IP Library › Granted Patent US 12,639,260
Granted Patent B2
US 12,639,260 · App. 18/759,520 · Granted May 26, 2026

Intelligent protection of computing snapshots

Inventors: Daniel Mark Rogers (Atherton, CA); Soham Mazumdar (San Francisco, CA); Michael Wronski (Johns Creek, GA); Inderpal Arora (Sunol, CA); Mudit Malpani (Sunnyvale, CA); Vasu Murthy (San Jose, CA)
Assignee: Rubrik, Inc.
G06F16/125G06F16/128G06F21/568
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,260
App. No.
18/759,520
Filed
Jun 28, 2024
Granted
May 26, 2026
Kind
B2
Art Unit
2164
USPC
707/694
Abstract

A data management system (DMS) may support intelligent snapshot protection techniques. For example, the DMS may backup a computing system and facilitate that capture and storage of snapshots of the computing system. The DMS may identify a deletion event associated with one or more of the snapshots, the deletion event being associated with the one or more snapshots being deleted at a first time. The DMS may determine that deletion event is anomalous and retain the one or more snapshots beyond the first time. For example, the DMS may determine that one or more parameters associated with the deletion event are indicative of the deletion event being anomalous. In response, the DMS may retain the one or more snapshots for a retention period beyond the first time.

Claims (50)

1 . A method, comprising:

receiving a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:

under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and

under the first retention policy, the one or more snapshots of the computing system would be nonexpired within the duration;

changing from the first retention policy to the second retention policy based at least in part on receiving the request; and

outputting, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.

2 . The method of claim 1 , further comprising:

verifying, based at least in part on outputting the indication that the one or more snapshots for the computing system are being retained, whether the expiration of the one or more snapshots was non-anomalous based at least in part on a multiple-party verification procedure; and

deleting, in response to verifying the expiration of the one or more snapshots was non-anomalous, the one or more snapshots.

3 . The method of claim 1 , further comprising:

identifying, based at least in part on changing the first retention policy to the second retention policy, a deletion event associated with the one or more snapshots of the computing system as a result of the one or more snapshots being expired under the second retention policy.

4 . The method of claim 3 , further comprising:

retaining, despite the deletion event occurring for the one or more snapshots, the one or more snapshots based at least in part on the one or more snapshots expiring within the duration after changing the first retention policy to the second retention policy.

5 . The method of claim 3 , further comprising:

determining, based at least in part on identifying the deletion event associated with the one or more snapshots of the computing system, that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous.

6 . The method of claim 5 , wherein determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous comprises:

determining that the one or more snapshots were generated within a threshold duration after the request to change the first retention policy to the second retention policy.

7 . The method of claim 5 , wherein determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous comprises:

determining that a quantity of the one or more snapshots satisfies a threshold quantity.

8 . The method of claim 5 , wherein a determination that the deletion event is anomalous is based at least in part on a capacity of a storage entity used to store the one or more snapshots.

9 . The method of claim 5 , further comprising:

retaining, in response to determining that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous, the one or more snapshots for a second duration.

10 . The method of claim 1 , further comprising:

storing the one or more retained snapshots in a second storage entity that is different than a first storage entity used to store the one or more snapshots, the second storage entity being associated with a greater access latency than the first storage entity; and

deleting the one or more retained snapshots from the first storage entity.

11 . The method of claim 1 , further comprising:

generating a data structure accessible by a user of the computing system that includes respective indications of the one or more retained snapshots.

12 . A data management system, comprising:

one or more processors; and

one or more memories storing instructions executable, individually or collectively, by the one or more processors to cause the data management system to:

receive a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:

under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and

under the first retention policy, the one or more snapshots of the plurality of snapshots of the computing system would be nonexpired within the duration;

change, from the first retention policy to the second retention policy based at least in part on receiving the request; and

output, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.

13 . The data management system of claim 12 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:

identify, based at least in part on changing the first retention policy to the second retention policy, a deletion event associated with the one or more snapshots of the computing system as a result of the one or more snapshots being expired under the second retention policy.

14 . The data management system of claim 13 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:

retain, despite the deletion event occurring for the one or more snapshots, the one or more snapshots based at least in part on the one or more snapshots expiring within the duration after changing the first retention policy to the second retention policy.

15 . The data management system of claim 13 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:

determine, based at least in part on identifying the deletion event associated with the one or more snapshots of the computing system, that the one or more parameters associated with the deletion event are indicative of the deletion event being anomalous.

16 . The data management system of claim 12 , wherein the instructions are executable, individually or collectively, by the one or more processors to cause the data management system to:

store the one or more retained snapshots in a second storage entity that is different than a first storage entity used to store the one or more snapshots, the second storage entity being associated with a greater access latency than the first storage entity; and

delete the one or more retained snapshots from the first storage entity.

