-
公开(公告)号:US20210218723A1
公开(公告)日:2021-07-15
申请号:US16742881
申请日:2020-01-14
Applicant: VMware, Inc.
Inventor: Georgi LEKOV , Rusko ATANASOV , Stanimir LUKANOV , Elena DIMITROVA , Dimo RAYCHEV
IPC: H04L29/06
Abstract: Hosts in a cluster in a virtualized computing environment bypass a management layer when communicating with an external key management service (KMS). One of the hosts is configured with KMS configuration information (including digital certificate information) that enables the host to directly communicate with the KMS via a secure communication connection, instead of communicating with the KMS via the management layer. This KMS configuration information is replicated in a distributed manner from the host to the other hosts in the cluster, thereby enabling the other hosts in the cluster to also directly and independently communicate with the KMS to obtain encryption keys to perform cryptographic operations.
-
2.
公开(公告)号:US20240320024A1
公开(公告)日:2024-09-26
申请号:US18189131
申请日:2023-03-23
Applicant: VMware, Inc.
Inventor: Alkesh SHAH , Brian Masao OKI , Leonid LIVSHIN , Stanimir LUKANOV , Petko PADEVSKI , Dimo RAYCHEV , Georgi Lyubomirov DIMITROV
IPC: G06F9/455
CPC classification number: G06F9/45558 , G06F2009/45562 , G06F2009/4557
Abstract: An example method of synchronizing a first inventory of a cross-cluster control plane (xCCP) with a second inventory of a cluster control plane (CCP) includes: receiving, at a replication engine of the xCCP from the CCP, a notification of a CCP operation that modified an object in the second inventory; determining, by the replication engine, a first operation to modify the first inventory with the object; identifying, in a buffer of the replication engine, a second operation to modify the first inventory with a related object associated with the object, the related object included in an earlier CCP notification, received at the xCCP before the notification, but not used to modify the first inventory due to an unresolved dependency; and calling, by the replication engine in response to satisfaction of the unresolved dependency, a service of the xCCP to modify the first inventory by performing the first and second operations.
-