IP Library Granted Patent US 12,554,849
Granted Patent B2
US 12,554,849 · App. 17/681,114 · Granted Feb 17, 2026

Dynamic data scan for object storage

Inventors: Yuval Lifshitz (Ra'anana, IL); Huamin Chen (Westboro, MA)
Assignee: Red Hat, Inc.
G06F21/565G06F21/566G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,849
App. No.
17/681,114
Granted
Feb 17, 2026
Kind
B2
Abstract

A first data object is received for storing in an object repository of a storage platform. An encryption value of the object repository is increased responsive to identifying that a current entropy level of the first data object exceeds a prior entropy level of the first data object by more than a first threshold value. Remediation is performed by a processing device on the object repository responsive to determining that the encryption value of the object repository exceeds a second threshold value.

Claims (46)

1 . A method comprising:

receiving a first data object for storing in a first object repository of a storage platform, wherein the first data object corresponds to an update to be performed on an original second data object stored within the first object repository, and wherein the first object repository comprises a logical grouping of data objects;

identifying that a current entropy level of the first data object exceeds a prior entropy level of the original second data object by more than a first threshold value, wherein the original second data object stored within the first object repository comprises:

metadata that stores the prior entropy level; and

data;

increasing an encryption value of the first object repository responsive to identifying that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, wherein the encryption value is a rate at which the data objects within the first object repository are encrypted;

determining that the encryption value of the first object repository exceeds a second threshold value, wherein the second threshold value is an encryption rate threshold value; and

performing, by a processing device, remediation on the first object repository responsive to determining that the encryption value of the first object repository exceeds the second threshold value, wherein performing the remediation on the first object repository comprises creating a copy of the second data object in a second object repository of the storage platform, and wherein the copy of the second data object has elevated access permissions compared to access permissions of the original second data object.

2 . The method of claim 1 , wherein performing the remediation on the first object repository comprises creating the copy of the second data object prior to storing the first data object in the first object repository.

3 . The method of claim 1 , wherein the first object repository comprises a plurality of data objects, and

wherein performing the remediation on the first object repository comprises creating a copy of each of the plurality of data objects of the first object repository prior to storing the first data object in the first object repository.

4 . The method of claim 1 , wherein performing the remediation on the first object repository comprises locking the first object repository for further write access.

5 . The method of claim 1 , wherein identifying that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, increasing the encryption value of the first object repository, and determining that the encryption value of the first object repository exceeds the second threshold value occur prior to storing the first data object in the first object repository of the storage platform.

6 . The method of claim 1 , wherein the first object repository is a plurality of object repositories, each of the plurality of object repositories comprising a plurality of data objects distributed among a plurality of object storage daemons (OSDs).

7 . The method of claim 1 , wherein the first data object and the original second data object are stored in a distributed format.

8 . A system comprising:

a processing device; and

a memory, operatively coupled to the processing device, that stores instructions that, when executed by the processing device, cause the processing device to:

receive a first data object for storing in a first object repository of a storage platform, wherein the first data object corresponds to an update to be performed on an original second data object stored within the first object repository, and wherein the first object repository comprises a logical grouping of data objects;

identify that a current entropy level of the first data object exceeds a prior entropy level of the original second data object by more than a first threshold value, wherein the original second data object stored within the first object repository comprises:

metadata that stores the prior entropy level; and

data;

increase an encryption value of the first object repository responsive to identifying that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, wherein the encryption value is a rate at which the data objects within the first object repository are encrypted;

determine that the encryption value of the first object repository exceeds a second threshold value, wherein the second threshold value is an encryption rate threshold value; and

perform remediation on the first object repository responsive to determining that the encryption value of the first object repository exceeds the second threshold value, wherein performing the remediation on the first object repository comprises creating a copy of the second data object in a second object repository of the storage platform, and wherein the copy of the second data object has elevated access permissions compared to access permissions of the original second data object.

9 . The system of claim 8 , wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to create the copy of the second data object prior to storing the first data object in the first object repository.

10 . The system of claim 8 , wherein the first object repository comprises a plurality of data objects, and

wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to create a copy of each of the plurality of data objects of the first object repository prior to storing the first data object in the first object repository.

11 . The system of claim 8 , wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to lock the first object repository for further write access.

