IP Library Granted Patent US 10,467,435
Granted Patent B1
US 10,467,435 · App. 16/221,309 · Granted Nov 5, 2019

Approaches for managing restrictions for middleware applications

Inventors: James Ding (New York, NY); Gonçalo Silva Santos (London, GB); Richard Helzberg (San Geronimo, CA); Thomas Playford (London, GB)
Assignee: PALANTIR TECHNOLOGIES INC.
G06F21/629G06F21/604H04L63/101H04L63/105G06F2221/2135G06F2221/2137G06F2221/2141G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,467,435
App. No.
16/221,309
Granted
Nov 5, 2019
Kind
B1
Abstract

Systems and methods are provided for determining an access request provided by an application that seeks to interact with one or more backend systems through a computing system. One or more predefined restrictions can be enforced on the application, the computing system, or the one or more backend systems.

Claims (33)

1. A computer-implemented method, comprising:

determining, by a management computing system, an access request provided by an application running on a computing device that seeks to interact with one or more backend systems through a middleware application system, wherein the access request is provided through an endpoint associated with the management computing system, and wherein the middleware application system provides a serverless application framework for processing the access request; and

enforcing, by the management computing system, one or more predefined restrictions on the application, the middleware application system, or the one or more backend systems, the enforcing further comprising:

determining, by the management computing system, that the application is performing one or more operations to perform service discovery;

enforcing, by the management computing system, a predefined restriction that requires the application to use a predefined library to perform the service discovery;

logging, by the management computing system, the one or more operations by the application to perform service discovery through the middleware application system in a log associated with the application, wherein the log associated with the application is isolated from logs associated with other applications.

2. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the management computing system.

3. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the management computing system.

4. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions require the application to use a predefined software development kit (SDK) or software library.

5. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions prevent the application from exceeding a predefined number of access requests to the one or more backend systems over a given period of time.

6. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions prevent the management computing system from sending an amount of data to the application in excess of a predefined amount.

7. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions require the application to be identified in a whitelist of applications that are permitted to interact with the management computing system and the one or more backend systems.

8. The computer-implemented method of claim 1 , wherein the one or more predefined restrictions isolate logs generated based on interactions between the application, the management computing system, and the one or more backend systems from logs generated based on interactions involving other applications.

9. A system, comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the system to perform:

determining an access request provided by an application running on a computing device that seeks to interact with one or more backend systems through a middleware application system, wherein the access request is provided through an endpoint associated with the system, and wherein the middleware application system provides a serverless application framework for processing the access request; and

enforcing one or more predefined restrictions on the application, the middleware application system, or the one or more backend systems, the enforcing further comprising:

determining that the application is performing one or more operations to perform service discovery;

enforcing a predefined restriction that requires the application to use a predefined library to perform the service discovery;

logging the one or more operations by the application to perform service discovery through the middleware application system in a log associated with the application, wherein the log associated with the application is isolated from logs associated with other applications.

10. The system of claim 9 , wherein the one or more predefined restrictions prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the system.

11. The system of claim 9 , wherein the one or more predefined restrictions prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the system.

12. The system of claim 9 , wherein the one or more predefined restrictions require the application to use a predefined software development kit (SDK) or software library.

13. A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors of a computing system to perform:

determining an access request provided by an application running on a computing device that seeks to interact with one or more backend systems through a middleware application system, wherein the access request is provided through an endpoint associated with the system, and wherein the middleware application system provides a serverless application framework for processing the access request; and

enforcing one or more predefined restrictions on the application, the middleware application system, or the one or more backend systems, the enforcing further comprising:

determining that the application is performing one or more operations to perform service discovery;

enforcing a predefined restriction that requires the application to use a predefined library to perform the service discovery;

logging the one or more operations by the application to perform service discovery through the middleware application system in a log associated with the application, wherein the log associated with the application is isolated from logs associated with other applications.

14. The non-transitory computer readable medium of claim 13 , wherein the one or more predefined restrictions prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the computing system.

15. The non-transitory computer readable medium of claim 13 , wherein the one or more predefined restrictions prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the computing system.

16. The non-transitory computer readable medium of claim 13 , wherein the one or more predefined restrictions require the application to use a predefined software development kit (SDK) or software library.

Assignments (9)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INVENTOR NAME PREVIOUSLY RECORDED AT REEL: 047919 FRAME: 0811. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 10, 2019
From: DING, JAMES; SANTOS, GONÇALO SILVA; HELZBERG, RICHARD; PLAYFORD, THOMAS
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 048044/0289 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2019
From: DING, JAMES; SANTOS, GONÇALO SILVA; HELZBERG, RICHARD; PLYFORD, THOMAS
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 047919/0811 →