IP Library › Granted Patent US 12,314,445
Granted Patent B2
US 12,314,445 · App. 18/499,461 · Granted May 27, 2025

Chaining, triggering, and enforcing entitlements

Inventors: Yisroel Gershon Taber (Raanana, IL); Tomer Turgeman (Tel Aviv, IL); Ittay Levy Ophir (Giv'atayim, IL); Lev Rozenbaum (Kfar-Saba, IL); Nerya Cohen (Elkana, IL)
Assignee: Microsoft Technology Licensing, LLC
G06F21/6254G06F9/3836G06F21/6272G06F21/645
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,314,445
App. No.
18/499,461
Granted
May 27, 2025
Kind
B2
Abstract

Embodiments are directed to techniques for enforcing entitlements used by data privacy pipelines. When a data consumer requests to trigger a pipeline that relies on an entitlement, an enforcement mechanism may operate to verify the data consumer's triggering of the pipeline will satisfy the entitlements. A rules engine may access all root entities of the pipeline that require an entitlement, load all contracts and/or corresponding pipelines that reference one of the root entities, and search for one valid access path through the loaded contracts/pipelines. If multiple contracts and/or multiple access paths allow access to a particular root entity, various conflict rules may be configured to choose which contract and access path to use. If all root entities have a valid access path, the constrained environment may execute the requested pipeline using the identified access path for each root entity.

Claims (57)

1. A data trustee environment comprising:

one or more computer storage media storing computer-useable instructions that, when used by one or more computing devices, cause the one or more computing devices to perform operations comprising:

receiving a request from a data consumer to trigger a data privacy pipeline required to execute within a data trustee environment;

identifying all root entities of the data privacy pipeline requiring an entitlement from a grantor that is not a participant to the data privacy pipeline;

loading contracts that govern access to the root entities within the data trustee environment;

for each root entity of the root entities, searching the contracts to identify a valid access path pursuant to an associated one of the contracts with which the data privacy pipeline can use the root entity while fulfilling constraints defined by the associated contract and applicable upon accessing the root entity, and while fulfilling policies defined by the associated contract and applicable to computations of the data privacy pipeline that are downstream from the root entity; and

based on each of the root entities having an identified valid access path pursuant to an identified associated one of the contracts, triggering execution of the data privacy pipeline within the data trustee environment using the identified valid access path and the associated identify contract to access each of the root entities, without exposing the root entities.

2. The data trustee environment of claim 1 , wherein identifying all root entities of the data privacy pipeline requiring an entitlement comprises accessing a digitized representation of the data privacy pipeline having an associated list, property, or metadata identifying the root entities.

3. The data trustee environment of claim 1 , the operations further comprising, prior to searching the contracts to identify a valid access path for each root entity, filtering out a set of the contracts that do not grant access to the data consumer based on an identity of the data consumer.

4. The data trustee environment of claim 1 , wherein searching the contracts for each root entity comprises, for each contract of the contracts governing access to the root entity:

identifying a potential access path having all computational steps that would be required to execute in the data trustee environment in order to trigger the data privacy pipeline in the data trustee environment using the contract to access the root entity; and

determining whether the potential access path would fulfill constraints defined by the contract and applicable upon accessing the root entity, and would fulfill policies defined by the contract and applicable to a set of the computational steps that are downstream from the root entity.

5. The data trustee environment of claim 1 , wherein searching the contracts for each root entity comprises, for each contract of the contracts governing access to the root entity:

identifying a potential access path having all computational steps that would be required to execute in the data trustee environment in order to trigger the data privacy pipeline in the data trustee environment using the contract to access the root entity; and

verifying the computational steps of the potential access path would satisfy applicable constraints and policies, without executing the computational steps.

6. The data trustee environment of claim 1 , wherein searching the contracts to identify a valid access path for each root entity comprises, evaluating computational steps of potential access paths without executing a first set of the computational steps, and conditionally executing a second set of the computational steps to evaluate a particular constraint or policy that is only capable of verification during runtime.

