IP Library Granted Patent US 12,301,629
Granted Patent B2
US 12,301,629 · App. 17/706,320 · Granted May 13, 2025

Dynamic security policy management

Inventor: Justin Paul Yancey (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L63/205H04L63/0227H04L63/101H04L63/107H04L63/108H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,629
App. No.
17/706,320
Filed
Mar 28, 2022
Granted
May 13, 2025
Kind
B2
Art Unit
2409
USPC
726/1
Abstract

Security policies can be dynamically updated in response to changes in endpoints associated with those policies. A user can indicate one or more regions or networks from which access is to be granted under a specific security policy. The user can subscribe to receive notifications upon a change relating to those endpoints, such as the addition or removal of one or more endpoints. When a change is detected, new policy information can be generated automatically and published for subscribed policies, which can then have the updates applied automatically or provided for manual review and application. Such a process enables access determinations to be made based upon up-to-date endpoint information.

Claims (54)

1. A computer-implemented method, comprising:

detecting a change in at least one endpoint that is virtual, that is for data service in a resource provider environment, and that is associated with a security policy for a resource, the security policy including an indication from an entity to automatically generate policy information based in part on the detected change in the at least one endpoint;

publishing new policy information associated with the change in the at least one endpoint; and

causing the new policy information to be applied for the security policy, wherein subsequent access request relating to the resource is enabled for the security policy that includes the new policy information.

2. The computer-implemented method of claim 1 , further comprising:

causing the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.

3. The computer-implemented method of claim 1 , further comprising:

receiving the new policy information in a customer policy manager;

generating a notification to a customer resource administrator regarding the new policy information; and

enabling the customer resource administrator to apply the new policy information for the security policy.

4. The computer-implemented method of claim 1 , further comprising:

detecting the change in at least one endpoint using a task-based resource;

generating the new policy information based at least in part on the change in the at least one endpoint; and

providing the new policy information for publication by a notification service.

5. The computer-implemented method of claim 1 , wherein the new policy information is stored to an information queue or transmitted using a data streaming service for publication.

6. The computer-implemented method of claim 1 , further comprising:

periodically polling an information queue for the new policy information wherein the new policy information includes at least one of a new policy definition or a new access control list.

7. The computer-implemented method of claim 1 , wherein the new policy information specifies the at least one endpoint for which access to the resource is to be granted or specifies at least one of second endpoint for which access is to be denied to the resource.

8. The computer-implemented method of claim 1 , wherein the new policy information is published using at least one of email messaging, instant messaging, short message service messaging, or text messaging.

9. The computer-implemented method of claim 1 , wherein the security policy is one of an access policy or a credential management policy.

10. The computer-implemented method of claim 1 , wherein the at least one endpoint correspond to one or more of an Internet Protocol (IP) address or geo-location of at least one of a sub-network or region of computing resources.

11. The computer-implemented method of claim 1 , further comprising:

validating a customer access credential, received with the subsequent access request, before granting access to the resource in response to the at least one endpoint of the subsequent access request falling within permissible endpoints specified by the new policy information.

12. A system, comprising:

at least one processor; and

memory including instructions that, when executed by the at least one processor, cause the system to:

detect a change in at least one endpoint that is virtual, that is for data service in a resource provider environment, and that is associated with a security policy for at least one resource;

automatically generate policy information associated with the at least one resource based in part on an indication in the security policy made by an entity to be associated with the at least one resource;

publish new policy information associated with the change in the at least one endpoint; and

cause the new policy information to be applied for the security policy, wherein subsequent access request relating to the resource is enabled for the security policy that includes the new policy information.

13. The system of claim 12 , wherein the instructions when executed further cause the system to:

cause the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.

14. The system of claim 12 , wherein the instructions when executed further cause the system to:

receive the new policy information in a customer policy manager;

generate a notification to a customer resource administrator regarding the new policy information; and

enable the customer resource administrator to apply the new policy information for the security policy.

15. The system of claim 12 , wherein the instructions when executed further cause the system to:

detect the change in the at least one endpoint using a task-based resource;

generate the new policy information based at least in part on the change in the at least one endpoint; and

provide the new policy information for publication by a notification service.

16. The system of claim 12 , wherein the new policy information is published using at least one of email messaging, instant messaging, short message service messaging, or text messaging.

17. The system of claim 12 , wherein the instructions when executed further cause the system to:

validate a customer access credential, received with the subsequent access request, before granting access to the resource in response to the at least one endpoint of the subsequent access request falling within permissible endpoints specified by the new policy information.

