IP Library › Granted Patent US 12,505,245
Granted Patent B2
US 12,505,245 · App. 18/058,596 · Granted Dec 23, 2025

System and method for role based access control for data

Inventors: Saurabh Soni (Telangana, IN); Prachi Jain (Telangana, IN); Amith Pallankize (Telangana, IN); Nishant Sethi (Karnataka, IN); Vidhi Raheja (Telangana, IN)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6227G06F21/604G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,245
App. No.
18/058,596
Granted
Dec 23, 2025
Kind
B2
Abstract

Example aspects include techniques for role based access control for data. These techniques may include assigning a data tag to an attribute of a plurality of database rows of a database table, the data tag identifying a pre-defined category associated with the attribute and generating an association between the data tag and a data usage scenario, the association indicating that the attribute is accessible to a plurality of requests associated with the data usage scenario. In addition, the techniques may include associating a user role to the data usage scenario, and determining, in response to a request, a permission of an account based on the data usage scenario and the user role associated with the request. Further, the techniques may include providing the attribute for a database row of the plurality of database rows based on the permission.

Claims (56)

1 . A method comprising:

assigning a data tag to an attribute of a plurality of database rows of a database table, the data tag identifying a pre-defined category associated with the attribute;

generating an association between the data tag and a data usage scenario, the data usage scenario corresponding to a workflow that generates a plurality of requests for data from the database table, the association indicating that the attribute is accessible to a plurality of requests associated with the data usage scenario based on the assigning of the data tag to the attribute;

associating a user role to the data usage scenario, the user role representing a job function performed by a plurality of user accounts possessing the user role;

determining, in response to a request of the plurality of requests associated with the data usage scenario, a permission of an account of the plurality of user accounts based on the data usage scenario and the user role associated with the request; and

providing, in response to the request and based on the permission, the attribute for a database row of the plurality of database rows.

2 . The method of claim 1 , further comprising:

receiving, via a web application, a data usage scenario selection and a data identifier corresponding to the attribute; and

generating the request based on the data usage scenario selection and the data identifier.

3 . The method of claim 1 , further comprising receiving the request from a client device, the request including at least an account identifier identifying the account and a data identifier corresponding to the attribute.

4 . The method of claim 1 , wherein the permission corresponds to membership within a security group, and wherein determining the permission of the account further comprises:

determining that the account is a member of the security group.

5 . The method of claim 4 , further comprising adding the account to the security group based upon the account possessing the user role.

6 . The method of claim 1 , wherein the permission is stored as metadata within a database, and further comprising:

detecting an update to the attribute, the database table, the plurality of user accounts, the data usage scenario, and/or the user role; and

dynamically updating the metadata based upon the detecting.

7 . The method of claim 1 , wherein the permission is a first permission, the attribute is a first attribute, and further comprising:

determining, in response to the request, absence of a second permission based on a security group of the account; and

denying access to a second attribute of the database row of the plurality of database rows based on the absence of the second permission.

8 . A system comprising:

a memory storing instructions thereon; and

at least one processor coupled with the memory and configured by the instructions to:

assign a data tag to an attribute of a plurality of database rows of a database table, the data tag identifying a pre-defined category associated with the attribute;

generate an association between the data tag and a data usage scenario, the data usage scenario corresponding to a workflow that generates a plurality of requests for data from the database table, the association indicating that the attribute is accessible to a plurality of requests associated with the data usage scenario based on the assigning of the data tag to the attribute;

associate a user role to the data usage scenario, the user role representing a job function performed by a plurality of user accounts possessing the user role;

determine, in response to a request of the plurality of requests associated with the data usage scenario, a permission of an account of the plurality of user accounts based on the data usage scenario and the user role associated with the request; and

provide, in response to the request and based on the permission, the attribute for a database row of the plurality of database rows.

9 . The system of claim 8 , wherein the at least one processor is further configured by the instructions to:

receive, via a web application, a data usage scenario selection and a data identifier corresponding to the attribute; and

generate the request based on the data usage scenario selection and the data identifier.

10 . The system of claim 8 , wherein the at least one processor is further configured by the instructions to receive the request from a client device, the request including at least an account identifier identifying the account and a data identifier corresponding to the attribute.

