IP Library Granted Patent US 7,461,066
Granted Patent B2
US 7,461,066 · App. 10/879,812 · Granted Dec 2, 2008

Techniques for sharing persistently stored query results between multiple users

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,461,066
App. No.
10/879,812
Granted
Dec 2, 2008
Kind
B2
Abstract

A method for managing access to query results and, more particularly, for managing access by multiple users to persistently stored query results, whereby at least some of the users may have different access rights. One embodiment provides a method of managing access to a query result obtained upon execution of a query against one or more databases. The method comprises creating security information configured for restricting access to the query result, wherein the query result comprises a dataset obtained from one or more database in response to execution of a query against the one or more databases. The security information is associated with the query result. Access to some or all of the query result is granted to a requesting entity on the basis of the security information and an attribute of the requesting entity.

Claims (32)

1. A method of managing access to query results, comprising:

generating a plurality of persistent data objects, wherein generating comprises, for each persistent data object;

receiving a query result comprising a dataset obtained from one or more databases in response to execution of a query against the one or more databases;

creating security information, wherein the security information is configured for restricting access to the query result;

associating the security information with the query result wherein the security information includes security settings for a plurality of potential requesting entities, the security settings defining access rights of each potential requesting entity to some or all of the query result; and

storing the query result with the associated security information in the respective persistent data object; whereby each of the persistent data objects is detached from the one or more databases from which the respective query result was obtained so that the persistent data objects are independently accessible on the basis of the respective security information contained within the respective persistent data object;

receiving, from a plurality of requesting entities, access requests to the plurality of persistent data objects; and

for each request:

granting access to a given requesting entity to at least a portion of a query result of a given persistent data object on the basis of the respective associated security information and an attribute of the given requesting entity; and

if access cannot be granted on the basis of the respective associated security information and the attribute, initiating a late binding of external security information to the given persistent data object, wherein the external security information is retrieved from a data source external to the given persistent data object.

2. The method of claim 1 , wherein the given requesting entity is a user and the attribute of the requesting entity is one of:

(i) a user name;

(ii) a role of the user; and

(iii) an authorization level of the user.

3. The method of claim 1 , wherein granting access to a given requesting entity to at least a portion of the query result of a given persistent data object on the basis of the respective associated security information and an attribute of the given requesting entity comprises:

hiding one or more portions of the query result from the given requesting entity on the basis of the security information and the attribute of the requesting entity.

4. The method of claim 1 , wherein the query result is defined using an instance of a Java® RowSet class and the persistent data object is defined using an instance of an extension to the Java® RowSet class.

5. The method of claim 1 , wherein the security information defines a link to security settings in the one or more databases, the security settings defining access rights of the potential requesting entities to some or all of the query result.

6. A method of managing access by multiple users to a limited subset of data, comprising:

(a) executing a query against one or more databases;

(b) attaching security information to the limited subset of data, wherein the limited subset of data comprises a dataset obtained from the one or more databases in response to executing the query;

(c) storing the limited subset of data and the attached security information as a persistent data object;

(d) repeating steps (a)-(c) to produce a plurality of persistent data objects, each having respective limited subsets of data and attached security information; whereby each of the persistent data objects is detached from the one or more databases from which the respective limited subset of data was obtained so that the persistent data objects are independently accessible on the basis of the respective security information contained within the respective persistent data object; and

allowing access to the limited subsets of data by the multiple users, whereby the access by a particular user is dependent on one or more attributes of the particular user and the respective security information attached to the respective limited subset of data; wherein when access to a respective limited subset of data of a given persistent data object is prevented on the basis of the one or more attributes of the particular user and the respective security information, initiating a late binding of external security information to the given persistent data object, wherein the external security information is retrieved from a data source external to the given persistent data object.

7. The method of claim 6 , wherein the one or more attributes of the particular user include at least one of:

(i) a user name;

(ii) a role of the user; and

(iii) an authorization level of the user.

8. The method of claim 6 , further comprising:

allowing one or more of the users to modify the respective limited subset of data of the given persistent data object; and

subsequently synchronizing the one or more databases with the modified subset of data.

9. The method of claim 6 , wherein the query is received from a user, and access to the limited subset of data by the user is restricted by modifying the query received from the user to remove one or more results fields from the query based on the security information attached to the subset of data and one or more attributes of the user.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2016
From: MIDWAY TECHNOLOGY COMPANY LLC
To: SERVICENOW, INC.
Reel/Frame 038324/0816 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2016
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: MIDWAY TECHNOLOGY COMPANY LLC
Reel/Frame 037704/0257 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2004
From: DETTINGER, RICHARD D.; DJUGASH, JUDY I.; KOLZ, DANIEL P.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 014858/0446 →