Cluster Claim for Unified Datacenter Storage Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users managing multiple datacenters remotely face challenges with separate browser sessions leading to confusion and errors, as they need to maintain multiple connections, which is inefficient and prone to mistakes.

Innovation Solution

A cluster claim procedure that allows users to register secondary storage systems with a cloud service system, enabling unified management through a single browser session by generating and propagating cluster state information, which includes a security token, to establish bidirectional communication without requiring a VPN connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate remote connections are used for each datacenter, then each datacenter can be accessed and managed, but the complexity of management increases and errors occur due to multiple browser sessions

Engineering Contradiction:
ImproveAbility to access multiple datacentersVSAvoidNumber of separate connections and browser sessions
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate remote connections into a single unified browser session. The cluster claim procedure allows a user to claim multiple secondary storage systems (across different datacenters) in one session, eliminating the need for separate VPN connections and browser sessions for each datacenter. This combining approach directly reduces connection complexity while maintaining multi-datacenter accessibility.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified browser session provides universal access to multiple datacenters through a single interface. The system enables one browser session to function as multiple separate connections would, allowing the user to manage secondary storage systems across different datacenters without needing specialized separate connection setups for each location.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate remote connections are maintained for each datacenter, then all datacenters can be managed, but time is lost due to session management and potential confusion

Engineering Contradiction:
ImproveAccess to multiple datacentersVSAvoidTime spent managing multiple connections and sessions
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

By combining multiple datacenter access operations into a single browser session through the cluster claim procedure, the system eliminates the time required to switch between separate VPN connections and browser sessions. The user claims multiple secondary storage systems in one session, reducing time loss associated with session management.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate connections are used for each datacenter, then each can be accessed independently, but reliability decreases due to confusion and errors from multiple sessions

Engineering Contradiction:
ImproveIndependent access to datacentersVSAvoidAccuracy of datacenter management operations
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple independent connection management tasks into a single unified session, eliminating the confusion that arises from managing multiple separate browser sessions. The cluster claim procedure maintains clear identification of which secondary storage system is being accessed within the unified session, preventing errors while preserving independent access capabilities.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If VPN connections are required for each datacenter, then secure access is achieved, but device complexity and ease of operation worsen due to multiple connection requirements

Engineering Contradiction:
ImproveSecurity of datacenter accessVSAvoidSimplicity of accessing multiple datacenters
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges multiple VPN connection requirements into a single browser session without compromising security. The cluster claim procedure establishes one secure connection that provides access to multiple secondary storage systems across different datacenters, eliminating the need for separate VPN connections while maintaining security standards.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified browser session acts as an intermediary that provides secure access to multiple datacenters without requiring separate VPN connections for each. This intermediary approach simplifies the connection process while maintaining the security previously achieved through individual VPN connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11522850B2Cluster claim
Publication Date: 2022.12.06 COHESITY INC
  • US11522850B2 patent drawing
  • US11522850B2 patent drawing
  • US11522850B2 patent drawing

AI summary

Cluster state information is generated in response to a request to establish a connection with a cloud service system. The cluster state information includes a first instance of a security token and host information. The cluster state information is provided to a web browser associated with a user. The web browser associated with the user is redirected to a cloud identity provider. The cloud identity provider is configured to provide to the cloud service system via the web browser associated with the user, the cluster state information that includes the first instance of the security token and the host information. A certificate is requested from the cloud service system. The cluster state information that includes a second instance of the security token is provided to the cloud service system. The cloud service system is configured to establish the connection based on comparison between the first instance of the security token and the second instance of the security token. The established connection enables the user to manage a secondary storage system via the cloud service system.