IP Library Granted Patent US 12,216,778
Granted Patent B2
US 12,216,778 · App. 16/743,863 · Granted Feb 4, 2025

Distributing data amongst storage components using data sensitivity classifications

Inventors: Yossef Saad (Ganei Tivka, IL); Itay Glick (Ramat Hasharon, IL)
Assignee: EMC IP Holding Company LLC
G06F21/6218G06F3/0623G06F3/065G06F3/0659G06F3/067G06F11/1451G06F16/13G06N20/00G06F2201/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,216,778
App. No.
16/743,863
Granted
Feb 4, 2025
Kind
B2
Abstract

Described is a system for distributing data amongst storage components using data sensitivity (or security) classifications. The system may define categories for classifying data files and assign a sensitivity (or security) rating to each of the defined categories. The categories and/or associated sensitivity ratings may be determined using machine learning components that may leverage industry-specific information or data sensitivity information used by other clients. The system may then continuously reevaluate (or reclassify) data files to determine whether they are stored on a storage component that meets the necessary data sensitivity requirements. If the system determines particular data files are stored on a corresponding storage component that does not meet certain data sensitivity requirements, the system may perform an action to secure the particular data files.

Claims (63)

1. A system comprising:

one or more processors; and

a non-transitory computer readable medium storing a plurality of instructions, which when executed, cause the one or more processors to:

initialize a data distribution policy for a first client of a storage system including defining categories for classifying data files stored within one or more storage components of the storage system by analyzing attributes of the data stored within the one or more storage components, and assigning a data security rating to each of the defined categories, each of the categories describing a group of the data files based on a shared attribute of the data files, wherein defining the categories for classifying the data files associated with the first client is based on at least one of an industry associated with the first client, or categories used for a different set of data files associated with a second client of the storage system;

determine, for each of the storage components, a security capability based on at least one or more network attributes or device attributes associated with the storage component, the security capability being associated with accessibility of the storage component and being proportional to a degree of security provided to the data files stored by the storage component, wherein security is associated with unauthorized access;

scan the storage components to identify a stored first data file for reevaluation of whether the first data file is stored in an appropriate storage component having a security capability that corresponds to a data security rating of the first data file, the data security rating being proportional to a degree of protection from unauthorized access for the first data file;

classify the first data file to a first category having an assigned data security rating from amongst the defined categories based on one or more attributes associated with the first data file;

determine whether the data security rating which is assigned to the first category and which specifies a degree of protection required for the first data file against unauthorized access is satisfied by a degree of protection provided against unauthorized access as specified by the security capability for a first storage component that stores the first data file; and

initiate an operation to secure the first data file, in response to determining the degree of protection required for the first data file against unauthorized access is not satisfied by the degree of protection provided against unauthorized access as specified by the security capability for the first storage component.

2. The system of claim 1 , wherein the plurality of instructions, when executed, further cause the one or more processors to:

determine the security capability for a second storage component corresponds to the data security rating assigned to the first category, in response to determining the data security rating assigned to the first category does not correspond to the security capability for the first storage component, and

wherein the operation to secure the first data file includes storing data of the first data file within the second storage component as a second data file.

3. The system of claim 2 , wherein the storing data of the first data file within the second storage component as the second data file includes:

instructing a backup application to resend, to the storage system, the data of the first data file, the backup application directing storage of the data of the first data file to the second data file within the second storage component.

4. The system of claim 1 , wherein the defining the categories includes:

providing, as part of a set of inputs for a processing performed by a machine learning component, the attributes associated with the data files stored by the storage system; and

receiving, as part of a set of outputs from the processing performed by the machine learning component, the defined categories for classifying data files stored within one or more storage components of a storage system, and the assigned data security ratings for each of the defined categories.

5. The system of claim 4 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, an identifier for the industry associated with the first client.

6. The system of claim 4 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, the categories or data security ratings used for the different set of data files associated with a second client of the storage system.

7. The system of claim 1 , wherein the classifying the first data file to the first category based on one or more attributes associated with the first data file includes:

determining, as at least one of the attributes, a file extension of a file associated with data stored within the first data file.

8. The system of claim 1 , wherein the classifying the first data file to the first category based on one or more attributes associated with the first data file includes:

performing a natural language processing of text of a file associated with data stored within the first data file to obtain at least one of the attributes.

