IP Library Granted Patent US 12,464,036
Granted Patent B2
US 12,464,036 · App. 17/896,969 · Granted Nov 4, 2025

Maintaining sessions information in multi-region cloud environment

Inventors: Kranthi Kiran Pandiri (Redmond, WA); Shobhank Sharma (Kirkland, WA); Girish Nagaraja (Sammamish, WA)
Assignee: Oracle International Corporation
H04L67/02H04L67/14G06F2209/5016
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,036
App. No.
17/896,969
Granted
Nov 4, 2025
Kind
B2
Abstract

Techniques are described that enable, in a multi-region cloud environment, information regarding one or more tenancy sessions that a network access program (e.g., a browser) participates in to be efficiently stored in a centralized location. The centrally stored sessions information can then be used for various purposes such as for restricting the number of tenancy sessions using a network access program, sessions cleanup, and other sessions-related tasks. In certain implementations, the centrally stored sessions information is used to prevent the network access program from opening multiple sessions for the same tenancy. In such implementations, for a particular tenancy, the network access program is allowed to have only one active session for the particular tenancy at a time. The centrally stored sessions information facilitates efficient sessions management including session cleanup after a session is closed.

Claims (47)

1 . A method comprising:

receiving, by a global region data center, information regarding a request to access an application using a browser executing on a user device;

communicating, by the global region data center to the user device, a first set of instructions for execution at the user device;

receiving, by the global region data center from the user device and due to execution of the first set of instructions on the user device, a request to log into a first tenancy via the browser, where the browser does not have an existing session for the first tenancy;

determining, by the global region data center, a home region for the first tenancy;

redirecting, by the global region data center, the browser to a home region data center in the identified home region, wherein the home region data center performs processing associated with the request to log into the first tenancy;

receiving, by the global region data center, information indicative of a first tenancy login into the first tenancy and creation of a new session for the first tenancy login;

causing, by the global region data center, sessions information stored on the user device to be updated to include information regarding the new session, wherein the sessions information comprises information identifying one or more sessions that the browser participates in; and

responsive to a log out from the application, causing, by the global region data center, the sessions information stored on the user device to be updated by removing the information regarding the new session from the sessions information.

2 . The method of claim 1 wherein the first set of instructions is executed by the browser on the user device.

3 . The method of claim 1 wherein the first set of instructions when executed by the browser causes:

sessions information stored on the user device to be read, the sessions information comprising information identifying one or more sessions that the browser participates in and information identifying a tenancy for each session in the one or more sessions.

4 . The method of claim 3 wherein the sessions information is stored by the browser in a data store associated with the global region data center.

5 . The method of claim 4 wherein the data store is an IndexedDB database associated with an application hosted by the global region data center.

6 . The method of claim 3 wherein the first set of instructions when executed by the browser further causes:

information to be output via the browser regarding the one or more sessions, wherein the information output for a session includes information identifying a tenancy corresponding to that session.

7 . The method of claim 6 wherein the first set of instructions when executed by the browser further prevents multiple sessions from being opened for a particular tenancy when the one or more sessions includes a session associated with the particular tenancy.

8 . The method of claim 6 wherein the first set of instructions when executed by the browser further enables input to be received identifying the first tenancy.

9 . The method of claim 1 wherein the information regarding the new session includes information identifying the first tenancy.

10 . The method of claim 1 further comprising: receiving, by the global region data center, information regarding a request to log out of the application accessed via the new session created for the first tenancy; redirecting, by the global region data center, the browser to the home region data center in the identified home region for the first tenancy; receiving, by the global region data center, a redirect of the browser after invalidation of the new session by the home region data center; and causing, by the global region data center, the sessions information stored on the user device to be updated by removing the information regarding the new session from the sessions information.

11 . The method of claim 10 wherein the causing the sessions information stored on the user device to be updated comprises:

communicating, by the global region data center to the user device, a second set of instructions for execution by the browser on the user device, wherein the second set of instructions when executed by the browser causes the information regarding the new session to be removed from the sessions information.

12 . The method of claim 11 wherein the second set of instructions when executed by the browser further cause processing to be performed at the user device comprising:

from the sessions information stored on the user device, identifying a set of one or more applications accessed using the new session; and

performing a logout for each application in the set of applications.

13 . The method of claim 1 further comprising:

validating, by the home region data center, the request to log into the first tenancy using one or more identity and access management artifacts stored by the home region data center for the first tenancy; and

upon successful validation, facilitating logging into the first tenancy and creation of the new session.

