IP Library Granted Patent US 12,229,018
Granted Patent B2
US 12,229,018 · App. 17/343,531 · Granted Feb 18, 2025

Restricted data transfer

Inventors: Michael Roche (Hamilton, CA); Michal Drozd (Windsor, CA); Scott Quesnelle (Burlington, CA)
Assignee: EMC IP Holding Company LLC
G06F11/1464G06F11/1451G06F11/1469H04L63/102H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,018
App. No.
17/343,531
Granted
Feb 18, 2025
Kind
B2
Abstract

One example method includes receiving, by a first computing entity from a second computing entity, a request for data, providing, by the first computing entity, a compliance API (Application Program Interface) to the second computing entity, receiving, by the first computing entity from the second computing entity, location information and/or data compliance information, by way of the compliance API, consulting, by the first computing entity, a mapping, and determining, based on information in the mapping and the location information and/or data compliance information, whether or not the data is permitted to be transmitted by the first computing entity to the second computing entity, and either transmitting the data to the second computing entity, or not transmitting the data to the second computing entity, based on data tags, the information in the mapping and the location information and/or data compliance information.

Claims (36)

1. A method performed by a backup application, said method comprising:

setting a compliance lock for a primary volume of the backup application, wherein the compliance lock is set using a compliance API (Application program interface) provided by a storage device, and wherein the compliance lock prevents requests to copy or replicate the primary volume;

adding an additional tag to the compliance lock;

receiving, from the storage device, a request for data controlled by the backup application;

providing access to the compliance API to the storage device;

receiving from the storage device, location information and/or data compliance information by way of the compliance API;

consulting a mapping and determining, based on information in the mapping and the data compliance information, whether or not the data is permitted to be transmitted by the backup application to the storage device;

when the data compliance information and the additional tag both indicate that transmission of the data is permitted, transmitting the data to the storage device; and

when the data compliance information indicates the transmission of the data is permitted but the additional tag indicates the transmission of the data is not permitted, preventing the transmission of the data to the storage device such that the additional tag is independently evaluated relative to the data compliance information and such that the transmission of the data occurs when both the data compliance information and the additional tag indicate the transmission of the data is permitted.

2. The method as recited in claim 1 wherein transmitting the data comprises transferring the data, or replicating the data.

3. The method as recited in claim 1 , wherein the data is tagged with a geo tag and/or a compliance tag.

4. The method as recited in claim 3 , wherein the geo tag indicates a geographical location to which the data is permitted to be transmitted, and the compliance tag indicates a data compliance standard that governs handling of the data.

5. The method as recited in claim 1 , wherein the backup application and the storage device have a trust relationship with each other.

6. The method as recited in claim 1 , wherein the storage device comprises a mapping that relates a volume of the storage device to a particular geographical location and/or to a particular data compliance standard.

7. The method as recited in claim 1 , wherein the mapping consulted by the backup application relates the primary volume of the backup application to a particular geographical location and/or to a particular data compliance standard.

8. The method as recited in claim 1 , wherein the data comprises a saveset created by a backup application.

9. The method as recited in claim 1 , wherein the additional tag indicates a geographical location, from which backup data was generated.

10. The method as recited in claim 1 , wherein the additional tag is independent of a data compliance standard that governs handling of the data.

11. A non-transitory computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to cause a backup application to perform operations comprising:

setting a compliance lock for a primary volume of the backup application, wherein the compliance lock is set using a compliance API (Application program interface) provided by a storage device, and wherein the compliance lock prevents requests to copy or replicate the primary volume;

adding an additional tag to the compliance lock;

receiving, from the storage device, a request for data controlled by the backup application;

providing access to the compliance API to the storage device;

receiving, from the storage device, data compliance information by way of the compliance API;

consulting a mapping and determining, based on information in the mapping and the data compliance information, whether or not the data is permitted to be transmitted by the backup application to the storage device;

when the data compliance information and the additional tag both indicate that transmission of the data is permitted, transmitting the data to the storage device; and

when the data compliance information indicates the transmission of the data is permitted but the additional tag indicates the transmission of the data is not permitted, preventing the transmission of the data to the storage device such that the additional tag is independently evaluated relative to the data compliance information and such that the transmission of the data occurs when both the data compliance information and the additional tag indicate the transmission of the data is permitted.

12. The non-transitory computer readable storage medium as recited in claim 11 wherein transmitting the data comprises transferring the data, or replicating the data.

13. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data is tagged with a geo tag and/or a compliance tag.

14. The non-transitory computer readable storage medium as recited in claim 13 , wherein the geo tag indicates a geographical location to which the data is permitted to be transmitted, and the compliance tag indicates a data compliance standard that governs handling of the data.

15. The non-transitory computer readable storage medium as recited in claim 11 , wherein the backup application and the storage device have a trust relationship with each other.

16. The non-transitory computer readable storage medium as recited in claim 11 , wherein the storage device comprises a mapping that relates a volume of the storage device to a particular geographical location and/or to a particular data compliance standard.

17. The non-transitory computer readable storage medium as recited in claim 11 , wherein the mapping consulted by the backup application relates the primary volume of the backup application to a particular geographical location and/or to a particular data compliance standard.

18. The non-transitory computer readable storage medium as recited in claim 11 , wherein the data comprises a saveset created by a backup application.

19. The non-transitory computer readable storage medium as recited in claim 11 , wherein the additional tag indicates a geographical location, from which backup data was generated.

20. The non-transitory computer readable storage medium as recited in claim 11 , wherein the additional tag is independent of a data compliance standard that governs handling of the data.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2023
From: ROCHE, MICHAEL; DROZD, MICHAL; QUESNELLE, SCOTT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 063295/0781 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
Continuity (1)
Related Publication 20220398167A1 · Dec 15, 2022
References Cited (5)
US 20170364302A1 · Atherton · 2017 [cited by examiner]
US 20180322297A1 · Rodriguez Bravo · 2018 [cited by examiner]
US 20190332494A1 · Natanzon · 2019 [cited by examiner]
US 20200007579A1 · Barday · 2020 [cited by examiner]
US 20210084077A1 · Brannon · 2021 [cited by examiner]