IP Library › Granted Patent US 12,363,042
Granted Patent B2
US 12,363,042 · App. 18/375,374 · Granted Jul 15, 2025

Egress traffic policy enforcement at target service

Inventors: Girish Nagaraja (Sammamish, WA); Martin John Sleeman (Redmond, WA); Thomas Ray Bakita (Saint George, UT); Richard Benjamin Stockton (Minneapolis, MN); Troy Ari Levin (Huntingdon Valley, PA); Jinsu Choi (Seoul, KR); Thomas James Andrews (Seattle, WA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L47/20H04L47/2483H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,042
App. No.
18/375,374
Filed
Sep 29, 2023
Granted
Jul 15, 2025
Kind
B2
Art Unit
2455
USPC
709/223
Abstract

Techniques for enforcing an egress policy at a target service are described. In an example, traffic is generated for a customer, where the traffic is generated by a customer network of the customer, such as a customer tenancy or an on-premise network, or by a multi-tenancy service on behalf of the customer. The traffic can be destined to the target service. The traffic can be tagged by the customer network (e.g., by a gateway of the customer network) or by the multi-tenancy service. The customer network can be associated with the egress policy. The target service can determine the egress policy based on the information tagged to the traffic and can enforce the egress policy on the traffic that the target service is receiving.

Claims (41)

1. A computer-implemented method comprising:

receiving, by a service of a service tenancy of a cloud infrastructure, traffic of a customer that is associated with a customer tenancy hosted by the cloud infrastructure, wherein the traffic is received from a network location and is destined to the service of the service tenancy, wherein the network location includes either a first network location of a network associated with the customer or a second network location of a multi-service tenancy hosting services for multiple customer tenancies, wherein the traffic is tagged by a gateway corresponding to the network location with an identifier of the network location, wherein the identifier is different from an internet protocol address, and wherein the identifier includes a data plane identifier (DPID), wherein the DPID is translated into a cloud identifier (CID), and wherein the CID is used to determine an egress policy associated with the customer tenancy;

determining, by the service of the service tenancy, an action to be performed on the traffic based on the egress policy, wherein the action includes either allowing or disallowing the traffic, and wherein the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location; and

performing, by the service of the service tenancy, the action on the traffic.

2. The computer-implemented method of claim 1 , wherein the traffic is received from the first network location, wherein the first network location belongs to an on-premise network of the customer and is associated with identifier the CID such that the first network location is represented as belonging to a virtual cloud network of the customer tenancy.

3. The computer-implemented method of claim 1 , wherein the traffic is received from the first network location, wherein the customer tenancy includes a virtual cloud network, and wherein the first network location belongs to the virtual cloud network.

4. The computer-implemented method of claim 1 , wherein the traffic is received from the second network location, wherein the second network location corresponds to the gateway that handles egress traffic of the services and tags the traffic as being associated with the customer tenancy.

5. The computer-implemented method of claim 1 , wherein the traffic includes network information, wherein the network information includes a first identifier of a network from which the traffic originated, a source internet protocol (IP) address, and a second identifier the network location from which the traffic egresses the network, and wherein determining the action comprises:

sending, to a data store storing egress policies, at least a portion of the network information, wherein the portion includes the second identifier; and

receiving a response indicating the action, wherein the response is generated based on the egress policy.

6. The computer-implemented method of claim 1 , wherein the traffic includes network information, wherein the network information includes a first identifier of a network from which the traffic originated, a source internet protocol (IP) address, and a second identifier of the network location from which the traffic egresses the network, and wherein determining the action comprises:

sending at least a portion of the network information, wherein the portion includes the second identifier;

receiving a first response indicating a third identifier of the network location, wherein the third identifier corresponds to a translation of the second identifier;

sending, to a data store storing egress policies, at least the third identifier; and

receiving a second response indicating the action, wherein the second response is generated based on the egress policy.

7. The computer-implemented method of claim 1 , wherein the traffic includes network information, wherein the network information includes a first identifier of a virtual cloud network from which the traffic originated, a source internet protocol (IP) address, and the DPID of the network location from which the traffic egresses the network.

8. The computer-implemented method of claim 7 , wherein the network information is included in one or more IP options fields of a packet that corresponds to the traffic.

