IP Library Granted Patent US 12,105,813
Granted Patent B2
US 12,105,813 · App. 17/554,010 · Granted Oct 1, 2024

Secure on-premises to cloud connector framework

Inventors: Hari Bhaskar Sankaranarayanan (Bangalore, IN); Harsh Vardhan Rai (Bengaluru, IN); Jean-Rene Gauthier (Temecula, CA)
Assignee: Oracle International Corporation
G06F21/604G06F21/6254H04L67/34G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,105,813
App. No.
17/554,010
Granted
Oct 1, 2024
Kind
B2
Abstract

Embodiments implement a secure connector framework at a cloud infrastructure. Embodiments receive one or more notebook profiles from an on-premises system corresponding to a first cloud customer, the on-premises system comprising at least one of one or more datasets, one or more models, or one or more libraries, the notebook profiles comprising permission sets that specify a level of access to the datasets, the models and the libraries, the notebook profiles corresponding to an on-premises machine learning (“ML”) notebook. Embodiments transform the received notebook profiles into a cloud policy set for sharing the datasets, the models and the libraries. Embodiments then transmit and receive corresponding data from the first cloud customer to a second cloud customer, the transmitted and received data based on the cloud policy set.

Claims (33)

1. A method of implementing a secure connector framework comprising:

at a cloud, receiving one or more notebook profiles from an on-premises system corresponding to a first cloud customer, the on-premises system comprising one or more machine learning (ML) models, the notebook profiles comprising permission sets that specify a level of access to the on-premises ML models, the notebook profiles corresponding to an on-premises ML notebook, wherein the ML notebook comprises an ML software environment for building ML models;

at the cloud, transforming the received notebook profiles into a cloud policy set for sharing the models; and

at the cloud, transmitting and receiving corresponding data from the first cloud customer to a second cloud customer, the transmitted and received data based on the cloud policy set and allows the second cloud customer access to the one or more ML models while the ML models are on-premises at the first cloud customer in accordance with the permission sets, the permissions sets providing access control for the second cloud customer for the one or more ML models.

2. The method of claim 1 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a first notebook profile that allows the second customer access to a first trained on-premises model of the one or more ML models, and prevents the second customer to access the one or more data sets.

3. The method of claim 1 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a second notebook profile that allows the second customer access to a first untrained on-premises ML model of the one or more ML models, and prevents the second customer to access the one or more datasets.

4. The method of claim 1 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a third notebook profile that allows the second customer access to a first untrained on-premises ML model of the one or more ML models, and access to only a subset of the one or more datasets.

5. The method of claim 1 , the on-premises system further comprising one or more datasets and one or more libraries, wherein the notebook profiles comprise a fourth notebook profile that allows the second customer access to the one or more ML models, the one or more datasets and the one or more libraries.

6. The method of claim 1 , the on-premises system further comprising one or more datasets and one or more libraries, wherein the one or more datasets, the one or more ML models, and the one or more libraries are not stored on the cloud.

7. The method of claim 1 , the transmitting and receiving occurring during a cloud interaction by the first customer and the second customer, further comprising:

deleting the data received by the first customer and the second customer during the cloud interaction when the cloud interaction ends.

8. The method of claim 1 , wherein the permission set is based on an Access Control List (ACL) or a Lightweight Directory Access Protocol (LDAP).

9. A non-transitory computer readable medium having instructions stored thereon that, when executed by one or more processors on a cloud infrastructure, cause the processors to provide a secure connector framework, the secure connector framework comprising:

receiving one or more notebook profiles from an on-premises system corresponding to a first cloud customer, the on-premises system comprising one or more machine learning (ML) models, the notebook profiles comprising permission sets that specify a level of access to the on-premises ML models, the notebook profiles corresponding to an on-premises ML notebook, wherein the ML notebook comprises an ML software environment for building ML models;

transforming the received notebook profiles into a cloud policy set for sharing the models; and

transmitting and receiving corresponding data from the first cloud customer to a second cloud customer, the transmitted and received data based on the cloud policy set and allows the second cloud customer access to the one or more ML models while the ML models are on-premises at the first cloud customer in accordance with the permission sets, the permissions sets providing access control for the second cloud customer for the one or more ML models.

10. The computer readable medium of claim 9 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a first notebook profile that allows the second customer access to a first trained on-premises model of the one or more ML models, and prevents the second customer to access the one or more data sets.

11. The computer readable medium of claim 9 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a second notebook profile that allows the second customer access to a first untrained on-premises ML model of the one or more ML models, and prevents the second customer to access the one or more datasets.

12. The computer readable medium of claim 9 , the on-premises system further comprising one or more datasets, wherein the notebook profiles comprise a third notebook profile that allows the second customer access to a first untrained on-premises ML model of the one or more ML models, and access to only a subset of the one or more datasets.

13. The computer readable medium of claim 9 , the on-premises system further comprising one or more datasets and one or more libraries, wherein the notebook profiles comprise a fourth notebook profile that allows the second customer access to the one or more ML models, the one or more datasets and the one or more libraries.

14. The computer readable medium of claim 9 , the on-premises system further comprising one or more datasets and one or more libraries, wherein the one or more datasets, the one or more ML models, and the one or more libraries are not stored on the cloud.

15. The computer readable medium of claim 9 , the transmitting and receiving occurring during a cloud interaction by the first customer and the second customer, the secure connector framework further comprising:

deleting the data received by the first customer and the second customer during the cloud interaction when the cloud interaction ends.

16. The computer readable medium of claim 9 , wherein the permission set is based on an Access Control List (ACL) or a Lightweight Directory Access Protocol (LDAP).

17. A cloud infrastructure comprising:

a secure connector server configured to interact with an on-premises system, the secure connector server comprising one or more processors configured to:

receive one or more notebook profiles from an on-premises system corresponding to a first cloud customer, the on-premises system comprising one or more machine learning (ML) models, the notebook profiles comprising permission sets that specify a level of access to the on-premises ML models, the notebook profiles corresponding to an on-premises ML notebook, wherein the ML notebook comprises an ML software environment for building ML models;

transform the received notebook profiles into a cloud policy set for sharing the models; and

transmit and receive corresponding data from the first cloud customer to a second cloud customer, the transmitted and received data based on the cloud policy set and allows the second cloud customer access to the one or more ML models while the ML models are on-premises at the first cloud customer in accordance with the permission sets, the permissions sets providing access control for the second cloud customer for the one or more ML models.

18. The cloud infrastructure of claim 17 , the on-premises system further comprising one or more datasets and one or more libraries, wherein the one or more datasets, the one or more models, and the one or more libraries are not stored on the cloud infrastructure.

19. The cloud infrastructure of claim 17 , the transmitting and receiving occurring during a cloud interaction by the first customer and the second customer, further comprising:

deleting the data received by the first customer and the second customer during the cloud interaction when the cloud interaction ends.

20. The cloud infrastructure of claim 17 , wherein the permission set is based on an Access Control List (ACL) or a Lightweight Directory Access Protocol (LDAP).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2021
From: SANKARANARAYANAN, HARI BHASKAR; RAI, HARSH VARDHAN; GAUTHIER, JEAN-RENE
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 058414/0595 →
Continuity (1)
Related Publication 20230195909A1 · Jun 22, 2023