IP Library Granted Patent US 12,418,481
Granted Patent B2
US 12,418,481 · App. 18/741,635 · Granted Sep 16, 2025

Egress traffic policy enforcement at target service on traffic from service tenancy

Inventors: Girish Nagaraja (Sammamish, WA); Martin John Sleeman (Redmond, WA); Thomas Ray Bakita (Sain George, UT); Richard Benjamin Stockton (Minneapolis, MN); Troy Ari Levin (Huntingdon Valley, PA); Jinsu Choi (Seoul, KR); Thomas James Andrews (Seattle, WA)
Assignee: Oracle International Corporation
H04L45/74H04L45/566H04L47/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,481
App. No.
18/741,635
Granted
Sep 16, 2025
Kind
B2
Abstract

Techniques for enforcing an egress policy at a target service are described. In an example, traffic is generated for a customer tenancy, where the traffic is generated by a multi-tenancy service. The traffic can be destined to the target service. The traffic can be tagged by the multi-tenancy service with information indicating that the traffic is egressing therefrom on behalf of the customer tenancy. The customer tenancy can be associated with the egress policy. The target service can determine the egress policy based on the information tagged to the traffic and can enforce the egress policy on the traffic that the target service is receiving.

Claims (52)

1. A computer-implemented method comprising:

receiving, by a gateway having a network location that belongs to a multi-customer tenancy hosting services for multiple customer tenancies hosted by a cloud infrastructure, traffic of a first service hosted by the multi-customer tenancy for a customer, wherein the traffic is destined to a second service of a service tenancy of the cloud infrastructure, and wherein the customer is associated with a customer tenancy hosted by the cloud infrastructure;

tagging, by the gateway, the traffic with a first identifier of the gateway,

wherein the first identifier is different from a network address of the gateway and includes a data plane identifier (DPID),

the first identifier is translated into a second identifier, wherein the second identifier is a cloud identifier (CID),

the first identifier and the second identifier are associated with an egress policy of the customer, and

the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location of the gateway; and

sending, by the gateway, the traffic after being tagged to the second service of the service tenancy.

2. The computer-implemented method of claim 1 , wherein the network location includes either a first network location of a network associated with the customer or a second network location of the multi-customer tenancy.

3. The computer-implemented method of claim 1 , wherein the second identifier is used to determine the egress policy associated with the customer tenancy.

4. The computer-implemented method of claim 3 , wherein the second identifier is generated based on a registration of the network location by the customer in association with defining the egress policy.

5. The computer-implemented method of claim 1 , wherein tagging the traffic comprises including, in the traffic, the first identifier, a third identifier of the customer tenancy, and a source internet protocol (IP) address.

6. The computer-implemented method of claim 5 , wherein the first identifier, the third identifier, and the source IP address are included in one or more IP options fields of a packet that corresponds to the traffic.

7. The computer-implemented method of claim 5 , further comprising:

receiving, by the second service of the service tenancy, the traffic;

determining, by the second service of the service tenancy, an action to be performed on the traffic based on a lookup of the egress policy, wherein the action includes either allowing or disallowing the traffic, and wherein the lookup is based on the third identifier; and

performing, by the second service of the service tenancy, the action on the traffic.

8. A system having a network location that belongs to a multi-customer tenancy hosting services for multiple customer tenancies hosted by a cloud infrastructure, the system comprising:

one or more processors; and

one or more memory storing instructions that, upon execution by the one or more processors, configure the system to:

receive traffic of a first service hosted by the multi-customer tenancy for a customer, wherein the traffic is destined to a second service of a service tenancy of the cloud infrastructure, and wherein the customer is associated with a customer tenancy hosted by the cloud infrastructure;

tag the traffic with a first identifier of a gateway,

wherein the first identifier is different from a network address of the gateway and includes a data plane identifier (DPID),

the first identifier is translated into a second identifier, wherein the second identifier is a cloud identifier (CID),

the first identifier and the second identifier are associated with an egress policy of the customer, and

the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location of the gateway; and

send the traffic after being tagged to the second service of the service tenancy.

9. The system of claim 8 , wherein the network location includes either a first network location of a network associated with the customer or a second network location of the multi-customer tenancy.

