Link Platform as a Service

By treating links as actors in the file system with access control lists and providing a link service, the technology addresses inconsistencies in link access control, enhancing flexibility and integration with existing systems, thus improving link management in content management systems.

JP7703037B2Active Publication Date: 2025-07-04DROPBOX INC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023552572
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-06-28
Filing Date
2022-02-07
Publication Date
2025-07-04
Estimated Expiration
2042-02-07

AI Technical Summary

Technical Problem

Content management systems face challenges in managing links due to uncoupling with file system access control logic, leading to complexities and limitations in link sharing, as the link caller's identity and access permissions are often unknown to the file system, resulting in inconsistent and inflexible access control.

Method used

The technology identifies links as actors within the file system, allowing them to be granted permissions in the access control list, enabling the file system to evaluate access consistently, and provides a link service that manages link-related functions such as logging and fraud prevention, while accommodating existing links and allowing co-management with third-party services.

Benefits of technology

This approach ensures consistent access control for links, enhances flexibility in access permission management, and supports seamless integration with existing systems, while reducing the need for traditional user accounts and improving link handling efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007703037000003
    Figure 0007703037000003
  • Figure 0007703037000004
    Figure 0007703037000004
  • Figure 0007703037000005
    Figure 0007703037000005
Patent Text Reader

Abstract

The present technology relates to a link service that can create, maintain, and service links to objects on behalf of a content management system or other service. The link service can optionally share management of links with other services and can also allow other services to publish links and manage the objects that are the targets of the links while providing other functionality to support the links. Additionally, the link service can interface with file systems that can support links as actors within the file system, providing greater control and flexibility in supporting links. The link service can also accommodate servicing and management of links published by legacy services. Legacy services have their own link logic that should be utilized to maintain a consistent user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present technology relates to links to objects within a content management system, and more particularly to identifying links as actors within a file system, whereby access to objects can be regulated using an access control list.

Background Art

[0002] In a content management system, it is common to share links that can provide access to objects. However, links are often not closely coupled to the file system of the content management system such that the access provided by the link may not match the access control logic utilized by the file system. In many cases, the content management system needs to utilize additional logic to determine whether a link is valid, whether the link caller is an appropriate link holder, and to bootstrap access permissions to objects within the file system of the link caller. Most file systems rely on subjects that are actors within the file system and statements of permissions. For example, a user can have read / write access rights. However, in the case of a link, if the link caller is not known to the file system, who should be identified as the actor to determine whether to permit access or what type of access should be permitted? Such problems create many complexities and limit the flexibility and functionality of link sharing by the content management system.

Brief Description of the Drawings

[0003] The above and other advantages and features of the present technology will become apparent by referring to the specific embodiments shown in the accompanying drawings. Those skilled in the art will understand that these drawings merely illustrate some examples of the present technology and do not limit the scope of the present technology to these examples. Furthermore, those skilled in the art will understand the principles of the present technology described and explained in more specific and detailed manner by using the following accompanying drawings.

[0004]

Figure 1

[0005]

Figure 2

[0006]

Figure 3

[0007]

Figure 4

[0008]

Figure 5

[0009]

Figure 6

[0010]

Figure 7

[0011]

Figure 8

[0012]

Figure 9

[0013]

Figure 10

[0014]

Figure 11A

[0015]

Figure 11B

[0016]

Figure 12A

Figure 12B

[0017]

Figure 13

[0018]

Figure 14

[0019]

Figure 15A

Figure 15B

[0020]

Figure 16

Embodiments for Carrying Out the Invention

[0021] Hereinafter, various embodiments of the present technology will be described in detail. It should be understood that specific implementations are described for illustrative purposes only. Those skilled in the relevant art will recognize that other components and configurations may be used without departing from the spirit and scope of the present technology.

[0022] Most content management systems are optimized for a specific usage model and are not very suitable for other usage mechanisms. This worked well for content management systems introduced for specific instances at the enterprise level, but is not suitable for the latest cloud - based content management systems.

[0023] An example demonstrating that modern content management systems require more flexibility is link sharing. It is common to share links that provide access to objects within a content management system. However, often the link is not tightly coupled to the content management system's file system, such that the access provided by the link may not match the access control logic utilized by the file system. In many cases, the content management system needs to utilize additional logic to determine if a link is valid when the link caller is an appropriate link holder and to bootstrap access permissions to objects within the file system of the link caller. Most file systems rely on a subject that is an actor within the file system and a statement of permissions recorded in an access control list. For example, a user may have read / write access rights. However, in the case of a link, if the link caller is not known to the file system, who should the file system identify as the actor to determine whether to grant access and what type of access should be granted? Such issues create much complexity and limit the flexibility and functionality of link sharing by a content management system. For example, in such a scenario, it can result in a user being granted access to an object even though access to the object is not permitted in the file system's access control list. Such behavior is undesirable, but the link sharing functionality needs to be enabled.

[0024] The disclosed technology addresses the need in the art for improving object access when an object is requested via a link by a link caller. Specifically, the present technology can identify a link as a known subject of the file system itself. Therefore, the link can be an actor granted permissions in an access control list. This provides many advantages. The main advantage is that the file system can directly determine access to the requested object using normal Access Control List (ACL) evaluation. Whether the object is requested by an anonymous link caller via a link or directly via a registered user account of a content management system having access permissions in the access control list, the file system can evaluate access to the object in the same way.

[0025] The present technology can efficiently check access during reading. When an object is requested by any client of the content management system, the content management system can efficiently determine whether there has been any change in access. And if it is determined that a change in access has occurred, the content management system can determine the new access rights (or the loss thereof).

[0026] The present technology also provides a more flexible access permission model. Access permissions for an object can be applied to an entire directory, can be applied only to a specific object, can be inherited from a global policy, can be inherited from a direct ancestor, can suppress permissions that should be inherited, can provide a policy that cannot be suppressed, etc. Any combination of the above policies can be aggregated to create an access control list for a specific object within a given directory tree. Therefore, the present technology can accommodate any set of customized access policies.

[0027] Access is always checked on read, and since access can be evaluated at the object level, access related to a link can be changed at any time by adjusting the access control lists related to the object and the link.

[0028] Furthermore, the technology eliminates the need for traditional user accounts in a content management system to provide links to objects. Other services or IoT devices may wish to send links. Thus, the technology includes a link service. The link service can be provided in a software - as - a - service model, and entities (user accounts, services, devices, etc.) can create links to objects within the file system. In addition to establishing links within the file system, the link service can perform various functions. For example, the link service can also perform logging, anti - fraud, blocking, etc. The link service can also implement or enforce additional link policies that go beyond the access policies implemented by the file system. The link service can be implemented as a service provided by the content management system or as another platform that interfaces with the content management system.

[0029] Furthermore, the technology can accommodate existing links. These existing links may utilize the aforementioned additional logic to support such links, but it is desirable that legacy links remain valid links. Thus, the link service of the technology can also interface with existing link logic while allowing the file system to evaluate access via the link as an actor within the file system.

[0030] Furthermore, additional services that may wish to utilize the link service may desire to provide a user experience such that the additional service can have more control over the link and its utilization. In other words, the additional service may not desire to completely hand over the handling of the link to the link service. This technology can also address such use cases by providing co-management of the link by the additional service and the link service of this technology. In this way, the additional service can maintain control over the parts it desires and delegate the remaining parts of the link handling to the link service.

[0031] These and other advantages over the prior art are described herein.

[0032] In some embodiments, the disclosed technology is introduced particularly in the context of a content management system having object synchronization and collaboration features. An exemplary system configuration 100 is shown in FIG. 1, which shows a content management system 110 that interacts with client devices 150.

[0033] Account

[0034] The content management system 110 can store objects associated with an account and perform various object management tasks such as searching, modifying, viewing, and / or sharing the objects. Further, the content management system 110 can enable an account to access the objects from multiple client devices.

[0035] The content management system 110 supports multiple accounts. Subjects (users, groups, teams, enterprises, third-party services, link services, devices, etc.) can create accounts using the content management system, and the details of the accounts can be stored in the subject database 140. The subject database 140 can identify registered subjects by subject ID and store profile information of the registered subjects in association with the subject ID. In some cases, the profile information of the registered subjects includes the subject name and / or email address. The subject database 140 can include account management information such as account type (e.g., various tiers of free or paid accounts), allocated storage space, used storage space, client device 150 on which the registered content management client application 152 resides, security settings, personal configuration settings, etc. In some embodiments, some information related to the account may not be directly stored; rather, this information may be derived. For example, the used storage space may be explicitly stored or calculated when needed.

[0036] In some embodiments, the subject database 140 does not need to store complete information related to the subject's account. Some of the information related to the subject's account can be stored in another database of the content management system 110, such as the metadata database 146, or in a database external to the content management system 110.

[0037] The subject database 140 can store a group of accounts related to a subject. The group can have permissions based on group permission statements and / or access control lists, and members of the group can inherit the permissions. For example, a marketing group can access a certain set of objects, and an engineering group can access another set of objects. The administrator group can make changes to the group, changes to subject accounts, etc. The group is also a subject identified by a subject ID.

[0038] In some embodiments, the subject database 140 can be divided into a plurality of tables, indexes, and other data structures.

[0039] Object Storage

[0040] A feature of the content management system 110 is the storage of objects, and the objects can be stored in the object storage 142. An object is generally any entity that can be recorded in a file system. An object can be any object including digital data such as a document, a collaboration object, a text file, an audio file, an image file, a video file, a web page, an executable file, a binary file, an object directory, a folder, a ZIP file, a playlist, an album, a symbolic link, a cloud document, a mount, or a placeholder object that references other objects within the content management system 110 or other content management systems.

[0041] In some embodiments, the objects can be grouped into a folder containing a plurality of objects, or a collection that references a plurality of objects associated or grouped by a common attribute.

[0042] In some embodiments, object storage 142 is combined with other types of storage or databases to handle specific functions. Object storage 142 can store objects, and metadata regarding the objects can be stored in metadata database 146. Similarly, data regarding where an object is stored in object storage 142 can be stored in object directory 144. Further, data regarding changes, access, etc. can be stored in object database 148. Object database 148 may also include subject account identifiers that identify subject IDs that can access an object.

[0043] In some embodiments, object database 148 can be divided into multiple tables, indexes, and other data structures.

[0044] Each of the various storage / databases such as object storage 142, object directory 144, object database 148, and metadata database 146 can be composed of two or more such storages or databases and can be distributed across many devices and locations. Other configurations are possible. For example, data from object storage 142, object directory 144, object database 148, and / or metadata database 146 may be combined into one or more object storages or databases, or may be further divided into additional object storages or databases. Thus, content management system 110 can include more or fewer storages and / or databases than shown in FIG. 1.

[0045] In some embodiments, the object storage 142 is associated with at least one file system 116, which includes software or other processor-executable instructions for managing the storage of objects. Managing the storage of objects includes, but is not limited to, receiving objects for storage, preparing objects for storage, selecting storage locations for objects, retrieving objects from storage, etc. In some embodiments, the file system 116 can divide an object into smaller chunks for storage in the object storage 142. The location of each chunk that makes up the object can be recorded in the object directory 144. The object directory 144 can include a content entry for each object stored in the object storage 142. The content entry can be associated with an object ID that uniquely identifies the object.

[0046] In some embodiments, each object and each chunk of an object may be identified from a deterministic hash function. A deterministic hash function outputs the same hash for all copies of the same object, but different hashes for different objects, so this method of identifying objects and object chunks ensures that object duplicates are recognized as such. Using this methodology, the file system 116 can output a unique hash for each different version of an object.

