# Advice for implementing a secure graph index with ElasticSearch

**URL:** <https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176>\
**Category:** Elasticsearch\
**Created:** [March 5, 2014, 5:10pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176 "2014-03-05T17:10:11Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jeff\_Kunkle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeff_kunkle/32/1301_2.png) [@Jeff\_Kunkle](https://discuss.elastic.co/u/Jeff_Kunkle)\
**Post date:** [March 5, 2014, 5:10pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/1 "2014-03-05T17:10:11Z")

</div>

I've been trying to figure out how I can index a graph data structure using  
ElasticSearch and could really use some advice from someone more  
knowledgeable than me. First, let me explain the challenge. The graph model  
has individual access controls at the vertex (node), edge (relationship),  
and property level. I'd like my users to be able to search the graph for  
vertices or edges containing matching properties, with two caveats:

1. They should not get vertex or edge results they don't have permission  
to see.
2. Properties a user does not have access to see should not be evaluated  
in the query.

My first thought was to index properties as either nested or child  
documents of a vertex/edge and use a custom filter to remove properties a  
user didn't have access to. The first problem I run into is when I try a  
boolean query across properties. For example, assume I want to query a  
person vertex by first name and date of birth. Since these properties are  
indexed as separate documents there is never a match.

What I essentially need is the ability to query across nested or child  
documents and return the parent only when there are matches across the  
child documents. For example, assume a parent vertex with one property  
document called "full\_name" set to Barak Obama and another property  
document named "political\_party" set to Democrat. Is there any way for me  
to query for the parent document of these two properties by asking for one  
property with full\_name="Barak Obama" and another property with  
political\_party="Democrat"?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Michael\_Sick](https://avatars.discourse-cdn.com/v4/letter/m/22d042/32.png) [@Michael\_Sick](https://discuss.elastic.co/u/Michael_Sick)\
**Post date:** [March 5, 2014, 5:41pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/2 "2014-03-05T17:41:59Z")

</div>

> **[Home](https://github.com/thinkaurelius/titan/wiki)**
>
> Distributed Graph Database. Contribute to thinkaurelius/titan development by creating an account on GitHub.

"Titan is a distributed graph  
database[http://en.wikipedia.org/wiki/Graph\_database](http://en.wikipedia.org/wiki/Graph_database) optimized  
for storing and querying  
graphs[http://en.wikipedia.org/wiki/Graph\_(mathematics)](http://en.wikipedia.org/wiki/Graph_(mathematics)) represented  
over a cluster of machines. The cluster can elastically scale to support a  
growing dataset and user base. Titan has a pluggable storage architecture  
which allows it to build on proven database technology such as Apache  
Cassandra [http://cassandra.apache.org/](http://cassandra.apache.org/), Apache  
HBase[http://hbase.apache.org/](http://hbase.apache.org/),  
or Oracle BerkeleyDB[http://www.oracle.com/technetwork/database/berkeleydb/](http://www.oracle.com/technetwork/database/berkeleydb/).  
Furthermore, the pluggable indexing architecture supports  
Elasticsearch[http://elasticsearch.com/](http://elasticsearch.com/)  
and Lucene [http://lucene.apache.org/](http://lucene.apache.org/)."

I did some basic research for ES + graph and found the Titan project  
interesting. Titan separates storage from indexing and only currently  
supports ES for the latter. I'm sure that you could implement a storage  
engine based on ES too (which makes more sense now that ES 1.x supports  
backup/restore). Didn't look into security at all but this might be a good  
starting point. Hope it's helpful. --Mike

On Wed, Mar 5, 2014 at 12:10 PM, Jeff Kunkle [kunklejr@gmail.com](mailto:kunklejr@gmail.com) wrote:

