IP Library › Granted Patent US 12,627,672
Granted Patent B2
US 12,627,672 · App. 18/773,300 · Granted May 12, 2026

Enforcing granular access control policy

Inventors: Peter Wilczynski (Denver, CO); Arseny Bogomolov (Arlington, VA); Alexander Mark (New York, NY); Teofana Hadzhiganeva (Bethesda, MD); Kevin Ng (New York, NY); Nathaniel Klein (Washington, DC); Sharon Hao (Redwood City, CA)
Assignee: Palantir Technologies Inc.
H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,672
App. No.
18/773,300
Filed
Jul 15, 2024
Granted
May 12, 2026
Kind
B2
Art Unit
2495
USPC
726/1
Abstract

An example method of enforcing granular access policy for embedded artifacts comprises: detecting an association of an embedded artifact with a resource container; associating the embedded artifact with at least a subset of an access control policy associated with the resource container; and responsive to receiving an access request to access the embedded artifact, applying the access control policy associated with the resource container for determining whether the access request is grantable.

Claims (66)

1 . A method for providing granular access control, comprising:

receiving an embedded artifact including a first part and a second part, the first part being associated with a first access control policy, the second part being associated with a second access control policy, the second access control policy being different from the first access control policy;

receiving an association of the embedded artifact with a resource container, the first access control policy being a subset of an access control policy of the resource container;

receiving an access request to access the embedded artifact;

applying the first access control policy to determine whether the access request is grantable for the first part;

applying the second access control policy to determine whether the access request is grantable for the second part; and

in response to determining that the access request is grantable for the first part and the access request for the second part, granting the access request;

wherein the method is performed using one or more processors.

2 . The method of claim 1 , wherein the granting the access request comprises:

generating a redacted first part based on the first part and the first access control policy; and

granting an access to the redacted first part.

3 . The method of claim 2 , wherein the first part includes a first data that is omitted or changed in the redacted first part.

4 . The method of claim 1 , wherein the applying the first access control policy further comprises:

identifying a permission associated with a user group associated with a user for whom the access request is submitted; and

determining whether the permission matches an access type specified by the access request.

5 . The method of claim 1 , wherein the subset of the access control policy of the resource container includes an intersection of the access control policy of the resource container and an initial access control policy of the embedded artifact;

wherein the initial access control policy is retrieved based on an access control policy pointer in metadata of the embedded artifact.

6 . The method of claim 1 , further comprising:

creating a copy of the subset of the access control policy;

associating the embedded artifact with the copy of the subset of the access control policy; and

disassociating the embedded artifact from the resource container.

7 . The method of claim 1 , further comprising:

creating a restrictive version of the first access control policy;

associating the embedded artifact with the restrictive version of the first access control policy;

redacting the embedded artifact to generate a redacted embedded artifact based on the restrictive version of the first access control policy; and

sharing the redacted embedded artifact with a user that is authorized to access the embedded artifact based on the restrictive version of the first access control policy.

8 . A system for providing granular access control, comprising:

one or more memories comprising instructions stored thereon; and

one or more processors configured to execute the instructions and perform operations comprising:

receiving an embedded artifact including a first part and a second part, the first part being associated with a first access control policy, the second part being associated with a second access control policy, the second access control policy being different from the first access control policy;

receiving an association of the embedded artifact with a resource container, the first access control policy being a subset of an access control policy of the resource container;

receiving an access request to access the embedded artifact;

applying the first access control policy to determine whether the access request is grantable for the first part;

applying the second access control policy to determine whether the access request is grantable for the second part; and

in response to determining that the access request is grantable for the first part and the access request for the second part, granting the access request.

9 . The system of claim 8 , wherein the granting the access request comprises:

generating a redacted first part based on the first part and the first access control policy; and

granting an access to the redacted first part.

10 . The system of claim 9 , wherein the first part includes a first data that is omitted or changed in the redacted first part.

