IP Library Granted Patent US 12,483,593
Granted Patent B2
US 12,483,593 · App. 17/721,038 · Granted Nov 25, 2025

Distributed hybrid model for security as a service

Inventors: Anamika Bhattacharya (Bangalore, IN); Deepak Bharadwaj (Bangalore, IN); Sriranga Seetharamaiah (Bangalore, IN); Abhisek Sanyal (Bangalore, IN); Siddaraya Revashetti (Cupertino, CA)
Assignee: Musarubra US LLC
H04L63/20H04L63/0414H04L63/104H04L63/108H04L63/205H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,593
App. No.
17/721,038
Granted
Nov 25, 2025
Kind
B2
Abstract

An apparatus includes a network interface and a processor. The network interface receives an application programming interface (API) request, transmits a customer management request including an identifier of the customer apparatus, and receives a customer management response including a policy. The processor performs a security service on the API request, at least in part based on the policy.

Claims (47)

1 . An apparatus to distribute security services between a vendor infrastructure and a customer infrastructure, the apparatus comprising:

a network interface to receive, from the vendor infrastructure associated with a security service in a hybrid cloud, a policy for performing the security service across the hybrid cloud;

executable instructions; and

one or more processor circuits to be programmed by the executable instructions to:

cause the network interface to transmit a service request to the vendor infrastructure to process non-sensitive data at the vendor infrastructure, the non-sensitive data included in an application programming interface (API) request for the security service;

maintain sensitive data included in the API request within the customer infrastructure without transferring the sensitive data outside the customer infrastructure; and

process, at the customer infrastructure, the sensitive data with the security service based on (1) the policy and (2) a service result generated at the vendor infrastructure based on the service request, the sensitive data included in the API request.

2 . The apparatus of claim 1 , wherein the service result is a first service result, and the network interface is to:

transmit the service request to the vendor infrastructure, the service request including the non-sensitive data;

receive a service response from the vendor infrastructure, the service response including the first service result; and

transmit an API response, the API response based on a second service result generated by the security service.

3 . The apparatus of claim 2 , wherein at least one of the one or more processor circuits is to separate the API request into the non-sensitive data and the sensitive data based on the policy.

4 . The apparatus of claim 1 , wherein the network interface is to transmit a policy request based on a receipt of the API request.

5 . The apparatus of claim 1 , wherein:

at least one of the one or more processor circuits is to produce a client artifact based on processing the sensitive data with the security service; and

the network interface is to transmit the client artifact.

6 . The apparatus of claim 1 , wherein the non-sensitive data at least one of a workload configuration or a checksum of a file, the workload configuration including at least one of an allowed length of a password, whether special characters are allowed for the password, or which of the special characters are allowed for the password.

7 . The apparatus of claim 1 , wherein the sensitive data includes at least one of an internet protocol address, a tag, a user identifier, or personally identifiable information.

8 . A method to distribute security services between a vendor infrastructure and a customer infrastructure, the method comprising:

receiving, from the vendor infrastructure associated with a security service in a hybrid cloud, a policy for performing the security service across the hybrid cloud;

transmitting a service request to the vendor infrastructure to process non-sensitive data at the vendor infrastructure, the non-sensitive data included in an application programming interface (API) request for the security service;

maintaining sensitive data included in the API request within the customer infrastructure without transferring the sensitive data outside the customer infrastructure; and

processing, at the customer infrastructure, the sensitive data with the security service based on (1) the policy and (2) a service result generated at the vendor infrastructure based on the service request.

9 . The method of claim 8 , wherein the service result is a first service result, and the method further includes:

transmitting the service request to the vendor infrastructure, the service request including the non-sensitive data;

receiving a service response from the vendor infrastructure, the service response including the first service result; and

transmitting an API response, the API response based on a second service result generated by the security service.

10 . The method of claim 9 , further including separating the API request into the non-sensitive data and the sensitive data based on the policy.

11 . The method of claim 8 , further including transmitting a policy request based on a receipt of the API request.

12 . The method of claim 8 , further including:

producing a client artifact based on processing the sensitive data with the security service; and

transmitting the client artifact.

13 . The method of claim 8 , wherein the non-sensitive data at least one of a workload configuration or a checksum of a file, the workload configuration including at least one of an allowed length of a password, whether special characters are allowed for the password, or which of the special characters are allowed for the password.

14 . The method of claim 8 , wherein the sensitive data includes at least one of an internet protocol address, a tag, a user identifier, or personally identifiable information.

15 . A non-transitory computer-readable medium comprising executable instructions that cause one or more processor circuits to:

receive, from a vendor infrastructure associated with a security service in a hybrid cloud, a policy for performing the security service across the hybrid cloud;

cause transmission of a service request to the vendor infrastructure to process non-sensitive data at the vendor infrastructure, the non-sensitive data included in an application programming interface (API) request for the security service;

maintain sensitive data included in the API request within a customer infrastructure without transferring the sensitive data outside the customer infrastructure; and

process, at the customer infrastructure, the sensitive data with the security service based on (1) the policy and (2) a service result generated at the vendor infrastructure based on the service request.

16 . The non-transitory computer-readable medium of claim 15 , wherein the service result is a first service result, and the executable instructions cause at least one of the one or more processor circuits to:

cause transmission of the service request to the vendor infrastructure, the service request including the non-sensitive data;

access a service response from the vendor infrastructure, the service response including the first service result; and

cause transmission of an API response, the API response based on a second service result generated by the security service.

17 . The non-transitory computer-readable medium of claim 16 , wherein the executable instructions cause at least one of the one or more processor circuits to separate the API request into the non-sensitive data and the sensitive data based on the policy.

18 . The non-transitory computer-readable medium of claim 15 , wherein the executable instructions cause at least one of the one or more processor circuits to transmit a policy request based on a receipt of the API request.

19 . The non-transitory computer-readable medium of claim 15 , wherein the non-sensitive data at least one of a workload configuration or a checksum of a file, the workload configuration including at least one of an allowed length of a password, whether special characters are allowed for the password, or which of the special characters are allowed for the password.

20 . The non-transitory computer-readable medium of claim 15 , wherein the sensitive data includes at least one of an internet protocol address, a tag, a user identifier, or personally identifiable information.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2023
From: BHATTACHARYA, ANAMIKA; BHARADWAJ, DEEPAK; SEETHARAMAIAH, SRIRANGA; SANYAL, ABHISEK
To: MUSARUBRA US LLC
Reel/Frame 064174/0335 →
Priority Claims (1)
IN 202141017560 · Apr 15, 2021 · national
Continuity (1)
Related Publication 20220337598A1 · Oct 20, 2022
References Cited (12)
US 8914406B1 · Haugsnes · 2014 [cited by examiner]
US 10979403B1 · Mutescu et al. · 2021 [cited by applicant]
US 11716323B1 · Moghal · 2023 [cited by examiner]
US 20150347765A1 · Hankins, Jr. · 2015 [cited by examiner]
US 20160269427A1 · Haugsnes · 2016 [cited by examiner]
US 20160366184A1 · Luo · 2016 [cited by examiner]
US 20170063930A1 · Chesla · 2017 [cited by examiner]
US 20200119981A1 · Guthrie · 2020 [cited by examiner]
US 20200380160A1 · Kraus · 2020 [cited by examiner]
US 20220141254A1 · Oswal · 2022 [cited by examiner]
US 20220210194A1 · Parekh · 2022 [cited by examiner]
US 20220239696A1 · Konda · 2022 [cited by examiner]