[0047] The file system 116 can also specify or record the parent of an object or the content path of an object in the object database 148. The content path can include the name of the object and / or the folder hierarchy associated with the object. For example, the content path can include the path of a folder or folders in which the object is stored in the local file system on the client device. In some embodiments, the object database can store only the direct ancestors or direct children of any object, thereby allowing the full path of the object to be derived, which can be more efficient than storing the entire path of the object.

[0048] Objects are stored in the object storage 142 in block units and may not be stored under a tree-like directory structure, although such a directory structure is a comfortable navigation structure for a subject browsing the objects. The file system 116 can define or record the content path of an object, and the "root" node of the directory structure can be any directory to which specific access rights are assigned, as opposed to a directory that inherits access rights from other directories.

[0049] In some embodiments, a root directory can be mounted under another root directory to give the appearance of a single directory structure. This can occur when an account has access to multiple root directories. As described above, the directory structure is merely a comfortable navigation structure for a subject browsing the objects and is not correlated with the storage location of the objects within the object storage 142.

[0050] The directory structure in which an account browses objects does not correlate with the storage location of objects in the content management system 110, but the directory structure can correlate with the storage location of objects in the client device 150 according to the file system used by the client device 150.

[0051] As described above, the content entry of the object directory 144 can also include the location of each chunk that makes up the object. More specifically, the content entry can include a content pointer that identifies the location within the object storage 142 of the chunks that make up the object.

[0052] The file system 116 can reduce the amount of storage space required by identifying duplicate objects or duplicate blocks that make up an object or a version of an object. Instead of storing multiple copies, the object storage 142 can store a single copy of an object or a block of an object, and the object directory 144 can include pointers or other mechanisms that link duplicates to the single copy.

[0053] The file system 116 can also store metadata that describes objects, object types, folders, file paths, and / or the relationships of objects to various accounts, collections, or groups, in the metadata database 146 in association with the object IDs of the objects.

[0054] The file system 116 can also store logs of data regarding changes, access, etc. to the object database 148. The object database 148 can include the object IDs of the objects and, optionally, can include an explanation of the change or access operation, along with a timestamp or version number and other related data. The object database 148 can also include pointers to the blocks affected by the change or object access. The file system 116 can also provide the ability to undo operations by using an object version control mechanism that tracks changes to objects, different versions of objects (including branched version trees), and the change history obtainable from the object database 148.

[0055] Synchronization of Objects

[0056] Another feature of the content management system 110 is the synchronization of objects with at least one client device 150. The client devices 150 can take different forms and have different capabilities. For example, client device 1501 is a computing device having a local file system accessible by a plurality of applications resident thereon. Client device 1502 is a computing device where objects are accessible only by a specific application or with permission granted by a specific application, and the objects are typically stored either in an application-specific space or in the cloud. Client device 1503 is any client device that accesses the content management system 110 via a web browser and accesses objects via a web interface. Exemplary client devices 1501, 1502, and 1503 are shown in form factors such as laptops, mobile devices, or web browsers, but it should be understood that the description is not limited to devices of these exemplary form factors. For example, a mobile device such as client 1502 may have a local file system accessible by a plurality of applications resident thereon, or client 1502 may access the content management system 110 via a web browser. Thus, when considering the functionality of client 150, the form factor should not be considered limiting. One or more of the functions described herein with respect to client device 150 may or may not be available on all client devices depending on the particular capabilities of the device (the file access model being one such capability).

[0057] In many embodiments, the client device 150 is associated with an account of the content management system 110, but in some embodiments, the client device 150 can access the content using a shared link and does not require an account.

[0058] As described above, some client devices can access the content management system 110 using a web browser. However, the client device can also access the content management system 110 using a client application 152 stored and executed on the client device 150. The client application 152 can include a client synchronization service 156.

[0059] The client synchronization service 156 can communicate with the server synchronization service 112 to synchronize changes to objects between the client device 150 and the content management system 110.

[0060] The client device 150 can synchronize content with the content management system 110 via the client synchronization service 156. The synchronization can be platform-independent. That is, the content can be synchronized across multiple client devices of various types, capabilities, operating systems, etc. The client synchronization service 156 can synchronize any changes (e.g., new, deleted, modified, copied, or moved objects) to objects located in a specified location in the file system of the client device 150.

[0061] Objects can be synchronized from the client device 150 to the content management system 110 and vice versa. In embodiments where synchronization is performed from the client device 150 to the content management system 110, the subject can directly manipulate objects from the file system of the client device 150, while the client synchronization service 156 can monitor directories on the client device 150 for changes to files within the monitored folder.

[0062] When the client synchronization service 156 detects a write, move, copy, or deletion of content within the directory it monitors, the client synchronization service 156 can synchronize that change to the content management storage service 116. In some embodiments, the client synchronization service 156 can perform some of the functions of the content management storage service 116, such as splitting an object into blocks, hashing an object to generate a unique identifier, and the like. The client synchronization service 156 can index the content in the client storage index 164 and save the result in the client storage index 164. Indexing can include saving, in addition to the path, an object identifier and a unique identifier for each object. In some embodiments, the client synchronization service 156 learns an object identifier from the server synchronization service 112 and learns a unique client identifier from the operating system of the client device 150.

[0063] The client synchronization service 156 can use the storage index 164 to facilitate synchronization between at least some of the objects in the client storage and the objects associated with the sub - subject accounts on the content management system 110. For example, the client synchronization service 156 can compare the storage index 164 with the content management system 110 and detect differences between the content on the client storage and the content associated with the sub - subject accounts on the content management system 110. Then, the client synchronization service 156 can attempt to match the differences by uploading, downloading, modifying, and deleting the content on the client storage as appropriate. The file system 116 can store modified or new objects for the object database 148, metadata database 146, object directory 144, object storage 142, sub - subject database 140, etc., as needed.

[0064] When synchronizing from the content management system 110 to the client device 150, the data regarding the mount, change, addition, deletion, and movement of the objects recorded in the object database 148 can trigger a notification using the notification service 117, which is sent to the client device 150. When the client device 150 is notified of the change, the client device 150 can request the changes listed in the object database 148 since the last known synchronization point of the client device. If the client device 150 determines that it is not synchronized with the content management system 110, the client synchronization service 156 requests the object blocks containing the changes and updates the local copy of the modified objects.

[0065] In some embodiments, the storage index 164 stores a tree data structure, one tree reflecting the latest representation of the directory according to the server synchronization service 112, and another tree reflecting the latest representation of the directory according to the client synchronization service 156. The client synchronization service can operate to ensure that the tree structures match by requesting data from the server synchronization service 112 or by committing changes on the client device 150 to the content management system 110.

[0066] Sometimes, the client device 150 may not have access to the network connection. In such a situation, the client synchronization service 156 can monitor the collection linked to the changes of the object and queue those changes for later synchronization to the content management system 110 when the network connection becomes available. Similarly, the subject can manually start, stop, pause, or resume synchronization with the content management system 110.

[0067] The client synchronization service 156 can synchronize all the content associated with a specific subject account on the content management system 110. Alternatively, the client synchronization service 156 can selectively synchronize a portion of the objects associated with a specific subject account on the content management system 110. Selectively synchronizing only a portion of the objects can free up space on the client device 150 and save bandwidth.

[0068] In some embodiments, the client synchronization service 156 selectively stores a portion of the objects associated with a particular subject account and stores placeholder objects for the remaining portions of the objects in the client storage. For example, the client synchronization service 156 can store placeholder objects that have the same file name, path, extension, and metadata as each complete object on the content management system 110 but lack the data of the complete objects. The size of the placeholder objects can be a few bytes or less, while the size of each complete object can be quite large. After the client device 150 attempts to access an object, the client synchronization service 156 can retrieve the data of the object from the content management system 110 and provide the complete object to the client device 150. This approach can provide significant savings in space and bandwidth while still providing complete access to the objects of the subject on the content management system 110.

[0069] The synchronization embodiments discussed above referred to the client device 150 and the server of the content management system 110, but it should be understood by those skilled in the art that the user account can have any number of client devices 150 that all synchronize objects with the content management system 110 such that changes to the objects on any one client device 150 can propagate to the other client devices 150 through their respective synchronizations with the content management system 110.

[0070] Collaboration feature

[0071] Another feature of the content management system 110 is to facilitate collaboration between subjects. The collaboration functions include sharing of objects, commenting on objects, collaborative work on objects in real time, instant messaging, providing presence and "seen" status information regarding objects, etc.

[0072] Sharing

[0073] The content management system 110 can manage the sharing of objects via the sharing service 128 or the link service 136. The sharing of content by the sharing service includes linking the content using the sharing service 128 and sharing the content within the content management system 110 with at least one additional subject account (in addition to the original subject account associated with the object) so that each subject account can access the object within its respective account. The additional subject account can obtain access to the content by accepting the content, and the content can be accessed directly via the web interface service 124 or from within the directory structure associated with those accounts on the client device 150. The sharing can be performed in a platform-independent manner. That is, the content can be shared across multiple client devices 150 with different types, capabilities, operating systems, etc. Also, the content can also be shared across various types of subject accounts.

[0074] To share an object within the content management system 110, the sharing service 128 can associate the subject ID of a team or one or more subject accounts with the object in the object database 148 associated with the object, and thus can grant access rights to the object to additional subject accounts. The sharing service 128 can also delete the subject IDs that are permitted to access the object in the object database 148 to restrict access to the object by the subject accounts. The sharing service 128 can record in the object database 148 the object identifier, the subject identifier granted access to the object, and the access level. For example, in some embodiments, the subject identifiers associated with a single object can specify different permissions for each subject identifier with respect to the associated object.

[0075] In some embodiments, the content management system 110 can include an access control list 145 that includes a complete description of the access rights associated with each object. The access control list for each object within the content management system can be derived from the object database 148. In some embodiments, it is not desirable to maintain a persistent access control list 145 for each object because the access control list 145 for each object can be derived when needed. In some embodiments, an object can inherit access rights from another object such as an ancestor object.

[0076] Objects can also be shared so that they are accessible via links. The link service 136 is a software-as-a-service platform that can create links to objects, handle link management, and perform link-related functions such as logging, fraud prevention, integration with third-party services, and other functions as described in more detail herein.

[0077] To share objects outside of the content management system 110, the link service 136 can generate a custom network address such as a Uniform Resource Locator (URL), which enables any web browser to access an object or collection within the content management system 110. The link service 136 can include content identification data in the generated URL, which can later be used to properly identify and return the requested object. For example, the link service 136 can receive a request to access an object identified by a link, perform link-related functions, communicate with the file system 116, and evaluate access permissions associated with the link. Once access is determined, the link service 136 can return a file access token within a message that identifies the object ID and optionally a sub-object ID that can be used by the link caller to retrieve the object from the file system 116.

[0078] In addition to generating the URL, the link service 136 can also be configured to record in the object database 148 that a URL to the object has been created. In some embodiments, an entry in the object database 148 related to an object can include a URL flag indicating whether a URL to the object has been created. For example, the URL flag can be a boolean value initially set to 0 or false to indicate that no URL to the object has been created. The sharing service 128 can change the value of the flag to 1 or true after generating the URL to the object. Also, the sharing service 136 can create a new subject ID for the link in the subject database 140 to identify the link. By this operation, the link becomes an actor within the link file system 116. As used herein, the subject ID of the link may be referred to as Link_sID.