> I've been trying to figure out how I can index a graph data structure  
> using Elasticsearch and could really use some advice from someone more  
> knowledgeable than me. First, let me explain the challenge. The graph model  
> has individual access controls at the vertex (node), edge (relationship),  
> and property level. I'd like my users to be able to search the graph for  
> vertices or edges containing matching properties, with two caveats:
> 
> 1. They should not get vertex or edge results they don't have  
> permission to see.
> 2. Properties a user does not have access to see should not be  
> evaluated in the query.
> 
> My first thought was to index properties as either nested or child  
> documents of a vertex/edge and use a custom filter to remove properties a  
> user didn't have access to. The first problem I run into is when I try a  
> boolean query across properties. For example, assume I want to query a  
> person vertex by first name and date of birth. Since these properties are  
> indexed as separate documents there is never a match.
> 
> What I essentially need is the ability to query across nested or child  
> documents and return the parent only when there are matches across the  
> child documents. For example, assume a parent vertex with one property  
> document called "full\_name" set to Barak Obama and another property  
> document named "political\_party" set to Democrat. Is there any way for me  
> to query for the parent document of these two properties by asking for one  
> property with full\_name="Barak Obama" and another property with  
> political\_party="Democrat"?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAP8axnAv7D3Ux4jXuPiYS9ZSBGSXSxiR0Qg3C3FzcVHoRZXgiw%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAP8axnAv7D3Ux4jXuPiYS9ZSBGSXSxiR0Qg3C3FzcVHoRZXgiw%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Jeff\_Kunkle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeff_kunkle/32/1301_2.png) [@Jeff\_Kunkle](https://discuss.elastic.co/u/Jeff_Kunkle)\
**Post date:** [March 5, 2014, 6:08pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/3 "2014-03-05T18:08:34Z")

</div>

Hi Mike,

Thanks for the reply. We actually started with Titan and its a very good  
project, but we couldn't easily add the needed security constraints on top  
of it. Hence why I'm exploring this topic. It would be rather  
straightforward to implement the index on Elasticsearch if all the data was  
open to everyone. I'd be able to consolidate all of a vertex's or edge's  
properties in a single document. Unfortunately, that's not the case. The  
project I'm working on is at [http://lumify.io](http://lumify.io) if that's helpful in any way.

Thanks Again,  
Jeff

On Wednesday, March 5, 2014 12:41:59 PM UTC-5, Michael Sick wrote:

> [Home · thinkaurelius/titan Wiki · GitHub](https://github.com/thinkaurelius/titan/wiki)
> 
> "Titan is a distributed graph database[http://en.wikipedia.org/wiki/Graph\_database](http://en.wikipedia.org/wiki/Graph_database) optimized  
> for storing and querying graphs[http://en.wikipedia.org/wiki/Graph\_(mathematics)](http://en.wikipedia.org/wiki/Graph_(mathematics)) represented  
> over a cluster of machines. The cluster can elastically scale to support a  
> growing dataset and user base. Titan has a pluggable storage architecture  
> which allows it to build on proven database technology such as Apache  
> Cassandra [http://cassandra.apache.org/](http://cassandra.apache.org/), Apache HBase[http://hbase.apache.org/](http://hbase.apache.org/),  
> or Oracle BerkeleyDB[http://www.oracle.com/technetwork/database/berkeleydb/](http://www.oracle.com/technetwork/database/berkeleydb/).  
> Furthermore, the pluggable indexing architecture supports Elasticsearch[http://elasticsearch.com/](http://elasticsearch.com/)  
> and Lucene [http://lucene.apache.org/](http://lucene.apache.org/)."
> 
> I did some basic research for ES + graph and found the Titan project  
> interesting. Titan separates storage from indexing and only currently  
> supports ES for the latter. I'm sure that you could implement a storage  
> engine based on ES too (which makes more sense now that ES 1.x supports  
> backup/restore). Didn't look into security at all but this might be a good  
> starting point. Hope it's helpful. --Mike
> 
> On Wed, Mar 5, 2014 at 12:10 PM, Jeff Kunkle \<[kunk...@gmail.com](mailto:kunk...@gmail.com)\<javascript:\>
> 
> > wrote:
> 
> > I've been trying to figure out how I can index a graph data structure  
> > using Elasticsearch and could really use some advice from someone more  
> > knowledgeable than me. First, let me explain the challenge. The graph model  
> > has individual access controls at the vertex (node), edge (relationship),  
> > and property level. I'd like my users to be able to search the graph for  
> > vertices or edges containing matching properties, with two caveats:
> > 
> > 1. They should not get vertex or edge results they don't have  
> > permission to see.
> > 2. Properties a user does not have access to see should not be  
> > evaluated in the query.
> > 
> > My first thought was to index properties as either nested or child  
> > documents of a vertex/edge and use a custom filter to remove properties a  
> > user didn't have access to. The first problem I run into is when I try a  
> > boolean query across properties. For example, assume I want to query a  
> > person vertex by first name and date of birth. Since these properties are  
> > indexed as separate documents there is never a match.
> > 
> > What I essentially need is the ability to query across nested or child  
> > documents and return the parent only when there are matches across the  
> > child documents. For example, assume a parent vertex with one property  
> > document called "full\_name" set to Barak Obama and another property  
> > document named "political\_party" set to Democrat. Is there any way for me  
> > to query for the parent document of these two properties by asking for one  
> > property with full\_name="Barak Obama" and another property with  
> > political\_party="Democrat"?
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com) \<javascript:\>.  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .  
> > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![Michael\_Sick](https://avatars.discourse-cdn.com/v4/letter/m/22d042/32.png) [@Michael\_Sick](https://discuss.elastic.co/u/Michael_Sick)\
**Post date:** [March 6, 2014, 12:52am UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/4 "2014-03-06T00:52:15Z")

