IP Library › Granted Patent US 11,573,719
Granted Patent B2
US 11,573,719 · App. 16/831,337 · Granted Feb 7, 2023

PMEM cache RDMA security

Inventors: Wei Zhang (Foster City, CA); Jia Shi (Campbell, CA); Zuoyu Tao (Belmont, CA); Kothanda Umamageswaran (Sunnyvale, CA)
Assignee: Oracle International Corporation
G06F3/064G06F3/067G06F3/0646G06F3/0685G06F9/3816G06F12/1081G06F16/906G06F3/0607
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,573,719
App. No.
16/831,337
Granted
Feb 7, 2023
Kind
B2
Abstract

Techniques are described for providing one or more clients with direct access to cached data blocks within a persistent memory cache on a storage server. In an embodiment, a storage server maintains a persistent memory cache comprising a plurality of cache lines, each of which represent an allocation unit of block-based storage. The storage server maintains an RDMA table that include a plurality of table entries, each of which maps a respective client to one or more cache lines and a remote access key. An RDMA access request to access a particular cache line is received from a storage server client. The storage server identifies access credentials for the client and determines whether the client has permission to perform the RDMA access on the particular cache line. Upon determining that the client has permissions, the cache line is accessed from the persistent memory cache and sent to the storage server client.

Claims (83)

1. A method comprising:

a storage server maintaining a persistent memory (PMEM) cache comprising a plurality of cache lines, each cache line of said plurality of cache lines caching an allocation unit of block-based storage managed by said storage server;

the storage server maintaining a Remote Direct Memory Access (RDMA) table that includes a plurality of table entries, each table entry of said plurality of table entries:

mapping a respective storage server client of a plurality of storage server clients to respective one or more cache lines of said plurality of cache lines that cache an allocation unit for said respective storage server client, and

including a respective remote access key value for accessing said respective one or more cache lines using RDMA access;

establishing an RDMA connection between said storage server and a particular storage server client of said plurality of storage server clients;

after establishing said RDMA connection, said storage server sending one or more table entries of said plurality of table entries to said particular storage server client, said one or more table entries including a particular table entry of said plurality of table entries that includes a particular remote access key value for a particular cache line of said plurality of cache lines;

after sending one or more table entries, receiving, via said RDMA connection from said particular storage se client, a RDMA request to access said particular cache line, said RDMA request including said particular remote access key value included in said particular table entry;

identifying, by the storage server, access credentials associated with the particular storage server client;

determining whether the particular storage server client has permission to perform an RDMA access to the particular cache line based on the access credentials and the particular remote access key value; and

upon determining that the particular storage server client has permission to perform the RDMA access, accessing and sending the particular cache line from said PMEM cache to the particular storage server client.

2. The method of claim 1 , further comprising, upon determining that the particular storage server client does not have permission to perform the RDMA access, terminating a connection between the particular storage server client and the storage server.

3. The method of claim 1 , wherein said RDMA connection is between a first host channel adapter on the particular storage server client and a second host channel adapter on the storage server.

4. The method of claim 1 , wherein the RDMA table is stored within the PMEM cache.

5. The method of claim 1 ,

wherein the RDMA request to access the particular cache line originated from a database process for a particular database cluster and particular database instantiated on the particular storage server client; and

wherein the access credentials are based on the particular database cluster and the particular database.

6. The method of claim 1 , wherein determining whether the particular storage server client has permission to perform the RDMA access to the particular cache line, comprises:

accessing, in the RDMA table, a record associated with the particular cache line using the particular remote access key value;

determining whether access credentials associated with the record match the access credentials associated with the particular storage server client.

7. The method of claim 6 , wherein determining whether the particular storage server client has permission to perform the RDMA access to the particular cache line is performed by a host channel adapter on the storage server.

8. The method of claim 1 , further comprising:

prior to receiving the RDMA request to access the particular cache line, receiving, from the particular storage server client, a request to access one or more data blocks stored on the storage server;

identifying, by the storage server, the access credentials associated with the particular storage server client;

determining whether a copy of the one or more data blocks is stored in the PMEM cache;

upon determining that the copy of the one or more data blocks are not stored in the PMEM cache:

allocating, by the storage server, one or more cache lines in the PMEM cache for storing the copy of the one or more data blocks;

associating, by the storage server, the one or more cache lines to the particular storage server client;

loading, by the storage server, the copy of the one or more data blocks into the one or more cache lines;

sending the copy of the one or more data blocks to the particular storage server client.

9. The method of claim 1 , further comprising:

prior to receiving the RDMA request to access the particular cache line:

receiving, from the particular storage server client, a request to access one or more data blocks stored on the storage server;

determining whether the particular storage server client is associated with the access credentials;

upon determining that the particular storage server client is not associated with the access credentials, generating, by the storage server, the access credentials for the particular storage server client based on a particular database cluster and a particular database associated with the particular storage server client;

allocating, by the storage server, one or more cache lines in the PMEM cache for storing a copy of the one or more data blocks;

associating, by the storage server, the one or more cache lines to the particular storage server client;

loading, by the storage server, the copy of the one or more data blocks into the one or more cache lines;

sending the copy of the one or more data blocks to the particular storage server client.