[0079] In some embodiments, the sharing service 128 can associate a set of permissions with the Link_sID for an object. For example, when an object is accessed via a URL, the sharing service 128 can provide a limited set of permissions for the object based on the permissions associated with the Link_sID for that object. Examples of limited permissions include restrictions such as the subject not being able to download the object, save the object, copy the object, modify the object, etc. In some embodiments, the limited permissions include a restriction that the object can only be accessed by a specified domain, i.e., within the corporate network domain, or by an account associated with the specified domain, such as an account associated with a corporate account (e.g., @acme.com).

[0080] In some embodiments, the link service 136 can also be configured to deactivate the generated URL. For example, each entry in the object database 148 can also include a URL active flag indicating whether content should be returned in response to a request from the generated URL. For example, the link service 136 can return the object requested by the generated link only if the URL active flag is set to 1 or true. Thus, access to the object for which the URL was generated can be easily restricted by changing the value of the URL active flag. This allows restricted access to the shared object for the subject without the need to move the object or delete the generated URL. Similarly, the sharing service 128 can reactivate the URL by changing the value of the URL active flag back to 1 or true. Thus, the subject can easily regain access to the object without the need to generate a new URL. Access to the object can also be changed by changing the permission statement associated with the Link_sID of the object. This can also occur after the link has been distributed.

[0081] In some embodiments, the content management system 110 can specify a URL for uploading an object. For example, a first subject having a subject account can request such a URL and provide the URL to the subject who is posting, and the subject who is posting can use the URL to upload the object to the subject account of the first subject.

[0082] The link service 136 is shown as a service provided as part of the content management system 110, but the link service 136 can be a separate service.

[0083] Team service

[0084] In some embodiments, the content management system 110 includes a team service 130. The team service 130 can provide functions for creating and managing a defined team of subject accounts. Teams can be created for enterprises with sub-teams (such as business units, project teams, etc.), and the subject accounts assigned to the teams and sub-teams, or the teams, can be created for any defined group. The team service 130 can provide a common shared space, private subject account folders, and access-restricted shared folders for the team. The team service 130 also provides an administrative interface for administrators to manage collections and objects within the team and can manage the subject accounts associated with the team. All teams, sub-teams, and subject accounts are assigned subject identifiers in the subject database 140, and the membership of the team by the subject account is also recorded in the subject database 140.

[0085] IAM (Identity and Access Management) service

[0086] In some embodiments, the content management system 110 includes an IAM service 132. The IAM service 132 can authenticate subject accounts. In the case of subject accounts with multiple privilege levels (for example, subject accounts with subject rights and administrator rights), the IAM service 132 can also facilitate explicit privilege elevation to avoid unintentional actions by administrators.

[0087] Object access

[0088] The file system 116 can receive a token from the client application 152 that complies with a request to access an object, and can return the capabilities permitted to the subject account. Although the file system 116 is shown as a separate entity from the object storage 142, a reference to the file system 116 can refer to the file system 116 performing operations on the object storage 142. For example, a reference to a subject making an object request from the file system 116 refers to the file system 116 determining whether access is permitted and performing an operation to obtain the object from the object storage 142. Thus, a reference to the file system 116 can be an alternative to a reference to the combination of the file system 116 and the object storage 142.

[0089] Presence and "seen" status

[0090] In some embodiments, the content management system can provide information on how or whether a subject with whom an object is shared is interacting with the object. In some embodiments, the content management system 110 can report that a subject with whom an object is shared is currently viewing the object. For example, the client collaboration service 160 can notify the notification service 117 when the client device 150 accesses an object. The notification service 117 can then notify all client devices of other subjects accessing the same object of the presence of the subject of the client device 150 with respect to the object.

[0091] In some embodiments, the content management system 110 can report the history of a subject's interaction with a shared object. The collaboration service 126 queries data sources such as the metadata database 146 and the object database 148 to determine, for example, that a subject has saved an object, that a subject has not yet viewed an object, etc., and uses the notification service 117 to distribute this status information to other subjects so that it is possible to know who is currently viewing an object, or who has viewed or modified it.

[0092] The collaboration service 126 can facilitate comments related to the content even if the object does not natively support a comment function. Such comments can be stored in the metadata database 146.

[0093] The collaboration service 126 can issue and send notifications to subjects. For example, when a subject mentions another subject in a comment, the collaboration service 126 can send a notification informing that subject that they have been mentioned in the comment. Various other object events, such as object deletion, object sharing, etc., can trigger notifications.

[0094] The collaboration service 126 can also provide a messaging platform through which subjects can send and receive instant messages, voice calls, emails, etc.

[0095] Collaboration Object

[0096] In some embodiments, the content management service can also include a collaborative document service 134 that provides an interactive object collaboration platform, whereby subjects can simultaneously create, comment on, and manage tasks within collaborative objects. A collaborative object can be a file that subjects can create and edit using a collaborative object editor and can include collaborative object elements. Collaborative object elements can include a collaborative object identifier, one or more creator identifiers, collaborative object text, collaborative object attributes, interaction information, comments, shared subjects, and the like. Collaborative object elements can be stored as database entities, whereby collaborative objects can be searched for and retrieved. Multiple subjects can access, view, edit, and collaborate on a collaborative object simultaneously or at different times. In some embodiments, this can be managed by requiring two subjects to access an object via a web interface and work simultaneously on the same copy of the object.

[0097] Collaboration Companion Interface

[0098] In some embodiments, the client collaboration service 160 can provide a native application companion interface for the purpose of displaying information related to an object presented on the client device 150. In embodiments where the object is stored and executed on the client device 150 at a specified location in the file system of the client device 150 and is accessed by a native application such that the object is managed by the content application 152, the native application may not be required to provide a native way to display the above-specified collaborative data. In such embodiments, the client collaboration service 160 can detect that a subject has opened the object and provide an overlay having additional information about the object, such as collaborative data. For example, the additional information can include comments on the object, the status of the object, activities of other subjects who have previously or are currently viewing the object, and the like. Such an overlay can warn the subject that changes may be lost because another subject is currently editing the object.

[0099] In some embodiments, one or more of the services or storage / databases described above can be accessed using a public or private application programming interface.

[0100] A particular software application can access the object storage 142 via an API on behalf of the subject. For example, a software package such as an application executed on the client device 150 can programmatically make API calls directly to the content management system 110 to perform operations such as reading, writing, creating, deleting, sharing, or other operations on the content when the subject provides authentication credentials.

[0101] The subject can view or operate on the content stored in the subject account via the web interface generated and provided by the web interface service 124. For example, the subject can navigate to the web address provided by the content management system 110 in a web browser. Changes or updates to the content in the object storage 142 made through the web interface, such as uploading a new version of an object, can be reflected in other client devices associated with the subject's account. For example, multiple client devices, each having its own client software, can be associated with a single account, and the objects within the account can be synchronized among each of the multiple client devices.

[0102] The client device 150 can connect to the content management system 110 on behalf of the subject. The subject can interact directly with the client device 150, for example, when the client device 150 is a desktop or laptop computer, a phone, a television, an IoT device, etc. Alternatively or additionally, the client device 150 can operate on behalf of the subject without the subject physically accessing the client device 150, for example, when the client device 150 is a server.

[0103] Some features of the client device 150 are enabled by applications installed on the client device 150. In some embodiments, the application can include components specific to the content management system. For example, the components specific to the content management system can be a stand-alone application 152, one or more application plug-ins, and / or a browser extension. However, the subject can also interact with the content management system 110 via a third-party application such as a web browser that resides on the client device 150 and is configured to communicate with the content management system 110. In various implementations, the client-side application 152 can present a subject interface (UI) for the subject to interact with the content management system 110. For example, the subject can interact with the content management system 110 via a file system explorer integrated with the file system or via a web page displayed using a web browser application.

[0104] In some embodiments, the client application 152 can be configured to manage and synchronize the content of multiple accounts of the content management system 110. In such embodiments, the client application 152 can remain logged in to multiple accounts and provide normal services for multiple accounts. In some embodiments, each account is represented as a folder in the file system, and all objects in that folder can be synchronized with the content management system 110. In some embodiments, the client application 152 can include a selector for selecting one of the multiple accounts as the primary account or the default account.

[0105] Third-Party Services

[0106] In some embodiments, content management system 110 can include the function of interfacing with one or more third-party services such as a workspace service, an email service, a task service, etc. In such embodiments, content management system 110 can be provided with login authentication information of a subject account of the third-party service to interact with the third-party service in order to bring functions or data from those third-party services to various subject interfaces provided by content management system 110.

[0107] In some embodiments, the third-party service can also interact with content management system 110 via link service 136, and the third-party service can request link service 136 to create a link on its behalf.

[0108] Although content management system 110 is shown with specific components, those skilled in the art should understand that the architectural configuration of system 100 is merely one possible configuration, and other configurations with more or fewer components are possible. Further, the services can have more or fewer functions, including even the functions described as being in another service. Additionally, the features described herein with respect to one embodiment can be combined with the features described with respect to another embodiment.

[0109] Although system 100 is shown with specific components, those skilled in the art should understand that the architectural configuration of system 100 is merely one possible configuration, and other configurations with more or fewer components are possible.

[0110] Figure 2 shows additional details of the content management system 110 according to some embodiments. For example, as described above, Figure 2 shows a file system 116 configured to determine, among other functions, where in the object storage 142 an object is stored.

[0111] The object storage 142 is divided into a plurality of object storage shards 142n, and each shard is shown as being associated with a part of the object database 148. Objects are distributed across the various object storage shards 142n, and data related to an object on a particular object storage shard 142n is also stored in the part of the object database 148 stored on the same shard. To facilitate this distribution of the object storage database 142 across multiple shards, the file system 116 can direct data to be written to the object database 148 to the appropriate part of the object database on the appropriate shard. Further, when an object is moved from one object storage shard 142n to another object storage shard 142n, the file system 116 is responsible for both migrating the object between shards and migrating the data within the object database 148 related to that object to the new object storage shard 142n.

[0112] Figure 2 also shows an IAM service 132 that communicates with the file system 116 and the subject database 140. As further described herein, the IAM service 132 can interact with the file system 116 and the object database 148 to determine access information related to an object. The IAM service 132 can also interact with the subject database 140 to perform authentication and access services.

[0113] FIG. 2 also generally shows the file system 116, the object database 148, or the metadata database 146 that may need to interact with any one of the services described in connection with FIG. 1 or one or more functions further described herein, or other services that may need to be these clients.

[0114] FIG. 2 also shows a link service 136 having one or more APIs 138 that provide an interface that can be called by the client device 150, the file system 116, the third-party service 170, and the legacy link service 135 to utilize the various functions performed by the link service 136.

[0115] The link service 136 is a software-as-a-service platform that can handle the creation of links to objects and can provide various link services. The most basic function of the link service 136 is to receive requests to create and issue links via the API 138. Upon receiving such a request, the link service 136 can create and / or map a URL to an object and / or entity using metadata regarding the URL. In some embodiments, the link service 136 can also handle the creation and enforcement of link settings such as link expiration, password, viewers, etc. The link service 136 can also control who can create a link to an object and can prevent link creation for unauthenticated users. The link service 136 can ensure that any link complies with other sharing or access policies associated with the object.

[0116] Another important function of the link service 136 is to receive, via the API 138, requests to access an object of metadata mapped by the URL called by the link caller. Receiving such requests involves more than just basic link verification and providing the requested content. The link service 136 can also perform functions related to rate limiting (limiting the frequency or speed at which a link can be called), fraud prevention, link prohibition, analysis, metrics and logging, tracking of link senders and visitors, and audit logging. The link service 136 can also provide an administrative interface for managing links.

