IP Library › Granted Patent US 12,260,261
Granted Patent B2
US 12,260,261 · App. 17/850,693 · Granted Mar 25, 2025

Remote cloud function invocation service

Inventors: Harshit Kumar Kalley (Sunnyvale, CA); Srikanth Vavilapalli (Dublin, CA); Akshay Atul Shah (San Jose, CA); Debjani Saha (Milpitas, CA); Alex Jun-Chern Chen (Fremont, CA)
Assignee: Oracle International Corporation
G06F9/5077G06F9/45558H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,260,261
App. No.
17/850,693
Granted
Mar 25, 2025
Kind
B2
Abstract

The present disclosure relates to a framework that provides execution of serverless functions in a cloud environment based on occurrence of events/notifications from services in an entirely different cloud environment. A target agent obtains a notification from a source agent, where the target agent is deployed in a target cloud environment and the source agent is deployed in a source cloud environment that is different than the target cloud environment. The target agent determines a function that is to be invoked based on the notification. Upon successfully verifying whether the target agent is permitted to invoke the function that is deployed in a target customer tenancy of the target cloud environment, the target agent invokes the function in the target customer tenancy of the target cloud environment.

Claims (43)

1. A method comprising:

deploying, by a remote function invocation service provided by a target cloud environment, a target agent in a dataplane of a target service tenancy instantiated in the target cloud environment;

deploying, by the remote function invocation service provided by the target cloud environment, a source agent in a corresponding dataplane of a source service tenancy instantiated in a source cloud environment, wherein the target cloud environment is provided by a first cloud service provider and the source cloud environment is provided by a second cloud service provider that is different than the first cloud service provider;

obtaining, by the target agent, a notification from the source agent, wherein the source agent receives the notification from a cloud resource that is deployed in a source customer tenancy of the source cloud environment and requests to utilize a function deployed in a target customer tenancy of the target cloud environment, wherein the target agent is configured to: (i) obtain an identifier associated with the notification, and (ii) query a mapping database to obtain the function associated with the identifier, wherein the mapping database is preconfigured with a plurality of mappings, each mapping identifying a particular function that is to be invoked with respect to a particular identifier;

determining, by the target agent, the function that is to be invoked based on the notification;

verifying whether the target agent that is deployed in the target service tenancy of the target cloud environment is permitted to invoke the function that is deployed in the target customer tenancy of the target cloud environment; and

responsive to a successful verification, invoking by the target agent the function in the target customer tenancy of the target cloud environment.

2. The method of claim 1 , wherein the target agent is communicatively coupled with the source agent by a secure communication channel.

3. The method of claim 1 , wherein the source agent: (i) registers with the cloud resource deployed in the source customer tenancy of the source cloud environment or polls a queue associated with the cloud resource so as to receive the notification, and (ii) forwards the notification to the target agent upon receiving the notification from the cloud resource.

4. The method of claim 1 , wherein the step of verifying further comprising:

determining whether the target agent is permitted to access the target customer tenancy in the target cloud environment in accordance with a policy associated with the target cloud environment.

5. The method of claim 4 , further comprising:

responsive to a successful determination, obtaining by the target agent a token from an identity management service of the target cloud environment; and

forwarding the token to a serverless functions service deployed in the target cloud environment.

6. The method of claim 5 , further comprising:

causing by the serverless functions service, the function deployed in the target customer tenancy of the target cloud environment to be executed.

7. The method of claim 5 , wherein the serverless functions service communicates with the identity management service of the target cloud environment to determine a set of privileges associated with the token.

8. A non-transitory computer readable medium storing specific computer-executable instructions that, when executed by a processor, cause a computer system to perform operations comprising:

deploying, by a remote function invocation service provided by a target cloud environment, a target agent in a dataplane of a target service tenancy instantiated in the target cloud environment;

deploying, by the remote function invocation service provided by the target cloud environment, a source agent in a corresponding dataplane of a source service tenancy instantiated in a source cloud environment, wherein the target cloud environment is provided by a first cloud service provider and the source cloud environment is provided by a second cloud service provider that is different than the first cloud service provider;

obtaining, by the target agent, a notification from the source agent, wherein the source agent receives the notification from a cloud resource that is deployed in a source customer tenancy of the source cloud environment and desires to utilize a function deployed in a target customer tenancy of the target cloud environment, wherein the target agent is configured to: (i) obtain an identifier associated with the notification, and (ii) query a mapping database to obtain the function associated with the identifier, wherein the mapping database is preconfigured with a plurality of mappings, each mapping identifying a particular function that is to be invoked with respect to a particular identifier;

determining, by the target agent, the function that is to be invoked based on the notification;

verifying whether the target agent that is deployed in the target service tenancy of the target cloud environment is permitted to invoke the function that is deployed in the target customer tenancy of the target cloud environment; and

responsive to a successful verification, invoking by the target agent the function in the target customer tenancy of the target cloud environment.

