Invention Grant
- Patent Title: Method and apparatus for specifying API authorization policies and parameters
-
Application No.: US16050130Application Date: 2018-07-31
-
Publication No.: US10592302B1Publication Date: 2020-03-17
- Inventor: Timothy L. Hinrichs , Teemu Koponen , Andrew Curtis , Torin Sandall , Octavian Florescu
- Applicant: Styra, Inc.
- Applicant Address: US CA Redwood City
- Assignee: STYRA, INC.
- Current Assignee: STYRA, INC.
- Current Assignee Address: US CA Redwood City
- Agency: Adeli LLP
- Main IPC: G06F9/54
- IPC: G06F9/54 ; H04L29/06 ; G06F16/11 ; G06F16/185

Abstract:
Some embodiments of the invention provide a system for defining, distributing and enforcing policies for authorizing API (Application Programming Interface) calls to applications executing on one or more sets of associated machines (e.g., virtual machines, containers, computers, etc.) in one or more datacenters. This system has a set of one or more servers that acts as a logically centralized resource for defining and storing policies and parameters for evaluating these policies. The server set in some embodiments also enforces these API-authorizing policies. Conjunctively, or alternatively, the server set in some embodiments distributes the defined policies and parameters to policy-enforcing local agents that execute near the applications that process the API calls. From an associated application, a local agent receives API-authorization requests to determine whether API calls received by the application are authorized. In response to such a request, the local agent uses one or more parameters associated with the API call to identify a policy stored in its local policy storage to evaluate whether the API call should be authorized. To evaluate this policy, the agent might also retrieve one or more parameters from the local policy storage.
Information query