Data provenance tracking service
Patent Information
- Application Number
- CN202180071738.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-22
- Filing Date
- 2021-07-30
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2041-07-30
Smart Images

Figure CN116490870B_ABST
Abstract
Description
Technical Field
[0001] Embodiments involve tracking the shared data as it moves between applications and / or computing devices. Some embodiments involve adding tracking tags to the data to facilitate tracking as it moves between applications and / or computing devices. Background Technology
[0002] Computer applications and web-based services can create, use, and store user-owned or user-related data to provide customized services. During the data's lifetime, it can be transferred between and stored on many different computing devices. For example, a web-based service may have multiple sites providing computing resources to provide the service, and the data may originate from or be transferred to one or more of these resources. Furthermore, data can be shared between different applications and / or services to enable seamless integration between those applications and / or services tailored to the customer. Finally, modern system design emphasizes distributed systems that utilize many different computing devices at multiple sites to allow for scalability and reliability. If one or more computing devices become unavailable, user data can subsequently be stored across multiple computing devices across the web-based service to continue providing the service.
[0003] Following several high-profile data breaches, both consumers and corporate clients are increasingly concerned about access to and potential misuse of their data. Historically, organizations have worked to quickly detect and prevent unauthorized access to customer data from applications or individuals. However, there is currently no technological solution that allows an application or service to ultimately prove itself to be a good manager in its use of customer data. Organizations can generally document their processes to protect customer data, but there is no way to archive what happened to every single piece of customer data through these increasingly sophisticated systems. Attached Figure Description
[0004] In the accompanying drawings, which are not necessarily drawn to scale, similar numbers may describe similar components in different views. Similar numbers with different letter suffixes may represent different instances of similar components. The accompanying drawings generally illustrate the various embodiments discussed in this document by way of example rather than limitation.
[0005] Figure 1 The illustration shows a schematic diagram of a data origin tracing service according to some examples of this disclosure.
[0006] Figure 2 The illustration shows a message sequence diagram of a data tracking system according to some examples of this disclosure.
[0007] Figure 3The illustration shows a flowchart of a method for a first computing device or application to send protected data to a second computing device or application according to some examples of this disclosure.
[0008] Figure 4 The diagram illustrates a flowchart of a method for tracking database registrations and events associated with protected data, according to some examples of this disclosure.
[0009] Figure 5 The illustration shows a flowchart of a method for requesting protected data items from a second application or computing device according to some examples of this disclosure.
[0010] Figure 6 The illustration shows a computing device and a tracking database according to some examples of this disclosure.
[0011] Figure 7 This is a block diagram illustrating an example of a machine on which one or more embodiments can be implemented. Detailed Implementation
[0012] The first potential solution to the data growth problem is to limit where data resides. This makes providing scalable and highly available services, as well as more transparent integration with other services and applications, more difficult, if not impossible. The second potential solution would be to set policies on how data is processed and then attempt to enforce those policies. While this is theoretically sound, there is no way to definitively prove that a specific data item is being processed according to those policies. Furthermore, data shared with third-party services or applications is now outside the control of these policies. A third potential solution to the above problems is to have a search infrastructure that searches for specific data items on one or more computing devices when requested. This solution may require dedicated hardware, which could increase cost and complexity. Moreover, while this finds specific instances of data, it does not provide indication of where the data was in the past.
[0013] Methods, systems, devices, and machine-readable media are disclosed in some examples that utilize digital tracking tags attached to data to monitor and / or control the data as it moves between applications and / or computing devices. The digital tracking tag may be embedded in the data (e.g., as a digital watermark) or associated with the data, e.g., as metadata. In some examples, the digital tracking tag may include information about the data, such as one or more of the following: an identifier of the data, information about the source and destination of the data, or a unique identifier of the data being accessed or the customer described by the data. In some examples, the digital tracking tag may include an address of a tracking database used to record one or more events related to the data. For example, a recipient, sender, or other participant in a data transfer event may register the data transfer event with the tracking database. In some examples, the tracking tag may have a link to a network location where information about the data resides (e.g., the identifier of the data, mappings, etc.).
[0014] The digital tracking tag may include rules regarding actions to be taken in response to events corresponding to the data. In other examples, the digital tracking tag may point to or indicate these rules. For example, the system may use information in the tracking tag to specify actions that occur when: the data is moved from one application or service to another; when the data is deleted; when the data is copied; when the data is modified; and so on. Actions may include one or more of the following: registering an action in a designated tracking database, actions applied to the data itself (deleting the data, modifying the data, encrypting the data, etc.), notification actions (such as notifying the subject or owner of the data (such as a user)), or other actions. In some examples, the actions may be performed by an executable code module included in the tracking tag. The executable code module may include object code, machine code, interpreted code (e.g., Java® code), etc. In some examples, the executable code module may be an OS-level virtualization container (e.g., a DOCKER® container) containing code.
[0015] A tracking database can record events that occur on the data items. In some examples, the tracking database can be a centralized, web-based service. That is, each service and each application can report events to the same tracking database (or group of databases). In other examples, the tracking database can be specific to a particular service or application. That is, the tracking database processes data records that move within or between one or more groups of services or applications that subscribe to a particular tracking database. Other services or applications may use different tracking database services.
[0016] In some examples, when data is moved from a first application or service reporting to a first tracking database to an application or service reporting to a second tracking database, the movement can be recorded in a record in the first tracking database, providing the address or identifier of the second tracking database. In some examples, an application or service can refuse to share data with another application or service unless it provides the address of the tracking database that the application or service uses to record events. This allows auditing of event records associated with data, even if the events were not recorded by the same tracking database. The audit begins with the first tracking database. Once the system reads a record indicating that data has been transferred to an application or service utilizing the second tracking database, the system uses the address in the record of the first tracking database to contact the second tracking database and retrieves additional records from the second tracking database, and so on.
[0017] In other examples, each tracking database may register with a central authority. The central authority may maintain a list of tracking databases, along with which applications and services they store records for. During an audit, a user can submit a request to the central authority for records that match submitted criteria. The central authority may have a directory indicating which tracking databases in an individual's tracking database have records matching a specific criterion. For example, the central authority might know which records a first tracking database has for an individual whose last name begins with the letter "am," and which records a second tracking database has for an individual with the last name "nz." Therefore, a query for a specific record for a specific identifier can be targeted only to those tracking databases that are likely to have a responding record. In other examples, the central authority queries all databases it has registered with. In still other examples, the central authority provides the addresses of databases for a user's computing device to query, rather than directly querying the databases themselves.
[0018] By tracking data moving between applications, computing devices, and services, the system allows the creation of auditable logs of data movement that can verify, for any given data item, whether the application or service has processed the data appropriately. The originating device can enforce rules on data use by specifying a set of rules that the data recipient must follow. Tracking and rules can be customized for data. In some examples, customization can be based on user preferences.
