US 12,314,424 B2
Data plane authorization
Bjoern Friedmann, Rheinmuenter (DE); Paulo Buettenbender, Sao Leopoldo (BR); Victor Matheus Silva Peixoto, Walldorf (DE); Lucas Mendonca de Souza Xavier, Sao Leopoldo (BR); Leonardo Pletsch, Porto Alegre (BR); Jascha Kanngiesser, Weisloch (DE); Joerg Franke, Brushsal (DE); Peter Haerle, Bammental (DE); and Ioannis Kostis, Walldorf (DE)
Assigned to SAP SE, Walldorf (DE)
Filed by SAP SE, Walldorf (DE)
Filed on Oct. 29, 2021, as Appl. No. 17/514,482.
Prior Publication US 2023/0140122 A1, May 4, 2023
Int. Cl. H04L 9/00 (2022.01); G06F 21/45 (2013.01); G06F 21/62 (2013.01)
CPC G06F 21/6245 (2013.01) [G06F 21/45 (2013.01); G06F 2221/2113 (2013.01); G06F 2221/2141 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A computer-implemented method, the method comprising:
receiving, from a source application, a replicated representation of a data entity of the source application and a replicated representation of application specific permissions defined for and associated with the data entity, the application specific permissions being defined by the source application sourcing the data entity;
storing the replicated representations of the data entity and the application specific permissions in a dedicated storage space for the source application within a consolidated cloud storage, the replicated representation of the application specific permissions and the replicated representation of the data entity stored within the consolidated cloud storage being separate and distinct from each other;
automatically generating, by a process of the dedicated storage space for the source application within the consolidated cloud storage, a secured data entity based on an integration of the replicated representation of the application specific permissions with the replicated representation of the data entity, user access to the secured data entity being defined by the replicated representation of the application specific permissions and reflect permissions as specified by the source application; and
storing the generated secured data entity in the dedicated storage space for the source application.