9. The non-transitory computer readable medium storing specific computer-executable instructions of claim 8 , wherein the target agent being communicatively coupled with the source agent by a secure communication channel.

10. The non-transitory computer readable medium storing specific computer-executable instructions of claim 8 , wherein the source agent: (i) registers with the cloud resource deployed in the source customer tenancy of the source cloud environment or polls a queue associated with the cloud resource so as to receive the notification, and (ii) forwards the notification to the target agent upon receiving the notification from the cloud resource.

11. The non-transitory computer readable medium storing specific computer-executable instructions of claim 8 , wherein the step of verifying further comprising:

determining whether the target agent is permitted to access the target customer tenancy in the target cloud environment in accordance with a policy associated with the target cloud environment.

12. The non-transitory computer readable medium storing specific computer-executable instructions of claim 11 , further comprising:

responsive to a successful determination, obtaining by the target agent a token from an identity management service of the target cloud environment; and

forwarding the token to a serverless functions service deployed in the target cloud environment.

13. The non-transitory computer readable medium storing specific computer-executable instructions of claim 12 , further comprising:

causing by the serverless functions service, the function deployed in the target customer tenancy of the target cloud environment to be executed.

14. The non-transitory computer readable medium storing specific computer-executable instructions of claim 13 , wherein the serverless functions service communicates with the identity management service of the target cloud environment to determine a set of privileges associated with the token.

15. A system comprising:

a processor; and

a memory including instructions that, when executed with the processor, cause the system to, at least:

deploy, by a remote function invocation service provided by a target cloud environment, a target agent in a dataplane of a target service tenancy instantiated in the target cloud environment;

deploy, by the remote function invocation service provided by the target cloud environment, a source agent in a corresponding dataplane of a source service tenancy instantiated in a source cloud environment, wherein the target cloud environment is provided by a first cloud service provider and the source cloud environment is provided by a second cloud service provider that is different than the first cloud service provider;

obtain, by the target agent, a notification from the source agent, wherein the source agent receives the notification from a resource that is deployed in a source customer tenancy of the source cloud environment and requests to utilize a function deployed in a target customer tenancy of the target cloud environment, wherein the target agent is configured to: (i) obtain an identifier associated with the notification, and (ii) query a mapping database to obtain the function associated with the identifier, wherein the mapping database is preconfigured with a plurality of mappings, each mapping identifying a particular function that is to be invoked with respect to a particular identifier;

determine, by the target agent, the function that is to be invoked based on the notification;

verify whether the target agent that is deployed in the target service tenancy of the target cloud environment is permitted to invoke the function that is deployed in the target customer tenancy of the target cloud environment; and

responsive to a successful verification, invoke by the target agent the function in the target customer tenancy of the target cloud environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2022
From: KALLEY, HARSHIT KUMAR; VAVILAPALLI, SRIKANTH; SHAH, AKSHAY ATUL; SAHA, DEBJANI; CHEN, ALEX JUN-CHERN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 060325/0441 →
Continuity (2)
Provisional Application 63339753 · May 9, 2022
Related Publication 20230359508A1 · Nov 9, 2023
References Cited (11)
US 10917358B1 · Herle · 2021 [cited by examiner]
US 11316936B2 · Wells et al. · 2022 [cited by applicant]
US 20160065417A1 · Sapuram · 2016 [cited by examiner]
US 20180139149A1 · Chen · 2018 [cited by examiner]
US 20200336570A1 · Harper · 2020 [cited by examiner]
US 20210067423A1 · Newman · 2021 [cited by examiner]
US 20210409345A1 · Elmenshawy et al. · 2021 [cited by applicant]
US 20220413903A1 · Kalley · 2022 [cited by examiner]
US 20230342179A1 · Suttle · 2023 [cited by examiner]
EP 3361700B1 · 2021 [cited by applicant]
PCT/US2023/019284 , “International Search Report and Written Opinion”, Aug. 10, 2023, 21 pages. [cited by applicant]