Techniques for replicating changes to access control lists on investigative analysis data
Abstract
Techniques for replicating changes to access control lists on investigative analysis data are disclosed. After a change is made in a database to an access control list (ACL) governing access to a secured component of a data object, an exporting nexus sends an ACL change network message to an importing nexus. The ACL change message includes information that importing nexus can use to apply the ACL change to the importing database. Applying the ACL change message includes using the information in the ACL change message to determine which change records for which secured components of the data object in the importing database the ACL change should be applied to. By doing so, user access to all change records in the importing database to which the ACL change is applied is governed by the new ACL, thereby preventing unauthorized access to the change records, including historical change records.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method of asynchronous replication among databases, comprising:
receiving, by a processor, one or more network messages comprising an identifier of a data object, first value data, and first access control list data,
the first value data being stored in a first database,
the first value data comprising a current value and one or more historical values of a first secured component of a data object,
the first secured component being associated in the first database with a first secured component identifier,
the data object being associated in the first database with a data object identifier,
the first access control list data being stored in the first database,
the first access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the first database, access to the current value and the one or more historical values of the first secured component;
storing, by the processor, second value data in a second database, the second value data comprising a current value and one or more historical values of a second secured component of the data object,
the second secured component being associated in the second database with a second secured component identifier that is different than the first secured component identifier,
the data object being associated in the second database with the data object identifier,
a change made to the first database to be propagated to the second database;
storing second access control list data in the second database,
the second access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the second database, access to the current value and the one or more historical values of the second secured component;
receiving the one or more network messages related to a change in the first access control list data; comparing the first value data to the second value data; comparing the first access control list data to the second access control list data; responsive to determining that the first value data matches the second value data and the first access control list data matches the second access control list data, identifying the second secured component as being associated with the first secured component and replacing, in the second database, each of the current access control list and the one or more historical access control lists in the second access control list data with the current access control list from the first access control list data as a new access control list in the second database.
2 . The computer-implemented method of claim 1 ,
the new access control list including a classification comprising one or more classification markings of a plurality of classification markings, each of the one or more classification markings indicating a sensitivity level of the second secured component.
3 . The computer-implemented method of claim 1 , the plurality of classification markings are related hierarchically.
4 . The computer-implemented method of claim 1 ,
the classification comprising multiple classification markings, further comprising granting access to the second secured component to a user computer when the user computer is authorized for each of the multiple classification markings.
5 . The computer-implemented method of claim 1 , further comprising storing change records for the new access control list in the second database.
6 . The computer-implemented method of claim 1 , further comprising:
receiving source information regarding how the second secured component was obtained from a source, the identifying the second secured component being further based on the source information.
7 . A system for asynchronous replication among databases, comprising:
at least one processor; at least one memory storing computer-executable instructions which when executed cause the at least one processor to execute a method, the method comprising: receiving one or more network messages comprising an identifier of a data object, first value data, and first access control list data,
the first value data being stored in a first database,
the first value data comprising a current value and one or more historical values of a first secured component of a data object,
the first secured component being associated in the first database with a first secured component identifier,
the data object being associated in the first database with a data object identifier,
the first access control list data being stored in the first database,
the first access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the first database, access to the current value and the one or more historical values of the first secured component;
storing second value data in a second database, the second value data comprising a current value and one or more historical values of a second secured component of the data object,
the second secured component being associated in the second database with a second secured component identifier that is different than the first secured component identifier,
the data object being associated in the second database with the data object identifier,
a change made to the first database to be propagated to the second database;
storing second access control list data in the second database,
the second access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the second database, access to the current value and the one or more historical values of the second secured component;
receiving the one or more network messages related to a change in the first access control list data; comparing the first value data to the second value data; comparing the first access control list data to the second access control list data; responsive to determining that the first value data matches the second value data and the first access control list data matches the second access control list data, identifying the second secured component as being associated with the first secured component and replacing, in the second database, each of the current access control list and the one or more historical access control lists in the second access control list data with the current access control list from the first access control list data as a new access control list in the second database.
8 . The system of claim 7 ,
the new access control list having a classification comprising one or more classification markings of a plurality of classification markings, each of the one or more classification markings indicating a sensitivity level of the second secured component.
9 . The system of claim 7 , the plurality of classification markings are related hierarchically.
10 . The system of claim 7 ,
the classification comprising multiple classification markings, further comprising granting access to the second secured component to a user computer when the user computer is authorized for each of the multiple classification markings.
