US 11,675,916 B2
Method and system for limiting data accessibility in composed systems
Yossef Saad, Ganei Tikva (IL); Mark Steven Sanders, Roanoke, VA (US); Gaurav Chawla, Austin, TX (US); and Mukund P. Khatri, Austin, TX (US)
Assigned to Dell Products L.P., Round Rock, TX (US)
Filed by Dell Products L.P., Hopkinton, MA (US)
Filed on Jan. 28, 2021, as Appl. No. 17/160,597.
Prior Publication US 2022/0237306 A1, Jul. 28, 2022
Int. Cl. G06F 21/62 (2013.01); G06F 21/52 (2013.01)
CPC G06F 21/62 (2013.01) [G06F 21/52 (2013.01); G06F 2221/033 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A system for managing composed information handling systems to manage access to data by applications hosted by the composed information handling systems, comprising:
a storage for storing authorization information; and
a system control processor manager programmed to:
instantiate a composed information handling system of the composed information handling systems using an at least one compute resource set that hosts at least one of the applications and at least one hardware resource set that stores a portion of the data;
associate, using the authorization information, storage areas of the at least one hardware resource set with the applications to obtain storage area associations;
obtain a data access request from the at least one compute resource set for the portion of the data which is stored in a storage area of the storage areas;
make a determination, based on the storage area associations and an initiator of the data access request, that the initiator of the data access request is not authorized to access the portion of the data;
refuse, based on the determination, to service the data access request;
identify a monitoring trigger event associated with monitoring modifications to the initiator, wherein the monitoring trigger event is the refusal to service the data access request;
in response to identifying the monitoring trigger event, make a second determination that the initiator was unknowingly modified; and
perform a remediation action set based on the second determination.