7. The data trustee environment of claim 1 , wherein searching the contracts to identify a valid access path for each root entity identifies a plurality of candidate contracts or a plurality of valid access paths for at least a first root entity of the root entities, the operations further comprising applying conflict rules to select one of the plurality of valid access paths as the identified valid access or select one of the plurality of candidate contracts as the identified associated contract for the first root entity.

8. One or more computer storage media storing computer-useable instructions that, when used by one or more computing devices, cause the one or more computing devices to perform operations comprising:

receiving a request from a data consumer to trigger a data privacy pipeline required to execute within a data trustee environment;

identifying all root entities of the data privacy pipeline requiring an entitlement from a grantor that is not a participant to the data privacy pipeline;

identifying a set of contracts governing access to the root entities within the data trustee environment and defining a valid access path for each of the root entities such that the data privacy pipeline can use the root entities while fulfilling constraints and policies defined by the set of contracts, the constraints applicable upon accessing the root entities, the policies applicable to computations of the data privacy pipeline that are downstream from the root entities; and

triggering execution of the data privacy pipeline within the data trustee environment using the identified set of the contracts to access the root entities, without exposing the root entities.

9. The one or more computer storage media of claim 8 , wherein identifying all root entities of the data privacy pipeline requiring an entitlement comprises accessing a digitized representation of the data privacy pipeline having an associated list, property, or metadata identifying the root entities.

10. The one or more computer storage media of claim 8 , the operations further comprising:

loading a plurality of contracts that govern access to the root entities within the data trustee environment;

filtering out a subset of the contracts that do not grant access to the data consumer based on an identity of the data consumer, leaving a remaining set of the contracts;

searching the remaining set of contracts to identify the set of contracts governing access to the root entities.

11. The one or more computer storage media of claim 8 , wherein identifying the set of contracts defining a valid access path for each of the root entities comprises, for each root entity and each contract governing access to the root entity:

identifying a potential access path having all computational steps that would be required to execute in the data trustee environment in order to trigger the data privacy pipeline in the data trustee environment using the contract to access the root entity; and

determining whether the potential access path would fulfill constraints defined by the contract and applicable upon accessing the root entity, and would fulfill policies defined by the contract and applicable to a set of the computational steps that are downstream from the root entity.

12. The one or more computer storage media of claim 8 , wherein identifying the set of contracts defining a valid access path for each of the root entities comprises, for each root entity and each contract governing access to the root entity:

identifying a potential access path having all computational steps that would be required to execute in the data trustee environment in order to trigger the data privacy pipeline in the data trustee environment using the contract to access the root entity; and

verifying the computational steps of the potential access path would satisfy applicable constraints and policies, without executing the computational steps.

13. The one or more computer storage media of claim 8 , wherein identifying the set of contracts defining a valid access path for each of the root entities comprises evaluating computational steps of potential access paths without executing a first set of the computational steps, and conditionally executing a second set of the computational steps to evaluate a particular constraint or policy that is only capable of verification during runtime.

14. The one or more computer storage media of claim 8 , wherein identifying the set of contracts defining a valid access path comprises, for at least a first root entity of the root entities:

identifying a plurality of candidate contracts or a plurality of valid access paths governing access to the first root entity; and

applying conflict rules to identify a single contract and a single valid access path for the first root entity based on at least one of the plurality of candidate contracts or the plurality of valid access paths.

15. A method comprising:

receiving a request from a data consumer, to trigger a data privacy pipeline required to execute within a constrained environment that is inaccessible to the data consumer, and to export from the constrained environment data generated by the data privacy pipeline;

determining that executing the data privacy pipeline within the constrained environment would satisfy an associated entitlement to use a root entity of the data privacy pipeline within the constrained environment, the associated entitlement specifying a constraint on accessing the root entity within the constrained environment and a policy on downstream computations within the constrained environment deriving from the root entity;

determining that the data consumer has permission to export the data from the constrained environment; and

triggering execution of the data privacy pipeline within the constrained environment using the root entity pursuant to the associated entitlement, without exposing the root entity.

