IP Library Granted Patent US 12,282,575
Granted Patent B2
US 12,282,575 · App. 17/859,720 · Granted Apr 22, 2025

Dynamic resolution and enforcement of data compliance

Inventors: Marcelo Yannuzzi (Vufflens-la-Ville, CH); Hervé Muyal (Gland, CH); Jean Andrei Diaconu (Haute-Savoie, FR); Frank Brockners (Cologne, DE); Carlos Goncalves Pereira (Carlsbad, CA)
Assignee: Cisco Technology, Inc.
G06F21/6218G06F9/543G06F21/60G06F16/24573G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,575
App. No.
17/859,720
Granted
Apr 22, 2025
Kind
B2
Abstract

In one embodiment, a device may obtain a location of an endpoint that communicates with an application service. The device may match the location of the endpoint to a data compliance policy. The device may identify sensitive data within the application service to which the data compliance policy applies. The device may configure the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy.

Claims (44)

1. A method comprising:

obtaining, by a device, a location of an endpoint that communicates with an application service, wherein the location of the endpoint is indicative of at least a geographical location of the endpoint;

matching, by the device, the location of the endpoint to a data compliance policy;

identifying, by the device, sensitive data within the application service to which the data compliance policy applies; and

configuring, by the device, the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy.

2. The method as in claim 1 , wherein the endpoint is authorized to at least one of access or send non-sensitive data via the application service regardless of its location.

3. The method as in claim 1 , wherein the sensitive data is flagged via annotations embedded into program code of the application service.

4. The method as in claim 3 , further comprising:

generating the data compliance policy based on the annotations embedded into program code of the application service.

5. The method as in claim 1 , wherein configuring the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy comprises:

sending token information to the application service for a token issued to the endpoint that is associated with the location.

6. The method as in claim 1 , further comprising:

querying the endpoint for its location according to a schedule as based on movement of the endpoint.

7. The method as in claim 1 , further comprising:

reconfiguring, by the device, the application service to prevent the endpoint from at least one of accessing or sending the sensitive data based on a new location of the endpoint.

8. The method as in claim 1 , wherein the application service is hosted in at least one of a cloud, an edge, or a private infrastructure.

9. The method as in claim 1 , wherein obtaining the location of the endpoint that accesses the application service comprises:

sending a challenge query to the endpoint for its location.

10. The method as in claim 1 , wherein the application service is executed in a data mesh.

11. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

obtain a location of an endpoint that communicates with an application service, wherein the location of the endpoint is indicative of at least a geographical location of the endpoint;

match the location of the endpoint to a data compliance policy;

identify sensitive data within the application service to which the data compliance policy applies; and

configure the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy.

12. The apparatus as in claim 11 , wherein the endpoint is authorized to at least one of access or send non-sensitive data via the application service regardless of its location.

13. The apparatus as in claim 11 , wherein the sensitive data is flagged via annotations embedded into program code of the application service.

14. The apparatus as in claim 13 , wherein the process when executed is further configured to:

generate the data compliance policy based on the annotations embedded into program code of the application service.

15. The apparatus as in claim 11 , wherein the application service is configured to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy by sending token information to the application service for a token issued to the endpoint that is associated with the location.

16. The apparatus as in claim 11 , wherein the process when executed is further configured to:

query the endpoint for its location according to a schedule as based on movement of the endpoint.

17. The apparatus as in claim 11 , wherein the process when executed is further configured to:

reconfigure the application service to prevent the endpoint from at least one of accessing or sending the sensitive data based on a new location of the endpoint.

18. The apparatus as in claim 11 , wherein the application service is hosted in at least one of a cloud, an edge, or a private infrastructure.

19. The apparatus as in claim 11 , wherein obtaining the location of the endpoint that accesses the application service comprises:

sending a challenge query to the endpoint for its location.

20. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

obtaining, by the device, a location of an endpoint that communicates with an application service, wherein the location of the endpoint is indicative of at least a geographical location of the endpoint;

matching, by the device, the location of the endpoint to a data compliance policy;

identifying, by the device, sensitive data within the application service to which the data compliance policy applies; and

configuring, by the device, the application service to permit the endpoint to at least one of access or send the sensitive data when permitted by the data compliance policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: YANNUZZI, MARCELO; MUYAL, HERVÉ; DIACONU, JEAN ANDREI; BROCKNERS, FRANK, DR.; GONCALVES PEREIRA, CARLOS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060434/0302 →
Continuity (1)
Related Publication 20240012921A1 · Jan 11, 2024
References Cited (52)
US 8850516B1 · Hrebicek · 2014 [cited by examiner]
US 9949129B1 · Henry et al. · 2018 [cited by applicant]
US 10713664B1 · Alagappan et al. · 2020 [cited by applicant]
US 10764357B1 · Bonczkowski · 2020 [cited by examiner]
US 11513910B2 · Natanzon · 2022 [cited by examiner]
US 11539709B2 · Bhaskar S · 2022 [cited by examiner]
US 20050021689A1 · Marvin et al. · 2005 [cited by applicant]
US 20070107043A1 · Newstadt · 2007 [cited by examiner]
US 20090099860A1 · Karabulut et al. · 2009 [cited by applicant]
US 20090183240A1 · Feather · 2009 [cited by examiner]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20140282840A1 · Guinan · 2014 [cited by examiner]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20160344736A1 · Khait et al. · 2016 [cited by applicant]
US 20170170970A1 · Leighton et al. · 2017 [cited by applicant]
US 20170171192A1 · Guinan · 2017 [cited by examiner]
US 20170201569A1 · Fu et al. · 2017 [cited by applicant]
US 20170300309A1 · Berger et al. · 2017 [cited by applicant]
US 20180027022A1 · Nagaratnam et al. · 2018 [cited by applicant]
US 20180096158A1 · Murphy · 2018 [cited by examiner]
US 20180124066A1 · Minkovich · 2018 [cited by examiner]
US 20180124113A1 · Lock · 2018 [cited by examiner]
US 20180212952A1 · Guinan · 2018 [cited by examiner]
US 20180260566A1 · Chaganti et al. · 2018 [cited by applicant]
US 20180276393A1 · Allen · 2018 [cited by examiner]
US 20180352003A1 · Winn · 2018 [cited by examiner]
US 20190014123A1 · Akireddy et al. · 2019 [cited by applicant]
US 20190228171A1 · Mathur · 2019 [cited by applicant]
US 20190332793A1 · Guinan · 2019 [cited by examiner]
US 20200293675A1 · Antonatos · 2020 [cited by examiner]
US 20200364351A1 · Sanchez et al. · 2020 [cited by applicant]
US 20210006972A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210152561A1 · Shelton et al. · 2021 [cited by applicant]
US 20210286638A1 · Fan et al. · 2021 [cited by applicant]
US 20210329001A1 · Barton · 2021 [cited by examiner]
US 20210360037A1 · Beckman et al. · 2021 [cited by applicant]
US 20220321362A1 · Konda · 2022 [cited by examiner]
US 20220345491A1 · Luo · 2022 [cited by examiner]
US 20230401332A1 · Vahidnia · 2023 [cited by examiner]
US 20240039959A1 · Yannuzzi · 2024 [cited by examiner]
US 20240176677A1 · Youssef · 2024 [cited by examiner]
“Global Apps, Local Compliance”, online: https://incountry.com/, accessed May 24, 2022, 10 pages. [cited by applicant]
“Global Cloud Service Provider”, online: https://us.ovhcloud.com/, accessed May 24, 2022, 11 pages. [cited by applicant]
“Google Distributed Cloud”, online: https://cloud.google.com/distributed-cloud, accessed May 24, 2022, 8 pages. [cited by applicant]
Kurian, Thomas, “How Google Cloud is addressing the need for data sovereignty in Europe in 2020”, online: https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europ… [cited by applicant]
“Gaia-X: A Federated Secure Data Infrastructure”, online: https://www.gaia-x.eu/, accessed May 24, 2022, 6 pages. [cited by applicant]
“RegTech 100”, online: https://fintech.global/regtech100/, accessed May 24, 2022, 14 pages. [cited by applicant]
“OneTrust Cloud Solutions”, online: https://www.onetrust.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Collibra—The Data Intelligence Cloud”, online: https://www.collibra.com/us/en, accessed May 24, 2022, 4 pages. [cited by applicant]
“LogicGate Risk Cloud”, online: https://www.logicgate.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Governance and Security for Low-Code/No-Code Applications”, online: https://www.zenity.io//, accessed May 24, 2022, 6 pages. [cited by applicant]
Zacks, et al., “Network Data Objectivization, Classification, Verification and Privacy via Ring-Oriented Metadata”, Defensive Publication Series, Jul. 2021, 11 pages, Technical Disclosure Commons. [cited by applicant]