Patents by Inventor Mark Ryland
Mark Ryland has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12634346Abstract: Techniques for per-customer transport layer security (TLS) controls in a multi-tenant provider network are described. An Internet Protocol (IP) packet is received that includes a request to establish a TLS session with an application programming interface (API) endpoint of a multi-tenant provider network, the request includes an indication of supported TLS parameters. An indication of permitted TLS parameters is obtained from a customer-defined TLS policy identified based at least in part on an indication of a customer included in the IP packet. The supported TLS parameters are determined to match the permitted TLS parameters, and the requested TLS session is established.Type: GrantFiled: February 8, 2023Date of Patent: May 19, 2026Assignee: Amazon Technologies, Inc.Inventors: Mark Ryland, Christoph Saalfeld
-
Patent number: 12177185Abstract: Techniques are described for enabling users of a cloud provider network to create policies used to control the use of temporary security credentials by computing resources other than a computing resource to which the credentials were issued. An identity and access management service encodes, into temporary security credentials, information about the virtual private network to which the credentials are issued. When a computing resource subsequently issues requests to perform actions and uses the temporary security credentials to sign the request, the cloud provider network further adds, to the network traffic, information associated with the virtual private network from which the request originates. A user can then create a policy with a statement indicating that request are to be permitted only if, e.g., the identity of the virtual private network as encoded in the temporary security credentials matches the identity of the virtual private network identified by the information included in the request.Type: GrantFiled: September 30, 2022Date of Patent: December 24, 2024Assignee: Amazon Technologies, Inc.Inventors: Mark Ryland, Joshua Benjamin Levinson
-
Patent number: 11914696Abstract: Quorum-based access control management may be implemented. Quorum controls may be created for determining whether to perform or deny access control operations to perform privileged tasks. When an access control operation is received, approval of the operation may be requested from members for the quorum control. If a policy for the quorum control is satisfied by approval responses, then approval to perform the access control operation may be provided.Type: GrantFiled: September 30, 2020Date of Patent: February 27, 2024Assignee: Amazon Technologies, Inc.Inventors: Dean H Saxe, Conor P Cahill, Dennis Tighe, Jonathan Robert Hurd, Brian Mead Tyler, Cristian Marius Ilac, Mark Ryland
-
Patent number: 10121026Abstract: A secure containment enclosure such as an equipment rack is disclosed that includes an electronic locking system. The electronic locking system locks and, upon receipt of a valid credential to a credential input device, unlocks an access door to the secure containment enclosure. The electronic locking system locks the access door during normal operation, and is prevented from unlocking the access door during normal operation and for a predetermined period of time after the secure containment enclosure is powered off to ensure that all data on electronic devices in the secure containment enclosure is erased. Other security features include storage encryption, network encryption, preventing administrative logon access to customers' compute nodes, and dedicated instances in which only virtual machines from specified customer accounts can be located on the same electronic device.Type: GrantFiled: December 31, 2015Date of Patent: November 6, 2018Assignee: Amazon Technologies, Inc.Inventor: Mark Ryland
-
Patent number: 9817703Abstract: A compute cluster including multiple compute nodes may implement distributed lock management using conditional updates to a distributed key value data store. It may be determined, at one or more compute nodes of a compute cluster, that particular lock is available based on a respective lock entry for the particular lock maintained in a lock manager table at a key value data store. The key value data store may be configured to perform conditional write requests for updates to data store at the key value, and may maintain data according to a distributed durability scheme. Compute nodes that determine that a lock is available may send a conditional write request to the key value data store in order to acquire the particular lock. The compute node that acquired the particular lock may be identified based on the successfully completed conditional write request to the respective lock entry.Type: GrantFiled: December 4, 2013Date of Patent: November 14, 2017Assignee: Amazon Technologies, Inc.Inventors: Mark Ryland, Alexander Slutsker, David Craig Yanacek
-
Patent number: 9438506Abstract: Methods and apparatus for providing identity and access management-based access control for connections between entities in virtual (overlay) network environments. At the encapsulation layer of the overlay network, an out-of-band connection creation process may be leveraged to enforce access control and thus allow or deny overlay network connections between sources and targets according to policies. For example, resources may be given identities, identified resources may assume roles, and policies may be defined for the roles that include permissions regarding establishing connections to other resources. When a given resource (the source) attempts to establish a connection to another resource (the target), role(s) may be determined, policies for the role(s) may be identified, and permission(s) checked to determine if a connection from the source to the target over the overlay network is to be allowed or denied.Type: GrantFiled: December 11, 2013Date of Patent: September 6, 2016Assignee: Amazon Technologies, Inc.Inventor: Mark Ryland
-
Publication number: 20150163158Abstract: Methods and apparatus for providing identity and access management-based access control for connections between entities in virtual (overlay) network environments. At the encapsulation layer of the overlay network, an out-of-band connection creation process may be leveraged to enforce access control and thus allow or deny overlay network connections between sources and targets according to policies. For example, resources may be given identities, identified resources may assume roles, and policies may be defined for the roles that include permissions regarding establishing connections to other resources. When a given resource (the source) attempts to establish a connection to another resource (the target), role(s) may be determined, policies for the role(s) may be identified, and permission(s) checked to determine if a connection from the source to the target over the overlay network is to be allowed or denied.Type: ApplicationFiled: December 11, 2013Publication date: June 11, 2015Applicant: Amazon Technologies, Inc.Inventor: MARK RYLAND
-
Patent number: 8505085Abstract: A flexible authentication system is described herein that fluidly switches between a federated authentication model and a local short-lived token model that does not require sophisticated authentication infrastructure at the relying party site. Upon detecting an event that causes the identity provider to be unavailable for authentication, the relying party switches to a temporary token model. The system generates a bearer token or challenge associated with the user's identity and (optionally) associated with time data that limits the period during which the token is valid. The relying party communicates the short-lived token to the user using contact information associated with the user and already stored by the relying party. Upon receiving the short-lived token, the user provides the short-lived token to the relying party, and the relying party processes the token to validate the user's identity and then allows the user to access the relying party's online services.Type: GrantFiled: April 8, 2011Date of Patent: August 6, 2013Assignee: Microsoft CorporationInventors: Angus P. D. Logan, Mark Ryland, Ariel Gordon, Vittorio Bertocci
-
Publication number: 20120260322Abstract: A flexible authentication system is described herein that fluidly switches between a federated authentication model and a local short-lived token model that does not require sophisticated authentication infrastructure at the relying party site. Upon detecting an event that causes the identity provider to be unavailable for authentication, the relying party switches to a temporary token model. The system generates a bearer token or challenge associated with the user's identity and (optionally) associated with time data that limits the period during which the token is valid. The relying party communicates the short-lived token to the user using contact information associated with the user and already stored by the relying party. Upon receiving the short-lived token, the user provides the short-lived token to the relying party, and the relying party processes the token to validate the user's identity and then allows the user to access the relying party's online services.Type: ApplicationFiled: April 8, 2011Publication date: October 11, 2012Applicant: Microsoft CorporationInventors: Angus P.D. Logan, Mark Ryland, Ariel Gordon, Vittorio Bertocci