IP Library Granted Patent US 10,891,312
Granted Patent B2
US 10,891,312 · App. 15/830,326 · Granted Jan 12, 2021

Sharing information between nexuses that use different classification schemes for information access control

Inventors: Richard Allen Ducott, III (Burlingame, CA); John Kenneth Garrod (Palo Alto, CA); Khan Tasinga (Palo Alto, CA)
Assignee: Palantir Technologies Inc.
G06F16/285G06F16/1837G06F16/213G06F16/24578G06F16/27G06F16/8358G06F16/951G06F21/604G06F21/6218G06F21/6236H04L63/105G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,891,312
App. No.
15/830,326
Granted
Jan 12, 2021
Kind
B2
Abstract

Systems and methods for sharing information between distributed computer systems connected to one or more data networks. In particular, a replication system implements methodologies for sharing database information between computer systems where the databases use different classification schemes for information access control.

Claims (87)

1. A method, comprising:

exporting a first copy of data associated with an access control list and stored by a first database system to a second database system, the data stored by the first database system subject to a first classification designation, the first classification designation used by the first database system for controlling access to information stored by the first database system;

during import of the first copy of the data exported:

determining that the first copy of the data exported corresponds with a particular translation path that is the shortest among a plurality of translation paths identified in the first copy of data, the particular translation path indicating a particular origin classification associated with a particular classification designation and for updating the access control list, and, in response, mapping, using a translation map associated with the second database system, the first classification designation to a second classification designation, the second classification designation used by the second database system for controlling access to information stored by the second database system, the first classification designation being different than the second classification designation; and

causing the second database system to store a second copy of the data subject to the second classification designation.

2. The method of claim 1 , further comprising:

exporting a third copy of the data from the second database system to the first database system; and

during import of the third copy of the data exported:

causing the first database system to store a fourth copy of the data subject to the first classification designation in the first database system.

3. The method of claim 1 , further comprising:

modifying the second copy of the data in the second database system to produce changed data in the second database system, the changed data subject to the second classification designation in the second database system;

exporting a first copy of the changed data from the second database system to the first database system; and

during import of the first copy of the changed data exported:

causing the first database system to store a second copy of the changed data subject to the first classification designation in the first database system.

4. The method of claim 1 , further comprising:

exporting an origin classification to the second database system, the origin classification exported for the first copy of the data exported;

during the import of the first copy of the data exported:

determining that the data stored by the first database system is subject to first classification designation in the first database system based on the origin classification; and

wherein the mapping the first classification designation to the second classification designation is performed responsive to determining that the data stored by the first database system is subject to the first classification designation in the first database system.

5. The method of claim 1 , further comprising:

after the import of the first copy of the data exported:

modifying the data stored in the first database system to produced changed data in the first database system, the changed data subject to the first classification designation in the first database system;

exporting a first copy of the changed data from the first database system to the second database system;

during import of the first copy of the changed data exported:

mapping the first classification designation to the second classification designation; and

causing the second database system to store a second copy of the changed data subject to the second classification designation in the second database system.

6. The method of claim 1 , wherein the first copy of the data exported reflects a database information item stored in the first database system.

7. The method of claim 1 , wherein the first classification designation is stored in an access control list associated with the data in the first database system.

8. The method of claim 1 , wherein determining that the first copy of the data exported corresponds with a particular translation path that is the shortest, comprises:

determining a set of origin classifications from the first copy of the data;

iterating over the set of origin classifications starting from a lowest ranked original classification until a translatable origin classification in the first copy of the data exported is found for which there is a translation rule in the translation map for translating a classification string of the translatable origin classification from the first classification designation to the second classification designation.

9. The method of claim 1 , wherein the translation map includes translation rules between every two classification designations used in a replication group.

10. One or more non-transitory computer-readable media storing one or more programs for execution by one or more processors, the one or more processors comprising instructions configured for:

exporting a first copy of data associated with an access control list and stored by a first database system to a second database system, the data stored by the first database system subject to a first classification designation, the first classification designation used by the first database system for controlling access to information stored by the first database system;

during import of the first copy of the data exported:

determining that the first copy of the data exported corresponds with a particular translation path that is the shortest among a plurality of translation paths identified in the first copy of data, the particular translation path indicating a particular origin classification associated with a particular classification designation and for updating the access control list, and, in response, mapping, using a translation map associated with the second database system, the first classification designation to a second classification designation, the second classification designation used by the second database system for controlling access to information stored by the second database system, the first classification designation being different than the second classification designation; and

causing the second database system to store a second copy of the data subject to the second classification designation.

