The present invention relates to network storage control, and more particularly, to a method for providing network-based services to a user of a network storage server, the associated network storage server and associated storage systems.
Nowadays, computer and communication systems require more and more storage space to store important files and media data. Conventionally, a person can carry a USB drive to store data and plug it into a computer to access the data. However, with advances in network communication technology, people tends to access data over internet instead of the USB drive. Network-based storage devices such as network attached storage (NAS) servers fulfill the need of accessing massive data over the Internet.
A NAS server can provide data accessing function for multiple users. Furthermore, a NAS server can not only store and share data, but also serve as a media entertainment center and a surveillance center. Especially for home users or medium-sized enterprises, it is very important for them to connect to their NAS server whenever they want so that they can use various services provided by the NAS. In order to make sure the services provided by the NAS will not fail, a disaster recovery (DR) plan should be implemented.
Regarding DR, it may involve some policies, tools and procedures to enable the recovery or continuation of vital technology infrastructure and systems following a natural or human-induced disaster. DR may focus on some information technology (IT) systems supporting critical business functions, and more particularly, keeping all essential aspects of a business functioning despite significant disruptive events. Although DR may be a solution to business continuity, some problems may occur. For example, there may be data security issues, since data transmission between the intranet and the world outside the intranet is typically required. For another example, the associated reconfiguration may be very complicated and time consuming. Thus, a novel method and associated architecture are required.
An objective of the present invention is to provide a method for providing network-based services to a user of a network storage server, the associated network storage server and associated storage systems, to solve the problems of the related art.
At least one embodiment of the present invention provides a method for providing network-based services to a user of a network storage server. The method may include: associating the network storage server with a virtual machine running at a disaster recovery site (DR site); replicating data associated with the network-based services from the network storage server to the virtual machine; configuring a first dynamic domain name system (DDNS) setting of a domain name system (DNS) server, wherein the first DDNS setting is arranged to map a public domain name to a public internet protocol (IP) address of the network storage server; configuring a first private DNS setting of a private DNS server, wherein the first private DNS setting is arranged to map a private domain name to a private network IP address of the network storage server; wherein when the network storage server is in a non-working status, the network-based services are recovered to the virtual machine running on the DR site by performing the following steps: triggering, by the virtual machine, a second DDNS setting of the DNS server, wherein the second DDNS setting is arranged to map the public domain name to a public IP address of the virtual machine; and triggering, by the virtual machine, a second private DNS setting of the private DNS server, wherein the second private DNS setting is arranged to map the private domain name to a virtual private network (VPN) IP address of the virtual machine.
Compared with the related art, the method and associated apparatus of the present invention can guarantee data security with aid of VPN. For example, when failover to the cloud server occurs, the users can continue accessing some services that are originally available in the private network, and the architecture implemented according to the method and associated apparatus of the present invention can provide the services to the users as if the services are still provided from the private network. Thus, file security can be guaranteed and privacy can be protected in the present invention architecture. In addition, the method and associated apparatus of the present invention can greatly improve the efficiency of DR-related setting and processing, and can improve user experience.
These and other objectives of the present invention will no doubt become obvious to those of ordinary skill in the art after reading the following detailed description of the preferred embodiment that is illustrated in the various figures and drawings.
Disaster recovery (DR) of a NAS from one place to another typically needs reconfiguring network properties of the operating system of the NAS to match the network configuration of the recovery site. This reconfiguration is a very complicated and time consuming process, and can have negatively affect user experience. However, without a recovery plan, users and enterprises will expose themselves to the risks of data lost and business shut down due to unexpected disasters, such as flood, terrorist attack, war, earthquake, etc. The present invention method and architecture can provide an efficient and user-friendly way to establish a recovery plan to protect user's data and enterprises' digital assets. In addition, the present invention method and architecture can guarantee data security when initiating failover. For example, when failover to the cloud server occurs, the users can continue accessing various services that are originally available in the private network, in which the services can be provided from the cloud server to the users through a VPN connection as if the services are still provided from the private network. As a result, accessing the services from the cloud server is as safe as accessing the services from the private network, and data and privacy can be protected.
