IP Library › Granted Patent US 12,494,901
Granted Patent B2
US 12,494,901 · App. 18/410,231 · Granted Dec 9, 2025

Issuing surrogate credentials for accessing target resources

Inventors: Thomas James Andrews (Seattle, WA); Girish Nagaraja (Sammamish, WA)
Assignee: Oracle International Corporation
H04L9/0825
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,901
App. No.
18/410,231
Granted
Dec 9, 2025
Kind
B2
Abstract

A system grants access for a computing entity to execute a requested operation upon a target resource based on a set of one or more access policies associated with a different computing entity. The access control service receives a surrogate access request from a first computing entity. The surrogate access request represents a request for the first computing entity to execute a requested operation upon a target resource based on a set of one or more access policies corresponding to a principal associated with a second computing entity. The system obtains a set of one or more access policies respectively, including a set of one or more authorized operations associated with the principal, and determines whether the requested operation corresponds to at least one authorized operation. Responsive to determining that the requested operation corresponds to at least one authorized operation, the system authorizes execution of the requested operation.

Claims (106)

1 . One or more non-transitory computer-readable media storing instructions that, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, from a first computing entity, a surrogate access request,

wherein the surrogate access request represents a request for the first computing entity to execute a requested operation upon a first target resource based on a first access policy corresponding to a principal associated with a second computing entity,

wherein the surrogate access request comprises a surrogate token and a principal token;

wherein the surrogate token identifies the requested operation, and

wherein the principal token identifies the principal associated with the second computing entity,

wherein the principal represents an identity of the second computing entity in an authorization system, and

obtaining, from the authorization system, a set of one or more access policies associated with the principal,

wherein each access policy, of the set of one or more access policies, comprises a set of one or more authorized operations;

determining, based at least in part on the set of one or more access policies, that the requested operation corresponds to at least a first authorized operation, of the set of one or more authorized operations corresponding to the first access policy;

responsive to determining that the requested operation corresponds to at least the first authorized operation, authorizing execution of the requested operation upon the first target resource.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein the requested operation represents a subset of the set of one or more authorized operations corresponding to the first access policy.

3 . The one or more non-transitory computer-readable media of claim 1 ,

wherein the surrogate token expires at a first expiry time, and

wherein the principal token is unexpired after the first expiry time.

4 . The one or more non-transitory computer-readable media of claim 1 , wherein the surrogate token is generated by the first computing entity.

5 . The one or more non-transitory computer-readable media of claim 4 , wherein subsequent to generating the surrogate token, the first computing entity transmits the surrogate token to the second computing entity, wherein the second computing entity (a) receives the surrogate token from the first computing entity, (b) digitally signs the surrogate token, and (b) transmits the surrogate token and the principal token to the first computing entity.

6 . The one or more non-transitory computer-readable media of claim 4 ,

wherein a first transmission of the surrogate token from the first computing entity to the second computing entity comprises or represents the first computing entity requesting an authorization from the second computing entity for the first computing entity to execute the requested operation;

wherein a second transmission of the surrogate token and the principal token from the second computing entity to the first computing entity comprises or represents the authorization by the second computing entity for the first computing entity to execute the requested operation.

7 . The one or more non-transitory computer-readable media of claim 4 , wherein the surrogate token is generated by the first computing entity in response to the second computing entity requesting for the first computing entity to execute the requested operation.

8 . The one or more non-transitory computer-readable media of claim 1 , wherein the operations further comprise:

validating the surrogate access request, wherein validating the surrogate access request comprises:

authenticating the first computing entity;

authenticating the surrogate token; and

authenticating the principal token.

9 . The one or more non-transitory computer-readable media of claim 8 ,

wherein the surrogate access request further comprises:

a first digital signature generated by the first computing entity using a first private key of a first asymmetric key pair corresponding to the first computing entity;

wherein the surrogate token comprises:

a first public key of the first asymmetric key pair;

wherein authenticating the first computing entity comprises:

validating the first digital signature against the first public key.

10 . The one or more non-transitory computer-readable media of claim 8 ,

wherein the surrogate token comprises:

a second digital signature generated by the second computing entity using a second private key of a second asymmetric key pair corresponding to the second computing entity;

wherein the principal token comprises:

a second public key of the second asymmetric key pair;

wherein authenticating the surrogate token comprises:

validating the second digital signature against the second public key.

11 . The one or more non-transitory computer-readable media of claim 8 ,

wherein the principal token comprises:

a third digital signature generated by the authorization system using a third private key of a third asymmetric key pair corresponding to the authorization system;

wherein authenticating the principal token comprises:

validating the third digital signature against a third public key of the third asymmetric key pair.

