US 11,706,260 B2
Security zone policy enforcement in a cloud infrastructure system
Igor Dozorets, Sammamish, WA (US); Thoulfekar Alrahem, Bellevue, WA (US); Jun Tong, Bellevue, WA (US); Leonid Kuperman, Toronto (CA); Nachiketh Rao Potlapally, McLean, VA (US); Bala Ganesh Chandran, Seattle, WA (US); Brian Pratt, Seattle, WA (US); Nathaniel Martin Glass, Bellevue, WA (US); Girish Nagaraja, Sammamish, WA (US); and Jonathan Jorge Nadal, Seattle, WA (US)
Assigned to ORACLE INTERNATIONAL CORPORATION, Redwood Shores, CA (US)
Filed by Oracle International Corporation, Redwood Shores, CA (US)
Filed on Aug. 3, 2021, as Appl. No. 17/393,347.
Claims priority of provisional application 63/068,943, filed on Aug. 21, 2020.
Claims priority of provisional application 63/068,945, filed on Aug. 21, 2020.
Prior Publication US 2022/0060517 A1, Feb. 24, 2022
Int. Cl. H04L 9/40 (2022.01); H04L 67/10 (2022.01)
CPC H04L 63/205 (2013.01) [H04L 63/10 (2013.01); H04L 63/102 (2013.01); H04L 63/107 (2013.01); H04L 63/20 (2013.01); H04L 67/10 (2013.01)] 21 Claims
OG exemplary drawing
 
1. A method comprising:
receiving, by a security zone policy enforcement system in a cloud service provider infrastructure, a request to perform an operation on a resource;
determining, by the security zone policy enforcement system, a compartment associated with the resource, the compartment associated with a set of one or more compartment policies;
determining, by the security zone policy enforcement system, that the operation on the resource is permitted based on the set of one or more compartment policies;
responsive to determining that the operation on the resource is permitted based on the set of one or more compartment policies, determining, by the security zone policy enforcement system, that the compartment is associated with a security zone, the security zone associated with one or more security zone policies;
determining, by the security zone policy enforcement system, whether the operation on the resource is permitted or not based on the set of one or more security zone policies; and
disallowing, by the security zone policy enforcement system, the operation to be performed on the resource upon determining that the operation on the resource is not permitted based on the set of one or more security zone policies.