IP Library Granted Patent US 12,470,546
Granted Patent B2
US 12,470,546 · App. 18/419,921 · Granted Nov 11, 2025

Enhanced infrastructure as code security

Inventors: Assaf Namer (Sunnyvale, CA); Brandon Maltzman (Deerfield, IL); Olanrewaju Ogunmola (Manassas, VA)
Assignee: Google LLC
H04L63/083H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,546
App. No.
18/419,921
Filed
Jan 23, 2024
Granted
Nov 11, 2025
Kind
B2
Art Unit
2451
USPC
726/6
Abstract

A method includes receiving, at a server, an authorizing request pertaining to authorization of future modification to a plurality of computing resources of a computing resource environment, the authorizing request comprising first credentials and an authorization value that is based on a first computing resource environment configuration file and a second computing resource environment configuration file. The method includes, responsive to a validation of the first credentials, storing the authorization value in a datastore. The method includes, receiving, at the server, a modification request comprising second credentials and comparing the modification request to the stored authorization value. The method further includes, responsive to the modification request matching the stored authorization value and a validation of the second credentials, modifying the plurality of computing resources of the computing resource environment based on the first computing resource environment configuration file and the second computing resource environment configuration file.

Claims (49)

1 . A method comprising:

receiving, at a server, an authorizing request pertaining to authorization of future modifications to a plurality of computing resources of a computing resource environment, the authorizing request comprising first credentials and an authorization value that is based on a first computing resource environment configuration file and a second computing resource environment configuration file;

responsive to a validation of the first credentials, storing the authorization value in a datastore;

receiving, at the server, a modification request comprising second credentials;

comparing the modification request to the stored authorization value; and

responsive to the modification request matching the stored authorization value and a validation of the second credentials, modifying the plurality of computing resources of the computing resource environment based on the first computing resource environment configuration file and the second computing resource environment configuration file.

2 . The method of claim 1 , wherein the first computing resource environment configuration file has been modified subject to validation of third credentials, and wherein the second computing resource environment configuration file has been modified subject to validation of fourth credentials, wherein the third credentials and the fourth credentials are different.

3 . The method of claim 1 , wherein the authorization value comprises a first encrypted hypertext transfer protocol (HTTP) request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

4 . The method of claim 3 , wherein the first encrypted HTTP request is generated by a source control and encrypted by a key management system (KMS).

5 . The method of claim 4 , wherein the modification request further comprises a second encrypted HTTP request received from the source control.

6 . The method of claim 1 , wherein the authorization value comprises a first encrypted hash based on a hash of an HTTP request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

7 . The method of claim 6 , wherein the comparing the modification request to the stored authorization value comprises:

retrieving the stored authorization value from the datastore;

decrypting the first encrypted hash of the stored authorization value to obtain a decrypted hash;

calculating a second hash based on at least a portion of the modification request; and

comparing the decrypted hash to the second hash.

8 . A system comprising:

a memory device; and

a processing device coupled to the memory device, the processing device to perform operations comprising:

receiving, at a server, an authorizing request pertaining to authorization of future modifications to a plurality of computing resources of a computing resource environment, the authorizing request comprising first credentials and an authorization value that is based on a first computing resource environment configuration file and a second computing resource environment configuration file;

responsive to a validation of the first credentials, storing the authorization value in a datastore;

receiving, at the server, a modification request comprising second credentials;

comparing the modification request to the stored authorization value; and

responsive to the modification request matching the stored authorization value and a validation of the second credentials, modifying the plurality of computing resources of the computing resource environment based on the first computing resource environment configuration file and the second computing resource environment configuration file.

9 . The system of claim 8 , wherein the first computing resource environment configuration file has been modified subject to validation of third credentials, and wherein the second computing resource environment configuration file has been modified subject to validation of fourth credentials, wherein the third credentials and the fourth credentials are different.

10 . The system of claim 8 , wherein the authorization value comprises a first encrypted hypertext transfer protocol (HTTP) request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

11 . The system of claim 10 , wherein the first encrypted HTTP request is generated by a source control and encrypted by a key management system (KMS).