11 . The system of claim 8 , wherein the applying the first access control policy further comprises:

identifying a permission associated with a user group associated with a user for whom the access request is submitted; and

determining whether the permission matches an access type specified by the access request.

12 . The system of claim 8 , wherein the subset of the access control policy of the resource container includes an intersection of the access control policy of the resource container and an initial access control policy of the embedded artifact;

wherein the initial access control policy is retrieved based on an access control policy pointer in metadata of the embedded artifact.

13 . The system of claim 8 , wherein the operations further comprise:

creating a copy of the subset of the access control policy;

associating the embedded artifact with the copy of the subset of the access control policy; and

disassociating the embedded artifact from the resource container.

14 . The system of claim 8 , wherein the operations further comprise:

creating a restrictive version of the first access control policy;

associating the embedded artifact with the restrictive version of the first access control policy;

redacting the embedded artifact to generate a redacted embedded artifact based on the restrictive version of the first access control policy; and

sharing the redacted embedded artifact with a user that is authorized to access the embedded artifact based on the restrictive version of the first access control policy.

15 . A non-transitory computer readable storage medium comprising executable instructions for providing granular access control that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving an embedded artifact including a first part and a second part, the first part being associated with a first access control policy, the second part being associated with a second access control policy, the second access control policy being different from the first access control policy;

receiving an association of the embedded artifact with a resource container, the first access control policy being a subset of an access control policy of the resource container;

receiving an access request to access the embedded artifact;

applying the first access control policy to determine whether the access request is grantable for the first part;

applying the second access control policy to determine whether the access request is grantable for the second part; and

in response to determining that the access request is grantable for the first part and the access request for the second part, granting the access request.

16 . The non-transitory computer readable storage medium of claim 15 , wherein the granting the access request comprises:

generating a redacted first part based on the first part and the first access control policy; and

granting an access to the redacted first part.

17 . The non-transitory computer readable storage medium of claim 15 , wherein the applying the first access control policy further comprises:

identifying a permission associated with a user group associated with a user for whom the access request is submitted; and