14 . The method of claim 1 wherein determining, by the global region data center, the home region for the first tenancy comprises:

using, by the global region data center, information mapping a set of tenancies to their corresponding home regions to determine the home region for the first tenancy.

15 . A non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more computer systems of a global region data center, cause the global region data center to perform processing comprising:

receiving, by the global region data center, information regarding a request to access an application using a browser executing on a user device;

communicating, by the global region data center to the browser, a first set of instructions for execution by the browser;

receiving, by the global region data center from the browser and due to execution of the first set of instructions by the browser, information identifying a first tenancy;

redirecting, by the global region data center, the browser to a home region data center in a home region for the first tenancy;

receiving, by the global region data center, information indicative of a first tenancy login and creation of a new session for the first tenancy login;

causing, by the global region data center, sessions information stored on the user device to be updated to include information regarding the new session, wherein the sessions information comprises information identifying one or more sessions that the browser participates in; and

responsive to a log out from the application, causing, by the global region data center, the sessions information stored on the user device to be updated by removing the information regarding the new session from the sessions information.

16 . The non-transitory computer-readable medium of claim 15 wherein the sessions information is stored by the browser in a data store associated with the global region data center.

17 . A system comprising:

one or more computer systems, wherein the one or more computer systems are configured to perform processing comprising:

receiving a browser redirect responsive to a request to access an application using the browser executing on a user device;

receiving, from the browser, information identifying a first tenancy for a new login using the browser;

redirecting the browser to a home region data center in a home region for the first tenancy;

receiving information indicative of a first tenancy login and creation of a new session for the first tenancy login;

causing sessions information to be stored by the browser indicative of the new session and the associated first tenancy; and

