IP Library Granted Patent US 12,212,622
Granted Patent B2
US 12,212,622 · App. 17/503,766 · Granted Jan 28, 2025

Data auditing for object storage public clouds

Inventor: Huamin Chen (Westborough, MA)
Assignee: Red Hat, Inc.
H04L67/1097G06F16/2365H04L67/56H04L67/562H04L67/564
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,622
App. No.
17/503,766
Granted
Jan 28, 2025
Kind
B2
Abstract

An example method for data auditing for object storage public clouds includes a service broker receiving a request to store data in public object storage, where the request includes user information or a container image. The service broker, based on either the user information or the container image, determines that data auditing is necessary. The service broker creates a storage unit, in public object storage, and a storage proxy. The method further includes the storage proxy storing data, and a data auditor retrieving data from the storage proxy. The data auditor determines a data qualification for the data, and notifies the storage proxy of the data qualification.

Claims (56)

1. A method comprising:

receiving, at a service broker, a request to store data in a public storage which includes at least one of (i) a block storage in which files are split into evenly sized blocks of data, and (ii) an object storage in which data is stored in objects in a flat structure, wherein the request includes at least one of user information or an image;

determining, by the service broker, based on the at least one of user information or the image, that data auditing is necessary;

creating, by the service broker, a storage unit in the object storage and a storage proxy;

storing, in the storage proxy, the data;

retrieving, by a data auditor, the data from the storage proxy;

determining, by the data auditor, a data qualification; and

notifying, by the data auditor, the storage proxy of the data qualification.

2. The method of claim 1 , wherein the data qualification is a compliance indication.

3. The method of claim 2 , further comprising:

sending the data, by the storage proxy, to the storage unit.

4. The method of claim 2 , further comprising:

sending storage unit credentials, by the service broker, to a user application, wherein the storage unit credentials include instructions for the user application to access the storage unit.

5. The method of claim 1 , wherein the data qualification is a flag, and wherein the flag indicates that the data includes information that should not be stored in the storage unit.

6. The method of claim 5 , further comprising:

sending, by the storage proxy, a notification of noncompliance to at least one of an administrator and an application.

7. The method of claim 5 , further comprising:

stopping, by the storage proxy, the data from being sent to the storage unit.

8. The method of claim 1 , further comprising:

updating, by the service broker, an endpoint for the data in a DNS server to be the storage proxy.

9. The method of claim 1 , wherein the request is sent by a user of an application.

10. The method of claim 1 , wherein the request is automatically sent by an application.

11. The method of claim 1 , further comprising:

labeling, by an administrator, the image with at least one workload type, wherein the at least one workload type corresponds to a category of information within the image.

12. The method of claim 11 , wherein the workload type is at least one of financial information, medical records, credit card numbers, banking information, telephone numbers, data mining information, email addresses, personal home addresses, personal records, relationship information, and source code.

13. The method of claim 11 , further comprising:

reading, by the storage proxy, the workload type; and

sending, by the storage proxy, the data to a first data auditor of a plurality of data auditors.

14. The method of claim 1 , further comprising:

preconfiguring, by an administrator, rules within the data auditor, wherein the rules determine the data qualification.

15. The method of claim 1 , further comprising:

monitoring, by the storage proxy, the data to ensure that data stored within the storage proxy reflects data updates.

16. A system comprising:

one or more processors;

a storage proxy;

a data auditor;

a service broker executing on the one or more processors, wherein the service broker is configured to:

receive a request to store data in a public storage which includes at least one of (i) a block storage in which files are split into evenly sized blocks of data, and (ii) an object storage in which data is stored in objects in a flat structure, wherein the request includes at least one of user information or an image,

determine that data auditing is necessary based on the at least one of user information or the image, and

create a storage unit in the object storage and the storage proxy,

wherein the storage proxy is configured to:

store the data, and

wherein the data auditor is configured to:

retrieve the data from the storage proxy, determine a data qualification, and

notify the storage proxy of the data qualification.

17. The system of claim 16 , wherein the data qualification is at least one of a compliance indication or a flag.

18. The system of claim 17 , wherein the storage proxy reads a workload type from the image, and sends the data to a first data auditor of a plurality of data auditors.

19. The system of claim 17 , wherein the storage unit is a bucket.

20. A non-transitory machine readable medium storing instruction, which when executed by one or more physical processors, is configured to:

receive, at a service broker, a request to store data in a public storage which includes at least one of (i) a block storage in which files are split into evenly sized blocks of data, and (ii) an object storage in which data is stored in objects in a flat structure, wherein the request includes at least one of user information or an image;

determine, by the service broker, based on the at least one of user information or the image, that data auditing is necessary;

create, by the service broker, a storage unit in the object storage and a storage proxy;

store, in the storage proxy, the data;

retrieve, by a data auditor, the data from the storage proxy;

determine, by the data auditor, a data qualification; and

notify, by the data auditor, the storage proxy of the data qualification.

Assignments (2)
CHANGE OF NAME Recorded Mar 3, 2026
From: RED HAT, INC.
To: RED HAT, LLC
Reel/Frame 074913/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: CHEN, HUAMIN
To: RED HAT, INC.
Reel/Frame 057822/0204 →
Continuity (2)
Continuation 15683321 · Aug 22, 2017
Related Publication 20220038537A1 · Feb 3, 2022
References Cited (20)
US 9357331B2 · Huang · 2016 [cited by applicant]
US 9537650B2 · Auradkar et al. · 2017 [cited by applicant]
US 9575841B2 · Mason, Jr. et al. · 2017 [cited by applicant]
US 10795812B1 · Duggal et al. · 2020 [cited by applicant]
US 11704431B2 · Kraus · 2023 [cited by examiner]
US 11892418B1 · Featonby · 2024 [cited by examiner]
US 11907173B1 · Warfield · 2024 [cited by examiner]
US 20120258777A1 · Huang · 2012 [cited by applicant]
US 20130326579A1 · Bhatti et al. · 2013 [cited by applicant]
US 20150019858A1 · Roth et al. · 2015 [cited by applicant]
US 20160196324A1 · Haviv et al. · 2016 [cited by applicant]
US 20160371134A1 · Raghavendra et al. · 2016 [cited by applicant]
US 20170041296A1 · Ford et al. · 2017 [cited by applicant]
US 20170185793A1 · Rotem et al. · 2017 [cited by applicant]
US 20180129665A1 · Bach et al. · 2018 [cited by applicant]
US 20190377656A1 · Choe et al. · 2019 [cited by applicant]
How to Configure Encryption for Amazon S3; https://www.cloudera.com/documentation/enterprise/latest/topics/sg_aws_s3_encryption.html; , generated Jul. 26, 2017; pp. 1-5. [cited by applicant]
Configure Object Storage with the S3 API; https://docs.openstack.org/kilo/configreference/content/configuring-openstack-object-storage-with-s3_api.html; retrieved Jul. 31, 2017; pp. 1-2. [cited by applicant]
Codedellemc/Ecs-Cf-Service-Broker: Cloud Foundry Service Broker for EMC ECS Object Storage; https://github.com/codedellemc/ecs-cf-service-broker; retrieved Jul. 31, 2017; pp. 1-6. [cited by applicant]
Object Storage I NeCTAR Support; https://web.archive.org/web/20170217082940/http://support.rc.nectar.org.au/docs/object-storage; retrieved Aug. 22, 2017 (4 pages). [cited by applicant]