Storage virtualization apparatus comprising encryption functions
7 claims: 3 independent, 4 dependent
- 1A device connected to a first external storage subsystem, which is an external first storage subsystem, and a second external storage subsystem, which is a second external storage subsystem. A storage virtualization unit that provides the first external logical volume of the first external storage subsystem as its own logical volume to a higher-level device, an encryption processing unit that encrypts data, and the encryption processing unit encrypts data. An encryption key registration unit that registers an encryption key, which is an electronic key used for conversion, in a storage area, a cache area, and an upper interface unit that is an interface to a higher-level device and receives a data write request from the higher-level device. The external interface unit, which is an interface to the external storage subsystem, the cache unit that stores the data received by the upper interface unit and / or the external interface unit in the cache area, and the received write request are specified. A determination unit that first determines whether or not the first external storage subsystem having the first external logical volume has the first encryption function, If the result of the first determination is affirmative, a write request for writing the data to the first external logical volume without having the encryption processing unit encrypt the data on the cache area is requested. By transmitting to the first external storage subsystem through the external interface unit, while the result of the first determination is negative, the data on the cache area is encrypted by the encryption processing unit. An I / O processing unit and the first external storage subsystem that generate encrypted data and transmit a write request for writing the encrypted data to the first external logical volume to the first external storage subsystem through the external interface unit. A migration processing unit that executes a migration process for migrating the data stored in the external logical volume of the second external storage subsystem to the second external logical volume of the second external storage subsystem is provided.At the time of the migration process, the first encryption function acquires an encryption key used for encrypting data from the first external storage subsystem, and the acquired encryption key is obtained by the encryption key registration unit. Register in storage area In the migration process, the determination unit makes a second determination as to whether or not the second external storage subsystem has a second encryption function. The migration processing unit may:(A) if the result of the second determination is affirmative, (a1) if the first external storage subsystem has the first encryption function, the first The data obtained by decrypting the encrypted data stored in the external logical volume of the first external logical volume by the first encryption function is received from the first external storage subsystem, while the first external When the storage subsystem does not have the first encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encryption key of the storage area is received. To decrypt the encrypted data using the above, (a2) transmit the encryption key of the storage area to the second external storage subsystem, and of the first external logical volume. The data obtained by decrypting the encrypted data in (a1) is transmitted to the second external storage subsystem without being encrypted by the encryption processing unit, whereby the second encryption is performed. The decrypted data is encrypted by the encryption function using the transmitted encryption key, and (B) if the result of the second determination is negative, (b1) the first external storage. When the subsystem has the first encryption function, the data obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function is used. Encrypted data received from the first external storage subsystem, while stored in the first external logical volume if the first external storage subsystem does not have the first encryption function. Is received from the first external storage subsystem, and the encryption processing unit is made to decrypt the encrypted data using the encryption key of the storage area, and (b2) of the first external logical volume. The data obtained by decrypting the encrypted data in (b1) is encrypted by the encryption processing unit using the encryption key of the storage area, and the encrypted data obtained by the encryption is used as described above. Second outsideA storage virtualization device that transmits to a unit storage subsystem, and the storage virtualization unit provides the second external logical volume as its own logical volume to a higher-level device after at least the migration process is completed. 外部に存在する第一のストレージサブシステムである第一の外部ストレージサブシステムと外部に存在する第二のストレージサブシステムである第二の外部ストレージサブシステムとに接続された装置であって、 前記第一の外部ストレージサブシステムが有する第一の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化部と、 データを暗号化する暗号処理部と、 前記暗号処理部がデータの暗号化に使用した電子的な鍵である暗号鍵を記憶領域に登録する暗号鍵登録部と、 キャッシュ領域と、 上位装置に対するインタフェースであって、前記上位装置からデータのライト要求を受信する上位インタフェース部と、 外部ストレージサブシステムに対するインタフェースである外部インタフェース部と、 前記上位インタフェース部及び/又は前記外部インタフェース部で受信したデータを前記キャッシュ領域に記憶させるキャッシュ部と、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行う判定部と、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることなく、そのデータを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信し、一方、前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることで暗号データを生成させ、その暗号データを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信するI/O処理部と 前記第一の外部論理ボリュームに記憶されているデータを前記第二の外部ストレージサブシステムが有する第二の外部論理ボリュームに移行する移行処理を実行する移行処理部とを備え、前記移行処理の際、前記第一の暗号化機能は、データの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を前記暗号鍵登録部により前記記憶領域に登録し、 前記判定部は、前記移行処理において、前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 前記移行処理部は、(A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、前記暗号処理部に暗号化させることなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、(B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて前記暗号処理部に暗号化させ、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 前記ストレージ仮想化部は、少なくとも前記移行処理の完了した後、前記第二の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化装置。
- 6The storage virtualization device includes a storage virtualization device, a first external storage subsystem having a first external logical volume, and a second external storage subsystem having a second external logical volume. A storage virtualization unit that provides the first external logical volume as its own logical volume to a higher-level device, an encryption processing unit that encrypts data, and an electronic key used by the encryption processing unit to encrypt data. An encryption key registration unit that registers a certain encryption key in a storage area, a cache area, an interface to a higher-level device, a higher-level interface unit that receives a data write request from the higher-level device, and an interface to an external storage subsystem. It has an external interface unit, a cache unit that stores data received by the upper interface unit and / or the external interface unit in the cache area, and a first external logical volume specified by the received write request. A determination unit that first determines whether or not the first external storage subsystem has the first encryption function, If the result of the first determination is affirmative, a write request for writing the data to the first external logical volume without having the encryption processing unit encrypt the data on the cache area is requested. By transmitting to the first external storage subsystem through the external interface unit, while the result of the first determination is negative, the data on the cache area is encrypted by the encryption processing unit. An I / O processing unit and the first external storage subsystem that generate encrypted data and transmit a write request for writing the encrypted data to the first external logical volume to the first external storage subsystem through the external interface unit. It is equipped with a migration processing unit that executes migration processing to migrate the data stored in the external logical volume ofAt the time of the migration process, the first encryption function acquires an encryption key used for encrypting data from the first external storage subsystem, and the acquired encryption key is obtained by the encryption key registration unit. Register in storage area The determination unit makes a second determination as to whether or not the second external storage subsystem has a second encryption function, and the migration processing unit makes a positive result of the second determination. Control the migration process based on whether it is present or negative The migration processing unit may:(A) if the result of the second determination is affirmative, (a1) if the first external storage subsystem has the first encryption function, the first The data obtained by decrypting the encrypted data stored in the external logical volume of the first external logical volume by the first encryption function is received from the first external storage subsystem, while the first external When the storage subsystem does not have the first encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encryption key of the storage area is received. To decrypt the encrypted data using the above, (a2) transmit the encryption key of the storage area to the second external storage subsystem, and of the first external logical volume. The data obtained by decrypting the encrypted data in (a1) is transmitted to the second external storage subsystem without being encrypted by the encryption processing unit, whereby the second encryption is performed. The decrypted data is encrypted by the encryption function using the transmitted encryption key, and (B) if the result of the second determination is negative, (b1) the first external storage. When the subsystem has the first encryption function, the data obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function is used. Encrypted data received from the first external storage subsystem, while stored in the first external logical volume if the first external storage subsystem does not have the first encryption function. Is received from the first external storage subsystem, and the encryption processing unit is made to decrypt the encrypted data using the encryption key of the storage area, and (b2) of the first external logical volume. The data obtained by decrypting the encrypted data in (b1) is encrypted by the encryption processing unit using the encryption key of the storage area, and the encrypted data obtained by the encryption is used as described above. Second outsideA storage system that transmits to a storage subsystem, and the storage virtualization unit provides the second external logical volume as its own logical volume to a higher-level device after at least the migration process is completed. ストレージ仮想化装置と、 第一の外部論理ボリュームを有する第一の外部ストレージサブシステムと、 第二の外部論理ボリュームを有する第二の外部ストレージサブシステムとを備え、 前記ストレージ仮想化装置が、前記第一の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージ仮想化部と、 データを暗号化する暗号処理部と、 前記暗号処理部がデータの暗号化に使用した電子的な鍵である暗号鍵を記憶領域に登録する暗号鍵登録部と、 キャッシュ領域と、 上位装置に対するインタフェースであって、前記上位装置からデータのライト要求を受信する上位インタフェース部と、 外部ストレージサブシステムに対するインタフェースである外部インタフェース部と、 前記上位インタフェース部及び/又は前記外部インタフェース部で受信したデータを前記キャッシュ領域に記憶させるキャッシュ部と、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行う判定部と、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることなく、そのデータを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信し、一方、前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記暗号処理部に暗号化させることで暗号データを生成させ、その暗号データを前記第一の外部論理ボリュームに書込むことのライト要求を前記外部インタフェース部を通じて前記第一の外部ストレージサブシステムに送信するI/O処理部と 前記第一の外部論理ボリュームに記憶されているデータを第二の外部論理ボリュームに移行する移行処理を実行する移行処理部とを備え、前記移行処理の際、前記第一の暗号化機能は、データの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を前記暗号鍵登録部により前記記憶領域に登録し、 前記判定部は、前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 前記移行処理部は、前記第二の判定の結果が肯定的であるか否定的であるかに基づいて、前記移行処理を制御し、 前記移行処理部は、(A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、前記暗号処理部に暗号化させることなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、(B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化することを前記暗号処理部に実行させ、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて前記暗号処理部に暗号化させ、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 前記ストレージ仮想化部は、少なくとも前記移行処理の完了した後、前記第二の外部論理ボリュームを自分の論理ボリュームとして上位装置に提供するストレージシステム。
