Bridging end user customer support with cloud operator customer support

By generating upgrade service tickets that do not contain access-restricted attributes, the information security issue of upgrade service tickets in the cloud computing environment is resolved, ensuring the security and reliability of the system.

CN121773442APending Publication Date: 2026-03-31ORACLE INT CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, when a service ticket for an affected entity needs to be upgraded in a cloud computing environment, it is impossible to transmit the ticket to a higher-level service provider without exposing access-restricted attributes, leading to information security risks.

Method used

The initial service ticket is processed after the problem is resolved by generating an upgrade service ticket that does not contain the access restriction attribute of the affected entity and transmitting it to a higher-level service provider.

Benefits of technology

This allows service tickets to be upgraded without exposing access-restricted attributes, improving information security and system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121773442A_ABST
    Figure CN121773442A_ABST
Patent Text Reader

Abstract

Technologies for upgrading a service work order between two service providers include receiving, at an initial service provider, an initial service work order for resolving a problem from an affected entity affected by the problem. The initial service work order includes a set of access limited attributes of the affected entity. Based on the initial service work order, the system generates an upgraded service work order at the initial service provider. The upgraded service work order identifies the problem and omits access limited attributes. The system passes the upgraded service work order to a higher level service provider that is not authorized to access the set of access limited attributes included in the initial service work order. In response to transmitting the upgraded service work order, the system receives information corresponding to the resolution of the problem from the higher level service provider and processes the initial service work order based on the information corresponding to the resolution of the problem.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Incorporate by reference; abandon declaration

[0002] The following applications are hereby incorporated herein by reference: Application No. 18 / 402,972, filed January 3, 2024; and Application No. 63 / 519,547, filed August 14, 2023. The applicant hereby withdraws any disclaimer regarding the scope of the claims in one or more of the parent applications or their examination history, and informs the United States Patent and Trademark Office (USPTO) that the claims in this application may be more extensive than any claims in the parent applications. Technical Field

[0003] This disclosure relates to systems and methods for providing a dedicated or private tag cloud (PLC) environment for tenants of a cloud infrastructure environment to access software products, services, or other offers associated with that environment. Specifically, this disclosure relates to receiving an initial service ticket from an affected entity at an initial service provider, determining that the initial service ticket requires an upgrade, generating an upgrade ticket that does not include certain access-restricted attributes of the affected entity, and submitting the upgrade ticket to another service provider. Background Technology

[0004] Cloud computing environments can be used to provide access to a range of complementary cloud-based components, such as software applications or services, enabling organizations or enterprise customers to operate their applications and services in a highly available managed environment.

[0005] The benefits of organizations moving their application and service needs to the cloud include reduced costs and complexity in designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other IT infrastructure.

[0006] Some organizations provide computer-related services to customers, including the use of software and / or hardware created and / or owned by third parties. In some cases, organizations may be able to provide customer support for computer-related services. However, in other cases, organizations may require support from third parties to resolve issues.

[0007] The methods described in this section are possible methods, but not necessarily methods that have been previously conceived or adopted. Therefore, unless otherwise indicated, no method described in this section should be assumed to qualify as prior art simply because it is included in this section. Attached Figure Description

[0008] In the accompanying drawings, embodiments are illustrated by way of example rather than limitation. It should be noted that references to "a" or "an" embodiment in this disclosure do not necessarily refer to the same embodiment, and they mean at least one. In the drawings:

[0009] Figure 1 The illustration depicts a system for providing a cloud infrastructure environment according to an embodiment.

[0010] Figure 2 The illustration further illustrates how a cloud infrastructure environment can be used to provide cloud-based applications or services according to embodiments.

[0011] Figure 3 The illustration shows an example cloud infrastructure architecture according to an embodiment.

[0012] Figure 4 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0013] Figure 5 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0014] Figure 6 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0015] Figure 7 The illustration shows how a system according to an embodiment can provide a dedicated or private tagged cloud environment for use by tenants or customers of a cloud infrastructure environment.

[0016] Figure 8 The illustration further illustrates the use of a private tag cloud domain for tenants or customers in a cloud infrastructure environment, according to an embodiment.

[0017] Figure 9 The illustration further illustrates the use of a private tag cloud domain for tenants or customers in a cloud infrastructure environment, according to an embodiment.

[0018] Figure 10 The illustration depicts a system according to an embodiment for providing access to software products or services in a cloud computing or other computing environment.

[0019] Figures 11A-11B The illustration shows a system according to one or more embodiments.

[0020] Figure 12 The illustration shows a set of example operations for escalating a service ticket to a third party, according to one or more embodiments.

[0021] Figure 13 An example of a machine learning model according to one or more embodiments is illustrated. Detailed Implementation

[0022] In the following description, numerous specific details are set forth for purposes of explanation in order to provide a thorough understanding. One or more embodiments may be practiced without these specific details. Features described in one embodiment may be combined with features described in different embodiments. In some examples, well-known structures and devices are described in the form of block diagrams to avoid unnecessarily obscuring this disclosure.

[0023] 1. General Overview

[0024] 2. Dedicated or private tag cloud environment

[0025] 3. Service Upgrade System Architecture

[0026] 4. Escalate the service ticket to a third party.

[0027] 5. Machine Learning

[0028] 6. Practical applications, advantages, and improvements

[0029] 7. Other matters; extension

[0030] 1. General Overview

[0031] One or more embodiments…

[0032] One or more embodiments described in this specification and / or recited in the claims may not be included in this general overview section.

[0033] 2. Dedicated or private tag cloud environment

[0034] One or more embodiments provide features associated with a dedicated or private tag cloud (PLC) environment for tenants of a cloud infrastructure environment to access software products, services, or other offerings associated with that environment.

[0035] Cloud computing or cloud infrastructure environments can be used to provide access to a range of complementary cloud-based components, such as software applications or services, enabling organizations or enterprise customers to operate their applications and services in a highly available managed environment.

[0036] The benefits of organizations moving their application and service needs to a cloud infrastructure environment include reduced costs and complexity in designing, building, operating, and maintaining their own on-premises data centers, software application frameworks, or other IT infrastructure.

[0037] The system can resolve service tickets that identify issues affecting "affected entities." To resolve such tickets, the system can use information generated by a higher-level service provider. One or more embodiments obtain information generated by a higher-level service provider for resolving the service ticket without sharing the access-restricted attributes of the affected entities included in the service ticket with the higher-level service provider.

[0038] The system receives an initial service ticket from a customer to resolve a problem. Because the problem affects the customer, the customer is referred to as the "affected entity." The initial service ticket from the customer includes a set of access-restricted attributes corresponding to the customer. Based on the initial service ticket itself (or an intermediate service ticket generated from the initial service ticket), the system determines that the problem needs to be escalated to a higher-level service provider that is not allowed access to the set of access-restricted attributes corresponding to the customer. The system generates an escalated service ticket from the intermediate service ticket (or directly from the initial service ticket). The escalated service ticket identifies the problem to be resolved in the initial service ticket. The escalated service ticket does not include the set of access-restricted attributes corresponding to the customer included in the initial service ticket. The system transmits the escalated service ticket to the higher-level service provider to resolve the problem. In response to the transmission of the escalated service ticket, the system receives information corresponding to the resolution of the problem. The system then processes the initial service ticket based on the information corresponding to the resolution of the problem.

[0039] One or more embodiments described in this specification and / or recited in the claims may not be included in this general overview section.

[0040] cloud infrastructure environment

[0041] Figure 1 and Figure 2 The illustration depicts a system for providing a cloud infrastructure environment according to an embodiment.

[0042] According to an embodiment, Figure 1 The components and processes shown herein, as well as those further described herein with respect to various embodiments, may be provided as software or program code executable by a computer system or other type of processing device (e.g., a cloud computing system).

[0043] The illustrated examples are provided to illustrate computing environments that can be used to provide dedicated or privately tagged cloud environments for tenants of cloud infrastructure to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.

