IP Library › Granted Patent US 11,196,772
Granted Patent B2
US 11,196,772 · App. 16/591,742 · Granted Dec 7, 2021

Data access policies

Inventors: Evgene Vahlis (Jersey City, NJ); Paul Giura (Cairo, NY)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/20G06F16/122G06F16/245G06F21/602G06F21/6227H04L9/3226H04L63/0428H04L63/105G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,196,772
App. No.
16/591,742
Granted
Dec 7, 2021
Kind
B2
Abstract

To verify compliance with a data access policy, a query result including data specified by a requesting entity and a representation of a data access policy is received from a database. Based on the representation of the data access policy included in the query result, it is verified whether the requesting entity is permitted to access the data included in the query result. Transmission of the data included in the query result to the requesting entity is controlled responsive to the verification. Related methods, systems, and computer program products are also discussed.

Claims (37)

1. A method, comprising:

receiving, by a server, a result of an electronic query associated with an electronic database, the result of the electronic query comprising an electronic data and an electronic data access policy identified by the electronic database, the electronic data access policy governing an access to the electronic data, wherein the electronic query is initiated by a requesting entity corresponding to a communication device;

comparing, by the server, the electronic data to the electronic data access policy identified by the electronic database;

determining, by the server, whether at least a portion of the electronic data complies with the electronic data access policy identified by the electronic database;

determining, by the server, that the access to the electronic data is permissible when the portion of the electronic data complies with the electronic data access policy identified by the electronic database; and

transmitting, by the server, the electronic data to the requesting entity when the access to the electronic data is permissible.

2. The method of claim 1 , further comprising determining that the portion of the electronic data fails to comply with the electronic data access policy.

3. The method of claim 2 , further comprising declining the access to the electronic data in response to the portion of the electronic data failing to comply with the electronic data access policy.

4. The method of claim 1 , further comprising hashing the electronic data using a hash function to generate a hash value representing the electronic data.

5. The method of claim 4 , further comprising comparing the hash value representing the electronic data to a cryptographic key representing the electronic data access policy.

6. The method of claim 1 , further comprising hashing the electronic data access policy using a hash function to generate a cryptographic key representing the electronic data access policy.

7. The method of claim 6 , further comprising receiving the cryptographic key from a data owner of the electronic data, wherein the determining, by the server, whether the at least a portion of the electronic data complies with the electronic data access policy identified by the electronic database is based on the cryptographic key received from the data owner.

8. A system, comprising:

a hardware processor of a first communication device; and

a memory device, the memory device storing instructions, the instructions when executed causing the hardware processor to perform operations, the operations comprising:

receiving a result of an electronic query associated with an electronic database, the result of the electronic query comprising an electronic data and an electronic data access policy governing an access to the electronic data, wherein the electronic query is initiated by a requesting entity corresponding to a second communication device;

comparing the electronic data to the electronic data access policy;

determining whether at least a portion of the electronic data complies with the electronic data access policy;

determining that the access to the electronic data is permissible when the portion of the electronic data complies with the electronic data access policy; and

transmitting the electronic data to the requesting entity when the access to the electronic data is permissible.

9. The system of claim 8 , wherein the operations further comprise determining that the portion of the electronic data fails to comply with the electronic data access policy.

10. The system of claim 9 , wherein the operations further comprise declining the access to the electronic data in response to the portion of the electronic data failing to comply with the electronic data access policy.

11. The system of claim 8 , wherein the operations further comprise hashing the electronic data using a hash function to generate a hash value representing the electronic data.

12. The system of claim 11 , wherein the operations further comprise comparing the hash value representing the electronic data to a cryptographic key representing the electronic data access policy.

13. The system of claim 8 , wherein the operations further comprise hashing the electronic data access policy using a hash function to generate a cryptographic key representing the electronic data access policy.

14. The system of claim 13 , wherein the operations further comprise receiving the cryptographic key from a data owner of the electronic data, wherein the determining whether the at least a portion of the electronic data complies with the electronic data access policy is based on the cryptographic key received from the data owner.

15. A non-transitory memory device storing instructions that when executed cause a hardware processor of a first communication device to perform operations, the operations comprising:

receiving a result of an electronic query associated with an electronic database, the result of the electronic query comprising an electronic data and an electronic data access policy governing an access to the electronic data, wherein the electronic query is initiated by a requesting entity corresponding to a second communication device;

comparing the electronic data to the electronic data access policy;

determining whether at least a portion of the electronic data complies with the electronic data access policy;

determining that the access to the electronic data is permissible when the portion of the electronic data complies with the electronic data access policy; and

transmitting the electronic data to the requesting entity when the access to the electronic data is permissible.

16. The non-transitory memory device of claim 15 , wherein the operations further comprise determining that the portion of the electronic data fails to comply with the electronic data access policy.

17. The non-transitory memory device of claim 16 , wherein the operations further comprise declining the access to the electronic data in response to the portion of the electronic data failing to comply with the electronic data access policy.

18. The non-transitory memory device of claim 15 , wherein the operations further comprise hashing the electronic data using a hash function to generate a hash value representing the electronic data.

19. The non-transitory memory device of claim 15 , wherein the operations further comprise hashing the electronic data access policy using a hash function to generate a cryptographic key representing the electronic data access policy.

20. The non-transitory memory device of claim 19 , wherein the operations further comprise receiving the cryptographic key from a data owner of the electronic data, wherein the determining whether the at least a portion of the electronic data complies with the electronic data access policy is based on the cryptographic key received from the data owner, and wherein the transmitting of the electronic data to the requesting entity when the access to the electronic data is permissible comprises transmitting the electronic data to the second communication device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2022
From: AT&T INTELLECTUAL PROPERTY I, L.P.
To: WORKDAY, INC.
Reel/Frame 058971/0940 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2019
From: VAHLIS, EVGENE; GIURA, PAUL
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 050663/0261 →
Continuity (4)
Continuation 15649692 · Jul 14, 2017
Continuation 14874874 · Oct 5, 2015
Continuation 14092112 · Nov 27, 2013
Related Publication 20200036755A1 · Jan 30, 2020