IP Library Granted Patent US 12,393,939
Granted Patent B2
US 12,393,939 · App. 18/429,786 · Granted Aug 19, 2025

Managing pre-provisioning and post-provisioning of resources using bitemporal analysis

Inventors: Brian Lee Wong (Midlothian, VA); Virendra K. Abelak (Ashburn, VA); Steven Lott (McLean, VA); Philip Austin Kedy (Oakton, VA)
Assignee: Capital One Services, LLC
G06Q20/389G06F16/215G06F16/219G06F16/2308G06F16/2358G06F16/2365G06F16/2379G06F16/9024G06Q20/08H04L41/0806H04L41/0816H04L41/0856H04L41/0866H04L67/34H04L69/02H04L69/08G06Q40/00H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,939
App. No.
18/429,786
Filed
Feb 1, 2024
Granted
Aug 19, 2025
Kind
B2
Art Unit
2443
USPC
709/220
Abstract

Embodiments disclosed are directed to ensuring resource compliance within a cloud-based environment. The embodiments include steps for performing both pre-provisioning and post-provisioning checks of resources, such as network protocols, prior to and after their deployment within the cloud-based environment. These steps include using bitemporal analysis to determine the impact of deploying resources within the environment through the use of multiple execution timelines where the impact of deploying a resource may be evaluated on an alternative timeline that does not change the current resource scope of the cloud-based environment. The analysis may further include tracking the impact of the resource after it has been deployed to ensure resource compliance.

Claims (51)

1. A computer-implemented method for improving protocol compliance in a cloud network that includes an immutable database, the method comprising:

maintaining, in a bitemporal ledger of the immutable database, a plurality of states of the cloud network on a current execution timeline, wherein the plurality of states comprises a current state of the cloud network and at least one prior state of the cloud network, wherein the current state reflects a current resource scope of the cloud network, and wherein the current execution timeline comprises at least one resource and at least one protocol currently deployed in the cloud network;

receiving a request to provision a new protocol in the cloud network;

determining whether to provision the new protocol by:

creating, in the bitemporal ledger, an alternate execution timeline separate from the current execution timeline;

duplicating, from the current execution timeline, the at least one resource and the at least one protocol to the alternate execution timeline;

receiving provisioning information associated with provisioning the new protocol in the cloud network, wherein the provisioning information comprises data necessary to provision the new protocol in the cloud network;

deploying, based on the provisioning information, the new protocol in the alternate execution timeline;

receiving a result of deploying the new protocol in the alternate execution timeline, wherein the result includes an alternate impact on the current state of the cloud network; and

determining whether to deploy or prevent deployment of the new protocol in the cloud network based on the result.

2. The computer-implemented method of claim 1 , further comprising deploying the new protocol in the cloud network responsive to the result indicating the new protocol is compliant with the cloud network.

3. The computer-implemented method of claim 2 , wherein the alternate impact reflects an alternate state of the cloud network, the method further comprising:

updating the current state with the alternate state of the cloud network.

4. The computer-implemented method of claim 1 , further comprising preventing deployment of the new protocol in the cloud network responsive to the result indicating that the new protocol is non-compliant with the cloud network.

5. The computer-implemented method of claim 4 , wherein the new protocol is considered non-compliant when deployment of the new protocol would violate a security rule of the cloud network.

6. The computer-implemented method of claim 4 , wherein the new protocol is considered non-compliant when deployment of the new protocol would violate a resource scope of the cloud network.

7. The computer-implemented method of claim 1 , wherein the alternate execution timeline comprises an execution space for testing the new protocol using an alternate history of transactions, wherein testing the new protocol comprises generating the result of deploying the new protocol.

8. The computer-implemented method of claim 1 , wherein the result indicates that the deploying the new protocol is permitted by a plurality of protocol rules associated with enforcement of policies in the cloud network.

9. A compliance system for a cloud network, the compliance system comprising:

an immutable database implementing a bitemporal ledger;

a processor configured to:

maintain, in the bitemporal ledger of the immutable database, a plurality of states of the cloud network on a current execution timeline, wherein the plurality of states comprises a current state of the cloud network and at least one prior state of the cloud network, wherein the current state reflects a current resource scope of the cloud network, and wherein the current execution timeline comprises at least one resource and at least one protocol currently deployed in the cloud network;

receive a request to provision a new protocol in the cloud network;

determine whether to provision the new protocol which comprises:

create, in the bitemporal ledger, an alternate execution timeline separate from the current execution timeline;

duplicate, from the current execution timeline, the at least one resource and the at least one protocol to the alternate execution timeline;

receive provisioning information associated with provisioning the new protocol in the cloud network, wherein the provisioning information comprises data necessary to provision the new protocol in the cloud network;

deploy, based on the provisioning information, the new protocol in the alternate execution timeline;

receive a result of deploying the new protocol in the alternate execution timeline, wherein the result includes an alternate impact on the current state of the cloud network; and

determine whether to deploy or prevent deployment of the new protocol in the cloud network based on the result.

