Domain Manager Mediating Multi-Domain Authentication in DMS Clusters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data management and storage systems face challenges in providing interoperability and efficient data portability across different virtual machine platforms and computing infrastructures, which are often hindered by the use of various operating systems, protocols, and authentication methods.

Innovation Solution

A data management and storage (DMS) cluster with peer nodes that provide domain shares and directory service authentication, allowing for the creation of containers for different domains, authenticating client devices, and connecting them to authorized domain shares across multiple domains, thereby enabling interoperability across diverse computing infrastructures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple different virtualization platforms and compute infrastructures are supported, then interoperability and data portability are improved, but system complexity and authentication management become more difficult

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a domain manager as an intermediary component that mediates between client devices and domain shares across different compute infrastructures. The domain manager receives authentication information, determines the client's domain, selects the appropriate container, and coordinates the authentication process with the target container, thereby simplifying cross-platform interoperability without requiring direct integration between all platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments domain shares into separate containers, where each container is associated with a specific domain. This segmentation allows the domain manager to selectively engage with only the relevant container for a given authentication request, reducing the complexity of managing multiple domains and platforms simultaneously while maintaining organized, isolated authentication contexts.

Inventive Principle:
Principle #1Segmentation

2Reliability

If domain-specific containers are created for different compute infrastructures, then authentication accuracy and access control are improved, but device complexity and management overhead increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The domain manager serves multiple functions within a single component: it receives authentication requests, determines client domains, selects appropriate containers, and coordinates authentication processes. This multi-functionality reduces the need for separate specialized components for each domain, thereby maintaining authentication accuracy while reducing overall system complexity and management overhead.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a domain manager coordinates authentication across multiple domains, then data security and access control are improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-organizing domain shares into domain-specific containers and establishing the domain manager's routing logic in advance. When an authentication request arrives, the domain manager can quickly determine the client's domain and select the appropriate container without ad-hoc analysis, thereby maintaining security through proper authentication coordination while reducing processing time through pre-established pathways.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If containers are selected based on client domain correspondence, then data portability across platforms is improved, but system complexity and authentication management become more difficult

Engineering Contradiction:
Improvedata portabilityVSAvoidauthentication management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The domain manager acts as an intermediary that handles the complexity of domain-based container selection. It receives authentication requests from client devices, determines the client's domain, and automatically selects the corresponding container. This mediation simplifies data portability across platforms by providing a unified interface for domain-based access control, while the domain manager internally manages the complexity of matching clients to the correct containers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10862887B2Multiple domain authentication using data management and storage node
Publication Date: 2020.12.08 RUBRIK INC
  • US10862887B2 patent drawing
  • US10862887B2 patent drawing
  • US10862887B2 patent drawing

AI summary

A data management and storage (DMS) cluster of peer DMS nodes provides domain shares and authentication for different domains. Each DMS node includes a domain manager and multiple containers, each container including a domain share. Each container associated with a domain may provide an authentication service for authenticating users for a different domain to access domain shares of the domain, such as by contacting a domain controller of a compute infrastructure associated with the domain. The domain manager controls the creation and deletion of containers and their domain shares. The domain manager also provides a proxy service for the containers for communication with client devices of different domains external to the DMS cluster.