System and method for providing multi-layer reporting in domain of cloud environment
By deploying multi-layered modules and metering services in the cloud environment, the problem of monitoring and evaluating service usage in multi-tenant cloud environments is solved, enabling effective management and hierarchical evaluation of cloud resources and improving resource utilization efficiency.
Patent Information
- Application Number
- CN202480028711.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-04-18
- Filing Date
- 2024-04-25
- Publication Date
- 2025-11-28
AI Technical Summary
Existing technologies struggle to effectively address the systems and methods provided in cloud computing environments, particularly how to provide multi-tenant systems and methods within cloud infrastructure, and how to provide multi-tiered usage reporting systems and methods in cloud environments.
A system and method are provided to monitor and process usage data to generate multi-tiered reports by deploying multi-tiered modules in a cloud environment, including one or more computers, carrier cloud environments, software products, and metering services, thereby supporting tiered assessment and metering of services in a multi-tenant cloud environment.
It enables effective monitoring and evaluation of service usage in the cloud environment, supports tiered evaluation and metering of services in multi-tenant cloud environments, and improves resource utilization efficiency and management effectiveness.
Smart Images

Figure CN121039632A_ABST
Abstract
Description
[0001] COPYRIGHT NOTICE
[0002] A portion of the disclosure of this patent document contains material which is subject to copyright protection. The copyright owner has no objection to the facsimile reproduction by anyone of the patent document or the patent disclosure, as it appears in the Patent and Trademark Office patent file or records, but otherwise reserves all copyright rights whatsoever.
[0003] CLAIM OF PRIORITY AND CROSS-REFERENCE TO RELATED APPLICATIONS
[0004] This application claims priority to U.S. Provisional Patent Application No. 63 / 462,878, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”; U.S. Provisional Patent Application No. 63 / 462,868, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”; U.S. Provisional Patent Application No. 63 / 462,875, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”; U.S. Provisional Patent Application No. 63 / 462,880, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”; U.S. Provisional Patent Application No. 63 / 462,882, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”; U.S. Provisional Patent Application No. 63 / 462,885, filed April 28, 2023, entitled “SYSTEM AND METHOD FOR PROVIDING DEDICATED CLOUD ENVIRONMENTS FOR USE WITH A CLOUD COMPUTING INFRASTRUCTURE”;and U.S. Patent Application No. 18 / 639,806, filed April 18, 2024, entitled “SYSTEM AND METHOD FOR PROVIDING MULTI-TIERED REPORTING IN A REALM OF A CLOUD ENVORONMENT,” which claims priority to U.S. Provisional Patent Application No. 63 / 251, 1 10, filed October 1, 2021, each of which is incorporated by reference herein, along with the content of each. TECHNICAL FIELD
[0005] Embodiments described herein generally relate to systems and methods for providing a cloud environment for use by tenants of a cloud infrastructure environment in accessing software products, services, or other offerings associated with the cloud environment, including providing multi-tiered modules for multi-tiered usage reporting in one or more realms of the cloud environment. BACKGROUND
[0006] Cloud computing environments can be used to provide access to a range of complementary cloud-based components, such as software applications or services, which enable organization or enterprise customers to operate their applications and services in a highly available, hosted environment.
[0007] The benefits to organizations of moving their application and service needs to a cloud environment include reducing the cost and complexity of designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other information technology infrastructures; allowing them to instead focus on managing their day-to-day business. SUMMARY
[0008] Embodiments described herein generally relate to systems and methods for providing a cloud environment, such as a dedicated or private labeled cloud (PLC) environment, for example, for use by tenants of a cloud infrastructure environment in accessing software products, services, or other offerings associated with the environment, including providing multi-tiered modules in a realm of the cloud environment.
[0009] According to embodiments, the system can include a system that provides tiered assessment of usage of services in a cloud environment.
[0010] According to embodiments, the system that provides tiered assessment of usage of services in a cloud environment can include one or more computers comprising one or more microprocessors; an operator cloud environment running on the one or more computers, wherein the operator cloud environment is deployed within a first realm owned by an operator tenant of the realm; a set of software products provided by a cloud infrastructure provider of the cloud environment to the first realm for access by a plurality of end users via the first realm as a provider cloud service; and a metering service.
[0011] According to an embodiment, a method provides a plurality of services deployed within one or more tenancies of a cloud environment within a cloud environment. A multi-tier reporting service is provided within a first tenancy, where the multi-tier reporting service is operable to monitor usage of services within the first tenancy. The multi-tier reporting service receives usage data, where the usage data records usage of the plurality of services by user entities within the first tenancy. The usage data includes identification data associating the user entities with their usage of services within the first tenancy. The usage data is provided as a first set of data to a first entity associated with control of the first tenancy, and the multi-tier reporting service generates a second set of data by processing the usage data to remove or transform the identification data. Additionally, in the method, the second set of data is provided to a second entity associated with control of the cloud environment.
[0012] According to an embodiment, a metering service of a system providing tiered assessment of usage of services in a cloud environment can be configured to receive end user consumption information from a provider cloud service, where the end user consumption information represents usage of the provider cloud service by each of a plurality of end users, deliver first end user consumption information representing usage of the provider cloud service by a first end user to the first end user, deliver second end user consumption information representing usage of the provider cloud service by a second end user to the second end user, aggregate the first end user consumption information and the second end user consumption information into aggregated end user consumption information, and deliver the aggregated end user consumption information to a cloud infrastructure provider. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 A system for providing a cloud infrastructure environment is illustrated in accordance with an embodiment.
[0014] Figure 2 Further illustrating how a cloud infrastructure environment is used to provide cloud-based applications or services in accordance with an embodiment.
[0015] Figure 3 An example cloud infrastructure architecture is illustrated in accordance with an embodiment.
[0016] Figure 4 Another example of a cloud infrastructure architecture is illustrated in accordance with an embodiment.
[0017] Figure 5 Another example of a cloud infrastructure architecture is illustrated in accordance with an embodiment.
[0018] Figure 6 Another example of a cloud infrastructure architecture is illustrated in accordance with an embodiment.
[0019] Figure 7A system providing a dedicated or private tag cloud environment used by tenants or customers of a cloud infrastructure environment is illustrated in accordance with an embodiment.
[0020] Figure 8 Further illustrated is use of a cloud field by a tenant or customer of a cloud infrastructure environment in accordance with an embodiment.
[0021] Figure 9 Further illustrated is use of a cloud field by a tenant or customer of a cloud infrastructure environment in accordance with an embodiment.
[0022] Figure 10 A system for providing access to a software product or service in a cloud computing or other computing environment is illustrated in accordance with an embodiment.
[0023] Figure 11 A system for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment is illustrated in accordance with an embodiment.
[0024] Figure 12 is a flow diagram illustrating a method for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment in accordance with an embodiment.
[0025] Figure 13 is a further flow diagram illustrating a method for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment in accordance with an embodiment.
[0026] Figure 14 is a further flow diagram illustrating a method for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment in accordance with an embodiment.
[0027] Figure 15 is a further flow diagram illustrating a method for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment in accordance with an embodiment.
[0028] Figure 16 is a further flow diagram illustrating a method for providing tiered evaluation of use of a software product or service in a cloud computing or other computing environment in accordance with an embodiment. DETAILED DESCRIPTION
[0029] A cloud computing or cloud infrastructure environment can be used to provide access to a range of complementary cloud-based components, such as software applications or services, which enables organization or enterprise customers to operate their applications and services in a highly available hosted environment.
[0030] The benefits of organizations moving their application and service needs to a cloud infrastructure environment include reduced costs and complexity in designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other IT infrastructure; and allowing them to focus on managing their day-to-day operations.
[0031] cloud infrastructure environment
[0032] Figure 1 and Figure 2 The illustration depicts a system for providing a cloud infrastructure environment according to an embodiment.
[0033] According to an embodiment, Figure 1 The components and processes shown herein, as well as those further described herein with respect to various embodiments, may be provided as software or program code executable by a computer system or other type of processing device (e.g., a cloud computing system).
[0034] The illustrated examples are provided to illustrate computing environments that can be used to provide dedicated or privately tagged cloud environments for tenants of cloud infrastructure to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.
[0035] like Figure 1 As shown, according to an embodiment, cloud infrastructure environment 100 can operate on cloud computing infrastructure 102, which includes hardware (e.g., processor, memory), software resources, and one or more cloud interfaces 104 or other application programming interfaces (APIs) that provide access to shared cloud resources via one or more load balancers 106.
[0036] According to the embodiment, the cloud infrastructure environment supports the use of availability domains, such as availability domains A 180 and B 182, which enables customers to create and access cloud networks 184 and 186, and run cloud instances A 192 and B 194.
[0037] According to an embodiment, a tenancy can be created for each cloud tenant / customer (e.g., tenants A 142 and B 144), which provides a secure and isolated partition within the cloud infrastructure environment where the customer can create, organize, and manage their cloud resources. Cloud tenants / customers can access availability domains and cloud networks to access each of their cloud instances.
