IP Library Granted Patent US 11,399,063
Granted Patent B2
US 11,399,063 · App. 16/399,635 · Granted Jul 26, 2022

Network authentication for a storage system

Inventors: Purvaja Narayanaswamy (San Jose, CA); Cary A. Sandvig (San Jose, CA); Robert Lee (San Carlos, CA)
Assignee: Pure Storage, Inc.
H04L67/1097G06F3/06G06F3/061G06F3/0604G06F3/065G06F3/067G06F3/0611G06F3/0613G06F3/0635G06F3/0655G06F3/0659G06F3/0685G06F3/0688G06F3/0689G06F11/108G06F11/1068G06F11/2092G06F12/0246G06F13/4022G06F13/4282G11C29/52H03M13/154H04L12/40169H04L49/10H04L67/16G06F2201/805G06F2201/845G06F2212/7206G06F2212/7207
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,399,063
App. No.
16/399,635
Granted
Jul 26, 2022
Kind
B2
Abstract

A method of operating a storage system is provided. The method includes establishing a security context between a client and the storage system, the security context comprising a single ticket for multiple nodes within the storage system. The method includes distributing a first request to a first blade within the storage system and distributing a second request to a second blade within the storage system. The distributing the first request and the second request includes determining a node for handling the first request and the second request based on data within the single ticket.

Claims (33)

1. A method, comprising:

establishing a security context between a client and a storage system, the security context comprising a ticket for multiple nodes within the storage system, the establishing triggered by a remote procedure call received by the storage system;

distributing a first request to a first blade within the storage system, the distributing comprising transmitting a message to an authority owning the first request, the authority one of a plurality of authorities within the storage system; and

distributing a second request from the first blade to a second blade within the storage system, wherein the distributing the first request and the second request comprises:

determining, by the first blade, a node for handling the first request and a node for handling the second request based on data within the ticket.

2. The method of claim 1 , wherein establishing the security context includes authentication through third party authorization.

3. The method of claim 1 , wherein the security context is incremented for each remote procedure call.

4. The method of claim 1 , wherein the storage system comprises multiple chassis and wherein the ticket includes a session key and a storage system key.

5. The method of claim 1 , wherein the multiple nodes of the storage system are projected as a single node.

6. The method of claim 1 , wherein the establishing comprises:

issuing a ticket through third party authorization.

7. The method of claim 1 , comprising:

caching a client principal name across all nodes.

8. The method of claim 1 , wherein the ticket is encrypted.

9. The method of claim 1 wherein the method operations are embodied as non-transitory computer readable media.

10. A storage system, comprising:

a plurality of storage nodes configured to communicate together as a storage cluster;

each of the plurality of storage nodes having nonvolatile solid-state memory for data storage; and

the plurality of storage nodes configured to distribute the data and metadata associated with the data throughout the plurality of storage nodes, the plurality of storage nodes configurable to:

establish a security context between a client and the plurality of storage nodes, the security context comprising a ticket for the plurality of storage nodes, establishment of the security context triggered by a remote procedure call received by the storage system;

distributing a first request to a first node within the storage system, the distributing comprising transmitting a message to an authority owning the first request, the authority one of a plurality of authorities within the storage system; and

distributing a second request from the first node to a second node within the storage system, wherein the distributing the first request and the second request comprises:

determining, by the first node, a further node for handling the first request and the second request based on data within the ticket.

11. The system of claim 10 , wherein establishing the security context includes authentication through third party authorization.

12. The system of claim 10 , wherein the security context is incremented for each remote procedure call.

13. The system of claim 10 , wherein the storage system comprises multiple chassis and wherein the ticket includes a session key and a storage system key.

14. The system of claim 10 , wherein the plurality of nodes of the storage system are projected as a single node.

15. The system of claim 10 , wherein the establishing comprises:

issuing a ticket through third party authorization.

16. The system of claim 10 , comprising:

caching a client principal name across each of the plurality of nodes.

17. The system of claim 10 , wherein the ticket is encrypted.

18. The system of claim 10 wherein method operations of the plurality of storage nodes configurable are embodied as non-transitory computer readable media.

Continuity (6)
Continuation In Part 15167792 · May 27, 2016
Continuation 14961665 · Dec 7, 2015
Continuation 14618999 · Feb 10, 2015
Continuation In Part 14296151 · Jun 4, 2014
Provisional Application 62725167 · Aug 30, 2018
Related Publication 20190356736A1 · Nov 21, 2019
Cited By (2)
US 12,248,475 US 12,505,103