IP Library Granted Patent US 12,405,948
Granted Patent B1
US 12,405,948 · App. 18/731,697 · Granted Sep 2, 2025

Comprehension indexing feature

Inventors: Torin Sandall (San Francisco, CA); Timothy L. Hinrichs (Los Altos, CA)
Assignee: STYRA, INC.
G06F16/2445G06F9/547G06F16/2246G06F16/2272G06F16/288
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,405,948
App. No.
18/731,697
Granted
Sep 2, 2025
Kind
B1
Abstract

Some embodiments of the invention provide a method for defining code-based policies. The method generates a policy-builder first view of a policy for display in a graphical user interface (GUI) by processing a syntax tree that is generated from a code second view of the policy. The method receives, through the policy-builder first view, a modification to a portion of the policy. To reflect the modification, the method updates a portion of the syntax tree that corresponds to the portion of the policy that is affected by the modification. Based on the updating of the syntax tree, the method updates the code second view by modifying a portion of the code second view that corresponds to the updated portion of the syntax tree.

Claims (26)

1. For a policy agent that executes on a host computer to process API-authorization requests from at least one application executing on the host computer, a method for optimizing performance for policies that perform search operations on datasets, the method comprising:

receiving an API-authorization request to authorize;

using a pre-generated index to generate a tree structure, wherein the pre-generated index is generated before the API-authorization request is received to speed up processing of the API-authorization request that is subsequently received; and

using the generated tree structure to evaluate whether the API-authorization request should be authorized.

2. The method of claim 1 , wherein the pre-generated index is associated with a particular API-authorization policy.

3. The method of claim 2 , wherein the pre-generated index is generated by performing an offline process for the particular API-authorization policy, wherein the offline process identifies one or more statements in the particular API-authorization policy that can be indexed.

4. The method of claim 3 , wherein the pre-generated index maps each identified statement in the particular API-authorization policy to a set of associated index keys.

5. The method of claim 4 , wherein the associated index keys of the set of associated index keys correspond to names of variables in the particular API-authorization policy.

6. The method of claim 3 , wherein identifying the one or more statements in the particular API-authorization policy that can be indexed comprises analyzing the particular API-authorization policy to identify statements that match a particular pattern.

7. The method of claim 4 , wherein the offline process is an offline first process, wherein generating the tree structure comprises, for each statement in the pre-generated index, performing an online second process (i) to evaluate the statement using available input data and (ii) to generate the tree structure comprising results of the evaluation.

8. The method of claim 7 , wherein the tree structure is keyed by the set of associated index keys from the index.

9. The method of claim 7 , wherein the tree structure comprises, for each statement in the pre-generated index, (i) subtrees for each variable in the statement and (ii) leaves corresponding to possible values of each variable.

10. The method of claim 7 , wherein performing the online second process to evaluate each statement comprises evaluating each statement in full using the available input data.

11. A non-transitory machine readable medium storing a comprehension indexing program for execution by at least one processing unit, the program for optimizing performance for policies that perform search operations on datasets, the program comprising sets of instructions for:

receiving an API-authorization request to authorize;

using a pre-generated index to generate a tree structure, wherein the pre-generated index is generated before the API-authorization request is received to speed up processing of the API-authorization request that is subsequently received; and

using the generated tree structure to evaluate whether the API-authorization request should be authorized.

12. The non-transitory machine readable medium of claim 11 , wherein the pre-generated index is associated with a particular API-authorization policy.

13. The non-transitory machine readable medium of claim 12 , wherein the pre-generated index is generated by performing an offline process for the particular API-authorization policy, wherein the offline process identifies one or more statements in the particular API-authorization policy that can be indexed.

14. The non-transitory machine readable medium of claim 13 , wherein the pre-generated index maps each identified statement in the particular API-authorization policy to a set of associated index keys.

15. The non-transitory machine readable medium of claim 14 , wherein the associated index keys of the set of associated index keys correspond to names of variables in the particular API-authorization policy.

16. The non-transitory machine readable medium of claim 13 , wherein the set of instructions for identifying the one or more statements in the particular API-authorization policy that can be indexed comprises a set of instructions for analyzing the particular API-authorization policy to identify statements that match a particular pattern.

17. The non-transitory machine readable medium of claim 14 , wherein the offline process is an offline first process, wherein the set of instructions for generating the tree structure comprises a set of instructions for performing, for each statement in the pre-generated index, an online second process (i) to evaluate the statement using available input data and (ii) to generate the tree structure comprising results of the evaluation.

18. The non-transitory machine readable medium of claim 17 , wherein the tree structure is keyed by the set of associated index keys from the index.

19. The non-transitory machine readable medium of claim 17 , wherein the tree structure comprises, for each statement in the pre-generated index, (i) subtrees for each variable in the statement and (ii) leaves corresponding to possible values of each variable.

