IP Library › Granted Patent US 12,189,796
Granted Patent B2
US 12,189,796 · App. 17/931,446 · Granted Jan 7, 2025

Just-in-time data object permission restriction and action implementation

Inventors: John Michael Harres (Thornton, CO); Darren James Moffat (Lower Earley, GB); Mark Leroy Shellenbaum (Westminster, CO)
Assignee: Oracle International Corporation
G06F21/604G06F21/6209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,796
App. No.
17/931,446
Granted
Jan 7, 2025
Kind
B2
Abstract

An instruction is received to define or modify a permission constraint corresponding to one or more file. A period of time is determined, where the period is one during which the defined or modified permission constraint is to apply to the one or more files. It is determined that the one or more files are to be deleted following completion of the period of time. A permission-instruction data set representing the permission constraint and a flag indicating that the one or more files are to be deleted following completion of the period of time are stored in a data store. It is detected that the period of time has ended. The one or more files are deleted in response to the detection.

Claims (70)

1. A method comprising:

receiving, using a computer system, an instruction to define or modify a permission constraint corresponding to one or more files accessible via a data management system;

determining a period of time during which the defined or modified permission constraint is to apply to the one or more files;

determining that the one or more files are to be deleted from the data management system following completion of the period of time;

storing, in one or more data stores, a permission-instruction data set representing the permission constraint and a flag indicating that the one or more files are to be deleted following completion of the period of time;

receiving a request to access at least one file of the one or more files from the data management system after the period of time has ended but before the at least one file of the one or more files is deleted from the data management system;

based at least in part on the request:

accessing the permission-instruction data set to determine that the at least one file of the one or more files is to be deleted following completion of the period of time;

detecting that the period of time has ended; and

in response to the detection, responding to the request indicating that the at least one file of the one or more files is not available even though the at least one file was not yet deleted from the data management system; and

deleting the one or more files after receiving the request.

2. The method of claim 1 , further comprising:

subsequent to an end of the period of time, intercepting a user request to access a particular file of the one or more files;

querying the one or more data stores to determine whether the requested access is to be permitted;

determining, in response to the querying, that the permission-instruction data set corresponds to the particular file;

outputting a response to the user request, wherein the response indicates that the particular file is not accessible.

3. The method of claim 2 , wherein an operating system performs the intercepting the user request, the querying the data store, and the determining that the permission-instruction data set corresponds to the particular file.

4. The method of claim 2 , further comprising:

detecting that the permission-instruction data set includes the flag indicating that the one or more files are to be deleted following completion of the period of time;

wherein the detecting that the period of time has ended occurs in response to detecting that the permission-instruction data set includes the flag.

5. The method of claim 1 , wherein the one or more files are deleted using a background deletion process that scans the one or more data stores for permission-instruction data sets that include the flag and corresponding to a period of time that has ended.

6. The method of claim 1 , wherein the determining that the one or more files are to be deleted following completion of the period of time includes determining that a same or different instruction indicates that the one or more files are to be deleted following completion of the period of time.

7. The method of claim 1 , wherein the instruction indicates that files having a particular attribute are to be locked to prevent modification for a particular duration of time from a specified type of trigger event, wherein each of the one or more files has the particular attribute, and wherein the period of time begins at an occurrence of a particular trigger event associated with the one or more files and has the particular duration of time.

8. A system comprising:

one or more data processors; and

a non-transitory computer readable storage medium containing instructions which, when executed on the one or more data processors, cause the one or more data processors to perform a set of actions including:

receiving an instruction to define or modify a permission constraint corresponding to one or more files accessible via a data management system;

determining a period of time during which the defined or modified permission constraint is to apply to the one or more files;

determining that the one or more files are to be deleted from the data management system following completion of the period of time;

storing, in one or more data stores, a permission-instruction data set representing the permission constraint and a flag indicating that the one or more files are to be deleted following completion of the period of time;

receiving a request to access at least one file of the one or more files from the data management system after the period of time has ended but before the at least one of the one or more files is deleted from the data management system;

based at least in part on the request:

accessing the permission-instruction data set to determine that the at least one file of the one or more files is to be deleted following completion of the period of time;

detecting that the period of time has ended; and

in response to the detection, responding to the request indicating that the at least one file of the one or more files is not available even though the at least one file was not yet deleted from the data management system; and

deleting the one or more files after receiving the request.

9. The system of claim 8 , wherein the set of actions further includes:

subsequent to an end of the period of time, intercepting a user request to access a particular file of the one or more files;

querying the one or more data stores to determine whether the requested access is to be permitted;

determining, in response to the querying, that the permission-instruction data set corresponds to the particular file;

outputting a response to the user request, wherein the response indicates that the particular file is not accessible.

10. The system of claim 9 , wherein an operating system performs the intercepting the user request, the querying the data store, and the determining that the permission-instruction data set corresponds to the particular file.

