IP Library › Granted Patent US 12,615,145
Granted Patent B2
US 12,615,145 · App. 18/649,783 · Granted Apr 28, 2026

Controlling operator access to customer cloud infrastructure environments

Inventors: Nachiketh Rao Potlapally (Seattle, WA); Karl Miller (Seattle, WA); Apurv Awasthi (Woodinville, WA); Zachary Gilburd (Seattle, WA)
Assignee: Oracle International Corporation
H04L9/0891H04L63/10H04L63/102H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,145
App. No.
18/649,783
Filed
Apr 29, 2024
Granted
Apr 28, 2026
Kind
B2
Art Unit
2436
USPC
380/227
Abstract

Techniques for enabling a customer operator of a cloud service provider (CSP) the ability to disable operator access to resources in a customer cloud environment are disclosed. Operator access may be disabled or suspended by operators of the CSP customer initiating a disable command. Disabling operator access includes (a) terminating existing sessions that provide operators access to the resources, (b) rejecting new requests for credentials to establish sessions that provide operator access, and/or (c) revoking existing credentials used to establish sessions that provide operator access. Disabling operator access may apply to resources in the customer cloud environment or to a subset of resources and/or may apply to some operators but not to other operators. The operators may be of the same or different categories of operators. At the conclusion of a designated period of time, the ability of operator to access the customer cloud environment may be restored.

Claims (73)

1 . One or more non-transitory computer-readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, from a customer operator associated with a customer of a cloud service provider (CSP), a command to disable CSP operator access to a first set of resources in a customer cloud environment;

wherein the CSP operator access to the first set of resources in the customer cloud environment is permitted based on a set of permissions; and

responsive to the command, performing one or more operations that disable the CSP operator access to the first set of resources, comprising one or more of:

terminating one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more existing sessions were established based at least in part on the set of permissions;

rejecting one or more new requests for credentials to establish sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more new requests for credentials are made based at least in part on the set of permissions; or

revoking existing credentials used to establish the one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the existing credentials were granted based at least in part on the set of permissions;

wherein the command to disable the CSP operator access to the first set of resources in the customer cloud environment is associated with a designated time period; and

responsive to detecting a conclusion of the designated time period, reversing the one or more operations that disable the CSP operator access to the first set of resources.

2 . The one or more non-transitory computer-readable media of claim 1 , wherein terminating the one or more existing sessions is performed by a bastion service configured to provision a set of bastion instances through which the one or more existing sessions are established, wherein the bastion service records information associated with the one or more existing sessions to generate recorded information, the recorded information including at least one of:

(a) if a requestor of the one or more existing sessions is a CSP operator, or

(b) if the one or more existing sessions is a connection into the customer cloud environment;

wherein the bastion service identifies the one or more existing sessions to be terminated based on the recorded information;

wherein the bastion service terminates the one or more existing sessions identified by the bastion service.

3 . The one or more non-transitory computer-readable media of claim 1 , wherein rejecting the one or more new requests for credentials is performed by a permissions service configured to manage the set of permissions.

4 . The one or more non-transitory computer-readable media of claim 1 , wherein revoking the existing credentials is performed by a permissions service configured to manage the set of permissions.

5 . The one or more non-transitory computer-readable media of claim 1 , wherein the command requests to disable the CSP operator access to all resources in the customer cloud environment, and one or more of the following is performed:

(a) terminating all existing sessions;

(b) rejecting all new requests for credentials; or

(c) revoking all existing credentials.

6 . The one or more non-transitory computer-readable media of claim 1 , wherein the command requests to disable the CSP operator access to a subset of resources in the customer cloud environment, and one or more of the following is performed:

(a) terminating a subset of existing sessions corresponding to the subset of resources;

(b) rejecting a subset of new requests for credentials corresponding to the subset of resources; or

(c) revoking a subset of existing credentials corresponding to the subset of resources.

7 . The one or more non-transitory computer-readable media of claim 1 , the operations further comprising: reversing one or more of:

(a) terminating the one or more existing sessions;

(b) rejecting the one or more new requests for credentials; or

(c) revoking the existing credentials.

8 . The one or more non-transitory computer-readable media of claim 1 , wherein the command sets a flag in a database accessible by one or more of (a) a bastion service configured to provision a set of bastion instances through which the one or more existing sessions are established or (b) a permissions service configured to manage the set of permissions.

9 . The one or more non-transitory computer-readable media of claim 1 , wherein terminating the CSP operator access to the first set of resources does not terminate the CSP operator access to a second set of resources in the customer cloud environment.

10 . The one or more non-transitory computer-readable media of claim 1 , wherein terminating the CSP operator access applies to a first CSP operator and does not terminate access for a second CSP operator.