[0038] According to an embodiment, a client device (such as a computing device 160 having device hardware 162 (e.g., a processor, memory) and a graphical user interface 166) can enable administrators or other users to communicate with the cloud infrastructure environment via a network (such as a wide area network, local area network, or the Internet) to create or update cloud services.
[0039] According to an embodiment, the cloud infrastructure environment provides access to the shared cloud resource 140 via, for example, a compute resource layer 150, a network resource layer 164, and / or a storage resource layer 170. Customers can launch cloud instances as needed to meet computing and application requirements. After a customer has provisioned and launched a cloud instance, the provisioned cloud instance can be accessed from, for example, a client device.
[0040] According to an embodiment, the computing resource layer may include resources such as, for example, bare-metal cloud instance 152, virtual machine 154, graphics processing unit (GPU) computing cloud instance 156, and / or container 158. The computing resource layer may be used, for example, to provision and manage bare-metal computing cloud instances, or to provision cloud instances as needed to deploy and run applications, just like in an on-premises data center.
[0041] For example, according to an embodiment, a cloud infrastructure environment can provide control over physical host (bare metal) machines within a computing resource tier, which run directly on bare metal servers as computing cloud instances without the need for a hypervisor.
[0042] According to an embodiment, the cloud infrastructure environment can also provide control over virtual machines within the computing resource layer, which can be booted, for example, from an image, wherein the type and quantity of resources available to the virtual machine cloud instance can be determined, for example, based on the image from which the virtual machine is booted.
[0043] According to an embodiment, the network resource layer may include multiple network-related resources, such as, for example, a virtual cloud network (VCN) 165, a load balancer 167, an edge service 168, and / or a connectivity service 169.
[0044] According to an embodiment, the storage resource layer may include multiple resources, such as, for example, data / block volume 172, file storage device 174, object storage device 176 and / or local storage device 178.
[0045] like Figure 2 As shown, according to an embodiment, the cloud infrastructure environment may include a series of complementary cloud-based components, such as cloud infrastructure applications and services 200, which enables organizations or enterprise customers to operate their applications and services in a highly available managed environment.
[0046] For example, according to an embodiment, a self-contained cloud region can be provided within an organization's data center as a complete, for example, Oracle Cloud Infrastructure (OCI) dedicated region, which can provide data center operators with the flexibility, scalability, and cost-effectiveness of a public cloud while retaining full control over their data and applications to meet security, regulatory, or data residency requirements.
[0047] For example, according to an embodiment, such an environment may include racks physically managed by a cloud infrastructure provider; customer racks; access rights for cloud operators to perform setup and hardware support; customer data center power and cooling; customer floor space; customer data center personnel area; and physical access cages.
[0048] According to the implementation, the dedicated zone provides tenants / customers with the same set of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) products or services available in the cloud infrastructure provider's public cloud zone, such as ERP, finance, HCM, and SCM. Customers can seamlessly extract and replace legacy workloads using the cloud infrastructure provider's services (such as bare metal computing, VMs, and GPUs; database services, such as autonomous databases; or container-based services, such as Kubernetes container engines).
[0049] According to an embodiment, a cloud infrastructure environment can operate according to an Infrastructure as a Service (IaaS) model, which enables the environment to provide virtualized computing resources over a public network (e.g., the Internet).
[0050] In the IaaS model, cloud infrastructure providers can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, cloud infrastructure providers can also supply various services to complement these infrastructure components (example services include billing software, monitoring software, logging software, load balancing software, or clustering software). Therefore, because these services can be policy-driven, IaaS users can implement policies to drive load balancing, thereby maintaining application availability and performance.
[0051] According to the embodiments, IaaS customers can access resources and services via a wide area network (WAN) such as the Internet, and can use the services of the cloud infrastructure provider to install the remaining elements of the application stack. For example, a user can log in to the IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as a database, create buckets for workloads and backups, and even install enterprise software into the VM. The customer can then use the provider's services to perform various functions, including balancing network traffic, troubleshooting application problems, monitoring performance, or managing disaster recovery.
[0052] According to the embodiments, cloud infrastructure providers may, but are not necessarily, third-party services that exclusively provide (e.g., provision, lease, or sell) IaaS. Entities may also choose to deploy private clouds, thereby becoming their own infrastructure service providers.
[0053] According to an embodiment, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server, etc. It may also include the processing of a preparation server (e.g., an installation library or daemon). This is typically managed by the cloud infrastructure provider, below the hypervisor layer (e.g., servers, storage devices, network hardware, and virtualization). Therefore, the customer can be responsible for disposition (OS), middleware, and / or application deployment (e.g., on self-service virtual machines, etc., which can be started on demand).
[0054] According to embodiments, IaaS provisioning may refer to acquiring computers or virtual hosts for use, and even installing necessary libraries or services on them. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.
[0055] According to embodiments, the challenges of IaaS provisioning include: the initial challenge of provisioning an initial set of infrastructure before anything is operational; and the challenge of evolving the existing infrastructure (e.g., adding new services, changing services, or removing services) once everything is provisioned. In some cases, these two challenges can be addressed by enabling configuration that declaratively defines the infrastructure. In other words, the infrastructure (e.g., which components are needed and how they interact) can be defined by one or more configuration files. Therefore, the overall topology of the infrastructure (e.g., which resources depend on which resources and how they work together) can be described declaratively. In some cases, once the topology is defined, workflows for creating and / or managing the different components described in the configuration files can be generated.
[0056] According to embodiments, cloud infrastructure can have many interconnected elements. For example, there may be one or more Virtual Private Clouds (VPCs) (e.g., potential on-demand pools of configurable and / or shared computing resources), also known as the core network. In some examples, one or more inbound / outbound traffic group rules may also be provided to define how inbound / outbound traffic to the network and one or more virtual machines (VMs) will be configured. Other infrastructure elements, such as load balancers, databases, etc., may also be provided. The infrastructure can evolve incrementally as more and / or more infrastructure elements are desired and / or added.
[0057] According to embodiments, continuous deployment techniques can be employed to enable the deployment of infrastructure code across various virtual computing environments. Furthermore, the described techniques enable infrastructure management within these environments. In some examples, service teams may write code that is intended to be deployed to one or more, but typically many, different production environments (e.g., across various geographical locations). However, in some examples, the infrastructure on which the code will be deployed must first be established. In some cases, provisioning can be done manually, resources can be provisioned using provisioning tools, and / or once the infrastructure is provisioned, deployment tools can be used to deploy the code.
[0058] Figure 3 The illustration shows an example cloud infrastructure architecture according to an embodiment.
[0059] like Figure 3 As shown, according to an embodiment, service operator 202 can communicatively couple to secure host lease 204, which may include virtual cloud network (VCN) 206 and secure host subnet 208.
[0060] In some examples, service operators may use one or more client computing devices, which may be portable handheld devices (e.g., telephones, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., head-mounted displays), running software such as Microsoft Windows and / or various mobile operating systems (e.g., iOS, Android, etc.), and supporting the Internet, email, short message service (SMS), or other communication protocols. Alternatively, client computing devices may be general-purpose personal computers, including, for example, personal computers and / or laptops running various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems. Client computing devices may be workstation computers running various commercially available UNIX® or UNIX-like operating systems, including but not limited to any of various GNU / Linux operating systems (such as, for example, Chrome). Alternatively or additionally, client computing devices may be any other electronic device, such as thin client computers, Internet-enabled gaming systems (e.g., Microsoft Xbox game consoles), and / or personal messaging devices capable of communicating over networks with access to VCNs and / or the Internet.
[0061] According to an embodiment, the VCN may include a local peering gateway (LPG) 210, which may be communicatively coupled to an SSH VCN 212 via an LPG contained in a Secure Shell (SSH) VCN. The SSH VCN may include an SSH subnet 214, and the SSH VCN may be communicatively coupled to a control plane VCN 216 via an LPG contained in a control plane VCN. Furthermore, the SSH VCN may be communicatively coupled to a data plane VCN 218 via an LPG. The control plane VCN and data plane VCN may be contained in a service lease 219 that may be owned and / or operated by a cloud infrastructure provider.
[0062] According to an embodiment, the control plane VCN may include a control plane demilitarized zone (DMZ) layer 220 that acts as a peripheral network (e.g., part of an enterprise network between an internal and external network). DMZ-based servers may have limited responsibility to help contain potential vulnerabilities. Furthermore, the DMZ layer may include one or more load balancer (LB) subnets 222, a control plane application layer 224 that may include one or more application subnets 226, and a control plane data layer 228 that may include one or more database (DB) subnets 230 (e.g., one or more front-end DB subnets and / or one or more back-end DB subnets). The one or more LB subnets included in the control plane DMZ layer may communicatively couple to the one or more application subnets included in the control plane application layer and to an Internet gateway 234 that may be included in the control plane VCN, and the one or more application subnets may communicatively couple to the one or more DB subnets included in the control plane data layer, as well as a service gateway 236 and a Network Address Translation (NAT) gateway 238. The control plane VCN may include a service gateway and a NAT gateway.
