IP Library › Granted Patent US 12,585,446
Granted Patent B2
US 12,585,446 · App. 18/647,781 · Granted Mar 24, 2026

Consent-driven access management for cloud resources

Inventors: Ayman Mohamed Aly Hassan Elmenshawy (Bellevue, WA); Daniel M. Vogel (Seattle, WA)
Assignee: Oracle International Corporation
G06F8/60G06F9/5005H04L9/3213H04L41/0806H04L41/0869H04L63/108H04L67/10G06Q30/015
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,446
App. No.
18/647,781
Granted
Mar 24, 2026
Kind
B2
Abstract

Techniques for consent-driven access management include: receiving, from a requestor, a request for consent for an actor to access a target set of resources in a cloud environment; identifying a consent workflow that specifies a name and/or an attribute of a set of one or more users from which to obtain respective approvals of the consent request; traversing the consent workflow to obtain the respective approvals from the set of one or more users; determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources; where access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources.

Claims (68)

1 . A method comprising:

receiving, from a requestor, a consent request for consent for an actor to access a target set of resources in a cloud environment;

identifying a consent workflow that specifies at least one of a name or an attribute of a set of one or more users from which to obtain respective approvals of the consent request;

traversing the consent workflow to obtain the respective approvals from the set of one or more users;

determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

granting a consent token responsive to obtaining the respective approvals;

transmitting a first request to access the target set of resources, the first request comprising the consent token;

wherein access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

wherein granting or denying the first request to access the target set of resources is conditioned, at least in part, on presence of the consent token; and

wherein the method is performed by at least one device including a hardware processor.

2 . The method of claim 1 , wherein granting or denying the first request to access the target set of resources is further conditioned on verifying the one or more access policies based on the consent token.

3 . The method of claim 1 , wherein granting or denying the first request to access the target set of resources is further conditioned on verifying, by an identity service, a scope of consent associated with the consent token.

4 . The method of claim 1 , further comprising:

storing, by an identity service in association with granting the consent token, information indicating a scope of consent associated with the consent token.

5 . The method of claim 1 :

wherein the consent token is activated for a first predetermined amount of time from when the consent token is granted;

wherein the consent token, when activated, is valid for a second predetermined amount of time.

6 . The method of claim 1 , wherein a first entity manages the one or more access policies and a second entity manages the consent workflow.

7 . The method of claim 1 , wherein the requestor is associated with a first entity and the set of one or more users from which to obtain respective approvals is associated with a second entity.

8 . The method of claim 7 :

wherein the first entity is a cloud service provider;

wherein the first entity controls, at least in part, access by the second entity to the cloud environment;

wherein the second entity controls, at least in part, access to a partition of the cloud environment by a third entity.

9 . The method of claim 7 :

wherein the first entity is a cloud service provider;

wherein the first entity bills the second entity for use of the cloud environment;

wherein the second entity bills a third entity for use of the cloud environment.

10 . The method of claim 1 , wherein the consent workflow corresponds to one of:

(a) standing consent, wherein the consent request is pre-approved by the set of one or more users;

(b) on-demand consent, wherein obtaining the respective approvals from the set of one or more users requires user input from the set of one or more users responsive to the consent request; or

(c) quorum consent, wherein obtaining the respective approvals from the set of one or more users requires approval of at least a minimum number of the set of one or more users.

11 . The method of claim 1 , wherein the consent workflow evaluates a condition that is based on state data at a time of the consent request.

12 . The method of claim 1 , further comprising:

detecting a situation in which the consent request would be denied in the absence of one or more override conditions;

determining if the one or more override conditions is satisfied;

responsive to determining that the one or more override conditions is satisfied:

authorizing the requestor to obtain consent to access the target set of resources in the cloud environment.

13 . The method of claim 1 , wherein the consent request comprises one or more search attributes that map to the target set of resources in the cloud environment.

14 . The method of claim 1 , wherein the requestor is the actor.

