IP Library Granted Patent US 12,282,585
Granted Patent B2
US 12,282,585 · App. 18/594,134 · Granted Apr 22, 2025

Controlling information privacy in a shared data storage management system

Inventors: Bhavyan Bharatkumar Mehta (Mumbai, IN); Anand Vibhor (Manalapan, NJ); Mrityunjay Upadhyay (Hyderabad, IN); Shree Nandhini Santhakumar (Kanyakumari, IN)
Assignee: Commvault Systems, Inc.
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,585
App. No.
18/594,134
Granted
Apr 22, 2025
Kind
B2
Abstract

An illustrative data storage management system uses a control layer that controls information content presented to users and ensures information privacy between diverse tenants and/or resellers who share the system. The system populates a relationship database as transactions roll in (intake processing), and uses information in the relationship database later when processing responses (output processing). The relationship database comprises associations between e.g., a company ID and any number of entities that were created by or on behalf of the company or that are related to the company's service in the system. The control layer parses raw results that are responsive to requests for information and prevents others' information from being included in the responsive message(s). The techniques disclosed herein are not limited to shared systems managed by service providers, and may be implemented in fully owned and operated systems to add security and privacy among diverse users and/or departments.

Claims (63)

1. A computer-implemented method comprising:

receiving a first transaction;

identifying a first company identifier of a first company that is associated with the first transaction;

based on a classification map that lists entities of a data storage management system, identifying a first entity of the data storage management system that is referenced in the first transaction,

wherein the data storage management system is shared by a plurality of companies, including the first company, wherein each company has a distinct company identifier in the data storage management system, generating one or more entries for a relationship database,

wherein the relationship database comprises associations between the first company identifier and a plurality of entities, including entities that are sub-tending to or related to the first entity,

wherein each of the one or more entries comprises the first entity referenced in the first transaction in association with the first company identifier;

adding the one or more entries to the relationship database;

receiving a request for information from a requester having a company identifier of the requester;

obtaining, from one or more components of the data storage management system, first information responsive to the request, wherein the first information references the first entity;

based on consulting the relationship database, determining that the first entity is associated with the first company identifier; and

based on determining that the company identifier of the requester is the same from the first company identifier associated with the first entity referenced in the first information responsive to the request, including an identifier of the first entity from a first response to the request provided to the requester.

2. The computer-implemented method of claim 1 , further comprising:

receiving an other request for information from a second requester having a company identifier of the second requester;

obtaining, from one or more components of the data storage management system, second information responsive to the other request, wherein the second information references the first entity;

based on consulting the relationship database, determining that the first entity is associated with the first company identifier; and

based on determining that the company identifier of the second requester is different from the first company identifier associated with the first entity referenced in the second information responsive to the other request, excluding an identifier of the first entity in a response to the other request provided to the second requester.

3. The computer-implemented method of claim 2 , further comprising: based on determining that the first information is classified as sensitive information, replacing the first information with a boilerplate message in the first response, wherein the first response lacks an identifier of the first entity.

4. The computer-implemented method of claim 1 , wherein the classification map comprises an association between the first entity and a second entity; and wherein the computer-implemented method further comprises:

generating one or more second entries for the relationship database, wherein each of the one or more second entries comprises the second entity in association with the first company identifier;

receiving an other request for information from a second requester having a company identifier of the second requester;

obtaining, from one or more components of the data storage management system, second information responsive to the other request, wherein the second information references the second entity;

based on consulting the relationship database, determining that the second entity is associated with the first company identifier; and

based on determining that the company identifier of the second requester is different from the first company identifier associated with the second entity referenced in the second information responsive to the other request, excluding an identifier of the second entity from a response to the other request provided to the second requester.

5. The computer-implemented method of claim 1 , wherein the request seeks one of more of: a query response, a report, a dashboard display, a log entry, a representational state transfer (REST) application programming interface (API) response, and a status.

6. The computer-implemented method of claim 1 , wherein the first transaction comprises receiving input for administering the first entity.

7. The computer-implemented method of claim 1 , wherein the first transaction comprises receiving a status of a job, wherein the job comprises one or more storage operations performed in the data storage management system.

8. The computer-implemented method of claim 1 , wherein the first transaction comprises receiving a log entry, an alert about a storage operation, input for administering the first entity, or a response to a message transmitted via a representational state transfer (REST) application programming interface (API).

