Method for protecting sensitive data and data storage system
By using sensitive data detection tools and API management permissions in the data storage system, the problems of data leakage and external leakage are solved, effectively protecting sensitive data and improving the security of the data storage system.
Patent Information
- Application Number
- CN202280101705.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
In protecting sensitive data within files and/or data objects in data storage systems, prior art is difficult to effectively prevent data leakage and data leakage.
By detecting the area of interest of the data storage system based on sensitive data detection tools, generating a list of files and/or data objects for sensitive data, and using the API of the data storage system to set a predefined user as the owner of the file or data object, restricting access rights of other users.
This method can detect sensitive data and automatically generate file system permissions, improve the protection of sensitive data, improve the security of data storage system, and prevent data leakage and data leakage.
Smart Images

Figure CN120202470A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to protecting sensitive data, and more particularly, to methods for protecting sensitive data within files and / or data objects in a data storage system. Background Art
[0002] Data privacy is becoming increasingly important. In more than 80 countries and regions, personally identifiable information (PII) is protected by information privacy laws, which impose restrictions on the collection and use of PII by public and private organizations. These laws require organizations to clearly inform individuals about what data is being collected, why it is being collected, and how it is planned to be used. In consent-based legal frameworks, such as the European Union's General Data Protection Regulation (GDPR), explicit consent from individuals is required. The GDPR extends the scope of EU data protection laws to all foreign companies that process the data of EU residents. It requires all companies to provide data breach notifications, appoint data protection officers, obtain user consent for data processing, anonymize data to protect privacy, etc. The United States also has laws regulating data breach disclosures. All 50 states in the US have data breach laws that, in some form, require affected parties to be notified as soon as possible, the government to be informed promptly, and some fines to be paid. Additionally, many other countries and regions have enacted legislation on data privacy protection, and more are in the process of doing so. The first step in protecting sensitive data is data classification. Different levels of protection are required depending on the sensitivity of the data. The key is to understand that not all data is equal, and it is best to focus the user's data protection efforts on protecting the sensitive data defined above. Examples of non-sensitive information include public information and everyday business information. Public information refers to information that already belongs to public records or knowledge, and everyday business information refers to business information that is regularly shared with anyone inside or outside any organization. Effective information security starts with assessing what information the user has and determining who has access rights. Understanding how sensitive data flows in, through, and out of any organization is crucial for assessing potential vulnerabilities and cybersecurity risks. This means figuring out all the places where the organization uses sensitive data, as well as where the organization gives sensitive data to third and fourth-party vendors. This will support the organization in understanding how information flows within the organization and give the organization a complete picture of who sends personal information to the organization, who receives sensitive data, what information is collected, who is in custody of the collected information, and who has access to this information. Most operating systems (OS) today are multi-user operating systems that can be accessed by many users simultaneously. Each file on a computer has file permissions. File permissions are attributes of a file that determine who has access to the file and what operations they can perform on the file. File permissions are determined by the system administrator, who is simply a user of the administrator account on the computer or a user who manages the computer network system, such as an IT administrator in an organization. The system administrator has full access to all files on the computer and can change the permissions of these files. Therefore, he or she has the power to decide who can access which files on the network.
[0003] There are three types of file permissions: (i) read (r) - allows users to read the file but not make any other edits, (ii) write (w) - allows users to read and write to the file, so they can make changes to the file, but if the file is a program, they cannot execute it, and (iii) execute (x) - allows users to execute the file. So, if the file is Python code, for example, or a bash script, the user must have execute permission to run the program.
[0004] Many organizations will have an IT department, or even an external company, to handle all IT and system administration issues, but sometimes in small businesses, there may be no IT staff to handle IT and system administration issues. System administrators may write scripts that only he or she needs to be able to run on the network. No other users should have execute permission for these files. They don't need to execute these scripts, and keeping these permissions could lead to these files being accidentally executed when they're not supposed to be (maybe there are scripts that delete certain types of data, and the user doesn't want anyone to accidentally delete the data). Other times, certain employees don't need access to certain files, such as company plans, customer lists, incorporation documents, or contracts. Administrators can restrict write permissions so that no one can change or tamper with these files. Or, the administrator may even want to restrict all permissions, including read permissions, so that no one except certain employees or members can view these files. Just some things should remain private and not everyone in the organization needs access to them. On the other hand, there may even be sensitive information on our personal computers, such as credit card numbers, social security numbers, addresses, etc., that we don't want other users on our computers or network to be able to access.
