IP Library › Granted Patent US 12,255,896
Granted Patent B2
US 12,255,896 · App. 18/328,990 · Granted Mar 18, 2025

Security systems, methods, and computer program products for information integration platform

Inventors: Jody Hupton Palmer (Cambridge, CA); Alexander Lilko (Maple, CA); Steve Molloy (Chambly, CA)
Assignee: Open Text SA ULC
H04L63/10G06F16/27G06F16/9038G06F16/9535G06F21/10G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,896
App. No.
18/328,990
Granted
Mar 18, 2025
Kind
B2
Abstract

An information integration system may include a set of integration services embodied on one or more server machines in a computing environment. The set of integration services may include connectors communicatively connected to disparate information systems. The connectors may be configured for integrating data stored in the disparate information systems utilizing a common model employed by the set of integration services. The common model may overlay, augment, integrate, or otherwise utilize a content management interoperability services data model and may include common property definitions and a common security model. The common security model may include permissions particularly defined for use by the set of integration services. These common property definitions and permissions may be uniquely defined and utilized by the information integration system.

Claims (56)

1. A method, comprising:

responsive to a search request from a device of a user, performing, by a computer, an inbound check on the search request, the inbound check comprising:

determining, utilizing a principals service, what principal is associated with the user across disparate information systems operating in a computing environment;

determining, utilizing a unified index, what content in the disparate information systems the user is allowed to access per association between the user and the principal and based on any respective permission indexed to the principal, the unified index storing permissions indexed from the disparate information systems; and

modifying the search request based on what the user is allowed to access as thus determined, the modifying comprising:

adding a filter to the search request; and

producing an augmented search request;

communicating, by the computer, the augmented search request to the disparate information systems, wherein each of the disparate information systems processes the augmented search request and returns a search result;

performing, by the computer, an outbound check on search results returned from the disparate information systems, the outbound check comprising:

filtering, utilizing an authorization service, the search results returned from the disparate information systems based on what the user is authorized to view, the filtering producing filtered search results; and

providing, by the computer, the filtered search results to the user for presentation on the device.

2. The method according to claim 1 , wherein the inbound check and the outbound check are defined in a security model.

3. The method according to claim 2 , wherein the security model is part of a common model, wherein the common model comprises common model permissions, and wherein the determining what content in the disparate information systems the user is allowed to access further comprises mapping the common model permissions with repository-specific permissions from the disparate information systems.

4. The method according to claim 3 , wherein the common model is employed by integration services that are communicatively connected to the disparate information systems.

5. The method according to claim 1 , wherein the principals service returns a state for each of the disparate information systems and wherein the inbound check further comprises:

determining, based on the state for each of the disparate information systems, whether any of the disparate information systems supports the inbound check.

6. The method according to claim 5 , wherein the filter added to the search request excludes any of the disparate information systems that does not support the inbound check.

7. The method according to claim 1 , wherein the filtering utilizes an authorization post filter based on authorization information provided by the authorization service.

8. A system, comprising:

a processor;

a non-transitory computer-readable medium; and

instructions stored on the non-transitory computer-readable medium and translatable by the processor for:

responsive to a search request from a device of a user, performing an inbound check on the search request, the inbound check comprising:

determining, utilizing a principals service, what principal is associated with the user across disparate information systems operating in a computing environment;

determining, utilizing a unified index, what content in the disparate information systems the user is allowed to access per association between the user and the principal and based on any respective permission indexed to the principal, the unified index storing permissions indexed from the disparate information systems; and

modifying the search request based on what the user is allowed to access as thus determined, the modifying comprising:

adding a filter to the search request; and

producing an augmented search request;

communicating the augmented search request to the disparate information systems, wherein each of the disparate information systems processes the augmented search request and returns a search result;

performing an outbound check on search results returned from the disparate information systems, the outbound check comprising:

filtering, utilizing an authorization service, the search results returned from the disparate information systems based on what the user is authorized to view, the filtering producing filtered search results; and

providing the filtered search results to the user for presentation on the device.