18. A non-transitory computer readable medium comprising instructions that when executed by a processor of a system causes the system to:

detect a change in at least one endpoint that is virtual, that is for data service in a resource provider environment, and that is associated with a security policy for at least one resource;

automatically generate policy information associated with the at least one resource based in part on an indication in the security policy made by an entity to be associated with the at least one resource;

publish new policy information associated with the change in the at least one endpoint; and

cause the new policy information to be applied for the security policy, wherein subsequent access request relating to the resource is enabled for the security policy that includes the new policy information.

19. The non-transitory computer readable medium of claim 18 , comprising the instructions that when executed by the processor of the system further causes the system to:

cause the new policy information to be applied for the security policy using a policy manager of a resource provider environment, the resource being at least one of a physical computing resource or a virtual computing resource provided using resources of the resource provider environment.

20. The non-transitory computer readable medium of claim 19 , further comprising:

receive the new policy information in a customer policy manager;

generate a notification to a customer resource administrator regarding the new policy information; and

enable the customer resource administrator to apply the new policy information for the security policy.

Continuity (3)
Continuation 17104905 · Nov 25, 2020
Continuation 15616456 · Jun 7, 2017
Related Publication 20220217182A1 · Jul 7, 2022
References Cited (181)
US 7478418B2 · Supramaniam · 2009 [cited by examiner]
US 7546629B2 · Albert · 2009 [cited by applicant]
US 7796593B1 · Ghosh · 2010 [cited by applicant]
US 7835348B2 · Kasralikar · 2010 [cited by examiner]
US 8074270B1 · Lordello · 2011 [cited by examiner]
US 8185935B2 · Hsu · 2012 [cited by examiner]
US 8307422B2 · Varadhan et al. · 2012 [cited by applicant]
US 8363658B1 · Delker et al. · 2013 [cited by applicant]
US 8479266B1 · Delker et al. · 2013 [cited by applicant]
US 8499348B1 · Rubin · 2013 [cited by examiner]
US 8612612B1 · Dukes · 2013 [cited by examiner]
US 8739257B1 · Robinson · 2014 [cited by examiner]
US 8806568B2 · Biazetti · 2014 [cited by examiner]
US 8881276B2 · Kratzer · 2014 [cited by examiner]
US 9088618B1 · Gridnev · 2015 [cited by applicant]
US 9167550B2 · Mahaffey · 2015 [cited by examiner]
US 9325739B1 · Roth · 2016 [cited by examiner]
US 9510388B1 · Gegout · 2016 [cited by examiner]
US 9521147B2 · Barton · 2016 [cited by examiner]
US 9584436B1 · Rodgers · 2017 [cited by examiner]
US 9621585B1 · Satish · 2017 [cited by examiner]
US 9736185B1 · Belamaric · 2017 [cited by examiner]
US 9756050B1 · Brandwine · 2017 [cited by examiner]
US 9787686B2 · Stuntebeck · 2017 [cited by applicant]
US 9854001B1 · Roth · 2017 [cited by examiner]
US 9935980B2 · Karhade · 2018 [cited by examiner]
US 10116662B2 · Stuntebeck · 2018 [cited by applicant]
US 10135874B1 · Perry · 2018 [cited by examiner]
US 10484334B1 · Lee · 2019 [cited by examiner]
US 10542077B1 · Balakrishnan · 2020 [cited by examiner]
US 10623528B2 · Saheba · 2020 [cited by applicant]
US 10635541B2 · Wei · 2020 [cited by applicant]
US 10673817B2 · Garcia Azorero · 2020 [cited by examiner]
US 10749987B2 · Moss · 2020 [cited by applicant]
US 10762559B2 · Alejo · 2020 [cited by applicant]
US 10764399B2 · Whang · 2020 [cited by applicant]
US 10834050B2 · Call · 2020 [cited by applicant]
US 10951473B1 · Jaisinghani · 2021 [cited by examiner]
US 11025647B2 · Cooper · 2021 [cited by examiner]
US 11467882B2 · Gossman · 2022 [cited by applicant]
US 11961026B2 · Ricard · 2024 [cited by applicant]
US 12076649B2 · Gillis · 2024 [cited by examiner]