[0044] like Figure 1As shown, according to an embodiment, cloud infrastructure environment 100 can operate on cloud computing infrastructure 102, which includes hardware (e.g., processors, memory), software resources, and one or more cloud interfaces 104 or other application programming interfaces (APIs) that provide access to shared cloud resources via one or more load balancers A 106, B 108. Cloud interface 102 includes user interfaces and APIs provided by cloud service providers for interacting with their cloud services. This includes tools and platforms that allow users and administrators to manage, configure, and monitor cloud resources and services. Cloud interface 102 may include a console, such as a web-based user interface, that provides a visual way to interact with and manage cloud resources. Through the console, users can, for example, create, configure, and monitor cloud services such as compute instances, databases, storage devices, and networking components. Cloud interface 102 may also include a command-line interface for users who prefer to operate the cloud infrastructure using command-line tools. In this embodiment, the CLI allows for the scripting and automation of cloud management tasks.

[0045] According to embodiments, load balancers A 106 and B 108 are services that distribute incoming network traffic across multiple servers, instances, or other resources to ensure that no single resource is overwhelmed by excessive demand. By distributing requests evenly across resources, load balancers enhance the responsiveness and availability of resources such as applications, websites, or databases. Load balancers A 106 and B 108 can be public load balancers accessible from the Internet and used for distributing external traffic, or they can be private load balancers used within a Virtual Cloud Network (VCN) and not accessible from the public Internet (and therefore well-suited for internal traffic distribution). In embodiments, load balancers A 106 and B 108 are designed for high availability and fault tolerance and are implemented in a redundant configuration across multiple availability or fault domains.

[0046] According to an embodiment, the cloud infrastructure environment supports the use of availability domains (such as availability domain A 180 and availability domain B 182), which enable customers to create and access cloud networks 184 and 186 and run cloud instances A 192 and B 194. In this embodiment, availability domain A 180 and availability domain B 182 may represent data centers, or a group of data centers located within a region. These availability domains may be isolated from each other, meaning they may not share the same physical infrastructure, such as power or cooling systems. This design provides a high degree of fault independence and robustness. In this embodiment, a fault domain can provide additional protection and resilience within a single availability domain by grouping hardware and infrastructure into availability domains isolated from other fault domains. This isolation may involve power, cooling, and other potential sources of failure.

[0047] According to an embodiment, a lease (a container of resources used by the tenant) can be created for each cloud tenant / customer (e.g., tenants A 142 and B 144). This lease provides a secure and isolated partition within the cloud infrastructure environment, where customers can create, organize, and manage their cloud resources. Cloud tenants / customers can access availability domains and cloud networks to access each of their cloud instances. Leases are isolated from other leases, ensuring that each customer's data and resources are secure and inaccessible to other customers. Within a lease, customers can create, manage, and organize various cloud resources, including compute instances, storage volumes, and networks. Identity and Access Management (IAM) services enable the management of users, groups, and policies within a lease. Through IAM, customers can control who has access to their resources and what actions they can perform. Leases also serve as a level for disposal billing and subscription management. All usage and costs associated with resources within a lease are tracked and billed uniformly under that lease. Each lease can be associated with specific service limits and quotas for various resources. These limits can be used to help manage capacity and facilitate resource allocation among all tenants.

[0048] According to an embodiment, a computing device (such as a client device 120 having device hardware 122 (e.g., a processor, memory) and a graphical user interface 126) can enable administrators or other users to communicate with a cloud infrastructure environment via a network (such as a wide area network, a local area network, or the Internet) to create or update cloud services.

[0049] According to an embodiment, the cloud infrastructure environment provides access to the shared cloud resource 140 via, for example, a compute resource layer 150, a network resource layer 160, and / or a storage resource layer 170. Customers can launch cloud instances as needed to meet computing and application requirements. After a customer has provisioned and launched a cloud instance, the provisioned cloud instance can be accessed from a client device (such as client device 120).

[0050] According to embodiments, computing resources 150 may include resources such as bare-metal cloud instances 152, virtual machines 154, graphics processing unit (GPU) computing cloud instances 156, and / or containers 158. A bare-metal instance represents a physical server with dedicated hardware that is fully allocated to a single tenant. Bare-metal instances provide direct access to the server's processor, memory, storage devices, and other hardware resources. A virtual machine (VM) is a software emulation of a physical computer that runs an operating system and applications like a physical computer. VMs allow multiple operating systems to run on a single physical machine or across multiple physical machines. A hypervisor layer sits between the hardware and the VMs, allocating physical resources (such as CPU, memory, and storage devices) to each VM. In embodiments, GPU computing cloud instances provide GPUs as well as traditional CPU resources. These instances are designed for tasks requiring high levels of parallel processing power, making them well-suited for applications such as machine learning, scientific computing, 3D rendering, and video processing. In embodiments, containers 158 use a virtualization approach that allows multiple isolated applications to run on a single controlling host, thus virtualizing only the operating system. Each container shares the host system's kernel but runs in an isolated user space, making the containers lightweight and efficient.

[0051] The components of computing resource 150 can be used to provision and manage bare-metal computing cloud instances, or to provision cloud instances as needed to deploy and run applications, just like in an on-premises data center. For example, according to an embodiment, the cloud infrastructure environment can provide control over physical host (bare-metal) machines within the computing resource tier that run directly on bare-metal servers as computing cloud instances without the need for a hypervisor.

[0052] According to an embodiment, the cloud infrastructure environment can also provide control over virtual machines within a computing resource layer, which can be launched from, for example, an image, wherein the type and quantity of resources available to the virtual machine cloud instance can be determined, for example, based on the image from which the virtual machine is launched.

[0053] According to an embodiment, the network resource layer may include several network-related resources, such as a Virtual Cloud Network (VCN) 162, a load balancer 164, an edge service 166, and / or a connectivity service 168. In this embodiment, the Virtual Cloud Network (VCN) is a customizable and private network in a cloud environment. The VCN provides a virtual version of a traditional network, including subnets, routing tables, and gateways. It allows users to establish a cloud-based network architecture according to their requirements. In this embodiment, the edge service 166 includes services and technologies designed to bring computing, data storage, and networking capabilities closer to the desired location. The edge service 166 can be used to optimize traffic, reduce latency, or provide other advantages.

[0054] According to an embodiment, the storage resource layer may include several resources, such as data / block volume 172, file storage device 174, object storage device 176, and / or local storage device 178. Data / block volume 172 provides unformatted block-level storage, which can be used to create a file system for a managed database or for other purposes requiring unformatted storage. File storage device 174 provides a file system in this embodiment and can provide a shared file system that can be accessed simultaneously by multiple instances using standard file storage protocols. Object storage device 176 manages data as objects within buckets. Objects have certain attributes, which may include data, metadata, and unique identifiers. Local storage device 178 refers to a storage device physically attached to a host computer.

[0055] like Figure 2 As shown, according to an embodiment, the cloud infrastructure environment may include a series of complementary cloud-based components, such as cloud infrastructure applications and services 200, which enable organizations or enterprise customers to operate their applications and services in a highly available managed environment.

[0056] According to an embodiment, a self-contained cloud region can be provided as a dedicated area of ​​Oracle Cloud Infrastructure (OCI) within an organization's data center, which provides data center operators with the flexibility, scalability, and cost-effectiveness of, for example, the OCI public cloud, while retaining full control over its data and applications to meet security, regulatory, or data residency requirements.

[0057] For example, according to an embodiment, such an environment may include racks physically managed by a cloud infrastructure provider (e.g., Oracle), customer racks, access permissions for cloud operators to configure and support hardware, customer data center power and cooling, customer floor space, customer data center personnel area, and physical access cages.

[0058] According to an embodiment, a dedicated zone provides tenants / customers with the same set of Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) products or services, such as ERP, finance, HCM, and SCM, available in the public cloud regions of a cloud infrastructure provider (e.g., Oracle). Customers can seamlessly extract and replace legacy workloads using services from the cloud infrastructure provider (e.g., bare metal computing, VMs, and GPUs), database services (e.g., Oracle Autonomous Database), or container-based services (e.g., Oracle Kubernetes Container Engine).

[0059] According to an embodiment, a cloud infrastructure environment can operate according to an Infrastructure as a Service (IaaS) model, which enables the environment to provide virtualized computing resources over a public network (e.g., the Internet).

[0060] In the IaaS model, cloud infrastructure providers can host infrastructure components (e.g., servers, storage devices, network nodes (e.g., hardware), deployment software, platform virtualization (e.g., hypervisor layer), etc.). In some cases, cloud infrastructure providers can also supply various services to complement these infrastructure components (example services include billing software, monitoring software, logging software, load balancing software, or clustering software). Therefore, because these services can be policy-driven, IaaS users can implement policies to drive load balancing, thereby maintaining application availability and performance.

