Secure Multitenant Hadoop Cluster Operator Onboarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Hadoop clusters lack effective methods for securing and automating multitenant operations, leading to inefficient and cumbersome access control configurations, especially in scenarios where multiple operators share the same hardware.

Innovation Solution

A method for secure operator onboarding and ingest job agent creation that includes authenticating operators, creating segregated access control lists, and establishing isolated data transfer pipelines within the Hadoop cluster, using a centralized directory and authentication server to automate the onboarding process and ensure secure multitenant operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual access control configurations are used in Hadoop clusters, then operators can access and modify all data on the cluster, but security is compromised and configuration becomes cumbersome

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments access control by creating separate access control lists for different operators, dividing the monolithic Hadoop cluster access into granular, operator-specific permission sets. This allows each operator to have customized access rights to specific data and resources rather than universal access, thereby improving security while maintaining ease of operation through automated provisioning.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control layer between operators and Hadoop cluster resources. This intermediary mechanism automatically provisions and manages access control lists, acting as a mediator that enforces security policies without requiring manual configuration by operators, thus resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If automated operator onboarding is implemented, then provisioning time is reduced, but system complexity increases

Engineering Contradiction:
Improveprovisioning timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-configuring access control templates and policies before operator onboarding. When an operator joins the cluster, the system automatically applies these pre-defined configurations, eliminating the need for manual setup and reducing provisioning time. The complexity is managed through template-based automation rather than ad-hoc configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service automated onboarding where operators can be provisioned automatically through self-contained workflows that handle account creation, access control list generation, and resource allocation without requiring administrator intervention. This reduces provisioning time while the self-service nature manages complexity through standardized processes.

Inventive Principle:
Principle #25Self-service

3Productivity

If multitenant data storage is implemented, then resource sharing is improved, but security isolation becomes more difficult to maintain

Engineering Contradiction:
Improveresource sharingVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by implementing operator-specific access control lists that customize permissions for each operator's local interactions with cluster resources. While data is physically shared across the cluster (improving resource sharing), each operator experiences locally tailored access rights that maintain security isolation. This allows multitenant storage while preserving security through granular, location-specific permission controls.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11979434B2System and method for secure multitenant operations of a distributed computing cluster
Publication Date: 2024.05.07 NORTHROP GRUMMAN SYSTEMS CORP
  • US11979434B2 patent drawing
  • US11979434B2 patent drawing
  • US11979434B2 patent drawing

AI summary

A system and a method for secure operator onboarding and creating an ingest job agent for secure multitenant operations of a distributed computing cluster are provided. Embodiments automate multitenant operations for distributed computing clusters. These operations include automation of operator onboarding, creation of logically segregated distributed data stores within the distributed computing clusters for the on-boarded operator, and creation of ingest agents with security isolation for transfer of large quantities of files into the distributed computing clusters. Embodiments provide multitenant security, in which the same Hadoop cluster serves multiple operators with each operator's data and processes in effective isolation. In this manner, multitenant security keeps each user's data storage and operations on the Hadoop cluster separated from other operators.