15 . The method of claim 1 , further comprising:

receiving, by the requestor from the actor, a second request to access the target set of resources in the cloud environment;

responsive to the second request to access the target set of resources in the cloud environment: generating, by the requestor, the consent request on behalf of the actor.

16 . The method of claim 1 , further comprising:

receiving, via a first console, user input that selects the consent workflow from among a plurality of available consent workflows;

wherein the requestor receives the consent request via a second console that is separate from the first console.

17 . The method of claim 16 , further comprising:

presenting, in the second console, a message indicating that approval of the consent request is pending action by the set of one or more users from which to obtain respective approvals.

18 . A system comprising:

one or more hardware processors;

one or more non-transitory computer-readable media; and

program instructions stored on the one or more non-transitory computer-readable media which, when executed by the one or more hardware processors, cause the system to perform operations comprising:

receiving, from a requestor, a consent request for consent for an actor to access a target set of resources in a cloud environment;

identifying a consent workflow that specifies at least one of a name or an attribute of a set of one or more users from which to obtain respective approvals of the consent request;

traversing the consent workflow to obtain the respective approvals from the set of one or more users;

determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

granting a consent token responsive to obtaining the respective approvals;

transmitting a first request to access the target set of resources, the first request comprising the consent token;

wherein access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

wherein granting or denying the first request to access the target set of resources is conditioned, at least in part, on presence of the consent token.

19 . One or more non-transitory computer-readable media storing instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, from a requestor, a consent request for consent for an actor to access a target set of resources in a cloud environment;

identifying a consent workflow that specifies at least one of a name or an attribute of a set of one or more users from which to obtain respective approvals of the consent request;

traversing the consent workflow to obtain the respective approvals from the set of one or more users;

determining that one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

granting a consent token responsive to obtaining the respective approvals;

transmitting a first request to access the target set of resources, the first request comprising the consent token;

wherein access by the actor to the target set of resources is conditioned on both (a) obtaining the respective approvals from the set of one or more users and (b) determining that the one or more access policies, separate from the consent workflow, permit the actor to access the target set of resources;

