IP Library Patent Application 17465390
Patent Application
App. No. 17/465,390

GENERATION OF A PRIVILEGE GRAPH TO REPRESENT DATA ACCESS AUTHORIZATIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/465,390
Abstract

The technology disclosed herein enables generation of a privilege graph to represent data access authorizations. In a particular embodiment, a method includes extracting identity information for a plurality of users from a plurality of identity environments and privilege information from a plurality of data environments. The method further includes forming subgraphs for the identity environments and the data environments from the identity information and the privilege information. The method also includes translating the subgraphs into a canonical schema and, after translating the subgraphs, combining the subgraphs into the privilege graph.

Claims (56)

1 . A method for generating a privilege graph representing data access authorizations, the method comprising:

extracting identity information for a plurality of users from a plurality of identity environments and privilege information from a plurality of data environments;

forming subgraphs for the identity environments and the data environments from the identity information and the privilege information;

translating the subgraphs into a canonical schema; and

after translating the subgraphs, combining the subgraphs into the privilege graph.

2 . The method of claim 1 , comprising:

displaying the privilege graph to an administrator authorized to view the privilege graph.

3 . The method of claim 1 , wherein forming the subgraphs comprises:

creating a user node for a user of the plurality of users and sequentially connecting the user node to one or more attribute nodes that each represent an attribute of the user indicated in the identity information.

4 . The method of claim 3 , comprising:

upon reaching a last attribute node of the one or more attribute nodes, connecting the last attribute node to a privileges node; and

connecting the privileges node to one or more nodes of authorized data environments of the plurality of data environments that the user is authorized to access.

5 . The method of claim 4 , wherein the one or more nodes of authorized data environments each represent data or a feature that the user is authorized to access.

6 . The method of claim 1 , wherein translating the subgraphs comprises:

for attribute nodes of the subgraphs, changing attribute labels representing attributes of a user to canonical labels defined by the canonical schema.

7 . The method of claim 1 , wherein combining the subgraphs comprises:

for an attribute represented by attribute nodes in multiple subgraphs, identifying a common attribute node and migrating connections with the attribute nodes to the common attribute node.

8 . The method of claim 7 , comprising:

identifying replicated connections with the common attribute node; and

deduplicating the replicated connections.

9 . The method of claim 1 , comprising:

identifying a change to the privilege information; and

updating the privilege graph based on the change.

10 . The method of claim 9 , wherein updating the privilege graph comprises:

adding or removing a connection between nodes in the privilege graph.

11 . An apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the processing system to:

extract identity information for a plurality of users from a plurality of identity environments and privilege information from a plurality of data environments;

form subgraphs for the identity environments and the data environments from the identity information and the privilege information;

translate the subgraphs into a canonical schema; and

after translating the subgraphs, combine the subgraphs into a privilege graph.

12 . The apparatus of claim 11 , wherein the program instructions direct the processing system to:

display the privilege graph to an administrator authorized to view the privilege graph.

13 . The apparatus of claim 11 , wherein to form the subgraphs, the program instructions direct the processing system to:

create a user node for a user of the plurality of users and sequentially connect the user node to one or more attribute nodes that each represent an attribute of the user indicated in the identity information.

14 . The apparatus of claim 13 , wherein the program instructions direct the processing system to:

upon reaching a last attribute node of the one or more attribute nodes, connect the last attribute node to a privileges node; and

connect the privileges node to one or more nodes of authorized data environments of the plurality of data environments that the user is authorized to access.

15 . The apparatus of claim 14 , wherein the one or more nodes of authorized data environments each represent data or a feature that the user is authorized to access.

16 . The apparatus of claim 11 , wherein to translate the subgraphs, the program instructions direct the processing system to:

for attribute nodes of the subgraphs, change attribute labels representing attributes of a user to canonical labels defined by the canonical schema.

17 . The apparatus of claim 11 , wherein to combine the subgraphs, the program instructions direct the processing system to:

for an attribute represented by attribute nodes in multiple subgraphs, identify a common attribute node and migrate connections with the attribute nodes to the common attribute node.

18 . The apparatus of claim 17 , wherein the program instructions direct the processing system to:

identify replicated connections with the common attribute node; and

deduplicate the replicated connections.

19 . The apparatus of claim 11 , wherein the program instructions direct the processing system to:

identify a change to the privilege information; and

update the privilege graph based on the change.

20 . One or more computer readable storage media having program instructions stored thereon that, when read and executed by a processing system, direct the processing system to:

extract identity information for a plurality of users from a plurality of identity environments and privilege information from a plurality of data environments;

form subgraphs for the identity environments and the data environments from the identity information and the privilege information;

translate the subgraphs into a canonical schema; and

after translating the subgraphs, combine the subgraphs into a privilege graph.

Assignments (2)
CHANGE OF NAME Recorded Aug 1, 2022
From: COOKIE AI, INC.
To: VEZA TECHNOLOGIES, INC.
Reel/Frame 061037/0393 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: THAKUR, TARUN; LU, MAOHUA
To: COOKIE.AI, INC.
Reel/Frame 057375/0881 →