[0117] In some embodiments, the link service 136 utilizes the logic of the file system 116 to determine whether a link caller can access the object referenced by the link. For example, the link service 136 can use the file system 116 to determine whether a link caller should be allowed to access the object referenced by the link. As discussed herein, the link service can establish a link as an actor within the file system 116 (i.e., a subject ID, sID, or, particularly when referring to a link, a link_sID), and the link_sID is associated with the specified permissions within a permission statement.

[0118] In some embodiments, the link service 136 utilizes logic external to the file system to determine whether the link caller can access the object that the link references, and the link service 136 can utilize a third-party service 170 to determine whether the link caller should be able to access the object. A third-party service in the context of this example can be a service that generates content, but it may also be a service that utilizes the link service to share content. The third-party service 170 may also use the content management system 110 to store the content generated by the third-party service 170. A third-party service 170 in the context of this example can also be a service that does not generate objects, but instead may be a service that provides services such as document signing, video conferencing, workflow, etc. where the objects are relevant. Utilizing the third-party service 170 to determine whether the link caller should be able to access the object is particularly useful when the third-party service utilizes the link service 136 to issue a link, but the third-party service 170 wants to share part of the management of the link. This example is also useful when the third-party service 170 issues a link, but wants to utilize the link service 136 to manage the link.

[0119] In another example where external logic outside the file system is utilized to determine whether the link caller can access the object referenced by the link, the link service 136 can utilize the legacy link service 135 to determine whether the link caller should be able to access the object. This example is particularly useful when the issued link utilizes access logic different from the access logic provided by the link service 136. In this way, the legacy link can continue to provide the user experience expected by the link caller, while the link service 136 can take over the management and maintenance of the link.

[0120] In some embodiments, the link service 136 can utilize the logic of the file system 116 together with the logic provided by the third - party service 170 or the legacy link service 135 to support some links.

[0121] FIG. 3 shows an example of an object database 148 according to some embodiments. The object database 148 can be composed of a set of tables and indexes, but FIG. 3 shows an access control list (ACL) table 202 and an object table 212.

[0122] All tables of the object database 148 are key - value stores, but the technology should not be limited to such a data structure. All tables of the object database 148 refer to an object ID (oID) and a hybrid logical clock (HLC). In the tables within the object database 148, the oID and HLC constitute keys for performing lookups in various tables within the object database 148.

[0123] The oID is the ID of an object. An object is generally any entity that can be recorded in a file system. A Hybrid Logical Clock (HLC) is a clock value that combines aspects of a time clock and a logical clock. The HLC guarantees that all events on a particular machine are recorded in the order in which they occurred, and also guarantees that all events on the receiving machine after transmission are recorded in order after the events on the sending machine before transmission.

[0124] As mentioned above, the object database 148 can be composed of several tables. The ACL table 202 is optimized to record all changes to the permissions (including access) related to an object. In some embodiments, permissions are represented by the items of a tuple of subject, action, capability, and inheritance, all of which are recorded in the ACL table 202. Although references to tuples are used throughout this description, those skilled in the art will understand that any mechanism for representing a collection of values can be used.

[0125] A subject (identified by a subject ID (sID)) is related to any actor within the content management system. In the case of a link, the subject ID may be called link_sID. An actor can be an individual's subject account, a team or group mapped to an individual's account, an organization mapped to a team, a group of groups, a link, a device, an organization, a third-party service 170, or any entity, etc. In some embodiments, multiple subject IDs can be listed in a permission statement.

[0126] An action defines whether a subject is permitted or not permitted to perform a capability and can be conditional on other factors. The following table illustrates some example actions. TIFF0007703037000001.tif90155 By combining these actions, it provides the ability to create highly customized permission statements. As described above, this technology provides improvements over the prior art by supporting a wide array of potential permissions and by considering diverse permission organization schemes in a very efficient system. Some entity counts may be governed by general top-level rules, but exceptions may also be necessary. For example, an organizational account may permit sharing of objects by team members only if the sharing is within the organization. This policy is a top-level policy that applies to all objects within the organizational account. However, exceptions may need to be created, and the actions described above permit such exceptions.

[0127] Some actions also refer to inheritance. The ACL table 202 also includes a column regarding the inheritance order that references whether an object should inherit permissions from other objects. Most content management systems follow the inherit last scheme where all nodes in a tree directory structure inherit permissions from their immediate ancestors. However, this technology can support inheritance from the top of the directory structure, inheritance from the immediate ancestor (inherit last), or not inherit permissions at all. These combinations of inheritance schemes also contribute to highly customizable permissions possible for any object. It is also possible for all objects to follow the inherit-first permission statement considered as the top policy applied to all objects below it in the directory tree, while also being able to inherit some properties from their immediate ancestors. It is also possible for a particular object not to inherit either the inherit-first or inherit-last permission statement. In some cases, it is also possible for a subject to access an object without accessing any ancestor or child objects within the directory structure.

[0128] The capability values of the ACL table 202 define which privileges are affected. The privileges in the capability column are defined in combination with the action column and the inheritance column. The following table identifies and explains some examples of capabilities (when combined with the "permission" action). TIFF0007703037000002.tif89155

[0129] The sID, action, capability, and inheritance columns collectively represent a tuple that constitutes a specific permission statement related to an object. Each row can include multiple of these tuples related to an object ID affected by a specified hybrid logic clock value.

[0130] Permissions can be added or changed for an object ID at a later time (a later hybrid logic clock value), and those permission statements can be listed in a new row related to the object ID and the hybrid logic clock value.

[0131] In the case of a link, the ability to create the link can be governed by the existing permission statements that govern the object. For example, if the object exists in object storage 142 that has existing permission statements, the ability to create the link depends on whether the user accessing it is permitted to create the link.

[0132] In some embodiments, a new object can be stored in object storage 142 only for the purpose of sharing a link. For example, the link service 136 can store an object in content storage 142 by interacting with the file system 116.

[0133] When the link service 136 is permitted to create a link to an object in the object storage 142, the link service 136 interfaces with the file system 116 to create a link_sID that identifies the link as an actor in the permission statement tuple. Enabling the link to be an actor recognized by the file system 116 provides the advantage that access to the object specified by the link does not require continuous access by the entity that created the link for the link to remain valid. For example, even if the entity that created the link loses access to the object, the link can continue to function. As another advantage, since the link is an actor recognized by the file system 116, even an anonymous user can still access the object via the link. Instead of providing access via a proxy for access by another user to the file system, the file system 116 and the link service 136 recognize that the object is accessed by an anonymous user.

[0134] When referring to the capabilities of a given object in the context of a content management system, it is common to refer to an access control list (ACL) that defines all the permissions provided to the object. In some embodiments of the present technology, the ACL is not stored, but as will be described with respect to FIG. 7 below, the ACL can be derived.

[0135] FIG. 3 also shows an object table 212 that records information about changes made to the object. The object table 212 also includes columns for the object ID, a hybrid logical clock for identifying the object, and the system time at which the change occurred. In addition to recording changes made to the object, the object table 212 can be used to identify the version of the object at a particular time.

[0136] The object table 212 can also be used to identify an approximate date and time, called a change time, to which a hybrid logical clock value can correspond. The change time represents the clock time (date and time) at which the change was made.

[0137] The object table 212 also includes a column for identifying the type of object. For example, the column can indicate whether the object is a file or a directory. In some embodiments, a change to an object may not be to change the object itself, but rather to mount a directory under another directory. In an example of a mount, the type of object can list the target object ID of the directory to which the object is mounted. As described above, the table in FIG. 3 collectively records information essential for performing access, synchronization, and version management tasks. The table in FIG. 3 is configured to be very efficient, and data that is not necessary for the efficient execution of the essential tasks of the content management system is excluded from these tables. Further, these tables are maintained individually to optimize the frequency and circumstances in which they need to be written to.

[0138] FIG. 4 shows the subject database 140. In FIG. 2, the subject database 140 is shown as being stored external to the object storage 142, but in some embodiments, it will be understood that the subject database 140 can be stored across shards 142n of the object storage 142, just like the object database 148.

[0139] The subject database 140 is configured to track essential information about a subject. A subject can be any entity that may have an account in the content management system 110 and / or may access or act on an object. In some embodiments, a link can access an object and act on an object and thus can be a subject. The subject database 140 can be divided into several different tables or can include additional information not shown in FIG. 4.

[0140] The subject table 250 is configured to record information about a subject represented as a subject ID (sID) in the subject table 250. Whenever an sID comes into existence, an sID is deleted, or other aspects of the data recorded in the subject table 250 are changed, a new row can be written to the subject table. In FIG. 4, sID:Z and sID:ILL are link_sIDs.

[0141] In addition to the columns of the subject table 250 that contain sIDs, the subject table 250 also includes a column for a hybrid logic clock (HLC) that can record the system time affected by the change that caused the row.

[0142] The subject table 250 also includes various subject fields that record information about the subject account represented by its sID. For example, the subject table 250 can also include a subject field for a subject name associated with the subject account or an email address associated with the account. If the subject is a link, the subject name can be blank, written as "link", or can include a link ID provided by the link service 136 as shown in FIG. 4.

[0143] In some embodiments, the subject table 250 can also record whether a subject account belongs to a particular domain. For example, if the subject account is associated with an organization that also has a subject account in the content management system, the subject table 250 can record the mapping between the subject account and its domain. If the subject is a link, as shown for Link_sID:ILL associated with the third - party service: ldct.com, the domain when the third - party service 170 created the link can be recorded.

[0144] The subject table 250 also includes a column indicating whether a subject ID is managed or controlled by a parent subject ID. Just as an object can have an ancestor from which it can inherit certain properties, a subject can also have a parent. The parent of a subject can be a subject account that has the authority to manage the subject, such as by giving restrictions or permissions to the subject. In some embodiments, a subject can also inherit certain properties from a parent subject. If the subject is a link, if it exists only for the purpose of an object being shared via the link, it may not be associated with a parent subject, and the Link_sID may have as its parent the subject that created the link. The subject that created the link can be a subject representing another user account in the content management system, a subject representing the link service 136, or a subject representing the third - party service 170 that uses the link service 136 to create or manage the link.

[0145] The subject table 250 also includes a column indicating the root object ID. In some embodiments, all subject accounts represented by sID can be associated with their own private directory that may appear as the root of that account. At the same time, other root objects can be mounted to the directory structure of subject accounts under the root object of that subject. For example, a subject account can have a root directory called "root subject", and at the same time, that subject account may be part of a group. The group itself can have its own root directory called "group". The group root directory can be mounted under the subject's root directory so that it appears in a directory structure such as " / root subject / group". In another case, when a subject account is tightly associated with an organization's subject account, the root of the subject account may appear under the root of the organization. For example, if the organization has a root directory called "organization", the subject's directory structure may appear as " / organization / root subject". The specific relationship between one root directory and another is purely one of implementation. However, these examples show that each subject account can have its own root directory and that any root directory can be mounted within another root directory, resulting in it appearing to be subordinate to another directory even if it is the root of the subject account.

[0146] If a link to an object that already exists in object storage 142 and is thus already located under a root directory associated with at least one other subject is created, the object that becomes shared by the link can remain located at its current location under the root directory associated with the other subject. Link_sID may be granted access to an object located at its current location under the root directory associated with the other subject. In some embodiments, file system 116 may also create a root directory for Link_sID, but that directory may not contain the object because the object is located at its current location. Rather, the root directory for Link_sID may, in some embodiments, contain a pointer or reference to the object at that location within a directory for another subject.

