IP Library › Granted Patent US 12,273,390
Granted Patent B2
US 12,273,390 · App. 18/176,330 · Granted Apr 8, 2025

Dynamic permissions management for cloud workloads

Inventors: Nitish Krishna Kaveri Poompatnam Chandrasekaran (Pleasanton, CA); Roman Porter (Bellevue, WA); Jeremy Erickson (Renton, WA); Tim Hofmann (San Francisco, CA)
Assignee: GM Cruise Holdings LLC
H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,390
App. No.
18/176,330
Granted
Apr 8, 2025
Kind
B2
Abstract

Applications supporting operations of an autonomous vehicle fleet can be implemented on and supported by cluster infrastructure. These applications have endpoints where data traffic runs in and out of these applications. Securing access to these endpoints can prevent unauthenticated and unauthorized access to these endpoints and the protected resources accessible through these endpoints. Securing access to these endpoints, managing entitlements and security policies, and maintaining security systems that can enforce the security policies are not trivial tasks. One solution addresses some of these challenges by offering a simple frontend for users to define the entitlements and security policies, leveraging an open source security solution, and ensuring backwards compatibility to other security solutions in the cluster infrastructure.

Claims (20)

1. A computer-implemented method for security policy management, comprising:

deploying a security policy agent sidecar application alongside an application deployed on cluster infrastructure;

receiving, from an application developer, a set of entitlements assigned to one or more of: users, groups, or services;

receiving, from the application developer, a route-based authorization policy for the application comprising one or more routes and entitlements to access the one or more routes;

generating a security policy bundle for the application by converting the set of entitlements and the route-based authorization policy into a format compatible with the security policy agent sidecar application; and

writing the security policy bundle for the application onto security policy bundle storage.

2. The computer-implemented method of claim 1 , wherein the set of entitlements and the route-based authorization policy are received through a user interface of a frontend application of an authorization manager.

3. The computer-implemented method of claim 1 , wherein the route-based authorization policy is received as a JavaScript Object Notation (JSON) file.

4. The computer-implemented method of claim 1 , further comprising:

transmitting a post request to send the route-based authorization policy to a backend application of a policy manager.

5. The computer-implemented method of claim 1 , further comprising:

validating and parsing, by a backend application of a policy manager, the route-based authorization policy; and

saving data parsed from the route-based authorization policy into a database.

6. The computer-implemented method of claim 1 , further comprising:

regularly checking a database storing security policies for one or more of: a new security policy, and a change to an existing security policy.

7. The computer-implemented method of claim 1 , wherein converting the set of entitlements and the route-based authorization policy comprises:

augmenting and formatting the entitlements and the route-based authorization policy into a JavaScript Object Notation (JSON) file and a policy code file; and

packaging the JSON file and the policy code file into an archive file, wherein the archive file is the security policy bundle for the application.

8. The computer-implemented method of claim 7 , wherein the JSON file includes the entitlements.

9. The computer-implemented method of claim 7 , wherein the JSON file includes entitlements directly assigned to users of a group.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2023
From: PORTER, ROMAN; ERICKSON, JEREMY; HOFMANN, TIM; KAVERI POOMPATNAM CHANDRASEKARAN, NITISH KRISHNA
To: GM CRUISE HOLDINGS LLC
Reel/Frame 062833/0215 →
Continuity (1)
Related Publication 20240291866A1 · Aug 29, 2024
References Cited (12)
US 7975286B1 · Fickey · 2011 [cited by examiner]
US 20190205115A1 · Gomes · 2019 [cited by examiner]
US 20220116445A1 · Filippou · 2022 [cited by examiner]
US 20220121470A1 · Saxena · 2022 [cited by examiner]
US 20220272127A1 · Yawalkar · 2022 [cited by examiner]
US 20230164567A1 · Fellows · 2023 [cited by examiner]
US 20240171613A1 · Pereira · 2024 [cited by examiner]
US 20240212496A1 · Xu · 2024 [cited by examiner]
[cited by applicant]
[cited by applicant]
[cited by applicant]
[cited by applicant]