Granular control over the authority of replicated information via fencing and unfencing
Abstract
"GRANULAR CONTROL ON THE AUTHORITY OF REPLICATED INFORMATION THROUGH PROTECTION AND DEPROTECTION". A method and system for controlling which content takes precedence and is replicated is described. A replica set is made up of a feature set. Each resource is associated with resource data and resource metadata. Resource data, for files, includes file contents and attributes, while resource metadata includes additional attributes that are relevant for negotiating synchronization during replication. An extra field, called a "protection value", is added to the metadata associated with each resource. During synchronization, protection values are compared. The resource with the highest protection value includes the content it is controlling and which has been replicated. If the protection values are the same (and greater than a particular value), the control feature is determined based on other metadata.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
33 claims: 7 independent, 26 dependent
- 1CLAIMS REIVINDICAÇÕES 1. Computer readable medium that has instructions executable by computer, CHARACTERIZED by the fact that it comprises:1. Meio legível por computador que tem instruções executáveis por computador, CARACTERIZADO pelo fato de que compreende: recuperar metadados de um recurso que esteja replicado em uma pluralidade de máquinas, o recurso possuindo metadados e conteúdo que reside em cada máquina na qual o recurso esteja replicado, os metadados incluindo um ou mais valores que são atualizados sempre que o conteúdo do recurso for mudado por meio de qualquer atualização local e um valor de proteção que é independente de qualquer mudança de local no conteúdo;retrieve metadata for a resource that is replicated on a plurality of machines, the resource having metadata and content that resides on each machine on which the resource is replicated, metadata including one or more values that are updated whenever the content of the resource is changed through any local update and a protection value that is independent of any change of location in the content;comparar um primeiro valor de proteção do conteúdo em uma primeira máquina da pluralidade de máquinas com um segundo valor de proteção do conteúdo em uma segunda máquina da pluralidade de máquinas;“ê se o primeiro valor de proteção for de maior precedência do que o segundo valor de proteção, atualizar a segunda máquina. compare a first content protection value on a first machine of the plurality of machines with a second content protection value on a second machine of the plurality of machines: “if the first protection value is of higher precedence than the second value protection, update the second machine.
- 4Computer readable medium according to • ··· 0 0 · 0 000 · · • 0 000 0 * 00 00000 4. Meio legível por computador, de acordo com a • ··· 0 0 · 0 000 · · • 0 000 0*00 00000 0 0 00 0 00 0 0 0 00 0 0 0 00 0 00 0 0 0 00 0 0 000 000 0000 000 0 000 000 0000 000 0 00 00·· 0 000 0 00 00·· 0 000 000 0 · 0 0000 0 0 * 0 claim 1, CHARACTERIZED by the fact that updating the second machine comprises transmitting only metadata. 000 0 · 0 0000 0 0*0 reivindicação 1, CARACTERIZADO pelo fato de que a atualização da segunda máquina compreende transmitir apenas metadados.
- 16Computer readable medium that has instructions executable by computer, CHARACTERIZED by the fact that it comprises:16. Meio legível por computador que tem instruções executáveis por computador, CARACTERIZADO pelo fato de que compreende: determinar se um primeiro recurso que reside em uma primeira máquina deve ser usado para atualizar um segundo recurso que reside em uma segunda máquina, cada recurso associado com metadados e conteúdo, cada metadado incluindo um ou mais campos que são atualizados sempre que o conteúdo do recurso associado mudar e um valor de proteção, cada valor de proteção indicando se seu recurso associado deve ser usado para atualizar um recurso em uma outra máquina em uma precedência maior do que dos outros metadados;determine whether a first resource that resides on a first machine should be used to update a second resource that resides on a second machine, each resource associated with metadata and content, each metadata including one or more fields that are updated whenever the content of the resource associated change and a protection value, each protection value indicating whether its associated resource should be used to update a resource on another machine to a higher precedence than other metadata;if the protection value of the second resource indicates that the second resource must not be propagated from the second machine, prevent the propagation from the second machine;and if the protection value of the first resource is of higher precedence than the protection value of the second resource, update the second resource from the first resource. se o valor de proteção do segundo recurso indicar que o segundo recurso não deve ser propagado da segunda máquina, impedir a propagação a partir da segunda máquina;e se o valor de proteção do primeiro recurso for de maior precedência do que o valor de proteção do segundo recurso, atualizar o segundo recurso a partir do primeiro recurso .
- 24Method for replicating data, CHARACTERIZED by the fact that it comprises:“loading data on a first machine;24. Método para replicar dados, CARACTERIZADO pelo fato de que compreende: “ carregar dados em uma primeira máquina;marcar os dados com um valor de proteção que indique que os dados não devem ser transmitidos da primeira má20 quina para atualizar dados em nenhuma outra máquina;mark the data with a protection value that indicates that the data must not be transmitted from the first machine to update data on any other machine;sincronizar pelo menos uma parte dos dados com dados em uma segunda máquina. synchronize at least part of the data with data on a second machine.
- 30Method according to 'claim 24', CHARACTERIZED by the fact that it additionally comprises changing a part of the data and marking the changed part with a protection value indicating that the changed part must be synchronized during synchronization. 30. Método, de’ acordo”“com a reivindicação 24, CARACTERIZADO pelo fato de que compreende adicionalmente mudar uma parte dos dados e marcar a parte mudada com um valor de proteção que indique que a parte mudada deve ser sincronizada durante a sincronização.
