IP Library › Granted Patent US 12,645,815
Granted Patent B2
US 12,645,815 · App. 18/750,328 · Granted Jun 2, 2026

Zero-knowledge protection for side channels in data protection to the cloud

Inventors: Amos Zamir (Beer Sheva, IL); Jehuda Shemer (Kfar Saba, IL); Kfir Wolfson (Beer Sheva, IL)
Assignee: EMC IP Holding Company LLC
G06F21/606G06F3/0613G06F3/0617G06F3/0656G06F3/0659G06F3/067G06F3/0683H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,645,815
App. No.
18/750,328
Granted
Jun 2, 2026
Kind
B2
Abstract

Masking a data rate of transmitted data is disclosed. As data is transmitted from a production site to a secondary site, the data rate is masked. Masking the data rate can include transmitting at a fixed rate, a random rate, or an adaptive rate. Each mode of data transmission masks or obscures the actual data rate and thus prevents others from gaining information about the data or the data owner from the data transfer rate.

Claims (30)

1 . A method for protecting a side channel associated with data, the method comprising:

determining a rate for transferring data between a first site and a second site; and

transferring the data at the determined rate, wherein the determined rate includes at least two rates selected from: a fixed rate, an adaptive rate, and/or a random rate, wherein the determined rate is adapted in response to changes in an amount of data expected to be transferred, cost, and a recovery point objective, wherein the recovery point objective measures how much data can be lost.

2 . The method of claim 1 , wherein the determined rate is configured to obscure performance metrics associated with the side channel and/or information related to the data being transferred.

3 . The method of claim 1 , wherein the first site is one of an on-premise system, a cloud-based system and the second site is a cloud site.

4 . The method of claim 1 , wherein the determined rate is related to a transfer time.

5 . The method of claim 1 , wherein the at least two rates are based on time frames, wherein a first of the at least two rates is used during a first time frame and a second of the at least two rates is used during a second time frame associated with transferring the data.

6 . The method of claim 5 , wherein transferring the data at the fixed rate includes padding or queuing the data as needed.

7 . The method of claim 6 , wherein transferring the data at a random rate includes using a randomization technique to select different fixed rates for successive time frames.

8 . The method of claim 7 , wherein the random rate is bounded by upper and lower rates.

9 . The method of claim 7 , wherein the adaptive rate is configured such that the determined rate provides a balance between privacy requirements, cost, and/or recovery point objective demands.

10 . The method of claim 9 , wherein, when transmitting using the adaptive rate, the method further comprising:

sending raw metric data from to a discretization engine;

performing a discretization process by the discretization engine based on the raw metric data and an allowed frequency;

predicting a data transmission rate; and

for a given time period during which the data is transmitted, masking the data transmission rate, wherein the transferred data is padded with extra data when there is insufficient data to achieve the data transmission rate and wherein the transferred data is queued when the data cannot be transmitted at the data transmission rate.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

determining a rate for transferring data between a first site and a second site; and

transferring the data at the determined rate, wherein the determined rate includes at least two rates selected from: a fixed rate, an adaptive rate, and/or a random rate, wherein the determined rate is adapted in response to changes in an amount of data expected to be transferred, cost, and a recovery point objective, wherein the recovery point objective measures how much data can be lost.

12 . The non-transitory storage medium of claim 11 , wherein the determined rate is configured to obscure performance metrics associated with the side channel and/or information related to the data being transferred, wherein the first site is one of an on-premise system, a cloud-based system and the second site is a cloud site and wherein the determined rate is related to a transfer time.

13 . The non-transitory storage medium of claim 11 , wherein the at least two rates are based on time frames, wherein a first of the at least two rates is used during a first time frame and a second of the at least two rates is used during a second time frame associated with transferring the data.

14 . The non-transitory storage medium of claim 13 , wherein transferring the data at the fixed rate includes padding or queuing the data as needed.

15 . The non-transitory storage medium of claim 14 , wherein transferring the data at a random rate includes using a randomization technique to select different fixed rates for successive time frames.

