COMPARTMENT LEVEL BINDING FOR WORKLOAD IDENTITY

    公开(公告)号:US20250030680A1

    公开(公告)日:2025-01-23

    申请号:US18422812

    申请日:2024-01-25

    Abstract: Techniques are described for mapping a namespace to a compartment. An example method includes receiving, by a manager instance and from a pod, a first request for a token. The manager instance can transmit, to a token issuance service, a second request for the token. The token issuance service can identify a mapping object that maps the namespace to the resource. The token issuance service can transmit, to an identity service, the mapping object and a third request for the token. The identity service can identify a compartment of the customer tenancy based at least in part on the compartment identifier, the compartment managing the resource. The identity service can determine whether the pod has permission to access the resource. The identity service can generate the token based at least in part on the mapping object and the policy. The identity service can transmit the token to the pod.

    PROVISIONING CLOUD RESOURCE INSTANCES ASSOCIATED WITH A VIRTUAL CLOUD NETWORK

    公开(公告)号:US20250030676A1

    公开(公告)日:2025-01-23

    申请号:US18353991

    申请日:2023-07-18

    Abstract: Techniques for provisioning a cloud resource instance associated with a virtual cloud network may include detecting a certificate bundle-retrieval trigger during a provisioning process for the cloud resource instance, and responsive to detecting the certificate bundle-retrieval trigger, sending, to an agent executing on a network interface linked to the cloud resource instance, a request for a certificate bundle for the cloud resource instance. Techniques may further include receiving the certificate bundle from the network interface. The certificate bundle may include a set of certificate authority (CA) certificates. Techniques may further include installing the certificate bundle in a storage medium associated with the cloud resource instance. Installing the certificate bundle may represent an operation of the provisioning process.

    REPLICATION OF CUSTOMER KEYS STORED IN A VIRTUAL VAULT

    公开(公告)号:US20250030542A1

    公开(公告)日:2025-01-23

    申请号:US18778722

    申请日:2024-07-19

    Abstract: Techniques are described for replicating encryption keys using a write ahead log (WAL). An example method can include receiving a request from a user device to transmit encryption keys stored in a first virtual vault of a first hardware security module (HSM) of a first data center to a second virtual vault of a second HSM of a second data center, the request comprising an account identifier. The method can further include identifying a first account-specific WAL of a plurality of account-specific WALs based at least in part on the account identifier, each account-specific WAL corresponding to the first HSM, and configured to record changes to a respective virtual vault of the plurality of virtual vaults. The method can further include accessing the encryption keys from the first account-specific WAL of the first HSM. The method can further include transmitting the encryption keys to the second data center.

    Information technology service incident ticket assignment

    公开(公告)号:US12205009B2

    公开(公告)日:2025-01-21

    申请号:US17106353

    申请日:2020-11-30

    Abstract: Embodiments assign an information technology service ticket to a queue and a sub-queue for optimized servicing. Embodiments extract from the service ticket a summary of the service ticket and a description of the service ticket. Embodiments provide as input to a trained neural network model the summary and description, the trained neural network model including a coarse network and a fine network. Embodiments predict the queue using the coarse network and predict the sub-queue using the fine network. Embodiments determine an uncertainty loss for the neural network model and when the uncertainty loss is below a threshold, assign the service ticket to the predicted queue and sub-queue.

    Multi-cloud infrastructure-database adaptor

    公开(公告)号:US12204955B2

    公开(公告)日:2025-01-21

    申请号:US18162939

    申请日:2023-02-01

    Abstract: Techniques are described for providing, in a first cloud infrastructure (FCI), an adaptor associated with a service provided by the FCI. The adaptor enables the service to be requested by one or more users associated with one or more accounts in a second cloud infrastructure (SCI), where the SCI is different than the FCI. The adaptor receives a first request from a first user associated with a first account in the SCI to create a resource in the FCI. The adaptor executes a workflow to provision the resource using the service, where the workflow includes processing comprising retrieving a resource-principal that is associated with the resource and transmitting a second request to the service provided by the FCI. The second request includes the resource-principal and corresponds to creation of the resource.

    Partitioning documents for contextual search

    公开(公告)号:US12204574B2

    公开(公告)日:2025-01-21

    申请号:US18634293

    申请日:2024-04-12

    Abstract: Operations of a search management system are disclosed. The operations may include: identifying a data corpus containing a plurality of documents, generating sets of feature vectors representing the plurality of documents, receiving a query to search the data corpus, generating a query vector for the query, identifying a target feature vector that meets a similarity threshold by comparing the query vector to the feature vectors, and presenting a query result that includes at least part of the document. The feature vectors may be generated by executing a multi-step partitioning process for partitioning a respective document into a plurality of document partitions, such that the sets of feature vectors that are generated correspond to the plurality of document partitions for the respective document. The query result may include a target partition from among the plurality of document partitions represented by the target feature vector.

    Incremental stack walking
    100.
    发明授权

    公开(公告)号:US12204436B2

    公开(公告)日:2025-01-21

    申请号:US18111423

    申请日:2023-02-17

    Abstract: Techniques for incremental stack walking are disclosed, including: performing a stack walk of a runtime stack, at least by traversing the runtime stack from a current frame to a root frame, to obtain a set of stack walking results; storing a cache of the set of stack walking results; and installing, on the runtime stack, a marker frame that marks a boundary of stack frames represented by the set of stack walking results.

Patent Agency Ranking