IP Library Granted Patent US 10,466,933
Granted Patent B1
US 10,466,933 · App. 16/226,366 · Granted Nov 5, 2019

Establishing a persistent connection with a remote secondary storage system

Inventors: Suresh Bysani Venkata Naga (San Jose, CA); Sudhir Srinivas (Cary, NC); Anubhav Gupta (Sunnyvale, CA)
Assignee: Cohesity, Inc.
G06F3/0664G06F3/0605G06F3/067G06F3/0622G06F3/0634H04L9/0825H04L9/3247H04L9/3263H04L45/745H04L63/02H04L63/10H04L67/1002H04L67/16H04L67/2814H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,466,933
App. No.
16/226,366
Granted
Nov 5, 2019
Kind
B1
Abstract

A first persistent connection pipe is established from a node of a secondary storage system to an access service associated with a cloud service system. A second persistent connection pipe is established from the node of the secondary storage system to the access service. A communication direction role of the second persistent connection pipe is switched to enable the access service to initiate a communication to the node of the secondary storage system via the second persistent pipe.

Claims (30)

1. A method, comprising:

establishing a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;

establishing a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and

reversing communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with a cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe.

2. The method of claim 1 , further comprising establishing a multiplexing protocol on the second persistent connection pipe.

3. The method of claim 2 , wherein the first persistent connection pipe is configured to multiplex a plurality of requests from the node of the secondary storage system.

4. The method of claim 1 , wherein the first persistent connection pipe is established using a first certificate associated with the cloud service system, wherein the first certificate is signed by a private key associated with a trusted third party.

5. The method of claim 4 , wherein the first persistent connection pipe is established using a second certificate associated with the cloud service system, wherein the second certificate is signed by a private key associated with the cloud service system.

6. The method of claim 1 , wherein the access service is configured to host a persistent connection virtualization container, wherein the persistent connection virtualization container is a virtual instance of a microservice.

7. The method of claim 1 , wherein the cloud service system is associated with a load balancer.

8. The method of claim 7 , wherein the load balancer is configured to intercept data packets sent from the secondary storage system to a persistent connection virtualization container.

9. The method of claim 8 , wherein the load balancer is configured to forward the data packets to a first destination of the access service based on a header associated with the data packets.

10. The method of claim 9 , wherein the load balancer is configured to forward the data packets to a second destination port of the access service based on the header associated with the data packets.

11. The method of claim 1 , wherein the first persistent connection pipe and the second persistent connection pipe have a same connection descriptor information.

12. The method of claim 1 , wherein the secondary storage system is located behind a firewall.

13. The method of claim 1 , wherein the first persistent connection pipe and the second persistent connection pipe are established between a persistent connection virtualization receiver container of the access service and a master node of the secondary storage system.

14. A system, comprising:

a processor configured to:

establish a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;

establish a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and

reverse communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with the cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe; and

a memory coupled to the processor and configured to provide the processor with instructions.

15. The system of claim 14 , wherein the processor is further configured to establish a multiplexing protocol on the second persistent connection pipe.

16. The system of claim 14 , wherein the first persistent connection pipe is configured to multiplex a plurality of requests from the node of the secondary storage system.

17. The system of claim 14 , wherein the first persistent connection pipe is established using a first certificate associated with the cloud service system and a second certificate associated with the cloud service system, wherein the first certificate is signed by a private key associated with a trusted third party, and wherein the second certificate is signed by a private key associated with the cloud service system.

18. The system of claim 14 , wherein the cloud service system is associated with a load balancer, wherein the load balancer is configured to intercept data packets sent from the secondary storage system to a persistent connection virtualization container.

19. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

establishing a first persistent connection pipe from a node of a secondary storage system to an access service associated with a cloud service system, wherein the first persistent connection pipe enables the node of the secondary storage system to initiate corresponding communications to the access service associated with the cloud service system;

establishing a second persistent connection pipe from the node of the secondary storage system to the access service associated with the cloud service system, wherein a direction of the second persistent connection pipe is controlled by communication direction roles of the second persistent connection pipe, wherein the node of the secondary storage system has a client role and the access service associated with the cloud service system has a server role; and

reversing communication direction roles of the second persistent connection pipe, wherein a corresponding communication direction role of the node of the secondary storage system is modified from the client role to the server role and a corresponding communication direction role of the access service associated with the cloud service system is modified from the server role to the client role, wherein the reversed communication direction role enables the access service associated with a cloud service system to initiate a communication to the node of the secondary storage system via the second persistent connection pipe.

Assignments (4)
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY (AS SUCCESSOR TO SILICON VALLEY BANK)
To: COHESITY, INC.
Reel/Frame 069584/0498 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
SECURITY INTEREST Recorded Sep 23, 2022
From: COHESITY, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 061509/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2019
From: BYSANI VENKATA NAGA, SURESH; SRINIVAS, SUDHIR; GUPTA, ANUBHAV
To: COHESITY, INC.
Reel/Frame 048559/0215 →
Continuity (1)
Provisional Application 62730458 · Sep 12, 2018
Cited By (2)
US 12,314,326 US 12,542,782