IP Library Granted Patent US 11,914,623
Granted Patent B2
US 11,914,623 · App. 17/077,792 · Granted Feb 27, 2024

Approaches for managing access control permissions

Inventors: James Baker (London, GB); Sander Kromwijk (Brooklyn, NY)
Assignee: Palantir Technologies Inc.
G06F16/285G06F16/221G06F16/248G06F16/24553G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,914,623
App. No.
17/077,792
Granted
Feb 27, 2024
Kind
B2
Abstract

Systems and methods are provided for determining a query involving at least one dataset comprising a plurality of records, the query being submitted by a first user operating a computing device. An archetype policy that governs access to records of the at least one dataset can be determined, wherein the archetype policy includes at least one logical formula to be evaluated when determining whether a requesting user is permitted to access a given record, and wherein the at least one logical formula is satisfied based at least in part on a state associated with the requesting user and at least one first variable evaluated by the at least one logical formula. At least one record that the first user is permitted to access can be determined based at least in part on satisfaction of the at least one logical formula associated with the archetype policy.

Claims (40)

1. A system comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, cause the system to perform:

determining a query involving at least one dataset comprising a plurality of records, the query being submitted by an entity operating a computing device;

determining an archetype policy that governs access to records of the at least one dataset, wherein the archetype policy includes a logical formula to be evaluated when determining whether the entity is permitted to access a given record;

evaluating the archetype policy, wherein the evaluating of the archetype policy comprises evaluating the logical formula based on values or attributes of a variable that are inferred from a different dataset or a different data source besides the at least one dataset, wherein the values or attributes of the variable are missing from the at least one dataset and correspond to a characteristic of the entity;

creating new entries corresponding to the respective records in the at least one dataset, wherein at least a portion of the new entries comprise or encode the inferred values or attributes of the variable; and

determining at least one record that the entity is permitted to access based at least in part on satisfaction of the logical formula associated with the archetype policy.

2. The system of claim 1 , wherein the characteristic of the entity identifies one or more properties associated with the entity including at least one of: a user name, a user identifier, and one or more groups associated with the entity.

3. The system of claim 1 , wherein determining at least one record that the entity is permitted to access further causes the system to perform:

determining the characteristic of the entity matches a value of the values or attributes of the variable.

4. The system of claim 1 , wherein the characteristic comprises a user identifier associated with the entity.

5. The system of claim 1 , wherein the characteristic comprises

a group name associated with the entity.

6. The system of claim 1 , wherein the instructions further cause the system to perform:

modifying the archetype policy to include a second logical formula that relies on a second variable.

7. The system of claim 1 , wherein determining at least one record that the entity is permitted to access based at least in part on satisfaction of the logical formula associated with the archetype policy further causes the system to perform:

generating a filter for identifying records of the at least one dataset that satisfy the logical formula, wherein the records identified are deemed accessible to the entity.

8. The system of claim 7 , wherein the filter is an Structured Query Language (SQL) expression including one or more where clauses to identify records that are accessible to the entity.

9. The system of claim 1 , wherein the entity comprises a first entity; and the logical formula is further based on a corresponding attribute of a second entity.

10. A computer-implemented method, comprising:

determining a query involving at least one dataset comprising a plurality of records, the query being submitted by an entity operating a computing device;

determining an archetype policy that governs access to records of the at least one dataset, wherein the archetype policy includes a logical formula to be evaluated when determining whether the entity is permitted to access a given record;

evaluating the archetype policy, wherein the evaluating of the archetype policy comprises evaluating the logical formula based on values or attributes of a variable that are inferred from a different dataset or a different data source besides the at least one dataset, wherein the values or attributes of the variable are missing from the at least one dataset and correspond to a characteristic of the entity;

creating new entries corresponding to the respective records in the at least one dataset, wherein at least a portion of the new entries comprise or encode the inferred values or attributes of the variable; and

determining at least one record that the entity is permitted to access based at least in part on satisfaction of the logical formula associated with the archetype policy.

11. The computer-implemented method of claim 10 , wherein the characteristic of the entity identifies one or more properties associated with the entity including at least one of: a user name, a user identifier, and one or more groups associated with the entity.

12. The computer-implemented method of claim 10 , wherein determining at least one record that the entity is permitted to access further causes the system to perform:

determining the characteristic of the entity matches a value of the values or attributes of the variable.

13. The computer-implemented method of claim 10 , wherein the characteristic comprises a user identifier associated with the entity.

14. A non-transitory computer readable medium comprising instructions that, when executed, cause one or more processors of a computing system to perform:

determining a query involving at least one dataset comprising a plurality of records, the query being submitted by an entity operating a computing device;

determining an archetype policy that governs access to records of the at least one dataset, wherein the archetype policy includes a logical formula to be evaluated when determining whether the entity is permitted to access a given record;

evaluating the archetype policy, wherein the evaluating of the archetype policy comprises evaluating the logical formula based on values or attributes of a variable that are inferred from a different dataset or a different data source besides the at least one dataset, wherein the values or attributes of the variable are missing from the at least one dataset and correspond to a characteristic of the entity;

creating new entries corresponding to the respective records in the at least one dataset, wherein at least a portion of the new entries comprise or encode the inferred values or attributes of the variable; and

determining at least one record that the entity is permitted to access based at least in part on satisfaction of the logical formula associated with the archetype policy.

15. The non-transitory computer readable medium of claim 14 , wherein the characteristic of the entity identifies one or more properties associated with the entity including at least one of: a user name, a user identifier, and one or more groups associated with the entity.

16. The non-transitory computer readable medium of claim 14 , wherein determining at least one record that the entity is permitted to access further causes the computing system to perform:

determining the characteristic of the entity matches a value of the values or attributes of the variable.

17. The non-transitory computer readable medium of claim 14 , wherein the characteristic comprises a user identifier associated with the entity.

Assignments (2)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2022
From: BAKER, JAMES; KROMWIJK, SANDER
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 059283/0498 →
Continuity (2)
Provisional Application 62925714 · Oct 24, 2019
Related Publication 20210124766A1 · Apr 29, 2021