IP Library Granted Patent US 12,406,078
Granted Patent B2
US 12,406,078 · App. 18/206,135 · Granted Sep 2, 2025

Call location based access control of query to database

Inventors: Bhushit Joshipura (Bangalore, IN); Soumyadipta Das (Bangalore, IN); Arun Yogeesh (Milpitas, CA); Navaneeth Ashok (Bangalore, IN)
Assignee: SONICWALL INC.
G06F21/6218G06F16/144G06F21/31G06F21/44G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,078
App. No.
18/206,135
Granted
Sep 2, 2025
Kind
B2
Abstract

The present disclosure is directed to protecting data stored at a database in a manner that increases data protection minimizing performance reductions. Apparatus and methods consistent with the present disclosure may collect information from user devices from which user inputs are received when collecting data that may be used to protect database data. Methods consistent with the present disclosure may identify code paths traversed, pages of program code where actions were initiated, and functions associated with those actions. This information may be cross-referenced with a set of data, constraints, rules, or command parameters when data associated with a database query is initially associated with an “allow” action or a “deny” action. This information may also be used to evaluate whether newly generated database queries should be allowed to be sent to a database server or to identify whether a database request should be blocked.

Claims (42)

1. A method for identifying data stored at database servers, the method comprising:

collecting a set of inputs over a communication network from a computing device, wherein the set of inputs is collected in association with a set of credentials sent by the computing device;

authenticating the computing device as a part of a predetermined set of computing devices allowed to access the database server in accordance with a set of rules based on the set of credentials;

generating a database query to a database server based on the set of inputs;

identifying one ore more parameters including at least one of code location data of an origin of the database query before the database query is sent to the database server;

applying, in response to the identification of the at least one code location data, the set of rules to the authenticated computing device for access to the database server, wherein applying the set of rules includes cross-referencing the identified parameters of the origin of the database query with one or more query origin locations of the set of rules, the identifying that the set of inputs corresponds to known denied queries when the set of inputs corresponds to data associated with a deny action that prevents the database query from being sent to the database server based on the cross-referenced parameters; and

blocking the database query from being sent to the database server based on the deny action identified by the application of the set of rules.

2. The method of claim 1 , further comprising receiving a set of access control information associated with the database request, the set of access control information comprising the set of rules.

3. The method of claim 2 , further comprising updating the set of access control information that includes information for a new rule, and enforcing the new rule by allowing the database query to be generated in accordance with the new rule.

4. The method of claim 1 , further comprising identifying whether the set of inputs corresponds to known allowed queris or the known denied queries based on execution of a set of program code at a program code page.

5. The method of claim 1 , wherein the set of rules are included in an access control list identifying that a first set of database queries is permitted to be processed by the database server and that a second set of database queries is prevented from being processed by the database server.

6. The method of claim 1 , wherein the collected set of inputs includes collected information regarding the computing device.

7. The method of claim 6 , further comprising:

storing the collected information regarding the computing device in a memory with information that identifies that the computing device is a suspicious device;

receiving a second set of inputs; and

identifying that the suspicious device provided the second set of inputs.

8. The method of claim 7 , further comprising preventing a second database request from being generated from the second set of inputs based on the identification that the suspicious device provided the second set of inputs.

9. A non-transitory computer-readable storage medium having embodied thereon a program for implementing a method for identifying data stored at database servers, the method comprising:

collecting a set of inputs over a communication network from a computing device, wherein the set of inputs is collected in association with a set of credentials sent by the computing device;

authenticating the computing device as a part of a predetermined set of computing devices allowed to access the database server in accordance with a set of rules based on the set of credentials;

generating a database query to a database server based on the set of inputs;

identifying one or more parameters including at least one of code location data of an origin of the database query before the database query is sent to the database server;

applying, in response to the identifiction of the at least one code location data, the set of rules to the authenticated computing device for access to the database server, wherein applying the set of rules includes cross-referencing the identified parameters of the origin of the database query with one or more query origin locations of the set of rules, and identifying that the set of inputs corresponds to known denied queries when the set of inputs corresponds to data associated with a deny action that prevents the database query from being sent to the database server based on the cross-referenced parameters; and

blocking the database query from being sent to the database server based on the deny action identified by the application of the set of rules.

