IP Library Granted Patent US 11,797,702
Granted Patent B2
US 11,797,702 · App. 17/198,734 · Granted Oct 24, 2023

Access control rights assignment capabilities utilizing a new context-based hierarchy of data based on new forms of metadata

Inventors: Nicole Reineke (Northborough, MA); Hanna Yehuda (Newton, MA); Omar Abdul Aal (Cairo, EG); Farida Shafik (Cairo, EG); Joel Christner (San Jose, CA); Shary Beshara (Cairo, EG); Ahmad Refaat Abdel Fadeel Ahmad El Rouby (Cairo, EG)
Assignee: EMC IP Holding Company LLC
G06F21/6218G06F16/2379
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,702
App. No.
17/198,734
Filed
Mar 11, 2021
Granted
Oct 24, 2023
Kind
B2
Examiner
YANG, HAN
Art Unit
2493
USPC
726/30
Abstract

One example method includes extracting content metadata from data, storing the content metadata in a data catalogue, receiving at the data catalogue, from a user, a request to access the data, transmitting, by the data catalogue to a security service provider, an access request that includes the extracted content metadata and metadata relating to the access request, accessing, by the security service provider, identity metadata concerning an identity of the user, and a data access policy, and transmitting, by the security service provider to the data catalogue, a decision as to whether or not access can be granted to the data, and the decision is based on the data access policy, the identity metadata, and the metadata in the access request.

Claims (32)

1. A method, comprising:

extracting content metadata from data;

storing the content metadata in, or in a location accessible to, a data catalogue;

receiving at the data catalogue, from a user, a request to access the data;

transmitting, by the data catalogue to a security service provider, an access request that includes the extracted content metadata and metadata relating to the access request;

accessing, by the security service provider, identity metadata concerning an identity of the user, and a data access policy; and

transmitting, by the security service provider to the data catalogue, a decision as to whether or not access can be granted to the data, and the decision is based on the data access policy, the identity metadata, and the metadata in the access request.

2. The method as recited in claim 1 , wherein the identity metadata is received by the security service provider from an identity server.

3. The method as recited in claim 1 , wherein the data access policy is automatically modified, without manual intervention by a human, in response to a change to the data.

4. The method as recited in claim 1 , wherein the extracted content metadata comprises metadata about one or more attributes of the data.

5. The method as recited in claim 1 , wherein the data access policy defines a hierarchy of multiple metadata attributes.

6. The method as recited in claim 1 , wherein the data access policy is enforceable with respect to the data regardless of the physical location of the data.

7. The method as recited in claim 1 , wherein the data access policy is enforceable with respect to the data regardless of the entity that generated the data, how the data was generated, or when the data was generated.

8. The method as recited in claim 1 , wherein the data access policy is immediately and automatically applied to newly added data.

9. The method as recited in claim 1 , wherein an alert is automatically generated when data is detected that is not covered by the data access policy.

10. The method as recited in claim 1 , wherein the data access policy defines a timeframe, or amount of time, that the user is permitted to access the data.

11. A non-transitory computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

extracting content metadata from data;

storing the content metadata in, or in a location accessible to, a data catalogue;

receiving at the data catalogue, from a user, a request to access the data;

transmitting, by the data catalogue to a security service provider, an access request that includes the extracted content metadata and metadata relating to the access request;

accessing, by the security service provider, identity metadata concerning an identity of the user, and a data access policy; and

transmitting, by the security service provider to the data catalogue, a decision as to whether or not access can be granted to the data, and the decision is based on the data access policy, the identity metadata, and the metadata in the access request.

12. The non-transitory computer readable storage medium as recited in claim 11 , wherein the identity metadata is received by the security service provider from an identity server.

13. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy is automatically modified, without manual intervention by a human, in response to a change to the data.

14. The non-transitory computer readable storage medium as recited in claim 11 , wherein the extracted content metadata comprises metadata about one or more attributes of the data.

15. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy defines a hierarchy of multiple metadata attributes.

16. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy is enforceable with respect to the data regardless of the physical location of the data.

17. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy is enforceable with respect to the data regardless of the entity that generated the data, how the data was generated, or when the data was generated.

18. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy is immediately and automatically applied to newly added data.

19. The non-transitory computer readable storage medium as recited in claim 11 , wherein an alert is automatically generated when data is detected that is not covered by the data access policy.

20. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data access policy defines a timeframe, or amount of time, that the user is permitted to access the data.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2023
From: REINEKE, NICOLE; YEHUDA, HANNA; ABDULAAL, OMAR; SHAFIK, FARIDA; CHRISTNER, JOEL; BESHARA, SHARY; EL ROUBY, AHMAD RAFAAT ABDEL FADEEL AHMAD
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 064955/0432 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
Continuity (1)
Related Publication 20220292211A1 · Sep 15, 2022
Cited By (1)
US 12,326,931