IP Library › Granted Patent US 12,724,875
Granted Patent B1
US 12,724,875 · App. 18/982,663 · Granted Sep 1, 2026

Generating security permissions for cloud computing assets in cloud platforms

Inventors: Shira Shamban (Hod-Hasharon, IL); David Hendri (Hod-Hasharon, IL)
Assignee: Cyesec Ltd.
G06F21/53G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,724,875
App. No.
18/982,663
Granted
Sep 1, 2026
Kind
B1
Abstract

An online system determines security specification for cloud computing assets of a cloud computing platform. The system initializes a security specification and monitors execution of an application over a time interval to receive information describing application programming interface (API) invocations performed by the application. For each action performed by the API invocation, the system determines whether the security specification allows the actions performed by the API invocation with the cloud computing asset. The system modifies the security specification if necessary to allow the application to perform the particular action with the particular cloud computing asset. The system enforces security permissions for applications running on cloud computing platform based on the generated security specification.

Claims (47)

1 . A computer-implemented method comprising:

receiving a request to generate security specification for cloud computing assets of a cloud platform;

initializing a security specification;

receiving, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;

for each action performed by the application that accesses a cloud computing asset, determining whether the security specification allows the action;

responsive to identifying a particular action performed by the application that is not allowed by the security specification, modifying the security specification to allow the application to perform the particular action; and

enforcing security permissions for applications running on cloud computing platform based on the security specification.

2 . The computer-implemented method of claim 1 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.

3 . The computer-implemented method of claim 1 , further comprising:

sending the generated security specification for display via a user interface for approval; and

responsive to receiving an approval, enforcing security permissions for applications running on cloud computing platform using the modified security specification.

4 . The computer-implemented method of claim 1 , wherein an action performs one of:

reading an object, adding an object, modifying an object, or deleting an object.

5 . The computer-implemented method of claim 1 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.

6 . The computer-implemented method of claim 1 , wherein the application is instrumented to provide metadata describing API invocations.

7 . The computer-implemented method of claim 1 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.

8 . A non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to:

receive a request to generate security specification for cloud computing assets of a cloud platform;

initialize a security specification;

receive, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;

for each action performed by the application that accesses a cloud computing asset, determine whether the security specification allows the action;

responsive to identifying a particular action performed by the application that is not allowed by the security specification, modify the security specification to allow the application to perform the particular action; and

enforce security permissions for applications running on cloud computing platform based on the security specification.

9 . The non-transitory computer readable storage medium of claim 8 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.

10 . The non-transitory computer readable storage medium of claim 8 , wherein the instructions further cause the computer processor to:

sending the generated security specification for display via a user interface for approval; and

responsive to receiving an approval, enforcing security permissions for applications running on cloud computing platform using the modified security specification.

11 . The non-transitory computer readable storage medium of claim 8 , wherein instructions for an action cause the computer processor to:

read an object, add an object, modify an object, or delete an object.

12 . The non-transitory computer readable storage medium of claim 8 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.

13 . The non-transitory computer readable storage medium of claim 8 , wherein the application is instrumented to provide metadata describing API invocations.

14 . The non-transitory computer readable storage medium of claim 8 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.

15 . A computer system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to:

receive a request to generate security specification for cloud computing assets of a cloud platform;

initialize a security specification;

receive, from a system analyzing execution of applications, information describing an access of cloud computing assets performed by an application as a result of execution of the application;

for each action performed by the application that accesses a cloud computing asset, determine whether the security specification allows the action;

responsive to identifying a particular action performed by the application that is not allowed by the security specification, modify the security specification to allow the application to perform the particular action; and

enforce security permissions for applications running on cloud computing platform based on the security specification.

16 . The computer system of claim 15 , wherein the application executes using a runtime environment, wherein the runtime environment is configured to intercept an API invocation and provide metadata describing the API invocation.

17 . The computer system of claim 15 , wherein instructions for an action cause the computer processor to:

read an object, add an object, modify an object, or delete an object.

18 . The computer system of claim 15 , wherein an asset is one of: a database, a cluster of computing systems, or a storage system.

19 . The computer system of claim 15 , wherein the application is instrumented to provide metadata describing API invocations.

20 . The computer system of claim 15 , wherein the application is configured to perform at least a first action using a first asset, and wherein responsive to the application failing to perform the first action using the first asset, the security specification prevents the application from performing the first action using the first asset.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2025
From: SHAMBAN, SHIRA; HENDRI, DAVID
To: PERSOLVO INC.
Reel/Frame 071650/0687 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2025
From: PERSOLVO INC.
To: CYESEC LTD.
Reel/Frame 071650/0722 →
Continuity (2)
Continuation 17940966 · Sep 8, 2022
Provisional Application 63242493 · Sep 10, 2021
References Cited (4)
US 11748189B1 · Mehta · 2023 [cited by examiner]
US 20210124610A1 · Gardner · 2021 [cited by examiner]
US 20220294817A1 · Parekh · 2022 [cited by examiner]
United States Office Action, U.S. Appl. No. 17/940,966, Jul. 26, 2024, seven pages. [cited by applicant]