IP Library Granted Patent US 11,010,068
Granted Patent B2
US 11,010,068 · App. 16/258,282 · Granted May 18, 2021

GPT-based multi-location data security system

Inventors: Chitrak Gupta (Karnataka, IN); Shekar Babu Suryanarayana (Kamataka, IN)
Assignee: Dell Products L.P.
G06F3/0622G06F3/067G06F3/0637G06F3/0644G06F12/1408G06F21/78G06F2212/1052G06F2212/402
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,010,068
App. No.
16/258,282
Granted
May 18, 2021
Kind
B2
Abstract

A GPT-based multi-location data security system includes a first server device coupled to a second server device through a network. The first server device includes a storage device that includes a GPT that identifies a data storage partition on the storage device that stores data, and that includes a security tag that identifies security requirements for the data stored on the data storage partition. A multi-location data security subsystem in the first server device is coupled to the storage device. The multi-location data security subsystem receives a request to transfer the data stored on the data storage partition to the second server device, and determines whether the second server device satisfies the security requirements for the data stored on the data storage partition. If the second server device satisfies the security requirements identified in the security tag, the first server device transfer the data to the second server device.

Claims (55)

1. A GPT-based multi-location data security system, comprising:

a first server device; and

a second server device that is coupled to the first server device through a network, wherein the second server device includes:

a storage device that includes a Globally Unique Identifier (GUID) Partition Table (GPT) that identifies:

a data storage partition on the storage device that includes data structures that store data; and

a distributed key entry partition on the storage device having a respective entry associated with each data structure included on the data storage partition, wherein each respective entry in the distributed key entry partition includes a security tag that identifies security requirements for data stored in the data structure associated with that respective entry; and

a multi-location data security subsystem that is coupled to the storage device, wherein the multi-location data security subsystem is configured to:

receive a request to transfer data stored in a first data structure to the first server device;

access a first security tag that identifies security requirements for the data stored in the first data structure in a first respective entry in the distributed key entry partition that is associated with the first data structure;

determine, based on the first security tag, whether the first server device satisfies the security requirements for the data stored in the first data structure; and

transfer, in response to determining that the first server device satisfies the security requirements identified in the first security tag, the data stored in the first data structure to the first server device.

2. The system of claim 1 , wherein the storage device is configured to:

detect the provisioning of data in each data structure included on the data storage partition and, in response, create the security tag that identifies security requirements for the data stored on that data structure, and store that security tag in the respective entry for that data structure in the distributed key entry partition in the GPT.

3. The system of claim 1 , wherein the multi-location data security subsystem is configured to:

transfer the first security tag to the first server device along with the data stored in the first data structure.

4. The system of claim 1 , wherein the multi-location data security subsystem is configured to:

synchronize the GPT with the first server device.

5. The system of claim 1 , wherein the multi-location data security subsystem is configured to:

prevent, in response to determining that the first server device does not satisfy the security requirements identified in the first security tag, the transfer of the data stored in the first data structure to the first server device.

6. The system of claim 5 , wherein the multi-location data security subsystem is configured to:

identify, in response to determining that the first server device does not satisfy the security requirements identified in the first security tag, security policies for implementation on the first server device in order for the first server device to satisfy the security requirements identified in the first security tag.

7. An Information Handling System (IHS), comprising:

at least one processing system; and

at least one memory system that is coupled to the at least one processing system and that include instruction that, when executed by the at least one processing system, cause the at least one processing system to perform operations including:

receiving a request to transfer data to a server device, wherein the data is stored in a first data structure included on a data storage partition that is provided on a storage device and that is identified by a Globally Unique Identifier (GUID) Partition Table (GPT);

accessing, in a distributed key entry partition that is provided on the storage device and that is identified by the GPT, a first security tag that is included in a first entry associated with the first data structure in the distributed key entry partition, wherein the first security tag identifies security requirements for the data stored in the first data structure;

determining, based on the security tag, whether the server device satisfies security requirements for the data stored in the first data structure; and

transferring, in response to determining that the server device satisfies the security requirements identified in the first security tag, the data stored in the first data structure to the server device.

8. The IHS of claim 7 , wherein the operations include:

detecting the storage of the data in the first data structure and, in response, creating the first security tag that identifies the security requirements for the data stored in the first data structure, and storing the first security tag in the first entry associated with the first data structure in the distributed key entry partition.

9. The IHS of claim 7 , wherein the operations includes:

transferring the first security tag to the server device along with the data stored in the first data structure.

10. The IHS of claim 9 , wherein the first security tag transferred to the server device identifies at least one source of the data stored in the first data structure.

11. The IHS of claim 7 , wherein the operations further include:

synchronizing the GPT with the server device.

12. The IHS of claim 7 , wherein the operations further include:

preventing, in response to determining that the server device does not satisfy the security requirements identified in the first security tag, the transfer of the data stored in the first data structure to the server device.

13. The IHS of claim 12 , wherein the operations further include:

identifying, in response to determining that the server device does not satisfy the security requirements identified in the first security tag, security policies for implementation on the server device in order for the server device to satisfy the security requirements identified in the first security tag.

14. A method for providing data security at multiple storage locations, comprising:

receiving, by a first server device, a request to transfer data to a second server device, wherein the data is stored in a first data structure included on a data storage partition that is provided on a storage device and that is identified by Globally Unique Identifier (GUID) Partition Table (GPT);

accessing, by the first server device in a distributed key entry partition that is provided on the storage device and that is identified by the GPT, a first security tag that is included in a first entry associated with the first data structure in the distributed key entry partition, wherein the first security tag identifies security requirements for the data stored in the first data structure;

determining, by the first server device based on the security tag, whether the second server device satisfies security requirements for the data stored in the first data structure included on the data storage partition; and

transfer, by the first server device in response to determining that the second server device satisfies the security requirements identified in the first security tag, the data stored in the first data structure to the second server device.

15. The method of claim 14 , further comprising:

detecting, by the first server device, the storage of the data in the first data structure and, in response, creating the first security tag that identifies the security requirements for the data stored in the first data structure, and storing the first security tag in the first entry associated with the first data structure in the distributed key entry partition.

16. The method of claim 14 , further comprising:

transferring, by the first server device, the first security tag to the second server device along with the data stored in the first data structure.

17. The method of claim 16 , wherein the first security tag transferred to the second server device identifies at least one source of the data stored in the first data structure.

18. The method of claim 14 , further comprising:

synchronizing, by the first server device, the GPT with the second server device.

19. The method of claim 14 , further comprising:

preventing, by the first server device in response to determining that the second server device does not satisfy the security requirements identified in the first security tag, the transfer of the data stored in the first data structure to the second server device.

20. The method of claim 19 , further comprising:

identifying, by the first server device in response to determining that the second server device does not satisfy the security requirements identified in the first security tag, security policies for implementation on the second server device in order for the second server device to satisfy the security requirements identified in the first security tag.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2019
From: GUPTA, CHITRAK; SURYANARAYANA, SHEKAR BABU
To: DELL PRODUCTS L.P.
Reel/Frame 048143/0052 →