[0005] The most important reason for implementing good file permission management is to protect their data. Hacking attacks, data breaches, and ransomware attacks are becoming increasingly common and sophisticated every day. At this point, even small organizations cannot afford these attacks. These malicious actors target not only large companies and groups but also small organizations that handle sensitive or large amounts of information, such as law firms or healthcare companies. An example where file permissions can play a role is a ransomware attack. A ransomware attack occurs when an external party places malware on a computer or computers in a network and encrypts all of the user's files, making them inaccessible to the user. Then one or more attackers typically demand a ransom for the encryption key. The malware can encrypt any file that the infected user originally had write permissions to. These attacks are very common and can occur in the simplest ways, such as clicking on a link in an email or even losing a laptop. There are many simple ways to guard against this, such as having good backups, avoiding unknown email links or phishing scams, and not connecting external or unknown devices to the computer. In this case, the most overlooked way to prevent large-scale data loss is to manage the file permissions of users. If users do not have write permissions to certain files, then those files will not be encrypted. To this end, users must implement appropriate file permissions across the network.
[0006] Therefore, the above technical problems / defects in protecting sensitive data within files and / or data objects in a data storage system need to be addressed by preventing data breaches and data exfiltration. Summary of the Invention
[0007] An object of the present disclosure is to provide methods for protecting sensitive data within files and / or data objects in a data storage system while avoiding one or more drawbacks of existing technology methods.
[0008] This object is achieved by the features of the independent claims. Other implementations are apparent from the dependent claims, the description, and the drawings.
[0009] The present disclosure provides methods for protecting sensitive data within files and / or data objects in a data storage system.
[0010] According to a first aspect, a method for protecting sensitive data within files and / or data objects in a data storage system is provided. The method includes: generating a first list of files and / or data objects including sensitive data in a region of interest in the data storage system based on detection results of sensitive data records in the region of interest by a sensitive data detection tool. The method includes: for each file or data object in the first list, using an application programming interface (API) of the data storage system to set one or more predefined users of the storage system as the owner of the file or data object. The method includes: for each file or data object in the first list, using the API of the data storage system to set the permissions of the file or data object to restrict access to the file or data object by one or more users in a predefined second group of the data storage system.
[0011] The method can detect sensitive data. The method can automatically generate file system permissions based on sensitive data detection. The method improves sensitive data protection through the automatic generation of file system permissions, thereby enhancing the security of the data storage system. The method prevents data leakage and data exfiltration.
[0012] Optionally, the sensitive data includes personally identifiable information (PII), and the sensitive data detection tool is used to detect PII records.
[0013] Optionally, the predefined first group and / or the predefined second group includes administrators of the data storage system.
[0014] Optionally, the predefined second group is the same as the predefined first group.
[0015] Optionally, the region of interest includes the entire data storage system.
[0016] Optionally, the method further includes periodically and / or in response to a user request repeating the steps of the above method.
[0017] Optionally, the method further includes: before generating the first list, (i) obtaining changes introduced into one or more files and / or one or more data objects in the data storage system by a computing system from an input-output (IO) interceptor, (ii) determining the region of interest to include the one or more changed files and / or one or more data objects.
[0018] According to a second aspect, a method for protecting sensitive data within files and / or data objects in a data storage system is provided. The method includes: generating a first list of files and / or data objects including sensitive data in a region of interest of the data storage system based on detection results of sensitive data records in the region of interest by a sensitive data detection tool. The method includes, for each file or data object in the first list, generating a second list of sensitive data records detected within the file or data object. Each sensitive data record in the second list includes the type and value of the detected sensitive data record. The method includes: obtaining a user mapping from a personal identifier (ID) to a system ID for all users of the data storage system. The method includes, for each file or data object in the first list, generating a third list of one or more users of the storage system, the one or more users being described by or associated with the sensitive data records in the second list associated with the file or data object. The method includes, for each file or data object in the first list, using an application programming interface (API) of the data storage system and the system IDs of one or more users in a predefined first group of the storage system to assign the first group of one or more users as the owner of the file or data object. The method includes, for each file or data object in the first list, using the API and the system IDs of one or more users in the third list to set permissions for the file or data object to restrict access to the file or data object by the one or more users in the third list.