responsive to a log out from the application, causing, by the global region data center, the sessions information stored on the user device to be updated by removing the information regarding the new session from the sessions information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2022
From: PANDIRI, KRANTHI KIRAN; SHARMA, SHOBHANK; NAGARAJA, GIRISH
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 060917/0893 →
Continuity (3)
Provisional Application 63356884 · Jun 29, 2022
Provisional Application 63250604 · Sep 30, 2021
Related Publication 20230097763A1 · Mar 30, 2023
References Cited (134)
US 8474018B2 · Mardikar et al. · 2013 [cited by applicant]
US 8732800B1 · Askew · 2014 [cited by applicant]
US 8776201B2 · Gao et al. · 2014 [cited by applicant]
US 8990911B2 · Olden et al. · 2015 [cited by applicant]
US 9053302B2 · Sastry et al. · 2015 [cited by applicant]
US 9491200B2 · Mardikar et al. · 2016 [cited by applicant]
US 9560036B2 · Hinton et al. · 2017 [cited by applicant]
US 9781122B1 · Wilson et al. · 2017 [cited by applicant]
US 9838376B1 · Lander et al. · 2017 [cited by applicant]
US 10225242B2 · Grim et al. · 2019 [cited by applicant]
US 10255061B2 · Lander et al. · 2019 [cited by applicant]
US 10341410B2 · Lander et al. · 2019 [cited by applicant]
US 10425386B2 · Wardell et al. · 2019 [cited by applicant]
US 10454940B2 · Lander et al. · 2019 [cited by applicant]
US 10484243B2 · Cole et al. · 2019 [cited by applicant]
US 10484382B2 · Wilson et al. · 2019 [cited by applicant]
US 10511589B2 · Gangawane et al. · 2019 [cited by applicant]
US 10594684B2 · Bansal et al. · 2020 [cited by applicant]
US 10616224B2 · Subramanian et al. · 2020 [cited by applicant]
US 10715564B2 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 10798165B2 · Srinivasan et al. · 2020 [cited by applicant]
US 10846390B2 · Subramanian et al. · 2020 [cited by applicant]
US 10878079B2 · Vepa et al. · 2020 [cited by applicant]
US 10931656B2 · Carru et al. · 2021 [cited by applicant]
US 11061929B2 · Xu et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11165634B2 · Medam et al. · 2021 [cited by applicant]
US 11308132B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11321343B2 · Srinivasan et al. · 2022 [cited by applicant]
US 11599677B2 · Buscaglia et al. · 2023 [cited by applicant]
US 11606391B2 · Greenebaum et al. · 2023 [cited by applicant]
US 11627123B2 · Stayskal · 2023 [cited by examiner]
US 11847239B2 · Grand · 2023 [cited by applicant]
US 11962624B2 · Kuehr-mclaren et al. · 2024 [cited by applicant]
US 12413569B2 · Sharma et al. · 2025 [cited by applicant]
US 20050154913A1 · Barriga et al. · 2005 [cited by applicant]
US 20060074894A1 · Remahl et al. · 2006 [cited by applicant]
US 20070056018A1 · Ridlon et al. · 2007 [cited by applicant]
US 20070143291A1 · Browne · 2007 [cited by applicant]
US 20080276296A1 · Larsen · 2008 [cited by applicant]
US 20090249060A1 · Dossett et al. · 2009 [cited by applicant]
US 20130227658A1 · Leicher et al. · 2013 [cited by applicant]
US 20130283350A1 · Afek et al. · 2013 [cited by applicant]
US 20140075942A1 · Rewers et al. · 2014 [cited by applicant]
US 20140082715A1 · Grajek et al. · 2014 [cited by applicant]
US 20140181003A1 · Kling et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150188906A1 · Minov et al. · 2015 [cited by applicant]
US 20150215348A1 · Koeten et al. · 2015 [cited by applicant]
US 20150350338A1 · Barnett et al. · 2015 [cited by applicant]
US 20160072839A1 · Mortimore, Jr. · 2016 [cited by applicant]
US 20160277390A1 · Minov et al. · 2016 [cited by applicant]
US 20160359861A1 · Manov et al. · 2016 [cited by applicant]
US 20170063931A1 · Seed et al. · 2017 [cited by applicant]
US 20170177894A1 · Stock et al. · 2017 [cited by applicant]
US 20170230419A1 · Prafullchandra et al. · 2017 [cited by applicant]
US 20170329957A1 · Vepa et al. · 2017 [cited by applicant]
US 20170331802A1 · Keshava et al. · 2017 [cited by applicant]
US 20170331832A1 · Lander et al. · 2017 [cited by applicant]
US 20180081905A1 · Kamath et al. · 2018 [cited by applicant]
US 20180144150A1 · Aakolk et al. · 2018 [cited by applicant]
US 20180234416A1 · Moerk et al. · 2018 [cited by applicant]
US 20180349593A1 · Mondello et al. · 2018 [cited by applicant]
US 20190068377A1 · Matsugashita et al. · 2019 [cited by applicant]
US 20190073468A1 · Kazerani et al. · 2019 [cited by applicant]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20190362087A1 · Ferrans et al. · 2019 [cited by applicant]
US 20200007530A1 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 20200053091A1 · Childress et al. · 2020 [cited by applicant]
US 20200120098A1 · Berg et al. · 2020 [cited by applicant]
