Mechanism for providing external access to a secured networked virtualization environment

US11310286B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11310286-B2
Application numberUS-202016747272-A
CountryUS
Kind codeB2
Filing dateJan 20, 2020
Priority dateMay 9, 2014
Publication dateApr 19, 2022
Grant dateApr 19, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for providing external access into a secured networked virtualization environment, includes performing a leadership election amongst nodes of the secured networked virtualization environment to elect a leader node, assigning a cluster virtual IP address to the leader node and generating a reverse tunnel, using a processor, by the leader node to allow for an external entity to communicate with the secured networked virtualization environment.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes a set of acts, the set of acts comprising: electing a leader node from a cluster of nodes within a secured networked virtualization environment, respective nodes of the cluster of nodes each having an IP address; assigning a cluster virtual IP address to the leader node, the cluster virtual IP address being different from the IP address of the leader node; and generating a reverse tunnel with at least the cluster virtual IP address, wherein the reverse tunnel gives a node external to the secured networked virtualization environment access to the secured networked virtualization environment. 2. The computer readable medium of claim 1 , wherein electing the leader node is performed by electing a first node corresponding to a first position in a queue as the leader node, wherein the queue is populated based on an order of receipt of heartbeat responses. 3. The computer readable medium of claim 1 , wherein the IP address for each of the respective nodes comprise a private IP address and communications within the secured networked virtualization environment utilize a corresponding private IP address. 4. The computer readable medium of claim 1 , wherein generating the reverse tunnel comprises identifying, by the leader node, a port number at the node external to the secured networked virtualization environment through which the node external to the secured networked virtualization environment is to communicate with the leader node. 5. The computer readable medium of claim 1 , wherein generating the reverse tunnel comprises identifying a port number at the node external to the secured networked virtualization environment by requesting the node external to the secured networked virtualization environment for an available port number and receiving the available port number from the node external to the secured networked virtualization environment. 6. The computer readable medium of claim 1 , wherein generating the reverse tunnel comprises performing a secured shell (SSH) command using a port number, the cluster virtual IP address and a public SSH key for the node external to the secured networked virtualization environment. 7. The computer readable medium of claim 1 , wherein the node external to the secured networked virtualization environment is identified by iterating over a list of external entities associated with the secured networked virtualization environment. 8. The computer readable medium of claim 1 , wherein a list of external entities associated with the secured networked virtualization environment is updated by requesting a current external entity from the list of external entities for an updated list of external entities and modifying the list of external entities to add or remove an external entity. 9. The computer readable medium of claim 1 , wherein a list of external entities associated with the secured networked virtualization environment is assigned to the secured networked virtualization environment based on a unique identifier for the secured networked virtualization environment. 10. The computer readable medium of claim 1 , wherein a node of the cluster of nodes present storage aggregated from a plurality of storage devices spread across the cluster of nodes. 11. A method, comprising: electing a leader node from a cluster of nodes within a secured networked virtualization environment, respective nodes of the cluster of nodes each having an IP address; assigning a cluster virtual IP address to the leader node, the cluster virtual IP address being different from the IP address of the leader node; and generating a reverse tunnel with at least the cluster virtual IP address, wherein the reverse tunnel gives a node external to the secured networked virtualization environment access to the secured networked virtualization environment. 12. The method of claim 11 , wherein electing the leader node is performed by electing a first node corresponding to a first position in a queue as the leader node, wherein the queue is populated based on an order of receipt of heartbeat responses. 13. The method of claim 11 , wherein the IP address for each of the respective nodes comprise a private IP address and communications within the secured networked virtualization environment utilize a corresponding private IP address. 14. The method of claim 11 , wherein generating the reverse tunnel comprises identifying, by the leader node, a port number at the node external to the secured networked virtualization environment through which the node external to the secured networked virtualization environment is to communicate with the leader node. 15. The method of claim 11 , wherein generating the reverse tunnel comprises identifying a port number at the node external to the secured networked virtualization environment by requesting the node external to the secured networked virtualization environment for an available port number and receiving the available port number from the node external to the secured networked virtualization environment. 16. The method of claim 11 , wherein generating the reverse tunnel comprises performing a secured shell (SSH) command using a port number, the cluster virtual IP address and a public SSH key for the node external to the secured networked virtualization environment. 17. The method of claim 11 , wherein a list of external entities associated with the secured networked virtualization environment is updated by requesting a current external entity from the list of external entities for an updated list of external entities and modifying the list of external entities to add or remove an external entity. 18. The method of claim 11 , wherein a list of external entities associated with the secured networked virtualization environment is assigned to the secured networked virtualization environment based on a unique identifier for the secured networked virtualization environment. 19. The method of claim 11 , wherein a node of the cluster of nodes present storage aggregated from a plurality of storage devices spread across the cluster of nodes. 20. The method of claim 11 , wherein the node external to the secured networked virtualization environment is identified by iterating over a list of external entities associated with the secured networked virtualization environment. 21. A system comprising: a memory to hold a sequence of instructions; and a processor to execute the sequence of instructions, which when executed cause a set of acts, the set of acts comprising: electing a leader node from a cluster of nodes within a secured networked virtualization environment, respective nodes of the cluster of nodes each having an IP address; assigning a cluster virtual IP address to the leader node, the cluster virtual IP address being different from the IP address of the leader node; and generating a reverse tunnel with at least the cluster virtual IP address, wherein the reverse tunnel gives a node external to the secured networked virtualization environment access to the secured networked virtualization environment. 22. The system of claim 21 , wherein electing the leader node is performed by electing a first node corresponding to a first position in a queue as the leader node, wherein the queue is populated based on an order of receipt of heartbeat responses. 23. The system of claim 21 , wherein th

Assignees

Inventors

Classifications

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • Hypervisor-specific management and integration aspects · CPC title

  • Network integration; Enabling network access in virtual machine instances · CPC title

  • H04L63/205Primary

    involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • Firewall traversal, e.g. tunnelling or, creating pinholes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11310286B2 cover?
A method for providing external access into a secured networked virtualization environment, includes performing a leadership election amongst nodes of the secured networked virtualization environment to elect a leader node, assigning a cluster virtual IP address to the leader node and generating a reverse tunnel, using a processor, by the leader node to allow for an external entity to communica…
Who is the assignee on this patent?
Nutanix Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/205. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 19 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).