Storage system using mapping information and cloud system including the same
A storage system includes a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users, a controller configured to receive mapping information, which is information about the plurality of user storage spaces, from an external computing device that performs an operation for each of the plurality of users through a plurality of virtual machines, and a memory storing the mapping information, wherein the controller is configured to generate, when receiving the mapping information, different user keys for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and user keys.
1 . A storage system comprising:
a plurality of storage devices including a plurality of user storage spaces allocated to each of a plurality of users;
a controller configured to receive mapping information about the plurality of user storage spaces, from an external computing device configured to perform an operation for each of the plurality of users through a plurality of virtual machines; and
a memory configured to store the mapping information,
wherein the controller is configured to generate a user key for each of the plurality of user storage spaces, based on the mapping information, in response to the controller receiving the mapping information, wherein each user key is unique to each of the plurality of user storage spaces, and
wherein the controller is further configured to manage user data stored in the plurality of storage devices by using the mapping information and the user keys.
2 . The storage system of claim 1 , wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
3 . The storage system of claim 1 , wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the external computing device.
4 . The storage system of claim 1 , wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the external computing device, in response to the controller receiving a data read request from the external computing device.
5 . The storage system of claim 1 , wherein the controller is configured to determine whether to encrypt the user data using the user keys, based on encryption function usage setting of each of the plurality of users.
6 . The storage system of claim 1 , wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to a user withdrawal request, in response to the controller receiving the user withdrawal request from the external computing device.
7 . The storage system of claim 1 , wherein the controller is configured to transmit a mapping information request to the external computing device and receive the mapping information from the external computing device in response to the storage system being reset or rebooted.
8 . A storage system comprising:
a plurality of storage devices comprising a plurality of user storage spaces allocated to each of a plurality of users;
a controller configured to
transmit a mapping information request to an external computing device that performs an operation for each of the plurality of users through a plurality of virtual machines, in response to the storage system being reset or rebooted,
receive mapping information about the plurality of user storage spaces, from the external computing device,
generate a user key for each of the plurality of user storage spaces, based on the mapping information, wherein each user key is unique to each of the plurality of user storage spaces, and
manage user data stored in the plurality of storage devices by using the mapping information and the user keys; and
a memory storing the mapping information.
9 . The storage system of claim 8 , wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
10 . The storage system of claim 8 , wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the external computing device.
11 . The storage system of claim 8 , wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the external computing device, in response to the controller receiving a data read request from the external computing device.
12 . The storage system of claim 8 , wherein the controller is configured to determine whether to encrypt the user data using the user keys, based on encryption function usage setting of each of the plurality of users.
13 . The storage system of claim 8 , wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to a user withdrawal request, in response to the controller receiving the user withdrawal request from the external computing device.
14 . A cloud system comprising:
a plurality of storage systems configured to store user data of each of a plurality of users; and
a plurality of computing devices configured to perform an operation for each of the plurality of users through a plurality of virtual machines and transmit to the plurality of storage systems, mapping information about a plurality of user storage spaces allocated to each of the plurality of users,
wherein the plurality of storage systems includes,
a plurality of storage devices comprising the plurality of user storage spaces allocated to each of the plurality of users;
a controller configured to generate a user key for each of the plurality of user storage spaces, based on the mapping information, and manage user data stored in the plurality of storage devices by using the mapping information and the user keys, in response to the controller receiving the mapping information, wherein each user key is unique to each of the plurality of user storage spaces; and
a memory storing the mapping information.
15 . The cloud system of claim 14 , wherein the plurality of computing devices are configured to
create a virtual machine in response to receiving a user sign-up request from an external user device,
allocate a user storage space inside the plurality of storage systems,
generate mapping information, and
transmit the mapping information to the plurality of storage systems.
16 . The cloud system of claim 14 , wherein the mapping information comprises at least one of user storage space identification information, computing device identification information, virtual machine identification information, storage system identification information, storage device identification information, and logic block address information.
17 . The cloud system of claim 14 , wherein the controller is configured to encrypt write data corresponding to the data write request by using the user keys, and write the encrypted write data to the plurality of storage devices, based on the mapping information, in response to the controller receiving a data write request from the plurality of computing devices.
18 . The cloud system of claim 14 , wherein the controller is configured to read encrypted read data corresponding to the data read request, from the plurality of storage devices, based on the mapping information, decrypt the encrypted read data by using the user keys, and transmit the decrypted read data to the plurality of computing devices, in response to the controller receiving a data read request from the plurality of computing devices.
19 . The cloud system of claim 14 , wherein the plurality of computing devices are configured to transmit a user withdrawal request to the controller, and
wherein the controller is configured to remove the mapping information, the user keys, and the user data corresponding to the user withdrawal request, in response to the controller receiving the user withdrawal request.
20 . The cloud system of claim 14 , wherein the controller is configured to transmit a mapping information request to the plurality of computing devices in response to the controller receiving the plurality of storage systems are reset or rebooted, and
wherein the plurality of computing devices are configured to transmit the mapping information to the controller in response to the controller receiving the mapping information request.