IP Library Granted Patent US 12,498,998
Granted Patent B1
US 12,498,998 · App. 16/914,244 · Granted Dec 16, 2025

Method and apparatus for enforcing policies for authorizing APIs

Inventors: Andrew Curtis (San Mateo, CA); Mikol Graves (San Francisco, CA); Teemu Koponen (San Francisco, CA); Timothy L. Hinrichs (Los Altos, CA); Torin Sandall (San Francisco, CA)
Assignee: Apple Inc.
G06F9/547G06F9/3891G06F9/5077H04L47/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,498,998
App. No.
16/914,244
Granted
Dec 16, 2025
Kind
B1
Abstract

Some embodiments provide API (Application Programming Interface) authorization platform that allows API-authorization policy stacks to be created and enforced. Policy stacks (called “stacks”) define API-authorization policies across different sets of managed resources in a workspace. A stack in some embodiments defines a uniform set of one or more API-authorization policies for multiple different sets of resources. By instituting common policies across multiple managed resource sets (also called managed systems), stacks can be used to guarantee uniform baseline policies for the workspace. A stack is typically applied to several managed resources that share a common trait. The API-authorization platform of some embodiments allows an administrator to define the traits of the managed resources through labels that are associated with the stacks and the managed systems. This platform in some embodiments also allows a stack to specify an exception for a managed system based on one or more features of the system.

Claims (31)

1 . A method of authorizing an application programming interface (API) call to an application executing on a host computer, the method comprising:

at a local agent executing on the host computer:

from the application, receiving the API call along with a request to perform an authorization process to determine whether the API call is authorized and whether an operation specified by the API call should be performed by the application;

based on a set of one or more parameters associated with the API call, identifying (i) at least a first policy from a first set of policies specified for a first set of resources that includes the application and (ii) at least a second policy from a second set of policies specified for each of the first set of resources and a second set of resources, the second set of resources being different than the first set of resources;

using the set of parameters to determine whether one or both of the first and second policies specify whether the API call is authorized and whether the operation specified by the API call should be performed by the application; and

after a determination that at least the second policy specifies that the API call is authorized and the operation specified by the API call should be performed, informing the application that the API call is authorized and that the operation specified by the API should be performed by the application.

2 . The method of claim 1 , wherein:

the first set of resources comprise resources of a first managed system that includes the application and the second set of resources comprise resources of a second managed system; and

a set of system policies that include the first policy is defined for the first managed system, while a set of stack policies that include the second policy is defined for a plurality of managed systems including the first and second managed systems.

3 . The method of claim 2 , wherein the first set of policies is defined by a first set of administrators for the first set of resources, while the second set of policies is defined by a second set administrators that are different than the first set of administrators and who are administrators for a plurality of sets of resources including the first and second sets of resources.

4 . The method of claim 3 , wherein the second set of administrators is a set of administrators of a workspace in a set of one or more software defined datacenters (SDDCs), while the first set of administrators is a set of administrators of just the first set of resources in the SDDC set.

5 . The method of claim 4 , wherein the plurality of sets of resources in the SDDC set comprises a plurality of clusters of Kubernetes compute nodes.

6 . The method of claim 4 , wherein the plurality of sets of resources in the SDDC set comprises a plurality of distributed applications that execute in the SDDC set.

7 . The method of claim 4 , wherein the plurality of sets of resources in the SDDC set comprises a plurality of distributed data storages that operate in the SDDC set.

8 . The method of claim 3 , wherein the second set of administrators comprises a set of administrators of a workspace that operates in one or more datacenters, while the first set of administrators comprise only administrators of the first set of resources that is part of the workspace.

9 . The method of claim 1 , wherein when the first policy specifies that the API call is authorized and the operation specified by the API call should be performed but the second policy specifies that the API call should be rejected and the operation specified by the API call should not be performed, informing the application that the API call is not authorized and that the operation specified by the API call should not be performed by the application.

10 . The method of claim 1 further comprising:

identifying a third policy from the second set of policies specified for the first and second sets of resources;

using the set of parameters to determine whether the third policy specifies whether the API call is authorized and whether the operation specified by the API call should be performed by the application; and

when the second policy specifies that the API call is authorized and the operation should be performed but the third policy specifies that the API call should be rejected and the operation should not be performed, using a conflict resolver to identify a resolution of the second or third policy based on priority levels assigned to the second and third policies.

11 . The method of claim 10 , wherein using the conflict resolver comprises informing the application that the API policy is authorized and the operation should be performed by the application when the second policy has a higher priority than the third policy.

12 . The method of claim 10 , wherein using the conflict resolver comprises informing the application that the API policy should be rejected and the operation should not be performed by the application when the third policy has a higher priority than the second policy.

13 . The method of claim 1 further comprising:

identifying a third policy from the first set of policies specified for first set of resources;

using the set of parameters to determine whether the third policy specifies whether the API call is authorized and whether the operation specified by the API call should be performed by the application; and

when the first policy rejects the API call and the operation specified by the API call but the third policy authorizes the API call and the operation specified by the API call, using a conflict resolver to identify a resolution of the first or third policy based on priority levels assigned to the first and third policies.