</div>

Hi Jeff,

Lumify looks very interesting - I'll have to take a serious look later.  
While I didn't get very far down the Titan path, my starting point would be  
to use Titan for all it's graphing features and add some type of query pre  
and post processing to insert ACL information into the ES queries and  
indexing statements. Not sure if Titan offers any hooks - but it seems it  
could be added.

I'd start with the Aurelius folks and see how something like this could be  
added with low impact to the existing interfaces. As far as the ES part, I  
have added ACL's to documents before by having the id's as an array. This  
worked in the simple case I needed because the owners of the documents  
changed infrequently (so there was not much reindexing load) and I didn't  
have to think it through more than that.

--Mike

On Wed, Mar 5, 2014 at 1:08 PM, Jeff Kunkle [kunklejr@gmail.com](mailto:kunklejr@gmail.com) wrote:

> Hi Mike,
> 
> Thanks for the reply. We actually started with Titan and its a very good  
> project, but we couldn't easily add the needed security constraints on top  
> of it. Hence why I'm exploring this topic. It would be rather  
> straightforward to implement the index on Elasticsearch if all the data was  
> open to everyone. I'd be able to consolidate all of a vertex's or edge's  
> properties in a single document. Unfortunately, that's not the case. The  
> project I'm working on is at [http://lumify.io](http://lumify.io) if that's helpful in any  
> way.
> 
> Thanks Again,  
> Jeff
> 
> On Wednesday, March 5, 2014 12:41:59 PM UTC-5, Michael Sick wrote:
> 
> > [Home · thinkaurelius/titan Wiki · GitHub](https://github.com/thinkaurelius/titan/wiki)
> > 
> > "Titan is a distributed graph database[http://en.wikipedia.org/wiki/Graph\_database](http://en.wikipedia.org/wiki/Graph_database) optimized  
> > for storing and querying graphs[http://en.wikipedia.org/wiki/Graph\_(mathematics)](http://en.wikipedia.org/wiki/Graph_(mathematics)) represented  
> > over a cluster of machines. The cluster can elastically scale to support a  
> > growing dataset and user base. Titan has a pluggable storage architecture  
> > which allows it to build on proven database technology such as Apache  
> > Cassandra [http://cassandra.apache.org/](http://cassandra.apache.org/), Apache HBase[http://hbase.apache.org/](http://hbase.apache.org/),  
> > or Oracle BerkeleyDB[http://www.oracle.com/technetwork/database/berkeleydb/](http://www.oracle.com/technetwork/database/berkeleydb/).  
> > Furthermore, the pluggable indexing architecture supports Elasticsearch[http://elasticsearch.com/](http://elasticsearch.com/)  
> > and Lucene [http://lucene.apache.org/](http://lucene.apache.org/)."
> > 
> > I did some basic research for ES + graph and found the Titan project  
> > interesting. Titan separates storage from indexing and only currently  
> > supports ES for the latter. I'm sure that you could implement a storage  
> > engine based on ES too (which makes more sense now that ES 1.x supports  
> > backup/restore). Didn't look into security at all but this might be a good  
> > starting point. Hope it's helpful. --Mike
> > 
> > On Wed, Mar 5, 2014 at 12:10 PM, Jeff Kunkle [kunk...@gmail.com](mailto:kunk...@gmail.com) wrote:
> > 
> > > I've been trying to figure out how I can index a graph data structure  
> > > using Elasticsearch and could really use some advice from someone more  
> > > knowledgeable than me. First, let me explain the challenge. The graph model  
> > > has individual access controls at the vertex (node), edge (relationship),  
> > > and property level. I'd like my users to be able to search the graph for  
> > > vertices or edges containing matching properties, with two caveats:
> > > 
> > > 1. They should not get vertex or edge results they don't have  
> > > permission to see.
> > > 2. Properties a user does not have access to see should not be  
> > > evaluated in the query.
> > > 
> > > My first thought was to index properties as either nested or child  
> > > documents of a vertex/edge and use a custom filter to remove properties a  
> > > user didn't have access to. The first problem I run into is when I try a  
> > > boolean query across properties. For example, assume I want to query a  
> > > person vertex by first name and date of birth. Since these properties are  
> > > indexed as separate documents there is never a match.
> > > 
> > > What I essentially need is the ability to query across nested or child  
> > > documents and return the parent only when there are matches across the  
> > > child documents. For example, assume a parent vertex with one property  
> > > document called "full\_name" set to Barak Obama and another property  
> > > document named "political\_party" set to Democrat. Is there any way for me  
> > > to query for the parent document of these two properties by asking for one  
> > > property with full\_name="Barak Obama" and another property with  
> > > political\_party="Democrat"?
> > > 
> > > --  
> > > You received this message because you are subscribed to the Google  
> > > Groups "elasticsearch" group.  
> > > To unsubscribe from this group and stop receiving emails from it, send  
> > > an email to [elasticsearc...@googlegroups.com](mailto:elasticsearc...@googlegroups.com).
> > > 
> > > To view this discussion on the web visit [https://groups.google.com/d/](https://groups.google.com/d/)  
> > > msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%  
> > > [40googlegroups.com](http://40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/a8beee5b-82d0-45fa-8666-31e956c03439%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > > .  
> > > For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).
> > 
> > --  
> > You received this message because you are subscribed to the Google Groups  
> > "elasticsearch" group.  
> > To unsubscribe from this group and stop receiving emails from it, send an  
> > email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> > To view this discussion on the web visit  
> > [https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com)[https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/1e8acfc2-81db-461f-817e-de1ca0b37c3e%40googlegroups.com?utm_medium=email&utm_source=footer)  
> > .
> 
> For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAP8axnAbPq\_TozXsh0b7RFe%3DEh4\_iuovLpSFuf%3DAz\_mWn1%3Dy7g%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAP8axnAbPq_TozXsh0b7RFe%3DEh4_iuovLpSFuf%3DAz_mWn1%3Dy7g%40mail.gmail.com).  
For more options, visit [https://groups.google.com/groups/opt\_out](https://groups.google.com/groups/opt_out).