- 7Control of storage virtualization devices connected to the first external storage subsystem, which is the first external storage subsystem, and the second external storage subsystem, which is the second external storage subsystem. The first method is to store the data according to the write request received from the host device in the cache area and to the first external storage subsystem having the first external logical volume specified by the received write request. The first determination as to whether or not there is an encryption function is performed, and if the result of the first determination is affirmative, the data on the cache area is encrypted by the encryption function of the storage virtualization device. If the data on the cache area is transmitted from the storage virtualization device to the first external storage subsystem and the result of the first determination is negative, the data on the cache area is used by the encryption key of the storage area. And the encrypted data obtained by the encryption is transmitted to the first external storage subsystem.When executing the migration process of migrating the data stored in the first external logical volume to the second external logical volume,The encryption key used by the first encryption function to encrypt the data is acquired from the first external storage subsystem, and the acquired encryption key is registered. A second determination is made as to whether or not the second external storage subsystem has a second encryption function, and (A) if the result of the second determination is affirmative, (a1) the first determination. When the external storage subsystem of the above has the first encryption function, it is obtained by decrypting the encrypted data stored in the first external logical volume by the first encryption function. Data is received from the first external storage subsystem, while if the first external storage subsystem does not have the first encryption function, it is stored in the first external logical volume. The encrypted data is received from the first external storage subsystem, the encrypted data is decrypted using the encryption key of the storage area, and (a2) the encryption key of the storage area is used by the second external storage subsystem. And the data obtained by decrypting the encrypted data of the first external logical volume in (a1) is transmitted to the second external storage subsystem without encryption. The second encryption function is used to encrypt the decrypted data by using the transmitted encryption key. (B) If the result of the second determination is negative, (b1) If the first external storage subsystem has the first encryption function, it is stored in the first external logical volume. The data obtained by decrypting the encrypted data by the first encryption function is received from the first external storage subsystem, while the first external storage subsystem receives the first. When there is no one encryption function, the encrypted data stored in the first external logical volume is received from the first external storage subsystem, and the encrypted data is received by using the encryption key of the storage area. (B2) The data obtained by decrypting the encrypted data of the first external logical volume in (b1) is encrypted using the encryption key of the storage area, and the encryption is performed. The encrypted data obtained by the above-mentioned second external storage subsystem is transmitted to the second external storage subsystem, and after at least the migration processing of (A) and (B) is completed, the second external logical volume is transferred to the storage virtualization device. A storage control method that is provided to the host device as a logical volume of. 外部に存在する第一のストレージサブシステムである第一の外部ストレージサブシステムと外部に存在する第二のストレージサブシステムである第二の外部ストレージサブシステムとに接続されたストレージ仮想化装置の制御方法であって、 上位装置から受信したライト要求に従うデータをキャッシュ領域に記憶させ、 前記受信したライト要求で指定されている第一の外部論理ボリュームを有する第一の外部ストレージサブシステムに第一の暗号化機能が有るか否かの第一の判定を行い、 前記第一の判定の結果が肯定的であれば、前記キャッシュ領域上のデータを前記ストレージ仮想化装置の暗号化機能で暗号化すること無く前記ストレージ仮想化装置から前記前記第一の外部ストレージサブシステムに送信し、 前記第一の判定の結果が否定的であれば、前記キャッシュ領域上のデータを前記記憶領域の暗号鍵を用いて暗号化し、その暗号化により得られた暗号データを、前記第一の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームに記憶されているデータを第二の外部論理ボリュームに移行する移行処理を実行する際に、前記第一の暗号化機能がそのデータの暗号化に使用した暗号鍵を前記第一の外部ストレージサブシステムから取得し、その取得した暗号鍵を登録し、 前記第二の外部ストレージサブシステムが第二の暗号化機能を有するか否かの第二の判定を行い、 (A)前記第二の判定の結果が肯定的の場合、(a1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化し、(a2)前記記憶領域の暗号鍵を前記第二の外部ストレージサブシステムに送信し、前記第一の外部論理ボリュームの暗号データが前記(a1)において復号化されることにより得られたデータを、暗号化することなく前記第二の外部ストレージサブシステムに送信し、それにより、前記第二の暗号化機能に、前記送信された暗号鍵を用いて、前記復号化されたデータを暗号化させ、 (B)前記第二の判定の結果が否定的の場合、(b1)前記第一の外部ストレージサブシステムに前記第一の暗号化機能が有る場合には、前記第一の外部論理ボリュームに記憶されている暗号データが前記第一の暗号化機能によって復号化されたことにより得られたデータを前記第一の外部ストレージサブシステムから受信し、一方、前記第一の外部ストレージサブシステムに前記第一の暗号化機能が無い場合には、前記第一の外部論理ボリュームに記憶されている暗号データを前記第一の外部ストレージサブシステムから受信し、前記記憶領域の暗号鍵を用いて該暗号データを復号化し、(b2)前記第一の外部論理ボリュームの暗号データが前記(b1)において復号化されることにより得られたデータを、前記記憶領域の暗号鍵を用いて暗号化し、該暗号化により得られた暗号データを、前記第二の外部ストレージサブシステムに送信し、 少なくとも前記(A)及び(B)の移行処理の完了した後、前記第二の外部論理ボリュームを前記ストレージ仮想化装置の論理ボリュームとして上位装置に提供する記憶制御方法。
Independent claims3
176 paragraphs, as filed
The present invention relates to encryption of data stored in a storage subsystem.
For example, in an organization such as a company, a storage subsystem configured separately from a host computer (hereinafter referred to as "host") is used to manage a large amount of data. Such a storage subsystem includes, for example, a large number of storage devices such as a hard disk drive (HDD) and a controller, and the controller can provide a large-capacity storage area to the host.
The storage subsystem stores various important information such as personal information such as an individual's address and name and information on credit status. Therefore, there is a need for a technique for secretly managing important information and preventing unauthorized access.
Encryption techniques may be used to protect the data. By encrypting the data inside the host and sending the encrypted data to the storage subsystem for storage, it is possible to prevent unauthorized use of the encrypted data by a third party.
However, if the data is encrypted inside the host, the data processing load on the host will increase, which will adversely affect the performance of the application program running on the host.
Therefore, for example, Patent Document 1 (Japanese Patent Laid-Open No. 2005-322201) proposes a technique that enables data encryption to be performed inside a storage subsystem.
In addition, as the amount of data handled by organizations such as companies increases, the number of organizations that operate and manage storage systems composed of a plurality of storage subsystems is increasing. Therefore, an increase in the management cost of the storage subsystem is regarded as a problem. In order to suppress the increase in management cost, one or more storage subsystems (hereinafter, the storage subsystem is referred to as "external storage subsystem") are connected to the storage virtualization device, and the storage virtualization device has one or more external storage. There is a technology that virtually provides the storage resources of the subsystem to the host as if they were the storage resources of the storage subsystem. The function by this technique is called a storage virtualization function (or an external connection function), and is disclosed in, for example, Patent Document 2 (Japanese Patent Laid-Open No. 2005-107645).
<patcit num="1"><text>Japanese Patent Application Laid-Open No. 2005-322201</text></patcit><patcit num="2"><text>Japanese Patent Application Laid-Open No. 2005-107645</text></patcit>
<p> When applying the encryption function disclosed in Patent Document 1 in an environment in which one or more external storage subsystems are connected to the storage virtualization device, first, the encryption function is applied to the storage virtualization device. Considered to be natural. However, if the storage virtualization device constantly performs encryption and decryption, the performance of the storage virtualization device may become a bottleneck.</p><p> Therefore, an object of the present invention is to reduce the load on the storage virtualization device having an encryption function.</p><p> Further objections of the present invention will become apparent from the later description.</p>
<p> The storage virtualization device is provided with a determination unit. The determination unit determines whether or not the external storage subsystem having the external logical volume of the write destination specified in the write request received from the host device has the encryption function. If the result of the judgment is negative, that is, if the judgment is that the external storage subsystem does not have the encryption function, the storage virtualization device encrypts the data according to the write request by its own encryption function and then externally. Send the encrypted data to the storage subsystem. However, if the result of the above determination is positive, that is, if the external storage subsystem has an encryption function, the storage virtualization device does not encrypt the data according to the write request by its own encryption function. By sending it to the external storage subsystem as it is, the data is encrypted by the encryption function of the external storage subsystem.</p>
In one embodiment, the storage virtualization unit of the storage virtualization device sets the first external logical volume of the first external storage subsystem, which is the first storage subsystem existing outside, as the storage virtualization device. It is provided to the host device as a logical volume of. The storage virtualization device has an encryption processing unit (that is, an encryption function) that encrypts data, a cache area, and a higher-level interface unit (for example, a communication port or a communication port) that receives a data write request from a higher-level device. An interface circuit), an external interface unit (for example, a communication port or an interface circuit having a communication port) that is an interface to an external storage subsystem, and a cache area for data received by the upper interface unit and / or the external interface unit. It can be provided with a cache unit, a determination unit, and an I / O processing unit to be stored in the data.
The determination unit makes a first determination as to whether or not the first external storage subsystem having the first external logical volume specified in the write request received from the host device has the first encryption function. be able to. Specifically, for example, the correspondence between the logical volume ID specified by the host device and the external logical volume ID, and the encryption indicating whether or not the external storage subsystem having which external logical volume has the encryption function. The management information representing the presence / absence information can be stored in advance in the storage resource of the storage virtualization device. The determination unit identifies the external logical volume ID corresponding to the logical volume ID specified in the received write request from the management information, and has an external storage sub having an external logical volume corresponding to the external logical volume ID. Whether or not the system has an encryption function can also be specified from the management information.
If the result of the first judgment is positive, the I / O processing unit writes the data on the cache area to the first external logical volume without having the encryption processing unit encrypt the data. The write request can be sent to the first external storage subsystem through the external interface section. On the other hand, if the result of the first determination is negative, the I / O processing unit causes the encryption processing unit to encrypt the data on the cache area to generate encrypted data, and the encrypted data is used as the first. A write request to write to an external logical volume can be sent to the first external storage subsystem through the external interface section.
In one embodiment, the storage virtualization device may further include an encryption key registration unit that registers an encryption key, which is an electronic key used by the encryption processing unit to encrypt data, in a storage area. The encryption key may be associated with each logical volume in the storage area, or may be associated with a different unit (for example, a subvolume unit when the logical volume is divided into a plurality of subvolumes). good.
In one embodiment, the storage virtualization device may further include a copy processing unit. This copy processing unit executes a copy process of copying the data stored in the first external logical volume to the second external logical volume when the encryption key stored in the storage area is changed. can do. In this case, the storage virtualization unit can provide the second external logical volume as its own logical volume to the higher-level device in place of or in addition to the first external logical volume, at least after the copy processing is completed. .. In this embodiment, the second external logical volume may exist in the first external storage subsystem or may exist in another external storage subsystem. Further, the copy process is to write the data stored in the first external logical volume to the second external logical volume, and the data to be copied is deleted from the first external logical volume or the data is deleted from the first external logical volume. It doesn't matter whether the data is left. If it is deleted, the copy process can be regarded as a migration process, and if it is left, the copy process can be regarded as a replication process.
In one embodiment, there is a second external storage subsystem that is a second storage subsystem that exists outside the storage virtualization device and has a second external logical volume. In this embodiment, the copy processing unit can execute the above-mentioned copy processing regardless of whether or not the encryption key is changed.
In one embodiment, the determination unit can make a second determination as to whether or not the second external storage subsystem has a second encryption function during the copy process. The copy processing unit can control the copy processing based on whether the result of the second determination is positive or negative.
