IP Library Granted Patent US 9,027,039
Granted Patent B2
US 9,027,039 · App. 12/011,956 · Granted May 5, 2015

Methods for analyzing, limiting, and enhancing access to an internet API, web service, and data

Inventors: Oren Michels (Lafayette, CA); Clay Loveless (Fremont, CA)
Assignee: Intel Corporation
G06F15/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,027,039
App. No.
12/011,956
Granted
May 5, 2015
Kind
B2
Abstract

The invention includes an API gateway server that monitors and controls the distribution of API elements from API sources to application developers based on a distribution rule set.

Claims (38)

1. An application program interface (API) management server comprising:

an API source interface to i) send a request for one or more API elements to an API source, and ii) receive the one or more API elements from the API source,

a processor to i) determine whether to allow a request from a client application for the one or more API elements based on a distribution rule set, wherein the distribution rule set includes a rule associated with a limit on a number of API calls, and ii) monitor distribution of the one or more API elements including monitoring of at least one of the number of API requests made by the client application over a period of time, usage trends by the client application, and usage trends based on Internet Protocol (IP) address;

an interface to i) receive the request for the one or more API elements from the client application and ii) send the one or more API elements to the client application in response to a determination by the processor to allow the request; and

a monitor interface to produce and display a web page that is capable of displaying (i) API access information of the API elements and (ii) an error code message, wherein the API access information includes API usage trend information, API usage plots, API access and usage amounts over a period of time, average API calls per developer, or average API calls per IP address, and wherein the error code message is specified by an API owner or provider.

2. The server of claim 1 , wherein the processor is to monitor the identity of the client application.

3. The server of claim 1 , wherein the monitor interface is further to send API distribution information to a user interface, wherein the user interface is remote from the management server.

4. The server of claim 3 , wherein the user interface includes a web browser.

5. The server of claim 1 , wherein the API source interface and the interface are included in a network interface unit or in different network interface units.

6. The server of claim 1 , wherein to determine whether to allow the request includes to determine whether the client application is authorized to access the one or more API elements and, if authorized, to allow the interface to send the one or more API elements to the client application or, if not authorized, to prevent the interface from sending the one or more API elements to the client application.

7. The server of claim 6 , wherein to determine whether the client application is authorized includes to validate a key associated with the request from the client application.

8. The server of claim 1 , wherein the client application includes a network-based application operating at run-time and the one or more API elements are run-time API elements.

9. The server of claim 1 , wherein the request for the one or more API elements from the client application is substantially the same as the request for the one or more API elements to the API source.

10. A method for controlling web-based application access to one or more application programmer interface (API) elements comprising:

receiving, at an intermediate server, a request for the one or more API elements from a client application,

sending a request to an API source for one or more API elements,

receiving, at the intermediate server, the one or more API elements from the API source,

determining, at the intermediate server, whether to allow the request from the client application for the one or more API elements based on a distribution rule set wherein the distribution rule set includes a rule associated with a limit on a number of API calls,

monitoring, at the intermediate server, the distribution of the one or more API elements including monitoring at least one of the number of API requests made by the client application over a period of time, usage trends by the client application, and usage trends based on Internet Protocol (IP) address,

sending the one or more API elements to the client application in response to determining to allow the request; and

producing and displaying a web page that is capable of displaying (i) API access information of the API elements and (ii) an error code message, wherein the API access information includes API usage trend information, API usage plots, API access and usage amounts over a period of time, average API calls per developer, or average API calls per IP address, and wherein the error code message is specified by an API owner or provider.

11. The method of claim 10 , wherein the monitoring includes monitoring the identity of the client application.

12. The method of claim 10 comprising sending API distribution information to a user interface, the user interface being remote from the intermediate server.

13. The method of claim 12 , wherein the user interface includes a web browser.

14. The method of claim 10 , wherein the sending and receiving are performed by a network interface unit or by different network interface units.

