IP Library Granted Patent US 11,237,921
Granted Patent B2
US 11,237,921 · App. 16/692,157 · Granted Feb 1, 2022

Protecting storage backup configuration

Inventors: Douglas E. LeCrone (Hopkinton, MA); Paul A. Linstead (Shrewsbury, MA); Brett A. Quinn (Lincoln, RI); Denis J. Burt (Plymouth, MA)
Assignee: EMC IP Holding Company LLC
G06F11/1469G06F11/1448G06F11/1461G06F11/1464G06F21/602G06F21/6218G06F2221/0711G06F2221/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,237,921
App. No.
16/692,157
Granted
Feb 1, 2022
Kind
B2
Abstract

Changing operational backup parameters on a storage system includes a first actor generating a request to change operational backup parameters, providing the request from the first actor to a second actor, the second actor authorizing the request, and modifying the operational backup parameters in response to the second actor authorizing the request. The first actor may be assigned a role that allows the first actor to generate the request to change operational backup parameters of the storage system and the second actor may be assigned a role that allows the second actor to authorize the request to change operational backup parameters of the storage system. The request may include a time window provided by the first actor. Authorizing a request to change operational backup parameters of the storage system may create a token and an authorization key. The token may be indicative of the request provided by the first actor.

Claims (43)

1. A non-transitory computer readable medium containing software that changes operational backup parameters on a storage system, the software comprising:

executable code that receives a request from a first actor to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

executable code that receives an authorization for the request from a second actor after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

executable code that modifies the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request and wherein the second actor is required to be in a different physical location than the first actor.

2. A non-transitory computer readable medium, according to claim 1 , wherein the request includes a time window provided by the first actor.

3. A non-transitory computer readable medium, according to claim 1 , wherein authorizing the request creates a token and an authorization key.

4. A non-transitory computer readable medium, according to claim 3 , wherein the token is indicative of the request provided by the first actor.

5. A non-transitory computer readable medium, according to claim 4 , wherein operational backup parameters on the storage system are only modified in response to confirming that the token was generated by the first actor and authorized by the second actor.

6. A non-transitory computer readable medium, according to claim 5 , wherein a digital signature is used to verify at least one of: the token and the authorization key.

7. A non-transitory computer readable medium, according to claim 5 , wherein users of the system are prohibited from making any changes that would allow modification of operational backup parameters on the storage system by other than confirming that the token was generated and authorized by the second actor and corresponds to operations performed by the first actor.

8. A method of changing operational backup parameters on a storage system, comprising:

a first actor generating a request to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

providing the request from the first actor to a second actor;

the second actor authorizing the request after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

modifying the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request and wherein the second actor is required to be in a different physical location than the first actor.

9. A method, according to claim 8 , wherein the request includes a time window provided by the first actor.

10. A method, according to claim 8 , wherein authorizing the request creates a token and an authorization key.

11. A method, according to claim 10 , wherein the token is indicative of the request provided by the first actor.

12. A method, according to claim 11 , wherein operational backup parameters on the storage system are only modified in response to confirming that the token was generated and authorized by the second actor.

13. A method, according to claim 12 , wherein a digital signature is used to verify at least one of: the token and the authorization key.

14. A method, according to claim 12 , wherein users of the system are prohibited from making any changes that would allow modification of operational backup parameters on the storage system by other than confirming that the token was generated and authorized by the second actor and corresponds to operations performed by the first actor.

15. A method of changing operational backup parameters on a storage system, comprising:

a first actor generating a request to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

providing the request from the first actor to a second actor;

the second actor authorizing the request after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

modifying the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request and wherein the second actor is required to be in a different department than the first actor.

16. A method of changing operational backup parameters on a storage system, comprising:

a first actor generating a request to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

providing the request from the first actor to a second actor;

the second actor authorizing the request after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

modifying the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request, wherein authorizing the request creates a token and an authorization key and wherein generating the request to change operational backup parameters of the storage system includes creating a single use token that is different from the token created in connection with authorizing the request.

17. A method, according to claim 16 , wherein the token created in connection with authorizing the request is indicative of the request provided by the first actor.

18. A method, according to claim 16 , wherein a digital signature is used to verify at least one of: the token created in connection with authorizing the request, the single use token, and the authorization key.

19. A non-transitory computer readable medium containing software that changes operational backup parameters on a storage system, the software comprising:

executable code that receives a request from a first actor to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

executable code that receives an authorization for the request from a second actor after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

executable code that modifies the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request and wherein the second actor is required to be in a different department than the first actor.

20. A non-transitory computer readable medium containing software that changes operational backup parameters on a storage system, the software comprising:

executable code that receives a request from a first actor to change operational backup parameters of the storage system after the first actor is assigned a first role that allows generating a request to change operational backup parameters of the storage system, wherein only actors that have been assigned the first role can generate requests to change operational backup parameters of the storage system;

executable code that receives an authorization for the request from a second actor after the second actor is assigned a second role that allows authorizing the request to change operational backup parameters of the storage system, wherein only actors that have been assigned the second role can approve requests to change operational backup parameters of the storage system; and

executable code that modifies the operational backup parameters on the storage system in response to the second actor authorizing the request, wherein the operational backup parameters on the storage system are not modified if the second actor does not authorize the request, wherein authorizing the request creates a token and an authorization key and wherein generating the request to change operational backup parameters of the storage system includes creating a single use token that is different from the token created in connection with authorizing the request.

21. A non-transitory computer readable medium, according to claim 20 , wherein the token created in connection with authorizing the request is indicative of the request provided by the first actor.

22. A non-transitory computer readable medium, according to claim 20 , wherein a digital signature is used to verify at least one of: the token created in connection with authorizing the request, the single use token, and the authorization key.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2019
From: LECRONE, DOUGLAS E.; LINSTEAD, PAUL A.; QUINN, BRETT A.; BURT, DENIS J.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051102/0351 →