IP Library Granted Patent US 12,393,706
Granted Patent B2
US 12,393,706 · App. 17/364,131 · Granted Aug 19, 2025

Classifying data and enforcing data access control using a context-based hierarchical policy

Inventors: Farida Shafik (Cairo, EG); Joel Christner (San Jose, CA); Nicole Reineke (Northborough, MA)
Assignee: EMC IP Holding Company LLC
G06F21/62G06F16/164H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,706
App. No.
17/364,131
Granted
Aug 19, 2025
Kind
B2
Abstract

One example method includes receiving a request from a user to access data stored in a filesystem, in response to the request, retrieving metadata of the data and metadata of the user, validating the metadata of the data and the metadata of the user against a data access rule, and granting the user access to the data upon successful validation of the metadata of the data and the metadata of the user.

Claims (32)

1. A method, comprising:

receiving a request from a user to access data stored in a filesystem;

generating access request metadata based on the request from the user;

in response to the request, retrieving metadata of the data and metadata of the user;

validating the metadata of the data, the metadata of the user, and the access request metadata against a data access rule which is an element of a context-based hierarchical policy, and the data access rule follows the data and is enforced by an entity external to the data, wherever the data is located, and the data access rule is enforced regardless of how the data is requested to be accessed;

granting the user access to the data upon successful validation of the metadata of the data and the metadata of the user; and

when a kernel underlying the filesystem, and operable to perform data access checks in conjunction with a security provider and communicate data access decisions, erroneously generates an indication to the filesystem that access to the data should be granted to the user, overriding the indication and denying access to the data by the user.

2. The method as recited in claim 1 , wherein access to the data by the user is granted or denied based on a combination of user identity and content of the data.

3. The method as recited in claim 1 , wherein other data in a same folder as the data is not accessible to the user.

4. The method as recited in claim 1 , wherein the metadata of the data is updated and stored, automatically, in response to a change to the data.

5. The method as recited in claim 1 , wherein the data access rule is updated automatically in response to a change in the data, and the data access rule is enforceable immediately after it has been updated.

6. The method as recited in claim 1 , wherein the metadata includes annotations that are based on content of the data.

7. The method as recited in claim 1 , wherein the data metadata is generated according to one or more rules.

8. The method as recited in claim 1 , wherein the data access rule is applicable at an individual data object level.

9. The method as recited in claim 1 , wherein the access request comprises a request to read the data or a request to write to the data.

10. A non-transitory computer readable storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving a request from a user to access data stored in a filesystem;

generating access request metadata based on the request from the user;

in response to the request, retrieving metadata of the data and metadata of the user;

validating the metadata of the data, the metadata of the user, and the access request metadata against a data access rule which is an element of a context-based hierarchical policy, and the data access rule follows the data and is enforced by an entity external to the data, wherever the data is located, and the data access rule is enforced regardless of how the data is requested to be accessed;

granting the user access to the data upon successful validation of the metadata of the data and the metadata of the user; and

when a kernel underlying the filesystem, and operable to perform data access checks in conjunction with a security provider and communicate data access decisions, erroneously generates an indication to the filesystem that access to the data should be granted to the user, overriding the indication and denying access to the data by the user.

11. The non-transitory computer readable storage medium as recited in claim 10 , wherein access to the data by the user is granted or denied based on a combination of user identity and content of the data.

12. The non-transitory computer readable storage medium as recited in claim 10 , wherein other data in a same folder as the data is not accessible to the user.

13. The non-transitory computer readable storage medium as recited in claim 10 , wherein the metadata of the data is updated and stored, automatically, in response to a change to the data.

14. The non-transitory computer readable storage medium as recited in claim 10 , wherein the data access rule is updated automatically in response to a change in the data, and the data access rule is enforceable immediately after it has been updated.

15. The non-transitory computer readable storage medium as recited in claim 10 , wherein the metadata includes annotations that are based on content of the data.

16. The non-transitory computer readable storage medium as recited in claim 10 , wherein the data metadata is generated according to one or more rules.

17. The non-transitory computer readable storage medium as recited in claim 10 , wherein the data access rule is applicable at an individual data object level.

18. The non-transitory computer readable storage medium as recited in claim 10 , wherein the access request comprises a request to read the data or a request to write to the data.

19. The method as recited in claim 1 , wherein prior to receipt of the request, the data was modified by a user other than the user who requested access to the data.

20. The non-transitory computer readable storage medium as recited in claim 10 , wherein prior to receipt of the request, the data was modified by a user other than the user who requested access to the data.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2021
From: SHAFIK, FARIDA; CHRISTNER, JOEL; REINEKE, NICOLE
To: EMC IP HOLDING COMPANY
Reel/Frame 056723/0171 →
Continuity (1)
Related Publication 20230004663A1 · Jan 5, 2023
References Cited (9)
US 20090300712A1 · Kaufmann · 2009 [cited by examiner]
US 20120324237A1 · D'Souza · 2012 [cited by examiner]
US 20160292445A1 · Lindemann · 2016 [cited by examiner]
US 20190268379A1 · Narayanaswamy · 2019 [cited by examiner]
US 20210073179A1 · Berman · 2021 [cited by examiner]
US 20210126823A1 · Poess · 2021 [cited by examiner]
US 20210303714A1 · Yaghoobi · 2021 [cited by examiner]
US 20220103566A1 · Faulkner · 2022 [cited by examiner]
WO WO2022011144A1 · 2022 [cited by examiner]