9. The computer-implemented method of claim 1 , wherein the first transaction comprises receiving one or more of: an operational status from a component of the data storage management system, an upgrade status from a component of the data storage management system, a software version of a component of the data storage management system, a firmware version of a component of the data storage management system, a communication status from a component of the data storage management system.

10. The computer-implemented method of claim 1 , wherein the classification map comprises associations among a plurality of entities that comprises one or more of: a plan, a storage policy, a schedule policy, a client, a subclient, a data access node, and a storage pool.

11. An information management system, the information management system comprising:

one or more computing devices comprising computer hardware in networked communication with one or more media agents,

wherein the one or more computing devices and the one or more media agents execute in a cloud services environment,

wherein the one or more computing devices is configured to: receive a first transaction;

identify a first company identifier of a first company that is associated with the first transaction;

based on a classification map that lists entities of a data storage management system, identify a first entity of the data storage management system that is referenced in the first transaction,

wherein the data storage management system is shared by a plurality of companies, including the first company, wherein each company has a distinct company identifier in the data storage management system,

generating one or more entries for a relationship database,

wherein the relationship database comprises associations between the first company identifier and a plurality of entities, including entities that are sub-tending to or related to the first entity,

wherein each of the one or more entries comprises the first entity referenced in the first transaction in association with the first company identifier;

add the one or more entries to the relationship database;

receive a request for information from a requester having a company identifier of the requester;

obtain first information responsive to the request, wherein the first information references the first entity;

based on consulting the relationship database, determine that the first entity is associated with the first company identifier; and

based on determining that the company identifier of the requester is the same from the first company identifier associated with the first entity referenced in the first information responsive to the request, include an identifier of the first entity from a first response to the request provided to the requester.

12. The information management system of claim 11 , wherein the one or more computing devices is further configured to:

receive an other request for information from a second requester having a company identifier of the second requester;

obtain, from one or more components of the data storage management system, second information responsive to the other request, wherein the second information references the first entity;

based on consulting the relationship database, determine that the first entity is associated with the first company identifier; and

based on determining that the company identifier of the second requester is different from the first company identifier associated with the first entity referenced in the second information responsive to the other request, exclude an identifier of the first entity in a response to the other request provided to the second requester.

13. The information management system of claim 12 , wherein the one or more computing devices is further configured to: based on determining that the first information is classified as sensitive information, replacing the first information with a boilerplate message in the first response, wherein the first response lacks an identifier of the first entity.

14. The information management system of claim 11 , wherein the classification map comprises an association between the first entity and a second entity; and wherein the one or more computing devices is further configured to:

generate one or more second entries for the relationship database, wherein each of the one or more second entries comprises the second entity in association with the first company identifier;

receiving an other request for information from a second requester having a company identifier of the second requester;

obtaining, from one or more components of the data storage management system, second information responsive to the other request, wherein the second information references the second entity;

based on consulting the relationship database, determining that the second entity is associated with the first company identifier; and

based on determining that the company identifier of the second requester is different from the first company identifier associated with the second entity referenced in the second information responsive to the other request, excluding an identifier of the second entity from a response to the other request provided to the second requester.

15. The information management system of claim 11 , wherein the request seeks one of more of: a query response, a report, a dashboard display, a log entry, a representational state transfer (REST) application programming interface (API) response, and a status.

16. The information management system of claim 11 , wherein the first transaction comprises receiving input for administering the first entity.

17. The information management system of claim 11 , wherein the first transaction comprises receiving a status of a job, wherein the job comprises one or more storage operations performed in the data storage management system.

18. The information management system of claim 11 , wherein the first transaction comprises receiving a log entry, an alert about a storage operation, input for administering the first entity, or a response to a message transmitted via a representational state transfer (REST) application programming interface (API).

19. The information management system of claim 11 , wherein the first transaction comprises receiving one or more of: an operational status from a component of the data storage management system, an upgrade status from a component of the data storage management system, a software version of a component of the data storage management system, a firmware version of a component of the data storage management system, a communication status from a component of the data storage management system.

20. The information management system of claim 11 , wherein the classification map comprises associations among a plurality of entities that comprises one or more of: a plan, a storage policy, a schedule policy, a client, a subclient, a data access node, and a storage pool.