12 . The one or more non-transitory computer-readable media of claim 1 ,

wherein the surrogate token comprises a requested operation-identifier, wherein the requested operation-identifier identifies the requested operation;

wherein the set of one or more access policies comprises a set of one or more authorized operation-identifiers,

wherein each authorized operation-identifier, of the set of one or more authorized operation-identifiers, respectively identifies at least one authorized operation, of the set of one or more authorized operations;

wherein determining that the requested operation corresponds to at least the first authorized operation comprises:

comparing the requested operation-identifier to the set of one or more authorized operation-identifiers,

determining that a first authorized operation-identifier, of the set of one or more authorized operation-identifiers, corresponds to the requested operation-identifier,

wherein the first authorized operation-identifier identifies at least the first authorized operation.

13 . The one or more non-transitory computer-readable media of claim 1 ,

wherein the principal token comprises a principal-identifier, wherein the principal-identifier identifies the principal associated with the second computing entity;

wherein obtaining the set of one or more access policies associated with the principal comprises:

transmitting a query to the authorization system, wherein the query comprises the principal-identifier; and

receiving from the authorization system, the set of one or more access policies associated with the principal-identifier, wherein the set of one or more access policies are identifiable in the authorization system based at least in part on the principal-identifier.

14 . The one or more non-transitory computer-readable media of claim 1 , wherein the first computing entity is a customer of the second computing entity, or wherein the first computing entity comprises a user profile associated with the customer of the second computing entity.

15 . The one or more non-transitory computer-readable media of claim 1 , wherein the authorization system comprises:

a first set of one or more access policies associated with a first compartment of a virtual cloud network,

a second set of one or more access policies associated with a second compartment of the virtual cloud network,

wherein the first set of one or more access policies comprises a first authorization for the first computing entity to perform the first authorized operation with respect to the first compartment,

wherein the first computing entity is unauthorized to perform the first authorized operation with respect to the second compartment,

wherein authorizing execution of the requested operation comprises authorizing the first computing entity to execute the first authorized operation with respect to the second compartment by executing the requested operation upon the first target resource based on the first access policy associated with the second computing entity.

16 . The one or more non-transitory computer-readable media of claim 15 , wherein the operations further comprise:

receiving, from the second computing entity, a second surrogate access request,

wherein the second surrogate access request represents a second request for the second computing entity to execute a second requested operation upon a second target resource based on a second access policy associated with the first computing entity; and

determining, based at least in part on the second set of one or more access policies, that the second requested operation corresponds to at least a second authorized operation, of a second set of one or more authorized operations corresponding to the second access policy, of the second set of one or more access policies;

responsive to determining that the second requested operation corresponds to at least the second authorized operation, authorizing execution of the second requested operation upon the second target resource in accordance with the second access policy.

17 . The one or more non-transitory computer-readable media of claim 16 ,

wherein the second set of one or more access policies comprises a second authorization for the second computing entity to perform the second authorized operation with respect to the second compartment in accordance with the second set of one or more access policies,

wherein the second computing entity is unauthorized to perform the second authorized operation with respect to the first compartment in accordance with the second set of one or more access policies,

wherein authorizing execution of the second requested operation comprises authorizing the second computing entity to execute the second authorized operation with respect to the first compartment by executing the second requested operation upon the second target resource based on the second access policy associated with the first computing entity.

18 . The one or more non-transitory computer-readable media of claim 1 , wherein the operations further comprise:

receiving, from the first computing entity, a second surrogate access request,

wherein the second surrogate access request represents a second request for the first computing entity to execute a second requested operation upon a second target resource based on a second access policy associated with the second computing entity; and

determining, based at least in part on a second set of one or more access policies associated with the second computing entity, that the second requested operation corresponds to at least a second authorized operation, of a second set of one or more authorized operations corresponding to the second access policy, of the second set of one or more access policies;

responsive to determining that the second requested operation corresponds to at least the second authorized operation, authorizing execution of the second requested operation upon the second target resource in accordance with the second access policy,

wherein the second authorized operation differs from the first authorized operation, or

wherein the second target resource differs from the first target resource.

