IP Library Patent Application 12609618
Patent Application
App. No. 12/609,618

DECLARATIVE MODEL SECURITY PATTERN

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/609,618
Abstract

The present invention extends to methods, systems, and computer program products for a declarative model security pattern for use in a database. Declarative language code can include a declared access control predicate and a separately declared data structure definition bound to the access control predicate. A portion of the database is instantiated from the declarative language code. The instantiated portion of the database includes one or more tables and a view of the one or more tables. A database management system enforces the access control predicate by dynamically calculating a value for the access control predicate and using the dynamically calculated value to define what operations may be performed on data in the one or more tables via the view.

Claims (44)

1 . At a computer system including one or more processors and system memory, a method comprising:

translating declarative language code into one or more statements, the declarative language code including:

a declared access control predicate; and

a declared data structure definition bound to the access control predicate, the access control predicate declared separately from the data structure definition; and

instantiating at least a portion of a database by executing the one or more statements, the database being hosted by a database management system, the at least a portion of a database including:

one or more tables; and

a view of the one or more tables, the database management system configured to enforce the access control predicate by dynamically calculating a value for the access control predicate and using the dynamically calculated value to define what operations may be performed on data from the one or more tables via the view.

2 . The method as in claim 1 , wherein the dynamically calculated value defines, at a row level, what operations may be performed on data from the one or more tables via the view.

3 . The method as in claim 1 , wherein the dynamically calculated value is based on one or more claims associated with a session with the database management system.

4 . The method as in claim 3 , wherein the database management system is configured to, in response to the session requesting access to the view, dynamically calculate the value for the access control predicate.

5 . The method as in claim 1 , wherein the dynamically calculated value defines, at a row level, what operations may be performed on data from the one or more tables via the view; and

wherein the dynamically calculated value is based on one or more claims associated with a session with the database management system.

6 . The method as in claim 5 , wherein the database management system is configured to, in response to the session requesting access to the view, dynamically calculate the value for the access control predicate.

7 . The method as in claim 1 , wherein the declarative language code is written in the M language.

8 . A computing system comprising:

one or more processors;

system memory; and

one or more computer storage media having stored thereon computer-executable instructions for performing a method, the method including:

dynamically calculating a value for an access control predicate; and

using the dynamically calculated value to define what operations may be performed on data from one or more tables of a database via a view, the view and the one or more tables of the database having been instantiated by an execution of one or more statements translated from declarative language code, the declarative language code including:

a declared access control predicate; and

a declared data structure definition bound to the access control predicate, the access control predicate declared separately from the data structure definition.

9 . The system as in claim 8 , wherein the dynamically calculated value defines, at a row level, what operations may be performed on data from the one or more tables via the view.

10 . The system as in claim 8 , wherein the dynamically calculated value is based on one or more claims associated with a session with a database management system that hosts the database.

11 . The system as in claim 10 , wherein the database management system is configured to, in response to the session requesting access to the view, dynamically calculate the value for the access control predicate.

12 . The system as in claim 8 , wherein the dynamically calculated value defines, at a row level, what operations may be performed on data from the one or more tables via the view; and

wherein the dynamically calculated value is based on one or more claims associated with a session with a database management system that hosts the database.

13 . The system as in claim 12 , wherein the database management system is configured to, in response to the session requesting access to the view, dynamically calculate the value for the access control predicate.

14 . At a computer system including one or more processors and system memory, a method comprising:

translating declarative language code into one or more SQL statements, the declarative language code including:

a declared access control predicate;

a first declared data structure definition bound to the access control predicate, the access control predicate declared separately from the first data structure definition; and

a second declared data structure definition bound to the access control predicate, the access control predicate declared separately from the second data structure definition; and

instantiating at least a portion of a database by executing the one or more SQL statements, the database being hosted by a database management system, the at least a portion of a database including:

a plurality of tables;

a first view of at least one of the tables; and

a second view of at least one of the tables, the database management system configured to enforce the access control predicate by dynamically calculating a value for the access control predicate and using the dynamically calculated value to define what operations may be performed on data from at least one of the tables via the first view and to define what operations may be performed on data from at least one of the tables via the second view.

15 . The method as in claim 14 , wherein the dynamically calculated value defines, at a row level, operations may be performed on data from at least one of the tables via the first and second views.

16 . The method as in claim 14 , wherein the dynamically calculated value is based on one or more claims associated with a session with the database management system.

17 . The method as in claim 16 , wherein the database management system is configured to, in response to the session requesting access to at least one of the first view or the second view, dynamically calculate the value for the access control predicate.

18 . The method as in claim 14 , wherein the dynamically calculated value defines, at a row level, operations may be performed on data from at least one of the tables via the first and second views; and

wherein the dynamically calculated value is based on one or more claims associated with a session with the database management system.

19 . The method as in claim 18 , wherein the database management system is configured to, in response to the session requesting access to at least one of the first view or the second view, dynamically calculate the value for the access control predicate.

20 . The method as in claim 14 , wherein the declarative language code is written in the M language.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2015
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034766/0509 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 17, 2010
From: BAKER, JAMES PATRICK SEYMOUR; BLOESCH, ANTHONY C.; SAKHNOV, IGOR; SHORT, KEITH W.
To: MICROSOFT CORPORATION
Reel/Frame 024394/0112 →