[0019] The method can detect sensitive data. The method can automatically generate file system permissions based on the detection of sensitive data. The method improves sensitive data protection through the automatic generation of file system permissions, thereby enhancing the security of the data storage system. The method prevents data leakage and data exfiltration.
[0020] Optionally, the sensitive data includes personally identifiable information (PII), and the sensitive data detection tool is used to detect PII records.
[0021] Optionally, the predefined first group and / or the predefined second group includes administrators of the data storage system.
[0022] Optionally, setting the permissions for the file or data object includes (i) creating a third group of the system IDs of one or more users in the third list, and (ii) setting the permissions for the file or data object to restrict access to the file or data object by the created third group.
[0023] Optionally, each sensitive data record in the second list further includes the offset of the detected sensitive data record within the file or data object.
[0024] Optionally, the method further includes: after generating the third list, obtaining a graph depicting the correlation between all sensitive data records detected in the file and / or data object based on the detection results of the sensitive data records in the area of interest by the sensitive data detection tool, (ii) for each file or data object in the first list, scanning the graph using a predefined distance, and supplementing the third list with one or more additional users, where the one or more additional users are described by or related to one or more sensitive data records, and the one or more sensitive data records are detected in the file or data object and another file or data object in the first list.
[0025] Optionally, the area of interest includes the entire data storage system.
[0026] Optionally, the method further includes periodically and / or in response to a user request repeating the steps of the above method.
[0027] Optionally, the method further includes: before generating the third list, (i) obtaining changes introduced by the computing system into one or more files and / or one or more data objects in the data storage system from an input-output (IO) interceptor, (ii) determining the area of interest to include the one or more files and / or one or more data objects that have changed.
[0028] According to a third aspect, there is provided a data storage system for storing files and / or data objects having sensitive data. The data storage system includes: a communication unit for receiving data from a computing system; a processing unit for performing the steps of the above method using a sensitive data detection tool.
[0029] Enable the processing unit of the data storage system to detect sensitive data. The processing unit can automatically generate file system permissions based on sensitive data detection. By automatically generating file system permissions, the processing unit improves sensitive data protection, thereby enhancing the security of the data storage system. The processing unit prevents data leakage and data exfiltration.
[0030] These and other aspects of the present disclosure will be apparent from one or more implementations described below. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Implementations of the present disclosure will be described below by way of example only, with reference to the accompanying drawings, in which:
[0032] Figure 1Block diagram of a data storage system according to an implementation of the present disclosure;
[0033] Figure 2 Exemplary table view of the mapping from a user's personal ID to a user file system ID according to an implementation of the present disclosure;
[0034] Figure 3 Exemplary graph of the correlation between all sensitive data records detected in a file and / or data object according to an implementation of the present disclosure;
[0035] Figure 4A Exemplary file system view before protecting sensitive data in a file and / or data object in a data storage system according to an implementation of the present disclosure;
[0036] Figure 4B Exemplary file system view after protecting sensitive data in a file and / or data object in a data storage system according to an implementation of the present disclosure;
[0037] Figure 5A and Figure 5B Flowchart of a method for protecting sensitive data in a file and / or data object in a data storage system using the API of the data storage system according to an implementation of the present disclosure;
[0038] Figures 6A to 6C Flowchart of a method for protecting sensitive data in a file and / or data object in a data storage system using an API and a system ID according to an implementation of the present disclosure;
[0039] Figure 7 Illustration of a computer system (such as a data storage system) in which various architectures and functions of the foregoing various implementations can be implemented. Detailed Description
[0040] Implementations of the present disclosure provide methods for protecting sensitive data in a file and / or data object in a data storage system.
[0041] To make the solutions of the present disclosure easier to understand for those skilled in the art, the following implementations of the present disclosure are described with reference to the accompanying drawings.
