Geo-aware file distribution

The restriction-aware device enforces geographic data restrictions through extended file attributes, ensuring data is transferred only to authorized locations, addressing unauthorized distribution in hybrid cloud environments.

JP7725147B2Active Publication Date: 2025-08-19INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2022536817
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-12-31
Filing Date
2020-12-22
Publication Date
2025-08-19
Estimated Expiration
2040-12-22

AI Technical Summary

Technical Problem

Existing cloud computing systems lack an active mechanism to enforce geographic data restrictions encoded in metadata, leading to unauthorized data distribution across unauthorized boundaries, particularly in hybrid cloud environments.

Method used

A restriction-aware device that encodes geographic restrictions as extended file attributes (xattrs) in metadata, using tools like parameter, distribution, and replication managers to manage and enforce data distribution according to defined geographic boundaries, preventing unauthorized transfers.

Benefits of technology

Ensures that data is replicated and transferred only to authorized locations, preventing accidental or unauthorized distribution and facilitating data movement within hybrid cloud environments by enforcing geographic restrictions before operations are performed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007725147000001
    Figure 0007725147000001
  • Figure 0007725147000002
    Figure 0007725147000002
  • Figure 0007725147000003
    Figure 0007725147000003
Patent Text Reader

Abstract

Embodiments relate to computer systems, computer program products, and methods for preventing unauthorized file distribution and duplication. File parameters are defined, and the defined file parameters include file distribution characteristics. The file is encoded with the defined file parameters as file metadata. The distribution and duplication of the file is managed according to the encoded file parameters. The defined parameters are evaluated along with a physical duplication destination. The file is selectively duplicated or transmitted according to the evaluation of the file parameters and the destination.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present embodiments relate to geography aware file dissemination. More particularly, the embodiments relate to encoding geographic designations into file metadata to manage the distribution of file data and, in one embodiment, to prevent unauthorized distribution of file data. [Background technology]

[0002] It is understood in the art that data has or can have demonstrable or inherent value. Cloud computing provides a remote source venue for data storage. Both cloud-based applications and data are accessible from almost any internet-connected device. For storage, users can choose public, private, or hybrid storage offerings depending on their security needs and other considerations. Cloud storage allows users to store data and files in an off-site location accessible via an internet connection or a dedicated private network connection. Cloud service providers typically store data on multiple machines to ensure redundancy and to support and enable continuity in the event of a disaster.

[0003] As cloud computing infrastructures span the globe, restrictions on data usage increase. Regulations governing data have long focused on data security and auditability, but they are increasingly imposing restrictions on physical location as well. Recent regulatory policies, such as the European Union's General Data Protection Regulation, impose restrictions on geographic data placement. With automated data redundancy and disaster recovery solutions common, it is important for systems to understand the restrictions placed on each piece of data when determining viable locations for data storage and backup. Summary of the Invention

[0004] Viewed from a first aspect, the present invention provides a computer system comprising: a processing unit operatively coupled to a memory; and a restriction device in communication with the processing unit having tools for supporting the prevention of file distribution, the tools comprising: a parameter manager for defining file parameters, the defined file parameters including file distribution characteristics; the parameter manager for encoding the file together with the defined file parameters as file metadata; a distribution manager for managing distribution of the file in response to the encoded file parameters, including evaluating the defined file parameters and a physical replication destination; and a replication manager for selectively replicating files in response to the file parameters and a destination assessment.

[0005] Viewed from a further aspect, the present invention provides a computer program product for preventing file distribution, the computer program product comprising a computer readable storage device having program code embodied therein, the program code being executable by a processor to: define file parameters, the defined parameters including file distribution characteristics; encode the file with the defined parameters as file metadata; manage distribution of the file in accordance with the encoded parameters, including evaluating the defined parameters and physical replication destinations; and selectively replicating the file in accordance with the evaluation of the parameters and the destinations.

[0006] Viewed from a further aspect, the present invention provides a method including: defining file parameters, the defined parameters including file distribution characteristics; encoding the file with the defined parameters as file metadata; managing distribution of the file in response to the encoded parameters, including evaluating the defined parameters and physical replication destinations; and selectively replicating the file in response to the evaluation of the parameters and the destinations.

[0007] Viewed from a further aspect, the present invention provides a method including encoding a file with file distribution parameters as file metadata; using the encoded distribution parameters to control file data transfer to a physical file destination, including evaluating the encoded parameters and a geographic location of the physical file destination; and selectively sending the file in response to the evaluation of the parameters and the destination.

[0008] Viewed from a further aspect, the present invention provides a method including: encoding a file as file metadata with extended file attributes, the extended file attributes indicating locations where the file is allowed to reside; using the encoded extended file attributes to control file data transfer to a physical file destination, including evaluation of the encoded extended attributes and a geographic location of the physical file destination; and selectively sending the file in response to evaluation of the encoded extended attributes and the destination.

[0009] Viewed from a further aspect, the present invention provides a computer program product for managing data distribution, the computer program product comprising a computer readable storage medium readable by a processing circuit, the computer readable storage medium storing instructions for execution by the processing circuit to perform a method for performing steps of the present invention.

[0010] Viewed from a further aspect, the present invention provides a computer program stored on a computer readable medium and loadable into the internal memory of a digital computer, comprising software code portions for performing the steps of the present invention when executed on a computer.

[0011] Embodiments described herein comprise systems, computer program products, and methods for storage management of complex files.

[0012] In one aspect, a computer system includes a processing unit operably coupled to a memory. The processing unit and the memory communicate with a restricted device having one or more associated tools embedded therein for managing file distribution. The tools include a parameter manager, a distribution manager, and a replication manager. The parameter manager functions to define file parameters, the defined file parameters including file distribution characteristics. The parameter manager encodes the file along with the defined file parameters as file metadata. The distribution manager functions to manage the distribution of the file according to the encoded file parameters. More specifically, the distribution manager evaluates the defined parameters taking into account physical replication destinations. The replication manager functions to selectively replicate files according to the evaluation of the file parameters and the destinations.

