Integration user for analytical access to read only data stores generated from transactional systems

US9923901B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9923901-B2
Application numberUS-201615229024-A
CountryUS
Kind codeB2
Filing dateAug 4, 2016
Priority dateOct 10, 2014
Publication dateMar 20, 2018
Grant dateMar 20, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The technology disclosed preserves the tenant specificity and user specificity of the tenant data by associating user IDs to complementary special IDs referred to as the integration user(s). In particular, it combines the traceability of user actions, the integration of security models and the flexibility of a service ID into one integration user(s).

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implemented method of controlling and tracking usage of an analytical data analysis system associated with a transactional data management system, the method including: receiving a logon request with an associated user ID for use of the transactional data management system that manages data stored in a transaction data store, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of the analytical data analysis system, wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in the transactional data store; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein: special ID rights provide access to at least one immutable analytic data store accessed through a specific analytical data analysis system; and use of the transactional data management system is separately licensed and accounted for from the analytical data analysis system. 2. The computer-implemented method of claim 1 , further including: associating with the special ID, security attributes particular to retrieval of data objects from the specific analytical data analysis system. 3. The computer-implemented method of claim 1 , further including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; and generating one or more security tokens to associate with the special ID when interacting with the specific analytical data analysis system, wherein the security tokens govern access using the special ID to objects managed by the specific analytical data analysis system. 4. The computer-implemented method of claim 1 , further including: associating with the special ID, security attributes particular to the specific analytical data analysis system by accessing two or more heterogeneous transactional data management systems that have divergent security models; accessing data in the two or more transactional data management systems and creating objects that merge the data from the transactional data management systems; and processing first security translation rules that accept data set security attributes from the two or more transactional data management systems as predicates and generating one or more security tokens to associate with secured objects that merge the data. 5. An apparatus to control and track usage of an analytical data analysis system associated with a transactional data management system, the apparatus comprising: a computer including a processor; a memory coupled to the processor, wherein the memory includes computer program instructions causing the computer to implement a process including: receiving a logon request with an associated user ID for use of the transactional data management system, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of the analytical data analysis system, wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in a transactional data store of the transactional data management system; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein: special ID rights provide access to at least one immutable analytic data store accessed through a specific analytical data analysis system; and use of the transactional data management system is separately licensed and accounted for from the analytical data analysis system. 6. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: associating with the special ID, security attributes particular to retrieval of data objects from the specific analytical data analysis system. 7. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; and generating one or more security tokens to associate with the special ID when interacting with the specific analytical data analysis system, wherein the security tokens govern access, using the special ID, to objects managed by the specific analytical data analysis system. 8. The apparatus of claim 5 , further including computer program instructions causing the computer to implement a process including: associating with the special ID, security attributes particular to the specific analytical data analysis system, by accessing two or more heterogeneous transactional data management systems that have divergent security models; accessing data in the two or more transactional data management systems and creating objects that merge the data from two or more of the transactional data management systems; and processing first security translation rules that accept data set security attributes from the two or more transactional data management systems as predicates and generating one or more security tokens to associate with secured objects that merge the data. 9. A tangible computer-readable memory including computer program instructions that cause a computer to implement a process including: receiving a logon request with an associated user ID for use of a transactional data management system that manages data stored in a transaction data store, authenticating the logon request, and identifying that authorizations associated with the user ID include usage of an analytical data analysis system, wherein the analytical data analysis system responds to requests to visualize data stored in an analytic data store that is a subset of, but not all of, the data stored in the transactional data store; and responsive to a request to use the analytical data analysis system with the user ID, invoking a complementary special ID linked to the user ID, wherein: special ID rights provide read-only access to at least one analytic data store accessed through a specific analytical data analysis system; and use of the special ID is separately licensed and accounted for from the user ID. 10. The tangible computer-readable memory of claim 9 , further including computer program instructions that cause the computer to implement a process including: associating with the special ID, security attributes particular to retrieval of data objects from the specific analytical data analysis system. 11. The tangible computer-readable memory of claim 9 , further including computer program instructions that cause the computer to implement a process including: applying first security translation rules that accept one or more security attributes from the transactional data management system as predicates; and generating one or more security tokens to associate with the special ID when interacting with the specific analytical data analysis system, wherein the one or more security tokens govern access using the special ID to objects managed by the specific analytical data analysis system. 12. The tangible computer-readable memory of claim 9 , further including computer program instructions that cause the computer to implement a process including: associating with the special ID, security attributes particular to the specific analytical data analysis system, by

Assignees

Inventors

Classifications

  • Physics · mapped topic

  • to a system of files or objects, e.g. local or distributed file system or database · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • Arrangements for software license management or administration, e.g. for managing licenses at corporate level · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9923901B2 cover?
The technology disclosed preserves the tenant specificity and user specificity of the tenant data by associating user IDs to complementary special IDs referred to as the integration user(s). In particular, it combines the traceability of user actions, the integration of security models and the flexibility of a service ID into one integration user(s).
Who is the assignee on this patent?
Salesforce Com Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 20 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).