Assignments (2)
SUPPLEMENTAL CONFIRMATORY GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Apr 16, 2025
From: COMMVAULT SYSTEMS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 070864/0344 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2024
From: MEHTA, BHAVYAN BHARATKUMAR; VIBHOR, ANAND; UPADHYAY, MRITYUNJAY; SANTHAKUMAR, SHREE NANDHINI
To: COMMVAULT SYSTEMS, INC.
Reel/Frame 067327/0284 →
Continuity (2)
Continuation 17557530 · Dec 21, 2021
Related Publication 20240202363A1 · Jun 20, 2024
References Cited (161)
US 4084231A · Capozzi et al. · 1978 [cited by applicant]
US 4267568A · Dechant et al. · 1981 [cited by applicant]
US 4283787A · Chambers · 1981 [cited by applicant]
US 4417321A · Chang et al. · 1983 [cited by applicant]
US 4641274A · Swank · 1987 [cited by applicant]
US 4654819A · Stiffler et al. · 1987 [cited by applicant]
US 4686620A · Ng et al. · 1987 [cited by applicant]
US 4912637A · Sheedy et al. · 1990 [cited by applicant]
US 4995035A · Cole et al. · 1991 [cited by applicant]
US 5005122A · Griffin et al. · 1991 [cited by applicant]
US 5093912A · Dong et al. · 1992 [cited by applicant]
US 5133065A · Cheffetz et al. · 1992 [cited by applicant]
US 5193154A · Kitajima et al. · 1993 [cited by applicant]
US 5212772A · Masters · 1993 [cited by applicant]
US 5226157A · Nakano et al. · 1993 [cited by applicant]
US 5239647A · Anglin et al. · 1993 [cited by applicant]
US 5241668A · Eastridge et al. · 1993 [cited by applicant]
US 5241670A · Eastridge et al. · 1993 [cited by applicant]
US 5276860A · Fortier et al. · 1994 [cited by applicant]
US 5276867A · Kenley et al. · 1994 [cited by applicant]
US 5287500A · Stoppani, Jr. · 1994 [cited by applicant]
US 5301286A · Rajani · 1994 [cited by applicant]
US 5321816A · Rogan et al. · 1994 [cited by applicant]
US 5347653A · Flynn et al. · 1994 [cited by applicant]
US 5410700A · Fecteau et al. · 1995 [cited by applicant]
US 5420996A · Aoyagi · 1995 [cited by applicant]
US 5454099A · Myers et al. · 1995 [cited by applicant]
US 5559991A · Kanfi · 1996 [cited by applicant]
US 5642496A · Kanfi · 1997 [cited by applicant]
US 6418478B1 · Ignatius et al. · 2002 [cited by applicant]
US 6542972B2 · Ignatius et al. · 2003 [cited by applicant]
US 6658436B2 · Oshinsky et al. · 2003 [cited by applicant]
US 6721767B2 · De Meno et al. · 2004 [cited by applicant]
US 6760723B2 · Oshinsky et al. · 2004 [cited by applicant]
US 7003641B2 · Prahlad et al. · 2006 [cited by applicant]
US 7035880B1 · Crescenti et al. · 2006 [cited by applicant]
US 7107298B2 · Prahlad et al. · 2006 [cited by applicant]
US 7130970B2 · Devassy et al. · 2006 [cited by applicant]
US 7162496B2 · Amarendran et al. · 2007 [cited by applicant]
US 7174433B2 · Kottomtharayil et al. · 2007 [cited by applicant]
US 7246207B2 · Kottomtharayil et al. · 2007 [cited by applicant]
US 7315923B2 · Retnamma et al. · 2008 [cited by applicant]
US 7343453B2 · Prahlad et al. · 2008 [cited by applicant]
US 7389311B1 · Crescenti et al. · 2008 [cited by applicant]
US 7395282B1 · Crescenti et al. · 2008 [cited by applicant]
US 7440982B2 · Lu et al. · 2008 [cited by applicant]
US 7454569B2 · Kavuri et al. · 2008 [cited by applicant]
US 7490207B2 · Amarendran et al. · 2009 [cited by applicant]
US 7500053B1 · Kavuri et al. · 2009 [cited by applicant]
US 7529782B2 · Prahlad et al. · 2009 [cited by applicant]
US 7536291B1 · Vijayan Retnamma et al. · 2009 [cited by applicant]