[0061] According to the implementation, IaaS customers can access resources and services via a wide area network (WAN) such as the Internet, and can use the cloud infrastructure provider's services to install the remaining elements of the application stack. For example, a user can log in to the IaaS platform to create virtual machines (VMs), install an operating system (OS) on each VM, deploy middleware such as databases, create buckets for workloads and backups, and install enterprise software into that VM. The customer can then use the provider's services to perform various functions, including balancing network traffic, troubleshooting application problems, monitoring performance, or managing disaster recovery.

[0062] According to the embodiments, cloud infrastructure providers may, but are not necessarily, third-party services that exclusively provide (e.g., provision, lease, or sell) IaaS. Entities may also choose to deploy private clouds, thereby becoming their own infrastructure service providers.

[0063] According to an embodiment, IaaS deployment is the process of placing a new application or a new version of an application onto a prepared application server, etc. It may also include the processing of a preparation server (e.g., an installation library or daemon). This is typically managed by the cloud infrastructure provider, below the hypervisor layer (e.g., servers, storage devices, network hardware, and virtualization). Therefore, the customer can be responsible for disposal (OS), middleware, and / or application deployment (e.g., on self-service virtual machines, etc., which can be started on demand).

[0064] According to embodiments, IaaS provisioning may refer to acquiring computers or virtual hosts for use and installing necessary libraries or services on them. In most cases, deployment does not include provisioning, and provisioning may need to be performed first.

[0065] According to embodiments, the challenges of IaaS provisioning include: the initial challenge of provisioning an initial set of infrastructure before anything is operational; and the challenge of evolving the existing infrastructure (e.g., adding new services, changing services, or removing services) once everything is provisioned. In some cases, these two challenges can be addressed by enabling configuration that declaratively defines the infrastructure. In other words, the infrastructure (e.g., which components are needed and how they interact) can be defined by one or more profiles. Therefore, the overall topology of the infrastructure (e.g., which resources depend on other resources and how they work together) can be described declaratively. In some cases, once the topology is defined, workflows for creating and / or managing the different components described in the profiles can be generated.

[0066] According to embodiments, cloud infrastructure can have many interconnected elements. For example, there may be one or more Virtual Private Clouds (VPCs) (e.g., potential on-demand pools of configurable and / or shared computing resources), also known as the core network. In some examples, one or more inbound / outbound traffic group rules may also be provided to define how inbound / outbound traffic will be set up for one or more virtual machines (VMs) in the network. Other infrastructure elements, such as load balancers, databases, etc., may also be provided. The infrastructure can evolve incrementally as more and / or more infrastructure elements are expected and added.

[0067] According to embodiments, continuous deployment techniques can be employed to enable the deployment of infrastructure code across various virtual computing environments. Furthermore, the described techniques enable infrastructure management within these environments. In some examples, service teams may write code that is intended to be deployed to one or more, but typically many, different production environments (e.g., across various geographical locations). However, in some examples, the infrastructure on which the code will be deployed needs to be provisioned. In some cases, provisioning can be done manually, provisioning tools can be used to provision resources, and / or once the infrastructure is provisioned, deployment tools can be used to deploy the code.

[0068] Figure 3 The illustration shows an example cloud infrastructure architecture according to an embodiment.

[0069] like Figure 3 As shown, according to an embodiment, service operator 202 can communicatively couple to secure host lease 204, which may include virtual cloud network (VCN) 206 and secure host subnet 208.

[0070] In some examples, service operators may use one or more client computing devices, which may be portable handheld devices (e.g., telephones, computing tablets, personal digital assistants (PDAs)) or wearable devices (e.g., head-mounted displays), running software such as Microsoft Windows and / or various mobile operating systems (e.g., iOS, Android, etc.), and supporting the Internet, email, short message service (SMS), or other communication protocols. Alternatively, client computing devices may be general-purpose personal computers, including, for example, personal computers and / or laptops running various versions of Microsoft Windows®, Apple Macintosh®, and / or Linux operating systems. Client computing devices may be workstation computers running various commercially available UNIX® or UNIX-like operating systems, including but not limited to any of the various GNU / Linux operating systems (such as Chrome OS). Additionally or alternatively, client computing devices may be any other electronic device, such as thin client computers, Internet-enabled gaming systems (e.g., Microsoft Xbox game consoles), and / or personal messaging devices capable of communicating over networks with access to VCNs and / or the Internet.

[0071] According to an embodiment, the VCN may include a local peering gateway (LPG) 210, which may be communicatively coupled to a secure shell (SSH) VCN 212 via an LPG included in the SSH VCN. The SSH VCN may include an SSH subnet 214, and the SSH VCN may be communicatively coupled to a control plane VCN 216 via an LPG included in the control plane VCN. Furthermore, the SSH VCN may be communicatively coupled to a data plane VCN 218 via an LPG. The control plane VCN and the data plane VCN may be contained in a service lease 219 that may be owned and / or operated by a cloud infrastructure provider.

[0072] According to an embodiment, the control plane VCN may include a control plane demilitarized zone (DMZ) layer 220 that acts as a peripheral network (e.g., part of an enterprise network between an internal and external network). DMZ-based servers may have limited responsibility to help contain potential vulnerabilities. Furthermore, the DMZ layer may include one or more load balancer (LB) subnets 222, a control plane application layer 224 that may include one or more application subnets 226, and a control plane data layer 228 that may include one or more database (DB) subnets 230 (e.g., one or more front-end DB subnets and / or one or more back-end DB subnets). The one or more LB subnets included in the control plane DMZ layer may communicatively couple to the one or more application subnets included in the control plane application layer and to an Internet gateway 234 that may be included in the control plane VCN, and the one or more application subnets may communicatively couple to the one or more DB subnets included in the control plane data layer, as well as a service gateway 236 and a Network Address Translation (NAT) gateway 238. The control plane VCN may include a service gateway and a NAT gateway.

[0073] According to an embodiment, the control plane VCN may include a data plane mirror application layer 240, which may include one or more application subnets. The one or more application subnets included in the data plane mirror application layer may include a virtual network interface controller (VNIC) capable of executing compute instances. The compute instances may communicatively couple the one or more application subnets of the data plane mirror application layer to the one or more application subnets that may be included in the data plane application layer.

[0074] According to an embodiment, the data plane VCN may include a data plane application layer, a data plane DMZ layer, and a data plane data layer. The data plane DMZ layer may include one or more LB subnets communicatively coupled to one or more application subnets of the data plane application layer and the internet gateway of the data plane VCN. The one or more application subnets may be communicatively coupled to the service gateway and NAT gateway of the data plane VCN. The data plane data layer may also include one or more DB subnets communicatively coupled to one or more application subnets of the data plane application layer.

[0075] According to an embodiment, the internet gateways of the control plane VCN and the data plane VCN can be communicatively coupled to a metadata management service 252, which can be communicatively coupled to a public internet 254. The public internet can be communicatively coupled to a NAT gateway of the control plane VCN and the data plane VCN. The service gateways of the control plane VCN and the data plane VCN can be communicatively coupled to a cloud service 256.

[0076] According to an embodiment, the service gateway of the control plane VCN or data plane VCN can make application programming interface (API) calls to cloud services without traversing the public internet. API calls from the service gateway to the cloud service can be unidirectional; the service gateway can make API calls to the cloud service, and the cloud service can send requested data to the service gateway. Generally, the cloud service cannot initiate API calls to the service gateway.

[0077] According to one embodiment, a secure host lease can be directly connected to a service lease that might otherwise be isolated. A secure host subnet can communicate with an SSH subnet via an LPG, which enables bidirectional communication between otherwise isolated systems. Connecting a secure host subnet to an SSH subnet allows the secure host subnet to access other entities within the service lease.

[0078] According to embodiments, a control plane VCN can allow users of a service lease to set up or otherwise provision desired resources. The desired resources provisioned in the control plane VCN can be deployed or otherwise used in the data plane VCN. In some examples, the control plane VCN can be isolated from the data plane VCN, and the data plane mirror application layer of the control plane VCN can communicate with the data plane application layer of the data plane VCN via VNICs, which can be included in both the data plane mirror application layer and the data plane application layer.

