IP Library › Granted Patent US 11,593,017
Granted Patent B1
US 11,593,017 · App. 17/159,010 · Granted Feb 28, 2023

Protection of objects in an object store from deletion or overwriting

Inventors: Shao-Ting Chang (Milpitas, CA); Nicholas Yang (Sunnyvale, CA); Ronald Karr (Palo Alto, CA)
Assignee: Pure Storage, Inc.
G06F3/0652G06F3/067G06F3/0622G06F3/0653G06F3/0659
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,593,017
App. No.
17/159,010
Granted
Feb 28, 2023
Kind
B1
Abstract

An illustrative method includes an object retention management system establishing a retention policy for a bucket of an object-based storage system, detecting an operation that causes an object to be stored within the bucket, and applying, based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration.

Claims (86)

1. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation provided by a client of the object-based storage system that causes an object to be stored within the bucket; and

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration, wherein the retention policy cannot be disabled for the bucket by a user associated with the client and can be disabled for the bucket based on a predefined rule that is independent from a user action of the user, the predefined rule specifying a set of required authorizations by one or more authorized entities to disable the retention policy for the bucket.

2. The method of claim 1 , wherein:

the predefined time duration is unmodifiable by the user associated with the client; and

the predefined time duration is modifiable based on an additional predefined rule that is independent from the user action of the user, the additional predefined rule specifying at least one of the set of required authorizations or a different set of required authorizations by the one or more authorized entities to modify the predefined time duration.

3. The method of claim 1 , wherein:

the retention policy specifies the predefined time duration based on one or more object attributes of the object.

4. The method of claim 1 , wherein the object comprises a first object version and a second object version, and wherein the applying the retention policy to the object includes:

preventing the first object version from being deleted or overwritten during a first retention period associated with the first object version, the first retention period starting at a creation timestamp of the first object version and extending for the predefined time duration; and

preventing the second object version from being deleted or overwritten during a second retention period associated with the second object version, the second retention period starting at a creation timestamp of the second object version and extending for the predefined time duration.

5. The method of claim 4 , wherein the applying the retention policy to the object includes:

determining that the first retention period associated with the first object version has ended; and

allowing, in response to the determining that the first retention period associated with the first object version has ended, the first object version of the object to be deleted or overwritten.

6. The method of claim 1 , further comprising:

determining, by the object retention management system from one or more object versions of one or more objects in the bucket, an object version of a first object and an object version of a second object in which a first retention period associated with the object version of the first object and a second retention period associated with the object version of the second object have ended; and

automatically deleting, by the object retention management system, the object version of the first object and the object version of the second object from the bucket.

7. The method of claim 1 , further comprising:

preventing, by the object retention management system, an object version of the object from being added to the bucket.

8. The method of claim 1 , further comprising:

establishing, by the object retention management system, an additional retention policy for a different bucket of the object-based storage system;

detecting, by the object retention management system, an additional operation that causes an additional object to be stored within the different bucket; and

applying, by the object retention management system based on the detecting of the additional operation, the additional retention policy to the additional object.

9. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

determining, by the object retention management system, a latest object version of the object in the bucket; and

preventing, by the object retention management system, an additional object version of the object from being added to the bucket during a retention period associated with the latest object version of the object.

10. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

detecting, by the object retention management system, an additional operation that causes an additional object version to be stored within the bucket;

determining, by the object retention management system, that a retention period associated with a latest object version of the object has ended;

storing, by the object retention management system in response to the determining that the retention period associated with the latest object version of the object has ended, the additional object version of the object within the bucket; and

preventing, by the object retention management system, the additional object version of the object from being deleted or overwritten during a retention period associated with the additional object version, the retention period associated with the additional object version starting at a creation timestamp of the additional object version and extending for the predefined time duration.

11. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket; and

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration, wherein the retention policy prevents the bucket from being eradicated during a recoverable time period after the bucket is deleted and the bucket is ineradicable by a user associated with a client of the object-based storage system.

12. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

automatically assigning, by the object retention management system, one or more metadata tags to one or more objects in the bucket;

detecting, by the object retention management system, an operation request associated with a metadata tag;

identifying, by the object retention management system, an object version of a particular object among the one or more objects based on the metadata tag and a retention period associated with the object version; and

performing the operation request using the object version of the particular object.

13. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

determining, by the object retention management system, that data of the object-based storage system is possibly being targeted by a security threat; and

preventing, by the object retention management system based on the determining that the data of the object-based storage system is possibly being targeted by the security threat, one or more object versions of the object from being deleted or overwritten during an additional retention period.

14. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

determining, by the object retention management system, that the object is additionally subjected to an indefinite hold policy, the indefinite hold policy preventing the object from being deleted or overwritten until the indefinite hold policy is disabled for the object;

determining, by the object retention management system, that the indefinite hold policy is disabled for the object during a retention period associated with an object version of the object in the bucket; and

preventing, by the object retention management system in response to the determining that the indefinite hold policy is disabled for the object during the retention period associated with the object version of the object, the object version of the object from being deleted or overwritten until the retention period associated with the object version has ended.

15. A method comprising:

establishing, by an object retention management system, a retention policy for a bucket of an object-based storage system;

detecting, by the object retention management system, an operation that causes an object to be stored within the bucket;

applying, by the object retention management system based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration;

determining, by the object retention management system, that the object is additionally subjected to a lifecycle policy, the lifecycle policy automatically deleting the object or moving the object to a different bucket of the object-based storage system when a life event of the object is triggered;

determining, by the object retention management system, that the life event of the object is triggered during a retention period associated with an object version of the object in the bucket; and

preventing, by the object retention management system in response to the determining that the life event of the object is triggered during the retention period associated with the object version of the object, the object version of the object from being deleted or moved to the different bucket until the retention period associated with the object version has ended.

16. A system comprising:

a memory storing instructions; and

a processor communicatively coupled to the memory and configured to execute the instructions to:

establish a retention policy for a bucket of an object-based storage system;

detect an operation provided by a client of the object-based storage system that causes an object to be stored within the bucket; and

apply, based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration, wherein the retention policy cannot be disabled for the bucket by a user associated with the client and can be disabled for the bucket based on a predefined rule that is independent from a user action of the user, the predefined rule specifying a set of required authorizations by one or more authorized entities to disable the retention policy for the bucket.

17. The system of claim 16 , wherein the object comprises a first object version and a second object version, and wherein the applying the retention policy to the object includes:

preventing the first object version from being deleted or overwritten during a first retention period associated with the first object version, the first retention period starting at a creation timestamp of the first object version and extending for the predefined time duration; and

preventing the second object version from being deleted or overwritten during a second retention period associated with the second object version, the second retention period starting at a creation timestamp of the second object version and extending for the predefined time duration.

18. The system of claim 16 , wherein the applying the retention policy to the object includes:

determining a latest object version of the object in the bucket; and

preventing an additional object version of the object from being added to the bucket during a retention period associated with the latest object version of the object.

19. A non-transitory computer-readable medium storing instructions that, when executed, direct a processor of a computing device to:

establish a retention policy for a bucket of an object-based storage system;

detect an operation provided by a client of the object-based storage system that causes an object to be stored within the bucket; and

apply, based on the detecting of the operation, the retention policy to the object, the retention policy preventing the object from being deleted or overwritten for a predefined time duration, wherein the retention policy cannot be disabled for the bucket by a user associated with the client and can be disabled for the bucket based on a predefined rule that is independent from a user action of the user, the predefined rule specifying a set of required authorizations by one or more authorized entities to disable the retention policy for the bucket.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2021
From: CHANG, SHAO-TING; YANG, NICHOLAS; KARR, RONALD
To: PURE STORAGE, INC., A DELAWARE CORPORATION
Reel/Frame 055039/0667 →
Continuity (3)
Provisional Application 63112963 · Nov 12, 2020
Provisional Application 63070671 · Aug 26, 2020
Provisional Application 63070677 · Aug 26, 2020
Cited By (2)
US 12,566,869 US 12,639,260