IP Library Granted Patent US 12,619,752
Granted Patent B2
US 12,619,752 · App. 18/125,707 · Granted May 5, 2026

Data management systems and methods

Inventors: Eric Swenson (Soquel, CA); Harbinder Singh Hayer (Menlo Park, CA)
Assignee: Intertrust Technologies Corporation
G06F21/6218G06F16/2455H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,752
App. No.
18/125,707
Granted
May 5, 2026
Kind
B2
Abstract

This disclosure relates to systems and methods for managing access to data through enforcement of one or more associated rules. In various embodiments, a directory may be used to manage and/or otherwise record various relationships between objects, that may include governed objects such as data sets, and associated rules and rule sets. Access requests involving governed objects may be compared with relevant rules to determine whether the requested access should be allowed and what, if any, restrictions should be applied in connection with such access. Various embodiments of the disclosed systems and methods may allow for a data governance model that is flexible, allows for use across multiple complex organizations, and is highly extensible.

Claims (30)

1 . A method for managing access to a governed object performed by a data management system comprising at least one processor and at least one non-transitory computer-readable medium storing instructions that, when executed by the at least one processor, cause the data management system to perform the method, the method comprising:

receiving, by a security service of the data management system, an access control request, the access control request comprising an indication of a subject associated with a validated access token, an indication of a specified data set associated with the access control request, and an indication of at least one requested access privilege associated with the request;

accessing, by the security service, a directory database to identify:

at least a first governed object in the directory database, the at least a first governed object corresponding with the specified data set associated with the access control request,

at least a first rule set in the directory database, the at least a first rule set being associated with the at least a first governed object in the directory database, the at least a first rule set comprising at least a first rule specifying a depth associated with the at least a first rule, the at least a first rule set being attached to at least a second governed object located above the at least a first governed object in a root path of a directory tree in the directory database, the at least a second governed object being located above the at least a first governed object within the depth specified in the at least a first rule, and

at least a first role in the directory database, the at least a first role being associated with the indication of the subject associated with the access token;

determining, by the security service, based on the at least a first rule, the at least a first role, and the access control request, that the access control request should be granted, wherein determining that the access control request should be granted comprises:

comparing the indication of the subject associated with the access token, the at least a first role, the indication of the specified data set, and the indication of the at least one requested access privilege with the at least a first rule, and

determining, based on the comparison, that the subject associated with the access token is permitted the at least one requested access privilege to the at least a first governed object associated with the specified data set;

issuing, to a service originating the access control request by the security service, an access control response granting access to the specified data set based on determining that the access control request should be granted.

2 . The method of claim 1 , wherein the access control request is received from a data service of the data management service.

3 . The method of claim 2 , wherein the access control response is issued by the security service to the data service.

4 . The method of claim 2 , wherein the access token is validated by the data service.

5 . The method of claim 1 , wherein the access token is validated by an authentication service of the data management service.

6 . The method of claim 1 , wherein the access token is validated by a remote authentication service.

7 . The method of claim 1 , wherein the validated access token comprises an access token that is not expired.

8 . The method of claim 1 , wherein the validated access token comprises an access token issued by an authentication service of the data management service based on determining that authentication credentials provided to the authentication service in connection with an access token request are associated with a valid account.

9 . The method of claim 1 , wherein the directory database is managed by a directory service of the data management system.

10 . The method of claim 1 , wherein the service originating the access control request comprises a data service of the data management system and the method further comprises:

retrieving, by the data service based on the access control response, the specified data set from a data store; and

transmitting, by the data service, a data access response to a requesting client system based on the retrieved specified data set.

11 . The method of claim 10 , wherein the data store comprises a local data store of the data management system.

12 . The method of claim 10 , wherein the data store comprises a remote data store.

13 . The method of claim 10 , wherein the access control response comprises at least one restriction, and wherein retrieving the specified data set from the data store comprises retrieving the specified data set in accordance with the at least one restriction.

14 . The method of claim 13 , wherein retrieving the specified data set in accordance with the at least one restriction comprises transmitting at least one data retrieval request issued to the data store in accordance with the at least one restriction.

15 . The method of claim 1 , wherein the at least a second governed object comprises an object associated with an organization.

16 . The method of claim 1 , wherein the method further comprises:

identifying, by the security service, at least a second rule set in the directory database, the at least a second rule set being associated with the at least a first governed object in the directory database, the at least a second rule set comprising at least a second rule; and

determining, by the security service, that the first rule set has a higher indicated priority than the second rule set.

17 . The method of claim 1 , wherein the subject associated with the access token comprises an account associated with the validated access token.

