IP Library Granted Patent US 11,675,503
Granted Patent B1
US 11,675,503 · App. 16/952,614 · Granted Jun 13, 2023

Role-based data access

Inventor: Ronald Ekins (Haywards Heath, GB)
Assignee: PURE STORAGE, INC.
G06F3/0622G06F3/067G06F3/0653G06F3/0683G06F21/78
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,675,503
App. No.
16/952,614
Granted
Jun 13, 2023
Kind
B1
Abstract

Role-based data access, including: assigning, to a storage volume of a storage system, a volume-level access policy; and determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access, including allowing the access responsive to the one or more attributes meeting the volume-level access policy or denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

Claims (34)

1. A method implemented by a computing device that includes a processor, the method comprising:

assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and

determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.

2. The method of claim 1 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

3. The method of claim 1 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

4. The method of claim 1 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

5. The method of claim 1 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

6. The method of claim 1 , wherein the volume-level access policy indicates one or more allowable storage operations and the one or more attributes comprise a type of storage operation of the request.

7. The method of claim 1 , further comprising:

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

allowing the request responsive to the updated volume-level access policy being more restrictive than the volume-level access policy.

8. The method of claim 1 , further comprising:

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.

9. An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and

determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.

10. The apparatus of claim 9 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

11. The apparatus of claim 9 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

12. The apparatus of claim 9 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

13. The apparatus of claim 9 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

14. The apparatus of claim 9 , wherein the volume-level access policy indicates one or more allowable storage operations and the one or more attributes comprise a type of storage operation of the request.

15. The apparatus of claim 9 , wherein the steps further comprise:

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

allowing the request responsive to the updated volume-level access policy being more restrictive than the volume-level access policy.

16. The apparatus of claim 9 , wherein the steps further comprise:

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.

17. A computer program product disposed upon a computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

assigning, to a storage volume of a storage system, a volume-level access policy, the storage volume storing a plurality of data objects, wherein assigning the volume-level access policy to the storage volume restricts access to each data object of the plurality of the data objects stored by the storage volume, and wherein the restriction is based on a role of an entity requesting access to any data object of the plurality of data objects stored by the storage volume; and

determining whether to allow access to the storage volume based on the volume-level access policy and one or more attributes of a request for the access.

18. The computer program product of claim 17 , wherein determining whether to allow access to the storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

19. The computer program product of claim 17 , wherein determining whether to allow access to the storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

20. The computer program product of claim 17 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2020
From: EKINS, RONALD
To: PURE STORAGE, INC.
Reel/Frame 054419/0357 →
Continuity (6)
Continuation In Part 17022702 · Sep 16, 2020
Continuation In Part 16175221 · Oct 30, 2018
Continuation In Part 16050698 · Jul 31, 2018
Provisional Application 62750764 · Oct 25, 2018
Provisional Application 62695433 · Jul 9, 2018
Provisional Application 62674570 · May 21, 2018
Cited By (13)
US 12,259,906 US 12,265,538 US 12,284,216 US 12,284,218 US 12,321,621 US 12,367,320 US 12,566,680 US 12,578,896 US 12,638,989 US 12,656,954 US 12,705,212 US 12,717,966 US 12,719,935