[0079] According to an embodiment, users or clients of the system can make requests, such as create, read, update, or delete (CRUD) operations, via the public internet that can transmit requests to the metadata management service. The metadata management service can transmit the request to the control plane VCN via an internet gateway. The request can be received by one or more LB subnets contained in the control plane DMZ layer. The one or more LB subnets can determine that the request is valid, and in response to this determination, the one or more LB subnets can transmit the request to one or more application subnets contained in the control plane application layer. If the request is verified and requires a call to the public internet, the call to the internet can be transmitted to a NAT gateway that can make the call to the internet. The metadata to be stored by the request can be stored in one or more DB subnets.

[0080] According to an embodiment, the data plane mirroring application layer can facilitate direct communication between the control plane VCN and the data plane VCN. For example, it may be desirable to apply configuration changes, updates, or other suitable modifications to resources contained in the data plane VCN. With the help of the VNIC, the control plane VCN can communicate directly with the resources contained in the data plane VCN, and thus can perform configuration changes, updates, or other suitable modifications.

[0081] According to one embodiment, the control plane VCN and data plane VCN can be included in a service lease. In this case, the system's users or customers may not own or operate the control plane VCN or data plane VCN. Alternatively, the cloud infrastructure provider may own or operate both the control plane VCN and data plane VCN, both of which can be included in a service lease. This embodiment enables network isolation, which can prevent users or customers from interacting with the resources of other users or customers. Furthermore, this embodiment allows the system's users or customers to privately store databases without relying on the public internet for storage, which may not provide the desired level of threat protection.

[0082] According to one embodiment, one or more LB subnets included in the control plane VCN can be configured to receive signals from the serving gateway. In this embodiment, the control plane VCN and the data plane VCN can be configured to be invoked by customers of the cloud infrastructure provider without invoking the public internet. Customers of the cloud infrastructure provider may expect this embodiment because the database(s) used by the customer can be controlled by the cloud infrastructure provider and can be stored on a service lease that is isolated from the public internet.

[0083] Figure 4 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0084] like Figure 4 As shown, according to an embodiment, the data plane VCN may be included in customer lease 221. In this case, the cloud infrastructure provider may provide a control plane VCN for each customer, and the cloud infrastructure provider may establish a unique compute instance for each customer included in the service lease. Each compute instance may allow communication between the control plane VCN included in the service lease and the data plane VCN included in the customer lease. The compute instance may allow resources provisioned in the control plane VCN included in the service lease to be deployed or otherwise used in the data plane VCN included in the customer lease.

[0085] According to an embodiment, a cloud infrastructure provider's customer may have a database managed and operated within a customer lease. In this example, the control plane VCN may include a data plane mirror application layer, which may include one or more application subnets. The data plane mirror application layer may reside in the data plane VCN, but it may not be provided within the data plane VCN. That is, the data plane mirror application layer may access the customer lease, but it may not exist in the data plane VCN, or be owned or operated by the customer. The data plane mirror application layer may be configured to invoke the data plane VCN, but it cannot be configured to invoke any entity contained within the control plane VCN. A customer may expect to deploy or otherwise use resources provisioned in the control plane VCN within the data plane VCN, and the data plane mirror application layer may facilitate the customer's expected deployment or other use of resources.

[0086] According to one embodiment, a cloud infrastructure provider's customers can apply filters to a data plane VCN. In this embodiment, the customer can determine what the data plane VCN can access and can restrict access to the public internet from the data plane VCN. The cloud infrastructure provider may not be able to apply filters or otherwise control the data plane VCN's access to any external networks or databases. Applying filters and controls to the data plane VCN included in the customer's lease helps isolate the data plane VCN from other customers and the public internet.

[0087] According to embodiments, cloud services can be invoked by a service gateway to access services that may not exist on the public internet, the control plane VCN, or the data plane VCN. The connection between the cloud service and the control plane VCN or data plane VCN may not be contiguous. Cloud services can reside on different networks owned or operated by a cloud infrastructure provider. Cloud services can be configured to accept calls from the service gateway and can be configured not to accept calls from the public internet. Some cloud services may be isolated from other cloud services, and the control plane VCN may be isolated from cloud services that may not be in the same region as the control plane VCN.

[0088] For example, according to an embodiment, the control plane VCN may be located in "Region 1", and the cloud service "Deployment 1" may be located in both Region 1 and "Region 2". If a service gateway contained in the control plane VCN located in Region 1 makes a call to Deployment 1, then the call can be transmitted to Deployment 1 in Region 1. In this example, the control plane VCN or Deployment 1 in Region 1 may not be communicatively coupled to or otherwise communicate with Deployment 1 in Region 2.

[0089] Figure 5The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0090] like Figure 5 As shown, according to an embodiment, one or more trusted application subnets 260 can be communicatively coupled to a service gateway contained in a data plane VCN, a NAT gateway contained in a data plane VCN, and one or more database subnets contained in a data plane data layer. One or more untrusted application subnets 264 can be communicatively coupled to a service gateway contained in a data plane VCN and one or more database subnets contained in a data plane data layer. The data plane data layer may include one or more database subnets that can be communicatively coupled to a service gateway contained in a data plane VCN.

[0091] According to an embodiment, one or more untrusted application subnets may include one or more primary VNICs (1)-(N) communicatively coupled to tenant virtual machines (VMs). Each tenant VM may be communicatively coupled to a corresponding application subnet 267 (1)-(N) that may be contained in a corresponding container egress VCN 268 (1)-(N), which may be contained in a corresponding customer lease 270 (1)-(N). A corresponding secondary VNIC may facilitate communication between the one or more untrusted application subnets contained in the data plane VCN and the application subnets contained in the container egress VCN. Each container egress VCN may include a NAT gateway communicatively coupled to the public internet.

[0092] According to an embodiment, the public internet can communicatively couple to a NAT gateway contained in a control plane VCN and a data plane VCN. Service gateways contained in the control plane VCN and the data plane VCN can communicatively couple to cloud services.

[0093] According to an embodiment, the data plane VCN can be integrated with customer leases. This integration may be useful or desirable for cloud infrastructure provider customers where additional support may be required when executing code. For example, a customer may provide code to be run that may be potentially destructive, may communicate with other customer resources, or may otherwise cause undesirable effects.

[0094] According to an embodiment, a cloud infrastructure provider's customer can grant temporary network access to the cloud infrastructure provider and request functionality to be attached to the data plane application layer. The code running this functionality can execute within a VM, and this code may not be configured to run anywhere else on the data plane VCN. Each VM can be connected to a customer lease. The corresponding containers (1)-(N) contained within the VM can be configured to run the code. In this case, dual isolation can exist (e.g., containers running code, where the containers may be contained within at least one VM contained in an untrusted application subnet), which helps prevent incorrect or otherwise unintended code from corrupting the cloud infrastructure provider's network or the networks of different customers. Containers can be communicatively coupled to the customer lease and can be configured to transmit or receive data from the customer lease. Containers can be configured not to transmit or receive data from any other entity in the data plane VCN. After the code execution is complete, the cloud infrastructure provider can dispose of these containers.

[0095] According to an embodiment, one or more trusted application subnets may run code that can be owned or operated by a cloud infrastructure provider. In this embodiment, one or more trusted application subnets may be communicatively coupled to one or more database subnets and configured to perform CRUD operations within the one or more database subnets. One or more untrusted application subnets may be communicatively coupled to one or more database subnets and configured to perform read operations within the one or more database subnets. Containers that may be contained within each customer's VM and may run code from the customer may not be communicatively coupled to the one or more database subnets.

[0096] According to embodiments, the control plane VCN and data plane VCN may be coupled without direct communication, or there may be no direct communication between them. However, communication can occur indirectly, where the cloud infrastructure provider can establish an LPG that facilitates communication between the control plane VCN and the data plane VCN. In another example, either the control plane VCN or the data plane VCN can invoke cloud services via a service gateway. For example, an invocation of a cloud service from the control plane VCN may include a request for a service that can communicate with the data plane VCN.

[0097] Figure 6 The illustration shows another example of a cloud infrastructure architecture according to an embodiment.

[0098] like Figure 6As shown, according to an embodiment, one or more trusted application subnets may be communicatively coupled to a service gateway contained in the data plane VCN, a NAT gateway contained in the data plane VCN, and one or more database subnets contained in the data plane data layer. One or more untrusted application subnets may be communicatively coupled to a service gateway contained in the data plane VCN and one or more database subnets contained in the data plane data layer. The data plane data layer may include one or more database subnets that can be communicatively coupled to a service gateway contained in the data plane VCN.