16. The method of claim 15 , the method further comprising:

identifying all root entities of the data privacy pipeline requiring a corresponding entitlement from a grantor that is not a participant to the data privacy pipeline;

wherein determining that executing the data privacy pipeline within the constrained environment would satisfy the associated entitlement to use the root entity comprises searching contracts that govern access to the root entities within the constrained environment to identify a valid access path for each of the root entities.

17. The method of claim 15 , the method further comprising identifying all root entities of the data privacy pipeline requiring a corresponding entitlement from a grantor that is not a participant to the data privacy pipeline by accessing a digitized representation of the data privacy pipeline having an associated list, property, or metadata identifying the root entities.

18. The method of claim 15 , the method further comprising:

identifying all root entities of the data privacy pipeline requiring a corresponding entitlement from a grantor that is not a participant to the data privacy pipeline;

loading a plurality of contracts that govern access to the root entities within the constrained environment; and

filtering out a subset of the plurality of contracts that do not grant access to the data consumer based on an identity of the data consumer, leaving a remaining set of the contracts;

wherein determining that executing the data privacy pipeline within the constrained environment would satisfy the associated entitlement to use the root entity comprises searching the remaining set of contracts to identify a valid access path for the root entity.

19. The method of claim 15 , wherein determining that executing the data privacy pipeline within the constrained environment would satisfy the associated entitlement to use the root entity comprises, for each of a plurality of contracts governing access to the root entity within the constrained environment:

identifying a potential access path having all computational steps that would be required to execute in the constrained environment in order to trigger the data privacy pipeline in the constrained environment using the contract to access the root entity; and

determining whether the potential access path would fulfill constraints defined by the contract and applicable upon accessing the root entity, and would fulfill policies defined by the contract and applicable to a set of the computational steps that are downstream from the root entity.

20. The method of claim 15 , wherein determining that executing the data privacy pipeline within the constrained environment would satisfy the associated entitlement to use the root entity comprises, for each of a plurality of contracts governing access to the root entity within the constrained environment:

identifying a potential access path having all computational steps that would be required to execute in the constrained environment in order to trigger the data privacy pipeline in the constrained environment using the contract to access the root entity; and