12 . The system of claim 8 , wherein to identify that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, increase the encryption value of the first object repository, and determine that the encryption value of the first object repository exceeds the second threshold value, the instructions, when executed by the processing device, cause the processing device to identify that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, increase the encryption value of the first object repository, and determine that the encryption value of the first object repository exceeds the second threshold value prior to storage of the first data object in the first object repository of the storage platform.

13 . The system of claim 8 , wherein the first object repository is a plurality of object repositories, each of the plurality of object repositories comprising a plurality of data objects distributed among a plurality of object storage daemons (OSDs).

14 . The system of claim 8 , wherein the first data object and the original second data object are stored in a distributed format.

15 . A non-transitory computer-readable storage medium including instructions that, when executed by a processing device, cause the processing device to:

receive a first data object for storing in a first object repository of a storage platform, wherein the first data object corresponds to an update to be performed on an original second data object stored within the first object repository, and wherein the first object repository comprises a logical grouping of data objects;

identify that a current entropy level of the first data object exceeds a prior entropy level of the original second data object by more than a first threshold value, wherein the original second data object stored within the first object repository comprises:

metadata that stores the prior entropy level; and

data;

increase an encryption value of the first object repository responsive to identifying that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, wherein the encryption value is a rate at which the data objects within the first object repository are encrypted;

determine that the encryption value of the first object repository exceeds a second threshold value, wherein the second threshold value is an encryption rate threshold value; and

perform, by the processing device, remediation on the first object repository responsive to determining that the encryption value of the first object repository exceeds the second threshold value, wherein performing the remediation on the first object repository comprises creating a copy of the second data object in a second object repository of the storage platform, and wherein the copy of the second data object has elevated access permissions compared to access permissions of the original second data object.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to create the copy of the second data object prior to storage of the first data object in the first object repository.

17 . The non-transitory computer-readable storage medium of claim 15 ,

wherein the first object repository comprises a plurality of data objects, and wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to create a copy of each of the plurality of data objects of the first object repository prior to storage of the first data object in the first object repository.

18 . The non-transitory computer-readable storage medium of claim 15 , wherein to perform the remediation on the first object repository, the instructions, when executed by the processing device, cause the processing device to lock the first object repository for further write access.

19 . The non-transitory computer-readable storage medium of claim 15 , wherein to identify that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, increase the encryption value of the first object repository, and determine that the encryption value of the first object repository exceeds the second threshold value, the instructions, when executed by the processing device, cause the processing device to identify that the current entropy level of the first data object exceeds the prior entropy level of the original second data object by more than the first threshold value, increase the encryption value of the first object repository, and determine that the encryption value of the first object repository exceeds the second threshold value prior to storage of the first data object in the first object repository of the storage platform.

20 . The non-transitory computer-readable storage medium of claim 15 , wherein the first data object and the original second data object are stored in a distributed format.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2022
From: LIFSHITZ, YUVAL; CHEN, HUAMIN
To: RED HAT, INC.
Reel/Frame 059105/0680 →
Continuity (1)
Related Publication 20230273997A1 · Aug 31, 2023
References Cited (15)
US 10229269B1 · Patton · 2019 [cited by examiner]
US 10346610B1 · Natanzon · 2019 [cited by applicant]
US 10469525B2 · Hittel · 2019 [cited by examiner]
US 10516688B2 · Tamir · 2019 [cited by examiner]
US 10609066B1 · Nossik · 2020 [cited by examiner]
US 10819738B2 · Saad · 2020 [cited by examiner]
US 11023327B2 · Linnen · 2021 [cited by examiner]
US 20210019403A1 · Mehta · 2021 [cited by examiner]
US 20210019411A1 · Schmugar · 2021 [cited by examiner]
US 20210400057A1 · Devane · 2021 [cited by examiner]
US 20230060606A1 · Dubey · 2023 [cited by examiner]
US 20230169166A1 · Shachar · 2023 [cited by examiner]
Igor Trubin: “Impact Session Spotlight: Catching Anomaly and Normality in Cloud by Neural Net and Entropy Calculation”, Jan. 2019, 3 pages. [cited by applicant]
Lee et al.: “Machine Learning Based File entropy Analysis for Ransomware Detection in Backup Systems”, Aug. 22, 2019, 11 pages. [cited by applicant]
Davies et al: “Differential Area Analysis for Ransomware Attack Detection within Mixed File Datasets”, Jun. 28, 2021, 13 pages. [cited by applicant]