IP Library Granted Patent US 11,886,431
Granted Patent B2
US 11,886,431 · App. 16/418,185 · Granted Jan 30, 2024

Real-time analytical queries of a document store

Inventors: Joel Bernstein (New York, NY); Michael Suzuki (Sunbury-on-Thames, GB); John Newton (Warfield, GB)
Assignee: Hyland UK Operations Limited
G06F16/24524G06F16/2228G06F16/244G06F16/2455G06F16/252H04L63/101H04L63/102G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,431
App. No.
16/418,185
Granted
Jan 30, 2024
Kind
B2
Abstract

A method for real-time analytical queries of a documents store is provided. The method includes receiving a query and an access control list associated with a user, the query requesting content managed by a content management system. The method further includes generating an execution plan based on the query and the access control list. The method further includes constraining, based on the execution plan, possible results returned from the query using a content index of a plurality of content items maintained in a repository of the content management system. The constraining includes limiting the at least one processor from adding a content item of the plurality of content items to a permissions-filtered results set based on the access control list identifying the user as not having permission to access the content item. The method further includes aggregating the permissions-filtered results set and returning the aggregated permissions-filtered results set.

Claims (44)

1. A computer-implemented method comprising:

receiving a query and an access control list associated with a user submitting the query for processing to a search engine, the access control list being assigned to the query for user authentication during query analysis by an insight engine, the query including a request to access content managed by a content management system;

generating an execution plan for the search engine to process the query, based on a virtual field included in a virtual database schema to specify different behaviors in generating the execution plan, the virtual field pointing to metadata stored in a database that is not assessable to the user submitting the query;

calculating the virtual field value based on one or more field values in the virtual database schema;

using the execution plan to search a search index and return a result set of documents, in response to receiving the query, wherein the virtual field does not exist in the search index;

constraining results returned from the query using a content index of a plurality of content items maintained in a repository of the content management system, the constraining comprising limiting a content item of the plurality of content items from being added to a permissions-filtered results set based on the access control list assigned to the query;

aggregating based on the execution plan, the permissions-filtered results set; and

returning the aggregated permissions-filtered results set to the content management system.

2. The method as in claim 1 , further comprising:

evaluating user permissions based on a user identity of the user, the evaluating comprising searching a user permissions index for permissions granted to the user based on the user identity.

3. The method as in claim 2 , wherein the user permissions index comprises an access control list index maintained by the content management system.

4. The method as in claim 3 , wherein the evaluating of the user permissions comprises searching an access control list index for access control lists designating the user identity as having a sufficient level of access to content items assigned to the access control lists.

5. The method as in claim 1 , wherein the query comprises a string of characters entered by the user into a user interface.

6. The method as in claim 5 , wherein the returning the aggregated permissions-filtered results set comprises providing the aggregated permissions-filtered results set to the user interface.

7. The method as in claim 1 , wherein the virtual field being configured to retrieve operational data including at least one of creations timestamps, deletion timestamps, lock timestamps, and time series data to eliminate need for users to specify complex SQL functions to specify time series queries that aggregate over datetime fields.

8. The method of claim 7 , wherein the virtual field comprises time series data.

9. The method of claim 7 , wherein the virtual field specifies a machine learning operation.

10. A system comprising:

at least one data processor; and

at least one memory storing instructions which, when executed by the at least one data processor, result in operations comprising:

receiving a query and an access control list associated with a user submitting the query for processing to a search engine, the access control list being assigned to the query for user authentication during query analysis by an insight engine, the query including a request to access content managed by a content management system;

generating an execution plan for the search engine to process the query based on a virtual field included in a virtual database schema to specify different behaviors in generating the execution plan, the virtual field pointing to metadata stored in a database that is not assessable to the user submitting the query;

calculating the virtual field value based on one or more field values in the virtual database schema;

using the execution plan to search a search index and return a result set of documents, in response to receiving the query, wherein the virtual field does not exist in the search index;

constraining results returned from the query using a content index of a plurality of content items maintained in a repository of the content management system, the constraining comprising limiting a content item of the plurality of content items from being added to a permissions-filtered results set based on the access control list assigned to the query;

aggregating based on the execution plan, the permissions-filtered results set and returning the aggregated permissions-filtered results set to the content management system.