[0063] According to an embodiment, the control plane VCN may include a data plane mirror application layer 240, which may include one or more application subnets. The one or more application subnets included in the data plane mirror application layer may include a virtual network interface controller (VNIC) capable of executing compute instances. The compute instances may communicatively couple the one or more application subnets of the data plane mirror application layer to the one or more application subnets that may be included in the data plane application layer.
[0064] According to an embodiment, the data plane VCN may include a data plane application layer 246, a data plane DMZ layer 248, and a data plane data layer 250. The data plane DMZ layer may include one or more LB subnets communicatively coupled to one or more application subnets of the data plane application layer and an internet gateway of the data plane VCN. The one or more application subnets may communicatively couple to a service gateway and a NAT gateway of the data plane VCN. The data plane data layer may also include one or more DB subnets communicatively coupled to one or more application subnets of the data plane application layer.
[0065] According to an embodiment, the internet gateways of the control plane VCN and the data plane VCN can be communicatively coupled to a metadata management service 252, which can be communicatively coupled to a public internet 254. The public internet can be communicatively coupled to a NAT gateway of the control plane VCN and the data plane VCN. The service gateways of the control plane VCN and the data plane VCN can be communicatively coupled to a cloud service 256.
[0066] According to an embodiment, the service gateway of the control plane VCN or data plane VCN can make application programming interface (API) calls to cloud services without traversing the public internet. API calls from the service gateway to the cloud service can be unidirectional: the service gateway can make API calls to the cloud service, and the cloud service can send requested data to the service gateway. Generally, the cloud service may not initiate API calls to the service gateway.
[0067] According to an embodiment, a secure host lease can be directly connected to a service lease, which may otherwise be isolated. A secure host subnet can communicate with an SSH subnet via an LPG, which enables bidirectional communication between otherwise isolated systems. Connecting a secure host subnet to an SSH subnet allows the secure host subnet to access other entities within the service lease.
[0068] According to embodiments, a control plane VCN can allow users of a service lease to set up or otherwise provision desired resources. The desired resources provisioned in the control plane VCN can be deployed or otherwise used in the data plane VCN. In some examples, the control plane VCN can be isolated from the data plane VCN, and the data plane mirror application layer of the control plane VCN can communicate with the data plane application layer of the data plane VCN via VNICs, which can be included in both the data plane mirror application layer and the data plane application layer.
[0069] According to an embodiment, users or clients of the system can make requests, such as create, read, update, or delete (CRUD) operations, via the public internet that can transmit requests to the metadata management service. The metadata management service can transmit requests to the control plane VCN via an internet gateway. The request can be received by one or more LB subnets contained in the control plane DMZ layer. The one or more LB subnets can determine that the request is valid, and in response to this determination, the one or more LB subnets can transmit the request to one or more application subnets contained in the control plane application layer. If the request is verified and a call to the public internet is required, the call to the internet can be transmitted to a NAT gateway that can make the call to the internet. The metadata to be stored can be stored in one or more DB subnets.
[0070] According to an embodiment, the data plane mirroring application layer can facilitate direct communication between the control plane VCN and the data plane VCN. For example, it may be desirable to apply configuration changes, updates, or other suitable modifications to resources contained in the data plane VCN. With the help of the VNIC, the control plane VCN can communicate directly with the resources contained in the data plane VCN, and thus can perform configuration changes, updates, or other suitable modifications to these resources.
[0071] According to one embodiment, the control plane VCN and data plane VCN can be included in a service lease. In this case, the system's users or customers may not own or operate the control plane VCN or data plane VCN. Alternatively, the cloud infrastructure provider may own or operate both the control plane VCN and data plane VCN, both of which can be included in a service lease. This embodiment enables network isolation, which can prevent users or customers from interacting with the resources of other users or customers. Furthermore, this embodiment allows the system's users or customers to privately store databases without relying on the public internet for storage, which may not provide the desired level of threat protection.
[0072] According to one embodiment, one or more LB subnets included in the control plane VCN can be configured to receive signals from the serving gateway. In this embodiment, the control plane VCN and the data plane VCN can be configured to be invoked by customers of the cloud infrastructure provider without invoking the public internet. Customers of the cloud infrastructure provider may expect this embodiment because the database(s) used by the customer can be controlled by the cloud infrastructure provider and can be stored on a service lease that is isolated from the public internet.
[0073] Figure 4 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.
[0074] like Figure 4 As shown, according to an embodiment, a data plane VCN may be included in customer lease 221. In this case, the cloud infrastructure provider may provide a control plane VCN for each customer, and the cloud infrastructure provider may establish a unique compute instance for each customer included in the service lease. Each compute instance may allow communication between the control plane VCN included in the service lease and the data plane VCN included in the customer lease. The compute instance may allow resources provisioned in the control plane VCN included in the service lease to be deployed or otherwise used in the data plane VCN included in the customer lease.
[0075] According to an embodiment, a cloud infrastructure provider's customer may have a database managed and operated within a customer lease. In this example, the control plane VCN may include a data plane mirror application layer, which may include one or more application subnets. The data plane mirror application layer may reside in the data plane VCN, but it may not be provided within the data plane VCN. That is, the data plane mirror application layer may access the customer lease, but it may not exist in the data plane VCN, or be owned or operated by the customer. The data plane mirror application layer may be configured to invoke the data plane VCN, but cannot be configured to invoke any entity contained within the control plane VCN. The customer may expect to deploy or otherwise use resources provided in the control plane VCN within the data plane VCN, and the data plane mirror application layer may facilitate the customer's expected deployment or other use of resources.
[0076] According to one embodiment, a cloud infrastructure provider's customers can apply filters to a data plane VCN. In this embodiment, customers can determine what the data plane VCN can access and can restrict access to the public internet from the data plane VCN. The cloud infrastructure provider may not be able to apply filters or otherwise control the data plane VCN's access to any external networks or databases. Applying filters and controls to the data plane VCN included in the customer's lease helps isolate the data plane VCN from other customers and the public internet.
[0077] According to embodiments, cloud services can be invoked by a service gateway to access services that may not exist on the public internet, the control plane VCN, or the data plane VCN. The connection between the cloud service and the control plane VCN or data plane VCN may not be contiguous. Cloud services can reside on different networks owned or operated by a cloud infrastructure provider. Cloud services can be configured to accept calls from the service gateway and can be configured not to accept calls from the public internet. Some cloud services can be isolated from other cloud services, and the control plane VCN can be isolated from cloud services that may not be in the same region as the control plane VCN.
[0078] For example, according to an embodiment, the control plane VCN may be located in "Region 1", and the cloud service "Deployment 1" may be located in both Region 1 and "Region 2". If a service gateway contained in the control plane VCN located in Region 1 makes a call to Deployment 1, then the call can be transmitted to Deployment 1 in Region 1. In this example, the control plane VCN or Deployment 1 in Region 1 may not be communicatively coupled to or otherwise communicate with Deployment 1 in Region 2.
[0079] Figure 5The illustration shows another example of a cloud infrastructure architecture according to an embodiment.
[0080] like Figure 5 As shown, according to an embodiment, one or more trusted application subnets 260 can be communicatively coupled to a service gateway contained in a data plane VCN, a NAT gateway contained in a data plane VCN, and one or more database subnets contained in a data plane data layer. One or more untrusted application subnets 264 can be communicatively coupled to a service gateway contained in a data plane VCN and one or more database subnets contained in a data plane data layer. The data plane data layer may include one or more database subnets that can be communicatively coupled to a service gateway contained in a data plane VCN.
[0081] According to an embodiment, one or more untrusted application subnets may include one or more primary VNICs (1)-(N) communicatively coupled to tenant virtual machines (VMs). Each tenant VM may be communicatively coupled to a corresponding application subnet 267 (1)-(N) that may be contained in a corresponding container egress VCN 268 (1)-(N), which may be contained in a corresponding customer lease 270 (1)-(N). A corresponding secondary VNIC may facilitate communication between the one or more untrusted application subnets contained in the data plane VCN and the application subnets contained in the container egress VCN. Each container egress VCN may include a NAT gateway communicatively coupled to the public internet.
[0082] According to an embodiment, the public internet can communicatively couple to a NAT gateway contained in a control plane VCN and a data plane VCN. Service gateways contained in the control plane VCN and the data plane VCN can communicatively couple to cloud services.
[0083] According to an embodiment, the data plane VCN can be integrated with customer leases. This integration may be useful or desirable for cloud infrastructure provider customers where additional support may be required when executing code. For example, a customer may provide code to be run that may be potentially destructive, may communicate with other customer resources, or may otherwise cause undesirable effects.
