IP Library Granted Patent US 10,242,212
Granted Patent B2
US 10,242,212 · App. 15/132,120 · Granted Mar 26, 2019

Preserving data protection and enabling secure content awareness in query services

Inventors: Abel Tegegne (Ottawa, CA); Elena Vinogradov (Kanata, CA); Guangning Hu (Kanata, CA)
Assignee: QUEST SOFTWARE, INC.
G06F21/6218G06F17/30528H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,242,212
App. No.
15/132,120
Filed
Apr 18, 2016
Granted
Mar 26, 2019
Kind
B2
Art Unit
2497
USPC
726/1
Abstract

Embodiments of the present disclosure include systems and methods for providing query service of secured contents. A data collection service collects data and security context associated with the data from a data source and stores the data with the security attributes in a datastore, where the security attributes are derived from the security context and used to determine access to the data so that access to the data is consistent with the security context. Upon receiving a query and a user context of a requester making the query of the datastore, a set of query results is obtained. Based on the user context and security attributes, it is determined whether the requestor has a proper right to access the query results. If the requestor has a proper right to access the query results, access to the query results is granted.

Claims (61)

1. A computer-implemented method, the method comprising:

collecting electronic data and security context associated with the electronic data from a data source;

extracting, from the electronic data, a set of one or more security attributes associated with accessing the electronic data using at least the security context associated with the electronic data;

protecting at least a portion of the electronic data by requesting the data source to protect the at least a portion of the electronic data;

receiving the at least a portion of the protected electronic data;

storing the protected electronic data in a datastore;

storing in the datastore the set of one or more security attributes as metadata to the electronic data, the set of one or more security attributes being used to determine access to the electronic data so that access to the electronic data is consistent with the security context;

receiving a query and a user context of a requester making the query of the datastore;

running the query to get a set of query results, each of the set of query results including the electronic data and the set of one or more security attributes associated with the electronic data;

for each of the set of query results:

based on the user context and the set of one or more security attributes, determining whether the requestor has a proper right to access the query result;

responsive to having the proper right to access the query result, granting access to the query result; and

responsive to not having the proper right to access the query result, refraining to grant access to the query result.

2. The computer-implemented method claim 1 , further comprising, prior to storing the data:

determining whether all or some of the data needs to be protected.

3. The computer-implemented method claim 2 , further comprising,

responsive to the all or some of the data that needs to be protected, protecting the all or some of the data in a protection format that is consistent with the security context.

4. The computer-implemented method claim 2 , wherein determining whether the all or some of the data of the data needs to be protected is based on at least one of Information Rights management (IRM) information associated with the data, metadata information associated with the data, items in the data and classification information associated with the data.

5. The computer-implemented method claim 1 , wherein the security context includes at least one of a list of people who are given a permission to access the data, a list of groups that are given a permission to access the data, information of protection that is used to protect all or some of the data, data security classification, organization policies/rules, and settings and restrictions to access the data.

6. The computer-implemented method claim 5 , wherein the security attributes are derived from the security context and includes at least one of email headers/x-headers, right management services (RMS) license properties, file system permissions, data loss prevention (DLP) and classification metadata, metadata managed by a browser-based document management platform, alternate data stream (ADS), image/exchangeable-Image-File-Format (exif) metadata, and custom attributes stored in a database.

7. The computer-implemented method claim 1 , further comprising:

encrypting the security attributes and the data in an additional format that is independent of the security context.

