direct direct block level I/O. An owning node maintains ownership of the storage device through a persistent reservation mechanism that writes a key to a registration table associated with the storage device. Non-owning nodes write a shared key. The owning node validates the shared keys against cluster membership data, and preempts (e.g., removes) any key deemed not valid. Security mechanisms for controlling access are also described.

    摘要翻译: 描述了存储卷由服务器集群的集群节点共享的技术。 在一个实现中,每个节点包括重定向器,其向该节点提供对卷的共享访问。 重定向器通过第一(例如SMB)通信路径将应用程序等的文件系统元数据请求路由到所有者节点,并通过第二高速通信路径将文件系统读写数据路由到存储设备,例如 直接直接块级I / O。 拥有节点通过将密钥写入与存储设备相关联的注册表的持久预留机制来维护存储设备的所有权。 非拥有节点写共享密钥。 拥有节点根据集群成员数据验证共享密钥,并抢占(例如删除)任何被认为无效的密钥。 还描述了用于控制访问的安全机制。

    Cluster shared volumes
    8.
    发明授权
    Cluster shared volumes 有权
    群集共享卷

    公开(公告)号:US07840730B2

    公开(公告)日:2010-11-23

    申请号:US12147956

    申请日:2008-06-27

    IPC分类号: G06F19/00

    摘要: Described is a technology by which a storage volume is shared by cluster nodes of a server cluster. In one implementation, each node includes a redirector that provides shared access to the volume from that node. The redirector routes file system metadata requests from applications and the like through a first (e.g., SMB) communications path to the owning node, and routes file system read and write data to the storage device through a second, high-speed communications path such as direct direct block level I/O. An owning node maintains ownership of the storage device through a persistent reservation mechanism that writes a key to a registration table associated with the storage device. Non-owning nodes write a shared key. The owning node validates the shared keys against cluster membership data, and preempts (e.g., removes) any key deemed not valid. Security mechanisms for controlling access are also described.

    摘要翻译: 描述了存储卷由服务器集群的集群节点共享的技术。 在一个实现中,每个节点包括重定向器,其向该节点提供对卷的共享访问。 重定向器通过第一(例如SMB)通信路径将应用程序等的文件系统元数据请求路由到所有者节点,并通过第二高速通信路径将文件系统读写数据路由到存储设备,例如 直接直接块级I / O。 拥有节点通过将密钥写入与存储设备相关联的注册表的持久预留机制来维护存储设备的所有权。 非拥有节点写共享密钥。 拥有节点根据集群成员数据验证共享密钥,并抢占(例如删除)任何被认为无效的密钥。 还描述了用于控制访问的安全机制。

    Volumes and file system in cluster shared volumes
    9.
    发明授权
    Volumes and file system in cluster shared volumes 有权
    集群共享卷中的卷和文件系统

    公开(公告)号:US08463762B2

    公开(公告)日:2013-06-11

    申请号:US12971322

    申请日:2010-12-17

    IPC分类号: G06F17/00

    CPC分类号: G06F17/30115

    摘要: The present invention extends to methods, systems, and computer program products for sharing volumes between clustered nodes. Embodiments of the invention include a Clustered Shared Volume File System (CsvFs) that appears to clients as a local file system. The CsvFs communicates to a node where a disk is mounted to coordinate access to files on the disks. CsvFs uses Opportunistic Locks (oplocks) to decide when direct access to a volume is safe. CsvFs can be extended with oplock upgrade mechanisms that allow a coordinating node to tell CsvFs when it is safe to attempt to upgrade oplock. CsvFs also uses a transitivity property of oplocks to be able to grant (delegate) oplocks to clients that are on top of CsvFs.

    摘要翻译: 本发明扩展到用于在集群节点之间共享卷的方法,系统和计算机程序产品。 本发明的实施例包括作为本地文件系统向客户端显示的群集共享卷文件系统(CsvF)。 CsvF与安装磁盘的节点通信,以协调对磁盘上文件的访问。 CsvFs使用机会锁(oplocks)来决定直接访问卷是否安全。 可以使用oplock升级机制来扩展CsvF,允许协调节点在尝试升级oplock时安全地告诉CsvF。 CsvFs还使用oplock的传递性属性能够向位于CsvF之上的客户端授予(委托)oplock。

    Full volume encryption in a clustered environment
    10.
    发明授权
    Full volume encryption in a clustered environment 有权
    集群环境中的全卷加密

    公开(公告)号:US08411863B2

    公开(公告)日:2013-04-02

    申请号:US12244888

    申请日:2008-10-03

    IPC分类号: H04L9/00

    CPC分类号: H04L9/08 G06F21/80 H04L9/0891

    摘要: Full volume encryption can be applied to volumes in a clustering environment. To simplify the maintenance of keys relevant to such encrypted volumes, a cluster key table construct can be utilized, where each entry of the cluster key table corresponds to an encrypted volume and comprises an identification of the encrypted volume and a key needed to access that volume. Keys can be protected by encrypting them with a key specific to each computing device storing the cluster key table. Updates can be propagated among the computing devices in the cluster by first decrypting the keys and then reencrypting them with a key specific to each computing device as they are stored on those computing devices. Access control requirements can also be added to the entries in the cluster key table. Alternative access control requirements can be accommodated by assigning multiple independent entries to a single encrypted volume.

    摘要翻译: 完整卷加密可以应用于群集环境中的卷。 为了简化与这种加密卷相关的密钥的维护,可以利用集群密钥表结构,其中集群密钥表的每个条目对应于加密卷,并且包括加密卷的标识和访问该卷所需的密钥 。 可以使用特定于存储群集密钥表的每个计算设备的密钥对密钥进行加密来保护密钥。 可以通过首先对密钥进行解密,然后在每个计算设备存储在这些计算设备上的每个计算设备特定的密钥来重新加密,从而可以在群集中的计算设备之间传播更新。 访问控制要求也可以添加到群集密钥表中的条目。 可以通过将多个独立条目分配给单个加密卷来实现替代的访问控制要求。