[0042] The terms "first", "second", "third", and "fourth" (if any) in the summary of the disclosure, the claims, and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific sequence or order. It should be understood that the terms used in this way are interchangeable under appropriate circumstances, so that the implementations of the present disclosure described herein can be implemented, for example, in a sequence other than the sequences shown or described herein. In addition, the terms "comprising" and "having" and any variants thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device comprising a series of steps or units is not necessarily limited to the steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such a process, method, product, or device.
[0043] Figure 1 FIG. 4 is a block diagram of a data storage system 100 for storing files and / or data objects having sensitive data according to an implementation of the present disclosure. The data storage system 100 includes a communication unit 102 and a processing unit 104. The communication unit 102 is configured to receive data from a computing system 106. The processing unit 104 is configured to protect sensitive data within files and / or data objects in the data storage system 100 using a sensitive data detection tool 108.
[0044] The processing unit 104 is configured to generate a first list of files and / or data objects including sensitive data in the area of interest of the data storage system 100 based on the detection results of the sensitive data records in the area of interest of the data storage system 100 by the sensitive data detection tool 108. The processing unit 104 is configured to, for each file or data object in the first list, use an application programming interface (API) of the data storage system 100 to set one or more predefined first users of the data storage system 100 as the owner of the file or data object. The processing unit 104 is configured to, for each file or data object in the first list, use the API of the data storage system 100 to set the permissions of the file or data object to restrict access to the file or data object by one or more predefined second users of the data storage system 100.
[0045] The processing unit 104 of the data storage system 100 is enabled to detect sensitive data. The processing unit 104 can automatically generate file system permissions based on the sensitive data detection. The automatic generation of file system permissions by the processing unit 104 improves the protection of sensitive data, thereby enhancing the security of the data storage system 100. The processing unit 104 prevents data leakage and data exfiltration.
[0046] The processing unit 104 is configured to generate, for each file or data object in the first list, a second list of sensitive data records detected within the file or data object. Each sensitive data record in the second list includes the type and value of the detected sensitive data record. The processing unit 104 is configured to obtain, for all users of the data storage system 100, a user mapping from a personal identifier (ID) to a system ID. The processing unit 104 is configured to generate, for each file or data object in the first list, a third list of one or more users of the data storage system 100, the one or more users being described by or associated with the sensitive data records of the second list associated with the file or data object. The processing unit 104 is configured to assign, for each file or data object in the first list, one or more users of a first predefined group of the data storage system 100 as owners of the file or data object using the application programming interface (API) of the data storage system 100 and the system IDs of the one or more users of the first predefined group. The processing unit 104 is configured to set permissions for the file or data object, using the API and the system IDs of the one or more users of the third list, to restrict access to the file or data object by the one or more users of the third list.
[0047] Optionally, the sensitive data includes personally identifiable information (PII), and the sensitive data detection tool 108 is configured to detect PII records.
[0048] Optionally, the first predefined group and / or the second predefined group includes administrators of the data storage system 100.
[0049] Optionally, the second predefined group is the same as the first predefined group.
[0050] Optionally, the area of interest includes the entire data storage system 100.
[0051] Optionally, the processing unit 104 is configured to, prior to generating the first list, (i) obtain, from an input-output (IO) interceptor, changes introduced into one or more files and / or one or more data objects in the data storage system 100 by a computing system, and (ii) determine the area of interest to include the one or more files and / or one or more data objects that have changed.
[0052] Optionally, setting the permissions of a file or data object includes (i) creating a third group of system IDs of one or more users for a third list, and (ii) setting the permissions of the file or data object to restrict access to the file or data object by the created third group.
[0053] Optionally, each sensitive data record in the second list further includes the offset of the detected sensitive data record within the file or data object.
[0054] Optionally, the processing unit 104 is configured to: after generating the third list, (i) obtain a graph depicting the correlation between all sensitive data records detected in the file and / or data object based on the detection results of the sensitive data records in the area of interest by the sensitive data detection tool 108, and (ii) for each file or data object in the first list, scan the graph using a predefined distance and supplement the third list with one or more additional users, where the one or more additional users are described by or related to one or more sensitive data records that are detected in the file or data object and another file or data object in the first list.
