Invention Grant
- Patent Title: Access control for long-lived resource principals
-
Application No.: US17198024Application Date: 2021-03-10
-
Publication No.: US11418343B2Publication Date: 2022-08-16
- Inventor: Ayman Mohammed Aly Hassan Elmenshawy , Girish Nagaraja , Daniel M. Vogel
- Applicant: Oracle International Corporation
- Applicant Address: US CA Redwood Shores
- Assignee: Oracle International Corporation
- Current Assignee: Oracle International Corporation
- Current Assignee Address: US CA Redwood Shores
- Agency: Kilpatrick Townsend & Stockton LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32 ; H04L9/30

Abstract:
Techniques are described for enabling resources within a cloud computing system to interact with each other. In certain embodiments, a token renewal mechanism is provided for extending the duration in which a first resource can access another resource. The token renewal mechanism can involve the first resource periodically causing a new credential to be generated for itself and then communicating the new credential to an identity and access management (IAM) system. The new credential may be generated for compliance with a credential rotation policy specifying that credentials should be changed after a certain period of time. The IAM system may associate a digital access token with the new credential so that for subsequent requests, the IAM system will only recognize the resource principal based upon the new credential. The digital token can be invalidated if a new credential is not changed within the specified period of time.
Public/Granted literature
- US20210409219A1 ACCESS CONTROL FOR LONG-LIVED RESOURCE PRINCIPALS Public/Granted day:2021-12-30
Information query