IP Library Granted Patent US 10,044,764
Granted Patent B2
US 10,044,764 · App. 14/980,009 · Granted Aug 7, 2018

Context-aware delegation engine

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,044,764
App. No.
14/980,009
Granted
Aug 7, 2018
Kind
B2
Abstract

A context-aware delegation engine can enable an account owner to identify granular criteria (or context) that will be used to determine what content a delegate will have access to. The account owner can therefore leverage a wide range of information to dynamically determine whether a delegate will receive access to particular content. The delegation engine can be configured to provide a delegation policy to be evaluated to determine whether a delegate should receive access to particular content. Such a delegation policy can be generated based on input provided by the delegator thereby providing the delegator with fine-grained control over which content will be accessible to a particular delegate. The delegation policy can be structured in accordance with an authorization protocol schema such as XACML, SAML, OAuth 2.0, OpenID, etc. to allow the evaluation of the delegation policy to be performed by a policy decision point in such authorization architectures.

Claims (50)

1. A method for creating and applying a delegation policy comprising:

in a system that includes content storage in which the content is stored, an access control system that the content storage employs to determine whether to grant access to the content, a delegation engine by which delegation policies are created, and a delegation policy store in which the delegation policies are stored;

receiving, by the delegation engine and from a client computing device employed by an account owner, one or more delegation conditions, each delegation condition defining one or more contexts to be used to limit a delegate's access to the account owner's content, the account owner's content including one or both of emails or files;

creating, by the delegation engine, and storing, within the delegation policy store, a delegation policy based on the one or more delegation conditions to thereby enable the delegation policy to be used to govern the delegate's access to the account owner's content;

after the delegation policy has been created and stored in the delegation policy store and in response to a request received from a client computing device employed by a delegate to access the account owner's content that is stored in the content storage, retrieving, by the access control system, the delegation policy from the delegation policy store;

identifying, by the access control system, the one or more defined contexts of each delegation condition in the delegation policy;

sending, by the access control system and to the delegation engine, a request to retrieve the one or more defined contexts;

retrieving, by the delegation engine, the one or more defined contexts from one or more context providers;

sending, by the delegation engine and to the access control system, the one or more retrieved contexts;

evaluating, by the access control system, the account owner's content in view of the one or more retrieved contexts to thereby identify items of the account owner's content that are to be made accessible to the delegate as well as items of the account owner's content that are not to be made accessible to the delegate; and

instructing the content storage to provide, to the client computing device employed by the delegate, only items of the account owner's content that were identified as items that are to be made accessible to the delegate.

2. The method of claim 1 , wherein the one or more contexts comprise a context of the account owner's content.

3. The method of claim 1 , wherein the one or more contexts comprise a context of the delegate.

4. The method of claim 1 , wherein the access control system retrieves the delegation policy in response to a request from the content storage that identifies the account's content.

5. The method of claim 1 , wherein the one or more content providers comprise multiple content providers.

6. The method of claim 1 , wherein the account owner's content comprises emails and the one or more contexts comprise one or more of a source or classification of the emails.

7. The method of claim 1 , wherein the account owner's content comprises files and the one or more contexts comprise a classification of the files.

8. The method of claim 1 , wherein identifying items of the account owner's content that are to be made accessible to the delegate comprises identifying items that match each of the one or more retrieved contexts.

9. The method of claim 1 , wherein identifying items of the account owner's content that are not to be made accessible to the delegate comprises identifying items that do not match at least one of the one or more retrieved contexts.

10. The method of claim 8 , wherein the one or more contexts comprise a business organization structure associated with the items and the delegate.

11. The method of claim 8 , wherein the one or more contexts comprise a role of the delegate.

12. The method of claim 8 , wherein the one or more contexts comprise a trust level of the delegate.

13. The method of claim 1 , wherein the request received from the client computing device employed by the delegate comprises a request to load the account owner's inbox.

14. The method of claim 1 , wherein the delegation policy is structured in accordance with one of XACML, SAML, OAuth 2.0, or OpenID.