---

<div class="post-metadata">

**Author:** ![mohit\_kaushik](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@mohit\_kaushik](https://discuss.elastic.co/u/mohit_kaushik)\
**Post date:** [May 16, 2014, 5:26am UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/5 "2014-05-16T05:26:28Z")

</div>

Hi! jeff  
You said, you are using lumify. And lumify user secure-graph which  
implicitly implements cell level security that you all need. You can easily  
have access controls on your user and query returns the vertices in the way  
you want. I recently started working with secure-graph and want to  
implement the class  
"/securegraph-core/src/main/java/org/securegraph/query/GraphQuery.java"  
wchich is provided in the package and as it has been much days to your post  
so hope you might have figured out it. If you have please notify me.

Thanks  
Mohit kaushik

On Wednesday, March 5, 2014 10:40:11 PM UTC+5:30, Jeff Kunkle wrote:

> I've been trying to figure out how I can index a graph data structure  
> using Elasticsearch and could really use some advice from someone more  
> knowledgeable than me. First, let me explain the challenge. The graph model  
> has individual access controls at the vertex (node), edge (relationship),  
> and property level. I'd like my users to be able to search the graph for  
> vertices or edges containing matching properties, with two caveats:
> 
> 1. They should not get vertex or edge results they don't have  
> permission to see.
> 2. Properties a user does not have access to see should not be  
> evaluated in the query.
> 
> My first thought was to index properties as either nested or child  
> documents of a vertex/edge and use a custom filter to remove properties a  
> user didn't have access to. The first problem I run into is when I try a  
> boolean query across properties. For example, assume I want to query a  
> person vertex by first name and date of birth. Since these properties are  
> indexed as separate documents there is never a match.
> 
> What I essentially need is the ability to query across nested or child  
> documents and return the parent only when there are matches across the  
> child documents. For example, assume a parent vertex with one property  
> document called "full\_name" set to Barak Obama and another property  
> document named "political\_party" set to Democrat. Is there any way for me  
> to query for the parent document of these two properties by asking for one  
> property with full\_name="Barak Obama" and another property with  
> political\_party="Democrat"?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0ff88ff7-425f-40ff-91be-826962c904aa%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0ff88ff7-425f-40ff-91be-826962c904aa%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![mohit\_kaushik](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@mohit\_kaushik](https://discuss.elastic.co/u/mohit_kaushik)\
**Post date:** [May 16, 2014, 6:05am UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/6 "2014-05-16T06:05:27Z")

