IP Library › Granted Patent US 12,463,866
Granted Patent B1
US 12,463,866 · App. 18/534,887 · Granted Nov 4, 2025

Managing access control of data pipelines configured on a cloud platform

Inventors: Tian Lai (Louisville, KY); Yuan Yao (Louisville, KY); Bing Zhang (Louisville, KY)
Assignee: Humana Inc.
H04L41/0813G06F9/3867G06F16/2457G06F16/254G06N7/01H04L63/104H04L67/1097
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,866
App. No.
18/534,887
Granted
Nov 4, 2025
Kind
B1
Abstract

A system performs continuous delivery of a data pipeline on a cloud platform. The system receives a specification of the data pipeline comprising data pipeline units. The system generates a deployment package for each data pipeline unit for a cloud platform. The system provisions computing infrastructure on the cloud platform according to the system configuration of the data pipeline unit. The data pipeline may be implemented as a data mesh. The data pipeline generates one or more data models. The system receives a schema representing a modification in a data model based on a change in the requirements of a consumer system. The system determines the changes to the data pipeline based on the received schema and reconfigures the data pipeline to generate the modified data model. The system manages access control of data to minimize the exposure to data in case of accidental or malicious data breach.

Claims (70)

1 . A computer-implemented method for managing access control of a data pipeline having data pipeline units deployed on a cloud platform, the method comprising:

receiving a specification of the data pipeline;

generating instructions from the specification for configuring the data pipeline units at the cloud platform;

creating a connection with the cloud platform;

for each of the data pipeline units:

creating a runtime system account on the cloud platform having access to at least a storage unit of the data pipeline unit;

provisioning computing infrastructure on the cloud platform for the data pipeline unit;

creating a group of runtime system accounts including the runtime system account created for the data pipeline unit and each runtime system account created for a data pipeline unit receiving as input, data output by the data pipeline unit; and

granting read access to the output data of the data pipeline unit to each runtime system account in the group of runtime system accounts;

executing the data pipeline;

receiving a modified specification of a respective data pipeline unit of the data pipeline, wherein the respective data pipeline unit provides input to a first set of data pipeline units and is associated with a first group of system accounts having read access to output ports of the respective data pipeline unit;

reconfiguring the respective data pipeline unit to conform to the modified specification including by providing input to a second set of data pipeline units; and

modifying the group of system accounts having read access to the output ports of the respective data pipeline unit according to a difference between the second set of data pipeline units and the first set of data pipeline units.

2 . The method of claim 1 wherein:

modifying the group of system accounts comprises, responsive to determining that the second set of data pipeline units includes a particular data pipeline unit that is absent from the first set of data pipeline units, adding a system account corresponding to the particular data pipeline unit to the group of system accounts.

3 . The computer-implemented method of claim 1 , further comprising:

for each data pipeline unit of the plurality of data pipeline units, creating an infrastructure system account with privileges to configure resources associated with the data pipeline unit, wherein the infrastructure account is used for provisioning computing infrastructure on the cloud platform for the data pipeline unit.

4 . The computer-implemented method of claim 3 , wherein the infrastructure accounts and the runtime accounts are system accounts for use by system processes.

5 . The computer-implemented method of claim 1 wherein the respective data pipeline unit has a plurality of output ports comprising a first output port and a second output port, wherein the group of runtime system accounts is a first group of runtime system accounts associated with the first output port, wherein the first group of runtime system accounts includes runtime system accounts created for data pipeline units receiving as input, data output by the first output port of the respective data pipeline unit, the method further comprising:

creating a second group of runtime system accounts including the runtime system account created for the respective data pipeline unit and each runtime system account created for a data pipeline unit receiving as input, data output by the second output port of the respective data pipeline unit; and

granting read access to the output data of the second output port of the respective data pipeline unit to each system account of the second group.

6 . The computer-implemented method of claim 1 , wherein the data pipeline unit outputs a first data set categorized as having a first level of sensitivity and a second data set categorized as having a second level of sensitivity, wherein the group of runtime system accounts is a first group of runtime system accounts that has access to data categorized as having a first level of sensitivity, the method further comprising:

creating a second group of runtime system accounts including the runtime system account created for the respective data pipeline unit and one or more runtime system accounts created for a data pipeline unit receiving as input, data output by the respective data pipeline unit and categorized as having a second level of sensitivity.

7 . The computer-implemented method of claim 1 , further comprising:

for each data pipeline unit of at least a subset of the data pipeline units, creating a group of user accounts with privileges to access the output data generated by the data pipeline unit.

