IP Library Granted Patent US 12,132,764
Granted Patent B2
US 12,132,764 · App. 18/196,269 · Granted Oct 29, 2024

Dynamic security policy management

Inventor: Justin Paul Yancey (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L63/205H04L63/0227H04L63/101H04L63/107H04L63/108H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,132,764
App. No.
18/196,269
Granted
Oct 29, 2024
Kind
B2
Abstract

Security policies can be dynamically updated in response to changes in endpoints associated with those policies. A user can indicate one or more regions or networks from which access is to be granted under a specific security policy. The user can subscribe to receive notifications upon a change relating to those endpoints, such as the addition or removal of one or more endpoints. When a change is detected, new policy information can be generated automatically and published for subscribed policies, which can then have the updates applied automatically or provided for manual review and application. Such a process enables access determinations to be made based upon up-to-date endpoint information.

Claims (54)

1. A computer-implemented method, comprising:

enabling a network endpoint to be within a virtual private network;

determining, based at least in part on a security policy for the network endpoint, that a resource is to be associated to the network endpoint using an Application Programming Interface (API) gateway, the API gateway to comprise different APIs in an interface layer that is to parse different requests for different resources that comprise the resource, individual ones of the APIs to receive the different requests for the different resources; and

causing the security policy to be enforced for all access relating to the resource.

2. The computer-implemented method of claim 1 , further comprising:

receiving permission data that indicates one or more permissions associated with an individual one of the different requests to execute user code on the resource; and

using the permission data with the security policy to access the resource on the virtual private network.

3. The computer-implemented method of claim 1 , further comprising:

enabling a data service to be associated with the network endpoint, wherein the resource is enabled to communicate with the data service through the virtual private network based in part on the security policy.

4. The computer-implemented method of claim 1 , further comprising:

detecting a change in the network endpoint using a task-based resource;

generating new policy information based at least in part upon the change in the network endpoint; and

providing the new policy information for publication by a notification service.

5. The computer-implemented method of claim 1 , wherein the security policy is updated using new policy information, wherein the new policy information is provided by at least one of storing the new policy information to an information queue or transmitting the new policy information using a data streaming service.

6. The computer-implemented method of claim 1 , further comprising:

enabling the API gateway to be part of dedicated APIs associated with network endpoints, individual ones of the dedicated APIs to receive the different requests for at least one action to be performed with a service associated with one of the network endpoints.

7. The computer-implemented method of claim 1 , further comprising:

providing new policy information that specifies a change to the security policy of the network endpoint;

publishing the new policy information; and

causing the new policy information to change the security policy.

8. The computer-implemented method of claim 7 , wherein the new policy information is published using at least one of email messaging, instant messaging, short message service messaging, or text messaging.

9. The computer-implemented method of claim 1 , wherein the security policy is one of an access policy or a credential management policy.

10. The computer-implemented method of claim 1 , wherein the network endpoint corresponds to geo-locations of at least one of a sub-network or region of computing resources.

11. The computer-implemented method of claim 1 , further comprising:

determine a change in the network endpoint; and

determine that the change in the network endpoint requires update in the security policy; and

causing the update to be applied to the security policy.

12. A system, comprising:

at least one processor; and

memory including instructions that, when executed by the at least one processor, cause the system to:

enable a network endpoint to be within a virtual private network;

determine, based at least in part on a security policy for the network endpoint, that a resource is to be associated to the network endpoint using an Application Programming Interface (API) gateway, the API gateway to comprise different APIs in an interface layer that is to parse different requests for different resources that comprise the resource, individual ones of the APIs to receive the requests for the different resources; and

cause the security policy to be enforced for all access relating to the resource.

13. The system of claim 12 , wherein the instructions when executed further cause the system to:

receive permission data that indicates one or more permissions associated with an individual one of the different requests to execute user code on the resource; and

use the permission data with the security policy to access the resource on the virtual private network.

14. The system of claim 12 , wherein the instructions when executed further cause the system to:

enable a data service to be associated with the network endpoint, wherein the resource is enabled to communicate with the data service through the virtual private network based in part on the security policy.

15. The system of claim 12 , wherein the instructions when executed further cause the system to:

detect a change in the network endpoint using a task-based resource;

generate new policy information based at least in part upon the change in the network endpoint; and

provide the new policy information for publication by a notification service.

16. The system of claim 12 , wherein the security policy is updated using new policy information, wherein the new policy information is provided by at least one of storing the new policy information to an information queue or transmitting the new policy information using a data streaming service.

17. The system of claim 12 , wherein the instructions when executed further cause the system to:

enable the API gateway to be part of dedicated APIs associated with network endpoints, individual ones of the dedicated APIs to receive the different requests for at least one action to be performed with a service associated with one of the network endpoints.

18. A non-transitory computer-readable medium comprising instructions that when executed by at least one processor causes the at least one processor to:

enable a network endpoint to be within a virtual private network;

determine, based at least in part on a security policy for the network endpoint, that a resource is to be associated to the network endpoint using an Application Programming Interface (API) gateway, the API gateway to comprise different APIs in an interface layer that is to parse different requests for different resources that comprise the resource, individual ones of the APIs to receive the requests for the different resources; and

cause the security policy to be enforced for all access relating to the resource.

19. The non-transitory computer-readable medium of claim 18 , comprising the instructions that when executed by the at least one processor further causes the at least one processor to:

receive permission data that indicates one or more permissions associated with an individual one of the different requests to execute user code on the resource; and

use the permission data with the security policy to access the resource on the virtual private network.

20. The non-transitory computer-readable medium of claim 18 , comprising the instructions that when executed by the at least one processor further causes the at least one processor to:

enable a data service to be associated with the network endpoint, wherein the resource is enabled to communicate with the data service through the virtual private network based in part on the security policy.

Continuity (4)
Continuation 17706320 · Mar 28, 2022
Continuation 17104905 · Nov 25, 2020
Continuation 15616456 · Jun 7, 2017
Related Publication 20230283644A1 · Sep 7, 2023
Cited By (1)
US 12,665,935