IP Library Granted Patent US 12682097
Granted Patent B2
US 12682097 · App. 18/426,638 · Granted Jul 14, 2026

API model for as-a-service data resilience management

Inventors: Mladen Brajković (Ljubljana, SI); Antal Nemeš (Ljubljana, SI); Subbiah Sundaram (Boston, MA)
Assignee: HYCU, INC.
G06F21/6218G06F11/1448
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12682097
App. No.
18/426,638
Granted
Jul 14, 2026
Kind
B2
Abstract

A platform we call an R-Cloud Data Protection Platform supports the ability to recover anything “as-a-Service” at a specified level of granularity. The approach splits data catalog information between the R-Cloud platform and R-Cloud Modules. It provides the ability to describe every as-a-Service related configuration and data hierarchy, their attributes, associations, relevance to data resilience and the associated methods required to protect and recover the different parts of the service and data. This enables the unique approach to cover all as-a-Service, from the simple ones like Google CloudSQL to the most complex ones having millions of dynamic and unstructured objects within.

Claims (47)

1 . A method for automatic data protection for one or more resources provided by a service, wherein the service operates in a computing environment that deploys one or more access points to which Application Programming Interface (API)-based requests are directed, and wherein the service resources relate to data objects arranged at one or more levels of a hierarchy, the method comprising:

responsive to receipt of an API request for data protection,

discovering data objects accessed by the service resource, by operating a selected one of plurality of modules, each module corresponding to one of a plurality of different services, and each module executing at least some requests that are specific to the service resource,

discovering attributes specific to the data objects, including a data protection attribute that indicates whether a data protection method is accessible to protect the data objects via the service resource at one or more levels of a hierarchy;

obtaining information for use with another data protection method that is other than via the service resource;

storing, in a centralized catalog, information that describes a data protection workflow for the service, including whether the data protection method is provided by the service or whether it is an other data protection method external to the service;

and executing a granular data protection process, by accessing the centralized catalog to determine data protection attribute information for each data object, and

when the data protection attribute is true,

invoking the data protection method accessible via the service resource;

else when the data protection attribute is false,

invoking the other data protection method.

2 . The method of claim 1 wherein discovering attributes further comprises determining a workflow for invoking a data protection method that is other than via the service resource.

3 . The method of claim 1 wherein the step of discovering attributes is implemented in a plug-in operating within the service.

4 . The method of claim 1 wherein the step of executing the granular data protection process is implemented on a data processing platform outside of the service resource.

5 . The method of claim 1 wherein the service is a SaaS, PaaS, DBaaS, or IaaS.

6 . The method of claim 1 wherein the data protection attribute indicates whether the service provides backup for the data object.

7 . The method of claim 1 wherein the data protection attribute indicates whether the service provides recovery of the data object.

8 . An apparatus comprising:

a hardware processor; and

computer memory holding computer program instructions executed by the hardware processor for access control in a computing environment in which clients interact with an application deploying one or more access points to which application programming interface (API)-based requests are directed, the computer program instructions configured for:

responsive to receipt of an API request for data protection,

discovering data objects accessed by the service resource, by operating a selected one of plurality of modules, each module corresponding to one of a plurality of different services, and each module executing at least some requests that are specific to the service resource;

discovering attributes specific to the data objects, including a data protection attribute that indicates whether a data protection method is accessible to protect the data objects via the service resource at one or more levels of a hierarchy;

obtaining information for use with another data protection method that is other than via the service resource;

storing, in a centralized catalog, information that describes a data protection workflow for the service, including whether the data protection method is provided by the service or whether it is an other data protection method external to the service;

and executing a granular data protection process, by accessing the centralized catalog to determine data protection attribute information for each data object, and

when the data protection attribute is true,

invoking the data protection method accessible via the service resource;

else when the data protection attribute is false,

invoking the other data protection method.

9 . The apparatus of claim 8 wherein discovering attributes further comprises determining a workflow for invoking a data protection method that is other than via the service resource.

10 . The apparatus of claim 8 wherein the step of discovering attributes is implemented in a plug-in operating within the service.

11 . The apparatus of claim 8 wherein the step of executing the granular data protection process is implemented on a data processing platform outside of the service resource.

12 . The apparatus of claim 8 wherein the service is a SaaS, PaaS, DBaaS, or IaaS.

13 . The apparatus of claim 8 wherein the data protection attribute indicates whether the service provides backup for the data object.

14 . The apparatus of claim 8 wherein the data protection attribute indicates whether the service provides recovery of the data object.

15 . A computer program product in a non-transitory computer readable medium for access control in a computing environment in which clients interact with an application deploying one or more access points to which application programming interface (API)-based requests are directed, the computer program product holding computer program instructions that, when executed by a data processing system, is configured to:

responsive to receipt of an API request for data protection,

discovering data objects accessed by the service resource, by operating a selected one of plurality of modules, each module corresponding to one of a plurality of different services, and each module executing at least some requests that are specific to the service resource;

discovering attributes specific to the data objects, including a data protection attribute that indicates whether a data protection method is accessible to protect the data objects via the service resource at one or more levels of a hierarchy;

obtaining information for use with another data protection method that is other than via the service resource;

storing, in a centralized catalog, information that describes a data protection workflow for the service, including whether the data protection method is provided by the service or whether it is an other data protection method external to the service;

and executing a granular data protection process, by accessing the centralized catalog to determine data protection attribute information for each data object, and

when the data protection attribute is true,

invoking the data protection method accessible via the service resource;

else when the data protection attribute is false,

invoking the other data protection method.