11 . The system of claim 8 , wherein the permission corresponds to membership within a security group, and to determine the permission of the account, the at least one processor is configured by the instructions to determining that the account is a member of the security group.

12 . The system of claim 11 , wherein the at least one processor is further configured by the instructions to add the account to the security group based upon the account possessing the user role.

13 . The system of claim 9 , wherein the permission is stored as metadata within a database, and the at least one processor is further configured by the instructions to:

detect an update to the attribute, the database table, the plurality of user accounts, the data usage scenario, and/or the user role; and

dynamically update the metadata based upon the detecting.

14 . The system of claim 9 , wherein permission is a first permission, the attribute is a first attribute, and the at least one processor is further configured by the instructions to:

determine, in response to the request, absence of a second permission based on a security group of the account; and

deny access to a second attribute of the database row of the plurality of database rows based on the absence of the second permission.

15 . A non-transitory computer-readable device having instructions thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

assigning a data tag to an attribute of a plurality of database rows of a database table, the data tag identifying a pre-defined category associated with the attribute;

generating an association between the data tag and a data usage scenario, the data usage scenario corresponding to a workflow that generates a plurality of requests for data from the database table, the association indicating that the attribute is accessible to a plurality of requests associated with the data usage scenario based on the assigning of the data tag to the attribute;

associating a user role to the data usage scenario, the user role representing a job function performed by a plurality of user accounts possessing the user role;

determining, in response to a request of the plurality of requests associated with the data usage scenario, a permission of an account of the plurality of user accounts based on the data usage scenario and the user role associated with the request; and

providing, in response to the request and based on the permission, the attribute for a database row of the plurality of database rows.

16 . The non-transitory computer-readable device of claim 15 , wherein the operations further comprise:

receiving, via a web application, a data usage scenario selection and a data identifier corresponding to the attribute; and

generating the request based on the data usage scenario selection and the data identifier.

17 . The non-transitory computer-readable device of claim 15 , wherein the operations further comprise receiving the request from a client device, the request including at least an account identifier identifying the account and a data identifier corresponding to the attribute.

18 . The non-transitory computer-readable device of claim 15 , wherein the permission corresponds to membership within a security group, and wherein determining the permission of the account further comprises determining that the account is a member of the security group.

19 . The non-transitory computer-readable device of claim 15 , wherein the permission is stored as metadata within a database, and the operations further comprise:

detecting an update to the attribute, the database table, the plurality of user accounts, the data usage scenario, and/or the user role; and

dynamically updating the metadata based upon the detecting.

20 . The non-transitory computer-readable device of claim 15 , wherein the permission is a first permission, the attribute is a first attribute, and the operations further comprise:

determining, in response to the request, absence of a second permission based on a security group of the account; and

denying access to a second attribute of the database row of the plurality of database rows based on the absence of the second permission.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE 5TH INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 063183 FRAME: 0377. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 29, 2023
From: SONI, SAURABH; JAIN, PRACHI; PALLANKIZE, AMITH; SETHI, NISHANT; RAHEJA, VIDHI
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 064746/0905 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2023
From: SONI, SAURABH; JAIN, PRACHI; SETHI, NISHANT; RAHEJA, VIDHJI; PALLANKIZE, AMITH
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063183/0377 →
Continuity (1)
Related Publication 20240169085A1 · May 23, 2024
References Cited (7)
US 20020095405A1 · Fujiwara · 2002 [cited by applicant]
US 20120102489A1 · Staiman · 2012 [cited by examiner]
US 20130117313A1 · Miao et al. · 2013 [cited by applicant]
US 20190362087A1 · Ferrans · 2019 [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2023/036631, mailed on Feb. 12, 2024, 11 pages. [cited by applicant]
“Variations on a Theme: Dynamic RLS Patterns”, Retrieved from: https://www.elegantbi.com/post/dynamicrlspatterns, Mar. 9, 2020, 9 Pages. [cited by applicant]
International preliminary report on patentability Received for PCT Application No. PCT/US23/036631, mailed on Jun. 5, 2025, 06 Pages. [cited by applicant]