IP Library Granted Patent US 11,496,523
Granted Patent B2
US 11,496,523 · App. 17/067,639 · Granted Nov 8, 2022

Policy engine for cloud platform

Inventors: Mark Lucovsky (Montecito, CA); Derek Collison (Atherton, CA); Vadim Spivak (Emerald Hills, CA); Gerald C. Chen (San Francisco, CA); Ramnivas Laddad (Palo Alto, CA)
Assignee: Pivotal Software, Inc.
H04L63/20G06F21/62G06F21/629H04L41/0893H04L63/0245H04L63/083H04L63/0815H04L63/10H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,523
App. No.
17/067,639
Granted
Nov 8, 2022
Kind
B2
Abstract

A policy engine is situated within the communications path of a cloud computing environment and a user of the cloud computing environment to comply with an organization's policies for deploying web applications in the cloud computing environment. The policy engine intercepts communications packets to the cloud computing environment from a user, such as a web application developer, for example, in preparation for deploying a web application in the cloud computing environment. The policy engine identifies commands corresponding to the communications packets and directs the communications packets to appropriate rules engines corresponding to such commands in order to execute rules to comply with an organization's policies. Upon completion of execution of the rules, the communications packets are forwarded to the cloud computing environment if they comply with the policies.

Claims (48)

1. A system comprising one or more computers and one or more storage devices storing instructions that are operable, when executed by the one or more computers, to cause the one or more computers to implement components comprising:

an application platform configured to execute on a plurality of first computers in a cloud computing environment, the application platform comprising a plurality of virtualized computing resources that are configured to host deployed applications,

wherein the application platform comprises a cloud controller that is configured to receive a plurality of commands to manage applications hosted on the application platform in the cloud computing environment; and

a policy engine comprising a plurality of rules engines, each rules engine corresponding to a respective command of the plurality of commands for the cloud controller of the application platform,

wherein the policy engine is configured to:

intercept a command issued to the cloud controller,

determine whether to permit or reject the intercepted command, according to one or more rules of the plurality of rules engines, the determining comprising:

directing the intercepted command to the corresponding rules engine of the plurality of rules engines,

applying, by the corresponding rules engine, one or more rules to the intercepted command, and

based on applying the one or more rules to the intercepted command, determining whether to permit or reject the intercepted command, and

in response to determining to permit the intercepted command, forward the intercepted command to the cloud controller.

2. The system of claim 1 , wherein the policy engine is further configured, if determining to reject the intercepted command, to send a notification of the rejection to an issuer of the intercepted command.

3. The system of claim 1 , wherein the policy engine is further configured to access a networked service before forwarding the intercepted command to the cloud controller.

4. The system of claim 1 , wherein the intercepted command is a cloud controller command for creating or managing an application on the application platform.

5. The system of claim 1 , wherein the policy engine is installed on a same computer system that issues commands to the cloud controller.

6. The system of claim 1 , wherein the policy engine is installed on the cloud computing environment.

7. A computer-implemented method comprising:

executing an application platform on a plurality of first computers in a cloud computing environment, the application platform comprising a plurality of virtualized computing resources that are configured to host deployed applications,

wherein the application platform comprises a cloud controller that is configured to receive a plurality of commands to manage applications hosted on the application platform in the cloud computing environment;

intercepting, by a policy engine installed on one or more second computers, a command issued to the cloud controller, the policy engine comprising a plurality of rules engines, each rules engine corresponding to a respective command of the plurality of commands for the cloud controller of the application platform;

determining, by the policy engine, whether to permit or reject the intercepted command, according to one or more rules of the plurality of rules engines, the determining comprising:

directing the intercepted command to the corresponding rules engine of the plurality of rules engines,

applying, by the corresponding rules engine, one or more rules to the intercepted command, and

based on applying the one or more rules to the intercepted command, determining whether to permit or reject the intercepted command; and

in response to determining to permit the intercepted command, forwarding, by the policy engine, the intercepted command to the cloud controller.

8. The method of claim 7 , further comprising:

if determining to reject the intercepted command, sending, by the policy engine, a notification of the rejection to an issuer of the intercepted command.

9. The method of claim 7 , further comprising:

accessing, by the policy engine, a networked service before forwarding the intercepted command to the cloud controller.

10. The method of claim 7 , wherein the intercepted command is a cloud controller command for creating or managing an application on the application platform.

11. The method of claim 7 , wherein the policy engine is installed on a same computer system that issues commands to the cloud controller.

12. The method of claim 7 , wherein the policy engine is installed on the cloud computing environment.

13. One or more non-transitory computer storage media encoded with computer program instructions that when executed by a plurality of computers cause the plurality of computers to perform operations comprising:

executing an application platform on a plurality of first computers in a cloud computing environment, the application platform comprising a plurality of virtualized computing resources that are configured to host deployed applications,

wherein the application platform comprises a cloud controller that is configured to receive a plurality of commands to manage applications hosted on the application platform in the cloud computing environment;

intercepting, by a policy engine installed on one or more second computers, a command issued to the cloud controller, the policy engine comprising a plurality of rules engines, each rules engine corresponding to a respective command of the plurality of commands for the cloud controller of the application platform;

determining, by the policy engine, whether to permit or reject the intercepted command, according to one or more rules of the plurality of rules engines, the determining comprising:

directing the intercepted command to the corresponding rules engine of the plurality of rules engines,

applying, by the corresponding rules engine, one or more rules to the intercepted command, and

based on applying the one or more rules to the intercepted command, determining whether to permit or reject the intercepted command; and

in response to determining to permit the intercepted command, forwarding, by the policy engine, the intercepted command to the cloud controller.

14. The non-transitory computer storage media of claim 13 , the operations further comprising:

if determining to reject the intercepted command, sending, by the policy engine, a notification of the rejection to an issuer of the intercepted command.

15. The non-transitory computer storage media of claim 13 , the operations further comprising:

accessing, by the policy engine, a networked service before forwarding the intercepted command to the cloud controller.

16. The non-transitory computer storage media of claim 13 , wherein the intercepted command is a cloud controller command for creating or managing an application on the application platform.

17. The non-transitory computer storage media of claim 13 , wherein the policy engine is installed on a same computer system that issues commands to the cloud controller.

18. The non-transitory computer storage media of claim 13 , wherein the policy engine is installed on the cloud computing environment.

Assignments (3)
MERGER Recorded May 20, 2026
From: PIVOTAL SOFTWARE, INC.
To: VMWARE LLC
Reel/Frame 075613/0980 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2023
From: VMWARE, INC.
To: PIVOTAL SOFTWARE, INC.
Reel/Frame 063408/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: LUCOVSKY, MARK; COLLISON, DEREK; SPIVAK, VADIM; CHEN, GERALD C.; LADDAD, RAMNIVAS
To: VMWARE, INC.
Reel/Frame 060228/0974 →
Continuity (7)
Continuation 15948874 · Apr 9, 2018
Continuation 15419992 · Jan 30, 2017
Continuation 14738558 · Jun 12, 2015
Continuation 14064992 · Oct 28, 2013
Continuation 13094500 · Apr 26, 2011
Provisional Application 61327898 · Apr 26, 2010
Related Publication 20210099491A1 · Apr 1, 2021