Contribution signatures for tagging

    公开(公告)号:US10536277B1

    公开(公告)日:2020-01-14

    申请号:US14979308

    申请日:2015-12-22

    IPC分类号: H04L29/06 H04L9/32 G06F12/14

    摘要: A request to add tags (e.g., labels, key-value pairs, or metadata) to resources can be digitally signed by the entity making the request, such that the source can be verified and an authorization determination made for each tag. For a request involving multiple services (or entities) that can each add tags, any tag added by a service can be included in the request and digitally signed by that service. Each service processing the request can also digitally sign the request before forwarding, so that each service signs a version of the request, which includes elements signed by other services earlier in the request chain. When the request is received to a tagging service, the service ensures that every tag was digitally signed by the appropriate authorized entity or service, and validates the signatures to ensure that no data was modified or omitted, before adding the tags to the designated resource(s).

    PROVISIONAL COMPUTING RESOURCE POLICY EVALUATION

    公开(公告)号:US20190245862A1

    公开(公告)日:2019-08-08

    申请号:US16384866

    申请日:2019-04-15

    IPC分类号: H04L29/06

    CPC分类号: H04L63/102 H04L63/20

    摘要: A policy management service receives a request to evaluate a provisional policy to determine the impact of implementation of the provisional policy. The policy management service evaluates an active policy against a request to access a computing resource to determine an authorization decision. The policy management service then evaluates the provisional policy against the request to access the computing resource to generate an evaluation of the provisional policy. The policy management service provides the evaluation and the authorization decision in response to the request to evaluate the provisional policy.

    LARGE-SCALE AUTHORIZATION DATA COLLECTION AND AGGREGATION

    公开(公告)号:US20190073488A1

    公开(公告)日:2019-03-07

    申请号:US16056322

    申请日:2018-08-06

    IPC分类号: G06F21/62 G06Q10/06 G06F17/30

    摘要: A record of usage data is obtained, with the record sampled according to a sampling rate from a set of usage data records, with the record specifying a request to access a resource of a computing resource service provider, with the request indicating a set of permissions, and with the sampling rate being based at least in part on a criterion associated with the request. The record is aggregated, based at least in part on a permission of the set of permissions, with at least another record sampled according to the sampling rate from the set of usage data records to produce a set of aggregated usage records and at least a portion of the set of aggregated usage records is provided.

    Large-scale authorization data collection and aggregation

    公开(公告)号:US10043030B1

    公开(公告)日:2018-08-07

    申请号:US14615347

    申请日:2015-02-05

    IPC分类号: G06F17/30 G06F21/62 G06Q10/06

    摘要: Techniques for large-scale authorization data collection and aggregation are disclosed herein. An authorization data service may first receive a set of usage data records, may next aggregate the set of usage data records to reduce the number of usage data records, may next store the aggregated set of usage data records in a usage data repository, and may next provide subsets of the aggregated set of usage data records in response to an application processing request to inform policy decisions associated with a computer system.