IP Library › Granted Patent US 11,811,679
Granted Patent B2
US 11,811,679 · App. 17/198,019 · Granted Nov 7, 2023

Stacked identities for resource principals

Inventors: Ayman Mohammed Aly Hassan Elmenshawy (Bellevue, WA); Girish Nagaraja (Sammamish, WA); Daniel M. Vogel (Seattle, WA)
Assignee: Oracle International Corporation
H04L47/82G06F9/50G06F9/5077
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,679
App. No.
17/198,019
Granted
Nov 7, 2023
Kind
B2
Abstract

Techniques are described for enabling resources within a cloud computing system to interact with each other. In certain embodiments, a base identifier assigned to a first resource is extended by mapping the base identifier onto a second identifier assigned to a logical resource that is built upon the first resource. This allows the first resource to have two identities, one identity indicating what the first resource is (e.g., a particular compute instance) and another identity indicating the purpose of the first resource (e.g., operating as a database for a particular tenancy). Consequently, the first resource may be provided with access privileges different from those associated with the base identifier. For example, the first resource may access another resource in the tenancy using the second identifier, but may have no access to the other resource using the base identifier.

Claims (45)

1. A method comprising:

receiving, by a computer system, a request to provision a first resource for use within a logical container associated with a client of the computer system, the first resource being one of a plurality of resources provided within the logical container by the computer system through one or more cloud services;

responsive to the request, allocating, by the computer system and from among a set of infrastructure resources, a second resource upon which the first resource is built, wherein the second resource is not accessible from within the logical container;

assigning, by the computer system, an identifier to the second resource;

generating, by the computer system, a second identifier that is mapped to the identifier assigned to the second resource; and

assigning, by the computer system, the second identifier to the first resource, wherein due to the second identifier being mapped to the identifier assigned to the second resource, the second resource is able to present itself as being the first resource and belonging to the logical container.

2. The method of claim 1 , further comprising:

storing, by the computer system, the second identifier for the first resource as a digital token in a memory of the computer system.

3. The method of claim 1 , further comprising:

responsive to the request, allocating, by the computer system and from among the set of infrastructure resources, a third resource upon which the first resource is built, wherein the third resource is not accessible from within the logical container; and

assigning, by the computer system, an identifier to the third resource, wherein the second identifier is mapped to the identifier assigned to the third resource, and wherein due to the second identifier being mapped to the identifier assigned to the third resource, the third resource can present itself as being the first resource and belonging to the logical container.

4. The method of claim 3 , wherein the second resource and the third resource are bare metal compute instances.

5. The method of claim 3 , wherein the second resource and the third resource are virtual machines.

6. The method of claim 1 , further comprising:

accessing, by the second resource using the second identifier, a third resource within the logical container.

7. The method of claim 6 , wherein the first resource is a cloud based database, and wherein the third resource is a cloud based object storage system.

8. The method of claim 6 , wherein the first resource is a load balancer, and wherein the third resource is a cloud based database.

9. A computer system comprising:

one or more processors; and

a memory in communication with the one or more processors, the memory storing instructions that, when executed by the one or more processors, cause the one or more processors to:

receive a request to provision a first resource for use within a logical container associated with a client of the computer system, the first resource being one of a plurality of resources provided within the logical container by the computer system through one or more cloud services;

responsive to the request, allocate, from among a set of infrastructure resources, a second resource upon which the first resource is built, wherein the second resource is not accessible from within the logical container;

assign an identifier to the second resource;

generate a second identifier that is mapped to the identifier assigned to the second resource; and

assign the second identifier to the first resource, wherein due to the second identifier being mapped to the identifier assigned to the second resource, the second resource is able to present itself as being the first resource and belonging to the logical container.

10. The computer system of claim 9 , wherein the instructions further cause the one or more processors to store the second identifier for the first resource as a digital token in a memory of the computer system.

11. The computer system of claim 9 , wherein the instructions further cause the one or more processors to:

responsive to the request, allocate, from among the set of infrastructure resources, a third resource upon which the first resource is built, wherein the third resource is not accessible from within the logical container; and

assign an identifier to the third resource, wherein the second identifier is mapped to the identifier assigned to the third resource, and wherein due to the second identifier being mapped to the identifier assigned to the third resource, the third resource can present itself as being the first resource and belonging to the logical container.

12. The computer system of claim 11 , wherein the second resource and the third resource are bare metal compute instances.

13. The computer system of claim 11 , wherein the second resource and the third resource are virtual machines.

14. The computer system of claim 9 , wherein the second resource is configured to access, using the second identifier, a third resource within the logical container.

15. The computer system of claim 14 , wherein the first resource is a cloud based database, and wherein the third resource is a cloud based object storage system.

16. The computer system of claim 14 , wherein the first resource is a load balancer, and wherein the third resource is a cloud based database.

17. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors of a computer system, cause the one or more processors to perform steps comprising:

receiving a request to provision a first resource for use within a logical container associated with a client of the computer system, the first resource being one of a plurality of resources provided within the logical container by the computer system through one or more cloud services;

responsive to the request, allocating, from among a set of infrastructure resources, a second resource upon which the first resource is built, wherein the second resource is not accessible from within the logical container;

assigning an identifier to the second resource;

generating a second identifier that is mapped to the identifier assigned to the second resource; and

assigning the second identifier to the first resource, wherein due to the second identifier being mapped to the identifier assigned to the second resource, the second resource is able to present itself as being the first resource and belonging to the logical container.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further cause the one or more processors to store the second identifier for the first resource as a digital token in a memory of the computer system.

19. The non-transitory computer-readable storage medium of claim 17 , wherein the instructions further cause the one or more processors to perform steps comprising:

responsive to the request, allocating, from among the set of infrastructure resources, a third resource upon which the first resource is built, wherein the third resource is not accessible from within the logical container; and

assigning an identifier to the third resource, wherein the second identifier is mapped to the identifier assigned to the third resource, and wherein due to the second identifier being mapped to the identifier assigned to the third resource, the third resource can present itself as being the first resource and belonging to the logical container.

20. The non-transitory computer-readable storage medium of claim 17 , wherein the second resource is configured to access, using the second identifier, a third resource within the logical container.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2021
From: ELMENSHAWY, AYMAN MOHAMMED ALY HASSAN; NAGARAJA, GIRISH; VOGEL, DANIEL M.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 055580/0249 →
Continuity (2)
Provisional Application 63044256 · Jun 25, 2020
Related Publication 20210409345A1 · Dec 30, 2021
Cited By (2)
US 12,500,889 US 12,724,863