Multi-Cloud Control Plane for Cross-Provider Identity Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud environments provide closed ecosystems, restricting customers to using services only within their own cloud environment, with no easy way to access services from different cloud providers.

Innovation Solution

A multi-cloud control plane (MCCP) framework allows users to access services from a different cloud environment, providing a user experience similar to their native environment, by creating a tenancy and a link-resource object that links the user's account across cloud environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud environments provide closed ecosystems for their customers, then service security and management control are improved, but service accessibility and customer flexibility deteriorate

Engineering Contradiction:
Improveservice securityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a link-resource object as an intermediary entity that connects users from one cloud environment to services in another cloud environment. This link-resource object contains identification information of both the user and the service, enabling cross-cloud access while maintaining the closed ecosystem structure of each individual cloud provider. The intermediary allows service accessibility to improve without compromising the security and management control of the original closed ecosystems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If cloud environments restrict customers to using only their own services, then service management complexity is reduced, but customer productivity and service utilization deteriorate

Engineering Contradiction:
Improveservice management complexityVSAvoidcustomer productivity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The link-resource object serves multiple functions: it identifies the user, identifies the service, establishes the connection between them, and enables cross-cloud access. This multi-functional approach allows customers to access services from different cloud environments without adding significant management complexity. The universal link-resource mechanism enables customers to utilize services across multiple clouds, thereby improving productivity while keeping the management interface relatively simple.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Stability of the object's composition

If cloud environments maintain isolated ecosystems, then service stability and provider control are improved, but service integration capability and customer flexibility deteriorate

Engineering Contradiction:
Improveservice stabilityVSAvoidservice integration capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent segments the cross-cloud access mechanism into distinct components: the link-resource object (containing identification information) and the service access interface. This segmentation allows each cloud environment to maintain its stable, isolated ecosystem internally while enabling controlled external connections through the standardized link-resource segment. The segmentation approach preserves service stability within each cloud while improving integration capability between clouds.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250247382A1Propagating identities across different cloud service providers
Publication Date: 2025.07.31 ORACLE INT CORP
  • US20250247382A1 patent drawing
  • US20250247382A1 patent drawing
  • US20250247382A1 patent drawing

AI summary

Techniques are described for providing a multi-cloud control plane (MCCP) in a first cloud infrastructure (included in a first cloud environment provided by a first cloud services provider) that enables services and/or resources provided in the first cloud infrastructure to be utilized by users of a second cloud environment. The first cloud infrastructure receives a request from a user associated with an account in the second cloud infrastructure. The request corresponding to using a service provided by the first cloud infrastructure. A tenancy is created for the user in the first cloud infrastructure to enable the user to utilize the service, and a link-resource object is created that includes information linking the tenancy of the user in the first cloud infrastructure to the account of the user in the second cloud infrastructure, the link-resource object enabling the user to utilize the service provided by the first cloud infrastructure.