Specifically, for example, if the result of the second determination is negative, and if the first storage subsystem has the first encryption function, the copy processing unit will be the first external logical volume. The encrypted data is decrypted by the first encryption function of the first storage subsystem, and the decrypted data is encrypted by the encryption processing unit of the storage virtualization device and written to the second external logical volume. It may be crowded. Further, for example, when the result of the second determination is negative, if the first storage subsystem does not have the first encryption function, the copy processing unit uses the encrypted data of the first external logical volume. , As it is, or may be decrypted and further encrypted by the encryption processing unit of the storage virtualization device and written to the second external logical volume.
Further, for example, when the result of the second determination is positive, if the first storage subsystem has the first encryption function, the copy processing unit transfers the encrypted data of the first external logical volume. It may be decrypted by the first encryption function of the first storage subsystem, and the decrypted data may be transmitted as it is to the second external storage subsystem. Further, for example, when the result of the second determination is positive, if the first storage subsystem does not have the first encryption function, the copy processing unit transfers the encrypted data of the first external logical volume. The encryption processing unit of the storage virtualization device may decrypt the data, and the data obtained by the decryption may be transmitted as it is to the second external storage subsystem. In these cases, the transmitted data is encrypted by the second encryption function in the second storage subsystem, and the encrypted data is written to the second external logical volume.
In one embodiment, the copy processing unit uses the encrypted data stored in the first external logical volume as the first encryption when the first external storage subsystem has the first encryption function. The data obtained by being decrypted by the function can be received from the first external storage subsystem. On the other hand, when the first external storage subsystem does not have the first encryption function, the copy processing unit receives the encrypted data stored in the first external logical volume from the first external storage subsystem. Then, the encryption processing unit can be made to decrypt the encrypted data by using the encryption key stored in the storage area.
In one embodiment, the copy processor is obtained by decrypting the encrypted data of the first external logical volume if the second external storage subsystem has a second encryption function. The data can be sent to a second external storage subsystem without being encrypted by the cryptographic processor. On the other hand, when the second external storage subsystem does not have the second encryption function, the copy processing unit encrypts the data obtained by decrypting the encrypted data of the first external logical volume. The processing unit can encrypt the encrypted data, and the encrypted data obtained by the encryption can be transmitted to the second external storage subsystem.
In one embodiment, the copy processing unit does not have the second encryption function in the second external storage subsystem, and the data stored in the first external logical volume is encrypted by the encryption processing unit. If the encrypted data is encrypted data, the encrypted data is read from the first external logical volume, and the encrypted data is decrypted by using the encryption key stored in the storage area, and the decryption is performed. A write request for having the encryption processing unit execute the encryption of the data obtained by the encryption using the encryption key and writing the encrypted data obtained by the encryption to the second external logical volume. It can be transmitted to the second external storage subsystem through the external interface unit.
In one embodiment, the encryption key used for decryption (first encryption key) and the encryption key used for encryption after decryption (second encryption key) may be different. The encryption key registration unit can update the first encryption key stored in the storage area to the second encryption key used for encryption. The change of the encryption key may be performed manually by the administrator, or may be performed automatically by a predetermined algorithm.
In one embodiment, if the data stored in the first external logical volume is encrypted data that is encrypted by the first encryption function, the encryption key registration unit is the first. The encryption key stored in the first external storage subsystem used for the encryption by the encryption function can be acquired, and the acquired encryption key can be registered in the storage area. This encryption key may be obtained directly from the first external storage subsystem, or may be obtained via a predetermined server, management device, or the like.
In one embodiment, the copy processing unit performs the first encryption function for the encrypted data stored in the first external logical volume when the second external storage subsystem does not have the second encryption function. The encrypted data can be read from the first external logical volume as it is without being decrypted by the encryption processing unit, and the encrypted data can be written to the second external logical volume as it is without being encrypted by the encryption processing unit.
In one embodiment, when the copy processing unit does not have the second encryption function in the second external storage subsystem, the encrypted data stored in the first external logical volume is subjected to the first encryption function. The data obtained by decryption is received from the first external storage subsystem through the external interface unit, and the received data is encrypted using an encryption key different from the encryption key registered in the storage area. This can be performed by the encryption processing unit, and the encrypted data obtained by the encryption can be written to the second external logical volume. The encryption key registration unit can update the encryption key stored in the storage area to the other encryption key.
In one embodiment, the upper interface unit designates the second external logical volume after the encrypted data stored in the first external logical volume is copied to the second external logical volume by the copy process. Can receive the read request. As the first determination, the determination unit determines whether or not the second external storage subsystem having the second external logical volume specified in the received read request has the second encryption function. It can be carried out. Read the I / O processor to read the encrypted data from the second external logical volume in response to the received read request if the second external storage subsystem does not have the second encryption function. The request is sent to the second external storage subsystem, and in response to the sent read request, the external interface unit receives the encrypted data read from the second external logical volume, and the cache unit receives the encrypted data. Is stored in the cache area, and then the encryption processing unit executes decryption of the encrypted data on the cache area using the encryption key registered in the storage area, and the data obtained by the decryption is used as described above. It can be transmitted to the host device through the host interface section.
In one embodiment, the upper interface unit writes to the second external logical volume after the encrypted data stored in the first external logical volume is copied to the second external logical volume by copy processing. Can receive requests. As the first determination, the determination unit determines whether or not the second external storage subsystem having the second external logical volume specified in the received write request has the second encryption function. be able to. If the result of the first judgment is negative, the I / O processing unit causes the encryption processing unit to encrypt the data on the cache area using the encryption key registered in the storage area. A write request for writing the encrypted data obtained by the encryption to the second external logical volume can be transmitted to the second external storage subsystem through the external interface unit.
In one embodiment, the encrypted data of the first external logical volume may be written to the second external logical volume as it is without going through the storage virtualization device.
In one embodiment, the storage virtualization device may further include an encryption key changing unit that periodically or indefinitely changes the encryption key stored in the storage area.
In one embodiment, the host interface unit can receive a data read request from the host device. The determination unit can make the first determination as to whether or not the first external storage subsystem having the first external logical volume specified in the received read request has the first encryption function. .. In response to the read request, the I / O processing unit sends a read request to read data from the first external logical volume to the first external storage subsystem, and the external interface unit sends the first external storage. After receiving data from the subsystem and storing the data in the cache area, if the result of the first determination described above is affirmative, the data on the cache area is directly transmitted to the upper device through the upper interface part. Can be sent. On the other hand, if the result of the first determination is negative, the I / O processing unit causes the encryption processing unit to decrypt the encrypted data on the cache area, and the data obtained by the decryption is used as the upper interface unit. It can be transmitted to the host device through.
In one embodiment, the host device can be a second external storage subsystem. Further, the storage virtualization device may be a storage subsystem having a plurality of logical volumes formed based on a plurality of physical storage devices (for example, HDD), or may be a switch device.
In one embodiment, when the copy process is executed, the encryption key registration unit of the storage virtualization device is transferred from the first external storage subsystem, which is the copy source (for example, the migration source), to the first copy source. If the encryption key corresponding to the external logical volume of is acquired and the second external storage subsystem that is the copy destination (for example, migration destination) has the second encryption function, the acquired encryption key is used as the second. Can be sent to the external storage subsystem of. The second external storage subsystem can manage the encryption key in a memory or the like in association with the second external logical volume which is the copy destination. Therefore, for example, when the second external storage subsystem receives the I / O request specifying the second external logical volume, the data subject to the I / O request is encrypted by the second encryption. Depending on the function, it can be encrypted or decrypted with the encryption key from the storage virtualization device stored in the memory or the like. If the second external storage subsystem does not have a second encryption function, the encryption processing unit of the storage virtualization device uses the encryption key obtained from the first external storage subsystem that is the copy source. Therefore, it is possible to encrypt the data written in the second external logical volume and decrypt the data read from the second external logical volume.
Each of the above-mentioned parts (for example, storage virtualization part, each interface part, encryption processing part, I / O processing part, copy processing part, encryption key registration part, encryption key change part) is a hardware, a computer program, or a combination thereof. It can be constructed by (for example, a part is realized by a computer program and the rest is realized by hardware). The computer program is loaded into a predetermined processor and executed. Further, when information processing is performed by reading a computer program into a processor, a storage area existing on a hardware resource such as a memory may be used as appropriate. Further, the computer program may be installed in the computer from a recording medium such as a CD-ROM, or may be downloaded to the computer via a communication network.
Hereinafter, some embodiments of the present invention will be described in detail with reference to the drawings.
<First embodiment>.
FIG. 1 shows a physical configuration example of a computer system according to the first embodiment of the present invention.
Multiple FCs (Fibre) A SAN (Storage Area Network) is constructed by Channel) switches 5 and 5 ́. A plurality of (or one) host computer (hereinafter, host) 4 and a host adapter 11 of the storage subsystem 1 are connected to the FC switch 5 by a Fiber Channel cable, and the host 4 is connected to the storage subsystem 1. Data I / O requests (eg read and write requests) can be sent. In Fig. 1, FC switch 5 and FC switch 5 ́ are connected, but this connection is not necessary. In addition, the external adapter 12 of the storage subsystem 1 and the external storage subsystems 2 and 2'are connected to the FC switch 5 ́ with a Fiber Channel cable, and the storage subsystem 1 is externally stored via the external adapter 12. Can communicate with subsystems 2, 2'.
The storage subsystem 1 can be, for example, a RAID (Redundant Arrays of Independent (or Inexpensive) Disks) system including a large number of HDDs 16 arranged in an array. However, the present invention is not limited to this, and the storage subsystem 1 can also be configured as a switch constituting a communication network, for example, a highly functional intelligent fiber channel switch. Further, for example, the functions of CHA11 and 12, which will be described later in the storage subsystem 1, the disk adapter 13, and the internal switch 15 are mounted on the FC switch 5, whereby the storage sub can be obtained by combining the FC switch 5 and a plurality of HDDs 16. System 1 may be realized.
Storage subsystem 1 has a storage virtualization function that virtually provides the storage resources of storage subsystems (hereinafter referred to as external storage subsystems) 2 and 2 ́ that exist outside of itself to host 4 as its own storage resources. doing. The storage subsystem 1 includes, for example, CHA11, 12, a disk adapter 13, a cache / control memory 14, and an internal switch 15 as controllers, and access to HDD 16 is controlled by the controller.
CHA11,12 are one or more I / Fs (eg, a communication port or a communication control circuit with a communication port) that are communicably connected to an external device (eg, a host or other storage subsystem) 113,123. And performs data communication with an external device. In the present embodiment, CHA 11 is referred to as a "host adapter" because it is an adapter that communicates with the host computer 14. CHA12 is called an "external adapter" because it is an external storage subsystem 2. The host adapter 11 and the external adapter 12 are configured as a microcomputer system (for example, a circuit board) provided with CPUs 111, 121, memories 112, 122, and the like. The host adapter 11 and the external adapter 12 may be integrated.
