IP Library › Granted Patent US 12,242,628
Granted Patent B2
US 12,242,628 · App. 17/931,511 · Granted Mar 4, 2025

Providing service tier information when validating API requests

Inventors: Amitesh Madhur (Fremont, CA); Manoj Thirutheri (San Jose, CA); Divya Venkatachalam (San Jose, CA); Ashwani Pandey (Delhi, IN); Sreejith Othayedath (Katy, TX); Shubham Kumar (San Jose, CA); Rajat Kumar Agrawal (Raigarh, IN); Nagashree Praveen Raj (Bangalore, IN)
Assignee: NUTANIX, INC.
G06F21/6218G06F9/547
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,628
App. No.
17/931,511
Filed
Sep 12, 2022
Granted
Mar 4, 2025
Kind
B2
Art Unit
2497
USPC
726/29
Abstract

In various embodiments, one or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors, cause the one or more processors to perform a method comprising receiving, from an API server, a request to access a service, the request including an API authorization identifier; validating the API authorization identifier to generate a validation result; determining a service tier of the service based on the request; and transmitting, to the API server, a response including the validation result and an indicator of the service tier based on the request.

Claims (56)

1. One or more non-transitory computer-readable media storing program instructions that, when executed by one or more processors of an authorization server, cause the one or more processors to perform a method comprising:

receiving, from an application programming interface (API) server, a request to access a service, the request including an API authorization identifier;

validating the API authorization identifier to generate a validation result;

determining a service tier of the service based on the request; and

transmitting, to the API server, a response to the request including the validation result and an indicator of the service tier based on the request.

2. The one or more non-transitory computer-readable media of claim 1 , wherein the API authorization identifier includes at least one of a key, a token, or a certificate.

3. The one or more non-transitory computer-readable media of claim 1 , wherein the indicator of the service tier indicates a level of performance to be used by the API server in performing the service.

4. The one or more non-transitory computer-readable media of claim 1 , wherein the service tier is determined based on identifying information of a user or a client device.

5. The one or more non-transitory computer-readable media of claim 1 , wherein the service tier is determined based on a subscription of a user or a client device that includes the service provided by the API server.

6. The one or more non-transitory computer-readable media of claim 5 , wherein the service tier is determined based on whether the user has a paid subscription or a free subscription to the service provided by the API server.

7. The one or more non-transitory computer-readable media of claim 1 , wherein the service tier is determined based on a subscription list that associates service tiers with subscribers.

8. The one or more non-transitory computer-readable media of claim 1 , further comprising determining a default service tier in response to a failure to determine a service tier based on the request.

9. The one or more non-transitory computer-readable media of claim 1 , wherein the indicator of the service tier includes a subscription associated with at least one of a user associated with the request or a client device associated with the request.

10. The one or more non-transitory computer-readable media of claim 1 , wherein the service tier indicates a performance of the service by the API server based on one or more of,

an availability of an operation of the service based on the service tier,

a level of detail of an operation of the service based on the service tier, or

a resource limit on resources to be used when performing an operation of the service based on the service tier.

11. The one or more non-transitory computer-readable media of claim 1 , wherein the service tier is selected from a plurality of service tiers, wherein each of the plurality of service tiers is associated with a different level of service in the API server.

12. A computer-implemented method of validating requests to access services, comprising:

receiving, in an authorization server and from an application programming interface (API) server, a request to access a service, the request including an API authorization identifier;

validating the API authorization identifier to generate a validation result;

determining a service tier of the service based on the request; and

transmitting, to the API server, a response to the request including the validation result and an indicator of the service tier based on the request.

13. The computer-implemented method of claim 12 , wherein the API authorization identifier includes at least one of a key, a token, or a certificate.

14. The computer-implemented method of claim 12 , wherein the indicator of the service tier indicates a level of performance to be used by the API server in performing the service.

15. The computer-implemented method of claim 12 , wherein the service tier is determined based on identifying information of a user or a client device.

16. The computer-implemented method of claim 12 , wherein the service tier is determined based on a subscription of a user or a client device that includes the service provided by the API server.

17. The computer-implemented method of claim 16 , wherein the service tier is determined based on whether the user has a paid subscription or a free subscription to the service provided by the API server.

18. The computer-implemented method of claim 12 , wherein the service tier is determined based on a subscription list that associates service tiers with subscribers.

19. The computer-implemented method of claim 12 , further comprising determining a default service tier in response to a failure to determine a service tier based on the request.

20. The computer-implemented method of claim 12 , wherein the indicator of the service tier includes a subscription associated with at least one of a user associated with the request or a client device associated with the request.

21. The computer-implemented method of claim 12 , wherein the service tier indicates a performance of the service by the API server based on one or more of,

an availability of an operation of the service based on the service tier,

a level of detail of an operation of the service based on the service tier, or

a resource limit on resources to be used when performing an operation of the service based on the service tier.

22. The computer-implemented method of claim 12 , wherein the service tier is selected from a plurality of service tiers, wherein each of the plurality of service tiers is associated with a different level of service in the API server.

23. An authorization server, comprising:

a memory that stores instructions, and

a processor that is coupled to the memory and, when executing the instructions, is configured to:

receive, from an application programming interface (API) server, a request to access a service, the request including an API authorization identifier;

validate the API authorization identifier to generate a validation result;

determine a service tier of the service based on the request; and

transmit, to the API server, a response to the request including the validation result and an indicator of the service tier based on the request.

24. The authorization server of claim 23 , wherein the API authorization identifier includes at least one of a key, a token, or a certificate.

25. The authorization server of claim 23 , wherein the indicator of the service tier indicates a level of performance to be used by the API server in performing the service.

26. The authorization server of claim 23 , wherein the service tier is determined based on identifying information of a user or a client device.

