A node based communication system and method
The node-based communication system addresses inefficiencies in distributed cloud storage by implementing periodic node verification, asynchronous messaging, and secure identification, improving performance and user experience through optimized communication paths.
Patent Information
- Application Number
- PCT/IL2024/051236
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-31
- Filing Date
- 2024-12-29
- Publication Date
- 2025-07-03
AI Technical Summary
Current data storage systems in distributed cloud environments face challenges with inefficient communication paths due to chattiness, server identification issues, and the need for robust security measures, leading to performance degradation and reduced user experience.
A node-based communication system with an orchestrator and connector module that performs periodic node state verification, generates messages only upon significant changes, uses a message broker for asynchronous communication, and employs a reverse communication protocol to bypass firewall restrictions, along with a unique identification process for secure access.
This system minimizes network chattiness, ensures secure and efficient communication paths, maintains system performance, and provides robust server identification, enhancing overall efficiency and user experience in multi-tenant environments.
Smart Images

Figure IL2024051236_03072025_PF_FP_ABST
Abstract
Description
[0001] ANODE BASED COMMUNICATION SYSTEM AND METHOD
[0002] FIELD OF THE INVENTION
[0003] The present invention relates in general to computer data storage methods and systems, and in particular to node-based communication system in distributed cloud storage environments.
[0004] BACKGROUND OF THE INVENTION
[0005] Providing data storage and data backup capabilities represent a significant concern as current computing systems, whether local, remote or cloud based (such as containers packages, private / public / multi-cloud systems, etc.), require ever more extensive data storage solutions for their proper operation. Usually, such data provision and management are made and offered by designated data centers and traditionally the provision of used or expected to be used data storage is provided by stacking physical data storing components, i.e. hybrid hard disk drive (HHD), hard disk drive (HDD), solid-state drive (SSD), etc. Because the methods by which data is stored and edited on different types of drives are so distinct, a similarly broad variety of network configurations and operating methods have emerged to meet the requirements of different network applications.
[0006] Many of these systems and methods include technical features which - whilst distinct - can serve similar functions in the very specific context in which they are disposed, albeit not functions that are independent of said context. Technical features relating to the storage, transfer, sensing, and management of data are employed in a variety of approaches, systems, methods, and network configurations, which have been developed to address a range of technical problems relating to data storage and network management broadly. Much of these are discussed below, in order to provide a broad overview of the relevant prior for the present invention. An approach well established in the field of data storage is the operation of stacking data storing components to create what is termed “Storage Arrays” (or alternatively “disk arrays”) which are used for different kinds of data, broadly categorized by: block-based storage; file-based storage; object storage, among other data types. Rather than store data on a server, storage arrays use multiple drives in a collection capable of storing a huge amount of data, controlled by a local / central controlling system interfacing via storage network protocols to the server.
[0007] Traditionally, a storage array controlling system provides multiple storage services so as to keep track of storage capacity; the allocation of space to different datasets, the management of sections of data storage capacity known as “volumes”; the periodic backup operation of the data to facilitate restoration and disaster recovery and the creation of point-intime copy of the data, known as snapshotting" the identification and tracking of errors; the encryption of data communication to protect the integrity and privacy of data; the compression of data to conserve storage capacity; etc. Services of such type require significant computing capacity, metadata, data storage, accelerators, etc. - thus, such services require the designation of extensive infrastructure and budget capacities and resources.
[0008] Commonly, a storage array is separated from a system server's operability and is configured to implement system and application operations on dedicated hardware, for example a server stack, a storage array stack, one or more hard disk or solid state drive (HDD or SSD) and media input / output (I / O) devices configured to communicate with the servers via the storage stack.
[0009] Another approach well established in the field is the employment of an orchestrator, which is a software module logically situated in the control plane (CP) of a distributed network and is responsible for managing the operations of the data plane (DP), such as provisioning and resource coordination. The DP is the layer within a network architecture responsible for the movement, processing and storage of data through the distributed network, whilst the CP is an associated network layer that responsible for controlling how said data flows through the DP. Positioned in the CP, the orchestrator provides centralized management of the DP network, automating data flow across network nodes in accordance with predefined rules. Such coordination is particularly important in distributed network environments where resources such as computational power, storage and network bandwidth are spread across multiple nodes, often in different physical locations. Another approach well established in the field of data storage is the operation of redundant arrays of independent disks (RAID), which can be operated as a way of storing the same data in different places to protect data in the case of a system failure.
[0010] RAID is a general approach and network configuration that virtualizes data and combines multiple physical disk drive components into one or more logical units. Persons skilled in the art will appreciate that the technical problem RAID operations are employed to address depend on the type of RAID operation undertaken: RAID 0 stripes data across multiple disks to address performance bottlenecks and capacity limitations; RAID 1 mirrors data across two or more disks to address data loss due to disk failure; RAID 2 stripes data at the bit level and uses Hamming code for error correction to address data errors and fault tolerance in high- reliability systems; RAID 3 stripes data at the byte level and uses a dedicated parity disk to address single-disk failure and sequential data access bottlenecks; RAID 4 stripes data at the block level with a dedicated parity disk to address single-disk failure and block-level performance bottlenecks; RAID 5 stripes data and distributes parity information across multiple disks to address single-disk failure and storage efficiency; RAID 6 stripes data with double distributed parity to address multiple disk failures and ensure data integrity; RAID 10 combines mirroring (RAID 1) and striping (RAID 0) to address performance bottlenecks and single-disk failure; RAID 01 mirrors two RAID 0 arrays to address performance bottlenecks and fault tolerance; RAID 50 combines RAID 5 arrays and stripes them using RAID 0 to address the performance and reliability limits of RAID 5; RAID 60 combines RAID 6 arrays and stripes them using RAID 0 to address the performance and redundancy limits of RAID 6; RAID 7 uses an embedded real-time OS and dedicated cache to improve performance and address bottlenecks associated with traditional RAID levels; RAID IE stripes mirrored data across an odd number of disks to address fault tolerance and performance in setups where an odd number of disks are available.
[0011] Another approach well established in the field of data storage is the operation of remote replication, which is the process of copying data to a device at a remote location for data protection or disaster recovery purposes. Remote replication may be either synchronous or asynchronous, the former writes data to the primary and secondary sites at the same time, and the latter at different times. Because asynchronous replication is designed to work over longer distances and requires less bandwidth, it is often considered a better option in the field for the recovery of data after a catastrophic disaster. However, the operation of asynchronous replication also introduces several risks, not least the risk of loss of data during a system outage as said data at the target device isn't synchronized with the source data. Most enterprises today use data storage vendors that include replication software on their high-end and mid-range storage arrays, to partially mitigate this risk.
