IP Library Granted Patent US 8,769,644
Granted Patent B1
US 8,769,644 · App. 14/137,226 · Granted Jul 1, 2014

Systems and methods for establishing cloud-based instances with independent permissions

Inventors: Thorsten von Eicken (Santa Barbara, CA); Jose Maria Blanquer Gonzalez (Santa Barbara, CA); Raphael George Jacques Simon (Santa Barbara, CA)
Assignee: Rightscale, Inc.
H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,769,644
App. No.
14/137,226
Granted
Jul 1, 2014
Kind
B1
Abstract

A method and system for facilitating management of cloud-based service instances, the system including one or more computing systems configured to communicate with at least one multi-tenant computing cloud, and configured to establish a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance. The system can receive a request for the cloud-based service instance, the request authenticated as originating from a requestor; consult a set of access controls associated with the cloud-based service instance; determine, responsive to the consulting, if the request is allowable by the requestor; and enable, responsive to determining that the request is allowable by the requestor, the requestor to complete the request using a restricted access credential associated with the access entity.

Claims (58)

1. A method of facilitating management of cloud-based service instances, the method comprising:

establishing, by a cloud management service configured to communicate with a multi-tenant computing cloud, a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance;

receiving, by the cloud management service, a request for the cloud-based service instance, the request authenticated as originating from a requestor, wherein the request is a request for direct access, by the requestor, to the cloud-based service instance;

consulting, by the cloud management service, a set of access controls associated with the cloud-based service instance;

determining, by the cloud management service, responsive to the consulting, if the request is allowable by the requestor; and

enabling, by the cloud management service responsive to determining that the request is allowable by the requestor, the requestor to complete the request using an access credential associated with the access entity by returning, to the requestor, the access credential associated with the access entity.

2. The method of claim 1 , wherein establishing the cloud-based service instance comprises communicating, by the cloud management service, with the multi-tenant computing cloud, to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

3. The method of claim 1 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

4. The method of claim 1 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

5. The method of claim 1 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

6. The method of claim 1 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

7. The method of claim 1 ,

further comprising establishing, by the cloud management service, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein enabling the requestor to complete the request comprises enabling the requestor to complete the request using an access credential associated with the custom access entity.

8. The method of claim 1 , wherein establishing further comprises storing, by the cloud management service, the access credential for the access entity.

9. A method of facilitating management of cloud-based service instances, the method comprising:

establishing, by a cloud management service configured to communicate with a multi-tenant computing cloud, a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance;

receiving, by the cloud management service, a request for the cloud-based service instance, the request authenticated as originating from a requestor, wherein the request is a request to perform an action on the cloud-based service instance;

consulting, by the cloud management service, a set of access controls associated with the cloud-based service instance;

determining, by the cloud management service, responsive to the consulting, if the request is allowable by the requestor; and

enabling, by the cloud management service responsive to determining that the request is allowable by the requestor, the requestor to complete the request using an access credential associated with the access entity by forwarding the request to the multi-tenant computing cloud, with the access credential associated with the access entity.

10. The method of claim 9 , wherein establishing the cloud-based service instance comprises communicating, by the cloud management service, with the multi-tenant computing cloud, to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

11. The method of claim 9 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

12. The method of claim 9 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

13. The method of claim 9 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

14. The method of claim 9 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

15. The method of claim 9 ,

further comprising establishing, by the cloud management service, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request,

wherein enabling the requestor to complete the request comprises enabling the requestor to complete the request using an access credential associated with the custom access entity.

16. The method of claim 9 , wherein establishing further comprises storing, by the cloud management service, the access credential for the access entity.

17. A system for facilitating management of cloud-based service instances, the system comprising one or more servers including one or more hardware processors configured to communicate with at least one multi-tenant computing cloud, the one or more servers including one or more hardware processors configured to:

establish a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance;

receive a request for the cloud-based service instance, the request authenticated as originating from a requestor, wherein the request is a request for direct access, by the requestor, to the cloud-based service instance;

consult a set of access controls associated with the cloud-based service instance;

determine, responsive to the consulting, if the request is allowable by the requestor; and

enable, responsive to determining that the request is allowable by the requestor, the requestor to complete the request using a access credential associated with the access entity by returning, to the requestor, the access credential associated with the access entity.

18. The system of claim 17 , wherein the one or more servers including one or more hardware processors is further configured to establish the cloud-based service instance by communicating with the multi-tenant computing cloud to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

19. The system of claim 17 , wherein the cloud-based service instance provides one of a database, a load balancer, a message queue, a communication channel, and data storage.

