IP Library › Granted Patent US 12,592,920
Granted Patent B2
US 12,592,920 · App. 18/422,608 · Granted Mar 31, 2026

Granular authorization flow in a distributed, multi-domain computing system

Inventors: Kerry D. Brabble (Orlando, FL); Robert K. Floyd, III (Clermont, FL); Nicholas Jordan Lewis (Saint Cloud, FL)
Assignee: DISNEY ENTERPRISES, INC.
H04L63/083H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,920
App. No.
18/422,608
Filed
Jan 25, 2024
Granted
Mar 31, 2026
Kind
B2
Art Unit
2434
USPC
726/1
Abstract

The present invention sets forth a technique for automatically managing access control authorization in a distributed computing system. This technique includes receiving an access request from a requesting entity and recording the access request in an audit log. The technique also includes retrieving access control policies associated with the access request and retrieving attribute data values from an entity data store. The technique further includes generating an access request evaluation based on the access request, the access control policies, and the attribute data values. The technique further includes transmitting the access request evaluation to the requesting entity.

Claims (55)

1 . A computer-implemented method for performing authorization flow, the computer-implemented method comprising:

receiving an access request from a requesting entity in a distributed computing system, wherein the access request specifies an automated workflow and includes first attribute values associated with one or more executable commands included in the automated workflow;

retrieving one or more access control policies associated with the access request;

retrieving, from an entity data store, second attribute values for one or more attributes included in the one or more access control policies;

generating, based on the first and second attribute values and the one or more access control policies, an access request evaluation; and

transmitting the access request evaluation to the requesting entity.

2 . The computer-implemented method of claim 1 , wherein the automated workflow is a first automated workflow, and the requesting entity is one of a human user, a computing system component, or a second automated workflow.

3 . The computer-implemented method of claim 1 , wherein the access request includes contextual attribute data associated with the requesting entity, a resource, or an action.

4 . The computer-implemented method of claim 1 , wherein the access request evaluation is an access request approval, the computer-implemented method further comprising:

generating an authorization token associated with the access request approval; and

transmitting the authorization token to the requesting entity.

5 . The computer-implemented method of claim 1 , further comprising storing the access request in an audit log.

6 . The computer-implemented method of claim 1 , wherein the computer-implemented method further comprises:

determining a plurality of users included in the entity data store;

generating, for each user in the plurality of users, an associated access request evaluation based on the access request and the user;

generating a subset of the plurality of users for which the access request evaluation associated with the user is an access request approval; and

displaying, via a graphical user interface, the subset of the plurality of users.

7 . The computer-implemented method of claim 1 , wherein the computer-implemented method further comprises receiving, via an application programming interface, an identity token associated with the requesting entity.

8 . One or more non-transitory computer-readable media storing instructions that, when executed by one or more processors, cause the one or more processors to perform the steps of:

receiving an access request from a requesting entity in a distributed computing system, wherein the access request specifies an automated workflow and includes first attribute values associated with one or more executable commands included in the automated workflow;

retrieving one or more access control policies associated with the access request;

retrieving, from an entity data store, second attribute values for one or more attributes included in the one or more access control policies;

generating, based on the first and second attribute values and the one or more access control policies, an access request evaluation; and

transmitting the access request evaluation to the requesting entity.

9 . The one or more non-transitory computer-readable media of claim 8 , wherein the automated workflow is a first automated workflow, and the requesting entity is one of a human user, a computing system component, or a second automated workflow.

10 . The one or more non-transitory computer-readable media of claim 8 , wherein the access request includes contextual attribute data associated with the requesting entity, a resource, or an action.

11 . The one or more non-transitory computer-readable media of claim 8 , wherein the access request evaluation is an access request approval, the computer-implemented method further comprising:

generating an authorization token associated with the access request approval; and

transmitting the authorization token to the requesting entity.

12 . The one or more non-transitory computer-readable media of claim 8 , wherein the instructions further cause the one or more processors to perform the step of storing the access request in an audit log.

