IP Library Granted Patent US 11,347,717
Granted Patent B2
US 11,347,717 · App. 16/523,960 · Granted May 31, 2022

Generalized verification scheme for safe metadata modification

Inventors: Viacheslav Dubeyko (San Jose, CA); Adam Manzanares (San Jose, CA)
Assignee: WESTERN DIGITAL TECHNOLOGIES, INC.
G06F16/2365G06F3/06G06F3/0619G06F3/0644G06F3/0659G06F11/30G06F16/122G06F16/273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,347,717
App. No.
16/523,960
Granted
May 31, 2022
Kind
B2
Abstract

System and method of verifying validity of a metadata modification request to prevent improper metadata operations. During initialization of a volume in a storage device and once a metadata area is reserved for a metadata structure, information characterizing the metadata structure and metadata area is stored in the storage device, which may be in the form of an area legend composed of descriptors such as a magic signature, a node size, a clump size of reservation, and extent of the metadata area. Responsive to a request for operating on metadata, relevant information provided in the request is verified against the stored characteristic information. If the verification discovers an inconsistency between the information provided in the request and the stored characteristic information, the request modification is treated as invalid and blocked from operation.

Claims (77)

1. A data storage system, comprising:

a processor; and

a storage device storing instructions that, when executed by the processor, cause performing:

processing a first write operation request for performing a first write operation on a first metadata record in a file system volume of the storage device;

prior to performing the first write operation in the file system volume and in response to the first write operation request:

extracting information from the first write operation request;

generating, in a namespace storage area of the storage device, a namespace for a first plurality of metadata areas, wherein the namespace comprises multiple values associated with multiple descriptors, wherein the multiple descriptors characterize a respective metadata area of the first plurality of metadata areas, wherein the file system volume comprises the first plurality of metadata areas, wherein the first plurality of metadata areas are configured to store a plurality of metadata records, wherein the plurality of metadata records comprises the first metadata record in the file system volume; and

verifying the first write operation request based on verification logic and based on comparing the extracted information, not all information, of the first write operation request to the multiple values associated with multiple descriptors of the namespace in the namespace storage area of the storage device; and

based on the verifying the first write operation, determining whether to perform the first write operation in the file system volume,

wherein:

the namespace storage area of the storage device is different than and outside of the file system volume of the storage device;

the first metadata record comprises information on usage of data blocks;

the namespace is different from the first metadata record; and

the multiple descriptors of the namespace are independent of peculiarities of a file system and independent of metadata content of the first metadata record.

2. The data storage system of claim 1 , wherein when the instructions are executed by the processor, the instructions cause performing:

processing a first indication to verify a write operation request associated with a category; and

identifying the first plurality of metadata areas in the file system volume of the storage device.

3. The data storage system of claim 2 , wherein the write operation request associated with the category comprises a flag, and

wherein when the instructions are executed by the processor, the instructions cause performing: identifying the flag in the first write operation request prior to verifying the first write operation request.

4. The data storage system of claim 2 , wherein the namespace is stored in a dedicated partition of the storage device, wherein the dedicated partition is separate from a partition in the storage device for storing the plurality of metadata records.

5. The data storage system of claim 1 , wherein when the instructions are executed by the processor, the instructions cause performing:

responsive to a second indication, reserving a second plurality of metadata areas without creating a namespace associated therewith, wherein the second plurality of metadata areas comprises a metadata area for a second metadata record.

6. The data storage system of claim 1 , wherein the verification logic is configured to:

receive a second indication to disable verification fora write operation request in the file system volume;

receive a second write operation request for a second write operation on a second metadata record; and

based on the second indication, perform the second write operation without verifying the second write operation request.

7. The data storage system of claim 6 , wherein when the instructions are executed by the processor, the instructions cause performing:

responsive to the second indication:

reserving a second plurality of metadata areas without creating a namespace, wherein the second plurality of metadata areas comprises a metadata area for the second metadata record.

8. The data storage system of claim 1 , wherein the verification logic is resident on the data storage system and implemented in hardware circuitry.

9. The data storage system of claim 1 , wherein a file system driver is configured to generate a corrected first write operation request based on the verifying.

