WO2009055083A1 - Real-time interactive authorization for enterprise search - Google Patents
Real-time interactive authorization for enterprise search Download PDFInfo
- Publication number
- WO2009055083A1 WO2009055083A1 PCT/US2008/058374 US2008058374W WO2009055083A1 WO 2009055083 A1 WO2009055083 A1 WO 2009055083A1 US 2008058374 W US2008058374 W US 2008058374W WO 2009055083 A1 WO2009055083 A1 WO 2009055083A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- user
- access
- document
- documents
- search
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/604—Tools and structures for managing or administering access control systems
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F16/00—Information retrieval; Database structures therefor; File system structures therefor
- G06F16/90—Details of database functions independent of the retrieved data types
- G06F16/95—Retrieval from the web
- G06F16/953—Querying, e.g. by the use of web search engines
- G06F16/9535—Search customisation based on user profiles and personalisation
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6218—Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
Definitions
- the present invention relates to providing user access to one or more documents in a collaborative computing environment through a search engine and, more particularly, to techniques for obtaining real-time grants of access from a supervising entity to one or more documents in which the user has limited access.
- Principles of the present invention provide techniques for providing at least one user access to one or more documents in a collaborative computing environment and, more particularly, techniques for obtaining, through a search engine, real-time grants of access from a supervising entity to one or more documents in which the user has limited access.
- a computer-based technique for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine is provided.
- a user is presented with search results, wherein the search results comprise at least one document comprising at least one portion to which the user has no access.
- a request from the user for access to the at least one document is received.
- a supervising entity is then notified of the user request to access the at least one document.
- An instruction from the supervising entity is then received. In accordance with the received instruction, the user is granted access to the at least one document.
- the one or more documents which are presented to the user in the search results may be selected in accordance with at least one of identity of the user, a policy of the collaborative system, and an access control list.
- the supervising entity may increase or decrease user access to one or more documents via the search engine.
- the search engine may track at least one of user access to the one or more documents, grants of access to the one or more documents, and levels of access to the one or more documents.
- a computer-based method provides for a user obtaining access to one or more documents in a collaborative computing environment using a search engine.
- the user searches for one or more documents, wherein the search engine provides search results comprising at least one document, the at least one document comprising at least one portion to which the user has no access.
- the user requests access to the at least one document using the search engine, wherein the search engine notifies a supervising entity of the request.
- the user receives access to the at least one document through the search engine.
- a computer-based method provides for a supervising entity granting user access to one or more documents in a collaborative computing environment using a search engine.
- the supervising entity indexes the one or more documents using the search engine, wherein at least one of the one or more documents comprises at least one portion to which the user has no access.
- the supervising entity then receives notification from the search engine of any user request to access the at least one document.
- the supervising entity then instructs the search engine to provide the user with access to the at least one document.
- an apparatus for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine which includes memory and at least one processor coupled to the memory.
- the processor is operative to present the user with search results, wherein the search results comprise at least one document comprising at least one portion to which the user has no access. If the user wants access to a particular document, the processor is further operative to receive a request from the user for access to the at least one document. After receiving a request for access, the processor is further operative to notify a supervising entity of the user request to access the at least one document, receive an instruction from the supervising entity with regard to the request, and grant access to the user to the at least one document in accordance with the received instruction.
- FIG. 1 is a diagram illustrating an example of a computer-based system for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine, according to an embodiment of the present invention
- FIG. 2 is a flow diagram illustrating a methodology for a search engine providing at least one user access to one or more documents in a collaborative computing environment, according to an embodiment of the present invention
- FIG. 3 is a flow diagram illustrating a methodology for a user obtaining access to one or more documents in a collaborative computing environment using a search engine, according to an embodiment of the present invention
- FIG. 4 is a flow diagram illustrating a methodology for a supervising entity granting a user access to one or more documents in a collaborative computing environment, according to an embodiment of the present invention
- FIG. 5 is a flow diagram illustrating an example workflow, according to an embodiment of the present invention
- FIG. 6 is a flow diagram illustrating a methodology for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine, according to an embodiment of the present invention
- FIGs. 7 A and 7B are a flow diagram illustrating the methodology of FIG. 6 as applied to a given example, according to an embodiment of the present invention
- FIG. 8 is a diagram illustrating an illustrative hardware implementation of a computing system in accordance with which one or more components/methodologies of the present invention may be implemented, according to an embodiment of the present invention.
- principles of the present invention provide techniques for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine. More specifically, an embodiment of the present invention includes techniques for granting access to the user to at least one document comprising at least one portion to which the user has no access in accordance with an instruction from a supervising entity. The principles of the present invention will be illustrated herein in conjunction with an exemplary technique for providing at least one user access to one or more documents in a collaborative computing environment using a search engine.
- entity as used herein is intended to be construed broadly so as to encompass, by way of example and without limitation, any organized group (e.g., a corporation, partnership, etc.).
- workflow as used herein is intended to be construed broadly so as to encompass, by way of example and without limitation, any set of fixed instructions which are used to complete a process.
- collaboration computing environment as used herein is intended to be construed broadly so as to encompass, by way of example and without limitation, any forum where multiple parties are in communication with each other due to a common interest (e.g., internet teleconference, virtual chat, e-mail, etc.)
- the term "supervising entity” as used herein is intended to be construed broadly so as to encompass, by way of example and without limitation, any party that has the authority to grant a user access to a document, which may include, but is not limited to, an employer, administrator, manager, supervisor, or automated system.
- virtual repository as used herein is intended to be construed broadly so as to encompass, by way of example and without limitation, any collection of pointers to documents, wherein the documents are stored at various locations.
