IP Library › Granted Patent US 11,711,368
Granted Patent B2
US 11,711,368 · App. 17/222,933 · Granted Jul 25, 2023

Security systems, methods, and computer program products for information integration platform

Inventors: Jody Hupton Palmer (Cambridge, CA); Alexander Lilko (Maple, CA); Steve Molloy (Chambly, CA)
Assignee: Open Text SA ULC
H04L63/10G06F16/27G06F16/9038G06F16/9535G06F21/10G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,711,368
App. No.
17/222,933
Granted
Jul 25, 2023
Kind
B2
Abstract

An information integration system may include a set of integration services embodied on one or more server machines in a computing environment. The set of integration services may include connectors communicatively connected to disparate information systems. The connectors may be configured for integrating data stored in the disparate information systems utilizing a common model employed by the set of integration services. The common model may overlay, augment, integrate, or otherwise utilize a content management interoperability services data model and may include common property definitions and a common security model. The common security model may include permissions particularly defined for use by the set of integration services. These common property definitions and permissions may be uniquely defined and utilized by the information integration system.

Claims (49)

1. A method, comprising:

receiving or generating, by an information integration system, a search query for searching cross disparate information systems communicatively connected to the information integration system and operating in a computing environment, the search query associated with a user, the information integration system having a unified index and adapted for providing a plurality of integration services, the plurality of integration services including a principals service and an authorization service;

performing, by the information integration system, an inbound check on the search query utilizing the principals service which provides principals for the user across the disparate information systems operating in the computing environment, the inbound check including:

determining a security level associated with the user based at least on the principals provided by the principals service; and

modifying the search query based at least on the security level associated with the user, the modifying including augmenting the search query with the principals provided by the principals service;

performing the search query, which has been modified through the inbound check, across the disparate information systems operating in the computing environment, the performing including evaluating the search query augmented with the principals, the evaluating including evaluating, in association with the principals for the user, permission information stored in the unified index of the information integration system;

performing, by the information integration system, an outbound check on the search results utilizing the authorization service which provides authorization information from the disparate information systems operating in the computing environment on what search result the user is permitted to view, the outbound check including filtering the search results for the user based on the authorization information provided by the authorization service; and

communicating, by the information integration system, the search results filtered through the outbound check to the user via a user device.

2. The method according to claim 1 , further comprising:

automatically generating the search query in response to a facet being selected by the user via a search interface running on the user device.

3. The method according to claim 1 , wherein the permission information stored in the unified index of the information integration system comprises permissions particularly defined for use by the plurality of integration services, the permissions including special common model permissions in addition to access control list permissions.

4. The method according to claim 3 , wherein the special common model permissions comprise predefined priorities and wherein the evaluating including evaluating the special common model permissions in order of the predefined priorities.

5. The method according to claim 3 , wherein the evaluating including mapping repository-specific permissions to the special common model permissions.

6. The method according to claim 1 , wherein the outbound check comprises accessing a credential store, retrieving credentials for the user from the credential store, and checking with the disparate information systems operating in the computing environment, utilizing the credentials for the user, on what search result the user is permitted to view.

7. The method according to claim 1 , further comprising:

translating or modifying the search query into a complex Boolean expression prior to evaluating the search query.

8. An information integration system, comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for:

receiving or generating a search query for searching cross disparate information systems operating in a computing environment and communicatively connected to the information integration system, the search query associated with a user, the information integration system having a unified index and adapted for providing a plurality of integration services, the plurality of integration services including a principals service and an authorization service;

performing an inbound check on the search query utilizing the principals service which provides principals for the user across the disparate information systems operating in the computing environment, the inbound check including:

determining a security level associated with the user based at least on the principals provided by the principals service; and

modifying the search query based at least on the security level associated with the user, the modifying including augmenting the search query with the principals provided by the principals service;

performing the search query, which has been modified through the inbound check, across the disparate information systems operating in the computing environment, the performing including evaluating the search query augmented with the principals, the evaluating including evaluating, in association with the principals for the user, permission information stored in the unified index of the information integration system;

performing an outbound check on the search results utilizing the authorization service which provides authorization information from the disparate information systems operating in the computing environment on what search result the user is permitted to view, the outbound check including filtering the search results for the user based on the authorization information provided by the authorization service; and

communicating the search results filtered through the outbound check to the user via a user device.