US 20030130953A1 · Narasimhan · 2003 [cited by applicant]
US 20040225717A1 · Cuervo · 2004 [cited by examiner]
US 20050073997A1 · Riley · 2005 [cited by examiner]
US 20050198363A1 · Ling · 2005 [cited by examiner]
US 20050239458A1 · Hurtta · 2005 [cited by examiner]
US 20050283823A1 · Okajo · 2005 [cited by examiner]
US 20070118881A1 · Mitchell · 2007 [cited by examiner]
US 20070143824A1 · Shahbazi · 2007 [cited by applicant]
US 20070157286A1 · Singh · 2007 [cited by examiner]
US 20080032729A1 · Luo · 2008 [cited by examiner]
US 20080127345A1 · Holtmanns · 2008 [cited by examiner]
US 20080175243A1 · Bhagwan · 2008 [cited by examiner]
US 20080209535A1 · Athey · 2008 [cited by examiner]
US 20080222692A1 · Andersson · 2008 [cited by examiner]
US 20080222694A1 · Nakae · 2008 [cited by examiner]
US 20090199178A1 · Keller · 2009 [cited by examiner]
US 20090249472A1 · Litvin · 2009 [cited by examiner]
US 20090327908A1 · Hayton · 2009 [cited by examiner]
US 20090327909A1 · Hayton · 2009 [cited by examiner]
US 20090328219A1 · Narayanaswamy · 2009 [cited by examiner]
US 20100042674A1 · Pantalone · 2010 [cited by examiner]
US 20100071024A1 · Eyada · 2010 [cited by examiner]
US 20100071043A1 · Babula · 2010 [cited by examiner]
US 20100115101A1 · Lain · 2010 [cited by examiner]
US 20100284327A1 · Miklos · 2010 [cited by examiner]
US 20100293596A1 · Terry · 2010 [cited by examiner]
US 20100332963A1 · Ellis · 2010 [cited by examiner]
US 20100333168A1 · Herrod · 2010 [cited by applicant]
US 20110009107A1 · Guba · 2011 [cited by examiner]
US 20110047125A1 · Matsumoto · 2011 [cited by applicant]
US 20110061014A1 · Frader-Thompson · 2011 [cited by examiner]
US 20110154320A1 · Verma · 2011 [cited by examiner]
US 20110158085A1 · Aloush · 2011 [cited by examiner]
US 20110231900A1 · Shimoe · 2011 [cited by examiner]
US 20110270908A1 · Kern · 2011 [cited by applicant]
US 20120023546A1 · Kartha · 2012 [cited by examiner]
US 20120030751A1 · Datta · 2012 [cited by examiner]
US 20130019276A1 · Biazetti · 2013 [cited by examiner]
US 20130047224A1 · Radhakrishnan · 2013 [cited by examiner]
US 20130047226A1 · Radhakrishnan · 2013 [cited by examiner]
US 20130107889A1 · Barabash · 2013 [cited by examiner]
US 20130117837A1 · Kapadia · 2013 [cited by examiner]
US 20130133059A1 · Maman · 2013 [cited by examiner]
US 20130170348A1 · Luna · 2013 [cited by examiner]
US 20130191257A1 · Koodli · 2013 [cited by examiner]
US 20130235822A1 · Scherer · 2013 [cited by examiner]
US 20130247217A1 · Junod · 2013 [cited by examiner]
US 20130304917A1 · Mittal · 2013 [cited by examiner]
US 20140007214A1 · Qureshi · 2014 [cited by examiner]
US 20140032758A1 · Barton · 2014 [cited by examiner]
US 20140033271A1 · Barton · 2014 [cited by examiner]
US 20140040979A1 · Barton · 2014 [cited by examiner]
US 20140068035A1 · Croy · 2014 [cited by applicant]
US 20140096134A1 · Barak · 2014 [cited by examiner]
US 20140115578A1 · Cooper · 2014 [cited by examiner]
US 20140156814A1 · Barabash · 2014 [cited by applicant]
US 20140181290A1 · Wong · 2014 [cited by applicant]
US 20140211795A1 · Chiba · 2014 [cited by examiner]
US 20140245423A1 · Lee · 2014 [cited by examiner]
US 20140280846A1 · Gourlay · 2014 [cited by examiner]
US 20140331277A1 · Frascadore · 2014 [cited by examiner]
US 20140359620A1 · Van Kerkwyk · 2014 [cited by examiner]
US 20140379915A1 · Yang · 2014 [cited by examiner]
US 20150005004A1 · Cuervo · 2015 [cited by examiner]
US 20150026758A1 · Payyappilly · 2015 [cited by examiner]
US 20150074756A1 · Deng · 2015 [cited by examiner]
US 20150082370A1 · Jayaraman · 2015 [cited by examiner]
US 20150085664A1 · Sachdev et al. · 2015 [cited by applicant]
US 20150131488A1 · Perez Martinez · 2015 [cited by examiner]
US 20150188947A1 · Zaitsev · 2015 [cited by examiner]
US 20150199506A1 · Gouda · 2015 [cited by examiner]
US 20150200808A1 · Gourlay · 2015 [cited by examiner]
US 20150263865A1 · Rangarajan · 2015 [cited by applicant]
US 20150312102A1 · Backholm · 2015 [cited by examiner]
