Systems and methods for providing secure multicast intra-cluster communication
Abstract
A system that facilitates secure multicast communication between any valid node in the cluster by using authentication between the node attempting to join the cluster and any single node that is effectively part of the cluster. And the method is disclosed. According to embodiments, cluster keys are used to provide security for intra-cluster communication. The cluster key of the embodiment is shared by a node that is already part of the cluster only after the node that is about to join the cluster and these two nodes mutually authenticate each other. The mutual authentication handshake of the embodiment implements a protocol in which the session key is calculated by both nodes, thereby providing a secure means by which the cluster key can be shared. Having a cluster key, each node in the cluster, whether individually (eg, unicast communication) or collectively (eg, multicast communication), with any other node in the cluster, according to embodiments. It becomes possible to communicate safely.
Term
5.6 yearsto projected expiry
Projected expiry 17 April 2032, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
23 claims: 4 independent, 19 dependent
- 1以下を含む、安全なマルチキャスト通信機能をクラスタの複数のノードに提供するための方法: 前記クラスタに参加しようとしているノードと、有効に前記クラスタの部分である任意の単一のノードとの間で相互認証セッションを実行すること、および 前記相互認証が成功である場合に、前記相互認証セッションに固有の安全な通信チャネルを使用して、前記クラスタに参加しようとしている前記ノードにクラスタ秘密を伝達することであって、前記クラスタ秘密が、前記クラスタに参加しようとしている前記ノードをクラスタノードにし、かつ前記クラスタノードの、有効に前記クラスタの部分である他の全てのノードとの安全な通信を可能にする、クラスタ秘密を伝達すること。
- 2前記クラスタに参加しようとしている前記ノードが、前記相互認証セッションを、有効に前記クラスタの部分である前記単一のノードのみと実行した後に、クラスタノードになる、請求項1に記載の方法。
- 3有効に前記クラスタの部分である前記単一のノードが、前記クラスタに参加しようとしている前記ノードのピアノードである、請求項1に記載の方法。
- 4相互認証セッションを実行することが、 前記クラスタに参加しようとしている前記ノードおよび前記単一のノードによって別々にセッション鍵を計算することであって、前記セッション鍵が前記相互認証セッションに固有である、別々にセッション鍵を計算すること を含む、請求項1に記載の方法。
- 5クラスタ秘密を伝達することが、 前記セッション鍵を使用して、前記クラスタに参加しようとしている前記ノードと前記単一のノードとの間でクラスタ鍵を伝達すること を含む、請求項4に記載の方法。
- 6相互認証セッションを実行することが、 前記クラスタに参加しようとしている前記ノードと、前記相互認証セッションを実行している前記クラスタの前記ノードを含む有効に前記クラスタの部分である全てのノードとによって保有されるクラスタ認証情報を使用して、前記相互認証セッションに対して別々にベリファイアを計算すること を含む、請求項1に記載の方法。
- 7クラスタ認証情報を使用してベリファイアを計算することが、前記クラスタに参加しようとしている前記ノードを一意に識別する情報をさらに使用する、請求項6に記載の方法。
- 8前記クラスタ認証情報が、前記クラスタに参加しようとしている前記ノードおよび前記相互認証セッションを実行している前記クラスタの前記ノードの各々に別々に投入されたクラスタパスワードを含む、請求項6に記載の方法。
- 9相互認証セッションを実行することが、 前記クラスタに参加しようとしている前記ノードが前記クラスタ内で許可されたノードの登録簿に含まれていると判断すること を含む、請求項1に記載の方法。
- 10前記クラスタ秘密が、対称暗号鍵を含む、請求項1に記載の方法。
- 11前記クラスタ秘密を再生成すること、および 有効に前記クラスタの部分である前記ノードの全てに、前記再生成されたクラスタ秘密を取得するために、かかるノードの各々と前記クラスタの別のノードとの間で相互認証セッションを再度実行することを要求すること をさらに含む、請求項1に記載の方法。
- 12前記クラスタ秘密を再生成することが定期的に実行される、請求項11に記載の方法。
- 13前記クラスタ秘密を再生成することが、ノードが前記クラスタから離れると実行される、請求項11に記載の方法。
- 14クラスタの第1のノードと前記クラスタの第2のノードとの間で相互認証ハンドシェイクを実行すること、 前記第1のノードと前記第2のノードとの間の前記相互認証ハンドシェイクによって確立された安全な通信チャネルを使用して、前記第1のノードと前記第2のノードとの間でクラスタ鍵を伝達すること、 前記クラスタの第3のノードと、前記第1のノードおよび第2のノードのうちの一方との間で相互認証ハンドシェイクを実行すること、 前記第3のノードと前記第1のノードおよび前記第2のノードのうちの前記一方との間の前記相互認証ハンドシェイクによって確立された安全な通信チャネルを使用して、前記第3のノードと前記第1のノードおよび第2のノードのうちの前記一方との間でクラスタ鍵を伝達すること、ならびに 前記クラスタ鍵を使用して、前記第1のノード、前記第2のノード、および前記第3のノードの間で安全なクラスタ通信を実行すること を含む方法。
- 15前記第1のノードと前記第2のノードとの間で前記相互認証ハンドシェイクを実行することが、前記第1のノードおよび前記第2のノードによって別々に第1のセッション鍵を計算することを含み、前記第1のノードと前記第2のノードとの間の前記相互認証ハンドシェイクによって確立された前記安全な通信チャネルが、前記第1のセッション鍵を使用して保護され、かつ、前記第3のノードと、前記第1のノードおよび前記第2のノードのうちの前記一方との間で前記相互認証ハンドシェイクを実行することが、前記第3のノードならびに、前記第1のノードおよび前記第2のノードのうちの前記一方によって別々に第2のセッション鍵を計算することを含み、前記第3のノードと、前記第1のノードおよび前記第2のノードのうちの前記一方との間の前記相互認証ハンドシェイクによって確立された前記安全な通信チャネルが、前記第2のセッション鍵を使用して保護される、請求項14に記載の方法。
- 16前記安全なクラスタ通信が、ユニキャスト通信およびマルチキャスト通信を含む、請求項14に記載の方法。
