IP Library Granted Patent US 12,287,906
Granted Patent B1
US 12,287,906 · App. 18/537,543 · Granted Apr 29, 2025

Leveraging standard protocols to interface unmodified applications and services

Inventors: Timothy L. Hinrichs (Los Altos, CA); Teemu Koponen (San Francisco, CA)
Assignee: STYRA, INC.
G06F21/629H04L63/0807H04L63/10H04L67/561H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,906
App. No.
18/537,543
Granted
Apr 29, 2025
Kind
B1
Abstract

Some embodiments provide a method for enforcing policies for authorizing API (Application Programming Interface) calls to an application operating on a host machine. The method receives a request to authenticate a client attempting to gain access to the application, and authenticates the client based on a first set of parameters associated with the request. Using a second set of parameters associated with the request, the method evaluates a set of one or more policies associated with a set of one or more API calls to the application. Based on the evaluated policies, the method defines a third set of one or more authentication field parameters that control the API calls that the client is authorized to make to the application. The method sends an authentication reply message with the defined third set of authentication field parameters in order to control the API calls that the client is authorized to make.

Claims (32)

1. A method for authorizing an API (Application Programming Interface) call sent from a client to an application, the method comprising:

providing, to an authentication provider, authentication credentials received from the application for the API call to receive, from the authentication provider, a set of one or more authentication parameters associated with the authentication credentials;

processing a set of one or more API policies for the API call and modifying the set of authentication parameters received from the authentication provider based on the processed set of API policies; and

providing the modified set of authentication parameters to the application for the application to send the modified set of authentication parameters to an authentication service that processes the modified set of authentication parameters to allow or reject the API call in accordance with the processed set of API policies.

2. The method of claim 1 , wherein the authentication credentials comprise an identifier that identifies the client.

3. The method of claim 2 , wherein the identifier comprises at least one of a username, a password, a user ID, a certificate, a group ID, and a credential associated with two-factor authentication.

4. The method of claim 1 , wherein the set of authentication parameters comprises role information associated with the client.

5. The method of claim 4 , wherein modifying the set of authentication parameters comprises modifying the role information associated with the client such that the role information provided to the application for the client is different than the role information received for the client from the authentication provider.

6. The method of claim 1 , wherein modifying the set of authentication parameters comprises ensuring that the API call is performed or rejected by the application based on the set of API policies.

7. The method of claim 1 , wherein the processed set of API policies influence what API calls or other actions the client can perform.

8. The method of claim 1 , wherein the set of API policies are stored in a hierarchical storage structure.

9. The method of claim 1 , wherein the authentication service is provided by a role-based access control (RBAC) system.

10. The method of claim 2 , wherein the client is one of a client application, a client machine, a client computer, or a client service.

11. The method of claim 1 , wherein:

the application is an Internet-based service that sends authentication requests to the authentication provider; and

the method is performed by an API authorization module interposed between the Internet-based service and the authentication provider.

12. The method of claim 11 , wherein the API authorization module processes authentication credentials and provides authentication parameters to a plurality of different Internet-based services.

13. The method of claim 1 , wherein:

the authentication parameters received from the authentication provider specify a first role for a user indicated in the received authentication credentials; and

modifying the set of authentication parameters based on the processed set of API policies comprises specifying a second role for the user based on the processed set of API policies, the second role provided to the application.

14. A non-transitory machine readable medium storing a program that when executed by a set of processing units authorizes an API (Application Programming Interface) call sent from a client to an application, the program comprising sets of instructions for:

providing, to an authentication provider, authentication credentials received for the API call to receive, from the authentication provider, a set of one or more authentication parameters associated with the authentication credentials;

processing a set of one or more API policies for the API call and modifying the set of authentication parameters received from the authentication provider based on the processed set of API policies; and

providing the modified set of authentication parameters to the application for the application to send the modified set of authentication parameters to an authentication service that processes the modified set of authentication parameters to allow or reject the API call in accordance with the processed set of API policies.

15. The non-transitory machine readable medium of claim 14 , wherein:

the authentication credentials comprise an identifier that identifies the client; and

the identifier comprises at least one of a username, a password, a user ID, a certificate, a group ID, and a credential associated with two-factor authentication.

