IP Library Granted Patent US 12,299,502
Granted Patent B1
US 12,299,502 · App. 18/120,810 · Granted May 13, 2025

Processing API calls by authenticating and authorizing API calls

Inventors: Timothy L. Hinrichs (Los Altos, CA); Teemu Koponen (San Francisco, CA); Andrew Curtis (San Mateo, CA); Torin Sandall (San Francisco, CA); Octavian Florescu (Kirkland, WA)
Assignee: STYRA, INC.
G06F9/54G06F9/45533G06F9/45558G06F9/546G06F9/547G06F16/122G06F16/185G06F21/30G06F21/604G06F21/629H04L63/10H04L63/20G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,299,502
App. No.
18/120,810
Granted
May 13, 2025
Kind
B1
Abstract

Some embodiments of the invention provide a system for defining, distributing and enforcing policies for authorizing API (Application Programming Interface) calls to applications executing on one or more sets of associated machines (e.g., virtual machines, containers, computers, etc.) in one or more datacenters. This system has a set of one or more servers that acts as a logically centralized resource for defining and storing policies and parameters for evaluating these policies. The server set in some embodiments also enforces these API-authorizing policies. Conjunctively, or alternatively, the server set in some embodiments distributes the defined policies and parameters to policy-enforcing local agents that execute near the applications that process the API calls. From an associated application, a local agent receives API-authorization requests to determine whether API calls received by the application are authorized. In response to such a request, the local agent uses one or more parameters associated with the API call to identify a policy stored in its local policy storage to evaluate whether the API call should be authorized. To evaluate this policy, the agent might also retrieve one or more parameters from the local policy storage.

Claims (29)

1. A method for authorizing API (Application Programming Interface) calls to an application executing on a machine that is one of a plurality of machines operating on a host computer, the method comprising:

on the machine, of the plurality of machines that execute on the host computer, on which the application executes:

receiving an API call to the application executing on the machine;

using a first agent to perform an authentication operation to evaluate a set of credentials associated with the API call to determine whether the API call is from an entity that is allowed to make such an API call to the application;

when the set of credentials is authenticated to determine that the entity is allowed to make the API call to the application, using a second agent to perform an authorization operation to evaluate a set of API-authorization policies to determine whether the API call should be authorized for processing by the application; and

directing the application to process the API call when the authorization operation determines that the API call should be processed by the application.

2. The method of claim 1 , wherein the first and second agents execute on the host computer.

3. The method of claim 2 , wherein the API call is received by an API handler executing within the application, wherein the API handler uses the first and second agents, also executing within the application, to perform the authentication and authorization operations.

4. The method of claim 1 , wherein the second agent executes on the machine but not within the application while the first agent executes within the application.

5. The method of claim 1 , wherein the first agent executes on the computer while the second agent executes on another computer.

6. The method of claim 1 , wherein when the API call is part of a communication session that was previously authenticated, the method foregoes using the first agent to perform the authentication operation.

7. The method of claim 1 , wherein when the set of credentials is not authenticated, the API call is rejected and the authorization operation is not performed.

8. The method of claim 7 , wherein when the API call is rejected the application sends a rejection to a source of the API call.

9. The method of claim 1 , wherein when the set of credentials is not authenticated, the second agent performs the authorization operation by using the failure to authenticate as a parameter to evaluate the set of API-authorization policies.

10. A non-transitory machine readable medium storing a program for execution by at least one processing unit of a host computer on which a plurality of machines operate, the sets of instructions for authorizing API (Application Programming Interface) calls to an application executing on a machine of the plurality of machines, the program executing on the machine and comprising sets of instructions for:

receiving an API call to the application executing on the machine that is one of the plurality of machines executing on the host computer;

using a first agent to perform an authentication operation to evaluate a set of credentials associated with the API call to determine whether the API call is from an entity that is allowed to make such an API call to the application;

when the set of credentials is authenticated to determine that the entity is allowed to make the API call to the application, using a second agent to perform an authorization operation to evaluate a set of API-authorization policies to determine whether the API call should be authorized for processing by the application; and

directing the application to process the API call when the authorization operation determines that the API call should be processed by the application.

11. The non-transitory machine readable medium of claim 10 , wherein the first and second agents are also executed by the at least one processing unit of the host computer.

12. The non-transitory machine readable medium of claim 11 , wherein the program is an API handler that executes within the application, wherein the API handler uses the first and second agents, also executing within the application, to perform the authentication and authorization operations.