15. The method of claim 10 , wherein determining whether to allow the request includes determining whether the client application is authorized to access the one or more API elements and, if authorized, allowing the sending of the one or more API elements to the client application or, if not authorized, preventing the sending of the one or more API elements to the client application.

16. The method of claim 15 , wherein determining whether the client application is authorized includes validating a key associated with the request from the client application.

17. The method of claim 10 , wherein the client application includes a network-based application operating at run-time and the one or more API elements are run-time API elements.

18. The method of claim 10 , wherein the request for the one or more API elements from the client application is substantially the same as the request for the one or more API elements to the API source.

19. An intermediate server for controlling the exchange of data in a network comprising:

a transceiver,

a processor in communication with the transceiver, and

a computer readable medium configured for enabling the processor to i) receive a request for one or more application program interface (API) elements from a client application, ii) send a request to an API source for the one or more API elements, iii) receive the one or more API elements from the API source, iv) determine whether to allow the request from the client application for the one or more API elements based on a distribution rule set, wherein the distribution rule set includes a rule associated with a limit on a number of API calls, v) monitor distribution of the one or more API elements including monitoring at least one of the number of API requests made by the client application over a period of time, usage trends by the client application, and usage trends based on Internet Protocol (IP) address, vi) send the one or more API elements to the client application in response to a determination to allow the request based on the distribution rule set; and vii) produce and display a web page that is capable of displaying (a) API access information of the API elements and (b) an error code message, wherein the API access information includes API usage trend information, API usage plots, API access and usage amounts over a period of time, average API calls per developer, or average API calls per IP address, and wherein the error code message is specified by an API owner or provider.

20. The server of claim 19 , wherein to determine whether to allow the request includes to determine whether the client application is authorized to access the one or more API elements and, if authorized, to allow the sending of the one or more API elements to the client application or, if not authorized, to prevent the sending of the one or more API elements to the client application.

21. The server of claim 20 , wherein to determine whether the client application is authorized includes to validate a key associated with the request from the client application.

22. The server of claim 19 , wherein the client application includes an application operating at run-time and the one or more API elements are run-time API elements.

23. The server of claim 19 , wherein the request for the one or more API elements from the client application is substantially the same as the request for the one or more API elements to the API source.

24. The server of claim 19 , wherein the distribution rule set includes rules associated with at least one of a limit on the number of API calls over a select period of time, a limit of API calls for the client application, and a limit of API calls for a select Internet Protocol (IP) address.

Assignments (17)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
CHANGE OF NAME Recorded Feb 7, 2023
From: TIBCO SOFTWARE INC.
To: CLOUD SOFTWARE GROUP, INC.
Reel/Frame 062714/0634 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
RELEASE REEL 052115 / FRAME 0318 Recorded Oct 3, 2022
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: TIBCO SOFTWARE INC.
Reel/Frame 061588/0511 →
RELEASE (REEL 038382 / FRAME 0242) Recorded Sep 30, 2022
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 061575/0018 →
RELEASE (REEL 054275 / FRAME 0975) Recorded May 7, 2021
From: JPMORGAN CHASE BANK, N.A.
To: TIBCO SOFTWARE INC.
Reel/Frame 056176/0398 →
SECURITY AGREEMENT Recorded Nov 2, 2020
From: TIBCO SOFTWARE INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 054275/0975 →
SECURITY AGREEMENT Recorded Mar 6, 2020
From: TIBCO SOFTWARE INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 052115/0318 →
SECURITY AGREEMENT Recorded Apr 7, 2016
From: TIBCO SOFTWARE INC., AS PLEDGOR
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038382/0242 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2016
From: INTEL CORPORATION
To: TIBCO SOFTWARE INC.
Reel/Frame 037561/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2014
From: MASHERY INC.
To: INTEL CORPORATION
Reel/Frame 032191/0049 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2008
From: MICHELS, OREN; LOVELESS, CLAY
To: MASHERY, INC.
Reel/Frame 020896/0242 →
Continuity (2)
Provisional Application 60898365 · Jan 29, 2007
Related Publication 20080209451A1 · Aug 28, 2008