IP Library Granted Patent US 11,954,220
Granted Patent B2
US 11,954,220 · App. 17/579,296 · Granted Apr 9, 2024

Data protection for container storage

Inventor: Ronald Ekins (Haywards Heath, GB)
Assignee: PURE STORAGE, INC.
G06F21/6218G06F21/604G06F2221/2111G06F2221/2113G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,954,220
App. No.
17/579,296
Granted
Apr 9, 2024
Kind
B2
Abstract

Data protection for container storage, including: assigning, to a container storage volume of a storage system, a volume-level access policy; and determining whether to allow access to the container storage volume based on the volume-level access policy and one or more attributes of a request for the access, including allowing the access responsive to the one or more attributes meeting the volume-level access policy or denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

Claims (37)

1. A method comprising:

assigning, by a computing device comprising at least one processor and memory, to a container storage volume, a volume-level access policy that indicates one or more allowable storage operations, wherein the container storage volume is presented to one or more containers by a storage management service;

receiving, by the computing device, a request to access the container storage volume;

determining, by the computing device, whether to allow access to the container storage volume based on the volume-level access policy and one or more attributes that comprise a type of storage operation of the request;

responsive to determining to allow access to the container storage volume, issuing, by the computing device, from the storage management service to a storage resource, the request;

responsive to determining not to allow access to the container storage volume, preventing, by the computing device, the request from being serviced by the storage resource;

receiving, by the computing device, a request to modify the volume-level access policy to an updated volume-level access policy; and

denying, by the computing device, the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.

2. The method of claim 1 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

3. The method of claim 1 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

4. The method of claim 1 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

5. The method of claim 1 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

6. The method of claim 1 further comprising locking the container storage volume.

7. The method of claim 1 further comprising receiving, by the storage management service, information describing data stored in the container storage volume.

8. The method of claim 1 , further comprising:

receiving another request to modify the updated volume-level access policy to another updated volume-level access policy; and

allowing the other request responsive to the other updated volume-level access policy being more restrictive than the updated volume-level access policy.

9. An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

assigning, to a container storage volume of a storage system, a volume-level access policy that indicates one or more allowable storage operations;

determining whether to allow access to the container storage volume based on the volume-level access policy and one or more attributes that comprise a type of storage operation of a request for the access;

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.

10. The apparatus of claim 9 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

11. The apparatus of claim 9 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

12. The apparatus of claim 9 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

13. The apparatus of claim 9 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

14. The apparatus of claim 9 , wherein the steps further comprise:

receiving another request to modify the updated volume-level access policy to another updated volume-level access policy; and

allowing the other request responsive to the other updated volume-level access policy being more restrictive than the updated volume-level access policy.

15. A computer program product disposed upon a non-transitory computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

assigning, to a container storage volume of a storage system, a volume-level access policy that indicates one or more allowable storage operations;

determining whether to allow access to the container storage volume based on the volume-level access policy and one or more attributes that comprise a type of storage operation of a request for the access;

receiving a request to modify the volume-level access policy to an updated volume-level access policy; and

denying the request responsive to the updated volume-level access policy being less restrictive than the volume-level access policy.

16. The computer program product of claim 15 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

17. The computer program product of claim 15 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

18. The computer program product of claim 15 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: EKINS, RONALD
To: PURE STORAGE, INC.
Reel/Frame 058698/0770 →
Continuity (8)
Continuation In Part 16952614 · Nov 19, 2020
Continuation In Part 17022702 · Sep 16, 2020
Continuation In Part 16175221 · Oct 30, 2018
Continuation In Part 16050698 · Jul 31, 2018
Provisional Application 62750764 · Oct 25, 2018
Provisional Application 62695433 · Jul 9, 2018
Provisional Application 62674570 · May 21, 2018
Related Publication 20220215111A1 · Jul 7, 2022
Cited By (2)
US 12,547,752 US 12,656,954