- 31System for replicating data, CHARACTERIZED by the fact that it comprises:31. Sistema para replicar dados, CARACTERIZADO pelo fato de que compreende: a first machine that has a first set of features;uma primeira máquina que tem um primeiro conjunto de recursos;a second machine that has a second set of resources, where each resource on each machine is associated with metadata and content, each metadata including one or more fields that are updated whenever the content of the resource • ··· · · · ·· · · · ··· associated change, and a protection value, each protection value indicating whether its associated resource should be used to update a resource on another machine regardless of other metadata, where the first and second machines are configured to: uma segunda máquina que tem um segundo conjunto de recursos, em que cada recurso em cada máquina é associado com metadados e conteúdo, cada metadado incluindo um ou mais campos que são atualizados sempre que o conteúdo do recurso • ··· · · · ··· · · ··· associado mudar, e um valor de proteção, cada valor de proteção indicando se seu recurso associado deve ser usado para atualizar um recurso em uma outra máquina independentemente de outros metadados, em que a primeira e segunda máquinas são configuradas para: communicate information regarding the resources contained by both;and update each asset that is out of date according to the following precedence: comunicar informação relativa aos recursos contidos por ambas;e atualizar cada recurso que esteja desatualizado de acordo com a precedência seguinte: if a protection value of a resource on one machine is of higher precedence than the protection value of a corresponding resource on the other machine, update the other machine with the resource on that machine;otherwise, update the resource on machines based on data other than protection values. se um valor de proteção de um recurso em uma das máquinas for de maior precedência do que o valor de proteção de um recurso correspondente na outra máquina, atualizar a outra máquina com o recurso na tal máquina;caso contrário atualizar o recurso nas máquinas com base em dados sem ser os valores de proteção.
- 32System, according to “ã” claim 3Tv CHARACTERIZED by the fact that the first set of resources is loaded from a backup copy and its protection values are established to make the first set of resources take precedence over any another feature set, such that any other feature set on any other machine that matches the feature set is updated from the first feature set. 32. Sistema, de acordo com “ã” reivindicação 3Tv CARACTERIZADO pelo fato de que o primeiro conjunto de recursos é carregado a partir de uma cópia de segurança e os seus valores de proteção são estabelecidos para fazer com que o primeiro conjunto de recursos tenha precedência sobre qualquer outro conjunto de recursos, de maneira tal que qualquer outro conjunto de recursos em qualquer outra máquina que corresponda ao conjunto de recursos seja atualizado a partir do primeiro conjunto de recursos.
Independent claims7
131 paragraphs in 10 sections, as filed
(54) Title: GRANULAR CONTROL ON THE AUTHORITY OF REPLICATED INFORMATION THROUGH PROTECTION AND DEPROTECTION (30) Unionist Priority: 10/07/2003 us 60 / 486,627; 10/12/2003 US 10 / 733,459 (71) Depositor (s): Microsoft Corporation (US) (72) Inventor (s): DanTeodosiu, Nikolaj S. Bjorner (74) Attorney: Nellie Anne Daniel Shores (57) Summary: GRANULAR CONTROL ON THE AUTHORITY OF REPLICATED INFORMATION THROUGH PROTECTION AND DEPROTECTION. A method and system for controlling which content takes precedence and is replicated is described. A replica set is made up of a feature set. Each resource is associated with resource data and resource metadata. Resource data, for files, includes file contents and attributes, while resource metadata includes additional attributes that are relevant for negotiating synchronization during replication. An extra field, called a protection value, is added to the metadata associated with each resource. During synchronization, protection values are compared. The resource with the highest protection value includes the content it is controlling and which has been replicated. If the protection values are equal (and greater than a particular value), the control feature is determined based on other metadata.
<img file="BRPI0402702A_D0001.tif" />
GRANULAR CONTROL ON THE AUTHORITY OF REPLICATED INFORMATION THROUGH PROTECTION AND DEPROTECTION
CROSS REFERENCE TO PATENT APPLICATIONS
RELATED
This patent application claims the benefit of US provisional patent application no. 60 / 486,627, filed on July 10, 2003, entitled GRANULAR CONTROL OVER THE AUTHORITY OF REPLICATED INFORMATION VIA FENCING AND UNFENCING, which patent application is hereby incorporated in its entirety.
FIELD OF THE INVENTION
The present invention relates in general to computing devices and, more particularly, to resource replication systems.
BACKGROUND OF THE INVENTION
In due course, multi-master replication systems allow for unrestricted changes in replicated content on any machine that participates in a given replica set. These potentially conflicting changes are reconciled under the control of the replication system using a set of conflict resolution criteria that define, for each conflict situation, which conflicting change takes precedence over the others. In the past, the main conflict resolution criterion used was the physical or logical timing of the change, with the most recent change taking precedence over all others.
However, there are a number of cases where users or applications may want to have additional ways of controlling •
<img file="BRPI0402702A_D0002.tif" />
control which concurrent updates take precedence over others and, conversely, which updates should give precedence. What is needed is a flexible method and system for controlling which content takes precedence and which is replicated.