- 17前記第1のノードと前記第2のノードとの間で相互認証セッションを実行することが、 前記第1のノードおよび前記第2のノードによって保有されるクラスタパスワードを使用して第1のベリファイアを計算することであって、前記クラスタパスワードが前記第1のノードおよび前記第2のノードの各々に別々に投入される、第1のベリファイアを計算すること を含み、かつ、前記第3のノードと、前記第1のノードおよび第2のノードのうちの一方との間で相互認証セッションを実行することが、 前記第3のノードならびに、前記第1のノードおよび第2のノードのうちの前記一方によって保有される前記クラスタパスワードを使用して第2のベリファイアを計算することであって、前記クラスタパスワードが前記第3のノードならびに前記第1のノードおよび第2のノードのうちの前記一方の各々に別々に投入される、第2のベリファイアを計算すること を含む、請求項14に記載の方法。
- 18第1のプロセッサベースのネットワーク接続された装置の動作を制御するコードに従って、複数のノードのクラスタの1つのノードとして動作するように適合された、第1のプロセッサベースのネットワーク接続された装置であって、前記第1のプロセッサベースのネットワーク接続された装置の前記コードが、前記クラスタのノードとして動作する1つまたは複数の他のプロセッサベースのネットワーク接続された装置に対する、前記クラスタの秘密の安全な供給源および前記クラスタの前記秘密の安全な受信者の両方としての前記第1のプロセッサベースのネットワーク接続された装置の動作を提供し、かつ、前記クラスタの前記秘密が前記クラスタの全てのノード間での安全な通信を可能にするように適合されている、第1のプロセッサベースのネットワーク接続された装置 を備えるシステム。
- 19前記クラスタの前記秘密が暗号クラスタ鍵を含む、請求項18に記載のシステム。
- 20前記第1のプロセッサベースのネットワーク接続された装置の、前記クラスタの前記秘密の供給源としての前記動作が、1つまたは複数の他のプロセッサベースのネットワーク接続された装置が、前記第1のプロセッサベースのネットワーク接続された装置のみとの認証を通じて、前記クラスタにノードとして参加するのを容易にし、かつ、前記第1のプロセッサベースのネットワーク接続された装置の、前記クラスタの前記秘密の受信者としての前記動作が、前記クラスタに参加しようとしている前記第1のプロセッサベースのネットワーク接続された装置を、前記1つまたは複数の他のプロセッサベースのネットワーク接続された装置のうちの1つの他のプロセッサベースのネットワーク接続された装置のみとの認証を通じて容易にする、請求項18に記載のシステム。
- 21前記第1のプロセッサベースのネットワーク接続された装置の前記コードが、前記他のプロセッサベースのネットワーク接続された装置のうちの1つのプロセッサベースのネットワーク接続された装置との相互認証セッションを実行するように適合されていて、相互認証セッションが、前記クラスタ秘密の安全な伝達に対して適合された前記相互認証セッションに固有の安全な通信チャネルを提供する、請求項18に記載のシステム。
- 22前記第1のプロセッサベースのネットワーク接続された装置が前記クラスタに参加しようとしている場合に、前記相互認証セッションが、前記第1のプロセッサベースのネットワーク接続された装置を有効に前記クラスタの部分であるノードとして認証し、前記安全な通信チャネルによって伝達された前記クラスタ秘密を受信するように動作可能であり、かつ、前記第1のプロセッサベースのネットワーク接続された装置が、前記1つまたは複数の他のプロセッサベースのネットワーク接続された装置のうちの前記1つのプロセッサベースのネットワーク接続された装置による前記クラスタの参加を交渉している場合に、前記相互認証セッションが、前記1つまたは複数の他のプロセッサベースのネットワーク接続された装置のうちの前記1つのプロセッサベースのネットワーク接続された装置を認証し、前記1つまたは複数の他のノードのうちの前記1つのプロセッサベースのネットワーク接続された装置が成功裏に認証された場合に前記安全な通信チャネルによって前記クラスタ秘密を伝達するように動作可能である、請求項21に記載のシステム。
- 23前記第1のプロセッサベースのネットワーク接続された装置が、複数のノードの前記クラスタの部分として、自身の前記動作を制御するコードに従って動作するように適合された複数のプロセッサベースのネットワーク接続された装置のうちの1つであり、前記複数のうちの各プロセッサベースのネットワーク接続された装置の前記コードが、前記クラスタの秘密の安全な供給源および前記クラスタの前記秘密の安全な受信者の両方としての前記それぞれのプロセッサベースのネットワーク接続された装置の動作を提供し、かつ、前記複数のうちの各プロセッサベースのネットワーク接続された装置が、前記複数のうちの単一の他のプロセッサベースのネットワーク接続された装置と認証する自身のコードの動作によって前記クラスタに参加し、前記複数のうちの他の全てのプロセッサベースのネットワーク接続された装置と安全に通信するように適合されている、請求項18に記載のシステム。
Independent claims23
50 paragraphs, as filed
The present invention relates generally to intra-cluster communication, and more specifically to providing secure multicast intra-cluster communication.
Background of the invention There are various system configurations in which different nodes in one cluster communicate with each other, and the nodes can operate to provide the desired function, service, or operation, or a portion thereof, an operating unit (eg, an operating unit). It is a processor-based system) and can collaborate with other nodes to form a cluster. For example, a data storage system often includes multiple storage devices located at different nodes of the data storage system. Such data storage systems can be implemented using various storage architectures such as network attached storage (NAS) environments, storage area networks (SAN), direct attached storage environments, and combinations thereof. Data storage system nodes can include processor-based systems such as file server systems, computer appliances, and computer workstations. Storage devices at different nodes can include disk drives, flash memory, optical memory, and the like. A selection of storage devices can be organized as a storage array according to the storage architecture. Thus, the nodes hosting the storage array storage devices as well as other networked devices may form a cluster of nodes that can work together to provide a data storage system.
