IP Library Granted Patent US 10,615,984
Granted Patent B1
US 10,615,984 · App. 15/723,418 · Granted Apr 7, 2020

Enhanced authentication method for Hadoop job containers

Inventor: Dong Wang (Scarborough, CA)
Assignee: EMC IP Holding Company LLC
H04L9/3247G06F9/4843G06F16/182H04L9/0861H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,615,984
App. No.
15/723,418
Granted
Apr 7, 2020
Kind
B1
Abstract

Embodiments for providing content authentication of job containers in a Hadoop Distributed File System (HDFS) network cluster having a name node and a data node, by inputting job specific files and encryption elements into a file signing engine component executed on the name node to generate a first identity value for the content; inputting the job specific files and the encryption elements into a file signing engine component executed on the data node to generate a second identity value for the content; comparing the first identity value with the second identity value; and proceeding with a task processing the content if the comparing yields a match or aborting the task if the comparing does not yield a match.

Claims (34)

1. A method of providing content authentication of job containers in a Hadoop Distributed File System (HDFS) network cluster having a name node and a data node, comprising:

inputting job specific files and encryption elements into a first file signing engine component executed on the name node to generate a first identity value for the content;

inputting the job specific files and the encryption elements into a second file signing engine component executed on the data node to generate a second identity value for the content;

comparing the first identity value with the second identity value; and

proceeding with a task processing the content if the comparing yields a match or aborting the task if the comparing does not yield a match,

wherein the encryption elements comprise a unique key and an initial value, and the unique key comprises a value indicating an identity of a job owner issuing the task, and further wherein the initial value comprises a unique session key that is randomly generated for the task.

2. The method of claim 1 further comprising, for each of the first and second file signing engine components, inputting the job specific files and the unique key into a digestion function to generate digested code, wherein the digestion function comprises a cryptographic hash function.

3. The method of claim 2 further comprising, for each of the first and second file signing engine components, inputting the digested code and the initial value into a combining function to generate a respective identity value of the first and second identity values.

4. The method of claim 3 wherein each of the unique key, initial value, and digested code are of a bit length, k.

5. The method of claim 1 wherein the data node comprises a plurality of data nodes, and wherein the job containers are spread across the plurality of data nodes for execution of the task processing the content.

6. A system of providing content authentication of job containers in a Hadoop Distributed File System (HDFS) network cluster having a name node and a data node, comprising:

a first file signing engine component executed on the name node receiving job specific files and encryption elements to generate a first identity value for the content;

a second file signing engine component executed on the data node receiving job specific files and encryption elements to generate a second identity value for the content;

a comparator comparing the first identity value with the second identity value; and

an execution component proceeding with a task processing the content if the comparing yields a match or aborting the task if the comparing does not yield a match,

wherein the encryption elements comprise a unique key and an initial value, and the unique key comprises a value indicating an identity of a job owner issuing the task, and further wherein the initial value comprises a unique session key that is randomly generated for the task.

7. The system of claim 6 wherein the first file signing engine comprises:

a first digestion function receiving the unique key and the job specific files to generate first digested code;

a first combining function receiving the initial value and the first digested code to generate the first identity value for the name node.

8. The system of claim 7 wherein the second file signing engine comprises:

a second digestion function receiving the unique key and the job specific files to generate second digested code;

a second combining function receiving the initial value and the second digested code to generate the second identity value for the data node.

9. The system of claim 8 wherein each of the first and second digestion functions comprises a cryptographic hash function.

10. The system of claim 9 wherein each of the unique key, initial value, and first and second digested codes are of a bit length, k.

11. The system of claim 10 wherein the data node comprises a plurality of data nodes, and wherein the job containers are spread across the plurality of data nodes for execution of the task processing the content.

12. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code adapted to be executed by one or more processors to perform a method of providing content authentication of job containers in a Hadoop Distributed File System (HDFS) network cluster having a name node and a data node, the method comprising:

inputting job specific files and encryption elements into a first file signing engine component executed on the name node to generate a first identity value for the content;

inputting the job specific files and the encryption elements into a second file signing engine component executed on the data node to generate a second identity value for the content;

comparing the first identity value with the second identity value; and

proceeding with a task processing the content if the comparing yields a match or aborting the task if the comparing does not yield a match,

wherein the encryption elements comprise a unique key and an initial value, and the unique key comprising a value indicating an identity of a job owner issuing the task, and further wherein the initial value comprising a unique session key that is randomly generated for the task.

13. The computer program product of claim 12 further comprising, for each of the first and second file signing engine components:

inputting the job specific files and the unique key into a digestion function to generate digested code, wherein the digestion function comprises a cryptographic hash function, and

inputting the digested code and the initial value into a combining function to generate a respective identity value of the first and second identity values.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (044535/0109) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0414 →
RELEASE OF SECURITY INTEREST AT REEL 044535 FRAME 0001 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0475 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 044535/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 044535/0109 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2017
From: WANG, DONG
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 043765/0144 →
Cited By (7)
US 12,314,752 US 12,321,766 US 12,327,133 US 12,381,878 US 12,476,978 US 12,566,654 US 12,671,671