[0099] According to an embodiment, one or more untrusted application subnets may include primary VNICs that are communicatively coupled to tenant virtual machines (VMs) residing within one or more untrusted application subnets. Each tenant VM may run code in a corresponding container and may be communicatively coupled to an application subnet that may be included in a data plane application layer, which may be included in a container egress VCN 280. Corresponding auxiliary VNICs 282(1)-(N) may facilitate communication between the one or more untrusted application subnets included in the data plane VCN and the application subnets included in the container egress VCN. The container egress VCN may include a NAT gateway that is communicatively coupled to the public internet.

[0100] According to an embodiment, an Internet gateway contained in a control plane VCN and a data plane VCN can be communicatively coupled to a metadata management service, which can be communicatively coupled to the public Internet. The public Internet can be communicatively coupled to a NAT gateway contained in both the control plane VCN and the data plane VCN. A service gateway contained in both the control plane VCN and the data plane VCN can be communicatively coupled to a cloud service.

[0101] According to an embodiment, Figure 6 The pattern shown can be regarded as Figure 5 This is an exception to the pattern shown, and it may be the pattern desired by customers if the cloud infrastructure provider cannot communicate directly with them (e.g., in a disconnected region). Customers have live access to the corresponding containers contained within each customer's VM. Containers can be configured to invoke appropriate secondary VNICs contained in one or more application subnets within the data plane application layer, which may be contained in the container's egress VCN. The secondary VNICs can then route the calls to a NAT gateway, which can then route the calls to the public internet. In this example, the containers that customers can access live can be isolated from the control plane VCN and from other entities contained within the data plane VCN. Containers can also be isolated from resources from other customers.

[0102] In other examples, customers can use containers to invoke cloud services. In this example, a customer can run code within a container that requests a service from the cloud service. The container can then forward the request to a secondary VNIC, which in turn forwards it to a NAT gateway, which in turn forwards it to the public internet. The public internet can then be used to forward the request via an internet gateway to one or more load balancer (LB) subnets contained within the control plane VCN. In response to determining that the request is valid, the LB subnets can forward the request to one or more application subnets, which in turn forward the request to the cloud service via a service gateway.

[0103] It should be recognized that the IaaS architecture depicted in the figures above may have components other than those depicted. Furthermore, the embodiments shown in the figures are merely some examples of cloud infrastructure systems that can be combined with embodiments of this disclosure. In some other embodiments, the IaaS system may have more or fewer components than shown in the figures, may combine two or more components, or may have different component configurations or arrangements.

[0104] In some embodiments, the IaaS system described herein may include a suite of application, middleware, and database service providers delivered to customers in a self-service, subscription-based, elastically scalable, reliable, highly available, and secure manner.

[0105] Private Tag Cloud Environment

[0106] According to an embodiment, a cloud infrastructure environment can be used to provide a dedicated cloud environment, such as one or more privately tagged cloud environments, for tenants of the cloud infrastructure environment to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment.

[0107] Figure 7 The illustration shows how a system according to an embodiment can provide a dedicated or private tagged cloud environment for use by tenants or customers of a cloud infrastructure environment.

[0108] like Figure 7 As shown, according to an embodiment, a cloud infrastructure provider (e.g., Oracle Cloud Infrastructure, OCI) may supply one or more private tag cloud (PLC) environments to a PLC operator 320 (e.g., an OCI customer operating as a reseller). The PLC operator / reseller can then customize and extend the private tag cloud for use by its customer 330 when accessing subscription-based software products, services, or other offerings associated with the cloud infrastructure environment.

[0109] For illustrative purposes, examples of such subscription-based products, services, or other offerings may include various Oracle cloud infrastructure software products, Oracle Fusion Applications products, or other types of products or services that allow customers to subscribe to use these products or services.

[0110] Figure 8 The illustration further illustrates the use of a privately labeled cloud domain by a tenant or customer of a cloud infrastructure environment, according to an embodiment.

[0111] like Figure 8 As shown, according to an embodiment, the system may include a cloud subscription service or component, referred to herein in some embodiments as an Oracle Cloud Subscription (OCS) service or component, which exposes one or more subscription management APIs for creating orders for joining new customers or initiating workflows for creating subscriptions and orchestrating billing and pricing services or other components for the PLC Domain 400.

[0112] According to an embodiment, when a PLC operator or its customer requests a private tagged cloud environment, the system creates a PLC domain for use within the PLC region, along with leases owned by one or more providers. These leases (e.g., Oracle OCI) allow the region to operate using its required service infrastructure and are managed by the cloud infrastructure provider.

[0113] According to an embodiment, the first step in this process is to create an operator lease for the PLC operator, and then transfer the region and associated domains to the PLC operator for subsequent management. The PLC operator then becomes the administrator of the lease, able to view and manage everything that happens within the region, including its customer accounts and those customers' use of cloud resources.

[0114] Generally, once a region is handed over or provided to a PLC operator, the cloud infrastructure provider cannot subsequently access the data within the operator's lease unless the operator authorizes the cloud infrastructure provider to do so, for example, to provide troubleshooting for any problems that may arise.

[0115] According to an embodiment, the PLC operator can then create additional internal leases intended for its own internal use, such as for evaluating the end-customer experience, providing sales demonstration leases, or operating a database for its own internal use. The operator can also create one or more customer leases, with the end customer acting as its administrator. Cloud infrastructure usage metrics (e.g., compute usage, storage usage, and usage of other infrastructure resources) can be aggregated by the operator to reflect usage by both the operator and customers. Cloud infrastructure usage can be reported to the cloud infrastructure provider.

[0116] According to embodiments, a user interface or console may be provided that allows PLC operators to manage their customer accounts and customer-supplied services. Cloud infrastructure providers may also use cloud infrastructure leasing (e.g., converged application leasing) to install any required infrastructure services for use by operators and their customers.

[0117] Figure 9 The illustration further illustrates the use of a privately labeled cloud domain by a tenant or customer of a cloud infrastructure environment, according to an embodiment.

[0118] like Figure 9 As shown in the example, according to an embodiment, the Oracle Cloud Subscription (OCS) service or component exposes one or more subscription management APIs for creating orders for joining new customers or initiating workflows to create subscriptions and orchestrate billing and pricing services or other components.

[0119] According to an embodiment, the system may also include a billing service or component that operates on a logical container for billing accounts or subscriptions and preferences used to generate invoices for customers.

[0120] According to an embodiment, the system may also include a subscription pricing service (SPS) or component that operates on a product catalog defining the products that customers can purchase. The subscription pricing service may also be used to provide a price list (e.g., a rate card) that is also available through the pricing service.

[0121] According to an embodiment, to support sales processing through the creation of subscriptions within the PLC domain, products can be selected from the product hub. Once an order is created, a subscription is created in the OCS, which then manages the subscription's lifecycle and supplies the content required for downstream services. The SPS component then manages pricing and usage aspects for the ability to collect final fees from the PLC operator or for the operator to charge its customers. Usage events are forwarded to the billing service or component, where, depending on the subscription's billing preferences, an invoice is created and pushed to the accounts receivable component.

[0122] According to an embodiment, although the services provided in the field report their usage to a metering service or component, such usage does not have any associated price. Billing processing, for example, determines the cost of each specific event by applying a rate card, determines the unit and cost of the subscription, associates the cost with the record, and then forwards it to the billing service or component.

[0123] like Figure 9As further illustrated, according to an embodiment, a PLC operator can control multiple domains A and B. For example, an operator operating in multiple countries might wish to operate a data center completely isolated from the United States, and a separate data center completely isolated from Europe, for example, to meet governance or regulatory requirements. According to an embodiment, usage associated with these multiple domains can be aggregated for billing the operator.

[0124] The examples of the various systems provided above are intended to illustrate computing environments that can be used to provide dedicated or privately tagged cloud environments for tenants of cloud infrastructure to use when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.

[0125] Private tag cloud subscription

[0126] Figure 10 The illustration depicts a system according to an embodiment for providing access to software products or services in a cloud computing or other computing environment.