[0055] Figure 2 Exemplary table view 200 of the mapping from user personal ID 202 to user file system ID 206 for all users of a data storage system according to an implementation of the present disclosure. The mapped table view 200 includes user personal ID 202, user name 204, and user file system ID 206. For example, user personal ID 29123456-0 is mapped to user file system ID 1000 of a user whose user name may be "Idan Z." This mapping can be represented as "users2uid-map". This mapping can be used in cases where users are supported to access files or data objects.
[0056] Optionally, the processing unit is configured to use the Linux file system command chown {uid} {fullpath / file-name} to set a predefined first group of one or more users of the data storage system as the owner of the file or data object.
[0057] Optionally, the processing unit is configured to use the Linux file system command chmod 700 {fullpath / file-name} to set the permissions of the file or data object to restrict access to the file or data object by a predefined second group of one or more users.
[0058] If the predefined first group includes a single user, the processing unit is used to (i) set the one or more users of the predefined first group of the data storage system as the owner of the file or data object using the Linux file system command chown {uid} {fullpath / file - name}, and (ii) set the permissions of the file or data object using the Linux file system command chmod 700 {fullpath / file - name} to restrict access to the file or data object by the one or more users of the predefined second group. {uid} can be set to the user ID as defined in users2uid - map, i.e., {uid} = users2uid - map[user ID].
[0059] If the predefined first group includes more than one user, the predefined second group is created using the API of the data storage system. The predefined second group includes the {uid} of all different users in the predefined first group. For example, in the case of the Linux file system, for each user in the predefined first group, the command groupadd {group - name} is used, followed by the usermod - G {group - name} {uid} command.
[0060] In the case of the Linux file system, the command chown {uid}:{gid} {fullpath / file - name} is used to set the owners of the predefined first group and the predefined second group.
[0061] In the case of the Linux file system, the command chmod 770 {fullpath / file - name} is used to set the permissions for the third list of one or more users.
[0062] When the permissions make the file or data object accessible by predefined users and / or a group of users (such as root / admin), the mapping may be irrelevant.
[0063] Figure 3 Exemplary diagram 300 for the correlation between all sensitive data records detected in files and / or data objects according to an implementation of the present disclosure. Exemplary diagram 300 shows the correlation between all sensitive data records detected in files and / or data objects in the data storage system.
[0064] For example, a medical report including detailed information about the subject of the examination, as well as detailed information about the doctor who performed the examination. The detailed information about the examination subject can be name, ID, examination details, etc. The detailed information about the doctor can be name, ID, medical license, such as Michael Z., 28123*, 167123467-0.
[0065] The sensitive data detection tool can combine the detailed information about the examination subject and the detailed information about the doctor who performed the examination without mixing their respective details.
[0066] Figure 4A Exemplary file system view 400 prior to protecting sensitive data within files and / or data objects in a protected data storage system according to an implementation of the present disclosure; exemplary file system view 400 shows the files and / or data objects in the data storage system prior to protecting the sensitive data within the files and / or data objects.
[0067] Exemplary file system view 400 shows files including sensitive data, such as, " / root / dir1 / file3_pii.txt", " / root / dir1 / file4_pii.doc", "root / dir2 / file6_mpii.txt". The files can be accessed by any user because the files are not protected.
[0068] Figure 4B Exemplary file system view 402 after protecting sensitive data within files and / or data objects in a protected data storage system according to an implementation of the present disclosure. Exemplary file system view 402 shows the files and / or data objects in the data storage system after protecting the sensitive data within the files and / or data objects. Exemplary file system view 402 shows files including sensitive data, such as " / root / dir1 / file3_pii.txt", " / root / dir1 / file4_pii.doc". The files with sensitive data can be protected and accessed by one or more users.
[0069] Exemplary file system view 402 shows the file " / root / dir1 / file4_pii.doc". The file may not include an ID or a sensitive data record, but only include shared sensitive data, namely the date of birth. The correlation between the shared sensitive data and the sensitive data can be detected using an association graph. If the association graph does not exist, user 1001 may not be associated with the file " / root / dir1 / file4_pii.doc". However, the file " / root / dir1 / file4_pii.doc" can be accessed by the owner of the file (such as admin / root).
