System and method for preventing identity theft or misuse by restricting access

Patent No. US10380374 (titled "System and method for preventing identity theft or misuse by restricting access") on Sep 29, 2014. The application was issued on Aug 13, 2019.

What is this patent about?

’374 is related to the field of data security and network file management. It specifically addresses the challenges faced by large enterprises, such as financial institutions, in identifying and protecting personally identifiable information (PII) scattered across vast numbers of unstructured data files. The background context involves the increasing legal and regulatory pressure to prevent identity theft by securing sensitive data like credit card numbers and social security numbers stored in archived emails or scanned documents.

The underlying idea behind ’374 is that sensitive data can be accurately identified without manual review by using a two-stage statistical and algorithmic filter. Instead of simply searching for keywords, the system evaluates the pattern density of potential sensitive strings relative to the file size and then applies a secondary validation layer. This secondary layer uses the mathematical properties of the data itself—specifically the presence of a valid check digit—to distinguish between random alphanumeric noise and actual sensitive records.

The claims of ’374 focus on a computer-implemented method and system that scans files for specific alphanumeric strings, calculates the density of these strings, and performs a Luhn algorithm or similar check-digit validation on the identified data. Once a file is validated as containing sensitive information, the claims cover a specific suite of restrictive actions, including the use of privilege masks, crypt checksums to prevent covert code execution, and the dynamic granting and revoking of identifiers during the file-opening process.

In practice, the invention operates by first isolating files where the frequency of account-like numbers suggests a high probability of sensitive content. By dividing the number of occurrences by the file size, the system avoids over-flagging large files that contain only incidental matches. The subsequent validation of the check digit ensures that the system only restricts access to files containing mathematically valid account numbers, which significantly reduces the false alarm rate compared to traditional keyword searches.

This approach differs from prior solutions by integrating the detection logic directly with a multi-faceted enforcement engine. Rather than just flagging a file for a later administrator response, the system can automatically implement site-specific commands to gather evidence of unauthorized access attempts or apply encryption and password protection in real-time. By focusing on the statistical likelihood of genuine data through pattern density and mathematical verification, the invention provides a scalable way to secure data without moving it to a centralized database.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2000s when ’374 was filed, data security within enterprise networks was typically implemented using perimeter-based defenses and static access control lists that relied on manual classification of sensitive documents. At a time when systems commonly relied on directory-level permissions rather than content-aware inspection, identifying protected information within large volumes of unstructured data, such as email archives or scanned correspondence, was constrained by the computational overhead of exhaustive text analysis. Hardware and software constraints made real-time, deep-packet or full-file inspection of every network asset non-trivial, often resulting in sensitive personally identifiable information remaining unprotected simply because its location within the file system was unknown to administrators.

Prosecution Position

The disclosed invention represents a technical advancement in automated data governance through a multi-stage filtering architecture that optimizes the identification of sensitive information. By first scanning data files for the density of specific patterns characteristic of proprietary or personal data and subsequently applying secondary validation, such as check-digit analysis, the system overcomes the technical constraint of processing large data volumes with high accuracy. This structural approach enables a dynamic security response where access restrictions and encryption are automatically triggered based on the detected presence and validity of sensitive content. The resulting technical effect is a reduction in the computational burden of file classification while increasing the reliability of identity theft prevention across distributed network storage.

Claims

This patent contains a total of 18 claims, with claims 1, 7, and 11 serving as the independent claims. The independent claims focus on a computer-implemented method and system for preventing the wrongful use of enterprise information by scanning files for specific alphanumeric strings, calculating and validating check digits based on string density, and implementing various access restrictions such as alarms, encryption, or password protection for identified sensitive files. The dependent claims serve to further define the technical parameters of the system, including specific density thresholds, the use of credit card numbers as keywords, public key encryption methods, and statistical ratios for triggering access restrictions.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Check digit
(Claim 1, Claim 7, Claim 11)
Additionally, files containing the selected pattern may be further analyzed to filter the files for sensitive information. For example, the data may be analyzed to see if it contains a valid check digit. This further analysis indicates whether sensitive data are likely to be contained in the file.A redundant digit derived from a block of digital data (specifically numeric financial data) used to verify the integrity or authenticity of that data through a mathematical validation process.
Density of the selected key word string
(Claim 1, Claim 7, Claim 11)
The system and method of the invention can then restrict access to the file if the density of the selected pattern in the text file is greater than or equal to a predetermined key word density threshold. Files containing the selected pattern may be further analyzed to filter the files for sensitive information. This density calculation serves as a metric to identify files likely to contain sensitive data such as PII.A calculated ratio determined by dividing the total number of times a specific key word string appears in a file by the total size of that file.
Key word string
(Claim 1, Claim 7, Claim 11)
The system and method includes scanning at least one data file for the density of a selected pattern, for example a pattern that tends preferentially to be present in proprietary data in the business area of the data being filtered. The data may be analyzed to see if it contains a valid check digit. The density of the selected pattern in the text file is compared to a predetermined key word density threshold.An alphanumeric sequence used as a search pattern that includes at least a portion of numeric data corresponding to financial account identifiers, such as bank, credit card, or debit card numbers.
Restricting access
(Claim 1, Claim 7, Claim 11)
The invention also relates to systems and methods for restricting access to files that have been identified as likely containing sensitive data, such as PII, and for providing security, such as restricted access and/or encryption, for those files. Restricting access can include activating an alarm, password protecting files, or controlling access based on user type and privileges. It may also involve preventing covert code from running by attaching a crypt checksum or privilege mask.The application of security measures to identified files, including alarming, password protection, role-based access control, evidence gathering, identifier management, crypt checksums, or encryption.
Restricting criteria
(Claim 1, Claim 7, Claim 11)
PII is information which might be used to uniquely identify, contact, or locate a single person, either alone or in combination with some other information. It includes such information as name, national identification number, telephone number, street address, and financial profiles. The system identifies files containing this information to prevent identity theft or misuse.A defined set of sensitive data categories—including names, addresses, social security numbers, and financial account numbers—stored within the database that the system seeks to protect from unauthorized access.
Special files
(Claim 1, Claim 7, Claim 11)
The inventions disclosed herein relate to a system and method to “filter” files for PII and other sensitive information, to identify files likely to contain such sensitive information and to protect those files. PII includes such information as name, national identification number, telephone number, street address, email address, IP address, vehicle registration number, driver's license number, biometrics, financial profiles, credit card numbers, and digital identity. The system restricts access to the file if further analysis indicates that sensitive data are likely to be contained in the file.Specific data files identified through density analysis and check digit validation as likely containing sensitive or personally identifiable information (PII) that requires restricted access.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00595Apr 18, 2025Digitaldoors, Inc. v. SouthPoint Bank
8:25-cv-00002Jan 1, 2025Digital Doors, Inc. v. Sandy Spring Bank

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US10380374

Application Number
US14499781A
Filing Date
Sep 29, 2014
Publication Date
Aug 13, 2019
External Links
Slate, USPTO , Google Patents