SUMMARY
Briefly, the present invention provides a method and system for controlling which content takes precedence and is replicated. A replica set consists of a set of resources. Each resource is associated with resource data and resource metadata. Resource data, for files, includes file contents and attributes, while resource metadata includes additional attributes that are relevant for negotiating synchronization during replication. An extra field called protection value is added to the metadata associated with each resource. During synchronization, the protection values are compared. The resource with the highest protection value includes the content it is controlling and which has been replicated. If the protection values are equal (and greater than a particular value), the control feature is determined based on other metadata.
Protection values are independent of changes in location in the content. That is, although a change of location in the content may affect other metadata (for example, a time tag, clock value, or otherwise), a change of location in the content does not affect a protection value, unless otherwise indicated.
In one aspect of the invention, a resource can have a
<img file="BRPI0402702A_D0003.tif" />
protection value that indicates that the resource is unprotected. If a resource is unprotected, it indicates that the resource must not be transmitted from the machine on which the resource is stored. When a competitive resource is received for synchronization, a resource that is unprotected loses (and is replaced during synchronization) for the resources that are protected.
In another aspect of the invention, only differences between resources on a machine with a winning resource and a machine with losing content are transmitted. For example, asset metadata can be passed without passing the asset's content. As another example, differences in the content of the resource can be transmitted during synchronization.
Other advantages will be apparent from the following detailed description'7<sup>-</sup> when taken in conjunction with the drawings, where:
BRIEF DESCRIPTION OF THE DRAWINGS
Figure 1 is a block diagram representing a computer system in which the present invention can be incorporated;
Figure 2 is a block diagram representing a resource replication system that includes two machines that replicate resources according to various aspects of the invention;
Figure 3 is a block diagram representing a system in which two machines attempt to reconcile an included resource, both according to various aspects of the invention;
Figure 4 shows some exemplary data and metadata that could be used for a machine of figures 2 and 3 according to various aspects of the invention;
Figure 5 shows some exemplary resource data and metadata that can be used according to various aspects of the invention;
Figure 6 is a flow chart that represents in general exemplary steps that can occur to synchronize a resource between two machines according to various aspects of the present invention;
Figure 7 is a flow chart that represents in general several exemplary steps that can take place to perform an unofficial backup recording according to various aspects of the invention; and
Figure 8 is a block diagram representing an example machine configured to operate in a resource replication system in accordance with various aspects of the invention.
DETAILED DESCRIPTION
EXAMPLE OPERATIONAL ENVIRONMENT
Figure 1 illustrates an example of a suitable computing system environment 100 in which the invention can be implemented. The computing system environment 100 is just one example of a suitable computing environment and should not suggest any limitations on the scope of use or functionality of the invention. Nor should computing environment 100 be interpreted with any dependency or
<img file="BRPI0402702A_D0004.tif" />
• · · · ·
<img file="BRPI0402702A_D0005.tif" />
• · · • ··· requirement related to none of the components, or combinations thereof, illustrated in the exemplary operating environment 100.
The invention is operational with numerous other environments or configurations of general purpose or special use computing systems. Examples of well-known computing systems, environments and / or configurations that may be suitable for use with the invention include, but are not limited to, personal computers, server computers, hand or pocket devices, multiprocessor systems, based systems microcontroller, television set-top boxes, programmable consumer electronics, network PCs, minicomputers, large computers, distributed computing environments that include any of the aforementioned systems or devices, and the like.
The invention can be described in the general context of computer executable instructions, such as program modules, which are executed by a computer. In general, program modules include routines, programs, objects, components, data structures, and so on, that perform particular tasks, or that implement particular abstract data types. The invention can also be practiced in distributed computing environments, where tasks are performed by remote processing devices that are connected via a communication network. In a distributed computing environment, program modules can be located on both local and remote computer storage media, including memory storage devices.
<img file="BRPI0402702A_D0006.tif" />
Referring to Figure 1, an exemplary system for implementing the invention includes a general purpose computing device in the form of a computer 110. Components of computer 110 may include, but are not limited to, a processing unit 120, a memory system 130, and a system bus 121 that couples various system components including system memory to processing unit 120. 0 system bus 121 can be any of several types of bus structures, including a memory bus or memory controller, a peripheral bus and a local bus using any of a variety of bus architectures. For example, and not by way of limitation, such architectures include the Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, 'Enhaced ISA (EISA) 7' bus ”Local Video Electronic Standards Association (VESA) bus and Peripheral Component Interconnect (PCI) bus, also known as Mezzanine bus.
computer 110 typically includes a variety of computer-readable media. Computer readable media can be any available shaft that can be accessed by computer 110 and includes both volatile and non-volatile media, removable and non-removable media. By way of example, and not by way of limitation, computer readable media may comprise computer storage media and communication media. Computer storage media includes both volatile and non-volatile media, removed
<img file="BRPI0402702A_D0007.tif" />
··· • · 4 · · ····· * «· ······· · 4 • · · · · · · · · · · · · · as non-removable implemented in any method or technology for information storage, such as computer-readable instructions, data structures, program modules or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile discs (DVD) or other optical disc storage, magnetic tapes, tape magnetic, magnetic disk storage or other magnetic storage devices, or any other means that can be used to store the desired information and that can be accessed by the computer 110. Communication media typically incorporate computer-readable instructions, data structures, program modules or other data into a modulated data signal, such as a carrier wave or other transport mechanism, and<sup>-</sup>includes<sup>-</sup> any means of delivering information. The term modulated data signal means a signal that has one or more of its characteristics established or changed in such a way as to encode information in the signal. By way of example, and not by way of limitation, means of communication include wired veins, such as a wired or direct wired network connection, and wireless means, such as acoustic, RF, infrared and other wireless means. Combinations of any of these should also be included in the scope of computer-readable media.