13 . The one or more non-transitory computer-readable media of claim 8 , wherein the instructions further cause the one or more processors to perform the steps of:

determining a plurality of users included in the entity data store;

generating, for each user in the plurality of users, an associated access request evaluation based on the access request and the user;

generating a subset of the plurality of users for which the access request evaluation associated with the user is an access request approval; and

displaying, via a graphical user interface, the subset of the plurality of users.

14 . The one or more non-transitory computer-readable media of claim 8 , wherein the instructions further cause the one or more processors to perform the step of receiving, via an application programming interface, an identity token associated with the requesting entity.

15 . A system comprising:

one or more memories storing instructions; and

one or more processors for executing the instructions to:

receive an access request from a requesting entity in a distributed computing system, wherein the access request specifies an automated workflow and includes first attribute values associated with one or more executable commands included in the automated workflow;

retrieve one or more access control policies associated with the access request;

retrieve, from an entity data store, second attribute values for one or more attributes included in the one or more access control policies;

generate, based on the first and second attribute values and the one or more access control policies, an access request evaluation; and

transmitting the access request evaluation to the requesting entity.

16 . The system of claim 15 , wherein the automated workflow is a first automated workflow, and the requesting entity is one of a human user, a computing system component, or a second automated workflow.

17 . The system of claim 15 , wherein the access request includes contextual attribute data associated with the requesting entity, a resource, or an action.

18 . The system of claim 15 , wherein the access request evaluation is an access request approval and the one or more processors are further configured to:

generate an authorization token associated with the access request approval; and

transmit the authorization token to the requesting entity.

19 . The system of claim 15 , wherein the one or more processors are further configured to store the access request in an audit log.

20 . The system of claim 15 , wherein the one or more processors are further configured to:

determine a plurality of users included in the entity data store;

generate, for each user in the plurality of users, an associated access request evaluation based on the access request and the user;

generate a subset of the plurality of users for which the access request evaluation associated with the user is an access request approval; and

display, via a graphical user interface, the subset of the plurality of users.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE SECOND INVENTORS FIRST NAME FROM ROBER TO ROBERT PREVIOUSLY RECORDED ON REEL 66971 FRAME 175. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 6, 2024
From: BRABBLE, KERRY D.; FLOYD, ROBERT K., III; LEWIS, NICHOLAS JORDAN
To: DISNEY ENTERPRISES, INC.
Reel/Frame 067327/0935 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2024
From: BRABBLE, KERRY D.; FLOYD, ROBER K., III; LEWIS, NICHOLAS JORDAN
To: DISNEY ENTERPRISES, INC.
Reel/Frame 066971/0175 →
Continuity (1)
Related Publication 20250247384A1 · Jul 31, 2025
References Cited (21)
US 7464162B2 · Chan · 2008 [cited by examiner]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 10467050B1 · Schmidgall et al. · 2019 [cited by applicant]
US 10956213B1 · Chambers et al. · 2021 [cited by applicant]
US 12169802B1 · Eldan et al. · 2024 [cited by applicant]
US 20050027585A1 · Wodtke et al. · 2005 [cited by applicant]
US 20070240099A1 · Jahn et al. · 2007 [cited by applicant]
US 20070250335A1 · Hodges et al. · 2007 [cited by applicant]
US 20090171708A1 · Bobak et al. · 2009 [cited by applicant]
US 20090204471A1 · Elenbaas et al. · 2009 [cited by applicant]
US 20100324948A1 · Kumar et al. · 2010 [cited by applicant]
US 20160072814A1 · Martinelli · 2016 [cited by examiner]
US 20160162478A1 · Blassin et al. · 2016 [cited by applicant]
US 20210117557A1 · Al-Shanqity · 2021 [cited by examiner]
US 20220083936A1 · Balinsky et al. · 2022 [cited by applicant]
US 20220239733A1 · Maheshwari · 2022 [cited by examiner]
US 20230179634A1 · Seaborn · 2023 [cited by examiner]
US 20240169438A1 · Biesack · 2024 [cited by applicant]
US 20240184632A1 · You et al. · 2024 [cited by applicant]
Non-Final Office Action received for U.S. Appl. No. 18/476,171 dated May 21, 2025, 16 pages. [cited by applicant]
Final Rejection received for U.S. Appl. No. 18/476,171, dated Dec. 2, 2025, 32 pages. [cited by applicant]