IP Library Granted Patent US 12,645,810
Granted Patent B1
US 12,645,810 · App. 18/903,189 · Granted Jun 2, 2026

Partial policy evaluation

Inventors: Torin Sandall (San Francisco, CA); Timothy L. Hinrichs (Los Altos, CA); Teemu Koponen (San Francisco, CA)
Assignee: Apple Inc.
G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,810
App. No.
18/903,189
Granted
Jun 2, 2026
Kind
B1
Abstract

Some embodiments provide a method for evaluating a policy for authorizing an API (Application Programming Interface) call to an application. Based on a first set of parameters available before receiving the API call, the method evaluates only a portion of the policy to produce a partially evaluated policy. The method stores the partially evaluated policy in a cache. The method then receives an API call to authorize, and determines whether the API call should be authorized by fully evaluating the policy, using the partially evaluated policy retrieved from the cache first storage, and a second set of parameters associated with the API call. The method responds to the API call with a policy decision based on the fully evaluated authorization policy.

Claims (38)

1 . A method for evaluating a policy for authorizing an API (Application Programming Interface) call to an application, the method comprising:

before receiving the API call, evaluating, based on a first set of available parameters, a portion of the policy to produce a partially evaluated policy;

receiving the API call to authorize;

evaluating an entirety of the policy using (1) the partially evaluated policy, (2) a second set of parameters, and (3) a second portion of the policy not previously evaluated to produce the partially evaluated policy; and

responding to the API call with a policy decision based on evaluating the entirety of the policy.

2 . The method of claim 1 , wherein the first set of parameters is associated with the API call.

3 . The method of claim 1 , wherein the second set of parameters includes at least one parameter received with the API call.

4 . The method of claim 1 , wherein the second set of parameters includes at least one parameter identified after receiving the API call.

5 . The method of claim 4 , wherein the partially evaluated policy is stored in a first storage, wherein the second set of parameters includes at least one parameter retrieved from a second storage after receiving the API call.

6 . The method of claim 5 , wherein the at least one parameter is retrieved from the second storage based on a parameter received with the API call.

7 . The method of claim 5 , wherein the at least one parameter is retrieved from the second storage and the partially evaluated policy is retrieved from the first storage.

8 . The method of claim 1 , wherein the policy is a role-based access control (RBAC) policy.

9 . The method of claim 1 , wherein the portion of the policy is partially evaluated before receiving the API call to reduce computations performed after receiving the API call.

10 . The method of claim 1 , wherein the second set of parameters comprises parameters available after receiving the API call.

11 . A non-transitory machine readable medium storing a program executing on at least one hardware processing unit of a computing device, the program for evaluating a policy for authorizing an API (Application Programming Interface) call to an application, the program comprising sets of instructions for:

before receiving the API call, evaluating, based on a first set of available parameters, a portion of the policy to produce a partially evaluated policy;

receiving the API call to authorize;

evaluating an entirety of the policy using (1) the partially evaluated policy, (2) a second set of parameters available after receiving the API call, and (3) a second portion of the policy not previously evaluated to produce the partially evaluated policy; and

responding to the API call with a policy decision based on evaluating the entirety of the policy.

12 . The non-transitory machine readable medium of claim 11 , wherein the first set of parameters is associated with the API call.

13 . The non-transitory machine readable medium of claim 11 , wherein the second set of parameters includes at least one parameter received with the API call.

14 . The non-transitory machine readable medium of claim 11 , wherein the second set of parameters includes at least one parameter identified after receiving the API call.

15 . The non-transitory machine readable medium of claim 14 , wherein the partially evaluated policy is stored in a first storage, wherein the second set of parameters includes at least one parameter retrieved from a second storage after receiving the API call.

16 . The non-transitory machine readable medium of claim 15 , wherein the at least one parameter is retrieved from the second storage based on a parameter received with the API call.

17 . The non-transitory machine readable medium of claim 15 ,

wherein the at least one parameter is retrieved from the second storage and the partially evaluated policy is retrieved from the first storage.

18 . The non-transitory machine readable medium of claim 11 , wherein the policy is a role-based access control (RBAC) policy.

19 . The non-transitory machine readable medium of claim 11 , wherein the portion of the policy is partially evaluated before receiving the API call to reduce computations performed after receiving the API call.

20 . The non-transitory machine readable medium of claim 11 , wherein the second set of parameters comprises parameters available after receiving the API call.

21 . A device comprising:

a memory; and

at least one processor configured to:

before receipt of an application programming interface (API) call to an application, evaluate, based on a first set of available parameters, a portion of a policy for authorizing the API call to produce a partially evaluated policy;

receive the API call to authorize;

evaluate an entirety of the policy using (1) the partially evaluated policy, (2) a second set of parameters, and (3) a second portion of the policy not previously evaluated to produce the partially evaluated policy; and

respond to the API call with a policy decision based on evaluation of the entirety of the policy.

22 . The device of claim 21 , wherein the device comprises a first storage that stores the partially evaluated policy and a second storage distinct from the first storage, and wherein the at least one processor is configured to, after receipt of the API call, identify at least one parameter of the second set and retrieve the identified at least one parameter from the second storage.

23 . The device of claim 22 , wherein retrieving the at least one parameter from the second storage is based on a parameter received with the API call.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072818/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2025
From: STYRA, INC.
To: APPLE INC.
Reel/Frame 072522/0568 →
Continuity (4)
Continuation 18239714 · Aug 29, 2023
Continuation 17392072 · Aug 2, 2021
Continuation 16293503 · Mar 5, 2019
Provisional Application 62722788 · Aug 24, 2018
References Cited (11)
US 7096367B2 · Garg · 2006 [cited by examiner]
US 8683560B1 · Brooker · 2014 [cited by examiner]
US 9420002B1 · McGovern · 2016 [cited by examiner]
US 10182129B1 · Peterson · 2019 [cited by examiner]
US 11080410B1 · Sandall et al. · 2021 [cited by applicant]
US 11741244B2 · Sandall et al. · 2023 [cited by applicant]
US 12118102B1 · Sandall et al. · 2024 [cited by applicant]
US 20090019533A1 · Hazlewood · 2009 [cited by examiner]
US 20090063665A1 · Bagepalli · 2009 [cited by examiner]
US 20160057027A1 · Hinrichs · 2016 [cited by examiner]
Preuveneers et al. “Access Control with Delegated Authorization Policy Evaluation for Data-Driven Microservice Workflows”, Future Internet 2017, 9, 58, 21 pages, Sep. 30, 2017 (Year: 2017). [cited by examiner]