IP Library Granted Patent US 11,258,824
Granted Patent B1
US 11,258,824 · App. 16/050,124 · Granted Feb 22, 2022

Method and apparatus for authorizing microservice APIs

Inventors: Timothy L. Hinrichs (Los Altos, CA); Teemu Koponen (San Francisco, CA); Andrew Curtis (San Mateo, CA); Torin Sandall (San Francisco, CA); Octavian Florescu (Kirkland, WA)
Assignee: STYRA, INC.
H04L63/20G06F9/45558G06F9/546G06F9/547G06F21/629H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,258,824
App. No.
16/050,124
Granted
Feb 22, 2022
Kind
B1
Abstract

Some embodiments of the invention provide a system for defining, distributing and enforcing policies for authorizing API (Application Programming Interface) calls to applications executing on one or more sets of associated machines (e.g., virtual machines, containers, computers, etc.) in one or more datacenters. This system has a set of one or more servers that acts as a logically centralized resource for defining and storing policies and parameters for evaluating these policies. The server set in some embodiments also enforces these API-authorizing policies. Conjunctively, or alternatively, the server set in some embodiments distributes the defined policies and parameters to policy-enforcing local agents that execute near the applications that process the API calls. From an associated application, a local agent receives API-authorization requests to determine whether API calls received by the application are authorized. In response to such a request, the local agent uses one or more parameters associated with the API call to identify a policy stored in its local policy storage to evaluate whether the API call should be authorized. To evaluate this policy, the agent might also retrieve one or more parameters from the local policy storage.

Claims (26)

1. A method for authorizing API (Application Programming Interface) calls for a micro-service application instance executing on a computer, the method comprising:

at an API authorizing module executing on the computer:

receiving a request to determine whether an API call received by a first micro-service application instance executing on the computer from a second micro-service application instance is authorized, said receiving the request comprising receiving the request as part of an Inter Process Communication (IPC) message from the first micro-service application instance through a network communication stack that executes on the computer, said first and second micro-service application instances forming a micro-service application;

using a set of parameters associated with the API call to determine that the API call should be approved; and

sending a response as part of an IPC reply message to the first micro-service application instance to authorize the first micro-service application instance to process the API call after determining that the API call should be approved.

2. The method of claim 1 , wherein the API call is a first API call, the method further comprising:

receiving a request to determine whether a second API call received by the first micro-service application instance executing on the computer is authorized;

using a set of parameters associated with the second API call to determine that the second API call should not be approved; and

sending a response to the first micro-service application instance to reject the second API call after determining that the second API call should not be approved.

3. The method of claim 1 , wherein using the parameter set comprises determining that the parameter set does not match a set of conditions defined for rejecting API calls.

4. The method of claim 3 , wherein the set of conditions are defined in a data storage that specifies rules for rejecting API calls.

5. The method of claim 4 , wherein different sets of rules in the data storage are part of different API-assessment policies for different API calls.

6. The method of claim 1 , wherein using the parameter set comprises determining that the parameter set matches a set of conditions defined for allowing API calls.

7. The method of claim 1 , wherein the network communication stack is part of a container on which the micro-service application and the API-authorizing module execute.

8. The method of claim 1 , wherein the network communication stack is part of a virtual machine on which the first micro-service application instance and the API-authorizing module execute.

9. The method of claim 1 , wherein at least a first parameter in the parameter set is received with the request, the method further comprising identifying at least a second parameter in the parameter set in a storage accessed by the API authorizing agent.

10. The method of claim 9 , wherein the first parameter is part of the API call.

11. The method of claim 1 , wherein the API call is part of a set of one or more data messages, each messaging comprising a header and a payload, wherein the API call is part of the payload of the set of data messages.

12. The method of claim 1 , wherein the first micro-service application instance operates on a machine that executes on the computer, and the API authorizing module operates on the machine along with the application.

13. A non-transitory machine readable medium storing an API (Application Programming Interface) authorizing program for execution by at least one processing unit of a computer, the program for authorizing API calls for a micro-service application executing on the computer, the program comprising sets of instructions for:

receiving a request to determine whether an API call received by a first micro-service application instance executing on the computer from a second micro-service application instance is authorized, said receiving the request comprising receiving the request as part of an Inter Process Communication (IPC) message from the first micro-service application instance through a network communication stack that executes on the computer, said first and second micro-service application instances forming a micro-service application;

using a set of parameters associated with the API call to determine that the API call should be approved; and

sending a response as part of an IPC reply message to the first micro-service application instance to authorize the first micro-service application instance to process the API call after determining that the API call should be approved.

14. The non-transitory machine readable medium of claim 13 , wherein the set of instructions for using the parameter set comprises a set of instructions for determining that the parameter set does not match a set of conditions defined for rejecting API calls.

15. The non-transitory machine readable medium of claim 14 , wherein the set of conditions are defined in a data storage that stores different API-assessment rules for rejecting API calls.

16. The non-transitory machine readable medium of claim 13 , wherein the network communication stack is part of a virtual machine on which the first micro-service application instance and the API-authorizing program execute.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2018
From: HINRICHS, TIMOTHY L.; KOPONEN, TEEMU; CURTIS, ANDREW; SANDALL, TORIN; FLORESCU, OCTAVIAN
To: STYRA, INC.
Reel/Frame 047668/0142 →
Continuity (2)
Provisional Application 62545458 · Aug 14, 2017
Provisional Application 62540547 · Aug 2, 2017
Cited By (12)
US 12,287,906 US 12,299,502 US 12,307,305 US 12,353,877 US 12,386,684 US 12,401,694 US 12,405,948 US 12,407,647 US 12,437,057 US 12,468,855 US 12,498,998 US 12,693,839