16 . The non-transitory storage medium of claim 15 , wherein the random rate is bounded by upper and lower rates.

17 . The non-transitory storage medium of claim 15 , wherein the adaptive rate is configured such that the determined rate provides a balance between privacy requirements, cost, and/or recovery point objective demands.

18 . The non-transitory storage medium of claim 15 , wherein, when transmitting using the adaptive rate, the method further comprising:

sending raw metric data from to a discretization engine;

performing a discretization process by the discretization engine based on the raw metric data and an allowed frequency;

predicting a data transmission rate; and

for a given time period during which the data is transmitted, masking the data transmission rate, wherein the transferred data is padded with extra data when there is insufficient data to achieve the data transmission rate and wherein the transferred data is queued when the data cannot be transmitted at the data transmission rate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: SHEMER, JEHUDA; ZAMIR, AMOS; WOLFSON, KFIR
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 067800/0024 →
Continuity (3)
Continuation 17807422 · Jun 17, 2022
Continuation 16744814 · Jan 16, 2020
Related Publication 20240338467A1 · Oct 10, 2024
References Cited (38)
US 6651113B1 · Grimsrud · 2003 [cited by applicant]
US 7174422B1 · Kowalchik et al. · 2007 [cited by applicant]
US 7337248B1 · Rao et al. · 2008 [cited by applicant]
US 9152821B2 · Paul · 2015 [cited by examiner]
US 11082129B1 · Nayar et al. · 2021 [cited by applicant]
US 11379595B2 · Zamir et al. · 2022 [cited by applicant]
US 20030229755A1 · Espeseth et al. · 2003 [cited by applicant]
US 20060050660A1 · Wells · 2006 [cited by applicant]
US 20070218931A1 · Beadle · 2007 [cited by examiner]
US 20070250752A1 · Prosch et al. · 2007 [cited by applicant]
US 20080198876A1 · Stanger et al. · 2008 [cited by applicant]
US 20130007380A1 · Seekins · 2013 [cited by examiner]
US 20140173275A1 · Johnson · 2014 [cited by examiner]
US 20150036695A1 · Gowda et al. · 2015 [cited by applicant]
US 20160241514A1 · Seul et al. · 2016 [cited by applicant]
US 20180227317A1 · Xu · 2018 [cited by examiner]
US 20180284758A1 · Cella · 2018 [cited by examiner]
US 20190229894A1 · Samid · 2019 [cited by applicant]
US 20200264796A1 · Lyu et al. · 2020 [cited by applicant]
US 20210152578A1 · Alanazi · 2021 [cited by applicant]
US 20210223964A1 · Zamir et al. · 2021 [cited by applicant]
US 20210263679A1 · Gunderson · 2021 [cited by examiner]
US 20220318409A1 · Zamir et al. · 2022 [cited by applicant]
US 20230035830A1 · Butler · 2023 [cited by examiner]
US 20240171387A1 · Zwanzger · 2024 [cited by examiner]
AU 2011336382A1 · 2013 [cited by applicant]
CN 111885009A · 2020 [cited by applicant]
DE 102015213263A1 · 2017 [cited by applicant]
EP 4174701A1 · 2023 [cited by examiner]
GB 2605732A · 2022 [cited by applicant]
JP H11143778A · 1999 [cited by examiner]
KR 102389139B1 · 2022 [cited by examiner]
WO WO9854657A2 · 1998 [cited by examiner]
WO WO2006071866A2 · 2006 [cited by examiner]
WO 2012075347A1 · 2012 [cited by applicant]
WO 2018085771A1 · 2018 [cited by applicant]
International Preliminary Report on Patentability received for PCT Patent Application No. PCT/US2020/063584, mailed on Jul. 28, 2022, 7 pages. [cited by applicant]
International Search Report and Written Opinion received for PCT Patent Application No. PCT/US2020/063584, mailed on Mar. 22, 2021, 11 pages. [cited by applicant]