17 . A non-transitory, computer-readable medium storing code that comprises instructions executable, individually or collectively, by one or more processors of a data management system to cause the data management system to:

receive a request to change a first retention policy for retaining a plurality of snapshots of a computing system to a second retention policy for retaining the plurality of snapshots of the computing system, wherein:

under the second retention policy, one or more snapshots of the plurality of snapshots of the computing system expire within a duration after changing the first retention policy to the second retention policy; and

under the first retention policy, the one or more snapshots of the plurality of snapshots of the computing system would be nonexpired within the duration;

change, from the first retention policy to the second retention policy based at least in part on receiving the request; and

output, based at least in part on changing the first retention policy to the second retention policy, an indication that the one or more snapshots of the plurality of snapshots for the computing system are being retained despite being expired under the second retention policy, wherein the indication is based at least in part on one or more parameters associated with an expiration of the one or more snapshots being indicative of the expiration of the one or more snapshots being anomalous.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2025
From: ROGERS, DANIEL MARK; MAZUMDAR, SOHAM; WRONSKI, MICHAEL; ARORA, INDERPAL; MALPANI, MUDIT; MURTHY, VASU
To: RUBRIK, INC.
Reel/Frame 070135/0686 →
Continuity (2)
Continuation 17972371 · Oct 24, 2022
Related Publication 20240354287A1 · Oct 24, 2024
References Cited (47)
US 7117322B2 · Hochberg · 2006 [cited by examiner]
US 7600086B2 · Hochberg · 2009 [cited by examiner]
US 7680830B1 · Ohr · 2010 [cited by examiner]
US 7930315B2 · Margolus · 2011 [cited by examiner]
US 10397236B1 · Chadha et al. · 2019 [cited by applicant]
US 10652025B2 · Strong · 2020 [cited by examiner]
US 10951651B1 · Golan et al. · 2021 [cited by applicant]
US 11249944B2 · Savir · 2022 [cited by examiner]
US 11520907B1 · Borowiec · 2022 [cited by examiner]
US 11593017B1 · Chang et al. · 2023 [cited by applicant]
US 11630744B2 · Bourgeois · 2023 [cited by examiner]
US 11954216B1 · Markle · 2024 [cited by examiner]
US 20050055518A1 · Hochberg et al. · 2005 [cited by applicant]
US 20060010177A1 · Kodama · 2006 [cited by examiner]
US 20080034003A1 · Stakutis · 2008 [cited by examiner]
US 20080307175A1 · Hart · 2008 [cited by examiner]
US 20110185134A1 · Toews et al. · 2011 [cited by applicant]
US 20160162364A1 · Mutha · 2016 [cited by examiner]
US 20170091256A1 · Gordon · 2017 [cited by examiner]
US 20170262157A1 · Shem et al. · 2017 [cited by applicant]
US 20180276223A1 · Dhanasekaran · 2018 [cited by examiner]
US 20180276232A1 · Dhanasekaran · 2018 [cited by examiner]
US 20180293024A1 · Baptist et al. · 2018 [cited by applicant]
US 20190013949A1 · Strong et al. · 2019 [cited by applicant]
US 20190227878A1 · Agarwal et al. · 2019 [cited by applicant]
US 20210117377A1 · Savir et al. · 2021 [cited by applicant]
US 20210141698A1 · Bourgeois · 2021 [cited by examiner]
US 20210157504A1 · Hinman · 2021 [cited by applicant]
US 20210224379A1 · Pientka · 2021 [cited by examiner]
US 20210326217A1 · Martin · 2021 [cited by examiner]
US 20220027472A1 · Golden et al. · 2022 [cited by applicant]
US 20220171681A1 · Upadhyay · 2022 [cited by examiner]
US 20220318099A1 · Kotwal et al. · 2022 [cited by applicant]
US 20220318118A1 · Adamson et al. · 2022 [cited by applicant]
US 20230007023A1 · Andrabi · 2023 [cited by examiner]
US 20230032714A1 · Pandit et al. · 2023 [cited by applicant]
US 20230079486A1 · Yarlagadda et al. · 2023 [cited by applicant]
US 20230103474A1 · Gunda et al. · 2023 [cited by applicant]
US 20230131333A1 · Mccolgan et al. · 2023 [cited by applicant]
US 20230176780A1 · Venugopal et al. · 2023 [cited by applicant]
US 20230222092A1 · Xiang et al. · 2023 [cited by applicant]
US 20230297541A1 · Boutell et al. · 2023 [cited by applicant]
CN 106506820A · 2017 [cited by applicant]
CN 109117308A · 2019 [cited by applicant]
CN 113407994A · 2021 [cited by applicant]
JP 2002251304A · 2002 [cited by examiner]
WO WO2023077283A1 · 2023 [cited by examiner]