IP Library Granted Patent US 8,086,637
Granted Patent B1
US 8,086,637 · App. 11/644,340 · Granted Dec 27, 2011

Access control for business process data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,086,637
App. No.
11/644,340
Granted
Dec 27, 2011
Kind
B1
Abstract

Controlling access to business process data is disclosed. An instance of a business process object configured to contain business process data is created. An access control list that is determined based at least in part on a business process with which the business process data is associated is associated with the business process object instance.

Claims (32)

1. A method for controlling access to business process data, comprising:

specifying a first business process object to hold business process data of a first business process, associating the first business process object with a first access control list for controlling access of first business process object by the first business process, instantiating an instance of the first business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the first business process;

associating with the first instance of the business process object an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the first instance of the first business process object with the first access control list;

specifying the first business process object to hold business process data of a second business process, associating the first business object with a second access control list for controlling access of the first business process object by the second business process, instantiating an instance of the second business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the second business process; and

associating with the second instance of the first business object with an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the second instance of the first business process object with the second access control list;

wherein the first business process and the second business process is each defined by an unique set of steps for manipulating data stored in one or more business process objects;

wherein the access control list indicates a type of access that an application and users will be allowed to have to the business process object.

2. A method as in claim 1 , further comprising storing the business process object instances in a repository configured to allow access to the stored business process object instances according to the associated access control list.

3. A method as in claim 2 , wherein the repository is associated with a content management system.

4. A method as in claim 1 , wherein access includes a permission including one or more of the following: none, browse, read, relate, version, write, change location, change owner, change state, change permission, delete, execute, annotate, or approve.

5. A method as in claim 1 , wherein access includes a restriction including one or more of the following: none, browse, read, relate, version, write, change location, change owner, change state, change permission, delete, execute, annotate, or approve.

6. A method as in claim 1 , wherein access specifies a permission or a restriction for an application, a user, or a group of users.

7. A method as in claim 1 , wherein access specifies that an accessing party be a specific application, a specific user, or a specific group of users.

8. A method as in claim 1 , wherein access specifies that access is restricted if an accessing party is a specific application, a specific user, or a specific group of users.

9. A computer program product for controlling access to business process data, the computer program product being embodied in a non-transitory computer readable medium and comprising computer instructions for:

specifying a first business process object to hold business process data of a first business process, associating the first business process object with a first access control list for controlling access of first business process object by the first business process, instantiating an instance of the first business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the first business process;

associating with the first instance of the business process object an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the first instance of the first business process object with the first access control list;

specifying the first business process object to hold business process data of a second business process, associating the first business object with a second access control list for controlling access of the first business process object by the second business process, instantiating an instance of the second business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the second business process; and

associating with the second instance of the first business object with an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the second instance of the first business process object with the second access control list;

wherein the first business process and the second business process is each defined by an unique set of steps for manipulating data stored in one or more business process objects;

wherein the access control list indicates a type of access that an application and users will be allowed to have to the business process object.

10. A computer program product as in claim 9 , further comprising computer instructions for storing the business process object instances in a repository configured to allow access to the stored business process object instance according to the associated access control list.

11. A computer program product as in claim 10 , wherein the repository is associated with a content management system.

12. A system for controlling access to business process data, comprising:

a processor; and

a memory coupled with the processor, wherein the memory is configured to provide the processor with instructions which when executed cause the processor to:

specify a first business process object to hold business process data of a first business process, associating the first business process object with a first access control list for controlling access of first business process object by the first business process, instantiating an instance of the first business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the first business process;

associate with the first instance of the business process object an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the first instance of the first business process object with the first access control list;

specify the first business process object to hold business process data of a second business process, associating the first business object with a second access control list for controlling access of the first business process object by the second business process, instantiating an instance of the second business process, including creating using a processor an instance of the first business process object configured to contain business process data that is to be manipulated by the instance of the second business process; and

associate with the second instance of the first business object with an access control list that is determined based at least in part on the business process accessing the first business process object, including associating the second instance of the first business process object with the second access control list;

wherein the first business process and the second business process is each defined by an unique set of steps for manipulating data stored in one or more business process objects;

wherein the access control list indicates a type of access that an application and users will be allowed to have to the business process object.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2017
From: EMC CORPORATION
To: OPEN TEXT CORPORATION
Reel/Frame 041579/0133 →
RELEASE OF SECURITY INTEREST Recorded Jan 23, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC CORPORATION
Reel/Frame 041073/0443 →
PATENT RELEASE (REEL:40134/FRAME:0001) Recorded Jan 23, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: EMC CORPORATION, AS GRANTOR
Reel/Frame 041073/0136 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2006
From: TSAI, KENWOOD; RAWAT, HARISH; TANG, XIAOTING; SHAHIDI, PAYAM
To: EMC CORPORATION
Reel/Frame 018743/0585 →