[0019] By providing such auditable records, good applications and services can demonstrate that they are good managers of user data, and users will have a clearer understanding of which applications, computers, and services are accessing data about them and what that data is. Applications and services can then use consistency with the system as a selling characteristic. In some examples, digital app stores may require applications that access user data to comply with these characteristics in order to list those applications in the store.
[0020] As previously mentioned, the tracking system will support reporting to stakeholders. Developers will be able to see reports showing which data their apps accessed and which copies of customer data they possess. This effectively creates a duplicated list of customer data for each app and each service. Customers can see which apps and services have accessed their data, when, for how long, and whether any copies have been created. Once the service is widely adopted by developers and customers, customers can demand compliance by refusing to use apps that don't use the service or prioritizing apps that do. Apps can be encouraged to promote their use and compliance with this concept in app store listings. While apps may evade these requirements and / or misrepresent their compliance, this is easily detected during audits or forensic investigations, similar to how compliance with other standards is verified. Intentional or frequent non-compliance may lead customers to question whether the app in question is truly a "good app."
[0021] Therefore, this invention solves the technical problems of tracking distributed data storage and replication, as well as sharing data between services and applications, using data-specific tracking tags and tracking databases. This improves the functionality of computer systems in many ways. For example, the described system assigns the work of tracking data and the events occurring on said data to custodians of copies of that data. These custodians then record the events in one or more (potentially distributed) tracking databases. This allows data to be shared between services and applications without limiting data to a small subset of available computing resources, while simultaneously eliminating the need for complex infrastructure and equipment required for alternative solutions.
[0022] The digital tracking tag can be associated with an entire copy of a data segment, or it can be attached to one or more parts or subsets of a data segment. For example, when a piece of data is split into multiple parts and one part can be stored in a first location while a second part is stored in a second location, the same digital tracking tag can be applied to both parts, or different digital tracking tags can be applied to different parts. Similarly, when two different data segments are combined into a single data segment, these two data segments can have two different tracking tags. Each tracking tag can be maintained—so that a single data segment can now have two different tracking tags.
[0023] Turn now Figure 1The present disclosure illustrates a schematic diagram of a data origination tracing service 100, based on some examples. The computing device 115 may have one or more applications, such as applications 135 and 140, which can collect, receive, or generate data items. Data items can be discrete segments of information stored digitally. Examples include user data, customer data, etc. Exemplary data items may include files, emails, text messages, videos, audio, collected information about users (e.g., location), etc. Protected data items are those protected by the tracing and origination system as described herein. Not all data items can be considered protected. Data items to be protected may be selected by an administrator (e.g., based on data type) or by rules that determine which data is protected.
[0024] In some examples, applications 135 and 140 may share one or more data items. Additionally, data items may be sent to one or more computing devices 110, 120, and 130. One or more computing devices 110, 120, and 130 may be associated with one or more different web-based services. One or more computing devices 110, 120, and 130 may be part of the same web-based service or different web-based services. Furthermore, one or more computing devices 110, 120, and 130 may be operated by the same or different entities.
[0025] As described above, the first application 135 and the second application 140 on computing device 115 can locally share data. In these examples, if the data item is protected, the originating application (e.g., the first application 135) can create a tracking tag and include the tracking tag along with the data item sent to the receiving application (e.g., the second application 140). One or both of the originating and receiving applications can utilize one or more tracking databases 125 to record transmission events and other events. In some examples, the tracking database 125 can be one or more centralized databases or one or more distributed databases. For example, the tracking database can be a node in a blockchain.
[0026] Data from computing device 115 may be transmitted across network 105 (e.g., the Internet) by one or more applications, either first application 135 or second application 140. For example, the data may be transmitted as part of one or more network-based services provided by computing devices 110, 120, or 130. If the data item is protected, a digital tracking tag may be used to transmit the data. In some examples, the digital tracking tag may be created when the protected data item is created, received, or collected. In other examples, the data copy is created when a copy of the data is received from a second application or service at the computing device or application that created or collected the protected data item.
[0027] In some examples, the digital tracking tag may be a data structure that may include one or more of the following: a unique identifier for the data item, a unique application identifier for the requesting application, a unique identifier for the customer whose data is being accessed, a timestamp, the address from which the request was made, the access type, the purpose of the access, or other relevant information such as whether the data access was performed with the permissions of the application or a delegate, and if delegated, which user / account it represents. As mentioned above, the tracking tag may include a mapping specifying the action to be taken by the recipient when a specified event occurs (such as registering the event in a tracking database). As previously mentioned, an action might be registering the event in a tracking database. The digital tracking structure may also have an address for a tracking database used to record events related to the data. For example, computing device 115 may send protected data to computing device 110. Computing device 115 (e.g., one or more applications in first application 135 or second application 140) may create one or more tracking tags and send protected data with said one or more tracking tags to computing device 110.
[0028] One or both of computing devices 115 and 110 may use the tracking tag to report to the tracking database 125 that protected data has been transferred from computing device 115 to computing device 110. For example, by reporting the transfer in the tracking database 125. Similarly, the transfer of protected data from computing device 110 to computing device 120 may be tracked and recorded. The same or different tracking tags may be used for this transfer. In some examples, the tracking tag may be updated to reflect new sources and receivers. In some examples, the tracking tag may have a unique identifier for the unchanged protected data item. The unique identifier can be used to associate records belonging to the same protected data item across all computing devices and across the tracking database. The tracking tag may be stored by the recipient of the protected data along with the data, or stored in a separate location.
[0029] As described, the copying of protected data from one computing device to another can be reported to the tracking database 125. In other examples, other data events are reported in addition to or instead of copy events. An event can be any state change associated with the data. Exemplary events may include loading data from a storage device into memory, copying data, aggregating data with other data from the same or different users, moving data, deleting data, encrypting data, decrypting data, modifying data, providing data to other applications, splitting data into multiple parts, combining data with other data, etc. The tracking database can provide an auditable record of events related to the data. For example, a sending application, a receiving application, or both can record information (or a portion of information) in the tracking structure. In some examples, each event may reference the same tracking database, but in other examples, different events may have different tracking databases (e.g., a deletion event may be reported to a first tracking database, and a copy event may be reported to a second tracking database).
[0030] By tracking events beyond mere movement (e.g., copying, deletion, etc.), more detailed audit logs can be created, providing additional information in data breach incidents. For example, by reporting when data was encrypted and decrypted, an audit can determine whether data was leaked in encrypted or decrypted form. This allows the user, as the subject of the data, to know if there is a possibility of unauthorized access to their data. In some examples, the event may include the encryption type and strength so that the user can assess the likelihood of an attacker compromising their data.