determining whether the permission matches an access type specified by the access request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2024
From: WILCZYNSKI, PETER; BOGOMOLOV, ARSENY; MARK, ALEXANDER; HADZHIGANEVA, TEOFANA; NG, KEVIN; KLEIN, NATHANIEL; HAO, SHARON
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 068809/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2024
From: WILCZYNSKI, PETER; BOGOMOLOV, ARSENY; MARK, ALEXANDER; HADZHIGANEVA, TEOFANA; NG, KEVIN; KLEIN, NATHANIEL; HAO, SHARON
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 068069/0760 →
Continuity (6)
Continuation 18238871 · Aug 28, 2023
Continuation 17992737 · Nov 22, 2022
Division 17386060 · Jul 27, 2021
Continuation 16803104 · Feb 27, 2020
Continuation 16521179 · Jul 24, 2019
Related Publication 20240430269A1 · Dec 26, 2024
References Cited (101)
US 891888A · Weiler · 1908 [cited by applicant]
US 5745714A · Glass · 1998 [cited by applicant]
US 6859805B1 · Rogers · 2005 [cited by applicant]
US 8245271B2 · Chan · 2012 [cited by applicant]
US 8447829B1 · Geller · 2013 [cited by applicant]
US 8533851B2 · Ginter · 2013 [cited by applicant]
US 8745128B2 · Kazerani · 2014 [cited by applicant]
US 8813170B2 · Novak · 2014 [cited by examiner]
US 8918818B2 · DeWeese · 2014 [cited by applicant]
US 9111108B2 · Levenshteyn · 2015 [cited by applicant]
US 9116917B1 · Ekwall · 2015 [cited by applicant]
US 9185147B1 · Keel · 2015 [cited by applicant]
US 9274907B1 · Bachu · 2016 [cited by applicant]
US 9342852B1 · Nagaraj · 2016 [cited by applicant]
US 9471798B2 · Vepa · 2016 [cited by applicant]
US 9516028B1 · Andruschuk · 2016 [cited by examiner]
US 9712466B2 · Cohen · 2017 [cited by applicant]
US 9846859B1 · Casale · 2017 [cited by applicant]
US 9870484B2 · Bellert · 2018 [cited by applicant]
US 10140739B1 · Burgin · 2018 [cited by applicant]
US 10146960B1 · Wilczynski · 2018 [cited by applicant]
US 10235533B1 · Thoren · 2019 [cited by applicant]
US 10250401B1 · Skiff · 2019 [cited by applicant]
US 10609041B1 · Wilczynski · 2020 [cited by applicant]
US 20020035593A1 · Salim · 2002 [cited by applicant]
US 20040139330A1 · Baar · 2004 [cited by applicant]
US 20050055327A1 · Agrawal · 2005 [cited by applicant]
US 20060053380A1 · Spataro · 2006 [cited by applicant]
US 20060265394A1 · Raman · 2006 [cited by applicant]
US 20060265395A1 · Raman · 2006 [cited by applicant]
US 20070174399A1 · Ogle et al. · 2007 [cited by applicant]
US 20070219979A1 · Jung · 2007 [cited by applicant]
US 20080222083A1 · Lim · 2008 [cited by applicant]
US 20080307498A1 · Johnson · 2008 [cited by applicant]
US 20090012987A1 · Kaminsky · 2009 [cited by examiner]
US 20090049509A1 · Chan · 2009 [cited by examiner]
US 20090198698A1 · Bahrs · 2009 [cited by applicant]
US 20090217344A1 · Bellwood · 2009 [cited by applicant]
US 20090327294A1 · Bailor · 2009 [cited by applicant]
US 20100070461A1 · Vella · 2010 [cited by applicant]
US 20100071031A1 · Carter · 2010 [cited by examiner]
US 20100169268A1 · John · 2010 [cited by applicant]
US 20100229246A1 · Warrington · 2010 [cited by applicant]
US 20110066606A1 · Fox · 2011 [cited by applicant]
US 20110265177A1 · Sokolan et al. · 2011 [cited by applicant]
US 20110276903A1 · Mehin · 2011 [cited by applicant]
US 20120159296A1 · Rebstock · 2012 [cited by applicant]
US 20120198559A1 · Venkata Naga Ravi · 2012 [cited by applicant]
US 20120209899A1 · Daenen · 2012 [cited by applicant]
US 20120331568A1 · Weinstein · 2012 [cited by applicant]
US 20130007895A1 · Brolley · 2013 [cited by applicant]
US 20130097688A1 · Bradley · 2013 [cited by applicant]
US 20130120369A1 · Miller · 2013 [cited by applicant]
US 20140026072A1 · Beaven · 2014 [cited by applicant]
US 20140089379A1 · Davis · 2014 [cited by applicant]
US 20140250534A1 · Flores · 2014 [cited by applicant]
US 20140280952A1 · Shear · 2014 [cited by applicant]
US 20140380404A1 · Raj · 2014 [cited by applicant]
US 20150067330A1 · Khan · 2015 [cited by applicant]
US 20150089663A1 · Gile · 2015 [cited by applicant]
US 20150143549A1 · Laitkorpi · 2015 [cited by applicant]
US 20150178516A1 · Mityagin · 2015 [cited by applicant]
US 20150242629A1 · Lindo · 2015 [cited by applicant]
US 20150319111A1 · Carino · 2015 [cited by applicant]
US 20150350251A1 · Brander · 2015 [cited by applicant]
US 20150358306A1 · Adams · 2015 [cited by applicant]
US 20160036872A1 · Lappin · 2016 [cited by applicant]
US 20160080510A1 · Dawoud Shenouda Dawoud · 2016 [cited by applicant]
US 20160100019A1 · Leondires · 2016 [cited by applicant]
US 20160321469A1 · Bhogal · 2016 [cited by applicant]
US 20160337291A1 · Park · 2016 [cited by applicant]
US 20160342786A1 · Gerebe · 2016 [cited by applicant]
US 20160366188A1 · Smith · 2016 [cited by applicant]
US 20160378999A1 · Panchapakesan · 2016 [cited by applicant]
US 20170180346A1 · Suarez · 2017 [cited by applicant]
US 20170270283A1 · Shiraishi · 2017 [cited by applicant]
US 20170346828A1 · Lorensson · 2017 [cited by applicant]
US 20180033072A1 · Karthikeyan · 2018 [cited by applicant]
US 20190073484A1 · Wilczynski · 2019 [cited by applicant]
US 20190171837A1 · Thoren · 2019 [cited by applicant]
US 20190182062A1 · Skiff · 2019 [cited by applicant]
US 20230093504A1 · Wilczynski · 2023 [cited by applicant]
EP 3770787 · 2021 [cited by applicant]
EP 4530909 · 2025 [cited by applicant]
USPTO, Notice of Allowance for U.S. Appl. No. 16/521,179, mailed Nov. 20, 2019. [cited by applicant]
USPTO, Notice of Allowance for U.S. Appl. No. 16/803,104, mailed Mar. 29, 2021. [cited by applicant]
USPTO, Nolice of Allowance for U.S. Appl. No. 17/386,060, mailed Aug. 25, 2022. [cited by applicant]
Cameron H. Malin, et al., 2012, Embedded Artifact, https://www.sciencedirect:com/topics/computer-science/embedded-artifact, pp. 1-0. [cited by applicant]
NIST, Dec. 13, 2016, https://web.archive.org/web/20161213215317/https://nvd.nist.gov/download/800-53/800-53-controls.xml, Govemors State Universtiy, pp. 1-64. [cited by applicant]
Harvard, Dec. 2015, Manage Access Requests in SharePoint, https://web.archive.org/web/20151214135632/ https://mso.harvard.edu/sp_access_requests, pp. 1-3. [cited by applicant]
Sergio Vincent Senese, Spring 2015, https://opus.govst.edu/cgi/viewcontent.cgi?referer-&htlpsredir=1&article=1056&context=theses, Governors State University, pp. 1-64. [cited by applicant]
Jana Rosero; et al., Granular: An access control model, and Confia: Its software tool, Sep. 2014, 2014 XL Latin American Computing Converence (CLEI), pp. 1-9. [cited by applicant]
Bertino et al: “Access Control Systems for Geospatial Data and Applications” In: “Spatial Data on the Web”, Jan. 1, 2007, Springer Berlin Heidelberg, Berlin, Heidelberg; ISBN: 978-3-540-69877-7, pp. 189214. [cited by applicant]
The extended European search report for EP Application No. EP20187538.2, mailed on Nov. 24, 2020, 8 pages. [cited by applicant]
Official Communication for European Patent Application No. 18209228.8 dated Jan. 22, 2019. [cited by applicant]
Lin et al.: “Analysis of Access Control Mechanisms for Spacial Database”, Jan. 1, 2008, <P055514572, Retrieved from the Internet: URL: http:/citeseerx.ist.psu.edu/viewdoc/download?oi=10.1.1.184.3608&rep=repl&type=pdf, [… [cited by applicant]
Official Communication for U.S. Appl. No. 15/940,744 dated Jun. 29, 2018. [cited by applicant]
Official Communication for U.S. Appl. No. 15/826,441 dated Feb. 27, 2018. [cited by applicant]
Official Communication for European Patent Application No. 18173063.1 dated Oct. 23, 2018. [cited by applicant]
Official Communication for U.S. Appl. No. 15/829,654 dated Apr. 19, 2018. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/183,267 dated Aug. 28, 2019. [cited by applicant]