[0147] File system 116 can handle complex policies associated with access to objects. For example, the policy can be associated with an object to permit only read access to anonymous link callers while permitting writeable access to link callers with an identified sID known to file system 116. It is also possible to permit a link caller to access only a specific version of an object so that while the object may be changed by its owner, the link caller has access only to a static document.

[0148] Subject table 250 is queried by receiving an sID identification and a range of HLC values, and such a query can return any information shown in another column of subject table 250. Although limited fields are shown as columns of subject table 250, those skilled in the art will understand that additional fields may also be included.

[0149] FIG. 5 shows an exemplary method for accessing an object referenced by a link managed by a link service, and FIG. 6 shows an exemplary sequence diagram for accessing an object referenced by a link managed by a link service. The exemplary method and sequence diagram depict a particular sequence of operations, but the sequence can be changed without departing from the scope of the present disclosure. For example, some of the depicted operations may be performed in parallel or in a different order that does not substantially affect the functionality of the technology. In other examples, different components of an exemplary device or system implementing the technology may function substantially simultaneously or in a particular order. FIGS. 5 and 6 are described together.

[0150] First, the link caller activates the link at node 301, resulting in a request to access the object referenced by the link. The request can point to API 138 to request the object, can include data embedded in the LinkUrl, and can optionally include a subject ID if the link caller is associated with a session with the content management system 110.

[0151] As used herein, the link caller can be a client device having an unidentified user (anonymous user), a client device having an established session with the content management system 110, a software service of the content management system 110, or a third-party service 170.

[0152] In some embodiments, the method includes receiving, at node 305, a request to access an object referenced by a link from a first client device. For example, the link service 136 can receive a request to access an object referenced by a link from the first client device. In some embodiments, the request is directed to API 138 before being transferred to the link service 136.

[0153] After receiving a request to access an object, the link service 136 can verify the link and / or execute other link services (308). In some embodiments, the link service 136 can verify the link by determining whether the link is currently a valid link, whether the link references an appropriate object, and examining various link metadata. The link metadata can include determining the link_sID, link properties, link capabilities (such as object acquisition, link modification, etc.). In some embodiments, the link service 136 can also execute various link services, as further described below. Some examples of link services are link logging, exploit prevention, link prohibition, rate throttling, etc.

[0154] The link service 138 can also identify the link caller as a user account or an anonymous account at the node 310. For example, the link service 136 can identify the link caller as a user account of the content management system 110, or, if the user account is not identified, the link service 136 can determine that the link caller is anonymous. In some embodiments, the link service 136 can identify the user account of the content management system 110 if the client device is associated with a session with the content management system 110. In some embodiments, the request to access an object can include the sID of the user account. In some embodiments, the link service 136 can interact with the IAM service 132 to identify the user account and sID associated with the client device 150.

[0155] However, in some embodiments, the link service 136 can identify that it is an anonymous user account associated with a request to access an object. For example, if the client device that calls the link is not associated with a session with the content management system 110 or is not known to the IAM service 132, the link service 136 may not be able to identify a known user account, and the link caller can be considered anonymous.

[0156] Regardless of whether the link caller is an identified user account or an anonymous user, the link can reference the link_sID of the link or be associated with the link_sID of the link.

[0157] When the link service 136 extracts or learns any sID (if any) of the user account and the link_sID associated with the link itself, at node 315, the link service 136 can return a file system access object to the client device 150 that includes the identification information of the object in the object storage 142 and a file system authentication token that includes any sID or link_sID that may provide permissions in the file system 116 to access the object. For example, the link service 136 can include the link_sID of the link in the authentication token and can include any sID (if any) associated with the identified user account in the authentication token. The authentication token gives the link caller temporary access to the file system 116.

[0158] This method further includes, at node 335, sending a file system access object 335 that includes an authentication token and identification information of an object in the file system to a first client device. For example, the link service 136 can send a file system access message that includes an authentication token and identification information of an object in the file system to the first client device / link caller. The file system access object can also include metadata that instructs the link caller to interact with the link service 136 to access one or more APIs of the file system to obtain an object, change link permissions, or change other link properties such as deleting a link.

[0159] Upon receiving the file system access object, the client device 150 can directly request the object from the file system (338). In some embodiments, this method includes, at node 340, receiving a request from the link caller to access the object identified in the file system access message. For example, the file system 116 can receive a request from the link caller to access the object identified in the file system access message. The file system access object can include an authentication token and identification information of an object in the file system. As described above, the authentication token is issued by the link service 136 that verified the link used by the link caller.

[0160] In some embodiments, the method includes, at node 345, determining whether the authentication token identifies, in addition to the link_sID, the subject ID (sID) of the user account that is permitted access in the object's access permissions. For example, the file system 116 can determine whether the authentication token identifies the subject ID. If the file system 116 determines that the subject ID (sID) of the user account is included in the authentication token, the file system 116 can determine whether an update to the subject database 140 or the object database 148 is necessary. For example, if the file system 116 determines that the authentication token identifies the user account (sID) in addition to the link_sID, at node 325, the file system 116 can associate the subject ID (sID) of the user account as a member of the link_sID of the link in the subject database 140, whereby the subject ID of the user account is associated with the link_sID of the link. Further, the file system 116 can associate the subject ID (sID) with the object in the object database 148.

[0161] In some embodiments, the method includes, at node 330, representing an object at a location within the user account. For example, since the subject ID (sID) of the user account of the content management system 110 is directly associated with the object ID (oID), the object can be represented at a location within the user account.

[0162] In some embodiments, the method includes, at node 350, evaluating any permission statements associated with access to an object by the file system. For example, file system 116 can evaluate any permission statements associated with access to an object by the file system that are associated with any sID or link_sID identified in decision 345. One advantage of the present technology is that file system 116 has the ultimate control over object access. File system 116 can evaluate object access as it normally does for any other object such that file system 116 determines that it can provide an object only if the subject ID (whether link_sID or some other sID) associated with the object is permitted to access the object in the access control list. More details regarding how file system 116 can determine whether a subject ID (sID or link_sID) can access an object are provided with respect to FIG. 7.

[0163] While the file system 116 controls access to the object, the file system 116 can also query the link service 136 to determine whether the link service 136 may have additional access restrictions or to confirm that the link is valid. For example, the file system 116 can request permission to access the object from the link service 136, and the link service 136 can make a determination (353) and send any access restrictions to the file system 116. In some embodiments, some of the link access restriction checks 353 may be redundant with the steps performed at 308, however, this check can confirm that the link has not been canceled within the time since the file system access object 335 was issued. The link access restriction check 353 can also be used to implement additional link policies not natively supported by the file system 116.

[0164] In some embodiments, the method includes, at node 355, sending to the link caller an object that matches the access permission for the object when the subject ID permits access to the object. For example, the file system 116 may send to the link caller an object that matches the access permission for the object when the subject ID permits access to the object.

[0165] The link caller can receive (357) the object.

[0166] FIG. 7 shows an exemplary method for evaluating an access control list composed of individual permission statements for objects within a directory tree. The exemplary method shown in FIG. 7 shows a particular sequence of operations, but the sequence can be changed without departing from the scope of the present disclosure. For example, some of the operations shown may be executed in parallel or in a different order that does not substantially affect the functionality of the method. In other examples, different components of the exemplary device or system implementing the method may function substantially simultaneously or in a particular order.

[0167] As described above, the complete access control list for any object may not persist in the content management system 110. Instead, the ACL list for a particular object is a vector of all permission statements recorded in the ACL table 202 for all objects within the directory tree above the particular object. The method shown in FIG. 7 first determines a list of the ancestors above a particular object and then constructs and evaluates the ACL.

[0168] When a client operating on behalf of a subject account requests access to an object or requests a write to the object database 148 and the object storage 142, it may be necessary to determine the subject's permissions as defined by the object's ACL.

[0169] In some embodiments, the method includes, at step 405, determining a list of ancestors of a specified object ID. For example, the file system 116 may determine a list of ancestors of the object ID. In one example, determining the list of ancestors may include obtaining the next ancestor object ID by searching for a query object ID (starting with the specified object ID) in a table containing ancestor data, building the list of ancestors by adding the next ancestor object ID as an ancestor to the query object ID, and recursively executing several steps including making the next ancestor ID the query object ID. This recursive process of building the list can be completed when the root of the tree is reached.

[0170] In some embodiments, for the purpose of determining an access control list for an object, the tree can include a root that cannot be accessed by a subject account. The recursive process of building a directory tree can build a directory tree with multiple roots or even multiple non-intersecting trees. This is a result of the content management system 110's ability to share objects stored under a root object to which a subject has no access rights.

[0171] In some embodiments, the method includes, at step 410, obtaining access permissions for each object ID in the ancestor tree. For example, the file system 116 may obtain a permission statement for each object ID in the ancestor tree from the ACL table 202. As described above, access permissions for an object define at least the subject to which the access permission applies, the capabilities granted to the subject, the permission (such as allow, deny, etc.) given to the subject for the object, and the inheritance properties of the access permission.

[0172] In some embodiments, the method includes ordering the permission statements into a sorted list according to the inheritance properties of each permission statement. A particular permission statement can have a "first" inheritance property and can be non-suppressible, whereby any subsequent permission statement in the sorted list of permission statements cannot override the particular permission statement. A particular permission statement can have a "first" inheritance property and can be suppressible, whereby any subsequent permission statement in the sorted list of permission statements can override the particular permission statement. Any permission statement with a first inheritance property is sorted to the front of the sorted list unless a subsequent permission statement requests its deletion. A particular permission statement can have a "last" inheritance property, and these permission statements are sorted to the end of the sorted list. A particular permission statement can have an "inherit none" inheritance property, and the permission statement is not displayed in the sorted list. A particular permission statement can have a "deny inherit" inheritance property, and the object ID does not inherit any permissions from its ancestors unless the ancestor's permission statement is "first" and non-suppressible.

[0173] The file system 116 determines (613) whether the obtained permissions for any object in the directory tree include the inheritance property of "do not inherit", and if so, the file system 116 can discard the permission statement for that object (614). The "do not inherit" property applies only to the specific object ID to which it is associated and does not affect whether any ancestor policies or descendant policies are merge-sorted within the list.

[0174] The file system 116 can determine (415) whether the obtained permissions for any object in the directory tree include the inheritance property of "inheritance denied", and if so, the file system 116 can discard the permission statements from all ancestors (objects higher in the directory tree than the object ID with the "inheritance denied" property) unless the inheritance policy is a non-suppressible first inheritance policy (420). The discarded permission statements are not merge-sorted into the list.

[0175] Using the remaining permission statements, the file system 116 can perform a merge-sort of these permission statements for proper ordering for evaluation. The ordering of the permission statements can include determining (425) that the permission statement for the object ID in the obtained permission statements has the inheritance property of "first". The file system 116 can place the permission statement with the "first" inheritance property higher in the ordered list of permission statements than the permission statement with the "last" inheritance property, by merge-sorting these permissions from the top to the bottom of the list, and each permission is included in the list in the order in which it appears from the top to the bottom of the directory tree.

