IP Library Granted Patent US 11,218,318
Granted Patent B2
US 11,218,318 · App. 16/386,167 · Granted Jan 4, 2022

Two-step data deletion having confirmation hold

Inventor: Zachary Ian Ducker (Lillington, NC)
Assignee: EMC IP Holding Company, LLC
H04L9/3228G06F3/0608G06F3/0623G06F3/0637G06F3/0652G06F3/0673G06F21/602H04L9/0894H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,218,318
App. No.
16/386,167
Granted
Jan 4, 2022
Kind
B2
Abstract

A data management process in a storage system comprises a two-step deletion process with a confirmation hold. Data identified in a service request for deletion is encrypted using a one-time use public key to render the data inaccessible to users and system processes. The data is decrypted using a corresponding private key and verified that the data corresponds to the data and is quarantined to prevent access by changing permissions. The quarantined data is further analyzed using a set of criteria that to determine whether access to the data by system users or process is still needed. If not, the data is permanently deleted by securely deleting the encryption and decryption keys.

Claims (28)

1. A computer implemented method of managing data in a storage system to remove unneeded data, comprising:

encrypting identified user data in-place in an original location of said identified user data in said storage system in response to a deletion request identifying said user data for deletion, said encrypting comprising encrypting immediately said identified user data using a one-time use encryption key, and said encrypting preventing further access to said user data;

decrypting temporarily the encrypted identified user data using a decryption key corresponding to said encryption key, and blocking access to the temporarily decrypted user data by changing access permissions;

verifying that the temporarily decrypted user data corresponds to the user data that was identified in said deletion request;

analyzing said temporarily decrypted user data using a confirmation process to determine whether permanent deletion of said user data should be confirmed; and

upon confirming said deletion, permanently deleting said user data.

2. The computer implemented method of claim 1 , wherein upon confirming said deletion, securely deleting said encryption and decryption keys.

3. The computer implemented method of claim 1 , wherein upon not confirming said deletion, maintaining said user data decrypted and restoring said access permissions.

4. The computer implemented method of claim 3 further comprising upon restoring said access permissions, deleting said encryption and decryption keys.

5. The computer implemented method of claim 1 , wherein said confirmation process comprises a hierarchical set of criteria that determines whether the user data is needed by system users or system processes.

6. The computer implemented method of claim 1 , wherein said confirmation process comprises a criterion that determines whether the data was accessed or created within a preceding predetermined period of time.

7. The computer implemented method of claim 6 , wherein said confirmation process further comprises a criterion that determines whether a service or user account that created the data has been deleted.

8. The computer implemented method of claim 6 , wherein said confirmation process further comprises a criterion that determines whether the user data was machine created or human created.

9. The computer implemented method of claim 8 , wherein said confirmation process further determines whether the user data is associated with either an active service account or an active user account, and, if so, keeps the user data.

10. Non-transitory computer readable media embodying executable instructions for controlling the operation of a processor to perform a method of managing data in a storage system to remove unneeded data, comprising:

encrypting identified user data in-place in an original location of said identified user data in said storage system in response to a deletion request identifying said user data for deletion, said encrypting comprising encrypting immediately said identified user data using a one-time use encryption key, and said encrypting preventing further access to said user data;

decrypting temporarily the encrypted identified user data using a decryption key corresponding to said encryption key, and blocking access to the temporarily decrypted user data by changing access permissions;

verifying that the temporarily decrypted user data corresponds to the user data that was identified in said deletion request;

analyzing said temporarily decrypted user data using a confirmation process to determine whether permanent deletion of said user data should be confirmed; and

upon confirming said deletion, permanently deleting said user data.

11. The non-transitory computer readable media of claim 10 , wherein upon confirming said deletion, securely deleting said encryption and decryption keys.

12. The non-transitory computer readable media of claim 10 , wherein upon not confirming said deletion, maintaining said user data decrypted and restoring said access permissions.

13. The non-transitory computer readable media of claim 12 further comprising upon restoring said access permissions, deleting said encryption and decryption keys.

14. The non-transitory computer readable media of claim 10 , wherein said confirmation process comprises a hierarchical set of criteria that determines whether the user data is needed by system users or system processes.

15. The non-transitory computer readable media of claim 10 , wherein said confirmation process comprises a criterion that determines whether the user data was accessed or created within a preceding predetermined period of time.

16. The non-transitory computer readable media of claim 15 , wherein said confirmation process further comprises a criterion that determines whether a service or user account that created the user data has been deleted.

17. The non-transitory computer readable media of claim 16 , wherein said confirmation process further comprises a criterion that determines whether the user data was machine created or human created.

18. The non-transitory computer readable media of claim 17 , wherein said confirmation process further determines whether the user data is associated with either an active service account or an active user account, and, if so, keeps the user data.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2019
From: DUCKER, ZACHARY IAN
To: EMC IP HOLDING COMPANY, LLC
Reel/Frame 048901/0376 →
Continuity (1)
Related Publication 20200336311A1 · Oct 22, 2020