Group access privatization in clustered computer system
25 claims: 4 independent, 21 dependent
- 1Způsob přístupu ke skupině v klastrovém počítačovém systému, kde klastrový počítačový systém obsahuje množství uzlů a skupina obsahuje množství členů, kteří jsou příslušným způsobem přítomní v množství uzlů, přičemž způsob zahrnuje:(a) obdržení požadavku na přístup v prvním uzlu z množství uzlů, přičemž požadavek na přístup označuje klastrově privátní jméno skupiny příslušející dané skupině a (b) zpracování požadavku na přístup v prvním uzlu pro vyvolání skupinové operace alespoň na podmnožině uzlů, které mapují na klastrově privátní jméno skupiny.
- 2Způsob podle nároku 1, dále obsahující generování požadavku na přístup uživatelskou úlohou přítomnou v prvním uzlu.
- 3Způsob podle nároku 2, dále obsahující předání požadavku na přístup klastrově infrastruktuře přítomné v prvním uzlu prostřednictvím volání z uživatelské úlohy.
- 4Způsob podle nároku 1, dále obsahující:(a) generování požadavku na přístup uživatelskou úlohou přítomnou ve druhém uzlu z množství uzlů a (b) zpracování požadavku na přístup proxy úlohou přítomnou ve druhém uzlu pomocí oznámení požadavku na přístup prvnímu uzlu.
- 5Způsob podle nároku 4, kde proxy úloha je členem skupiny klastrového řízení a způsob dále obsahuje:27 86821 (2786821_CZ.doc) 9.11.2003 • · · · · · . : · : : .: : · _ 23 ..... : · : · *·*’ · (a) předání požadavku na přístup z uživatelské úlohy proxy úloze a (b) předání požadavku na přístup z proxy úlohy klastrové infrastruktuře přítomné ve druhém uzlu prostřednictvím volání z proxy úlohy.
- 6Způsob podle nároku 1, dále obsahující získání klastrové privátního jména skupiny uživatelskou úlohou pomocí přístupu do klastrové privátní datové struktury. klastrové privátní datová struktura přítomná.
- 79. Způsob podle nároku 8, kde klastrové privátní datová struktura je přístupná pouze pro úlohy, které jsou přítomné v uzlu, v němž je přítomna klastrové privátní datová struktura.
- 810. Způsob podle nároku 1, kde vyvolání skupinové operace obsahuje distribuci zpráv do množství členů skupiny přítomných v uzlech, které mapují na klastrové privátní jméno skupiny.
- 911. Způsob podle nároku 10, kde vyvolání skupinové operace dále obsahuje přistoupení k datové struktuře skupinových adres pro získání množství síťových adres spojených s klastrové privátním jménem skupiny, přičemž 27 86821 (2786821_CZ.doc) 9.11.2003 • · · · • · · · · · distribuce zpráv do množství členů skupiny zahrnuje poslání zprávy na každou z daného množství síťových adres.
- 1012. Způsob podle nároku 1, kde vyvolání skupinové operace provádí klastrová infrastruktura přítomná v prvním uzlu.
- 1113. Způsob podle nároku 12, kde vyvolání klastrové operace obsahuje získání množství adres pomoci klastrové infrastruktury, kde adresy jsou mapovány pro klastrové privátní jméno skupiny v datové struktuře, která je lokální pro klastrovou infrastrukturu.
- 1214. Způsob podle nároku 1, kde vyvolání skupinové operace obsahuje v prvním uzlu lokální vyhodnocení mapování mezi klastrové privátním jménem skupiny a množstvím adres spojených alespoň s podmnožinou z množství uzlů.
- 1315. Zařízení, obsahující:(a) paměť přístupnou prvnímu uzlu z množství uzlů v klastrovém počítačovém systému a (b) program přítomný v paměti a prováděný prvním uzlem, přičemž program je nakonfigurován pro přístup ke skupině, která obsahuje množství členů přítomných postupně v množství uzlů, tím, že obdrží požadavek na přístup, který udává klastrové privátní jméno skupiny spojené se skupinou, a zpracuje požadavek na přístup, pro vyvolání skupinové operace alespoň na podmnožině z množství uzlů, které mapují na klastrové privátní jméno skupiny.