9. The system of claim 8 , wherein the inbound check and the outbound check are defined in a security model.

10. The system of claim 9 , wherein the security model is part of a common model, wherein the common model comprises common model permissions, and wherein the determining what content in the disparate information systems the user is allowed to access further comprises mapping the common model permissions with repository-specific permissions from the disparate information systems.

11. The system of claim 10 , wherein the common model is employed by integration services that are communicatively connected to the disparate information systems.

12. The system of claim 8 , wherein the principals service returns a state for each of the disparate information systems and wherein the inbound check further comprises:

determining, based on the state for each of the disparate information systems, whether any of the disparate information systems supports the inbound check.

13. The system of claim 12 , wherein the filter added to the search request excludes any of the disparate information systems that does not support the inbound check.

14. The system of claim 8 , wherein the filtering utilizes an authorization post filter based on authorization information provided by the authorization service.

15. A computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

responsive to a search request from a device of a user, performing an inbound check on the search request, the inbound check comprising:

determining, utilizing a principals service, what principal is associated with the user across disparate information systems operating in a computing environment;

determining, utilizing a unified index, what content in the disparate information systems the user is allowed to access per association between the user and the principal and based on any respective permission indexed to the principal, the unified index storing permissions indexed from the disparate information systems; and

modifying the search request based on what the user is allowed to access as thus determined, the modifying comprising:

adding a filter to the search request; and

producing an augmented search request;

communicating the augmented search request to the disparate information systems, wherein each of the disparate information systems processes the augmented search request and returns a search result;

performing an outbound check on search results returned from the disparate information systems, the outbound check comprising:

filtering, utilizing an authorization service, the search results returned from the disparate information systems based on what the user is authorized to view, the filtering producing filtered search results; and

providing the filtered search results to the user for presentation on the device.

16. The computer program product of claim 15 , wherein the inbound check and the outbound check are defined in a security model.

17. The computer program product of claim 16 , wherein the security model is part of a common model, wherein the common model comprises common model permissions, and wherein the determining what content in the disparate information systems the user is allowed to access further comprises mapping the common model permissions with repository-specific permissions from the disparate information systems.

18. The computer program product of claim 17 , wherein the common model is employed by integration services that are communicatively connected to the disparate information systems.

19. The computer program product of claim 15 , wherein the principals service returns a state for each of the disparate information systems and wherein the inbound check further comprises:

determining, based on the state for each of the disparate information systems, whether any of the disparate information systems supports the inbound check.