The I / F 123 of the external adapter 12 is provided with an encryption processing unit 124 that encrypts and decrypts the data input to the external adapter 12. The encryption processing unit 124, for example, encrypts the data input from the inside of the storage subsystem 1 (for example, the internal switch 15), or decrypts the data input from the outside of the storage subsystem 1 (for example, the FC switch 5 ́). It is configured to be converted.
In this embodiment, the host adapter 11 for communicating with the host computer and the external adapter 12 for communicating with the external storage subsystems 2 and 2'are described as different hardware, but the host adapter 11 The external adapter 12 may have the same hardware configuration, for example, the encryption processing unit may be arranged behind the I / F 113 of the host adapter 11. At that time, the host adapter 11 is set so as not to encrypt / decrypt the data input / output to / from the host adapter 11 (for example, a predetermined flag is set in the memory 112 or the encryption processing unit). Therefore, it is possible to prevent the encryption processing unit of the host adapter 11 from encrypting and decrypting the data input / output to / from the host adapter 11.
The disk adapter (DKA) 13 has a communication port (for example, FC port) 133 for connecting to each HDD 16, and can communicate with the HDD 16 via the communication port 133. The DKA13 is configured as a microcomputer system (for example, a circuit board) equipped with a CPU 131, a memory 132, and the like. The DKA22 can write the data written in the cache area of the cache / control memory 14 from CHA11 and 12 to the HDD16, and can write the data read from the HDD16 to the cache area. Further, like the external adapter 12, there is an encryption processing unit 134 between the port 133 and the internal switch 15, which encrypts the data written from the cache area to the HDD 16 or decrypts the data read from the HDD 16 to the cache area. Take on the role of
The cache / control memory 14 is, for example, a volatile or non-volatile memory. The cache / control memory 14 is a memory having a cache area and a control area. It may be separated into a memory having a cache area and a memory having a control area. Data received from an external device (for example, host 4 or external storage subsystem 2) and data read from HDD 16 are temporarily stored in the cache area. Information related to control in the storage subsystem 1 (hereinafter referred to as control information) is stored in the control area. The control information includes various tables described later.
The internal switch 15 is, for example, a crossbar switch that connects CHA11, 12, DKA13, and cache / control memory 14 to each other. Instead of the internal switch 15, another type of connection such as a bus may be adopted.
For example, a management terminal 6 is connected to the internal switch 15. The management terminal 6 is a calculator for managing the storage subsystem 1. The management terminal 6 can store various tables, which will be described later, in the control area of the cache / control memory 14, for example. The function performed by the management terminal 6 may be installed in the host 4. That is, various tables described later may be stored from the host 4.
In addition, the management terminals 7 and 7'are computers for managing the external storage subsystems 2 and 2', respectively, but the management terminal 6 is not limited to this, and for example, the management terminal 6 also manages the external storage subsystems 2 and 2'. You may. Management terminals 6, 7, and 7'are interconnected by LAN (or another type of communication network) 8.
The above is the description of the physical configuration example of the computer system according to the first embodiment of the present invention. The above description is an example, and it is not necessary to limit the configuration to this computer system. For example, the controller may have a simpler configuration, for example, a configuration in which a CPU and a memory are provided on one circuit board.
FIG. 2 shows a logical configuration example of the computer system according to the first embodiment of the present invention.
In the host adapter 11, for example, the command processing unit 901 is stored in the memory 112 as a computer program executed by the CPU 111. In the DKA13, for example, a disk I / O processing unit 902, a copy processing unit 903, and a logical-physical conversion unit 904 are stored in the memory 122, for example, as computer programs executed by the CPU 131. In the external adapter 12, for example, the external I / O processing unit 902'and the copy processing unit 903' are stored in the memory 132, for example, as computer programs executed by the CPU 121. Hereinafter, the explanation that describes the computer program as the subject is described as meaning that the processing is actually performed by the CPU that executes the computer program. The operation of each computer program will be described in detail later.
FIG. 3 is a diagram showing an example of the relationship between a plurality of HDD 16s and a logical volume.
A RAID group is composed of multiple HDDs 16-1, 16-2, 16-3 and 16-4 (for example, 4 units). In this example, three data are stored in three HDD 16, and the parity data generated based on the three data is stored in the other HDD 16.
In this embodiment, the storage space (a set of storage spaces of each HDD 16) provided by this RAID group is abbreviated as "VDEV" for Virtual Device. Each of the plurality of VDEV portions obtained by dividing the VDEV is a logical volume referred to in the present embodiment. The logical volume is specified by host 4 and is also identified inside storage subsystem 1. Therefore, hereinafter, the logical volume specified by the host 4 may be referred to as "LU" (Logical Unit), and the logical volume identified inside the storage subsystem 1 may be referred to as "LDEV" (Logical Device). In the example of this figure, three LDEVs are formed from one VDEV, but the number of LDEVs may be larger or smaller (for example, one LDEV may be one VDEV).
In the present embodiment, the data write destination and read source can be set to the external storage subsystem 2 instead of the HDD 16 by the storage virtualization function described above. As a technique related to the storage virtualization function, for example, the technique disclosed in Japanese Patent Application Laid-Open No. 2005-107645 (US Application No. 10/769805, US Application No. 11/471556) can be incorporated.
Hereinafter, various tables included in the control information stored in the cache / control memory 14 will be described with reference to FIGS. 4 to 8.
FIG. 4 shows a configuration example of the RAID configuration table.
The RAID configuration table 400 is a table for managing the RAID configuration of each VDEV. Specifically, for example, in this table 400, a column 401 in which the VDEV identification number is written, a column 402 in which the HDD identification number is written, a column 403 in which the RAID level is written, and a column in which the stripe size is written. There is 404. That is, in this table 400, the identification number of the VDEV, the identification number of the plurality of HDDs constituting the VDEV, the RAID level of the VDEV, and the stripe size are written for each VDEV.
FIG. 5 shows a configuration example of the VDEV configuration table.
The VDEV configuration table 500 is a table for managing the VDEV configuration. Specifically, for example, in this table 500, a column 501 in which the identification number of the VDEV is written, a column 502 in which the identification number of the LDEV is written, and a column 503 in which the start address of the logical address range in the VDEV of the LDEV is written. And column 504 where the end address of the logical address range in VDEV of LDEV is written. That is, in this table 500, what identification number LDEV exists in which logical address range of which VDEV is written.
FIG. 6 shows a configuration example of the LU configuration table.
The LU configuration table 600 is a table for managing the configuration of each LU. Specifically, for example, in this table 600, a column 601 in which the identification number of the LDEV is written, a column 602 in which the WWN (World Wide Name) is written, and a column 603 in which the LUN (Logical Unit Number) is written, There is a column 604 in which the storage capacity of the LDEV is written and a column 605 in which the encryption key is written. That is, in this table 600, the identification number of the LDEV, the WWN and LUN associated with the LDEV, the storage capacity of the LDEV, and the encryption key associated with the LDEV are displayed for each LU. Written. When the data in each LDEV is encrypted, the encryption key is recorded in column 605, and the data in the LDEV is not encrypted. That is, if it is not subject to encryption, the encryption key is not recorded in column 605 (0 is recorded).
In this embodiment, as described above, the logical volume specified by the host 4 is referred to as "LU". Specifically, for example, the logical volume to which the WWN and LUN in the Fiber Channel protocol are associated is called LU. Say. In addition, for example, in the mainframe, columns 602 and 603 of WWN and LUN may not be provided.
FIG. 7 shows a configuration example of the port configuration table.
The port configuration table 5400 is a table for managing the configuration of the communication ports of each I / F 113 and 123. Specifically, for example, in this table 5400, there is a column 5401 in which the identifier of the communication port (for example, WWN) is written, and a column 5402 in which the status of the communication port is written. The status "TARGET" represents the communication port on the I / F 113 of the host adapter 11. That is, the port is used to accept I / O requests from the host. The status "EXTERNAL" represents the communication port on the I / F 123 of the external adapter 12. That is, the port is used by the storage virtualization function to issue an I / O request to a storage subsystem such as the external storage subsystem 2. A plurality of I / F 113 and 123 may exist in one adapter 11 and 12, and the statuses of a plurality of ports in one adapter 11 and 12 may be different from each other. Further, a plurality of communication ports may exist in one I / F 113 and 123.
If the I / F 113 of the host adapter 11 has an encryption processing unit, and the status of the communication port of the I / F 113 is "TARGET", the encryption processing unit encrypts and decrypts. It is possible to prevent the conversion from being executed. For example, by setting a flag in the storage area of the encryption processing unit to prohibit execution of encryption and decryption, it is possible to prevent the encryption processing unit from executing encryption and decryption. it can.
FIG. 8 shows a configuration example of the EDEV information table.
Here, EDEV is an abbreviation for External Device, and is an external storage subsystem 2. A storage space provided by one or more HDDs present in. With the storage virtualization function, the storage subsystem 1 acts as if it were a host computer, and performs read / write processing on the storage space provided by the external storage subsystems 2 and 2'. In the present embodiment, the storage subsystem 1 and the external storage subsystems 2 and 2'communicate according to the SCSI-FCP protocol (a protocol that regulates the flow of SCSI commands on the Fiber Channel protocol), so that the storage subsystem 1 is Fiber the storage area of the external storage subsystem 2 or 2' Recognize and access as an LU uniquely determined by WWN and LUN in the Channel protocol. Therefore, the EDEV corresponds to the LU existing in the external storage subsystems 2 and 2'. Then, in the storage subsystem 1, each EDEV is treated as the same as one LDEV. That is, in the storage subsystem 1, the EDEV is not divided and treated as a plurality of LDEVs. This point is different from VDEV consisting of one or more HDD16s, but by assigning WWN and LUN to this one LDEV consisting of EDEVs, it can be accessed from host 4. The host cannot see the difference between the LDEV consisting of HDD 16 and the LDEV consisting of external storage subsystems 2 or 2'. As a modification, like the VDEV composed of HDD16, the EDEV of the external storage subsystem 2 or 2'is divided into a plurality of continuous areas and handled so that multiple LDEVs exist in one EDEV. Although it is possible, in the following description, it is assumed that one EDEV operates as one LDEV.
