Patent · US Active

Method and apparatus for authorizing microservice APIs

US11258824B1 · kind B1 · utility

33Cited by
22References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 31, 2018
Grant dateFeb 22, 2022
Priority date
Expiry dateJan 29, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/08
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

Some embodiments of the invention provide a system for defining, distributing and enforcing policies for authorizing API (Application Programming Interface) calls to applications executing on one or more sets of associated machines (e.g., virtual machines, containers, computers, etc.) in one or more datacenters. This system has a set of one or more servers that acts as a logically centralized resource for defining and storing policies and parameters for evaluating these policies. The server set in some embodiments also enforces these API-authorizing policies. Conjunctively, or alternatively, the server set in some embodiments distributes the defined policies and parameters to policy-enforcing local agents that execute near the applications that process the API calls. From an associated application, a local agent receives API-authorization requests to determine whether API calls received by the application are authorized. In response to such a request, the local agent uses one or more parameters associated with the API call to identify a policy stored in its local policy storage to evaluate whether the API call should be authorized. To evaluate this policy, the agent might also retr…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.