IP Library › Granted Patent US 11,785,082
Granted Patent B2
US 11,785,082 · App. 17/832,283 · Granted Oct 10, 2023

Domain replication across regions

Inventors: Arsalan Ahmad (Redmond, WA); Pradyumna Reddy Vajja (Bellevue, WA); Ashwin Kumar Vajantri (Seattle, WA); Nikhil Yograj Vaishnavi (Fremont, CA); Girish Yashawant Mande (San Jose, CA); Girish Nagaraja (Sammamish, WA); Gregg Alan Wilson (Austin, TX)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L67/1095G06F9/547
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,082
App. No.
17/832,283
Granted
Oct 10, 2023
Kind
B2
Abstract

The present embodiments relate to a CI replication service that can replicate domain data from IDCS control plane to data plane and to all subscribed regions of a domain. For instance, the CI replication service can provide replication of required resources of a domain for AuthN and AuthZ from an IDCS local region to other regions for high availability (e.g., to improve latency). The CI replication service can replicate the resources from a domain's home region to all subscribed regions for local availability of data for workloads running in those regions. Further, when a new region is subscribed for a domain, then the service can bootstrap that domain's data from home region before enabling that region for the domain.

Claims (46)

1. A method for replicating resources of a domain across multiple identity cloud service regions, the method comprising:

obtaining, at a multi-region replication service, domain replication data for replicating the resources of the domain from a first identity cloud service computing instance in a first region, the first region comprising both the first identity cloud service computing instance and an identity and access management computing instance;

identifying, by the multi-region replication service, a second region with a second identity cloud service computing instance that subscribes to the domain, the second identity cloud service computing instance maintaining a replica domain shard replicating the domain; and

forwarding, by the multi-region replication service, the domain replication data to the second identity cloud service computing instance at the second region, the second identity cloud service computing instance replicating the resources of the domain using the domain replication data.

2. The method of claim 1 , wherein the domain replication data is obtained from the first region via a first replication shard mapped to the domain.

3. The method of claim 1 , wherein the domain replication data is forwarded from the first identity cloud service computing instance to an identity shard service at the first region.

4. The method of claim 3 , wherein the domain replication data is stored at a domain cache shard mapping to the domain at the identity shard service.

5. The method of claim 1 , further comprising:

retrieving, by the multi-region replication service from the first identity cloud service computing instance via a replication log application programming interface, a replication log for the domain, the replication log logging instances of transmission of domain replication data from the domain to additional domains subscribing to the domain.

6. The method of claim 5 , further comprising:

retrieving, by the multi-region replication service from the first identity cloud service computing instance via the replication log application programming interface, a domain subscription map for the first identity cloud service computing instance, wherein the second region with the second identity cloud service computing instance is identified as subscribing to the domain by inspecting the domain subscription map.

7. The method of claim 1 , further comprising:

identifying, by the multi-region replication service, a request to add a third identity cloud service computing instance to subscribe to the domain;

copying, by the multi-region replication service, the domain replication data for the domain to a catchup outbox at the multi-region replication service for a third region; and

forwarding, by the multi-region replication service, the domain replication data from the catchup outbox to an inbox at the multi-region replication service for the third region, wherein the domain replication data is forwarded from the inbox to the third identity cloud service computing instance to replicate resources of the domain.

8. The method of claim 1 , wherein the domain replication data is obtained at an outbox buffer of the multi-region replication service and forwarded from the outbox buffer to an outbox and to an inbox specific to the second identity cloud service computing instance.

9. A multi-region replication service comprising:

a processor; and

a non-transitory computer-readable medium including instructions that, when executed by the processor, configure the processor to:

obtain domain replication data for replicating resources of a domain from a first identity cloud service computing instance in a first region, the first region comprising both the first identity cloud service computing instance and an identity and access management computing instance, the domain replication data being obtained from the first region via a first replication shard mapped to the domain;

identify a second region with a second identity cloud service computing instance that subscribes to the domain, the second identity cloud service computing instance maintaining a replica domain shard replicating the domain; and

forward the domain replication data to the second identity cloud service computing instance at the second region, wherein the second identity cloud service computing instance replicates the resources of the domain using the domain replication data.

