IP Library › Granted Patent US 11,343,248
Granted Patent B2
US 11,343,248 · App. 16/817,366 · Granted May 24, 2022

Sidecar architecture for stateless proxying to databases

Inventors: Manav Ratan Mital (Mountain View, CA); Srinivas Nageswarrao Vadlamani (San Jose, CA); Pramod Chandraiah (Pleasanton, CA); Hugo Araújo de Sousa (Belo Horizonte, BR)
Assignee: Cyral Inc.
H04L63/0884H04L63/0428H04L63/20H04L63/306H04L69/326H04L69/329
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,343,248
App. No.
16/817,366
Filed
Mar 12, 2020
Granted
May 24, 2022
Kind
B2
Art Unit
2457
USPC
713/168
Abstract

A mechanism for providing connection to a database is described. A connection to the database is intercepted. The connection is assigned to an instance of the database. A sidecar is configured to proxy the connection to the database. The sidecar is stateless and passes all communications for the connection to the instance of the database.

Claims (47)

1. A method, comprising:

intercepting a connection to a database, wherein the connection is for a client;

assigning the connection to an instance of the database;

authenticating the client; and

configuring a sidecar to proxy the connection to the instance of the database, wherein the sidecar is stateless and passes all communications for the connection for the instance of the database from the sidecar only if the client is authorized, wherein during the intercepting of the connection, the sidecar is in a step mode and stores the communications, and wherein after the client is authorized, the sidecar is placed in a stream mode and forwards the stored communications to the instance of the database.

2. The method of claim 1 , wherein the sidecar has a form factor selected from Docker, Kubernetes, cloud lambda, Debian and RPM.

3. The method of claim 1 , further comprising:

encrypting at least a portion of the communications for the connection before passing the at least the portion of the communications to the instance of the database.

4. The method of claim 1 ,

wherein the passing further includes:

recalling the communications before processing by the instance of the database if the client is not authorized to access the database.

5. The method of claim 1 , wherein the sidecar includes an open systems interconnection (OSI) Layer 4 dispatcher.

6. The method of claim 5 , further comprising:

providing at least a portion of the communications to the instance of the database and to at least one OSI Layer 7 service.

7. The method of claim 6 , further comprising:

analyzing the at least the portion of the communications by the at least one OSI Layer 7 service; and

enforcing at least one policy using the OSI Layer 7 service.

8. A system, comprising:

a processor configured to:

intercept a connection to a database, wherein the connection is for a client;

assign the connection to an instance of the database;

authenticate the client; and

configure a sidecar to proxy the connection to the instance of the database, wherein the sidecar is stateless and passes all communications for the connection for the instance of the database from the sidecar only if the client is authorized, wherein during the intercepting of the connection, the sidecar is in a step mode and stores the communications, and wherein after the client is authorized, the sidecar is placed in a stream mode and forwards the stored communications to the instance of the database; and

a memory coupled to the processor and configured to provide the processor with instructions.

9. The system of claim 8 , wherein the sidecar has a form factor selected from Docker, Kubernetes, cloud lambda, Debian and RPM.

10. The system of claim 8 , wherein the processor is further configured to:

encrypt at least a portion of the communications for the connection before passing the at least the portion of the communications.

11. The system of claim 8 , wherein the sidecar includes an open systems interconnection (OSI) Layer 4 dispatcher.

12. The system of claim 11 , wherein the processor is further configured to:

provide at least a portion of the communications to the instance of the database and to at least one OSI Layer 7 service.

13. The system of claim 12 , wherein the processor is further configured to:

analyze the at least the portion of the communications by the at least one OSI Layer 7 service; and

enforce at least one policy using the OSI Layer 7 service.

14. A computer program product, the computer program product being embodied in a tangible computer readable storage medium and comprising computer instructions for:

intercepting a connection to a database, wherein the connection is for a client;

assigning the connection to an instance of the database;

authenticating the client; and

configuring a sidecar to proxy the connection to the instance of the database, wherein the sidecar is stateless and passes all communications for the connection for the instance of the database from the sidecar only if the client is authorized, wherein during the intercepting of the connection, the sidecar is in a step mode and stores the communications, and wherein after the client is authorized, the sidecar is placed in a stream mode and forwards the stored communications to the instance of the database.

15. The computer program product of claim 14 , wherein the sidecar has a form factor selected from Docker, Kubernetes, cloud lambda, Debian and RPM.

16. The computer program product of claim 14 , wherein the computer instructions further include computer instructions for:

encrypting at least a portion of the communications for the connection before passing the at least the portion of the communications.

17. The computer program product of claim 14 , wherein the sidecar includes an open systems interconnection (OSI) Layer 4 dispatcher.

18. The computer program product of claim 16 , wherein the computer instructions further include instructions for:

providing at least a portion of the communications to the instance of the database and to at least one OSI Layer 7 service.

19. The computer program product of claim 17 , wherein the computer instructions further include instructions for:

analyzing the at least the portion of the communications by the at least one OSI Layer 7 service; and

enforcing at least one policy using the OSI Layer 7 service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2020
From: MITAL, MANAV RATAN; VADLAMANI, SRINIVAS NAGESWARRAO; CHANDRAIAH, PRAMOD; ARAÚJO DE SOUSA, HUGO
To: CYRAL INC.
Reel/Frame 052350/0184 →
Continuity (6)
Continuation In Part 16548732 · Aug 22, 2019
Provisional Application 62891795 · Aug 26, 2019
Provisional Application 62840847 · Apr 30, 2019
Provisional Application 62758223 · Nov 9, 2018
Provisional Application 62733013 · Sep 18, 2018
Related Publication 20200236108A1 · Jul 23, 2020