IP Library Patent Application 18588845
Patent Application
App. No. 18/588,845

DYNAMIC DISTRIBUTED DATA ACCESS CONTROL

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/588,845
Abstract

Dynamic data access control may be provided by granting an access request for accessed data that is governed by an access policy. A hash tree may be generated for the accessed data. The hash tree may be stored in conjunction with the access policy, and the access policy may be related to uploaded data, based on the hash tree.

Claims (76)

1 . A computer program product, the computer program product being tangibly embodied on a non-transitory computer-readable storage medium and comprising instructions that, when executed by at least one computing device, are configured to cause the at least one computing device to:

grant an access request for accessed data, the accessed data governed by an access policy;

generate a hash tree for the accessed data;

store the hash tree in conjunction with the access policy; and

relate the access policy to uploaded data, based on the hash tree.

2 . The computer program product of claim 1 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

intercept the access request;

duplicate the accessed data to obtain an accessed data copy; and

generate the hash tree using the accessed data copy.

3 . The computer program product of claim 2 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

intercept the access request and duplicate the accessed data in conjunction with downloading the accessed data;

forward the accessed data copy to a user space; and

generate the hash tree at the user space.

4 . The computer program product of claim 3 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

intercept and duplicate the access request at a kernel space; and

forward the accessed data copy to the user space from the kernel space.

5 . The computer program product of claim 2 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

partition the accessed data copy into a plurality of partitions;

generate hash values from the plurality of partitions; and

generate the hash tree using the hash values.

6 . The computer program product of claim 1 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

generate the hash tree as a binary hash tree.

7 . The computer program product of claim 1 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

generate the hash tree as a Merkle tree.

8 . The computer program product of claim 1 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

store the hash tree using a graph database; and

link the access policy in a policy database to a root node of the hash tree in the graph database.

9 . The computer program product of claim 1 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

receive a storage request for storing the uploaded data;

generate a second hash tree of the uploaded data;

perform a comparison of the hash tree and the second hash tree; and

relate the access policy to the uploaded data, based on the comparison.

10 . The computer program product of claim 9 , wherein the instructions, when executed, are further configured to cause the at least one computing device to:

perform the comparison including determining whether a portion exceeding a threshold of the second hash tree matches a corresponding portion of the hash tree.

11 . A computer-implemented method, the method comprising:

granting an access request for accessed data, the accessed data governed by an access policy;

generating a hash tree for the accessed data;

storing the hash tree in conjunction with the access policy; and

relating the access policy to uploaded data, based on the hash tree.

12 . The method of claim 11 , further comprising:

intercepting the access request;

duplicating the accessed data to obtain an accessed data copy; and

generating the hash tree using the accessed data copy.

13 . The method of claim 12 , further comprising:

intercepting the access request and duplicate the accessed data in conjunction with downloading the accessed data;

forwarding the accessed data copy to a user space; and

generating the hash tree at the user space.

14 . The method of claim 12 , further comprising:

partition the accessed data copy into a plurality of partitions;

generate hash values from the plurality of partitions; and

generate the hash tree using the hash values.

15 . The method of claim 11 , further comprising:

storing the hash tree using a graph database; and

linking the access policy in a policy database to a root node of the hash tree in the graph database.

16 . The method of claim 11 , further comprising:

receiving a storage request for storing the uploaded data;

generating a second hash tree of the uploaded data;

performing a comparison of the hash tree and the second hash tree; and

relating the access policy to the uploaded data, based on the comparison.

17 . The method of claim 16 , further comprising:

performing the comparison including determining whether a portion exceeding a threshold of the second hash tree matches a corresponding portion of the hash tree.

18 . A system comprising:

at least one memory including instructions; and

at least one processor that is operably coupled to the at least one memory and that is arranged and configured to execute instructions that, when executed, cause the at least one processor to:

grant an access request for accessed data, the accessed data governed by an access policy;

generate a hash tree for the accessed data;

store the hash tree in conjunction with the access policy; and

relate the access policy to uploaded data, based on the hash tree.

19 . The system of claim 18 , wherein the instructions, when executed, are further configured to cause the at least one processor to:

store the hash tree using a graph database; and

link the access policy in a policy database to a root node of the hash tree in the graph database.

20 . The system of claim 18 , wherein the instructions, when executed, are further configured to cause the at least one processor to:

receive a storage request for storing the uploaded data;

generate a second hash tree of the uploaded data;

perform a comparison of the hash tree and the second hash tree; and

relate the access policy to the uploaded data, based on the comparison.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2025
From: GLENSKI, JENNIFER ANN; ANDERSON, ERIC MICHAEL; MUTHALAKUZHY THOMAS, DEVASIA ANTONY; NORDAHL, THEO VICTOR PEREZ
To: BMC SOFTWARE, INC.
Reel/Frame 070443/0462 →
GRANT OF SECOND LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0568 →
GRANT OF FIRST LIEN SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 13, 2024
From: BMC SOFTWARE, INC.; BLADELOGIC, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 069352/0628 →