12 . The system of claim 11 , wherein the modification request further comprises a second encrypted HTTP request received from the source control.

13 . The system of claim 8 , wherein the authorization value comprises a first encrypted hash based on a hash of an HTTP request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

14 . The system of claim 13 , wherein the comparing the modification request to the stored authorization value comprises:

retrieving the stored authorization value from the datastore;

decrypting the first encrypted hash of the stored authorization value to obtain a decrypted hash;

calculating a second hash based on at least a portion of the modification request; and

comparing the decrypted hash to the second hash.

15 . A non-transitory computer-readable storage medium comprising instructions that, when executed by a processing device, cause the processing device to perform operations comprising:

receiving, at a server, an authorizing request pertaining to authorization of future modifications to a plurality of computing resources of a computing resource environment, the authorizing request comprising first credentials and an authorization value that is based on a first computing resource environment configuration file and a second computing resource environment configuration file;

responsive to a validation of the first credentials, storing the authorization value in a datastore;

receiving, at the server, a modification request comprising second credentials;

comparing the modification request to the stored authorization value; and

responsive to the modification request matching the stored authorization value and a validation of the second credentials, modifying the plurality of computing resources of the computing resource environment based on the first computing resource environment configuration file and the second computing resource environment configuration file.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein the first computing resource environment configuration file has been modified subject to validation of third credentials, and wherein the second computing resource environment configuration file has been modified subject to validation of fourth credentials, wherein the third credentials and the fourth credentials are different.

17 . The non-transitory computer-readable storage medium of claim 15 , wherein the authorization value comprises a first encrypted hypertext transfer protocol (HTTP) request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the first encrypted HTTP request is generated by a source control and encrypted by a key management system (KMS).

19 . The non-transitory computer-readable storage medium of claim 15 , wherein the authorization value comprises a first encrypted hash based on a hash of an HTTP request based on the first computing resource environment configuration file and the second computing resource environment configuration file.

20 . The non-transitory computer-readable storage medium of claim 19 , wherein the comparing the modification request to the stored authorization value comprises:

retrieving the stored authorization value from the datastore;

decrypting the first encrypted hash of the stored authorization value to obtain a decrypted hash;

calculating a second hash based on at least a portion of the modification request; and

