US2022269792A1PendingUtilityA1

Implementing a multi-dimensional unified security and privacy policy with summarized access graphs

Assignee: RAO SUPREETH HOSUR NAGESHPriority: Feb 24, 2021Filed: Mar 18, 2021Published: Aug 25, 2022
Est. expiryFeb 24, 2041(~14.6 yrs left)· nominal 20-yr term from priority
H04L 63/1433H04L 63/0245H04L 63/20H04L 63/0407H04L 63/1425G06F 21/604G06F 2221/034G06F 21/6245G06F 21/577H04L 63/1416H04L 63/1466G06F 16/2379H04L 63/0209G06F 9/541
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computerized method for implementing risk discovery with a set of unified security and privacy policies, includes the step of discovering a set of data and a set of data accesses within an enterprise computing system. The method includes the step of classifying the set of discovered data and the set of data accesses with an identification that shows which of the data assets are important or critical for the enterprise. The method includes the step of determining which of the set of discovered data and the set of data accesses have or are associated with sensitive information. The method includes the step of placing the set of discovered data and the set of data accesses that are associated with sensitive information into a set of discovered information about the infrastructure. The method includes the step of determining which of the set of discovered data and the set of data accesses are relevant in the context of a specified governmental data privacy regulation. The method includes the step of placing the set of discovered data and the set of data accesses that are relevant in the context of a specified governmental data privacy regulation into a set of discovered information about the infrastructure. The method includes the step of, with the set of discovered information about the infrastructure, mapping the set of discovered information about the infrastructure to a set of deterministic dimensions.

Claims

exact text as granted — not AI-modified
What is claimed by United States patent: 
     
         1 . A computerized method for implementing risk discovery with a set of unified security and privacy policies, comprising:
 discovering a set of data and a set of data accesses within an enterprise computing system;   classifying the set of discovered data and the set of data accesses with an identification that shows which of the data assets are important or critical for the enterprise by:
 determining which of the set of discovered data and the set of data accesses have or are associated with sensitive information, 
 placing the set of discovered data and the set of data accesses that are associated with sensitive information into a set of discovered information about the infrastructure, 
 determining which of the set of discovered data and the set of data accesses are relevant in the context of a specified governmental data privacy regulation, 
 placing the set of discovered data and the set of data accesses that are relevant in the context of a specified governmental data privacy regulation into a set of discovered information about the infrastructure; and 
   with the set of discovered information about the infrastructure, mapping the set of discovered information about the infrastructure to a set of deterministic dimensions.   
     
     
         2 . The computerized method of  claim 1 , further comprising:
 enabling the enterprise to select a subset of deterministic dimensions from the set deterministic dimensions to represent a policy or intent.   
     
     
         3 . The computerized method of  claim 2 , further comprising:
 providing an Open Policy Agent (OPA) as a general-purpose policy engine that implements a set of authorization and admission control to data filtering operations based on the selected subset of deterministic dimensions.   
     
     
         4 . The computerized method of  claim 2 , further comprising:
 generating a unified privacy and security OPA policy, wherein the unified privacy and security OPA policy assists enterprises to maintain a desired posture with respect to the specified governmental regulations.   
     
     
         5 . The computerized method of  claim 4 , wherein there are thirty-two (32) deterministic dimensions. 
     
     
         6 . The computerized method of  claim 5 , further comprising:
 generating a Risk criticality (RC) graph based on the subset of deterministic dimensions.   
     
     
         7 . The computerized method of  claim 6 , wherein the governmental regulation comprises the General Data Protection Regulation (GDPR). 
     
     
         8 . The computerized method of  claim 6 , wherein the governmental regulation comprises the California Consumer Privacy Act (CCPA). 
     
     
         9 . The computerized method of  claim 10 , wherein the RC graph quantifies a risk of a service or a data being subject to a cyber attack. 
     
     
         10 . The computerized method of  claim 1 , wherein a deterministic dimension has a cardinality of fixed attributes. 
     
     
         11 . The computerized method of  claim 10 , wherein an intent expressed by a specified set of deterministic dimensions is pre-defined.

Join the waitlist — get patent alerts

Track US2022269792A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.