System and method for maintaining graphs having a policy engine and blockchain
Abstract
Aspects of the subject disclosure may include, for example, a processing system including a processor and a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations. The operations include: identifying a set of one or more graphs in a blockchain ledger, wherein each graph of the set of one or more graphs comprises a set of one or more nodes and a graph permission level, wherein each node in the set of one or more nodes comprises a unique identifier, a node permission level, data and zero or more edges, wherein each edge in the zero or more edges defines a relationship between the node and another node in the set of one or more nodes, wherein the node permission level defines a prerequisite to access the data, the node permission level, or the zero or more edges, and wherein the graph permission level defines a prerequisite to access the set of one or more nodes; receiving a request from equipment utilized by a user to access first data in one or more nodes in a first graph, comparing a user permission of the user to a first permission level of the first graph to ensure that the user permission meets or exceeds the first permission level; applying rules of a rules engine to ensure that the user permission meets or exceeds a second permission level defined by the rules; and providing security keys to the equipment utilized by the user responsive to the user permission meeting or exceeding the first permission level and the second permission level, wherein the security keys provide access to the first data. Other embodiments are disclosed.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for maintaining graphs, comprising:
a plurality of node/edge custodians comprising a memory for storing one or more graphs; a blockchain ledger maintained by two or more distributed processors, wherein the blockchain ledger records transactions performed on the one or more graphs; a trusted entity that maintains cryptographic hashes for the blockchain ledger; and a user permission database, wherein at least one of the two or more distributed processors perform operations comprising:
receiving an unauthenticated transaction from a user equipment to access data stored by the one or more graphs;
retrieving a graph permission level provided by the plurality of node/edge custodians for the one or more graphs;
retrieving a user privilege level from the user permission database;
determining whether to authorize the unauthenticated transaction based on the user privilege level, the graph permission level and authorization from another distributed processor of the two or more distributed processors; and
providing temporary encryption keys to the user equipment responsive to a first determination that the unauthenticated transaction is authorized.
2 . The system of claim 1 , wherein the user privilege level is provided via an independent path.
3 . The system of claim 1 , wherein the temporary encryption keys enable the user equipment to decipher node/edge information associated with the one or more graphs.
4 . The system of claim 1 , wherein the determining whether to authorize the unauthenticated transaction requires unanimous authorization from the two or more distributed processors.
5 . The system of claim 1 , wherein the operations further comprise providing a deny result to the user equipment responsive to a second determination that the unauthenticated transaction is prohibited.
6 . The system of claim 1 , further comprising receiving an identifier for every node/edge of the one or more graphs that store data responsive to the unauthenticated transaction.
7 . The system of claim 1 , wherein the unauthenticated transaction comprises: viewing a first data of two or more nodes in a first graph of the one or more graphs, adding a new node to the first graph, defining an edge between a first node and a second node in the first graph, modifying data of the first node in the first graph, changing the graph permission level of the first graph, or a combination thereof.
8 . The system of claim 7 , wherein the modifying comprises joining the first node in the first graph to a third node in a second graph.
9 . The system of claim 8 , wherein comparing further comprises ensuring that the user privilege level meets or exceeds a node permission level of the data.
10 . The system of claim 9 , wherein the joining further comprises defining a supergraph comprising nodes of the first graph and the second graph and creating a new graph permission level of the supergraph.
11 . The system of claim 10 , wherein the joining comprises adding an edge between the first node to the second node.
12 . The system of claim 11 , wherein the joining further comprises merging the first node in the first graph with the second node in the second graph, wherein the merging adds edges of the second node to the first node, adds data of the second node to the first node, adds edges of the first node to the second node, and adds data of the first node to the second node.
13 . The system of claim 11 , wherein the operations further comprise recording the supergraph in the blockchain ledger.
14 . The system of claim 13 , wherein operations further comprise authenticating the blockchain ledger and reconciling a new permission level for the supergraph.
15 . A method, comprising:
receiving, by at least one distributed processor, an unauthenticated transaction from a user equipment to access data stored by one or more graphs; retrieving, by the at least one distributed processor, a graph permission level provided by a plurality of node/edge custodians for the one or more graphs; retrieving, by the at least one distributed processor, a user privilege level from a user permission database; determining, by the at least one distributed processor, whether to authorize the unauthenticated transaction based on the user privilege level, the graph permission level, and authorization from at least one additional distributed processor; and providing, by the at least one distributed processor, temporary encryption keys to the user equipment responsive to a first determination that the unauthenticated transaction is authorized.
16 . The method of claim 15 , wherein the unauthenticated transaction comprises viewing first data of one or more nodes in the one or more graphs, adding a new node to a first graph of the one or more graphs, modifying data of a first node in the first graph, changing the graph permission level of the first graph, or a combination thereof.
17 . The method of claim 15 , wherein the unauthenticated transaction comprises defining a supergraph comprising nodes of a first graph and a second graph of the one or more graphs; and creating a new graph permission level for the supergraph.
18 . The method of claim 17 , further comprising recording, by the distributed processor, the supergraph in a blockchain ledger.
19 . A non-transitory, machine-readable medium, comprising executable instructions that, when executed by a distributed processing system including two or more processors, facilitate performance of operations, the operations comprising:
receiving an unauthenticated transaction from a user equipment to access data stored by the one or more graphs; retrieving a graph permission level provided by a plurality of node/edge custodians for the one or more graphs; retrieving a user privilege level from a user permission database; determining whether to authorize the unauthenticated transaction based on the user privilege level and the graph permission level; and providing temporary encryption keys to the user equipment responsive to a determination that the unauthenticated transaction is authorized.
20 . The non-transitory, machine-readable medium of claim 19 , wherein the operations further comprise:
defining a supergraph comprising nodes of a first graph and a second graph of the one or more graphs; creating a new graph permission level for the supergraph; and recording the supergraph in a blockchain ledger.Join the waitlist — get patent alerts
Track US2022075893A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.