IP Library › Granted Patent US 12,309,133
Granted Patent B2
US 12,309,133 · App. 18/539,757 · Granted May 20, 2025

Integrating data access among disparate platforms over a cloud storage scheme

Inventors: Swapnil Suwalal Daga (Tathwade, IN); Vijay Kumar (Pune, IN); Zhengang Lu (Katy, TX); Jason Wang (Sugar Land, TX)
Assignee: SCHLUMBERGER TECHNOLOGY CORPORATION
H04L63/0807H04L63/083H04L63/102H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,133
App. No.
18/539,757
Granted
May 20, 2025
Kind
B2
Abstract

A method, computer system, and computer program product are provided for integrating access to multiple cloud storage sources from different applications. A storage account is joined to a local domain. The storage account is registered with a directory service in the local domain. A first service accesses the storage account by using a domain credential for accessing the local domain. A second service accesses the storage account by using a directory service credential to the directory service. The first service and the second service may concurrently access the storage account.

Claims (54)

1. A method comprising:

joining a storage account to a local domain;

registering the storage account with a directory service in the local domain;

accessing the storage account by a first service using a domain credential for accessing the local domain; and

accessing the storage account by a second service using a directory service credential to the directory service,

wherein the first service and the second service concurrently access the storage account.

2. The method of claim 1 , wherein joining the storage account to the local domain further comprises:

configuring the storage account to communicate with the directory service.

3. The method of claim 1 , wherein registering the storage account with the directory service further comprises:

creating a service account within the directory service that has been granted one or more permissions to the storage account.

4. The method of claim 1 , wherein the storage account is an Azure Storage account.

5. The method of claim 1 , wherein accessing the storage account by the first service further comprises:

authenticating the first service with the local domain using a Kerberos protocol.

6. The method of claim 1 , wherein accessing the storage account by the first service further comprises:

accessing the storage account via a Server Message Block driver over a Server Message Block protocol connection.

7. The method of claim 1 , wherein the first service is running on a virtual machine within the local domain.

8. The method of claim 1 , wherein the second service is a cloud-native service running in a containerized environment.

9. The method of claim 1 , wherein accessing the storage account by the second service further comprises:

obtaining, by the second service, a security token from Azure Active Directory; and

presenting, by the second service, the security token to access the storage account.

10. The method of claim 1 , wherein the directory service credential used by the second service is a managed identity that is not joined to the local domain.

11. The method of claim 1 , wherein accessing the storage account by the second service further comprises:

accessing the storage account via a container Storage Interface driver over a Hypertext Transfer Protocol Secure connection.

12. The method of claim 1 , wherein the concurrent access by the first service and the second service further comprises:

coordinating concurrent access by a concurrency management mechanism within the storage account.

13. A system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing program code, which when executed by the computer processor, performs a plurality of operations comprising:

joining a storage account to a local domain;

registering the storage account with a directory service in the local domain;

accessing the storage account by a first service using a domain credential for accessing the local domain; and

accessing the storage account by a second service using a directory service credential to the directory service,

wherein the first service and the second service concurrently access the storage account.

14. The system of claim 13 , wherein joining the storage account to the local domain further comprises:

configuring the storage account to communicate with an Active Directory Domain Services instance; and

wherein registering the storage account with the directory service further comprises:

creating a service account within the directory service that has been granted one or more permissions to the storage account.

15. The system of claim 13 , wherein accessing the storage account by the first service further comprises:

authenticating the first service with the local domain using a Kerberos authentication protocol; and

accessing the storage account via a Server Message Block driver over a Server Message Block protocol connection.

16. The system of claim 13 , wherein the first service is running on a virtual machine within the local domain.

17. The system of claim 13 , wherein the second service is a cloud-native service running in a containerized environment.

18. The system of claim 13 , wherein accessing the storage account by the second service further comprises:

obtaining, by the second service, a security token from Azure directory service via an OAuth authentication; and

presenting, by the second service, the security token to access the storage account.

19. The system of claim 13 , wherein the directory service credential used by the second service is a managed identity that is not joined to the local domain; and

wherein accessing the storage account by the second service further comprises:

accessing the storage account via a container Storage Interface driver over a Hypertext Transfer Protocol Secure connection.

20. A computer program product comprising a non-transitory computer readable storage medium storing program code, which when executed by a computer processor, performs a plurality of operations comprising:

joining a storage account to a local domain;

registering the storage account with a directory service in the local domain

accessing the storage account by a first service using a domain credential for accessing the local domain; and

accessing the storage account by a second service using a directory service credential to the directory service,

wherein the first service and the second service concurrently access the storage account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2025
From: DAGA, SWAPNIL SUWALAL; KUMAR, VIJAY; LU, ZHENGANG; WANG, JASON
To: SCHLUMBERGER TECHNOLOGY CORPORATION
Reel/Frame 070632/0589 →
Continuity (2)
Provisional Application 63387525 · Dec 15, 2022
Related Publication 20240205213A1 · Jun 20, 2024
References Cited (18)
US 9325791B1 · Blahaerath · 2016 [cited by examiner]
US 9565190B1 · Telvik · 2017 [cited by examiner]
US 10768985B1 · Batsura · 2020 [cited by examiner]
US 11196748B1 · Croney · 2021 [cited by examiner]
US 11405360B1 · Bose · 2022 [cited by examiner]
US 20110265147A1 · Liu · 2011 [cited by examiner]
US 20170171300A1 · Natarajan et al. · 2017 [cited by applicant]
US 20170289128A1 · Kelley et al. · 2017 [cited by applicant]
US 20180048636A1 · Anantha Padmanaban et al. · 2018 [cited by applicant]
US 20200067933A1 · Kukreja · 2020 [cited by examiner]
US 20200304481A1 · Rathore · 2020 [cited by examiner]
US 20200366661A1 · Mehta · 2020 [cited by examiner]
US 20200409796A1 · Terei · 2020 [cited by examiner]
US 20200412736A1 · Kissell et al. · 2020 [cited by applicant]
US 20210342196A1 · Natarajan · 2021 [cited by examiner]
US 20210377276A1 · Dasari et al. · 2021 [cited by applicant]
US 20240080316A1 · Wong · 2024 [cited by examiner]
International Search Report and Written Opinion of International Patent Application No. PCT/US2023/083956 dated on Apr. 5, 2024, 08 pages. [cited by applicant]