- a key challenge in providing user access to one or more documents in a collaborative computing environment in accordance with a search engine is streamlining the process for accessing documents of interest.
- conventional methods only allow users to see documents they have access to. Therefore, access-restricted documents are identified indirectly (e.g., word-of-mouth, reading related documents, guesswork, etc.). This is both time-consuming and resource draining.
- FIG. 1 a diagram illustrates an example of a computer-based system for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine, according to an embodiment of the present invention.
- System 100 illustrates the principle components of an improved enterprise search system.
- the enterprise search system is a collaborative computing environment composed of multiple users connected by a networked communications system.
- the end user terminal 105 is a network computing device from which an end user can initiate searches against an enterprise search server 120.
- the end user terminal is a laptop computer equipped with a wireless network interface which runs an internet browser (e.g., Microsoft Internet Explorer, Firefox, etc.).
- an internet browser e.g., Microsoft Internet Explorer, Firefox, etc.
- the preferred end user terminal is also capable of displaying text, graphics, and multimedia documents such as plain text files, Hypertext Markup Language (HTML) web pages, Microsoft Office rich-text documents, Adobe Acrobat files, bitmaps, and digital audio and video files.
- the end user terminal is a hand-held device, e.g., a Personal Digital Assistant (PDA) or a cell phone.
- PDA Personal Digital Assistant
- the end user terminal may also be a desktop computer or a cable- network set-top box.
- One or more credentials 110 are used to identify the user operating the end user terminal.
- the credentials can contain a logon user-id, a digital certificate, a search history, an employee serial number, or other identifying information.
- the credentials may also directly contain, or indirectly reference, the job of an individual within an enterprise, the manager of the individual, department, work history, and assigned projects.
- the types and formats of credentials are well-known to practitioners of enterprise system management.
- the end user terminal is connected 116(a) to a computer network 115.
- this network is an enterprise network using the well-known IP (Internet Protocol) infrastructure.
- the network is further comprised of satellite networks, public internet networks, wireless networks, additional private enterprise networks, Virtual Private Networks (VPNs), telephone networks, and/or cell phone networks.
- the network serves to allow digital communication between the end user terminal, the enterprise search server 120, the document server 130, the workflow server 140, and the document administrator terminal 150.
- the terminals 105 and 150, and servers 120, 130, 140 are simultaneously connected 116(a)-(e) to the network 115.
- the devices 105, 120, 130, 140, and 150 may be temporarily disconnected from the network, e.g., they may poll the network by connecting and disconnecting at periodic intervals, or require an outside event such as a telephone call, fax, e-mail or instant message to initiate a connection to the network.
- Server 120 is a computer which executes an Enterprise Search Service 125. This service allows an end user to search one or more document collections 170.
- the documents 170(a)-(c) contained within the document collections are part of a virtual repository wherein the documents are stored at various locations across the network.
- the IBM OmniFind Enterprise Edition is one such an enterprise search service. It allows searches to be conducted over document collections retrieved through server 130, which maintains secure intranets, corporate public websites, and information extraction applications.
- the Enterprise Search Service maintains one or more Search Indices 160 which indexes documents, e.g., 170(a), 170(b), 170(c), within the document collection.
- the search index comprises one or more index records 161(a), 161 (b), and 161 (c) which contain information about a specific document of the document collection.
- the index records 161(a), 161 (b), and 161 (c) contain fields identifying access control 162, optional workflow 164, and an optional non-confidential synopsis 166 of a document. And optionally, policies of the collaborative system 168.
- the access control field 162 enables the Enterprise Search Service to compare the credentials of an end user and determine if the end user is permitted to view a given document.
- the Enterprise Search Service may also consider additional policies of the collaborative system 168 before permitting end users to view documents. For example, a policy of the enterprise may state that end users can not preview or access any personal e-mails of executive officers.
- the access control field further enables the Enterprise Search Service to compare the credentials of an end user and determine if the end user is permitted to search within a given document.
- the access control field also conditionally enables search access within selective portions of a given document. For example, a policy of the enterprise may state that end users can not access the portion of a contract document which contains financial specifics, but end users may search within the terms of service portion of contracts. Another policy may state that end users may search through the full text of a publication but their preview and viewing access is limited to the abstract or bibliography sections of the publications. A policy may state that end users may not search within attachments to documents. Hence, policies may be used to limit or restrict access to one or more documents.
- the workflow field 164 identifies one or more workflows. Each workflow describes a series of steps that may conditionally grant end users access to the associated document.
- An example workflow includes the steps of: composing a message containing the text of the search query inputted by the end user, the name of the document of interest, and the credentials of the end user; sending the message as an instant message to the administrator of the document collection; receiving instructions and approval from the administrator; and then amending the credentials of the end user to permit access to the document of interest.
- Workflows are interpreted and executed by a Workflow Server 140. It should be noted that the workflow incorporates administrator contact information which is referenced when sending messages to administrators.
- the optional non-confidential synopsis field 166 contains a brief synopsis of the contents of a document. Furthermore, the synopsis may only contain segments of the document that the user has access to preview. In a preferred embodiment, the non-confidential synopsis of the document of interest is presented to the user at the end user terminal. Viewing a synopsis allows the end user to make the decision to initiate a workflow. In alternate embodiments, the non-confidential synopsis is generated automatically by the Enterprise Search Service after a search has been executed.