11. The system as in claim 10 , wherein the operations further comprise:

evaluating user permissions based on a user identity of the user, the evaluating comprising searching a user permissions index for permissions granted to the user based on the user identity.

12. The system as in claim 11 , wherein the user permissions index comprises an access control list index maintained by the content management system.

13. The system as in claim 12 , wherein the evaluating of the user permissions comprises searching an access control list index for access control lists designating the user identity as having a sufficient level of access to content items assigned to the access control lists.

14. The system as in claim 10 , wherein the query comprises a string of characters entered by the user into a user interface.

15. The method as in claim 14 , wherein the returning the aggregated permissions-filtered results set comprises providing the aggregated permissions-filtered results set to the user interface.

16. The method as in claim 10 , wherein the generating is based on a virtual field.

17. The method of claim 16 , wherein the virtual field comprises time series data.

18. The method of claim 16 , wherein the virtual field specifies a machine learning operation.

19. A non-transitory computer program product storing instructions which, when executed by at least one data processor, causes operations comprising:

receiving a query and an access control list associated with a user submitting the query for processing to a search engine, the access control list being assigned to the query for user authentication during query analysis by an insight engine, the query including a request to access content managed by a content management system;

generating an execution plan for the search engine to process the query based on a virtual field included in a virtual database schema to specify different behaviors in generating the execution plan, the virtual field pointing to metadata stored in a database that is not assessable to the user submitting the query;

calculating the virtual field value based on one or more field values in the virtual database schema;

using the execution plan to search a search index and return a result set of documents, in response to receiving the query, wherein the virtual field does not exist in the search index;

constraining results returned from the query using a content index of a plurality of content items maintained in a repository of the content management system, the constraining comprising limiting a content item of the plurality of content items from being added to a permissions-filtered results set based on the access control list assigned to the query;

aggregating based on the execution plan, the permissions-filtered results set and returning the aggregated permissions-filtered results set to the content management system.

20. The non-transitory computer program product of claim 19 ,

wherein the user permissions index comprises an access control list index maintained by the content management system, and wherein the evaluating of the user permissions comprises searching an access control list index for access control lists designating the user identity as having a sufficient level of access to content items assigned to the access control lists.

Assignments (8)
SECURITY INTEREST Recorded Jan 17, 2024
From: HYLAND UK OPERATIONS LIMITED
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 066339/0332 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 055820/0369 Recorded Sep 24, 2023
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT, A BRANCH OF CREDIT SUISSE
To: ALFRESCO SOFTWARE LIMITED (K/N/A HYLAND UK OPERATIONS LIMITED)
Reel/Frame 065018/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 55820/0343 Recorded Sep 21, 2023
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT, A BRANCH OF CREDIT SUISSE
To: ALFRESCO SOFTWARE LIMITED (K/N/A HYLAND UK OPERATIONS LIMITED)
Reel/Frame 064974/0425 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2023
From: BERNSTEIN, JOEL; SUZUKI, MICHAEL; NEWTON, JOHN
To: ALFRESCO SOFTWARE, INC.
Reel/Frame 064933/0031 →
CHANGE OF NAME Recorded Oct 13, 2021
From: ALFRESCO SOFTWARE LIMITED
To: HYLAND UK OPERATIONS LIMITED
Reel/Frame 057909/0840 →
SECURITY AGREEMENT SUPPLEMENT (SECOND LIEN) Recorded Mar 26, 2021
From: ALFRESCO SOFTWARE LIMITED
To: CREDIT SUISSE
Reel/Frame 055820/0369 →
SECURITY AGREEMENT SUPPLEMENT (FIRST LIEN) Recorded Mar 26, 2021
From: ALFRESCO SOFTWARE LIMITED
To: CREDIT SUISSE
Reel/Frame 055820/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2021
From: ALFRESCO SOFTWARE, INC.
To: ALFRESCO SOFTWARE LIMITED
Reel/Frame 054935/0642 →
Continuity (2)
Provisional Application 62675097 · May 22, 2018
Related Publication 20190361897A1 · Nov 28, 2019
Cited By (1)
US 12,657,330