- 1416. Zařízení podle nároku 15, dále obsahující uživatelskou úlohu nakonfigurovanou pro generování požadavku na přístup. 27 86821 (2786821_CZ.doc) 9.11.2003 ·· ····
- 1517. Zařízení podle nároku 16, kde program obsahuje klastrovou infrastrukturu přítomnou v prvním uzlu.
- 1618. Zařízení podle nároku 17, dále obsahující proxy úlohu nakonfigurovanou pro předání požadavku na přístup z uživatelské úlohy do klastrové infrastruktury.
- 1719. Zařízení podle nároku 15, dále obsahující:(a) klastrové privátní datovou strukturu nakonfigurovanou pro uložení klastrové privátního jména skupiny a (b) uživatelskou úlohu nakonfigurovanou pro přistupování ke klastrové privátní datové struktuře pro získání klastrové privátního jména skupiny a pro generování požadavku na přístup z ní.
- 1820. Zařízení podle nároku 19, kde klastrové privátní datová struktura je přítomná ve stejném uzlu jako uživatelská úloha.
- 1921. Zařízení podle nároku 20, kde klastrové privátní datová struktura je přístupná pouze z uzlu, v němž je přítomná klastrové privátní datová struktura.
- 2022. Zařízení podle nároku 15, dále obsahující datovou strukturu skupinových adres nakonfigurovanou pro uložení množství síťových adres spojených s klastrové privátním jménem skupiny, přičemž program je nakonfigurován pro vyvolání skupinové operace přistoupením k datové struktuře skupinových adres pro získání množství síťových adres a pro zaslání zprávy na každou z daného množství síťových adres. 27 86821 (2786821_CZ.doc) 9.11.2003 •9 9999 999 *
- 2123. Zařízení podle nároku 22, kde program obsahuje klastrovou infrastrukturu, přičemž datová struktura skupinových adres je lokální pro klastrovou infrastrukturu.
- 2224. Způsob podle nároku 15, kde program je dále nakonfigurován pro zpracování požadavku na přístup tím, že v prvním uzlu lokálně vyhodnotí mapování mezi klastrově privátním jménem skupiny a množstvím adres spojených alespoň s podmnožinou z množství uzlů.
- 2325. Klastrový počítačový systém, obsahující:(a) množství uzlů vzájemně propojených sítí, (b) skupinu obsahující množství členů přítomných postupně v množství uzlů a (c) program přítomný v prvním uzlu z množství uzlů a nakonfigurovaný k přistupování ke skupině tím, že obdrží požadavek na přístup, který udává klastrově privátní jméno skupiny spojené se skupinou, a zpracuje požadavek na přístup, pro vyvolání skupinové operaci alespoň na podmnožině z množství uzlů, které mapují na klastrově privátní jméno skupiny.
- 2426. Programový produkt, obsahující:(a) program přítomný v paměti a prováděný prvním uzlem z množství uzlů v klastrovém počítačovém systému, přičemž program je nakonfigurován pro přístup ke skupině, která obsahuje množství členů přítomných postupně v množství uzlů, tím, že obdrží požadavek na přístup, který udává klastrově privátní jméno skupiny spojené se skupinou, a zpracuje požadavek na přístup, pro vyvolání skupinové operace alespoň na podmnožině z množství uzlů, které mapují na klastrově privátní jméno skupiny a (b) médium nesoucí signál, které obsahuje program.
- 2527 86821 (2786821_CZ.doc) 9.11.2003 • · ···· 27. Programový produkt podle nároku 26, kde médium nesoucí signál zahrnuje alespoň jedno z přenosného média a zaznamenatelného média.
Independent claims25
94 paragraphs in 3 sections, as filed
The invention generally relates to clustered computer systems, and more particularly to controlling access to groups present in such systems.
BACKGROUND OF THE INVENTION Clustering generally refers to an arrangement of a computer system where multiple computers, or nodes, are interconnected in a network to perform computational tasks together. An important aspect of a computer cluster is that all nodes in the cluster give the impression of a single system - that is, nodes in the cluster look collectively as a single computer or entity.