US 20200264860A1 · Srinivasan et al. · 2020 [cited by applicant]
US 20210044595A1 · Childress et al. · 2021 [cited by applicant]
US 20210081252A1 · Bhargava et al. · 2021 [cited by applicant]
US 20210084031A1 · Lao et al. · 2021 [cited by applicant]
US 20210234706A1 · Nair et al. · 2021 [cited by applicant]
US 20210377044A1 · Leibmann et al. · 2021 [cited by applicant]
US 20220116376A1 · Stayskal · 2022 [cited by examiner]
US 20220210194A1 · Parekh et al. · 2022 [cited by applicant]
US 20220210195A1 · Parekh et al. · 2022 [cited by applicant]
US 20220210196A1 · Parekh et al. · 2022 [cited by applicant]
US 20220239640A1 · Wang · 2022 [cited by examiner]
US 20220247787A1 · Lippert et al. · 2022 [cited by applicant]
US 20230103886A1 · Sharma · 2023 [cited by examiner]
US 20250080530A1 · Trinelli · 2025 [cited by examiner]
CN 108737331A · 2018 [cited by applicant]
CN 110336820A · 2019 [cited by applicant]
CN 115699678A · 2023 [cited by applicant]
EP 3528454A1 · 2019 [cited by applicant]
WO 2018053122A1 · 2018 [cited by applicant]
Hu et al., Multiparty Authorization Framework for Data Sharing in Online Social Networks, Data and Applications Security and Privacy XXV, Jul. 11, 2011, pp. 29-43. [cited by applicant]
Moghaddam et al., A Multi-Layered Policy Generation and Management Engine for Semantic Policy, Digital Communications and Networks, vol. 6, No. 1, Feb. 1, 2020, pp. 38-50. [cited by applicant]
International Application No. PCT/US2022/045348, International Search Report and Written Opinion mailed on Jan. 19, 2023, 13 pages. [cited by applicant]
Intemational Application No. PCT/US2022/045370, International Search Report and Written Opinion mailed on Jan. 23, 2023, 13 pages. [cited by applicant]
Wu et al., A Trust-Evaluation-Enhanced Blockchain-Secured Industrial IoT System, IEEE Internet of Things Journal, vol. 8, No. 7, Oct. 13, 2020, pp. 5510-5517. [cited by applicant]
AWS Single Sign-On, AWS, Available online at https://aws.amazon.com/single-sign-on/, Accessed from Internet on Sep. 20, 2021, pp. 1-11. [cited by applicant]
International Application No. PCT/US2022/045348, International Preliminary Report on Patentability mailed on Apr. 11, 2024, 9 pages. [cited by applicant]
International Application No. PCT/US2022/045370, International Preliminary Report on Patentability mailed on Apr. 11, 2024, 10 pages. [cited by applicant]
Shoemaker, Introduction to IndexedDB: The In-Browser Database, CODE Magazine, Available Online at: https://www.codemag.com/article/1411041/Introduction-to-IndexedDB-The-In-Browser-Database, Aug. 31, 2021, 27 pages. [cited by applicant]
U.S. Appl. No. 17/955,820, Non-Final Office Action mailed on Sep. 16, 2024, 26 pages. [cited by applicant]
U.S. Appl. No. 17/957,146, Non-Final Office Action mailed on Sep. 23, 2024, 19 pages. [cited by applicant]
U.S. Appl. No. 17/957,522, Non-Final Office Action mailed on Sep. 10, 2024, 12 pages. [cited by applicant]
Bailey et al., Self-Adaptive Authorization Framework for Policy Based RBAC/ABAC Models, Institute of Electrical and Electronics Engineers Ninth International Conference on Dependable, Autonomic and Secure Computing, Dec… [cited by applicant]
Pal et al., On Design of A Fine-Grained Access Control Architecture for Securing IoT-Enabled Smart Healthcare Systems, Association for Computing Machinery, MobiQuitous: Proceedings of the 14th EAI International Conferen… [cited by applicant]
Schuster et al., Situational Access Control in the Internet of Things, Session 6A: IOT, Proceedings of the 2018 Association for Computing Machinery SIGSAC Conference on Computer and Communications Security, Oct. 15-19, … [cited by applicant]
Wang et al., Private Set Intersection with Authorization Over Outsourced Encrypted Datasets, Institute of Electrical and Electronics Engineers Transactions on Information Forensics and Security, vol. 16, Jul. 28, 2021, … [cited by applicant]
U.S. Appl. No. 17/955,820, Notice of Allowance mailed on May 1, 2025, 5 pages. [cited by applicant]
U.S. Appl. No. 17/957,146, Final Office Action, mailed on Mar. 7, 2025, 24 pages. [cited by applicant]
U.S. Appl. No. 17/957,522, Non-Final Office Action, mailed on Apr. 17, 2025, 15 pages. [cited by applicant]
Long et al., RACAC: An Approach toward RBAC and ABAC Combining Access Control, Institute of Electrical and Electronics Engineers 5th International Conference on Computer and Communications, Dec. 6, 2019, pp. 1609-1616. [cited by applicant]
Paul, Authentication and Authorization for the Front-end Web Developer, School of Science, Jun. 22, 2020, 61 pages. [cited by applicant]
