IP Library Granted Patent US 9,215,229
Granted Patent B2
US 9,215,229 · App. 14/317,159 · Granted Dec 15, 2015

Systems and methods for establishing cloud-based instances with independent permissions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,215,229
App. No.
14/317,159
Granted
Dec 15, 2015
Kind
B2
Abstract

A method and system for facilitating management of cloud-based service instances, the system including one or more computing systems configured to communicate with at least one multi-tenant computing cloud, and configured to establish a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance. The system can receive a request for the cloud-based service instance, the request authenticated as originating from a requestor; consult a set of access controls associated with the cloud-based service instance; determine, responsive to the consulting, if the request is allowable by the requestor; and enable, responsive to determining that the request is allowable by the requestor, the requestor to complete the request using a restricted access credential associated with the access entity.

Claims (56)

1. A method of facilitating management of cloud-based service instances, the method comprising:

receiving, by a cloud management service configured to communicate with a multi-tenant computing cloud, a request to perform an action on a cloud-based service instance hosted in the multi-tenant computing cloud, the request authenticated as originating from a requestor;

determining, by the cloud management service, that the request is allowable by the requestor based on a set of access controls associated with the cloud-based service instance; and

enabling, by the cloud management service responsive to determining that the request is allowable, the requestor to complete the request using an access credential associated with an access entity with permissions to access the cloud-based service instance by forwarding the request to the multi-tenant computing cloud with the access credential associated with the access entity.

2. The method of claim 1 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

3. The method of claim 1 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

4. The method of claim 1 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

5. The method of claim 1 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

6. The method of claim 1 , further comprising

establishing, by the cloud management service, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein enabling the requestor to complete the request comprises enabling the requestor to complete the request using an access credential associated with the custom access entity.

7. The method of claim 1 , further comprising establishing the cloud-based service instance by submitting, by the cloud management service to multi-tenant computing cloud, instructions to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

8. The method of claim 7 , further comprising establishing the access entity with permissions to access the established cloud service instance separately from establishing the cloud-based service instance.

9. A system for facilitating management of cloud-based service instances, the system comprising:

one or more servers including one or more hardware processors configured to communicate with at least one multi-tenant computing cloud; and

computer readable memory storing instructions that, when executed by the one or more hardware processors, cause the one or more servers to:

receive a request to perform an action on a cloud-based service instance hosted in the multi-tenant computing cloud, the request authenticated as originating from a requestor;

determine that the request is allowable by the requestor based on a set of access controls associated with the cloud-based service instance; and

enable the requestor, responsive to determining that the request is allowable, to complete the request using an access credential associated with an access entity with permissions to access the cloud-based service instance by forwarding the request to the multi-tenant computing cloud with the access credential associated with the access entity.

10. The system of claim 9 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

11. The system of claim 9 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

12. The system of claim 9 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

13. The system of claim 9 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

14. The system of claim 9 , the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to:

establish, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein the requestor is enabled to complete the request using an access credential associated with the custom access entity.

15. The system of claim 9 , wherein the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to establish the cloud-based service instance by submitting, by the cloud management service to multi-tenant computing cloud, instructions to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

16. The system of claim 15 , wherein the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to establish the access entity with permissions to access the established cloud service instance separately from establishing the cloud-based service instance.

17. A method of facilitating management of cloud-based service instances, the method comprising:

receiving, by a cloud management service configured to communicate with a multi-tenant computing cloud, a request for direct access to a cloud-based service instance hosted in the multi-tenant computing cloud, the request authenticated as originating from a requestor;

determining, by the cloud management service, that the request is allowable by the requestor based on a set of access controls associated with the cloud-based service instance; and

enabling, by the cloud management service responsive to determining that the request is allowable, the requestor to complete the request using an access credential associated with an access entity with permissions to access the cloud-based service instance by returning to the requestor the access credential associated with the access entity.

18. The method of claim 17 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

19. The method of claim 17 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

20. The method of claim 17 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

21. The method of claim 17 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

22. The method of claim 17 , further comprising

establishing, by the cloud management service, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein enabling the requestor to complete the request comprises enabling the requestor to complete the request using an access credential associated with the custom access entity.

23. The method of claim 17 , further comprising establishing the cloud-based service instance by submitting, by the cloud management service to multi-tenant computing cloud, instructions to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

24. The method of claim 23 , further comprising establishing the access entity with permissions to access the established cloud service instance separately from establishing the cloud-based service instance.

25. A system for facilitating management of cloud-based service instances, the system comprising:

one or more servers including one or more hardware processors configured to communicate with at least one multi-tenant computing cloud; and

computer readable memory storing instructions that, when executed by the one or more hardware processors, cause the one or more servers to:

receive a request for direct access to a cloud-based service instance hosted in the multi-tenant computing cloud, the request authenticated as originating from a requestor;

determine that the request is allowable by the requestor based on a set of access controls associated with the cloud-based service instance; and

enable the requestor, responsive to determining that the request is allowable, to complete the request using an access credential associated with an access entity with permissions to access the cloud-based service instance by returning, to the requestor, the access credential associated with the access entity.

26. The system of claim 25 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

27. The system of claim 25 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

28. The system of claim 25 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

29. The system of claim 25 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

30. The system of claim 25 , the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to:

establish, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein the requestor is enabled to complete the request using an access credential associated with the custom access entity.

31. The system of claim 25 , wherein the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to establish the cloud-based service instance by submitting, by the cloud management service to multi-tenant computing cloud, instructions to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

32. The system of claim 31 , wherein the instructions further comprising instructions that, when executed by the one or more hardware processors, cause the one or more servers to establish the access entity with permissions to access the established cloud service instance separately from establishing the cloud-based service instance.

Assignments (8)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS - REEL/FRAME 047719-0112 Recorded Aug 22, 2025
From: JEFFERIES FINANCE LLC
To: RIGHTSCALE, INC.
Reel/Frame 072565/0841 →
SECURITY INTEREST Recorded Aug 15, 2025
From: FLEXERA SOFTWARE LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL GENT
Reel/Frame 072460/0828 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Apr 18, 2024
From: JEFFERIES FINANCE LLC
To: BDNA CORPORATION; FLEXERA SOFTWARE LLC; PALAMIDA, INC.; RIGHTSCALE, INC.; RISC NETWORKS, LLC; REVULYTICS, INC.
Reel/Frame 067636/0534 →
SECOND LIEN SECURITY AGREEMENT Recorded Mar 3, 2021
From: BDNA CORPORATION; FLEXERA SOFTWARE LLC; PALAMIDA, INC.; RIGHTSCALE, INC.; RISC NETWORKS, LLC; REVULYTICS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 055487/0354 →
RELEASE OF SECOND LIEN SECURITY INTEREST Recorded Feb 28, 2020
From: JEFFERIES FINANCE LLC
To: FLEXERA SOFTWARE LLC; PALAMIDA, INC.; BDNA CORPORATION; RIGHTSCALE, INC.; RISC NETWORKS, LLC
Reel/Frame 052049/0560 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 5, 2018
From: RIGHTSCALE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047720/0472 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 4, 2018
From: RIGHTSCALE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047719/0112 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2014
From: EICKEN, THORSTEN VON; BLANQUER GONZALEZ, JOSE MARIA; JACQUES SIMON, RAPHAEL GEORGE
To: RIGHTSCALE INC.
Reel/Frame 033196/0636 →