[0012] Another configuration well established in the field of data storage is software-defined storage (SDS), which enables communality of operation of different hardware. SDS configurations include the abstraction of data storage resources from the underlying physical storage hardware, and thereby are able to provide flexible exploitation of available hardware and data storage resources. Typically, commercial off-the-shelf servers run a subset of SDS known as hyper-converged infrastructure HCI, in which the abstractions of both the area network and the underlying storage are implemented virtually in software, rather than physically in hardware.
[0013] Both conventional storage arrays and SDS configurations typically include an integrated “storage stack” - a layered software framework that organizes, manages and facilitates data storage, access and retrieval. Said storage stack t provides essential services such as data protection (e.g. backup, redundancy, recovery, etc.); space allocation; data optimization, backup and recovery, among other functions. Due to the broad array of functions required by SDSs, the integrated software stack is typically configured to have a high of reliability, and the efficiency of the code is also conventionally prioritized.
[0014] Another data storage configuration taught in the field is directed attached storage (DAS), which typically provides the direct local services (such as encryption, compression, RAID, etc.) in cases where central storage systems are not needed or desired. Conventionally, DAS configurations will exploit a robust collection of internal storage components, without which the means of operating said services would be insufficient for proper network function. Persons skilled in the art will appreciate that the technical problem DAS network configurations are employed to address is: the provision of data storage services in the absence of centralized data management nodes. DAS is mostly limited to non-critical applications due to an inherent drawback related to the fact that DAS is inherently tied to one host: server communication failure precludes data accessibility, typically limiting DAS to non-critical applications. This is in contrast to the SDS solutions previously described, which are typically accessible by multiple servers over the network; if one server or communication channel fails, other servers can still access the storage. Another approach well established in the field of data storage is the operation of hot spares. Traditionally, hot spares act as standby drives in RAID 1, RAID 5, or RAID 6 volume groups, but they have also been applied to other network management approaches. Generally, if a drive fails, for example in a volume group, some control software will reconstruct data from the failed drive on a hot spare. When a drive fails in a storage array, a hot spare drive can be substituted without requiring a physical swap. Persons skilled in the art will appreciate that the technical problem hot spare configurations are employed to address is: minimizing downtime and ensuring quick recovery from disk failures in RAID and other storage systems. Another approach well established in the field of data storage is the operation of snapshots of data. A snapshot is used to represent the content of a particular part of a data stored on a storage system at a particular point in time. The source of snapshots are typically base volumes, which are usually referred to as “member volumes” of a “consistency group”. The purpose of a consistency group is to facilitate the capture of simultaneous snapshot images of multiple volumes, thus obtaining copies of a collection of volumes at a particular point in time. In practice, most mid-range and high-end storage arrays create snapshot consistency groups within volumes inside the storage array. Persons skilled in the art will appreciate that the technical problems snapshot operations are employed to address are: loss prevention; data recovery; control of database version; rule compliance and auditing; monitoring of storage dynamics, among other technical problems.
[0015] Obtaining a local snapshot is enabled by a server operating system that includes a logical volume manager (LVM) - a software layer that abstracts physical storage disks into virtualized storage units (logical volumes) - enabling the obtaining of a local snapshot on a single virtualized volume. In distributed storage system, since the volumes are distributed across multiple servers, obtaining or creating a consistency group is not usually possible or supported, producing a number of data integrity risks. LVM works by partitioning the physical volumes (PVs) into physical extents (PEs), which are mapped onto logical extents (LEs) which are then pooled into volume groups (VGs), linked together as logical volumes (LVs). Persons skilled in the art will appreciate that the LVM approach is typically undertaken in order to address the technical problems posed by: inflexible partition sizes; fragmentation of disk space; limited scalability of storage infrastructure; complex mirroring and striping setups; difficulty in taking snapshots; and the efficient management of multi -disk systems.
[0016] Another approach well established in the field of data storage is quality of service (QoS), which is critical to deliver consistent storage performance applications where multiple workloads share a single limited resource by preventing the “noisiest neighbor” from disrupting the performance other applications on the same system. On physical storage arrays, QoS can be set for volumes as limits on data transfer. Unlike storage arrays, the distributed servers of storage stacks mean there isn’t a single point that can enforce QoS. Persons skilled in the art will appreciate that QoS is a general approach in data storage array management, which can be disposed to address a number of different challenges, including but not limited to: predictable performance in shared resources; performance spikes caused by noisy neighbors; difficulty maintaining SLA compliance; resource contention during peak loads; and the need for overprovisioning to avoid performance issues.
[0017] Another approach well established in the field of data storage is disk cloning, which is the process of making a copy of a part (or all) of a hard drive, typically undertaken at a particular point in time whilst hosts continue to access the data. Like QoS, this is an approach which is difficult to operate on shared storage stacks, since the source and target may reside on different physical entities. Persons skilled in the art will appreciate that disk cloning is typically undertaken in order to address the technical problems of: efficient data migration; disaster recovery; consistent system deployment; backup integrity, and the prevention of data loss due to hardware failure.
[0018] Another approach well established in the field of data storage is thick provisioning, where the complete amount of virtual disk storage capacity is pre-allocated on the physical storage when the virtual disk is created, rendering capacity unavailable for use by other volume. Persons skilled in the art will appreciate that the thick provisioning approach is typically undertaken in order to address the technical problems posed by: unpredictable availability of storage capacity; overcommitted storage resources; storage fragmentation, performance degradation, the risks of complex storage management; and the resultant shortages in capacity from said technical problems leading to data loss.
[0019] In contrast to thick provisioning, yet another approach well established in the field of data storage is thin provisioning, where a virtual disk consumes only the space that it needs initially, and grows with time according to increase in demand. Whilst thinly provisioned storage consumes less disk space, it consumes significantly more RAM to store the metadata of the thin allocation. Additionally, thin provisioning consumes much more CPU on the I / O transmissions needed to facilitate intensive random access to translate logical addresses to physical, since it has to navigate through a tree-like data structure. Despite these limitations, thin provisioning is a widely undertaken approach to address a number of different technical problems of the field, persons skilled in the art will appreciate that said technical problems include but are not limited to: the inefficient utilization of storage; high upfront capital costs; difficulty in scaling storage; and the over-allocation of resources.