[0176] Ordering the permission statements may further include determining that a permission statement for an object ID within the obtained permission statements has an inheritance property of "last". The file system 116 may place, in an ordered list of permission statements, the permission statements associated with ancestors of the object ID having a permission statement with an inheritance property of "last" by merge-sorting these permissions in reverse relative order such that their respective ancestors are arranged in the ancestor tree (430). In other words, access permissions for an object at the bottom of a directory tree are placed in an ordered list of permission statements above the permission statements for objects higher up in the directory tree. However, all "last" inherited access permissions are placed in an ordered list below the access permissions having a "first" inherited permission statement. The ordered list of all access permissions for an object can be considered an access control list (ACL) for the object.

[0177] In some embodiments, the method includes, at step 435, iterating through the ordered list of permission statements in order until a permission statement permits or denies access to the object. For example, the file system 116 may iterate through the ordered list of permission statements in order to determine whether access should be permitted or denied.

[0178] In some embodiments, when a permission statement permits or denies access, iteration through the list can be terminated. If the first inherited permission can be suppressed, it is necessary to at least iteratively execute through the tree until one of the last inherited permission statements provides or denies access. Thus, determining whether access should be permitted or denied includes determining whether access is permitted or denied by a non-suppressible first inherited permission (440). If a non-suppressible permission statement does not resolve the access determination, the file system 116 evaluates the remainder of the ordered list of permission statements (445) until a last inherited permission statement permits or denies access, and can permit or deny access based on the result of the ACL evaluation (450).

[0179] In some embodiments, suppressible first inherited access policies can also be processed by paying attention to whether those policies are suppressed by last inherited policies associated with objects elsewhere in the tree. In such cases, the suppressed first inherited access policies can be excluded from the merge sort (425), and the list of permission statements can be evaluated using a simple iteration of the list of permission statements (435), regardless of the sub-methods consisting of steps 440, 445, and 450.

[0180] In some embodiments, the output of FIG. 7 can be a list of capabilities for any object that has been evaluated.

[0181] The access determination method shown in FIG. 7 can have the advantage of being very flexible. A permission statement can be created that provides access rights to anyone attempting to access an object via a link, but more specific access permissions can be provided for a subject ID known to the content management system. For example, a user account for content management can be given greater access rights than an anonymous user.

[0182] In the case of a shared link, the root of the tree is generally at the level of the shared object of the object stored in the content management system 110 for the purpose of sharing using the link, or is mounted from another location in the content management system 110 if the object is shared from within an existing user account. In the first example, if the object is stored at the root of the link_sID account, the result of the method shown in FIG. 7 is generally determined by the access provided by the link. On the other hand, when the link is stored in another location in the content management system 110 and provides access to an object mounted at the root of the link_sID account, the access is determined by the restrictions on access to the object itself and the access provided by the link.

[0183] FIG. 8 shows a link service 136 and some exemplary services performed by the link service 136. As discussed above, the link service 136 can operate as a software-as-a-service platform that can perform all services related to the issuance, management, and processing of links by the link service 136. It will be understood by those skilled in the art that FIG. 8 does not show all possible services that can be provided by the link service 136 operating as a software-as-a-service platform. The link service 136 may be a service provided as part of the content management system 110, or the link service 136 may be a separate service.

[0184] As described above, a link caller, user, and service desiring to utilize the link service 136 can contact the link service 136 by calling one or more APIs 138 provided by the link service 136. For example, a user or service can call a link generation API that can cause the API 138 to initiate a link setting user interface 520 presented to the user for setting a link. In another example, a link caller can call a link access API, and the API 138 can interface with a link access service 515 to obtain an object referenced by the link. In another example, the file system 116 can call a link access level API, and the API 138 can interface with the link access service 515 to determine the access level provided by the link. As will be understood by those skilled in the art, there can be many APIs provided by the link service 136 corresponding to one or more functions that can be provided by the link service 136.

[0185] FIG. 9 shows some exemplary APIs and their functions. The APIs and their exemplary functions addressed herein should not be considered as limiting the functions that can be performed by the link service 136.

[0186] One function of the link service 136 can be the creation of a link to an object. Such a link service 136 includes a link setting user interface 520 that can be presented to the user via a web browser or an application on the client device 150 for creating and setting a link to the object. As further described below, FIG. 11A shows an example of a graphical user interface provided by the link setting user interface 520.

[0187] Link service 136 may also include a link generation service 505. The link generation service 505 can create links such that they are configured by a user using a link generation graphical user interface or are directed by a software service such as an application that interfaces with the link service 136 via a third party service 170 or one or more APIs 138.

[0188] For example, FIG. 10 shows an exemplary method for creating a link. The link generation service 505 can receive a request 550 that can identify an object for setting a link to the object. In some embodiments, the request 550 for setting a link to an object can come from a user interface as shown in FIG. 11A, or the request 550 for setting a link to an object can come from a service that interacts via the API 138. The link generation service 505 can create a URL for the link that uniquely identifies the link to the link service 136 (555). The link service 136 can also interface with the file system 116 to set a link within the file system 116 (560). The link service 136 can perform these functions using a file system interface 525 that can communicate with the file system 116 to establish the link as an actor within the file system as described above (560). The file system interface 525 can also set any permission statements associated with the link for inclusion in an access control list for the object (560).

[0189] In some environments, a request 550 to set a link to an object can identify the object by its oID when the object is stored in the object database 142. However, when a request 550 to set a link to an object refers to an object that is not stored in the object database 142, the request can include the object itself for storage in the object database 142. In some embodiments, the object referred to by the link may not need to be stored in the object database 142. The link service 136 can interface with third-party services to provide a link service that refers to objects stored in third-party services 170.

[0190] In addition to interfacing with the file system 116, the link generation service 505 can store in the link database 510 metadata associated with the link, including the link_sID and oID of the linked object, and any additional access restrictions (570).

[0191] Link service 136 also provides services related to access to an object by a link caller. For example, link service 136 can receive a request to access an object from a link caller that has activated a link issued by link generation service 505. Link service 136 can utilize link access service 515 to verify that the link is valid and to search for link metadata within link database 510. Link metadata can include information regarding the type of link (links issued by the link service, links issued by a partner service, legacy links supported by the link service, etc.), link permissions, link settings, policies associated with the link, the entity that established the link, and so on. Further, in some embodiments, file system 116 can request additional information regarding the link access level, and link access service 515 can return any required information.

[0192] Link service 136 can also interface with external services to manage links. In some environments, link service 136 can use link generation service 505 to provide links to third-party service 170, but in some embodiments, third-party service 170 or legacy service 135 may create links and desire for link service 135 to manage the maintenance and service aspects of the links. In such embodiments, external link logic interface 530 can be used to interface with third-party service 170 or legacy link service 135 to determine whether the link is valid or subject to any restrictions.

[0193] In addition to creating links and processing link access, link service 136 can further provide other link services. As shown in FIG. 8, other link service 540 represents a general placeholder for any additional link services. Some exemplary link services include link management, rate limiting of link access, fraud prevention, link prohibition, prevention of link creation by unauthenticated users, ensuring compliance with sharing policies that can be associated with objects, standard link settings, expiration dates, passwords, viewer management, analysis, metrics and logging, tracking of link senders and visitors, audit logging, administrative functions, data loss prevention, integration with file system permissions, and the like.

[0194] FIG. 11A shows an exemplary user interface for creating a link using link service 136. Link settings UI 520 can present the user interface shown in FIG. 11A as a result of a request by a user having access rights to the object for which the link is to be created. For example, link settings UI 520 can present the user interface shown in FIG. 11A as a result of a user calling the GetFileLinkActions API, as shown in FIG. 9.

[0195] The user interface shown in FIG. 11A can generate a link by calling the CreateApplicationLink API and present the public version of the link in field 605. The link can further be configured using one or more options 610. As shown in FIG. 11A, some of the options 610 can include providing an expiration date for the link and specifying the type of access. Although not shown in FIG. 11A, it should be understood that other options and more complex versions of these options can be supported. For example, depending on whether the link caller is anonymous, within a specified list of sIDs, or provides a password, various levels of link access may be provided.

[0196] FIG. 11B shows a user interface provided by a third-party service 170, which can create a link 615 that can redirect to the link service 136. The third-party service 170 may link to content stored in the third-party service 170, or the content may be stored in the object storage 142 by the content management system 110. FIG. 11B also provides link options 620 such as specifying a particular collaborator with whom to share the link and specifying the level of link access. Although not shown in FIG. 11B, it should be understood that other options and more complex versions of these options can be supported.

[0197] FIGS. 12A and 12B show a part of an exemplary method for jointly managing a link by the link service 136 and the third-party service 170 operating as a link platform-as-a-service.

[0198] FIG. 13 shows an exemplary sequence diagram for the collaborative management of links by the link service 136. The collaborative management of links can include the ability for both the link service 136 and the third-party service 170 to set links, and in particular, to provide link logic for determining when a link is valid or accessible, among other aspects.

[0199] Although FIGS. 12A and 12B are discussed with respect to the third-party service 170 as an example of a partner service, it will be understood that any service that collaboratively manages links with the link service 136 is possible.

[0200] The exemplary methods illustrated in the sequences of FIGS. 12A, 12B, and 13 show a particular sequence of operations, but the sequence can be changed without departing from the scope of the present disclosure. For example, some of the operations shown may be executed in parallel or in a different order that does not substantially affect the functionality of the method. In other examples, the different components of the exemplary device or system implementing the method may function substantially simultaneously or in a particular order.

[0201] A partner service (the third-party service 170 or another service of the content management system 110) can set a link for collaborative management by the link service 136. For example, the partner service can request (701) that the link service 136 establish a link, and the link service 136 can set the link (702). Part of setting the link is to interface with the file system 116 to create a link_sID for the link and give the link_sID permission to access the object referenced by the link. The partner service may already have stored the object in the file system 116, or may send the object for storage by the file system 116 as part of the request (701) to establish the link in the link service 136.

[0202] In some embodiments, the link caller can activate a link issued by a partner service (704), whereby the partner service can receive a request to access an object (705). The partner service can execute its own link logic (706) and can authenticate the link and approve the link caller. In some embodiments, the partner service may not perform this step.

[0203] The partner service can maintain a mapping between the link it issued and the co - managed link co - managed by the partner service and the link service 136. After receiving a request to access an object (705) and optionally executing any link logic (706), the partner service can contact the link service 136 using the co - managed link corresponding to the link issued by the partner service activated by the link caller.

[0204] In some embodiments, the method includes receiving, at node 707, a request to provide access to an object referenced by a partner service link. For example, link service 136 can receive, from a partner service, a request to provide access to an object referenced by a partner service link. In some embodiments, a request to provide access to an object from a partner service occurs after the partner service has made its own determination that the caller of the partner service link is permitted to access the object. For example, a partner service link may point to a third party service 170, and thus, when a user activates the link and becomes the link caller, the user is directed to the third party service 170. The third party service 170 can utilize its own criteria (706) to determine whether the partner service link is valid, and if the link caller is authorized, the partner service can contact link service 136 using a co - managed link stored by the partner service.

[0205] In some embodiments, the partner service can send the co - managed link to the link caller, instruct the link caller to follow the link to link service 136, and link service 136 can interact directly with the link caller.

[0206] In some embodiments, the partner service can also establish a link using link service 136 and send that link to the link caller. In such embodiments, when calling the link, the link caller does not interact with the partner service at all.