20. The non-transitory machine readable medium of claim 17 , wherein the set of instructions for performing the online second process to evaluate each statement comprises a set of instructions for evaluating each statement in full using the available input data.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2025
From: HINRICHS, TIMOTHY L.; SANDALL, TORIN
To: STYRA, INC.
Reel/Frame 072024/0468 →
Continuity (3)
Continuation 18114191 · Feb 24, 2023
Continuation 17239337 · Apr 23, 2021
Provisional Application 63082405 · Sep 23, 2020
References Cited (120)
US 5974549A · Golan · 1999 [cited by applicant]
US 6985953B1 · Sandhu et al. · 2006 [cited by applicant]
US 7096367B2 · Garg et al. · 2006 [cited by applicant]
US 7124192B2 · High, Jr. et al. · 2006 [cited by applicant]
US 7752661B2 · Hemsath et al. · 2010 [cited by applicant]
US 7913300B1 · Flank et al. · 2011 [cited by applicant]
US 8266694B1 · Roy · 2012 [cited by examiner]
US 8613070B1 · Borzycki et al. · 2013 [cited by applicant]
US 8683560B1 · Brooker et al. · 2014 [cited by applicant]
US 8782744B1 · Fuller et al. · 2014 [cited by applicant]
US 8789138B2 · Reierson et al. · 2014 [cited by applicant]
US 9397990B1 · Taly et al. · 2016 [cited by applicant]
US 9405767B2 · Novak et al. · 2016 [cited by applicant]
US 9530020B2 · Brandwine et al. · 2016 [cited by applicant]
US 9531757B2 · Henry · 2016 [cited by examiner]
US 9578004B2 · Greenspan et al. · 2017 [cited by applicant]
US 9648040B1 · Morkel et al. · 2017 [cited by applicant]
US 9769210B2 · Dotan · 2017 [cited by examiner]
US 10122757B1 · Kruse et al. · 2018 [cited by applicant]
US 10127393B2 · Ferraiolo et al. · 2018 [cited by applicant]
US 10182129B1 · Peterson et al. · 2019 [cited by applicant]
US 10257184B1 · Mehta et al. · 2019 [cited by applicant]
US 10353726B2 · Duan · 2019 [cited by applicant]
US 10423392B2 · Rabins · 2019 [cited by examiner]
US 10454975B1 · Sharifi Mehr · 2019 [cited by applicant]
US 10469314B2 · Ennis, Jr. et al. · 2019 [cited by applicant]
US 10574699B1 · Baer et al. · 2020 [cited by applicant]
US 10592302B1 · Hinrichs et al. · 2020 [cited by applicant]
US 10592683B1 · Lim et al. · 2020 [cited by applicant]
US 10715514B1 · Threlkeld · 2020 [cited by applicant]
US 10719373B1 · Koponen et al. · 2020 [cited by applicant]
US 10726051B2 · Mirizzi · 2020 [cited by applicant]
US 10740287B2 · Haviv et al. · 2020 [cited by applicant]
US 10740470B2 · Ionescu et al. · 2020 [cited by applicant]
US 10789220B2 · Mayer et al. · 2020 [cited by applicant]
US 10942814B2 · Chu et al. · 2021 [cited by applicant]
US 10984133B1 · Hinrichs et al. · 2021 [cited by applicant]
US 10986131B1 · Kruse et al. · 2021 [cited by applicant]
US 10990702B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11023292B1 · Hinrichs et al. · 2021 [cited by applicant]
US 11080410B1 · Sandall et al. · 2021 [cited by applicant]
US 11108827B2 · Beckman et al. · 2021 [cited by applicant]
US 11108828B1 · Curtis et al. · 2021 [cited by applicant]
US 11170099B1 · Sandall · 2021 [cited by examiner]
US 11228573B1 · Rangasamy et al. · 2022 [cited by applicant]
US 11232223B2 · Chasman · 2022 [cited by examiner]
US 11245728B1 · Curtis et al. · 2022 [cited by applicant]
US 11258824B1 · Hinrichs et al. · 2022 [cited by applicant]
US 11275733B1 · Batsakis et al. · 2022 [cited by applicant]
US 11327815B1 · Koponen et al. · 2022 [cited by applicant]
US 11425126B1 · Horal et al. · 2022 [cited by applicant]
US 11496517B1 · Hinrichs · 2022 [cited by examiner]
US 11509658B1 · Kulkarni · 2022 [cited by applicant]
US 11516253B1 · Van Deman et al. · 2022 [cited by applicant]
US 11520579B1 · Narkar · 2022 [cited by examiner]
US 11593363B1 · Sandall et al. · 2023 [cited by applicant]
US 11604684B1 · Hinrichs et al. · 2023 [cited by applicant]
US 11681568B1 · Hinrichs · 2023 [cited by examiner]
US 11741244B2 · Sandall · 2023 [cited by examiner]
US 11762712B2 · Koponen · 2023 [cited by examiner]
US 11847241B1 · Cahill et al. · 2023 [cited by applicant]
US 11853463B1 · Hinrichs · 2023 [cited by examiner]
US 12032567B1 · Sandall et al. · 2024 [cited by applicant]
US 12107866B2 · Hinrichs et al. · 2024 [cited by applicant]
