Data storage systems and methods
US-2016306984-A1 · Oct 20, 2016 · US
US10354078B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10354078-B2 |
| Application number | US-201715717363-A |
| Country | US |
| Kind code | B2 |
| Filing date | Sep 27, 2017 |
| Priority date | Apr 16, 2015 |
| Publication date | Jul 16, 2019 |
| Grant date | Jul 16, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
An approach is provided in which a knowledge manager generates a knowledge structure that includes security annotation tokens and term tokens. Each of the security annotation tokens are stored in a parallel field and align to at least one of the term tokens. The knowledge manager matches security policies corresponding to a search request to one or more of the security annotation tokens and, in turn, generates search results based upon obfuscation of one or more of the term tokens aligned to the matched security annotation tokens.
Opening claim text (preview).
The invention claimed is: 1. A method implemented by an information handling system that includes a memory and a processor, the method comprising: receiving, at a question answer system, a search request initiated by a user; identifying, by the question answer system, one or more user authorizations corresponding to the user; generating, by the question answer system, one or more answers of the search request based upon the one or more user authorizations, wherein the generation of the one or more answers comprises: creating one or more preliminary search results from searching a knowledge structure utilizing one or more search restriction policies corresponding to the one or more user authorizations, wherein the knowledge structure includes a plurality of security annotation tokens and a plurality of term tokens, each of the plurality of security annotation tokens stored in at least one of a plurality of parallel fields corresponding to at least one of the plurality of term tokens; scoring the one or more preliminary search results based upon one or more scoring security policies corresponding to the one or more user authorizations, resulting in one or more scored preliminary search results; and generating the one or more answers from the scored preliminary search results by removing one or more passages from the scored preliminary search results based upon one or more passage authorization security policies corresponding to the one or more user authorizations; and displaying, by the question answer system, a modified version of at least one of the one or more answers, wherein the modified version of the one or more answers obfuscates one or more of the plurality of term tokens whose corresponding security annotation token matches at least one or more visualization security policies corresponding to the one or more user authorizations. 2. An information handling system comprising: one or more processors; a memory coupled to at least one of the processors; and a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions of: receiving, at a question answer system, a search request initiated by a user; identifying, by the question answer system, one or more user authorizations corresponding to the user; generating, by the question answer system, one or more answers of the search request based upon the one or more user authorizations, wherein the generation of the one or more answers comprises: creating one or more preliminary search results from searching a knowledge structure utilizing one or more search restriction policies corresponding to the one or more user authorizations, wherein the knowledge structure includes a plurality of security annotation tokens and a plurality of term tokens, each of the plurality of security annotation tokens stored in at least one of a plurality of parallel fields corresponding to at least one of the plurality of term tokens; scoring the one or more preliminary search results based upon one or more scoring security policies corresponding to the one or more user authorizations, resulting in one or more scored preliminary search results; and generating the one or more answers from the scored preliminary search results by removing one or more passages from the scored preliminary search results based upon one or more passage authorization security policies corresponding to the one or more user authorizations; and displaying, by the question answer system, a modified version of at least one of the one or more answers, wherein the modified version of the one or more answers obfuscates one or more of the plurality of term tokens whose corresponding security annotation token matches at least one or more visualization security policies corresponding to the one or more user authorizations. 3. A computer program product stored in a computer readable storage medium, comprising computer program code that, when executed by an information handling system, causes the information handling system to perform actions comprising: receiving, at a question answer system, a search request initiated by a user; identifying, by the question answer system, one or more user authorizations corresponding to the user; generating, by the question answer system, one or more answers of the search request based upon the one or more user authorizations, wherein the generation of the one or more answers comprises: creating one or more preliminary search results from searching a knowledge structure utilizing one or more search restriction policies corresponding to the one or more user authorizations, wherein the knowledge structure includes a plurality of security annotation tokens and a plurality of term tokens, each of the plurality of security annotation tokens stored in at least one of a plurality of parallel fields corresponding to at least one of the plurality of term tokens; scoring the one or more preliminary search results based upon one or more scoring security policies corresponding to the one or more user authorizations, resulting in one or more scored preliminary search results; and generating the one or more answers from the scored preliminary search results by removing one or more passages from the scored preliminary search results based upon one or more passage authorization security policies corresponding to the one or more user authorizations; and displaying, by the question answer system, a modified version of at least one of the one or more answers, wherein the modified version of the one or more answers obfuscates one or more of the plurality of term tokens whose corresponding security annotation token matches at least one or more visualization security policies corresponding to the one or more user authorizations.
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Just-in-time application of countermeasures, e.g., on-the-fly decryption, just-in-time obfuscation or de-obfuscation · CPC title
Protecting personal data, e.g. for financial or medical purposes · CPC title
for controlling access to devices or network resources · CPC title
by anonymising data, e.g. decorrelating personal data from the owner's identification · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.