System memory 130 includes computer storage media in the form of volatile and / or non-volatile memory, such as read-only memory (ROM) 131 and me • 9
<img file="BRPI0402702A_D0008.tif" />
random access memory (RAM) 132. A basic input / output system 133 (BIOS), containing the basic routines that help transfer information between elements in computer 110, such as during startup, are typically stored in ROM 131. RAM 132 it typically contains data and / or program modules that are immediately accessible and / or that can currently be operated by processing unit 120. By way of example, and not by way of limitation, Figure 1 illustrates operating system 134, application programs 135, other program modules 136 and program data 137.
computer 110 may also include other removable / non-removable, volatile / non-volatile computer storage media. As an example only, figure 1 illustrates a hard disk drive 141 that reads or writes to non-removable / non-volatile magnetic media, a 15T magnetic disk drive that reads or writes to a<sup>-</sup>non-volatile removable magnetic disk 152 and an optical disk drive 155 that reads or writes to a non-volatile removable optical disk 156, such as a CD ROM or other optical media. Other removable / non-removable, volatile / non-volatile computer storage media that can be used in the exemplary operating environment include, but are not limited to, magnetic tape cassettes, flash memory cards, digital versatile disks, video tape digital, solid state RAM, solid state ROM and the like. Hard drive 141 is typically connected to the system bus 121 via a non-removable memory interface, such as interface 140, and magnetic disk drive 151 and the optical drive 155 are typically connected to the system bus 121 via a removable memory interface, such as interface 150.
The drives and their associated computer storage media discussed and illustrated in figure 1 provide storage of computer-readable instructions, data structures, program modules and other data for computer 110. In figure 1, for example, the disk drive drive 141 is illustrated by storing operating system 144, application programs 145, other program modules 146 and program data 147. Note that these components can be both the same and different from operating system 134, application programs 135, other program modules 136, and program data 137. Operating system 144, application programs 145, other program modules 146 is data ” '147 are' program numbers assigned with different numbers here to illustrate that, at the very least, they are different copies. A user can enter commands and information on computer 110 via input devices, such as a keyboard 162 and pointing device 161, commonly referred to as a mouse, ball mouse or touch pad. Other input devices (not shown) may include a microphone, game stick, game pad, satellite disc, scanner, a touchscreen and a portable PC or other computer with provision for coupling to a digitizer or similar. These and other input devices are usually connected to the processing unit 120 via an input interface of the
99 • 0 · 0 · · ·
0 0 0 · ·
0 0 0···· « 0 0 0 000 0 ·
0 · 0 0 · •00 * «0
0
0 0. · 0 0 0 0 user 160 which is coupled to the system bus 121, but can be connected by other interface and bus structures, such as a parallel port, game port or a universal serial bus (USB). A monitor 191 or other type of display device is also connected to the system bus 121 via an interface, such as a video interface 190. In addition to the monitor, computers can also include other peripheral output devices, such as speakers 197 and printer 196, which can be connected via an output peripheral interface 190.
Computer 110 can operate in a networked environment using logical connections to one or more remote computers, such as a remote computer 180. Remote computer 180 can be a personal computer, a server, a router, a network PC, a point device or other common network radio, and typically includes many or all of the above elements relating to computer 110, although only one memory storage device 181 has been illustrated in Figure 1. The logical connections shown in Figure 1 include a local area network (LAN) 171 and a wide area network (WAN) 173, but can also include other networks. Such network environments are common in offices, computer networks between companies, intranets and the Internet.
When used in a LAN network environment, computer 110 is connected to LAN 171 via a network interface or adapter 170. When used in a WAN network environment, computer 110 typically includes a 172 modem or other devices to establish WAN communications • 9 9 * · • · «···· ·; ·
9 4 9 9 9 9 4 · · ·
9 ··· 4999 9 9 9
9 4 9 9 9 9 9 9 9
99 999 9 · ···
172, which can be internal system bus 121 ion-m 1 £ Π m 1 mifrTn
173, such as the Internet. The modem, or external, can be connected to the appropriate mechanism via the input interface. In a networked environment, represented program modules relating to computer 110, or parts thereof, may be stored on the remote memory storage device. By way of example, and not by way of limitation, Figure 1 illustrates remote application programs 185 residing in memory device 181. It is noticed that the network connections shown are exemplary and that other devices for establishing a communications link between computers can be used.
UPDATE CONTROL WITH REPLICATION OF
RESOURCES
Figure 2 is a block diagram representing a resource replication system that includes two machines that replicate resources according to various aspects of the invention. Machines 201 and 202 both replicate resource A and update it simultaneously with content x for content y, u or z. The contents x, y, u, and z may correspond, for example, to different version sequence numbers and clocks for resource A. 0 The term machine is not simply limited to a physical machine. Instead, a single physical machine can include multiple virtual machines. Replication from one machine to another, in the form used here, implies replication of one or more components of the same replica set from one machine, virtual or physical, to another machine, virtual or physical. A single machine
<img file="BRPI0402702A_D0009.tif" />
physics can include multiple components of the same replica set. Thus, the replication components of a replica set can involve synchronizing the components of a single physical machine that includes two or more components of the same replica set.
