IP Library › Granted Patent US 12,739,241
Granted Patent B2
US 12,739,241 · App. 18/970,856 · Granted Sep 15, 2026

Apparatus and method for managing cloud computing infrastructure access based on dynamic parallel nodes

Inventors: Seok-Ho Son (Daejeon, KR); Dong-Jae Kang (Daejeon, KR); Byoung-Seob Kim (Sejong-si, KR); Soo-Young Kim (Daejeon, KR); Yun-Kon Kim (Daejeon, KR); Seung-Jo Bae (Daejeon, KR); Byeong-Thaek Oh (Sejong-si, KR); Young-Woo Jung (Daejeon, KR)
Assignee: Electronics and Telecommunications Research Institute
H04L63/083H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,241
App. No.
18/970,856
Granted
Sep 15, 2026
Kind
B2
Abstract

Disclosed herein are an apparatus and method for managing cloud computing infrastructure access based on dynamic parallel nodes. The apparatus for managing cloud computing infrastructure access based on dynamic parallel nodes may be configured to configure at least two of multiple compute nodes included in a computing infrastructure as representative nodes at preset intervals, validate, by the representative nodes, a user with respect to a remote command requested by the user for the computing infrastructure, and forward the remote command requested by a validated user to a target compute node included in the computing infrastructure.

Claims (43)

1 . An apparatus for managing cloud computing infrastructure access based on dynamic parallel nodes, comprising:

one or more processors; and

a memory configured to store at least one program that is executed by the one or more processors,

wherein the at least one program is configured to:

configure at least two of multiple compute nodes included in the cloud computing infrastructure as representative nodes at preset intervals,

validate, by the representative nodes, a user with respect to a remote command requested by the user for the cloud computing infrastructure, and

forward the remote command requested by the validated user to a target compute node included in the cloud computing infrastructure,

wherein the at least one program is configured to:

check, by each of the representative nodes, whether a same request has been received from the user by exchanging requests received from the user with each other; and

in response to determining that the same request has not been received by the representative nodes, return a falsified response value to the user so as to confuse a potential attacker.

2 . The apparatus of claim 1 , wherein the at least one program is configured to configure the representative nodes in a multi-layer structure.

3 . The apparatus of claim 2 , wherein the at least one program is configured to determine that validation of the user has succeeded only when the remote command is forwarded to the target compute node through the representative nodes configured in the multi-layer structure.

4 . The apparatus of claim 1 , wherein the at least one program is configured to set a time window for an accepted request time interval for the remote command with respect to the representative nodes.

5 . The apparatus of claim 4 , wherein the at least one program is configured to determine that validation of the user has succeeded only when the remote command is requested from representative nodes within the time window.

6 . The apparatus of claim 4 , wherein the at least one program is configured to set an accepted number of requests corresponding to the remote command requested from the representative nodes within the time window.

7 . The apparatus of claim 6 , wherein the at least one program is configured to determine that validation of the user has succeeded only when a remote command corresponding to the accepted number of requests is requested from the representative nodes within the time window.

8 . The apparatus of claim 1 , wherein the at least one program is configured to set a request sequence related to an order in which the remote command is requested from the representative nodes.

9 . The apparatus of claim 8 , wherein the at least one program is configured to determine that validation of the user has succeeded only when the order in which the remote command is requested from the representative nodes depending on the request sequence matches the set request sequence.

10 . The apparatus of claim 1 , wherein the at least one program is configured to convert the remote command of the user into a command format corresponding to the target compute node using information stored in a command mapping database.

11 . A method for managing cloud computing infrastructure access based on dynamic parallel nodes, comprising:

configuring at least two of multiple compute nodes included in the cloud computing infrastructure as representative nodes at preset intervals;

validating, by the representative nodes, a user with respect to a remote command requested by the user for the cloud computing infrastructure; and

forwarding the remote command requested by a validated user to a target compute node included in the cloud computing infrastructure,

wherein validating the user comprises:

checking, by each of the representative nodes, whether a same request has been received from the user by exchanging requests received from the user with each other; and

in response to determining that the same request has not been received by the representative nodes, returning a falsified response value to the user so as to confuse a potential attacker.

12 . The method of claim 11 , wherein configuring as the representative nodes comprises:

configuring the representative nodes in a multi-layer structure.

13 . The method of claim 12 , wherein validating the user comprises:

determining that validation of the user has succeeded only when the remote command is forwarded to the target compute node through the representative nodes configured in the multi-layer structure.

14 . The method of claim 11 , wherein configuring as the representative nodes comprises:

setting a time window for an accepted request time interval for the remote command with respect to the representative nodes.

15 . The method of claim 14 , wherein validating the user comprises:

determining that validation of the user has succeeded only when the remote command is requested from representative nodes within the time window.

16 . The method of claim 14 , wherein configuring as the representative nodes further comprises:

setting an accepted number of requests corresponding to the remote command requested from the representative nodes within the time window.

17 . The method of claim 16 , wherein validating the user comprises:

determining that validation of the user has succeeded only when a remote command corresponding to the accepted number of requests is requested from the representative nodes within the time window.

18 . The method of claim 11 , wherein configuring as the representative nodes comprises:

setting a request sequence related to an order in which the remote command is requested from the representative nodes.

19 . The method of claim 18 , wherein validating the user comprises:

determining that validation of the user has succeeded only when the order in which the remote command is requested from the representative nodes depending on the request sequence matches the set request sequence.

20 . The method of claim 11 , wherein forwarding the remote command comprises: converting the remote command of the user into a command format corresponding to the target compute node using information stored in a command mapping database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2024
From: SON, SEOK-HO; KANG, DONG-JAE; KIM, BYOUNG-SEOB; KIM, SOO-YOUNG; KIM, YUN-KON; BAE, SEUNG-JO; OH, BYEONG-THAEK; JUNG, YOUNG-WOO
To: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Reel/Frame 069503/0452 →
Priority Claims (1)
KR 10-2024-0031876 · Mar 6, 2024 · national
Continuity (1)
Related Publication 20250286883A1 · Sep 11, 2025
References Cited (8)
US 10511584B1 · Baer · 2019 [cited by examiner]
US 11323477B1 · Kumar · 2022 [cited by examiner]
US 11483285B2 · Tang · 2022 [cited by applicant]
US 11755381B1 · Hart · 2023 [cited by examiner]
US 20110314532A1 · Austin · 2011 [cited by examiner]
US 20140033266A1 · Kim · 2014 [cited by examiner]
Cittadini et al., “BeyondCorp Part III: The Access Proxy,” Usenix, The Advanced Computing Systems Association, Winter 2016, vol. 41, No. 4, Dec. 4, 2016. [cited by applicant]
Diego Ongaro and John Ousterhout, “In Search of an Understandable Consensus Algorithm,” 2014 USENIX Annual Technical Conference, The Advanced Computing Systems Association, Philadelphia, PA, Jun. 2014. [cited by applicant]