System, method, and computer program for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field
The present invention backs up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field. The system sets up the sensitive field for backup by adding an encrypted field to a data object that includes the sensitive field, configuring access to the sensitive field and the encrypted field, creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner, and storing the encrypted copy in the encrypted field. The system backs up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, where the external backup system has no access to the encryption key controlled by the data owner.
1 . A method, performed by a computer system, for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the method comprising:
providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;
receiving the backup configuration settings and the sensitive data definitions;
setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:
adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;
configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;
performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;
creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;
storing the encrypted copy in the encrypted field; and
backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.
2 . The method of claim 1 , further comprising:
restoring the sensitive field from the external backup system by performing the following:
restoring the encrypted field using the encrypted copy stored by the external backup system; and
decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.
3 . The method of claim 1 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.
4 . A non-transitory computer-readable medium comprising a computer program, that, when executed by a computer system, enables the computer system to perform the following steps for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the steps comprising:
providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;
receiving the backup configuration settings and the sensitive data definitions;
setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:
adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;
configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;
performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;
creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;
storing the encrypted copy in the encrypted field; and
backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.
5 . The non-transitory computer-readable medium of claim 4 , further comprising:
restoring the sensitive field from the external backup system by performing the following:
restoring the encrypted field using the encrypted copy stored by the external backup system; and
decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.
6 . The non-transitory computer-readable medium of claim 4 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.
7 . A computer system for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the system comprising:
one or more processors;
one or more memory units coupled to the one or more processors, wherein the one or more memory units store instructions that, when executed by the one or more processors, cause the system to perform the operations of:
providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;
receiving the backup configuration settings and the sensitive data definitions;
setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:
adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;
configuring access to the sensitive field and the encrypted field such that:
(1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;
performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;
creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;
storing the encrypted copy in the encrypted field; and
backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.
8 . The computer system of claim 7 , further comprising:
restoring the sensitive field from the external backup system by performing the following:
restoring the encrypted field using the encrypted copy stored by the external backup system; and
decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.
9 . The computer system of claim 7 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.
10 . A method for extracting data from a sensitive field in a data object in a storage system using an external extraction system without enabling the external extraction system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external extraction system is not the data owner, the method comprising:
providing an interface to the data owner to enter extraction configuration settings and to define sensitive data definitions;
receiving the extraction configuration settings and the sensitive data definitions;
setting up the sensitive field for extraction based at least in part on the extraction configuration settings and the sensitive data definitions by performing the following:
adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;
configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external extraction system; and (2) read and write access to the encrypted field is granted to the external extraction system;
performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;
creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;
storing the encrypted copy in the encrypted field; and
extracting data from the sensitive field without enabling the external extraction system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external extraction system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external extraction system.