IP Library Granted Patent US 10,402,589
Granted Patent B1
US 10,402,589 · App. 16/269,948 · Granted Sep 3, 2019

Method and system for securing cloud storage and databases from insider threats and optimizing performance

Inventors: Vijay Madisetti (Johns Creek, GA); Arshdeep Bahga (Chandigarh, IN)
Assignee: Vijay K. Madisetti
G06F21/6245G06F16/95
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,402,589
App. No.
16/269,948
Filed
Feb 7, 2019
Granted
Sep 3, 2019
Kind
B1
Art Unit
2497
USPC
726/1
Abstract

A method of organizing client application data including receiving an access request for data from a client application, deriving a tag for the access request, receiving tracing information related to the access request, storing the received tracing information in a trace storage database, analyzing the trace storage database to develop updated rules, updating a storage intelligence service with the updated rules, mapping the access request to a corresponding access request record, storing the mapping, receiving a read access request, receiving tracing information for the read access request, and routing the client database read access request from the client application based on the rules stored in the storage intelligence service and the mapping database to a corresponding cloud-based server database record, receiving data responsive to the read access request, defining retrieved data, and transmitting the retrieved data to the client application.

Claims (76)

1. A method of organizing client application data comprising:

receiving a client application database access request for creating or modifying client application data from a client application executing on a computerized device at a cloud-based server;

deriving a tag associated with the client application database access request at a storage router, the tag indicating storage requirements for at least one of security, access speed, or fault tolerance, comprising:

determining if the client application database access request has a tag assigned thereto;

upon determining the client application database access request has a tag assigned thereto, identifying the tag assigned to the client application database access request; and

upon determining the client application database access request does not have a tag assigned thereto:

determining the client application database access request does not have a tag assigned thereto;

analyzing the data comprised by the client application database access request; and

inserting a tag into the client application database access request responsive to the analysis of the data comprised by the client application database access request;

receiving tracing information related to the client application database access request at a storage intelligence service, defining received tracing information in terms of the tag and client application attributes comprising at least one of users, roles, privileges, database access patterns and usage characteristics;

storing the received tracing information in a cloud-based trace storage database;

analyzing the trace storage database to develop updated rules for client application database access requests;

updating the storage intelligence service with the updated rules;

mapping the client application database access request at the storage router to a corresponding server database access request record created or modified responsive to the tag derived from the client application database access request and a rule comprised by the storage router;

storing the mapping in a cloud-based mapping database;

receiving a client database read access request from a client application;

receiving tracing information associated with the client database read access request from the client application at the storage intelligence service; and

routing the client database read access request from the client application based on the rules stored in the storage intelligence service and the mapping database to a corresponding cloud-based server database record;

receiving data from the corresponding cloud-based server database record responsive to the client database read access request, defining retrieved data; and

transmitting the retrieved data to the client application.

2. The method of claim 1 wherein the mapping database is organized as a distributed hash table.

3. The method of claim 1 wherein the mapping database is replicated for fault-tolerance and availability.

4. The method of claim 1 further comprising determining a probable future client database read access request responsive to the tag and the tracing information associated with the client application database access request at the storage intelligence service.

5. The method of claim 1 further comprising:

receiving a plurality of client database read access requests from a single source at the cloud-based server;

receiving tracing information for each of the plurality of client database read access requests at the storage intelligence service;

analyzing the tracing information associated with the plurality of client database read access requests at the storage intelligence service to determine if a threshold number of requests within a threshold time period is exceeded; and

upon determining the threshold number of requests within the threshold time period is exceeded, flagging subsequent client database read access requests from the source for increased monitoring.

6. The method of claim 1 further comprising:

receiving a plurality of client database read access requests from a single source at the cloud-based server;

receiving tracing information for each of the plurality of client database read access requests at the storage intelligence service;

analyzing the tracing information associated with the plurality of client database read access requests at the storage intelligence service to determine if a threshold number of requests for read access of data a single category is exceeded; and

upon determining the threshold number of requests for read access of data of a single category is exceeded, flagging subsequent client database read access requests from the source for increased monitoring.

