IP Library › Granted Patent US 12,450,364
Granted Patent B2
US 12,450,364 · App. 17/819,683 · Granted Oct 21, 2025

Selective encryption while loading from network attached storage system

Inventors: Shailendra Moyal (Pune, IN); Sarbajit K. Rakshit (Kolkata, IN); Partho Ghosh (Kolkata, IN)
Assignee: International Business Machines Corporation
G06F21/602G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,364
App. No.
17/819,683
Granted
Oct 21, 2025
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for selective dataset encryption is provided. The embodiment may include identifying one or more data items within one or more datasets to be moved from network attached storage to cloud-based storage. The embodiment may also include determining an encryption method to be performed on each data item based on a level of confidentiality or sensitivity of each data item. The embodiment may further include sorting each data item into one or more groups based on the determined encryption method. The embodiment may also include performing each determined encryption method to the corresponding group.

Claims (55)

1. A processor-implemented method, the method comprising:

identifying, by a processor, one or more unencrypted data items within one or more datasets to be moved from storage in a network attached storage system to storage in a cloud-based storage system;

determining an encryption method to be performed on each unencrypted data item based on a level of confidentiality or sensitivity of each unencrypted data item;

sorting each unencrypted data item into one or more groups based on the determined encryption method;

assigning a unique name to each sorted, unencrypted data item in accordance with a preconfigured naming structure; and

performing each determined encryption method to a corresponding group within the one or more groups.

2. The method of claim 1 , wherein the identifying further comprises:

tagging metadata associated with each data item with a location of the data item within an unencrypted dataset within the one or more datasets; and

extracting each data item from the the unencrypted dataset.

3. The method of claim 2 , further comprising:

transmitting each encrypted group to the cloud-based storage;

performing a decryption method corresponding to each encryption method for each group; and

inserting each data item from each decrypted group based on the location within the tagged metadata.

4. The method of claim 3 , wherein each encrypted group is transmitted with a corresponding decryption key.

5. The method of claim 1 , wherein the encryption method is further determined by one or more criteria selected from a group consisting of performance limitations of each encryption method in relation to the unencrypted data items to be encrypted, legal or industrial regulations that require certain methods of encryption, and individual user preferences and preconfigurations.

6. The method of claim 1 , further comprising:

identifying the level of confidentiality or sensitivity of each unencrypted data item through an extraction engine using natural language processing and/or tag-based identification.

7. The method of claim 1 , wherein the identifying is triggered upon one or more user interactions with a graphical user interface or by expiration of a preconfigured time period.

8. A computer system, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

identifying, by a processor, one or more unencrypted data items within one or more datasets to be moved from storage in a network attached storage system to storage in a cloud-based storage system;

determining an encryption method to be performed on each unencrypted data item based on a level of confidentiality or sensitivity of each unencrypted data item;

sorting each unencrypted data item into one or more groups based on the determined encryption method;

assigning a unique name to each sorted, unencrypted data item in accordance with a preconfigured naming structure; and

performing each determined encryption method to a corresponding group within the one or more groups.

9. The computer system of claim 8 , wherein the identifying further comprises:

tagging metadata associated with each data item with a location of the data item within an unencrypted dataset within the one or more datasets; and

extracting each data item from the the unencrypted dataset.

10. The computer system of claim 9 , further comprising:

transmitting each encrypted group to the cloud-based storage;

performing a decryption method corresponding to each encryption method for each group; and

inserting each data item from each decrypted group based on the location within the tagged metadata.

11. The computer system of claim 10 , wherein each encrypted group is transmitted with a corresponding decryption key.

12. The computer system of claim 8 , wherein the encryption method is further determined by one or more criteria selected from a group consisting of performance limitations of each encryption method in relation to the unencrypted data items to be encrypted, legal or industrial regulations that require certain methods of encryption, and individual user preferences and preconfigurations.

13. The computer system of claim 8 , further comprising:

identifying the level of confidentiality or sensitivity of each unencrypted data item through an extraction engine using natural language processing and/or tag-based identification.

14. The computer system of claim 8 , wherein the identifying is triggered upon one or more user interactions with a graphical user interface or by expiration of a preconfigured time period.

15. A computer program product, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor capable of performing a method, the method comprising:

identifying, by a processor, one or more unencrypted data items within one or more datasets to be moved from storage in a network attached storage system to storage in a cloud-based storage system;

determining an encryption method to be performed on each unencrypted data item based on a level of confidentiality or sensitivity of each unencrypted data item;

sorting each unencrypted data item into one or more groups based on the determined encryption method;

assigning a unique name to each sorted, unencrypted data item in accordance with a preconfigured naming structure; and

performing each determined encryption method to a corresponding group within the one or more groups.

16. The computer program product of claim 15 , wherein the identifying further comprises:

tagging metadata associated with each data item with a location of the data item within an unencrypted dataset within the one or more datasets; and

extracting each data item from the the unencrypted dataset.

17. The computer program product of claim 16 , further comprising:

transmitting each encrypted group to the cloud-based storage;

performing a decryption method corresponding to each encryption method for each group; and

inserting each data item from each decrypted group based on the location within the tagged metadata.

