IP Library › Granted Patent US 12,524,558
Granted Patent B2
US 12,524,558 · App. 17/859,693 · Granted Jan 13, 2026

Data compliance based on automated annotations and protection bindings

Inventors: Marcelo Yannuzzi (Vufflens-la-Ville, CH); Hervé Muyal (Gland, CH); Jean Andrei Diaconu (Haute-Savoie, FR); Frank Brockners (Cologne, DE); Carlos Goncalves Pereira (Carlsbad, CA)
Assignee: Cisco Technology, Inc.
G06F21/62G06F9/543G06F21/6209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,524,558
App. No.
17/859,693
Granted
Jan 13, 2026
Kind
B2
Abstract

In one embodiment, a device obtains program code of an application that defines annotations denoting a plurality of data types handled by the application. The device determines, for each of the plurality of data types, an association between that data type and a category of sensitive data. The device creates, based on the association for each of the plurality of data types, a protection binding that defines a data handling scope bonded to the association between that data type and its associated category of sensitive data. The device causes data compliance policies to be applied to the application according to its corresponding associations and protection bindings.

Claims (41)

1 . A method comprising:

obtaining, by a device, program code of an application that defines annotations denoting a plurality of data types handled by the application;

determining, by the device and for each of the plurality of data types, an association between that data type and a category of sensitive data;

creating, by the device and based on the association for each of the plurality of data types, a protection binding that defines a data handling scope bonded to the association between that data type and its associated category of sensitive data; and

causing, by the device, data compliance policies to be applied to the application according to its corresponding associations and protection bindings, wherein at least one of the data compliance policies controls how a particular category of sensitive data is stored, accessed, or processed by the application within one or more designated processing environments that are determined based on the category of sensitive data.

2 . The method as in claim 1 , wherein the association is defined by a programmer via a user interface or an application programming interface.

3 . The method as in claim 1 , wherein the device automatically infers the association from a corresponding annotation of the annotations in the program code.

4 . The method as in claim 1 , further comprising:

associating, by the device, a token having a predefined access scope with a particular category of sensitive data.

5 . The method as in claim 1 , wherein at least one of the data compliance policies controls where a particular category of sensitive data is stored by the application.

6 . The method as in claim 1 , wherein at least one of the data compliance policies controls how a particular category of sensitive data is accessed by the application.

7 . The method as in claim 1 , wherein at least one of the data compliance policies controls where a workload of the application that is associated with a particular category of sensitive data is executed.

8 . The method as in claim 1 , further comprising:

associating, by the device, a pointer to an encryption key with a particular category of sensitive data.

9 . The method as in claim 1 , further comprising:

automatically generating, by the device, data compliance constraints based on a type of the application or where the application will be deployed.

10 . The method as in claim 9 , wherein the device automatically generates the data compliance constraints based on a repository of industrial regulations, governmental regulations, or organizational regulations.

11 . An apparatus, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

obtain program code of an application that defines annotations denoting a plurality of data types handled by the application;

determine, for each of the plurality of data types, an association between that data type and a category of sensitive data;

create, based on the association for each of the plurality of data types, a protection binding that defines a data handling scope bonded to the association between that data type and its associated category of sensitive data; and

cause data compliance policies to be applied to the application according to its corresponding associations and protection bindings, wherein at least one of the data compliance policies controls how a particular category of sensitive data is stored, accessed, or processed by the application within one or more designated processing environments that are determined based on the category of sensitive data.

12 . The apparatus as in claim 11 , wherein the association is defined by a programmer via a user interface or an application programming interface.

13 . The apparatus as in claim 11 , wherein the apparatus automatically infers the association from a corresponding annotation of the annotations in the program code.

14 . The apparatus as in claim 11 , wherein the process when executed is further configured to:

associate a token having a predefined access scope with a particular category of sensitive data.

15 . The apparatus as in claim 11 , wherein at least one of the data compliance policies controls where a particular category of sensitive data is stored by the application.

16 . The apparatus as in claim 11 , wherein at least one of the data compliance policies controls how a particular category of sensitive data is accessed by the application.

17 . The apparatus as in claim 11 , wherein at least one of the data compliance policies controls where a workload of the application that is associated with a particular category of sensitive data is executed.

18 . The apparatus as in claim 11 , wherein the process when executed is further configured to:

automatically generate data compliance constraints based on a type of the application or where the application will be deployed.

19 . The apparatus as in claim 18 , wherein the process when executed is further configured to:

automatically generate the data compliance constraints based on a repository of industrial regulations, governmental regulations, or organizational regulations.

