IP Library › Granted Patent US 12,609,822
Granted Patent B2
US 12,609,822 · App. 18/649,585 · Granted Apr 21, 2026

Accessing cloud environments through administrative tenancies to comply with sovereignty requirements

Inventors: Nachiketh Rao Potlapally (Seattle, WA); Christian A. Linacre (Fall City, WA); Apurv Awasthi (Woodinville, WA); Harsh Aseeja (Kirkland, WA); Qingyang Luo (Seattle, WA)
Assignee: Oracle International Corporation
H04L9/0891H04L63/10H04L63/102H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,822
App. No.
18/649,585
Granted
Apr 21, 2026
Kind
B2
Abstract

Techniques for providing user access to cloud environments through an administrative tenancy to comply with sovereignty requirements are disclosed. The administrative tenancy is one of multiple tenancies in the cloud environment. The administrative tenancy includes tools for communicating with services running outside of the administrative tenancy. The user may only be able to access these services through the administrative tenancy. User access to the administrative tenancy requires the user to satisfy one or more sovereignty requirements. After determining that the user satisfies the sovereignty requirements for the cloud environment, the system grants the user access to the tools within the administrative tenancy to communicate with services outside the administrative tenancy.

Claims (61)

1 . A method comprising:

receiving, in a cloud environment, a request for a first user to access one or more administrative tools in an administrative tenancy;

wherein the administrative tenancy is one of a plurality of tenancies in the cloud environment;

wherein the administrative tenancy comprises the one or more administrative tools for communicating with one or more services that are running outside of the administrative tenancy;

determining that the first user satisfies a sovereignty requirement for the cloud environment,

wherein determining that the first user satisfies the sovereignty requirement comprises performing a geographic location check based on a physical location of the first user,

wherein performing the geographic location check comprises determining if a source Internet Protocol (IP) address associated with the first user belongs to a preconfigured Classless Inter-Domain Routing (CIDR) range corresponding to a preapproved geographic region; and

based at least on determining that the first user satisfies the sovereignty requirement: granting the request for the first user to access the one or more administrative tools in the administrative tenancy;

wherein the method is performed by at least one device including a hardware processor.

2 . The method of claim 1 , wherein the one or more services running outside of the administrative tenancy are not otherwise accessible by the first user.

3 . The method of claim 1 , wherein:

the cloud environment comprises a set of cloud resources;

the set of cloud resources comprises the one or more administrative tools and the one or more services running outside of the administrative tenancy; and

access to the set of cloud resources is controlled by a set of access policies, each of the set of access policies having a maximum scope of one of the plurality of tenancies.

4 . The method of claim 1 :

wherein a set of one or more access policies allows access by the first user to the one or more administrative tools in the administrative tenancy;

wherein the set of one or more access policies specifies one or more of allowing or admitting a static or dynamic group of users comprising the first user to access a static or dynamic group of cloud resources comprising the one or more administrative tools in the administrative tenancy.

5 . The method of claim 1 , wherein no access policy allows access by the first user directly to the one or more services running outside of the administrative tenancy.

6 . The method of claim 1 , wherein:

the administrative tenancy is operated by a cloud service provider (CSP);

the one or more services running outside of the administrative tenancy is customer-operated;

the one or more services run in one or more tenancies, of the plurality of tenancies, that are each customer-operated; and

the first user is associated with the CSP.

7 . The method of claim 1 , wherein receiving the request is performed by a virtual private network (VPN) gateway associated with the administrative tenancy.

8 . The method of claim 1 :

wherein the cloud environment comprises a plurality of partitions;

wherein a first partition of the plurality of partitions comprises the administrative tenancy and is subject to the sovereignty requirement;

wherein access to a second administrative tenancy, in a second partition of the plurality of partitions, is not subject to the sovereignty requirement.

9 . The method of claim 1 , further comprising:

authenticating the first user on an ongoing basis during use of the administrative tenancy.

10 . The method of claim 9 , wherein authenticating the first user on an ongoing basis comprises performing two-factor authentication, on an ongoing basis, responsive to detecting a plurality of instances of one or more authentication triggers.

