System for automatic classification and protection unified to both cloud and on-premise environments
Abstract
Methods, systems, and computer program products are described herein for the classification, tagging, and protection of data objects. Such techniques may be imposed on the data objects automatically regardless of whether the data objects are created/generated/interacted/downloaded/uploaded/accessed on the cloud-based environments and/or on-premises environments. The foregoing techniques are orchestrated from a centralized policy that is treated uniformly regardless of the data objects' environment. Once a data object is identified, it is classified based on multiple criteria and a tag is associated therewith. An enforcement action may be applied to the data objects based on a defined policy. The tag attached to the data object may be used to search for related audit logs that track accesses to the data object. By associating the tag and protection persistently, data object(s) are treated uniformly (i.e., in the same manner) regardless of what environment it is in.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A server, comprising:
at least one processor circuit; and at least one memory that stores program code configured to be executed by the at least one processor circuit, the program code comprising:
a distribution service configured to:
receive, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object;
determine the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager;
receive, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and
determine a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device.
2 . The server of claim 1 , the distribution service further configured to:
receive, from the first computing device, a first identification of an access to the first instance of the data object via first computing device; receive, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and store the first identification and the second identification in a data store coupled to the server.
3 . The server of claim 2 , the program code further comprising:
a management console configured to access the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.
4 . The server of claim 1 , the program code further comprising:
a management console configured to provide a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.
5 . The server of claim 4 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object.
6 . The server of claim 4 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
a location of the first instance of the data object or the second instance of the data object; an ownership of the first instance of the data object or the second instance of the data object; content of the first instance of the data object or the second instance of the data object; metadata associated with the first instance of the data object or the second instance of the data object; or an application that accessed the first instance of the data object or the second instance of the data object.
7 . The server of claim 1 , wherein the server is in a first computing environment and at least one of the first computing device or the second computing device is in a second computing environment.
8 . A method implemented by a server, comprising:
receiving, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object; determining the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager; receiving, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and determining a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device.
9 . The method of claim 8 , further comprising:
receiving, from the first computing device, a first identification of an access to the first instance of the data object via first computing device; receiving, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and storing the first identification and the second identification in a data store coupled to the server.
10 . The method of claim 9 , further comprising:
accessing the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.
11 . The method of claim 8 , further comprising:
providing a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.
12 . The method of claim 11 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object.
13 . The method of claim 11 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
a location of the first instance of the data object or the second instance of the data object; an ownership of the first instance of the data object or the second instance of the data object; content of the first instance of the data object or the second instance of the data object; metadata associated with the first instance of the data object or the second instance of the data object; or an application that accessed the first instance of the data object or the second instance of the data object.
14 . The method of claim 8 , wherein the server is in a first computing environment and at least one of the first computing device or the second computing device is in a second computing environment.
15 . A computer-readable storage medium having program instructions recorded thereon that, when executed by at least one processor, perform a method on a server, the method comprising:
receiving, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object; determining the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager; receiving, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and determining a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device.
16 . The computer-readable storage medium of claim 15 , the method further comprising:
receiving, from the first computing device, a first identification of an access to the first instance of the data object via first computing device; receiving, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and storing the first identification and the second identification in a data store coupled to the server.
17 . The computer-readable storage medium of claim 16 , the method further comprising:
accessing the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.
18 . The computer-readable storage medium of claim 15 , the method further comprising:
providing a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.
19 . The computer-readable storage medium of claim 18 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object.
20 . The computer-readable storage medium of claim 18 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
a location of the first instance of the data object or the second instance of the data object; an ownership of the first instance of the data object or the second instance of the data object; content of the first instance of the data object or the second instance of the data object; metadata associated with the first instance of the data object or the second instance of the data object; or an application that accessed the first instance of the data object or the second instance of the data object.Join the waitlist — get patent alerts
Track US2021141915A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.