Qi et al., Access Control Model Based on Role and Attribute and Its Applications on Space-Ground Integration Networks, 4th International Conference on Computer Science and Network Technology, vol. 1, Dec. 19, 2015, pp. … [cited by applicant]
Access Control, Google Cloud, Available Online at: https://cloud.google.com/kubernetes-engine/docs/concepts/access-control, Accessed from Interneton Sep. 16, 2021, 3 pages. [cited by applicant]
AWS IAM Identity Center (Successorto AWS Single Sign-On), Centrally Manage Workforce Access to Multiple AWS Accounts and Applications, Available Online at: https://aws.amazon.com/iam/identity-center/, Accessed from Inte… [cited by applicant]
How does SAML Single Logout Requestwork?, Available Online at: https://support.servicenow.com/kbid=kb_article_view&sysparm_article=KB0788164, Sep. 20, 2021, 2 pages. [cited by applicant]
How Does Single Sign-on Work?, How Single Sign-on Works, Step by Step, Available online at https://www.onelogin.com/learn/how-single-sign-on-works, Accessed from Interneton Sep. 20, 2021, pp. 1-5. [cited by applicant]
IDM365 Identity and Access Management forthe RBAC/ABAC Hybrid Solution, IDM 365, Available Online at: https://idm365.com/idm365-the-rbac-abac-hybrid-solution/, Accessed from Internet on Sep. 20, 2021, 5 pages. [cited by applicant]
IdP Single Logout (SLO), Available Online at: https://docs.pingidentity.com/bundle/integrations/page/gdz1563995023643.html, Jul. 24, 2019, 1 page. [cited by applicant]
Multicloud Identity and Access Management Architecture, IBM Cloud, Available Online at: https://www.ibm.com/cloud/architecture/architectures/security-iam/reference-architecture, Accessed from Internet on Sep. 16, 2021, … [cited by applicant]
OpenID Connect Single Logout, Available Online at: https://is.docs.wso2.com/en/latest/leam/openid-connect-single-logout/, Accessed from Internet on Sep. 23, 2021, 18 pages. [cited by applicant]
Single Logout (SLO), Available Online at: https://identitydocs.akamai.com/gettingstarted/sessions/3logout/page2-slo/, Accessed from Internet on Sep. 20, 2021, 2 pagges. [cited by applicant]
Single Sign-On SSO, JWT SSO, Available Online at: https://www.miniorange.com/saml-identity-provider-with-jwt-protocol, Accessed from Internet on Sep. 20, 2021, 7 pages. [cited by applicant]
Single Sign-Out SAML Protocol, Microsoft Docs, Available Online at: https://docs.microsoft.com/enus/azure/activedirectory/develop/single-sign-out-saml-protocol, Aug. 24, 2021, 3 pages. [cited by applicant]
The Definitive Guide to Attribute-Based Access Control (ABAC), Nextlabs, Available Online at: https://www.nextlabs.com/products/technology/abac/, Accessed from Internet on Sep. 16, 2021, 10 pages. [cited by applicant]
Use IdP-Initiated Single Logout (SLO), Available Online at: https://help.sap.com/viewer/6d6d63354d1242d185ab4830fc04feb1/Cloud/enUS/da2e4f9866dc45f0b4723ca41f051bea.html, Accessed from Internet on Sep. 20, 2021, 1 page. [cited by applicant]
User Management Service Single Sign-on, IBM Documentation, Available online at https://www.ibm.com/docs/en/cloud-paks/1.0?topic=services-ums-single-sign, Accessed from Internet on Sep. 20, 2021, pp. 1-3. [cited by applicant]
What is Azure Attribute-Based Access Control (Azure ABAC)?, Microsoft Docs, Available Online at: https://docs.microsoft.com/en-us/azure/role-based-access-control/conditions-overview, May 13, 2021, 7 pages. [cited by applicant]
What is Azure role-based Access Control (Azure RBAC)?, Microsoft, Available Online at: https://docs.microsoft.com/en-us/azure/role-based-access-control/overview, May 17, 2021, 7 pages. [cited by applicant]
Why SSO is only Part of Multi-Cloud Identity, Available Online at: https://www.strata.io/resources/blog/multi-cloud-identity/sso-only-part-of-multi-cloud-identity/, Jun. 1, 2021, 6 pages. [cited by applicant]
Parker, A Guide to Authorization: A Discussion of New Best Practices Using Hybrid Role and Attribute Techniques, Available Online at: https://f.hubspotusercontent10.net/hubfs/174819/docs/A%20Guide%20To%20Authorization%2… [cited by applicant]
Van Blijderveen et al., How to Scale Your Authorization Needs by Using Attribute-Based Access Control With S3, Available Online at: https://aws.amazon.com/blogs/security/how-to-scale-authorization-needs-using-attribute-… [cited by applicant]
U.S. Appl. No. 17/955,820 , “Corrected Notice of Allowability”, Aug. 20, 2025, 2 pages. [cited by applicant]
U.S. Appl. No. 17/955,820 , “Corrected Notice of Allowability”, Jun. 18, 2025, 2 pages. [cited by applicant]
U.S. Appl. No. 17/957,146 , Non-Final Office Action, Mailed On Sep. 19, 2025, 17 pages Beyond, Jul. 6, 2018, 9 pages. [cited by applicant]
Chavan “Web Application Security: CAS and Beyond”, Jul. 6, 2018, 9 pages. [cited by applicant]