11. The one or more non-transitory computer-readable media of claim 10 , the instructions further configured for:

exporting a third copy of the data from the second database system to the first database system; and

during import of the third copy of the data exported:

causing the first database system to store a fourth copy of the data subject to the first classification designation in the first database system.

12. The one or more non-transitory computer-readable media of claim 10 , the instructions further configured for:

modifying the second copy of the data in the second database system to produce changed data in the second database system, the changed data subject to the second classification designation in the second database system;

exporting a first copy of the changed data from the second database system to the first database system; and

during import of the first copy of the changed data exported:

causing the first database system to store a second copy of the changed data subject to the first classification designation in the first database system.

13. The one or more non-transitory computer-readable media of claim 10 , the instructions further configured for:

exporting an origin classification to the second database system, the origin classification exported for the first copy of the data exported;

during the import of the first copy of the data exported:

determining that the data stored by the first database system is subject to first classification designation in the first database system based on the origin classification; and

wherein the mapping the first classification designation to the second classification designation is performed responsive to determining that the data stored by the first database system is subject to the first classification designation in the first database system.

14. The one or more non-transitory computer-readable media of claim 10 , the instructions further configured for:

after the import of the first copy of the data exported:

modifying the data stored in the first database system to produced changed data in the first database system, the changed data subject to the first classification designation in the first database system;

exporting a first copy of the changed data from the first database system to the second database system;

during import of the first copy of the changed data exported:

mapping the first classification designation to the second classification designation; and

causing the second database system to store a second copy of the changed data subject to the second classification designation in the second database system.

15. A computing system, comprising:

one or more processors;

storage media;

one or more programs stored in the storage media and configured for execution by the one or more processors, the one or more programs comprising instructions configured for:

exporting a first copy of data associated with an access control list and stored by a first database system to a second database system, the data stored by the first database system subject to a first classification designation, the first classification designation used by the first database system for controlling access to information stored by the first database system;

during import of the first copy of the data exported:

determining that the first copy of the data exported corresponds with a particular translation path that is the shortest among a plurality of translation paths identified in the first copy of data, the particular translation path indicating a particular origin classification associated with a particular classification designation and for updating the access control list, and, in response, mapping, using a translation map associated with the second database system, the first classification designation to a second classification designation, the second classification designation used by the second database system for controlling access to information stored by the second database system, the first classification designation being different than the second classification designation; and

causing the second database system to store a second copy of the data subject to the second classification designation.

16. The computing system of claim 15 , the instructions further configured for:

exporting a third copy of the data from the second database system to the first database system; and

during import of the third copy of the data exported:

causing the first database system to store a fourth copy of the data subject to the first classification designation in the first database system.

17. The computing system of claim 15 , the instructions further configured for:

modifying the second copy of the data in the second database system to produce changed data in the second database system, the changed data subject to the second classification designation in the second database system;

exporting a first copy of the changed data from the second database system to the first database system; and

during import of the first copy of the changed data exported:

causing the first database system to store a second copy of the changed data subject to the first classification designation in the first database system.

18. The computing system of claim 15 , the instructions further configured for:

exporting an origin classification to the second database system, the origin classification exported for the first copy of the data exported;

during the import of the first copy of the data exported:

determining that the data stored by the first database system is subject to first classification designation in the first database system based on the origin classification; and

wherein the mapping the first classification designation to the second classification designation is performed responsive to determining that the data stored by the first database system is subject to the first classification designation in the first database system.

19. The computing system of claim 15 , the instructions further configured for:

after the import of the first copy of the data exported:

modifying the data stored in the first database system to produced changed data in the first database system, the changed data subject to the first classification designation in the first database system;

exporting a first copy of the changed data from the first database system to the second database system;

during import of the first copy of the changed data exported:

mapping the first classification designation to the second classification designation; and

causing the second database system to store a second copy of the changed data subject to the second classification designation in the second database system.

Assignments (7)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Continuity (3)
Continuation 14726204 · May 29, 2015
Continuation 13657684 · Oct 22, 2012
Related Publication 20180107731A1 · Apr 19, 2018
Cited By (2)
US 12,287,894 US 12,572,566