Clustering is often used in relatively large multi-user computer systems where high is important performance and reliability . For example, clustering can be used to provide redundancy, or fault tolerance, so that if any node in the cluster fails, the other nodes in the cluster will take over the operations that the node previously performed. Clustering is also used to improve overall performance, because multiple nodes are often able to handle more jobs in parallel than would otherwise be able to handle a single computer. Often can also be used
86821 (2786821_EN.doc) 9.11.2003
<img file="CZ20032918A3_D0001.tif" />
load balancing to ensure that tasks are distributed fairly between nodes to avoid overloading individual nodes, thereby maximizing overall system performance. One particular clustering application is, for example, in providing multi-user access to a shared resource, such as a shared resource. to a database or storage device, since a plurality of nodes can handle a relatively large number of user access requests, and because the shared resource typically remains available to users even after any given node in the cluster fails.
Clusters typically handle computational tasks by performing “jobs” or “processes” on individual nodes. In some cases, tasks performed by different nodes work together to handle a computational task. Such cooperative tasks are typically capable of communicating with each other and are typically managed in a cluster by a logical entity known as a "group." A group is typically assigned some form of identifier, and each task in the group is marked with that identifier to indicate its membership in that group.
Membership tasks within a group typically communicate with each other through a ranked message scheme in which a specific order of messages is sent between group members so that each member sees messages sent by other members in the same order as each other member, ensuring synchronization between nodes. Requirements for operations to be performed by group members are commonly referred to as "protocols, and group members cooperatively perform tasks typically using one or more protocols."
While the member tasks in the group use ordered messages to communicate with each other for the purpose of cooperative
86821 To perform tasks, a clustered computer system typically also needs support for entities outside the group to send a request to the group to perform various group operations. Conventionally, external access to a group is supported by assigning a specific network address (e.g., a TCP / IP address) to the group, so that an external entity wishing to join the group can send a request to that specific address. This technique is sometimes called "N + 1 addressing, where there are N addresses assigned to N nodes in a group, plus one extra address for the group itself.
As with other conventional network addressing protocols, the clustered computer system provides a name service for mapping group network addresses to "group names." The name can generally take any form of acronym or alias for a particular group accessible through the network. The advantage of using a name instead of a direct address to access a network entity is that the entity can always be accessed by name, even if the name mapping is modified, as the network address assigned to the entity may change from time to time.
The address of an entity on a network, including a cluster node or group, is typically obtained on a conventional clustered computer system by accessing a network name server, such as a directory name service (DNS) server present on the network. Thus, if an entity wants to access another entity in the network, then typically the accessing entity evaluates the name of the entity to be accessed through the network name server, and then sends a message to the network address returned by the server. So, in the case of external access to a group, the entity that wants to send the request to the group evaluates the group name via
86821 (2786821_EN.doc) November 9, 2003 · Network Name Server and sends a message to the group address returned by the server.
Using an external name server to access a group poses a number of problems. First, a major concern is that a node or other entity outside the cluster could send messages to the group that could interfere with the group's activities. Particularly in view of the security risks posed by viruses, Trojans and other malicious programs, along with the increasing use of the Internet, the ability to access a group by simply accessing the network address associated with that group poses a serious security risk for a clustered computer system.
Second, in many cases, it may be desirable to implement a plurality of clusters, or cluster "instances," in a given clustered computer system, e.g., a logically partitioned system in which a plurality of cluster instances can operate concurrently on different logical computer systems operating in the same physical system. However, where there are multiple clusters, the restriction is that there cannot be the same group name in each cluster, because a typical name server is usually used that cannot resolve the group name to different network addresses. Conventionally, clusters can avoid these problems by requiring a separate local area network (LAN) for each cluster and banning the expansion of subnets of any cluster. However, it is often desirable to implement a clustered computer system in a variety of network topologies, including geographically separated implementations in which nodes can be interconnected over long distances, and implementations in which nodes are connected through a public network, such as the Internet. As a result, the cluster is not limited to
86821 (2786821_EN.doc) 9.11.2003 dedicated LAN in many situations desirable.
Thus, there is a serious need in the art for a method for supporting external access to groups present in a clustered computer system, and in particular a mechanism for supporting external access to groups that is capable of restricting access to authorized entities only.
