IP Library Granted Patent US 11,223,484
Granted Patent B1
US 11,223,484 · App. 16/802,382 · Granted Jan 11, 2022

Enhanced authentication method for Hadoop job containers

Inventor: Dong Wang (Scarborough, CA)
Assignee: EMC IP Holding Company LLC
H04L9/3247G06F9/4843G06F16/182H04L9/0861H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,223,484
App. No.
16/802,382
Granted
Jan 11, 2022
Kind
B1
Abstract

Embodiments for providing content authentication of data in a network having a name node and a data node which may be in a Hadoop Distributed File System (HDFS) network, by associating each data set of the data with a first key identifying a job owner issuing a task for the data set, the first key being a session key that is randomly generated for the task, generating a second identity value for the data set on the data node, and performing the task if the second identity value matches the first key.

Claims (35)

1. A method of providing content authentication of data in a network having a name node and a data node, comprising:

generating, by a first processing engine on the name node, a first identity value for the content through job specific files and encryption elements;

generating, by a second processing engine on the data node, a second identity value for the content through the job specific files and encryption elements;

associating each data set of the data with a first key identifying a job owner issuing a task for the data set, the first key being a session key that is randomly generated for the task;

and

performing the task if the first identity value matches the second identity value.

2. The method of claim 1 further comprising: packaging the data sets in job specific files into execution containers in a Hadoop Distributed File System (HDFS) network cluster.

3. The method of claim 1 wherein the encryption elements comprise a unique key and an initial value.

4. The method of claim 3 , wherein the unique key comprises a value indicating an identity of a job owner issuing the task, and wherein the initial value comprises a unique session key that is randomly generated for the task.

5. The method of claim 4 further comprising, for each of the first and second processing engines, inputting the job specific files and the unique key into a digestion function to generate digested code, wherein the digestion function comprises a cryptographic hash function.

6. The method of claim 5 wherein the first processing engine comprises a first file signing engine and the second processing engine comprises a second file signing engine, the method further comprising, for each of the first and second file signing engine components, inputting the digested code and the initial value into a combining function to generate a respective identity value of the first and second identity values.

7. The method of claim 6 wherein each of the unique key, initial value, and digested code are of a bit length, k.

8. The method of claim 1 wherein the data node comprises a plurality of data nodes, and wherein the job containers are spread across the plurality of data nodes for execution of the task processing the content.

9. A system of providing content authentication of data in a network having a name node and a data node, comprising:

first hardware processing means of the name node generating a first identity value for the content through job specific files and encryption elements;

second hardware processing means of the data node generating a second identity value for the content through the job specific files and encryption elements;

third hardware processing means associating each data set of the data with a first key identifying a job owner issuing a task for the data set, the first key being a session key that is randomly generated for the task, and performing the task if the first identity value matches the second identity value, wherein the hardware processing means comprise at least a processor and a memory.

10. The system of claim 9 further comprising: a component packaging the data sets in job specific files into execution containers in a Hadoop Distributed File System (HDFS) network cluster.

11. The system of claim 9 wherein the encryption elements comprise a unique key and an initial value.

12. The system of claim 11 wherein the unique key comprises a value indicating an identity of a job owner issuing the task, and wherein the initial value comprises a unique session key that is randomly generated for the task.

13. The system of claim 11 wherein each of the unique key, initial value, and first and second digested codes are of a bit length, k.

14. The system of claim 9 wherein the first hardware processing means comprises:

a first digestion function receiving the unique key and the job specific files to generate first digested code; and

a first combining function receiving the initial value and the first digested code to generate the first identity value for the name node.

15. The system of claim 14 wherein each of the first and second hardware processing means comprises a cryptographic hash function.

16. The system of claim 9 wherein the second hardware processing means comprises:

a second digestion function receiving the unique key and the job specific files to generate second digested code; and

a second combining function receiving the initial value and the second digested code to generate the second identity value for the data node.

17. The system of claim 9 wherein the data node comprises a plurality of data nodes, and wherein the job containers are spread across the plurality of data nodes for execution of the task processing the content.

18. A computer program product, comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein, the computer-readable program code adapted to be executed by one or more processors to perform a method of providing content authentication of data in a network having a name node and a data node, comprising:

generating, by a first processing engine on the name node, a first identity value for the content through job specific files and encryption elements;

generating, by a second processing engine on the data node, a second identity value for the content through the job specific files and encryption elements;

associating each data set of the data with a first key identifying a job owner issuing a task for the data set, the first key being a session key that is randomly generated for the task;

and

performing the task if the first identity value matches the second identity value.

Assignments (12)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0081) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0441 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052851/0917) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0509 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052852/0022) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0582 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 052771 FRAME 0906 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0298 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC; THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0081 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052851/0917 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052852/0022 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded May 28, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052771/0906 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →