Patents by Inventor Hari Sastry
Hari Sastry has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 10791087Abstract: A method for mapping SCIM resources to LDAP entries is provided. An LDAP Directory Information Tree (DIT), including a plurality of LDAP DIT entries that describe LDAP containers, users and groups, is provided. Each LDAP DIT entry includes a Distinguished Name and a plurality of LDAP attribute-value pairs, each of which include an attribute name and one or more attribute values. A SCIM directory, including a plurality of SCIM resource entries, is also provided. Each SCIM resource entry includes a plurality of SCIM attributes, each of which includes a name and one or more values. The plurality of SCIM resource entries are converted to corresponding LDAP DIT entries, and, for each SCIM resource entry that has a SCIM CMVA, the SCIM CMVA is mapped to a plurality of LDAP attributes in the corresponding LDAP DIT entry using LDAP attribute subtypes.Type: GrantFiled: September 15, 2017Date of Patent: September 29, 2020Assignee: Oracle International CorporationInventors: Venkateswara Reddy Medam, Hari Sastry, Xiaoxiao Xu, Michael Ray Frost
-
Patent number: 10567364Abstract: A method for hierarchically processing Lightweight Directory Access Protocol (LDAP) operations against a System for Cross-domain Identity Management (SCIM) directory is provided. The method includes providing an LDAP Directory Information Tree (DIT) including a plurality of LDAP DIT entries that describe LDAP containers, users and groups, providing a SCIM directory including a plurality of SCIM resource entries that describe SCIM users and groups, migrating the plurality of LDAP DIT entries to the SCIM directory including storing the LDAP DIT hierarchical information in the SCIM directory by mapping LDAP containers in the LDAP DIT to special marker SCIM groups in the SCIM directory, receiving, from an LDAP-based application over a network, an LDAP operation request, processing the LDAP operation request, and returning an LDAP operation response to the LDAP-based application over the network.Type: GrantFiled: September 15, 2017Date of Patent: February 18, 2020Assignee: Oracle International CorporationInventors: Kanika Vats, Hari Sastry
-
Patent number: 10530578Abstract: A key store microservice is provided for a cloud based identity management system. The key store microservice receives, over a network, a request from a client application to retrieve a key, the request including a tenancy identifier, and determines whether the key is present in a tenant specific memory cache associated with the tenancy identifier. When the key is determined to be present in the tenant specific memory cache, the key store microservice retrieves the key from the tenant specific memory cache, retrieves a decryption key from a key wallet, decrypts the key retrieved from the tenant specific memory cache using the decryption key retrieved from the key wallet, and sends, over the network, the key to the client.Type: GrantFiled: May 30, 2017Date of Patent: January 7, 2020Assignee: Oracle International CorporationInventors: Rakesh Keshava, Sreedhar Katti, Sirish Vepa, Hari Sastry
-
Patent number: 10505941Abstract: A method for providing an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service is provided. The method includes providing an LDAP Directory Information Tree (DIT) including LDAP DIT entries, providing a SCIM directory including SCIM resource entries, migrating the LDAP DIT entries to the SCIM directory, creating a virtual LDAP hierarchy based on LDAP DIT hierarchical information stored in the SCIM directory, and displaying a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy. Creating the virtual LDAP hierarchy includes storing the LDAP DIT hierarchical information in the SCIM directory by mapping LDAP containers to SCIM user or SCIM group attributes, mapping LDAP containers to special marker SCIM groups, mapping LDAP user DNs to SCIM user externalIDs, or mapping LDAP group DNs to SCIM group externalIDs.Type: GrantFiled: July 31, 2017Date of Patent: December 10, 2019Assignee: Oracle International CorporationInventors: Kanika Vats, Vinoth Janakiraman, Manohari Neelakanteshwar, Rajesh Purushothaman, Loganathan Ramasamy, Anand Murugesan, Hari Sastry
-
Patent number: 10454940Abstract: A system for authorizing access to a resource receives a request for an access token that corresponds to the resource, where the request includes user information and application information. The user information includes a role of the user and the application information includes a role of the application. The system evaluates the request by computing scopes for the access token, including determining an intersection between the user information and the application information. The system then provides the access token that includes the computed scopes, the scopes being based at least on the role of the user and the role of the application.Type: GrantFiled: March 30, 2017Date of Patent: October 22, 2019Assignee: Oracle International CorporationInventors: Vadim Lander, Hari Sastry, Sreedhar Katti, Sirish V. Vepa, Swathi Vinayak Shenoy
-
Patent number: 10230732Abstract: A global policy store, in which policies applicable to multiple applications in an enterprise environment can be stored, can be stored in association with that environment. An application-level policy combining algorithm can be associated with a specific application to resolve conflicts between the results of evaluating policies that pertain to that application's resources. A persistent model is defined for an Extensible Access Control Markup Language (XACML) target definition.Type: GrantFiled: September 28, 2016Date of Patent: March 12, 2019Assignee: Oracle International CorporationInventors: Sirish V. Vepa, Hari Sastry, Alan Cao, Cynthia Ding
-
Patent number: 10142371Abstract: Application customization enables many different types of customers, from small companies to large multinational enterprises, to use various applications provided by a cloud service provider. To accommodate these customizations, previous systems generally require manual human intervention to identify custom, customized, and cloud service provider authorization policies (also referred to herein as “seed” authorization policies) and to decide how each type of authorization policy should be upgraded. When applications are customized, artifacts that represent those customizations can be created. In some embodiments, the customizations can include new resources or entitlements, and grants to new roles. In addition to new resources, entitlements, and grants, existing resources, entitlements, and grants can be modified and artifacts corresponding to those modifications can be generated.Type: GrantFiled: December 18, 2015Date of Patent: November 27, 2018Assignee: ORACLE INTERNATIONAL CORPORATIONInventors: Hari Sastry, Krishnakumar Sriramadhesikan, Vineet Garg, Sirish V. Vepa, Srivatsa Manjunath, Yi Wang
-
Publication number: 20180083944Abstract: A method for hierarchically processing Lightweight Directory Access Protocol (LDAP) operations against a System for Cross-domain Identity Management (SCIM) directory is provided. The method includes providing an LDAP Directory Information Tree (DIT) including a plurality of LDAP DIT entries that describe LDAP containers, users and groups, providing a SCIM directory including a plurality of SCIM resource entries that describe SCIM users and groups, migrating the plurality of LDAP DIT entries to the SCIM directory including storing the LDAP DIT hierarchical information in the SCIM directory by mapping LDAP containers in the LDAP DIT to special marker SCIM groups in the SCIM directory, receiving, from an LDAP-based application over a network, an LDAP operation request, processing the LDAP operation request, and returning an LDAP operation response to the LDAP-based application over the network.Type: ApplicationFiled: September 15, 2017Publication date: March 22, 2018Inventors: Kanika VATS, Hari SASTRY
-
Publication number: 20180083915Abstract: A method for mapping SCIM resources to LDAP entries is provided. An LDAP Directory Information Tree (DIT), including a plurality of LDAP DIT entries that describe LDAP containers, users and groups, is provided. Each LDAP DIT entry includes a Distinguished Name and a plurality of LDAP attribute-value pairs, each of which include an attribute name and one or more attribute values. A SCIM directory, including a plurality of SCIM resource entries, is also provided. Each SCIM resource entry includes a plurality of SCIM attributes, each of which includes a name and one or more values. The plurality of SCIM resource entries are converted to corresponding LDAP DIT entries, and, for each SCIM resource entry that has a SCIM CMVA, the SCIM CMVA is mapped to a plurality of LDAP attributes in the corresponding LDAP DIT entry using LDAP attribute subtypes.Type: ApplicationFiled: September 15, 2017Publication date: March 22, 2018Inventors: Venkateswara Reddy MEDAM, Hari SASTRY, Xiaoxiao XU, Michael Ray Frost
-
Publication number: 20180041336Abstract: A key store microservice is provided for a cloud based identity management system. The key store microservice receives, over a network, a request from a client application to retrieve a key, the request including a tenancy identifier, and determines whether the key is present in a tenant specific memory cache associated with the tenancy identifier. When the key is determined to be present in the tenant specific memory cache, the key store microservice retrieves the key from the tenant specific memory cache, retrieves a decryption key from a key wallet, decrypts the key retrieved from the tenant specific memory cache using the decryption key retrieved from the key wallet, and sends, over the network, the key to the client.Type: ApplicationFiled: May 30, 2017Publication date: February 8, 2018Inventors: Rakesh Keshava, Sreedhar Katti, Sirish Vepa, Hari Sastry
