SERVICE-AGNOSTIC POLICY ENFORCEMENT CONTROL ENGINE
A method of service-agnostic policy enforcement includes receiving a first request comprising information in a non-standardized format and converting the information into a data package comprising a plurality of attributes in a standardized format. An orchestrator receives a second request comprising the data package to generate a license token for executing an action. The orchestrator invokes a policy-based controls engine to validate the second request. The controls engine identifies one or more policies applicable to the second request based on one or more of the plurality of attributes in the data package. The policies are implemented as computational constraint expressions. The controls engine validates the second request based on the attributes satisfying each of the constraint expressions. The method further includes generating the license token based on successful validation of the second request and executing the action using the license token.
1 . A method comprising:
receiving, at a computing environment, a first request from a merchant server via an application programming interface (API), the API associated with a computing service of a plurality of computing services associated with the computing environment, the first request comprising information in a non-standardized format;
converting, by a server in the computing environment, the information into a data package, the data package comprising a plurality of attributes in a standardized format;
receiving, at an orchestrator in the computing environment, a second request to generate a license token for executing an action, the second request comprising the data package;
invoking a policy-based controls engine in the computing environment to validate the second request, wherein the policy-based controls engine is automatically invoked upon receiving any request to generate a license token associated with any of the plurality of computing services;
identifying, by the policy-based controls engine, one or more policies applicable to the second request based on one or more of the plurality of attributes in the data package, wherein the one or more policies are implemented as one or more computational constraint expressions;
validating, by the policy-based controls engine, the second request based on the plurality of attributes satisfying each of the one or more computational constraint expressions;
generating the license token based on successful validation of the second request; and
executing action using the license token.
2 . The method of claim 1 , wherein:
a first computing service of the plurality of computing services associated with the computing environment receives requests comprises information in a first non-standardized format; and
a second computing service of the plurality of computing services associated with the computing environment receives requests comprises information in a second non-standardized format different from the first non-standardized format.
3 . The method of claim 1 , further comprising:
sending, by the orchestrator to the computing service, a response to the second request, the response comprising the license token.
4 . The method of claim 3 , further comprising:
receiving a third request via the computing service to execute the action, the third request comprising the license token.
5 . The method of claim 1 , further comprising:
receiving a third request from the orchestrator to execute the action, the third request comprising the license token.
6 . The method of claim 1 , wherein validating the second request includes the plurality of attributes satisfying all of the variables in each of the one or more computational constraint expressions.
7 . The method of claim 1 , further comprising:
creating or updating a record of the first or second request in a database, the record including one or more tags selected based at least in part on the one or more policies.
8 . A system comprising:
a processor; and
memory storing instructions that, when executed by the processor, cause the processor to:
receive, at a computing environment, a first request from a merchant server via an application programming interface (API), the API associated with a computing service of a plurality of computing services associated with the computing environment, the first request comprising information in a non-standardized format;
convert, by a server in the computing environment, the information into a standardized format;
receive, at an orchestrator in the computing environment, a second request to generate a license token for executing an action, the second request comprising the information in the standardized formal;
invoke a policy-based controls engine in the computing environment to validate the second request, wherein the policy-based controls engine is automatically invoked upon receiving any request to generate a license token associated with any of the plurality of computing services;
identify, by the policy-based controls engine, one or more policies applicable to the second request based on one or more of the plurality of attributes in the information in the standardized format, wherein the one or more policies are implemented as one or more computational constraint expressions;
validate or deny, by the policy-based controls engine, the second request based on whether the plurality of attributes satisfy the one or more policies;
generate a response based on whether the second request was validated or denied; and
transmit the response to the orchestrator.
9 . The system of claim 8 , wherein:
a first computing service of the plurality of computing services associated with the computing environment receives requests comprising information in a first non-standardized format; and
a second computing service of the plurality of computing services associated with the computing environment receives requests comprising information in a second non-standardized format.
10 . The system of claim 8 , wherein the instructions, when executed by the processor, further cause the processor to:
validate the second request;
generate a license token; and
send, by the orchestrator, the license token in response to the second request.
11 . The system of claim 10 , wherein the instructions, when executed by the processor, further cause the processor to:
receive a third request via the computing service to execute the action, the third request comprising the license token.
12 . The system of claim 8 , wherein the instructions, when executed by the processor, further cause the processor to:
validate the second request;
generate a license token; and
receive a third request from the orchestrator to execute the action, the third request comprising the license token.
13 . The system of claim 8 , wherein validating the second request includes the plurality of attributes satisfying each of the one or more policies.
14 . The system of claim 8 , wherein the instructions, when executed by the processor, further cause the processor to:
create or update a record of the first or second request in a database, the record including one or more tags selected based at least in part on the one or more policies.
15 . A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to:
receive, at a computing environment, a first request from a merchant server via an application programming interface (API), the API associated with a computing service of a plurality of computing services associated with the computing environment, the first request comprising information in a non-standardized format;
convert, by a server in the computing environment, the information into a data package, the data package comprising a plurality of attributes in a standardized format;
receive, at an orchestrator in the computing environment, a second request to generate a license token for executing an action, the second request comprising the data package;
invoke a policy-based controls engine in the computing environment to validate the second request;
identify, by the policy-based controls engine, one or more policies applicable to the second request based on one or more of the plurality of attributes in the data package, wherein the one or more policies are implemented as one or more computational constraint expressions;
validate, by the policy-based controls engine, the second request based on the plurality of attributes satisfying the one or more policies;
generate the license token based on successful validation of the second request; and
execute the action using the license token.
16 . The non-transitory computer-readable medium of claim 15 , wherein:
a first computing service of the plurality of computing services associated with the computing environment receives requests comprising information in a first non-standardized format; and
a second computing service of the plurality of computing services associated with the computing environment receives requests comprising information in a second non-standardized format.
17 . The non-transitory computer-readable medium of claim 15 , further comprising instructions that, when executed by the processor, cause the processor to:
send, by the orchestrator to the computing service, a response to the second request, the response comprising the license token.
18 . The non-transitory computer-readable medium of claim 17 , further comprising instructions that, when executed by the processor, cause the processor to:
receive a third request via the computing service to execute the action, the third request comprising the license token.
19 . The non-transitory computer-readable medium of claim 15 , further comprising instructions that, when executed by the processor, cause the processor to:
receive a third request from the orchestrator to execute the action, the third request comprising the license token.
20 . The non-transitory computer-readable medium of claim 15 , wherein validating the second request includes the plurality of attributes satisfying each of the one or more policies.