IP Library Granted Patent US 12,437,101
Granted Patent B2
US 12,437,101 · App. 17/464,928 · Granted Oct 7, 2025

Privilege graph-based representation of data access authorizations

Inventors: Tarun Thakur (Los Gatos, CA); Maohua Lu (Fremont, CA)
Assignee: Veza Technologies, Inc.
G06F21/6236G06F16/21G06F16/9024G06F21/604G06F21/6218G06F21/6227G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,101
App. No.
17/464,928
Granted
Oct 7, 2025
Kind
B2
Abstract

The technology disclosed herein enables representation of data access authorizations using a privilege graph. In a particular embodiment, a method includes identifying first attributes of a first user. The method further includes traversing nodes of a privilege graph using the first attributes to determine subsequent nodes until one or more nodes representing a first subset of environments of a plurality of data environments is reached. The method also includes authorizing the first user to access the first subset.

Claims (64)

1. A method for privilege graph-based representation of data access authorizations, the method comprising:

identifying first attributes of a first user;

performing a traversal of nodes of a privilege graph using the first attributes to determine subsequent nodes until one or more first nodes representing a first subset of environments of a plurality of data environments is reached, wherein the traversal passes through at least one parent node of the one or more first nodes, wherein the at least one parent node represents one or more privileges, and wherein the first user has the one or more privileges with respect to the first subset of environments as indicated by the traversal passing through the at least one parent node before reaching the first subset of environments; and

authorizing the first user to access the first subset.

2. The method of claim 1 , comprising:

identifying second attributes of a second user;

performing a second traversal of the nodes of the privilege graph using the second attributes to determine subsequent nodes until one or more second nodes representing a second subset of environments of the plurality of data environments is reached, wherein the second subset is different than the first subset; and

authorizing the second user to access the second subset.

3. The method of claim 1 , comprising:

displaying the privilege graph to an administrator authorized to view the privilege graph.

4. The method of claim 3 , comprising:

receiving a Boolean search query from the administrator; and

displaying a portion of the privilege graph that satisfies the Boolean search query.

5. The method of claim 1 , comprising:

determining that the first user should have access to a first data environment that is not included in the first subset;

identifying an attribute change to the first attributes that would allow the first user to access the first data environment; and

applying the attribute change to the first attributes.

6. The method of claim 5 , comprising:

presenting the attribute change to an administrator; and

receiving confirmation that the attribute change should be applied, wherein applying the attribute change occurs in response to the confirmation.

7. The method of claim 5 , comprising:

displaying the privilege graph to an administrator after the privilege graph is updated to reflect that the attribute change has been applied to the first attributes.

8. The method of claim 1 , comprising:

receiving one or more alert parameters from an administrator, wherein the alert parameters, when satisfied, trigger an alert to the administrator; and

presenting the alert to the administrator in response to determining that the privilege graph satisfies the alert parameters.

9. The method of claim 1 , comprising:

determining that an anomaly exists in the first subset relative to other users having similar attributes to the first attributes; and

notifying an administrator about the anomaly.

10. The method of claim 1 , wherein the first user is a human, an application, or a computing system.

11. An apparatus comprising:

one or more computer readable storage media;

a processing system operatively coupled with the one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media that, when read and executed by the processing system, direct the processing system to:

identify first attributes of a first user;

perform a traversal of nodes of a privilege graph using the first attributes to determine subsequent nodes until one or more first nodes representing a first subset of environments of a plurality of data environments is reached, wherein the traversal passes through at least one parent node of the one or more first nodes, wherein the at least one parent node represents one or more privileges, and wherein the first user has the one or more privileges with respect to the first subset of environments as indicated by the traversal passing through the at least one parent node before reaching the first subset of environments; and

authorize the first user to access the first subset.

12. The apparatus of claim 11 , wherein the program instructions direct the processing system to:

identify second attributes of a second user;

perform a second traversal of nodes of the privilege graph using the second attributes to determine subsequent nodes until one or more second nodes representing a second subset of environments of the plurality of data environments is reached, wherein the second subset is different than the first subset; and

authorize the second user to access the second subset.

13. The apparatus of claim 11 , wherein the program instructions direct the processing system to:

display the privilege graph to an administrator authorized to view the privilege graph.

14. The apparatus of claim 13 , wherein the program instructions direct the processing system to:

receive a Boolean search query from the administrator; and

display a portion of the privilege graph that satisfies the Boolean search query.