To operate as a cluster, the nodes of the cluster communicate with each other. Such communications may include various point-to-point communications (eg, single node to single node or unicast communications) and multicast communications (eg, single node to multiple nodes). Therefore, each node of the cluster may need to have the ability to communicate with any and all other nodes of the cluster in order to effectively collaborate and provide the desired behavior. However, such communications may include public or other network lines (eg, the Internet, public switched telephone network (PSTN), local area network (LAN), metropolitan area network (MAN), wide area network (WAN), etc.). It can pass through unsafe lines. Communication carried out through lines without such security measures may be susceptible to interception, eavesdropping, tampering, surveillance, sniffing, man-in-the-middle attacks, relay attack, replay attacks, etc. is there.
Therefore, various security protocols have been implemented in the past to facilitate communication between the nodes of the cluster (ie, intra-cluster communication). For example, Secure Sockets Layer (SSL) and Transport Layer Security (TLS) security protocols are implemented by the nodes of the cluster to secure intra-cluster communication. SSL and TLS are cryptographic protocols that provide communication security using asymmetric encryption for privacy and keyed message authentication code for message reliability. However, these security protocols are point-to-point security protocols. That is, a unique key set is used for each node pair. Therefore, secure multicast communication is not provided through the use of SSL and TLS security protocols.
Protocols have been developed to provide secure multicast communication, but such protocols have so far not provided sufficient security for multicast communication and are adequately capable of dynamically associating nodes with clusters. Absent. One such protocol that has been used to provide security for communications is JGROUPS. JGROUPS provides a multicast protocol in which a "grouping" layer is added through the transport protocol. To provide security for multicast communications, JGROUPS implements its AUTOH and ENCRYPT protocols. However, the AUTOH protocol uses one-way authentication (ie, only one node) using a single token-based authentication (eg, a password or other authentication certificate transmitted over an unsecured line). Only provides (to authenticate the other), so an eavesdropper can monitor communications and mimic a security handshake (eg, replay attack) to establish a fake authentication. The ENCRYPT protocol uses a cluster key to encrypt all multicast communications. However, the cluster key of the ENCRYPT protocol is provided to any node that provides its own public key and requests the cluster key. Therefore, even with the AUTOH and ENCRYPT protocols implemented by JGROUPS, intermediaries can easily join the cluster, and therefore the security provided for multicast communication is somewhat illusionary.
The present invention uses authentication between a node attempting to join a cluster and any single node that is effectively part of the cluster to ensure secure multicast communication between any valid node in the cluster. Regarding systems and methods to facilitate. According to an embodiment of the present invention, a cluster key (eg, a symmetric cryptographic key) is utilized to provide security for intra-cluster communication. The cluster key of the embodiment is shared by a node that is already part of the cluster only after the node that is about to join the cluster and these two nodes mutually authenticate each other. The mutual authentication handshake of the embodiment implements a protocol in which the session key is calculated by both nodes, or is otherwise associated with that protocol, thereby transmitting the session key over a network or other line. Facilitates secure lines between nodes without. A session key is provided so that the node attempting to join the cluster and the node already part of the cluster can securely share the cluster key after these two nodes mutually authenticate each other according to embodiments of the present invention. used. Having a cluster key, each node in the cluster securely communicates with any other node in the cluster, whether individually (eg, unicast communication) or collectively (eg, multicast communication). Will be possible.
From the above, it can be understood that the embodiment of the present invention facilitates a node to join the cluster by authenticating to any node in the cluster. Embodiments of the present invention do not rely on public key infrastructure (PKI) or certificates in providing authentication for nodes. Therefore, configuration and maintenance related to PKI or certificate management is avoided. However, embodiments herein are available authentication protocols, key sharing, albeit in new ways that have been tuned for use within a cluster environment for multicast communication or otherwise adapted. Key-agreement protocols and / or cryptographic algorithms or parts thereof may be utilized, thereby utilizing well-tested and fully documented basic techniques.
Once authenticated, trust in the participating nodes is established on the nodes throughout the cluster. That is, the node that is going to join the cluster basically authenticates to the cluster as a logical unit in order to join. Therefore, a node attempting to join a cluster may, according to embodiments herein, for all nodes in the cluster, or as required by any approach that implements a point-to-point protocol. You don't even have to authenticate to multiple nodes. Once joined, the nodes of the cluster will be able to communicate with the other nodes of the cluster using a variety of messaging techniques, including unicast and multicast messaging. In contrast to the operation of embodiments of the present invention, multicast communication technology is not readily implemented in point-to-point protocols.
The above outlines some of the features and technical advantages of the invention in order to better understand the details of the invention that follow. Additional features and advantages of the invention that form the subject matter of the claims of the invention are described below. It should be understood by those skilled in the art that the disclosed concepts and specific embodiments can be readily utilized as a basis for modification or design of other structures in order to accomplish the same object of the present invention. is there. Those skilled in the art should also appreciate that such equivalent structures do not deviate from the spirit and scope of the invention described in the appended claims. The novel features considered to be characteristics of the present invention, both with respect to the configuration and method of operation of the present invention, are better understood from the following description when considered in connection with the accompanying figures, along with additional objectives and advantages. Will be done. However, it should be clearly understood that each of the figures is provided for purposes of illustration and illustration only and is not intended as a limitation definition of the present invention.
For a more complete understanding of the present invention, the following description is referred to herein in conjunction with the accompanying figures.
<figref num="1A">A block diagram of a system adapted to allow each node of the cluster to securely communicate with any other node of the cluster according to an embodiment of the invention is shown.</figref><figref num="1B">A block diagram of a system adapted to allow each node of the cluster to securely communicate with any other node of the cluster according to an embodiment of the invention is shown.</figref><figref num="2">According to an embodiment of the present invention, a ladder diagram of a high level process flow is shown that allows each node of the cluster to securely communicate with any other node of the cluster.</figref><figref num="3">A ladder diagram of a more detailed process flow is shown that allows each node of the cluster to securely communicate with any other node of the cluster according to an embodiment of the invention.</figref>
Detailed description of the invention A concise description of the meaning of the particular terms used herein is provided below to help the reader better understand the concepts of the invention described in the description below. The following provides general meanings for a particular term, but it should be understood herein that additional meanings for a particular term may be provided in the context of the particular embodiments described below. ..