</div>

And i also want to ask you, are you from altamira????? i found you on  
lumify.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/e8f576c8-5d3f-4402-915d-8d0e9eaf8c10%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/e8f576c8-5d3f-4402-915d-8d0e9eaf8c10%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Jeff\_Kunkle](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeff_kunkle/32/1301_2.png) [@Jeff\_Kunkle](https://discuss.elastic.co/u/Jeff_Kunkle)\
**Post date:** [May 16, 2014, 1:01pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/7 "2014-05-16T13:01:45Z")

</div>

Hi Mohit,

Can you please ask your Lumify questions over on the Lumify google group at  
[https://groups.google.com/d/forum/lumify](https://groups.google.com/d/forum/lumify)? I'd rather not pollute the  
Elasticsearch group with unrelated messages.

Thanks,  
Jeff

On Friday, May 16, 2014 1:26:28 AM UTC-4, mohit kaushik wrote:

> Hi! jeff  
> You said, you are using lumify. And lumify user secure-graph which  
> implicitly implements cell level security that you all need. You can easily  
> have access controls on your user and query returns the vertices in the way  
> you want. I recently started working with secure-graph and want to  
> implement the class  
> "/securegraph-core/src/main/java/org/securegraph/query/GraphQuery.java"  
> wchich is provided in the package and as it has been much days to your post  
> so hope you might have figured out it. If you have please notify me.
> 
> Thanks  
> Mohit kaushik
> 
> On Wednesday, March 5, 2014 10:40:11 PM UTC+5:30, Jeff Kunkle wrote:
> 
> > I've been trying to figure out how I can index a graph data structure  
> > using Elasticsearch and could really use some advice from someone more  
> > knowledgeable than me. First, let me explain the challenge. The graph model  
> > has individual access controls at the vertex (node), edge (relationship),  
> > and property level. I'd like my users to be able to search the graph for  
> > vertices or edges containing matching properties, with two caveats:
> > 
> > 1. They should not get vertex or edge results they don't have  
> > permission to see.
> > 2. Properties a user does not have access to see should not be  
> > evaluated in the query.
> > 
> > My first thought was to index properties as either nested or child  
> > documents of a vertex/edge and use a custom filter to remove properties a  
> > user didn't have access to. The first problem I run into is when I try a  
> > boolean query across properties. For example, assume I want to query a  
> > person vertex by first name and date of birth. Since these properties are  
> > indexed as separate documents there is never a match.
> > 
> > What I essentially need is the ability to query across nested or child  
> > documents and return the parent only when there are matches across the  
> > child documents. For example, assume a parent vertex with one property  
> > document called "full\_name" set to Barak Obama and another property  
> > document named "political\_party" set to Democrat. Is there any way for me  
> > to query for the parent document of these two properties by asking for one  
> > property with full\_name="Barak Obama" and another property with  
> > political\_party="Democrat"?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3527e622-cba3-4e5e-8ed3-49df8acf53b8%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3527e622-cba3-4e5e-8ed3-49df8acf53b8%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![mohit\_kaushik](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@mohit\_kaushik](https://discuss.elastic.co/u/mohit_kaushik)\
**Post date:** [May 22, 2014, 4:59am UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/8 "2014-05-22T04:59:56Z")

</div>

ok thanks.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/5a316c9c-f519-4f7b-8574-ee3131e101c6%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/5a316c9c-f519-4f7b-8574-ee3131e101c6%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![justin\_hohner](https://avatars.discourse-cdn.com/v4/letter/j/c4cdca/32.png) [@justin\_hohner](https://discuss.elastic.co/u/justin_hohner)\
**Post date:** [June 30, 2014, 12:52pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/9 "2014-06-30T12:52:10Z")

</div>

Have you figured out a solution to this problem yet? This may be what  
Michael suggested but you might be able to apply the group permissions to  
the document. For example create a structure like:  
visibility: { groups: ["groupA", "group1"], exclude: ["groupB", "group2"]}

You could then apply the group visibility to the query.

It's not a perfect solutions, but I am curious if it would work and what  
sort of impact to expect if it was used.

