US2021141915A1PendingUtilityA1

System for automatic classification and protection unified to both cloud and on-premise environments

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Mar 5, 2018Filed: Jan 20, 2021Published: May 13, 2021
Est. expiryMar 5, 2038(~11.6 yrs left)· nominal 20-yr term from priority
G06F 21/6209G06F 21/6218G06F 21/62G06F 21/604H04L 63/1441H04L 63/105G06F 21/52H04L 63/20G06F 21/6281
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, systems, and computer program products are described herein for the classification, tagging, and protection of data objects. Such techniques may be imposed on the data objects automatically regardless of whether the data objects are created/generated/interacted/downloaded/uploaded/accessed on the cloud-based environments and/or on-premises environments. The foregoing techniques are orchestrated from a centralized policy that is treated uniformly regardless of the data objects' environment. Once a data object is identified, it is classified based on multiple criteria and a tag is associated therewith. An enforcement action may be applied to the data objects based on a defined policy. The tag attached to the data object may be used to search for related audit logs that track accesses to the data object. By associating the tag and protection persistently, data object(s) are treated uniformly (i.e., in the same manner) regardless of what environment it is in.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A server, comprising:
 at least one processor circuit; and   at least one memory that stores program code configured to be executed by the at least one processor circuit, the program code comprising:
 a distribution service configured to:
 receive, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object; 
 determine the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager; 
 receive, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and 
 determine a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device. 
 
   
     
     
         2 . The server of  claim 1 , the distribution service further configured to:
 receive, from the first computing device, a first identification of an access to the first instance of the data object via first computing device;   receive, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and   store the first identification and the second identification in a data store coupled to the server.   
     
     
         3 . The server of  claim 2 , the program code further comprising:
 a management console configured to access the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.   
     
     
         4 . The server of  claim 1 , the program code further comprising:
 a management console configured to provide a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.   
     
     
         5 . The server of  claim 4 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object. 
     
     
         6 . The server of  claim 4 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
 a location of the first instance of the data object or the second instance of the data object;   an ownership of the first instance of the data object or the second instance of the data object;   content of the first instance of the data object or the second instance of the data object;   metadata associated with the first instance of the data object or the second instance of the data object; or   an application that accessed the first instance of the data object or the second instance of the data object.   
     
     
         7 . The server of  claim 1 , wherein the server is in a first computing environment and at least one of the first computing device or the second computing device is in a second computing environment. 
     
     
         8 . A method implemented by a server, comprising:
 receiving, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object;   determining the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager;   receiving, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and   determining a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device.   
     
     
         9 . The method of  claim 8 , further comprising:
 receiving, from the first computing device, a first identification of an access to the first instance of the data object via first computing device;   receiving, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and   storing the first identification and the second identification in a data store coupled to the server.   
     
     
         10 . The method of  claim 9 , further comprising:
 accessing the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.   
     
     
         11 . The method of  claim 8 , further comprising:
 providing a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.   
     
     
         12 . The method of  claim 11 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object. 
     
     
         13 . The method of  claim 11 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
 a location of the first instance of the data object or the second instance of the data object;   an ownership of the first instance of the data object or the second instance of the data object;   content of the first instance of the data object or the second instance of the data object;   metadata associated with the first instance of the data object or the second instance of the data object; or   an application that accessed the first instance of the data object or the second instance of the data object.   
     
     
         14 . The method of  claim 8 , wherein the server is in a first computing environment and at least one of the first computing device or the second computing device is in a second computing environment. 
     
     
         15 . A computer-readable storage medium having program instructions recorded thereon that, when executed by at least one processor, perform a method on a server, the method comprising:
 receiving, from a first computing device storing a first instance of a data object and that is accessible over a network by the server, a first query for a policy specifying an enforcement action to be performed by a first instance of a data object manager executing on the first computing device with respect to the first instance of the data object, the first query comprising a first tag identifier that identifies a tag associated with the first instance of the data object;   determining the policy to be provided to the first computing device based on the first tag identifier and provide the determined policy to the first computing device, the policy being enforceable by the first instance of the data object manager;   receiving, from a second computing device storing a second instance of the data object and that is accessible over a network by the server, a second query for a policy specifying an enforcement action to be performed by a second instance of the data object manager executing on the second computing device with respect to the second instance of the data object, the second query comprising a second tag identifier that identifies the tag associated with the second instance of the data object, the second tag identifier being the same as the first tag identifier; and   determining a policy to be provided to the second computing device based on the second tag identifier and provide the determined policy to the second computing device, the policy provided to the second computing device being enforceable by the second instance of the data object manager and being the same as the policy provided to the first computing device.   
     
     
         16 . The computer-readable storage medium of  claim 15 , the method further comprising:
 receiving, from the first computing device, a first identification of an access to the first instance of the data object via first computing device;   receiving, from the second computing device, a second identification of an access to the second instance of the data object via the second computing device; and   storing the first identification and the second identification in a data store coupled to the server.   
     
     
         17 . The computer-readable storage medium of  claim 16 , the method further comprising:
 accessing the data store to provide an aggregated view of the accesses performed on the first instance and the second instance of the data object via the first computing device and the second computing device, the aggregated view being provided via a graphical user interface.   
     
     
         18 . The computer-readable storage medium of  claim 15 , the method further comprising:
 providing a graphical user interface that enables a user to specify a set of conditions that are used by at least one of the first instance of the data object manager to analyze at least one property of the first instance of the data object or the second instance of the data object manager to analyze at least one property of the second instance of the data object, the tag associated with the first instance of the data object being determined based on the analysis of the at least one property of the first instance of the data object, the tag associated with the second instance of the data object being determined based on the analysis of the at least one property of the second instance of the data object.   
     
     
         19 . The computer-readable storage medium of  claim 18 , wherein the graphical user interface is further configured to enable a search for the first instance of the data object and the second instance of the data object based on the tag associated with the first instance of the data object and the second instance of the data object. 
     
     
         20 . The computer-readable storage medium of  claim 18 , wherein the at least one property of the first instance of the data object or the second instance of the data object comprises at least one of:
 a location of the first instance of the data object or the second instance of the data object;   an ownership of the first instance of the data object or the second instance of the data object;   content of the first instance of the data object or the second instance of the data object;   metadata associated with the first instance of the data object or the second instance of the data object; or   an application that accessed the first instance of the data object or the second instance of the data object.

Join the waitlist — get patent alerts

Track US2021141915A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.