20. The computer program product of claim 19 , wherein the filter added to the search request excludes any of the disparate information systems that does not support the inbound check.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALMER, JODY HUPTON; LILKO, ALEXANDER; MOLLOY, STEVE
To: OPEN TEXT S.A.
Reel/Frame 063987/0868 →
IP BUSINESS SALE AGREEMENT Recorded Jun 20, 2023
From: OPEN TEXT S.A.
To: OT IP SUB, LLC
Reel/Frame 064022/0308 →
CERTIFICATE OF CONTINUANCE Recorded Jun 20, 2023
From: OT IP SUB, LLC
To: IP OT SUB ULC
Reel/Frame 064022/0322 →
CERTIFICATE OF AMALGAMATION Recorded Jun 20, 2023
From: IP OT SUB ULC
To: OPEN TEXT SA ULC
Reel/Frame 064022/0331 →
Continuity (6)
Continuation 17222933 · Apr 5, 2021
Continuation 16739957 · Jan 10, 2020
Continuation 15471669 · Mar 28, 2017
Continuation 14210536 · Mar 14, 2014
Provisional Application 61782984 · Mar 14, 2013
Related Publication 20230319042A1 · Oct 5, 2023
References Cited (59)
US 5910987A · Ginter · 1999 [cited by applicant]
US 5920861A · Hall · 1999 [cited by applicant]
US 6112181A · Shear · 2000 [cited by applicant]
US 7095854B1 · Ginter · 2006 [cited by applicant]
US 8311863B1 · Kemp · 2012 [cited by examiner]
US 8983994B2 · Neels · 2015 [cited by applicant]
US 10282372B2 · Dimassimo · 2019 [cited by applicant]
US 11709906B2 · Leclerc et al. · 2023 [cited by applicant]
US 11991179B2 · Palmer et al. · 2024 [cited by applicant]
US 20020048369A1 · Ginter · 2002 [cited by applicant]
US 20030028509A1 · Sah · 2003 [cited by examiner]
US 20030088573A1 · Stickler · 2003 [cited by applicant]
US 20030088593A1 · Stickler · 2003 [cited by applicant]
US 20030093434A1 · Stickler · 2003 [cited by applicant]
US 20030097365A1 · Stickler · 2003 [cited by applicant]
US 20030105746A1 · Stickler · 2003 [cited by applicant]
US 20030193994A1 · Stickler · 2003 [cited by applicant]
US 20030221171A1 · Rust · 2003 [cited by applicant]
US 20040186827A1 · Anick · 2004 [cited by examiner]
US 20050050054A1 · Clark · 2005 [cited by applicant]
US 20050177716A1 · Ginter · 2005 [cited by applicant]
US 20060165040A1 · Rathod · 2006 [cited by examiner]
US 20070050467A1 · Borrett · 2007 [cited by applicant]
US 20070100768A1 · Boccon-Gibod · 2007 [cited by applicant]
US 20070130137A1 · Oliver · 2007 [cited by examiner]
US 20070180470A1 · Gill · 2007 [cited by applicant]
US 20070185814A1 · Boccon-Gibod · 2007 [cited by applicant]
US 20070204078A1 · Boccon-Gibod · 2007 [cited by applicant]
US 20070276759A1 · Ginter · 2007 [cited by applicant]
US 20080072290A1 · Metzer · 2008 [cited by examiner]
US 20080263009A1 · Buettner · 2008 [cited by examiner]
US 20080275844A1 · Buzsaki · 2008 [cited by examiner]
US 20090055355A1 · Brunner · 2009 [cited by examiner]
US 20090106234A1 · Siedlecki · 2009 [cited by applicant]
US 20090327094A1 · Elien · 2009 [cited by applicant]
US 20100070753A1 · Kido · 2010 [cited by applicant]
US 20110040983A1 · Grzymala-Busse · 2011 [cited by examiner]
US 20110208822A1 · Rathod · 2011 [cited by examiner]
US 20120069131A1 · Abelow · 2012 [cited by examiner]
US 20140032926A1 · Prem · 2014 [cited by examiner]
US 20140074629A1 · Rathod · 2014 [cited by examiner]
US 20140222753A1 · Gladwin · 2014 [cited by examiner]
US 20140236663A1 · Smith · 2014 [cited by examiner]
US 20160373891A1 · Ramer · 2016 [cited by examiner]
US 20230214460A1 · Lilko et al. · 2023 [cited by applicant]
US 20230325448A1 · Leclerc et al. · 2023 [cited by applicant]
US 20240314132A1 · Palmer et al. · 2024 [cited by applicant]
Office Action issued for U.S. Appl. No. 17/878,618, mailed Aug. 31, 2023, 10 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 17/878,618, mailed Feb. 7, 2024, 11 pages. [cited by applicant]
Office Action issued for U.S. Appl. No. 18/182,457, mailed Jan. 5, 2024, 12 pages. [cited by applicant]
Office Action issued for U.S. Appl. No. 18/328,872, mailed Dec. 21, 2023, 10 pages. [cited by applicant]
Office Action issued for European Patent Application No. 21 216 461.0, Jun. 26, 2023, 3 pages. [cited by applicant]
Office Action issued for European Patent Application No. 21 216 461.0, Feb. 9, 2024, 7 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/182,457, mailed Jul. 17, 2024, 14 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/182,457, mailed Sep. 5, 2024, 15 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/328,872, mailed Aug. 29, 2024, 8 pages. [cited by applicant]
Office Action issued for U.S. Appl. No. 18/631,208, mailed Nov. 21, 2024, 19 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/182,457, mailed Jan. 10, 2025, 15 pages. [cited by applicant]
Notice of Allowance issued for U.S. Appl. No. 18/328,872, mailed Jan. 13, 2025, 8 pages. [cited by applicant]
Cited By (1)
US 12,301,577