[0084] According to an embodiment, a cloud infrastructure provider's customer can grant temporary network access to the cloud infrastructure provider and request functionality to be attached to the data plane application layer. The code running this functionality can execute within a VM, and this code may not be configured to run anywhere else on the data plane VCN. Each VM can be connected to a customer lease. The corresponding containers (1)-(N) contained within the VM can be configured to run the code. In this case, dual isolation can exist (e.g., containers running code, where the containers may be contained within at least one or more untrusted application subnets containing VMs), which helps prevent incorrect or otherwise unintended code from corrupting the cloud infrastructure provider's network or the networks of different customers. Containers can be communicatively coupled to the customer lease and can be configured to transmit or receive data from the customer lease. Containers may not be configured to transmit or receive data with any other entity in the data plane VCN. After the code execution is complete, the cloud infrastructure provider can dispose of these containers.
[0085] According to an embodiment, one or more trusted application subnets may run code that can be owned or operated by a cloud infrastructure provider. In this embodiment, one or more trusted application subnets may be communicatively coupled to one or more database subnets and configured to perform CRUD operations within the one or more database subnets. One or more untrusted application subnets may be communicatively coupled to one or more database subnets and configured to perform read operations within the one or more database subnets. Containers that may be contained in each customer's VM and may run code from the customer may not be communicatively coupled to the one or more database subnets.
[0086] According to embodiments, the control plane VCN and data plane VCN may be coupled without direct communication; or there may be no direct communication between them. However, communication can occur indirectly, where the cloud infrastructure provider can establish an LPG that facilitates communication between the control plane VCN and data plane VCN. In another example, either the control plane VCN or the data plane VCN can invoke cloud services via a service gateway. For example, an invocation of a cloud service from the control plane VCN may include a request for a service that can communicate with the data plane VCN.
[0087] Figure 6 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.
[0088] like Figure 6As shown, according to an embodiment, one or more trusted application subnets may be communicatively coupled to a service gateway contained in the data plane VCN, a NAT gateway contained in the data plane VCN, and one or more database subnets contained in the data plane data layer. One or more untrusted application subnets may be communicatively coupled to a service gateway contained in the data plane VCN and one or more database subnets contained in the data plane data layer. The data plane data layer may include one or more database subnets that can be communicatively coupled to a service gateway contained in the data plane VCN.
[0089] According to an embodiment, one or more untrusted application subnets may include primary VNICs that are communicatively coupled to tenant virtual machines (VMs) residing within one or more untrusted application subnets. Each tenant VM may run code in a corresponding container and be communicatively coupled to an application subnet that may be included in a data plane application layer 281, which may be included in a container egress VCN 280. Corresponding auxiliary VNICs 282(1)-(N) may facilitate communication between the one or more untrusted application subnets included in the data plane VCN and the application subnets included in the container egress VCN. The container egress VCN may include a NAT gateway that is communicatively coupled to the public internet.
[0090] According to an embodiment, an Internet gateway contained in a control plane VCN and a data plane VCN can be communicatively coupled to a metadata management service, which can be communicatively coupled to the public Internet. The public Internet can be communicatively coupled to a NAT gateway contained in both the control plane VCN and the data plane VCN. A service gateway contained in both the control plane VCN and the data plane VCN can be communicatively coupled to a cloud service.
[0091] According to an embodiment, Figure 6 The pattern shown can be regarded as Figure 5 Exceptions to the pattern illustrated, and patterns that customers might expect if the cloud infrastructure provider cannot communicate directly with the customer (e.g., in a disconnected region). Customers have live access to the corresponding containers contained within each customer's VM. Containers can be configured to invoke appropriate secondary VNICs contained in one or more application subnets within the data plane application layer, which may be contained in the container's egress VCN. The secondary VNICs can then route the calls to a NAT gateway, which can then route the calls to the public internet. In this example, the containers that customers can access live can be isolated from the control plane VCN, and can also be isolated from other entities contained within the data plane VCN. Containers can also be isolated from resources from other customers.
[0092] In other examples, customers can use containers to invoke cloud services. In this example, a customer can run code within a container that requests a service from the cloud service. The container can then forward the request to a secondary VNIC, which in turn forwards it to a NAT gateway, which in turn forwards it to the public internet. The public internet can then be used to forward the request via an internet gateway to one or more load balancer (LB) subnets contained within the control plane VCN. In response to determining that the request is valid, the LB subnets can forward the request to one or more application subnets, which in turn forward the request to the cloud service via a service gateway.
[0093] It should be recognized that the IaaS architecture depicted in the figures above may have components other than those depicted. Furthermore, the embodiments shown in the figures are merely some examples of cloud infrastructure systems that can be combined with embodiments of this disclosure. In some other embodiments, the IaaS system may have more or fewer components than shown in the figures, may combine two or more components, or may have different component configurations or arrangements.
[0094] In some embodiments, the IaaS system described herein may include a suite of application, middleware, and database service providers delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner.
[0095] cloud environment
[0096] According to an embodiment, a cloud infrastructure environment can be used to provide a dedicated cloud environment, such as one or more privately tagged cloud environments, for tenants of the cloud infrastructure environment to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment.
[0097] Figure 7 The illustration shows how a system according to an embodiment can provide a dedicated or private tagged cloud environment for use by tenants or customers of a cloud infrastructure environment.
[0098] While the examples described herein illustrate various systems, methods, and / or technologies that can be used in the context of providing a private tag cloud (PLC) environment, the systems, methods, and technologies described herein can be used within or with other types of cloud environments, depending on the various embodiments.
[0099] like Figure 7As shown, according to an embodiment, a cloud infrastructure provider may supply one or more cloud environments (e.g., PLC environments) or domains to an operator 320 (e.g., a cloud infrastructure customer operating as a reseller). The operator / reseller may then customize and extend the cloud environment for use by its customer 330 to access subscription-based software products, services, or other offerings associated with the cloud infrastructure environment.
[0100] For illustrative purposes, examples of such subscription-based products, services, or other offerings may include a variety of cloud infrastructure software products, such as Oracle Fusion Applications, or other types of products or services that allow customers to subscribe to use these products or services.
[0101] Figure 8 The illustration further illustrates the use of the cloud domain by tenants or customers in a cloud infrastructure environment according to an embodiment.
[0102] like Figure 8 As shown, according to an embodiment, the system may include a cloud subscription service or component, referred to herein as a subscription manager in some embodiments, which exposes one or more subscription management APIs for creating orders for joining new customers or initiating a workflow that may create subscriptions and coordinate billing and pricing services or other components for cloud domain 400.
[0103] According to an embodiment, when an operator (e.g., a PLC operator) or its customers request a cloud environment, the system creates domains for use within regions 402 and 404; and leases 416 owned by one or more providers. These leases allow the domains to operate using their required service infrastructure and to be managed by the cloud infrastructure provider.
[0104] According to an embodiment, the first step in this process is to create an operator lease 406 for the operator, and then transfer the region and associated domains to the operator for subsequent management. The operator then becomes the administrator of the lease, and they can view and manage everything that happens within the region, including their customer accounts and those customers' use of cloud resources 412.
[0105] Generally, once a region is handed over or provided to an operator, the cloud infrastructure provider cannot subsequently access the data within the operator's lease unless the operator authorizes the cloud infrastructure provider to do so, for example, to troubleshoot any problems that may arise.
[0106] According to an embodiment, the operator can then create additional internal leases 408 for its own internal use, such as for evaluating end-user or customer experience, providing sales demonstration leases, or operating databases for its own internal use. The operator can also create one or more customer leases 410, with the end-user or customer acting as its administrator. The use of cloud infrastructure (e.g., compute, storage, and other infrastructure resources) is consolidated by the operator, reflecting its own and its customers' usage, and reported to the cloud infrastructure provider.
[0107] According to embodiments, a user interface or console may be provided that allows operators to manage their customer accounts and provide services to customers. Cloud infrastructure providers may also use cloud infrastructure leasing (e.g., Fusion Applications leasing) to install any required infrastructure services for use by operators and their customers.
[0108] Figure 9 The illustration further illustrates the use of the cloud domain by tenants or customers in a cloud infrastructure environment according to an embodiment.
[0109] like Figure 9 As shown, according to an embodiment, the subscription manager 424 service or component exposes one or more subscription management APIs for creating orders for joining new customers, or initiating workflows for creating subscriptions and coordinating billing and pricing services or other components.
[0110] According to an embodiment, the system may also include a billing service 428 or component that operates on a logical container for billing accounts or subscriptions and preferences used to generate invoices for customers.
[0111] According to an embodiment, the system may also include a subscription pricing service (SPS) 426 or component that operates based on a product catalog that defines which products a customer can purchase, and a price list that can be used to provide (e.g., a rate card), which the pricing service also owns.
