IP Library Granted Patent US 7,890,394
Granted Patent B2
US 7,890,394 · App. 10/778,734 · Granted Feb 15, 2011

Secure access to transaction based information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,890,394
App. No.
10/778,734
Granted
Feb 15, 2011
Kind
B2
Abstract

The present invention includes a system and method for securing information and accessing secured information. In accordance with an embodiment of the present invention, information is secured by associating a context in which the information was generated, for example. To access the secured information, a user provides a point in time and a user identifier, which are used to determine whether that user is authorized to access the information.

Claims (84)

1. A method for securing information within a computing system, the method comprising:

identifying, using an applications server computer, a first entity associated with data representing at least a portion of transactional information;

retrieving, with the applications server computer, a first context associated with the first entity from a context table database, the first context having a first valid time period, the first context identifying a first subset of the at least a portion of transactional information that was generated during the first valid time period;

identifying, with the applications server computer, a second entity having a relationship to the first entity;

retrieving, with the applications server computer, a second context associated with the second entity from the context table database, the second context having a second valid time period, the second valid time period identifying a period of time the relationship is effective;

determining, with the applications server computer, a second subset of the first subset, the second subset identifying the at least a portion of transactional information that was generated during the second valid time period;

authorizing, with the applications server computer, access by the second entity to the second subset of data at any point in time, independent of the first valid time period or second valid time period;

authorizing, with the applications server computer, access by the second entity to the first subset of data during the second valid time period; and

denying, with the applications server computer, access to portions of the first subset of data that are not included in the second subset of data during periods outside of the second valid time period.

2. The method of claim 1 further comprising denying access to another subset of data generated other than during the relationship.

3. The method of claim 1 wherein the relationship is represented by a portion of a hierarchical data structure.

4. The method of claim 1 wherein the first entity and the second entity are identified as having a first role and a second role, respectively.

5. A method for securing information within a computing system, the method comprising:

identifying a first entity associated with data representing at least a portion of transactional information;

retrieving a first context associated with the first entity from a context table database, the first context having a first valid time period, the first context identifying a first subset of the at least a portion of transactional information that was generated during the first valid time period;

identifying a second entity having a relationship to the first entity;

retrieving a second context associated with the second entity from the context table database, the second context having a second valid time period, the second valid time period identifying a period of time the relationship is effective;

determining a second subset of the first subset, the second subset identifying the at least a portion of transactional information that was generated during the second valid time period; and

authorizing access by the second entity to the second subset of data at any point in time, independent of the first valid time period or second valid time period,

wherein the first entity and the second entity are identified as having a first role and a second role, respectively, wherein the relationship is defined at least by the first role and the second role.

6. The method of claim 1 wherein the relationship is such that the second entity receives compensation based upon a transaction performed by the first entity.

7. The method of claim 6 wherein the transaction is a sale.

8. The method of claim 6 wherein the first entity and the second entity are further identified as participants in a compensation plan.

9. A method for accessing a secured computer system by a user, the method comprising:

accepting via a user interface at least one input signal representing a user identifier associated with the user;

accepting via the user interface at least another input signal representing a point in time;

retrieving a first context from a context table database, the first context associated with the user identifier at the point in time;

identifying one or more subsets of data associated with the first context, each subset of data representing at least a portion of transactional information; and

providing to the user the one or more subsets of data at another point in time unrelated to the point in time.

10. The method of claim 9 wherein the one or more subsets of data are associated with a period of time including the point in time.

11. The method of claim 10 wherein the another point in time is outside the period of time.

12. The method of claim 9 wherein the transactional information includes information generated from a sale.

13. The method of claim 9 further comprising:

identifying one or more other subsets of data associated with neither the point in time nor the user identifier; and

denying access to one or more other subsets of data.

14. The method of claim 9 wherein identifying one or more subsets of data comprises:

associating an entity context to the portion of the transactional information;

associating a user context to the entity context; and

selecting the one or more subsets of data associated with the user context and the point in time.

15. The method of claim 9 wherein the entity context is defined in part by a first entity characteristic, which is an association to a first node of a hierarchical tree data structure.

16. The method of claim 15 wherein the first node is a child node.

17. The method of claim 15 wherein the context is further defined by a second entity characteristic, which is a name of a first person recognized for transacting the sale.

18. The method of claim 17 wherein the context is further defined by a third entity characteristic, which is a compensation plan identifier for determining the distribution of proceeds from the transaction.

