IP Library Granted Patent US 10,789,179
Granted Patent B1
US 10,789,179 · App. 15/895,653 · Granted Sep 29, 2020

Decentralized access management in information processing system utilizing persistent memory

Inventors: Stephen J. Todd (Shrewsbury, MA); Kenneth Durazzo (San Jose, CA)
Assignee: EMC IP Holding Company LLC
G06F12/1458G06F21/602H04L9/0637H04L9/0816H04L9/3242G06F2212/1052G06F2212/154
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,789,179
App. No.
15/895,653
Granted
Sep 29, 2020
Kind
B1
Abstract

In an information processing system comprising a set of computing devices wherein each computing device comprises a set of persistent memory modules resident in the computing device, and wherein one or more data structures associate one or more application programs executing on the set of computing devices with one or more memory regions of the set of persistent memory modules such that the one or more data structures are utilized to route data between a given one of the application programs and at least one memory region, maintaining a distributed ledger system with a plurality of nodes, wherein the set of computing devices is operatively coupled to the plurality of nodes of the distributed ledger system, and managing one or more data access requests by a given application program to a memory region of a persistent memory module in consultation with the distributed ledger system.

Claims (43)

1. A method comprising:

in an information processing system comprising a set of computing devices wherein each computing device comprises a set of persistent memory modules resident in the computing device, and wherein one or more data structures associate one or more application programs executing on the set of computing devices with one or more memory regions of the set of persistent memory modules such that the one or more data structures are utilized to route data between a given one of the application programs and at least one memory region;

maintaining a distributed ledger system with a plurality of nodes, wherein the set of computing devices is operatively coupled to the plurality of nodes of the distributed ledger system; and

managing one or more data access requests by a given application program to a memory region of a persistent memory module in consultation with the distributed ledger system by storing transaction data in the distributed ledger system that represents at least one of routing information, identity information, and binding information associated with the one or more application programs and the set of persistent memory modules;

wherein the association generated by the one or more data structures forms a per tenant binding between a given one of the application programs and at least one memory region; and

wherein the method is implemented via one or more processing devices each comprising a processor coupled to a memory.

2. The method of claim 1 , wherein the data access managing step further comprises verifying the identity of the given application program making the one or more data access requests based on the transaction data stored in the distributed ledger system.

3. The method of claim 2 , wherein the data access managing step further comprises rejecting the one or more data access requests when the identity of the given application program making the one or more data access requests is not verified.

4. The method of claim 1 , wherein the set of computing devices are associated with one or more data centers, and further comprising:

assigning a unique cryptographic private key to each of the one or more data centers to enable the one or more data centers to sign and publish their configurations on the distributed ledger system using their assigned cryptographic private key.

5. The method of claim 4 , wherein each of the one or more data centers creates transaction data stored in the distributed ledger system specifying routing information for their configuration.

6. The method of claim 5 , wherein the configuration is represented by a mapping of a given application program to the one or more memory regions of the set of persistent memory modules associated with computing devices of the given data center.

7. The method of claim 6 , wherein the mapping is stored as transaction data in the distributed ledger system.

8. The method of claim 4 , wherein each of the one or more data centers creates transaction data stored in the distributed ledger system specifying security information.

9. The method of claim 1 , further comprising assigning a unique cryptographic private key to each of the one or more application programs to enable the one or more application programs to sign and publish identity information on the distributed ledger system as transaction data using their assigned cryptographic private key.

10. The method of claim 9 , wherein the unique cryptographic private key assigned to each of the one or more application programs is also used to sign and publish binding information on the distributed ledger system as transaction data.

11. The method of claim 10 , wherein the binding information specifies a binding between a given one of the application programs and one or more memory regions of a given one of the persistent memory modules.

12. The method of claim 9 , wherein a unique cryptographic public key, associated with the assigned cryptographic private key as part of a key pair, is assigned to each of the one or more application programs.

13. The method of claim 12 , further comprising providing the cryptographic public key for a given one of the application programs to a given one of the set of computing devices to which the given application program is deployed via a container assignment request.