The EDEV information table 250 is a table for managing information about each EDEV, and one row represents the information of one EDEV. Specifically, for example, in this table 250, a column 251 in which the identification number of the EDEV is written, a WWN assigned to the EDEV (WWN assigned to the port of the external storage subsystem 2 or 2'), and There are columns 252 and 253 where the LUNs are written, respectively. Column 254 LDEV contains the LDEV number corresponding to the EDEV. Also, column 255 Cipher contains a value of 0 to 1. Column 255 When the value of Cipher is 1, it means that the EDEV of the relevant row is encrypted / decrypted by the encryption function of the external storage subsystems 2 and 2', and when it is 0, the relevant column. The LU specified by 252,253 is not encrypted or decrypted by the external storage subsystem 2 or 2'. That is, if the external storage subsystems 2 and 2'do not have encryption, the value in column 255 will be 0. The value in column 255 is set by the user manually inputting it via the management terminal 6, and the storage subsystem 1 via the I / F 123 or via the management terminal management terminals 6, 7, 7'. There may be a form in which the value is automatically set by inquiring the external storage subsystems 2 and 2'whether or not the external storage subsystems 2 and 2'have an encryption function. Note that the external storage subsystems 2 and 2'have an encryption function in the controller (for example, at least one of CHA and DKA) and / or the HDD of the external storage subsystems 2 and 2'. It is provided with a cryptographic processing unit similar to the above.
The above is the description of various tables. Hereinafter, the flow of various processes performed in the present embodiment will be described.
FIG. 9 shows the flow of processing for making the LDEV of the storage subsystem 1 available from the host 4. Specifically, it is a process of assigning WWN and LUN to the LDEV so that the LDEV can be recognized and accessed from the host 4. From now on, this process will be referred to as LU creation. The process of FIG. 9 starts from the state in which the LDEV has already been created. That is, before starting the process of FIG. 9, for HDD16 in the storage subsystem 1, RAID is formed and VDEV is created from HDD16, and VDEV is further divided to create a plurality of LDEVs, and the VDEV configuration table 500 is created. The process of registering the contents in is completed, and for the external storage subsystem, the LU in the external storage subsystems 2 and 2'is recognized as an EDEV by the storage subsystem 1, and the EDEV information is recognized as an LDEV. It is assumed that the process of registering in the table has been completed.
In step 10001, the user identifies one of the unused LDEVs, that is, one of the LDEVs to which WWN and LUN are not assigned, via the management terminal 6. Subsequently, the user operates the management terminal 6 to specify the WWN and LUN to be assigned to the LDEV (step 10002).
In step 10002, the WWN specification does not directly specify the WWN, and generally the WWN is assigned to the host I / F such as I / F 113 in advance, so the I used when the host 4 accesses it. By specifying / F 113 from the GUI on the management terminal, the same thing as specifying the WWN can be achieved.
Following the processing of steps 10001 and 10002, in step 10003, the storage subsystem 1 creates an entry for the LDEV in the LU configuration table 600, and the LDEV number (column 601), WWN (column 602), and LUN (column 603). ), Enter the value of capacity (column 604).
In step 10004, the user selects whether to encrypt the data in the LDEV specified in steps 10001 and 10002. This selection is made via management terminal 6. If it is encrypted, the process proceeds to step 10005, and if it is not encrypted, this process ends.
In step 10005, storage subsystem 1 is either an LDEV whose specified LDEV consists of HDD 16 in storage subsystem 1 (ie, an internal LDEV consisting of part of a VDEV), or an external storage subsystem 2 or Determine if it is an LDEV consisting of 2'volumes (that is, an external LDEV corresponding to EDEV). If it is an external LDEV corresponding to EDEV, the process proceeds to step 10006, and if it is an internal LDEV, the process proceeds to step 10011. Hereinafter, the designated LDEV may be referred to as "the LDEV".
In step 10011, storage subsystem 1 generates an encryption key to use when encrypting the LDEV. The encryption key can be automatically generated by using a random number algorithm or the like, or can be specified by the user via the management terminal 6. When step 10011 is completed, the process proceeds to step 10009, and the storage subsystem 1 registers the encryption key generated in step 10011 in the row corresponding to the LDEV in the LU configuration table 600, and the LU creation process ends.
In step 10006, the storage subsystem 1 determines whether or not the external storage subsystem having the EDEV (external LDEV) has an encryption function. This determination is realized by referring to column 255 (Cipher) of the EDEV information table. If the encryption function is provided, the process proceeds to step 10007, and if the encryption function is not provided, the process proceeds to step 10011.
In step 10007, the storage subsystem 1 instructs the external storage subsystem 2 or 2 ́ having the EDEV (external LDEV) to set the EDEV as an encrypted volume. This instruction may be instructed from the management terminal 6 via the management terminals 7, 7', or may be instructed directly to the external storage subsystems 2, 2'via the I / F 123 of the external adapter 12.
In step 10008, the storage subsystem 1 obtains the encryption key used to encrypt the EDEV (that is, the EDEV specified in step 1005) from the external storage subsystems 2, 2'. The encryption key acquired in step 10009 is recorded in the LU configuration table 600, and the LU creation process ends.
If the external storage subsystem 2 to 2'with the EDEV has an encryption function, the encryption process itself is performed by the external storage subsystems 2 to 2'in this embodiment, so that the encryption key in step 10008 Acquisition is not always necessary here. However, since the encryption key corresponding to EDEV may be required for the data migration process described later, in step 10008, the encryption key is acquired and stored in the LU configuration table 600. As a modification, when step 10008 is skipped and the encryption key is not acquired at this point, and the encryption key is required for data migration processing described later, storage subsystem 1 to external storage subsystem 2 or 2 There is also a method of issuing an encryption key acquisition request to'.
FIG. 10 shows the processing flow of the command processing unit 901 when the storage subsystem 1 receives an I / O (read or write) request from the host 4.
When accessing the LU, the host 4 makes an I / O request to the storage subsystem 1 that specifies the WWN and LUN assigned to the LU and the address (LBA: Logical Block Address) to be read or written. Issuance. In response to receiving the I / O request, the command processing unit 901 refers to the LU configuration table 600 and determines the LDEV identification number (LDEV number) corresponding to the LUN and WWN (step 1001). Subsequently, the command processing unit 901 determines whether or not the I / O request from the host 4 is a write request (step 1002). If it is a write request, it goes to step 1003, otherwise it goes to step 1005 (read request).
In step 1003, the command processing unit 901 stores the write data (data to be written according to the I / O request) in the unused area of the cache area of the cache / control memory 14, and in step 1004, the command processing unit 901 informs the host 4. Notify that the write process is completed. The process of step 1004 may be performed after this, for example, after step 1005. At the time of step 1004, the data writing to HDD 16 or the external storage subsystems 2 and 2'has not been completed, but when the write data is stored in the cache area, the host 4 is notified of the completion of processing. Therefore, the response time of the write process can be increased.
In step 1005, the command processing unit 901 performs read or write processing on the LDEV to which the LDEV number determined in step 1001 is assigned. The process of step 1005 will be described in detail in FIG. 11 et seq.
In step 1006, the command processing unit 901 determines whether the received I / O request is a read request. When the request is a read request, the read data (data to be read according to the read request) from the HDD 16 or from the external storage subsystems 2 and 2'is stored in the cache area by the process of step 1005 described above. Therefore, the command processing unit 901 returns the read data on the cache area to the host 4 (step 1007). If it is determined in step 1006 that the request is not a read request, this process ends.
FIG. 11 shows the flow of I / O processing for the LDEV executed by the command processing unit 901, that is, the details of the processing in step 1005 of FIG.
In this process, the write data on the cache area is transferred to the HDD 16 or the external storage subsystem 2, 2'in the case of the write process, and from the HDD 16 or the external storage subsystem 2, 2'in the case of the read process. This is a process in which read data is transferred to the cache area. This process may be executed by an I / O request from host 4 or may be executed in a process such as data migration process described later.
In step 1101, the command processing unit 901 refers to the VDEV configuration table 500 and the EDEV configuration table 650, and identifies whether the specified LDEV is an internal LDEV or an external LDEV. If it is an internal LDEV, the process proceeds to step 1103, and the command processing unit 901 calls the disk I / O processing unit 902 executed by the disk adapter 13 to execute the subsequent processing. In the case of the external LDEV, the process proceeds to step 1102, and the command processing unit 901 calls the external I / O processing unit 902'to execute the I / O processing to the external storage subsystems 2 and 2'. The processes of steps 1102 and 1103 are detailed in FIGS. 16, 12 to 13, respectively.
12 and 13 show an example of the flow of internal LDEV I / O processing, respectively. FIG. 12 shows an example when the internal LDEV is included in the VDEV configured with RAID-5, and FIG. 13 shows the case where the internal LDEV is included in the VDEV configured with RAID-1. An example is shown.
In the explanation of FIG. 12, the internal LDEV is referred to as "target internal LDEV", each HDD belonging to the VDEV is referred to as "target HDD", and is specified by the LBA specified in the I / O request from host 4. The address on the HDD to which the volume area is associated is called the "target physical address".
In step 1201, the LBA specified in the I / O request from host 4 is translated to the target physical address. Specifically, for example, the command processing unit 901 issues an I / O request including the LBA specified in the I / O request from the host 4 to the DKA13, and the disk I / O processing unit 902 in the DKA13. However, it receives the I / O request. The I / O request may be written in the control area of the cache / control memory 14, or may be sent to the DKA 13 via the internal switch 15. The DKA13 that receives the I / O request is the DKA13 connected to each target HDD16. The disk I / O processing unit 902 of the DKA 13 converts the LBA in the received I / O request into the target physical address.
In step 1202, the disk I / O processing unit 902 determines whether the received I / O request is a write request or a read request. If it is a write request, the process proceeds to step 1203, and if it is a read request, the process proceeds to step 1206. It should be noted that this step 1202 may be completed before the end of step 1201.
In step 1203, the disk I / O processing unit 902 sets the write target data (new data) to the target internal LDEV placed on the cache area, and the data and parity currently written in the target LDEV corresponding to the new data. Create a new parity using (old data and old parity).
In step 1204, the disk I / O processing unit 902 writes new data and new parity by transmitting a write request for new data and new parity that specifies the target physical address to each target HDD 16. This process will be described in detail in FIG.
In step 1211, the disk I / O processing unit 902 sends a read request specifying the target physical address to each target HDD 16. As a result, the ciphertext is converted into plaintext from each target HDD16, read, and stored in the cache area. Details of this process are illustrated in FIG.
