IP Library › Granted Patent US 10,572,678
Granted Patent B2
US 10,572,678 · App. 16/511,852 · Granted Feb 25, 2020

System and method for implementing domain based access control on queries of a self-describing data system

Inventors: Boris Levit (Auburndale, MA); Sergey Murashko (Minsk, BY); Valentsin Shapavalau (Minsk, BY); Andrei Samsonau (Minsk, BY); Gregory Rasin (Andover, MA); Andrey Knourenko (Wayland, MA)
Assignee: ARAS CORPORATION
G06F21/6227G06F16/2423G06F16/2448G06F16/24566H04L63/101H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,572,678
App. No.
16/511,852
Granted
Feb 25, 2020
Kind
B2
Abstract

A method for implementing access controls for items of data belonging to a self-describing data structure including obtaining a query definition specifying a requested item of data in the self-describing data structure, determining domains associated with the requested item, the domains including a set of items within the self-describing data structure on an execution path of a query executed according to the query definition. For each respective domain associated with the requested item, the method includes determining subdomains associated with the requested item, determining a role of the user for the respective domain, the role is associated with a set of access permissions to items of data within the domain, and generating an output corresponding to whether access to the requested item is granted based on a policy for each of the subdomains associated with the requested item and the role of the user for the domain.

Claims (46)

1. A method for implementing access controls for items of data belonging to a self-describing data structure, the method comprising:

obtaining a query definition specifying a requested item of data in the self-describing data structure;

determining one or more domains associated with the requested item, wherein the one or more domains comprise a set of items within the self-describing data structure on an execution path of a query executed according to the query definition, the requested item is included in a first subdomain of a first domain and a second subdomain of a second domain, and the query definition specifies accessing the requested item in the first subdomain of the first domain;

determining a first role of the user for the first domain, wherein the first role is associated with a set of access permissions to items of data within the first domain;

determining a second role of the user for the second domain, wherein the second role is associated with a set of access permissions to items of data within the second domain;

determining that the user has access to the requested item in the second subdomain of the second domain based on a policy for the second subdomain of the second domain and the second role of the user; and

generating an output to indicate that access to the user to the requested item is granted in the first subdomain of the first domain based on determining that the user has access to the requested item in the second subdomain of the second domain.

2. The method of claim 1 , further comprising maintaining a mapping of the one or more domains including one or more subdomains and the set of items in the one or more subdomains.

3. The method of claim 2 , further comprising updating the mapping when data included in the set of items is modified.

4. The method of claim 1 , wherein determining that the user has access to the requested item in the second subdomain of the second domain based on the policy for the second subdomain of the second domain and the second role of the user further comprises:

determining a state of the requested item; and

determining the user has access to the requested item using a rule data structure based on at least the state of the requested item and the second role of the user.

5. The method of claim 4 , wherein the rule data structure is a lookup table.

6. The method of claim 1 , wherein the output comprises different access rights that are granted for different roles of the user based on a state of the requested item, a state of a root item in the second subdomain of the second domain, or some combination thereof.

7. The method of claim 6 , wherein the access rights comprise get, update, and delete.

8. The method of claim 1 , wherein the access controls are implemented by a query engine in a system for performing recursive searches in the self-describing data structure.

9. A tangible, non-transitory computer-readable medium storing instructions that, when executed, cause one or more processing devices to:

obtain a query definition specifying a requested item of data in a self-describing data structure;

determine one or more domains associated with the requested item, wherein the one or more domains comprise a set of items within the self-describing data structure on an execution path of a query executed according to the query definition, the requested item is included in a first subdomain of a first domain and a second subdomain of a second domain, and the query definition specifies accessing the requested item in the first subdomain of the first domain;

determine a first role of the user for the first domain, wherein the first role is associated with a set of access permissions to items of data within the first domain;

determine a second role of the user for the second domain, wherein the second role is associated with a set of access permissions to items of data within the second domain;

determine that the user has access to the requested item in the second subdomain of the second domain based on a policy for the second subdomain of the second domain and the second role of the user; and

generate an output to indicate that access to the user to the requested item is granted in the first subdomain of the first domain based on determining that the user has access to the requested item in the second subdomain of the second domain.