As used herein, a cluster is a group of nodes that are connected or otherwise associated with each other to provide the desired functionality, service, or behavior. In many respects it forms a single logical element. A node is, for example, a processor-based system (eg, computer, network appliance, etc.) and an associated instruction set (eg, software) that can operate to provide the desired function, service, or operation, or a portion thereof. , Firmware, applications, etc.), which is the operating unit of networked equipment, which can work with other nodes to form a cluster. In-cluster communication is communication between two or more nodes in a cluster, such as unicast communication and multicast communication. Unicast communication is the transmission of one or more messages or information to a single network destination (eg, a node). Multicast communication is the transmission of one or more messages or information to multiple network destinations (eg, nodes) by a single transmission.
As used herein, authentication is the process by which one party (eg, a node) verifies the identity of another party (eg, another node), while mutual authentication is the process of two parties (eg, another node). , Node) is the process of confirming each other's identities. An authentication handshake is a dialogue of messages between two parties (eg, nodes) attempting to authenticate one or the other (authentication) or both (mutual authentication). In a key-agreement protocol, two or more parties (eg, nodes) calculate a unique key separately without the need for both parties to influence the outcome and thereby transfer a unique key (eg, a session key) between the parties. It is a protocol that can be shared about keys (eg, encryption keys used in data encryption and / or decryption) in such a way that it is easy to do and thus avoid eavesdropping and tampering. Eavesdropping is when a third party (eg, a node that is not part of the cluster) monitors the communication without the consent and / or knowledge of the parties involved in the communication (eg, the nodes of the cluster). Tampering is between parties communicating data without the knowledge of the parties involved in the communication (eg, the nodes of the cluster) by a third party (eg, a networked device that is not part of the cluster). If the data is being altered or otherwise tampered with during transmission. Cryptography makes information (called plaintext before encryption) unreadable by anyone other than those who have special information, usually called a key (for example, a cryptographic key). The process of converting using an algorithm, while decryption is the process of converting encrypted information back into plaintext.
With reference to FIG. 1A, a system 100 including a plurality of network-connected devices, represented as network-connected devices 110-130, coupled via the network 101 is shown. Networked devices 110-130 may include processor-based systems such as file server systems, computer appliances, computer workstations, and the like. Therefore, the network-connected devices 110 to 130 of the embodiment include a processor (eg, central processing unit (CPU), application-specific integrated circuit (ASIC), programmable gate array (PGA), etc.), memory (eg, random access). Memory (RAM), read-only memory (ROM), disk memory, optical memory, flash memory, etc.), and suitable input / output circuits (eg, network interface card (NIC), wireless network interface, display, keyboard, data bus, etc. )including. The processor-based system described above may operate under the control of an instruction set (eg, software, firmware, applets, code, etc.) that provides the behavior as described herein. The network 101 may include various forms of communication infrastructure such as the Internet, PSTN, LAN, MAN, WAN, wireless networks (eg, cellular communication networks, wireless LANs, etc.), and / or the like.
Various configurations of system 100 may be provided in which one or more clusters of nodes are formed from networked devices 110 and 120, thereby providing a cluster environment, within which cluster coordination. This operation is facilitated through communication between the nodes of the cluster. For example, a data storage system may be formed from networked devices 110-130 and may be one or more storage devices present in networked devices 110 and 120 (eg, disk drives, flash memory, optical memory, etc.). (Eg, storage devices 114 and 124) work together to provide accessible volumes for networked device 130. The networked devices 110 and 120 hosting the storage array storage and the client networked device 130 thus constitute a cluster of nodes that can work together to provide a data storage system. Can be.
FIG. 1B provides a block diagram showing additional details about an embodiment of System 100 adapted to allow each node of the cluster to securely communicate with any other node in the cluster. As mentioned above, the system 100 is networked to provide access to the data stored on the set of storage devices (represented as storage devices 114 and 124) that make up the storage of the system 100. It may include two or more interconnected devices, such as devices 110 and 120. Storage services may be provided by such nodes that implement various functional components that work together to provide a distributed storage system architecture for System 100.
By way of example, a node (eg, networked devices 110 and 120) has one or more network elements (N modules 112 and 122) and / or storage elements (D modules 113 and 123) and a management element (M host). It can be organized as 111 and 121). The N module may include a function that allows a node to connect to one or more clients (eg, networked device 130) via the computer network 101, while the D module may include (eg, network-connected device 130). It can be connected to a storage device (for example, as a storage array can be implemented). The M-host may provide cluster communication services between nodes to generate information sharing operations and to present a distributed file system image to system 100. A feature for allowing each node in the cluster to securely communicate with any other node in the cluster may be provided by an M-host adapted according to embodiments of the present invention.
It should be understood that network 101 can include various forms of network infrastructure, and even separate parts. For example, networked devices 110 and 120 may be interconnected by a cluster switching structure 102, while networked devices 110 and 120 may be networked by a more general data network (eg, internet, LAN, etc.). It may be interconnected to a networked device 130.
Although the same number of N and D modules that make up the illustrated embodiment of the node are shown, there may be different numbers and / or types of functional components that embody the node according to various embodiments of the invention. Should also be noted. For example, there may be multiple N and / or D modules interconnected within the system 100 that do not show a one-to-one correspondence between the modules of the networked devices 110 and 120. Therefore, the description of networked devices 110 and 120 including one N module and one D module should be construed as exemplary only, and the novel techniques are exemplary practices described herein. It will be understood that it is not limited to the form.
The networked device 130 can be a general purpose computer configured to interact with the networked devices 110 and 120 according to the information distribution client / server model. To that end, the networked device 130 may request the services of the networked devices 110 and 120 by submitting a read or write request to the cluster node containing the networked device. In response to the request, the node may return the result of the requested service by exchanging information packets over the network 101. The networked device 130 includes, for example, a common Internet file system (CIFS) protocol, a network file system (NFS) protocol, a small computer system interface (SCSI) protocol (SCSI) encapsulated via TCP, and a fiber. Access requests can be submitted by issuing packets using an object-based access protocol, such as SCSI (FCP) encapsulated over a channel. Preferably, networked devices 110 and 120 may implement a combination of file-based and block-based protocols to communicate with networked device 130.