- the Document Retrieval Service 135. receives requests from the end user terminal and retrieves documents from a document collection. The retrieval is dependent upon the credentials of the end user and the access control lists 172 of the document collection. Examples of document retrieval services include: web servers, J2EE application servers, relational database systems, ftp servers, multimedia servers, and content management systems, such as the Lotus Domino Document Manager, and IBM Lotus Notes and Domino 8.
- the document retrieval service retrieves documents from one or more document collections.
- the documents can be text files 174(a), documents from a word processor 174(b), scanned images (e.g., fax or bitmaps) 174(c), vector graphics files 174(d), and multi-media files 174(e) containing audio or video clips.
- Each document is associated with an access control list which identifies the necessary credentials required for retrieval.
- the access control list will typically specify necessary credentials for read access and write access.
- the access control list may, optionally, specify necessary credentials to enable copying, printing, modifying or cutting and/or pasting of the document. It may specify a different, possibly broader, set of credentials necessary to search within the document.
- the access control list may identify credentials for access to portions of the document. For instance, an access control list may allow access to certain cells or sheets within a Microsoft Excel spreadsheet. An access control list may allow search access to the lecture notes or transcripts of a video presentation but not necessarily allow playback of the video content.
- the Enterprise Search Service 125 is notified and the access control 162 fields for the respective search index 160 are updated whenever an access control list 172 is changed.
- Server 140 is a computer which directs execution of the workflows.
- Workflow servers are well-known in the art.
- Production workflow servers may execute software such as IBM's MQ Workflow Server and Adobe's Workflow Server.
- Software for custom workflow servers may also be developed to meet unique workflow requirements.
- servers 120, 130, and 140 may be combined into one physical computer. Furthermore, the servers may be distributed and/or clustered over multiple computers.
- the document administrator terminal 150 is where supervising entities can receive end user requests for access, control access to documents, and track access to documents.
- end user requests for access to specific documents are forwarded from the workflow server.
- a supervising entity has the ability to modify the access control lists, to grant or remove types of access and to set access control policies.
- the supervising entity can approve or deny a request for access after considering user information and information about the requested document, which are both forwarded with the request for access.
- the supervising entity can control access to documents by providing varying levels of access to the end user.
- the supervising entity may increase or decrease access to documents by unblocking or blocking, respectively, portions of the requested documents. Further, the supervising entity may set access time limits.
- the instruction to increase or decrease access is sent to the workflow server where the instruction is processed and implemented.
- the implementation of an instruction may include amending the credentials of an end user or creating redacted versions of the originally requested document.
- the supervising entity via the document administrator terminal, can include or exclude documents from the document collections and include or exclude documents from the search index at any time. Also, at any time, the supervising entity can create varying levels of access to particular documents by blocking or unblocking portions of documents as described above.
- a document access tracking system 180 allows the supervising entity to track grants of access to one or more documents, user access to one or more documents, and levels of access to one or more documents via the document administrator terminal.
- the tracking data may be stored at either the enterprise search server, document retrieval server, or the workflow server. In an alternate embodiment, the tracking data may be mirrored across the entire collaborative system.
- Methodology 200 begins at block 202 where the search engine presents the user with search results in response to a user query. If a document is inaccessible to the user, the search engine may receive a request from the user for access to the document 204. In response, the search engine notifies the supervising entity in charge of granting access to the specific document of the user request 206. The search engine then waits to receive an instruction from the supervising entity with regard to the user request 208. After receiving an instruction, the search engine may grant access to the user based on the instruction 210.
- Methodology 300 begins at block 302 where the user searches for documents of interest with a search engine provided by the enterprise search system. After finding an inaccessible document of interest, the user can request access to the document via the search engine 304. The search engine processes the request and responds. If the request is approved, the user receives access to the requested document through the search engine 306.
- Methodology 400 begins at block 402 where a supervising entity indexes one or more documents into a collaborative computing environment using a search engine. The supervising entity then receives notification of any user requests to access inaccessible documents 404. Depending on factors such as user credentials and sensitivity of the document, the supervising entity can instruct the search engine to provide varying levels of access 406.
- Workflow 500 begins at block 502 where, after invoked, the workflow processes a user request for access. This includes, but is not limited to, obtaining query information, user information, and document information. After processing the request information, the workflow then locates and composes a message to the supervising entity in charge of granting access to the document of interest 504. This message is then sent to the supervising entity 506. After sending the message, the workflow waits to receive a response from the supervising entity 508. Any received instruction is processed and the workflow changes user access accordingly 510. After changes are made, the workflow notifies any parties that may be interested in the change of access 512. This may include the user who requested access, the supervising entity who granted access, and any additional supervising entities.
- Process 600 shows the steps to gain real-time access control through enterprise search.
- the process begins at 605 when an end user requests a search 610 through an end user terminal.
- this search is made through a web interface.
- the search can be initiated through a cell phone, set-top box, instant message communications system, or some other graphical-user-interface (GUI).
- GUI graphical-user-interface
- the search request 611 includes a search criteria 612 and user credentials 110.
- the search criteria is in the form of concepts and words. Such search requests are well- known in the art.
- An enterprise search service receives the search request and executes the search 615.
- the enterprise search service identifies zero or more documents which match the search criteria given in the search request. These results are known as "search hits" 630.
- the enterprise search service partitions the search hits into three groups 620: (i) documents in which the user is allowed to view because the user is included in the access control list; (ii) documents in which the user is not allowed to view, wherein these hits are discarded from the search results and are typically not presented to the user; and (iii) documents where the end user could potentially obtain access by executing a workflow.
- Each search hit within the third group is annotated 625 with an optional non-confidential synopsis and a reference to an associated workflow.