7. The method of claim 1 wherein the data comprised by either of the client application database access request or the client database access read request is formatted for a first database type, further comprising:

determining if the first database type matches a database type associated with a database type of the corresponding server database access request record; and

upon determining the first database type does not match the database type of the corresponding server database access request record, converting the first database type to a second database type that matches the database type of the corresponding server database access request record.

8. The method of claim 7 wherein the first database and second database types may be one of a SQL or a NoSQL type.

9. The method of claim 1 wherein the retrieved data does not comprise information indicating a geographic location or an internet protocol location of the server comprising the cloud-based server database record.

10. The method of claim 1 wherein receiving the client application database access request comprises:

receiving the client application database access request at a load balancer;

adding tracing information to the client application database access request responsive to receiving the client application database access request at the load balancer, defined as load balancer tracing information;

sending the load balancer tracing information to the storage intelligence service;

sending the client application database access request to an application server of a plurality of application servers;

receiving the client application database access request at the application server of the plurality of application servers;

adding tracing information to the client application database access request responsive to receiving the client application database access request at the application server, defined as application server tracing information; and

sending the application server tracing information to the storage intelligence service.

11. A method of organizing client application data comprising:

receiving a client application database access request for creating or modifying client application data from a client application executing on a computerized device at a cloud-based server;

deriving a tag associated with the client application database access request at a storage router, the tag indicating storage requirements for at least one of security, access speed, or fault tolerance, comprising:

determining whether the client application database access request does or does not have a tag assigned thereto;

upon determining the client application database access request does not have a tag assigned thereto:

analyzing the data comprised by the client application database access request; and

inserting a tag into the client application database access request responsive to the analysis of the data comprised by the client application database access request; and

upon determining the client application database access request does have a tag assigned thereto, identifying the tag comprised by the client application database access request;

receiving tracing information related to the client application database access request at a storage intelligence service, defining received tracing information in terms of the tag and client application attributes comprising at least one of users, roles, privileges, database access patterns, and usage characteristics;

storing the received tracing information in a cloud-based trace storage database;

analyzing the trace storage database to develop updated rules for client application database access requests;

updating the storage intelligence service with the updated rules;

mapping the client application database access request at the storage router to a corresponding server database access request record created or modified responsive to the tag derived from the client application database access request and a rule comprised by the storage router;

storing the mapping in a cloud-based mapping database;

receiving a client database read access request from a client application;

receiving tracing information associated with the client database read access request from the client application at the storage intelligence service; and

routing the client database read access request from the client application based on the one or more rules stored in the storage intelligence service and the mapping database to a corresponding cloud-based server database record;

receiving data from the corresponding cloud-based server database record responsive to the client database read access request, defining retrieved data; and

transmitting the retrieved data to the client application.

12. The method of claim 11 wherein the data comprised by either of the client application database access request or the client database access read request is formatted for a first database type, further comprising:

determining if the first database type matches a database type associated with a database type of the corresponding server database access request record; and

upon determining the first database type does not match the database type of the corresponding server database access request record, converting the first database type to a second database type that matches the database type of the corresponding server database access request record.

13. The method of claim 11 wherein receiving the client application database access request comprises:

receiving the client application database access request at a load balancer;

adding tracing information to the client application database access request responsive to receiving the client application database access request at the load balancer, defined as load balancer tracing information;

sending the load balancer tracing information to the storage intelligence service;

sending the client application database access request to an application server of a plurality of application servers;

receiving the client application database access request at the application server of the plurality of application servers;

adding tracing information to the client application database access request responsive to receiving the client application database access request at the application server, defined as application server tracing information; and

sending the application server tracing information to the storage intelligence service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2019
From: BAHGA, ARSHDEEP
To: MADISETTI, VIJAY
Reel/Frame 048346/0483 →
Continuity (1)
Provisional Application 62782428 · Dec 20, 2018
Cited By (8)
US 12,265,648 US 12,278,802 US 12,346,318 US 12,346,994 US 12,430,292 US 12,495,075 US 12,670,082 US 12,694,150