10. The system of claim 8 , wherein the second identifier is used to determine the egress policy associated with the customer tenancy.

11. The system of claim 10 , wherein the second identifier is generated based on a registration of the network location by the customer in association with defining the egress policy.

12. The system of claim 8 , wherein tagging the traffic comprises including, in the traffic, the first identifier, a third identifier of the customer tenancy, and a source internet protocol (IP) address.

13. The system of claim 12 , wherein the first identifier, the third identifier, and the source IP address are included in one or more IP options fields of a packet that corresponds to the traffic.

14. The system of claim 12 , wherein the one or more memory store further instructions that, upon execution by the one or more processors, further configure the system to:

receive, by the second service of the service tenancy, the traffic;

determine, by the second service of the service tenancy, an action to be performed on the traffic based on a lookup of the egress policy, wherein the action includes either allowing or disallowing the traffic, and wherein the lookup is based on the third identifier; and

perform, by the second service of the service tenancy, the action on the traffic.

15. One or more non-transitory computer-readable storage media storing instructions that, upon execution on a system, cause the system to perform operations comprising:

receiving traffic of a first service hosted by a multi-customer tenancy for a customer, wherein the traffic is destined to a second service of a service tenancy of a cloud infrastructure, and wherein the customer is associated with a customer tenancy hosted by the cloud infrastructure, the system having a network location that belongs to the multi-customer tenancy hosting services for multiple customer tenancies hosted by the cloud infrastructure;

tagging the traffic with a first identifier of a gateway,

wherein the first identifier is different from a network address of the gateway and includes a data plane identifier (DPID),

the first identifier is translated into a second identifier, wherein the second identifier is a cloud identifier (CID),

the first identifier and the second identifier are associated with an egress policy of the customer, and

the egress policy indicates whether the traffic is to be allowed or disallowed based on the network location of the gateway; and

sending the traffic after being tagged to the second service of the service tenancy.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein the network location includes either a first network location of a network

associated with the customer or a second network location of the multi-customer tenancy.

17. The one or more non-transitory computer-readable storage media of claim 15 , wherein the second identifier is used to determine the egress

policy associated with the customer tenancy.

18. The one or more non-transitory computer-readable storage media of claim 17 , wherein the second identifier is generated based on a registration of the network location by the customer in association with defining the egress policy.

19. The one or more non-transitory computer-readable storage media of claim 15 , wherein tagging the traffic comprises including, in the traffic, the first identifier,

a third identifier of the customer tenancy, and a source internet protocol (IP) address.