- the search hit is further annotated with state information 632 which contains the search criteria presented during the search request. All this information is stored within a hit result data structure 626.
- the state information also includes prior search history (e.g., previously executed search criteria and/or search hits).
- the enterprise search index is encoded to allow fast retrieval, categorization, and filtering such that the steps of categorization and annotation (620, 625, 630) are performed in-line with the search execution 615.
- the search hits and hit results are then transmitted to the end user terminal and presented to the end user 650.
- the search hits are displayed within a webpage.
- the webpage displays a short synopsis or text surrounding a hit within a matching document, as well as the name, size, and format of the document.
- hyperlinks or other user interface controls are provided for retrieval of the document.
- a workflow 660 This may involve a workflow service where the service obtains access request information and selects a workflow 662.
- the access request data structure includes the state, search hit, and end user credentials or information.
- the selected workflow then triggers a request to the document administrator for access to the restricted document 663.
- the workflow transmits the access request information to a document administrator terminal.
- the workflow is executed in the web browser of the end user terminal using a scripting language such as JavaScript.
- all or part of the workflow is executed by the enterprise search service through a J2EE web application.
- the administrator reviews the request for access 670, which may include state information and end user credential information, and decides whether or not to grant access to the requested search hit document 675.
- the document administrator takes into consideration the job position of the user. For example, if the end user is requesting a sales document and has a sufficiently senior position within the sales department, then access may be granted. At this point, the document administrator may initiate further workflows or consult with other individuals or databases as necessary.
- the process ends 699. If the document administrator approves access 680, the workflow service is notified to grant access 664 and the user credentials and/or access controls of the document or document collection are updated. In a preferred embodiment, the document administrator may grant access to the entire document collection, or a portion of it, so as to anticipate future requests by the end user for access to other documents within the collection. Further, in an additional embodiment, the document administrator may, optionally, accompany the approval with specific instructions 682. These instructions may include blocking or unblocking portions of particular documents (e.g., sensitive text), in effect limiting or expanding user access to sensitive documents. Also, in an alternate embodiment, the instruction may set time limits to grants of access to prevent unlimited access to sensitive documents.
- the affected access control fields of the search index are also updated. Depending on the implementation of the enterprise search service, this may not be practical in realtime and this updating is optional.
- the function of the document administrator is automated and any or all requests are processed through an administrator service rather than by an individual. Further, there may be a team of document administrators who receive requests through a common queue or through other distribution means (e.g. database, instant messaging group or shared e-mail account).
- notifications are sent to document owners and administrators 665. Further, the end user is notified of the grant of access 666. Typical means of notification are through e-mail, instant messaging, or fax. Further, the steps of notification and granting of access may be performed in parallel. In an optional step, the user may be required to receive a notice of approval before viewing the document 690. This is an extra security measure to prevent unlawful access to documents and can be implemented by using a token, an authentication certificate, or cookie. The token, certificate, or cookie may be attached to the user notification and the user presents the token, certificate, or cookie at the time of viewing the document of interest. If this step is omitted, execution continues to 695.
- the document retrieval service will now permit the end user to retrieve the document since the user now has the appropriate credentials 695.
- the user can re-execute the search request and view the document of interest without restrictions.
- FIGs. 7A and 7B a flow diagram illustrates the methodology of FIG. 6 as applied to a given example, according to an embodiment of the present invention.
- block 700 illustrates one embodiment of the present invention.
- a sales executive in Atlanta, Georgia is researching "Win Strategies" in the telecommunications sector.
- the sales executive is looking for the best practices and ideas which will help him win more business deals.
- the sales executive first logs on to an enterprise search website 702 using his personal computer or end user terminal 105.
- the sales executive first issues a very general search, "cell network win strategy" 704.
- the enterprise search service 125 returns too many hits 706.
- the sales executive then issues a more focused search, "cell network win strategy Asia Pacific” 704.
- the search service executes the search and returns a more manageable number of hits 710.
- the search results are presented to the sales executive on his web browser 712 in an easy to read format.
- the sales executive scans the search results 714 by reading the descriptions of the documents which are displayed with the search results.
- the sales executive finds a business analysis document that seems to be relevant 716.
- This document contains confidential information and is not generally available to employees.
- the confidential document is labeled with a "lock" icon which means that the document is not directly accessible, but could potentially be accessible if the link were followed.
- the sales executive simply requests access to view the document by clicking on the icon 718. If using a conventional search system, the sales executive would have to fend for himself and figure out how to get access to the document on his own.
- the sales executive would not know how to request access because he does not know where the document is or who can grant access.
- a user would have to resort to backtracking with the URL, issuing other searches to box around the document, or network with peers (e.g., telephone, instant messaging, or through e-mail).
- the web browser prepares the access request 720. This process includes creating an information packet of end user credentials, state information, and search hit information 722.
- the web browser then transmits the access request to a workflow service 724.
- the sales executive's search query, name, job position and department, along with the name of the document he is requesting is forwarded to a workflow server.
- the workflow service takes the forwarded information and loads a workflow 726.
- the workflow is interpreted 728 and a work ticket is generated 730.
- the workflow locates and forwards the request information to a marketing program manager in the Hong Kong office 732.
- an access request message then appears on the desktop of an executive assistant in Hong Kong 734. This assistant either approves the request immediately or gathers additional information from the sales executive using collaborative software 736.
- the workflow continues and a change-request is created to grant the sales executive read access to all business analysis documents maintained by the Hong Kong marketing office 742.
- the workflow service then notifies the sales executive via e-mail or instant message 742.
