RDMA-ENABLED KEY-VALUE STORE
    1.
    发明申请

    公开(公告)号:WO2021055179A1

    公开(公告)日:2021-03-25

    申请号:PCT/US2020/049437

    申请日:2020-09-04

    Abstract: According to one or more embodiments, lookup, insertion, and deletion operations are allowed to continue during actions required for collision remediation. When relocation operations are used to resolve a collision, information encoded in header portions of the hash table entries that store the key-value pairs indicates when the associated key-value pairs are undergoing relocation. This information facilitates continued access to the RKVS during the relocation process by allowing other processes that access the RKVS to handle relocations without failure. Furthermore, when hash table expansion is needed in order to resolve a collision, a second, larger, hash table is allocated, and lookup operations continue on both the old hash table and the new hash table. One or more embodiments further prevent insertion, lookup, and deletion failures in the RKVS using flags, encoded in header information in hash table entries, that reflect the state of the respective key-value pairs in the store.

    SYSTEM AND METHOD FOR PROVIDING AN INTEGRATED FIREWALL FOR SECURE NETWORK COMMUNICATION IN A MULTI-TENANT ENVIRONMENT
    3.
    发明申请
    SYSTEM AND METHOD FOR PROVIDING AN INTEGRATED FIREWALL FOR SECURE NETWORK COMMUNICATION IN A MULTI-TENANT ENVIRONMENT 审中-公开
    用于在多个环境中提供安全网络通信的集成防火墙的系统和方法

    公开(公告)号:WO2016040485A1

    公开(公告)日:2016-03-17

    申请号:PCT/US2015/049193

    申请日:2015-09-09

    Abstract: An integrated firewall provides security in a multi-tenant environment having a connection-based switched fabric directly connecting database servers which provide a plurality of database services with application servers hosting database service consumers each having a different database service consumer identity. The firewall functionality integrated into each database server provides access control by discarding communication packets which do not include a database service consumer identity and using the database service consumer identity in combination with an access control list to control access from the database service consumers to the database services. The access control includes address resolution access control, connection establishment access control, and data exchange access control based on said access control list. The integrated firewall enables direct connection of database servers and application servers via an InfiniBand network providing without requiring a separate intermediary firewall appliance or security node.

    Abstract translation: 集成防火墙在多承租人环境中提供安全性,其具有直接连接数据库服务器的基于连接的交换结构,所述数据库服务器向承载具有不同数据库服务消费者身份的数据库服务消费者的应用服务器提供多个数据库服务。 集成到每个数据库服务器中的防火墙功能通过丢弃不包括数据库服务消费者身份的通信数据包并​​使用数据库服务消费者身份与访问控制列表组合来控制从数据库服务使用者到数据库服务的访问来提供访问控制 。 访问控制包括基于所述访问控制列表的地址解析访问控制,连接建立访问控制和数据交换访问控制。 集成防火墙可以通过InfiniBand网络直接连接数据库服务器和应用程序服务器,而无需单独的中间防火墙设备或安全节点。

    SYSTEM AND METHOD FOR SUPPORTING USE OF FORWARD AND BACKWARD CONGESTION NOTIFICATIONS IN A PRIVATE FABRIC IN A HIGH PERFORMANCE COMPUTING ENVIRONMENT

    公开(公告)号:WO2021101602A1

    公开(公告)日:2021-05-27

    申请号:PCT/US2020/045273

    申请日:2020-08-06

    Abstract: Systems and methods for using multiple CE (congestion experienced) flags in both FECN (forward explicit congestion notification) and BECN (backward explicit congestion notification) in a high performance computing environment. An exemplary method can provide a first subnet comprising a plurality of switches, a plurality of host channel adapters, and a plurality of end nodes. The method can receive, at an end node attached to a host channel adapter, an ingress packet from a remote end node, wherein the ingress packet traversed at least a portion of the first subnet prior to being received at the end node. The method can, on receiving the ingress packet, send a response message from the end node attached to the host channel adapter to the remote end node, the response message indicating that the ingress packet experienced congestion during the traversal of the at least a portion of the first subnet.