8 . The computer-implemented method of claim 1 , wherein generated instructions for the data pipeline comprise instructions for each data pipeline unit, wherein the instructions for a data pipeline unit comprise:

a system configuration for the data pipeline unit, the system configuration comprising instructions for configuring: one or more storage units on the cloud platform, a cluster of servers for execution of the data pipeline unit on the cloud platform, and one or more processing engines for executing instructions of the data pipeline unit; and

a deployment package comprising: data flow instructions for orchestrating the flow of data across resources of the data pipeline unit, and a transformation processing instructions package for performing the one or more data transformations of the data pipeline unit.

9 . The computer-implemented method of claim 1 , wherein an output of the data pipeline is one of:

a data stream that provides data elements at various time intervals; or

a batch input that provides a data set comprising a plurality of data elements at one point in time.

10 . The computer-implemented method of claim 1 , wherein the specification of a data pipeline unit comprises: inputs of the data pipeline unit, outputs of the data pipeline unit, one or more storage units used by the data pipeline unit, and one or more data transformations performed by the data pipeline unit.

11 . The computer-implemented method of claim 1 , wherein the plurality of data pipeline units comprises:

a set of input data pipeline units configured to receive input data processed by the data pipeline from one or more data sources;

a set of output data pipeline units configured to provide output data processed by the data pipeline to one or more consumer systems; and

a set of internal data pipeline units, wherein each internal data pipeline unit receives data output by a previous data pipeline unit and provides input to a next data pipeline unit of the data pipeline.

12 . A non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to perform the method of claim 1 .

13 . A computing system comprising:

a computer processor; and

a non-transitory computer readable storage medium storing instructions that when executed by a computer processor, cause the computer processor to perform the method of claim 1 .

14 . A computer-implemented method for managing access control of a data pipeline deployed on a cloud platform in accordance with a specification, the method comprising:

creating runtime system accounts on the cloud platform having access to at least storage unit of the data pipeline units;

provisioning computing infrastructure on the cloud platform for the data pipeline units;

creating groups of runtime system accounts including the runtime system accounts created for the data pipeline units and each of the runtime system accounts created for the data pipeline units receiving as input, data output by other of the data pipeline units;

granting read access to the output data of the data pipeline units to each of the runtime system accounts in the associated groups of runtime system accounts;

executing the data pipeline;

receiving a modified specification of a given data pipeline unit which provides input to a first set of data pipeline units and is associated with a first group of system accounts having read access to output ports of the given data pipeline unit;

reconfiguring the given data pipeline unit to conform to the modified specification including by providing input to a second set of data pipeline units; and

modifying the group of system accounts having read access to the output ports of the given data pipeline unit according to a difference between the second set of data pipeline units and the first set of data pipeline units.

15 . A computer-implemented method for managing access control of a data pipeline having data pipeline units deployed on a cloud platform in accordance with a specification, the method comprising:

for each of the data pipeline units:

creating a runtime system account on the cloud platform having access to at least a storage unit of the data pipeline unit;

provisioning computing infrastructure on the cloud platform for the data pipeline unit;

creating a group of runtime system accounts including the runtime system account created for the data pipeline unit and each runtime system account created for a data pipeline unit receiving as input, data output by the data pipeline unit; and

granting read access to the output data of the data pipeline unit to each runtime system account in the group of runtime system accounts;

executing the data pipeline;

receiving a modified specification of a respective data pipeline unit of the data pipeline, wherein the respective data pipeline unit provides input to a first set of data pipeline units and is associated with a first group of system accounts having read access to output ports of the respective data pipeline unit;

reconfiguring the respective data pipeline unit to conform to the modified specification including by providing input to a second set of data pipeline units; and

modifying the group of system accounts having read access to the output ports of the respective data pipeline unit according to a difference between the second set of data pipeline units and the first set of data pipeline units.

16 . The computer-implemented method of claim 14 further comprising:

modifying the group of system accounts comprises, responsive to determining that the second set of data pipeline units includes a particular data pipeline unit that is absent from the first set of data pipeline units, adding a system account corresponding to the particular data pipeline unit to the group of system accounts.

17 . The computer-implemented method of claim 14 wherein the respective data pipeline unit has a plurality of output ports comprising a first output port and a second output port, wherein the group of runtime system accounts is a first group of runtime system accounts associated with the first output port, wherein the first group of runtime system accounts includes runtime system accounts created for data pipeline units receiving as input, data output by the first output port of the respective data pipeline unit, the method further comprising:

creating a second group of runtime system accounts including the runtime system account created for the respective data pipeline unit and each runtime system account created for a data pipeline unit receiving as input, data output by the second output port of the respective data pipeline unit; and

granting read access to the output data of the second output port of the respective data pipeline unit to each system account of the second group.