11 . The method of claim 1 , further comprising:

determining one or more of (a) that the first user is on a pre-approved list of operators or (b) that the first user is not on a list of forbidden operators.

12 . The method of claim 1 , further comprising:

detecting a presence of a hardware security device coupled to a physical device used by the first user to access the administrative tenancy.

13 . The method of claim 12 , wherein the hardware security device is a hardware dongle.

14 . The method of claim 1 , wherein the one or more administrative tools available to the first user in the administrative tenancy is based on a first configuration specific to the first user.

15 . The method of claim 14 , wherein a second user has access to at least one administrative tool not included in the one or more administrative tools available to the first user, based on a second configuration specific to the second user.

16 . The method of claim 1 , further comprising:

maintaining an audit log of (a) access by the first user to the administrative tenancy and (b) actions taken by the first user within the administrative tenancy.

17 . One or more non-transitory computer-readable media storing instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, in a cloud environment, a request for a first user to access an administrative tenancy;

wherein the administrative tenancy is one of a plurality of tenancies in the cloud environment;

wherein the administrative tenancy comprises one or more administrative tools for communicating with one or more services that are running outside of the administrative tenancy;

determining that the first user satisfies a sovereignty requirement for the cloud environment;

wherein determining that the first user satisfies the sovereignty requirement comprises performing a geographic location check based on a physical location of the first user,

wherein performing the geographic location check comprises determining if a source Internet Protocol (IP) address associated with the first user belongs to a preconfigured Classless Inter-Domain Routing (CIDR) range corresponding to a preapproved geographic region; and

based at least on determining that the first user satisfies the sovereignty requirement: granting the request for the first user to access the administrative tenancy;

wherein the first user uses the one or more administrative tools in the administrative tenancy to make authenticated calls to the one or more services running outside of the administrative tenancy.

18 . A system comprising:

one or more hardware processors;

one or more non-transitory computer-readable media; and

program instructions stored on the one or more non-transitory computer-readable media which, when executed by the one or more hardware processors, cause the system to perform operations comprising:

receiving, in a cloud environment, a request for a first user to access an administrative tenancy;

wherein the administrative tenancy is one of a plurality of tenancies in the cloud environment;

wherein the administrative tenancy comprises one or more administrative tools for communicating with one or more services that are running outside of the administrative tenancy;

determining that the first user satisfies a sovereignty requirement for the cloud environment,

wherein determining that the first user satisfies the sovereignty requirement comprises performing a geographic location check based on a physical location of the first user,

wherein performing the geographic location check comprises determining if a source Internet Protocol (IP) address associated with the first user belongs to a preconfigured Classless Inter-Domain Routing (CIDR) range corresponding to a preapproved geographic region; and

based at least on determining that the first user satisfies the sovereignty requirement: granting the request for the first user to access the administrative tenancy;

