发明名称 Data classification for digital rights management
摘要 Information management is used to enforce and control rights associated with data through the use of policies implemented by a digital rights management (“DRM”) server. An information management system collects information about data objects in a computer system and classifies the data objects into one or more categories. The categories are mapped to service level objectives that include or request encryption and identify DRM policies to associate with data objects within each category. Each DRM policy identifies one or more users authorized to access data objects the DRM policy is associated with. Encryption is orchestrated, in one embodiment, by identifying a data object to the DRM server in an encryption request, and identifying a DRM policy to associate with the data object. The DRM server encrypts the data object and only allows it be decrypted by authorized users.
申请公布号 US9323901(B1) 申请公布日期 2016.04.26
申请号 US200711864764 申请日期 2007.09.28
申请人 EMC CORPORATION 发明人 Nair Manoj;Perrin Stephen R.
分类号 H04L29/06;G06F21/10 主分类号 H04L29/06
代理机构 Workman Nydegger 代理人 Workman Nydegger
主权项 1. A method of using information management to provide digital rights management (DRM), the method comprising: discovering an environment in which DRM can be performed, wherein discovering the environment includes discovering data objects residing in a computer system, and wherein discovery of the data objects is performed using one or more adapters; repeating part of the discovery process, wherein repeating part of the discovery process includes monitoring the computer system for a change to one or more of the data object; collecting metadata from each of a plurality of the data objects and generating additional metadata from each data object, wherein the data objects are stored on storage devices in a computer system, wherein at least the additional metadata is generated by applying rules to each of the data objects; recognizing different groupings associated with the data objects including a first grouping of data objects and a second grouping of data objects; selecting categorization rules for the data objects, the categorization rules including first rules for the first grouping of data objects and second rules for the second grouping of data objects; classifying each data object into one or more categories by assigning at least some of the one or more categories based on at least the metadata and the additional metadata, wherein each data object is classified independently of other data objects, wherein a first category included in the one or more categories requires digital rights management, wherein at least some of the data objects are classified in different categories, wherein assigning categories includes applying the categorization rules to each of the data objects by applying the first rules to the first grouping of data objects and by applying the second rules to the second grouping of data objects, and wherein a classification of a data object is used as a basis to evaluate a cost associated with implementation of a desired service level for that data object; mapping the data objects to service level objectives based on the categories associated with the data objects, wherein the service level objectives include first and second DRM service level objectives that are different from each other, wherein data objects associated with the first category are mapped to one or more of the DRM service level objectives and the data objects classified in categories other than the first category are mapped to service level objectives different from the DRM service level objectives; mapping the first and second DRM service level objectives to selected respective first and second DRM policies so that objects which have been mapped to a DRM service level objective are also mapped to a DRM policy, wherein selection of one or the other of the first and second DRM policies for mapping is based on a difference between the first and second DRM service level objectives; mapping the first DRM service level objective and the second DRM service level objective to services that are actually available from service providers that best match the first DRM service level objectives and the second DRM service level objectives, wherein a service gap is present when the first DRM service level objective or the second DRM service level objective does not match or is not satisfied by the services to which the first DRM service level objective is mapped or to which the second DRM service level objective is mapped; and orchestrating services associated with the DRM service level objectives such that a first data object receives DRM services associated with the first DRM service level objective and second data object receives DRM services associated with the second DRM service level objective, wherein the DRM services provided to the first data object are different from the DRM services provided to the second data object.
地址 Hopkinton MA US