IP Library Granted Patent US 12,413,627
Granted Patent B2
US 12,413,627 · App. 18/735,777 · Granted Sep 9, 2025

Policy engine for governing cloud environments

Inventors: Asif Ibrahimkutty (Trivandrum, IN); Biju Narayanan (Trivandrum, IN)
Assignee: Oracle International Corporation
H04L63/20G06F9/45558G06F9/5055G06F9/5072H04L41/0894H04L63/205G06F2009/45562G06F2009/45587G06F2009/45595H04L41/5096H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,627
App. No.
18/735,777
Granted
Sep 9, 2025
Kind
B2
Abstract

Embodiments govern cloud environments using a policy engine. A plurality of policy definitions for governing a plurality of managed environments can be received at a policy engine, each policy definition including one or more conditions and one or more actions, where the managed environments implement cloud based virtual machines that host cloud based applications. Events that relate to one or more of the managed environments can be received at the policy engine. Conditions for the policy definitions can be evaluated by the policy engine, where conditions for a first policy definition are triggered based on one or more of the received events. Based on the evaluating, one or more actions of the first policy definition can be performed, the one or more actions changing a first managed environment that is governed by the first policy definition.

Claims (49)

1. A method for governing cloud environments using a policy engine, the method comprising:

receiving, at a policy engine, a plurality of policy expressions for governing a plurality of managed environments, each policy expression comprising one or more conditions and one or more actions, wherein

the managed environments implement cloud based virtual machines that host cloud based applications, and

the policy expressions are processed to generate policy expression data structures for evaluating the policy expressions;

receiving, at the policy engine, one or more events that relate to one or more of the managed environments, wherein events payloads are received corresponding to the one or more events;

retrieving, by the policy engine, one or more policy objects associated with the one or more events, wherein retrieving at least a portion of the one or more policy objects comprises creating instances of the portion of policy objects based on event payloads from at least a portion of the one or more received events;

evaluating, by the policy engine, the conditions for the policy expressions using the policy expression data structures and the retrieved policy objects, wherein,

conditions for a first policy expression are triggered based on one or more of the received events, and

the conditions for the first policy expression are evaluated using one or more of the portion of retrieved policy objects; and

performing, based on the evaluating, one or more actions of the first policy expression, the one or more actions changing a first managed environment that is governed by the first policy expression, wherein the one or more actions of the first policy expression are performed via invoking at least one of the retrieved policy objects.

2. The method of claim 1 , wherein the one or more received events comprise predefined event structures, and the one or more policy objects retrieved are associated with the one or more received events based on the predefined event structures.

3. The method of claim 1 , wherein at least one policy object comprises an operating status information about one or more of the managed environments.

4. The method of claim 3 , wherein the policy engine compares one or more conditions from the policy expression data structure that corresponds to the first policy expression to the operating status information from the one or more policy objects to determine that the conditions for the first policy expression are triggered by the one or more of the received events.

5. The method of claim 1 , wherein the policy expressions are structured according to a predefined grammar.

6. The method of claim 5 , wherein one or more runtime objects, generated according to a structure of the predefined grammar, are used to process the policy expressions and generate the policy expression data structures.

7. The method of claim 1 , wherein the one or more actions of the first policy expression comprise one or more of starting the first managed environment, stopping the first managed environment, updating the first managed environment, backing up the first managed environment, scaling up cloud resources for the first managed environment, and scaling down cloud resources for the first managed environment.

8. The method of claim 1 , wherein the policy expression data structures comprise parse trees generated based on the policy expressions.

9. The method of claim 3 , wherein the operating status information about one or more of the managed environments is accessed by retrieving one or more properties of the at least one policy object.

10. The method of claim 9 , wherein the one or more properties of the at least one policy object are retrieved via invoking a method of the at least one policy object.

11. The method of claim 1 , wherein invoking at least one of the retrieved policy objects to perform the one or more actions comprises invoking a method of the at least one retrieved policy objects.

12. A system for governing cloud environments using a policy engine, the system comprising:

a processor; and

a memory storing instructions for execution by the processor, the instructions configuring the processor to:

receive, at a policy engine, a plurality of policy expressions for governing a plurality of managed environments, each policy expression comprising one or more conditions and one or more actions, wherein

the managed environments implement cloud based virtual machines that host cloud based applications, and

the policy expressions are processed to generate policy expression data structures for evaluating the policy expressions;

receive, at the policy engine, one or more events that relate to one or more of the managed environments, wherein events payloads are received corresponding to the one or more events;

retrieve, by the policy engine, one or more policy objects associated with the one or more events, wherein at least a portion of the one or more policy objects are retrieved by creating instances of the portion of policy objects based on event payloads from at least a portion of the one or more received events;

evaluate, by the policy engine, the conditions for the policy expressions using the policy expression data structures and the retrieved policy objects, wherein

conditions for a first policy expression are triggered based on one or more of the received events, and

the conditions for the first policy expression are evaluated using one or more of the portion of retrieved policy objects; and

perform, based on the evaluating, one or more actions of the first policy expression, the one or more actions changing a first managed environment that is governed by the first policy expression, wherein the one or more actions of the first policy expression are performed via invoking at least one of the retrieved policy objects.

13. The system of claim 12 , wherein the one or more received events comprise predefined event structures, and the one or more policy objects retrieved are associated with the one or more received events based on the predefined event structures.