[0031] In addition to reporting data events that have occurred, such as a copy being transferred from one computing device or application to another, the system can prohibit (by instructions in the tracking tag) other actions, such as deletion, encryption, decryption, etc.
[0032] Tracking database 125 can record reports from one or more computing devices. In some examples, tracking database 125 can aggregate and de-duplicate all events associated with the received records, resulting in a time record of events for each application, computing device, protected data item, and / or similar entity that has accessed specific customer data. This establishes the origin of discrete protected data access by each application and computing device. In some examples, where multiple tracking databases are used, the databases can coordinate with each other to aggregate, associate, and delete the tracking records. For example, a first tracking database (e.g., based on an allocation algorithm) can be selected to collect, associate, and delete records corresponding to a specific customer or other criteria. This tracking database can then extract records corresponding to the criteria from all other tracking databases. These other tracking databases can then delete these records.
[0033] In some examples, for computing device 110 to receive updated protected data items from computing device 115, computing device 110 needs to provide computing device 115 with a copy or part of a tracking tag. Similarly, computing devices 130 or 120 will provide computing device 110 with a copy (or part) of its tracking tag for updated protected data. For examples of pushing updated data from one computing device to another, the receiving computing device may have to periodically determine if it still has the most recent tracking tag by sending the tag to the sending computing device. For example, by periodically sending the tracking tag to the sending computing device. If the receiver fails to send the tracking tag, the next update of the user data may not be sent.
[0034] In some examples, one or more sending or receiving computing devices can instruct other computing devices holding protected data items to delete those data items. For example, the tracking tag may have one or more network addresses registered by the sender or receiver of the user data. Network addresses can be exchanged among the tracking tags. These network addresses can utilize network hooks or other APIs to instruct applications on the computing devices to delete data belonging to one or more tracking tags. This can be based on one or more criteria, such as a tracking identifier, a subject identifier (e.g., an identifier of the user to whom the data pertains), data type, size, date of receipt, etc.
[0035] In some examples, the tracking tag may include an expiration date specifying the amount of time the application can store the data. Once the time expires, the application will delete the data. In some examples, the tracking tag may have executable code run by the receiver that automatically sets a timer, which, when the timer expires, causes the data to be deleted.
[0036] In some examples, the tracking tag is attached to a data item. The tracking tag can be metadata of the data item. In some examples, the tracking tag is embedded in the data item, such as, for example, using watermarking or steganography techniques. Exemplary watermarking embedding techniques include spread spectrum, quantization type, amplitude modulation type, etc.
[0037] Figure 2 The diagram illustrates a message sequence diagram of a data tracking system according to some examples of this disclosure, labeled 200. Protected data can be sent from computing device 210 to computing device 215 using message 235. The protected data may include user data or any other data to be tracked. Computing device 215 may store the protected data. In some examples, computing device 210 may create a tracking tag and send the tracking tag along with the protected data. In other examples, the tracking tag may be created by computing device 215. In some examples, the tracking tag may specify that when computing device 215 receives a copy, computing device 215 registers the copy with tracking database 230. In these examples, computing device 215 may register ownership of the protected data using registration message 238 sent to tracking database 230. The registration message may include one or more portions of the tracking tag. In some examples, the registration message may be sent as a web hook to a URL specified by the tracking tag or otherwise.
[0038] Computing device 220 may be part of a service that is the same as or different from the service provided by computing device 215. Computing device 220 may request protected data using message 240. Computing device 215 may verify that computing device 220 is authorized to access the protected data. For example, if the protected data is user data, computing device 215 may verify that the user has been authorized to share the data.
[0039] Computing device 215 can create tracking tags or reuse tracking tags created by computing device 210 (if computing device 210 initially created the tracking tags). If a tracking tag is reused, it can be updated. Computing device 215 can send protected data with tracking tags using message 245 or using a different message. As described above, the tracking tag can be sent with the protected data or embedded in the protected data (e.g., using a digital watermark), or it can be sent separately from the data in a separate message. In some examples, the tracking tag can have a list of events and corresponding actions to be taken by computing device 220 when an event occurs. For example, an event could be the reception of data, and the action could be registration. Thus, computing device 220 will identify that an event has occurred by receiving data and trigger the action of registering the data. Computing device 220 and / or computing device 215 can register the transmission of protected data to tracking database 230 using messages 250 and / or 255. The message registering the transmission can include the tracking tag, or information from the tracking tag, such as a unique identifier for the data, a source computing device identifier, a destination computing device identifier, etc. Computing device identifiers can include unique identifiers such as Internet Protocol (IP) addresses, domain addresses, and service identifiers.
[0040] In addition to providing data registration, one or more of the computing devices 210, 215, and 220 can employ tracking tags to search for data. For example, where a computing device needs to easily locate data among millions of matching entries, the signature of a tracking tag can be easily searched to find matching data. In some examples where protected data is read and merged into different digital files (e.g., spreadsheets), tracking tags can be stored separately, and links to tracking tags can be created (e.g., in different digital files). In other examples, the protected data can be hashed, and the hash can be associated with a tracking tag (e.g., stored within the tracking tag). When protected data is matched against a tracking tag, the data is hashed and matched against the hash corresponding to the tracking tag. In some examples, a unique identifier for the data in the tracking tag can be or includes the hash of the protected data.
[0041] Computing device 220 can detect events 258 related to protected data. The tracking tag can specify one or more actions to be taken by computing device 220 when one or more of these events occur. In some examples, the actions may include registering the occurrence of the event with one or more tracking databases, such as tracking database 230. For example, in Figure 2The events recorded can be those to be reported to the tracking database 230, which can be done by sending a message 260 to the tracking database 230. The message used to register the event can include the tracking tag, or information from the tracking tag, such as a unique identifier for the data.
[0042] A computing device (such as the owner or subject of protected data) may request an audit of data that matches provided criteria. The subject of the protected data can be the user to whom or what the data (or a portion of the data) relates or describes. For example, if the protected data is location data of a user's device, the user may not "own" the data, but the subject of the data is the user because it describes the user's location. Audit request message 265 may include one or more criteria. Criteria may include returning records of data owned by one or more users, or the subject of one or more users, data type, date range, etc.
[0043] An audit request message 265 can be received from the tracking database 230. The tracking database 230 can search the database for any record that matches the provided criteria. In some examples, the record may indicate that other tracking databases may have matching information. For example, if data is shared with another computing device (not shown) that is reported to a different tracking database. The computing device sharing data with the computing device reporting to the different tracking database can obtain the address of the different tracking database and place the record of that tracking database in the tracking database 230. The tracking database 230 can pass this information back to the computing device 210 (which can then contact that other tracking database individually), or it can contact the other tracking database on behalf of the computing device 210. In the latter case, the tracking database 230 can then aggregate all records from its own database and other tracking databases thus identified, and provide them with an audit response 270.
