IP Library › Granted Patent US 12,744,660
Granted Patent B1
US 12,744,660 · App. 18/072,258 · Granted Sep 22, 2026

System, method, and computer program for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field

Inventors: Sovane Bin (San Francisco, CA); Saddek Dekoum (Ris Orangis, FR); Remi Poujeaux (Rueil-Malmaison, FR); Arnaud Deronne (Castelnau le Iez, FR); Francois Lopitaux (San Carlos, CA); Arnaud Treps (Paris, FR)
Assignee: Odaseva Technologies SAS
H04L9/0822H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,660
App. No.
18/072,258
Granted
Sep 22, 2026
Kind
B1
Abstract

The present invention backs up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field. The system sets up the sensitive field for backup by adding an encrypted field to a data object that includes the sensitive field, configuring access to the sensitive field and the encrypted field, creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner, and storing the encrypted copy in the encrypted field. The system backs up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, where the external backup system has no access to the encryption key controlled by the data owner.

Claims (58)

1 . A method, performed by a computer system, for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the method comprising:

providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;

receiving the backup configuration settings and the sensitive data definitions;

setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:

adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;

configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;

performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;

creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;

storing the encrypted copy in the encrypted field; and

backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.

2 . The method of claim 1 , further comprising:

restoring the sensitive field from the external backup system by performing the following:

restoring the encrypted field using the encrypted copy stored by the external backup system; and

decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.

3 . The method of claim 1 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.

4 . A non-transitory computer-readable medium comprising a computer program, that, when executed by a computer system, enables the computer system to perform the following steps for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the steps comprising:

providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;

receiving the backup configuration settings and the sensitive data definitions;

setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:

adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;

configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;

performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;

creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;

storing the encrypted copy in the encrypted field; and

backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.

5 . The non-transitory computer-readable medium of claim 4 , further comprising:

restoring the sensitive field from the external backup system by performing the following:

restoring the encrypted field using the encrypted copy stored by the external backup system; and

decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.

6 . The non-transitory computer-readable medium of claim 4 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.

7 . A computer system for backing up a sensitive field in a data object in a storage system using an external backup system without enabling the external backup system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external backup system is not the data owner, the system comprising:

one or more processors;

one or more memory units coupled to the one or more processors, wherein the one or more memory units store instructions that, when executed by the one or more processors, cause the system to perform the operations of:

providing an interface to the data owner to enter backup configuration settings and to define sensitive data definitions;

receiving the backup configuration settings and the sensitive data definitions;

setting up the sensitive field for backup based at least in part on the backup configuration settings and the sensitive data definitions by performing the following:

adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;

configuring access to the sensitive field and the encrypted field such that:

(1) access to the sensitive field is allowed only to the data owner and denied to the external backup system; and (2) read and write access to the encrypted field is granted to the external backup system;

performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;

creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;

storing the encrypted copy in the encrypted field; and

backing up the sensitive field without enabling the external backup system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external backup system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external backup system.

8 . The computer system of claim 7 , further comprising:

restoring the sensitive field from the external backup system by performing the following:

restoring the encrypted field using the encrypted copy stored by the external backup system; and

decrypting the encrypted copy into the sensitive field, wherein the decryption is performed using the encryption key controlled by the data owner.

9 . The computer system of claim 7 , wherein the storage system is part of a cloud-based, multi-tenant software-as-a-service (SaaS) application platform.

10 . A method for extracting data from a sensitive field in a data object in a storage system using an external extraction system without enabling the external extraction system to view the data in the sensitive field, wherein the data in the sensitive field belongs to a data owner and wherein the external extraction system is not the data owner, the method comprising:

providing an interface to the data owner to enter extraction configuration settings and to define sensitive data definitions;

receiving the extraction configuration settings and the sensitive data definitions;

setting up the sensitive field for extraction based at least in part on the extraction configuration settings and the sensitive data definitions by performing the following:

adding an encrypted field to a data object having a plurality of fields, wherein one of the plurality of fields is the sensitive field comprising sensitive data and wherein the encrypted field corresponds to the sensitive field;

configuring access to the sensitive field and the encrypted field such that: (1) access to the sensitive field is allowed only to the data owner and denied to the external extraction system; and (2) read and write access to the encrypted field is granted to the external extraction system;

performing compliance monitoring on the access configurations of the sensitive field by testing whether external applications can read the sensitive field;

creating an encrypted copy of the data in the sensitive field with an encryption key controlled by the data owner;

