System and method for preventing identity theft or misuse by restricting access

Patent No. US8849716 (titled "System and method for preventing identity theft or misuse by restricting access") on Sep 14, 2007. The application was issued on Sep 30, 2014.

What is this patent about?

’716 is related to the field of data security and automated content inspection. In large enterprise environments, particularly within the financial services sector, sensitive information such as personally identifiable information (PII) and credit card numbers is often scattered across vast databases in unstructured formats. Traditional security measures frequently fail to identify these high-risk files, leaving them vulnerable to identity theft or unauthorized internal access. The background context emphasizes the difficulty of manually auditing massive volumes of data to ensure compliance with privacy regulations.

The underlying idea behind ’716 is a multi-stage filtering process that combines statistical analysis with algorithmic verification to pinpoint sensitive data. Rather than relying solely on simple keyword matches, the invention utilizes pattern density to distinguish between incidental mentions and files that likely contain bulk sensitive records. By calculating the frequency of specific alphanumeric strings—such as those resembling credit card or bank account numbers—relative to the file size, the system can prioritize high-probability targets for deeper inspection.

The claims of ’716 focus on a specific sequence of identification and remediation steps that include scanning for alphanumeric strings, calculating a check digit (such as a Luhn algorithm result) to validate the authenticity of the discovered data, and automatically relocating identified files to a secure location. The independent claims specifically cover the use of these validation techniques to confirm that a numeric string is a genuine financial account number rather than a random sequence, followed by the application of granular access controls or encryption to the validated 'special files.'

In practice, the system functions as an automated gatekeeper that monitors the creation and storage of data across a network. Once a file is flagged for high pattern density and passes the check digit validation, the system can trigger a variety of protective actions, such as privilege masking or the execution of site-specific commands to gather evidence of unauthorized access attempts. This allows the enterprise to maintain a dynamic security posture where protection is applied based on the actual content of the file rather than just its metadata or storage directory.

This approach differentiates itself from prior art by reducing the 'alarm rate' through its two-tier verification strategy. While older systems might flag any document containing a 16-digit number, this invention uses the statistical likelihood of genuine data presence to minimize false positives. Furthermore, by integrating content-aware triggers with active network responses—such as revoking identifiers upon file closure or attaching crypt checksums to prevent covert code execution—the system provides a more robust defense against both external breaches and internal misuse.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2000s when ’716 was filed, data security within corporate networks was typically implemented using perimeter defenses and static access control lists that governed entire directories or volumes. At a time when systems commonly relied on manual classification or simple keyword matching to identify sensitive documents, the automated detection of specific data types across heterogeneous file archives was limited by high computational overhead. Hardware and software constraints made the real-time, deep-packet or deep-file inspection of large-scale storage repositories non-trivial, often resulting in a binary security model where data was either broadly accessible to internal users or entirely locked down, regardless of the specific information density within individual files.

Prosecution Position

The disclosed invention represents a technical advancement in data governance through an architectural shift from static file permissions to content-aware access restriction. By integrating a multi-stage filtering process that evaluates the density of specific patterns and validates data through algorithmic checks, such as check-digit verification, the system enables a more granular and automated security posture. This approach overcomes the technical constraint of manual data auditing by programmatically identifying files likely to contain personally identifiable information and dynamically applying encryption or access limitations. The resulting technical effect is a reduction in the exposure of sensitive data within large-scale storage environments without requiring exhaustive manual intervention or pre-existing metadata tags.

Claims

This patent contains 19 claims, including independent claims 1, 7, and 12, which focus on methods and systems for preventing identity theft by scanning databases for sensitive financial data using keyword strings or special patterns, validating these files through check digit calculations and density thresholds, and implementing protective actions such as secure relocation, access controls, or encryption upon access requests. The dependent claims serve to further define these processes by specifying the use of the Luhn algorithm for credit card validation, detailing specific density calculation methods and statistical thresholds for file protection, and outlining hardware configurations involving single or multiple processors.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Check digit
(Claim 1, Claim 7, Claim 12)
Data may be analyzed to see if it contains a valid check digit. The system calculates a check digit from numeric data in determined files and compares it to the numeric data in the files to validate if sensitive data are likely to be contained in the file. This validation step follows the initial density scanning to confirm the presence of sensitive information.A calculated numerical value derived from numeric data within a file used to verify the authenticity or validity of sensitive information, such as financial account numbers.
Key word string
(Claim 1, Claim 7, Claim 12)
The system scans data files for the density of a selected pattern that tends preferentially to be present in proprietary data in the business area of the data being filtered. This string is used to identify files likely to contain sensitive information such as personally identifiable information (PII). PII includes information such as national identification numbers, financial profiles, and credit card numbers.An alphanumeric sequence that includes at least a portion of numeric data used to identify financial accounts, such as bank, credit card, or debit card accounts, serving as a primary filter for identifying sensitive data.
Site specific commands
(Claim 1, Claim 7, Claim 12)
In response to receiving the access request, the system may perform steps such as executing site specific commands. These commands gather evidence of what actions an unauthorized user is undertaking or undertook without exposing one or more of the special files to the unauthorized user. This is part of the method for restricting access to files identified as likely containing sensitive data.Customized instructions executed in response to an access request that collect forensic evidence of an unauthorized user's actions without revealing the contents of the protected special files.
Special pattern
(Claim 7)
The invention relates to a system and method to 'filter' files for PII and other sensitive information to identify files likely to contain such sensitive information. The system scans for the density of a selected pattern that tends preferentially to be present in proprietary data. PII is information which might be used to uniquely identify, contact, or locate a single person, either alone or in combination with some other information.A composite search criteria comprising both a financial account alphanumeric string and a second string structured to identify specific personal identifiers like names, addresses, or social security numbers.
Threshold density
(Claim 1, Claim 7, Claim 12)
The system and method of the invention can restrict access to the file if the density of the selected pattern in the text file is greater than or equal to a predetermined key word density threshold. This density measurement is used to identify files likely to contain sensitive information. Files containing the selected pattern may be further analyzed to filter the files for sensitive information.A predetermined frequency or concentration level of a specific key word string or pattern within a file that, when exceeded, triggers further analysis or access restriction.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00595Apr 18, 2025Digitaldoors, Inc. v. SouthPoint Bank
8:25-cv-00002Jan 1, 2025Digital Doors, Inc. v. Sandy Spring Bank

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US8849716

Application Number
US11900982A
Filing Date
Sep 14, 2007
Publication Date
Sep 30, 2014
External Links
Slate, USPTO , Google Patents