[0044] Figure 3 The illustration shows a flowchart of a method 300 for sending protected data from a first computing device or application to a second computing device or application according to some examples of this disclosure. At operation 310, the first computing device or application receives a request for a copy of the protected data from the second computing device or application. At operation 315, it is determined whether the second computing device or application is authorized to access the protected data. For example, the data owner or subject may have other preferences regarding privacy or require consultation to ensure that the data is authorized to be shared with the second computing device or application. In other examples, the owner or subject may need to grant explicit permissions to share the data. Other exemplary authentication conditions may include the second computing device or application possessing a security token to prove that it has pre-registered with the first computing device or application.
[0045] If the second computing device or application is not authorized, the flow ends. The first computing device or application may provide a response, or may not provide a response indicating failure. If the second computing device or application is authorized, a tracking tag is created or modified at operation 320. As previously described, a tracking tag may include various fields. In some examples where protected data is received from another computing device and the data already has a tracking tag, the tracking tag may be immutable. In other examples, only specific fields of the tracking tag may be modified, while some fields may remain unmodified. For example, unique identifiers of the data, actions to be taken when an event occurs, etc., are immutable. In some examples, some fields may be modified to indicate that protected data is being transferred from the first computing device or application to the second computing device or application. In other examples, the origin of the data can be traced by adding the recipient to a list of devices that have the data. For example, if the protected data originates from device 1, is sent to device 2, and finally to device 3, the fields in the tracking tag may list all three devices in sequence: device 1 -> device 2 -> device 3.
[0046] At operation 330, the first computing device may send a copy of the protected data with the tracking tag to the second device. At operation 340, in some examples, the first computing device may register an event with the tracking database. In some examples, to register an event, the first computing device may send a tracking tag or a portion of a tracking tag to the tracking database.
[0047] Figure 4 A flowchart illustrating a method 400 for registering events associated with protected data in a tracking database according to some examples of this disclosure is shown. At operation 410, the tracking database may receive a registration message. The registration message may contain information about the event, which may vary based on the event. For example, an event indicating the transfer of a copy from one computing device to another may include source and destination identifiers of the computing devices involved. A data copy made on a single computing device may indicate the location of the copy (e.g., a path name). Other information may be general across events, such as a unique identifier for the protected data. In some examples, the unique identifier may be assigned by the tracking database. In other examples, the unique identifier may be specific to the system that created the tracking tag. In some examples, the information may include an identifier of the owner or subject of the protected data. For example, the identifier of the owner or subject of the protected data may include a user identifier.
[0048] At operation 420, the tracking database can create an event log based on information in the registration message. For example, the tracking database can convert one or more formats of the registration message into a standardized event log format for storage. At operation 430, the access log can be stored in the database. At operation 440, records matching one or more criteria can be aggregated. The one or more criteria can be a specific application, a specific data owner or data subject, a specific time frame, a specific source application or computing device, a specific destination application or computing device, a specific event, etc. Operation 440 can occur periodically and may not necessarily be in response to receiving a registration (but in other examples, it may be in response to receiving a registration).
[0049] Operations 450-480 describe method steps for responding to audit requests, which can be received by the tracking database at any time. At operation 450, the tracking database can receive requests for access log information. For example, audit requests may come from the owner or subject of the data; application developers; auditors; or other users. The request may include one or more criteria, such as a user identifier of the owner or subject, an application identifier (source, destination, or both), etc. At operation 460, the request can be authenticated. For example, a user can be authenticated to access their own data or access logs of data in which they are the subject. In other examples, an application developer can be authenticated to view access logs related to their application, etc. The submitted criteria can be used to determine whether the request should be authenticated. For example, a user can be authenticated to request access logs for some data but not others. If the user is not authenticated, the request may fail.
[0050] Once the request is authenticated, at operation 470, the tracking database can search its database for access logs that match the criteria. This may include retrieving access logs from other tracking databases. For example, if a copy of protected data is sent to another application or service that uses a different tracking database, the source application or service can record the tracking database used by the target application or service in the tracking database used by the source application or service. At operation 480, the matching record is returned to the requesting user.
[0051] Figure 5The diagram illustrates a flowchart of a method 500 for requesting a protected data item from a second application or computing device according to some examples of this disclosure. At operation 510, a request for a copy of the protected data item may be sent. The request may include authentication credentials (e.g., an access token) and identification information for the data. At operation 520, the computing device may receive a copy of the protected data, the copy including a tracking tag. At operation 530, information may be extracted from the tracking tag, such as an identifier of an event and a desired action. In some examples, an event is identified at operation 535, which may include receiving data at operation 520. Other events may include copying, accessing, encrypting, decrypting, deleting, or otherwise using the data. At operation 540, an action may be determined based on the event. For example, a mapping between actions from the tracking tag and events may be referenced. At operation 550, the corresponding action determined at operation 540 may be performed. For example, registering the event with a tracking database. Other actions may include deleting data, notifying a user or other application, etc. Operations 535-550 can be performed in response to any recognized event, not just based on the reception of new data items from operations 510-530. Therefore, operations 535-550 represent operations that can run independently of operations 510-530.
[0052] As previously mentioned, the tracking tag may include a unique application identifier of the application issuing the request, a unique identifier of the client or subject of the data, a unique identifier of the protected data, a unique identifier of the source and / or destination application or service, etc. These identifiers may be assigned by one or more web-based services, tracking databases, etc.
[0053] As previously mentioned, when an event is detected on protected data, the tracking tag can provide an action to be taken. In other examples, the action can specify a link to a source. For example, the source located at the link can provide the action. This allows for dynamically modifiable actions on events that may change after the tracking tag is created. In some examples, specific events may have default actions associated with those events. For example, when a copy of data is first received at a computing device, the default could be to register a copy of the data. These default actions may not be specified in the tracking tag.
[0054] In some examples, events can be registered in the tracking tag itself, instead of a tracking database. The tracking tag can follow the data and list one or more events that occur on the data. This can be beneficial in allowing tracking events, even when the data is passing through a computing device that does not have network access to a tracking database. Once the data moves to a computing device that does have network access, the events in the tracking tag can be reported to the tracking database.
[0055] In some examples, when a protected data item is sent from a first computing device to a second computing device, the first computing device provides the second computing device with a URL of a control resource. The first computing device can then issue instructions (e.g., deletion, encryption, etc.) regarding actions to be taken on a specific protected data item (e.g., identified by a unique identifier) that serves as the control resource. The second computing device can periodically poll the control resource. In other examples, the second computing device can provide the first computing device with a control URL. When the first computing device wants the second computing device to perform an action (e.g., deletion, encryption, etc.) on a specific data item (e.g., identified by a unique identifier), the first computing device can publish a message to the control resource URL (e.g., using a web hook). The second computing device can be notified and can take the requested action. In some examples, this technique can also be used to update a mapping table between actions and events, allowing the table to be dynamically modified after the tracking tag is updated. Because the first computing device publishes an update on a URL created for this purpose, the second computing device can determine which update action should be taken for an event targeting a specific protected data item. The second computing device can update or replace the action in the tracking tag for that event.