[0070] The exemplary file system view 402 shows the file " / root / dir2 / file6_mpii.txt". The file may include sensitive data of multiple users such as Assaf and Michael. Access to the file by users with IDs such as 1001 and 1002 can be supported by creating a group ID, for example, 2000.
[0071] Figure 5A and Figure 5B FIG. is a flowchart of a method for protecting sensitive data in a file and / or a data object in a data storage system using an API of the data storage system according to an implementation of the present disclosure. In step 502, based on the detection result of sensitive data records in the area of interest of the data storage system by a sensitive data detection tool, a first list of files and / or data objects including the sensitive data in the area of interest is generated. In step 504, for each file or data object in the first list, the predefined first group of one or more users of the storage system is set as the owner of the file or data object using the application programming interface (API) of the data storage system. In step 506, for each file or data object in the first list, the permissions of the file or data object are set using the API of the data storage system to restrict access to the file or data object by the predefined second group of one or more users.
[0072] The method can detect sensitive data. The method can automatically generate file system permissions based on sensitive data detection. The method improves sensitive data protection using the automatic generation of file system permissions, thereby enhancing the security of the data storage system. The method prevents data leakage and data exfiltration.
[0073] Optionally, the sensitive data includes personally identifiable information (PII), and the sensitive data detection tool is used to detect PII records.
[0074] Optionally, the predefined first group and / or the predefined second group includes the administrator of the data storage system.
[0075] Optionally, the predefined second group is equivalent to the predefined first group.
[0076] Optionally, the area of interest includes the entire data storage system.
[0077] Optionally, the method further includes repeating the steps of the above method periodically and / or in response to a user request.
[0078] Optionally, the method further includes: before generating the first list, (i) obtaining, from an input-output (IO) interceptor, changes in one or more files and / or one or more data objects introduced by the computing system into the data storage system, and (ii) determining a region of interest to include the one or more files and / or one or more data objects that have changed.
[0079] Figures 6A to 6C A flowchart of a method for protecting sensitive data in files and / or data objects in a data storage system using an API and a system ID according to an implementation of the present disclosure. In step 602, a first list of files and / or data objects including sensitive data in the region of interest is generated based on the detection results of sensitive data records in the region of interest of the data storage system by a sensitive data detection tool. In step 604, for each file or data object in the first list, a second list of sensitive data records detected within the file or data object is generated. Each sensitive data record in the second list includes the type and value of the detected sensitive data record. In step 606, a user mapping from personal identifier (ID) to system ID is obtained for all users of the data storage system. In step 608, for each file or data object in the first list, a third list of one or more users of the storage system is generated, the one or more users being described by or associated with the sensitive data records of the second list associated with the file or data object. In step 610, for each file or data object in the first list, one or more users of a predefined first group of the data storage system are assigned as owners of the file or data object using the application programming interface (API) of the data storage system and the system IDs of the one or more users of the first group. In step 612, for each file or data object in the first list, the permissions of the file or data object are set using the API and the system IDs of the one or more users in the third list to restrict access to the file or data object by the one or more users in the third list.
[0080] The method can detect sensitive data. The method can automatically generate file system permissions based on sensitive data detection. The method improves sensitive data protection through the automatic generation of file system permissions, thereby enhancing the security of the data storage system. The method prevents data leakage and data exfiltration. Optionally, the sensitive data includes personally identifiable information (PII), and the sensitive data detection tool is used to detect PII records.
[0081] Optionally, the predefined first group and / or the predefined second group includes an administrator of the data storage system.
[0082] Optionally, setting permissions for a file or data object includes (i) creating a third group of system IDs of one or more users in a third list, and (ii) setting permissions for the file or data object to restrict access to the file or data object by the created third group.
[0083] Optionally, each sensitive data record in the second list further includes an offset of the detected sensitive data record within the file or data object.
[0084] Optionally, the method further includes: after generating the third list, obtaining a graph describing the correlation between all sensitive data records detected in the file and / or data object based on the detection results of the sensitive data records in the area of interest by the sensitive data detection tool, and (ii) for each file or data object in the first list, scanning the graph using a predefined distance, and supplementing the third list with one or more additional users, where the one or more additional users are described by or related to one or more sensitive data records detected in the file or data object and another file or data object in the first list.
[0085] Optionally, the area of interest includes the entire data storage system.