wherein the first user uses the one or more administrative tools in the administrative tenancy to make authenticated calls to the one or more services running outside of the administrative tenancy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: POTLAPALLY, NACHIKETH RAO; LINACRE, CHRISTIAN A.; AWASTHI, APURV; ASEEJA, HARSH; LUO, QINGYANG
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067285/0723 →
Continuity (2)
Provisional Application 63462880 · Apr 28, 2023
Related Publication 20240364689A1 · Oct 31, 2024
References Cited (98)
US 9092502B1 · Cannaliato et al. · 2015 [cited by applicant]
US 9306814B1 · Roth et al. · 2016 [cited by applicant]
US 9438599B1 · Yuhan et al. · 2016 [cited by applicant]
US 9722895B1 · Sarukkai et al. · 2017 [cited by applicant]
US 9985947B1 · Elhard · 2018 [cited by applicant]
US 10757574B1 · Rule et al. · 2020 [cited by applicant]
US 10878483B1 · Felbinger et al. · 2020 [cited by applicant]
US 11552953B1 · Avadhanam · 2023 [cited by applicant]
US 11720536B1 · Kisser et al. · 2023 [cited by applicant]
US 20020198973A1 · Besaw · 2002 [cited by applicant]
US 20030154407A1 · Kato et al. · 2003 [cited by applicant]
US 20100212004A1 · Fu · 2010 [cited by applicant]
US 20130054426A1 · Rowland et al. · 2013 [cited by applicant]
US 20130297711A1 · Nhu · 2013 [cited by examiner]
US 20130304925A1 · Ferris et al. · 2013 [cited by applicant]
US 20140280595A1 · Mani · 2014 [cited by examiner]
US 20150363852A1 · Vautour · 2015 [cited by applicant]
US 20160043909A1 · Pogrebinsky et al. · 2016 [cited by applicant]
US 20160142211A1 · Metke et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani et al. · 2016 [cited by applicant]
US 20170230229A1 · Sasturkar et al. · 2017 [cited by applicant]
US 20180052861A1 · Seetharaman et al. · 2018 [cited by applicant]
US 20180219784A1 · Jiang et al. · 2018 [cited by applicant]
US 20180234256A1 · Bowen · 2018 [cited by applicant]
US 20190087835A1 · Schwed et al. · 2019 [cited by applicant]
US 20190156000A1 · Hoffmann et al. · 2019 [cited by applicant]
US 20190166007A1 · Sundaram et al. · 2019 [cited by applicant]
US 20190205045A1 · Hugot et al. · 2019 [cited by applicant]
US 20200014659A1 · Chasman et al. · 2020 [cited by applicant]
US 20200112497A1 · Yenumulapalli et al. · 2020 [cited by applicant]
US 20200117757A1 · Yanamandra et al. · 2020 [cited by applicant]
US 20200358756A1 · Rose · 2020 [cited by examiner]
US 20210216190A1 · Vakil et al. · 2021 [cited by applicant]
US 20210234864A1 · Dube et al. · 2021 [cited by applicant]
US 20210273914A1 · Cobb · 2021 [cited by applicant]
US 20210279109A1 · Ji et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari et al. · 2021 [cited by applicant]
US 20210392142A1 · Stephens · 2021 [cited by examiner]
US 20220091947A1 · Kothari et al. · 2022 [cited by applicant]
US 20220103618A1 · Pinheiro et al. · 2022 [cited by applicant]
US 20220150124A1 · Cooley et al. · 2022 [cited by applicant]
US 20220255902A1 · Woodson · 2022 [cited by applicant]
US 20220294818A1 · Parekh et al. · 2022 [cited by applicant]
US 20220335340A1 · Moustafa et al. · 2022 [cited by applicant]
US 20220374271A1 · Pogrebinsky et al. · 2022 [cited by applicant]
US 20230109926A1 · Nair · 2023 [cited by examiner]
US 20230132478A1 · Robinson et al. · 2023 [cited by applicant]
US 20230316348A1 · Dageville et al. · 2023 [cited by applicant]
US 20230342179A1 · Suttle et al. · 2023 [cited by applicant]
US 20230362161A1 · Spector et al. · 2023 [cited by applicant]
US 20230385286A1 · Glickman et al. · 2023 [cited by applicant]
US 20240054063A1 · Wichelman et al. · 2024 [cited by applicant]
US 20240095739A1 · Adogla et al. · 2024 [cited by applicant]
US 20240320240A1 · Podder · 2024 [cited by applicant]
EP 2893685B1 · 2017 [cited by applicant]
EP 3429156A1 · 2019 [cited by applicant]
EP 3271857B1 · 2020 [cited by applicant]
WO 2014039921A1 · 2014 [cited by applicant]
WO 2018010791A1 · 2018 [cited by applicant]
WO 2021145894A1 · 2021 [cited by applicant]
WO 2021150306A1 · 2021 [cited by applicant]
WO 2021150307A1 · 2021 [cited by applicant]
WO 2021174104A1 · 2021 [cited by applicant]
“Create a Reseller and Reseller Administrator User”, Retrieved from https://abiquo.atlassian.net/wiki/spaces/ABI54/pages/310740667/Create+a+Reseller+and+Reseller+Administrator+User, May 3, 2022, pp. 1-5. [cited by applicant]
“General Variables for All Requests”, Jun. 28, 2023, pp. 6. [cited by applicant]