- the workflow also sends various administrative e-mails, opens and closes work tickets as appropriate 744, and ends the workflow 746.
- Creation and processing of the change- request causes the access control lists 172 of all relevant documents to be updated so that the sales executive is permitted read access. This update, in turn, causes the Enterprise Search Service to update its indices 160 so that if the sales executive makes any future searches, the sales executive will no longer see lock icons next to any hits that reference the Hong Kong business analysis documents collection 750.
- block diagram 800 illustrates an exemplary hardware implementation of a computing system in accordance with which one or more components/methodologies of the invention (e.g., components/methodologies described in the context of FIGs. 1-7B) may be implemented, according to an embodiment of the present invention.
- the techniques for providing at least one user access to one or more documents in a collaborative computing environment in accordance with a search engine may be implemented in accordance with a processor 810, a memory 812, I/O devices 814, and a network interface 816, coupled via a computer bus 818 or alternate connection arrangement.
- processor as used herein is intended to include any processing device, such as, for example, one that includes a CPU (central processing unit) and/or other processing circuitry. It is also to be understood that the term “processor” may refer to more than one processing device and that various elements associated with a processing device may be shared by other processing devices.
- memory as used herein is intended to include memory associated with a processor or CPU, such as, for example, RAM, ROM, a fixed memory device (e.g., hard drive), a removable memory device (e.g., diskette), flash memory, etc.
- input/output devices or "I/O devices” as used herein is intended to include, for example, one or more input devices (e.g., keyboard, mouse, scanner, etc.) for entering data to the processing unit, and/or one or more output devices (e.g., speaker, display, printer, etc.) for presenting results associated with the processing unit.
- output devices e.g., speaker, display, printer, etc.
- network interface as used herein is intended to include, for example, one or more transceivers to permit the computer system to communicate with another computer system via an appropriate communications protocol.
- Software components including instructions or code for performing the methodologies described herein may be stored in one or more of the associated memory devices (e.g., ROM, fixed or removable memory) and, when ready to be utilized, loaded in part or in whole (e.g., into RAM) and executed by a CPU.
- ROM read-only memory
- RAM random access memory
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Databases & Information Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Software Systems (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Health & Medical Sciences (AREA)
- Automation & Control Theory (AREA)
- Data Mining & Analysis (AREA)
- Storage Device Security (AREA)
- Information Transfer Between Computers (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN200880113120A CN101836185A (en) | 2007-10-25 | 2008-03-27 | Real-time interactive authorization for enterprise search |
| JP2010531082A JP2011503688A (en) | 2007-10-25 | 2008-03-27 | Real-time interactive authentication method and apparatus for in-company search |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US11/924,219 | 2007-10-25 | ||
| US11/924,219 US9020913B2 (en) | 2007-10-25 | 2007-10-25 | Real-time interactive authorization for enterprise search |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2009055083A1 true WO2009055083A1 (en) | 2009-04-30 |
Family
ID=40579888
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/US2008/058374 Ceased WO2009055083A1 (en) | 2007-10-25 | 2008-03-27 | Real-time interactive authorization for enterprise search |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US9020913B2 (en) |
| JP (1) | JP2011503688A (en) |
| KR (1) | KR20100072014A (en) |
| CN (1) | CN101836185A (en) |
| WO (1) | WO2009055083A1 (en) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2012043144A (en) * | 2010-08-18 | 2012-03-01 | Casio Comput Co Ltd | Server based computing system and program |
| WO2014099826A1 (en) * | 2012-12-19 | 2014-06-26 | Microsoft Corporation | Orchestrated interaction in access control evaluation |
| WO2016069272A1 (en) * | 2014-10-26 | 2016-05-06 | Microsoft Technology Licensing, Llc | Access blocking for data loss prevention in collaborative environments |
Families Citing this family (31)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8078624B2 (en) * | 2007-12-20 | 2011-12-13 | International Business Machines Corporation | Content searching for portals having secure content |
| US20090265624A1 (en) * | 2008-04-18 | 2009-10-22 | Reiji Fukuda | Electronic forms preparing and managing system, electronic forms preparing and managing program, and program storing memory media |
| US20100262624A1 (en) * | 2009-04-14 | 2010-10-14 | Microsoft Corporation | Discovery of inaccessible computer resources |
| RU2602790C2 (en) * | 2011-02-01 | 2016-11-20 | Конинклейке Филипс Электроникс Н.В. | Secure access to personal health records in emergency situations |
| US20120246150A1 (en) * | 2011-03-23 | 2012-09-27 | Raytheon Company | System and Method for Storing Data and Providing Multi-Level Access Thereto |
| HUP1200427A2 (en) * | 2012-07-18 | 2014-02-28 | Initon Informatikai Fejlesztoe | System and method for providing service |
