IP Library Granted Patent US 7,984,066
Granted Patent B1
US 7,984,066 · App. 11/393,219 · Granted Jul 19, 2011

Mandatory access control list for managed content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,984,066
App. No.
11/393,219
Granted
Jul 19, 2011
Kind
B1
Abstract

Restricting access to managed content to users that are both ( 1 ) members of one or more required groups identified in an ACL associated a content item to which access is requested and ( 2 ) otherwise granted access under the ACL, e.g., by virtue of their individual identity, role, or group membership is disclosed. In some embodiments, an ACL is configured to identify one or more groups as being a “required” group, membership in which is required for a user to be granted access to a content item with which the ACL is associated. If a user is not a member of a required group, the user is denied access (or denied access above a certain level), even if the user is otherwise delegated access rights in the ACL.

Claims (39)

1. A method of controlling access to managed content, comprising:

receiving at a content management system a request associated with a user to access a content item included in a body of managed content;

reading an access control list associated with the content item;

determining at the content management system whether the user is granted an access right based on one or more entries included in the access control list;

determining at the content management system whether the user is a member of an aggregated required group, comprising one of the following:

determining the aggregated required group based on one individual required group if the access control list includes only one individual required group; and

determining the aggregated required group by combining two or more individual required groups using one or more AND operations or OR operations if the access control list includes two or more individual required groups; and

providing access to the user if the user is granted the access right and further is a member of the aggregated required group.

2. The method as recited in claim 1 , wherein the request is received from an application running on a framework associated with the content management system.

3. The method as recited in claim 1 , wherein the determination whether the user is a member of the aggregated required group is made by business logic associated with the content management system.

4. The method as recited in claim 1 , wherein determination whether the user is a member of the aggregated required group is based at least in part on one or more of the following: an individual identity of the user, a security classification or level of the user, a group of which the user is a member, a role associated with the user, a supplemental security classification associated with the user, a session data associated with the user, and a session data associated with the request.

5. The method as recited in claim 1 , wherein the requested access comprises one or more of the following types of access: browse, read, relate, version, write, and delete.

6. A content management system, comprising:

a communication interface configured to receive a request to access a content item included in a body of managed content; and

a processor coupled to the communication interface and configured to:

read an access control list associated with the content item;

determine at the content management system whether the user is granted an access right based on one or more entries included in the access control list;

determine at the content management system whether the user is a member of an aggregated required group, comprising one of the following:

determine the aggregated required group based on one individual required group if the access control list includes only one individual required group; and

determine the aggregated required group by combining two or more individual required groups using one or more AND operations or OR operations if the access control list includes two or more individual required groups; and

provide access to the user if the user is granted the access right and further is a member of the aggregated required group.

7. The system as recited in claim 6 , further comprising a content store configured to store the content item.

8. The system as recited in claim 6 , further comprising a metadata store configured to store the access control list and a linking data associating the access control data with the content item.

9. A computer program product for controlling access to managed content, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions which when executed by a computer cause the computer to perform the steps of

receiving at a content management system a request to access a content item included in a body of managed content;

reading an access control list associated with the content item;

determining at the content management system whether the user is granted an access right based on one or more entries included in the access control list;

determining at the content management system whether the user is a member of an aggregated required group, comprising one of the following:

determining the aggregated required group based on one individual required group if the access control list includes only one individual required group; and

determining the aggregated required group by combining two or more individual required groups using one or more AND operations or OR operations if the access control list includes two or more individual required groups; and

providing access to the user if the user is granted the access right and further is a member of the aggregated required group.

10. The computer program product as recited in claim 9 , wherein determination whether the user is a member of the aggregated required group is based at least in part on one or more of the following: an individual identity of the user, a security classification or level of the user, a group of which the user is a member, a role associated with the user, a supplemental security classification associated with the user, a session data associated with the user, and a session data associated with the request.

11. The method as recited in claim 1 , wherein determining whether the user is a member of the aggregated required group comprises using session data.

12. The system as recited in claim 6 , wherein determining whether the user is a member of the aggregated required group comprises using session data.

13. The computer program product as recited in claim 9 , wherein determining whether the user is a member of the aggregated required group comprises using session data.

14. The system as recited in claim 6 , wherein the request is received from an application running on a framework associated with the content management system.

15. The system as recited in claim 6 , wherein the determination whether the user is a member of the aggregated required group is made by business logic associated with the content management system.

16. The system as recited in claim 6 , wherein determination whether the user is a member of the aggregated required group is based at least in part on one or more of the following: an individual identity of the user, a security classification or level of the user, a group of which the user is a member, a role associated with the user, a supplemental security classification associated with the user, a session data associated with the user, and a session data associated with the request.

17. The system as recited in claim 6 , wherein the requested access comprises one or more of the following types of access: browse, read, relate, version, write, and delete.

Assignments (13)
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 063559/0805) Recorded Jun 21, 2024
From: BARCLAYS BANK PLC
To: OPEN TEXT CORPORATION
Reel/Frame 067807/0069 →
SECURITY INTEREST Recorded Aug 30, 2023
From: OPEN TEXT CORPORATION
To: THE BANK OF NEW YORK MELLON
Reel/Frame 064761/0008 →
SECURITY INTEREST Recorded May 7, 2023
From: OPEN TEXT CORPORATION
To: BARCLAYS BANK PLC
Reel/Frame 063559/0831 →
SECURITY INTEREST Recorded May 7, 2023
From: OPEN TEXT CORPORATION
To: BARCLAYS BANK PLC
Reel/Frame 063559/0839 →
SECURITY INTEREST Recorded May 7, 2023
From: OPEN TEXT CORPORATION
To: BARCLAYS BANK PLC
Reel/Frame 063559/0805 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2017
From: EMC CORPORATION
To: OPEN TEXT CORPORATION
Reel/Frame 041172/0706 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: EMC CORPORATION
To: OPEN TEXT CORPORATION
Reel/Frame 041579/0133 →
PATENT RELEASE (REEL:40134/FRAME:0001) Recorded Jan 23, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: EMC CORPORATION, AS GRANTOR
Reel/Frame 041073/0136 →
RELEASE OF SECURITY INTEREST Recorded Jan 23, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC CORPORATION
Reel/Frame 041073/0443 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 30, 2006
From: KILDAY, ROGER W.; FAROOQ, AAMIR
To: EMC CORPORATION
Reel/Frame 017741/0816 →