[0013] In another aspect, a computer program product for managing file distribution is provided. The computer program product includes a computer-readable storage device having program code embodied therein, the program code being executable by a processing unit. The program code is adapted to receive file parameters, the file parameters defining file distribution characteristics. The files are encoded with the received file parameters as file metadata. The program code manages the distribution of the files according to the encoded file parameters. More specifically, the program code evaluates the defined parameters taking into account physical replication destinations. The program code selectively replicates the files according to the evaluation of the file parameters and the destinations.

[0014] In yet another aspect, a method for managing file distribution is provided. File parameters are defined, the defined file parameters comprising file distribution characteristics. The file is encoded as file metadata along with the defined file parameters. Distribution of the file is managed in response to the encoded file parameters. The defined parameters are evaluated along with physical replication destinations. The file is selectively replicated in response to the evaluation of the file parameters and the destinations.

[0015] In yet another aspect, a method for managing file data transfer is provided, wherein a file is encoded as file metadata along with file distribution parameters. The encoded distribution parameters are evaluated along with a geographic location of a physical file destination to control the file data transfer to the physical file destination. The file is selectively transmitted in response to the evaluation of the parameters and the destination.

[0016] These and other features and advantages will become apparent from the following detailed description of the preferred embodiments, taken in conjunction with the accompanying drawings.

[0017] The drawings referenced herein form a part of this specification. Features shown in the drawings are intended as illustrations of some embodiments only, and not all embodiments, unless otherwise specified. [Brief explanation of the drawings]

[0018] [Figure 1] 1 is a block diagram illustrating an example of a computer system that supports and enables managing file duplication and preventing unauthorized file distribution. [Figure 2] FIG. 2 is a block diagram illustrating restriction device tools, and their associated application program interfaces, as shown and described in FIG. 1. [Figure 3]1 is a flowchart illustrating a process for encoding geographic characteristics in a file and managing data distribution using extended file attributes. [Figure 4] Figure 10 shows an example of a shell script for an overloaded find command. [Figure 5] FIG. 5 shows a schematic example of a system for implementing the process shown and described in FIGS. 1-4. [Figure 6] FIG. 1 is a block diagram illustrating a cloud computing environment. [Figure 7] FIG. 1 is a block diagram illustrating a set of functional abstraction model layers provided by a cloud computing environment. DETAILED DESCRIPTION OF THE INVENTION

[0019] It will be readily understood that the components of the present embodiments, as generally described and illustrated in the Figures herein, could be arranged and designed in a wide variety of different configurations. Thus, the following detailed description of the present device, system and method embodiments, as presented in the Figures, is not intended to limit the scope of the claimed embodiments, but is merely representative of selected embodiments.

[0020] References throughout this specification to "selected embodiments," "one embodiment," or "one embodiment" mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. Thus, the appearances of the phrases "selected embodiments," "in one embodiment," or "in one embodiment" in various places throughout this specification do not necessarily refer to the same embodiment.

[0021] The illustrated embodiments are best understood by reference to the drawings, in which like parts are designated by like numerals throughout, and the following description is intended by way of example only and briefly illustrates certain selected embodiments of devices, systems, and processes consistent with the embodiments claimed herein.

[0022] Restrictions and classifications imposed on data, such as authorized geographic locations, can be encoded in data files via metadata. Currently, there is no active mechanism for proactively enforcing restrictions and classifications encoded in metadata. By creating restriction-aware devices, specific rules can be enforced by checking a file's metadata before performing an operation. This approach can be used to orchestrate data movement within hybrid cloud environments, as well as to prevent the accidental transfer of data across authorized boundaries.

[0023] Extended file attributes, or xattrs, allow metadata to be stored with data in a manner that is searchable and understandable across environments and operating systems. Encoding geographic restrictions within the data itself can be used to prevent the accidental transfer or duplication of data across authorized boundaries. Commands such as "setfattr" and "getfattr" (in Linux®) allow extended attributes, such as xattr, to be discovered and modified. Linux is a registered trademark of Linus Torvalds in the United States, other countries, or both. The setfattr command associates a new value with the extended attribute name for each specified file. The getfattr command retrieves the extended attributes of a file system object. Overloaded commands allow the implementation of commands that operate on various argument types to be separated into separate procedures. Extended file attributes stored in metadata overload transfer commands, such as rsync, with functionality added from the extended attributes. If the geographic location of the transfer destination does not match or is not within the extended attributes, the transfer command is either prohibited by the extended attributes or is otherwise overloaded. Using extended file attributes to indicate geographic areas where data may effectively and functionally reside creates a restriction-aware device that can enforce rules that apply before operations are performed on the data. Furthermore, by encoding geographic boundaries or geographic definitions in file metadata as extended file attributes, a restriction-aware device can prevent or otherwise enforce the replication or transfer of data across authorized boundaries. Additionally, the functionality of a restriction-aware device may facilitate the coordination of data movement within a hybrid cloud environment. In the context of a replicated hybrid cloud environment, encoding authorized geographic areas enables a restriction-aware device to ensure that data is automatically replicated only to destinations defined and specified in the extended attributes.

[0024] A restriction-aware device, also referred to herein as a restriction device, encompasses functionality that prevents or otherwise mitigates unauthorized distribution of files and corresponding data and is described in detail and with associated figures. A restriction device defines and encodes parameters that directly affect the distribution of corresponding data files. The remote command, also known as rsync, is used in Linux® and Unix® operating systems to copy and synchronize files and directories remotely and locally. The find command is a command-line utility in Linux® or Unix® operating systems for walking file hierarchies. UNIX® is a registered trademark of The Open Group in the United States and other countries. It can be used to locate files and directories and perform subsequent operations on them. More specifically, the find command supports searching by file, folder, name, creation date, modification date, owner, and permissions. As shown and described herein and demonstrated in the figures, the "find" and "rsync" commands are overloaded to enforce rules defined in extended attributes. The restriction device described in detail herein applies tools and corresponding methodologies to support the distribution and duplication of data files according to encoded parameters.