[0086] Optionally, the method further includes periodically and / or in response to a user request repeating the steps of the above method.
[0087] Optionally, the method further includes: before generating the third list, (i) obtaining changes introduced into one or more files and / or one or more data objects in the data storage system by the computing system from an input-output (IO) interceptor, and (ii) determining the area of interest to include the one or more changed files and / or one or more data objects.
[0088] Figure 7A diagram of a computer system (such as a database management system) in which various architectures and functions of the foregoing various implementation manners can be implemented. As shown in the figure, the computer system 700 includes at least one processor 704 connected to a bus 702. Among them, the computer system 700 can be implemented using any suitable protocol, such as Peripheral Component Interconnect (PCI), PCI-Express, Accelerated Graphics Port (AGP), HyperTransport, or any other bus or one or more point-to-point communication protocols. The computer system 700 also includes a memory 706.
[0089] The control logic (software) and data are stored in the memory 706, and the memory 706 can take the form of a random-access memory (RAM). In the present disclosure, a single semiconductor platform can refer to a single semiconductor integrated circuit or chip. It should be noted that the term "single semiconductor platform" can also refer to a multi-chip module with increased connectivity. These multi-chip modules simulate on-chip modules with increased connectivity and on-chip operations, and make substantial improvements compared to implementations using traditional central processing units (CPUs) and buses. Of course, according to the needs of users, various modules can also be placed separately or in various combinations of semiconductor platforms.
[0090] The computer system 700 may also include an auxiliary memory 710. For example, the auxiliary memory 710 includes a hard disk drive and a removable storage drive, which represent a floppy disk drive, a tape drive, a compact disk drive, a digital versatile disk (DVD) drive, a recording device, and a universal serial bus (USB) flash drive. The removable storage drive reads from and / or writes to the removable storage unit in a well-known manner.
[0091] A computer program or a computer control logic algorithm can be stored in at least one of the memory 706 and the auxiliary memory 710. When these computer programs are executed, they enable the computer system 700 to perform various functions as described above. The memory 706, the auxiliary memory 710, and any other memory are possible examples of computer-readable media.
[0092] In one implementation, the architectures and functions described in the previous various figures can be implemented in the context of a processor 704, a graphics processor coupled to a communication interface 712, an integrated circuit (not shown) capable of having at least some of the capabilities of the processor 704 and the graphics processor, and a chipset (i.e., a set of integrated circuits designed to work and be sold as a unit for performing related functions, etc.).
[0093] In addition, the architectures and functions described in the previous various figures can be implemented in the context of a general computer system, a circuit board system, a game console system dedicated for entertainment purposes, and an application-specific system. For example, the computer system 700 can take the form of a desktop computer, a laptop computer, a server, a workstation, a game console, and an embedded system.
[0094] In addition, the computer system 700 can take the form of various other devices, including but not limited to personal digital assistant (PDA) devices, mobile phone devices, smart phones, televisions, etc. Additionally, although not shown, the computer system 700 can communicate by being coupled to a network (e.g., a telecommunications network, a local area network (LAN), a wireless network, a wide area network (WAN) such as the Internet, a peer-to-peer network, a wired network, etc.) through an I / O interface 708.
[0095] It should be understood that the arrangement of the components shown in the described figures is exemplary, and other arrangements are also possible. It should also be understood that the various system components (and modules) defined by the claims and described below and shown in various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and modules) can be implemented in whole or in part by at least some of the components in the arrangement shown in the described figures.
[0096] In addition, although at least one of these components is at least partially implemented as an electronic hardware component and thus constitutes a machine, other components can be implemented in software, which, when included in an execution environment, constitutes a machine, hardware, or a combination of software and hardware.
[0097] Although the present disclosure and its advantages have been described in detail, it should be understood that various changes, substitutions, and alterations can be made without departing from the spirit and scope of the present disclosure as defined by the appended claims.
Claims
1. A method for protecting sensitive data within files and / or data objects in a data storage system (100), characterized in that, Comprising: Based on the detection results of sensitive data records in the area of interest of the data storage system (100) by the sensitive data detection tool (108), generating a first list of files and / or data objects including the sensitive data in the area of interest, For each file or data object in the first list: Using the application programming interface API of the data storage system (100) to set one or more predefined first-group users of the data storage system (100) as the owners of the file or data object, Using the API of the data storage system (100) to set the permissions of the file or data object to restrict access to the file or data object by one or more predefined second-group users of the data storage system (100).