19 . A method, comprising:

receiving, from a first computing entity, a surrogate access request,

wherein the surrogate access request represents a request for the first computing entity to execute a requested operation upon a first target resource based on a first access policy corresponding to a principal associated with a second computing entity,

wherein the surrogate access request comprises a surrogate token and a principal token;

wherein the surrogate token identifies the requested operation, and

wherein the principal token identifies the principal associated with the second computing entity,

wherein the principal represents an identity of the second computing entity in an authorization system, and

obtaining, from the authorization system, a set of one or more access policies associated with the principal,

wherein each access policy, of the set of one or more access policies, comprises a set of one or more authorized operations;

determining, based at least in part on the set of one or more access policies, that the requested operation corresponds to at least a first authorized operation, of the set of one or more authorized operations corresponding to the first access policy;

responsive to determining that the requested operation corresponds to at least the first authorized operation, authorizing execution of the requested operation upon the first target resource;

wherein the method is performed by at least one device including a hardware processor.

20 . A system, comprising:

at least one hardware processor;

wherein the system is configured to execute operations, using the at least one hardware processor, the operations comprising:

receiving, from a first computing entity, a surrogate access request,

wherein the surrogate access request represents a request for the first computing entity to execute a requested operation upon a first target resource based on a first access policy corresponding to a principal associated with a second computing entity,

wherein the surrogate access request comprises a surrogate token and a principal token;

wherein the surrogate token identifies the requested operation, and

wherein the principal token identifies the principal associated with the second computing entity,

 wherein the principal represents an identity of the second computing entity in an authorization system, and

obtaining, from the authorization system, a set of one or more access policies associated with the principal,

wherein each access policy, of the set of one or more access policies, comprises a set of one or more authorized operations;

determining, based at least in part on the set of one or more access policies, that the requested operation corresponds to at least a first authorized operation, of the set of one or more authorized operations corresponding to the first access policy;