[0112] According to an embodiment, to support sales processing via subscription creation in domains 420 and 422, products can be selected from a product hub. Once an order is created via subscription service 430, a subscription is created in the subscription manager, which then manages the subscription's lifecycle and supplies the content required for downstream services. The SPS component then manages pricing and usage aspects for the ability to collect final fees from the operator or for the operator to charge its customers. Usage events are forwarded to a billing service or component, where, depending on the subscription's billing preferences, an invoice is created and pushed to the accounts receivable component.
[0113] According to an embodiment, although the services provided in the field report their usage to the metering service or component 432, such usage does not have any associated price. Rate processing, for example, involves determining the cost of each specific event by applying a rate card, determining the unit and cost of the subscription, associating the cost with the record, and then forwarding it to the billing service or component.
[0114] like Figure 9 As further illustrated, according to an embodiment, an operator can control multiple domains A and B—for example, an operator operating in multiple countries might want to operate a completely isolated data center for the United States and a completely isolated separate data center for Europe, for example, to meet governance or regulatory requirements. According to an embodiment, usage associated with these multiple domains can be aggregated 434 for use by a central subscription manager 435 and (where applicable) a primary billing service 436 for billing the operator.
[0115] The examples of the various systems shown above are intended to illustrate what can be used to provide dedicated or privately tagged cloud environments for tenants of cloud infrastructure to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.
[0116] Cloud subscription
[0117] Figure 10 The illustration depicts a system according to an embodiment for providing access to software products or services in a cloud computing or other computing environment.
[0118] like Figure 10 As shown, according to an embodiment, the system can be provided as a cloud computing or other computing environment, referred to herein as a platform in some embodiments, which supports the use of subscription-based products, services or other offerings.
[0119] Examples of such subscription-based products, services, or other offerings can include a variety of cloud infrastructure software products or services that allow customers to subscribe to use.
[0120] According to an embodiment, the environment may include multiple components provided as operator singleton 438, domain singleton 439, and regional service 440, as further described below.
[0121] According to embodiments, subscriptions may include artifacts such as products, commitments, billing models, and states. A subscription manager service or component may expose one or more subscription management APIs for creating orders for joining new customers, or for initiating workflows to create subscriptions and coordinate the creation of appropriate footprints in the billing and pricing service or component, as further described below.
[0122] According to an embodiment, the billing service or component operates based on a logical container of billing accounts or subscriptions and preferences used to generate invoices. Each billing account generates one invoice per billing period. The billing service includes a first pipeline and a second pipeline. The first pipeline receives usage and costs from the metering service or component via a REST API, whereby billing writes usage to a database, and a billing worker aggregates and calculates the balance from that database. The second pipeline is responsible for retrieving the aggregated usage and commitments, and calculating the costs within the billing interval.
[0123] According to an embodiment, the Subscription Pricing Service (SPS) 426 or component operates based on a product catalog that defines which products a customer can purchase. The product catalog forms the backbone of a price list (i.e., rate cards) also owned by the pricing service. Rate cards are modeled as pricing rules on top of publicly listed prices. The pricing service maintains a single price list for all products, allowing the addition of new product prices and the modification of existing prices. The price list has a complete history, with the latest version being the current rate card. Because some contracts may require a snapshot of the rate card, the pricing service handles this by recording when a customer's rate card was created and then querying the price list at that time.
[0124] According to an embodiment, the SPS or pricing service is responsible for communicating with the product and pricing hub 421 to provide information about products, the global price list, and specific price lists and discounts for end-user or customer subscriptions. For example, according to an embodiment, the SPS can synchronize product information from the product hub and the global price list from the pricing hub.
[0125] According to an embodiment, the subscription manager service or component operates as an upstream service to receive new order requests from the order management component (e.g., from an Oracle FusionOrder Management environment). The subscription manager service or component can provide subscription information, including subscription details such as the quote configuration time or subscription type (commitment, PayG), to the SPS service to help the SPS determine the effective base price (rate card) for the subscription. The subscription manager service or component can also send subscription discounts received from the order management component, which the SPS stores as a pricing rule entity.
[0126] In one embodiment, the SPS service runs as a background process to manage a ratecard service or component responsible for generating ratecards for new subscriptions and updating these ratecards when prices change. The SPS service can provide APIs to access ratecards and pricing rules. The metering inline rate engine can leverage these APIs to obtain subscription-specific ratecards and pricing rules, and then use this data for cost calculations.
[0127] According to an embodiment, additional SPS components may include, for example, a pricing / product hub integration component that allows operator entities providing subscription-based products, services, or other offerings within the environment to manage their product and price lists, such as product and price lists provided by a product hub and a pricing hub, respectively.
[0128] For example, according to such an embodiment, the SPS product integration process can listen for creation / update events in the product hub and make calls to the SPS product API. Similarly, the SPS pricing integration process can pull new price lists from the pricing hub to create them and call the corresponding SPS pricing API.
[0129] According to an embodiment, the system may also include an SPS core module that provides APIs for managing and accessing pricing entities. Pricing entities can be accessed through internal services (e.g., an inline rate engine).
[0130] According to an embodiment, the system may also include a rate card manager component. The SPS service maintains a single base price for a product at a given time. However, the price of a subscribed product depends on the base price at the time of the quote configuration and the subscription's price list change policy attributes. The SPS service uses these attributes to internally maintain the price to be used for the subscription. All these price lists are grouped in rate cards. The rate card manager can create and maintain rate cards, listen for price list changes and update existing rate cards with the new prices, and listen for new subscriptions and assign rate cards based on subscription attributes.
[0131] According to an embodiment, the SPS service manages the pricing rules for subscriptions, including discounts offered to end users or customers. The applicability of pricing rules can be based on product attributes such as discount groups, product categories, or specific SKUs. The SPS internally needs to identify a list of products to which these rules will apply. To achieve this, the rule decoder engine can compile the pricing rules into a format that allows the inline rate engine to use this information for cost calculations. This compilation process can be triggered when a product or pricing rule is created or updated.
[0132] like Figure 10As shown in the example, according to the embodiment: at 441, product and pricing information (e.g., managed in FusionApplications) is sent to the SPS component.
[0133] At position 442, the order is sent to the subscription manager component to create the subscription, rate card, and billing account.
[0134] At point 443, the pricing configuration and pricing rules are sent to SPS for use with new orders.
[0135] At 444, the subscription manager component is used to set up billing accounts in a billing service or component.
[0136] At 445, the subscription manager component publishes the event to the subscription manager stream component.
[0137] At point 446, the expense data is sent to accounts receivable component 425 to generate an invoice.
[0138] At 447, the subscription manager component uses the recycling and subscription lifecycle (RASL) events from the subscription manager stream.
[0139] At 448, the activation service 427 reads the subscription manager event stream.
[0140] At point 449, the customer obtains activation data from activation portal 429.
[0141] At 450, the lease lifecycle service 461 provides leases as part of a subscription activation.
[0142] At point 451, the lease lifecycle service creates an account footprint during the account provisioning period within component 463 of the account.
[0143] At location 452, the lease lifecycle service sets a restriction template for the account supply period within the restricted service 467.
[0144] At 453, the account component acts as a downstream RASL client to handle legacy recycling and subscription lifecycle. 465.
[0145] At 454, the aggregated costs and usage are sent to billing service 428 or component.
[0146] At point 455, organizations can use the lease lifecycle service to create subleases.
[0147] At position 456, metering service 432 or component obtains subscription mapping data.
[0148] At 457, subscription service 430 obtains organization data 469 for subscription mapping.
[0149] At 458, the RASL component reads the subscription manager event stream.
[0150] At 459, the subscription service reads the subscription manager event stream; and at 460, the metering service or component obtains the rate card data for each subscription, which can then be used to collect the final charge from the operator or the operator to charge its customers.
[0151] The examples provided above are intended to illustrate how they can be used to provide dedicated or privately tagged cloud environments for use by tenants of cloud infrastructure when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.
[0152] Layered assessment of service usage in the cloud infrastructure domain
[0153] Figure 11 The illustration depicts a system for hierarchical evaluation of the use of software products and / or services in cloud computing or other computing environments, according to an embodiment.
[0154] In general, and according to embodiments, this system provides a method and system for multi-tiered metering of resource usage, including a first-tier resource usage metering occurring at the operator level within the domain of a cloud infrastructure operator, and a second-tier resource usage metering occurring at the cloud infrastructure provider level.
[0155] While the examples described herein illustrate various systems, methods, and / or technologies that can be used in the context of providing a private tag cloud (PLC) environment, the systems, methods, and technologies described herein can be used within or with other types of cloud environments, depending on the various embodiments.
[0156] According to an embodiment, the first level of metering provides the operator with detailed resource usage information related to the specific resources used by one or more of its corresponding end users, the amount of resources used by one or more of its corresponding end users, and the time of resource usage by one or more of its corresponding end users.
