IP Library Granted Patent US 12,407,647
Granted Patent B1
US 12,407,647 · App. 18/731,658 · Granted Sep 2, 2025

Local controller for local API authorization method and apparatus

Inventors: Teemu Koponen (San Francisco, CA); Timothy L. Hinrichs (Los Altos, CA); Torin Sandall (San Francisco, CA); Stan Lagun (San Jose, CA)
Assignee: STYRA, INC.
H04L63/02G06F9/547G06F21/629H04L41/0893H04L63/0236H04L67/133H04L67/562G06F21/6218H04L63/10H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,647
App. No.
18/731,658
Granted
Sep 2, 2025
Kind
B1
Abstract

Some embodiments provide a local controller on a set of host computers that reduce the volume of data that is communicated between the server set and the set of host computers. The local controller executing on a particular host computer, in some embodiments, receives a portion of the namespace including only the policies (e.g., opcode) that are relevant to API-authorization processing for the applications executing on the particular host computer provided by a local agent executing on the computer to authorize the API requests based on policies and parameters. The local controller analyzes the received policies (e.g., policy opcodes) and identifies the parameters (e.g. operands), or parameter types, needed for API-authorization processing (e.g., evaluating the policy opcode upon receiving a particular API request) by the local agent. In some embodiments, the local controller performs this analysis for each updated set of policies (e.g., policy opcodes).

Claims (28)

1. A method for providing policies to a plurality of local API (Application Programming Interface) authorization agents executing on a plurality of computers to use to authorize API calls for processing by applications executing on the plurality of computers, the method comprising:

receiving definitions of a plurality of authorization policies for a set of one or more API calls to the applications executing on the plurality of computers;

storing the plurality of authorization policies; and

distributing different sets of authorization policies to different local controllers executing on the plurality of computers, each particular set of authorization policies distributed to each particular local controller comprising one or more authorization policies relevant for processing API calls to a set of one or more applications executing on a same host computer as the particular local controller, wherein for each application of a set of applications executing on a particular computer, the local controller executing on the particular computer identifies policies applicable to the particular application and provides to a local API authorization agent executing on the particular computer that authorizes API calls for processing by the particular application (i) the policies applicable to the application and (ii) parameter values retrieved from local data sources for use in evaluating the policies.

2. The method of claim 1 , wherein the receiving, storing, and distributing are performed by a set of one or more servers that acts as a logically centralized resource for defining, storing, distributing, and enforcing the policies to authorize the API calls for processing by the applications.

3. The method of claim 1 , wherein the applications executing on the plurality of computers belong to one or more tenants in one or more datacenters.

4. The method of claim 1 , wherein the applications execute as machines on the plurality of computers, the machines comprising one or more of virtual machines (VMs) and containers.

5. The method of claim 1 , wherein the definitions of the plurality of authorization policies are received through a web-based user interface.

6. The method of claim 5 , wherein the plurality of authorization policies comprises policies that are custom defined in terms of different sets of parameters for different sets of applications used in different deployment settings.

7. The method of claim 1 , wherein storing the plurality of authorization policies comprises storing the plurality of authorization policies as a namespace that is a single hierarchical storage structure.

8. The method of claim 7 , wherein the namespace allows each particular authorization policy and a set of parameters associated with the particular authorization policy to be retrieved by providing a location identifier that identifies a location in the namespace.

9. The method of claim 8 , wherein the location stores the set of parameters for the particular authorization policy.

10. The method of claim 8 , wherein the location stores one or more location-identifiers for one or more locations in the namespace at which the set of parameters is previously stored in the namespace.

11. The method of claim 7 , wherein each particular definition for each particular authorization policy is defined by a policy opcode.

12. The method of claim 7 , wherein distributing the different sets of authorization policies to the different local controllers comprises distributing different portions of the namespace to the different local controllers.

13. The method of claim 1 , wherein at least two sets of authorization policies distributed to at least two local controllers comprise at least one overlapping authorization policy.

14. The method of claim 1 , wherein a specific set of authorization policies are distributed to a specific local controller on a specific computer after receiving a query, from a local API authorization agent executing on the specific computer via the specific local controller executing on the specific computer, for policies relevant to the local API authorization agent.

15. The method of claim 1 , wherein the local controller executing on a specific computer retrieves the parameter values for use in evaluating a specific policy from the local data sources by (i) analyzing the specific policy to identify parameters used in evaluating the specific policy and (ii) requesting values for the identified parameters from the local data sources.

16. The method of claim 1 , wherein the local data sources comprise one or more network controllers responsible for controlling resources of a network to which the plurality of computers are connected operate.

