Systems and methods for secure data aggregation and computation
US-2020226284-A1 · Jul 16, 2020 · US
US11272024B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11272024-B2 |
| Application number | US-202016745272-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 16, 2020 |
| Priority date | Jan 16, 2020 |
| Publication date | Mar 8, 2022 |
| Grant date | Mar 8, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Persistent connections are provided between components in a container environment. A hypertext transfer protocol (HTTP) client may include a monitoring service and a proxy service. To obtain information regarding containers in the container environment, the monitoring service communicates a request to the proxy service. The proxy service in turn maintains a persistent connection for a session with a container management service using an authentication token, and communicates the request to the container management service during the session. The container management service obtains the requested information from the container(s) and returns the information in a response to the proxy service, which in turn returns the response to the monitoring service. The session is destroyed/ended only under certain error conditions—otherwise, the session between the proxy service and the container management system is kept persistent.
Opening claim text (preview).
We claim: 1. A method in a virtualized computing environment to communicate using a connection, the method comprising: establishing, by a proxy, a persistent connection between the proxy and a container management service using an authentication token, wherein the container management service is configured to communicate information with containers, residing in the virtualized computing environment, that are managed by the container management service; establishing, by the proxy, a session on the persistent connection based on the authentication token, an address of the container management service and an identifier (ID) of a particular container of the containers; receiving, by the proxy from a monitoring service, a request for the information; sending, by the proxy to the container management service, the request for the information; receiving, by the proxy from the container management service, a response to the request; maintaining the persistent connection and the session, if the response is indicative of a valid request and contains the requested information, and sending, by the proxy, the response to the monitoring service; and tearing down, by the proxy, the persistent connection, if the response is indicative of an error. 2. The method of claim 1 , wherein the persistent connection is a hypertext transfer protocol (HTTP) connection. 3. The method of claim 1 , wherein the proxy and the monitoring service are components of an HTTP client that presents the requested information in a monitoring dashboard. 4. The method of claim 1 , wherein establishing the session includes: determining the address of the container management service; acquiring the authentication token; determining the ID; and launching the proxy. 5. The method of claim 1 , wherein the error includes at least one of: an authentication error, a gateway error, an unavailable service, a request error, or an error to propagate to the monitoring service for review by a system administrator. 6. The method of claim 5 , further comprising, in response to the authentication error: requesting, by the proxy from the container management service, a new authentication token; receiving, by the proxy from the container management service, the new authentication token; using, by the proxy, the new authentication token to re-establish the persistent connection; and sending, by the proxy to the container management service, the request for the information using the re-established persistent connection. 7. The method of claim 1 , wherein the proxy is a service that processes the request to determine path information and payload information that specifies details of the request. 8. A non-transitory computer-readable medium having instructions stored thereon, which in response to execution by one or more processors, cause the one or more processors to perform or control performance of operations for a proxy in a virtualized computing environment to communicate using a connection, the operations comprising: establishing, by a proxy, a persistent connection between the proxy and a container management service using an authentication token, wherein the container management service is configured to communicate information with containers, residing in the virtualized computing environment, that are managed by the container management service; establishing, by the proxy, a session on the persistent connection based on the authentication token, an address of the container management service and an identifier (ID) of a particular container of the containers; receiving, by the proxy from a monitoring service, a request for the information; sending, by the proxy to the container management service, the request for the information; receiving, by the proxy from the container management service, a response to the request; maintaining the persistent connection and the session, if the response is indicative of a valid request and contains the requested information, and sending, by the proxy, the response to the monitoring service; and tearing down, by the proxy, the persistent connection, if the response is indicative of an error. 9. The non-transitory computer-readable medium of claim 8 , wherein the persistent connection is a hypertext transfer protocol (HTTP) connection. 10. The non-transitory computer-readable medium of claim 8 , wherein the proxy and the monitoring service are components of an HTTP client that presents the requested information in a monitoring dashboard. 11. The non-transitory computer-readable medium of claim 8 , wherein establishing the session includes: determining the address of the container management service; acquiring the authentication token; determining the identifier (ID) of a particular container to be monitored; and launching the proxy. 12. The non-transitory computer-readable medium of claim 8 , wherein the error includes at least one of: an authentication error, a gateway error, an unavailable service, a request error, or an error to propagate to the monitoring service for review by a system administrator. 13. The non-transitory computer-readable medium of claim 12 , wherein the operations further comprise, in response to the authentication error: requesting, by the proxy from the container management service, a new authentication token; receiving, by the proxy from the container management service, the new authentication token; using, by the proxy, the new authentication token to re-establish the persistent connection; and sending, by the proxy to the container management service, the request for the information using the re-established persistent connection. 14. The non-transitory computer-readable medium of claim 13 , wherein the proxy is a service that processes the request to determine path information and payload information that specifies details of the request. 15. A device, comprising: a processor to operate a proxy; and a non-transitory computer-readable medium coupled to the processor and having instructions stored thereon, which in response to execution by the processor, cause the processor to perform or control performance of operations for the proxy to communicate using a connection in a virtualized computing environment, wherein the operations include: establishing, by a proxy, a persistent connection between the proxy and a container management service using an authentication token, wherein the container management service is configured to communicate information with containers, residing in the virtualized computing environment, that are managed by the container management service; establishing, by the proxy, a session on the persistent connection based on the authentication token, an address of the container management service and an identifier (ID) of a particular container of the containers; receiving, by the proxy from a monitoring service, a request for the information; sending, by the proxy to the container management service, the request for the information; receiving, by the proxy from the container management service, a response to the request; maintaining the persistent connection and the session, if the response is indicative of a valid request and contains the requested information, and send, by the proxy, the response to the monitoring service; and tearing down, by the proxy, the persistent connection, if the response is indicative of an error. 16. The device of claim 15 , wherein the persistent connection is a hypertext transfer protocol (HTTP) connection. 17. The device of claim 15 , wherein the proxy and the monitoring
Adding application-functional data or data for application control, e.g. adding metadata · CPC title
using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title
Provisioning of proxy services (store-and-forward switching systems in data switching networks H04L12/54) · CPC title
using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title
by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.