storing the encrypted copy in the encrypted field; and

extracting data from the sensitive field without enabling the external extraction system to view the data in the sensitive field by sending the encrypted copy in the encrypted field to the external extraction system, wherein the encryption key controlled by the data owner is not transmitted between the data object and the external extraction system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2023
From: BIN, SOVANE; DEKOUM, SADDEK; POUJEAUX, REMI; DERONNE, ARNAUD; LOPITAUX, FRANCOIS; TREPS, ARNAUD
To: ODASEVA TECHNOLOGIES SAS
Reel/Frame 062953/0932 →
References Cited (118)
US 6642946B1 · Janes et al. · 2003 [cited by applicant]
US 8078645B2 · Singh · 2011 [cited by applicant]
US 8255320B1 · Seal et al. · 2012 [cited by applicant]
US 8667273B1 · Billstrom · 2014 [cited by examiner]
US 8775328B1 · Abhyanker · 2014 [cited by applicant]
US 9268587B2 · Kruglick · 2016 [cited by applicant]
US 9288184B1 · Kvamme et al. · 2016 [cited by applicant]
US 9330301B1 · Ozog · 2016 [cited by applicant]
US 9769131B1 · Hartley et al. · 2017 [cited by applicant]
US 9794064B2 · Anderson et al. · 2017 [cited by applicant]
US 9990511B1 · Dreyfus · 2018 [cited by examiner]
US 10142349B1 · Tomlin · 2018 [cited by examiner]
US 10664494B2 · Ding et al. · 2020 [cited by applicant]
US 11055123B1 · Bin et al. · 2021 [cited by applicant]
US 11256824B2 · Al-Mousa · 2022 [cited by examiner]
US 11609774B2 · Bin et al. · 2023 [cited by applicant]
US 12032718B1 · Bin et al. · 2024 [cited by applicant]
US 12056723B1 · Bin et al. · 2024 [cited by applicant]
US 12229099B1 · Bin et al. · 2025 [cited by applicant]
US 12235737B1 · Bin et al. · 2025 [cited by applicant]
US 20060150169A1 · Cook et al. · 2006 [cited by applicant]
US 20080016127A1 · Field · 2008 [cited by examiner]
US 20080049942A1 · Sprunk et al. · 2008 [cited by applicant]
US 20080162532A1 · Daga · 2008 [cited by applicant]
US 20080270444A1 · Brodie et al. · 2008 [cited by applicant]
US 20080310633A1 · Brown · 2008 [cited by examiner]
US 20090031230A1 · Kesler · 2009 [cited by applicant]
US 20100079460A1 · Breeds et al. · 2010 [cited by applicant]
US 20120059857A1 · Jackson, Jr. · 2012 [cited by applicant]
US 20120110566A1 · Park · 2012 [cited by applicant]
US 20120117558A1 · Futty et al. · 2012 [cited by applicant]
US 20120246472A1 · Berengoltz · 2012 [cited by examiner]
US 20120254197A1 · Kuzmin · 2012 [cited by applicant]
US 20120324242A1 · Kirsch · 2012 [cited by applicant]
US 20130191780A1 · Holmes et al. · 2013 [cited by applicant]
US 20130227703A1 · Sotos et al. · 2013 [cited by applicant]
US 20130246451A1 · Kaiser · 2013 [cited by applicant]
US 20130283060A1 · Kulkarni et al. · 2013 [cited by applicant]
US 20130297769A1 · Chang et al. · 2013 [cited by applicant]
US 20140040182A1 · Gilder et al. · 2014 [cited by applicant]
US 20140040196A1 · Wijayaratne et al. · 2014 [cited by applicant]
US 20140040197A1 · Wijayaratne et al. · 2014 [cited by applicant]
US 20140101438A1 · Elovici et al. · 2014 [cited by applicant]
US 20140143661A1 · Carreno-Fuentes et al. · 2014 [cited by applicant]
US 20140278534A1 · Romeo · 2014 [cited by applicant]
US 20140344778A1 · Lau et al. · 2014 [cited by applicant]
US 20150019858A1 · Roth et al. · 2015 [cited by applicant]
US 20160019233A1 · Wijayaratne et al. · 2016 [cited by applicant]
US 20160098568A1 · Bushman · 2016 [cited by examiner]
US 20160147999A1 · Fontanetta et al. · 2016 [cited by applicant]
US 20160156671A1 · Cabrera et al. · 2016 [cited by applicant]
US 20160197962A1 · Winn et al. · 2016 [cited by applicant]
US 20160277374A1 · Reid et al. · 2016 [cited by applicant]
US 20160308855A1 · Lacey et al. · 2016 [cited by applicant]