System 100 further includes a management console (referred to herein as management console 150) for providing management services to the entire cluster. For example, the management console 150 requests that the operation be performed on a cluster node composed of networked devices, and requests information from the node (eg, node configuration, operation metrics), or Alternatively, it may communicate with networked devices 110 and 120 via network 101 to provide information to the node. In addition, the management console 150 may be configured to receive input from a user of system 100 (eg, a storage administrator) and provide output to the user of system 100, thereby with the administrator and system 100. Acts as a centralized management interface between. In an exemplary embodiment, the management console 150 may be networked to networked devices 110-130, while other embodiments of the invention connect the management console 150 to system 100 or system 100. Can be implemented as a functional component of the nodes or any other processing system that make up.
In a distributed architecture, networked device 130 may submit to a node an access request for data stored on a remote node. As an example, an access request from a networked device 130 may be sent to a networked device 120 that may target a storage object (eg, a volume) on the networked device 110 in the storage 114. To accelerate the processing of access requests and optimize cluster performance, the networked device 120 may cache the requested volume in local memory or in storage 124. For example, during initialization of the networked device 120 as a cluster node, the networked device 120 may use all or part of the volume from the networked device 110 as a networked device for such data. Prior to the actual request by 130, it may be requested for storage in the networked device 120.
As can be seen from the above, the networked devices 110-130 may communicate with each other to operate as a cluster (eg, the data storage system described above). Such communications may include various forms of communications (eg, point-to-point or unicast communications, multicast communications, etc.). Therefore, in order to effectively collaborate and provide the desired behavior as a logical element, each node of the cluster is provided with the ability to communicate with any or all nodes of the cluster according to embodiments of the present invention. .. However, network 101 may provide unsafe lines, and thus such communications may be vulnerable to interception, eavesdropping, tampering, surveillance, sniffing, man-in-the-middle attacks, relay terminal attacks, replay attacks, and the like. As such, embodiments of the present invention use authentication between a node attempting to join the cluster and any single node that is effectively part of the cluster, and any valid of the cluster. Provides secure communication between nodes (eg unicast and multicast).
A node trying to join the cluster authenticates to the cluster as a logical unit to join, thus providing secure communication between the node trying to join and any other valid node in the cluster. In obtaining and facilitating secure communication, the operation according to embodiments of the present invention allows between a node attempting to join a cluster and any single node that is effectively part of the cluster. An authentication session is executed. If the mutual authentication is successful, the behavior according to the embodiment uses a secure communication channel unique to the mutual authentication session (eg, using the session key calculated in connection with the mutual authentication). Communicate the cluster secret (eg, the cluster key) to the node trying to join the cluster. According to embodiments of the present invention, possession of cluster secrets and cluster credentials makes the node attempting to join the cluster a cluster node, and cluster secrets are all other parts of the cluster node that are effectively part of the cluster. Allows secure communication with nodes.
FIG. 2 shows, according to embodiments herein, nodes attempting to join a cluster individually (eg, for example) without authenticating to all or even a plurality of nodes in the cluster. Demonstrates a process flow that allows each node in a cluster to securely communicate with any other node in the cluster, whether in unicast communication) or collectively (eg, multicast communication). In particular, the ladder diagram of FIG. 2 shows when a new node (eg, networked device 120) joins a cluster in which another node (eg, networked device 110) is the first member. Authentication handshake, session key sharing, which occurs according to the embodiment Agreement), and cluster key exchange is provided. The function of the process flow shown in FIG. 2 is that the elements of the embodiments of the present invention are essentially processor-based or computer systems (eg, networked devices 110, 120, and / or) to perform the required tasks. It should be understood that it can be implemented in software that is a code segment that can operate on 130). The program or code segment can be stored on a computer-readable medium (eg, one of the aforementioned memories of each of the networked devices 110-130).
According to the illustrated embodiment, each node that effectively becomes a part of the cluster is considered to have cluster authentication information (eg, cluster password). Therefore, in the process 201 of the illustrated embodiment, the cluster authentication information is input to prove that the network-connected device 110 is a node that is to be effectively included in the cluster. It should be understood that various techniques can be implemented for the input of cluster credentials. For example, a user of networked device 110 may type in the cluster password on the console of the networked device during boot, and the cluster password is a file protected by various means (eg, for example). It may be read from a file stored in the memory of a universal serial bus (USB) memory device temporarily attached to the networked device, and the cluster password is from other, perhaps secret, data. May be derived, etc. Regardless of the particular technique used to populate the node with cluster credentials, having the proper credentials allows the networked device 110 to effectively join the cluster.
In process 202, the networked device 110 determines that it is the first member in the cluster. Various techniques may be implemented for the networked device 110 to determine if other nodes in the cluster are present. For example, a networked device 110 may transmit one or more messages over the network 101 to query a response from another cluster node, and / or a networked device 110 may. , Can communicate with management nodes or other cluster resources that hold a database of member nodes (eg, management console, M-host, etc.). In addition or as an alternative, network-connected device 110 may monitor communication on network 101 to identify the presence of cluster communication traffic. In this way, in process 202, protecting the cluster communication, regardless of how the networked device 110 of the illustrated embodiment determines that it is the first member of the cluster. Generate a new cluster secret (eg, cluster key) to be used for.
Cluster keys, such as those utilized in accordance with embodiments herein, can be generated using a variety of techniques. For example, a cluster key can be generated using secure and / or random data. Systems often provide methods of generating pseudo-random data such that they can be seeded using data based on CPU temperature, fan speed, mouse movement, network traffic, and so on. Such pseudo-random data can be used in the calculation of cryptographic keys used as cluster keys herein. The cluster key generated according to an embodiment of the present invention includes a symmetric key (ie, the same cryptographic key provides symmetric encryption that provides both encryption and decryption). Therefore, configuration and maintenance related to PKI or certificate management is avoided for cluster communication using such cluster keys.
