Controlling Operator Access To Customer Cloud Infrastructure Environments

US2024364509A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2024364509-A1
Application numberUS-202418649783-A
CountryUS
Kind codeA1
Filing dateApr 29, 2024
Priority dateApr 28, 2023
Publication dateOct 31, 2024
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Techniques for enabling a customer operator of a cloud service provider (CSP) the ability to disable operator access to resources in a customer cloud environment are disclosed. Operator access may be disabled or suspended by operators of the CSP customer initiating a disable command. Disabling operator access includes (a) terminating existing sessions that provide operators access to the resources, (b) rejecting new requests for credentials to establish sessions that provide operator access, and/or (c) revoking existing credentials used to establish sessions that provide operator access. Disabling operator access may apply to resources in the customer cloud environment or to a subset of resources and/or may apply to some operators but not to other operators. The operators may be of the same or different categories of operators. At the conclusion of a designated period of time, the ability of operator to access the customer cloud environment may be restored.

First claim

Opening claim text (preview).

What is claimed is: 1 . One or more non-transitory computer-readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising: receiving, from a customer operator associated with a customer of a cloud service provider (CSP), a command to disable CSP operator access to a first set of resources in a customer cloud environment; wherein CSP operator access to the first set of resources in the customer cloud environment is permitted based on a set of permissions; and responsive to the command, performing one or more of: terminating one or more existing sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more existing sessions were established based at least in part on the set of permissions; rejecting one or more new requests for credentials to establish sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein the new requests for credentials are made based at least in part on the set of permissions; or revoking existing credentials used to establish sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein existing credentials were granted based at least in part on the set of permissions. 2 . The one or more non-transitory computer-readable media of claim 1 : wherein terminating the existing sessions is performed by a bastion service configured to provision a set of bastion instances through which the existing sessions are established, wherein the bastion service records information associated with the existing sessions to generate recorded information, the recorded information including at least one of: (a) if the requestor of the session is a CSP operator, or (b) if the session is a connection into the customer cloud environment; wherein the bastion service identifies the existing sessions to be terminated based on the recorded information; wherein the bastion service terminates the identified sessions. 3 . The one or more non-transitory computer-readable media of claim 1 , wherein rejecting the one or more new requests for credentials is performed by a permissions service configured to manage the set of permissions. 4 . The one or more non-transitory computer-readable media of claim 1 , wherein revoking the existing credentials is performed by a permissions service configured to manage the set of permissions. 5 . The one or more non-transitory computer-readable media of claim 1 , wherein the command requests to disable CSP operator access to all resources in the customer cloud environment, and one or more of the following is performed: (a) terminating all existing sessions; (b) rejecting all new requests for credentials; or (c) revoking all existing credentials. 6 . The one or more non-transitory computer-readable media of claim 1 , wherein the command requests to disable CSP operator access to a subset of resources in the customer cloud environment, and one or more of the following is performed: (a) terminating a subset of existing sessions corresponding to the subset of resources; (b) rejecting a subset of new requests for credentials corresponding to the subset of resources; or (c) revoking a subset of existing credentials corresponding to the subset of resources. 7 . The one or more non-transitory computer-readable media of claim 1 , wherein the command is associated with a designated time period, the operations further comprising: subsequent to conclusion of the designated time period, reversing one or more of: (a) terminating the existing sessions; (b) rejecting the new requests for credentials; or (c) revoking the existing credentials. 8 . The one or more non-transitory computer-readable media of claim 1 , wherein the command sets a flag in a database accessible by one or more of (a) a bastion service configured to provision a set of bastion instances through which the existing sessions are established or (b) a permissions service configured to manage the set of permissions. 9 . The one or more non-transitory computer-readable media of claim 1 , wherein terminating CSP operator access to the first set of resources does not terminate CSP operator access to a second set of resources in the customer cloud environment. 10 . The one or more non-transitory computer-readable media of claim 1 , wherein terminating CSP operator access applies to a first CSP operator and does not terminate access for a second CSP operator. 11 . The one or more non-transitory computer-readable media of claim 1 , wherein the CSP is a first entity, the customer of the CSP is a second entity, and the customer of the CSP provides cloud services to an end user associated with a third entity. 12 . The one or more non-transitory computer-readable media of claim 1 , wherein the command to disable access of the CSP operator is an application programming interface call made in response to user input supplied by the customer operator. 13 . A method comprising: receiving, from a customer operator associated with a customer of a cloud service provider (CSP), a command to disable CSP operator access to a first set of resources in a customer cloud environment; wherein CSP operator access to the first set of resources in the customer cloud environment is permitted based on a set of permissions; and responsive to the command, performing one or more of: terminating one or more existing sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein the one or more existing sessions were established based at least in part on the set of permissions; rejecting one or more new requests for credentials to establish sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein the new requests for credentials are made based at least in part on the set of permissions; or revoking existing credentials used to establish sessions that provide CSP operator access to the first set of resources in the customer cloud environment, wherein the existing credentials were granted based at least in part on the set of permissions, wherein the method is performed by at least one device including a hardware processor. 14 . The method of claim 13 : wherein terminating the existing sessions is performed by a bastion service configured to provision a set of bastion instances through which the existing sessions are established, wherein the bastion service records information associated with the existing sessions to generate recorded information, the recorded information including at least one of: (c) if a requestor of the session is a CSP operator, or (d) if the session is a connection into the customer cloud environment; wherein the bastion service identifies the existing sessions to be terminated based on the recorded information; wherein the bastion service terminates the identified sessions. 15 . The method of claim 13 , wherein rejecting the one or more new requests for credentials is performed by a permissions service configured to manage the set of permissions. 16 . The method of claim 13 , wherein revoking the existing credentials is performed by a permissions service configured to manage the set of permissions. 17 . The method of claim 13 , wherein the command requests to disable CSP operator access to all resources in the customer cloud environment, and one or more of the following is performe

Assignees

Inventors

Classifications

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • Virtual private networks · CPC title

  • in which an application is distributed across nodes in the network (software deployment G06F8/60; multiprogramming arrangements G06F9/46) · CPC title

  • H04L9/0891Primary

    Revocation or update of secret information, e.g. encryption key update or rekeying · CPC title

  • Entity profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2024364509A1 cover?
Techniques for enabling a customer operator of a cloud service provider (CSP) the ability to disable operator access to resources in a customer cloud environment are disclosed. Operator access may be disabled or suspended by operators of the CSP customer initiating a disable command. Disabling operator access includes (a) terminating existing sessions that provide operators access to the resour…
Who is the assignee on this patent?
Oracle Int Corp
What technology area does this patent fall under?
Primary CPC classification H04L9/0891. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Oct 31 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).