IP Library › Granted Patent US 12,361,168
Granted Patent B2
US 12,361,168 · App. 18/469,294 · Granted Jul 15, 2025

Automatically creating data protection roles using anonymized analytics

Inventors: Jennifer M. Minarik (Zionsville, IN); Mark Malamut (Aliso Viejo, CA); Jacob R. Hutcheson (Pflugerville, TX); Brian E. Freeman (Golden, CO)
Assignee: Dell Technologies, Inc.
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,168
App. No.
18/469,294
Granted
Jul 15, 2025
Kind
B2
Abstract

Selecting user access policies for a new system, by collecting user, access policy, and resource metadata for a plurality of other users storing data dictated by one or more access restriction policies. The collected metadata is anonymized with respect to personal identifying information, and is stored in an anonymized analytics database. The system receives specific user, access policy and resource metadata for the new system from a specific user, and matches the received specific user metadata to the collected metadata to identify an optimum access policy of the one or more access policies based on the assets and access restriction requirements of the new system. The new system is then configured with the identified optimum access policy as an initial configuration.

Claims (17)

1. A computer-implemented method of selecting data protection policies for a new system, comprising:

collecting, in a hardware-based asset metadata management component, role, permission, and resource metadata for a plurality of users accessing data in the respective systems under corresponding access rules, wherein the collected metadata is anonymized with respect to personal identifying information of the users;

storing the collected metadata in an anonymized analytics database, wherein the collected metadata is derived using a cluster analysis process and comprises access permissions of each user of the users that allow restriction by a user to a resource comprising at least one of: credential exchange, multi-factor authentication requirements, or use of an identity provider (IdP) service to gain access to the resource;

first receiving policy and asset metadata for the new system;

second receiving role, permission and resource metadata for the new system from a specific user;

first matching, in the component, the received policy and the asset metadata to the collected metadata to identify an optimum protection policy of one or more protection policies based on the assets and protection requirements of the new system;

second matching, in the component, the received specific policy and the asset metadata to the collected metadata to facilitate selection of an optimum access policy of one or more access policies based on assets and access restrictions of the new system;

defining a set of metrics characterizing each user in the system;

extracting metadata of the set of metrics from the specific user to be allowed access to the resource;

comparing each metric of the user with corresponding metadata of a plurality of clusters each containing one or more other users, wherein a unique access policy is assigned to each cluster of the plurality of clusters to be applied to each user within a respective cluster;

determining an overall affinity score of the user relative to each cluster; and

automatically grouping the specific user into a cluster with the highest overall affinity score; and

displaying to the specific user, through a graphical user interface (GUI), information regarding the matching to allow confirmation or change of identification of the optimum protection policy.

2. The method of claim 1 further comprising configuring the new system with the identified optimum access policy as an initial configuration of the new system.

3. The method of claim 2 wherein the new system is a newly deployed computer network installed at day zero of a deployment period.

4. The method of claim 1 wherein the collected metadata comprises at least one of: a company type based on common industry classification, geolocation information of the specific user role names; and resource signatures for the access permissions of the users to resources within a respective system.

5. The method of claim 4 wherein the resources comprise at least one of data stored within a system, or storage, interface, and processing devices within the system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2023
From: MINARIK, JENNIFER M.; MALAMUT, MARK; HUTCHESON, JACOB R.; FREEMAN, BRIAN E.
To: DELL PRODUCTS L.P.
Reel/Frame 064940/0073 →
Continuity (3)
Continuation In Part 17508161 · Oct 22, 2021
Continuation In Part 17400480 · Aug 12, 2021
Related Publication 20240070321A1 · Feb 29, 2024
References Cited (9)
US 20100274750A1 · Oltean · 2010 [cited by examiner]
US 20130124525A1 · Anderson · 2013 [cited by examiner]
US 20190079782A1 · Goldberg · 2019 [cited by examiner]
US 20200031041A1 · Goredema · 2020 [cited by examiner]
US 20200034051A1 · Zhang · 2020 [cited by examiner]
US 20200162255A1 · Hunt · 2020 [cited by examiner]
US 20210286868A1 · Kragh · 2021 [cited by examiner]
US 20210327189A1 · Jarvis · 2021 [cited by examiner]
US 20220012239A1 · Colcord · 2022 [cited by examiner]