IP Library Patent Application 19395626
Patent Application
App. No. 19/395,626

Natural Language Fleet Data Storage Security Controls

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/395,626
Abstract

An example method includes receiving, by a storage fleet control plane of a storage fleet, a natural language statement regarding access control for a data element stored on a storage system included in a plurality of storage systems of the storage fleet; determining, based on the natural language statement, an actor and an action regarding the access control for the data element; generating, based on the determining the actor and the action, an access control rule for the data element; applying, based on the generating the access control rule, the access control rule to the data element; receiving a request associated with the data element; and performing, based on the request and the access control rule, an operation with respect to the data element.

Claims (59)

1 . A method comprising:

receiving, by a storage fleet control plane of a storage fleet, a natural language statement regarding access control for a data element stored on a storage system included in a plurality of storage systems of the storage fleet;

determining, by the storage fleet control plane and based on the natural language statement, an actor and an action regarding the access control for the data element;

generating, by the storage fleet control plane and based on the determining the actor and the action, an access control rule for the data element;

applying, by the storage fleet control plane and based on the generating the access control rule, the access control rule to the data element;

receiving, by the storage fleet control plane, a request associated with the data element; and

performing, by the storage fleet control plane based on the request and the access control rule, an operation with respect to the data element.

2 . The method of claim 1 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is allowed access to the data element; and

granting, based on the determining, access to the data element to the user.

3 . The method of claim 1 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is not allowed access to the data element; and

denying, based on the determining, access to the data element to the user.

4 . The method of claim 3 , wherein the performing the operation with respect to the data element further comprises generating, based on the determining that the user associated with the request is not allowed access to the data element, an alert indicating an unauthorized access request for the data element.

5 . The method of claim 3 , wherein the performing the operation with respect to the data element further comprises generating, based on the determining that the user associated with the request is not allowed access to the data element, a log entry indicating an unauthorized access request for the data element.

6 . The method of claim 1 , wherein the actor comprises a defined group of users.

7 . The method of claim 1 , further comprising determining, based on the natural language statement, a type of the data element; and

wherein the generating the access control rule is further based on the type of the data element.

8 . The method of claim 1 , further comprising determining, based on the natural language statement, a location requested regarding the access control for the data element; and

wherein the generating the access control rule is further based on the location.

9 . The method of claim 1 , further comprising determining, based on the natural language statement, a duration requested regarding the access control for the data element; and

wherein the generating the access control rule is further based on the duration.

10 . The method of claim 1 , wherein the generating the access control rule comprises determining one or more conditions for the access control rule based on a lookup table associated with one or more parameters included in the natural language statement.

11 . The method of claim 1 , wherein the applying the access control rule to the data element comprises modifying a centralized directory storing access information.

12 . The method of claim 1 , wherein:

the data element comprises a managed directory; and

applying the access control rule to the data element comprises applying the access control rule to all data elements included in a directory tree of the managed directory.

13 . A system comprising:

a memory storing instructions; and

one or more processors communicatively coupled to the memory and configured to execute the instructions to perform a process comprising:

receiving a natural language statement regarding access control for a data element stored on the system;

determining, based on the natural language statement, an actor and an action regarding the access control for the data element;

generating, based on the determining the actor and the action, an access control rule for the data element;

applying, based on the generating the access control rule, the access control rule to the data element;

receiving a request associated with the data element; and

performing, based on the request and the access control rule, an operation with respect to the data element.

14 . The system of claim 13 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is allowed access to the data element; and

granting, based on the determining, access to the data element to the user.

15 . The system of claim 13 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is not allowed access to the data element; and

denying, based on the determining, access to the data element to the user.

16 . The system of claim 13 , further comprising determining, based on the natural language statement, a type of the data element; and

wherein the generating the access control rule is further based on the type of the data element.

17 . A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a natural language statement regarding access control for a data element stored on a storage system;

determining, based on the natural language statement, an actor and an action regarding the access control for the data element;

generating, based on the determining the actor and the action, an access control rule for the data element;

applying, based on the generating the access control rule, the access control rule to the data element;

receiving a request associated with the data element; and

performing, based on the request and the access control rule, an operation with respect to the data element.

18 . The computer program product of claim 17 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is allowed access to the data element; and

granting, based on the determining, access to the data element to the user.

19 . The computer program product of claim 17 , wherein the performing the operation with respect to the data element comprises:

determining, based on the request and the access control rule, that a user associated with the request is not allowed access to the data element; and

denying, based on the determining, access to the data element to the user.

20 . The computer program product of claim 17 , further comprising determining, based on the natural language statement, a type of the data element; and

wherein the generating the access control rule is further based on the type of the data element.