19. The method of claim 14 wherein the user context is defined in part by a first user characteristic, which is an association to a second node of a hierarchical tree data structure.

20. The method of claim 19 wherein the second node is a parent node, where the parent node is authorized to access transactional information relating to the child node.

21. The method of claim 19 wherein the context is further defined by a second user characteristic, which is a name of a second person associated with the user identifier.

22. The method of claim 21 wherein the context is further defined by a third user characteristic, which is the compensation plan identifier for determining an amount of proceeds received from the transaction.

23. The method of claim 9 wherein the user interface is a graphical user interface.

24. The method of claim 23 wherein providing to the user the one or more subsets of data further comprises:

displaying a graphical representation of a hierarchical tree data structure to the user, the hierarchical tree data structure including a number of interrelated nodes including at least one parent node and at least one child node related to the one parent node;

selecting at the another point in time the one parent node for displaying further additional nodes not displayed with the graphical representation;

displaying the additional nodes if the user is authorized to access the one child node during a period of time including the point in time; and

denying display of the additional nodes if the user is not authorized to access the one child node during another period of time excluding the point in time.

25. A system for securing information comprising:

means for identifying a first entity associated with data representing at least a portion of transactional information;

means for retrieving a first context associated with the first entity from a context table database, the first context having a first valid time period, the first context identifying a first subset of the at least a portion of transactional information that was generated during the first valid time period;

means for identifying a second entity having a relationship to the first entity;

means for retrieving a second context associated with the second entity from the context table database, the second context having a second valid time period, the second valid time period identifying a period of time the relationship is effective;

means for determining a second subset of the first subset, the second subset identifying the at least a portion of transactional information that was generated during the second valid time period; and

means for authorizing access by the second entity to the second subset of data at any point in time, independent of the first valid time period or second valid time period.

26. An apparatus for securing information comprising:

a server system configured for identifying a first entity associated with data representing at least a portion of transactional information;

the server system further configured for retrieving a first context associated with the first entity from a context table database, the first context having a first valid time period, the first context identifying a first subset of the at least a portion of transactional information that was generated during the first valid time period;

the server system further configured for identifying a second entity having a relationship to the first entity;

the server system further configured for retrieving a second context associated with the second entity from the context table database, the second context having a second valid time period, the second valid time period identifying a period of time the relationship is effective;

the server system further configured for determining a second subset of the first subset, the second subset identifying the at least a portion of transactional information that was generated during the second valid time period; and

the server system further configured for authorizing access by the second entity to the second subset of data at any point in time, independent of the first valid time period or second valid time period;

the server system further configured for authorizing access by the second entity to the first subset of data during the second valid time period; and

the server system further configured for denying access to portions of the first subset of data that are not included in the second subset of data during periods outside of the second valid time period.

27. A non-transitory computer readable medium containing programming code which when executed by a computing system causes the computing system to:

identify a first entity associated with data representing at least a portion of transactional information;

retrieve a first context associated with the first entity from a context table database, the first context having a first valid time period, the first context identifying a first subset of the at least a portion of transactional information that was generated during the first valid time period;

identify a second entity having a relationship to the first entity;

retrieve a second context associated with the second entity from the context table database, the second context having a second valid time period, the second valid time period identifying a period of time the relationship is effective;

determine a second subset of the first subset, the second subset identifying the at least a portion of transactional information that was generated during the second valid time period; and

authorize access by the second entity to the second subset of data at any point in time, independent of the first valid time period or second valid time period;

authorize access by the second entity to the first subset of data during the second valid time period; and

deny access to portions of the first subset of data that are not included in the second subset of data during periods outside of the second valid time period.

28. A non-transitory computer readable medium containing programming code which when executed by a computing system causes the computing system to:

accept via a user interface at least one input signal representing a user identifier associated with the user;

accept via a user interface at least another input signal representing a point in time;

identify one or more subsets of data associated with both the point in time and the user identifier, each subset of data representing at least a portion of transactional information; and

provide to the user the one or more subsets of data at another point in time unrelated to the one or more subsets; and

deny the user access to transactional information that is not associated with the user identifier or the point in time.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2006
From: PEOPLESOFT, INC.; J.D. EDWARDS & COMPANY, LLC
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 017730/0927 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2005
From: PEOPLESOFT, INC.; J.D. EDWARDS & COMPANY, LLC
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 016950/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2004
From: SANDFORD, GREGORY; SOLBERG, ERIC L.
To: PEOPLESOFT, INC.
Reel/Frame 014991/0689 →