Patent No. US8849716 (titled "System and method for preventing identity theft or misuse by restricting access") on Sep 14, 2007. The application was issued on Sep 30, 2014.
’716 is related to the field of data security and automated content inspection. In large enterprise environments, particularly within the financial services sector, sensitive information such as personally identifiable information (PII) and credit card numbers is often scattered across vast databases in unstructured formats. Traditional security measures frequently fail to identify these high-risk files, leaving them vulnerable to identity theft or unauthorized internal access. The background context emphasizes the difficulty of manually auditing massive volumes of data to ensure compliance with privacy regulations.
The underlying idea behind ’716 is a multi-stage filtering process that combines statistical analysis with algorithmic verification to pinpoint sensitive data. Rather than relying solely on simple keyword matches, the invention utilizes pattern density to distinguish between incidental mentions and files that likely contain bulk sensitive records. By calculating the frequency of specific alphanumeric strings—such as those resembling credit card or bank account numbers—relative to the file size, the system can prioritize high-probability targets for deeper inspection.
The claims of ’716 focus on a specific sequence of identification and remediation steps that include scanning for alphanumeric strings, calculating a check digit (such as a Luhn algorithm result) to validate the authenticity of the discovered data, and automatically relocating identified files to a secure location. The independent claims specifically cover the use of these validation techniques to confirm that a numeric string is a genuine financial account number rather than a random sequence, followed by the application of granular access controls or encryption to the validated 'special files.'
In practice, the system functions as an automated gatekeeper that monitors the creation and storage of data across a network. Once a file is flagged for high pattern density and passes the check digit validation, the system can trigger a variety of protective actions, such as privilege masking or the execution of site-specific commands to gather evidence of unauthorized access attempts. This allows the enterprise to maintain a dynamic security posture where protection is applied based on the actual content of the file rather than just its metadata or storage directory.
This approach differentiates itself from prior art by reducing the 'alarm rate' through its two-tier verification strategy. While older systems might flag any document containing a 16-digit number, this invention uses the statistical likelihood of genuine data presence to minimize false positives. Furthermore, by integrating content-aware triggers with active network responses—such as revoking identifiers upon file closure or attaching crypt checksums to prevent covert code execution—the system provides a more robust defense against both external breaches and internal misuse.
In the early 2000s when ’716 was filed, data security within corporate networks was typically implemented using perimeter defenses and static access control lists that governed entire directories or volumes. At a time when systems commonly relied on manual classification or simple keyword matching to identify sensitive documents, the automated detection of specific data types across heterogeneous file archives was limited by high computational overhead. Hardware and software constraints made the real-time, deep-packet or deep-file inspection of large-scale storage repositories non-trivial, often resulting in a binary security model where data was either broadly accessible to internal users or entirely locked down, regardless of the specific information density within individual files.
The disclosed invention represents a technical advancement in data governance through an architectural shift from static file permissions to content-aware access restriction. By integrating a multi-stage filtering process that evaluates the density of specific patterns and validates data through algorithmic checks, such as check-digit verification, the system enables a more granular and automated security posture. This approach overcomes the technical constraint of manual data auditing by programmatically identifying files likely to contain personally identifiable information and dynamically applying encryption or access limitations. The resulting technical effect is a reduction in the exposure of sensitive data within large-scale storage environments without requiring exhaustive manual intervention or pre-existing metadata tags.
This patent contains 19 claims, including independent claims 1, 7, and 12, which focus on methods and systems for preventing identity theft by scanning databases for sensitive financial data using keyword strings or special patterns, validating these files through check digit calculations and density thresholds, and implementing protective actions such as secure relocation, access controls, or encryption upon access requests. The dependent claims serve to further define these processes by specifying the use of the Luhn algorithm for credit card validation, detailing specific density calculation methods and statistical thresholds for file protection, and outlining hardware configurations involving single or multiple processors.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents