Invention Grant
- Patent Title: Distributed policy enforcement with verification mode
- Patent Title (中): 分布式策略执行与验证模式
-
Application No.: US12961182Application Date: 2010-12-06
-
Publication No.: US09258312B1Publication Date: 2016-02-09
- Inventor: Kevin O'Neill , Mark Cavage
- Applicant: Kevin O'Neill , Mark Cavage
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Kilpatrick Townsend & Stockton LLP
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06 ; G06F21/62

Abstract:
User-specified policies may be efficiently implemented and enforced with a distributed set of policy enforcement components. User-specified policies may be transformed into a normal form. Sets of normal form policies may be optimized. The optimized policies may be indexed and/or divided and provided to the distributed set of policy enforcement components. The distributed policy enforcement may have a sandbox mode and/or verification mode enabling policy configuration verification. With appropriate authorization, substitute data may be used in verification mode to evaluate requests with respect to policies. Evaluation results, relevant policies, and decision data utilized during request evaluation may be collected, filtered and reported at a variety of levels of detail. Originating user-specified policies may be tracked during the policy normalization process to enable reference to user-specified policies in verification mode reports.
Information query