[0056] Additionally, as previously mentioned, registration messages can utilize network hooks, allowing applications to register network hooks with the source computing device regarding when a copy or other data event occurs. For example, if application A uses the tracking service described herein to copy customer data, then application A allows application B to copy that data; allowing this may depend on application B (and any subsequent copyers) posting this fact to a network hook designed for this purpose. This would allow the system to track subsequent data copies and other events by third, fourth, fifth, etc., which we then log as a data access event type.
[0057] As mentioned earlier, an event can be something that happens to the protected data. This can extend to events that have occurred over time since another event (such as copying or receiving a protected data item). For example, an action could be deleting the protected data after a threshold amount of time has elapsed since a copy of the protected data was obtained from the computing device.
[0058] Although this disclosure defines a tracking tag for each protected data item, tracking tags can also be more granular. That is, actions and events are defined for accessing specific attributes or portions of the protected data item. For example, attribute A and attribute A+B within the protected data item. In other examples, tracking tags may replace or additionally have actions and events specific to a particular user. This can also be extended to specific attributes of a particular user, etc.
[0059] As described above, in some examples, in order for a second computing device to receive updates to protected data items received from a first computing device, the second computing device may have to prove compliance with the system. For example, by sending all or part of the tracking tag to the first computing device. In other examples, the second computing device may send a value calculated based on the tracking tag to the first computing device (e.g., a hash calculated from the tracking tag). In still other examples, the first computing device may audit the compliance of the second computing device to ensure that it conforms to the system before sending updates.
[0060] In some examples, the tracking database may be a blockchain, and each event log may be a record within the blockchain. Event logs may be unencrypted, or in some examples encrypted using a key that can be used to perform an audit. For example, event registration messages may be sent to one or more nodes on the blockchain, and audit requests may be made by searching for matching records in the blockchain.
[0061] As described above, a digital tracking tag can be associated with an entire copy of a protected data segment, or it can be attached to one or more portions or subsets of the protected data segment. In the latter example, a specific portion of the protected data can be tracked, or it can be left untracked. The protected portion can be identified by a pointer, hash, or other identifier in the tracking tag. In some examples, when an event associated with the data occurs, a specified action will be performed regardless of which portion the event occurs in. In other examples, the specified action can be performed only for events occurring on the data portion identified by the pointer, hash, or other identifier. If the tracked portion and the untracked portion of the protected data are separated, the tracking tag can continue to accompany the untracked portion or not (depending on the embodiment). The tracked portion can continue to be attached to the tracking tag. Depending on the event rules in the tracking tag, the separation can be reported.
[0062] In cases where a data item is protected and tracked by tracking tags, when the protected data segment is split into multiple parts, one part can be stored in a first location, and the second part in a second location. In some examples, the same digital tracking tag can be applied to both parts. In other examples, different digital tracking tags can be applied to different parts. In either example, the tag can be modified to reflect the storage and / or splitting at the new location. Similarly, when two different data segments are combined into a single data segment, these two data segments can have two different tracking tags. Each tracking tag can be maintained so that a single data segment can now have two different tracking tags.
[0063] Figure 6The illustration shows a schematic diagram of a computing device 605 and a tracking database 622 according to some examples of this disclosure. Components of the computing device 605 and the tracking database 622 can be implemented in hardware, such as in… Figure 7 The hardware shown is a computing device 605. The computing device 605 may be an example of computing devices 115, 110, 130, 120, 210, 215, or 220. Those skilled in the art who will benefit from this disclosure will understand that additional components, not shown, may be present on the computing device 605. For example, an operating system, applications, etc. The computing device 605 can execute... Figure 3 and Figure 5 One or more of the methods shown.
[0064] Computing device 605 may have an input / output interface 610. The input / output interface 610 can process and manage input and output requests for protected data. The input / output interface 610 may implement one or more application programming interfaces (APIs) specifying protocols for requesting and receiving protected data. The input / output interface 610 may, according to the protocol, send and receive packets from one or more other computing devices over a network via a network device (e.g., an Ethernet device or a wireless networking device) in one or more messages.
[0065] Tracking tag manager 612 can create and / or update tracking tags in response to requests for protected data. Tracking tag manager 612 can determine which data is protected—for example, by identifying the presence of tracking tags on the data; by identifying tracking tags associated with the data; or by identifying the class or type of data to be protected. Tracking tag manager 612 can create or update tracking tags before sending protected data to another device or during the collection or identification of protected data. Tracking tag manager 612 can catalog the tracking tags of data stored in storage device 620. For example, by storing tracking tags in storage device 620 together with the data or separately. If tracking tags are stored separately from the data, tracking tag manager 612 can have a data structure that links tracking tags to the location where the protected data is stored. Tracking tag manager 612 can also update and manage an event and action table based on tracking tags. This table can specify the action to be taken for each protected data item's event. In some examples, the tracking tag manager 612 can register events with the event monitor 614 for specific data items, indicating actions of one or more tracking tags managed by the tracking tag manager 612.
[0066] Event monitor 614 can monitor events corresponding to data items registered by the tracking tag manager. When an event is detected, details of the event are sent to action manager 616. For example, event monitor 614 can monitor the operating system's file system. Action manager 616 can consult an event and action table to determine an appropriate action. Action manager 616 can execute the appropriate action. Exemplary actions may include registering with tracking database 622. Storage device 620 can store protected data, tracking tags, event and action tables, etc.
[0067] Tracing database 622 may be an example of tracing databases 125 and 230. Those skilled in the art who benefit from this disclosure will understand that additional components, not shown, may be present on computing device 622. For example, operating system, applications, etc. Computing device 622 can execute... Figure 4 The method shown.
[0068] The tracking database 622 may have an input / output interface 625. The input / output interface 610 can handle requests to register events associated with protected data and audit requests. The input / output interface 625 can implement one or more application programming interfaces (APIs) specifying protocols for registering events. The input / output interface 610 can send and receive packets from one or more other computing devices over a network via a network device (e.g., an Ethernet device or a wireless networking device) according to the protocol.
[0069] Registration manager 630 can receive registration messages and convert them from a first format specified by the API to a second format according to the database schema for storage as records in storage device 660. Audit manager 640 can process audit requests. The audit manager can receive audit requests from input / output interface 625 and can authenticate such requests. Once the request is authenticated, input / output interface 625 can search storage device 660 to find records that match the criteria submitted with the request. The response result is sent to the requester via input / output interface 625. Database manager 650 can aggregate and / or summarize records according to criteria such as the application sending the record, the computing device sending the record, the owner or subject of the protected data, and the identifier of the protected data. Database manager 650 can also manage and maintain the database stored in storage device 660.
