IP Library Granted Patent US 11,108,828
Granted Patent B1
US 11,108,828 · App. 16/446,507 · Granted Aug 31, 2021

Permission analysis across enterprise services

Inventors: Andrew Curtis (San Mateo, CA); Mikol Graves (San Francisco, CA); Bryan J. Fulton (San Francisco, CA); Timothy L. Hinrichs (Los Altos, CA); Marco Sanvido (Belmont, CA); Teemu Koponen (San Francisco, CA)
Assignee: STYRA, INC.
H04L63/20H04L63/101H04L63/102H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,828
App. No.
16/446,507
Granted
Aug 31, 2021
Kind
B1
Abstract

Some embodiments provide a method for gaining insight into authorization policy enforcement for application programming interface (API) calls to at least one service that includes multiple resources. The method generates a permissions graph including nodes that represent the resources and multiple users, based on two or more received authorization policies that restrict access to the service for the users. The method receives a selection of a node that corresponds to a user, and in response to the received selection, modifies the graph to display connections between the node corresponding to the user and one or more nodes associated with resources of the service that the user is authorized to access based on the authorization policies.

Claims (34)

1. A method for permission analysis across enterprise services comprising:

identifying authorization policies that restrict access to a service for a plurality of users;

generating for display a permissions graph comprising a plurality of nodes and edges connecting the nodes, the nodes representing a plurality of users and a plurality of resources associated with the users based on two or more received authorization policies that provide policy enforcement for different application programming interface (API) calls to at least one service comprising the plurality of represented resources;

receiving a selection of a particular node in the permission graph display, the particular node corresponding to a particular user; and

in response to the received selection, modifying the graph to display edges between the particular node corresponding to the particular user and one or more nodes associated with resources of the service that the particular user is authorized to access, wherein the generated permission graph provides a traceable visualization between the connected nodes by using different appearances for the nodes to represent different API calls associated with a set of resources, the different appearances comprising at least two different appearances for at least two different edges in the permission graph display associated with the particular node for the particular user.

2. The method of claim 1 , wherein generating the graph comprises analyzing the identified policies to identify, for each user, (i) a set of resources that the user is permitted to access and (ii) a set of criteria that restrict that access.

3. The method of claim 2 , wherein analyzing the policies comprises analyzing the policies based on contextual data that is used by the policies to define access to the resources.

4. The method of claim 2 , wherein the edges between user nodes and resource nodes are represented in different visual appearances that indicate the different criteria restricting the access of the user to the resources.

5. The method of claim 1 , wherein generating the graph comprises analyzing usage data that identifies access attempts to the resources by the users over a period of time.

6. The method of claim 5 , wherein an edge between a user node and a first resource node indicates that the user had authorized access to the first resource node during the period of time, wherein an absence of an edge between the user node and a second resource node indicates that the user did not have authorization to access the second resource node during the period of time.

7. The method of claim 6 , wherein the edges between user nodes and resource nodes are displayed with different appearances to designate a successful attempt to invoke an API call during the period of time, a failed attempt to invoke an API call during the period of time, and a lack of any attempt to invoke an API call during the period of time.

8. The method of claim 1 , wherein the resource nodes comprise at least one of service nodes associated with one or more services that at least one of the users is authorized to access, action nodes representing an action associated with a resource, a cluster of resources, and a cluster of services.

9. The method of claim 8 , wherein at least one of the cluster of services and the cluster of resources is clustered by any of geographic location, bandwidth, and price.

10. The method of claim 1 , wherein a user node specifies any of a single user, a group, a role, and a cluster of users.

11. The method of claim 10 , wherein the cluster of users is clustered by any of usage level, organization, and geographic location.

12. The method of claim 1 , wherein generating the graph comprises:

expressing each policy as a policy code in a general policy language;

representing the expressed policies as a single unified policy code in the general policy language; and

generating the graph by executing the unified policy code.

13. The method of claim 1 , wherein at least one received policy comprises an access control list (ACL).

14. The method of claim 1 further comprising extending the permissions graph with at least one of aggregate user nodes, aggregate resource nodes, transitive edges, edge type information, policy conditions, usage data, tags, and metadata.

15. A non-transitory machine readable storage medium storing a program which when executed by at least one processing device for permission analysis across enterprise services, the program comprising sets of instructions for:

identifying authorization policies that restrict access to a service for a plurality of users;

generating for display a permissions graph comprising a plurality of nodes and connecting edges between the nodes, the nodes representing a plurality of users and a plurality of resources associated with the users based on two or more received authorization policies that provide policy enforcement for different application programming interface (API) calls to at least one service comprising the plurality of represented resources;

receiving a selection of a particular node in the permission graph display, the particular node corresponding to a particular user; and

in response to the received selection, modifying the graph to display edges between the particular node corresponding to the particular user and one or more nodes associated with resources of the service that the particular user is authorized to access, wherein the generated permission graph provides a traceable visualization between the connected nodes by using different appearances for the nodes to represent different API calls associated with the particular user and the one or more nodes, the different appearances comprising at least two different appearances for at least two different edges in the permission graph display.

16. The machine readable medium of claim 15 , wherein the set of instructions for generating the graph comprises a set of instructions for analyzing the identified policies to identify, for each user, (i) a set of resources that the user is permitted to access and (ii) a set of criteria that restrict that access.

17. The machine readable medium of claim 16 , wherein the set of instructions for analyzing the policies comprises a set of instructions for analyzing the policies based on contextual data that is used by the policies to define access to the resources.

18. The machine readable medium of claim 16 , wherein the edges between user nodes and resource nodes are represented in different visual appearances that indicate the different criteria restricting the access of the user to the resources.

19. The machine readable medium of claim 15 , wherein the set of instructions for generating the graph comprises a set of instructions for analyzing usage data that identifies access attempts to the resources by the users over a period of time.

20. The machine readable medium of claim 15 , wherein the set of instructions for generating the graph comprises sets of instructions for:

expressing each policy as a policy code in a general policy language;

representing the expressed policies as a single unified policy code in the general policy language; and

generating the graph by executing the unified policy code.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2019
From: CURTIS, ANDREW; GRAVES, MIKOL; FULTON, BRYAN J.; HINRICHS, TIMOTHY L.; SANVIDO, MARCO; KOPONEN, TEEMU
To: STYRA, INC.
Reel/Frame 050294/0102 →
Continuity (3)
Provisional Application 62839487 · Apr 26, 2019
Provisional Application 62785656 · Dec 27, 2018
Provisional Application 62746500 · Oct 16, 2018
Cited By (38)
US 12,210,638 US 12,212,677 US 12,218,941 US 12,231,429 US 12,242,626 US 12,287,906 US 12,299,502 US 12,306,974 US 12,307,305 US 12,335,281 US 12,353,579 US 12,353,582 US 12,353,877 US 12,368,716 US 12,380,093 US 12,386,684 US 12,388,847 US 12,401,655 US 12,401,694 US 12,405,948 US 12,407,647 US 12,413,569 US 12,432,231 US 12,437,057 US 12,464,036 US 12,498,998 US 12,541,726 US 12,542,813 US 12,563,038 US 12,572,547 US 12,592,928 US 12,625,979 US 12,639,469 US 12,645,821 US 12,647,426 US 12,693,839 US 12,696,088 US 12,706,953