    SYSTEM AND METHOD FOR SUPPORTING TARGET GROUPS FOR CONGESTION CONTROL IN A PRIVATE FABRIC IN A HIGH PERFORMANCE COMPUTING ENVIRONMENT

    公开(公告)号:WO2021101601A1

    公开(公告)日:2021-05-27

    申请号:PCT/US2020/045272

    申请日:2020-08-06

    Abstract: Systems and methods for supporting target groups for congestion control in a private fabric in a high performance computing environment. An exemplary method can provide, at one or more microprocessors, a first subnet, the first subnet comprising a plurality of switches, a plurality of host channel adapters, and a plurality of end nodes, including a plurality of virtual machines. The method can define a target group on one of an inter-switch link or at a port of a switch of the plurality of switches, wherein the target group defines a bandwidth limit on the at least one of an inter-switch link between two switches of the plurality of switches or at a port of a switch of the plurality of switches. The method can provide a target group repository stored in a memory of the host channel adapter where the defined target group in the target group repository is recorded.

    ONE-SIDED RELIABLE REMOTE DIRECT MEMORY OPERATIONS

    公开(公告)号:WO2020033012A1

    公开(公告)日:2020-02-13

    申请号:PCT/US2019/023264

    申请日:2019-03-20

    Abstract: Techniques are provided to allow more sophisticated operations to be performed remotely by machines that are not fully functional. Operations that can be performed reliably by a machine that has experienced a hardware and/or software error are referred to herein as Remote Direct Memory Operations or "RDMOs". Unlike RDMAs, which typically involve trivially simple operations such as the retrieval of a single value from the memory of a remote machine, RDMOs may be arbitrarily complex. The techniques described herein can help applications run without interruption when there are software faults or glitches on a remote system with which they interact.

    SYSTEM AND METHOD FOR PROVIDING AN INTEGRATED FIREWALL FOR SECURE NETWORK COMMUNICATION IN A MULTI-TENANT ENVIRONMENT
    10.
    发明公开
    SYSTEM AND METHOD FOR PROVIDING AN INTEGRATED FIREWALL FOR SECURE NETWORK COMMUNICATION IN A MULTI-TENANT ENVIRONMENT 审中-公开
    用于在多租户环境中为安全网络通信提供集成防火墙的系统和方法

    公开(公告)号:EP3192230A1

    公开(公告)日:2017-07-19

    申请号:EP15767397.1

    申请日:2015-09-09

    Abstract: An integrated firewall provides security in a multi-tenant environment having a connection-based switched fabric directly connecting database servers which provide a plurality of database services with application servers hosting database service consumers each having a different database service consumer identity. The firewall functionality integrated into each database server provides access control by discarding communication packets which do not include a database service consumer identity and using the database service consumer identity in combination with an access control list to control access from the database service consumers to the database services. The access control includes address resolution access control, connection establishment access control, and data exchange access control based on said access control list. The integrated firewall enables direct connection of database servers and application servers via an InfiniBand network providing without requiring a separate intermediary firewall appliance or security node.

    Abstract translation: 安全解决方案在包括基于连接的结构,保存与不同租户相关联的数据的存储单元,使用所述数据提供多个数据库服务的数据库服务器,托管数据库服务消费者的应用服务器的多租户环境中提供安全通信。 该架构被配置为将存储单元与数据库服务使用者隔离的分区。 应用程序服务器安全地将唯一的数据库服务使用者身份与每个数据库服务使用者以及与数据库服务器的所有通信相关联 数据库服务器拒绝来自不包含身份的应用程序服务器的所有通信,并使用访问控制列表来控制使用地址解析访问控制,连接建立访问控制和数据交换访问控制从数据库服务使用者到数据库服务的访问 基于所述访问控制列表。 DoS攻击预防也可以基于包中包含的消费者身份执行。

Patent Agency Ranking