verifying the computational steps of the potential access path would satisfy applicable constraints and policies, without executing the computational steps.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2023
From: COHEN, NERYA; ROZENBAUM, LEV; OPHIR, ITTAY LEVY; TABER, YISROEL GERSHON; TURGEMAN, TOMER
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 065437/0637 →
Continuity (3)
Continuation 17743341 · May 12, 2022
Continuation 17009414 · Sep 1, 2020
Related Publication 20240061958A1 · Feb 22, 2024
References Cited (131)
US 5907692A · Wise · 1999 [cited by applicant]
US 8621649B1 · Van Dijk et al. · 2013 [cited by applicant]
US 9338008B1 · Kirkland et al. · 2016 [cited by applicant]
US 10496653B1 · Epshteyn · 2019 [cited by applicant]
US 10642832B1 · Neumann · 2020 [cited by examiner]
US 11620179B1 · Tian · 2023 [cited by applicant]
US 20020026464A1 · Jones · 2002 [cited by applicant]
US 20050154729A1 · Gutsche · 2005 [cited by applicant]
US 20060282281A1 · Egetoft · 2006 [cited by applicant]
US 20090282045A1 · Hsieh · 2009 [cited by examiner]
US 20100162212A1 · Stall et al. · 2010 [cited by applicant]
US 20100192084A1 · Ingermanson · 2010 [cited by applicant]
US 20100242088A1 · Thomas · 2010 [cited by applicant]
US 20110085667A1 · Berrios · 2011 [cited by applicant]
US 20110307557A1 · Kadashevich · 2011 [cited by applicant]
US 20130179785A1 · Kim · 2013 [cited by applicant]
US 20130247204A1 · Schrecker · 2013 [cited by applicant]
US 20130268734A1 · Hotz · 2013 [cited by applicant]
US 20140007184A1 · Porras · 2014 [cited by applicant]
US 20140040979A1 · Barton et al. · 2014 [cited by applicant]
US 20140068732A1 · Hinton et al. · 2014 [cited by applicant]
US 20140082424A1 · Sanders · 2014 [cited by applicant]
US 20140373016A1 · Ruggiero · 2014 [cited by applicant]
US 20150271178A1 · Bhattacharya · 2015 [cited by applicant]
US 20150317490A1 · Carey · 2015 [cited by applicant]
US 20150319192A1 · Cabrera · 2015 [cited by applicant]
US 20160357778A1 · MacKenzie · 2016 [cited by applicant]
US 20170076113A1 · Mcnamara · 2017 [cited by applicant]
US 20170185752A1 · Lemay · 2017 [cited by applicant]
US 20170214696A1 · Cleaver et al. · 2017 [cited by applicant]
US 20170235645A1 · Theimer · 2017 [cited by examiner]
US 20170364568A1 · Reynolds et al. · 2017 [cited by applicant]
US 20170371881A1 · Reynolds · 2017 [cited by applicant]
US 20180007059A1 · Innes et al. · 2018 [cited by applicant]
US 20180032576A1 · Romero · 2018 [cited by examiner]
US 20180053012A1 · Myers · 2018 [cited by examiner]
US 20180060225A1 · Tao · 2018 [cited by applicant]
US 20180096028A1 · Masekera · 2018 [cited by applicant]
US 20180129585A1 · Martin · 2018 [cited by applicant]
US 20180157928A1 · Oliveira · 2018 [cited by applicant]
US 20180203701A1 · Nield · 2018 [cited by applicant]
US 20180210936A1 · Reynolds · 2018 [cited by examiner]
US 20180219674A1 · Mullins · 2018 [cited by applicant]
US 20180239639A1 · Novak · 2018 [cited by applicant]
US 20180262483A1 · Sharma · 2018 [cited by applicant]
US 20180262864A1 · Reynolds et al. · 2018 [cited by applicant]
US 20190058709A1 · Kempf et al. · 2019 [cited by applicant]
US 20190066052A1 · Boutros · 2019 [cited by applicant]
US 20190213346A1 · Friedman · 2019 [cited by examiner]
US 20190227910A1 · Raviv · 2019 [cited by applicant]
US 20190236598A1 · Padmanabhan · 2019 [cited by examiner]
US 20190303115A1 · Kelly et al. · 2019 [cited by applicant]
US 20190318198A1 · Griffin · 2019 [cited by applicant]
US 20190370370A1 · Wittern et al. · 2019 [cited by applicant]
US 20190370492A1 · Falchuk · 2019 [cited by applicant]
US 20200067789A1 · Khuti et al. · 2020 [cited by applicant]
US 20200167498A1 · Pridgen · 2020 [cited by applicant]
US 20200252210A1 · Sharfman · 2020 [cited by applicant]
US 20200265057A1 · Jolfaei · 2020 [cited by applicant]
US 20200311294A1 · Sim-Tang · 2020 [cited by applicant]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210272031A1 · Brannon · 2021 [cited by applicant]
