IP Library Granted Patent US 12,554,865
Granted Patent B2
US 12,554,865 · App. 18/422,827 · Granted Feb 17, 2026

Quorum-based authorization of requests associated with storage systems

Inventors: Ionut Dumitrascu (Prague, CZ); František Jahoda (Prague, CZ); Miroslav Kos (Prague, CZ); Lucie Kureckova (Klimkovice, CZ); Martin Schlemmer (Prague, CZ); Taher Vohra (Sunnyvale, CA); Paulo Marcon (Porto Alegre, BR); Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F21/602G06F3/0608G06F3/0652G06F3/067
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,865
App. No.
18/422,827
Filed
Jan 25, 2024
Granted
Feb 17, 2026
Kind
B2
Art Unit
2499
USPC
713/189
Abstract

An illustrative method includes detecting a request to perform a restricted operation with respect to a storage system; monitoring, in response to the request, for authorization events pertaining to the restricted operation and performed by a plurality of entities; detecting, while performing the monitoring, that a threshold plurality of the authorization events are performed by the plurality of entities; and directing, based on the detecting that the threshold plurality of authorization events are performed by the plurality of entities, the storage system to perform the restricted operation.

Claims (53)

1 . A method comprising:

detecting, by a storage management system, a request to perform a restricted operation with respect to a storage system;

monitoring, by the storage management system in response to the request, for authorization events pertaining to the restricted operation and performed by a plurality of entities;

detecting, by the storage management system while performing the monitoring, that a threshold plurality of the authorization events are performed by the plurality of entities;

directing, by the storage management system based on the detecting that the threshold plurality of authorization events are performed by the plurality of entities, the storage system to perform the restricted operation;

determining, by the storage management system, that a protection group associated with the storage system is disabled;

determining, by the storage management system based on the determining that the protection group associated with the storage system is disabled, that the storage system is possibly being targeted by a security threat; and

performing, by the storage management system based on the determining that the storage system is possibly being targeted by the security threat, a remedial action, the performing the remedial action comprising:

converting a recovery dataset into a protected recovery dataset that cannot be deleted without a specific instruction provided by an authorized entity;

determining, after the performing the remedial action, that the storage system is no longer possibly being targeted by the security threat; and

converting, based on the determining that the storage system is no longer possibly being targeted by the security threat, the protected recovery dataset back into the recovery dataset.

2 . The method of claim 1 , wherein the detecting that the threshold plurality of authorization events are performed by the plurality of entities comprises determining that each entity included in the plurality of entities logs into a cloud service associated with the storage management system and performs, while logged into the cloud service, an identity authentication procedure.

3 . The method of claim 1 , wherein the storage management system is implemented by a computing system communicatively coupled to the storage system by way of a network.

4 . The method of claim 1 , wherein the restricted operation comprises an operation with respect to a recovery dataset configured to be used by the storage system to recover from a data corruption event within the storage system.

5 . The method of claim 4 , wherein the operation with respect to the recovery dataset is configured to perform at least one of a deletion of the recovery dataset, a modification of the recovery dataset, a modification of a policy associated with the recovery dataset, or a modification of a parameter included in a data protection parameter set associated with the recovery dataset.

6 . The method of claim 4 , wherein the data corruption event comprises an attack by a bad actor against the storage system.

7 . The method of claim 1 , wherein the restricted operation comprises a modification of a policy that governs one or more operations performed with respect to the storage system.

8 . The method of claim 7 , wherein the policy identifies the plurality of entities.

9 . The method of claim 1 , wherein the storage management system is implemented by a controller within the storage system.

10 . The method of claim 1 , wherein the directing the storage system to perform the restricted operation is further based on the threshold plurality of authorization events being performed within a predetermined amount of time.

11 . The method of claim 1 , wherein the detecting that the threshold plurality of the authorization events are performed by the plurality of entities comprises detecting that the threshold plurality of the authorization events are performed by a majority of entities included in a set of entities having authorization to perform the authorization events.