16. The non-transitory machine readable medium of claim 14 , wherein the set of authentication parameters comprises role information associated with the client.

17. The non-transitory machine readable medium of claim 16 , wherein the set of instructions for modifying the set of authentication parameters comprises a set of instructions for modifying the role information associated with the client such that the role information provided to the application for the client is different than the role information received for the client from the authentication provider.

18. The non-transitory machine readable medium of claim 14 , wherein the set of instructions for modifying the set of authentication parameters comprises a set of instructions for ensuring that the API call is performed or rejected by the application based on the set of API policies.

19. The non-transitory machine readable medium of claim 14 , wherein the processed set of API policies influence what API calls or other actions the client can perform.

20. The non-transitory machine readable medium of claim 1 , wherein the client is one of a client application, a client machine, a client computer, or a client service.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2025
From: KOPONEN, TEEMU; HINRICHS, TIMOTHY L.
To: STYRA, INC.
Reel/Frame 072022/0555 →
Continuity (2)
Continuation 16293513 · Mar 5, 2019
Provisional Application 62721997 · Aug 23, 2018
References Cited (157)
US 5974549A · Golan · 1999 [cited by applicant]
US 6460141B1 · Olden · 2002 [cited by applicant]
US 6985953B1 · Sandhu · 2006 [cited by examiner]
US 7096367B2 · Garg et al. · 2006 [cited by applicant]
US 7124192B2 · High, Jr. et al. · 2006 [cited by applicant]
US 7752661B2 · Hemsath et al. · 2010 [cited by applicant]
US 7865931B1 · Stone et al. · 2011 [cited by applicant]
US 7913300B1 · Flank et al. · 2011 [cited by applicant]
US 7937755B1 · Guruswamy · 2011 [cited by applicant]
US 8266694B1 · Roy · 2012 [cited by applicant]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683560B1 · Brooker et al. · 2014 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8789138B2 · Reierson et al. · 2014 [cited by applicant]
US 8850528B2 · Biljon et al. · 2014 [cited by applicant]
US 9106661B1 · Stamos · 2015 [cited by applicant]
US 9189244B2 · McMahon · 2015 [cited by examiner]
US 9374417B1 · Greenfield et al. · 2016 [cited by applicant]
US 9397990B1 · Taly et al. · 2016 [cited by applicant]
US 9420002B1 · McGovern et al. · 2016 [cited by applicant]
US 9521032B1 · Worsley · 2016 [cited by applicant]
US 9530020B2 · Brandwine et al. · 2016 [cited by applicant]
US 9578004B2 · Greenspan et al. · 2017 [cited by applicant]
US 9648040B1 · Morkel et al. · 2017 [cited by applicant]
US 9948681B1 · Kruse et al. · 2018 [cited by applicant]
US 10021103B2 · Xu et al. · 2018 [cited by applicant]
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10127393B2 · Ferraiolo et al. · 2018 [cited by applicant]
US 10148493B1 · Ennis, Jr. et al. · 2018 [cited by applicant]
US 10182129B1 · Peterson et al. · 2019 [cited by applicant]
US 10257184B1 · Mehta et al. · 2019 [cited by applicant]
US 10263995B1 · Kruse et al. · 2019 [cited by applicant]
US 10339303B2 · Mehta et al. · 2019 [cited by applicant]
US 10353726B2 · Duan · 2019 [cited by applicant]
US 10454975B1 · Sharifi Mehr · 2019 [cited by examiner]
US 10469314B2 · Ennis, Jr. et al. · 2019 [cited by applicant]
US 10592302B1 · Hinrichs et al. · 2020 [cited by applicant]
US 10592683B1 · Lim et al. · 2020 [cited by applicant]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 10719373B1 · Koponen et al. · 2020 [cited by applicant]
US 10740470B2 · Ionescu et al. · 2020 [cited by applicant]
US 10789220B2 · Mayer et al. · 2020 [cited by applicant]
US 10984133B1 · Hinrichs et al. · 2021 [cited by applicant]
US 10986131B1 · Kruse et al. · 2021 [cited by applicant]
US 10990702B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11023292B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11080410B1 · Sandall et al. · 2021 [cited by applicant]
US 11108827B2 · Beckman et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11170099B1 · Sandall et al. · 2021 [cited by applicant]
US 11258824B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11327815B1 · Koponen et al. · 2022 [cited by applicant]
US 11425126B1 · Horal et al. · 2022 [cited by applicant]
US 11496517B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11509658B1 · Kulkarni · 2022 [cited by applicant]
US 11604684B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11681568B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11741244B2 · Sandall et al. · 2023 [cited by applicant]
US 11762712B2 · Koponen et al. · 2023 [cited by applicant]
US 11847241B1 · Cahill et al. · 2023 [cited by applicant]
US 11853463B1 · Hinrichs et al. · 2023 [cited by applicant]
US 20030115484A1 · Moriconi et al. · 2003 [cited by applicant]
US 20030220925A1 · Lior · 2003 [cited by applicant]
US 20040083367A1 · Garg et al. · 2004 [cited by applicant]
US 20050081058A1 · Chang et al. · 2005 [cited by applicant]
US 20050114674A1 · Carley · 2005 [cited by applicant]
US 20060053290A1 · Randle et al. · 2006 [cited by applicant]
US 20060059569A1 · Dasgupta et al. · 2006 [cited by applicant]
US 20070006325A1 · Gargaro · 2007 [cited by applicant]
US 20070156670A1 · Lim · 2007 [cited by applicant]
US 20070226320A1 · Hager et al. · 2007 [cited by applicant]
US 20080022357A1 · Agarwal et al. · 2008 [cited by applicant]
US 20080184336A1 · Sarukkai et al. · 2008 [cited by applicant]
US 20090019533A1 · Hazlewood et al. · 2009 [cited by applicant]
US 20090055749A1 · Chatterjee et al. · 2009 [cited by applicant]
US 20090063665A1 · Bagepalli et al. · 2009 [cited by applicant]
US 20090077618A1 · Pearce et al. · 2009 [cited by applicant]
US 20090138960A1 · Felty et al. · 2009 [cited by applicant]
US 20090281996A1 · Liu et al. · 2009 [cited by applicant]
US 20100070960A1 · Atsatt · 2010 [cited by applicant]
US 20100095373A1 · Levenshteyn et al. · 2010 [cited by applicant]
US 20100312852A1 · Kamga · 2010 [cited by examiner]
US 20100333079A1 · Sverdlov et al. · 2010 [cited by applicant]
US 20110113484A1 · Zeuthen · 2011 [cited by applicant]
US 20120030354A1 · Razzaq et al. · 2012 [cited by applicant]
US 20120066487A1 · Brown et al. · 2012 [cited by applicant]
US 20120066756A1 · Vysogorets · 2012 [cited by examiner]
US 20120311672A1 · Connor et al. · 2012 [cited by applicant]
US 20120331539A1 · Matsugashita · 2012 [cited by applicant]
US 20130226970A1 · Weber et al. · 2013 [cited by applicant]
US 20130227636A1 · Bettini et al. · 2013 [cited by applicant]
US 20130283370A1 · Vipat et al. · 2013 [cited by applicant]
US 20130305354A1 · King et al. · 2013 [cited by applicant]
US 20140032691A1 · Barton et al. · 2014 [cited by applicant]
US 20140032733A1 · Barton et al. · 2014 [cited by applicant]
US 20140032759A1 · Barton et al. · 2014 [cited by applicant]
US 20140033267A1 · Aciicmez · 2014 [cited by applicant]
US 20140122702A1 · Jung · 2014 [cited by examiner]
US 20140181186A1 · Stevens et al. · 2014 [cited by applicant]
US 20140237594A1 · Thakadu et al. · 2014 [cited by applicant]
US 20140372986A1 · Levin et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150213449A1 · Morrison · 2015 [cited by examiner]
US 20150244724A1 · Xu et al. · 2015 [cited by applicant]
US 20150254555A1 · Williams, Jr. et al. · 2015 [cited by applicant]
US 20160034900A1 · Nelsen · 2016 [cited by examiner]
US 20160057027A1 · Hinrichs et al. · 2016 [cited by applicant]
US 20160057107A1 · Call et al. · 2016 [cited by applicant]
US 20160103870A1 · Patiejunas et al. · 2016 [cited by applicant]
US 20160188898A1 · Karinta et al. · 2016 [cited by applicant]
US 20160205101A1 · Verma et al. · 2016 [cited by applicant]