13. The non-transitory machine readable medium of claim 11 , wherein the second agent executes on the machine but not within the application while the first agent executes within the application.

14. The non-transitory machine readable medium of claim 10 , wherein the first agent executes on the computer while the second agent executes on another computer.

15. The non-transitory machine readable medium of claim 10 , wherein the program further comprises a set of instructions for determining that the API call is part of a communication session that was previously authenticated, wherein the program foregoes using the first agent to perform the authentication operation when the API call is part of a communication session that was previously authenticated.

16. The non-transitory machine readable medium of claim 10 , wherein the program further comprises a set of instructions for rejecting the API call when the set of credentials is not authenticated.

17. The non-transitory machine readable medium of claim 16 , wherein the set of instructions for rejecting the API call comprises a set of instructions for sending a rejection to a source of the API call.

18. The non-transitory machine readable medium of claim 10 , wherein the second agent performs the authorization operation by using the failure to authenticate as a parameter to evaluate the set of API-authorization policies when the set of credentials is not authenticated.

19. The method of claim 3 , wherein a plurality of applications execute on the machine, each respective application of the plurality of applications having a respective API handler to receive respective API calls and to use respective authentication and authorization agents executing within the respective application to perform authentication and authorization operations for the respective API calls.

20. The method of claim 19 , wherein the plurality of applications are micro-service applications.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2025
From: HINRICHS, TIMOTHY L.; KOPONEN, TEEMU; CURTIS, ANDREW; SANDALL, TORIN; FLORESCU, OCTAVIAN
To: STYRA, INC.
Reel/Frame 072020/0857 →
Continuity (3)
Continuation 16050143 · Jul 31, 2018
Provisional Application 62545458 · Aug 14, 2017
Provisional Application 62540547 · Aug 2, 2017
References Cited (153)
US 5974549A · Golan · 1999 [cited by applicant]
US 6460141B1 · Olden · 2002 [cited by applicant]
US 6985953B1 · Sandhu et al. · 2006 [cited by applicant]
US 7096367B2 · Garg et al. · 2006 [cited by applicant]
US 7124192B2 · High, Jr. et al. · 2006 [cited by applicant]
US 7752661B2 · Hemsath et al. · 2010 [cited by applicant]
US 7865931B1 · Stone et al. · 2011 [cited by applicant]
US 7913300B1 · Flank et al. · 2011 [cited by applicant]
US 7937755B1 · Guruswamy · 2011 [cited by applicant]
US 8266694B1 · Roy · 2012 [cited by applicant]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683560B1 · Brooker et al. · 2014 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8789138B2 · Reierson et al. · 2014 [cited by applicant]
US 8850528B2 · Biljon et al. · 2014 [cited by applicant]
US 9106661B1 · Stamos · 2015 [cited by applicant]
US 9374417B1 · Greenfield et al. · 2016 [cited by applicant]
US 9397990B1 · Taly et al. · 2016 [cited by applicant]
US 9420002B1 · McGovern et al. · 2016 [cited by applicant]
US 9521032B1 · Worsley · 2016 [cited by applicant]
US 9530020B2 · Brandwine et al. · 2016 [cited by applicant]
US 9578004B2 · Greenspan et al. · 2017 [cited by applicant]
US 9648040B1 · Morkel et al. · 2017 [cited by applicant]
US 9948681B1 · Kruse et al. · 2018 [cited by applicant]
US 10021103B2 · Xu et al. · 2018 [cited by applicant]
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10127393B2 · Ferraiolo et al. · 2018 [cited by applicant]
US 10148493B1 · Ennis, Jr. et al. · 2018 [cited by applicant]
US 10182129B1 · Peterson et al. · 2019 [cited by applicant]
US 10257184B1 · Mehta et al. · 2019 [cited by applicant]
US 10263995B1 · Kruse et al. · 2019 [cited by applicant]
US 10339303B2 · Mehta et al. · 2019 [cited by applicant]
US 10353726B2 · Duan · 2019 [cited by applicant]