27. The authorization server of claim 23 , wherein the service tier is determined based on a subscription of a user or a client device that includes the service provided by the API server.

28. The authorization server of claim 27 , wherein the service tier is determined based on whether the user has a paid subscription or a free subscription to the service provided by the API server.

29. The authorization server of claim 23 , wherein the service tier is determined based on a subscription list that associates service tiers with subscribers.

30. The authorization server of claim 23 , wherein the processor, when executing the instructions, is further configured to determine a default service tier in response to a failure to determine a service tier based on the request.

31. The authorization server of claim 23 , wherein the indicator of the service tier includes a subscription associated with at least one of a user associated with the request or a client device associated with the request.

32. The authorization server of claim 23 , wherein the service tier indicates a performance of the service by the API server based on one or more of,

an availability of an operation of the service based on the service tier,

a level of detail of an operation of the service based on the service tier, or

a resource limit on resources to be used when performing an operation of the service based on the service tier.

33. The authorization server of claim 23 , wherein the service tier is selected from a plurality of service tiers, wherein each of the plurality of service tiers is associated with a different level of service in the API server.

Assignments (2)
SECURITY INTEREST Recorded Feb 13, 2025
From: NUTANIX, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 070206/0463 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2022
From: MADHUR, AMITESH; THIRUTHERI, MANOJ; VENKATACHALAM, DIVYA; PANDEY, ASHWANI; OTHAYEDATH, SREEJITH; KUMAR, SHUBHAM; AGRAWAL, RAJAT KUMAR; RAJ, NAGASHREE PRAVEEN
To: NUTANIX, INC.
Reel/Frame 061073/0092 →
Priority Claims (1)
IN 202241039541 · Jul 9, 2022 · national
Continuity (1)
Related Publication 20240012923A1 · Jan 11, 2024
References Cited (46)
US 8458051B1 · Saltzman et al. · 2013 [cited by applicant]
US 8549518B1 · Aron et al. · 2013 [cited by applicant]
US 8601473B1 · Aron et al. · 2013 [cited by applicant]
US 8850130B1 · Aron et al. · 2014 [cited by applicant]
US 8863124B1 · Aron · 2014 [cited by applicant]
US 9009106B1 · Aron et al. · 2015 [cited by applicant]
US 9069708B2 · Gill et al. · 2015 [cited by applicant]
US 9336132B1 · Aron et al. · 2016 [cited by applicant]
US 9652265B1 · Narayanasamy et al. · 2017 [cited by applicant]
US 9747287B1 · Bhardwaj et al. · 2017 [cited by applicant]
US 9772866B1 · Aron et al. · 2017 [cited by applicant]
US 10080048B2 · Phatak · 2018 [cited by applicant]
US 11388164B2 · Joyce et al. · 2022 [cited by applicant]
US 20140007198A1 · Durbha et al. · 2014 [cited by applicant]
US 20190303586A1 · Mahaffey · 2019 [cited by examiner]
US 20210037018A1 · Joyce et al. · 2021 [cited by applicant]
US 20210281555A1 · He · 2021 [cited by examiner]
CN 100596070C · 2010 [cited by examiner]
CN 108449417A · 2018 [cited by examiner]
Poitras, Steven. “The Nutanix Bible” (Oct. 15, 2013), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 11, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 20, 2014), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 7, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2015), from http://stevenpoitras.com/the-nutanix-bible/ (Publication date based on indicated capture date by Archive.org; first publication date unknown); pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 4, 2015), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 12, 2016), from https://nutanixbible.com/ ; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 9, 2016), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2017), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 8, 2017), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 3, 2018), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jun. 25, 2018), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jan. 8, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Jul. 25, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 17, 2019), from https://nutanixbible.com/; pp. all. [cited by applicant]
Cano, Ignacio et al. “Curator: Self-Managing Storage for Enterprise Clusters”; University of Washington; published Mar. 2017; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Mar. 2, 2020), from https://nutanixbible.com/; pp. all. [cited by applicant]
Poitras, Steven. “The Nutanix Bible” (Sep. 1, 2020), from https://nutanixbible.com/; pp. all. [cited by applicant]
Brinckwirth, John “Examples for Using API Policy Manager”, Nov. 20, 2021, 3 pages. [cited by applicant]
“API Management policies to validate requests and responses”, https://docs.microsoft.com/en-us/azure/api-management/validation-policies, Jul. 14, 2022, 3 pages. [cited by applicant]
“Protect serverless APIs with Azure API Management and Azure AD B2C for consumption from a SPA”, https://docs.microsoft.com/en-us/azure/api-management/howto-protect-backend-frontend-azure-ad-b2c, Jul. 6, 2022, 18 pages. [cited by applicant]
“What is Azure Cognitive Search?”, https://docs.microsoft.com/en-us/azure/search/search-what-is-azure-search, Jul. 23, 2022, 2 pages. [cited by applicant]
“Service limits in Azure Cognitive Search”, https://docs.microsoft.com/en-us/azure/search/search-limits-quotas-capacity, Jun. 12, 2022, 6 pages. [cited by applicant]
“Set up basic request validation in API Gateway” https://docs.aws.amazon.com/apigateway/latest/developerguide/api-gateway-request-validation-set-up.html, Sep. 12, 2022, 9 pages. [cited by applicant]
“Creating API requests and handling responses”, https://cloud.google.com/compute/docs/api/how-tos/api-requests-responses, Sep. 12, 2022, 8 pages. [cited by applicant]
“Access and authentication for the Rest API”, https://docs.bmc.com/docs/ars2002/access-and-authentication-for-the-rest-api-915370111.html, Sep. 12, 2022, 2 pages. [cited by applicant]
International Search Report for Application No. PCT/US2023/027071 dated Oct. 30, 2023. [cited by applicant]