Unified Multi-Cluster Access with Cross-Cluster Role Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cluster management systems fail to provide effective and efficient user access to multi-cluster and multi-tenant environments, requiring manual account creation and different interfaces for each computing cluster, leading to an inefficient decentralized setup.

Innovation Solution

A centralized system is implemented where a primary computing cluster is bootstrapped to secondary clusters, allowing users to access them via a persistent connection using a single interface, with credentials and roles bound to multiple clusters, enabling seamless access and management across multiple computing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual account creation and separate interfaces are used for each computing cluster, then user access control is maintained, but system complexity and operational difficulty increase

Engineering Contradiction:
Improveuser access controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate cluster interfaces into a single unified interface that provides access to multiple computing clusters. The system combines authentication mechanisms and user management across clusters, allowing users to access multiple clusters through one interface instead of creating separate accounts for each cluster.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a universal interface that serves multiple functions: it provides authentication, authorisation, and access management across multiple computing clusters simultaneously. This single interface is designed to be multi-functional, handling various user access scenarios across different clusters without requiring separate specialized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Stability of the object's composition

If separate interfaces are provided for each computing cluster, then cluster independence is maintained, but user efficiency and accessibility deteriorate

Engineering Contradiction:
Improvecluster independenceVSAvoiduser efficiency
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system that sits between users and multiple computing clusters. This intermediary interface manages the complexity of interacting with multiple independent clusters by providing a unified access point. The intermediary handles authentication, authorisation, and request routing, allowing users to access multiple clusters without directly managing their independence.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If decentralized user management is implemented across multiple clusters, then autonomy is preserved, but time consumption and operational overhead increase

Engineering Contradiction:
ImproveautonomyVSAvoidtime consumption
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing authorisation relationships and credentials between clusters before users need to access them. The system performs advance configuration of trust relationships, authentication mechanisms, and access policies, so that when users need to access multiple clusters, the groundwork is already in place and they can proceed without time-consuming setup.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12406039B2Multi-cluster access
Publication Date: 2025.09.02 KASTEN INC
  • US12406039B2 patent drawing
  • US12406039B2 patent drawing
  • US12406039B2 patent drawing

AI summary

Disclosed herein are system, method, and computer program product embodiments for multi-cluster access. In some embodiments, the server receives a first request to bind one or more cluster roles associated with a user to each of one or more secondary computing clusters. The server binds the user's credentials with the one or more cluster roles corresponding to each of one or more secondary computing clusters. Furthermore, the server receives a second request for providing the user access to the primary computing cluster. Moreover, the server receives a third request from the user interface intended for at least one secondary computing cluster. The server forwards the third request to the at least one secondary computing cluster while impersonating at least one cluster role of the one or more cluster roles corresponding to the at least one secondary computing cluster.