IP Library Granted Patent US 10,949,545
Granted Patent B2
US 10,949,545 · App. 16/805,859 · Granted Mar 16, 2021

Data privacy awareness in workload provisioning

Inventors: Sergio Varga (Campinas-SP, BR); Jørgen E. Borup (Rungsted Kyst, DK); Thiago Cesar Rotta (Campinas-SP, BR); Marco Aurelio Stelmar Netto (São Paulo, BR); Kris Blöndal (Fornebu, NO)
G06F21/60G06F9/505G06F9/542G06F21/30H04W4/02H04W4/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,949,545
App. No.
16/805,859
Granted
Mar 16, 2021
Kind
B2
Abstract

Data privacy information pertaining to particular data hosted by a first workload provisioned to a first location can be received. The first workload can be monitored to determine whether the first workload is accessed by a second workload, determine whether the second workload is indicated as being authorized, in the data privacy information, to access the particular data hosted by first workload, and determine whether the second workload has access to the particular data hosted by the first workload. If so, information identifying the second workload and a manner in which the second workload accessed the particular data hosted by the first workload can be stored to a data storage.

Claims (76)

1. A method, comprising:

receiving data privacy information pertaining to particular data hosted by a first workload provisioned to a first location;

monitoring the first workload, the monitoring the first workload comprising:

determining whether the first workload is accessed by a second workload;

responsive to determining that the first workload is accessed by the second workload, determining whether the second workload is indicated as being authorized, in the data privacy information, to access the particular data hosted by first workload; and

responsive to determining that the second workload is not indicated as being authorized to access the particular data hosted by the first workload, determining whether the second workload has access to the particular data hosted by the first workload; and

responsive to determining that the second workload has access to the particular data hosted by the first workload, automatically storing, using a processor, to a data storage information identifying the second workload and a manner in which the second workload accessed the particular data hosted by the first workload.

2. The method of claim 1 , further comprising:

responsive to determining that the second workload has access to the data hosted by the first workload, automatically communicating a notification to a system or compliance administrator indicating that the first workload has been accessed by an unauthorized workload, the notification comprising the information identifying the second workload and the manner in which the second workload accessed the particular data hosted by the first workload.

3. The method of claim 1 , further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically storing to the data storage information identifying the issue with the first workload regarding the data privacy.

4. The method of claim 1 , further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically communicating a notification to a system or compliance administrator indicating the issue with the first workload regarding the data privacy.

5. The method of claim 4 , wherein the notification indicates that the first workload has been provisioned to a location that is not a location where the workload is allowed to be provisioned.

6. The method of claim 1 , further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned; and

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, automatically provisioning the first workload to a second location to which provisioning of the first workload is allowed based on the data privacy information.

7. The method of claim 6 , further comprising:

communicating the data privacy information pertaining to the particular data to a data privacy advisor application;

responsive to the communicating the data privacy information pertaining to the particular data to the data privacy advisor application, receiving from the data privacy advisor application locations allowed information and identifying, as candidate locations, locations indicated in the locations allowed information; and

selecting the second location from the candidate locations.

8. A system, comprising:

a processor programmed to initiate executable operations comprising:

receiving data privacy information pertaining to particular data hosted by a first workload provisioned to a first location;

monitoring the first workload, the monitoring the first workload comprising:

determining whether the first workload is accessed by a second workload;

responsive to determining that the first workload is accessed by the second workload, determining whether the second workload is indicated as being authorized, in the data privacy information, to access the particular data hosted by first workload; and

responsive to determining that the second workload is not indicated as being authorized to access the particular data hosted by the first workload, determining whether the second workload has access to the particular data hosted by the first workload; and

responsive to determining that the second workload has access to the particular data hosted by the first workload, automatically storing to a data storage information identifying the second workload and a manner in which the second workload accessed the particular data hosted by the first workload.