9. The information integration system of claim 8 , wherein the stored instructions are further translatable by the processor for:

automatically generating the search query in response to a facet being selected by the user via a search interface running on the user device.

10. The information integration system of claim 8 , wherein the permission information stored in the unified index of the information integration system comprises permissions particularly defined for use by the plurality of integration services, the permissions including special common model permissions in addition to access control list permissions.

11. The information integration system of claim 10 , wherein the special common model permissions comprise predefined priorities and wherein the evaluating including evaluating the special common model permissions in order of the predefined priorities.

12. The information integration system of claim 10 , wherein the evaluating including mapping repository-specific permissions to the special common model permissions.

13. The information integration system of claim 8 , wherein the outbound check comprises accessing a credential store, retrieving credentials for the user from the credential store, and checking with the disparate information systems operating in the computing environment, utilizing the credentials for the user, on what search result the user is permitted to view.

14. The information integration system of claim 8 , wherein the stored instructions are further translatable by the processor for:

translating or modifying the search query into a complex Boolean expression prior to evaluating the search query.

15. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor of an information integration system for:

receiving or generating a search query for searching cross disparate information systems operating in a computing environment and communicatively connected to the information integration system, the search query associated with a user, the information integration system having a unified index and adapted for providing a plurality of integration services, the plurality of integration services including a principals service and an authorization service;

performing an inbound check on the search query utilizing the principals service which provides principals for the user across the disparate information systems operating in the computing environment, the inbound check including:

determining a security level associated with the user based at least on the principals provided by the principals service; and

modifying the search query based at least on the security level associated with the user, the modifying including augmenting the search query with the principals provided by the principals service;

performing the search query, which has been modified through the inbound check, across the disparate information systems operating in the computing environment, the performing including evaluating the search query augmented with the principals, the evaluating including evaluating, in association with the principals for the user, permission information stored in the unified index of the information integration system;

performing an outbound check on the search results utilizing the authorization service which provides authorization information from the disparate information systems operating in the computing environment on what search result the user is permitted to view, the outbound check including filtering the search results for the user based on the authorization information provided by the authorization service; and

communicating the search results filtered through the outbound check to the user via a user device.

16. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

automatically generating the search query in response to a facet being selected by the user via a search interface running on the user device.

17. The computer program product of claim 15 , wherein the permission information stored in the unified index of the information integration system comprises permissions particularly defined for use by the plurality of integration services, the permissions including special common model permissions in addition to access control list permissions.

18. The computer program product of claim 17 , wherein the special common model permissions comprise predefined priorities and wherein the evaluating including evaluating the special common model permissions in order of the predefined priorities.

19. The computer program product of claim 17 , wherein the evaluating including mapping repository-specific permissions to the special common model permissions.

20. The computer program product of claim 15 , wherein the outbound check comprises accessing a credential store, retrieving credentials for the user from the credential store, and checking with the disparate information systems operating in the computing environment, utilizing the credentials for the user, on what search result the user is permitted to view.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2021
From: PALMER, JODY HUPTON; LILKO, ALEXANDER; MOLLOY, STEVE
To: OPEN TEXT S.A.
Reel/Frame 057140/0647 →
CERTIFICATE OF CONTINUANCE Recorded Aug 10, 2021
From: OT IP SUB, LLC
To: IP OT SUB ULC
Reel/Frame 057156/0819 →
IP BUSINESS SALE AGREEMENT Recorded Aug 10, 2021
From: OPEN TEXT S.A.
To: OT IP SUB, LLC
Reel/Frame 057156/0921 →
CERTIFICATE OF AMALGAMATION Recorded Aug 10, 2021
From: IP OT SUB ULC
To: OPEN TEXT SA ULC
Reel/Frame 057156/0935 →
Continuity (5)
Continuation 16739957 · Jan 10, 2020
Continuation 15471669 · Mar 28, 2017
Continuation 14210536 · Mar 14, 2014
Provisional Application 61782984 · Mar 14, 2013
Related Publication 20210226954A1 · Jul 22, 2021
Cited By (2)
US 12,235,919 US 12,235,935