IP Library Granted Patent US 9,811,669
Granted Patent B1
US 9,811,669 · App. 14/144,635 · Granted Nov 7, 2017

Method and apparatus for privacy audit support via provenance-aware systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,811,669
App. No.
14/144,635
Granted
Nov 7, 2017
Kind
B1
Abstract

Example embodiments of the present invention relate to a method, an apparatus, and a computer program product for privacy audit support via provenance-aware systems. The method includes associating a first identifier with a first data object and associating a second identifier with a second data object derived from the first data object according to a control object. Metadata for the second data object identifying the first data object and identifying the control object then may be stored.

Claims (66)

1. A computer-implemented method comprising:

associating a first identifier with a first data object in an object addressable storage (OAS) datastore, wherein the first data object includes consumer data;

associating a second identifier with a second data object in the OAS datastore, the second data object derived from the first data object according to a control object in the OAS datastore, wherein the second data object is an anonymized data object, and the control object is a terms of use object;

storing metadata in the OAS datastore for the second data object, wherein the metadata includes one or more content addresses for identifying the first data object and identifying the control object according to which the second data object was derived from the first data object;

creating a lineage map based on the stored metadata;

wherein the second data object is derived from the first data object by a translator object; and further comprising:

storing metadata for the second data object identifying the translator object.

2. The method of claim 1 further comprising storing metadata for one or more of the control object and the translator object identifying one or more of the first data object and the second data object.

3. The method of claim 1 further comprising, for a plurality of second data objects, performing data analytics on the plurality of second data objects.

4. The method of claim 1 further comprising auditing compliance of the second data object with a control object identified in metadata for the second data object.

5. A method comprising:

receiving metadata from an object addressable storage (OAS) datastore for a second data object, the second data object having an associated first data object, wherein the data objects are stored in the OAS datastore as pairs according to respective control objects according to which each derived data object is derived from its respective first data object, wherein the first data object includes consumer data, and wherein the second data object is an anonymized data object, and the control object is a terms of use object;

determining whether the second data object was derived from the first data object according to the control object; and

auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived from the first data object according to the control object;

wherein auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived according to the control object from the first data object comprises:

iterating over a plurality of second data objects, wherein the first data object determined in a previous iteration is used as the second data object in a subsequent iteration; and

building a map of respective first data object and second data object pairs.

6. The method of claim 5 wherein auditing compliance of the first data object, the second data object, and the control object associated with the second data object to determine a lineage of the second data object as being derived according to the control object from the first data object further comprises auditing the control object according to the first data object and the second data object.

7. The method of claim 5 :

wherein the second data object has an associated translator object; and

wherein auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived according to the control object from the first data object associated with the second data object further comprises auditing the translator object according to the first data object and the second data object.

8. A system comprising:

an OAS datastore;

one or more processors; and

memory storing computer executable code that when executed on the one or more processors performs the operations of:

associating a first identifier with a first data object in the OAS datastore, wherein the first data object includes consumer data;

associating a second identifier with a second data object in the OAS datastore, the second data object derived from the first data object according to a control object in the OAS datastore, wherein the second data object is an anonymized data object, and the control object is a terms of use object;

storing metadata in the OAS datastore for the second data object, wherein the metadata includes one or more content addresses for identifying the first data object and identifying the control object according to which the second data object was derived from the first data object; and

creating a lineage map based on the stored metadata;

wherein the second data object is derived from the first data object by a translator object; and

wherein the memory further stores computer executable code that when executed on the one or more processors performs the operation of storing metadata for the second data object identifying the translator object.

9. The system of claim 8 wherein the memory further stores computer executable code that when executed on the one or more processors performs the operation of storing metadata for one or more of the control object and the translator object identifying one or more of the first data object and the second data object.

10. The system of claim 8 wherein the memory further stores computer executable code that when executed on the one or more processors performs, for a plurality of second data objects, data analytics on the plurality of second data objects.