11 . The one or more non-transitory computer-readable media of claim 1 , wherein the CSP is a first entity, the customer of the CSP is a second entity, and the customer of the CSP provides cloud services to an end user associated with a third entity.

12 . The one or more non-transitory computer-readable media of claim 1 , wherein the command to disable the CSP operator access is an application programming interface call made in response to user input supplied by the customer operator.

13 . A method comprising:

receiving, from a customer operator associated with a customer of a cloud service provider (CSP), a command to disable CSP operator access to a first set of resources in a customer cloud environment;

wherein the CSP operator access to the first set of resources in the customer cloud environment is permitted based on a set of permissions; and

responsive to the command, performing one or more operations that disable the CSP operator access to the first set of resources, comprising one or more of:

terminating one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more existing sessions were established based at least in part on the set of permissions;

rejecting one or more new requests for credentials to establish sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more new requests for credentials are made based at least in part on the set of permissions; or

revoking existing credentials used to establish the one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the existing credentials were granted based at least in part on the set of permissions;

wherein the command to disable the CSP operator access to the first set of resources in the customer cloud environment is associated with a designated time period; and

responsive to detecting a conclusion of the designated time period, reversing the one or more operations that disable the CSP operator access to the first set of resources;

wherein the method is performed by at least one device including a hardware processor.

14 . The method of claim 13 , wherein terminating the one or more existing sessions is performed by a bastion service configured to provision a set of bastion instances through which the one or more existing sessions are established, wherein the bastion service records information associated with the one or more existing sessions to generate recorded information, the recorded information including at least one of:

(a) if a requestor of the one or more existing sessions is a CSP operator, or

(b) if the one or more existing sessions is a connection into the customer cloud environment;

wherein the bastion service identifies the one or more existing sessions to be terminated based on the recorded information;

wherein the bastion service terminates the one or more existing sessions identified by the bastion service.

15 . The method of claim 13 , wherein rejecting the one or more new requests for credentials is performed by a permissions service configured to manage the set of permissions.

16 . The method of claim 13 , wherein revoking the existing credentials is performed by a permissions service configured to manage the set of permissions.

17 . The method of claim 13 , wherein the command requests to disable the CSP operator access to all resources in the customer cloud environment, and one or more of the following is performed:

(a) terminating all existing sessions;

(b) rejecting all new requests for credentials; or

(c) revoking all existing credentials.

18 . The method of claim 13 , wherein the command requests to disable the CSP operator access to a subset of resources in the customer cloud environment, and one or more of the following is performed:

(a) terminating a subset of existing sessions corresponding to the subset of resources;

(b) rejecting a subset of new requests for credentials corresponding to the subset of resources; or

(c) revoking a subset of existing credentials corresponding to the subset of resources.

19 . The method of claim 13 , further comprising: subsequent to a conclusion of the designated time period, reversing one or more of:

(a) terminating the one or more existing sessions;

(b) rejecting the one or more new requests for credentials; or

(c) revoking the existing credentials.

20 . A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

receiving, from a customer operator associated with a customer of a cloud service provider (CSP), a command to disable CSP operator access to a first set of resources in a customer cloud environment;

wherein the CSP operator access to the first set of resources in the customer cloud environment is permitted based on a set of permissions; and

responsive to the command, performing one or more operations that disable the CSP operator access to the first set of resources, comprising one or more of:

terminating one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more existing sessions were established based at least in part on the set of permissions;

rejecting one or more new requests for credentials to establish sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more new requests for credentials are made based at least in part on the set of permissions; or

revoking existing credentials used to establish the one or more existing sessions that provide the CSP operator access to the first set of resources in the customer cloud environment, wherein the existing credentials were granted based at least in part on the set of permissions;

wherein the command to disable the CSP operator access to the first set of resources in the customer cloud environment is associated with a designated time period; and

