IP Library Granted Patent US 10,572,453
Granted Patent B2
US 10,572,453 · App. 15/881,028 · Granted Feb 25, 2020

Virtual private cloud that provides enterprise grade functionality and compliance

Inventors: Ondrej Hrebicek (San Carlos, CA); Leonard Chung (San Francisco, CA)
Assignee: EMC IP Holding Company LLC
G06F16/178G06F16/122G06F16/125G06F16/162G06F16/1734G06F16/21G06F21/6218H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,572,453
App. No.
15/881,028
Granted
Feb 25, 2020
Kind
B2
Abstract

Techniques to enforce policies with respect to managed files and/or endpoints are disclosed. A policy to be applied with respect to one or more files included in a synchronization set and/or an endpoint associated with the synchronization set is received. Compliance with the policy is ensured across a plurality of heterogeneous endpoints associated with the synchronization set.

Claims (46)

1. A method of managing files, comprising:

obtaining, by one or more processors associated with a file management system that is connected to a plurality of endpoints via a network, a policy to be applied with respect to a synchronization set, wherein the plurality of endpoints are associated with the synchronization set and a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein at least two of the plurality of endpoints have different types of native file stores; and

providing, by one or more processors associated with the file management system, the policy to at least a first one of the plurality of endpoints, wherein the first one of the plurality of endpoints enforces the policy in response to determining that a policy triggering event associated with one or more files in the synchronization set occurred.

2. The method of claim 1 , further comprising:

obtaining, by the one or more processors associated with the file management system, an indication of the policy triggering event; and

synchronizing, by the one or more processors associated with the file management system, the one or more files in the synchronization set across at least a second one of the plurality of endpoints, wherein the one or more files in the synchronization set is synchronized based at least in part on the policy triggering event, and wherein one or more files in the synchronization set is synchronized in a manner based at least in part on a type of the native file store of the at least the second one of the plurality of endpoints.

3. The method of claim 1 , wherein one or more files in the synchronization set is synchronized in a manner based at least in part on a capability of the at least the second one of the plurality of endpoints.

4. The method of claim 1 , wherein the policy triggering event includes a request to access, create, change, or delete a file to which the policy applies.

5. The method of claim 1 , wherein the policy restricts access to a file from one or more of the endpoints.

6. The method of claim 1 , wherein enforcing the policy includes preventing access to the file by the one or more endpoints at which access is restricted.

7. The method of claim 1 , wherein each of the plurality of endpoints is configured to enforce at the endpoint policies received from the file management system, including by responding in a manner prescribed by the policy to occurrence of a policy-triggering event defined in the policy.

8. The method of claim 1 , wherein each of the plurality of endpoints is configured to store or can access at least a subset of files to which the policy is to be applied.

9. The method of claim 1 , wherein the policy comprises one or more of a retention policy, a security policy, and an access restriction policy.

10. The method of claim 1 , further comprising:

monitoring one or more of the plurality of endpoints to detect the occurrence of the policy-triggering event; and

responding to the occurrence of the policy triggering event by performing one or more operations prescribed by the policy.

11. The method of claim 1 , wherein the policy prescribes restriction to access to a file upon the occurrence of the policy-triggering event, and wherein enforcing the policy includes preventing access to the file upon the occurrence of the policy-triggering event.

12. The method of claim 1 , wherein:

the policy comprises a retention policy; and

in response to obtaining an indication of the policy-triggering event, a retention policy operation prescribed by the retention policy is performed.

13. The method of claim 1 , wherein at least partially in response to the policy trigger event, the file is marked as deleted at one or more endpoints at which the file has been stored, and a copy of the file is retained until expiration of a retention period specified in the policy.

14. The method of claim 13 , wherein the copy of the file is stored centrally.

15. The method of claim 13 , wherein the copy is stored, but not made visible to users, at one or more of the endpoints.

16. The method of claim 1 , further comprising:

providing an administrative user interface to enable the policy to be defined.

17. The method of claim 16 , wherein the administrative user interface is configured to receive an identification of files to which the policy is to be applied.

18. The method of claim 1 , further comprising:

creating and storing an audit record or other data that evidences that a compliance action required by the policy has been performed.

19. The method of claim 1 , further comprising:

taking, with respect to a file as stored at the first one of the plurality of endpoints, an action required by the policy and propagating an effect of the action to one or more other endpoints of the plurality of endpoints.

20. The method of claim 1 , wherein the policy requires data associated with one or more of a file, a user, an endpoint, and a device to be deleted.

21. The method of claim 1 , further comprising:

initiating remotely an operation to cause data associated with a file, user, endpoint, and device, to be deleted.

22. The method of claim 21 , wherein the operation causes associated file management system metadata to be updated or deleted.

23. The method of claim 1 , wherein at least one of the plurality of endpoints corresponds to a network storage system that provides access to one or more files stored on the associated one or more non-transitory computer-readable storage medium.

24. The method of claim 23 , wherein the network storage system is associated with a web service that provides a storage service that provides access to one or more files stored on the associated one or more non-transitory computer readable storage medium.

25. The method of claim 1 , further comprising:

propagating, to one or more of the plurality of endpoints, a file in a native file format corresponding to the one or more of the plurality of endpoints, or

propagating, to one or more of the plurality of endpoints, an effect of an action to be taken on a file stored at the one or more of the plurality of endpoints, wherein the effect includes one or more commands for the action to be taken on the file based at least in part on the native file format corresponding to the one or more of the plurality of endpoints.

26. A file management system that is connected to a plurality of endpoints via a network, the file management system comprising:

one or more processors configured to:

obtain a policy to be applied with respect to a synchronization set, wherein the policy includes an indication of one or more policy triggering events, the policy triggering events including one or more permitted or restricted events relating to a file in the synchronization set, wherein the plurality of endpoints are associated with the synchronization set and a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein at least two of the plurality of endpoints have different types of native file stores; and

providing, by one or more processors associated with the file management system, the policy to at least a first one of the plurality of endpoints, wherein the first one of the plurality of endpoints enforces the policy in response to determining that a policy triggering event associated with one or more files in the synchronization set occurred.

27. A computer program product to manage files, the computer program product being embodied in a tangible, non-transitory computer readable storage medium and comprising computer instructions for:

obtaining, by a file management system that is connected to a plurality of endpoints via a network, a policy to be applied with respect to a synchronization set, wherein the policy includes an indication of one or more policy triggering events, the policy triggering events including one or more permitted or restricted events relating to a file in the synchronization set, wherein the plurality of endpoints are associated with the synchronization set and a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein at least two of the plurality of endpoints have different types of native file stores; and

providing, by one or more processors associated with the file management system, the policy to at least a first one of the plurality of endpoints, wherein the first one of the plurality of endpoints enforces the policy in response to determining that a policy triggering event associated with one or more files in the synchronization set occurred.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: HREBICEK, ONDREJ; CHUNG, LEONARD
To: EMC CORPORATION
Reel/Frame 044742/0235 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045167/0177 →
Continuity (5)
Continuation 15136574 · Apr 22, 2016
Continuation 14472209 · Aug 28, 2014
Continuation 13530763 · Jun 22, 2012
Provisional Application 61500036 · Jun 22, 2011
Related Publication 20180150475A1 · May 31, 2018