IP Library Granted Patent US 10,027,551
Granted Patent B1
US 10,027,551 · App. 15/696,094 · Granted Jul 17, 2018

Access controls through node-based effective policy identifiers

Inventors: Neil Rickards (Hertfordshire, GB); James Baker (London, GB); Marco Gelmi (London, GB); Radu-Cosmin Balan (London, GB); Savino Sguera (London, GB)
Assignee: Palantir Technologies, Inc.
H04L41/0893H04L41/12H04L65/608H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,027,551
App. No.
15/696,094
Granted
Jul 17, 2018
Kind
B1
Abstract

Techniques for implementing a node-based access control system are described herein. In an embodiment, a server computer stores a node based policy system wherein each node identifies a resource and a policy for the resource. The server computer identifies a policy for a first node and an identifier of a second node wherein the second node is a parent node to the first node. The server computer maps an effective policy identifier to the policy for the first node and the identifier of the second node. The server computer stores data associating the effective policy identifier with the first node. The server computer identifies a policy for a third node and an identifier of the second node, wherein the second node is a parent node to the third node and wherein the policy for the third node is equivalent to the policy for the first node. The server computer then stores data associating the effective policy identifier with the third node.

Claims (111)

1. A data processing method comprising:

storing a node based policy system wherein each node identifies a resource and a policy for the resource;

identifying a policy for a first node and an identifier of a second node, wherein the second node is a parent node to the first node;

generating an effective policy identifier for the policy for the first node and the identifier of the second node;

storing data associating the effective policy identifier with the first node;

identifying a policy for a third node and an identifier of the second node, wherein the second node is a parent node to the third node and wherein the policy for the third node is equivalent to the policy for the first node;

in response to the second node being a parent node to the third node and the policy for the third node being equivalent to the policy for the first node, storing data associating the effective policy identifier with the third node.

2. The method of claim 1 , further comprising:

storing data associating one or more user identifiers with the effective policy identifier;

receiving a request for a particular resource identified by the first node from a client computing device, wherein the request includes a particular user identifier;

determining that the one or more user identifiers include the particular user identifier;

in response to determining, responding to the request for the particular resource with the particular resource.

3. The method of claim 1 , further comprising:

storing data associating one or more user identifiers with the effective policy identifier;

storing data associating a second effective policy identifier with the second node, wherein the second effective policy identifier is mapped to a policy of the second node and an identifier of a fourth node, wherein the fourth node is a parent node to the second node;

receiving updated policy data identifying a new policy for the second node;

updating the data associating the second effective policy identifier with the second node with data associating a new effective policy identifier with the second node, wherein the new effective policy identifier is mapped to the new policy and the identifier of the fourth node;

in response to updating the data associating the second effective policy identifier with the second node, storing data invalidating the data associating the one or more user identifiers with the effective policy identifier.

4. The method of claim 1 , further comprising:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the particular node and an identifier of a fifth node, wherein the fifth node is a parent node of the fourth node;

storing data associating the second effective policy identifier with the fourth node.

5. The method of claim 1 , further comprising:

identifying a policy for a fourth node;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the fourth node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the fourth node and an identifier of the particular node;

storing data associating the second effective policy identifier with the fourth node.

6. The method of claim 1 , further comprising:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a first particular node is identified with a non-null policy;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the first particular node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a second particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the first particular node and an identifier of the second particular node;

storing data associating the second effective policy identifier with the fourth node.

7. A system comprising:

one or more processors;

one or more storage media;

one or more instructions stored in the storage media which, when executed by the one or more processors, cause performance of:

storing a node based policy system wherein each node identifies a resource and a policy for the resource;

identifying a policy for a first node and an identifier of a second node, wherein the second node is a parent node to the first node;

generating an effective policy identifier for the policy for the first node and the identifier of the second node;

storing data associating the effective policy identifier with the first node;

identifying a policy for a third node and an identifier of the second node, wherein the second node is a parent node to the third node and wherein the policy for the third node is equivalent to the policy for the first node;

in response to the second node being a parent node to the third node and the policy for the third node being equivalent to the policy for the first node, storing data associating the effective policy identifier with the third node.