Assignments (2)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
Continuity (3)
Continuation 16778934 · Jan 31, 2020
Provisional Application 62800103 · Feb 1, 2019
Related Publication 20230244804A1 · Aug 3, 2023
References Cited (105)
US 5941947A · Brown et al. · 1999 [cited by applicant]
US 6038563A · Bapat et al. · 2000 [cited by applicant]
US 6158010A · Moriconi et al. · 2000 [cited by applicant]
US 6363393B1 · Ribitzky · 2002 [cited by applicant]
US 6487552B1 · Lei et al. · 2002 [cited by applicant]
US 6640244B1 · Bowman-Amuah · 2003 [cited by examiner]
US 6715080B1 · Starkovich et al. · 2004 [cited by applicant]
US 6889210B1 · Vainstein · 2005 [cited by applicant]
US 6931530B2 · Pham et al. · 2005 [cited by applicant]
US 7185192B1 · Kahn · 2007 [cited by examiner]
US 7315903B1 · Bowden · 2008 [cited by applicant]
US 7467142B2 · Sinn et al. · 2008 [cited by applicant]
US 7716240B2 · Lim · 2010 [cited by applicant]
US 7895445B1 · Albanese et al. · 2011 [cited by applicant]
US 8490163B1 · Harsell et al. · 2013 [cited by applicant]
US 8640188B2 · Riley et al. · 2014 [cited by applicant]
US 8996482B1 · Singh et al. · 2015 [cited by applicant]
US 9118617B1 · Giroux et al. · 2015 [cited by applicant]
US 9805209B2 · Naglost et al. · 2017 [cited by applicant]
US 10380568B1 · Rogers et al. · 2019 [cited by applicant]
US 10614466B2 · Palermo et al. · 2020 [cited by applicant]
US 10831883B1 · Pawar et al. · 2020 [cited by applicant]
US 10878079B2 · Vepa · 2020 [cited by examiner]
US 10983963B1 · Venkatasubramanian et al. · 2021 [cited by applicant]
US 20010018746A1 · Lin · 2001 [cited by examiner]
US 20020010679A1 · Felsher · 2002 [cited by applicant]
US 20030154401A1 · Hartman · 2003 [cited by examiner]
US 20040255137A1 · Ying · 2004 [cited by applicant]
US 20050004831A1 · Najmi et al. · 2005 [cited by applicant]
US 20050081063A1 · Patrick · 2005 [cited by examiner]
US 20050108563A1 · Becker et al. · 2005 [cited by applicant]
US 20050210212A1 · Nagasoe · 2005 [cited by examiner]
US 20050257245A1 · Patrick · 2005 [cited by examiner]
US 20060149408A1 · Speeter et al. · 2006 [cited by applicant]
US 20060168584A1 · Dawson et al. · 2006 [cited by applicant]
US 20060248069A1 · Qing et al. · 2006 [cited by applicant]
US 20070055658A1 · Hsiao et al. · 2007 [cited by applicant]
US 20070100768A1 · Boccon-Gibod et al. · 2007 [cited by applicant]
US 20070168461A1 · Moore · 2007 [cited by applicant]
US 20070204078A1 · Boccon-Gibod et al. · 2007 [cited by applicant]
US 20070208607A1 · Amerasinghe · 2007 [cited by examiner]
US 20070256124A1 · Ih · 2007 [cited by examiner]
US 20080153599A1 · Atashband · 2008 [cited by examiner]
US 20090007021A1 · Hayton · 2009 [cited by examiner]
US 20090125712A1 · Janes · 2009 [cited by applicant]
US 20090249060A1 · Dossett et al. · 2009 [cited by applicant]
US 20090328167A1 · O'Mahony · 2009 [cited by applicant]
US 20100064354A1 · Irvine · 2010 [cited by applicant]
US 20110258605A1 · Ioannou · 2011 [cited by examiner]
US 20110313930A1 · Bailey, Jr. · 2011 [cited by applicant]
US 20120017263A1 · Dillaway et al. · 2012 [cited by applicant]
US 20120117638A1 · Radier et al. · 2012 [cited by applicant]
US 20120296888A1 · Anthony · 2012 [cited by examiner]
US 20130096943A1 · Carey et al. · 2013 [cited by applicant]
US 20130117313A1 · Miao et al. · 2013 [cited by applicant]
US 20130232474A1 · Leclair et al. · 2013 [cited by applicant]
US 20140096199A1 · Dave et al. · 2014 [cited by applicant]
US 20140325587A1 · Nilsson et al. · 2014 [cited by applicant]
US 20150012966A1 · Tandon · 2015 [cited by examiner]
US 20150220659A1 · Rissanen · 2015 [cited by applicant]
US 20150227749A1 · Schincariol et al. · 2015 [cited by applicant]
US 20150302421A1 · Caton et al. · 2015 [cited by applicant]
