IP Library Granted Patent US 10,412,102
Granted Patent B1
US 10,412,102 · App. 15/372,643 · Granted Sep 10, 2019

Cloud based data loss prevention system using graphical processing units for index filtering

Inventors: Vitali Fridman (Redwood City, CA); Sekhar Sarukkai (Cupertino, CA); Snehal Chennuru (Sunnyvale, CA)
Assignee: Skyhigh Networks, LLC
H04L63/1416G06F16/901G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,412,102
App. No.
15/372,643
Granted
Sep 10, 2019
Kind
B1
Abstract

A system for providing data loss prevention services includes an indexer system configured to generate a search index based on structured data to be protected and a detection system configured to receive the search index and network data content and to detect in the network data content for matching data based on the search index. The detection system includes a first processor and multiple graphical processing units. The first processor provides words from the network data content in parallel to each of the graphical processing units, each graphical processing unit receiving a different word from the network data content. The graphical processing units perform detection of the words in parallel to detect for matched data content in at least a portion of the search index.

Claims (29)

1. A system for providing data loss prevention services to an enterprise operating an enterprise data network, the system comprising:

a first hardware processor and a plurality of graphical processing units, wherein the first hardware processor is configured to:

receive, from a remote storage site, a search index based on structured data to be protected, wherein the search index is based on hash values of the structured data to be protected, wherein the structured data to be protected is encoded with a forward hash function based on a key;

receive network data content belonging to the enterprise;

apply the forward hash function based on the key to the network data content;

generate a sub-index from the search index, the sub-index being a portion of the search index;

apply a Bloom filter to the sub-index;

detect in the network data content matching data using the Bloom filter applied to the sub-index;

generate an alert in response to matched data being found in the network data content;

load the sub-index into each of the plurality of graphical processing units; and

provide hash values of words from the network data content in parallel to each of the plurality of graphical processing units, each graphical processing unit receiving a different word from the network data content,

wherein each of the plurality of graphical processing units are configure to receive a hash value of a different word from the network data content, and wherein the plurality of graphical processing units are configured to perform detection of the words in parallel to detect for matched data content in the sub-index.

2. The system of claim 1 , further comprising a plurality of memory units, each memory unit being coupled to a respective graphical processing unit, wherein the first processor is configured to load the sub-index into the plurality of memory units associated with the plurality of graphical processing units.

3. The system of claim 1 , wherein the first hardware processor is further configured to apply remediation measures in response to matched data content being found in the network data content.

4. A method for providing data loss prevention services to an enterprise operating an enterprise data network, the method comprising:

generating, using a hardware processor, a search index based on hash values of structured data to be protected;

receiving, from a remote storage site, a search index based on the structured data to be protected, wherein the structured data to be protected is encoded using a forward hash function based on a key;

receiving, at a hardware processor, network data content belonging to the enterprise;

applying, at the hardware processor, the forward hash function based on the key to the network data content;

generating, at the hardware processor, a sub-index from the search index, the sub-index being a portion of the search index;

applying, at the hardware processor, a Bloom filter to the sub-index;

loading the sub-index with the Bloom filter applied into a plurality of graphical processing units;

providing hash values of words from the network data content in parallel to each of the plurality of graphical processing units, each graphical processing unit receiving a hash value of a different word from the network data content;

detecting, at the plurality of graphical processing units, words in parallel for matched data content using the Bloom filter applied to the sub-index; and

generating, at the hardware processor, an alert in response to matched data content being found in the network data content.

5. The method of claim 4 , further comprising:

detecting, at the plurality of graphical processing units, hash values of words in parallel for matched data content using the Bloom filter applied to the sub-index; and

generating an alert in response to matched data content being found in the hash values of the network data content.

6. The method of claim 4 , wherein detecting, at the plurality of graphical processing units, words in parallel for matched data content using the Bloom filter applied to the sub-index comprises detecting, using the plurality of graphical processing units, the words from the network data content in parallel for matched data content using the Bloom filter applied to the sub-index.

Assignments (15)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 049153/0364 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2017
From: FRIDMAN, VITALI; SARUKKAI, SEKHAR; CHENNURU, SNEHAL
To: SKYHIGH NETWORKS, INC.
Reel/Frame 041218/0288 →
Continuity (1)
Provisional Application 62268821 · Dec 17, 2015
Cited By (1)
US 12,493,712