17. A system comprising:

a set of one or more servers that receive definitions of a plurality of authorization policies for API (application programming interface) calls to applications and that store the plurality of authorization policies; and

a plurality of computers, each computer executing:

a set of one or more applications that receive and process API calls;

a set of one or more local API authorization agents that authorize API calls to the set of applications according to the authorization policies relevant to the set of applications; and

a set of one or more local controllers that receive authorization policies relevant to the set of applications from the set of one or more servers and, for each application executing on the computer, identify policies applicable to the application and provide to one of the local API authorization agents executing on the particular computer that authorizes API calls for processing by the application, (i) the policies relevant to the application and (ii) parameter values retrieved from local data sources for use in evaluating the policies.

18. The system of claim 17 , wherein the set of local controllers executing on a particular computer provides the policies and parameter values relevant to a particular application to a particular local API authorization agent by populating an API authorization storage that is accessed by the particular local API authorization agent.

19. The system of claim 17 , wherein the policies relevant to a particular application are distributed by the set of one or more servers to a particular local controller in response to a request for the policies from the particular local controller.

20. The system of claim 17 , wherein the local data sources comprise one or more network controllers responsible for controlling resources of a network to which the plurality of computers are connected operate.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2025
From: HINRICHS, TIMOTHY L.; SANDALL, TORIN; KOPONEN, TEEMU; LEGUN, STAN
To: STYRA, INC.
Reel/Frame 072022/0766 →
Continuity (3)
Continuation 18109215 · Feb 13, 2023
Continuation 16889761 · Jun 1, 2020
Provisional Application 62966502 · Jan 27, 2020
References Cited (113)
US 5974549A · Golan · 1999 [cited by applicant]
US 6985953B1 · Sandhu et al. · 2006 [cited by applicant]
US 7124192B2 · High, Jr. et al. · 2006 [cited by applicant]
US 7752661B2 · Hemsath et al. · 2010 [cited by applicant]
US 8266694B1 · Roy · 2012 [cited by applicant]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683560B1 · Brooker et al. · 2014 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8789138B2 · Reierson et al. · 2014 [cited by applicant]
US 9397990B1 · Taly et al. · 2016 [cited by applicant]
US 9530020B2 · Brandwine et al. · 2016 [cited by applicant]
US 9578004B2 · Greenspan et al. · 2017 [cited by applicant]
US 9648040B1 · Morkel · 2017 [cited by examiner]
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10127393B2 · Ferraiolo et al. · 2018 [cited by applicant]
US 10257184B1 · Mehta et al. · 2019 [cited by applicant]
US 10353726B2 · Duan · 2019 [cited by applicant]
US 10454975B1 · Sharifi Mehr · 2019 [cited by applicant]
US 10469314B2 · Ennis, Jr. et al. · 2019 [cited by applicant]
US 10574699B1 · Baer · 2020 [cited by examiner]
US 10592302B1 · Hinrichs · 2020 [cited by examiner]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 10719373B1 · Koponen · 2020 [cited by examiner]
US 10789220B2 · Mayer et al. · 2020 [cited by applicant]
US 10984133B1 · Hinrichs · 2021 [cited by examiner]
US 10986131B1 · Kruse · 2021 [cited by examiner]
US 10990702B1 · Hinrichs · 2021 [cited by examiner]
US 11023292B1 · Hinrichs · 2021 [cited by examiner]
US 11080410B1 · Sandall · 2021 [cited by examiner]
US 11108827B2 · Beckman et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis · 2021 [cited by examiner]
US 11170099B1 · Sandall · 2021 [cited by examiner]
US 11228573B1 · Rangasamy et al. · 2022 [cited by applicant]
US 11245728B1 · Curtis · 2022 [cited by examiner]
US 11258824B1 · Hinrichs · 2022 [cited by examiner]
US 11327815B1 · Koponen · 2022 [cited by examiner]
US 11425126B1 · Horal · 2022 [cited by examiner]
US 11470121B1 · Curtis · 2022 [cited by examiner]
US 11477238B1 · Curtis · 2022 [cited by examiner]
US 11477239B1 · Curtis · 2022 [cited by examiner]
US 11494518B1 · Curtis · 2022 [cited by examiner]
US 11496517B1 · Hinrichs · 2022 [cited by examiner]
US 11502992B1 · Koponen · 2022 [cited by examiner]
