IP Library Granted Patent US 10,073,979
Granted Patent B2
US 10,073,979 · App. 14/616,562 · Granted Sep 11, 2018

Method, system, and program for an improved enterprise spatial system

Inventors: Tim A. Von Kaenel (Coto de Caza, CA); David Neil Dyrnaes (Newport Coast, CA); C. Suresh Kumar (Ladera Ranch, CA); Jared Paul Wayman (Laguna Niguel, CA); Jonathan David Goodwin (Laguna Niguel, CA); Craig Evan Trivelpiece (Newport Beach, CA); Joseph Mihalich (Rancho Santa Margarita, CA); Anthony Page Jenkins (Aliso Viejo, CA); Richard Hoyt Odom, Jr. (Charlottesville, VA); Mark Andrew Stier (Laguna Niguel, CA); Anne Janetta Obee (Santa Ana, CA)
Assignee: THE PARADIGM ALLIANCE, INC.
G06F21/604G06F17/30G06F17/30241G06Q40/08Y10S707/99933Y10S707/99945Y10S707/99948
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,073,979
App. No.
14/616,562
Granted
Sep 11, 2018
Kind
B2
Abstract

Disclosed is a method, system, and program for providing access to spatial data. A request for data is received. Enterprise and third party data are integrated. The integrated data is processed. Spatially referenced results are generated using the processed data. The spatially referenced results are returned in response to the request.

Claims (47)

1. A method for access control, comprising:

controlling, with a processor of a computer, access to a data set associated with a data layer using a layer definition table, a user table, a resource access control list table, and an application definition table, wherein the layer definition table has a layer identifier column that maps to a resource identifier column of the resource access control list table, and wherein the resource access control list table has a user identifier column that maps to a user identifier column of the user table and has an entry in an access type column that points to a row of the application definition table, by:

receiving a request, from a user having a user identifier, to access the data set associated with the data layer having a data layer identifier;

accessing a resource access control list entry of the resource access control list table to determine whether the user has access to the data layer based on whether there is a first match of a user identifier of the user identifier column of the resource access control list entry and the user identifier of the user and a second match of a resource identifier of the resource identifier column of the resource access control list entry and the data layer identifier of the data layer;

in response to determining that there is the first match and the second match, providing access to the data layer by:

locating a layer definition table entry in the layer definition table using the data layer identifier of the data layer;

identifying a data store in the layer definition table entry; and

retrieving data for the data set from the data store; and

in response to determining that the resource access control list entry does not specify the data layer identifier, denying access to the data layer.

2. The method of claim 1 , further comprising:

filtering the data set using a data filter in the layer definition table entry.

3. The method of claim 1 , further comprising:

rendering the data set using a rendering specification.

4. The method of claim 1 , further comprising:

obtaining access credentials from the layer definition table entry to access a data store string the data set.

5. A system for access control, comprising:

a processor; and

a storage device connected to the processor, wherein the storage device has stored thereon a program, and wherein the processor is configured to execute instructions of the program to perform operations, wherein the operations comprise:

controlling access to a data set associated with a data layer using a layer definition table, a user table, a resource access control list table, and an application definition table, wherein the layer definition table has a layer identifier column that maps to a resource identifier column of the resource access control list table, and wherein the resource access control list table has a user identifier column that maps to a user identifier column of the user table and has an entry in an access type column that points to a row of the application definition table, by:

receiving a request, from a user having a user identifier, to access the data set associated with the data layer having a data layer identifier;

accessing a resource access control list entry of the resource access control list table to determine whether the user has access to the data layer based on whether there is a first match of a user identifier of the user identifier column of the resource access control list entry and the user identifier of the user and a second match of a resource identifier of the resource identifier column of the resource access control list entry and the data layer identifier of the data layer;

in response to determining that there is the first match and the second match, providing access to the data layer by:

locating a layer definition table entry in the layer definition table using the data layer identifier of the data layer;

identifying a data store in the layer definition table entry; and

retrieving data for the data set from the data store; and

in response to determining that the resource access control list entry does not specify the data layer identifier, denying access to the data layer.

6. The system of claim 5 , wherein the operations further comprise:

filtering the data set using a data filter in the layer definition table entry.

7. The system of claim 5 , wherein the operations further comprise:

rendering the data set using a rendering specification.

8. The system of claim 5 , wherein the operations further comprise:

obtaining access credentials from the layer definition table entry to access a data store string the data set.

9. An article of manufacture comprising a non-transitory computer readable medium storing a program for access control, wherein the program, when executed by a processor of a computer, is configured to perform:

controlling access to a data set associated with a data layer using a layer definition table, a user table, a resource access control list table, and an application definition table, wherein the layer definition table has a layer identifier column that maps to a resource identifier column of the resource access control list table, and wherein the resource access control list table has a user identifier column that maps to a user identifier column of the user table and has an entry in an access type column that points to a row of the application definition table, by:

receiving a request, from a user having a user identifier, to access the data set associated with the data layer having a data layer identifier;

accessing a resource access control list entry of the resource access control list table to determine whether the user has access to the data layer based on whether there is a first match of a user identifier of the user identifier column of the resource access control list entry and the user identifier of the user and a second match of a resource identifier of the resource identifier column of the resource access control list entry and the data layer identifier of the data layer;

in response to determining that there is the first match and the second match, providing access to the data layer by:

locating a layer definition table entry in the layer definition table using the data layer identifier of the data layer;

identifying a data store in the layer definition table entry; and

retrieving data for the data set from the data store; and

in response to determining that the resource access control list entry does not specify the data layer identifier, denying access to the data layer.

10. The article of manufacture of claim 9 , wherein the program, when executed by the processor of the computer, is configured to perform:

filtering the data set using a data filter in the layer definition table entry.

11. The article of manufacture of claim 9 , wherein the program, when executed by the processor of the computer, is configured to perform:

rendering the data set using a rendering specification.

12. The article of manufacture of claim 9 , wherein the program, when executed by the processor of the computer, is configured to perform:

obtaining access credentials from the layer definition table entry to access a data store string the data set.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2020
From: THE PARADIGM ALLIANCE, INC.
To: CELERITASWORKS, LLC
Reel/Frame 052268/0969 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2016
From: QUESTERRA LLC
To: THE PARADIGM ALLIANCE, INC.
Reel/Frame 040067/0976 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2016
From: VON KAENEL, TIM A.; DYRNAES, DAVID NEIL; KUMAR, C. SURESH; WAYMAN, JARED PAUL; GOODWIN, JONATHAN DAVID; TRIVELPIECE, CRAIG EVAN; MIHALICH, JOSEPH; JENKINS, ANTHONY PAGE; STIER, MARK ANDREW; OBEE, ANNE JANETTA; ODOM, RICHARD H., JR.
To: QUESTERRA CORPORATION
Reel/Frame 040423/0384 →
CHANGE OF NAME Recorded Oct 19, 2016
From: QUESTERRA CORP.
To: QUESTERRA, LLC
Reel/Frame 040423/0557 →
Continuity (7)
Division 13178452 · Jul 7, 2011
Division 11458663 · Jul 19, 2006
Division 10388666 · Mar 14, 2003
Provisional Application 60364807 · Mar 16, 2002
Provisional Application 60433597 · Dec 16, 2002
Provisional Application 60437990 · Jan 6, 2003
Related Publication 20150193630A1 · Jul 9, 2015
Cited By (2)
US 12,639,469 US 12,681,778