IP Library Granted Patent US 10,397,229
Granted Patent B2
US 10,397,229 · App. 16/134,586 · Granted Aug 27, 2019

Controlling user creation of data resources on a data processing platform

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,397,229
App. No.
16/134,586
Granted
Aug 27, 2019
Kind
B2
Abstract

Methods and systems are disclosed for controlling user creation of data resources on a software platform for storing and executing data resources for multiple users. The methods and systems may be performed using one or more processors or special-purpose computing hardware and may comprise receiving from a user a user request to create a data resource on the software platform, the user request comprising, or identifying, a specification indicative of the data resource and a user identifier associated with said user. A further operation may comprise performing verification of said user using the user identifier to determine if said user is permitted to create or modify the data resource indicated in the specification in accordance with a predetermined set of permissions. A further operation may comprise, responsive to verifying said user in accordance with the predetermined set of permissions, creating a version the data resource indicated in accordance with the specification for deployment on the software platform for subsequent access or execution by said user.

Claims (21)

1. A computer system comprising:

one or more processors;

one or more non-transitory computer-readable storage media coupled to the one or more processors and storing one or more sequences of instructions which when executed cause performing:

receiving a user request to create a data resource on the software platform, the user request comprising, or identifying, a specification indicative of the data resource, a user identifier associated with said user, and an indication that the data resource is required to be accessible to one or more other users, external to the software platform, via a network link;

performing verification using the user identifier to determine if said user is permitted to create or modify the data resource indicated in the specification in accordance with a predetermined set of permissions;

responsive to verifying said user, creating a version of the data resource indicated in accordance with the specification for deployment on the software platform for subsequent access or execution by said user;

verifying that said user is permitted to allow access to the data resource by external users;

responsive to verifying that said user is so permitted, creating one or more replicas of the data resource, and subsequently routing access requests from one or more external users to the one or more replicas.

2. The computer system of claim 1 , further comprising instructions which when executed cause performing, responsive to verifying said user:

identifying one or more annotations in the data resource specification;

associating an executable launch function appropriate to the or each identified annotation to the created data resource, wherein the launch function, when executed, transmits a data resource identifier to a software platform controller and receives therefrom information necessary for one or more actions to be performed on or by the created data resource.

3. The computer system of claim 2 , further comprising instructions which when executed cause determining that the user has been verified prior to providing the launch function with said information.

4. The computer system of claim 2 , further comprising instructions which when executed cause determining attributes of the user and/or the data resource using the data resource identifier, and, provides said information based on said attributes.

5. The computer system of claim 2 , further comprising instructions which when executed cause performing, in response to identifying an annotation associated with a security feature, the method further comprises associating an executable launch function that, when executed, obtains secret information necessary for accessing or executing the data resource when deployed on the software platform.

6. The computer system of claim 5 , further comprising instructions which when executed cause receiving the secret information from a secure vault, external to the launch function and the software platform controller.

7. The computer system of claim 6 , further comprising instructions which when executed cause receiving the secret information as a wrapped token, and wherein the launch function queries the secure server using the secret information to obtain the secret information.

8. The computer system of claim 6 , wherein the secret information comprises a password and/or a digital certificate.

9. The computer system of claim 2 , wherein the said information defines whether the user is permitted to create, edit and/or delete the data resource.

10. The computer system of claim 1 , further comprising instructions which when executed cause verifying that said user is permitted to create new data resources in accordance with the predefined set of permissions.

11. The computer system of claim 1 , wherein the indication that the data resource is required to be accessible to one or more other users comprises identifying an annotation in the user request associated with said external user access, and further comprising instructions which when executed cause identifying other user access requests to the data resource by means of a corresponding annotation in the other user requests, the annotation optionally being a URL path.

12. The computer system of claim 1 , further comprising instructions which when executed cause creating a plurality of replicas of the data resource and routing access requests from the one or more other users by means of a load balancing algorithm.

Assignments (7)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Cited By (1)
US 12,217,091