[0207] In some embodiments, the partner link may be a co - managed link, whereby the link caller is directly directed to the link service 136 without first contacting the partner service. The link service 136 can recognize the link as a co - managed link and, optionally, use the external link logic interface 530 to interface with the third - party service 170, enabling the third - party service to determine whether the link is valid and whether the link caller is permitted. In this way, both the partner service and the link service can perform their own access determinations. Such embodiments can be useful when the partner service wishes to reduce its involvement in the link - processing process, as a result of which the partner service may issue links that it does not need to service. At the same time, the partner service, as the link issuer, can interface with the link service 136 to set (or reset) the link as desired.

[0208] Accordingly, there is a mechanism for the partner service to be less involved in link management and servicing link callers. FIG. 13 assumes an embodiment where it is desired for the partner service to appear as if it is issuing the link and providing the object.

[0209] It will be understood that co - management of the link by the partner service can include sharing any link - management or link - servicing function and is not limited to determining whether the link is valid and whether the link caller is permitted.

[0210] In some embodiments, the identification information (715) of the authorized entity is the s_ID corresponding to the link. When the partner service link directly guides the link caller to the partner service, the partner service can include additional information in contacting the link service 136 using the co-management link. For example, a request to provide access to an object referred to by the partner service link can identify the end user requesting the object, and any user identification information can be included in the request (707) to the link service.

[0211] Even if the partner service does not know the sID of the link caller, the partner service can transfer the email address or other user identifier if it is known. The link service 136 can attempt to match any email address or user identifier with information that maps it to an sID in the subject database 250.

[0212] In some embodiments, the method includes performing an anti-fraud and link access logging function at the node 710. For example, the link service 136 can perform an anti-fraud and link access logging function and / or any other service desired from the link service 136 operating as a link platform-as-a-service.

[0213] After receiving a request to access an object, the link service 136 can verify the link (715) and / or execute other link services 308. In some embodiments, the link service 136 can verify the link by determining whether the link is a currently valid link and whether the link refers to an appropriate object, and by examining various link metadata. The link metadata can include determining the link_sID, link properties, link capabilities (such as object acquisition, link modification, etc.).

[0214] In some embodiments, the link service 136 and the partner service determine that the link is valid and, after performing other services with respect to the link, the method includes creating, at node 715, a file system access object that refers to the file system 116 of the content management system 110. In some embodiments, the file system access object includes a token having an expiration date to limit the time for which the file system access object remains valid. The file system access object enables an entity having an authentication token within the file system access object to interface with the file system 116 to obtain the object. The expiration date ensures that future calls to the object are made using the original link so that the link service 136 and the partner service can perform the desired functions when the link is invoked.

[0215] In some embodiments, the method includes sending, by the link service 136 to the partner service, a file system access object that refers to the file system. The file system access object includes, at node 720, an authorization token, identification information of an authorized entity, and an object ID. The file system access object can include the information necessary to access the file system 116 and can identify any subject ID known to the link service 136. For example, the file system access object can include the link_sID of the link and, if the link caller can be associated with a user account known to the content management system 110, the file system access object can include the sID of the user account. The file system access object can also include an object ID that identifies the object with respect to the file system 116.

[0216] The file system access object can also include metadata that instructs the link caller to interact with the link service 136 to access one or more APIs in the file system to obtain an object or change permissions for a link, or to modify other link properties such as deleting a link.

[0217] In some embodiments, the partner service can receive a file system access object and request the object from the file system 116 (723).

[0218] The method further includes, at node 725, receiving, by the file system, a request to access an object identified by the file system access object. For example, the file system 116 can receive a request to access an object identified in the file system access object.

[0219] In some embodiments, the method includes, at node 740, transmitting, by the file system, an access level request associated with the file system access object to the link service. For example, the file system 116 can transmit an access level request associated with the file system access object to the link service 116. The file system 116 can determine the permissions granted to the subject ID with respect to the object, but in some embodiments, the link service 136 can also include some additional configurations that can affect access to the object. Accordingly, the file system 116 can communicate with the link service 136 to determine any additional access level information.

[0220] The link service 136 can determine (745) the access level associated with the file system access object and send (750) the access level associated with the redirect link to the file system 116. In some embodiments, some of the link access restriction checks 353 may be redundant with the steps performed at 308, but this check can confirm that the link has not been canceled within the time since the file system access object 335 was issued. The link access restriction check 353 can also be used to implement additional link policies not natively supported by the file system 116.

[0221] In some embodiments, the method includes the file system determining whether the file system access object identifies an sID that is permitted access in the access permissions of the object at node 755. For example, the file system 116 can determine whether the file system access object identifies an sID that is permitted access in the access permissions for the object. The authorization token for the redirect link should at least identify a link_sID that permits the link to be an actor within the file system. In some embodiments, the authorization token can also identify the sID of the user account of the content management system.

[0222] In some embodiments, the method includes determining at node 760 that an end user has a user account in the content management system. In some embodiments, the file system 116 may also determine that the link caller has a user account in the content management system 110. For example, the link service 136 may know that the link caller has an active session with the content management system 110 and that the authorization token includes the sID of the user account (765). Alternatively, the file system 116 may detect an active session or otherwise identify that the link caller is associated with the sID of the user account. For example, the link service 136 or the file system 116 may be able to identify the sID associated with the email address associated with the link caller provided by the partner service.

[0223] When it is determined (760) that the link caller has a user account in the content management system 110, the method includes updating an ID table in the file system 116 to associate the user account as a member of the link, whereby at node 770, the user account is associated with the link. In some embodiments, at node 775, the file system 116 represents the object referenced by the link at a location within the user account. For example, the object can be added to the user account by associating the sID of the user account with the oID of the object in the file system 116, whereby the object becomes directly accessible to the user account without requiring a link for future access.

[0224] In some embodiments, when the sID permits access to an object, at node 780, the object is sent to a partner service that matches the access permission for the object. For example, as long as the authorization token identifies a valid link_sID that provides access to the object, the link caller can receive the object. This allows an anonymous user to access the object referenced by the link. When the sID permits access to an object, the file system 116 sends an object that matches the access permission for the object to the link caller.

[0225] In some embodiments, the method includes sending (785) the object to an entity that contacted the link service 136. For example, when a partner service provides a link to the link service 136, the link caller directly receives (787) the object from the file system 116. FIG. 13 shows an embodiment where the file system 116 sends the object to the partner service (785) and the partner service can transfer the object to the link caller. In such an embodiment, this allows the partner service to wrap the object in any UI or markup and make it appear as if the object was provided by the partner service.

[0226] The co-management of the link by the partner service and the link service can involve more than two entities that apply link logic to determine whether the link caller should be given the right to access the object. FIG. 13 shows an embodiment where the link caller requests an object, but the partner service can interact with the link service 136 through the co-managed link at its own start-up.

[0227] Through the joint management of the link, both entities (partner service and link service 136) can participate in the ongoing management of the link, including changing the link settings, deleting the link, or further sharing the link. In some embodiments, the method includes receiving, at node 790, a request to change the access level from the partner service via the API of the link service. For example, the API 138 of the link service can receive a request to change the access level from a partner service such as the third-party service 170. In some embodiments, the request to change the access level includes changing at least one access parameter for the object. The change of at least one access parameter can be applied to the end user having the link.

[0228] Other operations are also possible. In some embodiments, the partner service can contact the link service 136 using the jointly managed link. The link service 136 can return link metadata including a collection of link functions that can be executed by the link service 136 or by the partner service that interacts with the file system 116. The partner service can then contact the appropriate API of the link service 136 or the file system 116 to execute a management function or request or modify the object that is the target of the link.

[0229] FIG. 14 shows an exemplary method for supporting legacy links. In some embodiments, the link may already exist before being provided to the link service 136 for management. In such embodiments, the link may already be directed elsewhere than the link service 136. Further, the link may be associated with behavior or logic different from the behavior or logic provided by the link service 136, and it may not be desirable to change the user experience associated with the existing link. At the same time, it may be desirable to have the content management system 110 store and manage the object pointed to by the link, or to provide additional link functionality to the link service 136. The method shown in FIG. 14 is directed to such embodiments.

[0230] FIGS. 15A and 15B are sequence diagrams showing alternative call flows for supporting legacy links. In particular, FIG. 15A shows an exemplary sequence in which activation of a link instructs an API 138 that calls the functions of the link service. This embodiment is useful when the API is updated to point to the link service 136 instead of the legacy service. However, FIG. 15B shows the sequence when the legacy link continues to point to the legacy link service and the legacy link service is updated to reference the link service 136.

[0231] The link caller can activate the link (801). In some embodiments, as shown in FIG. 15A, the activated link can direct the link caller to a legacy link service (802) that can receive requests for objects. In some embodiments, as shown in FIG. 15B, the activated link can direct the link caller to a link service 135 (803) that can receive requests to access the object referenced by the link. The link service 136 can determine the link 804 that the link caller queried as a legacy link to the link service 136 by looking up the link in the link database 510 and transfer the request to the legacy link service.

[0232] In some embodiments, the method includes evaluating a legacy link at node 805 according to legacy link evaluation logic. For example, the link service 136 can evaluate the legacy link according to legacy link evaluation logic.

[0233] In some embodiments, evaluating a legacy link at node 805 according to legacy link evaluation logic can include the link service 136 using an external link logic interface 530 to interact with the legacy link logic in order to interact with the link logic from the legacy service, as shown in FIG. 15B.

[0234] In some embodiments, the link service 136 can be configured with instructions to evaluate the legacy link logic and need not contact the legacy service.

[0235] In some embodiments, the legacy link service may determine that the link caller cannot access the object. For example, some legacy link services only permit access if the user who provided access to the object currently maintains access to the object. If the user who provided access to the object no longer has access rights to the object, some legacy link services do not permit other users to access the object, even when accessing via a public link.

[0236] After the legacy link service determines that the link caller can access the object, the legacy link service can attempt to identify a proxy link associated with the object referenced by the legacy link and use the proxy link to call the link service 136.

[0237] However, in some embodiments, the proxy link may not yet exist. In some embodiments, if the link service 136 is configured to cooperate with the legacy link service, many links may have been previously issued by the legacy link service. Many of those links are likely to never be reactivated. Therefore, it would be inefficient to pre-create proxy links for all legacy links. Instead, the present technology can create proxy links on demand when needed. In such embodiments, the legacy link service can attempt to identify a proxy link associated with the object, and if it fails, the legacy link service can request a proxy link from the link service 136 (not shown) instead of accessing the link service 136 using a known proxy link.

[0238] In some embodiments, the method includes receiving, at node 810, a request to provide access to an object referenced by a legacy link. For example, link service 136 can receive a request to provide access to an object referenced by a legacy link. This request can be the result of the legacy link service following a proxy link to the object referenced by the legacy link, or requesting the issuance of a proxy link.

[0239] If request 810 is the first request for a legacy link received by link service 136 and the legacy link service is requesting a proxy link, it may be necessary to set link_sID in object storage 142 and set a proxy link, or link service 136 may already have a proxy link established for the object. If a new proxy link needs to be created, link service 136 can communicate with file system 116 using file system interface 525 to create a proxy link associated with link_sID in file system 116. In some embodiments, the proxy link is associated with its own subject ID (link_sID) within the file system. For example, the method includes generating, by the link service, a proxy link at node 815 that points to a file system object, and file system 116 can set the proxy link and record the link_sID for the proxy link (817). For example, link service 136 can generate a proxy link that points to file system 116.

