IP Library Granted Patent US 8,429,364
Granted Patent B1
US 8,429,364 · App. 13/475,933 · Granted Apr 23, 2013

Systems and methods for identifying the presence of sensitive data in backups

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,429,364
App. No.
13/475,933
Granted
Apr 23, 2013
Kind
B1
Abstract

A computer-implemented method for identifying the presence of sensitive data in a backup may comprise identifying a backup, identifying sensitive data in the backup, creating metadata that identifies the presence of the sensitive data in the backup, and associating the metadata with the backup. In addition, a method for preventing sensitive data from being placed in a backup may comprise identifying a file, identifying sensitive data in the file, and preventing the file from being placed in a backup. Corresponding systems and computer-readable media are also disclosed.

Claims (44)

1. A computer-implemented method for identifying the presence of sensitive data in backups, at least a portion of the method being performed by a computing system comprising at least one processor, the method comprising:

identifying a backup;

identifying sensitive data in the backup;

creating metadata that identifies both the presence of the sensitive data in the backup and at least one characteristic of the sensitive data;

associating the metadata with the backup to signal the presence of the sensitive data in the backup;

wherein at least a portion of the metadata is stored in a manner that enables the presence of the sensitive data in the backup to be identified even after the backup has been encrypted or compressed.

2. The method of claim 1 , wherein identifying the sensitive data in the backup comprises identifying a file in the backup that contains the sensitive data.

3. The method of claim 2 , wherein identifying the file in the backup that contains the sensitive data comprises:

scanning the file before it is added to the backup;

identifying the sensitive data in the file.

4. The method of claim 1 , wherein identifying the sensitive data in the backup comprises identifying a digital signature for the sensitive data in the backup.

5. The method of claim 1 , wherein associating the metadata with the backup comprises storing the metadata in the backup.

6. The method of claim 1 , wherein associating the metadata with the backup comprises:

storing the metadata in a file that is separate from the backup;

associating the file with the backup.

7. The method of claim 1 , wherein the metadata comprises a digital signature for the sensitive data.

8. The method of claim 1 , further comprising transmitting a notification to at least one other computing system that indicates the presence of the sensitive data in the backup.

9. The method of claim 1 , wherein at least a portion of the metadata is stored in an unencrypted and uncompressed format.

10. The method of claim 1 , further comprising preventing, based on the metadata that identifies the presence of the sensitive data in the backup, the sensitive data from being distributed to an unauthorized location.

11. A system for identifying the presence of sensitive data in backups, the system comprising:

a sensitive-data-detection module programmed to:

identify a backup;

identify sensitive data in the backup;

a metadata module programmed to:

create metadata that identifies both the presence of the sensitive data in the backup and at least one characteristic of the sensitive data;

associate the metadata with the sensitive data identified in the backup to signal the presence of the sensitive data in the backup;

wherein at least a portion of the metadata is stored in a manner that enables the presence of the sensitive data in the backup to be identified even after the backup has been encrypted or compressed;

at least one processor configured to execute the sensitive-data-detection module and the metadata module.

12. The system of claim 11 , wherein at least a portion of the metadata is stored in an unencrypted and uncompressed format.

13. A non-transitory computer-readable medium containing information that identifies the presence of sensitive data in a backup, the non-transitory computer-readable medium comprising:

backup data that comprises sensitive data;

metadata that identifies both the presence of the sensitive data in the backup data and at least one characteristic of the sensitive data;

wherein the metadata is associated with the backup data to signal the presence of the sensitive data in the backup data;

wherein at least a portion of the metadata is stored in a manner that enables the presence of the sensitive data in the backup data to be identified even after the backup data has been encrypted or compressed.

14. The non-transitory computer-readable medium of claim 13 , wherein the metadata comprises a digital signature for the sensitive data.

15. The non-transitory computer-readable medium of claim 13 , wherein the metadata is stored in at least one of:

the backup data;

a file that is separate from the backup data.

16. The non-transitory computer-readable medium of claim 13 , wherein at least a portion of the metadata is stored in an unencrypted and uncompressed format.

17. The non-transitory computer-readable medium of claim 13 , wherein the backup data comprises at least one of:

a partial backup;

a full backup;

an incremental backup;

a differential backup.

Assignments (13)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC (F/K/A VERITAS US IP HOLDINGS LLC)
Reel/Frame 069712/0090 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY IN PATENTS AT R/F 037891/0726 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS US IP HOLDINGS, LLC
Reel/Frame 054535/0814 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
MERGER AND CHANGE OF NAME Recorded Apr 18, 2016
From: VERITAS US IP HOLDINGS LLC; VERITAS TECHNOLOGIES LLC
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 038455/0752 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037891/0726 →
SECURITY INTEREST Recorded Feb 23, 2016
From: VERITAS US IP HOLDINGS LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037891/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2016
From: SYMANTEC CORPORATION
To: VERITAS US IP HOLDINGS LLC
Reel/Frame 037697/0412 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2012
From: ORCUTT, NIEL
To: SYMANTEC CORPORATION
Reel/Frame 028237/0436 →