14 . The method of claim 13 , wherein using the conflict resolver comprises informing the application that the API call is authorized and the operation should be performed by the application when the third policy has a higher priority than the first policy.

15 . The method of claim 13 , wherein using the conflict resolver comprises informing the application that the API policy should be rejected and the operation should not be performed by the application when the first policy has a higher priority than the third policy.

16 . The method of claim 1 , wherein the first policy specifies that the API call should be rejected and the operation should not be performed by the application, while the second policy specifies that the API call is authorized and the operation should be performed by the application.

17 . The method of claim 16 , wherein when the second policy specifies that the API call is allowed but can be rejected when a policy specified just for the first set of resources specifies that the API call should be rejected and the operation should not be performed by the application, the method further comprises informing the application that the API call should be rejected and the operation should not be performed by the application based on the first policy.

18 . The method of claim 1 , wherein using the set of parameters to determine whether one or both of the first and second policies specify whether the API call is authorized and whether the operation specified by the API call should be performed by the application comprises using a set of feature attributes associated with the application to determine whether the API call relates to a feature that has been associated with the first managed system that includes the application as an exception to the first policy that specifies that the API call should be rejected and the operation should not be performed.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2020
From: CURTIS, ANDREW; GRAVES, MIKOL; KOPONEN, TEEMU; HINRICHS, TIMOTHY L.; SANDALL, TORIN
To: STYRA, INC.
Reel/Frame 053728/0112 →
Continuity (2)
Provisional Application 63036991 · Jun 9, 2020
Provisional Application 62984291 · Mar 2, 2020
References Cited (120)
US 5329626A · Klein · 1994 [cited by examiner]
US 5974549A · Golan · 1999 [cited by applicant]
US 6985953B1 · Sandhu et al. · 2006 [cited by applicant]
US 7096367B2 · Garg et al. · 2006 [cited by applicant]
US 7124192B2 · High, Jr. et al. · 2006 [cited by applicant]
US 7752661B2 · Hemsath et al. · 2010 [cited by applicant]
US 7913300B1 · Flank et al. · 2011 [cited by applicant]
US 8266694B1 · Roy · 2012 [cited by applicant]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683560B1 · Brooker et al. · 2014 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8789138B2 · Reierson et al. · 2014 [cited by applicant]
US 9171172B2 · Goldschlag · 2015 [cited by examiner]
US 9397990B1 · Taly et al. · 2016 [cited by applicant]
US 9471798B2 · Vepa · 2016 [cited by examiner]
US 9501666B2 · Lockett · 2016 [cited by examiner]
US 9530020B2 · Brandwine et al. · 2016 [cited by applicant]
US 9552463B2 · Marshall · 2017 [cited by examiner]
US 9578004B2 · Greenspan et al. · 2017 [cited by applicant]
US 9648040B1 · Morkel et al. · 2017 [cited by applicant]
US 9652271B2 · Cropper · 2017 [cited by examiner]
US 9792459B2 · Forsberg · 2017 [cited by examiner]
US 9848041B2 · Einkauf · 2017 [cited by examiner]
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10127393B2 · Ferraiolo et al. · 2018 [cited by applicant]
US 10182129B1 · Peterson et al. · 2019 [cited by applicant]
US 10257184B1 · Mehta et al. · 2019 [cited by applicant]
US 10353726B2 · Duan · 2019 [cited by applicant]
US 10362623B2 · Liang · 2019 [cited by examiner]
US 10432644B2 · Burns · 2019 [cited by examiner]
US 10454975B1 · Mehr · 2019 [cited by applicant]
US 10459647B1 · Lazier · 2019 [cited by examiner]
US 10469314B2 · Ennis, Jr. et al. · 2019 [cited by applicant]
US 10574699B1 · Baer et al. · 2020 [cited by applicant]
US 10592302B1 · Hinrichs et al. · 2020 [cited by applicant]
US 10592683B1 · Lim et al. · 2020 [cited by applicant]
US 10601876B1 · Levy · 2020 [cited by examiner]
US 10613888B1 · Mentz · 2020 [cited by examiner]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 10719373B1 · Koponen et al. · 2020 [cited by applicant]
US 10740287B2 · Haviv · 2020 [cited by examiner]
US 10740470B2 · Ionescu et al. · 2020 [cited by applicant]
US 10789220B2 · Mayer et al. · 2020 [cited by applicant]
US 10802746B1 · Lazier · 2020 [cited by examiner]
US 10984133B1 · Hinrichs et al. · 2021 [cited by applicant]
US 10986131B1 · Kruse et al. · 2021 [cited by applicant]
US 10990702B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11023292B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11080410B1 · Sandall et al. · 2021 [cited by applicant]
US 11108827B2 · Beckman et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11170099B1 · Sandall et al. · 2021 [cited by applicant]
US 11228573B1 · Rangasamy · 2022 [cited by examiner]
US 11245728B1 · Curtis et al. · 2022 [cited by applicant]