11 . The system of claim 7 , the method further comprising storing change records for the new access control list in the second database.
12 . The system of claim 7 , the method further comprising:
receiving source information regarding how the second secured component was obtained from a source, the identifying the second secured component being further based on the source information.
13 . One or more non-transitory storage media,
storing computer-executable first instructions which when executed cause one or more first processors to perform a first method, the first method comprising:
storing first value data in a first database, the first value data comprising a current value and one or more historical values of a first secured component of a data object, the first secured component associated in the first database with a first secured component identifier, the data object associated in the first database with a data object identifier;
storing first access control list data in the first database, the first access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the first database, access to the current value and the one or more historical values of the first secured component;
sending one or more network messages comprising an identifier of the data object, the first value data, and the first access control list data;
further storing computer-executable second instructions which when executed cause one or more second processors to perform a second method, the second method comprising:
storing second value data in a second database, the second value data comprising a current value and one or more historical values of a second secured component of the data object, the second secured component associated in the second database with a second secured component identifier that is different than the first secured component identifier, the data object associated in the second database with the data object identifier, a change made to the first database to be propagated to the second database;
storing second access control list data in the second database, the second access control list data comprising a current access control list and one or more historical access control lists governing, with respect to the second database, access to the current value and the one or more historical values of the second secured component;
receiving the one or more network messages related to a change in the first access control list data;
comparing the first value data to the second value data;
comparing the first access control list data to the second access control list data;
responsive to determining that the first value data matches the second value data and the first access control list data matches the second access control list data, identifying the second secured component as being associated with the first secured component and replacing, in the second database, each of the current access control list and the one or more historical access control lists in the second access control list data with the current access control list from the first access control list data.
14 . The one or more non-transitory storage media of claim 13 ,
wherein change records for the first secured component are identified in the first database using a first identifier, wherein change records for the second secured component are identified in the second database using a second identifier, wherein the first identifier cannot be used to identify, in the second database, change records for the second secured component, wherein the second identifier cannot be used to identify, in the first database, change records for the first secured component.
15 . The one or more non-transitory storage media of claim 13 ,
wherein the first instructions when executed further cause the one or more first processors:
to store first component type data in the first database, the first component type data comprising a current component type and one or more historical component types of the first secured component;
to send one or more network messages comprising an identifier of the data object, the first value data, the first access control list data, and the first component type data;
wherein the second instructions when executed further cause the one or more second processors:
to store second component type data in the second database, the second component type data comprising a current component type and one or more historical component types of the second secured component;
to compare the first component type data with the second component type data;
responsive to determining that the first value data matches the second value data, the first access control list data matches the second access control list data, and the first component type data matches the second component type data, to replace, in the second access control list data in the second database, each of the current access control list and the one or more historical access control lists in the second access control list data with the current access control list from the first access control list data.
16 . The one or more non-transitory storage media of claim 13 ,
wherein the first secured component and the second secured component are both properties of the data object, the first secured component and the second secured component having the same property name.
17 . The one or more non-transitory storage media of claim 13 ,
wherein each access control list in the first access control list data comprises one or more access control items, each access control item comprising a user or a group of users and one or more permissions of the user or the group of users with respect to the first secured component, wherein each access control list in the second access control list data comprises one or more access control items, each access control item comprising a user or a group of users and one or more permissions of the user or the group of users with respect to the second secured component.
18 . The one or more non-transitory storage media of claim 13 ,
wherein the first instructions when executed further cause the one or more first processors to store the first value data in one or more first change records in the first database, each change record of the one or more first change records corresponding to the current value or one of the one or more historical values of the first secured component, wherein the second instructions when executed further cause the one or more second processors to store the second value data in one or more second change records in the second database, each change record of the one or more second change records corresponding to the current value or one of the one or more historical values of the second secured component.
19 . The one or more non-transitory storage media of claim 13 ,
wherein the current access control list of the second access control data is the same as the current access control list of the first access control data, wherein the second instructions when executed further cause the one or more second processors to store the current access control list of the first access control data in the second database as the current access control list of the second access control data in response to receiving the one or more network messages.
20 . The one or more non-transitory storage media of claim 13 ,
wherein the current value of the second value data is the same as the current value of the first value data, wherein the second instructions when executed further cause the one or more processors to store the current value of the first value data in the second database as the current value of the second value data in response to receiving the one or more network messages.Join the waitlist — get patent alerts
Track US2019356667A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.