IP Library Granted Patent US 10,484,382
Granted Patent B2
US 10,484,382 · App. 15/680,362 · Granted Nov 19, 2019

Data management for a multi-tenant identity cloud service

Inventors: Gregg Wilson (Austin, TX); Venkateswara Reddy Medam (Modesto, CA)
Assignee: Oracle International Corporation
H04L63/10G06F16/951G06F21/41G06F21/604H04L63/0281H04L63/0815H04L63/20H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,484,382
App. No.
15/680,362
Granted
Nov 19, 2019
Kind
B2
Abstract

Cloud based identity management is provided by receiving a request from an application by a web gate for a resource, where the request includes an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of a plurality of tenants. Embodiments access a microservice based on the request, resolve the resource type, and validate that the operation is supported by the resource type based on metadata. Embodiments get a data provider associated with the tenant, call the data provider to perform the operation, and then return the resource.

Claims (46)

1. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud based identity management, the providing comprising:

receiving a request from an application by a web gate for a resource, wherein the request comprises an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of a plurality of tenants, the resource type comprising a schema definition, and the schema definition comprises a plurality of attributes and metadata for each of the attributes, the resource type comprising one of a user or a second application;

accessing a microservice based on the request;

resolving the resource type comprising determining the resource type and retrieving corresponding schema and schema definitions;

validating that the operation is supported by the resource type based on the metadata;

getting a data provider associated with the tenant;

calling the data provider to perform the operation; and

returning the resource.

2. The non-transitory computer readable medium of claim 1 , wherein the metadata comprises a JavaScript Object Notation (JSON).

3. The non-transitory computer readable medium of claim 1 , wherein the validating comprises checking for valid attribute names, valid data types and missing required attributes.

4. The non-transitory computer readable medium of claim 1 , the resolving further comprising determining which attributes are required for the resource type based on the schema in order to perform the validating.

5. The non-transitory computer readable medium of claim 1 , wherein for multiple versions of the resource type, at least one version of the resource type comprises a tag indicating a deprecated attribute with respect to a previous version, and at least one version of the resource type comprises a tag indicating an added attribute with respect to a previous resource type, further comprising:

performing the operation using the version of the resource type based on corresponding tags of the resource type.

6. The non-transitory computer readable medium of claim 1 , wherein the operation comprises one of create, update, delete, get or search.

7. The non-transitory computer readable medium of claim 1 , wherein the resource type is a user, and the corresponding schema comprises a password state.

8. The non-transitory computer readable medium of claim 1 , wherein the data provider comprises one of a database or an Lightweight Directory Access Protocol (LDAP) provider.

9. A method of providing cloud based identity management, the method comprising:

receiving a request from an application by a web gate for a resource, wherein the request comprises an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of a plurality of tenants, the resource type comprising a schema definition, and the schema definition comprises a plurality of attributes and metadata for each of the attributes, the resource type comprising one of a user or a second;

accessing a microservice based on the request;

resolving the resource type comprising determining the resource type and retrieving corresponding schema and schema definitions;

validating that the operation is supported by the resource type based on the metadata;

getting a data provider associated with the tenant;

calling the data provider to perform the operation; and

returning the resource.

10. The method of claim 9 , wherein the metadata comprises a JavaScript Object Notation (JSON).

11. The method of claim 9 , wherein the validating comprises checking for valid attribute names, valid data types and missing required attributes.

12. The method of claim 9 , the resolving further comprising determining which attributes are required for the resource type based on the schema in order to perform the validating.

13. The method of claim 9 , wherein for multiple versions of the resource type, at least one version of the resource type comprises a tag indicating a deprecated attribute with respect to a previous version, and at least one version of the resource type comprises a tag indicating an added attribute with respect to a previous resource type, further comprising:

performing the operation using the version of the resource type based on corresponding tags of the resource type.

14. The method of claim 9 , wherein the operation comprises one of create, update, delete, get or search.

15. The method of claim 9 , wherein the resource type is a user, and the corresponding schema comprises a password state.

16. The method of claim 9 , wherein the data provider comprises one of a database or an Lightweight Directory Access Protocol (LDAP) provider.

17. A system for providing cloud based identity and access management, comprising:

a plurality of tenants;

a plurality of microservices; and

one or more hardware processors that execute instructions to:

receive a request from an application by a web gate for a resource, wherein the request comprises an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of the plurality of tenants, the resource type comprising a schema definition, and the schema definition comprises a plurality of attributes and metadata for each of the attributes, the resource type comprising one of a user or a second application;

access a microservice out of the plurality of microservices based on the request;

resolve the resource type comprising determining the resource type and retrieving corresponding schema and schema definitions;

validate that the operation is supported by the resource type based on the metadata;

get a data provider associated with the tenant;

call the data provider to perform the operation; and

return the resource.

18. The system of claim 17 , wherein the metadata comprises a JavaScript Object Notation (JSON).

19. The system of claim 17 , wherein the validating comprises checking for valid attribute names, valid data types and missing required attributes.

20. The system of claim 17 , the resolve further comprising determining which attributes are required for the resource type based on the schema in order to perform the validate.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 043332 FRAME 0466. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECT ASSIGNEE NAME IS ORACLE INTERNATIONALCORPORATION.. Recorded Oct 24, 2017
From: WILSON, GREGG; MEDAM, VENKATESWARA REDDY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 044280/0485 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2017
From: WILSON, GREGG; MEDAM, VENKATESWARA REDDY
To: ORACLE CORPORATION
Reel/Frame 043332/0466 →
Continuity (2)
Provisional Application 62381866 · Aug 31, 2016
Related Publication 20180063143A1 · Mar 1, 2018
Cited By (13)
US 12,229,297 US 12,238,101 US 12,273,343 US 12,316,491 US 12,316,762 US 12,411,971 US 12,413,569 US 12,452,233 US 12,464,036 US 12,468,609 US 12,500,876 US 12,592,928 US 12,598,172