US 20170025040A1 · Maturana et al. · 2017 [cited by applicant]
US 20170048252A1 · Straub et al. · 2017 [cited by applicant]
US 20170091293A1 · Cummings et al. · 2017 [cited by applicant]
US 20170249656A1 · Gantner et al. · 2017 [cited by applicant]
US 20180081905A1 · Kamath et al. · 2018 [cited by applicant]
US 20180089270A1 · Qiu et al. · 2018 [cited by applicant]
US 20180150476A1 · Koos et al. · 2018 [cited by applicant]
US 20180176117A1 · Gudetee et al. · 2018 [cited by applicant]
US 20180181613A1 · Acharya et al. · 2018 [cited by applicant]
US 20180232402A1 · Bhatti et al. · 2018 [cited by applicant]
US 20180336209A1 · Burshteyn · 2018 [cited by applicant]
US 20180375838A1 · Hersans · 2018 [cited by examiner]
US 20190007206A1 · Surla et al. · 2019 [cited by applicant]
US 20190034509A1 · Ding et al. · 2019 [cited by applicant]
US 20190042988A1 · Brown et al. · 2019 [cited by applicant]
US 20190050925A1 · Hodge et al. · 2019 [cited by applicant]
US 20190303270A1 · Hoermann · 2019 [cited by applicant]
US 20200026532A1 · Bill et al. · 2020 [cited by applicant]
US 20200067772A1 · Tomkins et al. · 2020 [cited by applicant]
US 20200073854A1 · Wijayaratne et al. · 2020 [cited by applicant]
US 20200082890A1 · Karr et al. · 2020 [cited by applicant]
US 20200104478A1 · Chauhan · 2020 [cited by applicant]
US 20200127937A1 · Busick et al. · 2020 [cited by applicant]
US 20200159700A1 · Wijayaratne et al. · 2020 [cited by applicant]
US 20200183906A1 · Spillane et al. · 2020 [cited by applicant]
US 20200226953A1 · Anand et al. · 2020 [cited by applicant]
US 20200336481A1 · Fan et al. · 2020 [cited by applicant]
US 20200342117A1 · Richards · 2020 [cited by examiner]
US 20200387625A1 · Saad · 2020 [cited by examiner]
US 20200394317A1 · White · 2020 [cited by examiner]
US 20210026982A1 · Amarendran · 2021 [cited by examiner]
US 20210049029A1 · Kumble et al. · 2021 [cited by applicant]
US 20210067324A1 · Valente et al. · 2021 [cited by applicant]
US 20210191629A1 · Vibhor · 2021 [cited by examiner]
US 20210255991A1 · Koos et al. · 2021 [cited by applicant]
US 20210255992A1 · Wijayaratne et al. · 2021 [cited by applicant]
US 20210349580A1 · Dentzer · 2021 [cited by applicant]
US 20210365414A1 · Lu et al. · 2021 [cited by applicant]
US 20210365587A1 · Lu et al. · 2021 [cited by applicant]
US 20220067115A1 · Zheng et al. · 2022 [cited by applicant]
US 20220107826A1 · Bin et al. · 2022 [cited by applicant]
US 20220129804A1 · Dooley et al. · 2022 [cited by applicant]
US 20220148084A1 · Baker · 2022 [cited by applicant]
US 20220188334A1 · Chen · 2022 [cited by applicant]
US 20220207489A1 · Gupta et al. · 2022 [cited by applicant]
US 20220263657A1 · Chang · 2022 [cited by examiner]
US 20220269809A1 · Chopra · 2022 [cited by examiner]
US 20220317831A1 · Karis et al. · 2022 [cited by applicant]
US 20230010219A1 · Howley et al. · 2023 [cited by applicant]
US 20230082010A1 · Clifford et al. · 2023 [cited by applicant]
US 20230130457A1 · Zhang · 2023 [cited by applicant]
US 20230145349A1 · Watari · 2023 [cited by applicant]
US 20230237034A1 · Garg et al. · 2023 [cited by applicant]
US 20230281305A1 · Savry et al. · 2023 [cited by applicant]
US 20230315694A1 · Koos et al. · 2023 [cited by applicant]
US 20230325360A1 · Wijayaratne et al. · 2023 [cited by applicant]
US 20240012921A1 · Yannuzzi et al. · 2024 [cited by applicant]
US 20240020414A1 · Burns · 2024 [cited by applicant]
US 20240045811A1 · Gurin · 2024 [cited by examiner]
US 20240064020A1 · Kiraz et al. · 2024 [cited by applicant]
US 20240220656A1 · Nozawa et al. · 2024 [cited by applicant]
US 20250165357A1 · Bin et al. · 2025 [cited by applicant]
CA 2634576A1 · 2008 [cited by examiner]
WO 2022081408 · 2022 [cited by applicant]