8. A computer-implemented method, comprising:

extracting, from electronic data, a set of one or more security attributes associated with accessing the electronic data using a security context associated with the electronic data;

protecting at least a portion of the electronic data;

storing the set of one or more security attributes as metadata to the electronic data, the set of one or more security attributes being used to determine access to the electronic data so that access to the electronic data is consistent with the security context;

receiving a query and a user context of a requester making the query of a secure electronic datastore;

running the query on the secure electronic datastore to get a set of query results, each of the set of query results including electronic data and a set of one or more security attributes associated with the electronic data;

for each of the set of query results:

based on the user context and the set of one or more security attributes, determining whether the requestor has a proper right to access the query result;

responsive to a determination that the requester has the proper right to access the query result, granting access to the query result to the requester, wherein granting the access comprises unprotecting all or some of the electronic data by:

contacting a data source that protected the all or some of the electronic data to unprotect the all or some of the electronic data; and

receiving the unprotected all or some of the electronic data from the original data source; and

responsive to a determination that the requester does not have the proper right to access the query result, not granting access to the query result to the requester.

9. The computer-implemented method claim 8 , further comprising:

responsive to the requester not being allowed to access the query result, from sending the query result to the requester.

10. The computer-implemented method claim 8 , further comprising:

responsive to the query result having a non-protected portion, sending the non-protected portion of the query result to the requestor.

11. The computer-implemented method claim 8 , wherein the user context comprises information that is used to uniquely identify the requester.

12. The computer-implemented method claim 8 , wherein the security attributes are derived from the security context and include at least one of email headers/x-headers, right management services (RMS) license properties, file system permissions, data loss prevention (DLP) and classification metadata, metadata managed by a browser-based document management platform, alternate data stream (ADS), image/exchangeable-Image-File-Format (exif) metadata, and custom attributes stored in a database.

13. An information handling system for providing query service of protected data, comprising:

one or more processors;

a datastore; and

a non-transitory computer-readable medium or media comprising one or more sequences of instructions which, when executed by the one or more processors, the information system to perform operations comprising:

collect electronic data and security context associated with the electronic data from a data source;

extract, from the electronic data, a set of one or more security attributes associated with accessing the electronic data using at least the security context associated with the electronic data;

protect at least a portion of the electronic data by requesting the data source to protect the at least a portion of the electronic data;

receive the at least a portion of the protected electronic data;

store the protected electronic data in the datastore;

store in the datastore the set of one or more security attributes as metadata to the data, the set of one or more security attributes being used to determine access to the electronic data so that access to the data is consistent with the security context;

receive a query and a user context of a requester making the query of the datastore;

run the query to get a set of query results, each of the set of query results including the electronic data and the set of one or more security attributes associated with the electronic data;

for each of the set of query results:

based upon the user context and the set of one or more security attributes, determine whether the requestor has a proper right to access the query result;

responsive to having the proper right to access the query result, grant access to the query result; and

responsive to not having the proper right to access the query result, refrain to grant access to the query result.

14. The information handling system claim 13 , wherein be performed further comprises, prior to storing the electronic data:

determining whether all or some of the electronic data needs to be protected based on at least one of Information Rights management (IRM) information associated with the electronic data, metadata information associated with the electronic data, items in the electronic data and classification information associated with the electronic data.

15. The information handling system claim 13 , wherein not granting access to the query result includes sending a non-sensitive portion of the query result to the requester.

16. The information handling system of as recited in claim 13 , wherein the step of granting an access includes:

unprotecting all or some of the data.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
CHANGE OF NAME Recorded Jun 19, 2018
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 046393/0009 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF REEL 038665 FRAME 0041 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040028/0375 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 038664 FRAME 0908 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040027/0390 →
RELEASE OF REEL 038665 FRAME 0001 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; SECUREWORKS, CORP.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040021/0348 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 038665/0001 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded May 11, 2016
From: DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 038664/0908 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded May 11, 2016
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; WYSE TECHNOLOGY, L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 038665/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2016
From: TEGEGNE, ABEL; VINOGRADOV, ELENA; HU, GUANGNING
To: DELL SOFTWARE, INC.
Reel/Frame 038443/0802 →
Continuity (1)
Related Publication 20170300702A1 · Oct 19, 2017
Cited By (4)
US 12,450,217 US 12,488,136 US 12,493,754 US 12,596,736