11. The system of claim 8 wherein the memory further stores computer executable code that when executed on the one or more processors performs the operation of auditing compliance of the second data object with a control object identified in metadata for the second data object.

12. A system comprising:

an object addressable storage (OAS) datastore;

one or more processors; and

memory storing computer executable code that when executed on the one or more processors performs the operations of:

receiving metadata from the OAS datastore for a second data object, the second data object having an associated first data object, wherein the data objects are stored in the OAS datastore as pairs according to respective control objects according to which the derived data object is derived from its respective first data object, wherein the first data object includes consumer data, and wherein the second data object is an anonymized data object, and the control object is a terms of use object;

determining whether the second data object was derived from the first data object according to the control object; and

auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived from the first data object according to the control object;

wherein auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived according to the control object from the first data object comprises:

iterating over a plurality of second data objects, wherein the first data object determined in a previous iteration is used as the second data object in a subsequent iteration; and

building a map of respective first data object and second data object pairs.

13. The system of claim 12 wherein auditing compliance of the first data object, the second data object, and the control object associated with the second data object to determine a lineage of the second data object as being derived according to the control object from the first data object further comprises auditing the control object according to the first data object and the second data object.

14. The system of claim 12 :

wherein the second data object has an associated translator object; and

wherein auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived according to the control object from the first data object associated with the second data object further comprises auditing the translator object according to the first data object and the second data object.

15. A non-transitory computer readable storage medium including computer program code stored thereon that, when executed on a processor of a computer, causes the computer to provide privacy audit support, the computer program product comprising:

computer program code for associating a first identifier with a first data object in an object addressable storage (OAS) datastore, wherein the first data object includes consumer data;

computer program code for associating a second identifier with a second data object in the OAS datastore, the second data object derived from the first data object according to a control object in the OAS datastore, wherein the second data object is an anonymized data object, and the control object is a terms of use object;

computer program code for storing metadata in the OAS datastore for the second data object, wherein the metadata include one or more content addresses for identifying the first data object and identifying the control object according to which the second data object was derived from the first data object;

computer program code for creating a lineage map based on the stored metadata;

wherein the second data object is derived from the first data object by a translator object; and further comprising:

computer program code for storing metadata for the second data object identifying the translator object.

16. The non-transitory computer readable storage medium of claim 15 further comprising computer program code for storing metadata for one or more of the control object and the translator object identifying one or more of the first data object and the second data object.

17. The non-transitory computer readable storage medium of claim 15 further comprising computer program code for auditing compliance of the second data object with a control object identified in metadata for the second data object.

18. A non-transitory computer readable storage medium including computer program code stored thereon that, when executed on a processor of a computer, causes the computer to provide privacy audit support, the computer program product comprising:

computer program code for determining whether a second data object in an object addressable storage (OAS) datastore, having an associated first data object in the OAS datastore and an associated control object in the OAS datastore, was derived from the first data object according to the control object, and first data object stored in the OAS datastore, wherein the first data object includes consumer data, and wherein the second data object is an anonymized data object, and the control object includes a terms of use object;

computer program code for auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived from the first data object according to the control object;

computer program code for iterating over a plurality of second data objects, wherein the first data object determined in a previous iteration is used as the second data object in a subsequent iteration; and

computer program code for building a map of respective first data object and second data object pairs.

19. The non-transitory computer readable storage medium of claim 18 wherein auditing compliance of the first data object, the second data object, and the control object associated with the second data object to determine a lineage of the second data object as being derived according to the control object from the first data object comprises auditing the control object according to the first data object and the second data object.

20. The non-transitory computer readable storage medium of claim 18 :

wherein the second data object has an associated translator object; and

wherein auditing compliance of the first data object, the second data object, and the control object to determine a lineage of the second data object as being derived according to the control object from the first data object associated with the second data object comprises auditing the translator object according to the first data object and the second data object.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2017
From: TODD, STEPHEN J.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 043529/0978 →