Authorization and access control system for access rights using relationship graphs

Inventors

Venable, Jeff

Assignees

Brex Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12210638-B2

Patent

Publication Date

2025-01-28

Expiration Date


Abstract

There are provided systems and methods for an authorization and access control system for access rights using relationship graphs. A service provider may provide an authorization and access control system that allows users within the service provider and/or customer entities to assign and change access rights or permissions to computing resources. When providing control of these access rights, the service provider may utilize relationship graphs, queried and generated using a graph database, to visualize and determine access rights that are inherited through different relationships and policies defining these access rights. The relationship graph may show edges for nodes that correspond to related objects, such as actors, groups, and resources. Paths over the relationship graph may be used to determine access rights that may be inherited by users. Once determined, these access rights may be established and/or updated with computing systems.

Core Innovation

The invention provides an access control system that receives a request to view one or more access rights of a user and queries a graph database for a relationship graph of the user, including one or more connections between nodes of related objects for the one or more access rights. Based on the querying, it generates and displays a visual representation of the relationship graph within a user interface.

The system includes at least one editing tool for the visual representation, where the editing tool allows changing the one or more access rights using the connections and the nodes. The system receives a change to the visual representation in the user interface using the editing tool, and the change effectuates a delegation of a new access right to the user based on updated data for a user node in the relationship graph.

The system modifies the relationship graph by creating a new connection from the user node to a node associated with the new access right. The new connection enables the graph database to be queried using multiple query types in a graph query language for the new access right of the user, and the system enables the change across the plurality of applications for the organization based on the modified relationship graph.

Claims Coverage

The document includes three independent claims that collectively cover an access-control visualization and editing method, a corresponding service provider system, and a corresponding non-transitory machine-readable medium. Across these independent claims, the inventive subject matter centers on editable visual representation of a relationship graph in a user interface, graph database modification via created connections for delegated access rights, and enabling permissions across a plurality of applications based on the modified relationship graph.

Editable visual representation of a user relationship graph for access rights

Generating, within a user interface, a visual representation of the relationship graph for the user based on the querying; displaying the visual representation in the user interface with at least one editing tool for the visual representation, wherein the at least one editing tool allows for changing the one or more access rights using the one or more connections and the nodes.

Delegation of a new access right via UI change and graph modification

Receiving a change to the visual representation in the user interface using the at least one editing tool to effectuate a delegation of a new access right to the user based on updated data for a user node of the user in the relationship graph; modifying, based on the change, the relationship graph by creating a new connection from the user node to one of the nodes associated with the new access right.

Permissions across multiple applications enabled by modified relationship graph

Determining, for the new access right, a permission to a computing resource of an organization to the user via a plurality of applications, wherein the permission allows the user to access or modify data from the computing resource; enabling, by the access control system, the change across the plurality of applications for the organization based on the modified relationship graph, wherein the enabling includes providing the permission to the user via the plurality of applications.

Graph query language enabling for the new access right

Modifying, based on the change, the relationship graph by creating a new connection from the user node to one of the nodes associated with the new access right, and wherein the new connection enables the graph database to be queried using multiple query types in a graph query language for the new access right of the user.

Across the independent claims, the core claim coverage is directed to an access control approach where access rights are visualized as a relationship graph in a user interface with editing tools, user-driven changes delegate new access rights by creating new graph connections, and the resulting modified relationship graph is used to determine and enable permissions across a plurality of applications.

Stated Advantages

Documented Applications

No documented applications found

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.