SUMMARY OF THE INVENTION
The invention addresses these and other problems associated with the prior art by providing a device, a clustered computer system, a program product, and a method that relies on cluster-private group names to access groups that are present in a clustered computer system. In other words, in a cluster accessible group, all nodes that are able to participate in the cluster are configured to map to the same cluster private group name for the group so that any external user who has access to the cluster can access and use the group name the name of the group to start operations with this group. Unauthorized users (e.g. users from unauthorized nodes, on the other hand, are typically denied access to a group name or making cluster requests using a group name, thereby preventing them from accessing the group.
In embodiments of the present invention, the mapping of cluster private group names to group member addresses (e.g., network addresses of nodes in which group members are present) can be effectively "hidden from nodes or users outside the cluster, using the group data structure
86821 (2786821_EN.doc) 9.11.2003 addresses that are only accessible on nodes participating in the cluster. In addition, embodiments of the present invention typically evaluate mapping of group names to group member addresses locally on each node, eliminating the need for an external name server or other centralized resource.
The cluster infrastructure on each node is typically used to host and use name-address mapping so that group access requests can be handled internally within and between cluster infrastructures of different nodes in the cluster. Only entities as such that have access to the cluster infrastructure on the node (typically entities that are present on the same node) as well as the appropriate group name to access the cluster infrastructure are allowed access to a particular group.
Accordingly, in one aspect of the invention, a group in a clustered computer system is partially accessed such that the first node of the plurality of nodes receives an access request, wherein the access request identifies a cluster private group name belonging to the group. The access request is further processed on the first node to run a group operation at least on a subset of the plurality of nodes that map to the cluster private group name.
Overview of the drawings
BRIEF DESCRIPTION OF THE DRAWINGS FIG. 1 is a block diagram of a network computer comprising:
86821 (2786821_EN.doc) 9/11/2003 • ·. Fig. 2 is a block diagram of a node in the cluster computer system of Fig. 1 Fig. 3 is a block diagram of a group address table present in the node of Fig. 2 Fig. 4 is a flow chart illustrating a sequence of operations occurring during an access a group invoked by a user task on a node in the cluster computer system of FIG. 1
DETAILED DESCRIPTION OF THE INVENTION
Typically, the embodiments described herein utilize cluster private group names to access groups present in the cluster computer system. Typically, group names can represent any unique identifier that can be associated with a software entity, including a combination of alphanumeric characters, a binary number, a pointer, or other form of handler, token, or indicator. A group name is cluster-private when the group name cannot be accessed from outside a node that is participating in a particular cluster, or clustered instance. For example, a group name can be cluster private if the group name is present on a node that is participating in a cluster instance and can be accessed using tasks that run on that node, ie. if the group name on the node is local. The group name can also be clustered private if, for example, some form of authorization mechanism is used to restrict access to the group name to only
86821 (2786821__EN.doc) 9.11.2003 »· nodes and / or tasks that may be involved in a cluster.
Group access requests triggered in conjunction with a group name can take many forms according to the present invention. For example, a group access request may include a message sent to the cluster infrastructure or group member present on the same or another node as the requesting entity (e.g., user task). In another alternative, the group access request may include functional calls to the cluster infrastructure. Alternatively, other methods of issuing a request, e.g. through a dedicated network.
Group accesses typically take the form of running group operations, that is, operations performed by one or more group members, either together or separately. As described here, any function that the software, and specifically the cluster group, can execute or run, can be implemented in the group and by requesting access to the group. For example, a print service group that controls print operations for one or more printers connected to a clustered computer system can support various printer operations such as printing, printer setup, spool or queue control, printer initialization or shutdown, redirection print jobs on specific printers, etc. Other types of groups may support other types of group operations. Moreover, it can be appreciated that the types of operations that can be run on behalf of external users can be limited to a subset of the possible group operations provided by the group, ie some operations may be internal to the group and inaccessible from outside the group.
To ensure the ability to restrict access to groups
86821 (2786821_EN.doc) 9.11.2003
<img file="CZ20032918A3_D0002.tif" />
For operations against unauthorized entities, the illustrated embodiments mainly use the cluster infrastructure present on each node participating in a particular cluster to maintain local mapping of group names to group member addresses and / or nodes in which such members are present. As messages are distributed to group members, and specifically to the addresses of those members, they are effectively hidden from the tasks or applications that access the cluster infrastructure as such. Thus, instead of initiating a group operation by sending a request to a specific address, the request is sent to the cluster infrastructure and is managed by the cluster infrastructure at a higher software layer and protocol than the low-level network addresses conventionally used to access cluster groups. In addition, each node, and typically the cluster infrastructure on each node, is able to locally evaluate the group name mapping address of the group member. Typically, an external name server is not required.
a number of unauthorized
There are advantages in using group names as described herein. For example, external access of entities to a group is greatly restricted due to the fact that such entities do not have the ability to identify the appropriate group name and / or make a request that identifies the group name, as well as local name-address mapping on each node. The security of the cluster itself is considerably strengthened.
