IP Library Granted Patent US 9,367,549
Granted Patent B2
US 9,367,549 · App. 14/472,209 · Granted Jun 14, 2016

Virtual private cloud that provides enterprise grade functionality and compliance

Inventors: Ondrej Hrebicek (San Carlos, CA); Leonard Chung (San Francisco, CA)
Assignee: EMC Corporation
G06F17/30085G06F17/30082G06F17/30117G06F17/30174G06F17/30289H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,367,549
App. No.
14/472,209
Granted
Jun 14, 2016
Kind
B2
Abstract

Techniques to enforce policies with respect to managed files and/or endpoints are disclosed. A policy to be applied with respect to a synchronization set is received at a file management system. Compliance with the policy across a plurality of heterogeneous endpoints associated with the synchronization set is ensured by propagating the policy to the heterogeneous endpoints. Each of the endpoints is configured to enforce at the endpoint policies received from the file management system, including by responding in a manner prescribed by the policy to occurrence of a policy-triggering event defined in the policy.

Claims (45)

1. A method of managing files, comprising:

receiving, at a file management system, a policy to be applied with respect to a synchronization set, wherein the policy comprises a retention policy; and

ensuring compliance with the policy across a plurality of heterogeneous endpoints associated with the synchronization set by propagating the policy to the heterogeneous endpoints, wherein the plurality of endpoints are associated with a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein each of the endpoints is configured to enforce at the endpoint policies received from the file management system, including by responding in a manner prescribed by the policy to occurrence of a policy-triggering event defined in the policy,

wherein the policy restricts access to a file from one or more of the endpoints,

wherein the policy triggering event comprises receipt of a request to delete a file to which the retention policy applies,

wherein at least partially in response to the policy trigger event, the file is marked as deleted at one or more endpoints at which the file has been stored, and a copy of the file is retained until expiration of a retention period specified in the policy, and

wherein ensuring compliance with the policy includes preventing access to the file by the one or more endpoints at which access is restricted.

2. The method of claim 1 , wherein each of the endpoints is configured to store or can access at least a subset of files to which the policy is to be applied.

3. The method of claim 1 , wherein the policy comprises one or more of a retention policy, a security policy, and an access restriction policy.

4. The method of claim 1 , wherein enforcing comprises:

monitoring the endpoint to detect the occurrence of the policy-triggering event; and

responding to the occurrence by performing operations prescribed by the policy.

5. The method of claim 1 , wherein the policy restricts access to a file upon the occurrence of the policy-triggering event, and wherein ensuring compliance with the policy includes preventing access to the file upon the occurrence of the policy-triggering event.

6. The method of claim 1 , wherein:

the policy comprises a retention policy; and

responding comprises detecting the occurrence of the policy-triggering event and performing a retention policy operation prescribed by the retention policy.

7. The method of claim 1 , wherein the copy is stored centrally.

8. The method of claim 1 , wherein the copy is stored, but not made visible to users, at one or more of the endpoints.

9. The method of claim 1 , further comprising providing an administrative user interface to enable the policy to be defined.

10. The method of claim 9 , wherein the administrative user interface is configured to receive an identification of files to which the policy is to be applied.

11. The method of claim 1 , further comprising creating and storing an audit record or other data that evidences that a compliance action required by the policy has been performed.

12. The method of claim 1 , further comprising taking, with respect to a file as stored at a first endpoint, an action required by the policy and propagating an effect of the action to other endpoints.

13. The method of claim 1 , wherein the policy requires data associated with one or more of a file, a user, an endpoint, and a device to be deleted.

14. The method of claim 1 , further comprising initiating remotely an operation to cause data associated with a file, user, endpoint, and device, to be deleted.

15. The method of claim 14 , wherein the operation causes associated file management system metadata to be updated or deleted.

16. The method of claim 1 , wherein at least one of the endpoints corresponds to a network storage system that provides access to one or more files stored on the associated one or more non-transitory computer-readable storage medium.

17. The method of claim 16 , wherein the network storage system is associated with a web service that provides a storage service that provides access to one or more files stored on the associated one or more non-transitory computer readable storage medium.

18. The method of claim 1 , wherein one or more of the plurality of endpoints is connected to the file management system over a network.

19. The method of claim 1 , wherein one or more of the plurality of endpoints is connected to the file management system via the Internet.

20. A file management system, comprising:

a processor configured to:

receive, at a file management system, a policy to be applied with respect to a synchronization set, wherein the policy comprises a retention policy; and

ensure compliance with the policy across a plurality of heterogeneous endpoints associated with the synchronization set by propagating the policy to the heterogeneous endpoints, wherein the plurality of endpoints are associated with a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein each of the endpoints is configured to enforce at the endpoint policies received from the file management system, including by responding in a manner prescribed by the policy to occurrence of a policy-triggering event defined in the policy, wherein the policy restricts access to a file from one or more of the endpoints, wherein the policy triggering event comprises receipt of a request to delete a file to which the retention policy applies, wherein at least partially in response to the policy trigger event, the file is marked as deleted at one or more endpoints at which the file has been stored, and a copy of the file is retained until expiration of a retention period specified in the policy, and wherein ensuring compliance with the policy includes preventing access to the file by the one or more endpoints at which access is restricted; and

a memory or other storage device coupled to the processor and configured to store the policy.

21. The system of claim 20 , wherein enforcing comprises:

monitoring the endpoint to detect the occurrence of the policy-triggering event; and

responding to the occurrence by performing operations prescribed by the policy.

22. The system of claim 20 , wherein each of at least a subset of the endpoints is configured to store or can access at least a subset of the files to which the policy is to be applied.

23. A computer program product to manage files, the computer program product being embodied in a tangible, non-transitory computer readable storage medium and comprising computer instructions for:

receiving, at a file management system, a policy to be applied with respect to a synchronization set, wherein the policy comprises a retention policy; and

ensuring compliance with the policy across a plurality of heterogeneous endpoints associated with the synchronization set by propagating the policy to the heterogeneous endpoints, wherein the plurality of endpoints are associated with a plurality of computing systems respectively including one or more non-transitory computer-readable storage mediums, and wherein each of the endpoints is configured to enforce at the endpoint policies received from the file management system, including by responding in a manner prescribed by the policy to occurrence of a policy-triggering event defined in the policy,

wherein the policy restricts access to a file from one or more of the endpoints,

wherein the policy triggering event comprises receipt of a request to delete a file to which the retention policy applies,

wherein at least partially in response to the policy trigger event, the file is marked as deleted at one or more endpoints at which the file has been stored, and a copy of the file is retained until expiration of a retention period specified in the policy, and

wherein ensuring compliance with the policy includes preventing access to the file by the one or more endpoints at which access is restricted.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2014
From: HREBICEK, ONDREJ; CHUNG, LEONARD
To: EMC CORPORATION
Reel/Frame 033642/0594 →
Continuity (3)
Continuation 13530763 · Jun 22, 2012
Provisional Application 61500036 · Jun 22, 2011
Related Publication 20140372382A1 · Dec 18, 2014