10. The multi-region replication service of claim 9 , wherein the domain comprises an identity and access management entity representing an identity cloud service stripe within the first identity cloud service computing instance.

11. The multi-region replication service of claim 9 , wherein the domain replication data is forwarded from the first identity cloud service computing instance to a domain cache shard mapping to the domain at an identity shard service at the first region.

12. The multi-region replication service of claim 9 , wherein the instructions further cause the processor to:

retrieve, from the first identity cloud service computing instance via a replication log application programming interface (API), a replication log for the domain, the replication log logging instances of transmission of domain replication data from the domain to additional domains subscribing to the domain.

13. The multi-region replication service of claim 12 , wherein the instructions further causes the processor to:

retrieve, from the first identity cloud service computing instance via the replication log application programming interface, a domain subscription map for the first identity cloud service computing instance, wherein the second region with the second identity cloud service computing instance is identified as subscribing to the domain by inspecting the domain subscription map.

14. The multi-region replication service of claim 9 , wherein the instructions further cause the processor to:

identify a request to add a third identity cloud service computing instance to subscribe to the domain;

copy the domain replication data for the domain to a catchup outbox at the multi-region replication service for a third region; and

forward the domain replication data from the catchup outbox to an inbox at the multi-region replication service for the third region, wherein the domain replication data is forwarded from the inbox to the third identity cloud service computing instance to replicate resources of the domain.

15. A non-transitory computer-readable medium including stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a process comprising:

obtaining, at a multi-region replication service, domain replication data for replicating resources of a domain from a first identity cloud service computing instance in a first region, the first region comprising both the first identity cloud service computing instance and an identity and access management computing instance;

identifying, by the multi-region replication service, a second region with a second identity cloud service computing instance that subscribes to the domain, the second identity cloud service computing instance maintaining a replica domain shard replicating the domain; and

forwarding, by the multi-region replication service, the domain replication data to the second identity cloud service computing instance at the second region, wherein the second identity cloud service computing instance replicates the resources of the domain using the domain replication data, and wherein the domain replication data is forwarded from the first identity cloud service computing instance to an identity shard service at the first region.

16. The non-transitory computer-readable medium of claim 15 , wherein the domain replication data is obtained from the first region via a first replication shard mapped to the domain.

17. The non-transitory computer-readable medium of claim 15 , wherein the domain replication data is stored at a domain cache shard mapping to the domain at the identity shard service.

18. The non-transitory computer-readable medium of claim 15 , wherein the process further comprises:

retrieving, from the first identity cloud service computing instance via a replication log application programming interface (API), a replication log for the domain, the replication log logging instances of transmission of domain replication data from the domain to additional domains subscribing to the domain.

19. The non-transitory computer-readable medium of claim 18 , wherein the process further comprises:

retrieving, from the first identity cloud service computing instance via the replication log application programming interface, a domain subscription map for the first identity cloud service computing instance, wherein the second region with the second identity cloud service computing instance is identified as subscribing to the domain by inspecting the domain subscription map.

20. The non-transitory computer-readable medium of claim 15 , wherein the process further comprises:

identifying a request to add a third identity cloud service computing instance to subscribe to the domain;

copying the domain replication data for the domain to a catchup outbox at the multi-region replication service for a third region; and

forwarding the domain replication data from the catchup outbox to an inbox at the multi-region replication service for the third region, wherein the domain replication data is forwarded from the inbox to the third identity cloud service computing instance to replicate resources of the domain.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2022
From: AHMAD, ARSALAN; VAJJA, PRADYUMNA REDDY; VAJANTRI, ASHWIN KUMAR; VAISHNAVI, NIKHIL YOGRAJ; MANDE, GIRISH YASHAWANT; NAGARAJA, GIRISH; WILSON, GREGG ALAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 060114/0525 →
Continuity (2)
Provisional Application 63250652 · Sep 30, 2021
Related Publication 20230101337A1 · Mar 30, 2023
Cited By (1)
US 12,353,430