[0240] In some embodiments, claim 810 is the first request for a legacy link received by link service 136, and if the legacy link service is requesting a proxy link, link service 136 may already have a reusable proxy link created for the object. For example, link service 136 may have created a proxy link to the object for another legacy link, and this proxy link may be reused. The proxy link is somewhat different from the co-managed links of FIGS. 12A, 12B, and 13, or the links of FIGS. 5 and 6. This is because these links are associated with policies (permission statements) in file system 116 and perhaps also in link service 136, whereas legacy links have their policies controlled by the legacy link service. Thus, each proxy link for one or more legacy links typically has the same policy (permission statement) associated with the link in file system 116. The link_SID of the proxy link permits reading and writing of the object according to file system 116. Any additional restrictions from the legacy link service can be imposed by link service 136 in block 837, described below.

[0241] If a proxy link is already configured, the link service 136 can request an object from the file system 116 by using the proxy link and providing the link_sID and any known user sID. The file system can return a file system access object that includes an authorization token, identification information of an authorized entity, and an object ID. In some embodiments, the file system access object includes a token with an expiration date to limit the time for which the file system access object remains valid. The expiration date can be relatively short to ensure that when the link caller wants to access the object again, a legacy link has to be used and the legacy link logic has to be followed.

[0242] In some embodiments, the method includes the file system receiving a request 830 for an object identified by a file system access object. For example, the file system 116 can receive a request 830 for an object identified by a file system access object. The file system access object can include an authorization token that includes identification information of an authorized entity. If the authorization token includes the subject ID (sID and / or link_sID) that was granted access in the access permission for the object at node 835 (835), the file system 116 can send the object at node 840, and the link caller has access permission that matches the access permission for the object. In some embodiments, before sending the object to the link caller (840), the file system 116 can interact with the link service 136 to determine (837) whether there can be other link access restrictions - for example, access restrictions as defined by a legacy link service.

[0243] The link caller can receive the object (845).

[0244] Figure 16 shows an example of a computing system 900, which can be, for example, any computing device that constitutes a link service 136, or any component thereof where the components of the system communicate with each other using a connection 905. The connection 905 can be a physical connection via a bus or a direct connection to a processor 910 such as a chipset architecture. The connection 905 can also be a virtual connection, a network connection, or a logical connection.

[0245] In some embodiments, the computing system 900 is a distributed system where the functions described in this disclosure can be distributed within one data center, multiple data centers, a peer network, etc. In some embodiments, one or more of the described system components represent a number of such components each of which executes a part or all of the functions for which the component is described. In some embodiments, the components can be physical devices or virtual devices.

[0246] The exemplary system 900 includes a connection 905 that couples various system components to a processor 910, including at least one processing unit (CPU or processor) 910 and a system memory 915 such as a read-only memory (ROM) 920 and a random-access memory (RAM) 925. The computing system 900 can include a cache of a high-speed memory 912 that is directly connected to the processor 910, connected in proximity to the processor 910, or integrated as part of the processor 910.

[0247] Processor 910 can include any general-purpose processor, hardware services or software services such as services 932, 934, and 936 stored in storage device 930 configured to control processor 910, and a dedicated processor in which software instructions are incorporated into an actual processor design. Processor 910 can essentially be a fully self - contained computing system including multiple cores or processors, buses, memory controllers, caches, etc. The multi - core processor can be symmetric or asymmetric.

[0248] To enable interaction with the user, computing system 900 includes an input device 945, which can represent any number of input mechanisms such as a microphone for voice, a touch - sensitive screen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. Computing system 900 can also include an output device 935, which can be one or more of a number of output mechanisms known to those skilled in the art. In some examples, a multimodal system can be enabled to provide multiple types of input / output for the user to communicate with computing system 900. Computing system 900 can include a communication interface 940, which can generally govern and manage user input and system output. There is no limitation on operating with any particular hardware configuration, and thus the basic features herein can be easily replaced with improved hardware or firmware configurations as they are developed.

[0249] The memory device 930 can be a non-volatile memory device and can be a hard disk, or other types of computer-readable media that can store data accessible by a computer, such as a magnetic cassette, a flash memory card, a solid state memory device, a digital versatile disk, a cartridge, a random access memory (RAM), a read-only memory (ROM), and / or some combination of these devices.

[0250] The memory device 930 can include software services, servers, services, etc. When the code defining such software is executed by the processor 910, it causes the system to perform functions. In some embodiments, a hardware service that performs a particular function can include software components stored in a computer-readable medium in relation to the hardware components necessary to perform the function, such as the processor 910, the connection 905, the output device 935, etc.

[0251] For clarity of explanation, in some cases, the present technology may be presented as including individual functional blocks including devices, device components, steps or routines in a method implemented in software, or functional blocks consisting of a combination of hardware and software.

[0252] Any of the steps, operations, functions, or processes described herein may be performed or implemented by a service or combination of services of hardware and software, alone or in combination with other devices. In some embodiments, the service can reside in the memory of one or more servers of a client device and / or a content management system and can be software that performs one or more functions when the processor executes the software associated with the service. In some embodiments, the service can be a program or collection of programs that perform a particular function. In some embodiments, the service can be considered a server. The memory can be a non-transitory computer-readable medium.

[0253] In some embodiments, a computer-readable storage device, medium, and memory may include a cable signal or a wireless signal, such as a bitstream. However, when mentioned, a non-transitory computer-readable storage medium explicitly excludes media such as energy, carrier signals, electromagnetic waves, and signals themselves.

[0254] The methods according to the above-described embodiments can be implemented using computer-executable instructions stored from or otherwise available on a computer-readable medium. Such instructions can include, for example, instructions and data that cause a general-purpose computer, a special-purpose computer, or a special-purpose processing device to perform or otherwise configure specific functions or groups of functions. Some of the computer resources used may be accessible via a network. The executable computer instructions may be, for example, binary, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that can be used to store the instructions, information, and / or information created during the methods according to the described embodiments include magnetic disks or optical disks, solid-state memory devices, flash memory, USB devices with non-volatile memory, networked storage devices, and the like.

[0255] Devices that implement the methods according to these disclosures can be composed of hardware, firmware, and / or software and can take any of various form factors. Typical examples of such form factors include servers, laptops, smartphones, small form factor personal computers, personal digital assistants, and the like. Also, the functions described herein can be embodied in peripheral devices or add-in cards. Such functions can also be implemented, as a further example, on a circuit board between different chips or different processes executed within a single device.

[0256] Commands, a medium for transmitting such commands, computing resources for executing them, and other configurations for supporting such computing resources are means for providing the functions described in these disclosures.

Claims

1. A method for providing a link service by a link platform as a service system, comprising: In the link platform as a service system, receiving, from a partner service system, a request to configure a link for management by the link platform as a service system, wherein the request to configure the link includes information regarding options associated with the link; In the link platform as a service system, receiving, from the partner service system, a request to access an object that is the target of the link, wherein the request to access the object includes an indicator indicating that the link is co-managed; In the link platform as a service system, processing the link according to the options associated with the link; Verifying the link; A method comprising the above.

2. In the link platform as a service system, creating the link by interfacing with a file system and establishing the link as a subject having access permission to the object in the file system; The method according to claim 1, further comprising the above.

3. In the link platform as a service system, after verifying the link, transmitting a file system access link together with an authorization token for accessing the object from the file system to the partner service system or the link caller; The method according to claim 2.

4. In the link platform as a service system, creating the link and storing metadata corresponding to the link, wherein the metadata includes the options associated with the link; The method according to claim 1.

5. The option is to store the object that is the target of the link in the partner service system, and the method includes: After verifying the link, redirecting the link caller in a communication including an access token to obtain the object from the partner service system; The method according to claim 1, comprising: **Claim 6** The option is to enable the partner service system to perform a part of the verification of the link, and processing the link according to the option is In the link platform as a service system, after receiving the request to access the object, redirecting the link caller to the partner service system; The method according to claim 1, comprising: **Claim 7** The option is for the partner service system to provide a public link that guides the partner service system, and receiving the request to access the object is the result of the partner service system calling a link service or redirecting the link caller to the link service; The method according to claim 1. **Claim 8** In the link platform as a service system, receiving a request from the partner service system to change the access permission related to the link; In the link platform as a service system, interfacing with the file system to change the access permission related to the link in the file system; The method according to claim 6, further comprising: **Claim 9** A program including instructions, which when executed by a link platform as a service system, cause the link platform as a service system to In the link platform as a service system, receiving a request from the partner service system to configure an administrative link, wherein the request to configure the link includes information about an option associated with the link; In the link platform as a service system, receiving a request to access an object targeted by the link, wherein the request to access the object includes an indicator indicating that the link is co-administered; In the link platform as a service system, processing the link according to the option associated with the link; verifying the link; A program for causing the above to be performed.

10. When the program is executed by the link platform as a service system, the link platform as a service system is caused to interface with a file system to establish a link as a subject having access permission to an object in the file system; The program according to claim 9, further comprising an instruction for causing the above to be performed.

11. When the program is executed by the link platform as a service system, the link platform as a service system is caused to after verifying the link, send a file system access link to the partner service system or the link caller together with an authorization token for accessing the object from the file system; The program according to claim 10, further comprising an instruction for causing the above to be performed.

12. The option is to store the object that is the target of the link in the partner service system, and the instruction causes the link platform as a service system to after verifying the link, redirect the link caller in a communication including an access token to obtain the object from the partner service system; The program according to claim 9, for causing the above to be performed.

13. The option is to enable the partner service system to execute a part of the verification of the link, and processing the link according to the option is after receiving the request to access the object, redirecting the link caller to the partner service system; The program according to claim 9, including the above.

14. When the program is executed by the link platform as a service system, the link platform as a service system is caused to receive a request from the partner service system to change access permissions related to the link; Interface with the file system to change the access permissions associated with the link in the file system. The program according to claim 10, further comprising an instruction to cause the above to be performed.

15. At least one API for providing one or more services for each link, wherein the one or more services are executed on behalf of at least one partner service system that hosts each object with which each link is associated. At least one API, A link generation service for generating each of the links, A link database for storing information regarding each of the links, each object associated with each of the links, and policies, A request to access a first link of each of the links, the request to access the first link being received from a partner service system and including an indicator indicating that the link is co-managed, and determining whether the first link is valid. A link access service that interacts with the link database to determine which partner service system of the at least one partner service system the first link is, and to determine which object the first link is referring to. A link platform as a service system, including.

16. The link generation service is Receives a request to generate the first link to the object, Presents a link creation user interface that identifies selectable options associable with the object and the first link, Generates the first link, The link platform as a service system according to claim 15, configured as follows.

17. The link access service is Receives a request to access the first link, Executes an anti-fraud and link access logging function, Sends a link access message including the object referred to by the first link to the partner service system, the link access message identifying the link ID and the information of the requesting user. The link platform as a service system according to claim 15, configured as follows.

18. The at least one API is Receiving a request to perform an operation related to the first link or link creator, Returning the result of the operation to an authorized requester, The link platform as a service system according to claim 15, characterized in that it is configured as such.

19. The at least one API, Receiving a request to change the access level provided by the first link, Sending the changed access statement to the file system, The link platform as a service system according to claim 15, characterized in that it is configured as such.

20. The at least one API, Receiving a request to change the access permissions provided to a user account by the first link, Sending the changed access statement to the file system that changes the access permissions for the object of the user account, The link platform as a service system according to claim 15, characterized in that it is configured as such.

Citation Information

Patent Citations

  • Collection folder for collecting file submissions via customizable file requests

    JP2018513485A

  • Middleware security layer for cloud computing service

    JP2019153330A

  • External sharing with improved security

    US20180343243A1

  • Technologies for migrating content items from a server on a network to an online content management system

    US20210165759A1