10. The method of claim 9 , wherein generating the access credentials for the particular storage server client comprises:

generating an access credential value based on the particular database cluster and the particular database associated with the particular storage server client;

storing the access credential value in a data structure loaded in volatile memory and associated with the RDMA table.

11. One or more non-transitory storage media storing one or more sequences of instructions which, when executed by one or more computing devices, cause:

a storage server maintaining a persistent memory (PMEM) cache comprising a plurality of cache lines, each cache line of said plurality of cache lines caching an allocation unit of block-based storage managed by said storage server;

the storage server maintaining a Remote Direct Memory Access (RDMA) table that includes a plurality of table entries, each table entry of said plurality of table entries:

mapping a respective storage server client of a plurality of storage server clients to respective one or more cache lines of said plurality of cache lines that cache an allocation unit for said respective storage server client, and

including a respective remote access key value for accessing said respective one or more cache lines using RDMA access;

establishing an RDMA, connection between said storage server and a particular storage server client of said plurality of storage server clients;

after establishing said RDMA connection, said storage server sending one or more table entries of said plurality of table entries to said particular storage server client, said one or more table entries including a particular table entry of said plurality of table entries that includes a particular remote access key value for a particular cache line of said plurality of cache lines;

after sending one or more table entries, receiving, via said RDMA connection from said particular storage server client, a RDMA request to access said particular cache line, said RDMA request including said particular remote access key value included in said particular table entry;

identifying, by the storage server, access credentials associated with the particular storage server client;

determining whether the particular storage server client has permission to perform an RDMA access to the particular cache line based on the access credentials and the particular remote access key value; and

upon determining that the particular storage server client has permission to perform the RDMA access, accessing and sending the particular cache line from said PMEM cache to the particular storage server client.

12. The one or more non-transitory computer-readable media of claim 11 , wherein the one or more sequences of instructions include instruction that, when executed by said one or more computing devices cause upon determining that the particular storage server client does not have permission to perform the RDMA access, terminating a connection between the particular storage server client and the storage server.

13. The one or more non-transitory computer-readable media of claim 11 , wherein said RDMA connection is between a first host channel adapter on the particular storage server client and a second host channel adapter on the storage server.

14. The one or more non-transitory computer-readable media of claim 11 , wherein the RDMA table is stored within the PMEM cache.

15. The one or more non-transitory computer-readable media of claim 11 ,

wherein the RDMA request to access the particular cache line originated from a database process for a particular database cluster and particular database instantiated on the particular storage server client; and

wherein the access credentials are based on the particular database cluster and the particular database.

16. The one or more non-transitory computer-readable media of claim 11 , wherein determining whether the particular storage server client has permission to perform the RDMA access to the particular cache line, comprises:

accessing, in the RDMA table, a record associated with the particular cache line using the particular remote access key value;

determining whether access credentials associated with the record match the access credentials associated with the particular storage server client.

17. The one or more non-transitory computer-readable media of claim 16 , wherein determining whether the particular storage server client has permission to perform the RDMA access to the particular cache line is performed by a host channel adapter on the storage server.

18. The one or more non-transitory computer-readable media of claim 11 , wherein the one or more sequences of instructions include instruction that, when executed by said one or more computing devices cause:

prior to receiving the RDMA request to access the particular cache line, receiving, from the particular storage server client, a request to access one or more data blocks stored on the storage server;

identifying, by the storage server, the access credentials associated with the particular storage server client;

determining whether a copy of the one or more data blocks is stored in the PMEM cache;

upon determining that the copy of the one or more data blocks are not stored in the PMEM cache:

allocating, by the storage server, one or more cache lines in the PMEM cache for storing the copy of the one or more data blocks;

associating, by the storage server, the one or more cache lines to the particular storage server client;

loading, by the storage server, the copy of the one or more data blocks into the one or more cache lines;

sending the copy of the one or more data blocks to the particular storage server client.

19. The one or more non-transitory computer-readable media of claim 11 , wherein the one or more sequences of instructions include instruction that, when executed by said one or more computing devices cause:

prior to receiving the RDMA request to access the particular cache line, receiving, from the particular storage server client, a request to access one or more data blocks stored on the storage server;

determining whether the particular storage server client is associated with the access credentials;

upon determining that the particular storage server client is not associated with the access credentials, generating, by the storage server, the access credentials for the particular storage server client based on a particular database cluster and a particular database associated with the particular storage server client;

allocating, by the storage server, one or more cache lines in the PMEM cache for storing a copy of the one or more data blocks;

associating, by the storage server, the one or more cache lines to the particular storage server client;

loading, by the storage server, the copy of the one or more data blocks into the one or more cache lines;

sending the copy of the one or more data blocks to the particular storage server client.

20. The one or more non-transitory computer-readable media of claim 19 , wherein generating the access credentials for the particular storage server client comprises:

generating an access credential value based on the particular database cluster and the particular database associated with the particular storage server client;

storing the access credential value in a data structure loaded in volatile memory and associated with the RDMA table.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2020
From: ZHANG, WEI; SHI, JIA; TAO, ZUOYU; UMAMAGESWARAN, KOTHANDA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 052238/0588 →
Continuity (1)
Related Publication 20210303154A1 · Sep 30, 2021