A replication system typically maintains two sets of data related to each resource: resource data and resource metadata. In replication systems that include mid-10 file-based data stores in a file system, resource data can include file contents, as well as any file attributes that are stored on the file system in association with the file contents. File attributes can include access control lists (ACLs), time of creation / modification, and other data associated with a file. In replication systems' that include data stores not based on files named in a file system (for example, those in which resources are stored in a database or in data storage
0 based), data from the appropriate resources for data storage is stored. In this document, file-based replication systems in a file system are generally used for illustration, but it should be realized that any data storage capable of storing content can be used without departing from the spirit or scope of the present invention.
Resource metadata comprises a set of additional attributes that are relevant to trading sin13
<img file="BRPI0402702A_D0010.tif" />
timing during replication. For each resource, resource metadata can include a globally unique identifier (GUID), if the resource was deleted, a version sequence number together with the author of a change, a clock value to reflect the time when a change occurred and other fields, such as a summary that summarizes the values of the resource data and that can include signatures for the resource content. A summary can be used for quick comparison to deviate from data transfer during replication synchronization, for example. If a resource on a target machine is synchronized with the content on a source machine (for example, as indicated by a summary), poor network performance can be minimized by transmitting only the resource's metadata, without transmitting the data from the resource. feature itself. The transmission of the resource metadata is done in such a way that the target machine can reflect the metadata included in the source machine in its subsequent replication activities. This can allow the target machine, for example, to become a source machine for subsequent replication activity. Resource metadata can be stored with or separate from resource data, escaping the spirit or scope of the invention.
In general, in distributed area systems, it is not feasible to consider clock synchronization at a very granular level. This prevents replication systems from using a global clock to determine the winners for competing updates and creations. Replicators typically use distributed logical clocks that are stamped in metadata for distributed content. A logic clock is incremented when the content is updated, as opposed to being overwritten by the local physical clock at the time of change. Logical watches thus respect chance: updates of the same content are stamped with ever-increasing clock values. The clock value of A: x in figure 2, for example, can be four (4). The replication system then ensures that the clock values associated with A: y and A: z are greater than four. 0 The relationship between these clock values is arbitrary. The values may or may not be identical, as they are assigned independently (for example, machine 201 assigns the clock value to A: y, while machine 202 assigns the clock value to A: z).
In normal replication synchronization, clock values can be used to determine a conflict winner based on a last-record-winning conflict resolution strategy. Higher clock value data may indicate more recent data than replicated data with lower clock value. The last-of-the-gravaganha strategy is consistent with logical clocks, as they preserve chance.
In accordance with an aspect of the present invention, resource metadata is augmented with a numeric field called a protection value. A protection value can be assigned to each resource or part of it. Protection values are used during conflict resolution, in conjunction15
<img file="BRPI0402702A_D0011.tif" />
with the other metadata, according to a set of rules defined below.
In an embodiment of the invention, according to the rules, protection values are initialized to either zero or one. A value of zero indicates that the resource must not be transmitted or made visible (via the replication mechanism) to another machine. A value of one indicates that the resource can be replicated and made visible to other machines. A resource that has a protection value of zero can be considered a slave resource, while a resource that has a protection value of one can be considered a primary resource.
If, during a replication activity between two machines, a resource (for example, resource A) on one of the machines (for example, machine 201) has a protection value greater than that of the same resource on another machine (for example, example, on machine 202), the resource that has the highest protection value is replicated on the machine with the resource that has the lowest protection value. In other words, the resource with the highest protection value wins (and is replicated), regardless of what other metadata for the resource is present.
In the replication of a resource that already exists on two machines, but that are different, mechanisms can be used that try to propagate as little data as possible to synchronize the resource. For example, instead of transmitting all the data associated with a resource, the replication mechanism can determine which data on the resource on the machine it is transmitting from is different from the data on the resource on • ·· · · ··· · • ··· receiving machine and transmit one or more differences or deltas to update the resource on the receiving machine.
If, during the replication activity, the protection values 5 are the same and are greater than zero, then which resource wins (and which is replicated) depends on other resource metadata associated with each resource. In other words, when the protection values are the same, replication proceeds according to the normal rules associated with replication.
Thus, protection values provide refined control over the conflict resolution process, since they take precedence in resolving the conflict. That is, when metadata for two assets is purchased, the asset with the highest protection value takes precedence. Other attributes, such as logical references, are compared only when the protections are the same.
Protection values can have properties similar to logic clocks, as in an implementation they can only be incremented, or reset to zero. For example, a protection value can be increased when a user or process instructs the replication system to do so. This is sometimes referred to as resource protection or simply protection. An increase in the protection value is independent of updates to the resource data. Increments of protection become visible (for example, they are transmitted in metadata) through replication. Since protection is not a frequent operation, an entire representation of the clock time can be used to increase protection to the maximum (of the current protection value plus one) and (current clock time).
A protection value can be reset to zero when a user or process instructs the replication system to do so. This is sometimes referred to as deprotection of the resource or simply deprotection. Slave-mode features that are unprotected (that is, whose protection values have been reset to zero) cannot be replicated to any other machine outside the machine that owns them. This prevents a slave mode resource from becoming visible externally.
