IP Library Granted Patent US 12,348,522
Granted Patent B2
US 12,348,522 · App. 18/056,977 · Granted Jul 1, 2025

Extended security scheme for reducing the prevalence of broken object level authorization

Inventors: Rami Haddad (Assendelft, NL); Rim El Malki (Palaiseau, FR); Daniel-Serban Cozma (Braila, RO); Hendrikus G. P. Bosch (Aalsmeer, NL)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/101H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,522
App. No.
18/056,977
Granted
Jul 1, 2025
Kind
B2
Abstract

A system and method for an extended security scheme for reducing the prevalence of broken object level authorization. In one embodiment, a method includes receiving code associated with an application programming interface (API), wherein the code includes one of an API definition and an API server stub, and parsing the code for one or more keywords associated with an extended security scheme. If the code includes the API definition, the method further includes generating an associated API server stub based on at least one of the one or more keywords and the API definition. If the code includes the API server stub, the method further includes generating an associated API definition based on at least one of the one or more keywords and the API server stub.

Claims (46)

1. A method for providing an extended security scheme for reducing prevalence of broken object level authorization for a user, comprising:

receiving, by an application programming interface (API) generator, code associated with an API received from the user, wherein the code comprises one of an API definition and an API server stub;

parsing, by the API generator, the code for one or more keywords associated with the extended security scheme;

if the code comprises the API definition, generating, by the API generator, an associated API server stub based on at least one of the one or more keywords and the API definition, wherein the associated API server stub implements the extended security scheme;

if the code comprises the API server stub, generating, by the API generator, an associated API definition based on at least one of the one or more keywords and the API server stub, wherein the associated API definition implements the extended security scheme; and

transmitting, by the API generator, the associated API server stub or the associated API definition to the user.

2. The method of claim 1 , wherein the code comprises instructions associated with object-level security features.

3. The method of claim 1 , wherein generating the associated API server stub comprises implementing an authorization module that is configured to automatically generate an access control list for objects created by calls to the associated API server stub during runtime.

4. The method of claim 1 , further comprising:

detecting a call from the user to an object at the associated API server stub during runtime;

checking an access control list for one or more user privileges associated with the object; and

rejecting the call based on determining that the one or more user privileges does not include access to the object.

5. The method of claim 1 , wherein generating the associated API definition comprises generating an API definition file comprising the extended security scheme available for use in API development.

6. The method of claim 1 , wherein the extended security scheme is an object-level security scheme.

7. The method of claim 1 , wherein the extended security scheme comprises a wrapper function for generating an object privilege.

8. A system for providing an extended security scheme for reducing prevalence of broken object level authorization for a user, comprising:

one or more processors; and

one or more non-transitory computer-readable storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations comprising:

receiving, by an application programming interface (API) generator, code associated with an API received from the user, wherein the code comprises one of an API definition and an API server stub;

parsing, by the API generator, the code for one or more keywords associated with the extended security scheme;

if the code comprises the API definition, generating, by the API generator, an associated API server stub based on at least one of the one or more keywords and the API definition, wherein the associated API server stub implements the extended security scheme;

if the code comprises the API server stub, generating, by the API generator, an associated API definition based on at least one of the one or more keywords and the API server stub, wherein the associated API definition implements the extended security scheme; and

transmitting, by the API generator, the associated API server stub or the associated API definition to the user.

9. The system of claim 8 , wherein the code comprises instructions associated with object-level security features.

10. The system of claim 8 , wherein generating the associated API server stub comprises implementing an authorization module that is configured to automatically generate an access control list for objects created by calls to the associated API server stub during runtime.

11. The system of claim 8 , further comprising:

detecting a call from the user to an object at the associated API server stub during runtime;

checking an access control list for one or more user privileges associated with the object; and

rejecting the call based on determining that the one or more user privileges does not include access to the object.

12. The system of claim 8 , wherein generating the associated API definition comprises generating an API definition file comprising the extended security scheme available for use in API development.

13. The system of claim 8 , wherein the extended security scheme is an object-level security scheme.

14. The system of claim 8 , wherein the extended security scheme comprises a wrapper function for generating an object privilege.

15. One or more non-transitory computer-readable storage media embodying instructions for providing an extended security scheme for reducing prevalence of broken object level authorization for a user, the instructions when executed by a processor, cause performance of operations comprising:

receiving, by an application programming interface (API) generator, code associated with an API received from the user, wherein the code comprises one of an API definition and an API server stub;

parsing, by the API generator, the code for one or more keywords associated with the extended security scheme;

if the code comprises the API definition, generating, by the API generator, an associated API server stub based on at least one of the one or more keywords and the API definition, wherein the associated API server stub implements the extended security scheme;

if the code comprises the API server stub, generating, by the API generator, an associated API definition based on at least one of the one or more keywords and the API server stub, wherein the associated API definition implements the extended security scheme; and

transmitting, by the API generator, the associated API server stub or the associated API definition to the user.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein the code comprises instructions associated with object-level security features.

17. The one or more non-transitory computer readable storage media of claim 15 , wherein generating the associated API server stub comprises implementing an authorization module that is configured to automatically generate an access control list for objects created by calls to the associated API server stub during runtime.

18. The one or more non-transitory computer-readable storage media of claim 15 , the operations further comprising:

detecting a call from the user to an object at the associated API server stub during runtime;

checking an access control list for one or more user privileges associated with the object; and

rejecting the call based on determining that the one or more user privileges does not include access to the object.

19. The one or more non-transitory computer-readable storage media of claim 15 , wherein generating the associated API definition comprises generating an API definition file comprising the extended security scheme available for use in API development.

20. The one or more non-transitory computer readable storage media of claim 15 , wherein the extended security scheme is an object-level security scheme.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2022
From: HADDAD, RAMI; EL MALKI, RIM; COZMA, DANIEL-SERBAN; BOSCH, HENDRIKUS G. P.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 061827/0153 →
Continuity (2)
Provisional Application 63376112 · Sep 19, 2022
Related Publication 20240098090A1 · Mar 21, 2024
References Cited (14)
US 10956242B1 · Kumar · 2021 [cited by examiner]
US 20030115487A1 · Andrews · 2003 [cited by examiner]
US 20080109897A1 · Moran et al. · 2008 [cited by applicant]
US 20100251340A1 · Martin et al. · 2010 [cited by applicant]
US 20130238589A1 · Yarramreddy · 2013 [cited by examiner]
US 20140109198A1 · Brown et al. · 2014 [cited by applicant]
US 20150278243A1 · Vincent et al. · 2015 [cited by applicant]
US 20160105408A1 · Cooper · 2016 [cited by examiner]
US 20160373455A1 · Shokhrin · 2016 [cited by examiner]
US 20200110584A1 · Irimescu · 2020 [cited by examiner]
US 20200153850A1 · Krishnan · 2020 [cited by examiner]
US 20200396223A1 · Dube · 2020 [cited by examiner]
US 20220053000A1 · Dube et al. · 2022 [cited by applicant]
US 20220057999A1 · Pitchai Muthu · 2022 [cited by examiner]