IP Library Granted Patent US 11,281,667
Granted Patent B2
US 11,281,667 · App. 14/980,525 · Granted Mar 22, 2022

Distributed storage and distributed processing policy enforcement utilizing virtual identifiers

Inventors: Pratik Verma (Hopkins, MN); Rakesh Khanduja (Hopkins, MN); Prerna Verma (Hopkins, MN)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F16/24534G06F16/245G06F16/248G06F16/25
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,281,667
App. No.
14/980,525
Granted
Mar 22, 2022
Kind
B2
Abstract

A non-transitory computer readable storage medium has instructions executed by a processor to assign virtual identifiers to blocks of a file that contain identical information in different data sources. A distributed storage and distributed processing query statement is received. Real name attributes of the query statement are equated with selected virtual identifiers. Access control policies are applied to the selected virtual identifiers to obtain policy results. The policy results are applied to the real name attributes of the query statement to obtain query results.

Claims (22)

1. A non-transitory computer readable storage medium with instructions executed by a processor to:

assign virtual identifiers to blocks of a file that contain identical information in different data sources of a distributed storage and distributed processing system;

receive a query statement, wherein the query statement is a distributed storage and distributed processing query statement for processing by the distributed storage and distributed processing system;

equate real name attributes of the query statement with selected virtual identifiers that manifest a common concept that is expressed using different real terms in different data sources of the distributed storage and distributed processing system, such that each virtual identifier operates as a proxy for disparate expressions used in the different data sources;

apply access control policies to the selected virtual identifiers to obtain policy results in a virtual domain; and

apply the policy results from the virtual domain to the real name attributes of the query statement to obtain query results.

2. The non-transitory computer readable storage medium of claim 1 wherein the access control policies specify access control at a user level.

3. The non-transitory computer readable storage medium of claim 1 wherein the access control policies specify access control at a user group level.

4. The non-transitory computer readable storage medium of claim 1 wherein the virtual identifiers have associated table mappings.

5. The non-transitory computer readable storage medium of claim 1 wherein the virtual identifiers have associated column mappings.

6. The non-transitory computer readable storage medium of claim 1 further comprising instructions executed by the processor to enter audit entries in a policy enforcement log for each policy enforcement action.

7. A non-transitory computer readable storage medium with instructions executed by a processor to:

assign virtual identifiers to columns of a table that contain identical information in different databases of a distributed storage and distributed processing system;

receive a query statement, wherein the query statement is a distributed storage and distributed processing query statement for processing by the distributed storage and distributed processing system;

equate real name attributes of the query statement with selected virtual identifiers that manifest a common concept that is expressed using different real terms in different data sources of the distributed storage and distributed processing system, such that each virtual identifier operates as a proxy for disparate expressions used in the different data sources;

apply access control policies to the selected virtual identifiers to obtain policy results in a virtual domain; and

apply the policy results from the virtual domain to the real name attributes of the query statement to obtain query results.

8. The non-transitory computer readable storage medium of claim 7 wherein the access control policies specify access control at a user level.

9. The non-transitory computer readable storage medium of claim 7 wherein the access control policies specify access control at a user group level.

10. The non-transitory computer readable storage medium of claim 7 wherein the virtual identifiers have associated table mappings.

11. The non-transitory computer readable storage medium of claim 7 wherein the virtual identifiers have associated column mappings.

12. The non-transitory computer readable storage medium of claim 7 further comprising instructions executed by the processor to enter audit entries in a policy enforcement log for each policy enforcement action.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2020
From: BLUETALON, INC.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 053101/0963 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2016
From: VERMA, PRATIK; KHANDUJA, RAKESH; VERMA, PRERNA
To: BLUETALON, INC.
Reel/Frame 037689/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2015
From: VERMA, PRATIK; KHANDUJA, RAKESH; VERMA, PRERNA
To: BLUETALON, INC.
Reel/Frame 037394/0032 →
Continuity (2)
Provisional Application 62101341 · Jan 8, 2015
Related Publication 20160203181A1 · Jul 14, 2016
Cited By (1)
US 12,373,248