Secure computing system record access control
Abstract
A computing system record security architecture comprises, in one example, a record generation component configured to generate a record in a computing system, the record identifying a set of users associated with the record, and having an owner property that identifies a first user as an owner of the record, a co-owner assignment component configured to receive a co-owner assignment request, from the first user, to assign a second user to the record as a co-owner, and a record security component configured to receive a record modification request, from the second user, that requests a modification to the record, and to propagate the record modification request to the set of users with a unique identifier that identifies the first user.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A computer-implemented method comprising:
generating a record that defines an event and identifies a set of users associated with the event, the record including an owner property that identifies a first user as an owner of the record; receiving a co-owner assignment request, that is associated with the first user, to assign a second user to the record as a co-owner; based on the co-owner assignment request, generating a co-owner property on the record that identifies the second user as a co-owner of the record; receiving a record modification request that requests a modification to the record, and identifies a requestor associated with the record modification request; based on a comparison of the co-owner property and the requestor associated with the record modification request, propagating the record modification request to the set of users by: for each respective user in the set of users,
sending a structured electronic message to the respective user, the structured electronic message identifying the requested modification and having a protected header field that is generated by an electronic messaging server and includes a unique identifier that identifies the first user as a sender of the structured electronic message, wherein the protected header field is protected through control of the protected header field by the electronic messaging server.
22 . A computer-implemented method of claim 21 , wherein the structured electronic message comprises an email and the electronic messaging system comprises an email server.
23 . A computer-implemented method of claim 22 , and further comprising:
sending a separate email to each respective user, the email including a protected email header that is controlled by the email server and includes the unique identifier of the first user.
24 . A computer-implemented method of claim 21 , wherein the co-owner assignment request defines an ownership privilege of the second user relative to the record.
25 . A computer-implemented method of claim 24 , wherein the first user has a first set of ownership privileges relative to the record, and the co-owner has a second set of the ownership privileges that is different than the first set of ownership privileges.
26 . A computer-implemented method of claim 25 , wherein the second set of ownership privileges comprises a subset of the first set of ownership privileges.
27 . The computer-implemented method of claim 21 , wherein further comprising:
based on the co-owner assignment request, setting a status attribute on the data record indicating that co-owner assignment is pending; sending a communication to the second user indicative of the co-owner assignment request; and based on a response to the communication received from the second user, modifying the status attribute to indicate that the co-owner assignment request is complete.
28 . The computer-implemented method of claim 21 , wherein the event record comprises a calendar event record that stores at least one of time or location information associated with an event.
29 . The computer-implemented method of claim 21 , and further comprising:
receiving a request, from the first user, to remove the second user as a co-owner of the record and, in response, modifying the co-owner property associated with the record.
30 . A computing system comprising:
a record generation component configured to:
generate a data record that represents an event and identifies a set of users associated with the event, the data record includes an owner property that identifies a first user as an owner of the record;
a co-owner assignment component configured to:
based on a co-owner assignment request associated with the first user, generate a co-owner property on the record that identifies a second user as a co-owner of the record; and
a record security component configured to:
receive a record modification request that is indicative of a requested modification to the record, and identifies a requestor associated with the record modification request;
validate the requested modification based on the identified requestor and the co-owner property; and
based on the validation, propagate the requested modification to the set of users by:
for each respective user of the set of users, sending a structured electronic message to a separate computing system associated with the respective user, wherein
the structured electronic message identifies the requested modification; and
the separate computing system associated with the respective user maintains a separate copy of the data record and modifies the separate copy based on the requested modification identified in the structured electronic message.
31 . The computing system of claim 30 , wherein the structured electronic message includes a protected header that is generated by an electronic messaging server and stores a unique identifier that identifies a sender of the structured electronic message, wherein the protected header is protected through control of the protected header by the electronic messaging server.
32 . The computing system of claim 31 , wherein the structured electronic message comprises an email and the electronic messaging system comprises an email server.
33 . The computing system of claim 31 , wherein the unique identifier is based on a combination of:
a mailbox identifier that identifies a mailbox assigned to the sender in the electronic messaging system; and a unique object distinguished name that is assigned to the mailbox.
34 . The computing system of claim 30 , wherein the requested modification to the record comprises at least one of updating the record or deleting the record.
35 . The computing system of claim 30 , wherein the co-owner assignment component is configured to receive a request, from the first user, to remove the second user as a co-owner of the record and, in response, modify the co-owner property associated with the record.
36 . The computing system of claim 30 , wherein the event record comprises a calendar event record that stores at least one of time or location information associated with a calendar event.
37 . The computing system of claim 30 , wherein the record security component is configured to prevent the requested modification to the record based on the comparison of the requestor to the co-owner property.
38 . The computing system of claim 30 , wherein
the co-owner assignment request identifies ownership privileges of the second user relative to the record, and the first user has a first set of ownership privileges relative to the record, and the co-owner has a second set of the ownership privileges that is different than the first set of ownership privileges.
39 . A computing system comprising:
a record generation component configured to:
generate a data record that represents a calendar event and identifies a set of users associated with the calendar event, the data record includes an owner property that identifies the first user as an owner of the data record;
a co-owner assignment component configured to:
based on a co-owner assignment request associated with the first user, generate a co-owner property on the data record that identifies a second user as a co-owner of the data record; and
a record security component configured to:
receive a record modification request that is indicative of a requested modification to the data record, and identifies a requestor associated with the record modification request;
validate the requested modification based on the identified requestor and the co-owner property; and
based on the validation, propagate the requested modification to the set of users by:
for each respective user of the set of users, instructing a first email server to send an email to a second email server that is separate from the first email server and is associated with the respective user, wherein
the email identifies the requested modification; and
a calendar server associated with the respective user maintains a separate copy of the data record and modifies the separate copy based on the requested modification identified in the email.
40 . The computing system of claim 39 , wherein the first and second email servers comprise different types of email servers.Join the waitlist — get patent alerts
Track US2018183803A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.