The network interface circuit 112 is arranged to couple the network storage server 110 to the router device 8 through a wired or wireless connection. The storage interface circuit 113 is arranged to install the storage device 114 at the network storage server 110, in which the at least one storage device is arranged to store data of the user. The processing circuit 111 is arranged to control operations of the network storage server 110. In addition, the network interface circuit 122 is arranged to couple the cloud server 120 to the network. The storage interface circuit 123 is arranged to install the storage device 124 at the cloud server 120, in which the storage device 124 may be arranged to store a replication version of data of the user. The processing circuit 121 is arranged to control operations of the cloud server 120, and control the cloud server 120 to run a virtual machine (e.g. any of the virtual machines, such as any of the virtual NASs 81 and 82) to emulate the network storage server 110 when needed. For example, the OS and the apps of the NAS may run on the processor within the processing circuit 111, the host OS and other program modules (e.g. the hypervisor, the virtual machines, etc.) may run on the processor within the processing circuit 121, and the combination of the hardware components in the cloud server 120 (e.g. the processing circuit 121, the network interface circuit 122, the storage interface circuit 123, and the storage device 124) may be regarded as the hardware shown in
In the architecture shown in
Based on the architecture shown in
In Step S10, the processing circuit 111 may associate the network storage server 110 with a virtual machine running at the DR site (e.g. the cloud server 120), for example, the virtual machine running on the cloud server 120. According to this embodiment, the processing circuit 111 may establish a link between the network storage server 110 and the virtual machine running at the DR site, for example, the user may login to a predetermined account of the network storage server 110, and the processing circuit 121 may assign the virtual machine corresponding to the network storage server 110 for the user, for further DR usage. The login process may be carried out by a replication wizard having some control windows such as that shown in
In Step S20, the processing circuit 111 may trigger the network storage server 110 to replicate data associated with the network-based services from the network storage server 110 to the virtual machine. Examples of the data may include, but are not limited to: data of one or more specific services, such as that of the file transferring service or file editing service. In an embodiment, the processing circuit 111 may set up the replication schedule for the user. Taking
After binding the NAS to the DR site, the processing circuit 111 may automatically calculate the needed space on the DR site for the physical NAS. For example, regarding calculating the needed space, the storage space in the DR site may be determined in unit of TB (Terabyte). As a result, if the physical site (e.g. the physical NAS) is ranged from 0 to 1 TB, the DR site may allocate 1 TB space for the physical site. However, the file system may need to store some metadata, so the calculating rule may be adjusted as follow:
In Step S32, the first DDNS setting of the DNS server is configured to map the public domain name of the network storage device 110 to a public IP address of the network storage server 110, in which the first DDNS setting is arranged to perform this mapping operation. In an embodiment, the manufacturer of the network storage device 110 may provide the service of DDNS setting, but the present invention is not limited thereto. Other parties other than the NAS vendor can also provide the service of the DDNS setting. After the first DDNS setting is complete, the processing circuit 111 will update the public IP address of the network storage server 110 to the DDNS service provider automatically (the public IP address of the network storage server 110 may change from time to time). Furthermore, the domain name of network storage server 110 and the information of the DDNS service provider are replicated to the cloud server 120 by the processing circuit 111 automatically after step S32 is complete. The example of the information of the DDNS service provider may include IP address, authentication information, and name of the DDNS service provider. By doing so, the cloud server 120 can update its public IP address to the DDNS service provider when initiating failover so that the client device 10 may connect to the cloud server 120. The user has no need to know the IP address of either the network storage server 110 or the cloud server.
In embodiments, the public domain name of the network storage device 110 can be used for the external clients, and is therefore named with “public”, but the present invention is not limited thereto. The internal clients may also use the public domain name to connect the network storage server 110.
In Step S34, the first private DNS setting of the private DNS server is configured within the router device 8, to map a private domain name of the network storage server 110 to the private network IP address of the network storage server 110, in which the first private DNS is arranged to perform this mapping operation. In an embodiment, the router device 8 may provide the service of the private DNS setting. However, in order to use LAN 5 to access the cloud server 120 on DR site, a VPN connection is required for data security. Once the network storage server 110 has been switched over to the cloud server 120, a VPN connection will be automatically established to allow the client device within the LAN to access data on the cloud server 120 through a file service protocol. The file service protocol in this embodiment is a protocol that used within LAN environment, and is not suitable to be used external to the LAN in conventional art because of the security issue. By establishing the VPN connection between the cloud server 120 and the router device 8, the client device within the LAN 5 can access the data and services provided by the cloud server 120 through the file service protocol, and it is as safe as accessing the services from the private network. In an embodiment, the file service protocol may be implemented by Samba, AFP, but the present application is not limited thereto. In an embodiment, the processing circuit 111 may set up the VPN setting, so the DR site may link to the VPN server when needed. More specifically, the VPN setting may include the IP address of the VPN server. In an embodiment, the VPN connection can be implemented by using L2TP/IPsec or OpenVPN method, but the present application is not limited thereto.