18. The computer program product of claim 17 , wherein each encrypted group is transmitted with a corresponding decryption key.

19. The computer program product of claim 15 , wherein the encryption method is further determined by one or more criteria selected from a group consisting of performance limitations of each encryption method in relation to the unencrypted data items to be encrypted, legal or industrial regulations that require certain methods of encryption, and individual user preferences and preconfigurations.

20. The computer program product of claim 15 , further comprising:

identifying the level of confidentiality or sensitivity of each unencrypted data item through an extraction engine using natural language processing and/or tag-based identification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2022
From: MOYAL, SHAILENDRA; RAKSHIT, SARBAJIT K.; GHOSH, PARTHO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060804/0990 →
Continuity (1)
Related Publication 20240054236A1 · Feb 15, 2024
References Cited (44)
US 9614670B1 · Ghetti · 2017 [cited by examiner]
US 11393046B1 · McCluskey · 2022 [cited by examiner]
US 20070101123A1 · Kollmyer · 2007 [cited by examiner]
US 20130246808A1 · Orsini · 2013 [cited by examiner]
US 20140032925A1 · Panchbudhe · 2014 [cited by examiner]
US 20150365382A1 · Balakrishnan · 2015 [cited by examiner]
US 20160021109A1 · Jueneman · 2016 [cited by examiner]
US 20160306984A1 · Amarendran · 2016 [cited by examiner]
US 20170053125A1 · Savagaonkar · 2017 [cited by examiner]
US 20170063525A1 · Bacon · 2017 [cited by examiner]
US 20170093573A1 · Androulaki · 2017 [cited by examiner]
US 20170262645A1 · Gupta · 2017 [cited by examiner]
US 20180032446A1 · Amarendran · 2018 [cited by examiner]
US 20180232527A1 · Haager · 2018 [cited by examiner]
US 20180248887A1 · Sayed · 2018 [cited by examiner]
US 20180309739A1 · Kumhyr · 2018 [cited by examiner]
US 20190005248A1 · Krishnamurthy · 2019 [cited by examiner]
US 20190075087A1 · Baig · 2019 [cited by examiner]
US 20190253237A1 · Jezewski · 2019 [cited by examiner]
US 20200177370A1 · Jordan · 2020 [cited by examiner]
US 20200204361A1 · Fries · 2020 [cited by examiner]
US 20200344295A1 · Lindeman · 2020 [cited by examiner]
US 20210097894A1 · Iyer · 2021 [cited by examiner]
US 20210150038A1 · Valecha · 2021 [cited by examiner]
US 20210344485A1 · Levin · 2021 [cited by examiner]
US 20220103339A1 · Brooker · 2022 [cited by examiner]
US 20220191024A1 · Liu · 2022 [cited by examiner]
US 20220292221A1 · Sohail · 2022 [cited by examiner]
US 20220405416A1 · Liu · 2022 [cited by examiner]
US 20230108423A1 · Wisgo · 2023 [cited by examiner]
US 20230185934A1 · Seilnacht · 2023 [cited by examiner]
US 20230224159A1 · Meena · 2023 [cited by examiner]
US 20230259640A1 · Metzler · 2023 [cited by examiner]
US 20230336327A1 · Lu · 2023 [cited by examiner]
US 20230421351A1 · Yampolsky · 2023 [cited by examiner]
Lookabaugh, Tom, and Douglas C. Sicker. “Selective encryption for consumer applications.” IEEE communications magazine 42.5 (2004): 124-129. [cited by examiner]
Derler, David, et al. “Bloom filter encryption and applications to efficient forward-secret 0-RTT key exchange.” Journal of Cryptology 34 (2021): 1-59. [cited by examiner]
Author Unknown, “Loading CSV data from Cloud Storage,” Google Cloud, Accessed: May 17, 2022, https://cloud.google.com/bigquery/docs/loading-data-cloud-storage-csv, 21 pages. [cited by applicant]
Author Unknown, “Loading data to IBM Cloud,” IBM, Sep. 28, 2021, https://www.ibm.com/docs/en/db2woc?topic=data-loading-cloud, 4 pages. [cited by applicant]
Author Unknown, “What is a NAS device and how does it work?,” ioSafe, Accessed: May 17, 2022, https://iosafe.com/data-protection-topics/what-is-a-nas-device/, 8 pages. [cited by applicant]
Author Unknown, “What is network-attached storage?,” Red Hat, Mar. 8, 2018, https://www.redhat.com/en/topics/data-storage/network-attached-storage, 9 pages. [cited by applicant]
Buurst Staff, “Moving your on-Premises NAS to the Azure Cloud,” Buurst, Accessed: May 17, 2022, https://www.puurst.com/2016/06/06/on-premise-nas-azure-cloud/, 15 pages. [cited by applicant]
Horandner et al., “Selective end-to-end data-sharing in the cloud,” Journal of Banking and Financial Technology (2020) 4, Jul. 2, 2020, https://link.springer.com/article/10.1007/s42786-020-00017-y, pp. 139-157. [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, National Institute of Standards and Technology, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]