IP Library › Granted Patent US 12,041,090
Granted Patent B2
US 12,041,090 · App. 17/227,074 · Granted Jul 16, 2024

Cloud security based on object metadata

Inventors: Krishna Narayanaswamy (Saratoga, CA); Lebin Cheng (Saratoga, CA); Abhay Kulkarni (Cupertino, CA); Ravi Ithal (Los Altos, CA); Chetan Anand (San Francisco, CA); Rajneesh Chopra (Sunnyvale, CA)
Assignee: Netskope, Inc.
H04L63/20G06F16/285G06F16/951G06F21/6209H04L63/0281H04L63/10H04L63/104H04L63/105H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,041,090
App. No.
17/227,074
Granted
Jul 16, 2024
Kind
B2
Abstract

The technology disclosed relates to a proxy receiving a request to manipulate a data object on an independent object store. The proxy is interposed between a user system from which the request originates and the independent object store. The technology disclosed further relates to the proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata. The technology disclosed further relates to the proxy enforcing a policy on the request based on the object metadata. Enforcing the policy further includes enforcing malware detection policies and threat detection policies.

Claims (24)

1. A computer-implemented method, including:

a cloud-based proxy receiving a request to manipulate a data object on an independent object store, wherein the cloud-based proxy is interposed between a user system from which the request originates and the independent object store;

the cloud-based proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata; and

the cloud-based proxy, without accessing the data object, enforcing a policy on the request based on the object metadata.

2. The computer-implemented method of claim 1 , wherein the object metadata is generated by the cloud-based proxy in advance of the request.

3. The computer-implemented method of claim 1 , wherein the request identifies the data object.

4. The computer-implemented method of claim 1 , wherein enforcing the policy further includes enforcing malware detection policies.

5. The computer-implemented method of claim 1 , wherein enforcing the policy further includes enforcing threat detection policies.

6. A non-transitory computer readable storage medium impressed with computer program instructions, the instructions, when executed on a processor, implement a method comprising:

a cloud-based proxy receiving a request to manipulate a data object on an independent object store, wherein the cloud-based proxy is interposed between a user system from which the request originates and the independent object store;

the cloud-based proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata; and

the cloud-based proxy, without accessing the data object, enforcing a policy on the request based on the object metadata.

7. The non-transitory computer readable storage medium of claim 6 , wherein the object metadata is generated by the cloud-based proxy in advance of the request.

8. The non-transitory computer readable storage medium of claim 6 , wherein the request identifies the data object.

9. The non-transitory computer readable storage medium of claim 6 , wherein enforcing the policy further includes enforcing malware detection policies.

10. The non-transitory computer readable storage medium of claim 6 , wherein enforcing the policy further includes enforcing threat detection policies.

11. A system including one or more processors coupled to memory, the memory loaded with computer instructions, the instructions, when executed on the processors, implement actions comprising:

a cloud-based proxy receiving a request to manipulate a data object on an independent object store, wherein the cloud-based proxy is interposed between a user system from which the request originates and the independent object store;

the cloud-based proxy accessing a metadata store that contains object metadata for the data object and retrieving the object metadata; and

the cloud-based proxy, without accessing the data object, enforcing a policy on the request based on the object metadata.

12. The system of claim 11 , wherein the object metadata is generated by the cloud-based proxy in advance of the request.

13. The system of claim 11 , wherein the request identifies the data object.

14. The system of claim 11 , wherein enforcing the policy further includes enforcing malware detection policies.

15. The system of claim 11 , wherein enforcing the policy further includes enforcing threat detection policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2023
From: NARAYANASWAMY, KRISHNA; CHENG, LEBIN; KULKARNI, ABHAY; ITHAL, RAVI; ANAND, CHETAN; CHOPRA, RAJNEESH
To: NETSKOPE, INC.
Reel/Frame 063246/0054 →
Continuity (6)
Continuation 16409685 · May 10, 2019
Continuation 16000132 · Jun 5, 2018
Continuation 15368240 · Dec 2, 2016
Continuation 15368246 · Dec 2, 2016
Provisional Application 62307305 · Mar 11, 2016
Related Publication 20210226998A1 · Jul 22, 2021