Consequently, the resetting of the protection value is not visible by replication. Except for protection and deprotection, protection values remain constant during replication. In particular, a positive protection value does not change, when the resource data is updated, or when the logical clocks change. Protection values validated at zero should also not change when updating content for slave machines.
It must be realized that the protection of a resource on a machine allows to force the replication of said resource, regardless of concurrent updates of the resource or other components of the replica set. As you can also see, the unprotection of a resource allows you to force any other replicated resource that takes precedence over a (unprotected) location and that prevents the unprotected resource from being replicated.
<img file="BRPI0402702A_D0012.tif" />
Protections can be established on an existing resource through an application programming interface (API) of the replication system that protects selected resources. Furthermore, protections can be established on future resources by exposing an API that protects resources that match specific parameters (such as resource names and attributes), when those resources are visible to the replication system. Protection control and future unprotection can also be provided by specifying stickiness: creation of indirectly related resources, such as resources under a protected / unprotected directory, can imply the protection value based on a policy established in the parent.
Deprotection also provides a granular way to control the principal or slave behavior of replication partners. Setting an err protection. selected features effectively make a machine a primary of that version of the content (until the content is updated for the first time). The lack of protection of the selected resources makes a machine behave like a slave in relation to the content associated with the selected resources.
It should be noted that protection and deprotection can be used in a number of areas, including restoring backups, out-of-band replication, upgrading to a newer version of the replicator, and providing administrator control. A machine that includes an unprotected resource (for example, with a protection value of zero), can choose to change the protection value of the des19 resource
<td> • ·</td><td> • · ·</td><td> • · · ·</td><td> *··</td><td> • ·</td>
<td></td><td></td><td></td><td></td><td></td>
<td> • ·</td><td> •</td><td> • · ··· · · ·</td><td> •</td><td> • · ·</td>
<td></td><td> •</td><td> • · · · · ·</td><td> •</td><td> • · ·</td>
<td></td><td> • · ·</td><td> • · * ···</td><td> •</td><td> • ···</td>
protected for a protected resource value (for example, one) for a resource that is updated locally on the slave. This can be done, for example, to make the update visible.
Figure 3 is a block diagram representing a system in which two machines attempt to reconcile a resource included in both according to various aspects of the invention. In figure 3, each machine has its own version of the resource and the resource has the same name or identifier. At the end of the reconciliation, the goal is to have a replicated resource that has both x and y content. In the system shown in figure 3, the content x of machine 301 beats the content y of machine 302. This can occur, for example, if a protection value is higher for resource A on machine 301 or by comparing other resource metadata. Figure 4 shows some data ”is metadata of the e = xemplar resources that could be used for A: x of figures 2 and 3 according to various aspects of the invention. The asset's metadata includes a protection value of 1, a clock value, a GUID, a replica component that authorized the change, and a summary. The resource data includes a resource name, the data itself, a creation time, a modification time, and other attributes of the resource data.
Figure 5 shows some exemplary resource data and metadata that can be used according to various aspects of the invention, related to the synchronization shown in figure 3. Content on machine 501 (for example, x) beats content on machine 502 (for example, y) and, consequen20 ·· · · · ··· · · · · · · · ··· · · · · · ··· • ··· · · · ··· · · ··· would be replicated to machine 502, because the protection value for the resource associated with x (for example, 1056603359) is greater than the protection value for the resource associated with y (ie, 1). Note that, in conventional replication methods, y would win x, due to a longer update time on the clock.
Figure 6 is a flowchart that represents, in general, exemplary steps that can occur to synchronize a resource between two machines according to various aspects of the present invention. The process begins at block 605.
In block 610, a determination is made whether at least one of the protection values indicates that the resource should be propagated. Both protection values can be set in an unprotected state (for example, 0). In this case, the resource should not be propagated. If one of the protection values is set to an unprotected value (for example, 1 or more), then the resource must be propagated if necessary to synchronize the two resources.
In block 615, if the resource is to be propagated20, processing drifts to block 620; otherwise, processing drifts to block 635. In block 620, a determination is made whether the protection values are equal. If so, processing drifts to block 625, where other metadata is used to determine how to propagate the resource. In block 627, the resource or a part of it (for example, metadata, protection value, differences in content and the like) is propagated from the machine that was determined in block 625.
• ·· • · · 9^99 ······ 9 . ....9 »······ » · • · · 9 · 9 · • · ·*····
If the protection values are not the same in block 620, processing drifts to block 63 0. In block 630, the resource or a part of it (for example, metadata, protection values, differences in content and the like) is propagated from the machine that has the highest protection value for the resource to the machine that has the lowest protection value for the resource. In block 635, processing ends.
The following are some example scenarios in which aspects of the present invention can be used.