11. The system of claim 9 , wherein the set of actions further includes:

detecting that the permission-instruction data set includes the flag indicating that the one or more files are to be deleted following completion of the period of time;

wherein the detecting that the period of time has ended occurs in response to detecting that the permission-instruction data set includes the flag.

12. The system of claim 8 , wherein the one or more files are deleted using a background deletion process that scans the one or more data stores for permission-instruction data sets that include the flag and corresponding to a period of time that has ended.

13. The system of claim 8 , wherein the determining that the one or more files are to be deleted following completion of the period of time includes determining that a same or different instruction indicates that the one or more files are to be deleted following completion of the period of time.

14. The system of claim 8 , wherein the instruction indicates that files having a particular attribute are to be locked to prevent modification for a particular duration of time from a specified type of trigger event, wherein each of the one or more files has the particular attribute, and wherein the period of time begins at an occurrence of a particular trigger event associated with the one or more files and has the particular duration of time.

15. A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to perform a set of actions including:

receiving an instruction to define or modify a permission constraint corresponding to one or more files accessible via a data management system;

determining a period of time during which the defined or modified permission constraint is to apply to the one or more files;

determining that the one or more files are to be deleted from the data management system following completion of the period of time;

storing, in one or more data stores, a permission-instruction data set representing the permission constraint and a flag indicating that the one or more files are to be deleted following completion of the period of time;

receiving a request to access at least one file of the one or more files from the data management system after the period of time has ended but before the at least one file of the one or more files is deleted from the data management system;

based at least in part on the request:

accessing the permission-instruction data set to determine that the at least one file of the one or more files is to be deleted following completion of the period of time;

detecting that the period of time has ended; and

in response to the detection, responding to the request indicating that the at least one of the one or more files is not available even though the at least one file was not yet deleted from the data management system; and

deleting the one or more files after receiving the request.

16. The computer-program product of claim 15 , wherein the set of actions further includes:

subsequent to an end of the period of time, intercepting a user request to access a particular file of the one or more files;

querying the one or more data stores to determine whether the requested access is to be permitted;

determining, in response to the querying, that the permission-instruction data set corresponds to the particular file;

outputting a response to the user request, wherein the response indicates that the particular file is not accessible.

17. The computer-program product of claim 16 , wherein an operating system performs the intercepting the user request, the querying the data store, and the determining that the permission-instruction data set corresponds to the particular file.

18. The computer-program product of claim 16 , wherein the set of actions further includes:

detecting that the permission-instruction data set includes the flag indicating that the one or more files are to be deleted following completion of the period of time;

wherein the detecting that the period of time has ended occurs in response to detecting that the permission-instruction data set includes the flag.

19. The computer-program product of claim 15 , wherein the one or more files are deleted using a background deletion process that scans the one or more data stores for permission-instruction data sets that include the flag and corresponding to a period of time that has ended.

20. The computer-program product of claim 15 , wherein the determining that the one or more files are to be deleted following completion of the period of time includes determining that a same or different instruction indicates that the one or more files are to be deleted following completion of the period of time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2022
From: HARRES, JOHN MICHAEL; MOFFAT, DARREN JAMES; SHELLENBAUM, MARK LEROY
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 061209/0943 →
Continuity (3)
Continuation In Part 17569442 · Jan 5, 2022
Continuation 17561469 · Dec 23, 2021
Related Publication 20230205900A1 · Jun 29, 2023
References Cited (20)
US 10521401B2 · Madaan · 2019 [cited by examiner]
US 11170102B1 · Bhattacharya et al. · 2021 [cited by applicant]
US 20080306954A1 · Hornqvist et al. · 2008 [cited by applicant]
US 20130218999A1 · Martin · 2013 [cited by applicant]
US 20140245461A1 · O'Neill et al. · 2014 [cited by applicant]
US 20160359859A1 · Capone · 2016 [cited by applicant]
US 20190114330A1 · Xu et al. · 2019 [cited by applicant]
US 20200120098A1 · Berg et al. · 2020 [cited by applicant]
US 20200380155A1 · Sarferaz · 2020 [cited by examiner]
US 20210097190A1 · Scrivano · 2021 [cited by applicant]
US 20210209243A1 · Gallardo · 2021 [cited by applicant]
US 20210397987A1 · Dixit et al. · 2021 [cited by applicant]
US 20220052988A1 · Gadnis et al. · 2022 [cited by applicant]
US 20220237148A1 · Perlman · 2022 [cited by examiner]
US 20230205899A1 · Harres et al. · 2023 [cited by applicant]
US 20230205903A1 · Harres et al. · 2023 [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/569,442, dated Apr. 4, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/561,469, dated Apr. 9, 2024. [cited by applicant]
Office Action for U.S. Appl. No. 17/561,469, dated Dec. 21, 2023. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/569,442, dated Aug. 28, 2024. [cited by applicant]