15. The apparatus of claim 11 , wherein the program instructions direct the processing system to:

determine that the first user should have access to a first data environment that is not included in the first subset;

identify an attribute change to the first attributes that would allow the first user to access the first data environment; and

apply the attribute change to the first attributes.

16. The apparatus of claim 15 , wherein the program instructions direct the processing system to:

present the attribute change to an administrator; and

receive confirmation that the attribute change should be applied, wherein applying the attribute change occurs in response to the confirmation.

17. The apparatus of claim 15 , wherein the program instructions direct the processing system to:

display the privilege graph to an administrator after the privilege graph is updated to reflect that the attribute change has been applied to the first attributes.

18. The apparatus of claim 11 , wherein the program instructions direct the processing system to:

receive one or more alert parameters from an administrator, wherein the alert parameters, when satisfied, trigger an alert to the administrator; and

present the alert to the administrator in response to determining that the privilege graph satisfies the alert parameters.

19. The apparatus of claim 11 , wherein the program instructions direct the processing system to:

determine that an anomaly exists in the first subset relative to other users having similar attributes to the first attributes; and

notify an administrator about the anomaly.

20. One or more non-transitory computer readable storage media having program instructions stored thereon that, when read and executed by a processing system, direct the processing system to:

identify first attributes of a first user;

perform a traversal of nodes of a privilege graph using the first attributes to determine subsequent nodes until one or more first nodes representing a first subset of environments of a plurality of data environments is reached, wherein the traversal passes through at least one parent node of the one or more first nodes, wherein the at least one parent node represents one or more privileges, and wherein the first user has the one or more privileges with respect to the first subset of environments as indicated by the traversal passing through the at least one parent node before reaching the first subset of environments; and

authorize the first user to access the first subset.

Assignments (2)
CHANGE OF NAME Recorded Aug 1, 2022
From: COOKIE AI, INC.
To: VEZA TECHNOLOGIES, INC.
Reel/Frame 061037/0393 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2022
From: THAKUR, TARUN; LU, MAOHUA
To: COOKIE.AI, INC.
Reel/Frame 059669/0642 →
Continuity (3)
Provisional Application 63073751 · Sep 2, 2020
Provisional Application 63067193 · Aug 18, 2020
Related Publication 20220067186A1 · Mar 3, 2022
References Cited (27)
US 8965991B1 · McKinnon et al. · 2015 [cited by applicant]
US 9146733B1 · McKinnon et al. · 2015 [cited by applicant]
US 10733055B1 · Grisby · 2020 [cited by applicant]
US 20020186260A1 · Young · 2002 [cited by applicant]
US 20050138420A1 · Sampathkumar · 2005 [cited by applicant]
US 20100082865A1 · Kirshenbaum · 2010 [cited by applicant]
US 20100257206A1 · Brown · 2010 [cited by applicant]
US 20130144893A1 · Voigt et al. · 2013 [cited by applicant]
US 20140298481A1 · Gilroy · 2014 [cited by applicant]
US 20160087960A1 · Pleau · 2016 [cited by examiner]
US 20180013777A1 · DiValentin · 2018 [cited by applicant]
US 20180075252A1 · Rasmussen · 2018 [cited by applicant]
US 20180159876A1 · Park et al. · 2018 [cited by applicant]
US 20180196928A1 · Gilpin et al. · 2018 [cited by applicant]
US 20180211056A1 · Delisser · 2018 [cited by examiner]
US 20180307853A1 · Mehta · 2018 [cited by applicant]
US 20190384926A1 · Wu et al. · 2019 [cited by applicant]
US 20200074338A1 · Florentino · 2020 [cited by examiner]
US 20200125543A1 · Zhang · 2020 [cited by applicant]
US 20200134362A1 · Luo et al. · 2020 [cited by applicant]
US 20200175071A1 · Ogrinz et al. · 2020 [cited by applicant]
US 20200280564A1 · Badawy et al. · 2020 [cited by applicant]
US 20200334377A1 · Turgeman et al. · 2020 [cited by applicant]
US 20200358778A1 · Gopinathapai et al. · 2020 [cited by applicant]
US 20210201198A1 · Li et al. · 2021 [cited by applicant]
US 20210243190A1 · Bargury · 2021 [cited by applicant]
US 20230351287A1 · Thompson · 2023 [cited by applicant]