IP Library › Granted Patent US 10,341,410
Granted Patent B2
US 10,341,410 · App. 15/469,718 · Granted Jul 2, 2019

Security tokens for a multi-tenant identity and data security management cloud service

Inventors: Vadim Lander (Newton, MA); Ajay Sondhi (San Jose, CA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L67/02G06F21/33G06F21/6218H04L63/0807H04L63/0815H04L67/10H04L67/20H04L67/22H04L67/28G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,410
App. No.
15/469,718
Granted
Jul 2, 2019
Kind
B2
Abstract

A system provides cloud-based identity and access management. The system receives a request from a client for obtaining an access token for a user to access a resource. The system determines, based on the request, a tenancy of the client, a tenancy of the user, and a tenancy of the resource. The system accesses a microservice based on the request, and performs an identity management service by the microservice based on the request, where the identity management service includes generating the access token that identifies the tenancy of the resource and the tenancy of the user.

Claims (38)

1. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud-based identity and access management service, the providing comprising:

receiving a request from a client for obtaining an access token for a user to access a resource, the user, the client, and the resource each comprising entities of the cloud-based identity and access management service, wherein the client comprises a software application that has registered with the cloud-based identity and access management service;

determining, based on the request, a tenancy of the client, a tenancy of the user, and a tenancy of the resource, wherein each entity of the identity and access management service belongs to one of a plurality of tenancies, and the tenancy of the client, tenancy of the user, and tenancy of the resource are determined from among the plurality of tenancies;

accessing a microservice of the cloud-based identity and access management service based on the request; and

performing an identity management service by the microservice based on the determined tenancies, wherein the identity management service includes generating the access token that identifies the tenancy of the resource, the tenancy of the client, and the tenancy of the user; and

using the generated access token to authenticate the user's access to the resource, wherein the user tenancy and resource tenancy are different.

2. The computer readable medium of claim 1 , wherein at least two of the tenancy of the client, the tenancy of the user, and the tenancy of the resource are the same tenancy.

3. The computer readable medium of claim 1 , wherein the request includes a client assertion token identifying the tenancy of the client and a user assertion token identifying the tenancy of the user.

4. The computer readable medium of claim 1 , wherein a header of the request indicates the tenancy of the resource.

5. The computer readable medium of claim 4 , wherein the request is a Hypertext Transfer Protocol (HTTP) request that indicates the tenancy of the resource.

6. The computer readable medium of claim 1 , wherein the request indicates an authorization standard for authenticating the user and obtaining the access token.

7. The computer readable medium of claim 6 , wherein the authorization standard is OAuth.

8. The computer readable medium of claim 7 , wherein the client is an OAuth client.

9. The computer readable medium of claim 1 , wherein the token is a JavaScript Object Notation (JSON) Web Token (JWT).

10. The computer readable medium of claim 1 , wherein data of the tenancy of the client, the tenancy of the user, and the tenancy of the resource are stored in a database, wherein the database and the microservice are configured to scale independently of one another.

11. The computer readable medium of claim 10 , wherein the database comprises a distributed data grid.

12. The computer readable medium of claim 1 , wherein the client comprises the software application that submitted the request, the determined tenancy for the client comprises a determined tenancy for the software application that submitted the request, and the tenancy of the client, user, and resource are different from one another.

13. The computer readable medium of claim 1 , wherein, when registering with the cloud-based identity and access management service, the client is issued a client ID, and the generated access token includes the client ID.

14. The computer readable medium of claim 1 , wherein,

the cloud-based identity and access management service includes a plurality of microservices, and

the generated access token is used to secure microservice to microservice communication performed using HTTP requests.

15. The computer readable medium of claim 1 , wherein the client registration with the cloud-based identity and access management service identifies an authorization protocol used to authenticate the client.

16. A method of providing cloud-based identity and access management service, comprising:

receiving a request from a client for obtaining an access token for a user to access a resource, the user, the client, and the resource each comprising entities of the cloud-based identity and access management service, wherein the client comprises a software application that has registered with the cloud-based identity and access management service;

determining, based on the request, a tenancy of the client, a tenancy of the user, and a tenancy of the resource, wherein each entity of the identity and access management service belongs to one of a plurality of tenancies, and the tenancy of the client, tenancy of the user, and tenancy of the resource are determined from among the plurality of tenancies;

accessing a microservice of the cloud-based identity and access management service based on the request; and

performing an identity management service by the microservice based on the determined tenancies, wherein the identity management service includes generating the access token that identifies the tenancy of the resource, the tenancy of the client, and the tenancy of the user; and

using the generated access token to authenticate the user's access to the resource, wherein the user tenancy and resource tenancy are different.

17. The method of claim 16 , wherein at least two of the tenancy of the client, the tenancy of the user, and the tenancy of the resource are the same tenancy.

18. The method of claim 16 , wherein the request includes a client assertion token identifying the tenancy of the client and a user assertion token identifying the tenancy of the user.

19. The method of claim 16 , wherein a header of the request indicates the tenancy of the resource.

20. The method of claim 16 , wherein the client comprises the software application that submitted the request, the determined tenancy for the client comprises a determined tenancy for the software application that submitted the request, and the tenancy of the client, user, and resource are different from one another.

21. A system for providing cloud-based identity and access management service, comprising:

a receiving module that receives a request from a client for obtaining an access token for a user to access a resource, the user, the client, and the resource each comprising entities of the cloud-based identity and access management service, wherein the client comprises a software application that has registered with the cloud-based identity and access management service;

a determining module that determines, based on the request, a tenancy of the client, a tenancy of the user, and a tenancy of the resource, wherein each entity of the identity and access management service belongs to one of a plurality of tenancies, and the tenancy of the client, tenancy of the user, and tenancy of the resource are determined from among the plurality of tenancies;

an accessing module that accesses a microservice of the cloud-based identity and access management service based on the request; and

a performing module of the microservice that, using a hardware processor, performs an identity management service based on the determined tenancies, wherein the identity management service includes generating the access token that identifies the tenancy of the resource, the tenancy of the client, and the tenancy of the user; and

an authentication module that authenticates the user's access to the resource, wherein the user tenancy and resource tenancy are different.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2017
From: LANDER, VADIM; SONDHI, AJAY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 041749/0242 →
Continuity (5)
Provisional Application 62334645 · May 11, 2016
Provisional Application 62371336 · Aug 5, 2016
Provisional Application 62376069 · Aug 17, 2016
Provisional Application 62395463 · Sep 16, 2016
Related Publication 20170331829A1 · Nov 16, 2017
Cited By (17)
US 12,197,615 US 12,229,297 US 12,261,889 US 12,273,343 US 12,294,573 US 12,301,631 US 12,316,491 US 12,316,762 US 12,363,049 US 12,413,569 US 12,452,233 US 12,464,036 US 12,468,609 US 12,500,876 US 12,592,928 US 12,598,172 US 12,739,119