10. The non-transitory computer-readable storage medium of claim 9 , further comprising instructions executable to receive a set of access control information associated with the database request, the set of access control information comprising the set of rules.

11. The non-transitory computer-readable storage medium of claim 10 , further comprising instructions executable to update the set of access control information that includes information for a new rule, and enforcing the new rule by allowing the database query to be generated in accordance with the new rule.

12. The non-transitory computer-readable storage medium of claim 9 , further comprising instructions executable to identify whether the set of inputs corresponds to known allowed queries or the known denied queries based on execution of a set of program code at a program code page.

13. The non-transitory computer-readable storage medium of claim 9 , wherein the set of rules are included in an access control list identifying that a first set of database queries is permitted to be processed by the database server and that a second set of database queries is prevented from being processed by the database server.

14. The non-transitory computer-readable storage medium of claim 9 , wherein the collected set of inputs includes collected information regarding the computing device.

15. The non-transitory computer-readable storage medium of claim 14 , further comprising instructions executable to:

store the collected information regarding the computing device in a memory with information that identifies that the computing device is a suspicious device;

receive a second set of inputs; and

identify that the suspicious device provided the second set of inputs.

16. The non-transitory computer-readable storage medium of claim 15 , further comprising instructions executable to prevent a second database request from being generated from the second set of inputs based on the identification that the suspicious device provided the second set of inputs.

17. A system for identifying data stored at database servers, the system comprising:

a communication interface that communicates over a communication network with a computing device, wherein the communication interface collects a set of inputs in association with a set of credentials sent by the computing device; and

a processor that executes instructions stored in memory, wherein the processor executes the instructions to:

authenticate the computing device as a part of a predetermined set of computing devices allowed to access the database server in accordance with a set of rules based on the set of credentials;

generate a database query to a database server based on the set of inputs;

identify one or more parameters including at least one of code location data of an origin of the database query before the database query is sent to the database server;

apply, in response to the identifiction of the at least one code location data, the set of rules to the authenticated computing device for access to the database, wherein applying the set of rules includes cross-referencing the identified parameters of the origin of the database query with one or more query origin locations of the set of rules, and identifying that the set of inputs corresponds to known denied queries when the set of inputs corresponds to data associated with a deny action that prevents the database query from being sent to the database server based on the cross-referenced parameters; and

block the database query from being sent to the database server based on the deny actions identified by the application of the set of rules.