9. A method comprising:

initializing a data distribution policy for a first client of a storage system including defining categories for classifying data files stored within one or more storage components of the storage system by analyzing attributes of the data stored within the one or more storage components, and assigning a data security rating to each of the defined categories, each of the categories describing a group of the data files based on a shared attribute of the data files, wherein defining the categories for classifying the data files associated with the first client is based on at least one of an industry associated with the first client, or categories used for a different set of data files associated with a second client of the storage system;

determining, for each of the storage components, a security capability based on at least one or more network attributes or device attributes associated with the storage component, the security capability being associated with accessibility of the storage component and being proportional to a degree of security provided to the data files stored by the storage component, wherein security is associated with unauthorized access;

scanning the storage components to identify a stored first data file for reevaluation of whether the first data file is stored in an appropriate storage component having a security capability that corresponds to a data security rating of the first data file, the data security rating being proportional to a degree of protection from unauthorized access for the first data file;

classifying the first data file to a first category having an assigned data security rating from amongst the defined categories based on one or more attributes associated with the first data file;

determining whether the data security rating which is assigned to the first category and which specifies a degree of protection required for the first data file against unauthorized access is satisfied by a degree of protection provided against unauthorized access as specified by the security capability for a first storage component that stores the first data file; and

initiating an operation to secure the first data file, in response to determining the degree of protection required for the first data file against unauthorized access is not satisfied by the degree of protection provided against unauthorized access as specified by the security capability for the first storage component.

10. The method of claim 9 , further comprising:

determining the security capability for a second storage component corresponds to the data security rating assigned to the first category, in response to determining the data security rating assigned to the first category does not correspond to the security capability for the first storage component, and

wherein the operation to secure the first data file includes storing data of the first data file within the second storage component as a second data file.

11. The method of claim 10 , wherein the storing data of the first data file within the second storage component as the second data file includes:

instructing a backup application to resend, to the storage system, the data of the first data file, the backup application directing storage of the data of the first data file to the second data file within the second storage component.

12. The method of claim 9 , wherein the defining the categories includes:

providing, as part of a set of inputs for a processing performed by a machine learning component, the attributes associated with the data files stored by the storage system; and

receiving, as part of a set of outputs from the processing performed by the machine learning component, the defined categories for classifying data files stored within one or more storage components of a storage system, and the assigned data security ratings for each of the defined categories.

13. The method of claim 12 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, an identifier for the industry associated with the first client.

14. The method of claim 12 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, the categories or data security ratings used for the different set of data files associated with a second client of the storage system.

15. A computer program product comprising a non-transitory computer-readable medium having a computer-readable program code embodied therein to be executed by one or more processors, the program code including instructions to:

initialize a data distribution policy for a first client of a storage system including defining categories for classifying data files stored within one or more storage components of the storage system by analyzing attributes of the data stored within the one or more storage components, and assigning a data security rating to each of the defined categories, each of the categories describing a group of the data files based on a shared attribute of the data files, wherein defining the categories for classifying the data files associated with the first client is based on at least one of an industry associated with the first client, or categories used for a different set of data files associated with a second client of the storage system;

determine, for each of the storage components, a security capability based on at least one or more network attributes or device attributes associated with the storage component, the security capability being associated with accessibility of the storage component and being proportional to a degree of security provided to the data files stored by the storage component, wherein security is associated with unauthorized access;

scan the storage components to identify a stored first data file for reevaluation of whether the first data file is stored in an appropriate storage component having a security capability that corresponds to a data security rating of the first data file, the data security rating being proportional to a degree of protection from unauthorized access for the first data file;

classify the first data file to a first category having an assigned data security rating from amongst the defined categories based on one or more attributes associated with the first data file;

determine whether the data security rating which is assigned to the first category and which specifies a degree of protection required for the first data file against unauthorized access is satisfied by a degree of protection provided against unauthorized access as specified by the security capability for a first storage component that stores the first data file; and

initiate an operation to secure the first data file, in response to determining the degree of protection required for the first data file against unauthorized access is not satisfied by the degree of protection provided against unauthorized access as specified by the security capability for the first storage component.

16. The computer program product of claim 15 , wherein the program code includes further instructions to:

determine the security capability for a second storage component corresponds to the data security rating assigned to the first category, in response to determining the data security rating assigned to the first category does not correspond to the security capability for the first storage component, and

wherein the operation to secure the first data file includes storing data of the first data file within the second storage component as a second data file.

17. The computer program product of claim 16 , wherein the storing data of the first data file within the second storage component as the second data file includes:

instructing a backup application to resend, to the storage system, the data of the first data file, the backup application directing storage of the data of the first data file to the second data file within the second storage component.

18. The computer program product of claim 15 , wherein the defining the categories includes:

providing, as part of a set of inputs for a processing performed by a machine learning component, the attributes associated with the data files stored by the storage system; and

receiving, as part of a set of outputs from the processing performed by the machine learning component, the defined categories for classifying data files stored within one or more storage components of a storage system, and the assigned data security ratings for each of the defined categories.

19. The computer program product of claim 18 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, an identifier for the industry associated with the first client.

20. The computer program product of claim 18 , wherein the defining the categories further includes:

providing, as part of the set of inputs for the processing performed by the machine learning component, the categories or data security ratings used for the different set of data files associated with a second client of the storage system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (052216/0758) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0680 →
RELEASE OF SECURITY INTEREST AF REEL 052243 FRAME 0773 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0152 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 26, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 052243/0773 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 24, 2020
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 052216/0758 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: SAAD, YOSSEF; GLICK, ITAY
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051527/0129 →