Policy enforcement as a service for third party platforms with asynchronous user tracking mechanisms

US10771353B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10771353-B2
Application numberUS-201815885664-A
CountryUS
Kind codeB2
Filing dateJan 31, 2018
Priority dateJan 31, 2018
Publication dateSep 8, 2020
Grant dateSep 8, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and computer-readable media for providing a Policy Enforcement as a Service (PEaaS) are described. The PEaaS may allow customer service providers to define policies for usage restrictions to be implemented across their distributed systems/platforms. The policy enforcement mechanisms of the PEaaS may prevent users from overloading the systems/platforms of the customer service providers. The PEaaS may also include mechanisms for asynchronously (or “lazy”) tracking user infractions or suspensions. The lazy tracking mechanism may track and perform asynchronous (async) computation of infraction records and suspension sets/lists. Other embodiments may be described and/or claimed.

First claim

Opening claim text (preview).

The invention claimed is: 1. One or more non-transitory computer-readable media (NTCRM) comprising instructions for providing a Policy Enforcement as a Service web service (PEaaS-WS), wherein execution of the instructions by one or more processors of a computing system is operable to cause the computing system to: generate or update, in response to each received user request to access a service provided by a third party platform (TPP) of a plurality of TPPs, usage metrics of user systems that sent each received user request; generate or update, based on each received user request to access the service provided by the TPP, an alert database object (DBO) to store alert attribute value pairs (AVPs) for each received user request, each alert AVP comprising: a value to indicate a client identifier (client_id) associated with a user or user system that sent a user request, and an attribute including a policy identifier (policy_id), the policy_id indicating a policy defined by the TPP for the service provided by the TPP; determine, in response to obtaining a dequeued alert AVP, whether an infraction has occurred based on the usage metrics, the infraction being a violation of the policy indicated by the policy_id of the dequeued alert AVP that is committed by a user indicated by the client_id of the dequeued alert AVP; generate or update a suspension DBO including infraction records, each infraction record comprising: an infraction client_id field to indicate a client_id of a user that has committed one or more infractions, and a suspension period field to indicate a suspension period, the suspension period being a period that a user indicated by the infraction client_id field is to be prevented from accessing the service; delete an individual infraction record from the suspension DBO when a suspension period indicated by the individual infraction record has expired; control transmission, in response to a request for suspended users, of a suspension indication to indicate the suspension DBO; and control transmission of a reinstatement message when the suspension period indicated by the individual infraction record has expired, the reinstatement message to indicate that the suspension period indicated by the individual infraction record has expired. 2. The one or more NTCRM of claim 1 , wherein execution of the instructions is operable to cause the computing system to: control transmission of the reinstatement message after the reinstatement message has been generated; or control transmission of a message that includes both the reinstatement message and the suspension indication. 3. The one or more NTCRM of claim 1 , wherein each infraction record further comprises a policy enabled field to indicate whether a policy defined for the service is active or inactive for the user indicated by the infraction client_id field, and execution of the instructions is operable to cause the computing system to: update the policy enabled field to indicate that the policy defined for the service is inactive when a suspension period for the user indicated by the infraction client_id field has expired. 4. A computing system, comprising: a processing system communicatively coupled with a memory system, wherein the processing system is configured to: collect and store one or more sets of policy parameter values from one or more third party platforms (TPPs), respectively, wherein each set of policy parameter values corresponds to a service provided by a TPP of the one or more of TPPs, and each set of policy parameter values defines when to issue a user suspension for the service provided by the TPP, collect and store one or more usage metric sets provided by the one or more TPPs, respectively, based on receipt of user requests to access services provided by respective TPPs of the one or more TPPs, wherein each usage metric set includes one or more usage metrics for one or more users, respectively, the usage metrics being based on interactions between the one or more users and the respective TPP, generate or update alert attribute value pairs (AVPs) based on each received user request to access the service, each alert AVP including a value to indicate a client identifier (client_id) of a user or user system that sent a user request to access an individual service provided by an individual TPP, and an attribute to indicate a policy identifier (policy_id), the policy_id to indicate a set of policy parameter values defined by the individual TPP to correspond to the individual service, store each alert AVP in a message queue, compare, in response to obtaining a dequeued alert AVP, each of the usage metrics to a corresponding one of the sets of policy parameter values to identify users that have committed one or more infractions for one or more services, each of the one or more infractions being a violation of the policy indicated by the policy_id of the dequeued alert AVP that is committed by a user indicated by the client_id of the dequeued alert AVP, generate, in response to identification of ones of the identified users that have committed one or more infractions, infraction records indicative of a the infractions committed by corresponding ones of the identified users, and generate or update a suspension database object (DBO) to include the infraction records, each infraction record comprising: an infraction client_id field to indicate a client_id of a user that has committed one or more infractions, and a suspension period field to indicate a suspension period, the suspension period being a period that a user indicated by the suspended client_id field is to be prevented from accessing the service, and delete an individual infraction record from the suspension DBO when a suspension period indicated by the individual infraction record has expired; and a communication system communicatively coupled with the processing system, the communication system configured to: transmit suspension indications to corresponding ones of the TPPs, the suspension indications usable by the corresponding ones of the TPPs to determine whether to deny requests from the ones of the identified users for respective services; and transmit reinstatement messages to corresponding ones of the TPPs when the suspension period indicated by corresponding infraction records has expired, the reinstatement message to indicate that the suspension period indicated by the individual corresponding infraction records has expired. 5. The computing system of claim 4 , wherein each infraction record in the suspension DBO comprises: an infraction client_id field to indicate a client_id of a user that has committed one or more infractions; and a suspension period field to indicate a suspension period, the suspension period being a time that a user indicated by the suspended client_id field is to be prevented from accessing the service. 6. The computing system of claim 4 , wherein the processing system is configured to: delete individual infraction records from the suspension DBO when a suspension period indicated by the individual infraction records has expired. 7. The computing system of claim 6 , wherein the processing system is configured to: generate reinstatement messages when the suspension period indicated by the corresponding infraction records has expired, the reinstatement message to indicate that the suspension period indicated by the corresponding infraction records has expired. 8. The computing system of claim 7 , wherein the communication system is configured to transmit the reinstatement message after the reinstatement message has been generated. 9. The computing system of claim 7 , wherein the processor system is configured to generate a message that includes both the reins

Assignees

Inventors

Classifications

  • Creating or negotiating SLA contracts, guarantees or penalties · CPC title

  • using third party service providers · CPC title

  • wherein the managed service relates to distributed or central networked applications · CPC title

  • Indexing; Data structures therefor; Storage structures · CPC title

  • based on type of value added network service under agreement · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10771353B2 cover?
Systems, methods, and computer-readable media for providing a Policy Enforcement as a Service (PEaaS) are described. The PEaaS may allow customer service providers to define policies for usage restrictions to be implemented across their distributed systems/platforms. The policy enforcement mechanisms of the PEaaS may prevent users from overloading the systems/platforms of the customer service p…
Who is the assignee on this patent?
Salesforce Com Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/5006. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 08 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).