US 20150358358A1 · Karhade · 2015 [cited by applicant]
US 20150378765A1 · Singh · 2015 [cited by examiner]
US 20160044060A1 · Biswas · 2016 [cited by applicant]
US 20160050141A1 · Wu · 2016 [cited by examiner]
US 20160070551A1 · Miller · 2016 [cited by applicant]
US 20160073146A1 · Phillips · 2016 [cited by examiner]
US 20160092257A1 · Wang · 2016 [cited by examiner]
US 20160105446A1 · Chen · 2016 [cited by applicant]
US 20160191466A1 · Pernicha · 2016 [cited by examiner]
US 20160212166A1 · Henry · 2016 [cited by examiner]
US 20160212167A1 · Dotan · 2016 [cited by examiner]
US 20160212168A1 · Dotan · 2016 [cited by examiner]
US 20160212170A1 · Martherus · 2016 [cited by examiner]
US 20160241443A1 · Bidaralli · 2016 [cited by examiner]
US 20160277448A1 · Saida · 2016 [cited by examiner]
US 20160308908A1 · Kirby · 2016 [cited by applicant]
US 20160359913A1 · Gupta · 2016 [cited by applicant]
US 20170046183A1 · Lei · 2017 [cited by applicant]
US 20170048107A1 · Dosovitsky · 2017 [cited by examiner]
US 20170048713A1 · Guday · 2017 [cited by examiner]
US 20170054757A1 · Siswick · 2017 [cited by examiner]
US 20170063927A1 · Schultz · 2017 [cited by examiner]
US 20170093913A1 · Summers · 2017 [cited by examiner]
US 20170099182A1 · DeBolle · 2017 [cited by examiner]
US 20170099187A1 · Dale · 2017 [cited by examiner]
US 20170103201A1 · Fox · 2017 [cited by examiner]
US 20170104755A1 · Arregoces · 2017 [cited by applicant]
US 20170109187A1 · Cropper · 2017 [cited by examiner]
US 20170111476A1 · Saheba · 2017 [cited by applicant]
US 20170149843A1 · Amulothu · 2017 [cited by applicant]
US 20170170990A1 · Gaddehosur · 2017 [cited by examiner]
US 20170214717A1 · Bush · 2017 [cited by examiner]
US 20170244723A1 · Prasad · 2017 [cited by applicant]
US 20170264622A1 · Cooper · 2017 [cited by examiner]
US 20170331692A1 · Hague · 2017 [cited by examiner]
US 20170331791A1 · Wardell · 2017 [cited by examiner]
US 20170366551A1 · Brandwine · 2017 [cited by applicant]
US 20170374568A1 · Heath · 2017 [cited by examiner]
US 20180034777A1 · Jeong · 2018 [cited by examiner]
US 20180124734A1 · Upadhyaya · 2018 [cited by applicant]
US 20180176186A1 · Chao · 2018 [cited by examiner]
US 20180176257A1 · Kumar · 2018 [cited by applicant]
US 20180255102A1 · Ward · 2018 [cited by applicant]
US 20180262454A1 · Zandi · 2018 [cited by examiner]
US 20180262585A1 · Zandi · 2018 [cited by examiner]
US 20180262592A1 · Zandi · 2018 [cited by examiner]
US 20180270133A1 · Yedavalli · 2018 [cited by applicant]
US 20180270363A1 · Guday · 2018 [cited by examiner]
US 20180316676A1 · Gilpin · 2018 [cited by applicant]
US 20190021124A1 · Fernandez Alonso · 2019 [cited by examiner]
US 20190028992A1 · Kim · 2019 [cited by examiner]
US 20190075133A1 · Chen · 2019 [cited by applicant]
US 20190273635A1 · McNamee · 2019 [cited by examiner]
US 20200037148A1 · Wang · 2020 [cited by examiner]
US 20200059492A1 · Janakiraman · 2020 [cited by applicant]
Non-Final Rejection issued in U.S. Appl. No. 17/104,905, dated Jul. 13, 2022 (020346.094402). [cited by applicant]
Final Rejection issued in U.S. Appl. No. 17/104,905, dated Dec. 14, 2022 (020346.094402). [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 17/104,905, dated Mar. 1, 2023 (020346.094402). [cited by applicant]
Non-Final Rejection issued in U.S. Appl. No. 15/616,456, dated Apr. 11, 2019 (020346.094401). [cited by applicant]
Final Rejection issued in U.S. Appl. No. 15/616,456, dated Oct. 28, 2019 (020346.094401). [cited by applicant]
Non-Final Rejection issued in U.S. Appl. No. 15/616,456, dated Mar. 20, 2020 (020346.094401). [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 15/616,456, dated Aug. 20, 2020 (020346.094401). [cited by applicant]
Final Rejection issued in U.S. Appl. No. 18/196,269, dated May 22, 2024. [cited by applicant]
Non-Final Rejection issued in U.S. Appl. No. 18/196,269, dated Dec. 19, 2023. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 18/196,269, dated Jul. 10, 2024. [cited by applicant]