responsive to detecting a conclusion of the designated time period, reversing the one or more operations that disable the CSP operator access to the first set of resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2024
From: POTLAPALLY, NACHIKETH RAO; MILLER, KARL; AWASTHI, APURV; GILBURD, ZACHARY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 067279/0441 →
Continuity (2)
Provisional Application 63462880 · Apr 28, 2023
Related Publication 20240364509A1 · Oct 31, 2024
References Cited (101)
US 9092502B1 · Cannaliato et al. · 2015 [cited by applicant]
US 9306814B1 · Roth et al. · 2016 [cited by applicant]
US 9438599B1 · Yuhan · 2016 [cited by examiner]
US 9722895B1 · Sarukkai et al. · 2017 [cited by applicant]
US 9985947B1 · Elhard · 2018 [cited by applicant]
US 10757574B1 · Rule et al. · 2020 [cited by applicant]
US 10878483B1 · Felbinger et al. · 2020 [cited by applicant]
US 11552953B1 · Avadhanam · 2023 [cited by applicant]
US 11720536B1 · Kisser et al. · 2023 [cited by applicant]
US 20020198973A1 · Besaw · 2002 [cited by applicant]
US 20030154407A1 · Kato et al. · 2003 [cited by applicant]
US 20100212004A1 · Fu · 2010 [cited by applicant]
US 20110055399A1 · Tung · 2011 [cited by examiner]
US 20130054426A1 · Rowland · 2013 [cited by examiner]
US 20130297711A1 · Nhu · 2013 [cited by applicant]
US 20130304925A1 · Ferris et al. · 2013 [cited by applicant]
US 20140280595A1 · Mani et al. · 2014 [cited by applicant]
US 20150363852A1 · Vautour · 2015 [cited by applicant]
US 20160043909A1 · Pogrebinsky et al. · 2016 [cited by applicant]
US 20160142211A1 · Metke et al. · 2016 [cited by applicant]
US 20160277411A1 · Dani · 2016 [cited by examiner]
US 20170230229A1 · Sasturkar et al. · 2017 [cited by applicant]
US 20180052861A1 · Seetharaman et al. · 2018 [cited by applicant]
US 20180219784A1 · Jiang et al. · 2018 [cited by applicant]
US 20180234256A1 · Bowen · 2018 [cited by applicant]
US 20190087835A1 · Schwed · 2019 [cited by examiner]
US 20190156000A1 · Hoffmann et al. · 2019 [cited by applicant]
US 20190166007A1 · Sundaram et al. · 2019 [cited by applicant]
US 20190205045A1 · Hugot et al. · 2019 [cited by applicant]
US 20190213104A1 · Qadri · 2019 [cited by examiner]
US 20200014659A1 · Chasman et al. · 2020 [cited by applicant]
US 20200112497A1 · Yenumulapalli et al. · 2020 [cited by applicant]
US 20200117757A1 · Yanamandra et al. · 2020 [cited by applicant]
US 20200358756A1 · Rose et al. · 2020 [cited by applicant]
US 20210216190A1 · Vakil et al. · 2021 [cited by applicant]
US 20210234864A1 · Dube et al. · 2021 [cited by applicant]
US 20210273914A1 · Cobb · 2021 [cited by applicant]
US 20210279109A1 · Ji et al. · 2021 [cited by applicant]
US 20210377272A1 · Dasari · 2021 [cited by examiner]
US 20210392142A1 · Stephens et al. · 2021 [cited by applicant]
US 20220091947A1 · Kothari et al. · 2022 [cited by applicant]
US 20220103618A1 · Pinheiro et al. · 2022 [cited by applicant]
US 20220150124A1 · Cooley et al. · 2022 [cited by applicant]
US 20220255902A1 · Woodson · 2022 [cited by applicant]
US 20220294818A1 · Parekh et al. · 2022 [cited by applicant]
US 20220335340A1 · Moustafa et al. · 2022 [cited by applicant]
US 20220374271A1 · Pogrebinsky et al. · 2022 [cited by applicant]
US 20230109926A1 · Nair et al. · 2023 [cited by applicant]
US 20230132478A1 · Robinson et al. · 2023 [cited by applicant]
US 20230316348A1 · Dageville et al. · 2023 [cited by applicant]
US 20230342179A1 · Suttle et al. · 2023 [cited by applicant]
US 20230362161A1 · Spector et al. · 2023 [cited by applicant]
US 20230385286A1 · Glickman et al. · 2023 [cited by applicant]
US 20240054063A1 · Wichelman et al. · 2024 [cited by applicant]
US 20240095739A1 · Adogla et al. · 2024 [cited by applicant]
US 20240320240A1 · Podder · 2024 [cited by applicant]
EP 2893685B1 · 2017 [cited by applicant]
EP 3429156A1 · 2019 [cited by applicant]
EP 3271857B1 · 2020 [cited by applicant]
WO 2014039921A1 · 2014 [cited by applicant]
WO 2018010791A1 · 2018 [cited by applicant]
WO 2021145894A1 · 2021 [cited by applicant]
WO 2021150306A1 · 2021 [cited by applicant]
WO 2021150307A1 · 2021 [cited by applicant]
WO 2021174104A1 · 2021 [cited by applicant]
F. John Krautheim ; Private Virtual Infrastructure for Cloud Computing; USENIX:2009; pp. 1-5. [cited by examiner]
“Create a Reseller and Reseller Administrator User”, Retrieved from https://abiquo.atlassian.net/wiki/spaces/ABI54/pages/310740667/Create+a+Reseller+and+Reseller+Administrator+User, May 3, 2022, pp. 1-5. [cited by applicant]
“General Variables for All Requests”, Jun. 28, 2023, pp. 6. [cited by applicant]