14. The system of claim 12 , wherein at least one policy object comprises an operating status information about one or more of the managed environments.

15. The system of claim 14 , wherein the policy engine compares one or more conditions from the policy expression data structure that corresponds to the first policy expression to the operating status information from the one or more policy objects to determine that the conditions for the first policy expression are triggered by the one or more of the received events.

16. The system of claim 12 , wherein the policy expressions are structured according to a predefined grammar.

17. The system of claim 16 , wherein one or more runtime objects, generated according to a structure of the predefined grammar, are used to process the policy expressions and generate the policy expression data structures.

18. The system of claim 12 , wherein the one or more actions of the first policy expression comprise one or more of starting the first managed environment, stopping the first managed environment, updating the first managed environment, backing up the first managed environment, scaling up cloud resources for the first managed environment, and scaling down cloud resources for the first managed environment.

19. The system of claim 12 , wherein the policy expression data structures comprise parse trees generated based on the policy expressions.

20. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to govern cloud environments using a policy engine, wherein, when executed, the instructions cause the processor to:

receive, at a policy engine, a plurality of policy expressions for governing a plurality of managed environments, each policy expression comprising one or more conditions and one or more actions, wherein

the managed environments implement cloud based virtual machines that host cloud based applications, and

the policy expressions are processed to generate policy expression data structures for evaluating the policy expressions;

receive, at the policy engine, one or more events that relate to one or more of the managed environments, wherein events payloads are received corresponding to the one or more events;

retrieve, by the policy engine, one or more policy objects associated with the one or more events, wherein at least a portion of the one or more policy objects are retrieved by creating instances of the portion of policy objects based on event payloads from at least a portion of the one or more received events;

evaluate, by the policy engine, the conditions for the policy expressions using the policy expression data structures and the retrieved policy objects, wherein

conditions for a first policy expression are triggered based on one or more of the received events, and

the conditions for the first policy expression are evaluated using one or more of the portion of retrieved policy objects; and

perform, based on the evaluating, one or more actions of the first policy expression, the one or more actions changing a first managed environment that is governed by the first policy expression, wherein the one or more actions of the first policy expression are performed via invoking at least one of the retrieved policy objects.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2024
From: IBRAHIMKUTTY, ASIF; NARAYANAN, BIJU
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067644/0567 →
Priority Claims (1)
IN 202141012524 · Mar 23, 2021 · national
Continuity (2)
Continuation 17391488 · Aug 2, 2021
Related Publication 20240333774A1 · Oct 3, 2024
References Cited (30)
US 8532978B1 · Turner · 2013 [cited by applicant]
US 11593363B1 · Sandall · 2023 [cited by examiner]
US 20050091185A1 · Koutyrine et al. · 2005 [cited by applicant]
US 20070260976A1 · Slein et al. · 2007 [cited by applicant]
US 20090288135A1 · Chang et al. · 2009 [cited by applicant]
US 20110265168A1 · Lucovsky et al. · 2011 [cited by applicant]
US 20130263209A1 · Panuganty · 2013 [cited by applicant]
US 20130290239A1 · Vaquero · 2013 [cited by examiner]
US 20150212893A1 · Pawar · 2015 [cited by examiner]
US 20150328550A1 · Herzig et al. · 2015 [cited by applicant]
US 20160057027A1 · Hinrichs et al. · 2016 [cited by applicant]
US 20160277249A1 · Singh · 2016 [cited by examiner]
US 20170099188A1 · Chang et al. · 2017 [cited by applicant]
US 20190014152A1 · Verma · 2019 [cited by examiner]
US 20210014119A1 · Seshadri et al. · 2021 [cited by applicant]
US 20210374767A1 · Kurian et al. · 2021 [cited by applicant]
US 20230342179A1 · Suttle · 2023 [cited by examiner]
CN 102739770B · 2015 [cited by applicant]
CN 104092565B · 2017 [cited by applicant]
WO 2013107141A1 · 2013 [cited by applicant]
WO 2016025321A1 · 2016 [cited by applicant]
Makwe et al., “A Survey of Scheduling Policies in Cloud Computing Environment”, Published Apr. 2016, International Journal of Emerging Trends & Technology in Computer Science, 34(4), pp. 169-173. [cited by applicant]
Moghaddam et al., “Policy Engine as a Service (PEaaS): An Approach to a Reliable Policy Management Framework in Cloud Computing Environments”, conference Aug. 22-24, 2016, https://ieeexplore.ieee.org/document/7575855. [cited by applicant]
Unknown, “Configure a cloud policy rule”, ServiceNow, https://cutt.ly/FkYr7xM, last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, “Creating and managing organization policies”, https://cutt.ly/5kYrXQD, last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, “IBM Netcool Operations Insight”, https://cutt.ly/skYtrsR, last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, “Managing alerting policies”, https://cutt.ly/YkYr10S , last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, “Policies for Cloud Provisioning”, https://cutt.ly/2kYr3kf, last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, Flexera CMP APIs, “Policy Automation”, https://docs.rightscale.com/policies/, last downloaded Feb. 10, 2021. [cited by applicant]
Unknown, IBM Tivoli Netcool/Impact, version 7.1.0, “Running policies using schedules”, https://cutt.ly/dkYtuzq, last downloaded Feb. 10, 2021. [cited by applicant]