In addition, by using group names that are local to a particular cluster instance, it is possible to ensure the conflict-free use of the same group name in multiple cluster instances on the same network, eg in a logically partitioned system where multiple cluster instances
86821 (2786821_EN.doc) 9/11/2003 • ·· · φ
<img file="CZ20032918A3_D0003.tif" />
runs jobs on the same network. In addition, for the purpose of supporting group operations, it is often irrelevant what network topology the clustered computer system uses because the distribution of group messages in response to an authorized external request is managed in the cluster infrastructure at each participating node. In addition, if desired, the embodiments described herein support the ability to restrict access to a group to only a subset of nodes participating in a cluster, provided the ability to locally manage group names on such nodes.
Referring now to the drawings in which like numbers refer to like parts in several views, FIG. 1 illustrates a cluster computer system 100 comprising a plurality of nodes 102 (also referred to as nodes 1-8) interconnected in a distributed manner, e.g., over a local area network (LAN). ) 104, 105 and WAN 108. In the illustrated embodiment, a subset of nodes in the system 100 (e.g., nodes 1-7) function cooperatively as a cluster 110, thereby giving the impression of a single system for external computing devices. Other devices may also be present in the system 100 and may be included in it, but such devices may not participate in clustering or may be participating in a cluster other than cluster 110 (e.g., node 8 that is not involved in the configuration shown in FIG. 1). cluster 110).
In accordance with the invention, any number of network topologies commonly used in clustered computer systems and other networked computer systems in general may be used to interconnect nodes 102. In addition, individual nodes 102 may be physically located in close proximity to other nodes or may be geographically separated from
86821 (2786821_EN.doc) November 9, 2003 other nodes, as is well known in the art. Further, networks used to interconnect nodes may be private or public in nature, or may include a combination of private and public networks.
Referring to Fig. 2, an exemplary hardware combination for one of the nodes 102 in the cluster 110 is shown. Node 102 generally represents, for example, any of a number of multi-user computers such as a network server, middle class computer, mainframe, etc. it should be appreciated that the invention may be practiced in other computers and data processing systems, e.g. independent computers or single-user computers such as workstations, desktops, laptops, etc., or other programmable electronic devices (eg, embedded embedded controllers, etc.).
The node 102 generally comprises one or more system processors 12 connected to main memory 14 using one or more cache levels arranged in the system cache 16. The main memory 14 is further connected to a variety of external device types via system input / output (I / O) a bus 18 and a plurality of interface devices, e.g., an I / O adapter 20, a workstation controller 22 and a memory controller 24, which provide external access to one or more external networks (e.g. network 104), respectively. one or more workstations 28 and / or one or more storage devices, such as Direct Access Storage Device 30 (DASD). Alternatively, any number of alternative computer architectures may be used.
In order to implement the functionality of the privatized
86821 (2786821_EN.doc) November 9, 2003 Typically, each node in a cluster contains a clustered cluster management infrastructure for access to a group according to the present invention. based operations on the node. For example, it is shown that node 102 has an operating system 30 present in main memory 14 that implements a cluster infrastructure referred to as resource clustering services 32. Also depicted is one or more tasks or applications 34, each of which has access to clustering functionality implemented in resource clustering services 32. In addition, it is shown that node 102 includes a user task 36, which may or may not be a member of a cluster group or have access to clustering functionality implemented in resource clustering services 32.
As will be seen below, one particular application of the privatized group access functionality described herein is used when an entity outside the group is accessing the cluster group, e.g., so that an entity that is not allowed to participate in the cluster group can make requests to that group. Thus, in the illustrated embodiment, the user task 36 will typically be an external entity that is not a member of the group to be accessed, but is able to access the services or resources supported or managed by the group to be accessed (regardless of whether it has this user task access to clustering services or not and whether this user service is a member of another group or not). In other embodiments, the privatized group access functionality described herein can be used in conjunction with internal communication between group members.
