IP Library › Granted Patent US 12,470,387
Granted Patent B2
US 12,470,387 · App. 18/422,916 · Granted Nov 11, 2025

Workload identity resource principle

Inventors: Jacob M. Lindholm (Londonderry, NH); Joshua Aaron Horwitz (Centreville, VA)
Assignee: Oracle International Corporation
H04L9/3213G06F16/27H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,387
App. No.
18/422,916
Granted
Nov 11, 2025
Kind
B2
Abstract

Techniques are described herein for authenticating a pod. A method can include a manager instance receiving a first request for a first token to access a computing resource. The manager instance can determine an identity of the service account and generate a second request for the first token based at least in part on the authentication. The manager instance can transmit the second request to a token issuance service of the computing system. The token issuance service can generate a third request for the first token, the third request comprising the identity of the service account and a token issuance service signature. The token issuance service can transmit the third request to an identity service of the computing system. The identity service can generate the first token based at least in part on determining whether to generate the first token.

Claims (96)

1 . A method, comprising:

receiving, by a manager instance of a computing system, a first request for a first token to access a computing resource, the first request from a computing process of a plurality of computing processes associated with a service account,

determining, by the manager instance of the computing system, an identity of the service account based at least in part on an authentication;

generating, by the manager instance of the computing system, a second request for the first token based at least in part on the authentication;

transmitting, by the manager instance of the computing system, the second request to a token issuance service of the computing system, the second request comprising a manager instance signature and the identity of the service account;

generating, by the token issuance service of the computing system, a third request for the first token, the third request comprising the identity of the service account and a token issuance service signature;

transmitting, by the token issuance service of the computing system, the third request to an identity service of the computing system;

determining, by the identity service of the computing system, whether to generate the first token based at least in part on a policy associated with the service account; and

generating, by the identity service of the computing system, the first token based at least in part on determining whether to generate the first token.

2 . The method of claim 1 , wherein the method further comprises:

detecting a creation of a container for storing the computing process;

generating, by an application programming interface (API) server, a second token associated with the computing process based at least in part on detecting the creation of the container; and

transmitting the second token to an agent of the computing system.

3 . The method of claim 2 , wherein the first request comprises the second token, and wherein the method further comprises:

transmitting a fourth request to the API server to authenticate the second token; and

receiving from the API server a response indicating the second token is authenticated, wherein the response further comprises a respective identity of a cluster and a namespace associated with the service computing process, and wherein the identity service determines whether to generate the first token based at least in part on the respective identity of the cluster, the namespace, and the service account.

4 . The method of claim 3 , wherein the first request comprises a cryptographic signature, and wherein the method further comprises:

accessing a cryptographic key associated with the computing process;

decrypting the cryptographic signature based at least in part on the cryptographic key;

accessing a first hash value from the first request based at least in part on decrypting the cryptographic signature;

determining a second hash value based at least in part on the first request,

comparing the first hash value to the second hash value, wherein the first request is authenticated based at least in part on the comparing the first hash value to the second hash value.

5 . The method of claim 3 , wherein the method further comprises:

transmitting the second token to an authentication provider of the computing system;

generating, by the authentication provider, a fourth request for a computing service managing the computing resource, wherein the fourth request comprises a fifth request from the computing process for the computing resource and the second token; and

transmitting the fourth request to the computing service.

6 . The method of claim 5 , wherein the computing process is a first computing process, and wherein the method further comprises:

receiving, by the authentication provider, a sixth request for the computing resource from a second computing process associated with the service account;

generating a seventh request comprising the six the request and the second token; and

transmitting the seventh request to the computing service.

7 . The method of claim 1 , wherein the method further comprises:

authenticating the second request is performed by a network interface controller that provides an interface between the manager instance and the token issuance service.

8 . A computing system comprising:

one or more processors; and

one or more computer-readable media having stored thereon a sequence of instructions, when executed, cause the one or more processors to:

receive, by a manager instance of the computing system, a first request for a first token to access a computing resource, the first request from a computing process of a plurality of computing processes associated with a service account,

determine, by the manager instance of the computing system, an identity of the service account based at least in part on an authentication;

generate, by the manager instance of the computing system, a second request for the first token based at least in part on the authentication;

transmit, by the manager instance of the computing system, the second request to a token issuance service of the computing system, the second request comprising a manager instance signature and the identity of the service account;

generate, by the token issuance service of the computing system, a third request for the first token, the third request comprising the identity of the service account and a token issuance service signature;

transmit, by the token issuance service of the computing system, the third request to an identity service of the computing system;

determine, by the identity service of the computing system, whether to generate the first token based at least in part on a policy associated with the service account; and

generate, by the identity service of the computing system, the first token based at least in part on determining whether to generate the first token.

9 . The computing system of claim 8 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

detect a creation of a container for storing the computing process;

generate, by an application programming interface (API) server, a second token associated with the computing process based at least in part on detecting the creation of the container; and

transmit the second token to an agent of the computing system.

10 . The computing system of claim 9 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

transmit a fourth request to the API server to authenticate the second token; and

receive from the API server a response indicating the second token is authenticated, wherein the response further comprises a respective identity of a cluster and a namespace associated with the service computing process, and wherein the identity service determines whether to generate the first token based at least in part on the respective identity of the cluster, the namespace, and the service account.