[0025] Referring to Figure 1, a schematic diagram of a computing system (100) is shown. As shown, a server (110) is provided that communicates with multiple computing devices (180), (182), (184), (186), (188), and (190) via a network connection (105). The server (110) is comprised of a processing unit (112), e.g., a processor, that communicates with memory (116) via a bus (114). The server (110) is shown with a restriction device (150) that supports and enables distribution and duplication of files over the network (105) from one or more of the computing devices (180), (182), (184), (186), (188), and (190). More specifically, computing devices 180, 182, 184, 186, 188, and 190 communicate with each other and other devices or components via one or more wired and / or wireless data communication links, each of which may comprise one or more wires, routers, switches, transmitters, receivers, etc. In this networked configuration, server 110 and computer network 105 enable communication detection, recognition, and resolution. Server 110 is in operative communication with the computer network via communication links 102 and 104. Links 102 and 104 may be wired or wireless. Other embodiments of server 110 may be used with components, systems, subsystems, or devices, or combinations thereof, other than those illustrated herein.

[0026] A restriction device (150) is presented herein that comprises tools for supporting file and corresponding data functions, i.e., for managing file replication and file distribution, including preventing unauthorized file distribution. The tools support and enable encoding of data files with specific parameters. More specifically, the tools support enforcement of data file distribution and replication according to the encoded parameters. The tools function to implement an optimized methodology for preventing accidental, improper, or unauthorized transfer of data with respect to defined boundaries. In one embodiment, it is understood in the art that transfer of data may also include replication and copying of data at a new location. Accordingly, the restriction device (150) comprises tools for encoding geographic designations into file metadata to manage distribution of file data.

[0027] The tools of the restriction device (150) shown herein include, but are not limited to, a parameter manager (152), a distribution manager (154), a replication manager (156), and a coordination manager (158). The restriction device (150) receives input from the network (105) and can selectively encode data files with file parameters using a data source (170), also referred to herein as a corpus or knowledge base. As shown, the data source (170) comprises a library (172) with a plurality of files, the files being selectively encoded with file parameters. By way of example, the library (172) can be a file A (174 A ),file B (174 B ),...file N (174 N ), each of which is shown with a field configured to selectively receive one or more file parameters. As shown, the file A(174 A ) is a field A (176 A ) and the file B (174 B ) is a field B (176 B ) and the file N (174 N ) is a field N (176 N ) each of the fields is shown with the file parameters encoded within it. As shown, the fields A (176 A ) is a parameter A (178 A ), and the field B (176 B ) is a parameter B (178 B ), and the field N (176 N ) is a parameter N (178 N ). While each field is shown with only one file parameter, this should not be considered limiting as each field may contain multiple file parameters. The parameter manager (152) functions to create and manage file parameters and selectively encode one or more library files. Details of how the file parameters are encoded in the data files are shown and explained in detail below. Thus, the library (172) is represented locally to the server (110) and the knowledge base (170) which is operatively coupled to the restricted device (150).

[0028] The parameter manager (152) functions to define file parameters associated with data files. The defined file parameters are file distribution characteristics that govern where and how the data files can be transferred or replicated. In one embodiment, the file parameters are geographic boundaries that indicate where the data files can physically reside. It is understood in the art that files can be subject to replication and / or transfer individually or collectively. The parameter manager (152) selectively assigns file parameters to files and embeds the parameters in corresponding file fields. Parameter assignments may be modified by the parameter manager (152), e.g., updated, changed, or reset. The parameter manager (152) encodes the data files with the defined file parameters. The encoding or embedding of file parameters can be performed individually or collectively. For example, in one embodiment, the parameter manager (152) can identify multiple files and collectively assign and encode specified parameters to each of the files in the collection. Thus, the parameter manager (152) functions to selectively allocate and encode knowledge base files with distribution parameters.

[0029] File parameters, including restrictions on how a data file may be replicated or where a data file may reside, are encoded into the data file as metadata. As shown in Figure 1, file parameters are encoded into the data file itself. More specifically, files are individually encoded with extended file attributes (xattrs) to indicate where the data file may physically reside. The extended file attributes serve as file metadata and are stored with the file. The extended file attributes are searchable and understandable across multiple environments and operating systems, i.e., Linux®, Windows®, MacOS®, etc. For example, the fieldA (176 A ) is an example of an extended attribute parameter A (178 A ) The parameter manager (152) thus functions to encode the defined file parameters as extended file attributes of the data file.

[0030] The distribution manager (154), shown herein operatively coupled to the parameter manager (152), functions as a tool for managing the distribution of data files according to encoded file parameters, such as encoded extended attributes. The distribution manager (154) evaluates the encoded file parameters, such as metadata, along with the physical replica destination. In one embodiment, operating system commands such as "setfattr" and "getfattr" enable the discovery of extended attributes. The physical replica destination can be explicitly defined, or in one embodiment, it may not be explicitly defined and require evaluation to identify. For example, in one embodiment, the physical replica destination can be determined using, individually or collectively, a set of Global Positioning System (GPS) coordinates, a specific domain / Internet Protocol (IP) address range, etc. The distribution manager (154) evaluates the encoded extended attributes along with the physical replica destination to determine whether the extended attributes allow the data file to reside in the geographic location of the physical replica destination. In one embodiment, the distribution manager (154) evaluates the encoded extended attributes along with the physical locations of one or more intermediate replica destinations in addition to or instead of the final destination. Thus, the distribution manager (154) interfaces with the parameter manager (152) to evaluate whether the permissible characteristics of the data file can exist at the physical replica destinations based on the file parameters encoded in the data file's metadata.

[0031] The replication manager 156, shown herein as operatively coupled to both the distribution manager 154 and the parameter manager 152, functions as a tool for selectively replicating data files according to defined file parameters in evaluating extended attributes and physical destinations. In one embodiment, the defined file parameters are geographic boundaries or locations, and the replication manager restricts file replication to defined locations within the boundaries. The replication manager 156 selectively replicates data files using an evaluation of the defined file parameters and the physical replica destinations created by the distribution manager 154. For example, the replication manager 156 may allow replication to proceed if the destination location matches or is within the parameters defined by the extended attributes. However, if the destination location does not match or is not within the defined parameters, the replication manager 156 may prohibit or otherwise overload the replication command or, in one embodiment, may need to modify or redefine the extended attributes in order to execute the replication transaction. Thus, the replication manager (156) selectively replicates data files depending on the evaluation performed by the distribution manager (154).