Next, FIG. 13 describes the flow of I / O processing when the internal LDEV is included in the VDEV of RAID1. The only difference from FIG. 12 is that steps 1203 and 1204 in FIG. 12 have been changed to steps 1203'and 1204' in FIG. In step 1203', instead of creating parity, a mirror copy of the data to be written is created and stored in the cache area. In step 1204', the data to be written and its mirror copy are transmitted to each HDD 16. Since the mirror copy is a duplicate of the original write data and the data content does not change, the processing of step 1203'is not essential, and the HDD16 that stores the write data in step 1204'without making a mirror copy in step 1203'. The same processing can be realized by transmitting the write target data stored in the cache area to both the HDD 16 and the HDD 16 that stores the mirror copy.
FIG. 14 shows an example of data writing processing performed by the disk I / O processing unit 902 on the HDD 16.
In step 2001, the disk I / O processing unit 902 reversely converts the target physical address specified in the write request to the write target LDEV and its address, and the write target LDEV calculated by the reverse conversion is encrypted. Whether or not it is a target is determined by referring to the LU configuration table 600. If the write target LDEV is the encryption target, proceed to step 2002, and if it is not the encryption range, proceed to step 2003.
In step 2002, the disk I / O processing unit 902 passes the encryption key corresponding to the write target LDEV to the encryption processing unit 134, and instructs the encryption processing. By this process, in the data transfer process to the HDD 16 carried out in the next step 2003, the transferred data is encrypted by the encryption processing unit 134.
In step 2003, the disk I / O processing unit 902 transfers data from the cache area to each target HDD 16. If the encryption process is instructed in step 2002, the transferred data is encrypted by the encryption processing unit and written to the HDD 16 in the process of data transfer.
FIG. 15 shows an example of data reading processing from HDD 16 by the disk I / O processing unit 902.
In step 2101, as in step 2001, the disk I / O processing unit 902 identifies the target LDEV by performing reverse conversion processing to determine which LDEV the target physical address (LBA) specified in the read request corresponds to. Then, it is determined by referring to the LU configuration table whether or not the target LDEV is the encryption target. If the target LDEV is an encryption target, proceed to step 2102, and if it is not an encryption target, proceed to step 2103.
In step 2102, a process similar to that of step 2002 is performed. Specifically, the disk I / O processing unit 902 passes the encryption key corresponding to the read target LDEV to the encryption processing unit 134, and instructs the decryption process. By this process, in the data transfer process from HDD 16 to the cache area performed in the next step 2103, the transfer data is decrypted by the encryption processing unit 134.
In step 2103, the disk I / O processing unit 902 reads data from the target HDD 16. If the decryption process is instructed in step 2102, the transferred data is decrypted by the encryption processing unit 134 and stored in the cache area in the process of data transfer.
FIG. 16 shows an example of the flow of external LDEV I / O processing. In the explanation of FIG. 16, the external LDEV to be accessed is referred to as "target external LDEV", the EDEV including the target external LDEV is referred to as "target EDEV", and the LBA specified in the I / O request from host 4 is used. The address in the target EDEV calculated from is called the "target EDEV address".
In step 1301, the LBA specified in the I / O request from host 4 is translated to the target EDEV address. Specifically, for example, the command processing unit 901 makes an I / O request to the external storage subsystem 2 as a target EDEV address based on the LUN, WWN, and LBA specified in the I / O request from the host 4. Find the LUN, WWN, and LBA specified in. This address translation can be performed, for example, by the method disclosed in Japanese Patent Application Laid-Open No. 2005-107645 (US Application No. 10/769805, US Application No. 11/471556).
In step 1302, the external I / O processing unit 902'determines whether the received I / O request is a write request or a read request. If it is a write request, the process proceeds to step 1303, and if it is a read request, the process proceeds to step 1311.
In step 1303, the external I / O processing unit 902'checks the value of column 605 corresponding to the target LDEV in the LU configuration table 600 to determine whether the target external LDEV is the encryption target. If it is an encryption target, the process proceeds to step 1304, and if not, the process proceeds to step 1306.
In step 1304, the external I / O processing unit 902'determines whether or not the external storage subsystems 2 and 2'where the target external LDEV exists have an encryption function by referring to the EDEV information table 250. To do. If there is an encryption function, the encryption process is performed in the external storage subsystem 2 or 2', so the encryption process in the storage subsystem 1 is not performed. Therefore, the process proceeds to step 1306. If there is no encryption function, proceed to step 1305.
In step 1305, the external I / O processing unit 902'identifies the encryption key corresponding to the target external LDEV from the LU configuration table 600, and notifies the encryption processing unit 124 of the specified encryption key. As a result, in the process of transferring the write data to the external storage subsystems 2 to 2'in step 1306, the plaintext (the write data to be transferred) is encrypted in the encryption processing unit 124.
In step 1306, the plaintext (write data) stored in the cache area is converted into a ciphertext by the ciphertext processing unit 124 in the process of being transferred to the external storage subsystem 2, and the ciphertext is converted into a ciphertext by the external I / O processing unit. By 902', it is stored in the external storage subsystem 2 or 2 ́ having the target external LDEV.
In step 1311, as in step 1303, it is determined whether the target external LDEV is the encryption target. If it is an encryption target, the process proceeds to step 1312, and if it is not an encryption target, the process proceeds to step 1314.
In step 1312, it is determined in the same process as in step 1304 whether the external storage subsystem 2 or 2'where the target external LDEV exists has an encryption function. If there is an encryption function, the process proceeds to step 1314, and if there is no encryption function, the process proceeds to step 1313.
Step 1313 is the same process as in step 1305, and the encryption key is set in the encryption processing unit 124. At step 1314, a data read from external storage subsystem 2 or 2'is performed. Specifically, for example, the external I / O processing unit 902 ́ issues a read request to the external storage subsystem 2 together with the target EDEV address. In response to the read request, the I / F 123 of the external adapter 12 receives the ciphertext from the external storage subsystem 2, and the ciphertext is stored in the cache area. When the encryption key is set in step 1313 and the decryption should be performed, the encryption processing unit 124 executes the decryption using the above-set encryption key in the process of being stored in the cache area. , Plaintext is stored in the cache area.
Next, the volume transfer and key change processing in the present embodiment will be described with reference to FIGS. 17 to 20.
The volume migration process is used, for example, when changing the data position due to a change in the usage and / or frequency of use of the data or a replacement of the storage subsystem. For example, when data is transferred to the external LDEV of the external storage subsystem 2 or 2'or the external storage subsystem 2 is discarded due to the decrease in the frequency of use of the data in the internal LDEV composed of HDD16. In some cases, the data that was previously in the external LDEV in the external storage subsystem 2 may be moved to the external storage subsystem 2'or HDD16.
Further, in the present embodiment, in order to improve security, a process of changing the encryption key periodically or irregularly is executed. This process is referred to as "key change process" in the description of this embodiment. When the key change process is executed, the ciphertext is once converted to plaintext, re-encrypted using an encryption key different from the previous encryption key, and the re-encrypted result (ciphertext) is transferred to another LDEV. Is executed. The key change process may be performed at the same time as the volume transfer, but in the description of the present embodiment, the volume transfer and the key change will be described separately.
An outline of the migration / key change processing, which is a series of processing including the volume migration processing and the key change processing, will be described with reference to FIG.
In the migration / key change process, the user specifies the migration source LDEV and the migration destination LDEV in the storage subsystem 1 via the management terminal 6 and executes the migration process. The migration source LDEV may be in the form of specifying the LDEV number, or may be in the form of specifying the WWN and LUN assigned to the migration source LDEV. For the migration destination LDEV, specify the LDEV number to which you want to migrate the data. Alternatively, the management terminal 6 or the storage subsystem 1 may automatically select an LDEV that is not currently in use. In addition to the form in which the user gives instructions via the management terminal 6, the migration instruction can also be executed via the management software of the storage subsystem 1 if the management software of the storage subsystem 1 is installed on the host 4. You can. There is also a form of periodically migrating data or performing key change processing, in which case the user simply specifies the data migration or key change cycle (6 months, etc.) via the management terminal 6. Then, the subsequent processing may be automatically executed in the storage subsystem 1.
The migration / key change process is mainly executed by the copy processing unit 903 or 903'of the storage subsystem 1. Hereinafter, the processing performed by the copy processing unit 903 and / or 903'will be mainly described.
First, in step 3001, the copy processing unit 903 and / or 903'receives the LDEV number of the migration source LDEV, the LDEV number of the migration destination LDEV, and the necessity of key change from the management terminal 6. In step 3002, the copy processing unit 903 and / or 903'determines whether or not the key change is instructed, and if the key change is instructed, proceeds to step 3011, and if not, the step Proceed to 3003.
In step 3003, the copy processing unit 903 and / or 903'changes the setting contents in the LU configuration table 600 so that the data stored in the migration destination LDEV is encrypted with the same key as the migration source LDEV. Specifically, the copy processing unit 903 and / or 903'searches the row corresponding to the migration source LDEV number from the LU configuration table 600, and the encryption key associated with the migration source LDEV number, that is, the search. Enter the encryption key stored in the area where the row and column 605 (Key) intersect (hereinafter referred to as the key registration field) as it is in the key registration field of the line corresponding to the migration destination LDEV number. When the migration destination LDEV is an external LDEV, the copy processing unit 903 and / or 903'from the storage subsystem 1 to the migration source LDEV with respect to the external storage subsystems 2 and 2'where the external LDEV exists. It is necessary to send the encryption key associated with and have the external storage subsystem 2 or 2'set the encryption key. This process will be described in detail in FIG.
On the other hand, when the process proceeds to step 3011, the encryption key is changed, so that the copy processing unit 903 and / or 903'migrates so that the migration destination LDEV is encrypted with an encryption key different from the migration source LDEV. Generate an encryption key different from the encryption key stored in the key registration field of the line corresponding to the original LDEV number, and register the generated encryption key in the key registration field of the line corresponding to the migration destination LDEV number. As an example of the method of generating the encryption key, there is a method of using a random number algorithm, but other than that, the user is made to directly specify the encryption key, or the user is made to input a simple character string or the like into the management terminal 6 and it is used. It is also possible to take a method such as generating a new encryption key by using a hash algorithm or the like in the storage subsystem 1 based on the above. When the process of step 3003 or 3011 is completed, the process proceeds to step 3004.
In step 3004, the copy processing unit 903 and / or 903'performs a process (copy process) of copying data from the migration source LDEV to the migration destination LDEV. The details of the copy process will be described in detail in FIG.
When the copy process is completed, the settings are switched so that host 4 will access the migration destination LDEV. Specifically, the copy processing unit 903 and / or 903'on the LU configuration table 600 so as to assign the WWN, LUN previously assigned to the migration source LDEV to the migration destination LDEV. Update the contents of 600. When the contents of the LU configuration table 600 are updated, the subsequent I / O processing from the host 4 will be performed on the migration destination LDEV instead of the migration source LDEV. The command processing unit 901 suspends the processing of the I / O request received from the host 4 during the processing of step 3005 until the processing of step 3005 is completed, and when the processing of step 3005 is completed, the processing is interrupted. , Processing can be resumed.