US 12118102B1 · Sandall et al. · 2024 [cited by applicant]
US 20040083367A1 · Garg et al. · 2004 [cited by applicant]
US 20050114674A1 · Carley · 2005 [cited by applicant]
US 20070156670A1 · Lim · 2007 [cited by applicant]
US 20080184336A1 · Sarukkai et al. · 2008 [cited by applicant]
US 20090063665A1 · Bagepalli et al. · 2009 [cited by applicant]
US 20090077618A1 · Pearce et al. · 2009 [cited by applicant]
US 20090281996A1 · Liu et al. · 2009 [cited by applicant]
US 20100333079A1 · Sverdlov et al. · 2010 [cited by applicant]
US 20110113484A1 · Zeuthen · 2011 [cited by applicant]
US 20120030354A1 · Razzaq et al. · 2012 [cited by applicant]
US 20120066756A1 · Vysogorets et al. · 2012 [cited by applicant]
US 20120311672A1 · Connor et al. · 2012 [cited by applicant]
US 20120331539A1 · Matsugashita · 2012 [cited by applicant]
US 20130226970A1 · Weber et al. · 2013 [cited by applicant]
US 20140032691A1 · Barton et al. · 2014 [cited by applicant]
US 20140032759A1 · Barton et al. · 2014 [cited by applicant]
US 20140033267A1 · Aciicmez · 2014 [cited by applicant]
US 20140237594A1 · Thakadu et al. · 2014 [cited by applicant]
US 20150089575A1 · Vepa et al. · 2015 [cited by applicant]
US 20150213449A1 · Morrison et al. · 2015 [cited by applicant]
US 20150244724A1 · Xu et al. · 2015 [cited by applicant]
US 20160034900A1 · Nelsen et al. · 2016 [cited by applicant]
US 20160057107A1 · Call et al. · 2016 [cited by applicant]
US 20160188898A1 · Karinta et al. · 2016 [cited by applicant]
US 20170024428A1 · Patiejunas et al. · 2017 [cited by applicant]
US 20170111336A1 · Davis et al. · 2017 [cited by applicant]
US 20170161120A1 · Sasaki et al. · 2017 [cited by applicant]
US 20170220370A1 · Klompje et al. · 2017 [cited by applicant]
US 20170237729A1 · Uppalapati · 2017 [cited by applicant]
US 20170302655A1 · Sondhi et al. · 2017 [cited by applicant]
US 20170346807A1 · Blasi · 2017 [cited by applicant]
US 20170364702A1 · Goldfarb et al. · 2017 [cited by applicant]
US 20180067790A1 · Chheda et al. · 2018 [cited by applicant]
US 20180082053A1 · Brown et al. · 2018 [cited by applicant]
US 20180109538A1 · Kumar et al. · 2018 [cited by applicant]
US 20180309746A1 · Blasi · 2018 [cited by applicant]
US 20190007418A1 · Cook et al. · 2019 [cited by applicant]
US 20190007443A1 · Cook et al. · 2019 [cited by applicant]
US 20190080103A1 · Hadzic et al. · 2019 [cited by applicant]
US 20190190959A1 · Yuan · 2019 [cited by applicant]
US 20190230130A1 · Beckman et al. · 2019 [cited by applicant]
US 20190245862A1 · Kruse et al. · 2019 [cited by applicant]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
US 20190386973A1 · Patwardhan et al. · 2019 [cited by applicant]
US 20200007580A1 · Liderman · 2020 [cited by examiner]
US 20210029029A1 · Mehmedagic et al. · 2021 [cited by applicant]
US 20210240550A1 · Hinrichs et al. · 2021 [cited by applicant]
US 20210248017A1 · Hinrichs et al. · 2021 [cited by applicant]
Author Unknown, “API Best Practices Managing the API Lifecycle: Design, Delivery, and Everything in Between,” Dec. 2016, 37 pages, Apigee, retrieved from https://pages.apigee.com/rs/351-WXY-166/images/API-Best-Practices… [cited by applicant]
Costa, Jeff, “Improve API Performance with Caching,” API Gateway, May 31, 2018, 18 pages, Akamai Developer, retrieved from https://developer.akamai.com/blog/2018/05/31/improve-api-performance-caching. [cited by applicant]
Moffett, Jonathan D., et al., “Policy Hierarchies for Distributed Systems Management,” IEEE Journal on Selected Areas in Communications, Dec. 1993, 11 pages, vol. 11, IEEE, USA. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 16/050,119, filed Jul. 31, 2018, 55 pages, Styra, Inc. [cited by applicant]
Non-Published commonly Owned U.S. Appl. No. 18/120,810, filed Mar. 13, 2023, 63 pages, Styra, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/369,471, filed Sep. 18, 2023, 74 pages, Styra, Inc. [cited by applicant]
Win, Thu Yein, et al., “Virtualization Security Combining Mandatory Access Control and Virtual Machine Introspection,” 2014 IEEE/ACM 7th International Conference on Utility and Cloud Computing, Dec. 8-11, 2014, 6 pages,… [cited by applicant]