[0032] The coordination manager (158) is shown herein operatively coupled to the replication manager (156), the distribution manager (154), and the parameter manager (152). The coordination manager (158) serves as a tool for coordinating data movement within a hybrid remote storage environment. Hybrid storage is a term used to describe a storage system designed with a combination of storage devices and corresponding storage categories. For example, hybrid storage may be a storage system that combines flash-based solid-state disk drives and hard disk drives. With respect to remote data storage, such as cloud-based storage, hybrid storage may require both local and remote resources and may employ remote resources to supplement local data storage. Hybrid storage, also referred to herein as a hybrid cloud implementation, operates as a homogenous storage system and is commonly used to facilitate backup processes and disaster recovery planning. It is understood that in a hybrid storage environment, workloads are moved between local and remote resources, with the remote resources being located in a physical location distinct from the local resources. In other words, the local and remote resources have distinct physical destinations. The coordination manager (158) utilizes the replication manager (156) to evaluate defined file parameters, such as extended attributes, stored in the metadata of the data file against the physical locations of the storage replication destinations. If the replication manager (156) determines that one or more of the physical storage replication destinations is within the bounds of the defined file parameters encoded in the data file, the coordination manager (158) selectively performs the movement of replicated data to the selected data. Thus, the coordination manager (158), in combination with the replication manager (156), coordinates the movement of data within the hybrid storage environment.

[0033] The network (105) may include local network connections and remote connections in various embodiments, such that the restricted device (150) may operate in environments of any size, including local and global, such as the Internet. Additionally, the restricted device (150) functions as a front-end system that can make available various knowledge extracted from or represented in network-accessible sources and / or structured data sources. In this manner, several processes and tools populate the restricted device (150), which also includes one or more input interfaces or portals for receiving requests and responding accordingly.

[0034] The parameter manager (152), distribution manager (154), replication manager (156), and coordination manager (158), collectively referred to as restriction device tools, are shown embodied in or integrated within the restriction device (150) of the server (110). The restriction device tools may be implemented in a separate computing system (e.g., 190) connected to the server (110) via the network (105). Whenever embodied, the restriction device tools function to define and encode file parameters into data files, manage file distribution, and more specifically, prevent file distribution to locations outside the boundaries defined by extended attributes.

[0035] The types of information handling systems that can utilize the restricted device (150) range from small handheld devices, such as a handheld computer / mobile phone (180), to large mainframe systems, such as a mainframe computer (182). Examples of handheld computers (180) include personal digital assistants (PDAs) and personal entertainment devices, such as MP4 players, portable televisions, and compact disc players. Other examples of information handling systems include pen or tablet computers (184), laptop or notebook computers (186), personal computer systems (188), and servers (190). As shown, various information handling systems can be networked together using a computer network (105). Types of computer networks (105) that can be used to interconnect various information handling systems include local area networks (LANs), wireless local area networks (WLANs), the Internet, public switched telephone networks (PSTNs), other wireless networks, and any other network topology that can be used to interconnect information handling systems. Many information handling systems include a non-volatile data store, such as a hard drive or non-volatile memory, or both. Some information handling systems may use a separate non-volatile data store (e.g., a server (190) may use a non-volatile data store (190)). A ), the mainframe computer (182) uses a non-volatile data store (182 A )). Non-volatile data store (182 A ) can be components external to the various information handling systems or can be internal to one of the information handling systems.

[0036] An information handling system adapted to support a restricted device (150) can take many forms, some of which are shown in FIG. 1. For example, the restricted device may take the form of a desktop, server, portable, laptop, notebook, or other form factor computer or data processing system. In addition, an information handling system supporting a restricted device (150) may take other form factors, such as a personal digital assistant (PDA), gaming device, ATM machine, portable telephone device, communications device, or other device including a processor and memory. In addition, the information handling system need not necessarily embody a north bridge / south bridge controller architecture, as it is understood that other architectures may also be applied.

[0037] An application program interface (API) is understood in the art as a software intermediary between two or more applications. With respect to the restricted device 150 shown and described in FIG. 1, one or more APIs may be utilized to support one or more of the tools 152-158, illustrated here as tools 252-258, and their associated functionality. Referring to FIG. 2, a block diagram 200 is provided illustrating the tools 252-258 and their associated APIs. As shown, multiple tools are embedded within the restricted device 205, including a parameter manager 252 associated with API 0 212, a distribution manager 254 associated with API 1 222, a replication manager 256 associated with API 2 232, and a coordination manager 258 associated with API 3 242.

[0038] Each of the APIs may be implemented in one or more languages and interface specifications. API 0 (212) provides functional support for selectively assigning and encoding knowledge base files with distribution parameters; API 1 (222) provides functional support for evaluating whether a data file's permissible characteristics can exist at a physical replication destination based on file parameters encoded in the data file's metadata; API 2 (232) provides functional support for selectively replicating the data file based on the evaluation; and API 3 (242) provides functional support for coordinating data movement within a hybrid storage environment. As shown, each of APIs 212, 222, 232, and 242 is operably coupled to an API coordinator 270, also known as a coordination layer and understood in the art to function as an abstraction layer for transparently threading separate APIs together. In one embodiment, the functionality of separate APIs may be combined or combined. Therefore, the configuration of APIs shown herein should not be considered limiting. Thus, as set forth herein, the functionality of the tools may be embodied or supported by their respective APIs.

[0039] Referring to FIG. 3, a flowchart (300) illustrating a process for encoding geographic restrictions in data using extended file attributes to manage data distribution is provided. One or more file parameters are defined for a data file (302). The defined file parameters are file distribution characteristics that govern where the data file can be transferred or replicated. In one embodiment, the file parameters are geographic designations that indicate where the data file can physically reside. For example, it is understood that a file being transmitted may "hop" between locations before arriving at the destination location. In this case, the file parameters direct the distribution of the file to the destination, not the location of the hop. The file parameters from step (302) are encoded as metadata in file extended attributes, or xattrs (304). Extended file attributes allow metadata to be stored in a manner that is searchable and understandable across environments and operating systems, i.e., Linux®, Microsoft® Windows®, MacOS®, etc. Microsoft and Windows are registered trademarks of Microsoft Corporation in the United States, other countries, or both. In one embodiment, file parameters can be stored as metadata in extended attributes of each data file. In one embodiment, the geographic designation of the file data is automatically encoded as metadata in the extended file attributes. In one embodiment, the geographic designation is not persistent and can be changed in the future by modifying the file parameters stored in the file metadata. Thus, the file parameters are defined and encoded as metadata in the extended attributes of the data file.