US 11509658B1 · Kulkarni · 2022 [cited by examiner]
US 11516253B1 · Van Deman et al. · 2022 [cited by applicant]
US 11582235B1 · Koponen · 2023 [cited by examiner]
US 11593363B1 · Sandall · 2023 [cited by examiner]
US 11593525B1 · Sandall · 2023 [cited by examiner]
US 11604684B1 · Hinrichs · 2023 [cited by examiner]
US 11645423B1 · Curtis · 2023 [cited by examiner]
US 11681568B1 · Hinrichs · 2023 [cited by examiner]
US 11847241B1 · Cahill · 2023 [cited by examiner]
US 11853463B1 · Hinrichs · 2023 [cited by examiner]
US 11968292B1 · Char · 2024 [cited by examiner]
US 12003543B1 · Ali · 2024 [cited by examiner]
US 12020086B2 · Hinrichs · 2024 [cited by examiner]
US 12021832B1 · Koponen et al. · 2024 [cited by applicant]
US 12107866B2 · Hinrichs · 2024 [cited by examiner]
US 12118102B1 · Sandall et al. · 2024 [cited by applicant]
US 20050114674A1 · Carley · 2005 [cited by applicant]
US 20070156670A1 · Lim · 2007 [cited by applicant]
US 20090063665A1 · Bagepalli et al. · 2009 [cited by applicant]
US 20090077618A1 · Pearce et al. · 2009 [cited by applicant]
US 20100333079A1 · Sverdlov et al. · 2010 [cited by applicant]
US 20110113484A1 · Zeuthen · 2011 [cited by applicant]
US 20120030354A1 · Razzaq · 2012 [cited by examiner]
US 20120066756A1 · Vysogorets et al. · 2012 [cited by applicant]
US 20120311672A1 · Connor et al. · 2012 [cited by applicant]
US 20120331539A1 · Matsugashita · 2012 [cited by applicant]
US 20130226970A1 · Weber et al. · 2013 [cited by applicant]
US 20140032691A1 · Barton et al. · 2014 [cited by applicant]
US 20140032759A1 · Barton et al. · 2014 [cited by applicant]
US 20140033267A1 · Aciicmez · 2014 [cited by applicant]
US 20140101713A1 · Entin · 2014 [cited by examiner]
US 20140237594A1 · Thakadu et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150213449A1 · Morrison et al. · 2015 [cited by applicant]
US 20160034900A1 · Nelsen et al. · 2016 [cited by applicant]
US 20160057107A1 · Call · 2016 [cited by examiner]
US 20170024428A1 · Patiejunas et al. · 2017 [cited by applicant]
US 20170161120A1 · Sasaki et al. · 2017 [cited by applicant]
US 20170220370A1 · Klompje et al. · 2017 [cited by applicant]
US 20170237729A1 · Uppalapati · 2017 [cited by applicant]
US 20170302655A1 · Sondhi et al. · 2017 [cited by applicant]
US 20170346807A1 · Blasi · 2017 [cited by applicant]
US 20170364702A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180067790A1 · Chheda et al. · 2018 [cited by applicant]
US 20180082053A1 · Brown et al. · 2018 [cited by applicant]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20180309746A1 · Blasi · 2018 [cited by applicant]
US 20180367311A1 · Stahlberg et al. · 2018 [cited by applicant]
US 20190007418A1 · Cook et al. · 2019 [cited by applicant]
US 20190007443A1 · Cook et al. · 2019 [cited by applicant]
US 20190190959A1 · Yuan · 2019 [cited by applicant]
US 20190213322A1 · Dehon · 2019 [cited by examiner]
US 20190230130A1 · Beckman et al. · 2019 [cited by applicant]
US 20190245862A1 · Kruse · 2019 [cited by examiner]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20190386973A1 · Patwardhan et al. · 2019 [cited by applicant]
US 20200007580A1 · Liderman et al. · 2020 [cited by applicant]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210240550A1 · Hinrichs · 2021 [cited by examiner]
US 20210248017A1 · Hinrichs · 2021 [cited by examiner]
US 20210365571A1 · Sandall · 2021 [cited by examiner]
US 20220269549A1 · Koponen · 2022 [cited by examiner]
US 20230032313A1 · Curtis · 2023 [cited by examiner]
US 20240004728A1 · Hinrichs · 2024 [cited by examiner]
Author Unknown, “API Best Practices Managing the API Lifecycle: Design, Delivery, and Everything in Between,” Dec. 2016, 37 pages, Apigee, retrieved from https://pages.apigee.com/rs/351-WXY-166/images/API-Best-Practices… [cited by applicant]
Costa, Jeff, “Improve API Performance with Caching,” API Gateway, May 31, 2018, 18 pages, Akamai Developer, retrieved from https://developer.akamai.com/blog/2018/05/31/improve-api-performance-caching. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,119, filed Jul. 31, 2018, 55 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 18/120,810, filed Mar. 13, 2023, 63 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/369,471, filed Sep. 18, 2023, 74 pages, Styra, Inc. [cited by applicant]
Win, Thu Yein, et al., “Virtualization Security Combining Mandatory Access Control and Virtual Machine Introspection,” 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, Dec. 8-11, 2014, 6 pages,… [cited by applicant]