IP Library › Granted Patent US 11,785,017
Granted Patent B2
US 11,785,017 · App. 17/992,737 · Granted Oct 10, 2023

Enforcing granular access control policy

Inventors: Peter Wilczynski (San Francisco, CA); Arseny Bogomolov (Arlington, VA); Alexander Mark (New York, NY); Teofana Hadzhiganeva (Bethesda, MD); Kevin Ng (New York, NY); Nathaniel Klein (Washington, DC); Sharon Hao (Redwood City, CA)
Assignee: Palantir Technologies Inc.
H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,017
App. No.
17/992,737
Filed
Nov 22, 2022
Granted
Oct 10, 2023
Kind
B2
Art Unit
2495
USPC
726/1
Abstract

An example method of enforcing granular access policy for embedded artifacts comprises: detecting an association of an embedded artifact with a resource container; associating the embedded artifact with at least a subset of an access control policy associated with the resource container; and responsive to receiving an access request to access the embedded artifact, applying the access control policy associated with the resource container for determining whether the access request is grantable.

Claims (49)

1. A method, comprising:

detecting, by a computer system, an association of a first artifact with a first resource container;

modifying an access control policy of the first artifact to comply with an access control policy of the first resource container;

detecting an association of a second artifact with a first artifact acting as a second resource container, wherein the second artifact acts as an embedded artifact with respect to the first artifact;

modifying an access control policy of the second artifact to comply with the modified access control policy of the second resource container provided by the first artifact, wherein the modified access control policy of the second artifact includes an intersection of the modified access control policy of the second resource container provided by the first artifact and an initial access control policy of the second artifact;

responsive to receiving an access request to access the second artifact, applying the modified access control policy of the second artifact for determining whether the access request is grantable; and

responsive to determining that the access request is grantable, granting the access request.

2. The method of claim 1 , wherein modifying an access control policy of the second artifact further comprises:

modifying an access control policy pointer stored by metadata of the second artifact to reference the modified access control policy of the second resource container provided by the first artifact.

3. The method of claim 1 , wherein the second artifact comprises a first part associated with the modified access control policy of the second artifact and a second part associated with the modified access control policy of the second artifact.

4. The method of claim 1 , wherein applying the modified access control policy of the second artifact further comprises:

identifying a permission associated, by the access control policy, with a user group associated with a user that initiated the access request; and

determining whether the permission matches an access type specified by the access request.

5. The method of claim 1 , further comprising:

creating a copy of the modified access control policy of the second artifact;

associating the embedded artifact with the copy of the modified access control policy of the second artifact; and

disassociating the second artifact from the first artifact acting as the second resource container.

6. A system, comprising:

memory; and

one or more processors coupled to the memory, the one or more processors configured to:

detect an association of a first artifact with a first resource container;

modify an access control policy of the first artifact to comply with an access control policy of the first resource container;

detect an association of a second artifact with a first artifact acting as a second resource container, wherein the second artifact acts as an embedded artifact with respect to the first artifact;

modify an access control policy of the second artifact to comply with the modified access control policy of the second resource container provided by the first artifact, wherein the modified access control policy of the second artifact includes an intersection of the modified access control policy of the second resource container provided by the first artifact and an initial access control policy of the second artifact;

responsive to receiving an access request to access the second artifact, apply the modified access control policy of the second artifact for determining whether the access request is grantable; and

responsive to determining that the access request is grantable, grant the access request.

7. The system of claim 6 , wherein modifying an access control policy of the second artifact further comprises:

modifying an access control policy pointer stored by metadata of the second artifact to reference the modified access control policy of the second resource container provided by the first artifact.

8. The system of claim 6 , wherein the second artifact comprises a first part associated with the modified access control policy of the second artifact and a second part associated with the modified access control policy of the second artifact.

9. The system of claim 6 , wherein applying the modified access control policy of the second artifact further comprises:

identifying a permission associated, by the access control policy, with a user group associated with a user that initiated the access request; and

determining whether the permission matches an access type specified by the access request.

10. The system of claim 6 , wherein the one or more processors are further configured to:

create a copy of the modified access control policy of the second artifact;

associate the embedded artifact with the copy of the modified access control policy of the second artifact; and

disassociate the second artifact from the first artifact acting as the second resource container.

11. A non-transitory computer-readable storage medium comprising executable instructions that, when executed by a computer system, cause the computer system to:

detect an association of a first artifact with a first resource container;

modify an access control policy of the first artifact to comply with an access control policy of the first resource container;

detect an association of a second artifact with a first artifact acting as a second resource container, wherein the second artifact acts as an embedded artifact with respect to the first artifact;

modify an access control policy of the second artifact to comply with the modified access control policy of the second resource container provided by the first artifact, wherein the modified access control policy of the second artifact includes an intersection of the modified access control policy of the second resource container provided by the first artifact and an initial access control policy of the second artifact;

responsive to receiving an access request to access the second artifact, apply the modified access control policy of the second artifact for determining whether the access request is grantable; and

responsive to determining that the access request is grantable, grant the access request.

12. The non-transitory computer-readable storage medium of claim 11 , wherein modifying an access control policy of the second artifact further comprises:

modifying an access control policy pointer stored by metadata of the second artifact to reference the modified access control policy of the second resource container provided by the first artifact.

13. The non-transitory computer-readable storage medium of claim 11 , wherein the second artifact comprises a first part associated with the modified access control policy of the second artifact and a second part associated with the modified access control policy of the second artifact.

14. The non-transitory computer-readable storage medium of claim 11 , wherein applying the modified access control policy of the second artifact further comprises:

identifying a permission associated, by the access control policy, with a user group associated with a user that initiated the access request; and

determining whether the permission matches an access type specified by the access request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2022
From: WILCZYNSKI, PETER; BOGOMOLOV, ARSENY; MARK, ALEXANDER; HADZHIGANEVA, TEOFANA; NG, KEVIN; KLEIN, NATHANIEL; HAO, SHARON
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 061865/0899 →
Continuity (4)
Division 17386060 · Jul 27, 2021
Continuation 16803104 · Feb 27, 2020
Continuation 16521179 · Jul 24, 2019
Related Publication 20230093504A1 · Mar 23, 2023