IP Library › Granted Patent US 10,516,672
Granted Patent B2
US 10,516,672 · App. 15/609,321 · Granted Dec 24, 2019

Service discovery for a multi-tenant identity and data security management cloud service

Inventors: Lokesh Gupta (Belmont, CA); Vadim Lander (Newton, MA)
Assignee: Oracle International Corporation
H04L63/102G06F21/41G06F21/53H04L63/0815G06F9/45558H04L63/04H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,516,672
App. No.
15/609,321
Filed
May 31, 2017
Granted
Dec 24, 2019
Kind
B2
Art Unit
2491
USPC
726/29
Abstract

A system provides cloud-based identity and access management. The system receives a request for an identity management service, authenticates the request, and forwards the request to a microservice configured to perform the identity management service, where the microservice is implemented by a microservice virtual machine provisioned by a provisioning framework, and the forwarding is according to routing information configured based on metadata information stored in a registry by the provisioning framework. The system then performs the identity management service by the microservice.

Claims (39)

1. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud-based identity and access management, the providing comprising:

receiving a request for an identity management service;

authenticating the request;

forwarding the request to a first microservice configured to perform the identity management service, the first microservice being at least one of a plurality of microservices implemented by microservice virtual machines that are provisioned by a provisioning framework, wherein

the provisioning framework stores metadata information about the provisioned microservice virtual machines in a registry,

the forwarding is according to routing information configured based on metadata information stored in the registry and is performed in part by a routing tier that discovers routes to the provisioned microservice virtual machines; and

performing the identity management service by the microservice.

2. The computer readable medium of claim 1 , wherein the metadata information identifies a first microservice virtual machine that implements the first microservice.

3. The computer readable medium of claim 1 , wherein the metadata information comprises an internet protocol (IP) address of the first microservice virtual machine that implements the first microservice.

4. The computer readable medium of claim 1 , wherein a service discovery agent (SDA) is implemented as a common code kernel on virtual machines provisioned by the provisioning framework to implement a service node, a cache node, or a routing node, wherein the provisioning framework stores respective metadata information in the registry for implemented virtual machines.

5. The computer readable medium of claim 4 , wherein the metadata information stored in the registry for the microservice virtual machines is used by one or more SDAs on one or more routing nodes in the routing tier to determine the routing information for routing the request.

6. The computer readable medium of claim 5 , wherein a resource related to the identity management task is cached in a remote cache, wherein the provisioning framework provisions cache virtual machines that each implement a cache node in a cache cluster that implements the remote cache, wherein the provisioning framework stores in the registry metadata information for the cache virtual machines.

7. The computer readable medium of claim 6 , wherein the metadata information stored for the cache virtual machines is used by SDAs at cache nodes to form the cache cluster.

8. The computer readable medium of claim 6 , wherein the metadata information stored for the cache virtual machines is used by an SDA at the first microservice to reach the remote cache.

9. The computer readable medium of claim 6 , wherein the first microservice is stateless, wherein the remote cache comprises a distributed data grid, wherein the remote cache and the first microservice are configured to scale independently of one another.

10. The computer readable medium of claim 6 , wherein the remote cache implements a different namespace for each tenant that uses the identity management service.

11. The computer readable medium of claim 1 , wherein the first microservice virtual machine implements the first microservice as an instance of the identity management service.

12. The computer readable medium of claim 1 , wherein the metadata stored in the registry is updated upon a status change of the first microservice or the first microservice virtual machine.

13. The computer readable medium of claim 12 , wherein the status change comprises a node provisioning, a node de-provisioning, a node crash, a node hang, a service crash, a service hang, a service time-out, or a topology change.

14. The computer readable medium of claim 1 , wherein the status change is determined based on status information available through a health check endpoint implemented by the first microservice virtual machine.

15. A method of providing cloud-based identity and access management, comprising:

receiving a request for an identity management service;

authenticating the request;

forwarding the request to a first microservice configured to perform the identity management service, the first microservice being at least one of a plurality of microservices implemented by microservice virtual machines that are provisioned by a provisioning framework, wherein

the provisioning framework stores metadata information about the provisioned microservice virtual machines in a registry,

the forwarding is according to routing information configured based on metadata information stored in the registry and is performed in part by a routing tier that discovers routes to the provisioned microservice virtual machines; and

performing the identity management service by the microservice.

16. The method of claim 15 , wherein the metadata information identifies a first microservice virtual machine that implements the first microservice.

17. The method of claim 15 , wherein the metadata information comprises an internet protocol (IP) address of the first microservice virtual machine that implements the first microservice.

18. The method of claim 15 , wherein a service discovery agent (SDA) is implemented as a common code kernel on virtual machines provisioned by the provisioning framework to implement a service node, a cache node, or a routing node, wherein the provisioning framework stores respective metadata information in the registry for implemented virtual machines.

19. The method of claim 18 , wherein the metadata information stored in the registry for the microservice virtual machines is used by one or more SDAs on one or more routing nodes in the routing tier to determine the routing information for routing the request.

20. A system for providing cloud-based identity and access management, comprising:

a processor coupled to memory storing instructions, wherein, when executing the instructions, the processor is configured to:

receive a request for an identity management service;

authenticate the request;

forward the request to a first microservice configured to perform the identity management service, the first microservice being at least one of a plurality of microservices implemented by microservice virtual machines that are provisioned by a provisioning framework, wherein

the provisioning framework stores metadata information about the provisioned microservice virtual machines in a registry,

the forwarding is according to routing information configured based on metadata information stored in the registry and is performed in part by a routing tier that discovers routes to the provisioned microservice virtual machines; and

perform the identity management service by the microservice.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2017
From: GUPTA, LOKESH; LANDER, VADIM
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 042539/0961 →
Continuity (5)
Provisional Application 62371336 · Aug 5, 2016
Provisional Application 62376069 · Aug 17, 2016
Provisional Application 62395463 · Sep 16, 2016
Provisional Application 62395045 · Sep 15, 2016
Related Publication 20180041515A1 · Feb 8, 2018
Cited By (8)
US 12,273,343 US 12,367,320 US 12,438,871 US 12,549,380 US 12,602,246 US 12,657,051 US 12,693,889 US 12,717,612