10. A data storage system, comprising:

a processor;

a storage device;

means for processing, utilizing the processor, a first write operation request for performing a first write operation on a first metadata record in a file system volume of the storage device;

prior to performing the first write operation in the file system volume:

means for extracting information from the first write operation request;

means for generating, utilizing the processor, in a namespace storage area of the storage device, a namespace for a first plurality of metadata areas, wherein the namespace comprises multiple values associated with multiple descriptors, wherein the multiple descriptors characterize a respective metadata area of the first plurality of metadata areas, wherein the file system volume comprises the first plurality of metadata areas, wherein the first plurality of metadata areas are configured to store a plurality of metadata records, wherein the plurality of metadata records comprises the first metadata record; and

means for verifying, utilizing the processor, the first write operation request based on verification logic and based on comparing the extracted information, not all information, of the first write operation request to the multiple values associated with multiple descriptors of the namespace in the namespace storage area of the storage device; and

based on verifying the first write operation, means for determining, utilizing the processor, whether to perform the first write operation in the file system volume,

wherein:

the namespace storage area of the storage device is different than and outside of the file system volume of the storage device;

the first metadata record comprises information on usage of data blocks;

the namespace is different from the first metadata record; and

the multiple descriptors of the namespace are independent of peculiarities of a file system and independent of metadata content of the first metadata record.

11. A machine-implemented method, comprising:

processing, utilizing a processor, a first write operation request to perform a first write operation on a first metadata record in a file system volume of a storage device;

prior to performing the first write operation in the file system volume:

extracting information from the first write operation request;

generating, utilizing the processor, in a namespace storage area of the storage device, a namespace fora first plurality of metadata areas, wherein the namespace comprises multiple values associated with multiple descriptors, wherein the multiple descriptors characterize a respective metadata area of the first plurality of metadata areas, wherein the file system volume comprises the first plurality of metadata areas, wherein the first plurality of metadata areas are configured to store a plurality of metadata records, wherein the plurality of metadata records comprises the first metadata record; and

verifying, utilizing the processor, the first write operation request based on verification logic and based on comparing the extracted information, not all information, of the first write operation request to the multiple values associated with multiple descriptors of the namespace in the namespace storage area of the storage device; and

based on the verifying the first write operation, determining, utilizing the processor, whether to perform the first write operation in the file system volume,

wherein:

the namespace storage area of the storage device is different than and outside of the file system volume of the storage device;

the first metadata record comprises information on usage of data blocks;

the namespace is different from the first metadata record; and

the multiple descriptors of the namespace are independent of peculiarities of a file system and independent of metadata content of the first metadata record.

12. The machine-implemented method of claim 11 , comprising:

processing a first indication to verify a write operation request associated with a category; and

identifying the first plurality of metadata areas in the file system volume of the storage device.

13. The machine-implemented method of claim 12 , wherein the write operation request associated with the category comprises a flag, and

wherein the method comprises identifying the flag in the first write operation request prior to verifying the first write operation request.

14. The machine-implemented method of claim 12 , comprising:

writing the namespace in a dedicated partition of the storage device, wherein the dedicated partition is separate from a partition in the storage device for storing the plurality of metadata records, and

wherein the namespace is stored in a plain text format, a binary format, or Extensible Markup Language (XML) format.

15. The machine-implemented method of claim 12 , comprising:

writing the namespace in a dedicated non-volatile chip that is separate from the storage device for storing the plurality of metadata records.

16. The machine-implemented method of claim 15 , wherein the writing comprises encrypting the namespace, and wherein the verifying comprises extracting a secret key from the first write operation request.

17. The machine-implemented method of claim 12 , wherein the write operation request associated with the category is generated by a file system driver, and wherein the verifying the first write operation request is caused to be performed at a host server in a host-storage system, wherein information in the first write operation request comprises one or more of: a predetermined signature; a node size; a clump size of reservation; and an extent.

18. The machine-implemented method of claim 11 , comprising:

receiving a second indication to disable verification fora write operation request in the file system volume;

receiving a second write operation request fora second write operation on a second metadata record; and

based on the second indication, performing the second write operation without verifying the second write operation request.

19. The machine-implemented method of claim 18 , comprising:

responsive to the second indication, reserving a second plurality of metadata areas without creating a namespace associated therewith, wherein the second plurality of metadata areas comprises a metadata area for a second metadata record.

20. The machine-implemented method of claim 11 , comprising:

generating, by a file system driver, a corrected first write operation request based on verifying the first write operation request, wherein verifying the first write operation request is performed at the storage device.

Assignments (11)
SECURITY AGREEMENT (SUPPLEMENTAL) Recorded Nov 14, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 069411/0208 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2024
From: SANDISK TECHNOLOGIES, INC.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 069168/0273 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052915 FRAME 0566 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 059127/0001 →
SECURITY INTEREST Recorded Feb 6, 2020
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS AGENT
Reel/Frame 052915/0566 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2019
From: DUBEYKO, VIACHESLAV; MANZANARES, ADAM
To: HGST NETHERLANDS B.V.
Reel/Frame 049962/0773 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2019
From: HGST NETHERLANDS B.V.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 049965/0010 →