IP Library Granted Patent US 11,138,342
Granted Patent B2
US 11,138,342 · App. 16/586,553 · Granted Oct 5, 2021

Approaches for managing restrictions for middleware applications

Inventors: James Ding (New York, NY); Gonçalo Silva Santos (London, GB); Richard Helzberg (San Geronimo, CA); Thomas Playford (London, GB)
Assignee: Palantir Technologies Inc.
G06F21/629G06F21/604H04L63/101H04L63/105G06F2221/2135G06F2221/2137G06F2221/2141G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,138,342
App. No.
16/586,553
Granted
Oct 5, 2021
Kind
B2
Abstract

Systems and methods are provided for determining an access request provided by an application that seeks to interact with one or more backend systems through a computing system. One or more predefined restrictions can be enforced on the application, the computing system, or the one or more backend systems.

Claims (36)

1. A computer-implemented method, comprising:

processing, by a middleware application system, access requests provided by a first application and a second application running on respective first and second computing devices that interact with one or more backend systems through the middleware application system;

logging, in a first log, data generated from an interaction between the first application, the one or more backend systems, and the middleware application system;

logging, in a second log, data generated from an interaction between the second application, the one or more backend systems, and the middleware application system;

determining, by the middleware application system, data access restrictions associated with the first application and the second application; and

applying log data access restrictions to the first log and the second log that are commensurate with the determined data access restrictions.

2. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the middleware application system.

3. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the middleware application system.

4. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that require the application to use a predefined software development kit (SDK) or software library.

5. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that require the application to use a predefined library for service discovery.

6. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that prevent the application from exceeding a predefined number of access requests to the one or more backend systems over a given period of time.

7. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that prevent the middleware application system from sending an amount of data to the application in excess of a predefined amount.

8. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that require the application to be identified in a list of applications that are permitted to interact with the middleware application system and the one or more backend systems.

9. The computer-implemented method of claim 1 , further including enforcing, by the middleware application system, one or more predefined restrictions that isolate logs generated based on interactions between the application, the middleware application system, and the one or more backend systems from logs generated based on interactions involving other applications.

10. A middleware application system, comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the middleware application system to perform:

processing access requests provided by a first application and a second application running on respective first and second computing devices that interact with one or more backend systems through the middleware application system;

logging, in a first log, data generated from an interaction between the first application, the one or more backend systems, and the middleware application system;

logging, in a second log, data generated from an interaction between the second application, the one or more backend systems, and the middleware application system;

determining, by the middleware application system, data access restrictions associated with the first application and the second application; and

applying log data access restrictions to the first log and the second log that are commensurate with the determined data access restrictions.

11. The system of claim 10 , wherein the instructions further cause the middleware application system to enforce one or more predefined restrictions that prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the middleware application system.

12. The system of claim 10 , wherein the instructions further cause the middleware application system to enforce one or more predefined restrictions that prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the middleware application system.

13. The system of claim 10 , wherein the instructions further cause the middleware application system to enforce one or more predefined restrictions that require the application to use a predefined software development kit (SDK) or software library.

14. The system of claim 10 , wherein the instructions further cause the middleware application system to enforce one or more predefined restrictions that require the application to use a predefined library for service discovery.

15. A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors of a middleware application system to perform:

processing access requests provided by a first application and a second application running on respective first and second computing devices that interact with one or more backend systems through the middleware application system;

logging, in a first log, data generated from an interaction between the first application, the one or more backend systems, and the middleware application system;

logging, in a second log, data generated from an interaction between the second application, the one or more backend systems, and the middleware application system;

determining, by the middleware application system, data access restrictions associated with the first application and the second application; and

applying log data access restrictions to the first log and the second log that are commensurate with the determined data access restrictions.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions further cause the one or more processors of the middleware application system to enforce one or more predefined restrictions that prevent continuous deployment of new and updated software in compliance with a software dependency matrix, wherein the software dependency matrix includes dependency information for software relied upon by the middleware application system.

17. The non-transitory computer readable medium of claim 15 , wherein the instructions further cause the one or more processors of the middleware application system to enforce one or more predefined restrictions that prevent modifications to data in compliance with a data dependency matrix, wherein the data dependency matrix includes dependency information for data relied upon by the application or the middleware application system.

18. The non-transitory computer readable medium of claim 15 , wherein the instructions further cause the one or more processors of the middleware application system to enforce one or more predefined restrictions that require the application to use a predefined software development kit (SDK) or software library.

19. The non-transitory computer readable medium of claim 15 , wherein the instructions further cause the one or more processors of the middleware application system to enforce one or more predefined restrictions that require the application to use a predefined library for service discovery.

Assignments (2)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2020
From: DING, JAMES; SANTOS, GONÇALO SILVA; HELZBERG, RICHARD; PLAYFORD, THOMAS
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052686/0622 →