IP Library Granted Patent US 9,684,453
Granted Patent B2
US 9,684,453 · App. 14/555,289 · Granted Jun 20, 2017

Cluster federation and trust in a cloud environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,684,453
App. No.
14/555,289
Granted
Jun 20, 2017
Kind
B2
Abstract

An improved scalable object storage system allows multiple clusters to work together. In one embodiment, a trust and federation relationship is established between a first cluster and a second cluster. This is done by designating a first cluster as a trust root. The trust root receives contact from another cluster, and the two clusters exchange cryptographic credentials. The two clusters mutually authenticate each other based upon the credentials, and optionally relative to a third information service, and establish a service connection. Services from the remote cluster are registered as being available to the cluster designated as the trust root. Multi-cluster gateways can also be designated as the trust root, and joined clusters can be mutually untrusting. Two one-way trust and federation relationships can be set up to form a trusted bidirectional channel.

Claims (38)

1. A method, comprising:

designating a first cluster as a trust root, the first cluster including a first set of containers, each container of the first set of containers being based on one or more user accounts;

setting a first user account in the first set of clusters to synchronize with a second user account in a second cluster, the first user account being specified by an authentication response uniform resource locator (URL);

after a period of time has elapsed, synchronizing the second user account with the first user account; and

switching, based on the synchronizing, the authentication response URL from the first cluster to the second cluster, wherein after the switching, the second user account is specified by the authentication response URL.

2. The method of claim 1 , wherein the first cluster is controlled by a first cloud service provider.

3. The method of claim 2 , wherein the second cluster is controlled by the first cloud service provider.

4. The method of claim 2 , wherein the second cluster is controlled by a second cloud service provider different from the first cloud service provider.

5. The method of claim 1 , further including:

receiving contact from the second cluster at the trust root over a communications medium, wherein the second cluster includes a second set of containers, and each container of the second set of containers is based on one or more user accounts.

6. The method of claim 1 , further including:

providing account tokens to the first cluster.

7. The method of claim 6 , further including:

revoking, based on the switching, the account tokens.

8. The method of claim 1 , further including:

setting, based on the switching, the first user account into a read-only mode.

9. The method of claim 8 , further including:

turning off the synchronizing from the first user account to the second user account.

10. The method of claim 1 , further including:

after a second period of time has elapsed, purging the first account.

11. A system, comprising:

a first cluster including a plurality of information processing devices, wherein the first cluster includes a first set of containers, and each container of the first set of containers is based on one or more user accounts; and

a first cluster controller that, by one or more hardware processors, sets a first user account in the first set of clusters to synchronize with a second user account in a second cluster, wherein after a period of time has elapsed, the first cluster controller synchronizes the second user account with the first user account,

wherein the first user account is specified by an authentication response uniform resource locator (URL), and the first cluster controller switches, based on the synchronizing, the authentication response URL from the first cluster to the second cluster, wherein after the first cluster controller switches the authentication response URL from the first cluster to the second cluster, the second user account is specified by the authentication response URL.

12. The system of claim 11 , wherein the first cluster is controlled by a first cloud service provider.

13. The system of claim 12 , wherein the second cluster is controlled by the first cloud service provider.

14. The system of claim 12 , wherein the second cluster is controlled by a second cloud service provider different from the first cloud service provider.

15. The system of claim 11 , wherein the first cluster controller receives contact from the second cluster at the trust root over a communications medium, and wherein the second cluster includes a second set of containers, and each container of the second set of containers is based on one or more user accounts.

16. The system of claim 11 , wherein the first cluster controller sets, based on the switching, the first user account into a read-only mode.

17. The system of claim 16 , wherein the first cluster controller turns off the synchronizing from the first user account to the second user account.

18. The system of claim 17 , wherein after a second period of time has elapsed, the first cluster controller purges the first account.

19. A non-transitory machine-readable medium comprising a plurality of machine-readable instructions that when executed by one or more processors is adapted to cause the one or more processors to perform a method comprising:

designating a first cluster as a trust root, the first cluster including a first set of containers, each container of the first set of containers being based on one or more user accounts;

setting a first user account in the first set of clusters to synchronize with a second user account in a second cluster, the first user account being specified by an authentication response uniform resource locator (URL);

after a period of time has elapsed, synchronizing the second user account with the first user account; and

switching, based on the synchronizing, the authentication response URL from the first cluster to the second cluster, wherein after the switching, the second user account is specified by the authentication response URL.

20. The machine-readable medium of claim 19 , the method further including:

receiving contact from the second cluster at the trust root over a communications medium, wherein the second cluster includes a second set of containers, and each container of the second set of containers is based on one or more user accounts.

Assignments (5)
RELEASE OF PATENT SECURITIES Recorded Mar 13, 2024
From: CITIBANK, N.A.
To: RACKSPACE US, INC.
Reel/Frame 066795/0177 →
SECURITY AGREEMENT (FIRST LIEN) Recorded Mar 13, 2024
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066795/0282 →
CORRECTIVE ASSIGNMENT TO CORRECT THE DELETE PROPERTY NUMBER PREVIOUSLY RECORDED AT REEL: 40564 FRAME: 914. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 21, 2019
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 048658/0637 →
SECURITY AGREEMENT Recorded Nov 4, 2016
From: RACKSPACE US, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 040564/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2015
From: HOLT, GREGORY LEE; GERRARD, CLAY; GOETZ, DAVID PATRICK; BARTON, MICHAEL
To: RACKSPACE US, INC.
Reel/Frame 035193/0567 →