-
Publication number: 20180041516Abstract: A method for providing an on-premises virtual directory system for an LDAP (Lightweight Directory Access Protocol) to SCIM (System for Cross-domain Identity Management) proxy service is provided. The method includes providing an LDAP Directory Information Tree (DIT) including LDAP DIT entries, providing a SCIM directory including SCIM resource entries, migrating the LDAP DIT entries to the SCIM directory, creating a virtual LDAP hierarchy based on LDAP DIT hierarchical information stored in the SCIM directory, and displaying a graphical user interface (GUI) for a directory services application that includes a data tree pane that depicts the virtual LDAP hierarchy. Creating the virtual LDAP hierarchy includes storing the LDAP DIT hierarchical information in the SCIM directory by mapping LDAP containers to SCIM user or SCIM group attributes, mapping LDAP containers to special marker SCIM groups, mapping LDAP user DNs to SCIM user externalIDs, or mapping LDAP group DNs to SCIM group externalIDs.Type: ApplicationFiled: July 31, 2017Publication date: February 8, 2018Inventors: Kanika Vats, Vinoth Janakiraman, Manohari Neelakanteshwar, Rajesh Purushothaman, Loganathan Ramasamy, Anand Murugesan, Hari Sastry
-
Publication number: 20170331832Abstract: A system for authorizing access to a resource receives a request for an access token that corresponds to the resource, where the request includes user information and application information. The user information includes a role of the user and the application information includes a role of the application. The system evaluates the request by computing scopes for the access token, including determining an intersection between the user information and the application information. The system then provides the access token that includes the computed scopes, the scopes being based at least on the role of the user and the role of the application.Type: ApplicationFiled: March 30, 2017Publication date: November 16, 2017Inventors: VADIM LANDER, Hari SASTRY, Sreedhar KATTI, Sirish V. VEPA, Swathi Vinayak SHENOY
-
Publication number: 20170019408Abstract: A global policy store, in which policies applicable to multiple applications in an enterprise environment can be stored, can be stored in association with that environment. An application-level policy combining algorithm can be associated with a specific application to resolve conflicts between the results of evaluating policies that pertain to that application's resources. A persistent model is defined for an Extensible Access Control Markup Language (XACML) target definition.Type: ApplicationFiled: September 28, 2016Publication date: January 19, 2017Applicant: Oracle International CorporationInventors: Sirish V. Vepa, Hari Sastry, Alan Cao, Cynthia Ding
-
Publication number: 20160315965Abstract: Application customization enables many different types of customers, from small companies to large multinational enterprises, to use various applications provided by a cloud service provider. To accommodate these customizations, previous systems generally require manual human intervention to identify custom, customized, and cloud service provider authorization policies (also referred to herein as “seed” authorization policies) and to decide how each type of authorization policy should be upgraded. When applications are customized, artifacts that represent those customizations can be created. In some embodiments, the customizations can include new resources or entitlements, and grants to new roles. In addition to new resources, entitlements, and grants, existing resources, entitlements, and grants can be modified and artifacts corresponding to those modifications can be generated.Type: ApplicationFiled: December 18, 2015Publication date: October 27, 2016Inventors: Hari Sastry, Krishnakumar Sriramadhesikan, Vineet Garg, Sirish V. Vepa, Srivatsa Manjunath, Yi Wang
-
Patent number: 9471798Abstract: A global policy store, in which policies applicable to multiple applications in an enterprise environment can be stored, can be stored in association with that environment. An application-level policy combining algorithm can be associated with a specific application to resolve conflicts between the results of evaluating policies that pertain to that application's resources. A persistent model is defined for an Extensible Access Control Markup Language (XACML) target definition.Type: GrantFiled: September 11, 2014Date of Patent: October 18, 2016Assignee: Oracle International CorporationInventors: Sirish V. Vepa, Hari Sastry, Alan Cao, Cynthia Ding
-