9. The system of claim 8 , the executable operations further comprising:

responsive to determining that the second workload has access to the data hosted by the first workload, automatically communicating a notification to a system or compliance administrator indicating that the first workload has been accessed by an unauthorized workload, the notification comprising the information identifying the second workload and the manner in which the second workload accessed the particular data hosted by the first workload.

10. The system of claim 8 , the executable operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically storing to the data storage information identifying the issue with the first workload regarding the data privacy.

11. The system of claim 8 , the executable operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically communicating a notification to a system or compliance administrator indicating the issue with the first workload regarding the data privacy.

12. The system of claim 11 , wherein the notification indicates that the first workload has been provisioned to a location that is not a location where the workload is allowed to be provisioned.

13. The system of claim 8 , the executable operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned; and

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, automatically provisioning the first workload to a second location to which provisioning of the first workload is allowed based on the data privacy information.

14. The system of claim 13 , the executable operations further comprising:

communicating the data privacy information pertaining to the particular data to a data privacy advisor application;

responsive to the communicating the data privacy information pertaining to the particular data to the data privacy advisor application, receiving from the data privacy advisor application locations allowed information and identifying, as candidate locations, locations indicated in the locations allowed information; and

selecting the second location from the candidate locations.

15. A computer program product, comprising:

a computer readable storage medium having program code stored thereon, the program code executable by a data processing system to initiate operations including:

receiving data privacy information pertaining to particular data hosted by a first workload provisioned to a first location;

monitoring the first workload, the monitoring the first workload comprising:

determining whether the first workload is accessed by a second workload;

responsive to determining that the first workload is accessed by the second workload, determining whether the second workload is indicated as being authorized, in the data privacy information, to access the particular data hosted by first workload; and

responsive to determining that the second workload is not indicated as being authorized to access the particular data hosted by the first workload, determining whether the second workload has access to the particular data hosted by the first workload; and

responsive to determining that the second workload has access to the particular data hosted by the first workload, automatically storing to a data storage information identifying the second workload and a manner in which the second workload accessed the particular data hosted by the first workload.

16. The computer program product of claim 15 , wherein the program code is executable by the data processing system to initiate operations further comprising:

responsive to determining that the second workload has access to the data hosted by the first workload, automatically communicating a notification to a system or compliance administrator indicating that the first workload has been accessed by an unauthorized workload, the notification comprising the information identifying the second workload and the manner in which the second workload accessed the particular data hosted by the first workload.

17. The computer program product of claim 15 , wherein the program code is executable by the data processing system to initiate operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically storing to the data storage information identifying the issue with the first workload regarding the data privacy.

18. The computer program product of claim 15 , wherein the program code is executable by the data processing system to initiate operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned;

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, determining whether there is an issue with the first workload regarding data privacy; and

responsive to determining that there is an issue with the first workload regarding the data privacy, automatically communicating a notification to a system or compliance administrator indicating the issue with the first workload regarding the data privacy.

19. The computer program product of claim 15 , wherein the program code is executable by the data processing system to initiate operations further comprising:

determining, based on the data privacy information, whether the first location is a location where the first workload is allowed to be provisioned; and

responsive to determining that the first location is a location where the first workload is not allowed to be provisioned, automatically provisioning the first workload to a second location to which provisioning of the first workload is allowed based on the data privacy information.

20. The computer program product of claim 19 , wherein the program code is executable by the data processing system to initiate operations further comprising:

communicating the data privacy information pertaining to the particular data to a data privacy advisor application;

responsive to the communicating the data privacy information pertaining to the particular data to the data privacy advisor application, receiving from the data privacy advisor application locations allowed information and identifying, as candidate locations, locations indicated in the locations allowed information; and

selecting the second location from the candidate locations.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2020
From: VARGA, SERGIO; BORUP, JØRGEN E.; ROTTA, THIAGO CESAR; STELMAR NETTO, MARCO AURELIO; BLONDAL, KRIS
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 051972/0843 →