IP Library Granted Patent US 9,614,826
Granted Patent B1
US 9,614,826 · App. 14/282,856 · Granted Apr 4, 2017

Sensitive data protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,614,826
App. No.
14/282,856
Granted
Apr 4, 2017
Kind
B1
Abstract

A computer-implemented method for protecting sensitive data is described. In one embodiment, the method includes identifying data stored at a first storage system. The identified data is classified as sensitive data. The method includes copying at least a portion of the identified sensitive data from the first storage system, transferring the copied portion of the identified sensitive data from the first storage system to a file stored at a second storage system, and storing a virtual symbolic link at the first storage system. The virtual symbolic link includes information regarding the file stored at the second storage system.

Claims (50)

1. A computer-implemented method for protecting sensitive data, comprising:

identifying data within a first file stored at a first storage system, a portion of the identified data being classified as sensitive data and being configured in an original file format;

copying the portion of the identified data classified as sensitive data from the first storage system;

transferring the copied portion of the identified data from the first storage system to a second file stored at a second storage system;

deleting the copied portion of the identified data from within the first file stored at the first storage system; and

replacing the deleted portion with a virtual symbolic link within the first file stored at the first storage system, the virtual symbolic link being configured in a proprietary file format and comprising an active link to the second file stored at the second storage system, wherein selecting the active link provides access to the second file stored at the second storage system.

2. The method of claim 1 , further comprising:

acquiring credentials to one or more cloud storage systems, the first storage system being among the one or more cloud storage systems; and

using the acquired credentials in conjunction with a public application programming interface (API) from the one or more cloud storage systems to access content on the one or more cloud storage systems.

3. The method of claim 2 , further comprising:

scanning the content on the one or more cloud storage systems to identify files containing sensitive data.

4. The method of claim 2 , further comprising:

upon accessing the content from each of the one or more cloud storage systems, displaying an aggregated view of the accessed content.

5. The method of claim 2 , further comprising:

periodically scanning the content on the one or more cloud storage systems to identify new sensitive data.

6. The method of claim 2 , further comprising:

detecting, via a notification callback API, creation of new data at one of the one or more cloud storage systems; and

detecting sensitive data in the new data.

7. The method of claim 1 , further comprising:

registering an application as a handler of the proprietary file format.

8. A computing device configured for protecting sensitive data, comprising:

a processor;

memory in electronic communication with the processor;

instructions stored in the memory, the instructions being executable by the processor to:

identify data within a first file stored at a first storage system, a portion of the identified data being classified as sensitive data and being configured in an original file format;

copy the portion of the identified data classified as sensitive data from the first storage system;

transfer the copied portion of the identified data from the first storage system to a second file stored at a second storage system;

delete the copied portion of the identified data from within the first file stored at the first storage system; and

replace the deleted portion with a virtual symbolic link within the first file stored at the first storage system, the virtual symbolic link being configured in a proprietary file format and comprising an active link to the second file stored at the second storage system, wherein selecting the active link provides access to the second file stored at the second storage system.

9. The computing device of claim 8 , wherein the instructions are executable by the processor to:

acquire credentials to one or more cloud storage systems; and

use the acquired credentials in conjunction with a public application programming interface (API) from the one or more cloud storage systems to access content on the one or more cloud storage systems.

10. The computing device of claim 9 , wherein the instructions are executable by the processor to:

scan the content on the one or more cloud storage systems to identify files containing sensitive data.

11. The computing device of claim 9 , wherein the instructions are executable by the processor to:

upon accessing the content from each of the one or more cloud storage systems, display an aggregated view of the accessed content.

12. The computing device of claim 9 , wherein the instructions are executable by the processor to:

periodically scan the content on the one or more cloud storage systems to identify new sensitive data.

13. The computing device of claim 9 , wherein the instructions are executable by the processor to:

detect, via a notification callback API, creation of new data at one of the one or more cloud storage systems; and

detect sensitive data in the new data.

14. A computer-program product for protecting sensitive data, by a processor, the computer-program product comprising a non-transitory computer-readable medium storing instructions thereon, the instructions being executable by the processor to:

identify data within a first file stored at a first storage system, a portion of the identified data being classified as sensitive data and being configured in an original file format;

copy the portion of the identified data classified as sensitive data from the first storage system;

transfer the copied portion of the identified data from the first storage system to a second file stored at a second storage system;

delete the copied portion of the identified data from within the first file stored at the first storage system; and

replace the deleted portion with a virtual symbolic link within the first file stored at the first storage system, the virtual symbolic link being configured in a proprietary file format and comprising an active link to the second file stored at the second storage system, wherein selecting the active link provides access to the second file stored at the second storage system.

15. The computer-program product of claim 14 , wherein the instructions are executable by the processor to:

acquire credentials to one or more cloud storage systems; and

use the acquired credentials in conjunction with a public application programming interface (API) from the one or more cloud storage systems to access content on the one or more cloud storage systems.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jan 30, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051759/0845 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2014
From: MCCORKENDALE, BRUCE
To: SYMANTEC CORPORATION
Reel/Frame 032934/0770 →