IP Library › Granted Patent US 10,187,473
Granted Patent B2
US 10,187,473 · App. 15/143,492 · Granted Jan 22, 2019

Gateway policy enforcement and service metadata binding

Inventors: Jason Michael Webb (San Marcos, CA); Amit Ramchandra Jere (San Diego, CA); Thomas Barnes (San Diego, CA); Miroslav Svetoslavov Boussarov (San Diego, CA); Viraj Raghunath Kulkarni (San Diego, CA); Shailesh Shamarao Sawant (San Marcos, CA); Santosh Shenoy (San Diego, CA); Michael Scott Obendorf (San Diego, CA)
Assignee: INTUIT INC.
H04L67/14H04L41/0803H04L43/08H04L67/28H04L67/2804H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,187,473
App. No.
15/143,492
Granted
Jan 22, 2019
Kind
B2
Abstract

The invention relates to a method for gateway policy enforcement. The method includes receiving configuration data from a services registry. Also, the method includes annotating, based on the configuration data, a plurality of policies with flags. In addition, the method includes binding, using the annotations of the policies, a route to at least one of the annotated policies.

Claims (46)

1. A method for gateway policy enforcement, comprising:

receiving configuration data from a services registry;

annotating, based on the configuration data, a plurality of policies with flags, wherein each of the flags identifies a portion of code to be mandatorily executed under a policy, based on the annotation of the policy with the flag; and

binding, using the annotations of the policies, a route to at least one of the annotated policies.

2. The method of claim 1 , further comprising:

receiving a request from a client; and

matching, using a content of the request, the request to the route.

3. The method of claim 2 , further comprising:

in response to matching the request to the route, executing, against the request, the at least one of the policies bound to the route.

4. The method of claim 3 , further comprising:

processing the request when the at least one of the policies is successfully executed against the request.

5. The method of claim 3 , further comprising:

denying the request when the at least one of the policies is not successfully executed against the request.

6. The method of claim 3 , wherein the configuration data is received from the services registry during an initialization process.

7. The method of claim 3 , further comprising preventing execution, against the request, of any of the policies not bound to the route.

8. The method of claim 3 , wherein the at least one of the policies bound to the route includes at least one of: an authentication type, an authorization rule, a throttling rule, and a traffic swimlane.

9. A system for gateway policy enforcement, comprising:

a hardware processor and memory; and

software instructions stored in the memory and configured to execute on the hardware processor, which, when executed by the hardware processor, cause the hardware processor to:

receive configuration data from a services registry;

annotate, based on the configuration data, a plurality of policies with flags, wherein each of the flags identifies a portion of code to be mandatorily executed under a policy, based on the annotation of the policy with the flag; and

bind, using the annotations of the policies, a route to at least one of the annotated policies.

10. The system of claim 9 , wherein the software instructions are configured to, when executed by the hardware processor, further cause the hardware processor to:

receive a request from a client; and

match, using a content of the request, the request to the route.

11. The system of claim 10 , wherein the software instructions are configured to, when executed by the hardware processor, further cause the hardware processor to:

in response to matching the request to the route, execute, against the request, the at least one of the policies bound to the route.

12. The system of claim 11 , wherein the software instructions are configured to, when executed by the hardware processor, further cause the hardware processor to:

process the request when the at least one of the policies is successfully executed against the request.

13. The system of claim 11 , wherein the software instructions are configured to, when executed by the hardware processor, further cause the hardware processor to:

deny the request when the at least one of the policies is not successfully executed against the request.

14. The system of claim 11 , wherein the configuration data is received from the services registry during an initialization process.

15. The system of claim 11 , wherein the software instructions are configured to, when executed by the hardware processor, further cause the hardware processor to:

prevent execution, against the request, of any of the policies not bound to the route.

16. The system of claim 11 , wherein the at least one of the policies bound to the route includes at least one of: an authentication type, an authorization rule, a throttling rule, and a traffic swimlane.

17. A non-transitory computer readable medium for gateway policy enforcement comprising instructions that, when executed by a processor, perform a method, comprising:

receiving configuration data from a services registry;

annotating, based on the configuration data, a plurality of policies with flags, wherein each of the flags identifies a portion of code to be mandatorily executed under a policy, based on the annotation of the policy with the flag; and

binding, using the annotations of the policies, a route to at least one of the annotated policies.

18. The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed by the processor, further perform a method, comprising:

receiving a request from a client; and

matching, using a content of the request, the request to the route.

19. The non-transitory computer readable medium of claim 18 , wherein the instructions, when executed by the processor, further perform a method, comprising:

in response to matching the request to the route, executing, against the request, the at least one of the policies bound to the route.

20. The non-transitory computer readable medium of claim 19 , wherein the instructions, when executed by the processor, further perform a method, comprising:

processing the request when the at least one of the policies is successfully executed against the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2017
From: WEBB, JASON MICHAEL; JERE, AMIT RAMCHANDRA; BARNES, THOMAS; BOUSSAROV, MIROSLAV SVETOSLAVOV; KULKARNI, VIRAJ RAGHUNATH; SAWANT, SHAILESH SHAMARAO; SHENOY, SANTOSH; OBENDORF, MICHAEL SCOTT
To: INTUIT INC.
Reel/Frame 041823/0378 →
Continuity (1)
Related Publication 20170318095A1 · Nov 2, 2017