US 20230281109A1 · Taber · 2023 [cited by applicant]
CN 102187314A · 2011 [cited by applicant]
CN 102708316A · 2012 [cited by applicant]
CN 102986190A · 2013 [cited by applicant]
CN 103532981A · 2014 [cited by applicant]
CN 104050201A · 2014 [cited by applicant]
CN 104205096A · 2014 [cited by applicant]
CN 103118053B · 2015 [cited by applicant]
CN 106797383A · 2017 [cited by applicant]
CN 108351807B · 2022 [cited by applicant]
EP 2116954A1 · 2009 [cited by applicant]
WO 2013132377A1 · 2013 [cited by applicant]
WO 2015165111A1 · 2015 [cited by applicant]
Poller et al., “An Asset to Security Modeling ?: Analyzing Stakeholder Collaborations Instead of Threats to Assets”, NSPW '14: Proceedings of the 2014 New Security Paradigms Workshop, pp. 69-82, Published: Sep. 15, 2014. [cited by examiner]
“Non Final Office Action Issued in U.S. Appl. No. 17/656,057”, Mailed Date: Nov. 13, 2023, 35 Pages. [cited by applicant]
“Notice of Allowance Issued in U.S. Appl. No. 17/743,341”, Mailed Date: Nov. 15, 2023, 12 Pages. [cited by applicant]
Xia, et al., “MeDShare: Trust-Less Medical Data Sharing Among Cloud Service Providers via Blockchain”, In Journal of IEEE Access, vol. 5, Jul. 24, 2017, pp. 14757-14767. [cited by applicant]
Office Action Received for Chinese Application No. 202080028567.3, mailed on Jan. 31, 2024, 14 pages (English Translation Provided). [cited by applicant]
Notice of Allowance mailed on Feb. 26, 2024, in U.S. Appl. No. 17/743,341, 2 pages. [cited by applicant]
Bajpai, “A Survey on Internet Performance Measurement Platforms and Related Standardization Efforts,” IEEE, 2015, pp. 1-32. [cited by applicant]
Batini, “Methodologies for Data Quality Assessment and Improvement,” ACM Computing Surveys, 1-52 Pages, Jul. 2009. [cited by applicant]
Liu, et al., “Mona: Secure Multi-Owner Data Sharing for Dynamic Groups in the Cloud,” in IEEE Transactions on Parallel and Distributed Systems, vol. 24, No. 6, Jun. 2013, pp. 1182-1191. [cited by applicant]
Non-Final Office Action mailed on Aug. 24, 2023, in U.S. Appl. No. 17/656,051, 37 pages. [cited by applicant]
Non-Final Office Action mailed on Dec. 8, 2023, in U.S. Appl. No. 17/656,066, 35 pages. [cited by applicant]
Non-Final Office Action mailed on Oct. 10, 2023, in U.S. Appl. No. 17/656,079, 31 pages. [cited by applicant]
Non-Final Office Action mailed on Oct. 27, 2023, in U.S. Appl. No. 17/656,082, 36 pages. [cited by applicant]
Notice of Allowance mailed on Dec. 20, 2023, in U.S. Appl. No. 17/684,210, 3 pages. [cited by applicant]
Notice of Allowance mailed on Dec. 27, 2023, in U.S. Appl. No. 17/684,204, 7 pages. [cited by applicant]
Notice of Allowance mailed on Nov. 8, 2023, in U.S. Appl. No. 17/684,210, 12 pages. [cited by applicant]
Office Action Received for European Application No. 20719528.0, mailed on Oct. 25, 2023, 6 pages. [cited by applicant]
Office Action Received for Chinese Application No. 202080029000.8, mailed on Mar. 1, 2024, 11 pages (English Translation Provided). [cited by applicant]
Dimitrova, et al., “Authorization-Aware Optimization for MultiProvider Queries,” Proceedings of the 34th ACM/SIGAPP Symposium on Applied Computing, 2019, pp. 431-438. [cited by applicant]
Final Office Action mailed on Jun. 6, 2024, in U.S. Appl. No. 17/656,082, 35 pages. [cited by applicant]
Final Office Action mailed on Jun. 21, 2024, in U.S. Appl. No. 17/656,062, 34 pages. [cited by applicant]
Final Office Action mailed on Jun. 21, 2024, in U.S. Appl. No. 17/656,066, 34 pages. [cited by applicant]
Final Office Action mailed on Mar. 1, 2024, in U.S. Appl. No. 17/656,051, 33 pages. [cited by applicant]
Final Office Action mailed on Mar. 1, 2024, in U.S. Appl. No. 17/656,073, 34 pages. [cited by applicant]
Final Office Action mailed on Mar. 14, 2024, in U.S. Appl. No. 17/656,057, 35 pages. [cited by applicant]