12 . The method of claim 1 , wherein the detecting that the threshold plurality of the authorization events are performed by the plurality of entities comprises detecting that a first set of authorization events are performed by a first minimum threshold number of entities included in a first set of entities and that a second set of authorization events are performed by a second minimum threshold number of entities included in a second set of entities.

13 . The method of claim 1 , wherein:

the restricted operation comprises transmitting data from the storage system to an additional storage system; and

the detecting that the threshold plurality of the authorization events are performed by the plurality of entities comprises detecting that a first authorization event is performed by a first entity associated with the storage system and that a second authorization event is performed by a second entity associated with the additional storage system.

14 . A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

detecting a request to perform a restricted operation with respect to a storage system;

monitoring, in response to the request, for authorization events pertaining to the restricted operation and performed by a plurality of entities;

detecting, while performing the monitoring, that a threshold plurality of the authorization events are performed by the plurality of entities;

directing, based on the detecting that the threshold plurality of authorization events are performed by the plurality of entities, the storage system to perform the restricted operation;

determining that a protection group associated with the storage system is disabled;

determining, based on the determining that the protection group associated with the storage system is disabled, that the storage system is possibly being targeted by a security threat; and

performing, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action, the performing the remedial action comprising:

converting a recovery dataset into a protected recovery dataset that cannot be deleted without a specific instruction provided by an authorized entity;

determining, after the performing the remedial action, that the storage system is no longer possibly being targeted by the security threat; and

converting, based on the determining that the storage system is no longer possibly being targeted by the security threat, the protected recovery dataset back into the recovery dataset.

15 . The system of claim 14 , wherein the detecting that the threshold plurality of authorization events are performed by the plurality of entities comprises determining that each entity included in the plurality of entities logs into a cloud service and performs, while logged into the cloud service, an identity authentication procedure.

16 . The system of claim 14 , wherein the system is implemented by a computing system communicatively coupled to the storage system by way of a network.

17 . The system of claim 14 , wherein the restricted operation comprises an operation with respect to a recovery dataset configured to be used by the storage system to recover from a data corruption event within the storage system.

18 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

detecting a request to perform a restricted operation with respect to a storage system;

monitoring, in response to the request, for authorization events pertaining to the restricted operation and performed by a plurality of entities;

detecting, while performing the monitoring, that a threshold plurality of the authorization events are performed by the plurality of entities;

directing, based on the detecting that the threshold plurality of authorization events are performed by the plurality of entities, the storage system to perform the restricted operation;

determining that a protection group associated with the storage system is disabled;

determining, based on the determining that the protection group associated with the storage system is disabled, that the storage system is possibly being targeted by a security threat; and

performing, based on the determining that the storage system is possibly being targeted by the security threat, a remedial action, the performing the remedial action comprising:

converting a recovery dataset into a protected recovery dataset that cannot be deleted without a specific instruction provided by an authorized entity;

determining, after the performing the remedial action, that the storage system is no longer possibly being targeted by the security threat; and

converting, based on the determining that the storage system is no longer possibly being targeted by the security threat, the protected recovery dataset back into the recovery dataset.

