US2007073691A1PendingUtilityA1

Server side filtering and sorting with field level security

Assignee: MICROSOFT CORPPriority: Sep 27, 2005Filed: Oct 31, 2005Published: Mar 29, 2007
Est. expirySep 27, 2025(expired)· nominal 20-yr term from priority
G06F 16/9535Y10S707/99939Y10S707/99932G06F 21/6227
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A project management system is enabled to implement filtering, sorting, and field level security for data associated with managed projects. A filter for field selection is prepared by a project client application and forwarded to a project server. The server generates an access attribute table based the user permissions that may be set for each field within the managed projects. Upon retrieving the selected fields from project database, the project server builds a secured list of fields. A data set to be provided to the project client is prepared by removing the fields for which the user lacks the requisite access permission prior to sorting the data. The removed data may be used for user-transparent computations within the project server, but guarded from client applications.

Claims

exact text as granted — not AI-modified
1 .- 20 . (canceled)  
   
   
       21 . A computer-implemented method for securely filtering data in a business logic application, comprising: 
 receiving a request for a portion of data associated with the business logic application, wherein the request includes a filter based on a rule for selecting the portion of data;    preparing a query based on the filter and at least one security attribute associated with a user;    retrieving the selected portion of the data;    sorting the retrieved data based on the filter and at least one post-processing criterion; and providing the data to a requesting application.    
   
   
       22 . The computer-implemented method of  claim 21 , wherein the filter includes a look-up table based on the rule for selecting the portion of data.  
   
   
       23 . The computer-implemented method of  claim 21 , wherein preparing the query includes assigning the security attribute to one of each field of the selected portion of data and a group of fields of the selected portion of data.  
   
   
       24 . The computer-implemented method of  claim 21 , wherein preparing the query includes assigning an enterprise level security attribute to one of each field of the selected portion of data and a group of fields of the selected portion of data.  
   
   
       25 . The computer-implemented method of  claim 21 , further comprising determining the security attribute from one or more rules.  
   
   
       26 . The computer-implemented method of  claim 21 , wherein the selected portion of the data includes at least one field associated with one of a cost and a baseline of a project.  
   
   
       27 . The computer-implemented method of  claim 26 , wherein the selected portion of the data includes a field for baseline cost that is derived from a comparison of the corresponding cost and baseline fields.  
   
   
       28 . The computer-implemented method of  claim 21 , wherein preparing the query includes assigning a security attribute to a field of the selected portion of data by inferring the security attribute from at least one other field of the selected portion of data.  
   
   
       29 . The computer-implemented method of  claim 28 , wherein the inferred security attribute is determined from a content of the at least one other field.  
   
   
       30 . A project server for securely filtering and sorting project data, comprising: 
 a communication module configured to communicate with a project client and a project database;    a processor configured to: 
 receive a request for a portion of the project data from the project client, wherein the request includes a plurality of filters based on at least one rule for selecting the portion of the project data;  
 determine at least one access attribute for a permission status of a user;  
 prepare a query for a plurality of projects based on the plurality of filters and the permission status;  
 retrieve a selected portion of the project data from a project database based on the query;  
 sort the retrieved portion of the project data based on a plurality of filters and access attributes for each project and at least one post-processing criterion, wherein a predetermined value is used for restricted fields that are defined by the permission status; and  
 provide the post-processed data to the requesting project client.  
   
   
   
       31 . The project server of  claim 30 , wherein the processor is further configured to prepare the query for the plurality of projects based on distinct rules for each project provided by a plurality of project clients.  
   
   
       32 . The project server of  claim 30 , wherein the processor is further configured to dynamically modify the query, if the selected portion of the project data is modified.  
   
   
       33 . The project server of  claim 30 , wherein the processor is further configured to determine the access attributes at one of a field level, a group level, a project level, and an enterprise level.  
   
   
       34 . The project server of  claim 30 , wherein at least one of the filters and the query are prepared in eXtensible Markup Language (XML).  
   
   
       35 . The project server of  claim 34 , wherein the query is extensible.  
   
   
       36 . A business logic system for server-side filtering and sorting data in a secure manner, the system comprising: 
 a database configured to store business logic data;    a filter building module configured to: 
 prepare a filter based on a selection criterion;  
   a query building module configured to: 
 receive the filter from the filter building module;  
 determine access attributes based on a permission rule associated with a user; and  
 prepare a query based on the filter and the access attributes for a portion of the business logic data; and  
   a processing module configured to: 
 retrieve a selected portion of business logic data from the database based on the query;  
 determine a restriction status of the retrieved portion of the data based on the access attributes;  
 sort the retrieved portion of the data based on the filter, wherein a null value is used for restricted data; and  
 provide the sorted data to a client application.  
   
   
   
       37 . The system of  claim 36 , wherein the processing module is further configured to post-process the restricted, sorted data with further selection criteria.  
   
   
       38 . The system of  claim 36 , wherein the filter includes at least one table derived from at least one rule associated with selecting the portion of the data.  
   
   
       39 . The system of  claim 36 , wherein the processing module is further configured to dynamically modify at least one of the filter and the access attributes in response to a change in the selected portion of the data.  
   
   
       40 . The system of  claim 36 , wherein the processing module is further configured to use the sorted data in a client-transparent operation regardless of the restriction status.

Join the waitlist — get patent alerts

Track US2007073691A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.