10. The computer-readable medium of claim 9 , wherein the one or more processing devices are further to execute the instructions to maintain a mapping of the one or more domains including one or more subdomains and the set of items in the one or more subdomains.

11. The computer-readable medium of claim 10 , wherein the one or more processing devices are further to execute the instructions to update the mapping when data included in the set of items is modified.

12. The computer-readable medium of claim 9 , wherein determining that the user has access to the requested item in the second subdomain of the second domain based on the policy for the second subdomain of the second domain and the second role of the user further comprises:

determining a state of the requested item; and

determining the user has access to the requested item using a rule data structure based on at least the state of the requested item and the second role of the user.

13. The computer-readable medium of claim 12 , wherein the rule data structure is a lookup table.

14. The computer-readable medium of claim 9 , wherein the output comprises different access rights that are granted for different roles of the user based on a state of the requested item, a state of a root item in the second subdomain of the second domain, or some combination thereof.

15. The computer-readable medium of claim 14 , wherein the access rights comprise get, update, and delete.

16. The computer-readable medium of claim 9 , wherein the access controls are implemented by a query engine in a system for performing recursive searches in the self-describing data structure.

17. A system, comprising:

a memory device storing instructions; and

a processing device operatively coupled to the memory device, the processing device to execute the instructions to:

obtain a query definition specifying a requested item of data in a self-describing data structure;

determine one or more domains associated with the requested item, wherein the one or more domains comprise a set of items within the self-describing data structure on an execution path of a query executed according to the query definition, the requested item is included in a first subdomain of a first domain and a second subdomain of a second domain, and the query definition specifies accessing the requested item in the first subdomain of the first domain;

determine a first role of the user for the first domain, wherein the first role is associated with a set of access permissions to items of data within the first domain;

determine a second role of the user for the second domain, wherein the second role is associated with a set of access permissions to items of data within the second domain;

determine that the user has access to the requested item in the second subdomain of the second domain based on a policy for the second subdomain of the second domain and the second role of the user; and

generate an output to indicate that access to the user to the requested item is granted in the first subdomain of the first domain based on determining that the user has access to the requested item in the second subdomain of the second domain.

18. The system of claim 17 , wherein the processing device is further to execute the instructions to maintain a mapping of the one or more domains including one or more subdomains and the set of items in the one or more subdomains.

19. The system of claim 17 , wherein the processing device is further to execute the instructions to update the mapping when data included in the set of items is modified.

20. The system of claim 17 , wherein determining that the user has access to the requested item in the second subdomain of the second domain based on the policy for the second subdomain of the second domain and the second role of the user further comprises:

determining a state of the requested item; and

determining the user has access to the requested item using a rule data structure based on at least the state of the requested item and the second role of the user.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 14, 2021
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
To: ARAS CORPORATION
Reel/Frame 055912/0643 →
SECURITY INTEREST Recorded Apr 13, 2021
From: ARAS CORPORATION
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 055900/0111 →
SECURITY INTEREST Recorded Nov 3, 2020
From: ARAS CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 054257/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2019
From: LEVIT, BORIS; MURASHKO, SERGEY; SHAPAVALAU, VALENTSIN; SAMSONAU, ANDREI; KNOURENKO, ANDREY
To: ARAS CORPORATION
Reel/Frame 049953/0740 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2019
From: RASIN, GREGORY
To: ARAS CORPORATION
Reel/Frame 049953/0874 →
Continuity (3)
Continuation 16390985 · Apr 22, 2019
Provisional Application 62664557 · Apr 30, 2018
Related Publication 20190340382A1 · Nov 7, 2019