IP Library Granted Patent US 12,475,208
Granted Patent B2
US 12,475,208 · App. 18/669,491 · Granted Nov 18, 2025

Systems and methods for increased security in cluster formation

Inventors: Alay Vyomeshbhai Shah (San Jose, CA); Alexander Michael Bunch (San Jose, CA); Sandeep Goutele (Bangalore, IN); Toms Varghese (Bangalore, IN)
Assignee: Nutanix, Inc.
G06F21/40G06F21/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,208
App. No.
18/669,491
Filed
May 20, 2024
Granted
Nov 18, 2025
Kind
B2
Art Unit
2432
USPC
726/4
Abstract

An apparatus may include one or more processors and non-transitory, computer-readable instructions which, when executed by the one or more processors, cause the one or more processors to receive, using a first security model, an indication to form a cluster including a set of nodes, establish, using the first security model, a connection with the set of nodes, in response to the set of nodes forming the cluster, automatically disable the first security model, and receive, as part of the cluster, using a second security model, a request directed to the cluster.

Claims (32)

1 . An apparatus comprising one or more processors and non-transitory, computer-readable instructions which, when executed by the one or more processors, cause the one or more processors to:

receive, using a first security model, an indication to form a cluster including a set of nodes;

establish a connection with the set of nodes;

in response to the set of nodes forming the cluster, automatically disable the first security model; and

receive, as part of the cluster, using a second security model, a request directed to the cluster.

2 . The apparatus of claim 1 , wherein the first security model is a node-based security model, and wherein the second security model is a cluster-based security model.

3 . The apparatus of claim 1 , wherein the second security model includes quorum-based verification from the set of nodes forming the cluster.

4 . The apparatus of claim 1 , wherein each node of the set of nodes receives, using the first security model, the indication to form the cluster.

5 . The apparatus of claim 1 , wherein disabling the first security model includes closing one or more ports associated with the first security model.

6 . The apparatus of claim 1 , wherein the request directed to the cluster includes a request for a cluster formation status of the cluster.

7 . The apparatus of claim 1 , wherein the second security model includes authenticating requests to the cluster using a cluster-level password.

8 . The apparatus of claim 7 , wherein the indication to form the cluster includes the cluster-level password.

9 . The apparatus of claim 1 , wherein the instructions further cause the one or more processors to transmit one or more messages to the set of nodes to form the cluster.

10 . The apparatus of claim 1 , wherein the instructions further cause the one or more processors to:

provide a status of the set of nodes to a client device using the first security model prior to the first security model being disabled; and

provide a status of the cluster to the client device using the second security model after the first security model is disabled.

11 . A method comprising:

receiving, at a node, using a first security model, an indication to form a cluster comprising a set of nodes;

establishing, by the node, a connection with the set of nodes;

in response to the set of nodes forming the cluster, automatically disabling, by the node, the first security model;

receiving, at the node, as part of the cluster, using a second security model, a request directed to the cluster.

12 . The method of claim 11 , wherein the first security model is a node-based security model, and wherein the second security model is a cluster-based security model.

13 . The method of claim 11 , wherein the second security model includes quorum-based verification from the set of nodes forming the cluster.

14 . The method of claim 11 , wherein each node of the set of nodes receives, using the first security model, the indication to form the cluster.

15 . The method of claim 11 , wherein disabling the first security model includes closing one or more ports associated with the first security model.

16 . The method of claim 11 , wherein the request directed to the cluster includes a request for a cluster formation status of the cluster.

17 . The method of claim 11 , wherein the second security model includes authenticating requests to the cluster using a cluster-level password.

18 . The method of claim 17 , wherein the indication to form the cluster includes the cluster-level password.

19 . The method of claim 11 , further comprising transmitting, by the node, one or more messages to the set of nodes to form the cluster.

20 . The method of claim 11 , further comprising:

providing a status of the set of nodes to a client device using the first security model prior to the first security model being disabled; and

providing a status of the cluster to the client device using the second security model after the first security model is disabled.

Assignments (2)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2024
From: SHAH, ALAY VYOMESHBHAI; BUNCH, ALEXANDER MICHAEL; GOUTELE, SANDEEP; VARGHESE, TOMS
To: NUTANIX, INC.
Reel/Frame 067470/0583 →
Priority Claims (1)
IN 202441015236 · Mar 1, 2024 · national
Continuity (1)
Related Publication 20250278470A1 · Sep 4, 2025
References Cited (29)
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 8863124B1 · Aron · 2014 [cited by applicant]
US 9009106B1 · Aron et al. · 2015 [cited by applicant]
US 9069708B2 · Gill et al. · 2015 [cited by applicant]
US 9336132B1 · Aron et al. · 2016 [cited by applicant]
US 9652265B1 · Narayanasamy et al. · 2017 [cited by applicant]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 20200195743A1 · Jiang · 2020 [cited by examiner]
US 20220222098A1 · Srivastava · 2022 [cited by examiner]
US 20240370306A1 · Hopper · 2024 [cited by examiner]
“Disable SSH access after creation of EKS Cluster #4690”, Jan. 26, 2022, https://groups.google.com/g/rocks-clusters/c/xBEmY8w8DKs?pli=1. [cited by applicant]
AWS, “How do I troubleshoot “Connection refused” or “Connection timed out” errors when I use SSH to connect to my EC2 instance?”, 2025, https://repost.aws/knowledge-center/ec2-linux-resolve-ssh- connection-errors. [cited by applicant]
Broadcom, “VMware Aria Automation 8.14”, 2025, https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-automation/8-14.html. [cited by applicant]
Cano, Ignacio, et al. “Curator: Self-Managing Storage for Enterprise Clusters” (Mar. 27, 2017), from https://www.usenix.org/conference/nsdi17/. [cited by applicant]
Cisco, “Cisco Expressway Cluster Creation and Maintenance”, Dec. 2009, Cisco Expressway X8.10, https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8- 10/Cisco-Expressway-Cluster-Creation-and… [cited by applicant]
Google Groups, “How to configure—user can access to computs node by ssh unless use qsub”, https://groups.google.com/g/rocks-clusters/c/xBEmY8w8DKs?pli=1. [cited by applicant]
Netapp, “Manage SSH Functionality on the management node”, https://docs.netapp.com/us-en/hci/docs/task_mnode_ssh_management.html#disable-or-enable-the-ssh-capability-on-the- management-node-using-netapp-hybrid-cloud-con… [cited by applicant]
Netapp, “Ontap 9 Documentation”, https://docs.netapp.com/us-en/ontap/system-admin/access-cluster-ssh-task.html. [cited by applicant]
Oracle, “Connect to a Cluster Node Through Secure Shell (SSH)”, https://docs.oracle.com/en/cloud/paas/big-data-cloud/csbdi/connect-cluster-node-secure-shell-ssh.html#GUID-84261712-B6BA-4786-AE93-653B4AAF40B1. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix- bible/ (Publication date based on indicated capture date by Archive. org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 17, 2019), from https://nutanixbible.com/. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix- bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix- bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix- bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown). [cited by applicant]
Stack Overflow, “How can I disable SSH on nodes in a GKE node pool?”, Nov. 3, 2022, https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/expressway/config_guide/X8-10/Cisco-Expressway-Cluster-Creation-and-Maintenance… [cited by applicant]
Teleport, “Deploying a High Availability Teleport Cluster”, https://goteleport. com/docs/admin- guides/deploy-a-cluster/high-availability/. [cited by applicant]