[0020] Another approach well established in the field of data storage is the Clustered Logical Volume Manager (CLVM), which is a set of clustering extensions to LVM, an approach discussed earlier. These extensions allow a cluster of computers to manage shared storage using LVM by locking access to physical storage while a logical volume is being configured. A single misbehaving node can impact the health of the entire cluster, introducing significant risk for the integrity of data stored on a data storage system. Persons skilled in the art will appreciate that the technical problems the CLVM approach is disposed to address include but are not limited to: uncoordinated access to shared storage introducing storage performance limitations; corruption of stored data from multiple read / write operations; limitations to the scalability of storage environments; low storage availability; inefficient data sharing; and the risks of high complexity in the management and expansion of shared storage.
[0021] Another approach well established in the field of data storage is the deployment of a hardware security module (HSM), which is a physical device that manages digital keys for strong authentication. Persons skilled in the art will appreciate that HSMs are typically deployed in order to address the technical problems posed by: secure key generation and storage; tamper detection and resistance; performance bottlenecks for cryptographic operations; regulatory compliance; controlled key access; secure cryptographic operations; auditing; and logging.
[0022] Another approach well established in the field of data storage is the use of tunneling protocols, which are a communications protocols that allow for the movement of private data from one network to another across a public network, using a process called encapsulation. Persons skilled in the art will appreciate that tunneling protocols are typically operated in order to address the technical problems posed by: secure transmission of data over untrusted networks; bypassing network restrictions and firewalls; ensuring confidentiality and integrity of data in transit; preventing eavesdropping and man-in-the-middle attacks; encapsulating incompatible or sensitive protocols; and reducing exposure to external threats. Other approaches have been taught in the art to address the challenges of secure communication in distributed storage environments, including virtual private networks (VPNs)_; reverse proxies; agent-based models; and secure APIs. VPNs and encrypted tunnels create secure connections, but add latency and require extensive setup. Reverse proxies and API gateways offer controlled access to storage servers by routing external requests through a single entry point, but they also add routing layers that create bottlenecks and increase complexity. Agent-based models, which rely on modules within a network to pull commands from the control software rather than receive them directly, help bypass firewall restrictions but delay orchestration by requiring periodic updates instead of real-time communication. Secure APIs, which rely on authentication protocols, provide direct access to storage resources but can be challenging to scale across large networks due to resource demands.
[0023] Similar to the challenges of security, many approaches have been taught in the art to address chattiness, which is when communication between servers consists of repetitive, non-essential notifications that create unnecessary traffic. This challenges is typically addressed using: traffic filtering; message batching; and rate limiting, which selectively blocks non-essential communications; aggregates multiple smaller messages into fewer transmissions; and restricting the volume of messages over a defined interval, respectively.
[0024] Not unlike solutions to chattiness, many systems and methods have been taught in the art to address the challenge of identification of servers within node-based cloud storage networks, particularly in multi-tenant environments. Conventional means for server identification typically rely on: IP address verification; hostname recognition; and basic authentication protocols such as API keys or token-based systems
[0025] Storage systems may be implemented as on-premises data centers, wherein servers and infrastructure are privately owned and managed, or as networked storage environments, such as those offered via cloud computing service providers. Cloud storage systems may exploit shared resources both for the storage media, which physically stores the data, and for the network infrastructure, which serves to connect the storage system to other systems and clients. In some configurations, storage systems utilize shared networks for general operations, while in others, dedicated networks may be required for each function in order to optimize performance and manage system resources more efficiently. Persons skilled in the art will appreciate that the choice of whether to employ shared or dedicated networks may depend on various technical factors, including but not limited to: workload types, data throughput requirements, latency considerations, as well as scaling requirements.
[0026] Node systems are critical components within a networked environment, acting as intermediaries that facilitate communication and data exchange across all devices in the network. In the context of a data communication network, a node refers to a distinct device capable of transmitting, receiving, or routing data. In addition to their fundamental role in data transmission, node systems often provide quality of service (QoS) monitoring capabilities, ensuring that data flow across the network meets predefined performance metrics. A particular implementation of node systems is cloud storage, which delivers scalable and flexible storage solutions for individuals and organizations. Cloud storage nodes operate in distributed environments and are thus capable of dynamically adjusting to accommodate fluctuating storage demands. Cloud storage systems face several technical challenges which impact performance and reliability.
[0027] Distributed storage system orchestration requires secure access and communication paths to cloud storage servers. Communication in on-premises storage facilities is relatively straightforward, as there is direct communication between components. In distributed storage systems, however, data transmission requires a secure communication path through active cyber security systems, particularly firewalls. For instance, a firewall may block messages originating from outside the storage network as they attempt to reach certain storage components. In standard orchestration, commands are pushed from the orchestrator to the servers. Such direct communication is often blocked by firewalls in cloud computing environments, preventing an external orchestration module from efficiently exerting control over the cloud computing network. Consequently, the orchestration module must comply with strict security protocols, which complicates the establishment of secure communication paths while maintaining data integrity and system performance.
[0028] Chattiness in cloud storage systems may have a significant negative impact on performance. This occurs when some of the communication between servers consists of repetitive, non-essential notifications, such as routine messages indicating that the system is functioning normally. These excessive communications create unnecessary network traffic, consuming resources that could be better utilized for more critical tasks. Numerous services, such as databases, authentication systems, and firewalls, generate large volumes of excessive communication traffic, leading to network congestion and increased latency. This excessive exchange of unnecessary or redundant data consumes valuable network bandwidth and system resources, diminishing overall performance.
[0029] The constant back-and-forth communication between servers consumes network bandwidth, increases latency, and introduces unnecessary overhead. The accumulation of generic and repetitive notifications can overwhelm the system, leading to reduced throughput and slower response times. This performance degradation impacts not only the cloud storage provider but also end users, who may experience delays in accessing and retrieving their data. Chattiness can significantly impact the user experience in cloud storage systems. Repetitive notifications and updates may overwhelm users with irrelevant information, leading to reduced productivity. Constant interruptions caused by chattiness can disrupt workflows and hinder users' ability to complete tasks efficiently. This diminishes the overall user experience, undermining the convenience and ease of use that cloud storage systems aim to deliver.
[0030] Precise identification of servers within node-based cloud storage solutions pertains to ensuring the precise identification of servers through accurate certification. Robust mechanisms must be in place to authenticate all entities involved whether they are the orchestrator, the tenant, or the server itself. This process becomes particularly important in multi-tenant environments, where multiple users or organizations share the same infrastructure while maintaining strict isolation of their data and operations. Each tenant must be authenticated independently to prevent unauthorized access and maintain system security.
