Blockchain technology for regulatory compliance of data management systems
One example method includes performing a data management transaction, such as a data read operation, a data write operation, or a data delete operation, generating transaction metadata relating to the data management transaction, transmitting the transaction metadata to a blockchain network, and receiving, from the blockchain network, confirmation that the transaction metadata has been stored in a distributed ledger associated with the blockchain network.
1 . A method, comprising:
receiving, at a blockchain network from an auditor, a first request for read access to a ledger of the blockchain network, the blockchain network comprising a plurality of nodes each associated with a respective data backup system, data storage system, or data management system of an enterprise;
authenticating and, upon successful authentication, authorizing, by the blockchain network, the auditor to access the ledger;
transmitting, by the blockchain network to the auditor, an indication that the first request for read access to the ledger has been granted;
performing, at one of the plurality of nodes, a data management transaction at the respective data backup system, data storage system, or data management system;
automatically generating, in response to performance of the data management transaction, transaction metadata representing the data management transaction;
registering the transaction metadata as a block in the ledger of the blockchain network;
in a configuration that the auditor is located externally to the blockchain network, receiving, by the blockchain network from the auditor, a second request for read access to specific ledger records stored in the ledger, wherein the second request includes a basis specifying the specific ledger records based on at least one of a defined time period, a specified data management event type, or a specified data entity;
transmitting, by the blockchain network to the auditor, a confirmation that the second request for read access to the specific ledger records is granted; and
granting, by the blockchain network, access to the auditor so that the auditor is able to access the specific ledger records stored in the ledger in response to the confirmation,
wherein the second request for access to the specific ledger records relates to a data management transaction that has occurred among entities of the blockchain network.
2 . The method as recited in claim 1 , wherein the auditor comprises an audit application.
3 . The method as recited in claim 1 , wherein the auditor is external to an entity that hosts the blockchain network.
4 . The method as recited in claim 1 , wherein the auditor is not permitted to modify the specific ledger records.
5 . The method as recited in claim 1 , wherein the data management transaction comprises a write operation, or a delete operation.
6 . The method as recited in claim 1 , wherein data involved in the data management transaction comprises personal data, or financial data.
7 . The method as recited in claim 1 , wherein a data backup system, a data storage system, and a data management system, each comprise a respective node of the blockchain network.
8 . The method as recited in claim 1 , wherein the specific ledger records are within a defined time period.
9 . The method as recited in claim 1 , wherein the specific ledger records relate to specific data management events.
10 . The method as recited in claim 1 , wherein the specific ledger records are for specific data entities.
11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:
receiving, at a blockchain network from an auditor, a first request for read access to a ledger of the blockchain network, the blockchain network comprising a plurality of nodes each associated with a respective data backup system, data storage system, or data management system of an enterprise;
authenticating and, upon successful authentication, authorizing, by the blockchain network, the auditor to access the ledger;
transmitting, by the blockchain network to the auditor, an indication that the first request for read access to the ledger has been granted;
performing, at one of the plurality of nodes, a data management transaction at the respective data backup system, data storage system, or data management system;
automatically generating, in response to performance of the data management transaction, transaction metadata representing the data management transaction;
registering the transaction metadata as a block in the ledger of the blockchain network;
in a configuration that the auditor is located externally to the blockchain network, receiving, by the blockchain network from the auditor, a second request for read access to specific ledger records stored in the ledger, wherein the second request includes a basis specifying the specific ledger records based on at least one of a defined time period, a specified data management event type, or a specified data entity;
transmitting, by the blockchain network to the auditor, a confirmation that the second request for read access to the specific ledger records is granted; and
granting, by the blockchain network, access to the auditor so that the auditor is able to access the specific ledger records stored in the ledger in response to the confirmation,
wherein the second request for access to the specific ledger records relates to a data management transaction that has occurred among entities of the blockchain network.
12 . The non-transitory storage medium as recited in claim 11 , wherein the auditor comprises an audit application.
13 . The non-transitory storage medium as recited in claim 11 , wherein the auditor is external to an entity that hosts the blockchain network.
14 . The non-transitory storage medium as recited in claim 11 , wherein the auditor is not permitted to modify the specific ledger records.
15 . The non-transitory storage medium as recited in claim 11 , wherein a data backup system, a data storage system, and a data management system, each comprise a respective node of the blockchain network.
16 . The non-transitory storage medium as recited in claim 11 , wherein the data management transaction comprises a write operation, or a delete operation.
17 . The non-transitory storage medium as recited in claim 11 , wherein data involved in the data management transaction comprises personal data, or financial data.
18 . A system, comprising:
one or more hardware processors; and
a non-transitory storage medium having stored therein instructions that are executable by the one or more hardware processors to perform operations comprising:
receiving, at a blockchain network from an auditor, a first request for read access to a ledger of the blockchain network, the blockchain network comprising a plurality of nodes each associated with a respective data backup system, data storage system, or data management system of an enterprise;
authenticating and, upon successful authentication, authorizing, by the blockchain network, the auditor to access the ledger;
transmitting, by the blockchain network to the auditor, an indication that the first request for read access to the ledger has been granted;
performing, at one of the plurality of nodes, a data management transaction at the respective data backup system, data storage system, or data management system;
automatically generating, in response to performance of the data management transaction, transaction metadata representing the data management transaction;
registering the transaction metadata as a block in the ledger of the blockchain network;
in a configuration that the auditor is located externally to the blockchain network, receiving, by the blockchain network from the auditor, a second request for read access to specific ledger records stored in the ledger, wherein the second request includes a basis specifying the specific ledger records based on at least one of a defined time period, a specified data management event type, or a specified data entity;
transmitting, by the blockchain network to the auditor, a confirmation that the second request for read access to the specific ledger records is granted; and
granting, by the blockchain network, access to the auditor so that the auditor is able to access the specific ledger records stored in the ledger in response to the confirmation,
wherein the second request for access to the specific ledger records relates to a data management transaction that has occurred among entities of the blockchain network.
19 . The system as recited in claim 18 , wherein a data backup system, a data storage system, and a data management system, each comprise a respective node of the blockchain network.
20 . The system as recited in claim 18 , wherein data involved in the data management transaction comprises personal data, or financial data.