IP Library Granted Patent US 9,049,182
Granted Patent B2
US 9,049,182 · App. 12/608,389 · Granted Jun 2, 2015

Techniques for virtual representational state transfer (REST) interfaces

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,049,182
App. No.
12/608,389
Granted
Jun 2, 2015
Kind
B2
Abstract

Techniques for virtual Representational State Transfer (REST) interfaces are provided. A proxy is interposed between a client and a REST service over a network. The proxy performs independent authentication of the client and provides credentials to the client and for the client to authenticate to the REST service using a REST service authentication mechanism. The proxy inspects requests and responses and translates the requests and responses into formats expected by the client and the REST service. Moreover, the proxy enforces policy and audits the requests and responses occurring between the client and the REST service over the network.

Claims (30)

1. A method implemented and residing within a computer-readable storage medium that is executed by one or more processors of a network to perform the method, comprising:

configuring a proxy device to act as an intermediary between a client and a Representational State Transfer (REST) service executing on a server of the network, wherein the REST service is multiple REST services merged to act as one service;

intercepting, at the proxy device, a REST formatted request sent from the client to the REST service;

enforcing, at the proxy device, an enterprise policy against the REST formatted request, the enterprise policy is a set of conditions defined by an enterprise, the set of conditions are automatically evaluated and specific actions taken in response thereto, the actions including implementing enterprise-specific security, integrating different REST services, and auditing REST service interactions, wherein enforcement of the enterprise policy enables: implementation of enterprise security independent of the REST service or other REST services, integration of the REST services, and auditing of REST service interactions, defining and validating REST requests without changes to or knowledge to the multiple REST services; and

providing, by the proxy device, the REST formatted request when the enterprise policy is satisfied to the REST service for processing on behalf of the client.

2. The method of claim 1 , wherein configuring further includes configuring the proxy device as a reverse proxy that the client and the REST service are unaware of and that the client and the REST service are not directly configured to interact with.

3. The method of claim 1 , wherein enforcing further includes authenticating, by the proxy device, a user of the client for access to the REST service in response to a first set of user-supplied credentials provided with the REST formatted request.

4. The method of claim 3 , wherein authenticating further includes using, by the proxy device, a third-party authentication service to authenticate the user via the first set of user-supplied credentials.

5. The method of claim 4 , wherein using further includes acquiring, by the proxy device, a second set of user credentials that the proxy device inserts into the REST formatted request on behalf of the user to authenticate the user and the client directly to the REST service, the second set of user credentials expected by the REST service and unknown to the user that supplied the first set of user-supplied credentials.

6. The method of claim 5 , wherein acquiring further includes maintaining, by the proxy, the first set of user-supplied credentials and subsequently inserting a third set of user credentials that the proxy device inserts into a second REST formatted request on behalf of the user to authenticate the user and the client directly to a second REST service that processes the second REST formatted request, the third set of user credentials expected by the second REST service and unknown to the user that supplied the first set of user-supplied credentials, the REST service using a different authentication mechanism than that which is used by the second REST service and the authentication mechanisms managed by the proxy device to provide single sign-on services to the user.

7. The method of claim 1 , wherein enforcing further includes enforcing the enterprise policy against one or more second REST formatted requests directed to one or more second REST services associated with one or more second servers.

8. The method of claim 1 , wherein enforcing further includes translating one or more components of the REST formatted request into an expected format that the REST service processes in response to enforcing the enterprise policy.

9. A method implemented and residing within a computer-readable storage medium that is executed by one or more processors of a network to perform the method, comprising:

interposing a proxy between a Representational State Transfer (REST) service and a client of the network, wherein the REST service is multiple REST services merged to act as one service;

enforcing security, at the proxy, between interactions of the REST service and the client and wherein enforcement of the security enables: implementation of enterprise security independent of the REST service or other REST services, integration of the REST service, and auditing of REST service interactions;

selectively modifying, at the proxy, the interactions between the REST service and the client and defining and validating REST requests without changes to or knowledge of the multiple REST services; and

custom auditing, at the proxy, the interactions between the REST service and the client in an automated fashion.

10. The method of claim 9 , wherein interposing further includes configuring the proxy as a forward proxy and a reverse proxy to the REST service and to one or more second REST services of the network.

11. The method of claim 9 , wherein enforcing further includes authenticating, by the proxy, the client to the REST service by first authenticating the client to an enterprise using a first authentication mechanism and then providing the client with credentials to authenticate to the REST service via a second and different authentication mechanism.

12. The method of claim 9 , wherein enforcing further includes authenticating, by the proxy, the client for a specific access request to the REST service in response to a specific action labeled function appearing with a particular interaction that the client is attempting with the REST service.

13. The method of claim 9 , wherein selectively modifying further includes using, by the proxy, a policy to change a request in a first format to a REST service recognized format.

14. The method of claim 13 , wherein using further includes changing, by the proxy, portions of the request in response to content included with the request in the first format and as directed by the policy.

15. The method of claim 9 , wherein auditing further includes logging selective details of the interactions in response to content provided by the client with some of the interactions being directed to the REST service.

16. The system of claim 15 , wherein the proxy service authenticates the client requests and the REST server responses using an enterprise authentication mechanism that is independent of separate authentication mechanisms used by the REST servers.

17. The system of claim 16 , wherein the proxy service utilizes the separate authentication mechanisms expected by the REST servers once the enterprise authentication mechanism is satisfied, and the clients are unaware of the separate authentication mechanisms expected by the REST servers.

18. The system of claim 15 , wherein the clients and the REST servers are unaware of the proxy service and are not configured for direct interaction with the proxy service.

19. The method of claim 9 , wherein auditing further includes logging selective details of the interactions in response to content provided by the REST service with some of the interactions being directed back to the client.

20. A multiprocessor-implemented system, comprising:

one or more processors configured with a proxy service implemented in a non-transitory computer-readable storage medium and to execute on the one or more processors of a proxy of a network;

the proxy service configured to act as an intermediary between clients of a network and Representational State Transfer (REST) servers to: authenticate client requests, translate the requests, enforce enterprise policy against the requests, and custom audit interactions, and the proxy service configured to authenticate REST server responses, translate the responses and enforce the enterprise policy against the responses, wherein the enterprise policy is a set of conditions defined by an enterprise, the set of conditions are automatically evaluated and specific actions taken in response thereto, the actions including implementing enterprise-specific security independent of the REST service or other REST services, integrating different REST services, and auditing REST service interactions, wherein at least one REST service is multiple REST services merged to act as one service and the proxy service configured to define and validate REST requests without changes on or knowledge by the REST services.

Assignments (16)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2009
From: BURCH, LLOYD LEON; EARL, DOUGLAS GARRY; BULTMEYER, JONATHAN PAUL; MCCLAIN, CAROLYN B.
To: NOVELL, INC.
Reel/Frame 023567/0953 →