Cluster management task 33 (CTL) is also implemented at node 102 and participates on behalf of the node in the cluster management group to assist in managing functionality
86821 (2786821_EN.doc) 9.11.2003
<img file="CZ20032918A3_D0004.tif" />
• ················ · H
- 13 clustering. In the illustrated embodiment, the cluster control task is required to be present on each node participating in the cluster, and it is by the cluster control group that various cluster control operations are performed. For example, the presence of a cluster control task on each node allows a user task to issue a request for access to a cluster control task on the same node, whereby the cluster control task acts as a "proxy task to forward the request to the resource clustering services for processing." However, in other embodiments, a user task may be allowed to access resource clustering services directly, either when the user task is participating in clustering or, in some cases, when the user task is outside the clustering but is present on the node that participates in clustering. .. Access to resource clustering services typically creates a functional call, although other forms of requesting the task from resource clustering services (e.g. message-based requests, etc.).
Briefly, referring back to Figure 1, there is shown a sample cluster control group having CTL1-CTL7 members present at nodes 1-7 as well as a sample group A comprising A1-A7 members capable of performing the particular group operations required by users or tasks. One such user is represented by task U1, which is present on the node that participates in clustering (node 1), and is therefore able to access the group name belonging to group A. Conversely, another U2 user present in node 8 is shown, but U2 user access to the group will be prevented since node 8 does not participate in the cluster. In this example scenario, U2 as such is prohibited from running a group operation on group A.
86821 (2786821_EN.doc) 09/11/2003 • · · · · *
• 9>
« ·
Referring back to Fig. 2, it should be appreciated that functionality described herein can be implemented in other software layers at node 102 and that functionality can be allocated among other programs, computers, or components in cluster 110. Therefore, the invention is not limited to specific software implementation described herein.
The following description will focus on specific routines that are used to implement the privatized group access functionality described above. Routines run to implement embodiments of the invention, whether implemented as part of an operating system or a particular application, component, program, object, module, or sequence of instructions, will be referred to herein as "computer programs or simply" programs. Computer programs typically contain one or more instructions that are present at different times on the computer in different storage and storage devices and which, when read and run by one or more processors on the computer, cause the computer to perform the steps necessary to run steps or elements embodying various aspects. invention. Moreover, since the invention includes and will be described in the context of fully functional computers and computer systems, those skilled in the art will appreciate that various embodiments of the invention can be distributed as a program product in various forms and that the invention applies in the same way to realize the invention. Examples of signal-bearing media include, but are not limited to, recordable media such as, but not limited to, recordable media. energy-dependent and independent storage devices, floppy and other removable disks, hard disks, optical disks (eg CDROM, DVD, etc.), and transmission-type media such as digital and analog communication lines.
86821 (2786821_EN.doc) 9.11.2003
V 9
It will be appreciated that the various programs described herein can be identified based on the application for which they are implemented in a specific embodiment of the invention. However, it should be appreciated that any particular designation that follows is used for convenience only, and the use of the invention is therefore not limited to any particular application identified and / or envisaged by such designation.
A variety of data structures can be used to implement a privatized group approach according to the invention. For example, as shown in FIG. 2, for all tasks present in the node, the group name data structure 38 may be accessible including the group name for each group present in the node. In the illustrated embodiment, the group name data structure is maintained as a global data structure that is accessible to any task present on the node. However, the data structure of group names is typically private to the cluster. In other words, any node that does not participate in the cluster is denied access to the group name data structure, and likewise any task present in such an external node is denied access to the group name data structure. By requiring that all group-directed requests be made using the group name belonging to the group, external nodes and tasks are prevented from making requests to the group.
According to the invention, a variety of different data structures can be used to implement group name data structure 38. For example, in some embodiments, a table of available group names may be used. In other embodiments, other data structures, e.g., link lists, and the like may be used instead.
86821 (2786821_EN.doc) November 9, 2003 • 9 · 3 · 9
In addition, identical copies of the table may be present and maintained on each node in the cluster. In an alternative embodiment, a user task on one node may be allowed access to the group name data structure present on another node in a cluster or database accessible to a plurality of nodes, provided that access to the group name data structure is prohibited for tasks or other entities, that are not present in the node that participates in the cluster. Authorization may also be required to access the group name data structure, and the respective authorization information may be stored for each group in its respective entry in the group name data structure. Other information, such as access lists, access rights, etc., may also be included in such a data structure according to the invention.