Final Office Action mailed on Mar. 14, 2024, in U.S. Appl. No. 17/656,079, 36 pages. [cited by applicant]
First Examination Report Received for Indian Application No. 202117045001, mailed on Jan. 24, 2024, 07 pages. [cited by applicant]
First Examination Report received in Indian Application No. 202117044994, Jan. 15, 2024, 8 pages. [cited by applicant]
First Office Action Received for Chinese Application No. 202080028730.6, mailed on Apr. 25, 2024, 09 pages. (English Translation Provided). [cited by applicant]
First Office Action Received for Chinese Application No. 202080029251.6, mailed on Feb. 26, 2024, 12 pages (English Translation Provided). [cited by applicant]
Non-Final Office Action issued in U.S. Appl. No. 17/656,079, mailed on Jul. 19, 2024, 39 Pages. [cited by applicant]
Non-Final Office Action mailed on Apr. 1, 2024, in U.S. Appl. No. 17/684,189, 22 pages. [cited by applicant]
Non-Final Office Action mailed on Aug. 1, 2024, in U.S. Appl. No. 17/656,051, 34 pages. [cited by applicant]
Non-Final Office Action mailed on Aug. 2, 2024, in U.S. Appl. No. 17/656,057, 38 pages. [cited by applicant]
Non-Final Office Action mailed on Aug. 2, 2024, in U.S. Appl. No. 17/656,073, 38 pages. [cited by applicant]
Notice of Allowance mailed on May 13, 2024, in U.S. Appl. No. 17/684,204, 05 pages. [cited by applicant]
Notification to Grant Received for Chinese Application No. 202080029000.8, mailed on May 15, 2024, 4 pages. [cited by applicant]
Office Action Received for Chinese Application No. 202080029070.3, mailed on Jun. 28, 2024, 12 pages (English Translation Provided). [cited by applicant]
Office Action Received for Indian Application No. 202117044999, mailed Nov. 10, 2023, 08 pages. [cited by applicant]
Communication under Rule 71(3) received in European Application No. 20719528.0, mailed on Oct. 28, 2024, 8 pages. [cited by applicant]
Final Office Action mailed on Oct. 30, 2024, in U.S. Appl. No. 17/684,189, 20 pages. [cited by applicant]
Non-Final Office Action mailed on Dec. 8, 2023, in U.S. Appl. No. 17/656,062, 35 pages. [cited by applicant]
Notice of Grant Received for Chinese Application No. 202080028730.6, mailed on Sep. 24, 2024, 4 pages. (English Translation Provided). [cited by applicant]
Office Action Received for Chinese Application No. 202080029070.3, mailed on Sep. 10, 2024, 6 pages. (English Translation available). [cited by applicant]
Second Office Action Received for Chinese Application No. 202080028567.3, mailed on Oct. 12, 2024, 04 pages (English Translation Provided). [cited by applicant]
Zaharia, “Resilient Distributed Datasets: A Fault-Tolerant Abstraction for In-Memory Cluster Computing,” Proceedings of the 9th USENIX conference on Networked Systems Design and Implementation, 14 pages, Apr. 2012. [cited by applicant]
Non-Final Office Action mailed on Jan. 10, 2025, in U.S. Appl. No. 17/887,989, 36 pages. [cited by applicant]
Final Office Action mailed on Feb. 12, 2025, in U.S. Appl. No. 17/656,051, 37 pages. [cited by applicant]
Final Office Action mailed on Jan. 29, 2025, in U.S. Appl. No. 17/656,073, 40 Pages. [cited by applicant]
Final Office Action mailed on Jan. 29, 2025, in U.S. Appl. No. 17/656,057, 41 Pages. [cited by applicant]
Final Office Action mailed on Jan. 30, 2025, in U.S. Appl. No. 17/656,079, 42 pages. [cited by applicant]
Mao, et al., “A Survey on Mobile Edge Computing: The Communication Perspective”, arXiv: 1701.01090v4, Jun. 13, 2017, 37 pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 12, 2025, in U.S. Appl. No. 17/656,062, 36 pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 13, 2025, in U.S. Appl. No. 17/656,066, 37 pages. [cited by applicant]
Non-Final Office Action mailed on Feb. 27, 2025, in U.S. Appl. No. 17/656,082, 40 pages. [cited by applicant]
Decision to grant a European patent pursuant to Article 97(1) Received in European Patent Application No. 20719528.0, mailed on Mar. 27, 2025, 02 pages. [cited by applicant]
Cited By (1)
US 12,688,323