IP Library Granted Patent US 12,335,252
Granted Patent B2
US 12,335,252 · App. 18/198,030 · Granted Jun 17, 2025

Network security dynamic access control and policy enforcement

Inventors: Robert Dykes (Los Altos Hills, CA); Lebin Cheng (Saratoga, CA); Ravindra K. Balupari (San Jose, CA)
Assignee: IMPERVA, Inc.
H04L63/0807H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,252
App. No.
18/198,030
Granted
Jun 17, 2025
Kind
B2
Abstract

A network security system and method provide dynamic access control for a protected resource using a client-initiated ticket generation scheme. A client application receives, from an access control manager, a limited-use access ticket and may include the limited-use access ticket within application program interface (API) calls to a service application. The service application may forward the limited-use access ticket as a service access ticket to a ticket-based access control layer. A transaction monitor monitors run-time transaction information generated by the API calls to the service application and if the limited-use access ticket is detected in the run-time transaction information, forward the limited-use access ticket to the access control manager to perform validation of the limited-use access ticket. The ticket-based access control layer compares the service access ticket to the validated limited-use access ticket and determine whether to grant the client application access to the protected resource based on the comparison.

Claims (48)

1. A method comprising:

receiving, from an access control manager, a limited-use access ticket at a client application;

including the limited-use access ticket within application program interface (API) calls to a service application, the API calls to request data from a protected resource;

forwarding the limited-use access ticket as a service access ticket to a ticket-based access control layer;

monitoring run-time transaction information generated by the API calls to the service application, wherein a transaction monitor monitors the run-time transaction information and forwards the limited-use access ticket to the access control manager for a validation of the limited-use access ticket;

in response to detecting the limited-use access ticket in the run-time transaction information, performing the validation of the limited-use access ticket;

comparing, by the ticket-based access control layer, the service access ticket to the validated limited-use access ticket;

in response to determining that the service access ticket matches the validated limited-use ticket, granting the client application access to the protected resource.

2. The method of claim 1 , wherein the limited-use access ticket is a randomized limited-use access ticket.

3. The method of claim 1 , wherein the service access ticket is forwarded by the service application to the ticket-based access control layer while the service application performs application functions on behalf of the client application.

4. The method of claim 1 , wherein the limited-use access ticket is forwarded to the access control manager with an indication that the limited-use access ticket originates from the client application.

5. The method of claim 4 , further comprising:

providing, by the access control manager, the validated limited-use access ticket to the ticket-based access control layer.

6. The method of claim 1 , further comprising:

in response to determining that the service access ticket does not match the validated limited-use ticket, denying the client application access to the protected resource.

7. The method of claim 1 , wherein the validated limited-use ticket is one ticket in a list of validated access tickets stored on the ticket-based access control layer.

8. A system comprising:

a memory; and

a processor operatively coupled to the memory, the processor to:

receive, from an access control manager, a limited-use access ticket at a client application;

include the limited-use access ticket within application program interface (API) calls to a service application, the API calls to request data from a protected resource;

forward the limited-use access ticket as a service access ticket to a ticket-based access control layer;

monitor run-time transaction information generated by the API calls to the service application, wherein the processor uses a transaction monitor to monitor the run-time transaction information and forward the limited-use access ticket to the access control manager for a validation of the limited-use access ticket;

in response to detecting the limited-use access ticket in the run-time transaction information, perform the validation of the limited-use access ticket;

compare, by the ticket-based access control layer, the service access ticket to the validated limited-use access ticket;

in response to determining that the service access ticket matches the validated limited-use ticket, grant the client application access to the protected resource.

9. The system of claim 8 , wherein the limited-use access ticket is a randomized limited-use access ticket.

10. The system of claim 8 , wherein the processor forwards the service access ticket to the ticket-based access control layer using the service application while the service application performs application functions on behalf of the client application.

11. The system of claim 8 , wherein the limited-use access ticket is forwarded to the access control manager with an indication that the limited-use access ticket originates from the client application.

12. The system of claim 11 , wherein the processor is further to:

provide, by the access control manager, the validated limited-use access ticket to the ticket-based access control layer.