[0031] Current methods for server identification in distributed storage systems typically rely on IP address verification, hostname recognition, and basic authentication protocols. IP addresses and hostnames serve as unique identifiers, enabling the network to locate and verify servers; however, these identifiers can change frequently in cloud environments due to load balancing and resource scaling, complicating consistent identification. Basic authentication protocols, such as API keys or token-based systems, add a layer of security but often lack the rigorous certification required to ensure secure identification in multi-tenant infrastructures. As a result, traditional identification methods face limitations in node-based cloud storage systems, where frequent changes and the need for strict isolation demand more robust, adaptive approaches to maintain reliable, secure operations across distributed networks.
[0032] There is thus a need in the art for a system that addresses the critical challenges of communication, chattiness, and server identification in distributed cloud storage environments. Such a system should facilitate secure and efficient communication paths that comply with strict cybersecurity protocols while maintaining system performance. Additionally, there is a need to minimize network chattiness to reduce congestion and latency, improving overall system efficiency and user experience. Furthermore, robust mechanisms for server identification are required to authenticate and certify entities in multi-tenant environments
[0033] SUMMARY OF THE INVENTION
[0034] The following embodiments and aspects thereof are described and illustrated in conjunction with systems, devices and methods which are meant to be exemplary and illustrative and not limiting in scope. In various embodiments, one or more of the abovedescribed problems have been reduced or eliminated, while other embodiments are directed to other advantages or improvements.
[0035] The following embodiments and aspects thereof are described and illustrated in conjunction with systems, devices and methods which are meant to be exemplary and illustrative and not limiting in scope. In various embodiments, one or more of the abovedescribed problems have been reduced or eliminated, while other embodiments are directed to other advantages or improvements.
[0036] According to a first aspect of the invention, a node-based communication system comprises: (i) at least one orchestrator; and (ii) at least one node comprising at least one connector module, wherein said at least one orchestrator is in communication with said at least one connector module of said node, and wherein said at least one connector module repetitively, at specified time intervals, operates a node state verification procedure generating at least one connector originated message, and wherein said at least one connector module is configured to send said at least one connector originated message to said at least one orchestrator upon a change in said message characteristics identified by the at least one connector module, said identified change being in accordance with criteria predesignated by the at least one orchestrator and accordingly communicated to said at least one connector module.
[0037] According to another aspect of the invention, the at least one connector module-initiated node state verification procedure evaluates various parameters of the at least one node, including but not limited to storage availability, performance metrics, network connectivity, and deviations from expected operational behavior. If the at least one connector module detects a change in the parameters measured by the node state verification procedure that exceeds thresholds or criteria predesignated by the at least one orchestrator, it generates at least one message encapsulating the updated state information and sends said message to the at least one orchestrator.
[0038] According to another aspect of the invention, the node-based communication system further comprises at least one message broker.
[0039] According to another aspect of the invention, the message broker acts as an intermediary, ensuring that messages are properly queued, routed, and delivered, when the at least one node or the at least one orchestrator is unavailable.
[0040] According to another aspect of the invention, the message broker enables asynchronous communication by decoupling the sender and receiver, allowing operations to proceed independently of the real-time availability of other system components.
[0041] According to another aspect of the invention, the message broker can further perform tasks such as message transformation, prioritization, and filtering.
[0042] According to another aspect of the invention, the at least one node initiates a reverse communication with the at least one orchestrator thereby circumventing network security protocols, including firewall restrictions. According to another aspect of the invention, the reverse communication initiated by the at least one node is implemented using a GET request.
[0043] According to another aspect of the invention, the network security system is a firewall network security system.
[0044] According to another aspect of the invention, the at least one node is a storage node containing at least one storage component.
[0045] According to another aspect of the invention, the at least one storage component comprises at least one designated connector module configured to initiate and maintain a communication port between the at least one orchestrator and the at least one node, wherein said communication port is designated to allow data flow in a reverse direction between the at least one orchestrator and the at least one node.
[0046] According to another aspect of the invention the at least one orchestrator is configured to define and adjust thresholds that determine whether messages are transmitted from the at least one connector module to the at least one orchestrator.
[0047] According to another aspect of the invention, the at least one orchestrator is configured to instruct the at least one connector module to transmit updates to the at least one orchestrator only when changes in the output parameters of the at least one node exceeds a predefined threshold, and to prevent updates to the at least one orchestrator when changes remain below this threshold.
[0048] According to another aspect of the invention, the at least one orchestrator includes an anti-failure mechanism configured to detect and resolve communication malfunctions between said at least one orchestrator and the at least one connector module of the at least one node. According to another aspect of the invention, said anti-failure mechanism monitors the communication paths and system components for potential disruptions, such as network interruptions, hardware malfunctions, or software errors. Upon identifying a failure, the antifailure mechanism initiates corrective actions, which may include but is not limited to reestablishing communication paths, deploying backup configurations, or triggering a selfupdate process for the connector module from an external repository.
[0049] According to another aspect of the invention, the at least one orchestrator orchestrates an identification process designated to create a unique identification sequence configured to facilitate identification of the at least one node, the at least one orchestrator, and at least one tenant requesting access to the at least one node.
[0050] According to another aspect of the invention, the unique identification sequence is a unique cryptographic sequence.
[0051] According to another aspect of the invention, the at least one connector module is configured to establish and maintain the identification process.
[0052] According to another aspect of the invention, the generation of the identification sequence designated to identify the at least one node section is influenced by and dependent on the generation of the identification sequence designated to identify at least one tenant.
[0053] According to another aspect of the invention, the identification prosses is provided by an integrated third-party service.
[0054] According to another aspect of the invention, a designated cryptographic token is created for each tenant and each at least one node in order to provide an exact identification. According to another aspect of the invention a method for node-based communication, comprises: (i) operating at least one orchestrator in communication with at least one node, the node comprising at least one connector module; (ii) executing, by the at least one connector module, a node state verification procedure repetitively at specified time intervals, wherein the procedure generates a connector-originated message based on the operational state of the node; (iii) identifying, by the at least one connector module, changes in the message characteristics generated during the node state verification procedure, wherein the changes are determined based on criteria predesignated by the at least one orchestrator and communicated to the at least one connector module; (iv) transmitting the at least one connector-originated message from the at least one connector module to the at least one orchestrator upon detecting changes in the message characteristics that meet or exceed the predesignated criteria; and wherein the at least one orchestrator adjusts system resources or operations based on the received at least one connector-originated message.
[0055] BRIEF DESCRIPTION OF THE FIGURES
[0056] Some embodiments of the invention are described herein with reference to the accompanying figures. The description, together with the figures, makes apparent to a person having ordinary skill in the art how some embodiments may be practiced. The figures are for the purpose of illustrative description and no attempt is made to show structural details of an embodiment in more detail than is necessary for a fundamental understanding of the invention.
