IP Library › Granted Patent US 12,242,633
Granted Patent B2
US 12,242,633 · App. 17/658,797 · Granted Mar 4, 2025

Regulation based protection of data for storage systems

Inventors: Pierpaolo Tommasi (Dublin, IE); Marco Simioni (Dublin, IE); Stephane Deparis (Dublin, IE)
Assignee: International Business Machines Corporation
G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,633
App. No.
17/658,797
Granted
Mar 4, 2025
Kind
B2
Abstract

Embodiments for providing enhanced data protection for storage systems in a computing environment by a processor. One or more queries received by a storage system may be identified. Approval or denial of transmission of data with the storage system may be regulated in relation to the one or more queries based a queried metadata and a plurality of rules and administrative policies.

Claims (57)

1. A method, by a processor, for providing enhanced data protection for storage systems in a computing environment, comprising:

identifying one or more queries received by a storage system;

fetching metadata comprising a geographical position of a user issuing the one or more queries;

defining each of the plurality of rules and administrative policies, wherein the plurality of rules or administrative policies apply operations which comprise legal, ethical, moral, or jurisdictional rules or policies, and wherein the defining further comprises:

defining the plurality of rules and administrative policies to one or more operations to perform for preserving data security; and

applying the plurality of rules and administrative policies to a write operation or a read operation using a machine learning operation;

parsing, concurrently to fetching the metadata, the one or more queries;

regulating approval or denial of transmission of data responsive to the one or more queries from the storage system a plurality of rules and administrative policies; and

in response to approval of the transmission, transmitting the data.

2. The method of claim 1 , wherein the metadata is further selected from a group consisting of a query history, geographical positions of one or more servers, and privacy data.

3. The method of claim 1 , further including suggesting one or more additional rules and administrative policies to update or replace one or more of the plurality of rules and administrative policies.

4. The method of claim 1 , further including allowing the transmission of the data based on feedback data.

5. The method of claim 1 , further including:

identifying one or more data patterns, user behavior patterns, or a combination thereof; and

providing one or more alerts suggesting one or more additional rules and administrative policies based on the one or more data patterns, the user behavior patterns, or a combination thereof.

6. The method of claim 1 , further including:

monitoring and tracking the data associated with the storage system; and

learning one or more data patterns, user behavior patterns, rules and administrative policies, and metadata a machine learning operation.

7. A system providing enhanced data protection for storage systems in a computing environment, comprising:

one or more computers with executable instructions that when executed cause the system to:

identify one or more queries received by a storage system; and

fetch metadata comprising a geographical position of a user issuing the one or more queries;

define each of the plurality of rules and administrative policies, wherein the plurality of rules or administrative policies apply operations which comprise legal, ethical, moral, or jurisdictional rules or policies, and wherein the defining further comprises:

define the plurality of rules and administrative policies to one or more operations to perform for preserving data security; and

apply the plurality of rules and administrative policies to a write operation or a read operation using a machine learning operation;

parse, concurrently to fetching the metadata, the one or more queries;

regulate approval or denial of transmission of data responsive to the one or more queries from the storage system a plurality of rules and administrative policies; and

in response to approval of the transmission, transmit the data.

8. The system of claim 7 , wherein the metadata is further selected from a group consisting of a query history, geographical positions of one or more servers, and privacy data.

9. The system of claim 7 , wherein the executable instructions when executed cause the system to suggest one or more additional rules and administrative policies to update or replace one or more of the plurality of rules and administrative policies.

10. The system of claim 7 , wherein the executable instructions when executed cause the system to allow the transmission of the data based on feedback data.

11. The system of claim 7 , wherein the executable instructions when executed cause the system to:

identify one or more data patterns, user behavior patterns, or a combination thereof; and

provide one or more alerts suggesting one or more additional rules and administrative policies based on the one or more data patterns, the user behavior patterns, or a combination thereof.

12. The system of claim 7 , wherein the executable instructions when executed cause the system to:

monitor and tracking the data associated with the storage system; and

learn one or more data patterns, user behavior patterns, rules and administrative policies, and metadata a machine learning operation.