[0040] After encoding the metadata of the data file in step 304, the data file is subject to replication and transmission to a destination location different from the original location 306. In one embodiment, the data replication is performed automatically. Totalis assigned to represent the amount of data files requested to be replicated (308), and a corresponding data file count variable X is initialized (310). An operating system (O / S) command such as rsync requests the Internet Protocol (IP) address of the replication destination and the number of data files requested by the transfer. X Identify the geographic metadata of the data file (312). X The file parameter metadata stored in the extended file attributes of the rsync command overwrites the transfer command with additional functionality (314). X A determination is made (316) as to whether to allow the data file to be sent to the specified destination location. X The determining step (316) may include comparing the geographic designation in the extended file attributes to the geographic locations associated with the IP addresses of one or more intermediate replication locations in addition to or instead of the final replication destination. Thus, a file parameter in the extended file attributes of the data file overloads the data transfer command, and it is determined whether the geographic designation in the file parameter matches the geographic location of the IP address from which the request was sent.

[0041] If step (316) determines that the geographic location of the IP address is not within the boundaries defined by the extended file attributes, the data file X However, if step 316 determines that the IP address is within the boundaries defined by the extended file attributes, then the data file is transferred (318). Xare then sent (320). Following either step (318) or (320), a data file count variable X is incremented (322) and a determination is made (324) as to whether all of the requested or identified data files have been evaluated. A negative response to step (324) returns the process to step (312) for evaluation of the next data file. A positive response to step (324) indicates that all of the requested data files have been evaluated and the process is complete.

[0042] In one embodiment, the operational command in step (312) is directed to replicating a data file within a hybrid storage environment having two or more physical storage replication destinations. Similar to step (310), the geographic metadata addition function extends the replication command to determine whether the geographic metadata matches the physical boundaries defined by the geographic location of the storage replication destination. The desired geographic storage location of a data file may be subject to change over time. In one embodiment, the geographic metadata is modified when the geographic storage location of the data file changes. If the geographic location matches the metadata, the replication command allows the data file to proceed with copying. Thus, the geographic designation metadata encoded in the data file prevents the data file from being transferred or replicated to a location not indicated by the metadata.

[0043] As shown and described in Figures 1-3, the restriction device (150) provides a solution aimed at encoding geographic restrictions within the data itself and using extended file attributes to indicate the geographic regions in which the data may reside. The process shown in Figure 3 illustrates the enforcement and application of the restriction device (150) before any operations are performed on the subject data. Thus, encoding authorized regions in extended attributes is used not only to prevent the transfer of data across authorized boundaries, but also to coordinate data movement within a hybrid cloud environment.

[0044] Referring to FIG. 4, an exemplary shell script (400) for an overloaded search command is shown, and as shown and described herein, extended file attributes allow metadata to be stored with data in a manner that is searchable and understandable across environments and operating systems. Several commands for interfacing with extended attributes are supported and, in one embodiment, may vary depending on the operating system. The shell script shown herein is for the Linux® operating system. In one embodiment, the shell script can be modified to support the scripting languages of different operating systems. For example, in a Linux® operating system as shown in FIG. 4, the command setfattr may be used to establish or modify attributes (402), and the command getfattr may be used to find established attributes (404). For example, the following command: setfattr -n user.geolock -v only USA. / foo may be used to restrict a file called "foo" to a region within the United States (406). Commands for encoding attributes and for finding encoded attributes in a file ensure that standard file commands respect the encoding.

[0045] It is understood that different types of data may be stored on a volume and that a volume may be subject to replication at a target destination. The encoding of extended attributes and the enforcement of the encoding ensure that data is replicated to the appropriate target destination without violating data rules that may vary from file to file. The encoding and enforcement disclosed herein are server-targeted and use file metadata, rather than file annotations, to prevent the transfer of data.

[0046] As shown and described in Figures 1-4, geographic restrictions are encoded within the data itself, and commands are utilized to interface with the encoded file attributes and control distribution of the data according to the encoded restrictions. Aspects of the tools, e.g., 152-158, and their associated functionality can be embodied in a computer system / server at a single location, or, in one embodiment, can be configured in a cloud-based system that shares computing resources. Similarly, encoded data may be distributed to one or more locations via a cloud-based system that shares computing resources. Referring to Figure 5, a block diagram 500 is provided illustrating an example of a computer system / server 502, hereafter referred to as the cloud-based support system host 502, that implements the systems and processes described above with respect to Figures 1-4. The host 502 is operable in many other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, or configurations, or combinations thereof, that may be suitable for use with the host (502) include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and file systems that include any of the above systems, devices, and their equivalents (e.g., distributed storage environments and distributed cloud computing environments).

[0047] The host (502) may be described in the general context of computer system-executable instructions, such as program modules, executed by a computer system. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. The host (502) may be practiced in a distributed cloud computing environment where tasks are performed by remote processing devices linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media, including memory storage devices.

[0048] As shown in FIG. 5, the host (502) is depicted in the form of a general-purpose computing device. The components of the host (502) may include, but are not limited to, one or more processors or processing units (504), a system memory (506), and a bus (508) coupling various system components, including the system memory (506), to the processor (504). The bus (508) may represent one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. By way of example, such architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus. The host (502) typically includes various computer system-readable media. Such media can be any available media that is accessible by the host (502) and includes both volatile and nonvolatile media, removable and non-removable media.

[0049] The memory (506) may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) (512) and / or cache memory (514). By way of example only, the storage system (516) may provide for reading from and writing to non-removable, non-volatile magnetic media (not shown, commonly referred to as a "hard drive"). Although not shown, a magnetic disk drive may be provided for reading from and writing to removable, non-volatile magnetic disks (e.g., "floppy disks"), and an optical disk drive may be provided for reading from or writing to removable, non-volatile optical disks, such as CD-ROMs, DVD-ROMs, or other optical media. In such cases, each may be connected to the bus (508) by one or more data media interfaces.

