Integration user for analytical access to read only data stores generated from transactional systems

US9449188B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9449188-B2
Application numberUS-201414512249-A
CountryUS
Kind codeB2
Filing dateOct 10, 2014
Priority dateOct 10, 2014
Publication dateSep 20, 2016
Grant dateSep 20, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The technology disclosed preserves the tenant specificity and user specificity of the tenant data by associating user IDs to complementary special IDs referred to as the integration user(s). In particular, it combines the traceability of user actions, the integration of security models and the flexibility of a service ID into one integration user(s).

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method of controlling and tracking usage of an analytic data analysis system associated with a transactional data management system, the method including: a transactional data management system that manages data stored in a transaction data store receiving a logon request with an associated user ID for use of the transactional data management system, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of the analytical data analysis system; wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in the transactional data store; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein the special ID grants rights related to a specific analytic data analysis system; the special ID rights provide read-only access to at least one analytic data store accessed through the specific analytic data analysis system; and use of the transactional data management system is separately licensed and accounted for from the analytical data analysis system. 2. The computer-implemented method of claim 1 , further including: associating with the special ID security attributes particular to retrieval of data objects from the specific analytic data analysis system. 3. The computer-implemented method of claim 1 , further including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; and generating one or more security tokens to associate with the special ID when interacting with the specific analytic data analysis system; and wherein the security tokens govern access using the special ID to objects managed by the specific analytic data analysis system. 4. The computer-implemented method of claim 1 , further including: associating with the special ID security attributes particular to the specific analytic data analysis system by accessing a plurality of heterogeneous transactional data management systems that have divergent security models; accessing data in the plurality of transactional data management systems and creating objects that merge the data from two or more of the transactional data management systems; and processing first security translation rules that accept the data set security attributes from the two or more transactional data management systems as predicates and generating one or more security tokens to associate with each secured object that merges the data. 5. An apparatus to control and track usage of an analytic data analysis system associated with a transactional data management system, the apparatus comprising: a computer including a processor; a memory coupled to the processor, wherein the memory includes computer program instructions causing the computer to implement a process including: a transactional data management system that manages data stored in a transaction data store receiving a logon request with an associated user ID for use of the transactional data management system, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of the analytical data analysis system; wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in the transactional data store; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein the special ID grants rights related to a specific analytic data analysis system; the special ID rights provide read-only access to at least one analytic data store accessed through the specific analytic data analysis system; and use of the transactional data management system is separately licensed and accounted for from the analytical data analysis system. 6. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: associating with the special ID security attributes particular to retrieval of data objects from the specific analytic data analysis system. 7. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; and generating one or more security tokens to associate with the special ID when interacting with the specific analytic data analysis system; and wherein the security tokens govern access using the special ID to objects managed by the specific analytic data analysis system. 8. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: associating with the special ID security attributes particular to the specific analytic data analysis system by accessing a plurality of heterogeneous transactional data management systems that have divergent security models; accessing data in the plurality of transactional data management systems and creating objects that merge the data from two or more of the transactional data management systems; and processing first security translation rules that accept the data set security attributes from the two or more transactional data management systems as predicates and generating one or more security tokens to associate with each secured object that merges the data. 9. A non-transitory computer-readable storage medium storing computer program instructions that cause a computer to implement a process including: a transactional data management system that manages data stored in a transaction data store receiving a logon request with an associated user ID for use of the transactional data management system, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of the analytical data analysis system; wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in the transactional data store; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein the special ID grants rights related to a specific analytic data analysis system; the special ID rights provide read-only access to at least one analytic data store accessed through the specific analytic data analysis system; and use of the transactional data management system is separately licensed and accounted for from the analytical data analysis system. 10. A non-transitory computer-readable storage medium of claim 9 , further including computer program instructions that cause the computer to implement a process including: associating with the special ID security attributes particular to retrieval of data objects from the specific analytic data analysis system. 11. A non-transitory computer-readable storage medium of claim 9 , further including computer program instructions that cause the computer to implement a process including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; generating one or more security tokens to associate with the special ID when interacting

Assignees

Inventors

Classifications

  • H04L63/102Primary

    Entity profiles · CPC title

  • to a system of files or objects, e.g. local or distributed file system or database · CPC title

  • Physics · mapped topic

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Physics · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9449188B2 cover?
The technology disclosed preserves the tenant specificity and user specificity of the tenant data by associating user IDs to complementary special IDs referred to as the integration user(s). In particular, it combines the traceability of user actions, the integration of security models and the flexibility of a service ID into one integration user(s).
Who is the assignee on this patent?
Salesforce Com Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 20 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).