[0127] like Figure 10 As shown, according to an embodiment, the system can be provided as a cloud computing or other computing environment, referred to herein as a platform in some embodiments, which supports the use of subscription-based products, services or other offerings.

[0128] Examples of such subscription-based products, services, or other offerings may include various Oracle Cloud Infrastructure (OCI) software products, Oracle Fusion Applications products, or other types of products or services that allow customers to subscribe to use these products or services.

[0129] According to embodiments, subscriptions may include artifacts such as products, commitments, billing models, and states. The OCS service may expose one or more subscription management APIs for creating orders for joining new customers or initiating workflows to create subscriptions and orchestrate appropriate footprints in the billing and pricing services or components, as further described below.

[0130] According to an embodiment, a billing service or component operates on a logical container of billing accounts or subscriptions and preferences used to generate invoices. Each billing account generates one or more invoices per billing period. The billing service includes a first pipeline that receives usage and costs from a metering service or component. Usage can be received via a REST API or other interface. The billing service writes the usage to a database from which the billing service or other services can calculate and aggregate balances. The billing service may include a second pipeline responsible for obtaining aggregated usage and commitments and calculating costs for one or more billing intervals.

[0131] According to an embodiment, a subscription pricing service (SPS) or component operates on a product catalog that defines the products a customer can purchase. The product catalog forms the backbone of a price list (i.e., rate cards) also owned by the pricing service. Rate cards are modeled as pricing rules on top of publicly listed prices. The pricing service maintains a single price list for each product; new product prices can be added, and existing prices can be changed. The price lists have a complete history, with the latest version being the current rate card. Because some contracts may require snapshots of the rate cards, the pricing service handles this by recording when a customer's rate card was created and then querying the price list at that time.

[0132] According to embodiments, the SPS or pricing service is responsible for providing information about products, a global price list, and end-customer subscription-specific price lists and discounts. For example, according to embodiments, the SPS can synchronize product information from the Oracle Fusion Product Hub and a global price list from the Oracle Fusion Pricing Hub.

[0133] According to the embodiment, the OCS service operates as an upstream service to receive new order requests, for example, from the Oracle Fusion Order Management environment. The OCS service can provide subscription information to the SPS service. Subscription details such as the timing of the quote, configuration, and subscription type (commitment, PayG) help the SPS determine the effective base price (rate card) for the subscription. The OCS service can also send subscription discounts, for example, received from Oracle Fusion Order Management, which the SPS stores as a pricing rule entity.

[0134] In one embodiment, the SPS service runs as a background process to manage a rate card service or component responsible for generating rate cards for new subscriptions and updating them when prices change. The SPS service can expose APIs to access rate cards and pricing rules. The metering inline billing engine can leverage these APIs to obtain subscription-specific rate cards and pricing rules and use this data for cost calculations.

[0135] According to an embodiment, additional SPS components may include, for example, the Pricing / Product Hub Oracle Integration Cloud (OIC) integration component, which allows PLC operator entities to manage, for example, their product and price lists provided by the Oracle Fusion Product Hub and the Oracle Fusion Pricing Hub, respectively, within the environment to offer subscription-based products, services, or other offerings.

[0136] For example, according to this embodiment, the SPS OIC product integration process can listen for creation / update events in the product hub and invoke the SPS product API. Similarly, the SPS OIC pricing integration process can retrieve new price list creation from the pricing hub and invoke the corresponding SPS pricing API.

[0137] According to one embodiment, the system may also include an SPS core module that provides APIs for managing and accessing pricing entities. Pricing can be accessed through internal services, such as an inline billing engine.

[0138] According to an embodiment, the system may also include a rate card manager component. The SPS service maintains a single base price for a product at a given time. However, the price of a subscribed product depends on the base price at the time of the quote configuration and the subscription's price list change policy attributes. The SPS service uses these attributes to internally maintain the prices to be used for subscriptions. These price lists are grouped in rate cards. The rate card manager can create and maintain rate cards, as well as listen for price list changes and update existing rate cards with the new prices. It also listens for new subscriptions and assigns rate cards based on subscription properties.

[0139] According to an embodiment, the system may also include a rule decoder engine. The SPS service is responsible for managing the pricing rules for subscriptions, including discounts offered to end customers. Pricing rule applicability can be based on product attributes such as discount groups, product categories, or specific SKUs. Internally, the SPS needs to identify a list of products to which these rules will apply. To achieve this, the rule decoder engine can compile the pricing rules into a format that the inline billing engine can use for cost calculations. This compilation process can be triggered when a product or pricing rule is created / updated.

[0140] If passed Figure 10As illustrated in the example, according to the embodiment: At 441, product and pricing information, such as that managed in a converged application, is sent to the SPS component. At 442, an order is sent to the OCS component to create a subscription, rate card, and billing account. At 443, the pricing configuration and pricing rules for the new order are sent to the SPS. At 444, the OCS is used to establish a billing account in the billing service or component. At 445, the OCS publishes an event to the OCI streaming component. At 446, fee data is sent to the Accounts Receivable component to generate an invoice. At 447, the OCS uses Recycling and Subscription Lifecycle (RASL) events from the OCI streaming component. At 448, the activation service reads the OCS event stream. At 449, the customer retrieves activation data from the portal. At 450, the Lease Lifecycle Service provisiones the lease as part of the subscription activation. At 451, the Lease Lifecycle Service creates an account footprint during account provisioning. At 452, the Lease Lifecycle Service sets a limit template during account provisioning. At 453, the account component acts as a downstream RASL client to handle legacy repossession. At 454, aggregated costs and usage are sent to the billing service or component. At 455, organizations can create subleases using the lease lifecycle service. At 456, the metering service or component retrieves subscription mapping data. At 457, the subscription service retrieves organizational data used for subscription mapping. At 458, RASL reads the OCS event stream. At 459, the subscription service reads the OCS event stream; and at 460, the metering service or component retrieves rate card data for each subscription, which can then be used to collect final charges from PLC operators or enable PLC operators to charge their customers.

[0141] The examples provided above are intended to illustrate computing environments that can be used to provide dedicated or privately tagged cloud environments for use by tenants of cloud infrastructure when accessing subscription-based software products, services, or other provisioning items associated with the cloud infrastructure environment. According to other embodiments, the various components, processes, and features described herein can be used with other types of cloud computing environments.

[0142] 3. Service Upgrade System Architecture

[0143] Figure 11A and Figure 11B A system 1100 according to one or more embodiments is illustrated. For example... Figure 11A As shown, system 1100 includes interface 1102, service provider system 1104, and upgrade ticket processing component 1140. Service provider system 1104 may include or access data storage 1120. In one or more embodiments, system 1100 may include a... Figure 11A The components shown may have more or fewer components. Figure 11AThe components shown can be located locally or remotely to each other. Figure 11A The components shown can be implemented using software and / or hardware. Each component can be distributed across multiple applications and / or machines. Multiple components can be combined into a single application and / or machine. Operations described for one component can be performed by another component.

[0144] In one or more embodiments, service provider system 1104 refers to hardware and / or software configured to perform the operations described herein for redacting service tickets from one service provider to another. Examples of the operations for redacting service tickets will be referenced below. Figure 7 Describe it.

[0145] Service provider system 1104 may be owned and / or operated by an initial service provider entity. In one or more embodiments, the initial service provider entity is a company, organization, enterprise, or other entity that provides services to a customer entity. Services may include, for example, providing access to software and / or hardware in a cloud service. In one or more embodiments, when an aspect of the service causes a problem for the customer that the initial service provider entity cannot resolve, the initial service provider entity provides customer support to the customer entity. The customer affected by the problem may be referred to herein as affected entity 1101.

[0146] When a problem occurs due to the use of the service, the affected entity can create an initial service ticket 1130. The initial service ticket 1130 may include one or more problem attributes 1132. Problem attributes 1132 may include information describing the problem, such as an error code, a textual description of the problem, information identifying the hardware components and / or software versions used when the problem occurred, and / or other conditions and settings present at the time of the problem. Problem attributes 1132 may also include access-restricted attributes 1134. Access-restricted attributes 1134 may include information identifying the affected entity, confidential information of the affected entity, geographically restricted information, politically restricted information, or any other information that the affected entity does not wish to be accessed by entities other than the affected entity and the initial service provider.

