FULL VOLUME ENCRYPTION IN A CLUSTERED ENVIRONMENT
    1.
    发明申请
    FULL VOLUME ENCRYPTION IN A CLUSTERED ENVIRONMENT 有权
    集体环境中的全部体积增加

    公开(公告)号:US20100086134A1

    公开(公告)日:2010-04-08

    申请号:US12244888

    申请日:2008-10-03

    IPC分类号: H04L9/06

    CPC分类号: H04L9/08 G06F21/80 H04L9/0891

    摘要: Full volume encryption can be applied to volumes in a clustering environment. To simplify the maintenance of keys relevant to such encrypted volumes, a cluster key table construct can be utilized, where each entry of the cluster key table corresponds to an encrypted volume and comprises an identification of the encrypted volume and a key needed to access that volume. Keys can be protected by encrypting them with a key specific to each computing device storing the cluster key table. Updates can be propagated among the computing devices in the cluster by first decrypting the keys and then reencrypting them with a key specific to each computing device as they are stored on those computing devices. Access control requirements can also be added to the entries in the cluster key table. Alternative access control requirements can be accommodated by assigning multiple independent entries to a single encrypted volume.

    摘要翻译: 完整卷加密可以应用于群集环境中的卷。 为了简化与这种加密卷相关的密钥的维护,可以利用集群密钥表结构,其中集群密钥表的每个条目对应于加密卷,并且包括加密卷的标识和访问该卷所需的密钥 。 可以使用特定于存储群集密钥表的每个计算设备的密钥对密钥进行加密来保护密钥。 可以通过首先对密钥进行解密,然后在每个计算设备存储在这些计算设备上的每个计算设备特定的密钥来重新加密,从而可以在群集中的计算设备之间传播更新。 访问控制要求也可以添加到群集密钥表中的条目。 可以通过将多个独立条目分配给单个加密卷来实现替代的访问控制要求。

    Full volume encryption in a clustered environment
    2.
    发明授权
    Full volume encryption in a clustered environment 有权
    集群环境中的全卷加密

    公开(公告)号:US08411863B2

    公开(公告)日:2013-04-02

    申请号:US12244888

    申请日:2008-10-03

    IPC分类号: H04L9/00

    CPC分类号: H04L9/08 G06F21/80 H04L9/0891

    摘要: Full volume encryption can be applied to volumes in a clustering environment. To simplify the maintenance of keys relevant to such encrypted volumes, a cluster key table construct can be utilized, where each entry of the cluster key table corresponds to an encrypted volume and comprises an identification of the encrypted volume and a key needed to access that volume. Keys can be protected by encrypting them with a key specific to each computing device storing the cluster key table. Updates can be propagated among the computing devices in the cluster by first decrypting the keys and then reencrypting them with a key specific to each computing device as they are stored on those computing devices. Access control requirements can also be added to the entries in the cluster key table. Alternative access control requirements can be accommodated by assigning multiple independent entries to a single encrypted volume.

    摘要翻译: 完整卷加密可以应用于群集环境中的卷。 为了简化与这种加密卷相关的密钥的维护,可以利用集群密钥表结构,其中集群密钥表的每个条目对应于加密卷,并且包括加密卷的标识和访问该卷所需的密钥 。 可以使用特定于存储群集密钥表的每个计算设备的密钥对密钥进行加密来保护密钥。 可以通过首先对密钥进行解密,然后在每个计算设备存储在这些计算设备上的每个计算设备特定的密钥来重新加密,从而可以在群集中的计算设备之间传播更新。 访问控制要求也可以添加到群集密钥表中的条目。 可以通过将多个独立条目分配给单个加密卷来实现替代的访问控制要求。

    Volumes and file system in cluster shared volumes
    4.
    发明授权
    Volumes and file system in cluster shared volumes 有权
    集群共享卷中的卷和文件系统

    公开(公告)号:US08463762B2

    公开(公告)日:2013-06-11

    申请号:US12971322

    申请日:2010-12-17

    IPC分类号: G06F17/00

    CPC分类号: G06F17/30115

    摘要: The present invention extends to methods, systems, and computer program products for sharing volumes between clustered nodes. Embodiments of the invention include a Clustered Shared Volume File System (CsvFs) that appears to clients as a local file system. The CsvFs communicates to a node where a disk is mounted to coordinate access to files on the disks. CsvFs uses Opportunistic Locks (oplocks) to decide when direct access to a volume is safe. CsvFs can be extended with oplock upgrade mechanisms that allow a coordinating node to tell CsvFs when it is safe to attempt to upgrade oplock. CsvFs also uses a transitivity property of oplocks to be able to grant (delegate) oplocks to clients that are on top of CsvFs.