8. The system of claim 7 , wherein the instructions, when executed by the one or more processors, further cause performance of:

storing data associating one or more user identifiers with the effective policy identifier;

receiving a request for a particular resource identified by the first node from a client computing device, wherein the request includes a particular user identifier;

determining that the one or more user identifiers include the particular user identifier;

in response to determining, responding to the request for the particular resource with the particular resource.

9. The system of claim 7 , wherein the instructions, when executed by the one or more processors, further cause performance of:

storing data associating one or more user identifiers with the effective policy identifier;

storing data associating a second effective policy identifier with the second node, wherein the second effective policy identifier is mapped to a policy of the second node and an identifier of a fourth node, wherein the fourth node is a parent node to the second node;

receiving updated policy data identifying a new policy for the second node;

updating the data associating the second effective policy identifier with the second node with data associating a new effective policy identifier with the second node, wherein the new effective policy identifier is mapped to the new policy and the identifier of the fourth node;

in response to updating the data associating the second effective policy identifier with the second node, storing data invalidating the data associating the one or more user identifiers with the effective policy identifier.

10. The system of claim 7 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the particular node and an identifier of a fifth node, wherein the fifth node is a parent node of the fourth node;

storing data associating the second effective policy identifier with the fourth node.

11. The system of claim 7 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a policy for a fourth node;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the fourth node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the fourth node and an identifier of the particular node;

storing data associating the second effective policy identifier with the fourth node.

12. The system of claim 7 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a first particular node is identified with a non-null policy;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the first particular node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a second particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the first particular node and an identifier of the second particular node;

storing data associating the second effective policy identifier with the fourth node.

13. One or more non-transitory computer-readable media storing instructions which, when executed by one or more processors, cause performance of:

storing a node based policy system wherein each node identifies a resource and a policy for the resource;

identifying a policy for a first node and an identifier of a second node, wherein the second node is a parent node to the first node;

generating an effective policy identifier for the policy for the first node and the identifier of the second node;

storing data associating the effective policy identifier with the first node;

identifying a policy for a third node and an identifier of the second node, wherein the second node is a parent node to the third node and wherein the policy for the third node is equivalent to the policy for the first node;

in response to the second node being a parent node to the third node and the policy for the third node being equivalent to the policy for the first node, storing data associating the effective policy identifier with the third node.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

storing data associating one or more user identifiers with the effective policy identifier;

receiving a request for a particular resource identified by the first node from a client computing device, wherein the request includes a particular user identifier;

determining that the one or more user identifiers include the particular user identifier;

in response to determining, responding to the request for the particular resource with the particular resource.

15. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

storing data associating one or more user identifiers with the effective policy identifier;

storing data associating a second effective policy identifier with the second node, wherein the second effective policy identifier is mapped to a policy of the second node and an identifier of a fourth node, wherein the fourth node is a parent node to the second node;

receiving updated policy data identifying a new policy for the second node;

updating the data associating the second effective policy identifier with the second node with data associating a new effective policy identifier with the second node, wherein the new effective policy identifier is mapped to the new policy and the identifier of the fourth node;

in response to updating the data associating the second effective policy identifier with the second node, storing data invalidating the data associating the one or more user identifiers with the effective policy identifier.

16. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the particular node and an identifier of a fifth node, wherein the fifth node is a parent node of the fourth node;

storing data associating the second effective policy identifier with the fourth node.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a policy for a fourth node;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the fourth node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the fourth node and an identifier of the particular node;

storing data associating the second effective policy identifier with the fourth node.

18. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of:

identifying a null policy for a fourth node;

in response to identifying the null policy for the fourth node, traversing the node based policy system through one or more parent nodes of the fourth node until a first particular node is identified with a non-null policy;

identifying a null policy for a fifth node, wherein the fifth node is a parent of the first particular node;

in response to identifying the null policy for the fifth node, traversing the node based policy system through one or more parent nodes of the fifth node until a second particular node is identified with a non-null policy;

mapping a second effective policy identifier to the policy for the first particular node and an identifier of the second particular node;

storing data associating the second effective policy identifier with the fourth node.

Assignments (7)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Continuity (1)
Provisional Application 62526955 · Jun 29, 2017