13. A computer program product for providing enhanced data protection for storage systems in a computing environment, the computer program product comprising:

one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instruction comprising:

program instructions to identify one or more queries received by a storage system; and

program instructions to fetch metadata comprising a geographical position of a user issuing the one or more queries;

program instructions to define each of the plurality of rules and administrative policies, wherein the plurality of rules or administrative policies apply operations which comprise legal, ethical, moral, or jurisdictional rules or policies, and wherein the defining further comprises:

program instructions to define the plurality of rules and administrative policies to one or more operations to perform for preserving data security; and

program instructions to apply the plurality of rules and administrative policies to a write operation or a read operation using a machine learning operation;

program instructions to parse, concurrently to fetching the metadata, the one or more queries;

program instructions to regulate approval or denial of transmission of data responsive to the one or more queries from the storage system a plurality of rules and administrative policies; and

in response to approval of the transmission, program instructions to transmit the data.

14. The computer program product of claim 13 , wherein the metadata is further selected from a group consisting of a query history, geographical positions of one or more servers, and privacy data.

15. The computer program product of claim 13 , further including program instructions to:

suggest one or more additional rules and administrative policies to update or replace one or more of the plurality of rules and administrative policies.

16. The computer program product of claim 13 , further including program instructions to allow the transmission of the data based on feedback data.

17. The computer program product of claim 13 , further including program instructions to:

identify one or more data patterns, user behavior patterns, or a combination thereof; and

provide one or more alerts suggesting one or more additional rules and administrative policies based on the one or more data patterns, the user behavior patterns, or a combination thereof.

18. The computer program product of claim 13 , further including program instructions to:

monitor and tracking the data associated with the storage system; and

learn one or more data patterns, user behavior patterns, rules and administrative policies, and metadata a machine learning operation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2022
From: TOMMASI, PIERPAOLO; SIMIONI, MARCO; DEPARIS, STEPHANE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 059565/0134 →
Continuity (1)
Related Publication 20230325523A1 · Oct 12, 2023
References Cited (22)
US 7082456B2 · Mani-Meitav · 2006 [cited by examiner]
US 7243097B1 · Agrawal · 2007 [cited by examiner]
US 7748027B2 · Patrick · 2010 [cited by applicant]
US 9275065B1 · Ganesh · 2016 [cited by examiner]
US 9760075B2 · Peterson et al. · 2017 [cited by applicant]
US 10223523B2 · Fram · 2019 [cited by applicant]
US 10726148B2 · Hughes · 2020 [cited by examiner]
US 10853329B2 · Thereska et al. · 2020 [cited by applicant]
US 11023615B2 · Larson et al. · 2021 [cited by applicant]
US 20090300002A1 · Thomas · 2009 [cited by examiner]
US 20150271666A1 · Arunachalam · 2015 [cited by examiner]
US 20180018590A1 · Szeto · 2018 [cited by examiner]
US 20200327252A1 · McFall et al. · 2020 [cited by applicant]
US 20200389495A1 · Crabtree et al. · 2020 [cited by applicant]
US 20210248252A1 · Darji · 2021 [cited by examiner]
EP 1089200A2 · 2001 [cited by examiner]
Celdran et al., “Protector: Towards the protection of sensitive data in Europe and the US,” Computer Networks 181, DOI:10.1016/j.comnet.2020.107448, 2020, 25 pages. [cited by applicant]
Istvan et al., “Software-Defined Data Protection: Low Overhead Policy Compliance at the Storage Layer is Within Reach!,” Proceedings of the VLDB Endowment 14, No. 7 (2021): 1167-1174. (8 pages). [cited by applicant]
Ardagna et al., “Privacy-enhanced Location-based Access Control”, Handbook of Database Security, pp. 531-552, Mar. 2007, DOI:10.1007/978-0-387-48533-1_22, (22 pages). [cited by applicant]
Sanchez Navarro, Francisco, “Location based service restrictions for Android devices”, Bachelor Thesis, University of Madrid, Computer Engineering, Feb. 2012/2013, (114 pages). [cited by applicant]
Mokbel, Mohamed F., “Towards Privacy-Aware Location-Based Database Servers”, 22nd International Conference on Data Engineering Workshops (ICDEW'06), 2006, pp. 93-93, DOI: 10.1109/ICDEW.2006.152 (10 pages). [cited by applicant]
Wikipedia, “Geo-blocking”, https://en.wikipedia.org/wiki/Geo-blocking, Accessed on Apr. 11, 2022, (8 pages). [cited by applicant]