9. The computer-implemented method of claim 8 , wherein receiving the traffic includes receiving a Hypertext Transfer Protocol (HTTP) or a proxy protocol version two (PPV2) header that includes the CID corresponding to a translation of the DPID, and wherein determining the action comprises:

sending, to an identity data plane, at least the CID; and

receiving a response from the identity data plane indicating the action, wherein the response is generated by the identity data plane based on the egress policy.

10. The computer-implemented method of claim 1 , wherein the traffic is received from the second network location, wherein the second network location corresponds to the gateway that handles egress traffic of the services and tags the traffic with the CID to indicate that the traffic is associated with the customer tenancy, and wherein the CID is generated based on a registration of a service by the multi-service tenancy for the customer tenancy.

11. The computer-implemented method of claim 1 , wherein the traffic is received from the first network location, wherein the first network location belongs to an on-premise network of the customer and is associated with the CID such that the first network location is represented as belonging to a virtual cloud network of the customer tenancy, and wherein the CID is generated based on a registration of the first network location.

12. A system comprising:

one or more processor; and

one or more memory storing instructions that, upon execution by the one or more processors, configure the system to provide a service of a service tenancy of a cloud infrastructure, wherein the service is configured to:

receive traffic of a customer that is associated with a customer tenancy hosted by the cloud infrastructure, wherein the traffic is received from a network location and is destined to the service of the service tenancy, wherein the network location includes either a first network location of a network associated with the customer or a second network location of a multi-service tenancy hosting services for multiple customer tenancies, and wherein the traffic includes network information, wherein the network information includes a first identifier of a virtual cloud network from which the traffic originated, a source internet protocol (IP) address, and a data plane identifier (DPID) of the network location from which the traffic egresses the network;

determine an action to be performed on the traffic based on an egress policy associated with the customer tenancy, wherein the action includes either allowing or disallowing the traffic, and wherein the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location; and

perform the action on the traffic.

13. The system of claim 12 , wherein the traffic is received from the first network location, wherein the first network location belongs to an on-premise network of the customer and is associated with a cloud identifier such that the first network location is represented as belonging to the virtual cloud network of the customer tenancy.

14. The system of claim 12 , wherein the traffic is received from the first network location, wherein the customer tenancy includes the virtual cloud network, and wherein the first network location belongs to the virtual cloud network.

15. The system of claim 12 , wherein the traffic is received from the second network location, wherein the second network location corresponds to a gateway that handles egress traffic of the services and tags the traffic as being associated with the customer tenancy.

16. One or more non-transitory computer-readable storage media storing instructions that, upon execution on a system, cause the system to perform operations comprising providing a service of a service tenancy of a cloud infrastructure, wherein the service is configured to:

receive traffic of a customer that is associated with a customer tenancy hosted by the cloud infrastructure, wherein the traffic is received from a network location and is destined to the service of the service tenancy, wherein the network location includes either a first network location of a network associated with the customer or a second network location of a multi-service tenancy hosting services for multiple customer tenancies, wherein the traffic is tagged by a gateway corresponding to the network location with an identifier of the network location, wherein the identifier is different from an internet protocol address, and wherein the identifier includes a data plane identifier (DPID), wherein the DPID is translated into a cloud identifier (CID), and wherein the CID is used to determine an egress policy associated with the customer tenancy;

determine an action to be performed on the traffic based on the egress policy, wherein the action includes either allowing or disallowing the traffic, and wherein the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location; and

perform the action on the traffic.

17. The system of claim 12 , wherein the traffic is tagged by a gateway corresponding to the network location with an identifier of the network location, wherein the identifier is different from an internet protocol address.

18. The system of claim 17 , wherein the identifier includes the DPID, wherein the DPID is translated into a cloud identifier (CID), and wherein the CID is used to determine the egress policy.

19. The system of claim 12 , wherein the network information is included in one or more IP options fields of a packet that corresponds to the traffic.

20. The system of claim 19 , wherein receiving the traffic includes receiving a Hypertext Transfer Protocol (HTTP) or a proxy protocol version two (PPV2) header that includes a cloud identifier (CID) corresponding to a translation of the DPID, and wherein determining the action comprises:

