IP Library › Granted Patent US 11,586,746
Granted Patent B2
US 11,586,746 · App. 16/915,665 · Granted Feb 21, 2023

Integration management of applications

Inventors: David Mowatt (Dublin, IE); Ankit Govil (Marathahalli, IN)
Assignee: Microsoft Technology Licensing, LLC
G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,746
App. No.
16/915,665
Granted
Feb 21, 2023
Kind
B2
Abstract

The technology described herein improves data security and software functionality in an integrated application deployment. Security is improved by providing granular permission management to application resources at the application program interface (API) level. This granular control allows the primary application to provide access to only the minimal resources the secondary application needs to complete a task. The technology described herein provides a more efficient access control scheme by facilitating group management of permissions. The technology described herein also improves an application update process by eliminating the need for permissions to be reassigned every time a primary application or secondary application is updated. Finally, the technology described herein provides a centralized permission enforcement that is independent of the primary or secondary application.

Claims (44)

1. A computer-implemented method for managing application integrations, the method comprising:

receiving, via a user interface, a notice identifying a primary-application API of a primary application that two or more secondary applications require access to upon integration with the primary application;

receiving from a user, via the user interface, a single permission instruction granting the two or more secondary applications access to the primary-application API in a computing environment;

saving in a permissions store an indication that the two or more secondary applications have permission to access the primary-application API within the computing environment;

receiving, from the primary application, an API security request inquiring whether an individual secondary application has access to the primary-application API;

determining that the individual secondary application has access to the primary-application API according to the permissions store;

communicating to the primary application that the individual secondary application has access to the primary-application API; and

upon receiving an instruction to integrate one of the two or more secondary applications, outputting an explanation that the two or more secondary applications are adapted to be deployed together.

2. The method of claim 1 , wherein the two or more secondary applications are not available in a single application store, but are accessed from two different application stores.

3. The method of claim 1 , wherein the method further comprises:

receiving a request to integrate an updated version of a secondary application into the primary application;

determining that the updated version accesses a new primary-application API that a previous version of the secondary application does not have permission to access;

automatically seeking permission for the updated version to access the new primary-application API;

receiving a new permission instruction granting the updated version access to the new primary-application API in the computing environment; and

saving in the permissions store a new indication that the updated version has permission to access the new primary-application API within the computing environment.

4. The method of claim 1 , wherein the single permission instruction grants all secondary applications having an attribute in common access to the primary-application API in the computing environment.

5. The method of claim 4 , wherein the attribute in common is an application source.

6. The method of claim 1 , wherein the method further comprises:

receiving a request to integrate an updated version of a secondary application into the primary application;

determining that the updated version accesses only primary-application APIs that a previous version of the secondary application has permission to access; and

automatically installing the updated version without seeking access permissions.

7. The method of claim 6 , further comprising determining that the updated version does not access a specific primary-application API that a previous version of the secondary application has permission to access; and automatically revoking the updated version's access to the specific primary-application API.

8. A computer-implemented method for managing application integrations, the method comprising:

receiving, via a user interface, a notice identifying a primary-application API of a primary application that two or more secondary applications require access to upon integration with the primary application;

receiving from a user, via the user interface, a single permission instruction granting the two or more secondary applications access to the primary-application API in a computing environment;

saving in a permissions store an indication that the two or more secondary applications have permission to access the primary-application API within the computing environment;

receiving, from the primary application, an API security request inquiring whether an individual secondary application has access to the primary-application API;

determining that the individual secondary application has access to the primary-application API according to the permissions store;

communicating to the primary application that the individual secondary application has access to the primary-application API;

receiving a request to integrate an updated version of a secondary application into the primary application;

determining that the updated version accesses a new primary-application API that a previous version of the secondary application does not have permission to access;

automatically seeking permission for the updated version to access the new primary-application API;

receiving a new permission instruction granting the updated version access to the new primary-application API in the computing environment; and

saving in the permissions store a new indication that the updated version has permission to access the new primary-application API within the computing environment.

9. A computer-implemented method for managing application integrations, the method comprising:

receiving, via a user interface, a notice identifying a primary-application API of a primary application that two or more secondary applications require access to upon integration with the primary application;

receiving from a user, via the user interface, a single permission instruction granting the two or more secondary applications access to the primary-application API in a computing environment;

saving in a permissions store an indication that the two or more secondary applications have permission to access the primary-application API within the computing environment;

receiving, from the primary application, an API security request inquiring whether an individual secondary application has access to the primary-application API;

determining that the individual secondary application has access to the primary-application API according to the permissions store;

communicating to the primary application that the individual secondary application has access to the primary-application API;

receiving a request to integrate an updated version of a secondary application into the primary application;

determining that the updated version accesses only primary-application APIs that a previous version of the secondary application has permission to access; and

automatically installing the updated version without seeking access permissions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2020
From: MOWATT, DAVID; GOVIL, ANKIT
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 053366/0258 →
Continuity (1)
Related Publication 20210141912A1 · May 13, 2021