IP Library Granted Patent US 7,590,630
Granted Patent B2
US 7,590,630 · App. 10/736,001 · Granted Sep 15, 2009

Managing electronic information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,590,630
App. No.
10/736,001
Granted
Sep 15, 2009
Kind
B2
Abstract

Electronic information management includes techniques for developing and applying database security. In certain implementations, database access statements issued for applications in use are analyzed. Analyzing issued database access statements may include capturing the database access statements, normalizing the database access statements, and eliminating redundancies from the database access statements. A standardized set of issued database access statements may result from the analysis procedure. From the analyzed database access statements, the items accessed and types of access may be determined for an application, and a set of permissions may be determined from the determined items accessed and types of access for the application. A role associated with the application may be developed based on the permissions for the application. The role may be used to allow a user database access when associated with the application.

Claims (64)

1. A method implemented by a computer, the method comprising:

analyzing a plurality of database access statements stored in a computer memory that were issued for an application during the application's use to determine previous accessed items and types of access for the application; and

developing a role for the application based on the previous accessed items and types of access for the application, wherein when the application is in use by a user, the developed role for the application allows the user database access.

2. The method of claim 1 wherein analyzing the issued database access statements comprises:

capturing the plurality of database access statements;

normalizing the captured database access statements; and

eliminating redundancies in the normalized database access statements.

3. The method of claim 2 wherein the database access statements comprise Structured Query Language (SQL) queries.

4. The method of claim 1 wherein the previous accessed items and types of access include objects accessed and operations performed on the objects.

5. The method of claim 1 wherein developing a role comprises determining permissions for the application based on the previous accessed items and types of access.

6. The method of claim 1 further comprising determining which of a set of users are authorized to use the application.

7. The method of claim 1 further comprising:

detecting a user request to establish an application session;

finding the role for the application; and

assigning the role to a user.

8. The method of claim 7 wherein detecting a user request to establish an application session comprises determining if a user is authorized to use the application.

9. The method of claim 7 further comprising:

detecting an end of the application session; and

if an end of the application session is detected, disabling the assigned role for the user.

10. An article of manufacture comprising:

a machine-readable storage medium storing instructions configured to cause one or more machines to perform operations comprising:

analyzing a plurality of database access statements that were issued for an application during the application's use to determine previous accessed items and types of access for the application; and

developing a role for the application based on the previous accessed items and types of access for the application, wherein when the application is in use by a user, the developed role for the application allows the user database access.

11. The article of claim 10 , wherein analyzing the issued database access statements comprises:

determining whether the plurality of database access statements have been captured;

normalizing the captured database access statements; and

eliminating redundancies in the normalized database access statements.

12. The article of claim 10 wherein the previous accessed items and types of access include objects accessed and operations performed on the objects.

13. The article of claim 10 wherein developing a role comprises determining permissions for the application based on the previous accessed items and types of access.

14. The article of claim 10 wherein the instructions are further configured to cause one or more machines to perform operations comprising determining which of a set of users are authorized to use the application.

15. The article of claim 10 wherein the instructions are further configured to cause one or more machines to perform operations comprising:

determining whether a user request to establish an application session has been detected; finding the role for the application; and

assigning the role to a user.

16. The article of claim 15 wherein determining whether a user request to establish an application session has been detected comprises determining if a user is authorized to use the application.

17. The article of claim 15 wherein the instructions are further configured to cause one or more machines to perform operations comprising:

detecting an end of the application session; and if an end of the application session is detected, disabling the assigned role for the user.

18. A database security analyzer comprising:

a communication interface configured to receive a plurality of database access statements that were issued for an application during the application's use;

a memory configured to store the issued database access statements; and

a processor configured to develop a role for the application based on the previously issued database access statements for the application, wherein when the application is in use by a user, the developed role for the application allows a user database access.

19. The analyzer of claim 18 wherein developing a role comprises:

analyzing the database access statements to determine previous accessed items and types of access for the application;

determining permissions for the application based on the previous accessed items and types of access for the application; and

developing a role associated with the application based on the determined permissions.

20. The analyzer of claim 19 wherein the previous accessed items and types of access include objects accessed and operations performed on the objects.

21. The analyzer of claim 18 wherein developing a role comprises:

determining whether the received database access statements have been captured;

normalizing the captured database access statements; and

eliminating redundancies in the normalized database access statements.

22. The analyzer of claim 18 wherein the memory comprises instructions, and the processor operates according to the instructions.

23. A method implemented by a computer comprising:

capturing a plurality of database access statements that were issued for one or more applications during the application's use, wherein the database access statements comprise Structured Query Language (SQL) queries;

normalizing the captured database access statements;

eliminating redundancies in the normalized database access statements;

analyzing the normalized database access statements stored in a computer memory to determine previous accessed items and types of access for an application, wherein the previous accessed items and types of access include objects accessed and operations performed on the objects;

determining permissions for the application based on the previous accessed items and types of access for the application;

developing a role for the application based on the determined permissions;

determining which of a set of users are authorized to use the application;

detecting a user request to establish a session of the application;

determining if the user is authorized to use the application;

if the user is authorized to use the application, finding the role for the application;

assigning the role to the user;

detecting an end of the application session; and

if an end of the application session is detected, disabling the assigned role for the user.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2009
From: ELECTRONIC DATA SYSTEMS, LLC
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 022449/0267 →
CHANGE OF NAME Recorded Mar 24, 2009
From: ELECTRONIC DATA SYSTEMS CORPORATION
To: ELECTRONIC DATA SYSTEMS, LLC
Reel/Frame 022460/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2003
From: RICHTER, JOHN D.
To: ELECTRONIC DATA SYSTEMS CORPORATION
Reel/Frame 014826/0279 →