IP Library Granted Patent US 10,425,386
Granted Patent B2
US 10,425,386 · App. 15/591,358 · Granted Sep 24, 2019

Policy enforcement point for a multi-tenant identity and data security management cloud service

Inventors: Stephan Wardell (Hoboken, NJ); Andrew B. Folkins (Edmonton, CA); Vadim Lander (Newton, MA); Prateek Mishra (Union City, CA); Rich Levinson (Concord, MA); Cory Womacks (Sherwood Park, CA); Dino E. Cuthbert (Edmonton, CA)
Assignee: Oracle International Corporation
H04L63/0281H04L41/0893H04L41/18H04L41/5003H04L63/0815H04L63/205H04L67/146H04L67/2814H04W12/06H04L41/28H04L41/5096H04L67/02H04L67/2842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,425,386
App. No.
15/591,358
Granted
Sep 24, 2019
Kind
B2
Abstract

A system provides cloud-based identity and access management. The system receives a request by a web gate for an identity management service for reaching an application, and determines a tenancy from a header value of the request. The system looks up a policy configured to be applied for the tenancy, and applies the policy to the request. The system then sends the request to a microservice based on a result of the applying of the policy to the request, where the microservice performs the identity management service for reaching the application.

Claims (36)

1. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud-based identity and access management for a plurality of tenancies, the providing comprising:

receiving a request by a cloud gate for an identity management service for reaching an application, the request having a corresponding request endpoint that also requires access to a resource of the application;

determining a tenancy of the plurality of tenancies from a header value of the request;

looking up a policy configured to be applied for the tenancy, the policy indicating whether access to the resource by the request endpoint is allowed and a method of access;

applying the policy to the request including the method of access; and

sending the request to a microservice based on a result of the applying of the policy to the request when the policy determines that access to the resource is allowed, wherein the microservice performs the identity management service for reaching the application.

2. The computer readable medium of claim 1 , wherein the method of access comprises one of basic authentication or token based authentication.

3. The computer readable medium of claim 1 , wherein the policy is specified in a file managed by the cloud gate.

4. The computer readable medium of claim 1 , wherein the microservice implements OAuth functionality.

5. The computer readable medium of claim 1 , wherein the cloud gate implements cookie-based session management functionality for accessing the application.

6. The computer readable medium of claim 1 , wherein the cloud gate acts as an OAuth relaying party for accessing the application.

7. The computer readable medium of claim 1 , wherein the microservice is stateless and retrieves data from a database to perform the identity management service.

8. The computer readable medium of claim 7 , wherein the database and the microservice are configured to scale independently of one another.

9. The computer readable medium of claim 7 , wherein the database comprises a distributed data grid.

10. A method of providing cloud-based identity and access management for a plurality of tenancies, comprising:

receiving a request by a cloud gate for an identity management service for reaching an application, the request having a corresponding request endpoint that also requires access to a resource of the application;

determining a tenancy of the plurality of tenancies from a header value of the request;

looking up a policy configured to be applied for the tenancy, the policy indicating whether access to the resource by the request endpoint is allowed and a method of access;

applying the policy to the request including the method of access; and

sending the request to a microservice based on a result of the applying of the policy to the request when the policy determines that access to the resource is allowed, wherein the microservice performs the identity management service for reaching the application.

11. The method of claim 10 , wherein the method of access comprises one of basic authentication or token based authentication.

12. The method of claim 10 , wherein the policy is specified in a file managed by the cloud gate.

13. The method of claim 10 , wherein the microservice implements OAuth functionality.

14. The method of claim 10 , wherein the cloud gate implements cookie-based session management functionality for accessing the application.

15. The method of claim 10 , wherein the cloud gate acts as an OAuth relaying party for accessing the application.

16. The method of claim 10 , wherein the microservice is stateless and retrieves data from a database to perform the identity management service.

17. The method of claim 16 , wherein the database and the microservice are configured to scale independently of one another.

18. A system for providing cloud-based identity and access management for a plurality of tenancies, comprising:

a processor executing stored instructions to implement a plurality of modules, the modules comprising:

a receiving module that receives a request by a cloud gate for an identity management service for reaching an application, the request having a corresponding request endpoint that also requires access to a resource of the application;

a determining module that determines a tenancy of the plurality of tenancies from a header value of the request;

a look up module that looks up a policy configured to be applied for the tenancy, the policy indicating whether access to the resource by the request endpoint is allowed and a method of access;

an applying module that applies the policy to the request including the method of access; and

a sending module that sends the request to a microservice based on a result of the applying of the policy to the request when the policy determines that access to the resource is allowed, wherein the microservice performs the identity management service for reaching the application.

19. The system of claim 18 , wherein the method of access comprises one of basic authentication or token based authentication.

20. The system of claim 18 , wherein the policy is specified in a file managed by the cloud gate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 24, 2017
From: WARDELL, STEPHAN; FOLKINS, ANDREW B.; LANDER, VADIM; MISHRA, PRATEEK; LEVINSON, RICH; WOMACKS, CORY; CUTHBERT, DINO E.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 042492/0395 →
Continuity (6)
Provisional Application 62395463 · Sep 16, 2016
Provisional Application 62377056 · Aug 19, 2016
Provisional Application 62376069 · Aug 17, 2016
Provisional Application 62371336 · Aug 5, 2016
Provisional Application 62334645 · May 11, 2016
Related Publication 20170331791A1 · Nov 16, 2017
Cited By (12)
US 12,229,297 US 12,238,101 US 12,273,343 US 12,316,491 US 12,316,762 US 12,413,569 US 12,452,233 US 12,464,036 US 12,468,609 US 12,500,876 US 12,598,172 US 12,640,933