IP Library Granted Patent US 11,675,916
Granted Patent B2
US 11,675,916 · App. 17/160,597 · Granted Jun 13, 2023

Method and system for limiting data accessibility in composed systems

Inventors: Yossef Saad (Ganei Tikva, IL); Mark Steven Sanders (Roanoke, VA); Gaurav Chawla (Austin, TX); Mukund P. Khatri (Austin, TX)
Assignee: Dell Products L.P.
G06F21/62G06F21/52G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,675,916
App. No.
17/160,597
Granted
Jun 13, 2023
Kind
B2
Abstract

A system for managing composed information handling systems to manage access to data by applications hosted by the composed information handling systems includes a system control processor that instantiates a composed information handling system using a compute resource set that hosts applications and a hardware resource set that stores a portion of the data, associates, using authorization information, storage areas of the at least one hardware resource set with the applications to obtain storage area associations, obtains a data access request from the compute resource set for the portion of the data which is stored in a storage area of the storage areas, makes a determination, based on the storage area associations and an initiator of the data access request, that the initiator of the data access request is not authorized to access the portion of the data, and refuses to service the data access request.

Claims (50)

1. A system for managing composed information handling systems to manage access to data by applications hosted by the composed information handling systems, comprising:

a storage for storing authorization information; and

a system control processor manager programmed to:

instantiate a composed information handling system of the composed information handling systems using an at least one compute resource set that hosts at least one of the applications and at least one hardware resource set that stores a portion of the data;

associate, using the authorization information, storage areas of the at least one hardware resource set with the applications to obtain storage area associations;

obtain a data access request from the at least one compute resource set for the portion of the data which is stored in a storage area of the storage areas;

make a determination, based on the storage area associations and an initiator of the data access request, that the initiator of the data access request is not authorized to access the portion of the data;

refuse, based on the determination, to service the data access request;

identify a monitoring trigger event associated with monitoring modifications to the initiator, wherein the monitoring trigger event is the refusal to service the data access request;

in response to identifying the monitoring trigger event, make a second determination that the initiator was unknowingly modified; and

perform a remediation action set based on the second determination.

2. The system of claim 1 , wherein the storage area associations specify that the initiator is not associated with the storage area.

3. The system of claim 2 , wherein the initiator of the data access request is an application of the at least one of the applications.

4. The system of claim 1 , wherein the data access request indicates an identity of the initiator and the storage area.

5. The system of claim 1 , wherein instantiating a composed information handling system of the composed information handling systems using a compute resource set that executes at least one of the applications and a hardware resource set that stores a portion of the data comprises preparing at least one control resource set to provide management services for the at least one compute resource set and the at least one hardware resource set.

6. The system of claim 5 , wherein the at least one control resource set comprises a system control processor.

7. The system of claim 6 , wherein the management services comprise:

intercepting data access requests from the at least one compute resource set by presenting the hardware resource set as bare metal resources; and

monitoring the applications to identify potentially compromised applications based on the intercepted data access requests and monitoring trigger events.

8. A method for managing composed information handling systems to manage access to data by applications hosted by the composed information handling systems, comprises:

instantiating a composed information handling system of the composed information handling systems using an at least one compute resource set that executes hosts at least one of the applications and an at least one hardware resource set that stores a portion of the data;

associating, using authorization information, different storage areas of the at least one hardware resource set with the applications to obtain storage area associations;

obtaining a data access request from the at least one compute resource set for the portion of the data which is stored in a storage area of the storage areas;

making a determination, based on the storage area associations and an initiator of the data access request, that the initiator of the data access request is not authorized to access the portion of the data;

refusing, based on the determination, to service the data access request;

identifying a monitoring trigger event associated with monitoring modifications to the initiator, wherein the monitoring trigger event is the refusal to service the data access request;

in response to identifying the monitoring trigger event, making a second determination that the initiator was unknowingly modified; and

performing a remediation action set based on the second determination.

9. The method of claim 8 , wherein the storage area associations specify that the initiator is not associated with the storage area.

10. The method of claim 9 , wherein the initiator of the data access request is an application of the at least one of the applications.

11. The method of claim 8 , wherein the data access request indicates an identity of the initiator and the storage area.

12. The method of claim 8 , wherein instantiating a composed information handling system of the composed information handling systems using a compute resource set that executes at least one of the applications and a hardware resource set that stores a portion of the data comprises preparing at least one control resource set to provide management services for the at least one compute resource set and the at least one hardware resource set.

13. The method of claim 12 , wherein the at least one control resource set comprises a system control processor.

14. The method of claim 13 , wherein the management services comprise:

intercepting data access requests from the at least one compute resource set by presenting the hardware resource set as bare metal resources; and

monitoring the applications to identify potentially compromised applications based on the intercepted data access requests and monitoring trigger events.

15. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for managing composed information handling systems to manage access to data by applications hosted by the composed information handling systems, the method comprising:

instantiating a composed information handling system of the composed information handling systems using an at least one compute resource set that executes hosts at least one of the applications and an at least one hardware resource set that stores a portion of the data;

associating, using authorization information, different storage areas of the at least one hardware resource set with the applications to obtain storage area associations;

obtaining a data access request from the at least one compute resource set for the portion of the data which is stored in a storage area of the storage areas;

making a determination, based on the storage area associations and an initiator of the data access request, that the initiator of the data access request is not authorized to access the portion of the data;

refusing, based on the determination, to service the data access request;

identifying a monitoring trigger event associated with monitoring modifications to the initiator, wherein the monitoring trigger event is the refusal to service the data access request;

in response to identifying the monitoring trigger event, making a second determination that the initiator was unknowingly modified; and

performing a remediation action set based on the second determination.

16. The non-transitory computer readable medium of claim 15 , wherein the storage area associations specify that the initiator is not associated with the storage area.

17. The non-transitory computer readable medium of claim 16 , wherein the initiator of the data access request is an application of the at least one of the applications.

18. The non-transitory computer readable medium of claim 15 , wherein the data access request indicates an identity of the initiator and the storage area.

19. The non-transitory computer readable medium of claim 15 , wherein instantiating a composed information handling system of the composed information handling systems using a compute resource set that executes at least one of the applications and a hardware resource set that stores a portion of the data comprises preparing at least one control resource set to provide management services for the at least one compute resource set and the at least one hardware resource set.

20. The non-transitory computer readable medium of claim 19 , wherein the at least one control resource set comprises a system control processor.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2021
From: SAAD, YOSSEF; SANDERS, MARK STEVEN; CHAWLA, GAURAV; KHATRI, MUKUND P.
To: DELL PRODUCTS L.P.
Reel/Frame 055109/0419 →