[0070] Figure 7A block diagram of an exemplary machine 700 is illustrated, on which any one or more of the techniques (e.g., methods) discussed herein can be executed. In alternative embodiments, machine 700 can operate as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, machine 700 can operate as a server machine, a client machine, or both in a server-client network environment. In the example, machine 700 can act as a peer-to-peer (P2P) (or other distributed) network environment. Machine 700 can be a computing device (e.g., computing devices 110, 115, 120, 130), a tracking database 125, etc. Machine 700 can perform... Figure 3-5 One or more of the methods shown. Machine 700 may take the form of a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), mobile phone, smartphone, network device, network router, switch or bridge, or any machine capable of executing instructions (sequentially or otherwise) specifying actions to be taken by said machine. Furthermore, although only a single machine is illustrated, the term "machine" should also be understood to include any collection of machines that individually or jointly execute a set (or more) of instructions to perform any one or more methods discussed herein, such as cloud computing, Software as a Service (SaaS), and other computer cluster configurations.
[0071] Examples as described herein may include or operate logic or multiple components, modules, or mechanisms. A module is a tangible entity (e.g., hardware) capable of performing a specified operation and may be configured or arranged in a certain way. In the examples, circuitry may be arranged as a module in a specified manner (e.g., internal or external to an entity such as other circuitry). In the examples, all or part of one or more computer systems (e.g., standalone, client, or server computer systems) or one or more hardware processors may be configured by firmware or software (e.g., instructions, application portions, or applications) to operate to perform the specified operation. In the examples, the software may reside on a machine-readable medium. In the examples, when executed by the underlying hardware of the module, the software causes the hardware to perform the specified operation.
[0072] Therefore, the term "module" is understood to include tangible entities, that is, entities that are physically constructed, specifically configured (e.g., hardwired) or temporarily (e.g., provisionally) configured (e.g., programmed) to operate or perform any of the operations described herein in a particular manner. Considering the example of temporarily configured modules, each module does not need to be instantiated at any given time. For example, in the case where modules include a general-purpose hardware processor configured using software, the general-purpose hardware processor can be configured as different modules at different times. The software can thus configure the hardware processor, for example, to constitute a particular module at one time instance and different modules at different time instances.
[0073] Machine (e.g., computer system) 700 may include a hardware processor 702 (e.g., a central processing unit (CPU), graphics processing unit (GPU), hardware processor core, or any combination thereof), main memory 704, and static memory 706, some or all of which may communicate with each other via interconnect (e.g., bus) 708. Machine 700 may also include a display unit 710, an alphanumeric input device 712 (e.g., keyboard), and a user interface (UI) navigation device 714 (e.g., mouse). In the example, display unit 710, input device 712, and UI navigation device 714 may be a touchscreen display. Machine 700 may also include a storage device (e.g., drive unit) 716, a signal generation device 718 (e.g., speaker), a network interface device 720, and one or more sensors 721, such as a global positioning system (GPS) sensor, compass, accelerometer, or other sensors. Machine 700 may include output controller 728, for example, serial (e.g., Universal Serial Bus (USB), parallel, or other wired or wireless (e.g., infrared (IR), near field communication (NFC), etc.) connection, to communicate or control one or more peripheral devices (e.g., printer, card reader, etc.).
[0074] Storage device 716 may include machine-readable medium 722 on which one or more sets of data structures or instruction sets 724 (e.g., software) are stored, said data structures or instruction sets embodying or being used by any one or more of the techniques or functions described herein. Instructions 724 may also reside wholly or at least partially in main memory 704, static memory 706, or hardware processor 702 during execution of machine 700. In the example, one or any combination of hardware processor 702, main memory 704, static memory 706, or storage device 716 may constitute a machine-readable medium.
[0075] Although the machine-readable medium 722 is shown as a single medium, the term "machine-readable medium" can include a single medium or multiple media (e.g., a centralized or distributed database, and / or associated caches and servers) configured to store one or more instructions 724.
[0076] The term "machine-readable medium" can include any medium capable of storing, encoding, or carrying instructions for execution by machine 700 and causing machine 700 to perform any one or more of the technologies disclosed herein, or a data structure capable of storing, encoding, or carrying data used by or associated with such instructions. Examples of non-limiting machine-readable media can include solid-state memory as well as optical and magnetic media. Specific examples of machine-readable media can include: non-volatile memory, such as semiconductor memory devices (e.g., electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM)) and flash memory devices; disks, such as internal hard disks and removable disks; magneto-optical disks; random access memory (RAM); solid-state drives (SSDs); and CD-ROMs and DVD-ROMs. In some examples, machine-readable media can include non-transitory machine-readable media. In some examples, machine-readable media can include machine-readable media that are not transient propagating signals.
[0077] Instruction 724 can also be sent or received on communication network 726 via network interface device 720 using a transmission medium. Machine 700 can communicate with one or more machines using any of a variety of transmission protocols, such as Frame Relay, Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Hypertext Transfer Protocol (HTTP), etc. Exemplary communication networks may include local area networks (LANs), wide area networks (WANs), packet data networks (e.g., the Internet), mobile phone networks (e.g., cellular networks), common legacy telephone (POTS) networks, and wireless data networks (e.g., the IEEE 802.11 standard series known as Wi-Fi®, the IEEE 802.16 standard series known as WiMAX®), the IEEE 802.15.4 standard series, the Long Term Evolution (LTE) standard series, the Universal Mobile Telecommunications System (UMTS) standard series, peer-to-peer (P2P) networks, etc. In the example, network interface device 720 may include one or more physical jacks (e.g., Ethernet, coaxial, or telephone jacks) or one or more antennas for connection to communication network 726. In the example, network interface device 720 may include multiple antennas to perform wireless communication using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) technologies. In some examples, network interface device 720 may use multi-user MIMO technology for wireless communication.
[0078] Other notes and examples
[0079] Example 1 is a method for tracking user data shared among multiple computing devices, the method comprising: at a first computing device: sending a request to a second computing device for a copy of a data item stored by the second computing device; receiving from the second computing device the copy of the data item, the copy including a tracking tag specific to the data item, the tracking tag including data for identifying an identifier of the data item and a mapping between one or more actions to be performed and one or more events associated with the copy of the data item; extracting the identifier and mapping of the data item contained in the tracking tag associated with the copy of the data item; determining that a first event has occurred corresponding to the copy of the data item; determining a first action corresponding to the first event based on the tracking tag, the first action including a registration action to a tracking database identified in the mapping; and responding to determining the first action. The process includes: registering the occurrence of the event in a first access record of the tracking database using the identifier of the extracted data item and information about the tracking database identified in the mapping; at the tracking database: recording the occurrence of the event in the first access record; aggregating a first plurality of access records in the tracking database corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; receiving a request for access record information at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and the tracking database providing a second plurality of records matching the search criteria, the second plurality of records being selected from the first plurality of access records and including the first access record.
