IP Library Granted Patent US 12,367,294
Granted Patent B2
US 12,367,294 · App. 17/859,707 · Granted Jul 22, 2025

Automated data compliance and observability

Inventors: Marcelo Yannuzzi (Vufflens-la-Ville, CH); Hervé Muyal (Gland, CH); Jean Andrei Diaconu (Haute-Savoie, FR); Frank Brockners (Cologne, DE); Carlos Goncalves Pereira (Carlsbad, CA)
Assignee: Cisco Technology, Inc.
G06F21/602G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,294
App. No.
17/859,707
Granted
Jul 22, 2025
Kind
B2
Abstract

In one embodiment, an observability and assurance service, associated with various clusters of application services for an application that are executed in a data mesh, may configure a data compliance filter for a particular application service in one of the clusters of application services according to a data compliance policy. The observability and assurance service may monitor the data and traffic associated with the particular application service, wherein the data compliance filter is applied to the traffic to restrict sensitive data in the traffic from being processed by the particular application service. The observability and assurance service may make a determination that the data compliance policy has been violated by the particular application service. The observability and assurance service may modify, based on the determination, the data compliance filter for the particular application service.

Claims (37)

1. A method comprising:

configuring, by an observability and assurance service associated with various clusters of application services for an application that are executed in a data mesh, a data compliance filter for a particular application service in one of the various clusters of application services according to a data compliance policy that indicates a targeted compliance state for the various clusters of application services according by region;

monitoring, by the observability and assurance service, data and traffic associated with the particular application service, wherein the data compliance filter is applied to the traffic to restrict sensitive data in the traffic from being processed by the particular application service;

making, by the observability and assurance service, a determination that the data compliance policy has been violated by the particular application service; and

modifying, by the observability and assurance service and based on the determination, the data compliance filter for the particular application service.

2. The method as in claim 1 , wherein the traffic is from another application service within the various clusters of application services.

3. The method as in claim 1 , wherein the traffic is sent from outside the various clusters of application services.

4. The method as in claim 1 , wherein the data compliance filter comprises one or more data compliance rules that restrict a portion of the sensitive data from being processed by the particular application service based on a geographic location associated with the sensitive data and a geographic location associated with the particular application service.

5. The method as in claim 1 , further comprising:

reporting, by the observability and assurance service, the determination that the data compliance policy has been violated.

6. The method as in claim 1 , wherein the data compliance filter is based in part on an annotation in program code for the application that indicates a category of sensitive data.

7. The method as in claim 1 , wherein the determination indicates that a specific type of sensitive data in the traffic is being processed by the particular application service.

8. The method as in claim 7 , wherein modifying the data compliance filter causes the specific type of sensitive data to be prevented from being processed by the particular application service.

9. The method as in claim 1 , wherein the data compliance filter is a data traffic filter that:

detects the traffic associated with the particular application service arriving at a port associated with the particular application service; and

makes a routing decision for the traffic based on one or more data compliance rules.

10. An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

configure, by an observability and assurance service associated with various clusters of application services for an application that are executed in a data mesh, a data compliance filter for a particular application service in one of the various clusters of application services according to a data compliance policy that indicates a targeted compliance state for the various clusters of application services according by region;

monitor data and traffic associated with the particular application service, wherein the data compliance filter is applied to the traffic to restrict sensitive data in the traffic from being processed by the particular application service;

make a determination that the data compliance policy has been violated by the particular application service; and

modify, based on the determination, the data compliance filter for the particular application service.

11. The apparatus as in claim 10 , wherein the traffic is from another application service within the various clusters of application services.

12. The apparatus as in claim 10 , wherein the traffic is sent from outside the various clusters of application services.

13. The apparatus as in claim 10 , wherein the data compliance filter comprises one or more data compliance rules that restrict a portion of the sensitive data from being processed by the particular application service based on a geographic location associated with the sensitive data and a geographic location associated with the particular application service.

14. The apparatus as in claim 10 , wherein the process when executed is further configured to:

report, by the observability and assurance service, the determination that the data compliance policy has been violated.

15. The apparatus as in claim 10 , wherein the data compliance filter is based in part on an annotation in program code for the application that indicates a category of sensitive data.

16. The apparatus as in claim 10 , wherein the determination indicated that a specific type of sensitive data in the traffic is being processed by the particular application service.

17. The apparatus as in claim 16 , wherein the process when executed is configured to modify the data compliance filter by causing the specific type of sensitive data to be prevented from being processed by the particular application service.

18. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

configuring, by an observability and assurance service associated with various clusters of application services for an application that are executed in a data mesh, a data compliance filter for a particular application service in one of the various clusters of application services according to a data compliance policy that indicates a targeted compliance state for the various clusters of application services according by region;

monitoring, by the observability and assurance service, data and traffic associated with the particular application service, wherein the data compliance filter is applied to the traffic to restrict sensitive data in the traffic from being processed by the particular application service;

making, by the observability and assurance service, a determination that the data compliance policy has been violated by the particular application service; and

modifying, by the observability and assurance service and based on the determination, the data compliance filter for the particular application service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: YANNUZZI, MARCELO; MUYAL, HERVÉ; DIACONU, JEAN ANDREI; BROCKNERS, FRANK, DR.; GONCALVES PEREIRA, CARLOS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060434/0087 →
Continuity (1)
Related Publication 20240012911A1 · Jan 11, 2024
References Cited (46)
US 9949129B1 · Henry · 2018 [cited by examiner]
US 10713664B1 · Alagappan et al. · 2020 [cited by applicant]
US 11507408B1 · Gabrielson · 2022 [cited by examiner]
US 11982993B2 · Cella · 2024 [cited by examiner]
US 20030086422A1 · Klinker · 2003 [cited by examiner]
US 20050021689A1 · Marvin et al. · 2005 [cited by applicant]
US 20090099860A1 · Karabulut et al. · 2009 [cited by applicant]
US 20140098671A1 · Raleigh · 2014 [cited by examiner]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20150254456A1 · Jacquin · 2015 [cited by examiner]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20160344736A1 · Khait et al. · 2016 [cited by applicant]
US 20170149737A1 · Betzler · 2017 [cited by examiner]
US 20170170970A1 · Leighton et al. · 2017 [cited by applicant]
US 20170201569A1 · Fu et al. · 2017 [cited by applicant]
US 20170300309A1 · Berger et al. · 2017 [cited by applicant]
US 20180027022A1 · Nagaratnam et al. · 2018 [cited by applicant]
US 20180115586A1 · Chou · 2018 [cited by examiner]
US 20180124066A1 · Minkovich et al. · 2018 [cited by applicant]
US 20180124113A1 · Lock et al. · 2018 [cited by applicant]
US 20180260566A1 · Chaganti et al. · 2018 [cited by applicant]
US 20180357226A1 · Su · 2018 [cited by examiner]
US 20190014123A1 · Akireddy et al. · 2019 [cited by applicant]
US 20190228171A1 · Mathur · 2019 [cited by applicant]
US 20200159947A1 · Shenefiel · 2020 [cited by examiner]
US 20200364351A1 · Sanchez et al. · 2020 [cited by applicant]
US 20210006972A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210152561A1 · Shelton et al. · 2021 [cited by applicant]
US 20210286638A1 · Fan et al. · 2021 [cited by applicant]
US 20210329001A1 · Barton et al. · 2021 [cited by applicant]
US 20210360037A1 · Beckman et al. · 2021 [cited by applicant]
US 20220070189A1 · Liu · 2022 [cited by examiner]
US 20230155984A1 · Adam · 2023 [cited by examiner]
US 20230195515A1 · Zhang · 2023 [cited by examiner]
Williamson et al., “Throttling viruses: restricting propagation to defeat malicious mobile code”, 18th Annual Computer Security Applications Conference, 2002. Proceedings, Date of Conference: Dec. 9-13 (Year: 2002). [cited by examiner]
“Global Apps, Local Compliance”, online: https://incountry.com/, accessed May 24, 2022, 10 pages. [cited by applicant]
“Global Cloud Service Provider”, online: https://us.ovhcloud.com/, accessed May 24, 2022, 11 pages. [cited by applicant]
“Google Distributed Cloud”, online: https://cloud.google.com/distributed-cloud, accessed May 24, 2022, 8 pages. [cited by applicant]
Kurian, Thomas, “How Google Cloud is addressing the need for data sovereignty in Europe in 2020”, online: https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europ… [cited by applicant]
“Gaia-X: A Federated Secure Data Infrastructure”, online: https://www.gaia-x.eu/, accessed May 24, 2022, 6 pages. [cited by applicant]
“RegTech 100”, online: https://fintech.global/regtech100/, accessed May 24, 2022, 14 pages. [cited by applicant]
“OneTrust Cloud Solutions”, online: https://www.onetrust.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Collibra—The Data Intelligence Cloud”, online: https://www.collibra.com/us/en, accessed May 24, 2022, 4 pages. [cited by applicant]
“LogicGate Risk Cloud”, online: https://www.logicgate.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Governance and Security for Low-Code/No-Code Applications”, online: https://www.zenity.io//, accessed May 24, 2022, 6 pages. [cited by applicant]
Zacks, et al., “Network Data Objectivization, Classification, Verification and Privacy via Ring-Oriented Metadata”, Defensive Publication Series, Jul. 2021, 11 pages, Technical Disclosure Commons. [cited by applicant]