In an embodiment, the processing circuit 111 may set the firewall rules. One or more specific services can be selected to enable those services on the DR site. More specifically, when initiating the DR plan, in addition to the OS configuration data, the files and the configuration data of the selected services will be also replicated to the DR site. After the final setting, the UI of the replication wizard may summarize the setting to the user to make a final confirmation.
In Step S40, a failover operation is initiated. That is, when the network storage server 110 is in a non-working status (e.g. the network storage server 110 is not operating normally), the network-based services are recovered to the virtual machine running on the DR site. In an embodiment, the network storage server 110 may communicate to the cloud server 120 periodically to determine whether the network storage server 110 operates normally or not. For example, the network storage server 110 may send a survival signal to the cloud server 120 periodically. Once the cloud server 120 fails to receive the survival signal in a period of time, the cloud server 120 may trigger a series of steps (for example, step S42 and step S44) to provide the services and data that are originally provided by the network storage server 110. In another example, the network storage server 110 may detect its own operation condition. If a volume crash event is detected or at least a portion of the services of the network storage server 110 fails, the network storage server 110 may send a recovery request to the cloud server 120. Once the cloud server 120 receives the recovery request, the cloud server 120 may trigger a series of steps to provide the services and data that are originally provided by the network storage server 110. In yet another example, there may be an intermediate server utilized for determine whether the network storage server 110 operates normally or not. The intermediate server is positioned external to the LAN 5, and is used to communicate between the network storage server 110 and the cloud server 120. The intermediate server may detect the DDNS service and the VPN connection of the network storage server 110 periodically. If the intermediate server cannot connect to the network storage server 110 through the DDNS service and the VPN connection, the intermediate server may send a recovery request to the cloud server 120 to recovery the services and data that are originally provided by the network storage server 110.
In Step S42, the processing circuit 121 may trigger, by utilizing the virtual machine, the second DDNS setting of the DNS server, to map the public domain name of the network storage device 110 to a public IP address of the virtual machine, in which the second DDNS setting is arranged to perform this mapping operation. For example, the virtual machine may update the IP address for this mapping operation in the DNS server, and this maybe done without complicated settings whenever the network storage server 110 is in the non-working status so that the client device can connect to the virtual machine use the public domain name of the network storage device 110.
In Step S44, the processing circuit 121 may trigger, by utilizing the virtual machine, the second private DNS setting of the private DNS server, to map the private domain name of the network storage device 110 to a VPN IP address of the virtual machine, in which the second private DNS setting is arranged to perform this mapping operation. For example, the virtual machine may update the IP address for this mapping operation in the private DNS server. Afterward, the client device within the LAN 5 may connect to the cloud server 120 by using the private domain, and the VPN connection can ensure the data security between the cloud server 120 and the network storage device 110. By doing this, the data and services originally provided by the network storage device 110 can be seamless provided by the virtual machine (the cloud server 120).
For better comprehension, some steps of the working flow 300 may be described with reference to the architecture shown in one or more of
In addition, the network storage server 110 may provide at least one network-based UI (e.g. browser-executable UI), such as the UI of the replication wizard, to allow the user to set multiple configurations regarding the set of network-based services. The configurations may include a normal configuration (which may correspond to the normal control scheme) for providing the network-based services including the set of network-based services from the network storage server to the user, and further include a failover configuration (which may correspond to the failover control scheme) for providing the set of network-based services from the cloud server 120 such as the C2 cloud (more particularly, from the virtual machine 110V) to the user.