[0057] In the Figures:
[0058] FIG. 1 constitutes a schematic illustration of a conventional storage array system.
[0059] FIG. 2 constitutes a schematic illustration of a conventional storage array system.
[0060] FIG. 3 constitutes a conventional cloud-based data management system. FIG. 4 constitutes a schematic view of a node-based communication system, according to some embodiments of the invention.
[0061] FIG. 5 constitutes a schematic view of the architecture of a node-based communication system, according to some embodiments of the invention.
[0062] FIG. 6 constitutes a schematic illustration of the transmission of connector-originated messages, contingent upon the outcome of the node state verification procedure, according to some embodiments of the invention.
[0063] FIG. 7 constitutes a schematic view of unique identification processes designated to increase security levels as part of the operation of the node-based communication system, according to some embodiments of the invention.
[0064] DETAILED DESCRIPTION OF SOME EMBODIMENTS
[0065] In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the invention. However, it will be understood by those skilled in the art that the present invention may be practiced without these specific details. In other instances, well-known methods, procedures, and components, modules, units and / or circuits have not been described in detail so as not to obscure the invention. Some features or elements described with respect to one embodiment may be combined with features or elements described with respect to other embodiments. For the sake of clarity, discussion of same or similar features or elements may not be repeated.
[0066] Although embodiments of the invention are not limited in this regard, discussions utilizing terms such as, for example, “controlling” “processing,” “computing,” “calculating,” “determining,” “establishing”, “analyzing”, “checking”, “setting”, “receiving”, or the like, may refer to operation(s) and / or process(es) of a controller, a computer, a computing platform, a computing system, or other electronic computing device, that manipulates and / or transforms data represented as physical (e.g., electronic) quantities within the computer's registers and / or memories into other data similarly represented as physical quantities within the computer's registers and / or memories or other information non-transitory storage medium that may store instructions to perform operations and / or processes.
[0067] Unless explicitly stated, the method embodiments described herein are not constrained to a particular order or sequence. Additionally, some of the described method embodiments or elements thereof can occur or be performed simultaneously, at the same point in time, or concurrently.
[0068] The term "Controller" as used herein refers to any type of computing platform or component equipped with a Central Processing Unit (CPU) or microprocessor and capable of supporting multiple input / output (I / O) ports. The term “Network security protocol” as used herein, refers to policies, processes and practices adopted to prevent, detect and monitor unauthorized access, misuse, modification, or denial of a computer network and network- accessible resources.
[0069] The term "Firewall" as used herein refers to a network security component designed to monitor and control incoming and outgoing network traffic based on predefined security rules. Acting as a protective barrier between a trusted network and an untrusted network, such as the internet, a firewall safeguards systems from unauthorized access, malware, and other cyber threats. Firewalls filter network traffic based on security policies, ensuring only legitimate communications are allowed. They can be implemented as hardware devices, software solutions, or cloud-based services, and are commonly deployed in environments such as routers, personal computers, cloud platforms, and enterprise networks. A packet-filtering firewall is one of the most basic types and operates by inspecting individual packets of data. It applies rules based on source and destination IP addresses, ports, and protocols to determine whether to allow or block traffic. A circuit-level gateway focuses on the handshake process of TCP connections, validating session legitimacy before data exchange occurs, ensuring that only secure communication channels are established.
[0070] Another type of firewall is the application-level gateway, often referred to as a proxy firewall, which operates at the application layer. This type filters traffic based on specific applications or protocols, providing precise control over incoming and outgoing data. A stateful inspection firewall enhances security by monitoring the state of active connections. It evaluates traffic based on the state, port, and protocol of connections and tracks all activity from initiation to closure, offering a more comprehensive approach than packet filtering.
[0071] More advanced firewalls, such as next-generation firewalls (NGFWs), combine traditional firewall capabilities with modem security features. These include intrusion prevention systems (IPS), application-layer filtering, and advanced threat detection and remediation. NGFWs are designed to address complex and evolving cyber threats, making them suitable for high-security environments.
[0072] Firewalls can be deployed as hardware, software, or cloud-based. Hardware firewalls are physical devices installed at network entry points, designed to filter and monitor traffic with dedicated processing power. Software firewalls, in contrast, are applications installed on individual devices or nodes, providing customizable and granular security control. Cloud-based firewalls, also known as firewall-as-a-service (FWaaS), operate within cloud environments and offer scalable, centralized management of security policies. The term “Communication port,” as used herein, refers to a virtual endpoint within firewalls and networks where network connections are initiated and terminated. Communication ports are software-defined constructs managed by a computer’s operating system, with each port associated with a specific process or service to facilitate data exchange over the network.
[0073] In the context of firewalls, communication ports play a crucial role in determining which network traffic is permitted or blocked. Firewalls operate by enforcing security rules that specify whether traffic on particular ports should be allowed to pass between networks. Typically, firewalls are deployed between a trusted network and an untrusted network to control access and protect against unauthorized communication.
[0074] As mentioned, firewalls are security systems that block or allow network traffic based on a set of security rules. They usually sit between a trusted network and an untrusted network, often the untrusted network being the Internet. For client computers to communicate with site systems, certain communication ports must be added as exceptions to a firewall protocol.
[0075] The term “Cryptographic token” as used herein, refers to a digital representation of a real -world asset or utility within a cryptographic system. It utilizes cryptographic techniques to ensure security, integrity, and ownership verification. These tokens are typically created and managed through blockchain or distributed ledger technology.
[0076] Cryptographic tokens serve various purposes, such as facilitating secure transactions, providing access to services or platforms, representing ownership rights, or representing a stake in a project or ecosystem. They can be fungible or non-fungible, depending on whether each token is interchangeable with others of the same type or if each token has unique characteristics. Cryptographic tokens often leverage cryptographic algorithms and digital signatures to verify the authenticity and integrity of transactions and ensure that only authorized individuals can transfer or access them. They can be utilized in various applications, including cryptocurrencies, security tokens, utility tokens, non-fungible tokens (NFTs), and more.
[0077] The term “Identification Sequence” as used herein refers to a unique, cryptographically secure string or code generated during the identification process to distinguish and verify entities within the system. The identification process is configured to create an identification sequence for uniquely identifying nodes, orchestrators, and tenants requesting access to the nodes. The identification sequence may incorporate cryptographic techniques, such as digital signatures or secure hashing algorithms, to ensure authenticity and prevent tampering.
[0078] The term “Pull operation” as used herein refers to a communication mechanism in which individual nodes within a distributed network environment initiate requests to retrieve commands or data from the orchestrator. This process circumvents traditional network firewall restrictions by allowing nodes to initiate outbound requests, effectively bypassing inbound connection blocks commonly enforced by firewalls.