[0080] In Example 2, the subject of Example 1 includes, wherein the data used to determine the identifier of the data item and the mapping includes pointers to network locations where the identifier and the mapping are stored.
[0081] In Example 3, the subject matter of Examples 1-2 includes, wherein the data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
[0082] In Example 4, the subject matter of Examples 1-3 includes, wherein the tracking label is a watermark, and wherein the operation of extracting the identifier and the mapping of the data item contained in the tracking label associated with the copy of the data item includes reading the watermark.
[0083] In Example 5, the subject matter of Examples 1-4 includes, wherein the tracking tag includes source and destination identifiers of the computing device.
[0084] In Example 6, the subject of Examples 1-5 includes, wherein recording the occurrence of the event includes recording the access record as a node in the blockchain.
[0085] In Example 7, the subject of Examples 1-6 includes the tracking tag comprising executable code that, when run, causes the first computing device to perform the registration.
[0086] Example 8 is a system for tracking user data shared among multiple computing devices, the system comprising: a first computing device including: a first processor; a first memory storing instructions, the instructions which, when executed by the first processor, cause the first computing device to perform operations including: sending a request to a second computing device for a copy of a data item stored by the second computing device; receiving the copy of the data item from the second computing device, the copy including a tracking tag specific to the data item, the tracking tag including data for determining an identifier of the data item and a mapping between one or more actions to be performed and one or more events associated with the copy of the data item; extracting the identifier of the data item and the mapping contained in the tracking tag associated with the copy of the data item; determining that a first event has occurred corresponding to the copy of the data item; determining a first action corresponding to the first event based on the tracking tag, the first action including a registration action to a tracking database identified in the mapping; and responding to determining the first event... An action includes a registration action, registering the occurrence of the event in a first access record of the tracking database using an identifier of the extracted data item and information about the tracking database identified in the mapping; the tracking database includes: a second processor; a second memory including instructions that, when executed by the second processor, cause the tracking database to perform operations including: recording the occurrence of the event in the first access record; aggregating a first plurality of access records in the tracking database corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; receiving a request for access record information at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and the tracking database providing a second plurality of records matching the search criteria, the second plurality of records being selected from the first plurality of access records and including the first access record.
[0087] In Example 9, the subject of Example 8 includes, wherein the data used to determine the identifier of the data item and the mapping includes pointers to network locations where the identifier and the mapping are stored.
[0088] In Example 10, the subject of Examples 8-9 includes, wherein the data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
[0089] In Example 11, the subject of Examples 8-10 includes, wherein the tracking label is a watermark, and wherein the operation of extracting the identifier and the mapping of the data item contained in the tracking label associated with the copy of the data item includes reading the watermark.
[0090] In Example 12, the subject of Examples 8-11 includes, wherein the tracking tag includes source and destination identifiers of the computing device.
[0091] In Example 13, the subject of Examples 8-12 includes the operation of recording the occurrence of the event, which includes recording the access record as a node in the blockchain.
[0092] In Example 14, the subject of Examples 8-13 includes the following: the tracking tag includes executable code that, when run, causes the first computing device to perform the registration.
[0093] Example 15 is a system comprising: a first computing device, including: units for sending a request to a second computing device for a copy of a data item stored by the second computing device; units for receiving the copy of the data item from the second computing device, the copy including a tracking tag specific to the data item, the tracking tag including data for determining an identifier of the data item and a mapping between one or more actions to be performed and one or more events associated with the copy of the data item; units for extracting the identifier of the data item and the mapping contained in the tracking tag associated with the copy of the data item; units for determining that a first event has occurred corresponding to the copy of the data item; units for determining a first action corresponding to the first event based on the tracking tag, the first action including a registration action to a tracking database identified in the mapping; and units for responding to determining that the first action includes the registration action. The tracking database includes: a unit for registering the occurrence of the event in a first access record of the tracking database using the identifier of the extracted data item and information about the tracking database identified in the mapping; the tracking database includes: a unit for recording the occurrence of the event in the first access record; a unit for aggregating a first plurality of access records in the tracking database corresponding to the data item, the first plurality of access records including a first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; a unit for receiving a request for access record information at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and a unit for providing a second plurality of records matched by the search criteria from the tracking database, the second plurality of records being selected from the first plurality of access records and including the first access record.
[0094] In Example 16, the subject of Example 15 includes, wherein the data used to determine the identifier of the data item and the mapping includes pointers to network locations where the identifier and the mapping are stored.
[0095] In Example 17, the subject matter of Examples 15-16 includes, wherein the data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
[0096] In Example 18, the subject matter of Examples 15-17 includes, wherein the tracking tag is a watermark, and wherein the unit for extracting the identifier and the mapping of the data item contained in the tracking tag associated with the copy of the data item includes a unit for reading the watermark.
[0097] In Example 19, the subject of Examples 15-18 includes, wherein the tracking tag includes source and destination identifiers of the computing device.
[0098] In Example 20, the subject of Examples 15-19 includes, wherein the unit for recording the occurrence of the event includes a unit for recording the access record as a node in the blockchain.
[0099] In Example 21, the subject of Examples 15-20 includes the tracking tag comprising executable code that, when run, causes the first computing device to perform the registration.
[0100] Example 22 is a machine-readable medium storing instructions that, when executed by a machine, cause the machine to perform operations including: at a first computing device: sending a request to a second computing device for a copy of a data item stored by the second computing device; receiving from the second computing device the copy of the data item, the copy including a tracking tag specific to the data item, the tracking tag including data for determining an identifier of the data item and a mapping between one or more actions to be performed and one or more events associated with the copy of the data item; extracting the identifier of the data item and the mapping contained in the tracking tag associated with the copy of the data item; determining that a first event has occurred corresponding to the copy of the data item; determining a first action corresponding to the first event based on the tracking tag, the first action including a registration action to a tracking database identified in the mapping; in response to determining... The first action includes a registration action, registering the occurrence of the event in a first access record of the tracking database using the identifier of the extracted data item and information about the tracking database identified in the mapping; at the tracking database: recording the occurrence of the event in the first access record; aggregating a first plurality of access records in the tracking database corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; receiving a request for access record information at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and the tracking database providing a second plurality of records that match the search criteria, the second plurality of records being selected from the first plurality of access records and including the first access record.