18 . The computer-implemented method of claim 14 , wherein the data pipeline unit outputs a first data set categorized as having a first level of sensitivity and a second data set categorized as having a second level of sensitivity, wherein the group of runtime system accounts is a first group of runtime system accounts that has access to data categorized as having a first level of sensitivity, the method further comprising:

creating a second group of runtime system accounts including the runtime system account created for the respective data pipeline unit and one or more runtime system accounts created for a data pipeline unit receiving as input, data output by the respective data pipeline unit and categorized as having a second level of sensitivity.

19 . The computer-implemented method of claim 15 further comprising:

modifying the group of system accounts comprises, responsive to determining that the second set of data pipeline units includes a particular data pipeline unit that is absent from the first set of data pipeline units, adding a system account corresponding to the particular data pipeline unit to the group of system accounts.

20 . The computer-implemented method of claim 15 , wherein the data pipeline unit outputs a first data set categorized as having a first level of sensitivity and a second data set categorized as having a second level of sensitivity, wherein the group of runtime system accounts is a first group of runtime system accounts that has access to data categorized as having a first level of sensitivity, the method further comprising:

creating a second group of runtime system accounts including the runtime system account created for the respective data pipeline unit and one or more runtime system accounts created for a data pipeline unit receiving as input, data output by the respective data pipeline unit and categorized as having a second level of sensitivity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2024
From: LAI, TIAN; YAO, YUAN; ZHANG, BING
To: HUMANA INC.
Reel/Frame 067089/0844 →
Continuity (2)
Continuation 17390944 · Jul 31, 2021
Provisional Application 63175283 · Apr 15, 2021
References Cited (40)
US 9020945B1 · Hollister et al. · 2015 [cited by applicant]
US 9355060B1 · Barber et al. · 2016 [cited by applicant]
US 9483622B1 · Snyder · 2016 [cited by applicant]
US 9501304B1 · Powers et al. · 2016 [cited by applicant]
US 9741197B2 · Ghouri et al. · 2017 [cited by applicant]
US 9912752B1 · Davis et al. · 2018 [cited by applicant]
US 10118773B2 · Mahar · 2018 [cited by applicant]
US 10163175B2 · Stephenson · 2018 [cited by applicant]
US 10179706B2 · Kapadia · 2019 [cited by applicant]
US 10263946B2 · Fehling · 2019 [cited by applicant]
US 10394691B1 · Cole et al. · 2019 [cited by applicant]
US 10540478B2 · Singh et al. · 2020 [cited by applicant]
US 10643750B2 · Ghouri · 2020 [cited by applicant]
US 11698915B1 · Yao et al. · 2023 [cited by applicant]
US 11843664B1 · Lai et al. · 2023 [cited by applicant]
US 20050278152A1 · Blaszczak · 2005 [cited by applicant]
US 20060283930A1 · Shafer · 2006 [cited by applicant]
US 20170078161A1 · Cimprich · 2017 [cited by applicant]
US 20180107525A1 · Govindaraju et al. · 2018 [cited by applicant]
US 20180131752A1 · Corley et al. · 2018 [cited by applicant]
US 20190354720A1 · Tucker et al. · 2019 [cited by applicant]
US 20200004858A1 · Gitelman et al. · 2020 [cited by applicant]
US 20200125540A1 · Thatte et al. · 2020 [cited by applicant]
US 20200183839A1 · Lin et al. · 2020 [cited by applicant]
US 20200201831A1 · Shekhawat et al. · 2020 [cited by applicant]
US 20200334377A1 · Turgeman et al. · 2020 [cited by applicant]
US 20210006636A1 · Koehler et al. · 2021 [cited by applicant]
US 20210064475A1 · Baker · 2021 [cited by applicant]
US 20210096883A1 · Miller et al. · 2021 [cited by applicant]
US 20210133456A1 · Lee et al. · 2021 [cited by applicant]
US 20210240519A1 · Gitelman et al. · 2021 [cited by applicant]
US 20210303584A1 · Fan et al. · 2021 [cited by applicant]
US 20210303585A1 · Fan et al. · 2021 [cited by applicant]
US 20220066813A1 · Taher et al. · 2022 [cited by applicant]
US 20220067200A1 · Taber et al. · 2022 [cited by applicant]
US 20220121479A1 · Chivukula et al. · 2022 [cited by applicant]
US 20220236975A1 · Wiegley · 2022 [cited by applicant]
US 20240061958A1 · Taber · 2024 [cited by examiner]
United States Office Action, U.S. Appl. No. 17/363,453, dated Mar. 16, 2023, 23 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/363,453, dated Sep. 1, 2022, 19 pages. [cited by applicant]