Since it holds the cluster secret and the cluster credentials, the networked device 110 is a member of the cluster (although it is currently the only member). The networked device 110, for example, broadcasts one or more messages, communicates with a management node or other cluster resource (eg, management console, M-host, etc.) that holds a database of member nodes, and so on. Can act to signal that it is a member of the cluster.
In the embodiment shown in FIG. 2, the networked device 120 wants to join a cluster in which the networked device 110 is currently the only member. Therefore, in the process 203 of the illustrated embodiment, the cluster authentication information is input to prove that the network-connected device 120 is a node that is to be effectively included in the cluster. As mentioned above for the networked device 110, various techniques can be implemented to populate the cluster credentials. Regardless of the particular technique used to populate the networked device with the cluster credentials, with the appropriate credentials, the networked device 120 can effectively join the cluster.
In process 204, the networked device 120 determines that at least one member is already in the cluster. As described above for the networked device 110, various techniques may be implemented for the networked device 120 to determine if other nodes in the cluster are present. In this way, in process 204, via network 101, regardless of how the networked device 120 of the illustrated embodiment determines that at least one member is already a member of the cluster. Then, a mutual authentication handshake is performed between the network-connected device 120 (which is about to join the cluster) and the existing cluster member (in this case, the network-connected device 110). To perform mutual authentication herein, the particular cluster node selected by the node that is trying to join has some criteria (eg, the cluster node that is the oldest member of the cluster, the most of the nodes that are trying to join. It can be selected based on one of the cluster nodes physically located nearby, the cluster node where the line with the fewest hops can be used, the cluster node with the least utilization, and so on. It should be understood that the cluster member selected for use in providing mutual authentication herein can be a peer node of a node attempting to join the cluster. That is, the management node or other centralized cluster resource does not need to be utilized, but rather is mutually authenticated and is mutually authenticated unless it is a peer node that is effectively part of the cluster (eg, the node that initiated the cluster secret). Each (holding a cluster secret) may provide authentication and cluster join processing according to embodiments herein.
An authentication handshake, as performed in accordance with embodiments of the present invention, results in mutual authentication of both networked device 120 and networked device 110. The use of such a mutual authentication handshake is a valid part of a networked device or cluster for which cluster secrets and / or credentials or other security information are not authorized as provided to valid members of the cluster. Guarantee that it will not be provided to other nodes that are not (eg, intermediaries). Various mutual authentication protocols can be utilized in providing the authentication handshake for process 204. Details regarding one such mutual authentication protocol are provided below in connection with the embodiment shown in FIG. Regardless of the particular mutual authentication protocol implemented, each of the networked devices 110 and 120 will be subjected to the operation of the mutual authentication handshake of the illustrated embodiment against the other of the networked devices 120 and 110. Be authenticated. At any time, if the networked device 110 or the networked device 120 detects an authentication failure, the participation process is preferably aborted.
In an operation according to an embodiment of the invention, both the networked device 110 and the networked device 120 have a session secret (as part of a mutual authentication handshake or in connection with a mutual authentication handshake). For example, the session key) is derived. Session secrets, such as those utilized in accordance with embodiments herein, can be generated using a variety of techniques. For example, the session key can be generated from the data collected during the authentication handshake. Details regarding one such technique for session key generation are provided below in connection with the embodiment shown in FIG. In the operation according to the embodiment of the present invention, cluster authentication information, user derived information, information common to all nodes in the cluster, and a detectable pattern can be presented or a session secret calculated separately. No other information that could otherwise compromise the security of the session secret is used to derive the session secret itself. Regardless of the particular technique used to generate the session secret, the embodiment operates to generate the session secret separately for each node participating in the mutual authentication handshake, and thus the session secret (eg, session). The key) is not passed through the line connecting the nodes (eg, network 101). Thus, in the illustrated embodiment, process 205 is performed by networked device 110 to calculate session secrets, separate from process 206 performed by networked device 120 to calculate session secrets. Will be done.
If the mutual authentication is successful, the session secret described above is in accordance with embodiments of the present invention in order to securely transmit the cluster secret from the networked device 110 to the networked device 120 via the network 101. It will be used. Therefore, in process 207 of the illustrated embodiment, the networked device 110 uses the session secret (eg, session key) to encrypt the cluster secret (eg, cluster key), and the encrypted cluster secret. Is transmitted to the device 120 connected to the network. For example, in process 207 of the embodiment, the cluster key encryption using the session key may use AES-128 symmetric key encryption. However, other cryptographic key algorithms (eg, IDEA (International Data Encryption)) Algorithm) and other symmetric cryptographic key algorithms such as the CAST-128 encryption algorithm) may be used according to embodiments of the present invention. The session key utilized in accordance with embodiments of the present invention does not rely on the use of PKI or certificates in providing node authentication and therefore avoids configuration and maintenance related to the management of PKI or certificates.
After transmitting the cluster secret to the networked device 120, a cluster join session between the networked devices 110 and 120 is completed with respect to the networked device 110 according to embodiments of the present invention, and thus the network. The connected device 110 can then destroy the session key. The networked device 110 effectively updates the list of nodes that are part of the cluster to include the newly added networked device 120, for example for use in later cluster operations, according to embodiments. Can work like this. It is understood that the networked device 110 can transmit additional information, such as the aforementioned list of nodes that are effectively part of the cluster, to the networked device 120 (before destroying the session secret). Should be. The network-connected device 120 of the embodiment decrypts the encrypted cluster secret received from the network-connected device 110 by using the session secret to acquire the cluster secret. After decrypting the cluster secret received from the networked device 110, a cluster join session between the networked devices 110 and 120 is completed with respect to the networked device 120 according to embodiments of the present invention, and therefore. The networked device 120 can then destroy the session key. The networked device 110 and / or the networked device 120 transmits information that identifies the networked device 120 as a cluster node to other nodes in the cluster (eg, using cluster secrets). obtain.