US 10454975B1 · Mehr · 2019 [cited by applicant]
US 10469314B2 · Ennis, Jr. et al. · 2019 [cited by applicant]
US 10574699B1 · Baer et al. · 2020 [cited by applicant]
US 10592302B1 · Hinrichs · 2020 [cited by examiner]
US 10592683B1 · Lim et al. · 2020 [cited by applicant]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 10719373B1 · Koponen et al. · 2020 [cited by applicant]
US 10740470B2 · Ionescu et al. · 2020 [cited by applicant]
US 10789220B2 · Mayer et al. · 2020 [cited by applicant]
US 10984133B1 · Hinrichs et al. · 2021 [cited by applicant]
US 10986131B1 · Kruse et al. · 2021 [cited by applicant]
US 10990702B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11023292B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11080410B1 · Sandall et al. · 2021 [cited by applicant]
US 11108827B2 · Beckman et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11170099B1 · Sandall et al. · 2021 [cited by applicant]
US 11228573B1 · Rangasamy et al. · 2022 [cited by applicant]
US 11258824B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11327815B1 · Koponen et al. · 2022 [cited by applicant]
US 11425126B1 · Horal et al. · 2022 [cited by applicant]
US 11496517B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11509658B1 · Kulkarni · 2022 [cited by applicant]
US 11604684B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11681568B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11847241B1 · Cahill et al. · 2023 [cited by applicant]
US 11853463B1 · Hinrichs et al. · 2023 [cited by applicant]
US 20030115484A1 · Moriconi et al. · 2003 [cited by applicant]
US 20030220925A1 · Lior · 2003 [cited by applicant]
US 20040083367A1 · Garg et al. · 2004 [cited by applicant]
US 20050081058A1 · Chang et al. · 2005 [cited by applicant]
US 20050114674A1 · Carley · 2005 [cited by applicant]
US 20060053290A1 · Randle et al. · 2006 [cited by applicant]
US 20060059569A1 · Dasgupta · 2006 [cited by examiner]
US 20070006325A1 · Gargaro · 2007 [cited by applicant]
US 20070156670A1 · Lim · 2007 [cited by applicant]
US 20070226320A1 · Hager et al. · 2007 [cited by applicant]
US 20080022357A1 · Agarwal et al. · 2008 [cited by applicant]
US 20080184336A1 · Sarukkai et al. · 2008 [cited by applicant]
US 20090019533A1 · Hazlewood et al. · 2009 [cited by applicant]
US 20090055749A1 · Chatterjee et al. · 2009 [cited by applicant]
US 20090063665A1 · Bagepalli et al. · 2009 [cited by applicant]
US 20090077618A1 · Pearce et al. · 2009 [cited by applicant]
US 20090138960A1 · Felty et al. · 2009 [cited by applicant]
US 20090281996A1 · Liu et al. · 2009 [cited by applicant]
US 20100095373A1 · Levenshteyn et al. · 2010 [cited by applicant]
US 20100333079A1 · Sverdlov et al. · 2010 [cited by applicant]
US 20110113484A1 · Zeuthen · 2011 [cited by applicant]
US 20120030354A1 · Razzaq et al. · 2012 [cited by applicant]
US 20120066487A1 · Brown et al. · 2012 [cited by applicant]
US 20120066756A1 · Vysogorets et al. · 2012 [cited by applicant]
US 20120311672A1 · Connor et al. · 2012 [cited by applicant]
US 20120331539A1 · Matsugashita · 2012 [cited by applicant]
US 20130226970A1 · Weber et al. · 2013 [cited by applicant]
US 20130227636A1 · Bettini et al. · 2013 [cited by applicant]
US 20130283370A1 · Vipat et al. · 2013 [cited by applicant]
US 20130305354A1 · King et al. · 2013 [cited by applicant]
US 20140032691A1 · Barton et al. · 2014 [cited by applicant]
US 20140032733A1 · Barton et al. · 2014 [cited by applicant]
US 20140032759A1 · Barton et al. · 2014 [cited by applicant]
US 20140033267A1 · Aciicmez · 2014 [cited by applicant]
US 20140181186A1 · Stevens et al. · 2014 [cited by applicant]
US 20140237594A1 · Thakadu et al. · 2014 [cited by applicant]
US 20140372986A1 · Levin et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150213449A1 · Morrison et al. · 2015 [cited by applicant]
US 20150244724A1 · Xu et al. · 2015 [cited by applicant]
US 20160034900A1 · Nelsen et al. · 2016 [cited by applicant]
US 20160057027A1 · Hinrichs et al. · 2016 [cited by applicant]
US 20160057107A1 · Call et al. · 2016 [cited by applicant]
US 20160103870A1 · Patiejunas et al. · 2016 [cited by applicant]