20 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:

obtaining, by the device, program code of an application that defines annotations denoting a plurality of data types handled by the application;

determining, by the device and for each of the plurality of data types, an association between that data type and a category of sensitive data;

creating, by the device and based on the association for each of the plurality of data types, a protection binding that defines a data handling scope bonded to the association between that data type and its associated category of sensitive data; and

causing, by the device, data compliance policies to be applied to the application according to its corresponding associations and protection bindings, wherein at least one of the data compliance policies controls how a particular category of sensitive data is stored, accessed, or processed by the application within one or more designated processing environments that are determined based on the category of sensitive data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: YANNUZZI, MARCELO; MUYAL, HERVÉ; DIACONU, JEAN ANDREI; BROCKNERS, FRANK, DR.; GONCALVES PEREIRA, CARLOS
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060433/0920 →
Continuity (1)
Related Publication 20240012918A1 · Jan 11, 2024
References Cited (37)
US 9949129B1 · Henry et al. · 2018 [cited by applicant]
US 10484429B1 · Fawcett · 2019 [cited by examiner]
US 10713664B1 · Alagappan et al. · 2020 [cited by applicant]
US 11551117B1 · Malhotra · 2023 [cited by examiner]
US 20050021689A1 · Marvin et al. · 2005 [cited by applicant]
US 20060075228A1 · Black · 2006 [cited by examiner]
US 20090099860A1 · Karabulut et al. · 2009 [cited by applicant]
US 20140280961A1 · Martinez et al. · 2014 [cited by applicant]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20160335454A1 · Choe · 2016 [cited by examiner]
US 20160344736A1 · Khait et al. · 2016 [cited by applicant]
US 20170170970A1 · Leighton et al. · 2017 [cited by applicant]
US 20170201569A1 · Fu et al. · 2017 [cited by applicant]
US 20170300309A1 · Berger et al. · 2017 [cited by applicant]
US 20180027022A1 · Nagaratnam et al. · 2018 [cited by applicant]
US 20180124066A1 · Minkovich et al. · 2018 [cited by applicant]
US 20180124113A1 · Lock et al. · 2018 [cited by applicant]
US 20180260566A1 · Chaganti et al. · 2018 [cited by applicant]
US 20190014123A1 · Akireddy et al. · 2019 [cited by applicant]
US 20190228171A1 · Mathur · 2019 [cited by applicant]
US 20200364351A1 · Sanchez et al. · 2020 [cited by applicant]
US 20210006972A1 · Guim Bernat et al. · 2021 [cited by applicant]
US 20210152561A1 · Shelton et al. · 2021 [cited by applicant]
US 20210286638A1 · Fan et al. · 2021 [cited by applicant]
US 20210329001A1 · Barton et al. · 2021 [cited by applicant]
US 20210360037A1 · Beckman et al. · 2021 [cited by applicant]
“Global Apps, Local Compliance”, online: https://incountry.com/, accessed May 24, 2022, 10 pages. [cited by applicant]
“Global Cloud Service Provider”, online: https://us.ovhcloud.com/, accessed May 24, 2022, 11 pages. [cited by applicant]
“Google Distributed Cloud”, online: https://cloud.google.com/distributed-cloud, accessed May 24, 2022, 8 pages. [cited by applicant]
Kurian, Thomas, “How Google Cloud is addressing the need for data sovereignty in Europe in 2020”, online: https://cloud.google.com/blog/products/identity-security/how-google-cloud-is-addressing-data-sovereignty-in-europ… [cited by applicant]
“Gaia-X: A Federated Secure Data Infrastructure”, online: https://www.gaia-x.eu/, accessed May 24, 2022, 6 pages. [cited by applicant]
“RegTech 100”, online: https://fintech.global/regtech100/, accessed May 24, 2022, 14 pages. [cited by applicant]
“OneTrust Cloud Solutions”, online: https://www.onetrust.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Collibra—The Data Intelligence Cloud”, online: https://www.collibra.com/us/en, accessed May 24, 2022, 4 pages. [cited by applicant]
“LogicGate Risk Cloud”, online: https://www.logicgate.com/, accessed May 24, 2022, 5 pages. [cited by applicant]
“Governance and Security for Low-Code/No-Code Applications”, online: https://www.zenity.io//, accessed May 24, 2022, 6 pages. [cited by applicant]
Zacks, et al., “Network Data Objectivization, Classification, Verification and Privacy via Ring-Oriented Metadata”, Defensive Publication Series, Jul. 2021, 11 pages, Technical Disclosure Commons. [cited by applicant]