IP Library Granted Patent US 12,450,381
Granted Patent B2
US 12,450,381 · App. 18/488,428 · Granted Oct 21, 2025

Compacted object expression for user permissions

Inventors: Rufeng Peng (Walldorf, DE); Mingfeng Lu (Walldorf, DE); You Li (Walldorf, DE)
Assignee: SAP SE
G06F21/6218H04L9/3236G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,381
App. No.
18/488,428
Granted
Oct 21, 2025
Kind
B2
Abstract

Provided is a system that can validate a permission of a user with respect to data based on a hash value generated from a permission object. The hash value may be hashed more than one during the validation process. In one example, the method may include storing application data in a data store, receiving a request to access the application data within the data store, the request comprising an identifier of a user and a hash value, retrieving a permissions object of the user and hashing fields of data within the permission object to generate a locally-generated hash value, determining whether or not the locally-generated hash value is a match to the hash value in the received request, and in response to the determination that the locally-generated hash value is the match, granting permission to the application data in the data store.

Claims (49)

1. A computing system comprising:

a data store configured to store application data; and

a processor configured to:

receive a request from a user interface to access the application data within the data store, the request comprising an identifier of a user and a hash value,

retrieve a permissions object of the user and execute a predefined hash function on content from the permission object to generate a locally-generated hash value,

determine whether or not the locally-generated hash value is a match to the hash value in the received request,

execute a mixing algorithm on words of content from the permission object to mix together characters of content from the words into a single string value, and execute the predefined hash function on the single string value to generate the locally-generated hash value, and

in response to the determination that the locally-generated hash value is the match, grant permission to the application data in the data store.

2. The computing system of claim 1 , wherein the processor is configured to execute the predefined hash function on values stored in a plurality of fields of the permission object to generate a single string value.

3. The computing system of claim 2 , wherein the permissions object comprises a plurality of permissions defined for the user by a software application with respect to the application data stored in the data store.

4. A computing system comprising:

a data store configured to store application data; and

a processor configured to:

receive a request from a user interface to access the application data within the data store, the request comprising an identifier of a user and a hash value,

retrieve a permissions object of the user and execute a predefined hash function on content from the permission object to generate a locally-generated hash value,

determine whether or not the locally-generated hash value is a match to the hash value in the received request,

execute a second predefined hash function on the content from the permission object to generate a second locally-generated hash value, in response to the determination that the locally-generated hash value is not the match, and

in response to the determination that the locally-generated hash value is the match, grant permission to the application data in the data store.

5. The computing system of claim 4 , wherein the processor is configured to determine whether or not the second locally-generated hash value is a match to the hash value in the received request, and in response to a determination of the match, grant permission to the application data stored in the data store.

6. The computing system of claim 4 , wherein the processor is configured to determine whether or not the second locally-generated hash value is a match to the hash value in the received request, and in response to a determination that the match does not exist, deny permission to the application data stored in the data store.

7. The computing system of claim 4 , wherein the processor is configured to add a leading character to the locally-generated hash value and add a different leading character to the second locally-generated hash value.

8. A method comprising:

storing application data in a data store;

receiving a request to access the application data within the data store, the request comprising an identifier of a user and a hash value;

retrieving a permissions object of the user and hashing fields of data within the permission object to generate a locally-generated hash value;

determining whether or not the locally-generated hash value is a match to the hash value in the received request; and

in response to the determination that the locally-generated hash value is the match, granting permission to the application data in the data store;

wherein hashing comprises mixing together characters of words of content from the permission object in an interspersed pattern to create a single string value, and executing a predefined hash function on the single string value to generate the locally-generated hash value.

9. The method of claim 8 , wherein the hashing further comprises executing a predefined hash function on a plurality of values stored in a plurality of fields of the permission object to generate a single string value.

10. The method of claim 8 , wherein the permissions object comprises a plurality of permissions defined for the user by a software application with respect to the application data stored in the data store.

11. A method comprising:

storing application data in a data store;

receiving a request to access the application data within the data store, the request comprising an identifier of a user and a hash value;

retrieving a permissions object of the user and hashing fields of data within the permission object to generate a locally-generated hash value;

determining whether or not the locally-generated hash value is a match to the hash value in the received request;

granting permission to the application data in the data store in response to the determination that the locally-generated hash value is the match; and

executing a second predefined hash function on additional content from the permission object to generate a second locally-generated hash value, in response to the determination that the locally-generated hash value is not the match.

12. The method of claim 11 , wherein the method further comprises determining whether or not the second locally-generated hash value is a match to the hash value in the received request, and in response to a determination of the match, granting permission to the application data stored in the data store.

13. The method of claim 11 , wherein the method further comprises determining whether or not the second locally-generated hash value is a match to the hash value in the received request, and in response to a determination that the match does not exist, deny permission to the application data stored in the data store.

14. The method of claim 11 , wherein the method further comprises adding a leading character to the locally-generated hash value and adding a different leading character to the second locally-generated hash value.

15. A computer-readable medium comprising program instructions which, when executed by a processor, cause a computer to perform a method comprising:

storing application data in a data store;

receiving a request to access the application data within the data store, the request comprising an identifier of a user and a hash value;

retrieving a permissions object of the user and hashing fields of data within the permission object to generate a locally-generated hash value;

determining whether or not the locally-generated hash value is a match to the hash value in the received request;

mixing together characters of words of content from the permission object in an interspersed pattern to create a single string value, and executing a predefined hash function on the single string value to generate the locally-generated hash value; and

in response to the determination that the locally-generated hash value is the match, granting permission to the application data in the data store.

16. The computer-readable medium of claim 15 , wherein the executing comprises executing a predefined hash function on a plurality of values stored in a plurality of fields of the permission object to generate a single string value.

17. The computer-readable medium of claim 15 , wherein the permissions object comprises a plurality of permissions defined for the user by a software application with respect to the application data stored in the data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: PENG, RUFENG; LU, MINGFENG; LI, YOU
To: SAP SE
Reel/Frame 065252/0235 →
Continuity (1)
Related Publication 20250124154A1 · Apr 17, 2025
References Cited (20)
US 8566952B1 · Michaels · 2013 [cited by examiner]
US 11570180B1 · Fitzpatrick · 2023 [cited by examiner]
US 12223065B1 · Fathalla · 2025 [cited by examiner]
US 20210036854A1 · Dunjic · 2021 [cited by examiner]
US 20210112067A1 · Pandey · 2021 [cited by examiner]
US 20210124835A1 · Tran · 2021 [cited by examiner]
US 20210209077A1 · Snellman · 2021 [cited by examiner]
US 20220051756A1 · Notz · 2022 [cited by examiner]
US 20230283613A1 · Pandey · 2023 [cited by examiner]
US 20240015148A1 · Martini · 2024 [cited by examiner]
US 20250053510A1 · Colgrove · 2025 [cited by examiner]
US 20250053676A1 · Yang · 2025 [cited by examiner]
US 20250077498A1 · Hudson · 2025 [cited by examiner]
US 20250077699A1 · Ramos · 2025 [cited by examiner]
US 20250094386A1 · Higgins · 2025 [cited by examiner]
US 20250094403A1 · Chintala · 2025 [cited by examiner]
US 20250110919A1 · Vasudeva · 2025 [cited by examiner]
US 20250124152A1 · Suresh · 2025 [cited by examiner]
US 20250124156A1 · Beecham · 2025 [cited by examiner]
US 20250131118A1 · Zaharia · 2025 [cited by examiner]