Unofficial backup restore: When data becomes corrupted or lost, a user who manages a component of a replicated resource system can delete the component and ask if he gets all the data associated with the component through the replication system appeal. When a component is relatively large relative to the bandwidth of a link that connects the component to the resource replication system, this course of action can take a long time or be very expensive. Using one aspect of the invention, however, the user can restore a component's resources from a backup copy. 0 The user can then unprotect the resources in the backup (es., set the protection value to 0) and let the resource replication system update the resources that are out of date. In this case, the restored content only acts as a content supply store that a given appropriate logic can be used by the replicator to avoid transferring content over a link22
<td> 4 ·</td><td> » 99</td><td> •</td><td> 4</td><td></td><td> 4</td><td> 4</td><td> 444</td><td></td><td> 4</td><td> 4</td>
<td> • ·</td><td> 4</td><td> • 4</td><td> 4 4</td><td> 4</td><td> 4</td><td> 4</td><td> 4</td><td> 4</td><td> 4</td><td> 4</td>
<td> • «</td><td> •</td><td> • ·</td><td> • •4</td><td> 4</td><td> 4</td><td> 4</td><td> •</td><td> 4</td><td> 4</td><td> <</td>
<td></td><td> »</td><td> 4 ·</td><td> 4</td><td> 4</td><td> 4</td><td> 4</td><td> •</td><td> 4</td><td> 4</td><td> 4</td>
<td></td><td> • 44</td><td> 9</td><td> •</td><td></td><td> 4</td><td> • 4 4</td><td> 4</td><td></td><td> 4</td><td> 4 4 4</td>
ce slow (for example, by wire), thus maintaining the initial synchronization traffic that follows a backup restore restricted to metadata and resource data that needs to be updated. After synchronization, any remaining resources that have a protection value of 0 can be deleted or have their protection value set to 1 to allow them to replicate.
Out-of-band copying: new components of a replica set can potentially include a large amount of data. To facilitate faster and / or cheaper transfer, the new components can be transmitted through a channel that has less cost and / or faster service for the user. For example, new components can be copied to a hard drive or burned to CD-ROMs or DVD-ROMs and shipped overnight. With the copy of the new ”components in the system in the remote location, they can be unprotected in the above-described manner with respect to restoring unofficial backup. The deprotection of the new components is done to avoid transferring the copied content at the remote location to other locations.
Official backup restore: a user may want to restore from a backup and propagate the restored content to all systems on the replicated resource system. To do this, the user can restore resources to a system and then protect the resources that the user wants to propagate.
Ad hoc scenarios: a user may want to force a specific version of a feature set to replicate and • · · 9 9 ···
9 9 ··«· · ······ 9 ... 9 • · ··· * · · · • · · · · · · ··· · · ··· · • · 9 ·
9
9 take precedence over any other conflicting content in a replica set. This can be done by protecting the feature set.
Initial synchronization: Initial synchronization is a special case of out-of-band copying. When configuring or upgrading a replicated system, a user can designate one machine as the primary (that is, to contain content that must be replicated to the other machines) and designate the other machines as slaves (that is, to receive the content from the primary ). To do this, the user can protect the resource on the master to have an initial protection value of 1 and unprotect existing resources on slaves with a protection value of 0. A resource that starts to exist on a slave after this initialization can be protected with 1, so that it is replicated. Since an unprotected slave resource is not replicated, it is not necessary to synchronize additional metadata for such a resource when it is lost against a conflicting resource in the principal's name.
Figure 7 is a flowchart that generally represents exemplary steps that can take to perform an unofficial backup restoration according to various aspects of the invention. Data in a component is deleted or corrupted (block 710). The administrator restores from a backup (block 715). The administrator marks the restored data as unprotected (block 720). Synchronization takes place, as represented in the block
725. The administrator deletes or marks the remaining resources
<img file="BRPI0402702A_D0013.tif" />
with a protection value of 1 (block 730), and the process ends (block 735).
Figure 7 is provided as an example for the steps that can take place in the prescribed unofficial backup5. It should be noted that the other applications mentioned above were also described in sufficient detail to easily reduce the flowcharts. It should be understood that many other variations can be made in the steps of figure 7 or in the applications described above without departing from the spirit or scope of the present invention.
Figure 8 is a block diagram representing a machine configured to operate in a resource replication system in accordance with various aspects of the invention. Machine 805 includes an update mechanism 810, features 822, and a communication mechanism 840.
...... 'The update mechanism 810 includes “logic” for comparing protection 815 which is used to compare protection values and determine whether resources should be propagated from machine 805 or whether resources should still be visible to others machines. The 815 protection comparison logic can also be used to determine how protection values should be updated in the event of a protection or corruption operation or deletion and subsequent reconstruction of the 830 resource metadata (as described in more detail below) ).
The other 820 metadata conflict resolution logic includes the logic used to determine which resources win (and should be propagated), if protection values
<img file="BRPI0402702A_D0014.tif" />
resources are equivalent. Applying other metadata conflict resolution logic 820, update mechanism 810 can access data in resource 830 metadata and / or resource data 825 to determine whether a resource (or a part of it) should be propagated to a another machine or received from it.
Resources 822 include data from resource 825 and metadata from resource 830. The distinction between resource data and resource metadata was described earlier with reference to figure 2. Although shown in the same box, data from resource 825 can be stored in separate storage in relation to resource 830 metadata. The communication mechanism 840 allows the update mechanism 810 to communicate with other update mechanisms (not shown) or other machines. Together, the update mechanisms determine “what resources should be synchronized and how synchronization can occur. The communication mechanism 840 can be a network interface or adapter 170, modem 172 or any other device for establishing communications in the manner described with reference to figure 1.
It should be noted that other variations of the machine shown in figure 8 can be implemented without departing from the spirit or scope of the invention.