FIG. 18 shows the process of steps 3003 to 3011, that is, the process of setting the key in the migration destination LDEV.
In step 3501, the copy processing unit 903 and / or 903'registers the encryption key in the key registration field of the row corresponding to the migration destination LDEV number in the LU configuration table 600. If the encryption key is the same as the migration source LDEV number, the same encryption key as the encryption key corresponding to the migration source LDEV number is registered, and in the case of key change processing, the encryption is different from the encryption key corresponding to the migration source LDEV number. The key is registered.
If the migration source LDEV is an external LDEV, that is, an LDEV belonging to the external storage subsystems 2 or 2', and the external storage subsystem 2 or 2'has an encryption function, the encryption of the external LDEV is performed at this point. It is possible that the key is not registered in the LU configuration table 600 (if the encryption key was not obtained in step 10008 of the LU creation process in Figure 9). In that case, in step 3501, the copy processing unit 903 ́ sends a request to the external storage subsystems 2 to 2 to acquire the encryption key of the external LDEV. In response to the request, the external storage subsystems 2, 2 ́ obtain the encryption key associated with the external LDEV from the LU configuration table managed by the external storage subsystem, and obtain the obtained encryption key from the storage subsystem. Send to 1. The copy processing unit 903 ́ of the storage subsystem 1 receives the encryption key from the external storage subsystems 2 and 2', and receives the encryption key in the key registration field of the line corresponding to the migration source LDEV number on the LU configuration table 600. Register the encryption key, and then register the same encryption key in the key registration field of the line corresponding to the migration destination LDEV number.
In steps 3502 and 3503, the copy processing units 903 and / or 903'whether the migration destination LDEV is an external LDEV and whether the external storage subsystems 2 and 2 ́ with the external LDEV have an encryption function. To judge. If the migration destination LDEV is not an external LDEV, or if the migration destination LDEV is an external LDEV but the external storage subsystems 2 and 2 ́ with the external LDEV do not have the encryption function, this process ends. If the migration destination LDEV is an external LDEV and the external storage subsystems 2 and 2 ́ in which the external LDEV is located have an encryption function, the process proceeds to step 3504.
In step 3504, the copy processing unit 903 and / or 903'instructs the external storage subsystems 2 and 2'with the external LDEV to set the encryption key to the external LDEV. As a method of setting the encryption key to the external storage subsystems 2 to 2', for example, a method of instructing the external storage subsystems 2 to 2'from the external adapter 12 via a fiber channel cable and a method of instructing the external storage subsystems 2 to 2'via the management terminal 6. There is a method of issuing an instruction to each management terminal 7 to 7'of the external storage subsystem 2 to 2'. In response to the instruction, in the external storage subsystems 2, 2 ́, the encryption key corresponding to the external LDEV is registered in the LU management table in the external storage subsystems 2, 2 ́, for example.
FIG. 19 shows the flow of data copy processing from the migration source LDEV to the migration destination LDEV in step 3004 of FIG. The copy process is a process of copying the data from the start address of the migration source LDEV to the data at the end address in order to the migration destination LDEV.
First, the copy processing unit 903 and / or 903'records the control count value for sequentially copying the data in the cache / control memory 14. In this process, the count value is set to "A".
In step 3101, the copy processing unit 903 and / or 903'sets the count value A to 0. In step 3102, the copy processing unit 903 and / or 903'reads the data at the address A (the address having the same value as the count value A) of the migration source LDEV. The data read processing of the migration source LDEV can be the processing described with reference to FIGS. 11 to 16. In step 3103, the copy processing unit 903 and / or 903'writes the data read in step 3102 to the address A of the migration destination LDEV. The specific process can be the process described with reference to FIGS. 11 to 16 as in step 3102.
In step 3104, the copy processing unit 903 and / or 903'increases the value of the count value A by 1, and in step 3105, the count value A refers to the value of the count value A, and the count value A is the end of the migration source LDEV. Determine if the address has been exceeded. When the count value A exceeds the last address of the migration source LDEV, the copy processing unit 903 and / or 903'indicates that all the data has been copied to the migration destination LDEV, and thus this processing ends. .. If not, the process returns to step 3102 and the copy process is repeated.
In the process described in FIG. 19, the count value A is incremented by 1, that is, an example in which data copying is performed in units of 1 block (sector) is shown, but other than that, it is more than 1 block. It is possible to take a method of copying data in a large unit, for example, one track, one cylinder unit, or a fixed continuous area (1 MB, etc.) unit.
The migration / key change processing described with reference to FIGS. 17 to 19 can be executed while receiving an I / O request from the host 4 to the migration source LDEV.
FIG. 20 shows the flow of processing when an I / O request is received from host 4 during execution of migration / key change processing. This process replaces the process shown in FIG. 11, and if an I / O request is made to the migration source LDEV during the migration / key change process, FIG. 20 is executed instead of FIG. become.
In step 3201, the command processing unit 901 compares the address specified in the received I / O request with the value of the count value A used in the copy processing in FIG. 19, and specifies it in the I / O request. It is determined whether or not the given address and the count value A are equal. If they are equal, wait for a certain amount of time (for example, 1 millisecond) and return to step 3201 again.
In step 3202, the command processing unit 901 performs I / O processing to the migration source LDEV, that is, read or write processing. In this step, the process described in FIG. 11 is executed.
In step 3203, the command processing unit 901 determines whether the I / O request is a write request. If it is a write request, the process proceeds to step 3204, and if not, that is, if it is a read request, the process ends here.
In step 3204, the command processing unit 901 determines whether or not the address specified in the received I / O request is smaller than the count value A. If the address is larger than the count value A, the data on the address written in the migration source LDEV in step 3202 will soon be copied to the migration destination LDEV by the copy process shown in FIG. This process may be terminated without doing so. However, if the address specified in the I / O request is smaller than the count value A, the data at the address has already been copied by the copy process shown in FIG. 19, so the data at the address is copied again. There is no such thing. Therefore, it is necessary to copy the data written in this process to the migration destination LDEV. In step 3205, the command processing unit 901 calls the external I / O processing unit 902'as necessary, and the migration destination LDEV. Write write data to address A of. In order to carry out this writing process, the process described in FIG. 11 is executed as in step 3202.
The above is the description of the first embodiment.
In this first embodiment, at least one of the external storage subsystems 2 and 2 ́ may have the same configuration as the storage subsystem 1. Further, the encryption processing unit 134 may be mounted on the HDD 16 in place of or in addition to the DKA 13. In that case, in step 2002 of FIG. 14 and step 2102 of FIG. 15, the destination of the encryption key and the destination of the instruction is the encryption processing unit in the HDD 16.
<Second embodiment>.
Next, a second embodiment of the present invention will be described. The configuration of the computer system in the second embodiment is almost the same as that in the first embodiment. However, there are some differences in the information and functions managed in the storage subsystem 1, and the differences will be mainly explained below.
FIG. 21 shows a configuration example of the EDEV information table 250'managed by the storage subsystem 1 in the second embodiment.
The difference from the EDEV information table 250 in the first embodiment is that the flag information of column 256 is added. The value "1" in the column is the function that the external storage subsystem (2 to 2') with the EDEV reads the encrypted data (ciphertext) and the data received from the storage subsystem 1 (2 or 2'). For example, it means that it has a function to store the data in its own external LDEV without processing anything (without encrypting / decrypting it). On the other hand, the value "0" means that the external storage subsystem (2 or 2') in which the EDEV is located does not have those functions. These functions will be described later.
Further, the information setting in the column 256 is input by the user to the storage subsystem 1 via the management terminal 6. That is, the user determines whether or not the external storage subsystems 2 and 2'connected to the storage subsystem 1 have the function, and if so, inputs 1 in column 256. As another method, the storage subsystem 1 acquires information on the presence or absence of the function from the external storage subsystems 2 and 2'via the management terminals 6,7,7'or through the I / F 123. However, there may be a way to reflect the result in column 256.
In the volume migration process in the first embodiment, when the data of the migration source LDEV is once read into the cache area, it is always decrypted in plain text and then stored in the cache area, and encrypted when writing to the migration destination LDEV. Be made. However, in the second embodiment, in the volume migration process in which the encryption key change does not occur, the ciphertext in the migration source LDEV is copied to the migration destination LDEV without being decrypted as it is.
FIG. 22 shows the flow of data copy processing from the migration source LDEV to the migration destination LDEV in step 3004 of FIG. Since this process has many parts in common with the copy process of FIG. 19 in the first embodiment, the differences will be mainly described.
Before reading the data from the migration source LDEV (step 3101 or later), it is determined whether or not copying in this process is possible. First, in step 5001, the copy processing unit 903 and / or 903 ́ determines whether or not the migration source LDEV is an external LDEV. If it is an external LDEV, go to step 5002, otherwise go to step 5003.
In step 5002, the copy processing unit 903 and / or 903 ́ reads the undecrypted (still encrypted) data (ciphertext) from the external storage subsystems 2 and 2 ́ having the migration source LDEV. Is possible. If it is determined that it is impossible, the processes after step 3101 in FIG. 19 are performed.
Subsequently, in step 5003 and subsequent steps, the conditions related to the migration destination LDEV are determined.
Specifically, in step 5003, the copy processing unit 903 and / or 903 ́ determines whether or not the migration destination LDEV is an internal LDEV. In the case of an internal LDEV, the process proceeds to step 5004 to determine whether the RAID configuration of the migration destination LDEV is a RAID configuration in which a parity such as RAID-5 is created. In the case of a form such as RAID-5 in which parity is created, the process of FIG. 22 cannot be used, and the migration process is performed by the process of FIG.
If the migration destination LDEV is determined to be an external LDEV in step 5003, the process proceeds to step 5005, and the copy processing unit 903 and / or 903 ́ and the external storage subsystems 2 and 2 ́ with the migration destination LDEV keep the ciphertext as it is. Determine if it is possible to write. If possible, the process proceeds to step 3101, and if not possible, the processes after step 3001 in FIG. 19 are performed.
The processing after step 3101 in FIG. 22 is almost the same as the processing after step 3101 in FIG. In step 3102 of FIG. 19, instead of step 3102'in FIG. 22, the copy processing unit 903 and / or 903 ́ performs reading without decoding when reading data from the migration source LDEV. As a result, the data read from the migration source LDEV is a ciphertext. Further, step 3103 in FIG. 19 is changed to step 3103', and the copy processing unit 903 and / or 903 ́ does not encrypt the ciphertext read in step 3102' in the middle when writing data to the migration destination LDEV. To write to.