[0079] The term “Get request” as used herein, refers to a type of request usually used in web development and APIs to retrieve or fetch data from a data source or server. Generally, it is a method used to obtain information without modifying the resource being accessed. In the context of web applications, a GET request is typically initiated by a client (such as a web browser or an application) and sent to a server. The request specifies a specific resource or URL that the client wants to access. The server processes the request and returns the requested data as a response.
[0080] To mention some key characteristics of a GET request: • Retrieval of Data: The primary purpose of a GET request is to retrieve data from a data source or server. It is commonly used to access web pages, retrieve API data, or obtain specific resources such as images, files, or documents.
[0081] • URL-Based: A GET request includes a URL (Uniform Resource Locator) that identifies the desired resource. The URL typically contains the protocol (e.g., http: / / or https: / / ), the server address, and the path to the resource.
[0082] • Stateless: Each GET request is independent and self-contained. The server does not maintain any state or information about previous requests from the same client. Consequently, each GET request is considered independent of any other requests.
[0083] • Idempotent: A GET request is idempotent, meaning that multiple identical GET requests should produce the same result. Making the same GET request multiple times should not have any side effects or alter the resource being accessed.
[0084] • No Request Body: Unlike other request methods like POST or PUT, a GET request does not typically include a request body. All the necessary information is passed through the URL and query parameters.
[0085] • Caching: GET requests are often cacheable, meaning that the response can be stored by the client or intermediate systems like proxies. This caching mechanism can help improve performance and reduce the need for repeated requests for the same resource.
[0086] In summary, a GET refers to a method that may be used in web development and APIs to retrieve data from a data source or server and it may be characterized by its URL-based nature, stateless behavior, idempotency, and focus on data retrieval rather than data modification.
[0087] The term “Node” as used herein generally refers to a system or device that serves as a connection point within a network, enabling communication and data exchange between various components. Nodes can take different forms depending on the type of network and its purpose. Common examples of nodes in data communication networks include: Router: A router is a network device that forwards data packets between different networks. It examines the destination address of incoming data and determines the best path to send it to the appropriate destination.
[0088] • Switch: A switch is a network device that connects multiple devices within a local area network (LAN). It receives data packets and forwards them to the intended recipient based on the destination MAC (Media Access Control) address.
[0089] • Server: A server is a powerful computer that provides services or resources to other devices in the network. It can store data, host websites, manage email, run applications, and perform various network-related tasks.
[0090] • Computer: Any computer or computing device connected to the network can be considered a node. These include desktop computers, laptops, smartphones, tablets, and other devices that can send, receive, or process data.
[0091] • Wireless Access Point: In wireless networks, an access point serves as a central hub that enables devices to connect wirelessly to the network. It facilitates communication between wireless devices and allows them to access network resources.
[0092] • Modem: A modem is a device that converts digital data from a computer into a format suitable for transmission over a communication channel, such as a telephone line or a cable. It modulates the signals for transmitting data and demodulates them upon reception.
[0093] • Gateway: A gateway acts as an interface between different networks or protocols, allowing communication and data exchange between them. It translates data formats, manages routing, and facilitates interoperability between disparate networks. In summary, nodes are fundamental components of data communication networks, functioning as building blocks that work together to ensure efficient data transmission and delivery. They range in complexity from basic devices like switches and access points to sophisticated systems like servers and routers, depending on the network's scale and requirements Reference is now made to FIG. 1, which schematically illustrates a conventional storage array system 1. As shown, storage array 1.2 (that may be, for example, Dell EMC data storage and backup array or any other commercially available data storage system), contains multiple storage medias 1.4 configured to store and provide data accessibility to multiple servers 1.0. According to some embodiments, storage array 1.2 may be operatable by an operating system that includes various storage / control components designated to control and manage the operation of storage array 1.2 and the storage media 1.4 embedded within.
[0094] According to some embodiments, said conventional storage array system 1 may be configured to use a storage array 1.2 standard control plane (CP) and avoid installing any additional CP software on the servers 1.0. According to some embodiments, an operating system installed on the storage array 1.2 and includes storage and control components may be, by way of example, Linux based distributions, such as RedHat, SuSE, or Microsoft Windows server, etc.
[0095] Reference is now made to FIG. 2, which schematically illustrates a conventional storage array system 1. As shown, storage array 1.2 contains multiple storage media stacks 1.4 configured to store and provide data accessibility to multiple servers 1.0. According to some embodiments, storage array 1.2 contains data plane DP 1.6 and control plane CP 1.8 components and protocols, wherein the CP 1.8 components and protocols are configured to control various operations of the DP 1.6 components and protocols. Typically, the DP and the CP of storage solutions are coupled together, whereas such coupling presents inefficiencies and drawbacks wherein the integrated storage software oversees data services, such as data protection, high availability, space allocation, and / or data reduction as well as overseeing control services like volume creation, drive failure handling, snapshot rollback, etc.
[0096] Reference is now made to FIG. 3, which schematically illustrates a conventional cloudbased data management system 2. As shown, various components and protocols are designated to perform various tasks and ensure a reliable data allocation and storing. Said components and protocols require constant debugging and maintenance as well as update to technological advancement / s. Thus, the current quality and performance of the integrated cloud-based data management system 2 comes at a cost of considerable resources. According to some embodiments, cloud-based data management system 2 may be a solid-state drive (SSD) data center solution, meaning, its media storages are SSD stacking that form a part of a cloud -based storage array.
[0097] Reference is now made to FIG. 4 which schematically illustrates node-based communication system 10, according to some embodiments of the invention. As shown, node section 200 (that may be a distributed storage section) and orchestrator 100 may be configured to have a reverse communication channel allowing orchestratori 00 to connect to storage component 202 of node section 200.
[0098] According to some embodiments, the communication channel may be established by the node section 200 initiating a GET request to the orchestration section 100. Once this communication channel has been established, bi-directional flow of data between orchestrator 100 and the node 200 is enabled.
[0099] According to some embodiments, message broker 104 operates under the control of control component 102 of orchestrator 100. Control component 102 manages the configuration and operation of message broker 104 by defining routing rules and creating and monitoring message queues. By exerting control over message broker 104, control component 102 ensures that the configuration of message broker 104 aligns with the overall system’s operational requirements and workload demands.
[0100] According to some embodiments, firewall component 204 allows the orchestration section 100 to receive data from node section 200and vice versa since it is conducted via a reverse communication protocol for example, by way of a GET request, initiated by the node section 200 and hence the cyber security protocol of firewall component 204 does not need to be altered or changed in any way by a user using the system.