The networked device 120 is a member of the cluster (currently one of the two members) because it holds the cluster secret and the cluster credentials. Therefore, in the operation according to the embodiment, the network-connected device 120 trusts all the other members in the cluster, and all the other members in the cluster trust the network-connected device 120. Once joined, the nodes of the cluster use various messaging techniques, including unicast and multicast messaging via the use of cluster secrets (eg, encryption of messages using cluster keys), and other nodes of the cluster. Will be able to communicate with. That is, the networked device 120 can securely obtain the cluster secret shared by all other nodes in the cluster, and therefore the networked device 120 can use the cluster secret to obtain the cluster secret. They may communicate with those nodes either individually (eg, unicast communication) or collectively (eg, multicast communication). In this way, future communication to / from any member in the cluster uses cluster secrets (eg, cluster key encryption) as represented by process 208 in the illustrated embodiment. And be protected.
Message encryption using the cluster key in process 208 of the embodiment may use, for example, AES-128 symmetric key encryption. However, other cryptographic key algorithms (eg, other symmetric cryptographic key algorithms such as IDEA (International Data Encryption Algorithm) and CAST-128 cryptographic algorithms) may be used according to embodiments of the present invention. Cluster keys utilized in accordance with embodiments of the present invention do not rely on the use of PKI or certificates in providing node authentication, thus avoiding configuration and maintenance related to managing PKI or certificates.
As mentioned above, it should be understood that once authenticated by any node in the cluster, trust in the participating nodes is established in the nodes throughout the cluster. Therefore, a node attempting to join a cluster does not need to authenticate to all or even a plurality of nodes in the cluster according to embodiments herein. That is, a mutual authentication technique, such as that performed in accordance with embodiments herein, allows each node to be a cluster secret recipient that facilitates its own participation in the cluster, and other nodes to the cluster. It provides a configuration that is configured to be both a cluster secret source, which facilitates participation. Thus, a third node (eg, a networked device similar to the networked devices 110 and 120 in FIG. 1A) is formed to include the networked devices 110 and 120 in FIG. If you are trying to join a cluster, the node you are trying to join is with any single node that is already part of the cluster (eg, either networked device 110 or networked device 120). Perform mutual authentication and cluster secret sharing processes (eg, perform processes 203-207 in FIG. 2) to establish trust and any node in the cluster (eg, networked device 110 and networked device). The ability to communicate securely with both 120) can be established. That is, since the nodes that have successfully joined the cluster have a cluster secret (eg, a cluster key), any node can communicate with any other node in the cluster. This allows for unicast and multicast messages used for intra-cluster communication. As can be seen from the above, a node is provided with multicast communication functionality by only authenticating a single node in the cluster, as opposed to authenticating to all nodes in the cluster. This approach works for clusters of any size
FIG. 3 shows details about an embodiment of the process flow of FIG. 2 that provides an operation that allows each node of the cluster to securely communicate with any other node in the cluster. Specifically, the ladder diagram of FIG. 3 provides details about a mutual authentication protocol and techniques for session key generation that can be utilized in accordance with embodiments of the present invention. Therefore, processes 301-320 of FIG. 3 provide details about a process flow that can be operated to provide mutual authentication according to processes 204-207 of FIG. 2, and processes 315 and 319 are processes 205 and 206 of FIG. Provides details about process flows that can be operated to provide separate session secret calculations according to. Processes 201-203 and 208 of FIG. 3 correspond to processes 201-203 and 208 of FIG. 2, and processes 316, 317, 320 of FIG. 3 correspond to process 207 of FIG. Similar to the process flow of FIG. 2, the function of the process flow shown in FIG. 3 is that the elements of the embodiments of the present invention are essentially processor-based or computer systems (eg, networked) to perform the required tasks. It can be performed in software that is a code segment that can operate on devices 110, 120 and / or 130). The program or code segment can be stored on a computer-readable medium (eg, one of the aforementioned memories of each of the networked devices 110-130).
The embodiment shown in FIG. 3 utilizes a modified configuration of secure remote password protocol version 6a (SRP-6a) in providing mutual authentication and separate session secret computations. However, other authentication and key sharing protocols that provide mutual authentication of the two parties involved and a shared secret known only to the two parties involved in the handshake may be utilized in accordance with embodiments of the present invention. It is presumed that the authentication protocol, key sharing protocol, and encryption algorithm used are known to all nodes in advance, but the embodiments provided in accordance with the concepts herein are (eg, handshakes). It may act to dynamically select a particular protocol and / or algorithm that provides the behavior of this specification (through messages exchanged by the nodes, agreeing on a common set of protocols and algorithms before they occur).
In the operation according to the embodiment of the process flow shown in FIG. 3, the n and g values of the mutual authentication protocol are known to all the nodes in advance. For example, the values of n and g used in the embodiments may be agreed by the two parties in question. They can be preconfigured or the host can supply them to the client. In the latter case, the host should send the parameters with salt in the first message. For maximum security, n should be a safe prime (eg, a number in the form n = 2q + 1, where q in the equation is also a prime number). Also, g should be a generator modulo n, which has a value x of g ^ x% n == x for any x of 0 <x <n. Means that. However, alternative embodiments operate to return n and g values (eg, in process 304).
The K value of the mutual authentication protocol shown in the embodiment of FIG. 3 is used as the session key and is a pseudo-random function (PRF) (eg, the TLSv1 protocol defined in RFC 2246 section 5, the disclosure of which is herein by reference. Included) is calculated. However, a number of algorithms that can extend one secret (S) to another secret (K) can be used in session key calculations according to embodiments of the present invention.
It should be understood that the SRP-6a protocol was designed for use between the client and server, while the process flow mutual authentication shown in Figure 3 is performed on the nodes of the cluster. Is. In a client / server environment, the server typically stores a verifier (v) derived from the user's password, so the server does not store the user's password, but still validates the client using the user's password. Can work to do. In the cluster embodiment of the illustrated embodiment, each node knows the cluster password (eg, it can be entered by various means as described above) and therefore verifiers (v), SRP-6a. It does not need to be used by the protocol to store an ambiguous version of a user's password. Therefore, in the mutual authentication protocol shown in FIG. 3, at each authentication attempt (eg, processes 302 and 303), a salt (s) is generated and a verifier (v) is calculated (eg, trying to join the cluster). The cluster node name, address, or other information that uniquely or substantially uniquely identifies the existing node can be used as the username in the calculation). Each authentication attempt requires a verifier (v) calculation and therefore puts a load on the processing power that is not well suited for the large demands of the server environment, but the above modification is that in the client / server model. Facilitates the use of mutual authentication protocols by any node in the cluster rather than the use of a single point (server).
