Patent No. US10380374 (titled "System and method for preventing identity theft or misuse by restricting access") on Sep 29, 2014. The application was issued on Aug 13, 2019.
’374 is related to the field of data security and network file management. It specifically addresses the challenges faced by large enterprises, such as financial institutions, in identifying and protecting personally identifiable information (PII) scattered across vast numbers of unstructured data files. The background context involves the increasing legal and regulatory pressure to prevent identity theft by securing sensitive data like credit card numbers and social security numbers stored in archived emails or scanned documents.
The underlying idea behind ’374 is that sensitive data can be accurately identified without manual review by using a two-stage statistical and algorithmic filter. Instead of simply searching for keywords, the system evaluates the pattern density of potential sensitive strings relative to the file size and then applies a secondary validation layer. This secondary layer uses the mathematical properties of the data itself—specifically the presence of a valid check digit—to distinguish between random alphanumeric noise and actual sensitive records.
The claims of ’374 focus on a computer-implemented method and system that scans files for specific alphanumeric strings, calculates the density of these strings, and performs a Luhn algorithm or similar check-digit validation on the identified data. Once a file is validated as containing sensitive information, the claims cover a specific suite of restrictive actions, including the use of privilege masks, crypt checksums to prevent covert code execution, and the dynamic granting and revoking of identifiers during the file-opening process.
In practice, the invention operates by first isolating files where the frequency of account-like numbers suggests a high probability of sensitive content. By dividing the number of occurrences by the file size, the system avoids over-flagging large files that contain only incidental matches. The subsequent validation of the check digit ensures that the system only restricts access to files containing mathematically valid account numbers, which significantly reduces the false alarm rate compared to traditional keyword searches.
This approach differs from prior solutions by integrating the detection logic directly with a multi-faceted enforcement engine. Rather than just flagging a file for a later administrator response, the system can automatically implement site-specific commands to gather evidence of unauthorized access attempts or apply encryption and password protection in real-time. By focusing on the statistical likelihood of genuine data through pattern density and mathematical verification, the invention provides a scalable way to secure data without moving it to a centralized database.
In the early 2000s when ’374 was filed, data security within enterprise networks was typically implemented using perimeter-based defenses and static access control lists that relied on manual classification of sensitive documents. At a time when systems commonly relied on directory-level permissions rather than content-aware inspection, identifying protected information within large volumes of unstructured data, such as email archives or scanned correspondence, was constrained by the computational overhead of exhaustive text analysis. Hardware and software constraints made real-time, deep-packet or full-file inspection of every network asset non-trivial, often resulting in sensitive personally identifiable information remaining unprotected simply because its location within the file system was unknown to administrators.
The disclosed invention represents a technical advancement in automated data governance through a multi-stage filtering architecture that optimizes the identification of sensitive information. By first scanning data files for the density of specific patterns characteristic of proprietary or personal data and subsequently applying secondary validation, such as check-digit analysis, the system overcomes the technical constraint of processing large data volumes with high accuracy. This structural approach enables a dynamic security response where access restrictions and encryption are automatically triggered based on the detected presence and validity of sensitive content. The resulting technical effect is a reduction in the computational burden of file classification while increasing the reliability of identity theft prevention across distributed network storage.
This patent contains a total of 18 claims, with claims 1, 7, and 11 serving as the independent claims. The independent claims focus on a computer-implemented method and system for preventing the wrongful use of enterprise information by scanning files for specific alphanumeric strings, calculating and validating check digits based on string density, and implementing various access restrictions such as alarms, encryption, or password protection for identified sensitive files. The dependent claims serve to further define the technical parameters of the system, including specific density thresholds, the use of credit card numbers as keywords, public key encryption methods, and statistical ratios for triggering access restrictions.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents