IP Library Granted Patent US 12,360,800
Granted Patent B2
US 12,360,800 · App. 17/760,791 · Granted Jul 15, 2025

Distributed attribute based access control as means of data protection and collaboration in sensitive (personal) digital record and activity trail investigations

Inventors: Alexander Kremer (Lexington, MA); Tamir Pivnik (Nahariya, IL)
Assignee: Proofpoint, Inc.
G06F9/468G06F9/5011G06F9/541
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,360,800
App. No.
17/760,791
Granted
Jul 15, 2025
Kind
B2
Abstract

A distributed system provides access by a principal to a resource associated with sensitive data. Micro-services in communication with an authorization engine each include a resource provider that receives a resource action request from the principal to access the resource, determines a context for the request, and transmits the context to the authorization engine in an authorization request. The authorization engine receives the authorization request, resolves the authorization request context against a plurality of pre-defined resource conditions, and responds to the resource provider with an authorization response of allow, deny, or allow-with-conditions. The context for the request includes metadata regarding attributes of the principal, and each of the resource conditions includes a logical expression operating upon the attributes.

Claims (37)

1. A distributed system in a communication network for attribute based access control providing a principal access to a resource comprising sensitive data, comprising:

a plurality of computer-based micro-services in communication with an authorization engine executing on one or more hardware processors and memory, via the communication network, wherein each of the computer-based micro-services executes a resource provider application program interface (API) on the one or more hardware processors configured to:

receive from the principal a resource action request to access the resource;

determine an authorization request context for the resource action request to access the resource, the authorization request context comprising metadata regarding the principal and an action by the principal associated with the resource action request; and

transmit to the authorization engine an authorization request comprising the authorization request context; and

the authorization engine comprising a database of policies comprising principals, resources, actions upon resources, and conditions, each condition comprising a logical expression operating upon one or more attributes of the principals and actions upon resources, the authorization engine configured to:

receive the authorization request;

resolve the authorization request context against a plurality of the pre-defined conditions to determine an authorization response selected from the group of allow, deny, and allow-with-conditions by:

searching the database for a policy with conditions matching the authorization request context;

selecting an authorization response of “deny” when no matching policy is found;

selecting an authorization response of “allow” when all found conditions are matching; and

selecting an authorization response of “allow-with-conditions” when one or more found matching policy has further restrictions to be resolved by the resource provider API and all other found conditions are matching;

record the authorization request, the authorization response, and a timestamp in an access audit log; and

transmit the authorization response to the resource provider API,

wherein the principal comprises an entity having a recognized identity used in an authorization process.

2. The system of claim 1 , wherein resolving the authorization request context further comprises accessing the access audit log comprising metadata regarding previous attempts to access the sensitive data.

3. The system of claim 1 , wherein the resource provider API is further configured to:

receive, from the authorization engine, the allow-with-conditions authorization response comprising a condition of the plurality of pre-defined conditions;

resolve the condition; and

provide the principal access to the resource.

4. The system of claim 1 , wherein the resource provider API is further configured to:

receive, from the authorization engine the allow-with-conditions authorization response comprising a condition of the plurality of pre-defined conditions;

fail to resolve the condition; and

deny the principal access to the resource.

5. A computer-based method by an authorization engine executing on one or more hardware processors and memory, in communication with a computer-based micro-service resource that executes a resource provider application program interface (API) on the one or more hardware processors via a communication network for controlling attribute based access by a principal to a resource comprising sensitive data, the authorization engine comprising a database of policies comprising principals, resources, actions upon resources, and conditions, each condition comprising a logical expression operating upon one or more attributes of the principals and actions upon resources, the method comprising:

receiving an authorization request from the resource provider API comprising an authorization request context for the request for the resource;

resolving the authorization request context against a plurality of pre-defined conditions associated with the resource to determine an authorization response selected from the group of allow, deny, and allow-with-conditions by:

searching the database for a policy with conditions matching the authorization request context;

selecting an authorization response of “deny” when no matching policy is found;

selecting an authorization response of “allow” when all found conditions are matching; and

selecting an authorization response of “allow-with-conditions” when one or more found matching policy has further restrictions to be resolved by the resource provider API and all other found conditions are matching;

recording the authorization request, the authorization response, and a timestamp in an access audit log; and

transmitting to the resource provider API an authorization response of the group consisting of allow, deny, and allow-with-conditions,

wherein the principal comprises an entity having a recognized identity used in an authorization process, the authorization request context for the request for the resource comprises metadata regarding a plurality of attributes of the principal and an action by the principal associated with the authorization request, and each of the plurality of conditions comprises a logical expression operating upon one or more attributes of the plurality of attributes.

6. The method of claim 5 , wherein the allow-with-conditions authorization response comprises a condition of the plurality of pre-defined conditions that the authorization engine did not resolve.

7. The method of claim 5 , wherein resolving the authorization request context further comprises accessing the access audit log.

8. The method of claim 5 , wherein the authorization response comprises privileges providing access to the resource.

Assignments (5)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: KREMER, ALEX; PIVNIK, TAMIR; MEIROVICH, IRIT LAHAT; KAMINSKY, LIOR; TAUBER, DAVID ZEEV; COVNEY, CHRISTOPHER MICHAEL; MESHULAM, YIGAL; GHAFOOR, KHURRAM; BARUCH, ODED; CERBONE, MICHAEL JOSEPH
To: OBSERVEIT LTD
Reel/Frame 060226/0559 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: SHAH, HEMAL
To: OBSERVEIT LTD
Reel/Frame 060226/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2022
From: OBSERVEIT LTD
To: PROOFPOINT, INC.
Reel/Frame 060226/0759 →
Continuity (2)
Provisional Application 62903853 · Sep 22, 2019
Related Publication 20220334869A1 · Oct 20, 2022
References Cited (8)
US 10042618B1 · Hulbert · 2018 [cited by examiner]
US 10530760B2 · Beck · 2020 [cited by examiner]
US 20080294586A1 · Lim · 2008 [cited by examiner]
US 20120060207A1 · Mardikar · 2012 [cited by examiner]
US 20190227856A1 · Xu · 2019 [cited by examiner]
US 20190272195A1 · Hsu · 2019 [cited by examiner]
US 20190273746A1 · Coffing · 2019 [cited by applicant]
International Search Report for PCT/US20/51939 mailed Jan. 12, 2021. [cited by applicant]