IP Library › Granted Patent US 12,306,921
Granted Patent B2
US 12,306,921 · App. 17/963,134 · Granted May 20, 2025

Authorization between integrated cloud products using association

Inventors: Mauruthi Geetha Mohan (Seattle, WA); Anthony Long (Edmonds, WA); Mina Michel Gorgy Anes (Bothell, WA); Sanjeeb Kumar Sahoo (Pleasanton, CA); Yingyu Yang (Bellevue, WA); Bakhtiyar Uddin (Leander, TX); Thomas James Andrews (Seattle, WA)
Assignee: Oracle International Corporation
G06F21/33
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,306,921
App. No.
17/963,134
Granted
May 20, 2025
Kind
B2
Abstract

Techniques described herein relate to authorization between integrated cloud products. An example includes receiving, by a computing device and from a first resource, a first request for permission to access a certificate to verify a requestor's identity. The computing device can transmit a second request to a second resource to authorize permitting access to the certificate. The computing device can receive a response from the second resource comprising an authorization to permit access to the certificate. The computing device can grant permission to the first resource to access the certificate, wherein the first resource is configured to verify the requestor's identity based on accessing the certificate. The computing device can receive a third request from the first resource to generate an association object between the first resource and the certificate. The computing device can generate the association object, wherein the association object associates the first resource and the certificate.

Claims (55)

1. A method, comprising:

receiving, by a computing device and from a first resource, a first request for permission to access a certificate to verify a requestor's identity;

transmitting, by the computing device and based at least in part on the first request, a second request to a second resource to authorize permitting access to the certificate;

receiving, by the computing device and based at least in part on the second request, a response from the second resource comprising an authorization to permit access to the certificate;

granting, by the computing device and based at least in part on the response, permission to the first resource to access the certificate, wherein the first resource is configured to verify the requestor's identity based on accessing the certificate;

receiving, by the computing device and based at least in part on the grant, a third request from the first resource to generate an association object between the first resource and the certificate; and

generating, by the computing device and based at least in part on the third request, the association object, wherein the association object associates the first resource and the certificate.

2. The method of claim 1 , wherein the first request comprises a token from the first resource, wherein transmitting the second request comprises transmitting the token to the second resource, wherein the first resource is configured to receive the token from the second resource, and wherein the authorization to permit access to the certificate is based at least in part on the token.

3. The method of claim 1 , wherein the method further comprises:

receiving, from the first resource, a fourth request to access the certificate; and

granting access to the certificate, based at least in part on the association object associating the first resource and the certificate.

4. The method of claim 1 , wherein the certificate is a renewed certificate, and wherein the method further comprises:

detecting an event stored at a third resource, wherein the event is a data structure associated with the renewed certificate;

replicating the event based at least in part on the detecting the event stored at the third resource;

storing the event associated with the certificate at a database associated with the computing device.

5. The method of claim 1 , wherein the first request is received via a transport layer security (TLS) protocol or a mutual transport layer security protocol (mTLS), and wherein the method further comprises validating that the certificate exists.

6. The method of claim 1 , wherein the computing device implements a certificate service, and the second resource is an identity service.

7. The method of claim 1 , wherein the certificate is created by the computing device.

8. A computing device, comprising:

one or more processors; and

one or more non-transitory, computer-readable media comprising instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving, from a first resource, a first request for permission to access a certificate to verify a requestor's identity;

transmitting, based at least in part on the first request, a second request to a second resource to authorize permitting access to the certificate;

receiving, based at least in part on the second request, a response from the second resource comprising an authorization to permit access to the certificate;

granting, based at least in part on the response, permission to the first resource to access the certificate, wherein the first resource is configured to verify the requestor's identity based on accessing the certificate;

receiving, based at least in part on the grant, a third request from the first resource to generate an association object between the first resource and the certificate; and

generating, based at least in part on the third request, the association object, wherein the association object associates the first resource and the certificate.

9. The computing device of claim 8 , wherein the first request comprises a token from the first resource, wherein transmitting the second request comprises transmitting the token to the second resource, wherein the first resource is configured to receive the token from the second resource, and wherein the authorization to permit access to the certificate is based at least in part on the token.