[0050] A program / utility (518) having a set (at least one) of program modules (520) may be stored in memory (506), as well as, by way of example and not limitation, an operating system, one or more application programs, other program modules, and program data. Each of the operating system, one or more application programs, other program modules, and program data, or some combination thereof, may comprise an implementation of a network environment. The program modules (520) generally perform the functions and / or methodologies of embodiments of file decomposition and related reassembly, as described herein. For example, the set of program modules (520) may include a module configured to implement management of file data distribution, and in one embodiment, to prevent unauthorized distribution of file data, as described above with reference to Figures 1-4.

[0051] The host (502) may also communicate with one or more external devices (540), such as a keyboard, pointing device, etc., a display (550), one or more devices that allow a user to interact with the host (502), or any device (e.g., a network card, modem, etc.) that allows the host (502) to communicate with one or more other computing devices, or a combination thereof. Such communication may occur through an input / output (I / O) interface (510). Nevertheless, the host (502) may communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), or a public network (e.g., the Internet), or a combination thereof, through a network adapter (530). As shown, the network adapter (530) communicates with the other components of the host (502) through a bus (508). In one embodiment, multiple nodes of a distributed file system (not shown) communicate with a host (502) via an I / O interface (510) or via a network adapter (530). Although not shown, it should be understood that other hardware and / or software components may be used in conjunction with the host (502). Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archive storage systems.

[0052] In this document, the terms "computer program medium," "computer usable medium," and "computer readable medium" are used generally to refer to media such as main memory (506), including RAM (512), cache (514), and storage systems (516), such as removable storage drives and hard disks installed in hard disk drives.

[0053] Computer programs (also called computer control logic) are stored in the memory (506). They may also be received via a communications interface, such as a network adapter (530). When executed, such computer programs enable the computer system to perform the functions of the present embodiment as discussed herein. In particular, when executed, the computer programs enable the processing unit (504) to perform the functions of the computer system. Thus, such computer programs represent the controller of the computer system.

[0054] The present embodiments may be a system, a method, and / or a computer program product, which may include a computer-readable storage medium (or media) having computer-readable program instructions for causing a processor to perform aspects of the present embodiments.

[0055] A computer-readable storage medium may be a tangible device capable of holding and storing instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disks (DVDs), memory sticks, floppy disks, punch cards or mechanically encoded devices such as raised structures in grooves with instructions recorded on them, and any suitable combination of the foregoing. As used herein, computer-readable storage media should not be construed as being ephemeral signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses passing through fiber optic cable), or electrical signals transmitted over wires.

[0056] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device over a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may comprise copper transmission cables, optical fiber transmission cables, wireless transmission cables, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.

[0057] The computer-readable program instructions for carrying out the operations of the present embodiments may be either assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk®, C++, and traditional procedural programming languages such as the “C” programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer, partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, a field programmable gate array (FPGA), or a programmable logic array (PLA) can execute computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry to perform aspects of the present embodiments.

[0058] In one embodiment, the host (502) is a node in a cloud computing environment. As known in the art, cloud computing is a service delivery model for enabling convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal administrative effort or interaction with the provider of the service. This cloud model may include at least five characteristics, at least three service models, and at least four deployment models. Examples of such characteristics are: On-demand self-service: Cloud consumers can unilaterally provision computing capacity, such as server time or network storage, automatically as needed, without requiring human interaction with the provider of the service. Broad network access: Capabilities are available over the network and accessed via standard mechanisms that facilitate use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource pooling: A provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with various physical and virtual resources dynamically allocated and reallocated according to demand. Consumers typically have no control or knowledge over the exact location of the provided resources, although there is a sense of location independence in that they may be able to specify location at a higher level of abstraction (e.g., country, state, or data center). Rapid Elasticity: Capabilities can be rapidly and elastically provisioned, sometimes automatically, rapidly scaled out, rapidly released, and rapidly scaled in. To the consumer, the capabilities available for provisioning often appear unlimited and can be purchased in any quantity at any time. Metering Services: Cloud systems automatically control and optimize resource usage by leveraging metering capabilities at some level of abstraction appropriate to the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, providing transparency to both providers and consumers of utilized services.

[0059] The service model is as follows: Software as a Service (SaaS): The functionality offered to the consumer is the use of the provider's applications running on a cloud infrastructure. The applications are accessible from a variety of client devices through a thin-client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even personal application functionality, except for possibly limited user-specific application configuration settings. Platform as a Service (PaaS): The capability offered to the consumer is to deploy applications they create or acquire, written using programming languages and tools supported by the provider, onto a cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, such as the network, servers, operating systems, or storage, but does control the deployed applications and, in some cases, the configuration of the application hosting environment. Infrastructure as a Service (IaaS): The capability offered to the consumer is to provision processing, storage, network, and other basic computing resources on which the consumer can deploy and run any software, which may include operating systems and applications. The consumer does not manage or control the underlying cloud infrastructure, but does have control over the operating system, storage, deployed applications, and, in some cases, limited control over select networking components (e.g., host firewalls).

[0060] The deployment model is as follows: Private Cloud: The cloud infrastructure is operated solely for the organization. It may be managed by the organization or a third party and may reside on or off premises. Community Cloud: Cloud infrastructure is shared among multiple organizations to support a specific community with shared interests (e.g., mission, security requirements, policies, and compliance considerations). The cloud infrastructure may be managed by the organization or a third party and may reside on or off premises. Public Cloud: Cloud infrastructure is made available to the general public or large industry groups and is owned by an organization that sells cloud services. Hybrid Cloud: A cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain unique entities but are bound together by standardized or proprietary technologies (e.g., cloud bursting for load balancing between clouds) that allow for data and application portability.

[0061] A cloud computing environment is a service oriented environment that focuses on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing is an infrastructure that comprises a network of interconnected nodes.

