IP Library Granted Patent US 11,336,650
Granted Patent B1
US 11,336,650 · App. 16/780,115 · Granted May 17, 2022

Systems and methods for producing access control list caches including effective information access permissions across disparate storage devices

Inventors: Shailesh Dargude (San Jose, CA); Satish Grandhi (Santa Clara, CA); Harshit Shah (Mumbai, IN)
Assignee: Veritas Technologies LLC
H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,336,650
App. No.
16/780,115
Granted
May 17, 2022
Kind
B1
Abstract

The disclosed computer-implemented method for producing access control list caches including effective information access permissions across disparate storage devices may include (i) receiving, at a computing device, an instruction to prepare an access control list (ACL) cache and (ii) performing a security action. The security action may include (A) recursively parsing, at the computing device, at least one respective ACL for information stored on at least two disparate storage devices, (B) identifying, at each step of recursion, each direct user and each indirect user having information access permissions in at least one of the respective ACLs, (C) determining, for each unique user in the respective ACLs, per-control point effective permissions, and (D) storing the per-control point effective information access permissions in the ACL cache. Various other methods, systems, and computer-readable media are also disclosed.

Claims (49)

1. A computer-implemented method for producing access control list caches including effective information access permissions across disparate storage devices, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving, at the computing device, an instruction to prepare an access control list (ACL) cache; and

performing a security action, the security action comprising:

recursively parsing, at the computing device, at least one respective ACL for information stored on at least two disparate storage devices;

identifying, at each step of recursion, each direct user and each indirect user having information access permissions in at least one of the respective ACLs;

determining, for each unique user in the respective ACLs, per-control point effective information access permissions across the at least two disparate storage devices, wherein each control point is a level in an information storage hierarchy at which respective access control is present; and

storing the per-control point effective information access permissions in the ACL cache.

2. The computer-implemented method of claim 1 , further comprising:

fetching, for each file stored on the at least two disparate storage devices, the respective ACLs;

looking-up, in the ACL cache, each respective ACL; and

performing the security action when the information describing each ACL is absent from the ACL cache.

3. The computer-implemented method of claim 2 , further comprising periodically repeating the fetching, the looking-up, and the performing the security action.

4. The computer-implemented method of claim 1 , further comprising receiving the instruction to prepare the ACL cache in response to the ACL cache being invalidated.

5. The computer-implemented method of claim 1 , further comprising searching the ACL cache for a per-control point effective information access permission for a specific user.

6. The computer-implemented method of claim 1 , wherein the control point is a file.

7. The computer-implemented method of claim 1 , wherein the control point is a folder.

8. The computer-implemented method of claim 1 , wherein the security action further comprises generating a report of information in the ACL cache.

9. The computer-implemented method of claim 1 , wherein the security action further comprises displaying information from the ACL cache on a display device.

10. The computer-implemented method of claim 1 , further comprising storing the per-control point effective information access permissions in the ACL cache in a per-user, per-access format comprising a user identifier, respective information access type, and respective access permission mask information.

11. A system for producing access control list caches including effective information access permissions across disparate storage devices, the system comprising:

a first receiving module, stored in a memory, that receives an instruction to prepare an access control list (ACL) cache; and

a first performing module, stored in the memory, that performs a security action, the security action comprising:

recursively parsing, at the system, at least one respective ACL for information stored on at least two disparate storage devices;

identifying, at each step of recursion, each direct user and each indirect user having information access permissions in at least one of the respective ACLs;

determining, for each unique user in the respective ACLs, per-control point effective information access permissions across the at least two disparate storage devices, wherein each control point is a level in an information storage hierarchy at which respective access control is present;

storing the per-control point effective information access permissions in the ACL cache; and

at least one physical processor that executes the receiving module and the performing module.

12. The system of claim 11 , further comprising:

a fetching module, stored in the memory, that fetches, for each file stored on the at least two disparate storage devices, the respective ACLs;

a looking-up module, stored in the memory, that looks-up, in the ACL cache, each respective ACL; and

a second performing module, stored in the memory, that performs the security action when the information describing each ACL is absent from the ACL cache.

13. The system of claim 12 , wherein the fetching module, the looking-up module, and the second performing module periodically repeat the fetching, the looking-up, and the performing the security action.

14. The system of claim 11 , further comprising a second receiving module, stored in the memory, that receives the instruction to prepare the ACL cache in response to the ACL cache being invalidated.

15. The system of claim 11 , further comprising a searching module, stored in the memory, that searches the ACL cache for a per-control point effective information access permission for a specific user.

16. The system of claim 11 , wherein the security action further comprises displaying information from the ACL cache on a display device.

17. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive, at the computing device, an instruction to prepare an access control list (ACL) cache; and

perform a security action, the security action comprising:

recursively parsing, at the computing device, at least one respective ACL for information stored on at least two disparate storage devices;

identifying, at each step of recursion, each direct user and each indirect user having information access permissions in at least one of the respective ACLs;

determining, for each unique user in the respective ACLs, per-control point effective information access permissions across the at least two disparate storage devices, wherein each control point is a level in an information storage hierarchy at which respective access control is present; and

storing the per-control point effective information access permissions in the ACL cache.

18. The non-transitory computer-readable medium of claim 17 , wherein the security action further comprises:

fetching, for each file stored on the at least two disparate storage devices, the respective ACLs;

looking-up, in the ACL cache, each respective ACL; and

performing the security action when the information describing each ACL is absent from the ACL cache.

19. The non-transitory computer-readable medium of claim 17 , further comprising one or more computer-executable instructions that, when executed by the at least one processor of the computing device, cause the computing device to receive the instruction to prepare the ACL cache in response to the ACL cache being invalidated.

20. The non-transitory computer-readable medium of claim 17 , wherein the security action further comprises searching the ACL cache for a per-control point effective information access permission for a specific user.

21. The non-transitory computer-readable medium of claim 17 , wherein the security action further comprises displaying information from the ACL cache on a display device.

Assignments (11)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2026
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 075377/0130 →
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069574/0951 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
TERMINATION AND RELESAE OF SECURITY INTEREST IN PATENTS AT R/F 053640/0780 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0492 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Aug 31, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 053640/0780 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 31, 2020
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 053373/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2020
From: DARGUDE, SHAILESH; GRANDHI, SATISH; SHAH, HARSHIT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 051702/0389 →
Continuity (2)
Continuation In Part PCTUS2019025801 · Apr 4, 2019
Provisional Application 62653541 · Apr 5, 2018
Cited By (1)
US 12,634,291