[0147] The service provider system 1104 may include one or more functional components, such as an initial work order processing component 1110. The initial work order processing component 1110 may include one or more functional components, such as an upgrade engine 1112, an editor 1114, and an optional intermediate service work order creator 1116.

[0148] The initial service order processing component 1110 can receive an initial service order 1130 via interface 1102. The escalation engine 1112 can examine the issue attributes 1132 to determine if the issue can be resolved by the initial service provider 1105 or if a higher-level service provider 1107 is required. The escalation engine 1112 can apply a machine learning model 1126 trained on training data 1128 to the initial service order 1130 to determine if the issue needs to be escalated to a higher-level service provider. The machine learning model 1126 and the training data 1128 are described in Part 5, titled “Machine Learning” below.

[0149] When upgrade engine 1112 determines that initial service ticket 1130 needs to be upgraded, initial service ticket processing component 1110 can use editor 1114 to create upgraded service ticket 1122. Upgraded service ticket 1122 may include problem attributes sufficient to identify the issue, while omitting any identifying, confidential, or otherwise sensitive attributes of the affected entity. In one or more embodiments, upgraded service ticket 1122 may have a different format than initial service ticket 1130, for example, if a higher-level service provider uses a different service ticket management system than service provider system 1104. Editor 1114 may apply a machine learning model 1126 trained on training data 1128 to initial service ticket 1130 to determine which information to remove or anonymize from initial service ticket. In one or more embodiments, upgraded service ticket 1122 is an anonymized version of initial service ticket 1130. This may occur when the set of access-restricted attributes 1134 includes an identifier corresponding to the affected entity that is subsequently excluded from upgraded service ticket 1122.

[0150] In one or more embodiments, when the upgrade engine 1112 determines that the initial service ticket 1130 requires an upgrade, the initial service ticket processing component 1110 can use the intermediate service ticket creator 1116 and the editor 1114 to generate an intermediate service ticket 1124. The intermediate service ticket 1124 may include problem attributes sufficient to identify the problem, while omitting any identifying, confidential, or otherwise sensitive attributes of the affected entity. The intermediate service ticket 1124 adopts the same format as the initial service ticket 1130 for use within the service provider system 1104. In one or more embodiments, the affected entity does not have access to the intermediate service ticket.

[0151] Initial service tickets, intermediate service tickets, and escalation service tickets can each include references that index each other. For example, if an initial service ticket includes a unique identifier, then an intermediate service ticket can have its own unique identifier and a reference to the unique identifier of its corresponding initial service ticket. Similarly, an escalation service ticket can include references to the initial service ticket, intermediate service tickets, or both. This allows information related to the issue to be communicated between systems when a higher-level service provider cannot access an intermediate or initial service ticket, and the affected entity and the initial service provider cannot access the escalation service ticket.

[0152] A higher-level service provider can control and operate the upgrade ticket processing component 1140. The upgrade ticket processing component 1140 can be configured to receive an upgrade service ticket 1122 from the service provider system 1104. The higher-level service provider determines how to resolve the issue raised in the upgrade service ticket 1122. If possible, the higher-level service provider can resolve the issue and update the upgrade service ticket 1122 to reflect that the issue has been resolved. If the higher-level service provider cannot resolve the issue, then the higher-level service provider can update the upgrade service ticket 1122 with instructions on how to resolve the issue for use by the initial service provider or the affected entity. The upgrade ticket processing component 1140 can then either return the updated upgrade service ticket 1122 to the initial service provider or return information indexed to the upgrade service ticket 1122.

[0153] In one or more embodiments, data storage 1120 is any type of storage unit and / or device for storing data (e.g., file system, database, collection of tables, or any other storage mechanism). Additionally, data storage 1120 may include multiple different storage units and / or devices. These multiple different storage units and / or devices may or may not be of the same type, or may or may not be located at the same physical site. Furthermore, data storage 1120 may be implemented or executed on the same computing system as service provider system 1104. Alternatively or additionally, data storage 1120 may be implemented or executed on a computing system separate from service provider system 1104. Data storage 1120 may be coupled to service provider system 1104 via a direct connection or via network communication.

[0154] Information describing service requests, machine learning models, and machine learning training data can be implemented in any component within system 1100. However, for clarity and explanation purposes, this information is illustrated as residing in data storage 1120.

[0155] In this embodiment, system 1100 is implemented on one or more digital devices. The term "digital device" generally refers to any hardware device that includes a processor. A digital device can refer to a physical device that executes an application or a virtual machine. Examples of digital devices include computers, tablets, laptops, desktops, netbooks, servers, web servers, network policy servers, proxy servers, general-purpose machines, function-specific hardware devices, hardware routers, hardware switches, hardware firewalls, hardware network address translation (NAT), hardware load balancers, mainframes, televisions, content receivers, set-top boxes, printers, mobile handheld terminals, smartphones, personal digital assistants (PDAs), wireless receivers and / or transmitters, base stations, communication management equipment, routers, switches, controllers, access points, and / or client devices.

[0156] In one or more embodiments, interface 1102 refers to hardware and / or software configured to facilitate communication between a user (e.g., an affected entity) and service provider system 1104. Interface 1102 renders user interface elements and receives input via these elements. Examples of interfaces include graphical user interfaces (GUIs), command-line interfaces (CLIs), haptic interfaces, and voice command interfaces. Examples of user interface elements include checkboxes, radio buttons, drop-down lists, list boxes, buttons, toggle switches, text fields, date and time pickers, command lines, sliders, pages, and forms. Interface 1102 may include an interface that allows a user from an affected entity to create an initial service ticket and submit it to an initial service provider. Interface 1102 may include an interface that allows a user from an affected entity to view the status of submitted initial service tickets, including when the initial service ticket has been resolved.

[0157] In this embodiment, different components of interface 1102 are specified using different languages. The behavior of user interface elements is specified using a dynamic programming language such as JavaScript. The content of user interface elements is specified using a markup language such as Hypertext Markup Language (HTML) or XML User Interface Language (XUL). The layout of user interface elements is specified using a stylesheet language such as Cascading Style Sheets (CSS). Alternatively, interface 1102 may be specified using one or more other languages ​​such as Java, C, or C++.

[0158] Figure 11BThe illustration shows an example where a higher-level service provider (Entity A) is a cloud service provider supplying cloud computing resources, enabling Entity A's customers (e.g., the initial service provider (Entity B)) to provide their own cloud services. Entity B uses Entity A's cloud computing resources to provide cloud services to customer C. Entity B's leases (including the initial ticket processing component 1110) and customer C's leases reside in premises owned and controlled by Entity B.

[0159] Entity A owns a lease within a geographic region containing Entity B, which allows Entity A to provide upgrade services for its cloud service computing resources. The upgrade ticket processing component 1140 can reside within the lease owned by Entity A. Entity A has no access to Entity B's lease or Customer C's lease. Similarly, Entity B and Customer C also have no access to Entity A's lease.

[0160] In one or more embodiments, a higher-level service provider may have an intermediate service ticket processing component 1118. The intermediate service ticket processing component 1118 may periodically poll or request any new intermediate service tickets from the initial service provider. When a new intermediate service ticket is found, the intermediate service ticket processing component 1118 may generate an upgraded service ticket and provide the upgraded service ticket to the upgraded service ticket processing component 1140.

[0161] 4. Escalate the service ticket to a third party.

[0162] Figure 12 The illustration depicts a set of example operations for escalating and revising an initial service ticket to a higher-level service provider, according to one or more embodiments. Figure 12 One or more operations shown can be modified, rearranged, or omitted entirely. Therefore, Figure 12 The specific order of operations shown should not be construed as limiting the scope of one or more embodiments.

[0163] In one or more embodiments, the system receives an initial service ticket (operation 1202) from an affected entity to resolve the problem identified by the initial service ticket. For example, a user at the affected entity can interact with a service request application provided by the initial service provider to provide information about the problem. The service request application can create an initial service ticket and submit it to the service provider system via an interface.

[0164] In one or more embodiments, the system determines whether the problem needs to be escalated (operation 1204). The system may input an initial service ticket into an escalation machine learning model, which processes the initial service ticket and outputs a determination as to whether the problem identified in the initial service ticket is one that needs to be escalated.

