IP Library Granted Patent US 12,657,301
Granted Patent B2
US 12,657,301 · App. 18/331,840 · Granted Jun 16, 2026

System and method for early notification of cyber vault data integrity scanner compromise

Inventors: Jehuda Shemer (Kfar Saba, IL); Girish Balvantrai Doshi (Pune, IN)
Assignee: Dell Products L.P.
G06F21/568G06F21/64H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,301
App. No.
18/331,840
Granted
Jun 16, 2026
Kind
B2
Abstract

One example method includes providing infected data to a vault as part of a simulated attack, when no report is received, at an expected time, concerning the infected data in the vault, raising an alarm indicating that a data integrity scanner of the vault is not functioning properly, when a report is received from the vault concerning the infected data, checking the report to determine if the report is valid, when the report received from the vault is determined not to be valid, raising an alarm indicating that the data integrity scanner is not functioning properly, and when the report received from the vault is determined to be valid, generating an indication that the data integrity scanner is functioning properly.

Claims (30)

1 . A method, comprising:

providing infected data to a vault as part of a simulated attack, wherein the infected data comprises a pre-infected backup copy intentionally infected with malware prior to being stored in the vault;

responsive to determining that no report is received, at an expected time, from a data integrity scanner of the vault concerning the infected data in the vault, raising an alarm indicating that the data integrity scanner of the vault is not functioning properly;

responsive to receiving, from the data integrity scanner, a report concerning the infected data, checking the report to determine if the report is valid, wherein checking the report comprises verifying that (i) a nature of infection identified in the report matches a known induced infection and (ii) a cryptographically protected random value associated with the infected data is correctly returned;

responsive to determining that the report is not valid, raising an alarm indicating that the data integrity scanner is not functioning properly; and

responsive to determining that the report is valid, generating an indication that the data integrity scanner is functioning properly, wherein the indication is generated based on successful completion of a challenge-response process by the data integrity scanner.

2 . The method as recited in claim 1 , wherein the infected data is provided to the vault on a randomized basis.

3 . The method as recited in claim 1 , wherein the infected data is tagged with a tag indicating a nature of an infection of the infected data.

4 . The method as recited in claim 1 , wherein the infected data is associated with an encrypted and signed random number.

5 . The method as recited in claim 1 , wherein communications to and from the vault are effected using a visual communication mechanism.

6 . The method as recited in claim 1 , wherein the alarm and an associated notification are generated in real-time, and without requiring physical access to the vault, after discovery that the data integrity scanner is not operating properly.

7 . The method as recited in claim 1 , wherein communications to and from the vault are effected using a non-network mechanism.

8 . The method as recited in claim 1 , wherein the indication that the data integrity scanner is functioning properly is received as a result of successful completion, by the data integrity scanner, of a challenge-response process.

9 . The method as recited in claim 1 , wherein the infected data was infected with malware.

10 . The method as recited in claim 1 , wherein the infected data is provided to the vault according to a regular cadence.

11 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

providing infected data to a vault as part of a simulated attack, wherein the infected data comprises a pre-infected backup copy intentionally infected with malware prior to being stored in the vault;

responsive to determining that no report is received, at an expected time, from a data integrity scanner of the vault concerning the infected data in the vault, raising an alarm indicating that the data integrity scanner of the vault is not functioning properly;

responsive to receiving, from the data integrity scanner, a report concerning the infected data, checking the report to determine if the report is valid, wherein checking the report comprises verifying that (i) a nature of infection identified in the report matches a known induced infection and (ii) a cryptographically protected random value associated with the infected data is correctly returned;

responsive to determining that the report received from the vault is not valid, raising an alarm indicating that the data integrity scanner is not functioning properly; and

responsive to determining that the report received from the vault is valid, generating an indication that the data integrity scanner is functioning properly, wherein the indication is generated based on successful completion of a challenge-response process by the data integrity scanner.

12 . The non-transitory storage medium as recited in claim 11 , wherein the infected data is provided to the vault on a randomized basis.

13 . The non-transitory storage medium as recited in claim 11 , wherein the infected data is tagged with a tag indicating a nature of an infection of the infected data.

14 . The non-transitory storage medium as recited in claim 11 , wherein the infected data is associated with an encrypted and signed random number.

15 . The non-transitory storage medium as recited in claim 11 , wherein communications to and from the vault are effected using a visual communication mechanism.

16 . The non-transitory storage medium as recited in claim 11 , wherein the alarm and an associated notification are generated in real-time, and without requiring physical access to the vault, after discovery that the data integrity scanner is not operating properly.

17 . The non-transitory storage medium as recited in claim 11 , wherein communications to and from the vault are effected using a non-network mechanism.

18 . The non-transitory storage medium as recited in claim 11 , wherein the indication that the data integrity scanner is functioning properly is received as a result of successful completion, by the data integrity scanner, of a challenge-response process.

19 . The non-transitory storage medium as recited in claim 11 , wherein the infected data was infected with malware.

20 . The non-transitory storage medium as recited in claim 11 , wherein the infected data is provided to the vault according to a regular cadence.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2023
From: SHEMER, JEHUDA; DOSHI, GIRISH BALVANTRAI
To: DELL PRODUCTS L.P.
Reel/Frame 063900/0770 →
Continuity (1)
Related Publication 20240411884A1 · Dec 12, 2024
References Cited (7)
US 11829486B1 · Lambotte · 2023 [cited by examiner]
US 20200280576A1 · Key · 2020 [cited by examiner]
US 20230156032A1 · Andriani · 2023 [cited by examiner]
US 20230327885A1 · Griffin · 2023 [cited by examiner]
CN 111866004A · 2020 [cited by examiner]
JP 4860856B2 · 2012 [cited by examiner]
JP 2019191670A · 2019 [cited by examiner]