On Wednesday, March 5, 2014 11:10:11 AM UTC-6, Jeff Kunkle wrote:

> I've been trying to figure out how I can index a graph data structure  
> using Elasticsearch and could really use some advice from someone more  
> knowledgeable than me. First, let me explain the challenge. The graph model  
> has individual access controls at the vertex (node), edge (relationship),  
> and property level. I'd like my users to be able to search the graph for  
> vertices or edges containing matching properties, with two caveats:
> 
> 1. They should not get vertex or edge results they don't have  
> permission to see.
> 2. Properties a user does not have access to see should not be  
> evaluated in the query.
> 
> My first thought was to index properties as either nested or child  
> documents of a vertex/edge and use a custom filter to remove properties a  
> user didn't have access to. The first problem I run into is when I try a  
> boolean query across properties. For example, assume I want to query a  
> person vertex by first name and date of birth. Since these properties are  
> indexed as separate documents there is never a match.
> 
> What I essentially need is the ability to query across nested or child  
> documents and return the parent only when there are matches across the  
> child documents. For example, assume a parent vertex with one property  
> document called "full\_name" set to Barak Obama and another property  
> document named "political\_party" set to Democrat. Is there any way for me  
> to query for the parent document of these two properties by asking for one  
> property with full\_name="Barak Obama" and another property with  
> political\_party="Democrat"?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/c2933a14-9882-4d6c-a6cc-5725160e1551%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/c2933a14-9882-4d6c-a6cc-5725160e1551%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Joe\_Ferner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_ferner/32/1447_2.png) [@Joe\_Ferner](https://discuss.elastic.co/u/Joe_Ferner)\
**Post date:** [June 30, 2014, 6:44pm UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/10 "2014-06-30T18:44:21Z")

</div>

I've been working with Jeff on this and I think we have figured out a  
solution.  
([https://github.com/altamiracorp/securegraph/tree/master/securegraph-elasticsearch-plugin](https://github.com/altamiracorp/securegraph/tree/master/securegraph-elasticsearch-plugin))

By using parent/child documents and a custom filter we were able to query  
documents with security. Each child document has a visibility string field  
along with "fieldName" field. The filter then filters child documents that  
do not have the proper authorizations supplied in the filter. This then  
causes the parent document to not return if no children are found.

On Monday, June 30, 2014 8:52:10 AM UTC-4, [justin...@gmail.com](mailto:justin...@gmail.com) wrote:

> Have you figured out a solution to this problem yet? This may be what  
> Michael suggested but you might be able to apply the group permissions to  
> the document. For example create a structure like:  
> visibility: { groups: ["groupA", "group1"], exclude: ["groupB", "group2"]}
> 
> You could then apply the group visibility to the query.
> 
> It's not a perfect solutions, but I am curious if it would work and what  
> sort of impact to expect if it was used.
> 
> On Wednesday, March 5, 2014 11:10:11 AM UTC-6, Jeff Kunkle wrote:
> 
> > I've been trying to figure out how I can index a graph data structure  
> > using Elasticsearch and could really use some advice from someone more  
> > knowledgeable than me. First, let me explain the challenge. The graph model  
> > has individual access controls at the vertex (node), edge (relationship),  
> > and property level. I'd like my users to be able to search the graph for  
> > vertices or edges containing matching properties, with two caveats:
> > 
> > 1. They should not get vertex or edge results they don't have  
> > permission to see.
> > 2. Properties a user does not have access to see should not be  
> > evaluated in the query.
> > 
> > My first thought was to index properties as either nested or child  
> > documents of a vertex/edge and use a custom filter to remove properties a  
> > user didn't have access to. The first problem I run into is when I try a  
> > boolean query across properties. For example, assume I want to query a  
> > person vertex by first name and date of birth. Since these properties are  
> > indexed as separate documents there is never a match.
> > 
> > What I essentially need is the ability to query across nested or child  
> > documents and return the parent only when there are matches across the  
> > child documents. For example, assume a parent vertex with one property  
> > document called "full\_name" set to Barak Obama and another property  
> > document named "political\_party" set to Democrat. Is there any way for me  
> > to query for the parent document of these two properties by asking for one  
> > property with full\_name="Barak Obama" and another property with  
> > political\_party="Democrat"?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/0ed5af3c-a599-42f4-996e-f0db41d6869a%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/0ed5af3c-a599-42f4-996e-f0db41d6869a%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:18am UTC](https://discuss.elastic.co/t/advice-for-implementing-a-secure-graph-index-with-elasticsearch/16176/11 "2017-07-06T01:18:50Z")

</div>


