IP Library › Granted Patent US 11,356,454
Granted Patent B2
US 11,356,454 · App. 16/678,171 · Granted Jun 7, 2022

Service discovery for a multi-tenant identity and data security management cloud service

Inventors: Lokesh Gupta (Belmont, CA); Vadim Lander (Newton, MA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L63/102G06F21/41G06F21/53H04L63/0815G06F9/45558H04L63/04H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,356,454
App. No.
16/678,171
Granted
Jun 7, 2022
Kind
B2
Abstract

A system provides cloud-based identity and access management. The system receives a request for an identity management service, authenticates the request, and forwards the request to a microservice configured to perform the identity management service, where the microservice is implemented by a microservice virtual machine provisioned by a provisioning framework, and the forwarding is according to routing information configured based on metadata information stored in a registry by the provisioning framework. The system then performs the identity management service by the microservice.

Claims (30)

1. A method for providing cloud-based identity and access management, the method comprising:

provisioning, by a provisioning framework, a first service implemented by a first virtual machine, wherein a plurality of services implemented by virtual machines have been provisioned by the provisioning framework and a plurality of service discovery agents (SDAs) are implemented as common code kernels on virtual machines provisioned by the provisioning framework;

discovering, by a routing tier, metadata information from the provisioning framework about the first service implemented by the first virtual machine, wherein the routing tier includes routing nodes that comprise services implemented by virtual machines provisioned by the provisioning framework; and

configuring, by the routing tier, one or more traffic routes that include the first service implemented by the first virtual machine based on the discovered metadata information such that one or more SDAs implemented on the routing nodes configure the one or more traffic routes using the metadata information about the first service, wherein one or more identity management service requests are routed to the first service based on the configured one or more traffic routes.

2. The method of claim 1 , wherein the first service and the plurality of services provisioned by the provisioning framework comprise microservices, and metadata information about running microservices that have been provisioned is stored in a registry by the provisioning framework.

3. The method of claim 2 , wherein the metadata information comprises an internet protocol (IP) address of the first virtual machine that implements the first service.

4. The method of claim 2 , wherein the discovering of the metadata information about the first service comprises accessing, by one or more SDAs implemented on the routing nodes, the registry stored by the provisioning framework.

5. The method of claim 2 , wherein, after provisioning when the first service is running, an SDA of the first service performs discovery of other microservices provisioned by the provisioning framework by accessing the registry stored by the provisioning framework.

6. The method of claim 5 , wherein the first service is provisioned as a cache node.

7. The method of claim 6 , further comprising:

discovering, by the SDA of the first service, one or more cache nodes provisioned by the provisioning framework based on accessing the registry stored by the provisioning framework; and

forming a cache cluster with the discovered one or more cache nodes, wherein the formed cache cluster implements a remote cache.

8. The method of claim 7 , wherein metadata information stored in the registry about the remote cache is used by one or more SDAs on the plurality of virtual machines provisioned by the provisioning framework to reach the remote cache.

9. The method of claim 2 , wherein the metadata stored in the registry is updated upon a status change of the first service or the first virtual machine, and the status change comprises a node provisioning, a node de-provisioning, a node crash, a node hang, a service crash, a service hang, a service time-out, or a topology change.

10. The method of claim 1 , wherein the first virtual machine implements the first service as an instance of an identity management service.

11. The method of claim 1 , wherein the discovering by the routing tier is part of a periodic discovery that is iteratively performed to discover provisioned services.

12. The method of claim 1 , wherein, after provisioning, the SDA of the first service discovers one or more running cache services provisioned by the provisioning framework by accessing a registry that stores metadata information about running microservices that have been provisioned by the provisioning framework.

13. The method of claim 1 , wherein the provisioning framework polls virtual machines that implement services provisioned by the provisioning framework to determine provisioned services that are actively running.

14. A non-transitory computer readable medium having instructions stored thereon that, when executed by a processor, cause the processor to provide cloud-based identity and access management, the providing comprising:

provisioning, by a provisioning framework, a first service implemented by a first virtual machine, wherein a plurality of services implemented by virtual machines have been provisioned by the provisioning framework and a plurality of service discovery agents (SDAs) are implemented as common code kernels on virtual machines provisioned by the provisioning framework;

discovering, by a routing tier, metadata information from the provisioning framework about the first service implemented by the first virtual machine, wherein the routing tier includes routing nodes that comprise services implemented by virtual machines provisioned by the provisioning framework; and

configuring, by the routing tier, one or more traffic routes that include the first service implemented by the first virtual machine based on the discovered metadata information such that one or more SDAs implemented on the routing nodes configure the one or more traffic routes using the metadata information about the first service, wherein one or more identity management service requests are routed to the first service based on the configured one or more traffic routes.

15. The non-transitory computer readable medium of claim 14 , wherein the discovering by the routing tier is part of a periodic discovery that is iteratively performed to discover provisioned services.

16. The non-transitory computer readable medium of claim 14 , wherein, after provisioning, the SDA of the first service discovers one or more running cache services provisioned by the provisioning framework by accessing a registry that stores metadata information about running microservices that have been provisioned by the provisioning framework.

17. The non-transitory computer readable medium of claim 14 , wherein the provisioning framework polls virtual machines that implement services provisioned by the provisioning framework to determine provisioned services that are actively running.

18. A system for providing cloud-based identity and access management, comprising:

a provisioning framework implemented on one or more computing devices configured to provision a first service implemented by a first virtual machine, wherein a plurality of services implemented by virtual machines have been provisioned by the provisioning framework; and

a routing tier implemented on one or more computing devices configured to:

discover metadata information from the provisioning framework about the first service implemented by the first virtual machine, wherein the routing tier includes routing nodes that comprise services implemented by virtual machines provisioned by the provisioning framework; and

configure one or more traffic routes that include the first service implemented by the first virtual machine based on the discovered metadata information such that one or more SDAs implemented on the routing nodes configure the one or more traffic routes using the metadata information about the first service, wherein one or more identity management service requests are routed to the first service based on the configured one or more traffic routes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2019
From: GUPTA, LOKESH; LANDER, VADIM
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 050958/0539 →
Continuity (6)
Continuation 15609321 · May 31, 2017
Provisional Application 62395463 · Sep 16, 2016
Provisional Application 62395045 · Sep 15, 2016
Provisional Application 62376069 · Aug 17, 2016
Provisional Application 62371336 · Aug 5, 2016
Related Publication 20200076817A1 · Mar 5, 2020
Cited By (3)
US 12,348,355 US 12,495,048 US 12,549,433