US 20160352695A1 · Kozolchyk et al. · 2016 [cited by applicant]
US 20160373455A1 · Shokhrin et al. · 2016 [cited by applicant]
US 20160381032A1 · Hashmi et al. · 2016 [cited by applicant]
US 20170024428A1 · Patiejunas et al. · 2017 [cited by applicant]
US 20170075938A1 · Black et al. · 2017 [cited by applicant]
US 20170111336A1 · Davis et al. · 2017 [cited by applicant]
US 20170124166A1 · Thomas et al. · 2017 [cited by applicant]
US 20170142068A1 · Devarajan et al. · 2017 [cited by applicant]
US 20170161120A1 · Sasaki et al. · 2017 [cited by applicant]
US 20170220370A1 · Klompje et al. · 2017 [cited by applicant]
US 20170237729A1 · Uppalapati · 2017 [cited by applicant]
US 20170279805A1 · Diaz-Cuellar et al. · 2017 [cited by applicant]
US 20170302655A1 · Sondhi et al. · 2017 [cited by applicant]
US 20170331629A1 · Kozolchyk et al. · 2017 [cited by applicant]
US 20170346807A1 · Blasi · 2017 [cited by applicant]
US 20170364702A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180062858A1 · Xu et al. · 2018 [cited by applicant]
US 20180067790A1 · Chheda et al. · 2018 [cited by applicant]
US 20180082053A1 · Brown et al. · 2018 [cited by applicant]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20180295036A1 · Krishnamurthy et al. · 2018 [cited by applicant]
US 20180309746A1 · Blasi · 2018 [cited by applicant]
US 20190007418A1 · Cook et al. · 2019 [cited by applicant]
US 20190007443A1 · Cook et al. · 2019 [cited by applicant]
US 20190020665A1 · Surcouf et al. · 2019 [cited by applicant]
US 20190080103A1 · Hadzic et al. · 2019 [cited by applicant]
US 20190190959A1 · Yuan · 2019 [cited by applicant]
US 20190230130A1 · Beckman et al. · 2019 [cited by applicant]
US 20190245862A1 · Kruse et al. · 2019 [cited by applicant]
US 20190386973A1 · Patwardhan et al. · 2019 [cited by applicant]
US 20200007580A1 · Liderman et al. · 2020 [cited by applicant]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210240550A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210248017A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20240004728A1 · Hinrichs et al. · 2024 [cited by applicant]
NPL Search Terms (Year: 2024). [cited by examiner]
Author Unknown, “API Best Practices Managing the API Lifecycle: Design, Delivery, and Everything in Between,” Dec. 2016, 37 pages, Apigee, retrieved from https://pages.apigee.com/rs/351-WXY-166/images/API-Best-Practices… [cited by applicant]
Costa, Jeff, “Improve API Performance with Caching,” API Gateway, May 31, 2018, 18 pages, Akamai Developer, retrieved from https://developer.akamai.com/blog/2018/05/31/improve-api-performance-caching. [cited by applicant]
Moffett, Jonathan D., et al., “Policy Hierarchies for Distributed Systems Management,” IEEE Journal on Selected Areas in Communications, Dec. 1993, 11 pages, vol. 11, IEEE, USA. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,119, filed Jul. 31, 2018, 55 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 18/120,810, filed Mar. 13, 2023, 63 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/239,714, filed Aug. 29, 2023, 68 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/369,471, filed Sep. 18, 2023, 68 pages, Styra, Inc. [cited by applicant]
Preuveneers, Davy, et al., “Access Control with Delegated Authorization Policy Evaluation for Data-Driven Microservice Workflows,” Future Internet, Sep. 30, 2017, 21 pages, vol. 9, Multidisciplinary Digital Publishing I… [cited by applicant]
Wei, Hao, et al., “Enhance OpenStack Access Control via Policy Enforcement Based on XACML,” In Proceedings of the 16th International Conference on Enterprise Information Systems, Apr. 2014, 7 pages, vol. 1, SciTePress, … [cited by applicant]
Win, Thu Yein, et al., “Virtualization Security Combining Mandatory Access Control and Virtual Machine Introspection,” 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, Dec. 8-11, 2014, 6 pages,… [cited by applicant]