10. The compliance system of claim 9 , further comprising deploying the new protocol in the cloud network responsive to the result indicating the new protocol is compliant with the cloud network.

11. The compliance system of claim 9 , wherein the alternate impact reflects an alternate state of the cloud network, the processor further configured to:

update the current state with the alternate state of the cloud network.

12. The compliance system of claim 9 , further comprising preventing deployment of the new protocol in the cloud network responsive to the result indicating that the new protocol is non-compliant with the cloud network.

13. The compliance system of claim 12 , wherein the new protocol is considered non-compliant when deployment of the new protocol would violate a security rule of the cloud network.

14. The compliance system of claim 12 , wherein the new protocol is considered non-compliant when deployment of the new protocol would violate a resource scope of the cloud network.

15. The compliance system of claim 9 , wherein the alternate execution timeline comprises an execution space for testing the new protocol using an alternate history of transactions, wherein testing the new protocol comprises generating the result of deploying the new protocol.

16. The compliance system of claim 9 , wherein the result indicates that the deploying the new protocol is permitted by a plurality of protocol rules associated with enforcement of policies in the cloud network.

17. A non-transitory computer-readable medium storing instructions, the instructions, when executed by a processor in a compliance system of a cloud network, cause the processor to perform operations comprising:

maintaining, in a bitemporal ledger of an immutable database implemented in the compliance system, a plurality of states of the cloud network on a current execution timeline, wherein the plurality of states comprises a current state of the cloud network and at least one prior state of the cloud network, wherein the current state reflects a current resource scope of the cloud network, and wherein the current execution timeline comprises at least one resource and at least one protocol currently deployed in the cloud network;

receiving a request to provision a new protocol in the cloud network;

determining whether to provision the new protocol by:

creating, in the bitemporal ledger, an alternate execution timeline separate from the current execution timeline;

duplicating, from the current execution timeline, the at least one resource and the at least one protocol to the alternate execution timeline;

receiving provisioning information associated with provisioning the new protocol in the cloud network, wherein the provisioning information comprises data necessary to provision the new protocol in the cloud network;

deploying, based on the provisioning information, the new protocol in the alternate execution timeline;

receiving a result of deploying the new protocol in the alternate execution timeline, wherein the result includes an alternate impact on the current state of the cloud network; and

determining whether to deploy or prevent deployment of the new protocol in the cloud network based on the result.

18. The non-transitory computer-readable medium of claim 17 , further comprising deploying the new protocol in the cloud network responsive to the result indicating the new protocol is compliant with the cloud network.

19. The non-transitory computer-readable medium of claim 17 , further comprising preventing deployment of the new protocol in the cloud network responsive to the result indicating that the new protocol is non-compliant with the cloud network.