13. The system of claim 8 , wherein the processor is further to:

in response to determining that the service access ticket does not match the validated limited-use ticket, deny the client application access to the protected resource.

14. The system of claim 8 , wherein the validated limited-use ticket is one ticket in a list of validated access tickets stored on the ticket-based access control layer.

15. A non-transitory computer-readable medium having instructions stored thereon which, when executed by a processor, cause the processor to:

receive, from an access control manager, a limited-use access ticket at a client application;

include the limited-use access ticket within application program interface (API) calls to a service application, the API calls to request data from a protected resource;

forward the limited-use access ticket as a service access ticket to a ticket-based access control layer;

monitor run-time transaction information generated by the API calls to the service application, wherein the processor uses a transaction monitor to monitor the run-time transaction information and forward the limited-use access ticket to the access control manager for a validation of the limited-use access ticket;

in response to detecting the limited-use access ticket in the run-time transaction information, perform the validation of the limited-use access ticket;

compare, by the ticket-based access control layer, the service access ticket to the validated limited-use access ticket;

in response to determining that the service access ticket matches the validated limited-use ticket, grant the client application access to the protected resource.

16. The non-transitory computer-readable medium of claim 15 , wherein the limited-use access ticket is a randomized limited-use access ticket.

17. The non-transitory computer-readable medium of claim 15 , wherein the processor forwards the service access ticket to the ticket-based access control layer using the service application while the service application performs application functions on behalf of the client application.

18. The non-transitory computer-readable medium of claim 15 , wherein the limited-use access ticket is forwarded to the access control manager with an indication that the limited-use access ticket originates from the client application.

19. The non-transitory computer-readable medium of claim 18 , wherein the processor is further to:

provide, by the access control manager, the validated limited-use access ticket to the ticket-based access control laver.

20. The non-transitory computer-readable medium of claim 15 , wherein the processor is further to: in response to determining that the service access ticket does not match the validated limited-use ticket, deny the client application access to the protected resource.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded May 20, 2025
From: IMPERVA, INC.; ARECABAY, INC.
To: IMPERVA, INC.
Reel/Frame 071162/0933 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2023
From: DYKES, ROBERT; CHENG, LEBIN; BALUPARI, RAVINDRA K.
To: ARECABAY, INC.
Reel/Frame 063842/0053 →
Continuity (4)
Continuation 17349913 · Jun 17, 2021
Continuation 16375686 · Apr 4, 2019
Provisional Application 62655577 · Apr 10, 2018
Related Publication 20230370442A1 · Nov 16, 2023
References Cited (15)
US 6954792B2 · Kang et al. · 2005 [cited by applicant]
US 7941562B2 · Cheng et al. · 2011 [cited by applicant]
US 9197668B2 · Boucher et al. · 2015 [cited by applicant]
US 9479492B1 · Roth et al. · 2016 [cited by applicant]
US 20020049912A1 · Honjo · 2002 [cited by examiner]
US 20030188117A1 · Yoshino et al. · 2003 [cited by applicant]
US 20040243834A1 · Stefik et al. · 2004 [cited by applicant]
US 20090222903A1 · Sherkin · 2009 [cited by examiner]
US 20100023582A1 · Pedersen · 2010 [cited by examiner]
US 20100100924A1 · Hinton · 2010 [cited by applicant]
US 20150244735A1 · Kumar · 2015 [cited by examiner]
US 20170244730A1 · Sancheti et al. · 2017 [cited by applicant]
US 20180278653A1 · Narayanaswamy et al. · 2018 [cited by applicant]
PCT International Search Report and Written Opinion from related PCT Application No. PCT/US2019/026311, mailed Jul. 5, 2019, 11 pages. [cited by applicant]
Yuill, J. et al. “Honeyfiles: Deceptive Files for Intrusion Detection”, Proc. IEEE Workshop on Information Assurance, U.S. Military Academy, West Point, NY (Jun. 2004), 7 pages, DOI: 10.1109/IAW.2004.1437806. [cited by applicant]