responsive to determining that the requested operation corresponds to at least the first authorized operation, authorizing execution of the requested operation upon the first target resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2024
From: ANDREWS, THOMAS JAMES; NAGARAJA, GIRISH
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 066103/0612 →
Continuity (1)
Related Publication 20250233744A1 · Jul 17, 2025
References Cited (134)
US 9092502B1 · Cannaliato et al. · 2015 [cited by applicant]
US 9164864B1 · Novick et al. · 2015 [cited by applicant]
US 9306814B1 · Roth et al. · 2016 [cited by applicant]
US 9438599B1 · Yuhan et al. · 2016 [cited by applicant]
US 9722895B1 · Sarukkai et al. · 2017 [cited by applicant]
US 9985947B1 · Elhard · 2018 [cited by examiner]
US 10394638B1 · Lay et al. · 2019 [cited by applicant]
US 10649834B2 · Dhayapule et al. · 2020 [cited by applicant]
US 10757574B1 · Rule · 2020 [cited by examiner]
US 10878483B1 · Felbinger et al. · 2020 [cited by applicant]
US 10992540B1 · Kandaswamy et al. · 2021 [cited by applicant]
US 11356273B1 · Patel et al. · 2022 [cited by applicant]
US 11720536B1 · Kisser et al. · 2023 [cited by applicant]
US 20020198973A1 · Besaw · 2002 [cited by applicant]
US 20030154407A1 · Kato · 2003 [cited by examiner]
US 20060230281A1 · Hofmann · 2006 [cited by applicant]
US 20070179859A1 · Chan et al. · 2007 [cited by applicant]
US 20080295095A1 · Watanabe et al. · 2008 [cited by applicant]
US 20100212004A1 · Fu · 2010 [cited by examiner]
US 20110055399A1 · Tung et al. · 2011 [cited by applicant]
US 20130054426A1 · Rowland et al. · 2013 [cited by applicant]
US 20130297711A1 · Nhu · 2013 [cited by applicant]
US 20130297802A1 · Laribi et al. · 2013 [cited by applicant]
US 20130304925A1 · Ferris et al. · 2013 [cited by applicant]
US 20140156846A1 · Stern et al. · 2014 [cited by applicant]
US 20140280595A1 · Mani et al. · 2014 [cited by applicant]
US 20150200824A1 · Sadovsky et al. · 2015 [cited by applicant]
US 20150350101A1 · Sinha et al. · 2015 [cited by applicant]
US 20150363852A1 · Vautour · 2015 [cited by applicant]
US 20160043909A1 · Pogrebinsky et al. · 2016 [cited by applicant]
US 20160080479A1 · Zhang et al. · 2016 [cited by applicant]
US 20160142211A1 · Metke · 2016 [cited by examiner]
US 20160203533A1 · Cheng et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20170230229A1 · Sasturkar et al. · 2017 [cited by applicant]
US 20180052861A1 · Seetharaman et al. · 2018 [cited by applicant]
US 20180173510A1 · Koshkin et al. · 2018 [cited by applicant]
US 20180219784A1 · Jiang et al. · 2018 [cited by applicant]
US 20180234256A1 · Bowen · 2018 [cited by examiner]
US 20180288063A1 · Koottayi et al. · 2018 [cited by applicant]
US 20180367542A1 · Wolf et al. · 2018 [cited by applicant]
US 20190036797A1 · Margalit et al. · 2019 [cited by applicant]
US 20190087835A1 · Schwed et al. · 2019 [cited by applicant]
US 20190155674A1 · Dhayapule et al. · 2019 [cited by applicant]
US 20190156000A1 · Hoffmann et al. · 2019 [cited by applicant]
US 20190166007A1 · Sundaram et al. · 2019 [cited by applicant]
US 20190213104A1 · Qadri et al. · 2019 [cited by applicant]
US 20190349426A1 · Smith et al. · 2019 [cited by applicant]
US 20200014659A1 · Chasman et al. · 2020 [cited by applicant]
US 20200112497A1 · Yenumulapalli et al. · 2020 [cited by applicant]
US 20200117757A1 · Yanamandra et al. · 2020 [cited by applicant]
US 20200134223A1 · Ye et al. · 2020 [cited by applicant]
US 20200236096A1 · Zhu et al. · 2020 [cited by applicant]
US 20200285496A1 · Cropper et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200358617A1 · Baierlein et al. · 2020 [cited by applicant]
US 20200358756A1 · Rose et al. · 2020 [cited by applicant]
US 20210144440A1 · Li et al. · 2021 [cited by applicant]
US 20210216190A1 · Vakil et al. · 2021 [cited by applicant]
US 20210234864A1 · Dube et al. · 2021 [cited by applicant]
US 20210273914A1 · Cobb · 2021 [cited by examiner]
US 20210279109A1 · Ji et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari et al. · 2021 [cited by applicant]
US 20210392142A1 · Stephens et al. · 2021 [cited by applicant]
US 20220091947A1 · Kothari et al. · 2022 [cited by applicant]
US 20220103618A1 · Pinheiro et al. · 2022 [cited by applicant]
US 20220150124A1 · Cooley et al. · 2022 [cited by applicant]
US 20220255902A1 · Woodson · 2022 [cited by applicant]
US 20220294818A1 · Parekh et al. · 2022 [cited by applicant]
US 20220335340A1 · Moustafa et al. · 2022 [cited by applicant]
US 20220374271A1 · Pogrebinsky et al. · 2022 [cited by applicant]
US 20230032585A1 · Jeuk et al. · 2023 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230126757A1 · Roy et al. · 2023 [cited by applicant]
US 20230179525A1 · Pai et al. · 2023 [cited by applicant]
US 20230281100A1 · Wells et al. · 2023 [cited by applicant]
US 20230316348A1 · Dageville et al. · 2023 [cited by applicant]
US 20230342179A1 · Suttle et al. · 2023 [cited by applicant]
US 20230362161A1 · Spector et al. · 2023 [cited by applicant]
US 20230385286A1 · Glickman et al. · 2023 [cited by applicant]
US 20240054063A1 · Wichelman et al. · 2024 [cited by applicant]
US 20240095739A1 · Adogla et al. · 2024 [cited by applicant]
US 20240160517A1 · Fischer et al. · 2024 [cited by applicant]
US 20240259389A1 · Wu et al. · 2024 [cited by applicant]
US 20240320240A1 · Podder · 2024 [cited by applicant]
US 20240386054A1 · Wouhaybi et al. · 2024 [cited by applicant]
EP 2893685B1 · 2017 [cited by applicant]
EP 3429156A1 · 2019 [cited by applicant]
EP 3271857B1 · 2020 [cited by applicant]