[0157] According to an embodiment, the second-level metering provides the cloud provider system with generalized resource usage information related to the resources used by the domain operator and one or more corresponding end users. However, the generalized resource usage information is anonymized for the one or more corresponding end users. In this way, the cloud provider system is provided with resource usage information related to the specific resources attributed to the domain operator and its end users, the amount of resources attributed to the domain operator and its end users, and the time of resource usage attributed to the domain operator and its end users.
[0158] Commercially, Tier 1 metering allows operators to directly control the pricing of products offered to end users and the billing activities associated with those end users. Tier 2 metering provides cloud providers with accounting for all usage by the operator and its customers, enabling billing the operator for this combined usage.
[0159] According to the embodiments, data related to combined use by the operator and its customers is anonymized. For usage related to proprietary / private infrastructure and platform services used by the operator's customers, the accounting provided to the cloud infrastructure provider (e.g., OCI) only includes the resource consumption portion related to any platform infrastructure and platform services required or used to support the proprietary / private infrastructure and platform services used by the operator's customers.
[0160] According to the embodiments, continue to refer to Figure 11 The system shown provides a tiered assessment of the use of products and / or services within a cloud infrastructure environment. The carrier cloud environment runs on one or more computers, and is deployed within a First Domain A controlled or otherwise "owned" by a First Domain operator.
[0161] In an example embodiment, the first domain may be, for example, a PLC domain, controlled by a first domain operator. A cloud infrastructure provider of the cloud environment provides a set of software products to the first domain A as a vendor cloud service accessible to multiple end users via the first domain A. Metering service 432 is configured to receive end-customer usage information from the vendor cloud service, wherein the end-customer usage information represents the usage or consumption of the vendor cloud service by each of the multiple end users, and to deliver end-user consumption information representing the end-users' usage of the vendor cloud service to the domain A operator and the cloud infrastructure provider.
[0162] According to an embodiment, metering service 432 is also configured to receive operator consumption information from the group of software products, the operator consumption information representing the usage of the group of software products by operator A in domain A. The metering service can add end-user or customer consumption information to operator consumption information to obtain operator-attributable consumption information, and deliver the operator-attributable consumption information to the cloud infrastructure provider.
[0163] According to an embodiment, an operator subscription manager service is provided for managing operator subscriptions to a set of software products, wherein the operator subscription manager is configured to transmit a request to a cloud infrastructure provider in a cloud environment to subscribe to one or more software products, whereby the one or more software products can be received from the cloud infrastructure provider as part of the set of software products in a first domain A, for the operator to selectively provide to multiple end users or end customers as a provider cloud service.
[0164] In the example embodiment, the carrier subscription manager is configured to fulfill subscriptions by creating carrier subscriptions in domain A, wherein the carrier subscriptions include carrier subscription pricing attributes. Furthermore, the metering service includes a carrier billing usage service configured to receive carrier consumption information from the group of software products, wherein the carrier consumption information represents the carrier's usage of the group of software products. The carrier billing usage service is also configured to determine the carrier's usage costs incurred by the carrier and the group of end-user customers using the group of software products based on the carrier subscription pricing attributes and the sum of aggregated end-user consumption information and carrier consumption information. The usage costs of the domain A carrier, considering both the carrier's own use of the service or product and the use of the domain A carrier's customers, are delivered to the cloud infrastructure provider.
[0165] According to an embodiment, an end-user subscription manager is provided for operators in Domain A to manage multiple end-user subscriptions to vendor cloud services. In an example embodiment, the subscription manager is configured to receive requests from end-user customers to subscribe to multiple sets of vendor cloud services, and to fulfill the requested subscriptions by creating end-user customer subscriptions in the subscription manager, wherein the end-user customer subscriptions provide the end-user customers with access to the desired multiple sets of vendor cloud services.
[0166] According to an embodiment, the system provides tiered evaluation of the use of software products or services in cloud computing or other computing environments, such as tiered evaluation between operators in Domain A and among multiple different end-user customers. In this regard, a first end-user customer's first end-user subscription may include a first end-user pricing attribute, and similarly, a second end-user customer's second end-user subscription may include a second end-user pricing attribute. Metering services include an end-user customer billing service configured to determine the first end-user's usage cost of a first group of vendor cloud services based on the first end-user pricing attribute and the first end-user consumption information, and also to determine the second end-user's usage cost of a second group of vendor cloud services based on the second end-user pricing attribute and the second end-user consumption information.
[0167] According to an embodiment, the metering service of the system also includes a billing service configured to deliver to a first end user the usage costs of the first end user for using the cloud services of the first group of suppliers, and also to deliver to a second end user the usage costs of the second end user for using the cloud services of the second group of suppliers.
[0168] According to an embodiment, the system also includes a usage service for end-user customer billing, which is configured to determine the usage cost of the first end-user's use of the first group of supplier cloud services based on the first end-user's pricing attributes and the first end-user's consumption information, thereby enabling billing to end-user customers for usage via the billing service.
[0169] According to an embodiment, the system is configured to anonymize end-user customer consumption information based on end-user identification information and end-user pricing attributes, as anonymized end-user consumption information. This anonymized end-user consumption information can then be delivered to a cloud infrastructure provider.
[0170] According to an embodiment, the system's metering service may further include a carrier-billed usage service. This carrier-billed usage service is configured to receive carrier consumption information from the set of software products, representing the carrier's usage of the set of software products. Based on carrier subscription pricing attributes, carrier consumption information, and anonymized end-user consumption information, it determines the usage costs incurred by the Domain A carrier and its group of end-user customers using the set of software services or products. The usage costs of the Domain A carrier can be delivered to the cloud infrastructure provider's carrier through the subscription manager's primary billing service for appropriate billing.
[0171] According to an embodiment, the system shown for providing tiered assessments of the use of services and / or products in a cloud infrastructure environment 100 may include one or more computers, each including one or more microprocessors, on which the cloud environment 100 may run. Multiple products and / or services are deployed within one or more domains of the cloud environment, such as, for example, domain A and domain B. A tiered reporting service 475 is provided in first domain A, operable to monitor the use of services within first domain A. Similarly, a tiered reporting service 475 may be provided in second domain B, operable to monitor the use of services within second domain B.
[0172] In general, in the example embodiment, and focusing on the first domain A, the multi-tier reporting service 475 receives usage data that records the use of multiple services by user entities within the first domain A, wherein the usage data includes identification data that associates user entities with their use of services within the first domain A. The multi-tier reporting service provides this usage data as a first set of data to a first entity associated with the control of the first domain A. The multi-tier reporting service generates a second set of data by processing the usage data to remove or transform the identification data, wherein this second set of data is provided to a second entity associated with the control of the cloud environment.
[0173] In the example embodiment shown, the first entity may be an operator associated with control of a first domain A, and the second entity may be an operator associated with control of a second domain B.
[0174] In an example embodiment, the first entity may be a first operator associated with control of a first domain A, where the first domain A may be a first PLC domain; and the second entity may be a second operator associated with control of a second domain B, where the second domain B may be a second PLC domain of cloud infrastructure. Similarly, in this example embodiment, the second entity may be a cloud infrastructure provider associated with the overall control of cloud environment 100.
[0175] It is understood that, according to embodiments, the multi-level reporting service is preferably operable to generate a second set of data by replacing references to user entities in the usage data with references to a first entity.
[0176] It can also be recognized that the multi-tier reporting service is preferably operable to generate a second set of data by reformatting the usage data of a user entity for the use of multiple services, in order to conform to the records of the second entity's use of multiple services.
[0177] According to an embodiment, a second multi-tier reporting service 475 may be provided within a second domain B, wherein the second multi-tier reporting service is operable to monitor services and / or usage within the second domain B, and wherein the first entity may also be associated with control of the second domain B. In an example embodiment, the second multi-tier reporting service 475 operating within the second domain B receives usage data that records the usage of multiple services by user entities within the second domain B, wherein the usage data includes identification data that associates user entities with their usage of services within the second domain B.
[0178] According to an embodiment, a second multi-tier reporting service 475 operating within a second domain B generates a set of modified usage data by processing usage data to remove or transform identification data. The multi-tier reporting service is also operable to combine the modified sets of usage data received from a first domain A and a second domain B, describing the usage of user entities within the first domain A and the second domain B, to generate aggregated usage data, wherein the multi-tier reporting service is operable to provide the aggregated usage data to a second entity associated with the cloud environment. In the illustrated example embodiment, the multi-tier reporting service 475 may be distributed across the first domain A and the second domain B. Alternatively, the multi-tier reporting service 475 may be provided as instances of reporting services that collaborate to generate aggregated usage data and provide the aggregated usage data to a second entity associated with the cloud environment.
[0179] In an example embodiment, the multi-tier reporting service is operable to transmit one or more rules or policies, stored within a first domain and modifying the operation of the multi-tier reporting service when monitoring the use of services within the first domain, from a second entity associated with control of the cloud environment to a first entity associated with control of the first domain. For example, the first entity may be a domain operator, and the second entity may be a cloud infrastructure provider.
