Data consistency of policy enforcement for distributed applications

US11025513B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11025513-B2
Application numberUS-202016782852-A
CountryUS
Kind codeB2
Filing dateFeb 5, 2020
Priority dateJan 31, 2018
Publication dateJun 1, 2021
Grant dateJun 1, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, methods, and computer-readable media for providing a Policy Enforcement as a Service (PEaaS) are described. A processor may, in response to identification of a suspension of user(s) for one of one or more services, generate a suspension value indicative of the suspension and transmit the suspension value to a corresponding one of third party platforms of the service(s), respectively. The suspension value usable by the corresponding third party platform to determine whether to deny request(s) from the user for the distributed service, or not. A service of the service(s) comprises a distributed service provided by a plurality of hosts. In response to the service corresponding to the suspension including the distributed service, the suspension value may be transmitted to the first host, and the suspension value may be propagated to the one or more second hosts, respectively. Other embodiments may be described and/or claimed.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computing system to provide a Policy Enforcement as a Service (PEaaS) to a third party platform (TPP), the TPP comprising a plurality of hosts providing a distributed service, the computing system, the computing system comprising: a memory device coupled to a processing system, the memory device including instructions stored thereon, wherein the processing system is configurable by the instructions to: identify a policy for the distributed service, the policy defining criteria for tracking usage of the distributed service by individual users or individual user systems and a trigger condition; collect usage metrics from respective hosts of the plurality of hosts via respective interfaces between each host and the computing system, the usage metrics indicating usage of the distributed service by one or more users that interact with the respective hosts; control storage of the usage metrics according to the policy; and in response to detection of the trigger condition, generate records for the one or more users that interact with the respective hosts, the records indicating the usage metrics of the one or more users, and propagate the records to the respective hosts via the respective interfaces, the respective hosts to further provide the distributed service to the one or more users. 2. The computing system of claim 1 , wherein, to propagate the records to the respective hosts, the processing system is configurable by the instructions to: identify one or more synchronization requests from the respective hosts; and control transmission of respective responses to the one or more synchronization requests, each of the respective responses including the records. 3. The computing system of claim 2 , wherein the policy comprises one or more propagation interval values for the TPP, and the one or more synchronization requests are based on corresponding ones of the one or more propagation interval values. 4. The computing system of claim 3 , wherein the corresponding one of the one or more propagation interval values is taken from a selection from the TPP. 5. The computing system of claim 3 , wherein the corresponding one of the one or more propagation interval values comprises a default propagation interval value. 6. The computing system of claim 2 , wherein the one or more synchronization requests are received at one or more times, respectively, based on a same synchronization interval. 7. The computing system of claim 1 , wherein the policy defines criteria for issuing infractions for violation of the policy, the trigger condition is meeting or exceeding the criteria for issuing an infraction for individual users, and the records include user infractions of respective users of the one or more users. 8. The computing system of claim 1 , wherein the policy defines a plurality of user infraction thresholds for issuing a user suspension and a suspension period for each user infraction threshold of the plurality of user infraction thresholds. 9. The computing system of claim 8 , wherein the processing system is configurable by the instructions to: for each user of the one or more users determined to have met a user infraction threshold of the plurality of user infraction thresholds, generate the records to include a suspension value and a user that met the determined user infraction threshold, the suspension value indicating the determined user infraction threshold and a suspension period corresponding to the determined user infraction threshold. 10. The computing system of claim 9 , wherein each user infraction threshold indicates a number of user infractions identified within a defined amount of time, and the processing system is configurable by the instructions to: implement respective infraction counters for each user; increment the respective infraction counters in response to each detected user infraction for each user; generate the suspension value when the respective infraction counters reach a value defined by the policy. 11. One or more non-transitory computer-readable media (NTCRM) comprising instructions for providing a Policy Enforcement as a Service (PEaaS) to a third party platform (TPP), the TPP comprising a plurality of hosts providing a distributed service, wherein execution of the instructions by one or more processors of a computing system is operable to cause the computing system to: identify a policy for the distributed service, the policy defining criteria for tracking usage of the distributed service by individual users or individual user systems and a trigger condition; collect usage metrics from respective hosts of the plurality of hosts via respective interfaces between each host and the computing system, the usage metrics indicating usage of the distributed service by one or more users that interact with the respective hosts; control storage of the usage metrics according to the policy; and in response to detection of the trigger condition, generate records for the one or more users that interact with the respective hosts, the records indicating the usage metrics of the one or more users, and propagate the records to the respective hosts via the respective interfaces, the respective hosts to further provide the distributed service to the one or more users. 12. The one or more NTCRM of claim 11 , wherein, to propagate the records to the respective hosts, execution of the instructions is operable to cause the computing system to: identify one or more synchronization requests from the respective hosts; and control transmission of respective responses to the one or more synchronization requests, each of the respective responses including the records. 13. The one or more NTCRM of claim 12 , wherein the policy comprises one or more propagation interval values for the TPP, and the one or more synchronization requests are based on corresponding ones of the one or more propagation interval values. 14. The one or more NTCRM of claim 13 , wherein the corresponding one of the one or more propagation interval values is taken from a selection from the TPP. 15. The one or more NTCRM of claim 13 , wherein the corresponding one of the one or more propagation interval values comprises a default propagation interval value. 16. The one or more NTCRM of claim 12 , wherein the one or more synchronization requests are received at one or more times, respectively, based on a same synchronization interval. 17. The one or more NTCRM of claim 11 , wherein the policy defines criteria for issuing infractions for violation of the policy, the trigger condition is meeting or exceeding the criteria for issuing an infraction for individual users, and the records include user infractions of respective users of the one or more users. 18. The one or more NTCRM of claim 11 , wherein the policy defines a plurality of user infraction thresholds for issuing a user suspension and a suspension period for each user infraction threshold of the plurality of user infraction thresholds. 19. The one or more NTCRM of claim 18 , wherein execution of the instructions is operable to cause the computing system to: for each user of the one or more users determined to have met a user infraction threshold of the plurality of user infraction thresholds, generate the records to include a suspension value and a user that met the determined user infraction threshold, the suspension value indicating the determined user infraction threshold and a suspension period corresponding to the determined user infraction threshold.

Assignees

Inventors

Classifications

  • Policy-based network configuration management · CPC title

  • Configuration of virtualised networks or elements, e.g. virtualised network function or OpenFlow elements · CPC title

  • wherein the managed service relates to distributed or central networked applications · CPC title

  • Network utilisation, e.g. volume of load or congestion level · CPC title

  • using third party service providers · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11025513B2 cover?
Systems, methods, and computer-readable media for providing a Policy Enforcement as a Service (PEaaS) are described. A processor may, in response to identification of a suspension of user(s) for one of one or more services, generate a suspension value indicative of the suspension and transmit the suspension value to a corresponding one of third party platforms of the service(s), respectively. T…
Who is the assignee on this patent?
Salesforce Com Inc
What technology area does this patent fall under?
Primary CPC classification H04L41/5096. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 01 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).