[0165] In one or more embodiments, when the problem does not require escalation, the initial service provider resolves the problem and updates the initial service ticket (operation 1206). The system may forward the initial service ticket to the appropriate service personnel or an automated remediation system for resolution. The system may update the initial service ticket, for example, by changing the status field in the initial service ticket to "Resolved," by changing the Boolean field corresponding to the resolved status from false to true, or by otherwise indicating that the problem has been resolved. The system may also include notes or other instructions regarding any steps taken to resolve the problem, such as installing updates or replacing hardware components. Users at the affected entity can check the status of the initial service ticket via an interface to see if the problem has been resolved.

[0166] In one or more embodiments, when an issue does require escalation, the system generates an escalation service ticket (operation 1208) based on the initial service ticket. The system may create a copy of the initial service ticket and edit or anonymize access-restricted attributes from the copy to create the escalation service ticket. Alternatively, the system may create a new escalation ticket and copy or map the issue attributes from the initial service ticket to the escalation service ticket without copying the access-restricted attributes to the escalation service ticket.

[0167] The system can use a work order escalation machine learning model to generate intermediate service work orders and / or escalation work orders based on initial or intermediate service work orders. The work order escalation machine learning model can be trained to identify and exclude access-restricted attributes from the initial service work order when generating intermediate and / or escalation service work orders. The work order escalation machine learning model can also be trained to create escalation service work orders using a format used by higher-level services.

[0168] In one or more embodiments, the system transmits the upgraded service ticket to a higher-level service provider (operation 1210). The system may then place the upgraded service ticket into a queue in the higher-level service provider system. In some embodiments, the higher-level service provider system may pull or query any new upgraded service tickets from the initial service provider system.

[0169] In one or more embodiments, the system receives information corresponding to the resolution of the problem from a higher-level service provider (operation 1212). For example, an escalation service ticket may be returned to the system with updates indicating the status of the problem resolution or other fields. This information may include notes or other descriptions about the steps taken to resolve the problem (such as software updates or hardware repairs or replacements). This information may be received without an escalation service ticket, for example, as a file or other data structure indexed to an escalation service ticket.

[0170] In one or more embodiments, the system processes the initial service ticket (operation 1214) based on information corresponding to the resolution of the problem. The system can use an index from escalated service tickets to intermediate service tickets or initial service tickets to identify which initial service ticket has been resolved. The system then updates the initial service ticket to reflect the resolution.

[0171] 5. Machine Learning

[0172] Detailed examples are described below for clarity. The components and / or operations described below should be understood as specific examples and may not be applicable to some embodiments. Therefore, the components and / or operations described below should not be construed as limiting the scope of any claim.

[0173] Figure 13 The illustration depicts a machine learning process according to one or more embodiments. A machine learning model 1344 can be iteratively trained on initial training data 1310 to map a set of input variables to output variables. For an upgrade machine learning model, the initial training data 1310 may include one or more sets of initial service tickets, which are labeled based on whether the issues raised in the initial service tickets have been upgraded. For an upgrade service ticket generation machine learning model, the initial training data may include one or more sets of initial service tickets and their corresponding intermediate service tickets and / or upgrade service tickets.

[0174] Once initially trained, the upgrade machine learning model can be applied to input ticket 1302 (which can be an initial service ticket), and output 1304 can be a label or other indication that the initial service ticket should be upgraded or not. For the upgrade ticket generation machine learning model, input ticket 1302 can be an initial service ticket or an intermediate service ticket, and the upgrade ticket generation machine learning model can output an intermediate service ticket or an upgraded service ticket.

[0175] The training data can be updated based on feedback 1306, for example, regarding the accuracy of the current machine learning model 1344. The updated training data 1312 is then fed back into the machine learning algorithm, which in turn updates the machine learning model 1344.

[0176] Machine learning model 1344 is trained such that it best fits the training data dataset to the labels or outputs of the training data. Additionally or alternatively, machine learning model 1344 is trained such that when applied to the training data dataset, the maximum number of results determined by the model match the labels or outputs of the training data. Different target models can be generated based on different machine learning algorithms and / or different training datasets.

[0177] Machine learning algorithms can include supervised and / or unsupervised components. Various types of algorithms can be used, such as linear regression, logistic regression, linear discriminant analysis, classification and regression trees, Naive Bayes, k-nearest neighbors, learned vector quantization, support vector machines, bagging and random forests, boosting, backpropagation, and / or clustering.

[0178] 6. Practical applications, advantages, and improvements

[0179] In one or more embodiments, the system described herein enables an entity providing services to a customer to escalate a service problem that it cannot resolve to another third-party entity without exposing customer data or identification information to a third party.

[0180] 7. Other matters; extension

[0181] Unless otherwise defined, all terms (including technical and scientific terms) shall be given the meanings that are common and customary to those skilled in the art, and are not limited to special or customary meanings, unless otherwise expressly defined herein.

[0182] This application may include references to certain trademarks. While the use of trademarks is permitted in a patent application, the exclusivity of the trademark should be respected, and every effort should be made to prevent the trademark from being used in any way that may adversely affect its validity.

[0183] The embodiments are directed to a system having one or more devices, which include a hardware processor and are configured to perform any of the operations described herein and / or recited in any of the following claims.

[0184] In an embodiment, one or more non-transitory computer-readable storage media include instructions that, when executed by one or more hardware processors, cause to perform any operation described herein and / or recited in any of the claims.

[0185] In an embodiment, a method includes the operations described herein and / or recited in any of the claims, the method being performed by at least one device including a hardware processor.

[0186] Any combination of the features and functions described herein may be used according to one or more embodiments. In the foregoing description, embodiments have been described with reference to numerous specific details that may vary depending on the implementation. Therefore, the description and drawings should be considered illustrative rather than restrictive. The sole and exclusive measure of the scope of this disclosure, and what the applicant intends to define as the scope of this disclosure, is the literal and equivalent scope of the set of claims issued in this application, in the specific form of such claims, including any subsequent corrections.

Claims

1. One or more non-transitory computer-readable media comprising instructions that, when executed by one or more hardware processors, cause performance of operations comprising: at an initial service provider, receiving, from an affected entity affected by a problem identified by an initial service ticket, an initial service ticket for resolution of the problem, wherein the initial service ticket includes a set of access-restricted attributes of the affected entity, the set of access-restricted attributes including one or more attributes; based on the initial service ticket, generating, at the initial service provider, an escalated service ticket identifying escalation of the problem, wherein the escalated service ticket does not include the set of access-restricted attributes of the affected entity; transmitting the escalated service ticket to a higher-tier service provider, wherein the higher-tier service provider is not authorized to access the set of access-restricted attributes included in the initial service ticket; in response to transmitting the escalated service ticket: receiving, from the higher-tier service provider, information corresponding to resolution of the problem; and processing the initial service ticket based on the information corresponding to resolution of the problem.

2. The one or more non-transitory computer-readable media of claim 1, wherein the escalated service ticket is an anonymized version of the initial service ticket, and wherein the set of access-restricted attributes included in the initial service ticket but not included in the escalated service ticket includes an identifier corresponding to the affected entity.

3. The one or more non-transitory computer-readable media of claim 1, wherein generating the escalated service ticket comprises: generating a feature vector based on (a) the initial service ticket or (b) an intermediate service ticket generated based on the initial service ticket; and applying a machine learning model to the feature vector to generate the escalated service ticket.

4. The one or more non-transitory computer-readable media of claim 1, wherein generating the escalated service ticket based on the initial service ticket comprises: obtaining an intermediate service ticket generated by redacting information from the initial service ticket; and generating the escalated service ticket based on the intermediate service ticket, wherein the higher-tier service provider is not permitted and cannot access the initial service ticket or the intermediate service ticket.

5. The one or more non-transitory computer-readable media of claim 1, the operations further comprising: generating a feature vector based on the initial service ticket; applying an escalation machine learning model to the feature vector to determine that the problem identified in the initial service ticket requires escalation to the higher-tier service provider; and in response to the determination, generating the escalated service ticket.

6. The one or more non-transitory computer-readable media of claim 1, wherein the affected entity is not permitted and cannot access the escalated service ticket.

7. The one or more non-transitory computer-readable media of claim 1, wherein the initial service ticket uses a first format and the escalated service ticket uses a second format.

8. A method comprising the operations of any of claims 1-7.

9. A system comprising at least one device including a hardware processor, the system configured to perform the operations of any of claims 1-7. ​ ​ 10. A system comprising means for performing the operations of any of claims 1-7.