The normal configuration may include a first private DNS setting of the router device 8, such as that of a private DNS server (labeled “Private DNS” in any of
When the network storage server 110 is operating normally and the client device 10 held by the user is within the LAN 5, based on the normal configuration, the network storage server 110 is arranged to be accessible by the client device 10 through the router device 8 (e.g. the private DNS server therein) having the first private DNS setting (e.g. the setting of “primarysite.privatedns→192.168.1.92” shown in
The normal configuration may further include a first DDNS setting of a DNS server (labeled “DNS” in any of
When the network storage server 110 is operating normally and the client device 10 held by the user is in the network (e.g. the WAN) outside the LAN 5, based on the normal configuration, the network storage server 110 is arranged to be accessible by the client device 10 through the DNS server (labeled “DNS”) having the first DDNS setting (e.g. the setting of “DDNS” shown in
According to some embodiments, the network storage server 110 may be implemented with a NAS device such as that shown in
According to some embodiments, the method and the associated apparatus (e.g. a storage system including one or more of the router device 8, the client device 10, the network storage server 110, and the cloud server 120, such as any combination of the devices and servers in the architecture shown in
According to some embodiments, the network-based services may include a first subset of the network-based services that is accessible through the LAN 5 where the network storage server 110 is located, and the second private DNS setting may be arranged to access the first subset of the network-based services through the private domain name within the LAN 5. For example, the first subset of the network-based services may include some services that should be accessed within the LAN 5. The client device outside the LAN 5 cannot access the first subset of the network-based services because of the security issue. In an embodiment, the first subset of the network-based services may be provided by some file service protocols that designed to be used with the LAN 5. In an embodiment, such file service protocols maybe implemented by Samba, AFP. During failover, as the virtual machine linked to the VPN server may be regarded as being added into the LAN 5, the internal clients can obtain the first subset of the network-based services through VPN for the users. The internal clients are not limited to obtain the first subset of the network-based services, but can obtain all of the network-based services for the users. As the first subset of the network-based services can be accessible only through the internal network such as the LAN 5, the present invention method and apparatus can guarantee data security.
In addition, the network-based services may include a second subset of the network-based services that can be accessed through the network outside the LAN 5 where the network storage server 110 is located, and the second DDNS setting of the DNS server is arranged to access the second subset of the network-based services through the network outside the LAN 5. As the external clients can merely obtain a portion (e.g. the second subset) of the network-based services, rather than all of the network-based services, the present invention can guarantee data security. In an embodiment, the second subset of the network-based services may include mail service.
In some embodiments, the second private DNS setting may be arranged to access the first subset of the network-based services provided by the virtual machine 110V outside the LAN 5 . As the internal client device should be able to obtain all of the network-based services, the second private DNS setting can direct the request from the client device to the virtual machine 110V.
According to some embodiments, the network-based services may include a subset of the network-based services that is inaccessible through the network outside the LAN 5 where the network storage server 110 is located, and the first private DNS setting may be arranged to access this subset of the network-based services provided by the network storage server 110 within the LAN 5. When the network storage server 110 is operating normally, the internal clients may obtain this subset of the network-based services (e.g. some file transferring services) for the users through the private DNS server, in which the private DNS server is arranged to be used by the internal clients, rather than the external clients, to guarantee data security.
According to some embodiments, the network-based services include a subset of the network-based services that is accessible through a network, such as the second subset of the network-based services that is accessible through the network. The first DDNS settings of the DNS server maybe arranged to access this subset (e.g. the second subset) of the network-based services provided by the network storage server 110, and the second DDNS setting of the DNS server may be arranged to access this subset (e.g. the second subset) of the network-based services provided by the virtual machine (e.g. the virtual machine 110V). As a result, the present invention method and apparatus can provide seamless services such as this subset (e.g. the second subset) of the network-based services.
The replication module running on the processing circuit 111 may provide the UI that allows the user to set up the NAS through a client device which is linking to the NAS. First, the user may click a button of Create Replication in the UI. When a request of creating replication is identified through the UI, the replication wizard provided by the replication module will pop up on the screen of the client device, for the user to set up using a series of control windows of the replication wizard. For example, the replication scheduling sub-module can set up the replication schedule for the user, the authentication sub-module can communicate with the DR site to verify the account, and the storage allocation sub-module can automatically calculate the needed space on the DR site for the physical NAS. In addition, the replication scheduling sub-module can determine the replication schedule, and can provide the default setting and also provide the associated setting choices for the users. Based on the replication schedule, the data replication sub-module can perform data replication from the NAS to the DR site. Additionally, the network configuration sub-module can perform network configuration setting. For example, the DDNS setting component can automatically find out the registered DDNS of the NAS, and can access the DDNS information stored in the network configuration data, the VPN setting component can set up the VPN server for the user, to allow the DR site to link to the VPN server when needed, and the DNS setting component can set up the private DNS server (e.g. configure the private DNS setting of the private DNS server). Furthermore, the firewall configuration sub-module can perform firewall configuration setting, in which the firewall rules can be set through the firewall configuration sub-module.
Those skilled in the art will readily observe that numerous modifications and alterations of the device and method may be made while retaining the teachings of the invention. Accordingly, the above disclosure should be construed as limited only by the metes and bounds of the appended claims.
This application claims the benefit of U.S. provisional application No. 62/509,200, which was filed on May 22, 2017, and is included herein by reference.
Number | Date | Country | |
---|---|---|---|
62509200 | May 2017 | US |