    摘要翻译: 本发明扩展到用于在集群节点之间共享卷的方法,系统和计算机程序产品。 本发明的实施例包括作为本地文件系统向客户端显示的群集共享卷文件系统(CsvF)。 CsvF与安装磁盘的节点通信,以协调对磁盘上文件的访问。 CsvFs使用机会锁(oplocks)来决定直接访问卷是否安全。 可以使用oplock升级机制来扩展CsvF,允许协调节点在尝试升级oplock时安全地告诉CsvF。 CsvFs还使用oplock的传递性属性能够向位于CsvF之上的客户端授予(委托)oplock。

    VOLUMES AND FILE SYSTEM IN CLUSTER SHARED VOLUMES
    5.
    发明申请
    VOLUMES AND FILE SYSTEM IN CLUSTER SHARED VOLUMES 有权
    群集共享卷中的卷和文件系统

    公开(公告)号:US20120158681A1

    公开(公告)日:2012-06-21

    申请号:US12971322

    申请日:2010-12-17

    IPC分类号: G06F17/30

    CPC分类号: G06F17/30115

    摘要: The present invention extends to methods, systems, and computer program products for sharing volumes between clustered nodes. Embodiments of the invention include a Clustered Shared Volume File System (CsvFs) that appears to clients as a local file system. The CsvFs communicates to a node where a disk is mounted to coordinate access to files on the disks. CsvFs uses Opportunistic Locks (oplocks) to decide when direct access to a volume is safe. CsvFs can be extended with oplock upgrade mechanisms that allow a coordinating node to tell CsvFs when it is safe to attempt to upgrade oplock. CsvFs also uses a transitivity property of oplocks to be able to grant (delegate) oplocks to clients that are on top of CsvFs.

    摘要翻译: 本发明扩展到用于在集群节点之间共享卷的方法,系统和计算机程序产品。 本发明的实施例包括作为本地文件系统向客户端显示的群集共享卷文件系统(CsvF)。 CsvF与安装磁盘的节点通信,以协调对磁盘上文件的访问。 CsvFs使用机会锁(oplocks)来决定直接访问卷是否安全。 可以使用oplock升级机制来扩展CsvF,允许协调节点在尝试升级oplock时安全地告诉CsvF。 CsvFs还使用oplock的传递性属性能够向位于CsvF之上的客户端授予(委托)oplock。

    Resource arbitration via persistent reservation
    6.
    发明申请
    Resource arbitration via persistent reservation 审中-公开
    资源仲裁通过永久保留

    公开(公告)号:US20070168507A1

    公开(公告)日:2007-07-19

    申请号:US11273866

    申请日:2005-11-15

    IPC分类号: G06F15/173

    CPC分类号: H04L67/1097 H04L63/104

    摘要: Reserving ownership of a shared resource including registering a node with the shared resource using a first registration, delaying an interval of time and then attempting to detect the registration and, if the first registration is detected indicating no other node is maintaining ownership of the shared resource, preempting any pre-existing reservation placing a new reservation for the node with the shared resource, the new reservation limiting any other node from reserving ownership of the shared resource.

    摘要翻译: 保留共享资源的所有权,包括使用第一注册向共享资源注册节点,延迟时间间隔,然后尝试检测注册;以及如果检测到第一注册,指示没有其他节点维护共享资源的所有权 ,抢占任何预先存在的预留,为节点提供共享资源的新预留,新的预留限制任何其他节点保留共享资源的所有权。

    Quorum establishment based on a vote from a voting device
    10.
    发明授权
    Quorum establishment based on a vote from a voting device 有权
    以投票方式投票的法定人数

    公开(公告)号:US07644305B2

    公开(公告)日:2010-01-05

    申请号:US11419118

    申请日:2006-05-18

    IPC分类号: G06F11/00

    摘要: A cluster system including as few as two cluster nodes and a plurality of links, each one of the plurality of links coupling one of the cluster nodes to a voting device wherein a single surviving cluster node obtain a vote from the voting device. A method of establishing quorum in a cluster system including as few as two cluster nodes, the method comprising determining a single surviving cluster node of the as few as two cluster nodes, obtaining a vote from a voting device, and establishing quorum such that cluster operations are continued by the single surviving cluster node. A method for preventing a partition-in-time quorum establishment problem in a cluster system including as few as two cluster nodes, the method comprising determining that a revived cluster node is also a sole active cluster node of the cluster system, checking a last-surviving flag of the sole active cluster node, and if the last-surviving flag is set to FALSE, not restarting cluster operations.

    摘要翻译: 包括少至两个群集节点和多个链路的群集系​​统,所述多个链路中的每一个将所述群集节点中的一个链接到投票设备,其中单个幸存群集节点从所述投票设备获得投票。 一种在包括少至两个集群节点的集群系统中建立仲裁的方法,所述方法包括:确定少至两个集群节点中的单个幸存集群节点,从投票设备获取投票权,并建立群集操作 由单个幸存的群集节点继续。 一种用于在包括少至两个集群节点的集群系统中防止时间段仲裁建立问题的方法,所述方法包括确定恢复的集群节点也是集群系统的唯一主动集群节点, 唯一活动群集节点的生存标志,如果最后一个生存标志设置为FALSE,则不重新启动集群操作。