IP Library Granted Patent US 12,244,713
Granted Patent B2
US 12,244,713 · App. 18/363,974 · Granted Mar 4, 2025

Snapshot transfer for cloud-based storage across accounts

Inventors: Steven P. Long (Glen Allen, VA); Volkan Senkaynak (Wilmington, DE)
Assignee: Capital One Services, LLC
H04L9/321G06F16/128G06F21/602H04L9/0819H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,713
App. No.
18/363,974
Granted
Mar 4, 2025
Kind
B2
Abstract

In some implementations, a system may receive a first credential associated with a first account and a second credential associated with a second account and may instruct a cloud service, using the first credential, to generate a first snapshot of structured source data associated with the first account. The system may authorize the first account and the second account to use a master encryption key and instruct the cloud service to encrypt the first snapshot using the master encryption key. The system may instruct the cloud service, using the second credential, to copy the first snapshot to a second snapshot associated with the second account and to decrypt the second snapshot into structured target data using the master encryption key. The system may deauthorize the first account and the second account from using the master encryption key and output an indicator of completion to a user device.

Claims (50)

1. A device, comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

authorize a first account and a second account to use a master encryption key;

provide instructions to a cloud service to encrypt a first snapshot of the first account using the master encryption key;

provide instructions to the cloud service, using a credential associated with the second account, to copy the first snapshot to a second snapshot associated with the second account;

provide instructions to the cloud service to decrypt the second snapshot using the master encryption key and generate structured data, associated with the second account, based on the decryption; and

deauthorize, based on a condition associated with a quantity of jobs related to at least one of the first account or the second account being satisfied, the first account and the second account from using the master encryption key; and

output an indication associated with completion.

2. The device of claim 1 , wherein the credential is a second credential, and

wherein the first snapshot is generated based on a first credential associated with the first account.

3. The device of claim 1 , wherein the first snapshot is associated with structured data.

4. The device of claim 1 , wherein the structured data is structured target data, and

wherein the first snapshot is associated with structured source data that comprises a relational data structure with a schema or metadata.

5. The device of claim 1 , wherein the master encryption key is associated with a third account associated with the cloud service.

6. The device of claim 1 , wherein the one or more processors are further configured to:

encrypt the structured data based on a local encryption key associated with the second account.

7. The device of claim 1 , wherein the cloud service is configured to schedule execution of the instructions based on a load balancer.

8. A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

authorize a first account and a second account to use a master encryption key;

provide instructions to a cloud service to encrypt a first snapshot of the first account using the master encryption key;

provide instructions to the cloud service, using a credential associated with the second account, to copy the first snapshot to a second snapshot associated with the second account;

provide instructions to the cloud service to decrypt the second snapshot using the master encryption key and generate structured data, associated with the second account, based on the decryption;

deauthorize, based on a condition associated with a quantity of jobs related to at least one of the first account or the second account being satisfied, the first account and the second account from using the master encryption key; and

output an indication associated with completion.

9. The non-transitory computer-readable medium of claim 8 , wherein the credential is a second credential, and

wherein the first snapshot is generated based on a first credential associated with the first account.

10. The non-transitory computer-readable medium of claim 8 , wherein the first snapshot is associated with the structured data.

11. The non-transitory computer-readable medium of claim 8 , wherein the generated structured data is structured target data, and

wherein the first snapshot is associated with structured source data that comprises a relational data structure with a schema or metadata.

12. The non-transitory computer-readable medium of claim 8 , wherein the master encryption key is associated with a third account associated with the cloud service.

13. The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions further cause the device to:

encrypt the generated structured data based on a local encryption key associated with the second account.

14. The non-transitory computer-readable medium of claim 8 , wherein the one or more instructions further cause the device to schedule execution of the instructions based on a load balancer.

15. A method, comprising:

authorizing, by a device, a first account and a second account to use a master encryption key;

providing, by the device, instructions to a cloud service to encrypt a first snapshot of the first account using the master encryption key;

providing, by the device, instructions to the cloud service, using a credential associated with the second account, to copy the first snapshot to a second snapshot associated with the second account;

providing, by the device, instructions to the cloud service to decrypt the second snapshot using the master encryption key and generate structured data, associated with the second account, based on the decryption;

deauthorizing, by the device, and based on a condition associated with a quantity of jobs related to at least one of the first account or the second account being satisfied, the first account and the second account from using the master encryption key; and

outputting, by the device, an indication associated with completion.

16. The method of claim 15 , wherein the credential is a second credential, and

wherein the first snapshot is generated based on a first credential associated with the first account.

17. The method of claim 15 , wherein the first snapshot is associated with the structured data.

18. The method of claim 15 , wherein the generated structured data is structured target data, and

wherein the first snapshot is associated with structured source data that comprises a relational data structure with a schema or metadata.

19. The method of claim 15 , wherein the master encryption key is associated with a third account associated with the cloud service.

20. The method of claim 15 , further comprising:

encrypting the generated structured data based on a local encryption key associated with the second account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2023
From: LONG, STEVEN P.; SENKAYNAK, VOLKAN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 064469/0127 →
Continuity (2)
Continuation 17132276 · Dec 23, 2020
Related Publication 20230379158A1 · Nov 23, 2023
References Cited (5)
US 10346618B1 · Ah Kun · 2019 [cited by examiner]
US 20150319144A1 · Barton · 2015 [cited by examiner]
US 20190132299A1 · Tucker · 2019 [cited by examiner]
US 20220200804A1 · Long et al. · 2022 [cited by applicant]
Burrough M., “Pentesting Azure Applications,” No Starch Press, San Francisco, 2018, 209 pages. [cited by applicant]