| CN103269268A (en) * | 2013-04-28 | 2013-08-28 | 苏州亿倍信息技术有限公司 | Method and system for managing information safety |
| US9547699B2 (en) | 2013-09-09 | 2017-01-17 | Microsoft Technology Licensing, Llc | Providing enhanced connection data for shared resources |
| US9531722B1 (en) | 2013-10-31 | 2016-12-27 | Google Inc. | Methods for generating an activity stream |
| US9542457B1 (en) * | 2013-11-07 | 2017-01-10 | Google Inc. | Methods for displaying object history information |
| US9614880B1 (en) | 2013-11-12 | 2017-04-04 | Google Inc. | Methods for real-time notifications in an activity stream |
| US9817987B2 (en) | 2013-12-23 | 2017-11-14 | Dropbox, Inc. | Restricting access to content |
| US9509772B1 (en) | 2014-02-13 | 2016-11-29 | Google Inc. | Visualization and control of ongoing ingress actions |
| US20150262190A1 (en) * | 2014-03-14 | 2015-09-17 | Disney Enterprises, Inc. | Methods and Systems for Determining Consumer Entitlements for Playback Interoperability |
| JP6435628B2 (en) * | 2014-04-18 | 2018-12-12 | 株式会社リコー | Information processing system, information processing apparatus, and program |
| US9536199B1 (en) | 2014-06-09 | 2017-01-03 | Google Inc. | Recommendations based on device usage |
| US9507791B2 (en) | 2014-06-12 | 2016-11-29 | Google Inc. | Storage system user interface with floating file collection |
| US10078781B2 (en) | 2014-06-13 | 2018-09-18 | Google Llc | Automatically organizing images |
| CN106233292B (en) | 2014-06-24 | 2019-07-16 | 惠普发展公司有限责任合伙企业 | Synthesize document access |
| US9609032B2 (en) * | 2014-06-26 | 2017-03-28 | Microsoft Technology Licensing, Llc | Joint ownership of protected information |
| US9798726B2 (en) | 2014-06-26 | 2017-10-24 | International Business Machines Corporation | Identifying content under access control |
| US9870420B2 (en) | 2015-01-19 | 2018-01-16 | Google Llc | Classification and storage of documents |
| WO2017020947A1 (en) * | 2015-08-03 | 2017-02-09 | Hewlett-Packard Development Company L.P. | Document access |
| US10097557B2 (en) * | 2015-10-01 | 2018-10-09 | Lam Research Corporation | Virtual collaboration systems and methods |
| CN105847119A (en) * | 2016-04-01 | 2016-08-10 | 乐视控股(北京)有限公司 | Method and device of rapidly searching for contact person mails |
| US11062035B2 (en) * | 2018-04-30 | 2021-07-13 | Innoplexus Ag | Secure document management using blockchain |
| US10341824B1 (en) | 2018-06-11 | 2019-07-02 | Motorola Solutions, Inc. | Method for real-time authorization within a push to talk for the internet of things system |
| US12554872B2 (en) * | 2020-11-24 | 2026-02-17 | Motorola Solutions, Inc. | System and method for notifying users about publicly available data |
| CN112733121B (en) | 2021-01-13 | 2024-09-20 | 京东科技信息技术有限公司 | Data acquisition method, device, equipment and storage medium |
| CN115688149B (en) * | 2023-01-03 | 2023-05-16 | 大熊集团有限公司 | Encrypted data access method and system |
| US20250337747A1 (en) * | 2024-04-29 | 2025-10-30 | Palantir Technologies Inc. | Systems and methods for managing access control to one or more resources |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060053097A1 (en) * | 2004-04-01 | 2006-03-09 | King Martin T | Searching and accessing documents on private networks for use with captures from rendered documents |
| US20060080316A1 (en) * | 2004-10-08 | 2006-04-13 | Meridio Ltd | Multiple indexing of an electronic document to selectively permit access to the content and metadata thereof |
| US20070244867A1 (en) * | 2006-04-13 | 2007-10-18 | Tony Malandain | Knowledge management tool |
Family Cites Families (57)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5109413A (en) | 1986-11-05 | 1992-04-28 | International Business Machines Corporation | Manipulating rights-to-execute in connection with a software copy protection mechanism |
| US5552897A (en) * | 1994-03-07 | 1996-09-03 | At&T Corp. | Secure communication apparatus and method |
| US5887140A (en) * | 1995-03-27 | 1999-03-23 | Kabushiki Kaisha Toshiba | Computer network system and personal identification system adapted for use in the same |
| US6401091B1 (en) | 1995-12-05 | 2002-06-04 | Electronic Data Systems Corporation | Business information repository system and method of operation |
| US5850442A (en) | 1996-03-26 | 1998-12-15 | Entegrity Solutions Corporation | Secure world wide electronic commerce over an open network |
| US5802518A (en) | 1996-06-04 | 1998-09-01 | Multex Systems, Inc. | Information delivery system and method |
| EP0846386A1 (en) | 1996-06-26 | 1998-06-10 | Koninklijke Philips Electronics N.V. | Network access control method, and device and system for implementing this method |
| US5845067A (en) | 1996-09-09 | 1998-12-01 | Porter; Jack Edward | Method and apparatus for document management utilizing a messaging system |
| US5826265A (en) | 1996-12-06 | 1998-10-20 | International Business Machines Corporation | Data management system having shared libraries |
| US7437351B2 (en) | 1997-01-10 | 2008-10-14 | Google Inc. | Method for searching media |
| JPH10232878A (en) * | 1997-02-19 | 1998-09-02 | Hitachi Ltd | Document management method and apparatus |
| US6044378A (en) | 1997-09-29 | 2000-03-28 | International Business Machines Corporation | Method and system for a federated digital library by managing links |
| US6070171A (en) | 1998-05-15 | 2000-05-30 | Palantir Software, Inc. | Method and system for copy-tracking distributed software featuring tokens containing a key field and a usage field |
| US6389541B1 (en) | 1998-05-15 | 2002-05-14 | First Union National Bank | Regulating access to digital content |