[0062] Referring now to FIG. 6, an exemplary cloud computing network (600) is shown. As shown, the cloud computing network (600) includes a cloud computing environment (605) having one or more cloud computing nodes (610) with which local computing devices used by cloud consumers can communicate. Examples of these local computing devices include, but are not limited to, personal digital assistants (PDAs) or cellular phones (620), desktop computers (630), laptop computers (640), or automotive computer systems (650), or combinations thereof. Individual nodes within the nodes (610) can further communicate with each other. The nodes can be physically or virtually grouped (not shown) into one or more networks, such as the private, community, public, or hybrid clouds described above, or combinations thereof. This enables the cloud computing environment (600) to provide infrastructure, platform, and / or software as a service without requiring cloud consumers to maintain resources on their local computing devices. The types of computing devices (620)-(650) shown in FIG. 6 are intended to be illustrative only, and it is understood that the cloud computing environment (605) can communicate with any type of computerized device over any type of network and / or network-addressable connection (e.g., using a web browser).

[0063] Referring now to FIG. 7, a set of functional abstraction layers provided by the cloud computing network of FIG. 5 is illustrated. It should be understood in advance that the components, layers, and functions illustrated in FIG. 7 are intended to be illustrative only, and embodiments are not limited thereto. As illustrated, the following layers and corresponding functions are provided: a hardware and software layer (710), a virtualization layer (720), a management layer (730), and a workload layer (740). The hardware and software layer (710) includes hardware and software components. Examples of hardware components include mainframes, such as IBM® zSeries® systems, and RISC (Reduced Instruction Set Computer) architecture-based servers, such as IBM® pSeries® systems, IBM® xSeries® systems, and IBM® BladeCenter® systems, as well as storage devices and networks and networking components. Examples of software components include network application server software, one example of which is IBM® WebSphere® Application Server software, and database software, one example of which is IBM® DB2® Database software (IBM, zSeries, pSeries, xSeries, BladeCenter, WebSphere, and DB2 are registered trademarks of International Business Machines Corporation, registered in many jurisdictions worldwide).

[0064] The virtualization layer (720) provides an abstraction layer from which the following examples of virtual entities may be provided: virtual servers, virtual storage, virtual networks including virtual private networks, virtual applications and operating systems, and virtual clients.

[0065] In one example, the management layer (730) may provide the following functions: resource provisioning, metering and pricing, a user portal, service level management, and SLA planning and fulfillment. Resource provisioning provides dynamic procurement of computing and other resources utilized to perform tasks within the cloud computing environment. Metering and pricing provides cost tracking as resources are utilized within the cloud computing environment and billing or invoicing for the consumption of these resources. In one example, these resources may include application software licenses. Security provides identity verification for cloud consumers and tasks, and protection of data and other resources. A user portal provides access to the cloud computing environment for consumers and system administrators. Service level management provides allocation and management of cloud computing resources so that required service levels are met. Service level agreement (SLA) planning and fulfillment provides proactive provisioning and procurement of cloud computing resources in anticipation of future requirements according to SLAs.

[0066] The workload layer (740) provides examples of functions for which a cloud computing environment may be utilized. Examples of workloads and functions that may be provided from this layer include, but are not limited to, mapping and navigation, software development and lifecycle management, virtual classroom instruction delivery, data analytics processing, transaction processing, and geographic encoding in file metadata.

[0067] As will be appreciated by one skilled in the art, aspects may be embodied as a system, method, or computer program product. Accordingly, aspects may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, microcode, etc.), or an embodiment combining software and hardware aspects, all of which may be referred to generally herein as a "circuit," "module," or "system." Furthermore, aspects described herein may take the form of a computer program product embodied in one or more computer-readable medium(s) having computer-readable program code embodied therein.

[0068] A computer-readable signal medium may include a propagated data signal with computer-readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electromagnetic, optical, or any suitable combination thereof. A computer-readable signal medium is not a computer-readable storage medium, but may be any computer-readable medium capable of communicating, propagating, or transmitting a program for use by or in connection with an instruction execution system, apparatus, or device.

[0069] Embodiments are described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be embodied by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, executed by a processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowchart illustrations and / or block diagrams.

[0070] These computer program instructions may also be stored on a computer-readable medium that can instruct a computer, other programmable data processing apparatus, or other device to function in a particular manner, such that the instructions stored on the computer-readable medium produce an article of manufacture including instructions that perform the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0071] Computer program instructions may also be loaded into a computer, other programmable data processing apparatus, or other device to cause the computer, other programmable apparatus, or other device to perform a series of operational steps to generate a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide processing that performs the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0072] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions shown in the blocks may occur out of the order shown in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified functions or acts, or a combination of dedicated hardware and computer instructions.

[0073] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise. Furthermore, it is understood that the terms "comprises" and / or "comprising," when used herein, specify the presence of stated features, integers, steps, operations, elements, or components, or combinations thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups, or combinations thereof.

[0074] The embodiments described herein may be embodied in a system, method, and / or computer program product, which may include a computer-readable storage medium (or media) having computer-readable program instructions for causing a processor to perform the embodiments described herein.

[0075] Embodiments are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0076] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that the instructions, which execute on the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, to produce a machine. These computer-readable program instructions may also be stored on a computer-readable storage medium, such that the computer-readable storage medium having stored thereon instructions comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, and can direct a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular manner.

[0077] Although specific embodiments have been described herein for purposes of illustration, it will be appreciated that various modifications can be made without departing from the scope of the specific embodiments described herein. Accordingly, the scope of protection is limited only by the appended claims and their equivalents.

[0078] Aspects of the present embodiments are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to the embodiments. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0079] The computer-readable program instructions may also be loaded into a computer, other programmable data processing apparatus, or other device to cause the computer, other programmable apparatus, or other device to perform a series of operational steps to generate a computer-implemented process, such that the instructions executing on the computer, other programmable apparatus, or other device perform the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0080] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of an instruction, which comprises one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions shown in the blocks may occur out of the order shown in the figures. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified functions or acts, or a combination of dedicated hardware and computer instructions.

[0081] Corresponding structure, materials, acts, and equivalents of all means-plus-function or step-plus-function elements in the appended claims are intended to include any structure, material, or acts for performing the function in combination with other claimed elements as specifically claimed. The description of the present embodiments has been presented for purposes of illustration and description, but is not intended to be exhaustive or limited to the embodiments in the form disclosed.