WO 2014039921A1 · 2014 [cited by applicant]
WO WO2018010791A1 · 2018 [cited by examiner]
WO 2021150306A1 · 2021 [cited by applicant]
WO 2021150307A1 · 2021 [cited by applicant]
WO WO2021145894A1 · 2021 [cited by examiner]
WO 2021174104A1 · 2021 [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Security Guide for Exadata Database Service on Cloud@Customer Systems”, Apr. 1, 2023, XP093181902. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Overview of IAM”, Feb. 8, 2023, XP093184083. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Renaming a Cloud Account”, May 14, 2021, XP093185071. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Site-to-Site VPN Overview”, Feb. 8, 2023, XP093184733. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Billing and cost management overview”, Dec. 20, 2022, XP093183514. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Cloud Guard concepts”, Jan. 18, 2022, XP093183028. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Started with Policies”, Jan. 4, 2023, XP093184099. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Summary Information on the Overview Page”, Aug. 16, 2022, XP093183031. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Learn Best Practices for Set ting Up Your Tenancy”, Feb. 8, 2023, XP093184095. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Managing Compartments”, Feb. 8, 2023, XP093184098. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Monitoring Threats”, Sep. 28, 2022, XP093183035. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Overview of the Console Dashboards Service”, Mar. 14, 2023, XP093184740. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Prerequisites for Oracle Platform Services on Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093185058. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Welcome to Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093182493. [cited by applicant]
Anonymous: “Oracle Gen 2 Exadata Cloud@Customer Security Controls”, Jan. 11, 2023, XP093181973. [cited by applicant]
Anonymous: “Oracle Operator Access Control Configuration and Administration Guide”, Nov. 18, 2022, XP093181896. [cited by applicant]
Anonymous: “Oracle Public Sector Licensing and Permitting”, 2022, XP093184298. [cited by applicant]
Anonymous: “Oracle Sovereign Cloud”, Feb. 15, 2023, XP093184649. [cited by applicant]
Apps2fusion: “Security Roles in Oracle Fusion Cloud SLA”, Nov. 30, 2018, XP093184293. [cited by applicant]
Magouryrk Clay: “Announcing Oracle Alloy: The power of the cloud in your hands”, Oct. 18, 2022, XP093183485. [cited by applicant]
Q. S. Singh and Y. Liu, “A cloud service architecture for analyzing big monitoring data,” in Tsinghua Science and Technology, vol. 21, No. 1, pp. 55-70, Feb. 2016, doi: 10.1109/TST.2016.7399283 (Year: 2016). [cited by applicant]
“Create a Reseller and Reseller Administrator User”, Retrieved from https://abiquo.atlassian.net/wiki/spaces/ABI54/pages/310740667/Create+a+Reseller+and+Reseller+Administrator+User, May 3, 2022, pp. 1-5. [cited by applicant]
“Overview of Access Approval”, Retrieved from https://cloud.google.com/assured-workloads/access-approval/docs/overview, Jun. 6, 2024, pp. 5. [cited by applicant]
“Reinstate admin privileges for a customer's Azure CSP subscriptions”, Retrieved from https://learn.microsoft.com/en-us/partner-center/reinstate-csp, Aug. 1, 2023, pp. 7. [cited by applicant]
“Tenant administrator settings”, Retrieved from https://backstage.forgerock.com/docs/idcloud/latest/tenants/tenant-administrator-settings.html, Jun. 7, 2023, pp. 12. [cited by applicant]
Bhat S., “Admin access management in Azure Cloud Solution Provider (CSP) subscriptions”, Retrieved from https://techcommunity.microsoft.com/t5/security-compliance-and-identity/admin-access-management-in-azure-cloud-solu… [cited by applicant]
Ducharme et al., “Seamlessly Protect Your IBM Cloud Application Infrastructure with Privileged Access Gateway”, Oct. 3, 2022, pp. 13. [cited by applicant]
“Periodic 802.1X reauthentication”, Retrieved from https://techhub.hpe.com/eginfolib/networking/docs/switches/5130ei/5200-3946_security_cg/content/485048074.htm, Retrieved from Oct. 25, 2023, p. 1. [cited by applicant]
“IBM SmartCloud: Becoming a Cloud Service Provider”, IBM, Dec. 13, 2012, <https://www.redbooks.ibm.com/abstracts/redp4912.html> (Year: 2012). [cited by applicant]
“Overview of Search”, Oracle Cloud Infrastructure Documentation, May 13, 2024, pp. 15. [cited by applicant]
“Overview of Tagging”, Oracle Cloud Infrastructure Documentation, Mar. 28, 2024, pp. 12. [cited by applicant]
Anonymbus: “Tokenization—(data security)”, Wikipedia, Feb. 12, 2023, pp. 1-12. [cited by applicant]
George et al., “Data anonymization and integrity checking in cloud computing”, 2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 2013, pp. 5. [cited by applicant]
Ma et al., “ServiceRank: Root Cause Identification of Anomaly in Large-Scale Microservice Architectures”, : IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 5, Sep.-Oct. 2022, pp. 3087-3100. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro)Service-Based Cloud Applications: A Survey”, ACM Computing Surveys, vol. 55, No. 3, Article 59, Feb. 2022, pp. 1-39. [cited by applicant]
F. John Krautheim ; Private Virtual Infrastructure for Cloud Computing; USENIX:2009; pp. 1-5. [cited by applicant]
“General Variables for All Requests”, Jun. 28, 2023, pp. 6. [cited by applicant]
“Policy Syntax”, Jan. 4, 2023, pp. 7. [cited by applicant]
“Verbs”, Jun. 5, 2023, pp. 2. [cited by applicant]