Proximity based data access restrictions
Abstract
An example method may include a processing system including at least one processor detecting an interaction of a first user and a second user, providing a temporary authorization to the second user to access a data set based upon an authorization of the first user to access the data set, wherein the providing the temporary authorization is in response to the detecting the interaction, generating a record of an access of the second user to the data set, wherein the record includes a notation of the temporary authorization of the second user to access the data set based upon the authorization of the first user, detecting an end to the interaction of the first user and the second user, and revoking the temporary authorization of the second user to access the data set in response to the detecting of the end of the interaction.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
detecting, by a server deployed in a communication network, the server including at least one processor, an interaction at a physical location between a first user at the physical location and a second user at the physical location, wherein the detecting the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a presence of the first user and the second user at the physical location, wherein the presence of the first user at the physical location is detected via a detection of biometric data of the first user at the physical location; providing, by the server, a temporary authorization to the second user to access a data set stored in a database system via a device of the second user based upon an authorization level of the first user to access the data set, wherein the temporary authorization is provided by the server in response to the server detecting the interaction at the physical location, wherein the device of the second user is distinct from the server; generating, by the server, a record of an access of the second user to the data set via the device of the second user, wherein the record includes a notation of the temporary authorization of the second user to access the data set based upon the authorization of the first user, wherein the access includes a database query via the device of the second user that results in a modification to the data set that is stored in the database system; detecting, by the server, an end to the interaction at the physical location between the first user at the physical location and the second user at the physical location; and revoking, by the server, the temporary authorization of the second user to access the data set in response to the detecting of the end of the interaction at the physical location.
2 . The method of claim 1 , wherein the temporary authorization to the second user comprises at least a portion of privileges of the authorization level of the first user to access the data set.
3 . The method of claim 1 , wherein the access of the second user to the data set comprises a display of at least a portion of data from the data set via the device of the second user.
4 . The method of claim 3 , further comprising:
determining that the data from the data set contains restricted data; altering the restricted data of the data from the data set; and providing the restricted data that is altered to the device of the second user.
5 . The method of claim 4 , wherein the display of the at least a portion of the data from the data set via the device of the second user is in response to the database query.
6 . The method of claim 5 , wherein the restricted data comprises information that is unrelated to the database query.
7 . The method of claim 1 , wherein the presence of the second user at the physical location is detected via at least one of:
a biometric detection of the second user at the physical location; a detection of a mobile endpoint device of the second user at the physical location; or a detection of an identification badge of the second user at the physical location.
8 . The method of claim 1 , wherein the detecting the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises:
obtaining a verification from the first user of the interaction at the physical location between the first user and the second user, or determining a body orientation of the first user from the biometric data.
9 . The method of claim 1 , wherein the detecting the end to the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a presence of the first user or the second user at a different physical location.
10 . The method of claim 1 , wherein the presence of the second user is determined in response to a login of the second user at the device of the second user.
11 . The method of claim 1 , wherein the detecting the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a collaboration session between a device of the first user and the device of the second user.
12 . The method of claim 11 , wherein the detecting the end to the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a termination of the collaboration session.
13 . A server comprising:
a processing system including at least one processor; and a non-transitory computer-readable medium storing instructions which, when executed by the processing system when deployed in a communication network, cause the processing system to perform operations, the operations comprising:
detecting an interaction at a physical location between a first user at the physical location and a second user at the physical location, wherein the detecting the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a presence of the first user and the second user at the physical location, wherein the presence of the first user at the physical location is detected via a detection of biometric data of the first user at the physical location;
providing a temporary authorization to the second user to access a data set stored in a database system via a device of the second user based upon an authorization level of the first user to access the data set, wherein the temporary authorization is provided by the processing system in response to the processing system detecting the interaction at the physical location, wherein the device of the second user is distinct from the processing system;
generating a record of an access of the second user to the data set via the device of the second user, wherein the record includes a notation of the temporary authorization of the second user to access the data set based upon the authorization of the first user, wherein the access includes a database query via the device of the second user that results in a modification to the data set that is stored in the database system;
detecting an end to the interaction at the physical location between the first user at the physical location and the second user at the physical location; and
revoking the temporary authorization of the second user to access the data set in response to the detecting of the end of the interaction at the physical location.
14 . The server of claim 13 , wherein the temporary authorization to the second user comprises at least a portion of privileges of the authorization level of the first user to access the data set.
15 . The server of claim 13 , wherein the access of the second user to the data set comprises a display of at least a portion of data from the data set via the device of the second user.
16 . The server of claim 15 , the operations further comprising:
determining that the data from the data set contains restricted data; altering the restricted data of the data from the data set; and providing the restricted data that is altered to the device of the second user.
17 . The server of claim 16 , wherein the display of the at least a portion of the data from the data set via the device of the second user is in response to the database query.
18 . The server of claim 17 , wherein the restricted data comprises information that is unrelated to the database query.
19 . The server of claim 13 , wherein the presence of the second user at the physical location is detected via at least one of:
a biometric detection of the second user at the physical location; a detection of a mobile endpoint device of the second user at the physical location; or a detection of an identification badge of the second user at the physical location.
20 . A non-transitory computer-readable medium storing instructions which, when executed by a processor, cause the processor to perform operations, the operations comprising:
detecting an interaction at a physical location between a first user at the physical location and a second user at the physical location, wherein the detecting the interaction at the physical location between the first user at the physical location and the second user at the physical location comprises detecting a presence of the first user and the second user at the physical location, wherein the presence of the first user at the physical location is detected via a detection of biometric data of the first user at the physical location; providing a temporary authorization to the second user to access a data set stored in a database system via a device of the second user based upon an authorization level of the first user to access the data set, wherein the temporary authorization is provided by the processing system in response to the processing system detecting the interaction at the physical location, wherein the device of the second user is distinct from the processing system; generating a record of an access of the second user to the data set via the device of the second user, wherein the record includes a notation of the temporary authorization of the second user to access the data set based upon the authorization of the first user, wherein the access includes a database query via the device of the second user that results in a modification to the data set that is stored in the database system; detecting an end to the interaction at the physical location between the first user at the physical location and the second user at the physical location; and revoking the temporary authorization of the second user to access the data set in response to the detecting of the end of the interaction at the physical location.Join the waitlist — get patent alerts
Track US2022052998A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.