comparing the decrypted hash to the second hash.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: NAMER, ASSAF; MALTZMAN, BRANDON; OGUNMOLA, OLANREWAJU
To: GOOGLE LLC
Reel/Frame 066215/0908 →
Continuity (1)
Related Publication 20250240284A1 · Jul 24, 2025
References Cited (64)
US 7363361B2 · Tewari · 2008 [cited by examiner]
US 8214884B2 · Xia · 2012 [cited by examiner]
US 8452882B2 · Schneider · 2013 [cited by examiner]
US 8560820B2 · de Cesare · 2013 [cited by examiner]
US 8838961B2 · Zarfoss, III · 2014 [cited by examiner]
US 9584516B2 · Cai · 2017 [cited by examiner]
US 10382427B2 · Lambiase · 2019 [cited by examiner]
US 11068567B2 · Ramalingam · 2021 [cited by examiner]
US 11216265B1 · Hornbeck · 2022 [cited by examiner]
US 11368462B2 · North · 2022 [cited by examiner]
US 11372626B2 · White, III · 2022 [cited by examiner]
US 11429353B1 · Liguori · 2022 [cited by examiner]
US 11513864B2 · Koppes · 2022 [cited by examiner]
US 11550568B1 · Wall · 2023 [cited by examiner]
US 11811768B2 · Petersen · 2023 [cited by examiner]
US 11863562B1 · Mesard · 2024 [cited by examiner]
US 12105683B2 · Madan · 2024 [cited by examiner]
US 12174856B2 · Mehta · 2024 [cited by examiner]
US 12292982B2 · Plotnik · 2025 [cited by examiner]
US 12306819B2 · Pandey · 2025 [cited by examiner]
US 20110314532A1 · Austin · 2011 [cited by examiner]
US 20130205133A1 · Hess · 2013 [cited by examiner]
US 20140082350A1 · Zarfoss, III · 2014 [cited by examiner]
US 20140282919A1 · Mason · 2014 [cited by examiner]
US 20150007274A1 · Chang · 2015 [cited by examiner]
US 20150220718A1 · Hong · 2015 [cited by examiner]
US 20160011894A1 · Reddy · 2016 [cited by examiner]
US 20170048215A1 · Straub · 2017 [cited by examiner]
US 20170099148A1 · Ochmanski · 2017 [cited by examiner]
US 20190294477A1 · Koppes · 2019 [cited by examiner]
US 20210055917A1 · Khakare · 2021 [cited by examiner]
US 20210055927A1 · Sarukkai · 2021 [cited by examiner]
US 20210234925A1 · Cook · 2021 [cited by examiner]
US 20210326239A1 · Vaughan · 2021 [cited by examiner]
US 20220103518A1 · LaChance · 2022 [cited by examiner]
US 20220114023A1 · Choksi · 2022 [cited by examiner]
US 20230132503A1 · Plotnik · 2023 [cited by examiner]
US 20230132560A1 · Bunciak · 2023 [cited by examiner]
US 20230254330A1 · Singh · 2023 [cited by examiner]
US 20240037227A1 · Deutscher · 2024 [cited by examiner]
US 20240305583A1 · Naylor · 2024 [cited by examiner]
US 20240354293A1 · Liburdi · 2024 [cited by examiner]
US 20250016138A1 · Greene · 2025 [cited by examiner]
US 20250023771A1 · Chauhan · 2025 [cited by examiner]
US 20250030722A1 · Ragula · 2025 [cited by examiner]
US 20250047702A1 · Formicola · 2025 [cited by examiner]
US 20250111286A1 · Ghosh · 2025 [cited by examiner]
US 20250168219A1 · Li · 2025 [cited by examiner]
US 20250193020A1 · Patnala · 2025 [cited by examiner]
US 20250193151A1 · Kumar · 2025 [cited by examiner]
US 20250193152A1 · Madabhushi · 2025 [cited by examiner]
US 20250193155A1 · Narayanaswamy · 2025 [cited by examiner]
US 20250193231A1 · Chander · 2025 [cited by examiner]
US 20250193249A1 · Patnala · 2025 [cited by examiner]
US 20250193250A1 · Patnala · 2025 [cited by examiner]
US 20250193561A1 · Kumar · 2025 [cited by examiner]
Espinha Gasiba, Tiago, et al. “Raising security awareness of cloud deployments using infrastructure as code through cybersecurity challenges.” Proceedings of the 16th international conference on availability, reliabilit… [cited by examiner]
Sokolowski, Daniel. “Infrastructure as code for dynamic deployments.” Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering. 2022. [cited by examiner]
Verdet, Alexandre. Exploring security practices in infrastructure as code: An empirical study. MS thesis. Ecole Polytechnique, Montreal (Canada), 2023. [cited by examiner]
Rahman, Akond, Rezvan Mahdavi-Hezaveh, and Laurie Williams. “A systematic mapping study of infrastructure as code research.” Information and Software Technology 108 (2019): 65-77. [cited by examiner]
“API HMAC Authentication,” Oracle, 2022, downloaded Nov. 10, 2023, 5 pages. https://docs.oracle.com/en/cloud/saas/marketing/crowdtwist-develop/Developers/HMACAuthentication.html. [cited by applicant]
Li et al., et al., “Discovery Security Sample—WCF / Microsoft Learn,” Microsoft Ignite, Sep. 15, 2021, 4 pages. https://learn.microsoft.com/en-us/dotnet/framework/wcf/samples/discovery-security-sample. [cited by applicant]
Woodring, “How to Secure Webhook Endpoints with HMAC,” Prismatic, May 15, 2023, 11 pages. https://prismatic.io/blog/how-securewebhook-endpoints-hmac/. [cited by applicant]
Copparapu, “Digital signing with the new asymmetric keys feature of AWS KMS,” AWS Security Blog, Amazon, Nov. 25, 2019, 7 pages. https://aws.amazon.com/blogs/security/digital-signing-asymmetric-keys-aws-kms/. [cited by applicant]