Assignments (2)
FIRST LIEN IP SUPPLEMENT Recorded Jun 30, 2025
From: SONICWALL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 071758/0159 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2023
From: JOSHIPURA, BHUSHIT; DAS, SOUMYADIPTA; YOGEESH, ARUN; ASHOK, NAVANEETH
To: SONICWALL INC.
Reel/Frame 063862/0984 →
Continuity (3)
Continuation 16779262 · Jan 31, 2020
Provisional Application 62943132 · Dec 3, 2019
Related Publication 20230315890A1 · Oct 5, 2023
References Cited (58)
US 6820082B1 · Cook et al. · 2004 [cited by applicant]
US 7185357B1 · Wong · 2007 [cited by examiner]
US 7558796B1 · Bromwich et al. · 2009 [cited by applicant]
US 7962513B1 · Boles et al. · 2011 [cited by applicant]
US 8572037B2 · Kreuder et al. · 2013 [cited by applicant]
US 10212257B2 · Teodorescu et al. · 2019 [cited by applicant]
US 10726056B2 · Liu · 2020 [cited by examiner]
US 11030335B2 · Rodniansky · 2021 [cited by applicant]
US 11500824B1 · Tighe · 2022 [cited by examiner]
US 11675920B2 · Joshipura et al. · 2023 [cited by applicant]
US 20020161766A1 · Lawson et al. · 2002 [cited by applicant]
US 20040044655A1 · Cotner et al. · 2004 [cited by applicant]
US 20040225647A1 · Connelly · 2004 [cited by examiner]
US 20050177570A1 · Dutta et al. · 2005 [cited by applicant]
US 20050278276A1 · Andreev et al. · 2005 [cited by applicant]
US 20050289463A1 · Wu · 2005 [cited by examiner]
US 20070156666A1 · VanRiper et al. · 2007 [cited by applicant]
US 20070214497A1 · Montgomery et al. · 2007 [cited by applicant]
US 20080222134A1 · Krishnamurthy · 2008 [cited by examiner]
US 20080281809A1 · Anderson · 2008 [cited by examiner]
US 20090013194A1 · Mir et al. · 2009 [cited by applicant]
US 20090100004A1 · Andrei · 2009 [cited by examiner]
US 20090198679A1 · Lu · 2009 [cited by examiner]
US 20100036846A1 · Rafiq et al. · 2010 [cited by applicant]
US 20100332473A1 · Brodsky · 2010 [cited by examiner]
US 20120063593A1 · Camenisch et al. · 2012 [cited by applicant]
US 20120191748A1 · Gross · 2012 [cited by applicant]
US 20140244684A1 · Krishnamurthy · 2014 [cited by applicant]
US 20140280332A1 · Porterfield · 2014 [cited by applicant]
US 20150310067A1 · Svoboda · 2015 [cited by examiner]
US 20150317317A1 · Deng · 2015 [cited by examiner]
US 20160088676A1 · Zhao et al. · 2016 [cited by applicant]
US 20170063975A1 · Prakash et al. · 2017 [cited by applicant]
US 20170118221A1 · Hannel · 2017 [cited by examiner]
US 20180165366A1 · Kumar · 2018 [cited by applicant]
US 20180293399A1 · Chan · 2018 [cited by applicant]
US 20190042623A1 · Marcel · 2019 [cited by examiner]
US 20190058768A1 · Feijoo et al. · 2019 [cited by applicant]
US 20190081958A1 · Lee · 2019 [cited by examiner]
US 20190147108A1 · Liu · 2019 [cited by examiner]
US 20190205242A1 · Weis · 2019 [cited by examiner]
US 20190220607A1 · Dodor · 2019 [cited by examiner]
US 20190377891A1 · Krieger · 2019 [cited by examiner]
US 20200042647A1 · Pandey · 2020 [cited by examiner]
US 20200272750A1 · Hoeffer et al. · 2020 [cited by applicant]
US 20210026898A1 · Khillar · 2021 [cited by examiner]
US 20210165899A1 · Joshipura et al. · 2021 [cited by applicant]
US 20240086566A1 · Lim · 2024 [cited by examiner]
M. Davari and E. Bertino, “Access Control Model Extensions to Support Data Privacy Protection based on GDPR,” 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA, 2019, pp. 4017-4024 (Year: 2… [cited by examiner]
Shay, Richard, et al. “Don't even ask: Database access control throught query control.” ACM SIGMOD Record 47.3 (2019): 17-22. (Year: 2019). [cited by examiner]
U.S. Appl. No. 16/779,262 Office Action mailed Jul. 14, 2022. [cited by applicant]
U.S. Appl. No. 16/779,262 Final Office Action mailed Apr. 5, 2022. [cited by applicant]
U.S. Appl. No. 16/779,262 Office Action mailed Oct. 27, 2021. [cited by applicant]
U.S. Appl. No. 16/779,262 Notice of Allowance mailed Feb. 1, 2023. [cited by applicant]
Skrupsky et al., TamperProof: a server-agnostic defense for parameter tampering attacks on web applications. In Proceedings of the third ACM conference on Data and application security and privacy (CODASPY '13), pp. 129… [cited by applicant]
Puttaswamy et al., “Silverline: toward data confidentiality in storage-intensive cloud applications.” Proceedings of the 2nd ACM Symposium on Cloud Computing. 2011, pp. 1-13. (Year: 2011). [cited by applicant]
Cabaj et al., “Using software-defined networking for ransomware mitigation: the case of cryptowall.” IEEE Network 30.6 (2016): 14-20. (Year: 2016). [cited by applicant]
Zhuang et al. “ERi: A New Method for Ensuring Request Integrity.” Proceedings of the 9th EAi International Conference on Mobile Multimedia Communications. 2016, pp. 126-129. (Year: 2016). [cited by applicant]