US 7543125B2 · Gokhale · 2009 [cited by applicant]
US 7546324B2 · Prahlad et al. · 2009 [cited by applicant]
US 7603386B2 · Amarendran et al. · 2009 [cited by applicant]
US 7606844B2 · Kottomtharayil · 2009 [cited by applicant]
US 7613752B2 · Prahlad et al. · 2009 [cited by applicant]
US 7617253B2 · Prahlad et al. · 2009 [cited by applicant]
US 7617262B2 · Prahlad et al. · 2009 [cited by applicant]
US 7620710B2 · Kottomtharayil et al. · 2009 [cited by applicant]
US 7636743B2 · Erofeev · 2009 [cited by applicant]
US 7651593B2 · Prahlad et al. · 2010 [cited by applicant]
US 7657550B2 · Prahlad et al. · 2010 [cited by applicant]
US 7660807B2 · Prahlad et al. · 2010 [cited by applicant]
US 7661028B2 · Erofeev · 2010 [cited by applicant]
US 7734669B2 · Kottomtharayil et al. · 2010 [cited by applicant]
US 7747579B2 · Prahlad et al. · 2010 [cited by applicant]
US 7801864B2 · Prahlad et al. · 2010 [cited by applicant]
US 7809914B2 · Kottomtharayil et al. · 2010 [cited by applicant]
US 8156086B2 · Lu et al. · 2012 [cited by applicant]
US 8170995B2 · Prahlad et al. · 2012 [cited by applicant]
US 8229954B2 · Kottomtharayil et al. · 2012 [cited by applicant]
US 8230195B2 · Amarendran et al. · 2012 [cited by applicant]
US 8285681B2 · Prahlad et al. · 2012 [cited by applicant]
US 8307177B2 · Prahlad et al. · 2012 [cited by applicant]
US 8364652B2 · Vijayan et al. · 2013 [cited by applicant]
US 8370542B2 · Lu et al. · 2013 [cited by applicant]
US 8578120B2 · Attarde et al. · 2013 [cited by applicant]
US 8954446B2 · Vijayan Retnamma et al. · 2015 [cited by applicant]
US 9020900B2 · Vijayan Retnamma et al. · 2015 [cited by applicant]
US 9098495B2 · Gokhale · 2015 [cited by applicant]
US 9239687B2 · Vijayan et al. · 2016 [cited by applicant]
US 9444811B2 · Nara et al. · 2016 [cited by applicant]
US 9633033B2 · Vijayan et al. · 2017 [cited by applicant]
US 9639274B2 · Maranna et al. · 2017 [cited by applicant]
US 10228962B2 · Dornemann et al. · 2019 [cited by applicant]
US 10255143B2 · Vijayan et al. · 2019 [cited by applicant]
US 10592145B2 · Bedadala et al. · 2020 [cited by applicant]
US 10684924B2 · Kilaru et al. · 2020 [cited by applicant]
US 10983963B1 · Venkatasubramanian et al. · 2021 [cited by applicant]
US 20060224846A1 · Amarendran et al. · 2006 [cited by applicant]
US 20090319534A1 · Gokhale · 2009 [cited by applicant]
US 20100332456A1 · Prahlad et al. · 2010 [cited by applicant]
US 20120150818A1 · Vijayan Retnamma et al. · 2012 [cited by applicant]
US 20120150826A1 · Vijayan Retnamma et al. · 2012 [cited by applicant]
US 20140201170A1 · Vijayan et al. · 2014 [cited by applicant]
US 20160350391A1 · Vijayan et al. · 2016 [cited by applicant]
US 20170168903A1 · Dornemann et al. · 2017 [cited by applicant]
US 20170185488A1 · Kumarasamy et al. · 2017 [cited by applicant]
US 20170192866A1 · Vijayan et al. · 2017 [cited by applicant]
US 20170193003A1 · Vijayan et al. · 2017 [cited by applicant]
US 20170235647A1 · Kilaru et al. · 2017 [cited by applicant]
US 20170242871A1 · Kilaru et al. · 2017 [cited by applicant]
US 20190108341A1 · Bedhapudi et al. · 2019 [cited by applicant]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210209176A1 · Pogrebezky et al. · 2021 [cited by applicant]
US 20210216983A1 · Glickman et al. · 2021 [cited by applicant]
US 20220035949A1 · Blum et al. · 2022 [cited by applicant]
US 20220053002A1 · Chu et al. · 2022 [cited by applicant]