Publication number: 20150089575Abstract: A global policy store, in which policies applicable to multiple applications in an enterprise environment can be stored, can be stored in association with that environment. An application-level policy combining algorithm can be associated with a specific application to resolve conflicts between the results of evaluating policies that pertain to that application's resources. A persistent model is defined for an Extensible Access Control Markup Language (XACML) target definition.Type: ApplicationFiled: September 11, 2014Publication date: March 26, 2015Inventors: Sirish V. Vepa, Hari Sastry, Alan Cao, Cynthia Ding
-
Patent number: 7617257Abstract: Systems and methods for providing consistent metadata in a cluster database system are disclosed. Each node contains a number of LDAP server instances, as well as a monitor process. Each node contains a node shared memory, and the cluster contains a cluster shared memory stored on a directory store. When a client alters metadata in one of the LDAP server instances, the LDAP server instances writes the changes to the directory store, and provides update information, such as a version number, to the node shared memory. Other server instances on that node poll the node shared memory to determine whether updates have been made. If updates have been made, the other server instances update their on-heap caches based on the directory store. Each monitor process determines whether changes have been made to the cluster shared memory, and if so, updates the node shared memory based on the directory store.Type: GrantFiled: December 1, 2005Date of Patent: November 10, 2009Assignee: Oracle International CorporationInventors: Ramaprakash H. Sathyanarayan, Ajay Keni, Hari Sastry
-
Publication number: 20070118878Abstract: Embodiments of the invention provide a trust framework for governing service-to-service interactions. This trust framework can provide enhanced security and/or manageability over prior systems. Merely by way of example, in some cases, an information store can be used to store information security information (such as trust information, credentials, etc.) for a variety of services across an enterprise. In other cases, the trust framework can provide authentication policies to define and/or control authentication between services (such as, for example, types of authentication credentials and/or protocols are required to access a particular service—either as a user and/or as another service—and/or types of authentication credentials and/or protocols a service may be enabled to use to access another service). Alternatively and/or additionally, the trust framework can provide authorization policies to define and/or control authorization between services.Type: ApplicationFiled: March 22, 2006Publication date: May 24, 2007Applicant: Oracle International CorporationInventors: Hari Sastry, Romana Turlapati, Saurabh Shrivastava, Stephen Lee, Raymond Ng
-
Publication number: 20070118892Abstract: One embodiment of the present invention provides a system that associates a digital certificate with an enterprise profile. During operation, an identity store receives a digital certificate from a client. Next, the identity store searches for a mapping rule which determines if an enterprise profile is associated with the digital certificate, wherein the enterprise profile facilitates in identifying user capabilities. If a mapping rule is found, the identity store executes the mapping rule to determine if an enterprise profile is associated with the digital certificate. If so, the enterprise profile, which is associated with the digital certificate, is returned to the client.Type: ApplicationFiled: November 21, 2005Publication date: May 24, 2007Inventors: Hari Sastry, Dipankar Thakuria, Quan Dinh
-
Publication number: 20060123024Abstract: Systems and methods for providing consistent metadata in a cluster database system are disclosed. Each node contains a number of LDAP server instances, as well as a monitor process. Each node contains a node shared memory, and the cluster contains a cluster shared memory stored on a directory store. When a client alters metadata in one of the LDAP server instances, the LDAP server instances writes the changes to the directory store, and provides update information, such as a version number, to the node shared memory. Other server instances on that node poll the node shared memory to determine whether updates have been made. If updates have been made, the other server instances update their on-heap caches based on the directory store. Each monitor process determines whether changes have been made to the cluster shared memory, and if so, updates the node shared memory based on the directory store.Type: ApplicationFiled: December 1, 2005Publication date: June 8, 2006Applicant: Oracle International CorporationInventors: Ramaprakash Sathyanarayan, Ajay Keni, Hari Sastry