Giant. 2 also shows a group address data structure 40 present and accessible to a node in resource clustering services 30. As described above, mapping the group name to the addresses of members and / or nodes that actually implement the desired group operation is typically maintained locally for the clustering infrastructure at each node, and the data structure 40 as such is typically maintained as a local data structure that is accessible only for resource clustering services 32 on each node.
One exemplary implementation of data structure 40 is shown in Figure 3, although it will be appreciated that other data structures may be used to store the necessary group address mappings described herein. The data structure 40 is typically local to the clustering infrastructure in the node and replicates between the different nodes involved in the cluster. It should be appreciated that a method of distributing updates and synchronizing various local data structures can be used
86821 (2786821_EN.doc) November 9, 2003 ·· 9 9 9 «• • 99
<img file="CZ20032918A3_D0005.tif" />
in a cluster, for example, through a ordered message scheme used to interconnect resource clustering services on each node.
The data structure 40 is displayed as a table containing a plurality of entries that map a group name 42 to a plurality of node names to which messages to be routed to the group are to be sent. In the illustrated implementation, the node list is implemented as a linked list pointed to by pointer 44 associated with group name 42. The junction list comprises a plurality of node entries 46, each indicating a node name 48, as well as a pointer 50 to a list of network (e.g., IP) addresses that can be used to access the node. Each node name record 46 also includes a successor pointer 52 that points to the next node record 46 in the join list, with the last name record 46
<td>node in the list value saved</td><td>is in NULL.</td><td>indicators 52</td><td>to the successor</td><td>typical</td>
<td>IP list</td><td>addresses</td><td>serves as</td><td colspan="2">mapping IP addresses to</td>
<td>specific name</td><td>node</td><td>and contains</td><td>number of records</td><td>54 IP</td>
addresses each containing an IP address 56 and a successor pointer 58 that points to the next IP entry 54 in the junction list. For the last record 54 in the list, typically a NULL value is stored in the successor pointer 58.
As is well known in the art, multiple IP addresses may belong to a particular node so that, in the event of a failure when attempting to access a node via a particular IP address, a secondary IP address belonging to that node may be called.
It should be appreciated that to store the information in the data
86821 (2786821_EN.doc) 9.11.2003
<img file="CZ20032918A3_D0006.tif" />
structure 40, alternative data structures may be utilized. In addition, in some implementations, only one IP address can be associated with a particular node, with mapping between the group name and the plurality of nodes omitting the node name information, and in the mapping data structure, the group name entry can directly point to the IP address list. In addition, in some implementations, names or addresses may belong to group members instead of nodes, so that instead of mapping the group name to a node list, mapping between the group name and custom group members can be determined. Other modifications will be apparent to those skilled in the art.
In traffic, access to a group is typically triggered by a user task present on the node that participates in the cluster to request that a particular group operation be performed by the group located in the cluster. For example, Fig. 4 illustrates an exemplary group access operation 60 that may be performed to invoke a group operation in response to an access request issued by an authorized entity from outside the group in the cluster 110. In an exemplary operation, blocks 62-70 represent operations performed on a local node in which a user task requesting access to a group is present. Blocks 72-76 are executed by one or more remote nodes, in particular each node in which a member of the group to participate in the desired group operation is present.
As shown in block 62, the user task typically invokes a group access request by first discovering the group name from the group name data structure on the local node. As described above, in the illustrated embodiment, the group name data structure is global for all tasks present in the local node, but is private to entities that do not occur in the local node.
86821 (2786821_EN.doc) 9.11.2003
<img file="CZ20032918A3_D0007.tif" />
*> · · · · ·
Further, as shown in block 64, the user job sends a request to the local job for the group using the group name. In the depicted implementation as described above, it is assumed that each group has a member on each node participating in the cluster. As such, the local group member can serve as a proxy task for forwarding the group access request to the group members present on other nodes in the computer system. However, in other embodiments, the local group member may not be present at the local node, and the user task may be required to make a functional call or otherwise inform resource clustering services at the local node of the need to access the group. In yet other embodiments, the local cluster control task can act as a proxy task on behalf of another group in the cluster.