The behavior that allows each node of the cluster to securely communicate with any other node in the cluster, as provided by the embodiments described above in connection with FIGS. 2 and 3, is a cluster of any size. Not only is it extensible to, but also node reduction (node) It should be understood that attachment) management and / or can be easily adapted to provide enhanced security protocols. For example, the techniques implemented by the process flow described above can be extended to provide periodic cluster key rotation. In the operation according to the embodiment of periodic cluster key rotation, after a certain period of time, a new cluster key is generated by the node and all other nodes are reauthenticated to obtain the new cluster key. If a hacker or other unauthorized node has the current cluster key, the new cluster key is because the hacker or other unauthorized node can easily decrypt and obtain the new cluster key. Note that it will not be delivered to other nodes using the current cluster key. Such periodic cluster key rotation reduces the number of messages that can be decrypted if a hacker or other unauthorized node obtains or holds the cluster key as much as possible, thereby providing enhanced security.
The concept of periodic cluster key rotation described above can be utilized for nodes leaving the cluster, thereby providing management of node depletion. Nodes that leave the cluster leave the possibility that nodes that leave the cluster can still decrypt cluster messages. Therefore, in the operation according to the cluster key regeneration embodiment, after the node leaves the cluster, a new cluster key is generated by the node and all other nodes are reauthenticated to obtain the new cluster key. Be forced to. To prevent nodes leaving the cluster from eavesdropping on the mutual authentication handshake in the cluster key regeneration embodiment, and thus withdrawing the regenerated cluster key, a new cluster secret (eg, cluster password) is used. It can be populated on the remaining nodes without providing it to nodes that leave the cluster.
Techniques for providing enhanced security can impose further restrictions on nodes that are allowed to join the cluster. For example, a register of authorized nodes can be maintained. Any node that attempts to join the cluster may need to be both in this register and complete the mutual authentication handshake in order to join the cluster.
If a particular networked device fails to authenticate a certain number of times (eg, 5 times) within a period of time (eg, 1 hour), the enhanced security technology described herein will cause mutual authentication retries. Until permitted, the networked device may act to lock out of the mutual authentication process for a period of time. Since each node in the cluster has the ability to mutually authenticate the nodes that are trying to join the cluster, the lockout information for authentication failure is preferably (eg, how many times a particular node attempts to authenticate). It is shared between the nodes of the cluster (eg, using multicast communication facilitated through the use of cluster keys, using the cluster state). Such authentication failure lockout technology prevents active dictionary attacks.
The operation that allows each node of the cluster to securely communicate with any other node in the cluster, as provided by the embodiments described above in connection with FIGS. 2 and 3, is node depletion management and operation. It should be understood that not only can it be easily adapted to provide enhanced security protocols, but it can also be easily adapted to facilitate operation in several different environments and / or scenarios. is there. For example, after a node joins a cluster, message encryption with a cluster key can be selectively performed (eg, in an environment where a node with limited processing power is used) to improve performance. .. In one such embodiment, several methods to prevent tampering with better performance (eg, digital signature algorithms and / or other security techniques) may then be adopted, but the message does not contain confidential material. If considered, it does not need to be encrypted. The network is by other means (eg, IPsec, or segregated network). In an environment protected by network)), encryption using a cluster key can be turned off altogether.
Although the present invention and its advantages have been described in detail, various modifications, substitutions, are made herein, without departing from the spirit and scope of the invention, as defined in the appended claims. And it should be understood that alternatives can be made. Moreover, the scope of the present application is not intended to be limited to specific embodiments of the processes, machines, manufactures, compositions, means, methods and steps described herein. Those skilled in the art will either perform substantially the same functions as the corresponding embodiments described herein, which may be utilized in accordance with the present invention, or achieve substantially the same results, currently present, or later. A process, machine, manufacture, composition, means, method, or step to be developed will be readily understood from the disclosure of the present invention. Therefore, the appended claims are intended to include such processes, machines, manufactures, compositions, means, methods, or steps in their scope.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2014186553A | Cited by | Japan | Search report |
| JP2021527286A | Cited by | Japan | Search report |
| US11914736B2 | Cited by | United States of America | Applicant |
| JP2014186553A | Cited by | Japan | Examiner |
11 members in 5 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 201113218186 | United States of America | A | |
| 2012033904 | United States of America | W | |
| 13218186 | – | – | – |
| US201113218186 | – | – | – |
| US2012033904 | – | – | – |
| WO2012US33904 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| US2013054966A1 | United States of America | A1 | |
| WO2013028235A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2013028235A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US8719571B2 | United States of America | B2 | |
| EP2748967A2 | European Patent Office (EPO) | A2 | |
| CN103959735A | China | A | |
| US2014245390A1 | United States of America | A1 | |
| JP2014529238AThis record | Japan | A | |
| US9043598B2 | United States of America | B2 | |
| EP2748967A4 | European Patent Office (EPO) | A4 | |
| CN103959735B | China | B |
Numbers
- Publication
- 2014529238
- Publication, DOCDB
- 2014529238
- Publication, EPODOC
- JP2014529238
- Application
- 2014527143
- Application, DOCDB
- 2014527143
- Application, EPODOC
- JP20140527143
Titles2
- Japanese
- 安全なマルチキャストクラスタ内通信を提供するためのシステムおよび方法
- English
- Systems and methods for providing secure multicast intra-cluster communication
Classification
- CPC, 4
- H04L63/0869
- H04L9/3273
- H04L63/065
- H04L63/104
- IPC, 3
- H04L9 08
- G06F21 44
- H04L9 32