sending, to an identity data plane, at least the CID; and

receiving a response from the identity data plane indicating the action, wherein the response is generated by the identity data plane based on the egress policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2023
From: NAGARAJA, GIRISH; SLEEMAN, MARTIN JOHN; BAKITA, THOMAS RAY; STOCKTON, RICHARD BENJAMIN; LEVIN, TROY ARI; CHOI, JINSU; ANDREWS, THOMAS JAMES
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065139/0817 →
Continuity (3)
Provisional Application 63524550 · Jun 30, 2023
Provisional Application 63524539 · Jun 30, 2023
Related Publication 20250007843A1 · Jan 2, 2025
References Cited (46)
US 9294507B1 · Roth et al. · 2016 [cited by applicant]
US 9680801B1 · Martini · 2017 [cited by applicant]
US 10498665B1 · Meck et al. · 2019 [cited by applicant]
US 10855562B2 · Hegde et al. · 2020 [cited by applicant]
US 11457403B2 · Kim et al. · 2022 [cited by applicant]
US 11477165B1 · Mcdowall et al. · 2022 [cited by applicant]
US 12177110B1 · Choudhry et al. · 2024 [cited by applicant]
US 20120023217A1 · Wakumoto · 2012 [cited by applicant]
US 20120250502A1 · Brolin · 2012 [cited by applicant]
US 20120281706A1 · Agarwal et al. · 2012 [cited by applicant]
US 20160080212A1 · Ramachandran · 2016 [cited by examiner]
US 20190007275A1 · Clemm et al. · 2019 [cited by applicant]
US 20190296978A1 · Seshadri et al. · 2019 [cited by applicant]
US 20200076769A1 · Mishra et al. · 2020 [cited by applicant]
US 20210006551A1 · Sathasivam et al. · 2021 [cited by applicant]
US 20210273910A1 · Lu et al. · 2021 [cited by applicant]
US 20220021610A1 · Kreger-Stickles · 2022 [cited by examiner]
US 20220030495A1 · Qiao et al. · 2022 [cited by applicant]
US 20220038308A1 · Motwani et al. · 2022 [cited by applicant]
US 20220060858A1 · Manithara Vamanan et al. · 2022 [cited by applicant]
US 20220210035A1 · Hendrickson · 2022 [cited by examiner]
US 20220255854A1 · Baker et al. · 2022 [cited by applicant]
US 20220417150A1 · Jain et al. · 2022 [cited by applicant]
US 20230026865A1 · Rolando et al. · 2023 [cited by applicant]
US 20230093278A1 · Majila et al. · 2023 [cited by applicant]
US 20230164076A1 · Dawani et al. · 2023 [cited by applicant]
US 20230168917A1 · Kavathia et al. · 2023 [cited by applicant]
US 20230251908A1 · Hernandez Serrano · 2023 [cited by examiner]
US 20230344777A1 · Brar · 2023 [cited by examiner]
US 20240086218A1 · Olazabal et al. · 2024 [cited by applicant]
US 20240129258A1 · Ead · 2024 [cited by examiner]
US 20240179074A1 · Kommula · 2024 [cited by examiner]
US 20240235866A1 · Talebi Fard et al. · 2024 [cited by applicant]
US 20240259263A1 · Choi · 2024 [cited by examiner]
US 20240333626A1 · Thakore et al. · 2024 [cited by applicant]
WO 2022146466A1 · 2022 [cited by applicant]
WO 2023147051A1 · 2023 [cited by applicant]
U.S. Appl. No. 18/375,366, “Notice of Allowance”, mailed Mar. 28, 2024, 16 pages. [cited by applicant]
U.S. Appl. No. 18/375,387, Non-Final Office Action mailed on Nov. 27, 2024, 22 pages. [cited by applicant]
U.S. Appl. No. 18/741,635, Non-Final Office Action mailed on Feb. 13, 2025, 22 pages. [cited by applicant]
Application No. PCT/US2024/036101, International Search Report and Written Opinion mailed on Oct. 2, 2024, 13 pages. [cited by applicant]
Application No. PCT/US2024/036119, International Search Report and Written Opinion mailed on Oct. 16, 2024, 14 pages. [cited by applicant]
Application No. PCT/US2024/036133, International Search Report and Written Opinion mailed on Oct. 14, 2024, 14 pages. [cited by applicant]
Application No. PCT/US2024/036145, International Search Report and Written Opinion mailed on Oct. 16, 2024, 12 pages. [cited by applicant]
U.S. Appl. No. 18/375,382, Corrected Notice of Allowability mailed on May 5, 2025, 3 pages. [cited by applicant]
U.S. Appl. No. 18/375,382, Notice of Allowance mailed on Apr. 22, 2025, 14 pages. [cited by applicant]
Cited By (1)
US 12,418,481