[0101] In Example 23, the subject of Example 22 includes, wherein the data used to determine the identifier of the data item and the mapping includes pointers to network locations where the identifier and the mapping are stored.
[0102] In Example 24, the subject matter of Examples 22-23 includes, wherein the data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
[0103] In Example 25, the topics of Examples 22-24 include, wherein the tracking label is a watermark, and wherein the operation of extracting the identifier and the mapping of the data item contained in the tracking label associated with the copy of the data item includes reading the watermark.
[0104] In Example 26, the subject of Examples 22-25 includes, wherein the tracking tag includes source and destination identifiers of the computing device.
[0105] In Example 27, the subject of Examples 22-26 includes, wherein recording the occurrence of the event includes recording the access record as a node in the blockchain.
[0106] In Example 28, the subject of Examples 22-27 includes the following: the tracking tag includes executable code that, when run, causes the first computing device to perform the registration.
[0107] Example 29 is at least one machine-readable medium including instructions that, when executed by processing circuitry, cause the processing circuitry to perform an operation to implement any one of Examples 1-28.
[0108] Example 30 is an apparatus that includes a unit for implementing any of Examples 1-28.
[0109] Example 31 is a system for implementing any one of Examples 1-28.
[0110] Example 32 is a method for implementing any of Examples 1-28.
Claims
1. A system for tracking user data shared among multiple computing devices, the system comprising: A first computing device, comprising: First processor; A first memory stores instructions that, when executed by the first processor, cause the first computing device to perform operations including: Send a request to the second computing device for a copy of the data item stored by the second computing device; The copy of the data item is received from the second computing device, the copy including a digital tracking tag specific to the data item, the digital tracking tag including an identifier for determining the data item and data mapping between one or more actions to be performed and one or more events associated with the copy of the data item; Extract the identifier and the mapping of the data item contained in the digital tracking tag associated with the copy of the data item; A first event has occurred corresponding to the copy of the data item; Based on the digital tracking tag, a first action corresponding to the first event is determined, the first action including a registration action with a tracking database identified in the mapping; In response to determining that the first action includes a registration action, the occurrence of the event is registered in a first access record of the tracking database using the identifier of the extracted data item and the address of the tracking database identified in the mapping; The tracking database includes: Second processor; A second memory, comprising instructions that, when executed by a second processor, cause the tracking database to perform operations including: The occurrence of the event is recorded in the first access record; The tracking database is aggregated to include a first plurality of access records corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; A request for access record information is received at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and The tracking database provides a second plurality of records that match the search criteria, the second plurality of records being selected from the first plurality of access records and including the first access records.
2. The system according to claim 1, wherein, The data used to determine the identifier of the data item and the mapping includes pointers to the network locations where the identifier and the mapping are stored.
3. The system according to claim 1, wherein, The data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
4. The system according to claim 1, wherein, The digital tracking tag is a watermark, and the operation of extracting the identifier and the mapping of the data item contained in the digital tracking tag associated with the copy of the data item includes reading the watermark.
5. The system according to claim 1, wherein, The digital tracking tag includes source and destination identifiers for the computing device.
6. The system according to claim 1, wherein, The operation of recording the occurrence of the first event includes recording the access record as a node in the blockchain.
7. The system according to claim 1, wherein, The digital tracking tag includes executable code that, when executed, causes the first computing device to perform the registration.
8. A method for tracking user data shared among multiple computing devices, the method comprising: At the first computing device: Send a request to the second computing device for a copy of the data item stored by the second computing device; The copy of the data item is received from the second computing device, the copy including a digital tracking tag specific to the data item, the digital tracking tag including an identifier for determining the data item and data mapping between one or more actions to be performed and one or more events associated with the copy of the data item; Extract the identifier and the mapping of the data item contained in the digital tracking tag associated with the copy of the data item; A first event has occurred corresponding to the copy of the data item; Based on the digital tracking tag, a first action corresponding to the first event is determined, the first action including a registration action with a tracking database identified in the mapping; In response to determining that the first action includes a registration action, the occurrence of the event is registered in a first access record of the tracking database using the identifier of the extracted data item and the address of the tracking database identified in the mapping; At the aforementioned tracking database: The occurrence of the event is recorded in the first access record; The tracking database is aggregated to include a first plurality of access records corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; A request for access record information is received at the tracking database. The request includes one or more search criteria that identify the data item. The request is received from a fourth computing device. as well as The tracking database provides a second plurality of records that match the search criteria, the second plurality of records being selected from the first plurality of access records and including the first access records.
9. The method according to claim 8, wherein, The data used to determine the identifier of the data item and the mapping includes pointers to the network locations where the identifier and the mapping are stored.
10. The method according to claim 8, wherein, The data used to determine the identifier of the data item and the mapping includes the identifier of the data item and the mapping.
11. The method according to claim 8, wherein, The digital tracking tag is a watermark, and the operation of extracting the identifier and the mapping of the data item contained in the digital tracking tag associated with the copy of the data item includes reading the watermark.
12. The method according to claim 8, wherein, The digital tracking tag includes source and destination identifiers for the computing device.
13. The method according to claim 8, wherein, The operation of recording the occurrence of the first event includes recording the access record as a node in the blockchain.
14. A system comprising: A first computing device, comprising: A unit for sending a request to a second computing device for a copy of a data item stored by the second computing device; A unit for receiving a copy of the data item from the second computing device, the copy including a digital tracking tag specific to the data item, the digital tracking tag including data for determining an identifier of the data item and a mapping between one or more actions to be performed and one or more events associated with the copy of the data item; A unit for extracting the identifier and the mapping of the data item contained in the digital tracking tag associated with the copy of the data item; A unit for determining that a first event has occurred corresponding to the copy of the data item; A unit for determining a first action corresponding to the first event based on the digital tracking tag, the first action including a registration action to a tracking database identified in the mapping; A unit for registering the occurrence of the event in a first access record of the tracking database in response to determining that the first action includes a registration action, using the identifier of the extracted data item and the address of the tracking database identified in the mapping; The tracking database includes: A unit for recording the occurrence of the event in the first access record; A unit for aggregating a first plurality of access records in the tracking database corresponding to the data item, the first plurality of access records including the first access record and at least one other access record corresponding to a third computing device having a second copy of the data item; A unit for receiving a request for access record information at the tracking database, the request including one or more search criteria that identify the data item, the request being received from a fourth computing device; and A unit for providing a second plurality of records that match the search criteria from the tracking database, the second plurality of records being selected from and including the first plurality of access records.
15. The system according to claim 14, wherein, The data used to determine the identifier of the data item and the mapping includes pointers to the network locations where the identifier and the mapping are stored.
Citation Information
Patent Citations
Tracing unauthorized use of secure modules
CN102209266A
Method and system for securing cloud storage and databases from insider threats and optimizing performance
US10402589B1