IP Library Granted Patent US 12,242,626
Granted Patent B2
US 12,242,626 · App. 17/736,308 · Granted Mar 4, 2025

Framework for pushing access-privilege information from data environments

Inventors: Tarun Thakur (Los Gatos, CA); Maohua Lu (Fremont, CA)
Assignee: Veza Technologies, Inc.
G06F21/6218G06F9/54G06F21/31G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,626
App. No.
17/736,308
Granted
Mar 4, 2025
Kind
B2
Abstract

The technology disclosed herein enables pushing of access-privilege information from data environments to a graphing service. In a particular embodiment, a method includes registering a data environment to enable the data environment to use Application Programming Interface (API) calls and receiving an API call transmitted from the data environment. The API call provides information about access permissions for the data environment. The method further includes incorporating the information into a privilege graph representing data access authorizations.

Claims (44)

1. A method comprising:

in a graphing service:

registering a data environment with the graphing service to enable the data environment to use Application Programming Interface (API) calls of the graphing service;

registering a data source of the data environment with the graphing service;

receiving an API call transmitted from the data environment, wherein the API call provides, to the graphing service, information about access permissions for the data environment and includes a first identifier for the data source and a second identifier for the data environment; and

incorporating the information into a privilege graph representing data access authorizations.

2. The method of claim 1 , wherein the information comprises an incremental update of the access permissions since a previous instance of the API call was received from the data environment.

3. The method of claim 1 , wherein the data environment transmitted the API call after a time has elapsed since a previous instance of the API call was transmitted.

4. The method of claim 1 , wherein the data environment transmitted the API call in response to a change in the access permissions.

5. The method of claim 1 , comprising:

providing a token to the data environment, wherein the token is included with the API call to authenticate the data environment to the graphing service.

6. The method of claim 1 , comprising:

binding the data environment to a type of data environment, wherein the type corresponds to a template to which the information conforms.

7. The method of claim 1 , wherein incorporating the information into the privilege graph comprises:

forming a subgraph of the information; and

combining the subgraph into the privilege graph.

8. The method of claim 7 , comprising:

before combining the subgraph into the privilege graph, translating the subgraph into a canonical schema used by the privilege graph.

9. An apparatus implementing a graphing service, the apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the apparatus to:

register a data environment with the graphing service to enable the data environment to use Application Programming Interface (API) calls of the graphing service;

register a data source of the data environment with the graphing service;

receive an API call transmitted from the data environment, wherein the API call provides, to the graphing service, information about access permissions for the data environment and includes a first identifier for the data source and a second identifier for the data environment; and

incorporate the information into a privilege graph representing data access authorizations.

10. The apparatus of claim 9 , wherein the information comprises an incremental update of the access permissions since a previous instance of the API call was received from the data environment.

11. The apparatus of claim 9 , wherein the data environment transmitted the API call after a time has elapsed since a previous instance of the API call was transmitted.

12. The apparatus of claim 9 , wherein the data environment transmitted the API call in response to a change in the access permissions.

13. The apparatus of claim 9 , wherein the program instructions direct the processing system to:

provide a token to the data environment, wherein the token is included with the API call to authenticate the data environment to the graphing service.

14. The apparatus of claim 9 , wherein the program instructions direct the processing system to:

bind the data environment to a type of data environment, wherein the type corresponds to a template to which the information conforms.

15. The apparatus of claim 9 , wherein to incorporate the information into the privilege graph, the program instructions direct the processing system to:

form a subgraph of the information; and

combine the subgraph into the privilege graph.

16. The apparatus of claim 15 , wherein the program instructions direct the processing system to:

before combining the subgraph into the privilege graph, translate the subgraph into a canonical schema used by the privilege graph.

17. One or more non-transitory computer readable storage media having program instructions stored thereon for implementing a graphing service, the program instructions, when read and executed by a processing system, direct the processing system to:

register a data environment with the graphing service to enable the data environment to use Application Programming Interface (API) calls of the graphing service;

register a data source of the data environment with the graphing service;

receive an API call transmitted from the data environment, wherein the API call provides, to the graphing service, information about access permissions for the data environment and includes a first identifier for the data source and a second identifier for the data environment; and

incorporate the information into a privilege graph representing data access authorizations.

18. The one or more computer readable storage media of claim 17 , wherein the information comprises an incremental update of the access permissions since a previous instance of the API call was received from the data environment.

Assignments (2)
CHANGE OF NAME Recorded May 12, 2022
From: COOKIE AI, INC.
To: VEZA TECHNOLOGIES, INC.
Reel/Frame 060021/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2022
From: THAKUR, TARUN; LU, MAOHUA
To: COOKIE.AI, INC.
Reel/Frame 060380/0704 →
Continuity (2)
Provisional Application 63183773 · May 4, 2021
Related Publication 20220358233A1 · Nov 10, 2022
References Cited (7)
US 10432639B1 · Bebee · 2019 [cited by examiner]
US 11108828B1 · Curtis · 2021 [cited by examiner]
US 20200125543A1 · Zhang · 2020 [cited by examiner]
US 20200280564A1 · Badawy · 2020 [cited by examiner]
US 20220019579A1 · Meyerzon · 2022 [cited by examiner]
US 20230153355A1 · Crabtree · 2023 [cited by examiner]
A Comprehensive Analysis of the Android Permissions System, by Almomani et al., published 2020 (Year: 2020). [cited by examiner]