IP Library Granted Patent US 11,522,952
Granted Patent B2
US 11,522,952 · App. 16/913,745 · Granted Dec 6, 2022

Automatic clustering for self-organizing grids

Inventors: Nael Abu-Ghazaleh (Vestal, NY); Weishuai Yang (Ozone Park, NY); Michael Lewis (Vestal, NY)
Assignee: The Research Foundation for the State University of New York
H04L67/1044G06F15/16H04L41/12H04L43/10H04L47/70H04L67/02H04L67/10G06Q10/06H04L45/12H04L45/121H04L45/122H04L47/783H04L67/51
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,522,952
App. No.
16/913,745
Granted
Dec 6, 2022
Kind
B2
Abstract

A cluster of nodes, comprising: a plurality of nodes, each having a security policy, and being associated task processing resources; a registration agent configured to register a node and issue a node certificate to the respective node; a communication network configured to communicate certificates to authorize access to computing resources, in accordance with the respective security policy; and a processor configured to automatically dynamically partition the plurality of nodes into subnets, based on at least a distance function of at least one node characteristic, each subnet designating a communication node for communicating control information and task data with other communication nodes, and to communicate control information between each node within the subnet and the communication node of the other subnets.

Claims (42)

1. A non-transitory computer-readable medium storing executable instructions that, in response to execution, cause a processor of a first node device within a first subnet to perform operations comprising:

receiving, by the first node device, a node device certificate in response to a successful registration by a registration agent;

using the node device certificate to retrieve role information;

generating an access token from the node device certificate and retrieved role information;

communicating, by the first node device, the access token to a second node device within a second subnet to authorize access to computing resources of the second node device in accordance with a security policy of the second node device provided that the access token has not expired, wherein the first subnet comprises a plurality of node devices based on a distance function of a node device characteristic, and wherein the second subnet comprises a plurality of node devices different from the node devices comprising the first subnet based on the distance function of the node device characteristic; and

communicating, by the first node device, control information and task data to the second node device.

2. The non-transitory computer-readable medium of claim 1 , further comprising instructions that, in response to execution, cause the processor of the first node device to perform operations further comprising:

designating a set of preferred node devices for allocation of portions of a task, wherein the second node device is included in the preferred node devices.

3. The non-transitory computer-readable medium of claim 1 , further comprising instructions that, in response to execution, cause the processor of the first node device to perform operations further comprising:

designating a set of preferred node devices for allocating portions of a task, wherein the designated set is based on both the task and a partitioning algorithm based on the distance function of the node device characteristic.

4. The non-transitory computer-readable medium of claim 3 , wherein the node device characteristic includes a pairwise communication latency between respective node devices.

5. The non-transitory computer-readable medium of claim 1 , wherein the second node device controls each node device within the second subnet.

6. The non-transitory computer-readable medium of claim 1 , wherein the second node device communicates control information between each node device within the second subnet and the plurality of node devices of the plurality of subnets.

7. The non-transitory computer-readable medium of claim 1 , wherein the node device characteristic comprises a link delay metric.

8. The non-transitory computer-readable medium of claim 7 , wherein the first subnet and the second subnet are dynamically control led based on current conditions that are determined at least in part by proactive communications that include a heartbeat message.

9. The non-transitory computer-readable medium of claim 1 , further comprising instructions that, in response to execution, cause the processor of the first node device to perform operations further comprising:

partitioning the plurality of node devices in the first subnet into two new subnets in response to a failure of one or more of the plurality of node devices to respond to a predetermined number of consecutive heartbeat messages.

10. A method for clustering node devices for accomplishing a task, comprising:

receiving, by a first node device within a first subnet, a node device certificate in response to a successful registration by a registration agent;

using the node device certificate to retrieve role information;

generating an access token from the node device certificate and retrieved role information;

communicating, by the first node device, the access token to a second node device within a second subnet to authorize access to computing resources of the second node device in accordance with a security policy of the second node device provided that the access token has not expired, wherein the first subnet comprises a plurality of node devices based on a distance function of a node device characteristic, and wherein the second subnet comprises a plurality of node devices different from the node devices comprising the first subnet based on the distance function of the node device characteristic; and

communicating, by the first node device, control information and task data to the second node device of the second subnet; and

designating a set of preferred node devices for allocating portions of a task, wherein the designated set is based on the task and a partitioning algorithm based on the distance function of the node device characteristic.

11. The method of claim 10 , wherein the second node device is included in the set of preferred node devices.

12. The method of claim 10 , wherein the node device characteristic includes a pairwise communication latency between respective node devices.

13. The method of claim 10 , wherein the second node device controls each node device within the second subnet.

14. The method of claim 10 , wherein the second node device communicates control information between each node device within the second subnet and the plurality of node devices of the plurality of subnets.

15. The method of claim 10 , wherein the node device characteristic comprises a link delay metric.

16. The method of claim 10 , wherein the first subnet and the second subnet are dynamically controlled based on current conditions that are determined at least in part by proactive communications that include a heartbeat message.

17. The method of claim 10 , wherein the heartbeat message includes merged update messages.

18. The method of claim 10 , further comprising: partitioning the plurality of node devices in the first subnet into two new subnets in response to a failure of one or more of the plurality of node devices to respond to a predetermined number of consecutive heartbeat messages.

19. A system comprising:

a memory; and

a processor configured to:

receive, by the first node device, a node device certificate in response to a successful registration by a registration agent;

use the node device certificate to retrieve role information;

generate an access token from the node device certificate and retrieved role information;

communicate, by the first node device, the access token to a second node device within a second subnet to authorize access to computing resources of the second node device in accordance with a security policy of the second node device provided that the access token has not expired, wherein the first subnet comprises a plurality of node devices based on a distance function of a node device characteristic, and wherein the second subnet comprises a plurality of node devices different from the node devices comprising the first subnet based on the distance function of the node device characteristic; and

communicate, by the first node device, control information and task data to the second node device.

20. The system of claim 19 , wherein the processor is further configured to:

designate a set of preferred node devices for allocation of portions of a task, wherein the second node device is included in the preferred node devices.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2021
From: ABU-GHAZALEH, NAEL; YANG, WEISHUAI; LEWIS, MICHAEL
To: THE RESEARCH FOUNDATION OF STATE UNIVERSITY OF NEW YORK
Reel/Frame 057726/0488 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2021
From: ABU-GHAZALEH, NAEL; YANG, WEISHUAI; LEWIS, MICHAEL
To: THE RESEARCH FOUNDATION OF STATE UNIVERSITY OF NEW YORK
Reel/Frame 057726/0839 →
CHANGE OF NAME Recorded Oct 7, 2021
From: THE RESEARCH FOUNDATION OF STATE UNIVERSITY OF NEW YORK
To: THE RESEARCH FOUNDATION FOR THE STATE UNIVERSITY OF NEW YORK
Reel/Frame 057747/0500 →
Continuity (6)
Continuation 15463542 · Mar 20, 2017
Continuation 13770798 · Feb 19, 2013
Continuation 13243125 · Sep 23, 2011
Continuation 12236396 · Sep 23, 2008
Provisional Application 60974834 · Sep 24, 2007
Related Publication 20200382585A1 · Dec 3, 2020