20. The non-transitory computer-readable medium of claim 19 , wherein the new protocol is considered non-compliant when deployment of the new protocol would violate a security rule of the cloud network.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE SECOND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 066495 FRAME: 0684. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 21, 2024
From: WONG, BRIAN LEE; ABELAK, VIRENDRA K.; LOTT, STEVEN; KEDY, PHILIP AUSTIN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066641/0710 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2024
From: WONG, BRIAN LEE; ABELAK, VIRENDA K.; LOTT, STEVEN; KEDY, PHILIP AUSTIN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066495/0684 →
Continuity (3)
Continuation 17516329 · Nov 1, 2021
Provisional Application 63157455 · Mar 5, 2021
Related Publication 20240169348A1 · May 23, 2024
References Cited (64)
US 7681245B2 · Walker et al. · 2010 [cited by applicant]
US 9684570B1 · Wilding · 2017 [cited by applicant]
US 10360025B2 · Foskett et al. · 2019 [cited by applicant]
US 10476947B1 · Natarajan · 2019 [cited by applicant]
US 10503905B1 · Misra et al. · 2019 [cited by applicant]
US 10681049B2 · Jeuk et al. · 2020 [cited by applicant]
US 10764070B2 · Kass · 2020 [cited by applicant]
US 10789316B2 · Noble et al. · 2020 [cited by applicant]
US 10795977B2 · Salomon · 2020 [cited by applicant]
US 10866945B2 · Ventura et al. · 2020 [cited by applicant]
US 10872029B1 · Bawcom · 2020 [cited by applicant]
US 10924288B2 · Yan et al. · 2021 [cited by applicant]
US 10949406B1 · Calvo et al. · 2021 [cited by applicant]
US 11036873B2 · Lopez · 2021 [cited by applicant]
US 11080257B2 · Cseri et al. · 2021 [cited by applicant]
US 11140061B1 · Sanders et al. · 2021 [cited by applicant]
US 11196567B2 · Certain et al. · 2021 [cited by applicant]
US 11216788B1 · Vijayaraghavan · 2022 [cited by applicant]
US 11218854B2 · Raleigh et al. · 2022 [cited by applicant]
US 11275726B1 · Mikhtoniuk et al. · 2022 [cited by applicant]
US 11350254B1 · Natarajan et al. · 2022 [cited by applicant]
US 11544797B1 · Cohen · 2023 [cited by applicant]
US 20070156659A1 · Lim · 2007 [cited by applicant]
US 20070157288A1 · Lim · 2007 [cited by applicant]
US 20070185922A1 · Kapoor et al. · 2007 [cited by applicant]
US 20080250078A1 · Wimberly et al. · 2008 [cited by applicant]
US 20090319501A1 · Goldstein et al. · 2009 [cited by applicant]
US 20110231543A1 · Akazawa et al. · 2011 [cited by applicant]
US 20110320419A1 · Johnston et al. · 2011 [cited by applicant]
US 20130018849A1 · Johnston et al. · 2013 [cited by applicant]
US 20140236527A1 · Chan et al. · 2014 [cited by applicant]
US 20140310714A1 · Chan · 2014 [cited by examiner]
US 20150135084A1 · Rosenberger · 2015 [cited by applicant]
US 20150169697A1 · Kaufmann et al. · 2015 [cited by applicant]
US 20150254330A1 · Chan et al. · 2015 [cited by applicant]
US 20150261776A1 · Attarde et al. · 2015 [cited by applicant]
US 20160171372A1 · Fraleigh et al. · 2016 [cited by applicant]
US 20160342979A1 · Joshi et al. · 2016 [cited by applicant]
US 20180144823A1 · Raman et al. · 2018 [cited by applicant]
US 20180167492A1 · Bonig et al. · 2018 [cited by applicant]
US 20180117446A1 · Tran et al. · 2018 [cited by applicant]
US 20190018887A1 · Madisetti et al. · 2019 [cited by applicant]
US 20190361917A1 · Tran et al. · 2019 [cited by applicant]
US 20190370404A1 · Kessee et al. · 2019 [cited by applicant]
US 20190386877A1 · Vaidya et al. · 2019 [cited by applicant]
US 20200067697A1 · Puddu et al. · 2020 [cited by applicant]
US 20200183739A1 · Hashimoto et al. · 2020 [cited by applicant]
US 20200252404A1 · Padmanabhan · 2020 [cited by applicant]
US 20200344290A1 · Krishnaswamy et al. · 2020 [cited by applicant]
US 20200349142A1 · Padmanabhan · 2020 [cited by applicant]
US 20210035112A1 · Singh et al. · 2021 [cited by applicant]
US 20210055927A1 · Sarukkal et al. · 2021 [cited by applicant]
US 20210157794A1 · Tulsi · 2021 [cited by examiner]
US 20210158449A1 · Tulsi et al. · 2021 [cited by applicant]
US 20210256009A1 · Zhang et al. · 2021 [cited by applicant]
US 20210336896A1 · Calmon et al. · 2021 [cited by applicant]
US 20220284422A1 · Kedy et al. · 2022 [cited by applicant]
US 20220284423A1 · Kedy et al. · 2022 [cited by applicant]
US 20220284424A1 · Kedy et al. · 2022 [cited by applicant]
US 20220286352A1 · Wong et al. · 2022 [cited by applicant]
US 20220286353A1 · Wong et al. · 2022 [cited by applicant]
US 20220286359A1 · Wong et al. · 2022 [cited by applicant]
Kaufmann Martin et al: “Bi-temporal Timeline Index: A data structure for Processing Queries on bi-temporal data”, 2015 IEEE 31st International Conference on Data Engineering, IEEE, Apr. 13, 2015 (Apr. 13, 2015), pp. 471… [cited by applicant]
Supplementary European Search Report for EP Application No. EP 21 92 9413, Munich, Germany, mailed on Dec. 13, 2024, 11 pages. [cited by applicant]