15. One or more non-transitory computer storage media storing computer-executable instructions which when executed by one or more processors implement a method for creating and applying a delegation policy comprising:

in a system that includes content storage in which the content is stored, an access control system that the content storage employs to determine whether to grant access to the content, a delegation engine by which delegation policies are created, and a delegation policy store in which the delegation policies are stored;

receiving, by the delegation engine and from a client computing device employed by an account owner, one or more delegation conditions, each delegation condition defining one or more contexts to be used to limit a delegate's access to the account owner's content, the account owner's content including one or both of emails or files;

creating, by the delegation engine, and storing, within the delegation policy store, a delegation policy based on the one or more delegation conditions to thereby enable the delegation policy to be used to govern the delegate's access to the account owner's content;

after the delegation policy has been created and stored in the delegation policy store and in response to a request received from a client computing device employed by a delegate to access the account owner's content that is stored in the content storage, retrieving, by the access control system, the delegation policy from the delegation policy store;

identifying, by the access control system, the one or more defined contexts of each delegation condition in the delegation policy;

sending, by the access control system and to the delegation engine, a request to retrieve the one or more defined contexts;

retrieving, by the delegation engine, the one or more defined contexts from one or more context providers;

sending, by the delegation engine and to the access control system, the one or more retrieved contexts;

evaluating, by the access control system, the account owner's content in view of the one or more retrieved contexts to thereby identify items of the account owner's content that are to be made accessible to the delegate as well as items of the account owner's content that are not to be made accessible to the delegate; and

instructing the content storage to provide, to the client computing device employed by the delegate, only items of the account owner's content that were identified as items that are to be made accessible to the delegate.

16. The computer storage media of claim 15 , wherein the one or more contexts comprise a context of the account owner's content.

17. The computer storage media of claim 15 , wherein the one or more contexts comprise a context of the delegate.

18. The computer storage media of claim 15 , wherein the access control system retrieves the delegation policy in response to a request from the content storage that identifies the account owner's content.

19. The computer storage media of claim 15 , wherein the one or more context providers comprise multiple context providers.

20. A method for creating and applying a delegation policy governing a delegate's access to an inbox, the method comprising:

in a system that includes content storage in which content of an inbox is stored, an access control system that the content storage employs to determine to which items in the inbox a delegate should have access, a delegation engine by which delegation policies are created, and a delegation policy store in which the delegation policies are stored;

receiving, by the delegation engine and from a client computing device employed by an account owner, one or more delegation conditions, each delegation condition defining one or more contexts to be used to limit a delegate's access to the account owner's inbox;

creating, by the delegation engine, and storing, within the delegation policy store, a delegation policy based on the one or more delegation conditions to thereby enable the delegation policy to be used to govern the delegate's access to items in the account owner's inbox, the items including emails;

after the delegation policy has been created and stored in the delegation policy store and in response to a request received from a client computing device employed by a delegate to load the account owner's inbox, retrieving, by the access control system, the delegation policy from the delegation policy store;

identifying, by the access control system, the one or more defined contexts of each delegation condition in the delegation policy;

sending, by the access control system and to the delegation engine, a request to retrieve the one or more defined contexts;

retrieving, by the delegation engine, the one or more defined contexts from one or more context providers;

sending, by the delegation engine and to the access control system, the one or more retrieved contexts;

evaluating, by the access control system, items in the account owner's inbox in view of the one or more retrieved contexts to thereby identify items of the account owner's inbox that are to be made accessible to the delegate as well as items of the account owner's inbox that are not to be made accessible to the delegate; and

instructing the content storage to provide, to the client computing device employed by the delegate, only items of the account owner's inbox that were identified as items that are to be made accessible to the delegate.

Assignments (27)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
CHANGE OF NAME Recorded Sep 13, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 043834/0852 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF REEL 037848 FRAME 0210 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040031/0725 →
RELEASE OF REEL 037848 FRAME 0001 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0152 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 037847 FRAME 0843 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040017/0366 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 037848/0210 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037848/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Feb 18, 2016
From: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 037847/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2016
From: DELL PRODUCTS L.P.
To: DELL SOFTWARE, INC.
Reel/Frame 037491/0723 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2015
From: BRISEBOIS, MITCH; LE RUDULIER, OLIVIER
To: DELL PRODUCTS L.P.
Reel/Frame 037364/0555 →