US 11258824B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11327815B1 · Koponen et al. · 2022 [cited by applicant]
US 11494518B1 · Curtis et al. · 2022 [cited by applicant]
US 11496517B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11516253B1 · Van Deman, V · 2022 [cited by examiner]
US 11604684B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11645423B1 · Curtis et al. · 2023 [cited by applicant]
US 20040083367A1 · Garg et al. · 2004 [cited by applicant]
US 20070156670A1 · Lim · 2007 [cited by applicant]
US 20080184336A1 · Sarukkai et al. · 2008 [cited by applicant]
US 20090063665A1 · Bagepalli et al. · 2009 [cited by applicant]
US 20090077618A1 · Pearce et al. · 2009 [cited by applicant]
US 20090281996A1 · Liu et al. · 2009 [cited by applicant]
US 20100333079A1 · Sverdlov et al. · 2010 [cited by applicant]
US 20110113484A1 · Zeuthen · 2011 [cited by applicant]
US 20120030354A1 · Razzaq et al. · 2012 [cited by applicant]
US 20120110651A1 · Van Biljon · 2012 [cited by examiner]
US 20120311672A1 · Connor et al. · 2012 [cited by applicant]
US 20120331539A1 · Matsugashita · 2012 [cited by applicant]
US 20130226970A1 · Weber et al. · 2013 [cited by applicant]
US 20140032691A1 · Barton et al. · 2014 [cited by applicant]
US 20140032759A1 · Barton et al. · 2014 [cited by applicant]
US 20140033267A1 · Aciicmez · 2014 [cited by applicant]
US 20140229438A1 · Carriero · 2014 [cited by examiner]
US 20140237594A1 · Thakadu et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20160057107A1 · Call et al. · 2016 [cited by applicant]
US 20160182470A1 · Rubin · 2016 [cited by examiner]
US 20160188898A1 · Karinta et al. · 2016 [cited by applicant]
US 20170034075A1 · Burk · 2017 [cited by examiner]
US 20170111336A1 · Davis · 2017 [cited by examiner]
US 20170161120A1 · Sasaki et al. · 2017 [cited by applicant]
US 20170220370A1 · Klompje et al. · 2017 [cited by applicant]
US 20170237729A1 · Uppalapati · 2017 [cited by applicant]
US 20170346807A1 · Blasi · 2017 [cited by applicant]
US 20170364702A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180067790A1 · Chheda et al. · 2018 [cited by applicant]
US 20180082053A1 · Brown et al. · 2018 [cited by applicant]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20180309746A1 · Blasi · 2018 [cited by applicant]
US 20190007418A1 · Cook et al. · 2019 [cited by applicant]
US 20190007443A1 · Cook et al. · 2019 [cited by applicant]
US 20190080103A1 · Hadzic · 2019 [cited by examiner]
US 20190190959A1 · Yuan · 2019 [cited by applicant]
US 20190230130A1 · Beckman et al. · 2019 [cited by applicant]
US 20190245862A1 · Kruse et al. · 2019 [cited by applicant]
US 20190386973A1 · Patwardhan et al. · 2019 [cited by applicant]
US 20200007580A1 · Liderman et al. · 2020 [cited by applicant]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210240507A1 · Colombet · 2021 [cited by examiner]
US 20210240550A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210248017A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210365571A1 · Sandall et al. · 2021 [cited by applicant]
US 20220269549A1 · Koponen et al. · 2022 [cited by applicant]
Mohan et al.; “An attribute-based authorization policy framework with dynamic conflict resolution”; Apr. 2010; IDTRUST '10: Proceedings of the 9th Symposium on Identity and Trust on the Internet; 37 pages. (Year: 2010). [cited by examiner]
Ma et al.; “Conflict detection and resolution for authorization policies in workflow systems”; 2009; Journal of Zhejiang University—Science A 10.8; pp. 1082-1092. (Year: 2009). [cited by examiner]
Author Unknown, “API Best Practices Managing the API Lifecycle: Design, Delivery, and Everything in Between,” Dec. 2016, 37 pages, Apigee, retrieved from https://pages.apigee.com/rs/351-WXY-166/images/API-Best-Practices… [cited by applicant]
Costa, Jeff, “Improve API Performance with Caching,” API Gateway, May 3, 2018, 18 pages, Akamai Developer, retrieved from https://developer.akamai.com/blog/2018/05/31/improve-api-performance-caching. [cited by applicant]
Win, Thu Yein, et al., “Virtualization Security Combining Mandatory Access Control and Virtual Machine Introspection,” 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, Dec. 8-11, 2014, IEEE, Lo… [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,119, filed Jul. 31, 2018, 55 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,123, filed Jul. 31, 2018, 56 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,143, filed Jul. 31, 2018, 56 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned Related U.S. Appl. No. 16/914,239 with similar specification, filed Jun. 26, 2020, 47 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned Related U.S. Appl. No. 16/914,243 with similar specification, filed Jun. 26, 2020, 47 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/120,810, filed Mar. 13, 2023, 63 pages, Styra, Inc. [cited by applicant]
Moffett, Jonathan D., et al., “Policy Hierarchies for Distributed Systems Management,” IEEE Journal on Selected Areas in Communications, Dec. 1993, 11 pages, vol. 11, IEEE, USA. [cited by applicant]