Further, as shown in block 66, the local task for the group invokes a functional call to the resource clustering services to forward the access request to the group. Subsequently, as shown in block 68, resource clustering services access the group name data structure on the local node to obtain a list of IP addresses belonging to the group members to whom the group message is to be distributed. Then, as shown in block 70, resource clustering services send messages to different group members using an IP address list.
As shown in block 72, on each remote node that receives the sent message, the monitoring task present in the resource clustering services for the remote node detects the receipt of the message. This task then routes the message to the appropriate group member based on the group name associated with the message, as shown in block 74. As shown in block 76, the message is then processed by the remote group job, thereby giving that member
86821 (2786821_EN.doc) 9.11.2003 the group invokes the required group operation. It can be appreciated that other operations can also be performed after block 76, such as responding to other nodes or sending the result back to the user task. Typically, however, the processing of a message by a group task will vary greatly depending on the particular group operation being requested.
It will be appreciated that various methods of sending messages between group members using resource clustering services can be used according to the invention. For example, one suitable communication mechanism described in US Patent Application Serial No. 09 / 280,469, filed Mar. 30, 1999, Block et al. and US Patent Application Serial No. 09 / 173,090, filed Oct. 15, 1998 by Block et al. (each of which is incorporated herein by reference). Alternatively, other communication mechanisms may be used.
In addition, when processing messages on a remote node, various mechanisms can be used to detect and forward appropriate messages to group members present on the node. For example, if each node is implemented as an AS / 400 midrange computer system supplied by International Business Machines Corporation, each member of the group may have a Machine Interface (MI) queue associated with the group name and a monitoring task that reads from that queue. The queue can be registered with resource clustering services as a member of a group. When a group request is then made, the local node sends the request to the MI queue, where the monitoring task detects the message, reads the message, and then processes the message appropriately. Alternatively, other hardware and / or software implementations may be used.
Various modifications may be made without departing from the spirit and scope of the invention. In one implementation, it may be
86821 It is desirable to require a group to have a group member on each node, even if some nodes are not actively involved in intra-group messaging (ie, such nodes are "passive in terms of intra-group members involved). Other modifications will be apparent to those skilled in the art. The invention is therefore based on the appended claims.
Industrial applicability
The invention can be used to manage computer systems, in particular to control access to groups present in clustered computer systems.
Contents3
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
20 members in 10 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 84559601 | United States of America | A | |
| 84559601 | United States of America | A | |
| 2001845596 | – | – | – |
| US20010845596 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| US2002161768A1 | United States of America | A1 | |
| WO02088992A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1384162A1 | European Patent Office (EPO) | A1 | |
| CZ20032918A3This record | Czechia | A3 | |
| KR20040015083A | Republic of Korea | A | |
| HU0304044A2 | Hungary | A2 | |
| HUP0304044A2 | Hungary | A2 | |
| CN1494693A | China | A | |
| JP2004531817A | Japan | A | |
| PL364641A1 | Poland | A1 | |
| HU0304044A3 | Hungary | A3 | |
| HUP0304044A3 | Hungary | A3 | |
| KR100532339B1 | Republic of Korea | B1 | |
| TWI245185B | Taiwan Province of China | B | |
| JP3994059B2 | Japan | B2 | |
| EP1384162A4 | European Patent Office (EPO) | A4 | |
| CN100390776C | China | C | |
| US2008235333A1 | United States of America | A1 | |
| US7433957B2 | United States of America | B2 | |
| US8078754B2 | United States of America | B2 |
Numbers
- Publication, DOCDB
- 20032918
- Publication, EPODOC
- CZ20032918
- Application
- 20032918
- Application, DOCDB
- 20032918
- Application, EPODOC
- CZ20030002918
Titles2
- Czech
- Privatizace přístupu ke skupině v klastrovém počítačovém systému
- English
- Group access privatization in clustered computer system
Classification
- CPC, 5
- G06F9/5061
- G06F17/00
- H04L63/104
- G06F2209/505
- H04L67/1001
- IPC, 7
- G06F9 50
- G06F15 177
- G06F9 54
- G06F21 00
- G06F21 56
- H04L29 06
- H04L29 08
