IP Library Granted Patent US 12,476,970
Granted Patent B2
US 12,476,970 · App. 18/379,202 · Granted Nov 18, 2025

Validation of cloud provider application programming interface (API) privileges

Inventors: Suresh Balla (Visakhapatnam, IN); Umedh Meshram (Pune, IN)
Assignee: VMware LLC
H04L63/10G06F9/547
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,970
App. No.
18/379,202
Granted
Nov 18, 2025
Kind
B2
Abstract

Systems, apparatus, articles of manufacture, and methods are disclosed for template generation to enforce desired states on cloud accounts. An example apparatus disclosed herein includes programmable circuitry to access a privilege from a cloud account, the privilege associated with a resource to be deployed based on a template, validate the privilege relative to template privileges specified in the template, secure the resource before deployment of the resource by imputing a privilege access condition to the resource based on the privilege satisfying at least one of the template privileges, and deploy the resource based on the template in a secure state, the secure state corresponding to the privilege access condition.

Claims (41)

1 . An apparatus comprising:

interface circuitry;

machine readable instructions; and

programmable circuitry to at least one of instantiate or execute the machine readable instructions to:

access a privilege from a cloud account, the privilege associated with a resource to be deployed based on a template;

validate the privilege relative to template privileges specified in the template;

secure the resource before deployment of the resource by imputing a privilege access condition to the resource based on the privilege satisfying at least one of the template privileges; and

deploy the resource based on the template in a secured state, the secured state corresponding to the privilege access condition.

2 . The apparatus of claim 1 , wherein the privilege corresponds to an authorization of the cloud account to access a resource application programming interface (API) of a cloud provider using a credential.

3 . The apparatus of claim 2 , wherein the programmable circuitry is to compare the credential to the resource API to validate the privilege.

4 . The apparatus of claim 2 , wherein the programmable circuitry is to transmit an API call to get the template privileges corresponding to the cloud provider to perform an operation on the resource.

5 . The apparatus of claim 4 , wherein the programmable circuitry is to:

obtain an API response including the template privileges; and

compare the template privileges to a plurality of present privileges of the cloud account to validate the privilege, the privilege included in the plurality of present privileges.

6 . The apparatus of claim 2 , wherein the privilege is a first privilege, the resource is a first resource, the programmable circuitry is to validate a second privilege of the cloud account to secure a second resource before deployment of the second resource by imputing the privilege access condition to the second resource based on the second privilege satisfying at least one of the template privileges.

7 . The apparatus of claim 6 , wherein the programmable circuitry is to generate a notification indicating the second privilege is missing from the cloud account in response to the second privilege not being validated.

8 . A non-transitory machine readable storage medium comprising instructions to cause programmable circuitry to at least:

access a privilege from a cloud account, the privilege associated with a resource to be deployed based on a template;

validate the privilege relative to template privileges corresponding to the template;

secure the resource before deployment of the resource by imputing a privilege access condition to the resource based on the privilege satisfying at least one of the template privileges; and

deploy the resource based on the template in a secured state, the secured state corresponding to the privilege access condition.

9 . The non-transitory machine readable storage medium of claim 8 , wherein the privilege corresponds to an authorization of the cloud account to access a resource application programming interface (API) of a cloud provider using a credential.

10 . The non-transitory machine readable storage medium of claim 9 , wherein the instructions are to cause the programmable circuitry to compare the credential to the resource API to validate the privilege.

11 . The non-transitory machine readable storage medium of claim 10 , wherein the instructions are to cause the programmable circuitry to transmit an API call to get the template privileges corresponding to the cloud provider to perform an operation on the resource.

12 . The non-transitory machine read storage medium of claim 11 , wherein the instructions are to cause the programmable circuitry to:

obtain an API response including the template privileges; and

compare the template privileges to a plurality of present privileges of the cloud account to the validate the privilege, the privilege included in the plurality of present privileges.

13 . The non-transitory machine readable storage medium of claim 9 , wherein the privilege is a first privilege, the resource is a first resource, the instructions are to cause the programmable circuitry to validate a second privilege of the cloud account to secure a second resource before deployment of the second resource by imputing the privilege access condition to the second resource based on the second privilege satisfying at least one of the template privileges.

14 . The non-transitory machine readable storage medium of claim 13 , wherein the instructions are to cause the programmable circuitry to generate a notification indicating the second privilege is missing from the cloud account in response to the second privilege not being validated.

15 . A method comprising:

accessing a privilege from a cloud account, the privilege associated with a resource to be deployed based on a template;

validating the privilege relative to template privileges associated with the template;

securing, by executing an instruction with programmable circuitry, the resource before deployment of the resource by imputing a privilege access condition to the resource based on the privilege satisfying at least one of the template privileges; and

deploying, by executing an instruction with programmable circuitry, the resource based on the template in a secured state, the secured state corresponding to the privilege access condition.

16 . The method of claim 15 , wherein the privilege corresponds to an authorization of the cloud account to access a resource application programming interface (API) of a cloud provider using a credential, validating the privilege includes comparing the credential to the resource API.

17 . The method of claim 16 , further including transmitting an API call to get the template privileges corresponding to the cloud provider to perform an operation on the resource.

18 . The method of claim 17 , further including:

obtaining an API response including the template privileges; and

comparing the template privileges to a plurality of present privileges of the cloud account for validation of the privilege, the privilege included in the plurality of present privileges.

19 . The method of claim 16 , wherein the privilege is a first privilege, the resource is a first resource, further including validating a second privilege of the cloud account to secure a second resource before deployment of the second resource by imputing the privilege access condition to the second resource based on the second privilege satisfying at least one of the template privileges.

20 . The method of claim 19 , further including generating a notification indicating the second privilege is missing from the cloud account in response to the second privilege not being validated.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2023
From: BALLA, SURESH; MESHRAM, UMEDH
To: VMWARE, INC.
Reel/Frame 065192/0858 →
Priority Claims (1)
IN 202341053301 · Aug 9, 2023 · national
Continuity (1)
Related Publication 20250055847A1 · Feb 13, 2025
References Cited (7)
US 10382275B1 · Stickle · 2019 [cited by examiner]
US 10891121B2 · Govindaraju et al. · 2021 [cited by applicant]
US 20180227369A1 · DuCray · 2018 [cited by examiner]
US 20230409408A1 · Walshe · 2023 [cited by examiner]
US 20230412570A1 · Holm · 2023 [cited by examiner]
US 20240007492A1 · Shen · 2024 [cited by examiner]
US 20240305634A1 · Wattiau · 2024 [cited by examiner]