[0180] According to an embodiment, the multi-level reporting service is further configured to receive first entity consumption information from multiple services, the first entity consumption information being based on usage data representing the use of multiple services by a user entity within a first domain; receive second entity consumption information from multiple services, the second entity consumption information representing the use of multiple services by a second entity; add the first entity consumption information and the second entity consumption information to obtain total cloud environment consumption information; and deliver the total cloud environment consumption information to a second entity associated with the control of the cloud environment.
[0181] According to an embodiment, the system also includes an operator subscription service 430 operable to manage a first entity's subscription to a plurality of services, wherein the operator subscription service is configured to transmit a request to subscribe to one or more of the plurality of services to a second entity associated with control of the cloud environment, and to receive one or more services in the first domain as a plurality of services so that they can be selectively provided by the first entity to a user entity as a provider cloud service.
[0182] It is understood that, according to the embodiments, the operator subscription service 430 is operable to fulfill a subscription by creating a first entity subscription in the operator subscription service, the first entity subscription including a first entity subscription pricing attribute representing the pricing of the first entity using one or more of a plurality of services, and a user entity subscription pricing attribute representing the pricing of the user entity using one or more of the plurality of services.
[0183] In addition to the above, according to embodiments, the subscription manager service or component 424 also includes or functions as an end-user subscription manager (EUSM) to manage user entities' subscriptions to multiple services. The EUSM is configured to receive a first request from a first user entity to subscribe to a first group of services out of the multiple services, and a second request from a second user entity to subscribe to a second group of services out of the multiple services. The subscription manager / EUSM service or component is also operable to fulfill the first requested subscription by creating a first user entity subscription in the EUSM, wherein the first user entity subscription provides the first user entity with access to the first group of cloud services. The EUSM is also operable to fulfill the second requested subscription by creating a second user entity subscription in the EUSM, wherein the second user entity subscription provides the second user entity with access to the second group of cloud services.
[0184] Figure 12 This is a flowchart illustrating a method 500 for tiered evaluation of the use of software products or services in cloud computing or other computing environments, according to an embodiment.
[0185] like Figure 12 As shown, according to an embodiment, at 502, multiple services are deployed within one or more domains of a cloud environment running on one or more computers including one or more microprocessors.
[0186] At step 504, a multi-level reporting service is provided within the first domain. According to an embodiment, the multi-level reporting service provided within the first domain is operable to monitor the use of services within the first domain.
[0187] At step 506, the multi-tiered reporting service provided in the first domain at step 504 receives customer usage data. According to an example embodiment, this usage data records the use of multiple services by user entities within the first domain. For example, the usage data may include identification data that associates a user entity with its use of services within the first domain.
[0188] At point 508, usage data is provided to a first entity associated with control of the first domain. According to an example embodiment, the first entity may be, for example, a PLC operator.
[0189] At point 510, the multi-tiered reporting service generates a second set of data by processing usage data to remove or transform identifier data. It is understood that, according to embodiments, the processing of usage data by the multi-tiered reporting service preferably anonymizes the usage data by removing or transforming the identifier data therein. That is, the resulting second set of data does not contain information that associates the use of cloud products or services with any particular end-user or customer.
[0190] According to an example embodiment, generating a second set of data may include replacing references to user entities in the data with references to the first entity.
[0191] According to an example embodiment, generating the second set of data may include reformatting the usage data of a user entity that records the use of multiple services to conform to the records of the second entity's use of multiple services.
[0192] At point 512, the multi-tiered reporting service provides a second set of data to a second entity associated with control of the cloud environment. According to an example embodiment, the second entity could be a cloud infrastructure provider.
[0193] Figure 13 This is a further flowchart illustrating a method 520 for tiered evaluation of the use of software products or services in cloud computing or other computing environments, according to an embodiment.
[0194] like Figure 13 As shown, according to an embodiment, at point 524, a second multi-tier reporting service is provided in the second domain B, such as, for example... Figure 9 As shown in the example embodiment, the second multi-tier reporting service is operable to monitor service usage within a second domain, wherein the first entity is associated with control of the second domain. In the example embodiment, the second entity associated with control of the second domain may be, for example, a PLC operator.
[0195] According to an embodiment, at point 526, a second multi-tier reporting service operating within the second domain B receives customer usage data. It will be understood that, according to the embodiment, this usage data records the use of multiple services by user entities within the second domain B, wherein the usage data includes identification data that associates the user entity with its use of services within the second domain. For example, the user entity may be an end-user customer of a PLC operator.
[0196] Customer usage data received at 526 in the second-tier reporting service can be provided to PCL operators for reporting and confirming end-user customer usage of cloud services and products.
[0197] At point 528, a set of modified usage data is generated by a second-level reporting service operating within the second domain B. In the example embodiment, this set of modified usage data is generated by the second-level reporting service by processing the usage data to remove or transform identification data.
[0198] At point 530, aggregated usage data is generated by combining the modified usage data received from the first and second domains, wherein the aggregated usage data describes the usage of user entities within the first and second domains.
[0199] At point 532, aggregated usage data will be provided to the second entity cloud infrastructure operator associated with the cloud environment.
[0200] In addition, one or more rules or policies can be transferred from a second entity associated with the control of the cloud environment to a first entity associated with the control of the first domain, wherein one or more rules or policies can be stored within the first domain and modify the operation of the multi-level reporting service when monitoring the use of services within the first domain.
[0201] It is understood that, according to the embodiments, the first entity may be a domain operator and the second entity may be a cloud infrastructure provider.
[0202] Figure 14 This is a further flowchart illustrating a method 540 for tiered evaluation of the use of software products or services in cloud computing or other computing environments, according to an embodiment.
[0203] like Figure 14 As shown, according to an embodiment, the multi-level reporting service is configured to receive first entity consumption information from multiple services at point 542, wherein the first entity consumption information is based on usage data representing the use of multiple services by user entities within a first domain.
[0204] The multi-tier reporting service is also configured to receive second entity consumption information from multiple services at point 544, where the second entity consumption information represents the second entity's use of multiple services.
[0205] The multi-level reporting service adds the consumption information of the first entity to the consumption information of the second entity at 546 locations to obtain the total cloud environment consumption information.
[0206] The multi-tiered reporting service delivers total cloud environment consumption information to a second entity associated with the control of the cloud environment at 548 locations.
[0207] Figure 15 This is a further flowchart illustrating a method 550 for tiered evaluation of the use of software products or services in cloud computing or other computing environments, according to an embodiment.
[0208] like Figure 15 As shown in the example, according to an embodiment, an Operator Subscription Manager (OSM) is provided at 552 for managing the first entity's subscriptions to multiple services.
[0209] OSM is configured to transmit a request to subscribe to one or more services from a plurality of services to a second entity associated with the control of the cloud environment at position 554.
[0210] OSM is also configured to receive one or more services at 556 into the first domain as multiple services, which are selectively provided by the first entity to the user entity as vendor cloud services.
[0211] According to another example embodiment, OSM is configured to fulfill a subscription at 558 by creating a first entity subscription in OSM, the first entity subscription including a first entity subscription pricing attribute representing the pricing of the first entity using one or more of a plurality of services, and a user entity subscription pricing attribute representing the pricing of the user entity using one or more of the plurality of services.
[0212] Figure 16 This is a further flowchart illustrating a method 560 for tiered evaluation of the use of software products or services in cloud computing or other computing environments, according to an embodiment.
[0213] like Figure 16 As shown in the example, according to an embodiment, an End User Subscription Manager (EUSM) is provided at 562 for managing user entities' subscriptions to multiple services.
[0214] EUSM is operable to receive, at point 564, a first request from a first user entity to subscribe to a first group of services out of a plurality of services.
[0215] EUSM can also be operated at 566 to receive a second request from a second user entity to subscribe to a second group of services out of a plurality of services.
[0216] EUSM can also be operated to fulfill the order of the first request at 568 by creating a first user entity subscription in EUSM, wherein the first user entity subscription provides the first user entity with access to the first set of cloud services.
[0217] EUSM can also operate at 570 to fulfill a second requested subscription by creating a second user entity subscription in EUSM, wherein the second user entity subscription provides the second user entity with access to a second set of cloud services.
[0218] According to various embodiments, the teachings herein can be implemented using one or more computers, computing devices, machines, or microprocessors, including one or more processors, memories, and / or computer-readable storage media programmed according to the teachings herein. It will be apparent to those skilled in the art that a skilled programmer can easily prepare appropriate software code based on the teachings of this disclosure.
[0219] In some embodiments, the teachings herein may include a computer program product, which is one or more nontransitory computer-readable storage media having instructions stored thereon / therein that can be used to program a computer to perform any of the processing described herein. Examples of such storage media may include, but are not limited to, hard disk drives, solid disks, ROM, RAM, EPROM, EEPROM, DRAM, VRAM, flash memory devices, or other types of storage media or devices suitable for nontransitory storage of instructions and / or data.
