Data protection within an unsecured storage environment

US10540516B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10540516-B2
Application numberUS-201615292606-A
CountryUS
Kind codeB2
Filing dateOct 13, 2016
Priority dateOct 13, 2016
Publication dateJan 21, 2020
Grant dateJan 21, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A backup or storage management system is provided that can secure data within a primary storage environment that stores data in an unsecured format. The storage management system can automatically analyze data received for backup from the primary storage environment and determine whether the data includes information that has been identified as sensitive and/or information that is determined within a threshold degree of probability to be sensitive. The storage management system can then modify the storage of the data that includes sensitive information at the primary storage environment, thereby enabling the data to be secured within the unsecured, or partially secured, primary storage environment. Advantageously, in certain embodiments, by securing data with sensitive information within an unsecured storage environment, embodiments disclosed herein can reduce the occurrences of a data breach or data leak.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for securing data within an unsecured environment, the system comprising: a storage management system implemented in computer hardware, the storage management system separate from a primary storage environment, the storage management system configured to: receive data to be backed up from the primary storage environment, the data comprising a plurality of files, the primary storage environment comprising an at least partially unsecured storage environment, wherein at least some data stored in the at least partially unsecured storage environment is stored in an unencrypted form or in a storage location with shared access; perform a natural language processing process on the plurality of files to determine content of files within the plurality of files; access a security policy for the primary storage environment; tag the files within the plurality of files based at least in part on the content of the files and the security policy; select a file from the plurality files based at least in part on the tags of the files; index a location of the file at the primary storage environment, thereby enabling a secured version of the file to replace the file at the location of the file at the primary storage environment; and secure the file at the primary storage environment by at least modifying a storage location or storage format of the file. 2. The system of claim 1 , wherein the storage management system is further configured to secure the file by replacing the file at the primary storage environment with a stub file that points to a location of the file within a secure storage environment. 3. The system of claim 2 , wherein the secure storage environment comprises a backup storage environment. 4. The system of claim 2 , wherein the secure storage environment comprises the storage management system. 5. The system of claim 1 , wherein the storage management system is further configured to secure the file by replacing the file at the primary storage environment with an encrypted copy of the file. 6. The system of claim 1 , wherein the storage management system is further configured to secure the file by moving the file to a secure area within the primary storage environment. 7. The system of claim 1 , wherein the storage management system is further configured to determine a process for securing the file at the primary storage environment based at least in part on the security policy. 8. The system of claim 1 , wherein the storage management system is further configured to: detect an attempt to access the file by a user at an unsecured client device; prevent access to the file; and cause a message to be output to the user to access the file at a secured client device. 9. The system of claim 1 , wherein at least one file from the plurality of files comprises a proprietary format and wherein the storage management system is further configured to convert the at least one file to a non-proprietary text format prior to performing the natural language processing process on the at least one file. 10. A computer-implemented method of securing data within an unsecured environment, the computer-implemented method comprising: as implemented by a storage management system implemented in computer hardware and configured with specific computer-executable instructions, receiving data to be backed up from a primary storage environment, the data comprising a plurality of files, the primary storage environment comprising an at least partially unsecured storage environment, wherein at least some data stored in the at least partially unsecured storage environment is stored in an unencrypted form or in a storage location with shared access; performing a natural language processing process on the plurality of files to determine content of files within the plurality of files; accessing a security policy for the primary storage environment; tagging the files within the plurality of files based at least in part on the content of the files and the security policy; selecting a file from the plurality files based at least in part on the tags of the files; indexing a location of the file at the primary storage environment, thereby enabling a secured version of the file to replace the file at the location of the file at the primary storage environment; and securing the file at the primary storage environment by at least modifying a storage location or storage format of the file. 11. The computer-implemented method of claim 10 , wherein securing the file comprises replacing the file at the primary storage environment with a stub file that points to a location of the file within a secure storage environment. 12. The computer-implemented method of claim 11 , wherein the secure storage environment comprises a backup storage environment. 13. The computer-implemented method of claim 11 , wherein the secure storage environment comprises the storage management system. 14. The computer-implemented method of claim 10 , wherein securing the file comprises replacing the file at the primary storage environment with an encrypted copy of the file. 15. The computer-implemented method of claim 10 , wherein securing the file comprises moving the file to a secure area within the primary storage environment. 16. The computer-implemented method of claim 10 , further comprising determining a process for securing the file at the primary storage environment based at least in part on the security policy. 17. The computer-implemented method of claim 10 , further comprising: detecting an attempt to access the file by a user at an unsecured client device; preventing access to the file; and causing a message to be output to the user to access the file at a secured client device. 18. The computer-implemented method of claim 10 , wherein at least one file from the plurality of files comprises a proprietary format and wherein the method further comprises converting the at least one file to a non-proprietary text format prior to performing the natural language processing process on the at least one file.

Assignees

Inventors

Classifications

  • Backup restoration techniques · CPC title

  • Natural language query formulation or dialogue systems · CPC title

  • Using snapshots, i.e. a logical point-in-time copy of the data · CPC title

  • using management policies (point-in-time backing up or restoration of persistent data G06F11/1446; file migration policies for HSM systems G06F16/185) · CPC title

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10540516B2 cover?
A backup or storage management system is provided that can secure data within a primary storage environment that stores data in an unsecured format. The storage management system can automatically analyze data received for backup from the primary storage environment and determine whether the data includes information that has been identified as sensitive and/or information that is determined wi…
Who is the assignee on this patent?
Commvault Systems Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jan 21 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).