wherein granting or denying the first request to access the target set of resources is conditioned, at least in part, on presence of the consent token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: ELMENSHAWY, AYMAN MOHAMED ALY HASSAN; VOGEL, DANIEL M.
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067278/0850 →
Continuity (2)
Provisional Application 63462875 · Apr 28, 2023
Related Publication 20240364707A1 · Oct 31, 2024
References Cited (104)
US 9092502B1 · Cannaliato et al. · 2015 [cited by applicant]
US 9306814B1 · Roth et al. · 2016 [cited by applicant]
US 9438599B1 · Yuhan et al. · 2016 [cited by applicant]
US 9722895B1 · Sarukkai et al. · 2017 [cited by applicant]
US 9985947B1 · Elhard · 2018 [cited by applicant]
US 10757574B1 · Rule et al. · 2020 [cited by applicant]
US 10878483B1 · Felbinger et al. · 2020 [cited by applicant]
US 11552953B1 · Avadhanam · 2023 [cited by applicant]
US 11720536B1 · Kisser et al. · 2023 [cited by applicant]
US 20020198973A1 · Besaw · 2002 [cited by applicant]
US 20030154407A1 · Kato et al. · 2003 [cited by applicant]
US 20100212004A1 · Fu · 2010 [cited by applicant]
US 20130054426A1 · Rowland et al. · 2013 [cited by applicant]
US 20130297711A1 · Nhu · 2013 [cited by applicant]
US 20130304925A1 · Ferris et al. · 2013 [cited by applicant]
US 20140280595A1 · Mani et al. · 2014 [cited by applicant]
US 20150180949A1 · Maes · 2015 [cited by examiner]
US 20150363852A1 · Vautour · 2015 [cited by applicant]
US 20160043909A1 · Pogrebinsky et al. · 2016 [cited by applicant]
US 20160142211A1 · Metke et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20170230229A1 · Sasturkar et al. · 2017 [cited by applicant]
US 20180052861A1 · Seetharaman et al. · 2018 [cited by applicant]
US 20180219784A1 · Jiang et al. · 2018 [cited by applicant]
US 20180234256A1 · Bowen · 2018 [cited by applicant]
US 20190087835A1 · Schwed et al. · 2019 [cited by applicant]
US 20190097812A1 · Toth · 2019 [cited by examiner]
US 20190156000A1 · Hoffmann et al. · 2019 [cited by applicant]
US 20190166007A1 · Sundaram et al. · 2019 [cited by applicant]
US 20190205045A1 · Hugot et al. · 2019 [cited by applicant]
US 20200014659A1 · Chasman et al. · 2020 [cited by applicant]
US 20200112497A1 · Yenumulapalli et al. · 2020 [cited by applicant]
US 20200117757A1 · Yanamandra et al. · 2020 [cited by applicant]
US 20200358756A1 · Rose et al. · 2020 [cited by applicant]
US 20210216190A1 · Vakil et al. · 2021 [cited by applicant]
US 20210234864A1 · Dube et al. · 2021 [cited by applicant]
US 20210273914A1 · Cobb · 2021 [cited by applicant]
US 20210279109A1 · Ji et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari et al. · 2021 [cited by applicant]
US 20210392142A1 · Stephens et al. · 2021 [cited by applicant]
US 20220091947A1 · Kothari et al. · 2022 [cited by applicant]
US 20220103618A1 · Pinheiro et al. · 2022 [cited by applicant]
US 20220150124A1 · Cooley et al. · 2022 [cited by applicant]
US 20220255902A1 · Woodson · 2022 [cited by applicant]
US 20220294818A1 · Parekh et al. · 2022 [cited by applicant]
US 20220335340A1 · Moustafa et al. · 2022 [cited by applicant]
US 20220374271A1 · Pogrebinsky et al. · 2022 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230132478A1 · Robinson et al. · 2023 [cited by applicant]
US 20230316348A1 · Dageville et al. · 2023 [cited by applicant]
US 20230342179A1 · Suttle et al. · 2023 [cited by applicant]
US 20230362161A1 · Spector et al. · 2023 [cited by applicant]
US 20230385286A1 · Glickman et al. · 2023 [cited by applicant]
US 20230418979A1 · DeLuca · 2023 [cited by examiner]
US 20240054063A1 · Wichelman et al. · 2024 [cited by applicant]
US 20240095739A1 · Adogla et al. · 2024 [cited by applicant]
US 20240320240A1 · Podder · 2024 [cited by applicant]
US 20240364707A1 · Elmenshawy · 2024 [cited by examiner]
US 20240422215A1 · Khan · 2024 [cited by examiner]
EP 2893685B1 · 2017 [cited by applicant]
EP 3429156A1 · 2019 [cited by applicant]
EP 3271857B1 · 2020 [cited by applicant]
KR 20140066616A · 2014 [cited by examiner]
WO 2014039921A1 · 2014 [cited by applicant]
WO 2018010791A1 · 2018 [cited by applicant]
WO 2021145894A1 · 2021 [cited by applicant]
WO 2021150306A1 · 2021 [cited by applicant]
WO 2021150307A1 · 2021 [cited by applicant]
WO 2021174104A1 · 2021 [cited by applicant]
“Create a Reseller and Reseller Administrator User”, Retrieved from https://abiquo.atlassian.net/wiki/spaces/ABI54/pages/310740667/Create+a+Reseller+and+Reseller+Administrator+User, May 3, 2022, pp. 1-5. [cited by applicant]