20. The one or more non-transitory computer-readable storage media of claim 19 , wherein the first identifier, the third identifier, and the source IP address are included in one or more IP options fields of a packet that corresponds to the traffic.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2024
From: NAGARAJA, GIRISH; SLEEMAN, MARTIN JOHN; BAKITA, THOMAS RAY; STOCKTON, RICHARD BENJAMIN; LEVIN, TROY ARI; CHOI, JINSU; ANDREWS, THOMAS JAMES
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067719/0945 →
Continuity (4)
Continuation 18375366 · Sep 29, 2023
Provisional Application 63524550 · Jun 30, 2023
Provisional Application 63524539 · Jun 30, 2023
Related Publication 20250007832A1 · Jan 2, 2025
References Cited (55)
US 9294507B1 · Roth et al. · 2016 [cited by applicant]
US 9680801B1 · Martini · 2017 [cited by applicant]
US 10498665B1 · Meck · 2019 [cited by examiner]
US 10855562B2 · Hegde · 2020 [cited by examiner]
US 11457403B2 · Kim et al. · 2022 [cited by applicant]
US 11477165B1 · Mcdowall et al. · 2022 [cited by applicant]
US 12177110B1 · Choudhry · 2024 [cited by examiner]
US 12363042B2 · Nagaraja et al. · 2025 [cited by applicant]
US 20120023217A1 · Wakumoto · 2012 [cited by examiner]
US 20120250502A1 · Brolin · 2012 [cited by examiner]
US 20120281706A1 · Agarwal et al. · 2012 [cited by applicant]
US 20160080212A1 · Ramachandran et al. · 2016 [cited by applicant]
US 20170142007A1 · Nedeltchev et al. · 2017 [cited by applicant]
US 20190007275A1 · Clemm · 2019 [cited by examiner]
US 20190058768A1 · Feijoo et al. · 2019 [cited by applicant]
US 20190296978A1 · Seshadri · 2019 [cited by examiner]
US 20200076769A1 · Mishra et al. · 2020 [cited by applicant]
US 20210006551A1 · Sathasivam · 2021 [cited by examiner]
US 20210273910A1 · Lu · 2021 [cited by examiner]
US 20210377185A1 · Durrani et al. · 2021 [cited by applicant]
US 20220021610A1 · Kreger-Stickles · 2022 [cited by examiner]
US 20220030495A1 · Qiao et al. · 2022 [cited by applicant]
US 20220038308A1 · Motwani et al. · 2022 [cited by applicant]
US 20220060858A1 · Manithara Vamanan et al. · 2022 [cited by applicant]
US 20220210035A1 · Hendrickson et al. · 2022 [cited by applicant]
US 20220255854A1 · Baker et al. · 2022 [cited by applicant]
US 20220417150A1 · Jain et al. · 2022 [cited by applicant]
US 20230026865A1 · Rolando et al. · 2023 [cited by applicant]
US 20230093278A1 · Majila · 2023 [cited by examiner]
US 20230164076A1 · Dawani et al. · 2023 [cited by applicant]
US 20230168917A1 · Kavathia et al. · 2023 [cited by applicant]
US 20230251908A1 · Hernandez Serrano · 2023 [cited by applicant]
US 20230344777A1 · Brar et al. · 2023 [cited by applicant]
US 20240086218A1 · Olazabal · 2024 [cited by examiner]
US 20240129258A1 · Ead et al. · 2024 [cited by applicant]
US 20240179074A1 · Kommula et al. · 2024 [cited by applicant]
US 20240235866A1 · Talebi Fard et al. · 2024 [cited by applicant]
US 20240259263A1 · Choi et al. · 2024 [cited by applicant]
US 20240333626A1 · Thakore · 2024 [cited by examiner]
US 20240380638A1 · Zong et al. · 2024 [cited by applicant]
WO 2022146466A1 · 2022 [cited by applicant]
WO 2023147051A1 · 2023 [cited by applicant]
U.S. Appl. No. 18/375,366, “Notice of Allowance”, mailed Mar. 28, 2024, 16 pages. [cited by applicant]
U.S. Appl. No. 18/375,374, Non-Final Office Action mailed on Sep. 23, 2024, 18 pages. [cited by applicant]
U.S. Appl. No. 18/375,374, Notice of Allowance mailed on Mar. 7, 2025, 7 pages. [cited by applicant]
U.S. Appl. No. 18/375,382, Corrected Notice of Allowability mailed on May 5, 2025, 3 pages. [cited by applicant]
U.S. Appl. No. 18/375,382, Notice of Allowance mailed on Apr. 22, 2025, 14 pages. [cited by applicant]
U.S. Appl. No. 18/375,387, Non-Final Office Action mailed on Nov. 27, 2024, 22 pages. [cited by applicant]
International Application No. PCT/US2024/036101, International Search Report and Written Opinion mailed on Oct. 2, 2024, 13 pages. [cited by applicant]
International Application No. PCT/US2024/036119, International Search Report and Written Opinion mailed on Oct. 16, 2024, 14 pages. [cited by applicant]
International Application No. PCT/US2024/036133, International Search Report and Written Opinion mailed on Oct. 14, 2024, 14 pages. [cited by applicant]
International Application No. PCT/US2024/036145, International Search Report and Written Opinion mailed on Oct. 16, 2024, 12 pages. [cited by applicant]
U.S. Appl. No. 18/375,374, “Corrected Notice of Allowability”, Jun. 3, 2025, 2 pages. [cited by applicant]
U.S. Appl. No. 18/375,387, Final Office Action, Mailed On Jun. 13, 2025, 26 pages. [cited by applicant]
U.S. Appl. No. 18/375,382, “Corrected Notice of Allowability”, Mailed On Jul. 22, 2025, 3 pages. [cited by applicant]