IP Library Patent Application 18627730
Patent Application
App. No. 18/627,730

Implementing Volume-Level Access Policies In Storage Systems

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/627,730
Abstract

Data protection for container storage, including: assigning, to a container storage volume of a storage system, a volume-level access policy; and determining whether to allow access to the container storage volume based on the volume-level access policy and one or more attributes of a request for the access, including allowing the access responsive to the one or more attributes meeting the volume-level access policy or denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

Claims (33)

1 - 20 . (canceled)

21 . A method comprising:

determining, by a computing device comprising at least one processor and memory, whether to issue a request to access a container storage volume based on a volume-level access policy assigned to the container storage volume that indicates one or more allowable storage operations, and a storage operation attribute of the request; and

based on the determination, issuing the request.

22 . The method of claim 21 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

23 . The method of claim 21 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

24 . The method of claim 21 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

25 . The method of claim 21 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

26 . The method of claim 21 further comprising locking the container storage volume.

27 . The method of claim 21 further comprising receiving, by a storage management service, information describing data stored in the container storage volume.

28 . The method of claim 21 , further comprising:

receiving another request to change the volume-level access policy to another volume-level access policy; and

allowing the other request responsive to the other volume-level access policy being more restrictive than the volume-level access policy.

29 . An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

determining, by a computing device comprising at least one processor and memory, whether to issue a request to access a container storage volume based on a volume-level access policy assigned to the container storage volume that indicates one or more allowable storage operations, and a storage operation attribute of the request; and

based on the determination, issuing the request.

30 . The apparatus of claim 29 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

31 . The apparatus of claim 29 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

32 . The apparatus of claim 29 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

33 . The apparatus of claim 29 , wherein the volume-level access policy indicates a data sensitivity level and the one or more attributes comprise a security level.

34 . The apparatus of claim 29 , wherein the steps further comprise:

receiving another request to modify the volume-level access policy to another volume-level access policy; and

allowing the other request responsive to the other volume-level access policy being more restrictive than the volume-level access policy.

35 . A computer program product disposed upon a non-transitory computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

determining, by a computing device comprising at least one processor and memory, whether to issue a request to access a container storage volume based on a volume-level access policy assigned to the container storage volume that indicates one or more allowable storage operations, and a storage operation attribute of the request; and

based on the determination, issuing the request.

36 . The computer program product of claim 35 , wherein determining whether to allow access to the container storage volume comprises allowing the access responsive to the one or more attributes meeting the volume-level access policy.

37 . The computer program product of claim 35 , wherein determining whether to allow access to the container storage volume comprises denying the access responsive to the one or more attributes failing to meet the volume-level access policy.

38 . The computer program product of claim 35 , wherein the volume-level access policy indicates one or more geographic access permissions and the one or more attributes comprise a source of the request.

39 . The computer program product of claim 35 , wherein the steps further comprise:

receiving another request to modify the volume-level access policy to another volume-level access policy; and

allowing the other request responsive to the other volume-level access policy being more restrictive than the volume-level access policy.

40 . The computer program product of claim 35 further comprising receiving, by a storage management service, information describing data stored in the container storage volume.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2024
From: EKINS, RONALD
To: PURE STORAGE, INC.
Reel/Frame 067030/0793 →