“General Variables for All Requests”, Jun. 28, 2023, pp. 6. [cited by applicant]
“Overview of Access Approval”, Retrieved from https://cloud.google.com/assured-workloads/access-approval/docs/overview, Jun. 6, 2024, pp. 5. [cited by applicant]
“Periodic 802.1X reauthentication”, Retrieved from https://techhub.hpe.com/eginfolib/networking/docs/switches/5130ei/5200-3946_security_cg/content/485048074.htm, Retrieved from Oct. 25, 2023, p. 1. [cited by applicant]
“Policy Syntax”, Jan. 4, 2023, pp. 7. [cited by applicant]
“Reinstate admin privileges for a customer's Azure CSP subscriptions”, Retrieved from https://learn.microsoft.com/en-us/partner-center/reinstate-csp, Aug. 1, 2023, pp. 7. [cited by applicant]
“Tenant administrator settings”, Retrieved from https://backstage.forgerock.com/docs/idcloud/latest/tenants/tenant-administrator-settings.html, Jun. 7, 2023, pp. 12. [cited by applicant]
“Verbs”, Jun. 5, 2023, pp. 2. [cited by applicant]
Anonymbus: “Tokenization -(data security)”, Wikipedia, Feb. 12, 2023, pp. 1-12. [cited by applicant]
Bhat S., “Admin access management in Azure Cloud Solution Provider (CSP) subscriptions”, Retrieved from https://techcommunity.microsoft.com/t5/security-compliance-and-identity/admin-access-management-in-azure-cloud-solu… [cited by applicant]
Ducharme et al., “Seamlessly Protect Your IBM Cloud Application Infrastructure with Privileged Access Gateway”, Oct. 3, 2022, pp. 13. [cited by applicant]
George et al., “Data anonymization and integrity checking in cloud computing”, 2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 2013, pp. 5. [cited by applicant]
Ma et al., “ServiceRank: Root Cause Identification of Anomaly in Large-Scale Microservice Architectures”, : IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 5, Sep.-Oct. 2022, pp. 3087-3100. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro) Service-Based Cloud Applications: A Survey”, ACM Computing Surveys, vol. 55, No. 3, Article 59, Feb. 2022, pp. 1-39. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Security Guide for Exadata Database Service on Cloud@Customer Systems”, Apr. 1, 2023, XP093181902. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Overview of IAM”, Feb. 8, 2023, XP093184083. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Renaming a Cloud Account”, May 14, 2021, XP093185071. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Site-to-Site VPN Overview”, Feb. 8, 2023, XP093184733. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Billing and cost management overview”, Dec. 20, 2022, XP093183514. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Cloud Guard concepts”, Jan. 18, 2022, XP093183028. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Started with Policies”, Jan. 4, 2023, XP093184099. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Summary Information on the Overview Page”, Aug. 16, 2022, XP093183031. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Learn Best Practices for Set ting Up Your Tenancy”, Feb. 8, 2023, XP093184095. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Managing Compartments”, Feb. 8, 2023, XP093184098. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Monitoring Threats”, Sep. 28, 2022, XP093183035. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Overview of the Console Dashboards Service”, Mar. 14, 2023, XP093184740. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Prerequisites for Oracle Platform Services on Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093185058. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Welcome to Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093182493. [cited by applicant]
Anonymous: “Oracle Gen 2 Exadata Cloud@Customer Security Controls”, Jan. 11, 2023, XP093181973. [cited by applicant]
Anonymous: “Oracle Operator Access Control Configuration and Administration Guide”, Nov. 18, 2022, XP093181896. [cited by applicant]
Anonymous: “Oracle Public Sector Licensing and Permitting”, 2022, XP093184298. [cited by applicant]
Anonymous: “Oracle Sovereign Cloud”, Feb. 15, 2023, XP093184649. [cited by applicant]
Apps2fusion: “Security Roles in Oracle Fusion Cloud SLA”, Nov. 30, 2018, XP093184293. [cited by applicant]
Magouryrk Clay: “Announcing Oracle Alloy: The power of the cloud in your hands”, Oct. 18, 2022, XP093183485. [cited by applicant]
Q. S. Singh and Y. Liu, “A cloud service architecture for analyzing big monitoring data,” in Tsinghua Science and Technology, vol. 21, No. 1, pp. 55-70, Feb. 2016, doi: 10.1109/TST.2016.7399283 (Year: 2016). [cited by applicant]