US 20160188898A1 · Karinta et al. · 2016 [cited by applicant]
US 20160205101A1 · Verma et al. · 2016 [cited by applicant]
US 20160352695A1 · Kozolchyk et al. · 2016 [cited by applicant]
US 20160373455A1 · Shokhrin et al. · 2016 [cited by applicant]
US 20160381032A1 · Hashmi et al. · 2016 [cited by applicant]
US 20170024428A1 · Patiejunas et al. · 2017 [cited by applicant]
US 20170075938A1 · Black et al. · 2017 [cited by applicant]
US 20170111336A1 · Davis et al. · 2017 [cited by applicant]
US 20170124166A1 · Thomas et al. · 2017 [cited by applicant]
US 20170142068A1 · Devarajan et al. · 2017 [cited by applicant]
US 20170161120A1 · Sasaki et al. · 2017 [cited by applicant]
US 20170220370A1 · Klompje et al. · 2017 [cited by applicant]
US 20170237729A1 · Uppalapati · 2017 [cited by applicant]
US 20170279805A1 · Diaz-Cuellar et al. · 2017 [cited by applicant]
US 20170302655A1 · Sondhi et al. · 2017 [cited by applicant]
US 20170331629A1 · Kozolchyk et al. · 2017 [cited by applicant]
US 20170346807A1 · Blasi · 2017 [cited by applicant]
US 20170364702A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180062858A1 · Xu et al. · 2018 [cited by applicant]
US 20180067790A1 · Chheda et al. · 2018 [cited by applicant]
US 20180082053A1 · Brown et al. · 2018 [cited by applicant]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20180295036A1 · Krishnamurthy et al. · 2018 [cited by applicant]
US 20180309746A1 · Blasi · 2018 [cited by applicant]
US 20190007418A1 · Cook et al. · 2019 [cited by applicant]
US 20190007443A1 · Cook et al. · 2019 [cited by applicant]
US 20190020665A1 · Surcouf et al. · 2019 [cited by applicant]
US 20190080103A1 · Hadzic et al. · 2019 [cited by applicant]
US 20190190959A1 · Yuan · 2019 [cited by applicant]
US 20190230130A1 · Beckman et al. · 2019 [cited by applicant]
US 20190245862A1 · Kruse et al. · 2019 [cited by applicant]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20190386973A1 · Patwardhan et al. · 2019 [cited by applicant]
US 20200007580A1 · Liderman et al. · 2020 [cited by applicant]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210240550A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210248017A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210365571A1 · Sandall et al. · 2021 [cited by applicant]
US 20220269549A1 · Koponen et al. · 2022 [cited by applicant]
US 20240004728A1 · Hinrichs et al. · 2024 [cited by applicant]
Author Unknown, “API Best Practices Managing the API Lifecycle: Design, Delivery, and Everything in Between,” Dec. 2016, 37 pages, Apigee, retrieved from https://pages.apigee.com/rs/351-WXY-166/images/API-Best-Practices… [cited by applicant]
Costa, Jeff, “Improve API Performance with Caching,” API Gateway, May 31, 2018, 18 pages, Akamai Developer, retrieved from https://developer.akamai.com/blog/2018/05/31/improve-api-performance-caching. [cited by applicant]
Moffett, Jonathan D., et al., “Policy Hierarchies for Distributed Systems Management,” IEEE Journal on Selected Areas in Communications, Dec. 1993, 11 pages, vol. 11, IEEE, USA. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,119 with similar specification, filed Jul. 31, 2018, 55 pages, Styra, Inc. [cited by applicant]
Preuveneers, Davy, et al., “Access Control with Delegated Authorization Policy Evaluation for Data-Driven Microservice Workflows,” Future Internet, Sep. 30, 2017, 21 pages, vol. 9, Multidisciplinary Digital Publishing I… [cited by applicant]
Wei, Hao, et al., “Enhance OpenStack Access Control via Policy Enforcement Based on XACML,” In Proceedings of the 16th International Conference on Enterprise Information Systems, Apr. 2014, 7 pages, vol. 1, SciTePress, … [cited by applicant]
Win, Thu Yein, et al., “Virtualization Security Combining Mandatory Access Control and Virtual Machine Introspection,” 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, Dec. 8-11, 2014, 6 pages,… [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/239,714, filed Aug. 29, 2023, 68 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/369,471, filed Sep. 18, 2023, 74 pages, Styra, Inc. [cited by applicant]