2. The method according to claim 1, wherein The sensitive data includes personally identifiable information PII, and the sensitive data detection tool (108) is used to detect PII records.
3. The method according to claim 1 or 2, characterized in that, The predefined first group and / or the predefined second group includes the administrators of the data storage system (100).
4. The method according to any one of claims 1 to 3, characterized in that, The predefined second group is the same as the predefined first group.
5. The method according to any one of claims 1 to 4, characterized in that The area of interest includes the entire data storage system (100).
6. The method according to any one of claims 1 to 5, characterized in that Further comprising: Periodically and / or in response to a user request, Repeating the steps according to any one of claims 1 to 5.
7. The method according to any one of claims 1 to 3, characterized in that Further comprising, before generating the first list: Obtaining changes introduced into one or more files and / or one or more data objects in the data storage system (100) by the input / output IO interceptor from the input / output IO interceptor, Determining the area of interest to include the one or more files and / or the one or more data objects that have been changed.
8. A method for protecting sensitive data within files and / or data objects in a data storage system (100), characterized in that, Comprising: Based on the detection results of sensitive data records in the area of interest of the data storage system (100) by the sensitive data detection tool (108), generating a first list of files and / or data objects including the sensitive data in the area of interest, For each file or data object in the first list, generating a second list of sensitive data records detected within the file or data object, wherein each sensitive data record in the second list includes the type and value of the detected sensitive data record; Obtaining a user mapping from personal identifier ID to system ID for all users of the data storage system (100), For each file or data object in the first list, generating a third list of one or more users of the data storage system (100), the one or more users being described by or related to the sensitive data records in the second list associated with the file or data object, For each file or data object in the first list: Using the application programming interface API of the data storage system (100) and the system IDs of one or more predefined first-group users of the data storage system (100) to assign the one or more users in the first group as the owners of the file or data object, Set the permissions of the file or data object using the system IDs of the one or more users of the API and the third list to restrict access to the file or data object by the one or more users of the third list.
9. The method according to claim 8, characterized in that, The sensitive data includes personally identifiable information PII, and the sensitive data detection tool (108) is used to detect PII records.
10. The method according to claim 8 or 9, characterized in that The predefined first group includes the administrators of the data storage system (100).
11. The method according to any one of claims 8 to 10, characterized in that The setting of the permissions of the file or data object includes: Create a third group of the system IDs of the one or more users of the third list; Set the permissions of the file or data object to restrict access to the file or data object by the created third group.
12. The method according to any one of claims 8 to 11, characterized in that, Each sensitive data record in the second list further includes the offset of the detected sensitive data record within the file or data object.
13. The method according to any one of claims 8 to 12, characterized in that, Further includes, after generating the third list: Based on the detection results of the sensitive data records in the area of interest by the sensitive data detection tool (108), obtain a graph describing the correlation between all the sensitive data records detected in the file and / or data object, For each file or data object in the first list, By scanning the graph using a predefined distance, supplement the third list with one or more additional users, where the one or more additional users are described by or related to one or more sensitive data records, and the one or more sensitive data records are detected in the file or data object and another file or data object in the first list.
14. The method according to any one of claims 8 to 13, characterized in that, The area of interest includes the entire data storage system (100).
15. The method according to any one of claims 8 to 14, characterized in that, Further includes: Periodically and / or in response to a user request, repeat the steps according to any one of claims 8 to 14.
16. The method according to any one of claims 8 to 13, characterized in that Further includes, before generating the first list: Obtain the changes introduced into the one or more files and / or one or more data objects in the data storage system (100) by the computing system (106) from the input / output IO interceptor, Determine the area of interest to include the one or more files and / or the one or more data objects that have changed.
17. A data storage system (100), characterized in that, Store files and / or data objects with sensitive data, and the data storage system (100) includes: a communication unit (102) for receiving data from the computing system (106); a processing unit (104) for performing the steps according to any one of claims 1 to 16 using the sensitive data detection tool (108).