[0101] According to some embodiments, designated connector component 208 may establish and maintain a communication path between orchestrator 100 and node 200 (for example, distributed storage section / storage component 202). According to some embodiments, a cyber security protocol 204 such as a firewall may allow the orchestration section 100 to receive data from node section 200 (for example, distributed storage section / storage component 202) and vice versa since it is conducted through a communication port that has been initiated and opened by the node section 200 (for example, by distributed storage section / storage component 202) and hence, the cyber security protocol 204 does not need to be altered or changed in any way by a user using the system.
[0102] According to some embodiments, an open GET request may be automatically terminated after a predefined period of time to prevent it from remaining active indefinitely, which could otherwise increase the risk of a security breach.
[0103] According to some embodiments, message broker component 104 is designated to enable asynchronous communication by decoupling the timing of message transmission and retrieval. For example, the control component 102 or connector component 208 may send a message to the message broker 104. Once the message broker 104 receives the message, it processes and manages the communication independently, ensuring that the message is delivered to the node section 200 or orchestrator 100 at an appropriate time. This asynchronous mechanism allows the message broker 104 to flexibly handle communication between the node section 200 and the orchestration section 100, enabling efficient coordination without requiring the sender (e.g., control component 102 or connector component 208) and recipient (e.g., node section 200 or orchestrator 100) to interact simultaneously.
[0104] Reference is now made to FIG. 5 which schematically illustrates the architecture of a node based communication system 10, according to some embodiments of the invention. As shown, orchestration section 100 is configured to have various communication paths with node section 200 (for example, distributed storage section / storage component 202). According to some embodiments, message broker 104 (for example, a Kfka based component) may send massages to connector 206 (for example, container storage interface (CSI) connector by Kubernetes, etc.).
[0105] According to some embodiments, a message broker 104 is a software that enables applications, systems, and services to communicate with each other and exchange information. According to some embodiments, message broker 104 may be configured to translate messages between different languages, platforms, and protocols. It can also validate, transform, route, and deliver messages to the appropriate destinations. According to some embodiments, message broker may also be configured to reduce the mutual awareness and dependency of the communicating parties.
[0106] According to some embodiments, some examples of message brokers include: Amazon
[0107] MQ, Apache ActiveMQ, Apache Kafka, Apache Qpid, Apache Pulsar, Eclipse Mosquitto
[0108] MQTT Broker, EMQX MQTT Broker, Google Cloud Pub / Sub and more. According to some embodiments, message broker 104 may be used in various scenarios such as cartelized and distributed storage networks, e-commerce transactions where they help to process payments by communicating between user interfaces, payment gateways, and bank systems. Message broker 104 may also used in loT applications where they manage and control the communication between a large number of devices, sensors, and systems. According to some embodiments, a connector 206 may be an application / software program that enables communication between two or more applications, systems, or devices. In the context of Kubernetes, a connector application can be used to connect a Kubernetes cluster with other systems or applications.
[0109] According to some embodiments, some examples of connector applications may include the following examples:
[0110] • Config Connector by Google Cloud: Config Connector is an open-source Kubernetes addon that allows managing Google Cloud resources through Kubernetes. Config Connector, may leverage how Kubernetes manages Resources including RBAC for access control, events for visibility, single source of configuration and desired state management for reduced complexity, and eventual consistency for loosely coupling dependencies.
[0111] • Kubernetes Cluster Connector by Harness. io: a platform-agnostic connection to a Kubernetes cluster located anywhere. It may allow to connect Hamess to Kubernetes clusters using a Kubernetes Cluster Connector or Google Cloud Platform (GCP)
[0112] Connector. • Amazon EKS Connector: a tool that allows connecting an external Kubernetes cluster to Amazon EKS with AWS CLI and the AWS Management Console. The process involves two steps: Registering the cluster with Amazon EKS and applying a YAML manifest file to enable connectivity.
[0113] According to some embodiments, the communication between node section 200 (for example, distributed storage section / storage component 202) and orchestration section 100 is designated to be conducted using a designated port 208 (such as port 443, etc.)
[0114] According to some embodiments, designated port 208 may be port 443 which is a virtual port that may be used by computers to divert and handle network traffic. It is the universal port for all encrypted traffic on the internet. Websites may use HTTPS protocol through port 443 in order to secure data transfer and communication between the browser and the server. Port 443 may also make webpages available on both HTTP and HTTPS.
[0115] According to some embodiments, various cyber security components and DNS services are designated to protect and secure the messages fetching process, as part of the operation of node based communication system 10. Among them are: Route 53, WAF, Cognito, API gateway, AWS cloud front, S3, etc.
[0116] According to some embodiments and as previously mentioned, node based communication system 10 may include cybersecurity practices in order to protect critical systems and sensitive information from digital attacks. A strong cybersecurity strategy has layers of protection to defend against cybercrime, including cyberattacks that attempt to access, change, or destroy data; extort data from users or the organization; or aim to disrupt normal business operations. Some examples of cybersecurity components may include: Critical infrastructure security: practices for protecting the computer systems, networks, and other assets.
[0117] • Network security: security measures for protecting a computer network from intruders, including both wired and wireless (Wi-Fi) connections.
[0118] • Application security: processes that help protect applications operating on-premises and in the cloud. Security may be built into applications at the design stage, with considerations for how data is handled, user authentication, etc.
[0119] Cloud security: specifically, true confidential computing that encrypts cloud data at rest (in storage), in motion (as it travels to, from and within the cloud) and in use (during processing) to support customer privacy, business requirements and regulatory compliance standards. According to some embodiments, a massage broker component 104 may be a Kafka or any other known massage broker. According to some embodiments, massage broker component 104 may be a consumer producer message broker that may have a low latency since a fetched control massage may be “on air” and awaiting to be sent.
[0120] Reference is now made to FIG. 6 which schematically illustrates the transmission of connector-originated messages, contingent upon the outcome of the node state verification procedure, according to some embodiments of this invention.
[0121] According to some embodiments, in conventional systems, node section 200 may be configured to send multiple messages to orchestration section 100 to report on the status of the system. Excessive messages, or chattiness, may have a significant impact on the operational parameters of the node-based communication system 10, owing to the potential for excessive message traffic to overload communication pathways and consume processing resources, thereby reducing overall system performance. According to some embodiments, a solution for excessive chattiness is the inclusion of connector module 208 which may be configured to repetitively, at specified time intervals, operates a node state verification procedure, and thereby generates a connector-originated message.
