Invention Grant
- Patent Title: Document-level attribute-based access control
-
Application No.: US17244426Application Date: 2021-04-29
-
Publication No.: US11989314B2Publication Date: 2024-05-21
- Inventor: Adrien Grand
- Applicant: Elasticsearch B.V.
- Applicant Address: US CA Mountain View
- Assignee: Elasticsearch B.V.
- Current Assignee: Elasticsearch B.V.
- Current Assignee Address: NL Amsterdam
- Agency: Quinn IP Law
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F16/33 ; G06F16/35 ; G06F21/62

Abstract:
Methods and systems for a document-level attribute-based access control service are provided. The document-level attribute-based access control service may be positioned between a directory service and a search engine service. The directory service can manage information and permissions for users. The document-level attribute-based access control service can map security attributes to the user based on the information and permissions. Based on the mapping, it can be determined whether to permit the user making a query to the search engine service to access documents based on the query. Information and permissions attributes can be injected into queries dynamically via a template. Attributes may be combined with role query templates to create document-level attribute-based access control on top of role-based access control. The present technology can enable enforcement of security policies requiring all of a combination of attributes to be satisfied before permitting certain access.
Public/Granted literature
- US20210248250A1 Document-Level Attribute-Based Access Control Public/Granted day:2021-08-12
Information query