首页> 外国专利> Access control to block storage devices for a shared disk based file system

Access control to block storage devices for a shared disk based file system

机译:用于基于共享磁盘的文件系统的块存储设备的访问控制

摘要

For enhanced access control, a client includes a token in each read or write command sent to a block storage device. The block storage device evaluates the token to determine whether or not read or write access is permitted at a specified logical block address. For example, the token is included in the logical block address field of a SCSI read or write command. The client may compute the token as a function of the logical block address of a data block to be accessed, or a metadata server may include the token in each block address of each extent reported to the client in response to a metadata request. For enhanced security, the token also is a function of a client identifier, a logical unit number, and access rights of the client to a particular extent of file system data blocks.
机译:为了增强访问控制,客户端在发送到块存储设备的每个读或写命令中都包含一个令牌。块存储设备评估令牌,以确定是否在指定的逻辑块地址处允许读取或写入访问。例如,令牌包含在SCSI读取或写入命令的逻辑块地址字段中。客户端可以根据要访问的数据块的逻辑块地址来计算令牌,或者元数据服务器可以响应于元​​数据请求而将令牌包括在报告给客户端的每个扩展区的每个块地址中。为了增强安全性,令牌还取决于客户端标识符,逻辑单元号以及客户端对文件系统数据块的特定范围的访问权限。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号