| JP4190092B2 (en) | 1998-06-16 | 2008-12-03 | 雅信 鯨田 | Content providing device |
| US6826692B1 (en) | 1998-12-23 | 2004-11-30 | Computer Associates Think, Inc. | Method and apparatus to permit automated server determination for foreign system login |
| WO2000039987A1 (en) | 1998-12-29 | 2000-07-06 | Swisscom Ag | Method and system for making objects available to users of a telecommunications network |
| US6988199B2 (en) | 2000-07-07 | 2006-01-17 | Message Secure | Secure and reliable document delivery |
| FR2804938B1 (en) | 2000-02-16 | 2002-04-26 | Sidel Sa | DEVICE FOR INJECTING A PRODUCT ONTO A PREDETERMINED PLACE OF A MOVING OBJECT |
| JP2001273300A (en) | 2000-03-24 | 2001-10-05 | Maruzen Co Ltd | Electronic paper search and provision service device and electronic paper search and provision service method |
| US6728733B2 (en) | 2000-03-29 | 2004-04-27 | Komatsu Wall System Development Co., Ltd. | System, method, and program product for administrating document file in computerized network system |
| US6970869B1 (en) | 2000-05-09 | 2005-11-29 | Sun Microsystems, Inc. | Method and apparatus to discover services and negotiate capabilities |
| US7028180B1 (en) | 2000-06-09 | 2006-04-11 | Northrop Grumman Corporation | System and method for usage of a role certificate in encryption and as a seal, digital stamp, and signature |
| KR20020041809A (en) * | 2000-06-29 | 2002-06-03 | 요트.게.아. 롤페즈 | Multiple encryption of a single document providing multiple level access privileges |
| US6859806B1 (en) | 2000-07-21 | 2005-02-22 | Ideapath Inc. | System and method for legal docketing using a customizable rules subset |
| US20020128954A1 (en) | 2000-10-24 | 2002-09-12 | Regulus Integrated Solutions, Llc | Electronic trade confirmation system and method |
| ATE552562T1 (en) | 2000-11-10 | 2012-04-15 | Aol Musicnow Llc | DIGITAL CONTENT DISTRIBUTION AND SUBSCRIPTION SYSTEM |
| US7080076B1 (en) | 2000-11-28 | 2006-07-18 | Attenex Corporation | System and method for efficiently drafting a legal document using an authenticated clause table |
| US7024391B2 (en) | 2000-12-04 | 2006-04-04 | Kraft Foods Holdings, Inc. | System, method and program product for sharing information |
| US20030014384A1 (en) | 2001-02-22 | 2003-01-16 | Alan Ewald | Document exchange system |
| JP2003016068A (en) | 2001-03-27 | 2003-01-17 | Seiko Epson Corp | Information providing server, information providing site, program used therefor, and information providing method |
| US20030009691A1 (en) | 2001-07-06 | 2003-01-09 | Lyons Martha L. | Centralized clearinghouse for entitlement information |
| US7299496B2 (en) | 2001-08-14 | 2007-11-20 | Illinois Institute Of Technology | Detection of misuse of authorized access in an information retrieval system |
| US7188150B2 (en) | 2001-08-21 | 2007-03-06 | International Business Machines Corporation | System and method for sharing, searching, and retrieving web-based educational resources |
| JP2003108796A (en) | 2001-09-28 | 2003-04-11 | Basu Plus One:Kk | Document sales system |
| US7051036B2 (en) | 2001-12-03 | 2006-05-23 | Kraft Foods Holdings, Inc. | Computer-implemented system and method for project development |
| US6901401B2 (en) | 2002-03-21 | 2005-05-31 | International Business Machines Corporation | System and method for database integrity via local database lockout |
| JP4265737B2 (en) | 2002-09-20 | 2009-05-20 | 株式会社リコー | Document search apparatus, document search method, document search program, and recording medium |
| US7130877B2 (en) * | 2002-09-30 | 2006-10-31 | Alcatel Canada Inc. | Request processing switch |
| US20040068462A1 (en) | 2002-10-07 | 2004-04-08 | International Business Machines Corporation | Peer-to-peer internet trading system with distributed search engine |
| CA2409114A1 (en) | 2002-10-22 | 2004-04-22 | N-Liter Inc. | Method for information retrieval |
| TW200407745A (en) | 2002-11-14 | 2004-05-16 | Inventec Corp | Processing method and system for engineering change form |
| US7804982B2 (en) | 2002-11-26 | 2010-09-28 | L-1 Secure Credentialing, Inc. | Systems and methods for managing and detecting fraud in image databases used with identification documents |
| JP2004178498A (en) | 2002-11-29 | 2004-06-24 | Trecenti Technologies Inc | Browsable information management system and management method |
| WO2005003907A2 (en) | 2003-06-26 | 2005-01-13 | Ebay Inc. | Method and apparatus to authenticate and authorize user access to a system |
| JP2005049972A (en) | 2003-07-30 | 2005-02-24 | Ricoh Co Ltd | Multifunctional image forming apparatus and document information retrieval method |
| US20050131915A1 (en) | 2003-12-15 | 2005-06-16 | Hicks Jaye D. | Concept directory |
| US7269590B2 (en) | 2004-01-29 | 2007-09-11 | Yahoo! Inc. | Method and system for customizing views of information associated with a social network user |
| US7152139B1 (en) | 2004-02-19 | 2006-12-19 | Micron Technology, Inc. | Techniques for generating serial presence detect contents |
| JP2005284608A (en) * | 2004-03-29 | 2005-10-13 | Nec Corp | System and method for data search |
| US8650152B2 (en) * | 2004-05-28 | 2014-02-11 | International Business Machines Corporation | Method and system for managing execution of data driven workflows |
| WO2006058387A1 (en) * | 2004-12-02 | 2006-06-08 | Now Technologies Pty Limited | Managing unprotected and protected content in private networks |
| US7533420B2 (en) * | 2004-12-09 | 2009-05-12 | Microsoft Corporation | System and method for restricting user access to a network document |
| US20060272027A1 (en) * | 2005-05-26 | 2006-11-30 | Finisar Corporation | Secure access to segment of data storage device and analyzer |