10. The computing device of claim 8 , wherein the instructions that, when executed, further cause the one or more processors to perform operations comprising:

receiving, from the first resource, a fourth request to access the certificate; and

granting access to the certificate, based at least in part on the association object associating the first resource and the certificate.

11. The computing device of claim 8 , wherein the certificate is a renewed certificate, and wherein the instructions that, when executed, further cause the one or more processors to perform operations comprising:

detecting an event stored at a third resource, wherein the event is a data structure associated with the renewed certificate;

replicating the event based at least in part on the detecting the event stored at the third resource; and

storing the event associated with the certificate at a database associated with the computing device.

12. The computing device of claim 8 , wherein the first request is received via a transport layer security (TLS) protocol or a mutual transport layer security protocol (mTLS) and wherein the instructions that, when executed, further cause the one or more processors to perform operations comprising validating that the certificate exists.

13. The computing device of claim 8 , wherein the computing device implements a certificate service, and the second resource is an identity service.

14. The computing device of claim 8 , wherein the certificate is created by the computing device.

15. One or more non-transitory computer-readable media including stored thereon a sequence of instructions that, when executed, one or more processors to perform operations comprising:

receiving, from a first resource, a first request for permission to access a certificate to verify a requestor's identity;

transmitting, based at least in part on the first request, a second request to a second resource to authorize permitting access to the certificate;

receiving, based at least in part on the second request, a response from the second resource comprising an authorization to permit access to the certificate;

granting, based at least in part on the response, permission to the first resource to access the certificate, wherein the first resource is configured to verify the requestor's identity based on accessing the certificate;

receiving, based at least in part on the grant, a third request from the first resource to generate an association object between the first resource and the certificate; and

generating, based at least in part on the third request, the association object, wherein the association object associates the first resource and the certificate.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the first request comprises a token from the first resource, wherein transmitting the second request comprises transmitting the token to the second resource, wherein the first resource is configured to receive the token from the second resource, and wherein the authorization to permit access to the certificate is based at least in part on the token.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the sequence of instructions that, when executed, further cause the one or more processors to perform operations comprising:

receiving, from the first resource, a fourth request to access the certificate; and

granting access to the certificate, based at least in part on the association object associating the first resource and the certificate.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the certificate is a renewed certificate, and wherein the sequence of instructions that, when executed, further cause the one or more processors to perform operations comprising:

detecting an event stored at a third resource, wherein the event is a data structure associated with the renewed certificate;

replicating the event based at least in part on the detecting the event stored at the third resource; and

storing the event associated with the certificate at a database.

19. The one or more non-transitory computer-readable media of claim 15 , wherein the first request is received via a transport layer security (TLS) protocol or a mutual transport layer security protocol (mTLS) and wherein the sequence of instructions that, when executed, further cause the one or more processors to perform operations comprising validating that the certificate exists.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the second resource is an identity service.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE THIRD INVENTORS NAME PREVIOUSLY RECORDED AT REEL: 061368 FRAME: 0922. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 13, 2022
From: MOHAN, MAURUTHI GEETHA; LONG, ANTHONY; ANES, MINA MICHEL GORGY; SAHOO, SANJEEB KUMAR; YANG, YINGYU; UDDIN, BAKHTIYAR; ANDREWS, THOMAS JAMES
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061680/0646 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2022
From: MOHAN, MAURUTHI GEETHA; LONG, ANTHONY; AGNES, MINA MICHEL GORGY; SAHOO, SANJEEB KUMAR; YANG, YINGYU; UDDIN, BAKHTIYAR; ANDREWS, THOMAS JAMES
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061368/0922 →
Continuity (1)
Related Publication 20240119133A1 · Apr 11, 2024
References Cited (3)
US 8549300B1 · Kumar · 2013 [cited by examiner]
US 9584328B1 · Graham-Cumming · 2017 [cited by examiner]
US 20170171191A1 · Cignetti · 2017 [cited by examiner]
Cited By (1)
US 12,500,889