[0082] Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the embodiments. The embodiments have been chosen and described to best explain the principles and practical applications of the embodiments and to enable those skilled in the art to understand the embodiments with various modifications suited to the particular use contemplated. Thus, the decomposition and associated file organization recognizes multiple file formats at the file system layer and efficiently utilizes the characteristics of the associated storage array.

[0083] While specific embodiments are described herein for purposes of illustration, it will be understood that various modifications can be made without departing from the scope of the embodiments. Control of file distribution can be modified to include intermediate locations in addition to, or instead of, the final destination. Accordingly, the scope of protection for these embodiments is limited only by the appended claims and their equivalents.

Claims

1. a processing unit operably coupled to the memory; a restriction device in communication with the processing unit having a tool for supporting the prevention of file distribution over a network, the tool comprising: a parameter manager that defines file parameters for a file, the defined file parameters including file distribution characteristics that govern geographic locations where the file is allowed to be replicated, the parameter manager encoding the defined file parameters as file metadata for the file; a distribution manager that includes evaluating the defined file parameters and a physical copy destination geographic location to determine whether the file is allowed to be copied to the destination geographic location according to the encoded file parameters; a replication manager that selectively replicates the files to the destinations in response to the evaluation of the file parameters and the geographic locations of the destinations. Computer systems.

2. a coordination manager for coordinating the movement of data within a hybrid remote storage environment having two or more physical storage replication destinations; 2. The computer system of claim 1, wherein the selective replication further comprises the replication manager separately evaluating the defined file parameters for each of the two or more physical storage replication destinations.

3. 3. The computer system of claim 1, wherein the defined file parameters are geographical boundaries, and further comprising the replication manager restricting file replication to locations defined within the geographical boundaries.

4. 4. The computer system of claim 3, wherein the defined file parameter is a destination IP address associated with the copy.

5. 5. The computer system of claim 1, wherein the parameter manager further comprises resetting the defined file parameters by modifying the file parameters and encoding the modified file parameters as file metadata.

6. 6. A computer system according to claim 1, wherein file distribution control data is integrated directly with the file by encoding the defined file parameters as the file metadata of the file.

7. the distribution manager identifying intermediate file locations associated with the distribution of the file and evaluating the intermediate file locations taking into account the file parameters; 7. The computer system of claim 1, wherein the replication manager selectively transmits the files depending on an evaluation of the intermediate file location.

8. A computer-implemented method for managing data distribution over a network, comprising: defining file parameters for a file, said defined file parameters including file distribution characteristics that govern geographic locations where said file is allowed to be copied; encoding said defined file parameters as file metadata for said file; determining whether the file is permitted to be replicated to the destination geographic location in response to the encoded file parameters, including evaluating the defined file parameters and a physical replication destination geographic location; selectively replicating the file to the destination in response to the evaluation of the file parameters and the geographic location of the destination.

9. 9. The method of claim 8, further comprising: the computer coordinating data movement within a hybrid remote storage environment having two or more physical storage replication destinations, the selective replication further comprising separately evaluating the defined file parameters for each of the two or more physical storage replication destinations.

10. 10. The method of claim 8 or 9, wherein the defined file parameter is a geographic boundary, the method further comprising the computer restricting file replication to locations defined within the geographic boundary.

11. 11. The method of claim 8, wherein the defined file parameter is a destination IP address associated with the copy.

12. 12. The method of claim 8, further comprising the computer resetting the defined file parameters, including modifying the file parameters and encoding the modified file parameters as file metadata.

13. 13. A method according to any one of claims 8 to 12, wherein file distribution control data is integrated directly with the file by encoding the defined file parameters as the file metadata of the file.

14. 14. The method of claim 8, further comprising: the computer identifying an intermediate file location associated with the distribution of the file; evaluating the intermediate file location taking into account the file parameters; and selectively transmitting the file in response to the evaluation of the intermediate file location.

15. defining the file parameters and encoding the defined file parameters as the file metadata of the file includes encoding file distribution parameters as file metadata of the file; managing the distribution of the file includes using the encoded file distribution parameters to control file data transfer to the physical file destination, including evaluating the encoded file distribution parameters and a geographic location of the physical file destination; selectively replicating the file in response to an evaluation of the file parameters and the destination geographic location includes selectively transmitting the file in response to an evaluation of the file distribution parameters and the destination geographic location.

14. The method according to any one of claims 8 to 13.

16. 16. The method of claim 15, wherein the encoded file distribution parameter is a geographic boundary, the method further comprising the computer restricting file transmission to locations defined within the geographic boundary.

17. 17. The method of claim 15 or 16, further comprising the computer resetting the encoded file distribution parameters, comprising modifying the encoded file distribution parameters and encoding the modified file distribution parameters as file metadata.

18. 18. The method of claim 15, wherein controlling file data transfer to a physical file destination using the encoded file distribution parameters further comprises identifying an intermediate file location associated with the transfer, evaluating the intermediate file location taking into account the file distribution parameters, and selectively transmitting the file in response to the evaluation of the intermediate file location.

19. The method of claim 19, wherein defining file parameters for the file and encoding the defined file parameters as the file metadata for the file comprises encoding extended file attributes as file metadata for the file, the extended file attributes indicating where the file is allowed to reside; managing distribution of the file in accordance with the encoded file parameters includes using the encoded extended file attributes to control file data transfer to a physical file destination, including an evaluation of the encoded extended file attributes and a geographic location of the physical file destination; 19. The method of claim 8, wherein selectively replicating the files in response to an evaluation of the file parameters and the destination geographic location comprises selectively transmitting the files in response to an evaluation of the encoded extended file attributes and the destination geographic location.

20. 20. The method of claim 19, wherein the extended file attributes are searchable and understandable across multiple environments or operating systems.

21. 21. A computer readable storage medium readable by a processing circuit, the computer readable storage medium storing instructions for execution by the processing circuit to perform the method of any one of claims 8 to 20.

22. A computer program stored on a computer readable medium and loadable into the internal memory of a digital computer, comprising software code portions for performing the method of any one of claims 8 to 20, when said computer program is executed on a computer.

Citation Information

Patent Citations

  • Digital data storage system

    JP2003186711A

  • Network system

    JP2011044020A

  • Object duplication control device and program

    JP2012022461A

  • Access control system

    JP2014035655A

  • Program, information processing device and information processing method

    JP2017021429A