US2020228574A1PendingUtilityA1

Policy management for data migration

Assignee: AMAZON TECH INCPriority: Sep 24, 2015Filed: Mar 31, 2020Published: Jul 16, 2020
Est. expirySep 24, 2035(~9.2 yrs left)· nominal 20-yr term from priority
G06F 21/604H04L 63/105G06F 2221/2107G06F 2221/2141H04L 67/10H04L 63/08G06F 2221/2101H04L 63/20H04L 63/0846G06F 2221/2115G06F 21/6236
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A customer of a resource provider environment can apply policies at the data object level that will live with a data object during its lifecycle, even as the object moves across trusted boundaries. A customer can classify data, causing tags and/or predicates to be applied to the corresponding data object. Each tag corresponds to a policy, with predicates relating to various actions that can be performed on the data. A chain of custody is maintained for each data object, such that any changes to the object, tags, or policies for the data can be determined, as may be required for various audit processes. The support of such policies also enables the resource provider environment to function as an intermediary, whereby a third party can receive the data along with the tags, policies, and chain of custody as long as the environment trusts the third party to receive the data object.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system, comprising
 at least one processor; and   memory including instructions that, when executed by the at least one processor, cause the system to:   receive, in a second environment, a data object comprising data and a policy associated with accessing the data within a first environment;   determine that the policy is supported by and is free of conflicts from other policies of the second environment and of other environments providing other data objects for the second environment;   upon the determining, store the data and the policy to the second environment;   authenticate a request for data in the data object;   determine that access to the data is allowed under the policy in the second environment; and   generate an updated data object with the data by adding information to an audit log associated with the data in response to access or actions taken with respect to the data.   
     
     
         2 . The system of  claim 1 , wherein the instructions when executed further cause the system to:
 determine an account associated with the request permits validation of the request; and   validate a source of the request using stored information associated with the account as part of the authentication of the request.   
     
     
         3 . The system of  claim 1 , wherein the instructions when executed further cause the system to:
 determine a tag associated with the policy in the first environment;   determine that a source of the request is associated with a group in the second environment; and   enable a second tag that is associated with the tag for association with the data object in the second environment.   
     
     
         4 . The system of  claim 1 , wherein the instructions when executed further cause the system to:
 grant access to the data after the authentication of the request in the second environment;   determine that an action of a source of the request has caused a violation in the policy; and   prevent the source from accessing the data.   
     
     
         5 . The system of  claim 1 , wherein the instructions when executed further cause the system to:
 grant access to the data after the authentication of the request in the second environment;   determine a risk level has changed for a source of the request based in part on the policy; and   prevent further access to the data.   
     
     
         6 . A computer-implemented method, comprising:
 receiving, in a second environment, a data object comprising data and a policy associated with accessing the data within a first environment;   determining that the policy is supported by and is free of conflicts from other policies of the second environment and of other environments providing other data objects for the second environment;   upon the determining, storing the data and the policy to the second environment;   authenticating a request associated with the data object;   enabling access to the data under the policy in the second environment; and   adding information to an audit log associated with the data in response to access or actions taken with respect to the data.   
     
     
         7 . The computer-implemented method of  claim 6 , further comprising:
 determining an account associated with the request permits validation of the request; and   validating a source of the request using stored information associated with the account as part of the authentication of the request.   
     
     
         8 . The computer-implemented method of  claim 6 , further comprising:
 determining a tag associated with the policy in the first environment;   determining that a source of the request is associated with a group in the second environment; and   enabling a second tag that is associated with the tag for association with the data object in the second environment.   
     
     
         9 . The computer-implemented method of  claim 6 , further comprising:
 granting access to the data after the authentication of the request in the second environment;   determining that an action of a source of the request has caused a violation in the policy; and   preventing the source from accessing the data.   
     
     
         10 . The computer-implemented method of  claim 6 , further comprising:
 granting access to the data after the authentication of the request in the second environment;   determining a risk level has changed for a source of the request based in part on the policy; and   preventing further access to the data.   
     
     
         11 . The computer-implemented method of  claim 6 , further comprising:
 receiving the request for at least a portion of the data in the second environment;   determining that a source of the request is authenticated under the policy and separately from the authenticating of the request associated with the data object; and   generating a second data object including the data, the policy, and the audit log having the information for a destination specified by the request.   
     
     
         12 . The computer-implemented method of  claim 11 , further comprising:
 extracting the policy and the audit log from an envelope of the data object, the data and a data tag included in the envelope; and   generating the second data object by placing the data in a second envelope and including the policy and the audit log with the information in the second envelope.   
     
     
         13 . The computer-implemented method of  claim 6 , further comprising:
 causing the policy to be stored to a policy repository managed by a policy engine associated with the second environment; and   enforcing the policy in the second environment by the policy engine.   
     
     
         14 . The computer-implemented method of  claim 6 , further comprising:
 determining that the policy is immutable; and   preventing modification of the policy or specification of a new policy for the data in at least the second environment.   
     
     
         15 . The computer-implemented method of  claim 6 , further comprising:
 receiving a request to modify the policy, the policy being mutable;   determining that a source of the request is authorized to modify the policy;   modifying the policy; and   updating the audit log to reflect the modification of the policy.   
     
     
         16 . The computer-implemented method of  claim 6 , further comprising:
 storing a set of policies received with the data object, wherein a corresponding policy to enforce from the set of policies is based at least in part upon an action to be performed with respect to the data.   
     
     
         17 . A non-transitory computer-readable storage medium including instructions that, when executed by at least one processor of a computer system, cause the computer system to:
 receive, in a second environment, a data object comprising data and a policy associated with accessing the data within a first environment;   determine that the policy is supported by and is free of conflicts from other policies of the second environment and of other environments providing other data objects for the second environment;   upon the determination being made, store the data and the policy to the second environment;   authenticate a request associated with the data object;   enable access to the data under the policy in the second environment; and   add information to an audit log associated with the data in response to access or actions taken with respect to the data.   
     
     
         18 . The non-transitory computer-readable storage medium of  claim 17  including the instructions that, when executed by the at least one processor of the computer system, cause the computer system to:
 determine an account associated with the request permits validation of the request; and 
 validate a source of the request using stored information associated with the account as part of the authentication of the request. 
 
     
     
         19 . The non-transitory computer-readable storage medium of  claim 17  including the instructions that, when executed by the at least one processor of the computer system, cause the computer system to:
 determine a tag associated with the policy in the first environment; 
 determine that a source of the request is associated with a group in the second environment; and 
 enable a second tag that is associated with the tag for association with the data object in the second environment. 
 
     
     
         20 . The non-transitory computer-readable storage medium of  claim 17  including the instructions that, when executed by the at least one processor of the computer system, cause the computer system to:
 grant access to the data after the authentication of the request in the second environment; 
 determine a risk level has changed for a source of the request based in part on the policy; and 
 prevent further access to the data.

Join the waitlist — get patent alerts

Track US2020228574A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.