14. The method of claim 1 , further comprising one of the application programs extending data access permission to another one of the application programs by creating transaction data that specifies the extended permission and storing the transaction data in the distributed ledger system.

15. The method of claim 14 , further comprising a given one of the computing devices validating the other application program by consulting the transaction data stored on the distributed ledger system to verify the extended permission.

16. The method of claim 1 , wherein the one or more data structures further comprise an identifier field for specifying the given one of the application programs and the given tenant.

17. A system comprising:

one or more processing devices operatively coupled to one or more memories having program logic, which when executed by the one or more processing devices, are configured to:

in an information processing system comprising a set of computing devices wherein each computing device comprises a set of persistent memory modules resident in the computing device, and wherein one or more data structures associate one or more application programs executing on the set of computing devices with one or more memory regions of the set of persistent memory modules such that the one or more data structures are utilized to route data between a given one of the application programs and at least one memory region;

maintain a distributed ledger system with a plurality of nodes, wherein the set of computing devices is operatively coupled to the plurality of nodes of the distributed ledger system; and

manage one or more data access requests by a given application program to a memory region of a persistent memory module in consultation with the distributed ledger system by storing transaction data in the distributed ledger system that represents at least one of routing information, identity information, and binding information associated with the one or more application programs and the set of persistent memory modules;

wherein the association generated by the one or more data structures forms a per tenant binding between a given one of the application programs and at least one memory region.

18. The system of claim 17 , wherein the program logic, which when executed by the one or more processing devices, is configured to perform at least one of the following:

a) assigning a unique cryptographic private key to each of the one or more application programs to enable the one or more application programs to sign and publish identity information on the distributed ledger system as transaction data using their assigned cryptographic private key;

wherein the unique cryptographic private key assigned to each of the one or more application programs is also used to sign and publish binding information on the distributed ledger system as transaction data; and

wherein the binding information specifies a binding between a given one of the application programs and one or more memory regions of a given one of the persistent memory modules; and

b) extending by one of the application programs data access permission to another one of the application programs by creating transaction data that specifies the extended permission and storing the transaction data in the distributed ledger system.

19. An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processor causes said at least one processor to:

in an information processing system comprising a set of computing devices wherein each computing device comprises a set of persistent memory modules resident in the computing device, and wherein one or more data structures associate one or more application programs executing on the set of computing devices with one or more memory regions of the set of persistent memory modules such that the one or more data structures are utilized to route data between a given one of the application programs and at least one memory region;

maintain a distributed ledger system with a plurality of nodes, wherein the set of computing devices is operatively coupled to the plurality of nodes of the distributed ledger system; and

manage one or more data access requests by a given application program to a memory region of a persistent memory module in consultation with the distributed ledger system by storing transaction data in the distributed ledger system that represents at least one of routing information, identity information, and binding information associated with the one or more application programs and the set of persistent memory modules;

wherein the association generated by the one or more data structures forms a per tenant binding between a given one of the application programs and at least one memory region.

20. The article of manufacture of claim 19 , wherein the program code when executed by at least one processor causes said at least one processor to perform at least one of the following:

a) assign a unique cryptographic private key to each of the one or more application programs to enable the one or more application programs to sign and publish identity information on the distributed ledger system as transaction data using their assigned cryptographic private key;

wherein the unique cryptographic private key assigned to each of the one or more application programs is also used to sign and publish binding information on the distributed ledger system as transaction data; and

wherein the binding information specifies a binding between a given one of the application programs and one or more memory regions of a given one of the persistent memory modules; and

b) extend by one of the application programs data access permission to another one of the application programs by creating transaction data that specifies the extended permission and storing the transaction data in the distributed ledger system.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (046366/0014) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060450/0306 →
RELEASE OF SECURITY INTEREST AT REEL 046286 FRAME 0653 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0093 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 8, 2018
From: TODD, STEPHEN J.; DURAZZO, KENNETH
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046580/0868 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046286/0653 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 046366/0014 →