The determination in steps 5002 to 5005 is made based on the value in column 256 in the EDEV information table 250'in FIG. If the value of column 256 is 1, it is possible to read the undecrypted (still encrypted) data from the device with the migration source LDEV, and the device with the migration destination LDEV reads the encrypted data. It means that it can be written as it is.
In the process of step 5004, the reason that the process changes depending on the RAID configuration of the migration destination LDEV is that when the parity is generated based on the ciphertext in the storage subsystem 1, the value is different from the parity that should be originally created. In the storage subsystem 1, since the encryption process is performed immediately before writing to the HDD 16, normally, parity based on plaintext is generated and encrypted immediately before being stored in the HDD 16. That is, the parity written in HDD 16 is an encrypted parity generated from plain text. However, when the ciphertext is on the cache area as in the process of FIG. 22, the parity generated based on the ciphertext is generated, which is different from the parity generated from the plaintext. Therefore, in FIG. 22 In step 5004, if the migration destination LDEV is an internal LDEV, the RAID level (RAID 0, 1, 1, which does not generate parity in the RAID configuration) Limited to 0 + 1 etc.). However, the location of the encryption processing unit in the storage subsystem 1 is not DKA13, for example, the encryption processing unit exists in CHA11, and the encryption processing is executed when the data is stored in the cache area from the host. In the case of the form, such a restriction is unnecessary, that is, the determination process in step 5004 is unnecessary.
Steps 3102'to 3103' are processed by, in principle, performing almost the same processing as the I / O processing for the LDEV disclosed in FIGS. 11 to 16. However, in step 3102', the encrypted data (ciphertext) stored in the LDEV is read without being decrypted, and in step 3103', the data read in step 3102' is stored as a storage sub. Since the data is transmitted to the HDD 16 or the external storage subsystems 2 to 2'without being encrypted by the system 1, the processes of FIGS. 14 to 16 are slightly different.
In the read process of step 3102', when the read target is the internal LDEV, data is read from the HDD 16 to the cache area without performing steps 2101 and 2102 in FIG.
Figure 23 shows the flow of I / O processing for the external LDEV. This process is similar to FIG. 16, but without steps 1303, 1304, 1305, 1311, 1312, 1313 in FIG.
Further, step 1306 in FIG. 16 is changed to step 1306', and when the write request is sent in step 1306', the external storage subsystems 2 and 2 ́ are requested to write the write data without encryption. (Hereinafter, an encryption-free write request) is sent.
Further, step 1314 in FIG. 16 is changed to step 1314'. When sending the read request in step 1314', for example, a request to read the undecrypted data (ciphertext) as it is to the external storage subsystems 2 and 2 ́ (hereinafter referred to as a decryption-free read request) is made. Will be sent.
To read undecrypted data (ciphertext) or write data (ciphertext) unencrypted in external storage subsystems 2, 2 ́, for example, external storage subsystem 2 or 2'has the ability to receive encryption-free write requests and decryption-free read requests from storage subsystem 1 and return undecrypted data or store the data without performing encryption processing. It is necessary to be prepared. As one of the concrete methods, for example, instead of the READ / WRITE command specified in the SCSI-FCP protocol, a newly defined special command is issued from the storage subsystem 1 to the external storage subsystems 2 and 2'. There can be a way to issue it.
Also, for example, as a method for reading undecrypted data (ciphertext) or writing data (ciphertext) in the external storage subsystem 2, 2 ́ without encryption, an external I / The O processing unit 902 ́ may notify the external storage subsystems 2 and 2 ́ that the external LDEV to be accessed is not the encryption target. The external storage subsystems 2, 2 ́ that received this notification become NO in step 2001 or NO in step 2101, for example, in the process of FIG. 14 or FIG. 15 in the external storage subsystems 2, 2 ́. May be good.
The above is the description of the second embodiment.
In this second embodiment, at least one of the external storage subsystems 2 and 2 ́ may have the same configuration as the storage subsystem 1. In this case, for example, in the external storage subsystems 2 and 2 ́, if the command processing unit receives an encryption-free write request for writing the ciphertext, the encryption is applied to the disk I / O processing unit. Send a write request to write the ciphertext to the external LDEV specified in the write request. For example, the write request is set with encryption non-target information indicating that the external LDEV is not the encryption target. The disk I / O processing unit receives a write request from the command processing unit, and if encryption non-target information is set in the write request, the ciphertext that complies with the write request is directly applied to the HDD (based on the external LDEV). Data is transferred to the HDD). Also, for example, external storage subsystems 2, 2 In ́, when the command processing unit receives a decryption-free read request for reading the ciphertext, the disk I / O processing unit receives the decryption-free read request from the external LDEV specified in the decryption-free read request. Send a read request to read the ciphertext. For example, encryption non-target information indicating that the external LDEV is not the encryption target is set in the read request. The disk I / O processing unit receives a read request from the command processing unit, and if encryption non-target information is set in the read request, the ciphertext that follows the read request is used as it is on the HDD (based on the external LDEV). Data is transferred from the HDD) to the read cache area.
<Third embodiment>.
In the third embodiment, the data migration from the external storage subsystem 2 to the external storage subsystem 2 ́ is performed without going through the storage subsystem 1. This data migration can be performed when the encryption key associated with the migration source external LDEV is not changed.
For example, the management terminal 7 issues a data migration instruction for migrating data from the first external LDEV of the external storage subsystem 2 to the second external LDEV of the external storage subsystem 2 ́ as encrypted text. Send to system 2. In response to this, the external storage subsystem 2 (for example, the command processing unit) writes the ciphertext in the first external LDEV specified in the data migration instruction as the write target and specifies the second external LDEV. Send the request to the external storage subsystem 2 ́. If the external storage subsystem 2 ́ has an encryption function, the management terminal 7 or the external storage subsystem 2 does not need to encrypt the data to be written to the second external LDEV. Instruct storage subsystem 2 ́. As a result, the external storage subsystem 2 ́ writes the ciphertext according to the write request from the external storage subsystem 2 to the second external LDEV without encryption.
Further, the external storage subsystem 2 or the management terminal 7 notifies the storage subsystem 1 or the management terminal 6 that the data (ciphertext) in the first external LDEV has been transferred to the second external LDEV. In response to the notification, the storage subsystem 1 or the management terminal 6 updates the information corresponding to the first external LDEV in the EDEV information table 250 to the information corresponding to the second external LDEV. As a result, the storage subsystem 1 can execute the I / O for the second external LDEV when the host 4 receives the I / O request for which the first external LDEV is specified.
Although some embodiments of the present invention have been described above, these embodiments are merely examples for the purpose of explaining the present invention, and the scope of the present invention is not limited to those embodiments. The present invention can be carried out in various other aspects without departing from the gist thereof. For example, the encryption key may be not in the LDEV unit but in the sub-area unit constituting the LDEV, or in the HDD unit.
<figref num="1">An example of a physical configuration of a computer system according to the first embodiment of the present invention is shown.</figref><figref num="2">A logical configuration example of the computer system according to the first embodiment of the present invention is shown.</figref><figref num="3">It is a figure which shows an example of the relationship between a plurality of HDD16s and a logical volume.</figref><figref num="4">A configuration example of the RAID configuration table is shown.</figref><figref num="5">A configuration example of the VDEV configuration table is shown.</figref><figref num="6">A configuration example of the LU configuration table is shown.</figref><figref num="7">A configuration example of the port configuration table is shown.</figref><figref num="8">A configuration example of the EDEV information table is shown.</figref><figref num="9">The flow of the process of creating an LU in the storage subsystem 1 of the present invention is shown.</figref><figref num="10">An example of the processing flow executed when the host adapter receives an I / O request from the host is shown below.</figref><figref num="11">The flow of processing of the I / O request for LDEV in the storage subsystem is shown.</figref><figref num="12">An example of the processing flow of the I / O request for the internal LDEV is shown.</figref><figref num="13">An example of the processing flow of the I / O request for the internal LDEV is shown.</figref><figref num="14">An example of the writing process for the HDD is shown.</figref><figref num="15">An example of the writing process for the HDD is shown.</figref><figref num="16">An example of the processing flow of the I / O request for the external LDEV is shown.</figref><figref num="17">The flow of migration / key change processing is shown.</figref><figref num="18">The flow of the key setting process is shown.</figref><figref num="19">The flow of data copy processing from the migration source LDEV to the migration destination LDEV in step 3004 of FIG. 16 is shown.</figref><figref num="20">Shows the processing flow of the storage subsystem that received an I / O request from the host during execution of migration / key change processing.</figref><figref num="21">A configuration example of the EDEV information table managed by the storage subsystem according to the second embodiment of the present invention is shown.</figref><figref num="22">The flow of data copy processing from the migration source LDEV to the migration destination LDEV in the second embodiment is shown.</figref><figref num="23">The flow of I / O processing for the external LDEV when data read from the external LDEV or data write to the external LDEV is performed in the data copy processing from the migration source LDEV to the migration destination LDEV in FIG. 22 is shown.</figref>
Code description
1 ... Storage Subsystem 2, 2 ́ ... External Storage Subsystem 4 ... Host Calculator 5 ... Fiber Channel Switch 6, 7, 7 ́ ... Management Terminal 11 ... Host Adapter 12. .. External Adapter 13 ... Disk Adapter 14 ... Cache / Control Memory 15 ... Internal Switch 16 ... HDD
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11599279B2 | Cited by | United States of America | Applicant |
| JP2003316522A | Cites | Japan | – |
| JP2002312223A | Cites | Japan | – |
| JP2005026970A | Cites | Japan | – |
| JP2004259262A | Cites | Japan | – |
| JP2008108039A | Cites | Japan | – |
6 members in 3 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2007087531 | Japan | A | |
| JP20070087531 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| EP1975838A2 | European Patent Office (EPO) | A2 | |
| US2008240434A1 | United States of America | A1 | |
| JP2008250393A | Japan | A | |
| EP1975838A3 | European Patent Office (EPO) | A3 | |
| JP5117748B2This record | Japan | B2 | |
| US8422677B2 | United States of America | B2 |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 5117748
- Publication, DOCDB
- 5117748
- Publication, EPODOC
- JP5117748B
- Application
- 87531
- Application, DOCDB
- 2007087531
- Application, EPODOC
- JP20070087531
Titles2
- English
- Storage virtualization device with encryption function
- Japanese
- 暗号化機能を備えたストレージ仮想化装置
Classification
- CPC, 1
- G06F21/80
- IPC, 3
- G06F3 06
- G06F21 60
- G06F21 62