US 20160034305A1 · Shear · 2016 [cited by examiner]
US 20160254904A1 · Hjelm et al. · 2016 [cited by applicant]
US 20160337964A1 · Mochizuki · 2016 [cited by applicant]
US 20160352751A1 · Perrufel et al. · 2016 [cited by applicant]
US 20160373474A1 · Sood · 2016 [cited by examiner]
US 20160381185A1 · Vadivel · 2016 [cited by examiner]
US 20170060924A1 · Fitzhardinge · 2017 [cited by applicant]
US 20170093878A1 · Rodniansky · 2017 [cited by applicant]
US 20170099320A1 · Ratier · 2017 [cited by applicant]
US 20170116552A1 · Deodhar · 2017 [cited by examiner]
US 20170323089A1 · Duggal · 2017 [cited by examiner]
US 20170352245A1 · Maher et al. · 2017 [cited by applicant]
US 20180033009A1 · Goldman et al. · 2018 [cited by applicant]
US 20180039658A1 · Carey et al. · 2018 [cited by applicant]
US 20180060365A1 · Mujumdar et al. · 2018 [cited by applicant]
US 20180115554A1 · Dyon et al. · 2018 [cited by applicant]
US 20180137297A1 · Drias · 2018 [cited by applicant]
US 20180137401A1 · Kumar et al. · 2018 [cited by applicant]
US 20180183897A1 · Singhal · 2018 [cited by applicant]
US 20180189517A1 · Larson et al. · 2018 [cited by applicant]
US 20180367663A1 · Nagao · 2018 [cited by applicant]
US 20190229922A1 · Galloway · 2019 [cited by examiner]
US 20190327271A1 · Saxena et al. · 2019 [cited by applicant]
US 20190335003A1 · Wade et al. · 2019 [cited by applicant]
US 20200099515A1 · Hopkins · 2020 [cited by applicant]
US 20200228500A1 · Olumofin · 2020 [cited by applicant]
US 20200327252A1 · McFall et al. · 2020 [cited by applicant]
US 20220052993A1 · Zhuravlev et al. · 2022 [cited by applicant]
JP 2009181598 · 2009 [cited by applicant]
JP 2012239048 · 2012 [cited by applicant]
WO WO0133349A2 · 2001 [cited by examiner]
Ferraiolo, David, Serban Gavrila, and Wayne Jansen. “On the unification of access control and data services.” In Proceedings of the 2014 IEEE 15th International Conference on Information Reuse and Integration (IEEE IRI … [cited by examiner]
Ryutov, Tatyana, Clifford Neuman, Kim Dongho, and Zhou Li. “Integrated access control and intrusion detection for web servers.” IEEE transactions on parallel and distributed systems 14, No. 9 (2003): 841-850. (Year: 200… [cited by examiner]
Hao, Luoyao, Vibhas Naik, and Henning Schulzrinne. “DBAC: Directory-based access control for geographically distributed IoT systems.” In IEEE INFOCOM 2022—IEEE Conference on Computer Communications, pp. 360-369. IEEE, 2… [cited by examiner]
Pernici, Barbara. “Objects with roles. ”In Proceedings of the ACM SIGOIS and IEEECSTC—A conference on Office information systems, pp. 205-215. 1990.(Year: 1990). [cited by applicant]
Majetic, Ivo, and ErnstL. Leiss. “Authorization and revocation in object-oriented databases.”IEEE transactions on knowledge and data engineering 9, No. 4 (1997): 668-672. (Year: 1997). [cited by applicant]
Karjoth, Gu“nter. ”The authorization service of tivoli policy director. In Seventeenth Annual Computer Security Applications Conference, pp. 319-328. IEEE, 2001. (Year: 2001). [cited by applicant]
NPL—Scheffler—Privacy Enforcement with Data Owner Defined Policies. Published Sep. 2, 2013. [cited by applicant]
NPL—Rajasekar et al.—A Prototype Rule-Based Distributed Data Management System. Published Jan. 2006. [cited by applicant]
Oracle@ Database, Net Services Reference, 12c Release 1 (12.1), E17611-13, Dec. 2014, 232 pages. (Year: 2014). [cited by applicant]
Notice of Allowance dated Dec. 22, 2022 issued in U.S. Appl. No. 16/778,934. [cited by applicant]
Final Office Action dated Aug. 11, 2022 issued in U.S. Appl. No. 16/778,934. [cited by applicant]
Non-Final Office Action dated Mar. 15, 2022 issued in U.S. Appl. No. 16/778,934. [cited by applicant]