In one embodiment of the invention, there are three initial protection values: -1, 0 and 1. 0-1 plays the role of 0 above (that is, the unprotected value) and 0 can indicate that the resource can replicate, as long as there is no other resource with a protection value that is 1 or more. A utility like this
<img file="BRPI0402702A_D0015.tif" />
extension is in the treatment of loss of replication metadata. For example, a resource replicator can keep metadata in storage that is separate from the storage used to store resource data. Thus, the resource's metadata and data (that is, the content) can fail independently. During a rebuild, a machine that has lost its metadata can initially protect its resources with a value of -1, since it does not know whether this resource has already been replicated or was newly created locally (and therefore not known to others machines in the replica set). Changing the protection value from -1 to 1 prematurely could have the effect of reintroducing improvised content into the network, since the content of more up-to-date but disconnected machines can be overwritten. Moving the protection from -1 to 0, on the other hand, can allow such content to be reintroduced to the point where some other participant can determine that it is improvised. Note that 0, 1 and 2 (or some other numbering scheme) can be used instead, if only positive integers are desired by changing each of the above values.
Another modality of this invention uses e 0 as possible initial protection values. In functionality, the protection value of - replaces 0 (that is, it is the unprotected value), while 0 replaces 1 (that is, it indicates that the resource must be replicated). In addition, other negative protection values (for example, -1, -2, -3,..., -N) can be used to indicate resources that can be replicated. Such protection values would be lost against • ··· · · · ··· · · ··· protected resources with higher values. One utility of this generalization includes scenarios in which the availability of fresh resources is more important than the use of bandwidth during a restoration. Machines can each be assigned a different protection value (for example, -1, -2, ..., -n) that is used in the initial resources.
ordering gives precedence to a leading machine with the use of -1 protection, also non-conflicting content from all machines is immediately available.
Another application of this representation includes lowering the protection values each time a machine restores or reconstructs its metadata in response to corruption or loss of metadata. A heuristic value of this application is that each time the machine reconstructs its metadata, it is likely that the resource data stored on the machine will become<sup>-</sup> less reliable and / or updated. Through this mechanism, content on machines that reconstruct their metadata less frequently is considered more reliable and the content on machines on those that reconstruct their metadata more frequently wins through protection values.
It should be noted that the protection values described above are logical protection values that can be implemented in any variety of physical protection values. For example, protection values can be represented physically as unsigned integers, floating point numbers, bit values or any other type of numbering scheme, without departing from the spirit or scope of the invention.
As can be seen from the detailed description presented, an improved method and system for granular control of information replication is provided. Although the invention is susceptible to various modifications and alternative constructions, certain embodiments illustrated are shown in the drawings and have been described in detail earlier. It must be understood, however, that there is no intention to limit the invention to the specific forms described, but, on the contrary, the intention is to cover all modifications, alternative and equivalent constructions that fit the spirit and scope of the invention.
• · φ φ φ φ φ φ φφφφ φ φφφ
<img file="BRPI0402702A_D0016.tif" />
Contents10
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
22 members in 13 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 48662703 | United States of America | P | |
| 73345903 | United States of America | A | |
| 10733459 | – | – | – |
| 60486627 | – | – | – |
| US20030486627P | – | – | – |
| US20030733459 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| CA2472528A1 | Canada | A1 | |
| KR20050007179A | Republic of Korea | A | |
| EP1498814A1 | European Patent Office (EPO) | A1 | |
| US2005015413A1 | United States of America | A1 | |
| AU2004202863A1 | Australia | A1 | |
| JP2005032249A | Japan | A | |
| MXPA04006721A | Mexico | A | |
| CN1607500A | China | A | |
| BRPI0402702AThis record | Brazil | A | |
| RU2004121135A | Russian Federation | A | |
| CN100410874C | China | C | |
| RU2372649C2 | Russian Federation | C2 | |
| US7660833B2 | United States of America | B2 | |
| EP1498814B1 | European Patent Office (EPO) | B1 | |
| AT463789T | Austria | T | |
| ATE463789T1 | Austria | T1 | |
| DE602004026389D1 | Germany | D1 | |
| AU2004202863B2 | Australia | B2 | |
| ES2341245T3 | Spain | T3 | |
| JP2011253574A | Japan | A | |
| KR101109257B1 | Republic of Korea | B1 | |
| JP5192635B2 | Japan | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent lapsed as no evidence of payment of the annual fee has been furnished to inpi [chapter 8.11 patent gazette]LapsedREFERENTE AO DESPACHO 8.6 PUBLICADO NA RPI 2261 DE 06/05/2014.B08K | B08K | |
| Application dismissed because of non-payment of annual fees [chapter 8.6 patent gazette]REFERENTE A 10A ANUIDADE.B08F | B08F |
Numbers
- Publication, DOCDB
- PI0402702
- Publication, EPODOC
- BRPI0402702
- Application
- 4027027
- Application, DOCDB
- PI0402702
- Application, EPODOC
- BR2004PI02702
Titles2
- English
- Granular control over replicated information authority through protection and unprotection
- Portuguese
- Controle granular sobre a autoridade de informação replicada por meio de proteção e desproteção
Classification
- CPC, 3
- G06F16/1844
- G06F12/16
- Y10S707/99954
- IPC, 7
- G06F12 00
- G06F9 44
- G06F9 46
- G06F11 00
- G06F12 16
- G06F15 16
- G06F17 30