Invention Grant
- Patent Title: Managing multiple security policy representations in a distributed environment
- Patent Title (中): 在分布式环境中管理多个安全策略表示
-
Application No.: US13654111Application Date: 2012-10-17
-
Publication No.: US09083749B1Publication Date: 2015-07-14
- Inventor: Gregory Branchek Roth , Kevin Ross O'Neill , Brian Irl Pratt
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Hogan Lovells US LLP
- Main IPC: G06F21/60
- IPC: G06F21/60 ; H04L29/06

Abstract:
Customers accessing resources or services in a distributed environment can obtain assurance that a provider of that environment will only allow requests to access those resources or services when those requests satisfy at least one security policy associated with the customer. A customer can provide a security policy update that might be written in a different representation (e.g., version) than is supported by all relevant policy evaluation engines across the distributed environment. A component or service such as an access management service can evaluate the representation of the policy, as well as the representations supported by the evaluation engines, and can determine if the features of the policy update are supported by the representations of the engines. If so, the policy update can be translated to express the policy document in the supported representation(s), such that the policy can be utilized without having to update the relevant engines.
Information query