20. The system of claim 17 , wherein the cloud-based service instance is a virtual service provided in the multi-tenant computing cloud.

21. The system of claim 17 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

22. The system of claim 17 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

23. The system of claim 17 ,

wherein the one or more servers including one or more hardware processors is further configured to establish, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request; and

wherein the one or more servers including one or more hardware processors is configured to enable the requestor to complete the request using an access credential associated with the custom access entity.

24. The system of claim 17 , wherein the one or more servers including one or more hardware processors is further configured to store the access credential for the access entity.

25. A system for facilitating management of cloud-based service instances, the system comprising one or more servers including one or more hardware processors configured to communicate with at least one multi-tenant computing cloud, the one or more servers including one or more hardware processors configured to:

establish a cloud-based service instance hosted in the multi-tenant computing cloud and an access entity with permissions to access the established cloud-based service instance;

receive a request for the cloud-based service instance, the request authenticated as originating from a requestor, wherein the request is a request to perform an action on the cloud-based service instance;

consult a set of access controls associated with the cloud-based service instance;

determine, responsive to the consulting, if the request is allowable by the requestor; and

enable, responsive to determining that the request is allowable by the requestor, the requestor to complete the request using an access credential associated with the access entity by forwarding the request to the multi-tenant computing cloud with the access credential associated with the access entity.

26. The system of claim 25 , wherein the one or more servers including one or more hardware processors is further configured to establish the cloud-based service instance by communicating with the multi-tenant computing cloud to create, start, instantiate, discover, identify, duplicate, import, configure, or generate, the cloud-based service instance.

27. The system of claim 25 , wherein the access entity permissions are restricted to allow access only to the established cloud service instance.

28. The system of claim 25 , wherein the cloud-based service instance is associated with a resource pool comprising one or more cloud-based service instances and the access entity permissions are restricted to only accessing cloud-based service instances in the resource pool.

29. The system of claim 25 ,

wherein the one or more servers including one or more hardware processors is further configured to establish, responsive to determining that the request is allowable by the requestor, a custom access entity with permissions sufficient to perform the request; and

wherein the one or more servers including one or more hardware processors is configured to enable the requestor to complete the request using an access credential associated with the custom access entity.

30. The system of claim 25 , wherein the one or more servers including one or more hardware processors is further configured to store the access credential for the access entity.

Assignments (8)
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS - REEL/FRAME 047719-0112 Recorded Aug 22, 2025
From: JEFFERIES FINANCE LLC
To: RIGHTSCALE, INC.
Reel/Frame 072565/0841 →
SECURITY INTEREST Recorded Aug 15, 2025
From: FLEXERA SOFTWARE LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL GENT
Reel/Frame 072460/0828 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Apr 18, 2024
From: JEFFERIES FINANCE LLC
To: BDNA CORPORATION; FLEXERA SOFTWARE LLC; PALAMIDA, INC.; RIGHTSCALE, INC.; RISC NETWORKS, LLC; REVULYTICS, INC.
Reel/Frame 067636/0534 →
SECOND LIEN SECURITY AGREEMENT Recorded Mar 3, 2021
From: BDNA CORPORATION; FLEXERA SOFTWARE LLC; PALAMIDA, INC.; RIGHTSCALE, INC.; RISC NETWORKS, LLC; REVULYTICS, INC.
To: JEFFERIES FINANCE LLC
Reel/Frame 055487/0354 →
RELEASE OF SECOND LIEN SECURITY INTEREST Recorded Feb 28, 2020
From: JEFFERIES FINANCE LLC
To: FLEXERA SOFTWARE LLC; PALAMIDA, INC.; BDNA CORPORATION; RIGHTSCALE, INC.; RISC NETWORKS, LLC
Reel/Frame 052049/0560 →
SECOND LIEN SECURITY AGREEMENT Recorded Dec 5, 2018
From: RIGHTSCALE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047720/0472 →
FIRST LIEN SECURITY AGREEMENT Recorded Dec 4, 2018
From: RIGHTSCALE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 047719/0112 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2013
From: VON EICKEN, THORSTEN; GONZALEZ, JOSE MARIA BLANQUER; SIMON, RAPHAEL GEORGE JACQUES
To: RIGHTSCALE, INC.
Reel/Frame 031854/0546 →
Continuity (1)
Provisional Application 61786948 · Mar 15, 2013