“Overview of Access Approval”, Retrieved from https://cloud.google.com/assured-workloads/access-approval/docs/overview, Jun. 6, 2024, pp. 5. [cited by applicant]
“Periodic 802.1X reauthentication”, Retrieved from https://techhub.hpe.com/eginfolib/networking/docs/switches/5130ei/5200-3946_security_cg/content/485048074.htm, Retrieved from Oct. 25, 2023, p. 1. [cited by applicant]
“Policy Syntax”, Jan. 4, 2023, pp. 7. [cited by applicant]
“Reinstate admin privileges for a customer's Azure CSP subscriptions”, Retrieved from https://learn.microsoft.com/en-us/partner-center/reinstate-csp, Aug. 1, 2023, pp. 7. [cited by applicant]
“Tenant administrator settings”, Retrieved from https://backstage.forgerock.com/docs/idcloud/latest/tenants/tenant-administrator-settings.html, Jun. 7, 2023, pp. 12. [cited by applicant]
“Verbs”, Jun. 5, 2023, pp. 2. [cited by applicant]
Anonymbus: “Tokenization—(data security)”, Wikipedia, Feb. 12, 2023, pp. 1-12. [cited by applicant]
Bhat S., “Admin access management in Azure Cloud Solution Provider (CSP) subscriptions”, Retrieved from https://techcommunity.microsoft.com/t5/security-compliance-and-identity/admin-access-management-in-azure-cloud-solu… [cited by applicant]
Ducharme et al., “Seamlessly Protect Your IBM Cloud Application Infrastructure with Privileged Access Gateway”, Oct. 3, 2022, pp. 13. [cited by applicant]
George et al., “Data anonymization and integrity checking in cloud computing”, 2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 2013, pp. 5. [cited by applicant]
Ma et al., “ServiceRank: Root Cause Identification of Anomaly in Large-Scale Microservice Architectures”, : IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 5, Sep.-Oct. 2022, pp. 3087-3100. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro)Service-Based Cloud Applications: A Survey”, ACM Computing Surveys, vol. 55, No. 3, Article 59, Feb. 2022, pp. 1-39. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Security Guide for Exadata Database Service on Cloud@Customer Systems”, Apr. 1, 2023, XP093181902. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Overview of IAM”, Feb. 8, 2023, XP093184083. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Renaming a Cloud Account”, May 14, 2021, XP093185071. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Site-to-Site VPN Overview”, Feb. 8, 2023, XP093184733. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Billing and cost management overview”, Dec. 20, 2022, XP093183514. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Cloud Guard concepts”, Jan. 18, 2022, XP093183028. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Started with Policies”, Jan. 4, 2023, XP093184099. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Summary Information on the Overview Page”, Aug. 16, 2022, XP093183031. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Learn Best Practices for Set ting Up Your Tenancy”, Feb. 8, 2023, XP093184095. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Managing Compartments”, Feb. 8, 2023, XP093184098. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Monitoring Threats”, Sep. 28, 2022, XP093183035. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Overview of the Console Dashboards Service”, Mar. 14, 2023, XP093184740. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Prerequisites for Oracle Platform Services on Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093185058. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Welcome to Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093182493. [cited by applicant]
Anonymous: “Oracle Gen 2 Exadata Cloud@Customer Security Controls”, Jan. 11, 2023, XP093181973. [cited by applicant]
Anonymous: “Oracle Operator Access Control Configuration and Administration Guide”, Nov. 18, 2022, XP093181896. [cited by applicant]
Anonymous: “Oracle Public Sector Licensing and Permitting”, 2022, XP093184298. [cited by applicant]
Anonymous: “Oracle Sovereign Cloud”, Feb. 15, 2023, XP093184649. [cited by applicant]
Apps2fusion: “Security Roles in Oracle Fusion Cloud SLA”, Nov. 30, 2018, XP093184293. [cited by applicant]
Magouryrk Clay: “Announcing Oracle Alloy: The power of the cloud in your hands”, Oct. 18, 2022, XP093183485. [cited by applicant]
Q. S. Singh and Y. Liu, “A cloud service architecture for analyzing big monitoring data,” in Tsinghua Science and Technology, vol. 21, No. 1, pp. 55-70, Feb. 2016, doi: 10.1109/TST.2016.7399283 (Year: 2016). [cited by applicant]