US 20220114198A1 · Erett et al. · 2022 [cited by applicant]
US 20220222147A1 · Mitkar · 2022 [cited by examiner]
US 20220222215A1 · Kumarasamy · 2022 [cited by examiner]
US 20220239740A1 · Vibhor · 2022 [cited by examiner]
US 20220245034A1 · Nara · 2022 [cited by examiner]
US 20220245105A1 · Attarde · 2022 [cited by examiner]
US 20220247815A1 · Pradhan · 2022 [cited by examiner]
US 20220283989A1 · Bedadala · 2022 [cited by examiner]
US 20220292187A1 · Bhagi · 2022 [cited by examiner]
US 20220318199A1 · Bhagi · 2022 [cited by examiner]
US 20220345524A1 · Mitkar · 2022 [cited by examiner]
US 20220350922A1 · Blum et al. · 2022 [cited by applicant]
US 20220414103A1 · Upadhyay · 2022 [cited by examiner]
US 20230004294A1 · Dwarampudi · 2023 [cited by examiner]
US 20230004670A1 · Langseth et al. · 2023 [cited by applicant]
US 20230032790A1 · Mahajan · 2023 [cited by examiner]
US 20230043336A1 · Mitkar · 2023 [cited by examiner]
US 20230106269A1 · Mitkar · 2023 [cited by examiner]
US 20230107511A1 · Mitkar · 2023 [cited by examiner]
US 20230109510A1 · Polimera · 2023 [cited by examiner]
US 20230109690A1 · Mutha · 2023 [cited by examiner]
US 20230147671A1 · Narulkar · 2023 [cited by examiner]
US 20230153010A1 · Kapadia · 2023 [cited by examiner]
US 20230153438A1 · Bhagi · 2023 [cited by examiner]
US 20230168970A1 · Pradhan · 2023 [cited by examiner]
US 20230168971A1 · Mehta · 2023 [cited by applicant]
US 20230168976A1 · Kumar · 2023 [cited by applicant]
US 20230188431A1 · Esposito et al. · 2023 [cited by applicant]
US 20230195800A1 · Singh · 2023 [cited by applicant]
US 20230236938A1 · Nara · 2023 [cited by applicant]
US 20230236940A1 · Zakharkin · 2023 [cited by applicant]
US 20230251940A1 · Pramod · 2023 [cited by applicant]
US 20230251945A1 · Polimera · 2023 [cited by applicant]
US 20230315681A1 · Saurabh · 2023 [cited by applicant]
US 20230325104A1 · Ashraf · 2023 [cited by applicant]
US 20230388274A1 · Polimera · 2023 [cited by applicant]
US 20230393961A1 · Degaonkar · 2023 [cited by applicant]
EP 0259912A1 · 1988 [cited by applicant]
EP 0405926A2 · 1991 [cited by applicant]
EP 0467546A2 · 1992 [cited by applicant]
EP 0541281A2 · 1993 [cited by applicant]
EP 0774715A1 · 1997 [cited by applicant]
EP 0809184A1 · 1997 [cited by applicant]
EP 0899662A1 · 1999 [cited by applicant]
EP 0981090A1 · 2000 [cited by applicant]
WO 9513580A1 · 1995 [cited by applicant]
WO 9912098A1 · 1999 [cited by applicant]
WO 2006052872A2 · 2006 [cited by applicant]
Arneson, “Mass Storage Archiving in Network Environments,” Digest of Papers, Ninth IEEE Symposium on Mass Storage Systems, Oct. 31, 1988 Nov. 3, 1988, pp. 45-50, Monterey, CA. [cited by applicant]
Cabrera et al., “ADSM: A Multi-Platform, Scalable, Backup and Archive Mass Storage System,” Digest of Papers, Compcon '95, Proceedings of the 40th IEEE Computer Society International Conference, Mar. 5, 1995-Mar. 9, 199… [cited by applicant]
Eitel, “Backup and Storage Management in Distributed Heterogeneous Environments,” IEEE, Jun. 12-16, 1994, pp. 124-126. [cited by applicant]
Huff, KL, “Data Set Usage Sequence Number,” IBM Technical Disclosure Bulletin, vol. 24, No. 5, Oct. 1981 New York, US, pp. 2404-2406. [cited by applicant]
Rosenblum et al., “The Design and Implementation of a Log-Structure File System,” Operating Systems Review SIGOPS, vol. 25, No. 5, May 1991, New York, US, pp. 1-15. [cited by applicant]
Cited By (1)
US 12,639,467