11 . The computing system of claim 10 , wherein the first request comprises a cryptographic signature, wherein the sequence of instructions, when executed, further cause the one or more processors to:

access a cryptographic key associated with the computing process;

decrypt the cryptographic signature based at least in part on the cryptographic key;

access a first hash value from the first request based at least in part on decrypting the cryptographic signature;

determine a second hash value based at least in part on the first request,

compare the first hash value to the second hash value, wherein the first request is authenticated based at least in part on the comparing the first hash value to the second hash value.

12 . The computing system of claim 10 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

transmit the second token to an authentication provider of the computing system;

generate, by the authentication provider, a fourth request for a computing service managing the computing resource, wherein the fourth request comprises a fifth request from the computing process for the computing resource and the second token; and

transmit the fourth request to the computing service.

13 . The computing system of claim 12 , wherein the computing process is a first computing process, and wherein the sequence of instructions, when executed, further cause the one or more processors to:

receive, by the authentication provider, a sixth request for the computing resource from a second computing process associated with the service account;

generate a seventh request comprising the sixth request and the second token; and

transmit the seventh request to the computing service.

14 . The computing system of claim 8 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

authenticate the second request is performed by a network interface controller that provides an interface between the manager instance and the token issuance service.

15 . One or more non-transitory computer-readable media having stored thereon a sequence of instructions that, when executed by one or more processors of a computing system, cause the computing system to:

receive, by a manager instance of the computing system, a first request for a first token to access a computing resource, the first request from a computing process of a plurality of computing processes associated with a service account,

determine, by the manager instance of the computing system, an identity of the service account based at least in part on an authentication;

generate, by the manager instance of the computing system, a second request for the first token based at least in part on the authentication;

transmit, by the manager instance of the computing system, the second request to a token issuance service of the computing system, the second request comprising a manager instance signature and the identity of the service account;

generate, by the token issuance service of the computing system, a third request for the first token, the third request comprising the identity of the service account and a token issuance service signature;

transmit, by the token issuance service of the computing system, the third request to an identity service of the computing system;

determine, by the identity service of the computing system, whether to generate the first token based at least in part on a policy associated with the service account; and

generate, by the identity service of the computing system, the first token based at least in part on determining whether to generate the first token.

16 . The one or more non-transitory computer-readable media of claim 15 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

detect a creation of a container for storing the computing process;

generate, by an application programming interface (API) server, a second token associated with the computing process based at least in part on detecting the creation of the container; and

transmit the second token to an agent of the computing system.

17 . The one or more non-transitory computer-readable media of claim 16 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

transmit a fourth request to the API server to authenticate the second token; and

receive from the API server a response indicating the second token is authenticated, wherein the response further comprises a respective identity of a cluster and a namespace associated with the service computing process, and wherein the identity service determines whether to generate the first token based at least in part on the respective identity of the cluster, the namespace, and the service account.

18 . The one or more non-transitory computer-readable media of claim 17 , wherein the first request comprises a cryptographic signature, and wherein the sequence of instructions, when executed, further cause the one or more processors to:

access a cryptographic key associated with the computing process;

decrypt the cryptographic signature based at least in part on the cryptographic key;

access a first hash value from the first request based at least in part on decrypting the cryptographic signature;

determine a second hash value based at least in part on the first request,

compare the first hash value to the second hash value, wherein the first request is authenticated based at least in part on the comparing the first hash value to the second hash value.

19 . The one or more non-transitory computer-readable media of claim 17 , wherein the sequence of instructions, when executed, further cause the one or more processors to:

transmit the second token to an authentication provider of the computing system;

generate, by the authentication provider, a fourth request for a computing service managing the computing resource, wherein the fourth request comprises a fifth request from the computing process for the computing resource and the second token; and

transmit the fourth request to the computing service.

20 . The one or more non-transitory computer-readable media of claim 19 , wherein the computing process is a first computing process, and wherein the sequence of instructions, when executed, further cause the one or more processors to:

receive, by the authentication provider, a sixth request for the computing resource from a second computing process associated with the service account;

generate a seventh request comprising the sixth request and the second token; and

transmit the seventh request to the computing service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2024
From: LINDHOLM, JACOB M.; HORWITZ, JOSHUA AARON
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 066251/0686 →
Continuity (2)
Provisional Application 63528210 · Jul 21, 2023
Related Publication 20250030549A1 · Jan 23, 2025
References Cited (13)
US 10680827B2 · Barbour · 2020 [cited by examiner]
US 11431513B1 · Cannata · 2022 [cited by examiner]
US 20170339196A1 · Lewis · 2017 [cited by examiner]
US 20180083971A1 · Brown · 2018 [cited by examiner]
US 20180309759A1 · Leibmann et al. · 2018 [cited by applicant]
US 20180367528A1 · Schwarz · 2018 [cited by examiner]
US 20210157896A1 · Hashmi et al. · 2021 [cited by applicant]
US 20210328793A1 · Saravanan · 2021 [cited by examiner]
US 20210377044A1 · Leibmann · 2021 [cited by examiner]
US 20230163967A1 · Cannata, Jr. · 2023 [cited by examiner]
EP 3416333A1 · 2018 [cited by applicant]
“Granting Workloads Access to OCI Resources”, Available Online at: https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contenggrantingworkloadaccesstoresources.htm, Jul. 12, 2023, 17 pages. [cited by applicant]
International Patent Application No. PCT/US2024/036357 , “International Search Report and Written Opinion”, Sep. 25, 2024, 14 pages. [cited by applicant]