| US7770220B2 (en) * | 2005-08-16 | 2010-08-03 | Xerox Corp | System and method for securing documents using an attached electronic data storage device |
| US20070143123A1 (en) | 2005-12-06 | 2007-06-21 | Arkiva, Inc. | System, method and service for recording household assets |
| US20070162417A1 (en) * | 2006-01-10 | 2007-07-12 | Kabushiki Kaisha Toshiba | System and method for selective access to restricted electronic documents |
-
2007
- 2007-10-25 US US11/924,219 patent/US9020913B2/en not_active Expired - Fee Related
-
2008
- 2008-03-27 CN CN200880113120A patent/CN101836185A/en active Pending
- 2008-03-27 WO PCT/US2008/058374 patent/WO2009055083A1/en not_active Ceased
- 2008-03-27 JP JP2010531082A patent/JP2011503688A/en active Pending
- 2008-03-27 KR KR1020107007567A patent/KR20100072014A/en not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20060053097A1 (en) * | 2004-04-01 | 2006-03-09 | King Martin T | Searching and accessing documents on private networks for use with captures from rendered documents |
| US20060080316A1 (en) * | 2004-10-08 | 2006-04-13 | Meridio Ltd | Multiple indexing of an electronic document to selectively permit access to the content and metadata thereof |
| US20070244867A1 (en) * | 2006-04-13 | 2007-10-18 | Tony Malandain | Knowledge management tool |
Cited By (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2012043144A (en) * | 2010-08-18 | 2012-03-01 | Casio Comput Co Ltd | Server based computing system and program |
| WO2014099826A1 (en) * | 2012-12-19 | 2014-06-26 | Microsoft Corporation | Orchestrated interaction in access control evaluation |
| US9779257B2 (en) | 2012-12-19 | 2017-10-03 | Microsoft Technology Licensing, Llc | Orchestrated interaction in access control evaluation |
| WO2016069272A1 (en) * | 2014-10-26 | 2016-05-06 | Microsoft Technology Licensing, Llc | Access blocking for data loss prevention in collaborative environments |
| US9697349B2 (en) | 2014-10-26 | 2017-07-04 | Microsoft Technology Licensing, Llc | Access blocking for data loss prevention in collaborative environments |
| US9754098B2 (en) | 2014-10-26 | 2017-09-05 | Microsoft Technology Licensing, Llc | Providing policy tips for data loss prevention in collaborative environments |
| US10216919B2 (en) | 2014-10-26 | 2019-02-26 | Microsoft Technology Licensing, Llc | Access blocking for data loss prevention in collaborative environments |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20100072014A (en) | 2010-06-29 |
| US9020913B2 (en) | 2015-04-28 |
| CN101836185A (en) | 2010-09-15 |
| JP2011503688A (en) | 2011-01-27 |
| US20090112868A1 (en) | 2009-04-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US9020913B2 (en) | Real-time interactive authorization for enterprise search | |
| US12278844B2 (en) | Protecting contents and accounts using scan operation | |
| US9311679B2 (en) | Enterprise social media management platform with single sign-on | |
| US7672953B2 (en) | Publishing work activity information key tags associated with shared databases in social networks | |
| US20080250021A1 (en) | Method for Searching Private Data Via a Public Data Search Interface | |
| US8433712B2 (en) | Link analysis for enterprise environment | |
| CN112262388A (en) | Protecting Personal Identity Information (PII) using tagging and persistence of PII | |
| GB2478051A (en) | Storage and retrieval of information references based on workflow context using a contextual correlation engine | |
| US12400032B2 (en) | One-shot challenge to search and access unredacted vaulted electronic communications | |
| US20260086996A1 (en) | Audit records monitoring using a blockchain structure | |
| US20100058440A1 (en) | Interaction with desktop and online corpus | |
| US20150161345A1 (en) | Secure messaging services | |
| US20090210423A1 (en) | Methods and systems for maintaining personal data trusts | |
| Belfedhal et al. | A lightweight phishing detection system based on machine learning and url features | |
| Dowling | We have outgrown IP authentication | |
| EP3699785A1 (en) | Method for managing data of digital documents | |
| Yang | Analysis on cookies and cybersecurity | |
| Crowe et al. | Google Privacy: Something for Nothing? | |
| McLaughlin | Sharing You with You: Informational Privacy, Google & the Limits of Use Limitation | |
| Richardson | Dismissed by Paramount: Analyzing Salazar v. Paramount Global and the Video Privacy Protection Act. | |
| Vandevelde et al. | Apollo sued by investors over $570 mn tax payout to Black and top executives. | |
| TW202607590A (en) | System, method, and computer program product for information retrieval | |
| TW202607591A (en) | System, method, and computer program product for information retrieval | |
| BARRERA | Digital Justice with a Gender Perspective in Mexico | |
| KR20230157176A (en) | System and method for managing personal information of recruitment candidates of headhunting mediation platform |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 200880113120.5 Country of ref document: CN |
|
| DPE2 | Request for preliminary examination filed before expiration of 19th month from priority date (pct application filed from 20040101) | ||
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 08732905 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 20107007567 Country of ref document: KR Kind code of ref document: A |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2010531082 Country of ref document: JP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 08732905 Country of ref document: EP Kind code of ref document: A1 |