[0220] The above description is provided for illustrative and descriptive purposes only. It is not intended to be exhaustive or to limit the scope of protection to the precise forms disclosed. Further modifications and variations will be apparent to those skilled in the art.
[0221] The embodiments were chosen and described to better explain the principles taught herein and their practical application, thereby enabling others skilled in the art to understand the various embodiments and modifications suitable for the intended particular use. The scope of the invention is defined by the following claims and their equivalents.
Claims
1. A method comprising: Provide multiple services deployed in one or more domains within a cloud environment; A multi-level reporting service is provided within a first domain, the multi-level reporting service being operable to monitor the use of services within the first domain; The multi-level reporting service receives usage data that records the use of the multiple services by user entities within a first domain, the usage data including identification data that associates user entities with their use of services within the first domain; The data will be provided as the first set of data to the first entity associated with control of the first domain; A second set of data is generated by the multi-tiered reporting service by processing usage data to remove or transform identifying data; as well as The second set of data is provided to a second entity associated with the control of the cloud environment.
2. The method of claim 1, wherein: Generating the second set of data involves replacing references to the user entity in the data with references to the first entity.
3. The method of claim 1, wherein: Generating the second set of data includes: reformatting the usage data of the user entity that records the use of the multiple services to conform to the usage records of the second entity for the multiple services.
4. The method of claim 1, further comprising: A second-level reporting service is provided within the second domain, which is operable to monitor the use of services within the second domain, wherein the first entity is associated with the control of the second domain. The second-level reporting service, operating within the second domain, receives usage data that records the use of the multiple services by user entities within the second domain, the usage data including identification data that associates user entities with their use of the services within the second domain; The second-tier reporting service, operating within the second domain, generates a modified set of usage data by processing usage data to remove or transform identifier data; The modified usage data received from both the first and second domains, describing the usage of user entities within the first and second domains, are combined to generate aggregated usage data. as well as The aggregated usage data is provided to a second entity associated with the cloud environment.
5. The method of claim 1, further comprising: One or more rules or policies stored in the first domain and used to modify the operation of the multi-level reporting service when monitoring the use of services in the first domain are transferred from a second entity associated with the control of the cloud environment to a first entity associated with the control of the first domain.
6. The method of claim 1, wherein the first entity is a domain operator and the second entity is a cloud infrastructure provider.
7. The method of claim 1, wherein the multi-tier reporting service is configured as follows: Receive first entity consumption information from the plurality of services, the first entity consumption information being based on usage data representing the use of the plurality of services by a user entity within a first domain; Receive second entity consumption information from the plurality of services, the second entity consumption information representing the second entity’s use of the plurality of services; The consumption information of the first entity is added to the consumption information of the second entity to obtain the total cloud environment consumption information; as well as The total cloud environment consumption information is delivered to a second entity associated with the control of the cloud environment.
8. The method of claim 1, further comprising: Provide an Operator Subscription Manager (OSM) for managing the subscriptions of a first entity to the plurality of services, wherein the OSM is configured as follows: Transmit a request to order one or more of the plurality of services to a second entity associated with the control of the cloud environment; as well as The one or more services are received in the first domain as the plurality of services, which are selectively provided by the first entity to the user entity as supplier cloud services.
9. The method of claim 8, wherein: OSM is configured to fulfill the subscription by creating a first entity subscription in OSM, the first entity subscription including a first entity subscription pricing attribute representing the pricing of the first entity using one or more of the plurality of services, and a user entity subscription pricing attribute representing the pricing of the user entity using one or more of the plurality of services.
10. The method of claim 1, further comprising: An End-User Subscription Manager (EUSM) is provided to manage user entities' subscriptions to the multiple services, and the EUSM is configured as follows: Receive a first request from the first user entity to order a first group of services from the plurality of services; Receive a second request from the second user entity to order a second group of services from the plurality of services; The subscription requested for the first user entity is fulfilled by creating a first user entity subscription in the EUSM, which provides the first user entity with access to the first set of cloud services; as well as The second request is fulfilled by creating a second user entity subscription in EUSM, which provides the second user entity with access to a second set of cloud services.
11. A system for providing tiered assessment of service usage in a cloud environment, the system comprising: One or more computers, including one or more microprocessors; A cloud environment running on one or more of the computers; Multiple services deployed in one or more domains within a cloud environment; as well as A multi-tiered reporting service is provided within a first domain, which is operable to monitor the use of services within the first domain. The multi-level reporting service receives usage data that records the use of the multiple services by user entities within a first domain, and the usage data includes identification data that associates user entities with their use of services within the first domain; The data used is provided as the first set of data by a multi-tiered reporting service to the first entity associated with control of the first domain; The multi-tiered reporting service generates a second set of data by processing usage data to remove or transform identifier data. The second set of data is provided to a second entity associated with the control of the cloud environment.
12. The system of claim 11, wherein: The multi-tiered reporting service can operate to generate a second set of data by replacing references to user entities in the usage data with references to the first entity.
13. The system of claim 11, wherein: The multi-tier reporting service is operable to generate a second set of data by reformatting usage data that records a user entity's use of the multiple services, in order to conform to the records of a second entity's use of the multiple services.
14. The system of claim 11, further comprising: A second-tier reporting service is provided within the second domain, capable of operating to monitor service usage within the second domain, wherein the first entity is associated with control of the second domain. The second-level reporting service, operating within the second domain, receives usage data recording the use of the multiple services by user entities within the second domain. This usage data includes identification data that associates user entities with their use of the services within the second domain. The second-tier reporting service, operating within the second domain, generates a modified set of usage data by processing usage data to remove or transform identifier data. The multi-level reporting service combines modified usage data received from both the first and second domains, describing the usage of user entities within the first and second domains, to generate aggregated usage data. The multi-tiered reporting service can operate to provide aggregated usage data to a second entity associated with the cloud environment.
15. The system of claim 11, wherein: The multi-level reporting service is capable of transmitting one or more rules or policies stored in the first domain and modifying the operation of the multi-level reporting service when monitoring the use of services in the first domain from a second entity associated with the control of the cloud environment to a first entity associated with the control of the first domain.
16. The system of claim 11, wherein the first entity is a domain operator and the second entity is a cloud infrastructure provider.
17. The system of claim 11, wherein the multi-level reporting service is configured as follows: Receive first entity consumption information from the plurality of services, the first entity consumption information being based on usage data representing the use of the plurality of services by a user entity within a first domain; Receive second entity consumption information from the plurality of services, the second entity consumption information representing the second entity’s use of the plurality of services; The consumption information of the first entity is added to the consumption information of the second entity to obtain the total cloud environment consumption information; as well as The total cloud environment consumption information is delivered to a second entity associated with the control of the cloud environment.
18. The system of claim 11, further comprising: The carrier subscription service is operable to manage a first entity's subscriptions to the plurality of services, and the carrier subscription service is configured to: Transmit a request to order one or more of the plurality of services to a second entity associated with the control of the cloud environment; as well as The one or more services are received in the first domain as the plurality of services, which are selectively provided by the first entity to the user entity as supplier cloud services.
19. The system of claim 18, wherein: The carrier subscription service is operable to fulfill the subscription by creating a first entity subscription in the carrier subscription service, the first entity subscription including a first entity subscription pricing attribute representing the pricing of the first entity using one or more of the plurality of services, and a user entity subscription pricing attribute representing the pricing of the user entity using one or more of the plurality of services.
20. The system of claim 11, further comprising: The End User Subscription Manager (EUSM) is operable to manage user entities' subscriptions to the multiple services, and the EUSM is configured to: Receive a first request from the first user entity to order a first group of services from the plurality of services; Receive a second request from the second user entity to order a second group of services from the plurality of services; The subscription requested for the first user entity is fulfilled by creating a first user entity subscription in the EUSM, which provides the first user entity with access to the first set of cloud services; as well as The second request is fulfilled by creating a second user entity subscription in EUSM, which provides the second user entity with access to a second set of cloud services.
21. A non-transitory computer-readable storage medium comprising instructions stored thereon, the instructions, when read and executed by one or more computers in a cloud environment, causing the one or more computers to perform a method comprising the following steps: Provide multiple services deployed in one or more domains within a cloud environment; A multi-level reporting service is provided within a first domain, the multi-level reporting service being operable to monitor the use of services within the first domain; The multi-level reporting service receives usage data that records the use of the multiple services by user entities within a first domain, the usage data including identification data that associates user entities with their use of services within the first domain; The data will be provided as the first set of data to the first entity associated with control of the first domain; A second set of data is generated by the multi-tiered reporting service by processing usage data to remove or transform identifying data; as well as The second set of data is provided to a second entity associated with the control of the cloud environment.