“Overview of Access Approval”, Retrieved from https://cloud.google.com/assured-workloads/access-approval/docs/overview, Jun. 6, 2024, pp. 5. [cited by applicant]
“Periodic 802.1X reauthentication”, Retrieved from https://techhub.hpe.com/eginfolib/networking/docs/switches/5130ei/5200-3946_security_cg/content/485048074.htm, Retrieved from Oct. 25, 2023, p. 1. [cited by applicant]
“Policy Syntax”, Jan. 4, 2023, pp. 7. [cited by applicant]
“Reinstate admin privileges for a customer's Azure CSP subscriptions”, Retrieved from https://learn.microsoft.com/en-us/partner-center/reinstate-csp, Aug. 1, 2023, pp. 7. [cited by applicant]
“Tenant administrator settings”, Retrieved from https://backstage.forgerock.com/docs/idcloud/latest/tenants/tenant-administrator-settings.html, Jun. 7, 2023, pp. 12. [cited by applicant]
“Verbs”, Jun. 5, 2023, pp. 2. [cited by applicant]
Anonymbus: “Tokenization—(data security)”, Wikipedia, Feb. 12, 2023, pp. 1-12. [cited by applicant]
Bhat S., “Admin access management in Azure Cloud Solution Provider (CSP) subscriptions”, Retrieved from https://techcommunity.microsoft.com/t5/security-compliance-and-identity/admin-access-management-in-azure-cloud-solu… [cited by applicant]
Ducharme et al., “Seamlessly Protect Your IBM Cloud Application Infrastructure with Privileged Access Gateway”, Oct. 3, 2022, pp. 13. [cited by applicant]
George et al., “Data anonymization and integrity checking in cloud computing”, 2013 Fourth International Conference on Computing, Communications and Networking Technologies (ICCCNT), Jul. 2013, pp. 5. [cited by applicant]
Ma et al., “ServiceRank: Root Cause Identification of Anomaly in Large-Scale Microservice Architectures”, : IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 5, Sep.-Oct. 2022, pp. 3087-3100. [cited by applicant]
Soldani et al., “Anomaly Detection and Failure Root Cause Analysis in (Micro)Service-Based Cloud Applications: A Survey”, ACM Computing Surveys, vol. 55, No. 3, Article 59, Feb. 2022, pp. 1-39. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Security Guide for Exadata Database Service on Cloud@Customer Systems”, Apr. 1, 2023, XP093181902. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation-Overview of IAM”, Feb. 8, 2023, XP093184083. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Renaming a Cloud Account”, May 14, 2021, XP093185071. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Site-to-Site VPN Overview”, Feb. 8, 2023, XP093184733. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Billing and cost management overview”, Dec. 20, 2022, XP093183514. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Cloud Guard concepts”, Jan. 18, 2022, XP093183028. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Started with Policies”, Jan. 4, 2023, XP093184099. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Getting Summary Information on the Overview Page”, Aug. 16, 2022, XP093183031. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Learn Best Practices for Setting Up Your Tenancy”, Feb. 8, 2023, XP093184095. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Managing Compartments”, Feb. 8, 2023, XP093184098. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Monitoring Threats”, Sep. 28, 2022, XP093183035. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Overview of the Console Dashboards Service”, Mar. 14, 2023, XP093184740. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Prerequisites for Oracle Platform Services on Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093185058. [cited by applicant]
Anonymous: “Oracle Cloud Infrastructure Documentation—Welcome to Oracle Cloud Infrastructure”, Mar. 23, 2023, XP093182493. [cited by applicant]
Anonymous: “Oracle Gen 2 Exadata Cloud@Customer Security Controls”, Jan. 11, 2023, XP093181973. [cited by applicant]
Anonymous: “Oracle Operator Access Control Configuration and Administration Guide”, Nov. 18, 2022, XP093181896. [cited by applicant]
Anonymous: “Oracle Public Sector Licensing and Permitting”, 2022, XP093184298. [cited by applicant]
Anonymous: “Oracle Sovereign Cloud”, Feb. 15, 2023, XP093184649. [cited by applicant]
AppsZfusion: “Security Roles in Oracle Fusion Cloud SLA”, Nov. 30, 2018, XP093184293. [cited by applicant]
Magouryrk Clay: “Announcing Oracle Alloy: The power ofthe cloud in your hands”, Oct. 18, 2022, XP093183485. [cited by applicant]
Q. S. Singh and Y. Liu, “A cloud service architecture for analyzing big monitoring data,” in Tsinghua Science and Technology, vol. 21, No. 1, pp. 55-70, Feb. 2016, doi: 10.1109/TST.2016.7399283 (Year: 2016). [cited by applicant]