IP Library Granted Patent US 11,803,519
Granted Patent B2
US 11,803,519 · App. 17/231,706 · Granted Oct 31, 2023

Method and system for managing and securing subsets of data in a large distributed data store

Inventors: Subramanian Ramesh (San Jose, CA); Jaspaul Singh Chahal (Fremont, CA)
Assignee: Dataguise, Inc.
G06F16/182
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,803,519
App. No.
17/231,706
Granted
Oct 31, 2023
Kind
B2
Abstract

A system groups multiple entities in a large distributed data store (DDS), such as directories and files, into a subset called a domain. The domain is treated as a unit for defining policies to detect and treat sensitive data. Sensitive data can be defined by enterprise or industry. Treatment of sensitive data may include quarantining, masking, and encrypting, of the data or the entity containing the data. Data in a domain can be copied as a unit, with or without the same structure, and with transformations such as masking or encryption, into parts of the same DDS or to a different DDS. Domains can be the unit of access control for organizations, and assigned tags useful for identifying their purpose, ownership, location, or other characteristics. Policies and operations, assigned at the domain level, may vary from domain to domain, but within a domain are uniform, except for specific exclusions.

Claims (22)

1. A system for managing data in a Distributed Data Store (DDS), said system including:

a Distributed Data Store (DDS), wherein said DDS includes a first domain, wherein said first domain comprises a first set of a plurality of data entities, wherein said first set of a plurality of data entities includes one or more directories, files, collections, documents, or other logical units of data,

wherein said plurality of data entities of said first set are marked as being part of said first domain; and

wherein said DDS includes a second domain, wherein said second domain comprises a second set of a plurality of data entities, wherein said second set of a plurality of data entities includes one or more directories, files, collections, documents, or other logical units of data,

wherein said plurality of data entities of said second set are marked as being part of said second domain; and

a repository storing first metadata relating to said first domain, wherein said first metadata identifies said first domain and identifies a set of first properties of said first domain,

wherein said set of first properties includes an identification of at least one first sensitive data type,

wherein said repository includes at least one first policy assigned to said at least one first sensitive data type,

said repository also storing second metadata relating to said second domain, wherein said second metadata identifies said second domain and identifies a set of second properties of said second domain, wherein said set of second properties is different from said set of first properties

wherein said set of second properties includes an identification of at least one second sensitive data type,

wherein said repository includes at least one second policy assigned to said at least one second sensitive data type,

wherein data is managed in said DDS by scanning said first domain by applying said identification of said at least one first sensitive data type to said first set of a plurality of data entities to identify at least one data entity of said first set of a plurality of data entities as belonging to said at least one first sensitive data type,

retrieving said at least one first policy assigned to said at least one first sensitive type, and

applying said at least one first policy to said at least one data entity of said first set of a plurality of data entities belonging to said at least one first sensitive data type, and

scanning said second domain by applying said identification of said at least one second sensitive data type to said second set of a plurality of data entities to identify at least one data entity of said second set of a plurality of data entities as belonging to said at least one second sensitive data type,

retrieving said at least one second policy assigned to said at least one second sensitive type, and

applying said at least one second policy to said at least one data entity of said second set of a plurality of data entities belonging to said at least one second sensitive data type.

2. The system of claim 1 wherein at least one of said at least one first policy assigned to said at least one first sensitive data type and said at least one second policy assigned to said at least one second sensitive data type includes masking at least one of said at least one first sensitive data type and said at least one second sensitive data type.

3. The system of claim 1 wherein at least one of said at least one first policy assigned to said at least one first sensitive data type and said at least one second policy assigned to said at least one second sensitive data type includes encrypting at least one of said at least one first sensitive data type and said at least one second sensitive data type.

4. The system of claim 1 wherein at least one of said at least one first policy assigned to said at least one first sensitive data type and said at least one second policy assigned to said at least one second sensitive data type includes quarantining at least one of said at least one first sensitive data type and said at least one second sensitive data type.

5. The system of claim 1 wherein said at least one first sensitive data type and said at least one second sensitive data type are one of credit card numbers, social security numbers, medical record numbers, addresses, names of patients, names high net-worth individuals, driver's license numbers, and bank account numbers.

6. The system of claim 1 wherein said repository is outside said DDS.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 3, 2025
From: BMO BANK N.A. (F/K/A BMO HARRIS BANK N.A.), AS AGENT
To: DATAGUISE, INC.
Reel/Frame 071307/0355 →
SECURITY INTEREST Recorded Jun 2, 2025
From: DATAGUISE, INC.
To: AUDAX PRIVATE DEBT LLC, AS AGENT
Reel/Frame 071279/0520 →
PATENT SECURITY AGREEMENT Recorded Jan 3, 2023
From: DATAGUISE, INC.
To: BMO HARRIS BANK N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 062256/0756 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2021
From: RAMESH, SUBRAMANIAN; CHAHAL, JASPAUL SINGH
To: DATAGUISE, INC.
Reel/Frame 057051/0462 →
Continuity (3)
Continuation 14216840 · Mar 17, 2014
Provisional Application 61793584 · Mar 15, 2013
Related Publication 20210232546A1 · Jul 29, 2021