19 . The computer program product of claim 18 , wherein the detecting that the threshold plurality of authorization events are performed by the plurality of entities comprises determining that each entity included in the plurality of entities logs into a cloud service associated with the storage management system and performs, while logged into the cloud service, an identity authentication procedure.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA PREVIOUSLY RECORDED ON REEL 66251 FRAME 126. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 30, 2025
From: DUMITRASCU, IONUT; JAHODA, FRANTISEK; KOS, MIROSLAV; KURECKOVA, LUCIE; SCHLEMMER, MARTIN; VOHRA, TAHER; MARCON, PAULO; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 074136/0904 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2024
From: DUMITRASCU, IONUT; JAHODA, FRANTI¿EK; KOS, MIROSLAV; KURECKOVA, LUCIE; SCHLEMMER, MARTIN; VOHRA, TAHER; MARCON, PAULO; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 066251/0126 →
Continuity (44)
Continuation In Part 18127926 · Mar 29, 2023
Continuation In Part 17980354 · Nov 3, 2022
Continuation In Part 17846301 · Jun 22, 2022
Continuation In Part 17725182 · Apr 20, 2022
Continuation In Part 17723903 · Apr 19, 2022
Continuation In Part 17541870 · Dec 3, 2021
Continuation In Part 17506509 · Oct 20, 2021
Continuation In Part 17506501 · Oct 20, 2021
Continuation In Part 17463088 · Aug 31, 2021
Continuation In Part 17409124 · Aug 23, 2021
Continuation In Part 17409130 · Aug 23, 2021
Continuation In Part 17409135 · Aug 23, 2021
Continuation In Part 17342203 · Jun 8, 2021
Continuation In Part 17235737 · Apr 20, 2021
Continuation 17161553 · Jan 28, 2021
Continuation In Part 17074313 · Oct 19, 2020
Continuation In Part 17039536 · Sep 30, 2020
Continuation In Part 17039604 · Sep 30, 2020
Continuation In Part 17039486 · Sep 30, 2020
Continuation In Part 17039556 · Sep 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16917030 · Jun 30, 2020
Continuation In Part 16916903 · Jun 30, 2020
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Continuation In Part 16711060 · Dec 11, 2019
Provisional Application 63442589 · Feb 1, 2023
Provisional Application 62985229 · Mar 4, 2020
Provisional Application 62939518 · Nov 22, 2019
Related Publication 20240193283A1 · Jun 13, 2024
References Cited (34)
US 7707176B2 · Schmidt · 2010 [cited by examiner]
US 8150806B2 · Boyd · 2012 [cited by examiner]
US 8468385B1 · Balachandriah · 2013 [cited by examiner]
US 9116862B1 · Rath · 2015 [cited by examiner]
US 9210178B1 · Roth · 2015 [cited by examiner]
US 9578006B2 · Balasubramanian · 2017 [cited by examiner]
US 10078836B2 · Tenenboym · 2018 [cited by examiner]
US 10503427B2 · Botes · 2019 [cited by examiner]
US 10530788B1 · Kinger · 2020 [cited by examiner]
US 10705732B1 · Bernat · 2020 [cited by examiner]
US 11120133B2 · Dontov · 2021 [cited by examiner]
US 11341256B2 · Kumbhashi · 2022 [cited by examiner]
US 11528607B2 · Adrangi · 2022 [cited by examiner]
US 11789651B2 · Pabón · 2023 [cited by examiner]
US 12236121B2 · Pabón · 2025 [cited by examiner]
US 20040243772A1 · Wissenbach · 2004 [cited by examiner]
US 20070067565A1 · Taninaka · 2007 [cited by examiner]
US 20080109822A1 · Chokshi · 2008 [cited by examiner]
US 20080284597A1 · Shah · 2008 [cited by examiner]
US 20090276833A1 · Paul · 2009 [cited by examiner]
US 20180341773A1 · Khatri · 2018 [cited by examiner]
US 20190179564A1 · Bernat · 2019 [cited by examiner]
US 20200021590A1 · Jeuk · 2020 [cited by examiner]
US 20200090090A1 · Padmanabhan · 2020 [cited by examiner]
US 20200311583A1 · Manamohan · 2020 [cited by examiner]
US 20200401325A1 · Lamba · 2020 [cited by examiner]
US 20210081216A1 · Komarov · 2021 [cited by examiner]
US 20210096957A1 · Rahman · 2021 [cited by examiner]
US 20210103490A1 · LeCrone · 2021 [cited by examiner]
US 20220150241A1 · Nadiminti · 2022 [cited by examiner]
US 20230273726A1 · Jagannati · 2023 [cited by examiner]
US 20230362172A1 · Mandagere · 2023 [cited by examiner]
US 20240012673A1 · Garbett · 2024 [cited by examiner]
International Search Report and Written Opinion for International Application No. PCT/US2023/023859, mailed Sep. 20, 2023, 13 pages. [cited by applicant]