[0122] According to some embodiments, connector module 208 operates under the control of orchestrator 100, which defines the parameters and conditions for the transmission of the connector-originated messages which are generated based on the results of the node state verification procedure, which connector module 208 executes to monitor and evaluate the operational state of the node.
[0123] According to some embodiments, connector module 208 does not have the capacity to interpret the responses to the node state verification procedure and can only detect a change in the parameters of the connector originated message in response to the node state verification procedure.
[0124] According to some embodiments, node 200 relays the connector originated message only when connector module 208 detects that the parameters set by orchestrator 100 have been breached.
[0125] According to some embodiments, this reduces chattiness by limiting the number of messages sent from node 200 to orchestrator 100, ensuring that communication occurs only when there is a meaningful change in the node's status, as defined by orchestrator 100. By filtering out redundant or unnecessary updates, the connector module 208 prevents excessive message traffic, reducing the load on communication pathways and processing resources, and thereby improving the overall efficiency and responsiveness of the node-based communication system 10. Reference is now made to FIG. 7 which schematically represents a unique identification process designated to increase security levels as part of the operation of the node based communication system 10, according to some embodiments of the invention. As shown, connector 108 may be configured to identify a specific certificate / sequence in order to ensure that the traffic originate from the orchestration section 100 is designated to reach a particular node section 200 (for example, distributed storage section / storage component 202) and vice versa. According to some embodiments, said identification process may be conducted using designated technological means such as cryptography.
[0126] According to some embodiments, the identification process designated to create a unique identification sequence configured to enable an exact identification of at least one particular tenant having an access to at least one particular node section 200 (for example, distributed storage section / storage component 202). According to some embodiments, a designated cryptographic token is created for each particular tenant and node section (for example, distributed storage section / storage component 202) in order to provide an exact identification of a particular node section / a node component.
[0127] For example, a designated token may be created in order to represent a certain node section 200 (for example, distributed storage section / storage component 202) and in according to the following steps:
[0128] • 402- Distributed storage section 200 or a storage component 202 is conjoined with a designated cryptographic token.
[0129] • 404- Connector 108 is identified as designated to interact with a particular storage center 200 / storage component 202. 406- An application programming interface (API) responds with node section 200 (for example, distributed storage section / storage component 202) which is uniquely conjoined with connector 108 using a designated token.
[0130] • 408- Connector 108 is configured to save distributed storage section 200 / storage component 202 with its conjoined token locally.
[0131] According to some embodiments, a third party designated service may be used to produce and maintain the cryptographic process. According to some embodiments, the API gateway and Cognito used for identification may be integrated with the cryptographic methods disclosed above.
[0132] Although the present invention has been described with reference to specific embodiments, this description is not meant to be construed in a limited sense. Various modifications of the disclosed embodiments, as well as alternative embodiments of the invention will become apparent to persons skilled in the art upon reference to the description of the invention. It is, therefore, contemplated that the appended claims will cover such modifications that fall within the scope of the invention.
Claims
CLAIMS1. Anode-based communication system comprising:(i) at least one orchestrator, and(ii) at least one node comprising at least one connector module, wherein the at least one orchestrator is in communication with at least one connector module of the at least one node; wherein the at least one connector module repetitively, at specified time intervals, operates a node state verification procedure generating a connector originated message; and wherein the at least one connector module is configured to send said at least one connector originated message to the at least one orchestrator upon a change in message characteristics identified by the at least one connector module, the identified change being in accordance with criteria predesignated by the at least one orchestrator and accordingly communicated to the at least one connector module.
2. The system of claim 1, wherein the Node based communication system further comprises at least one message broker.
3. The system of claim 1, wherein the at least one node initiates a reverse communication with the at least one orchestrator thereby circumventing network security protocols, including firewall restrictions.
4. The system of claim 3, wherein the reverse communication initiated by the at least one node is implemented using a GET request.
5. The system of claim 3, wherein the network security system is a firewall network security system.
6. The system of claims 1, wherein the at least one node is a storage node containing at least one storage component.
7. The system of claim 6, wherein the at least one storage component comprises at least one designated connector module configured to initiate and maintain a communication port between the at least one orchestrator and the at least one node, wherein the communication port is designated to allow data flow in a reverse direction between the at least one orchestrator and the at least one node.
8. The system of claim 6, wherein the at least one storage component may comprise various types of storage devices, including hard disk drives (HDDs), solid-state drives (SSDs), non-volatile memory express (NVMe) drives, storage class memory (SCM), and RAM disks, as well as storage systems such as object storage, block storage, and file storage.
9. The system of claim 1, wherein the at least one orchestrator is configured to define and adjust thresholds that determine whether messages are transmitted from the at least one connector module to the at least one orchestrator.
10. The system of claim 9, wherein the at least one orchestrator is configured to instruct the at least one connector module to transmit updates to the at least one orchestrator only when changes in the output parameters of the at least one node exceeds a predefined threshold, and to prevent updates to the at least one orchestrator when changes remain below this threshold.
11. The system of claim 1, wherein at least one orchestrator includes an anti-failure mechanism configured to detect and resolve communication malfunctions between the at least one orchestrator and the at least one connector module of the at least one node.
12. The system of claim 1, wherein an identification process is performed to generate a unique identification sequence configured to facilitate identification of the at least one node, the at least one orchestrator, and the at least one tenant requesting access to the at least one node.
13. The system of claim 12, wherein the unique identification sequence is a unique cryptographic sequence.
14. The system of claim 12, wherein the at least one connector module is configured to establish and maintain the unique identification sequence.
15. The system of claim 12, wherein the identification prosses is provided by an integrated third-party service.
16. The system of claim 12, wherein a designated cryptographic token is created for each tenant and each at least one node in order to provide an exact identification.
17. A method for node-based communication, comprising:(i) operating at least one orchestrator in communication with at least one node, wherein the node comprises at least one connector module;(ii) executing, by the at least one connector module, a node state verification procedure repetitively at specified time intervals, wherein the procedure generates at least one connector-originated message based on the operational state of the at least one node;(iii) identifying, by the at least one connector module, changes in the message characteristics generated during the node state verification procedure, wherein the changes are determined based on criteria predesignated by the at least one orchestrator and communicated to the at least one connector module;(iv) transmitting the connector-originated message from the at least one connector module to the at least one orchestrator upon detecting changes in the message characteristics that meet or exceed the predesignated criteria; andwherein the at least one orchestrator adjusts system resources or operations based on the received connector-originated message.
Citation Information
Patent Citations
Security orchestration and network immune system deployment framework
US20180368007A1
Hierarchical orchestration of a computer network
US20190140958A1