Digital information infrastructure and method for security designated data and with granular data stores

Patent No. US9734169 (titled "Digital information infrastructure and method for security designated data and with granular data stores") on May 23, 2013. The application was issued on Aug 15, 2017.

What is this patent about?

’169 is related to the field of distributed cloud-based data management and information security. It addresses the technical challenge of protecting sensitive information within an open ecosystem where data is frequently moved, shared, or stored in unstructured formats. The background context involves the risk of data leakage from both external hackers and internal actors, necessitating a more robust method for isolating mission-critical content from common data across a network of distributed storage nodes.

The underlying idea behind ’169 is the physical and logical decoupling of sensitive information from its original context through a process of granular extraction and dispersal. Rather than relying solely on perimeter defenses or file-level encryption, the invention identifies specific high-value data elements—referred to as select content—and separates them from the remaining data. This creates a state of 'formlessness' where the sensitive components and the residual 'remainder' data are stored in different locations, rendering the information useless to an unauthorized actor who cannot access all the necessary pieces simultaneously.

The claims of ’169 focus on a method for organizing data by extracting security (SEC) designated data and storing it in specific select content (SC) data stores, while simultaneously parsing the remaining data into granular data stores. This process is governed by a dual-parsing mechanism that utilizes both random distribution and predetermined algorithms linked to the sensitive content. Access to any of these distributed components is strictly regulated by independent access controls at each store, ensuring that data can only be withdrawn and reconstructed when the proper credentials are provided.

In practice, the system functions by scanning incoming data streams or documents and identifying predetermined words, images, or objects that match an enterprise's security policy. These elements are pulled into the cloud-based SC stores, while the leftover data is broken into fragments and scattered across granular stores. To rebuild the original information, a reconstruction module must navigate the access controls of multiple stores to pull the SEC data and the parsed remainder data back together, effectively acting as a secure compiler for the authorized user.

This approach differs from prior solutions by moving away from simple classification labels, which can be manipulated or bypassed by attackers. Traditional systems often treat a document as a single unit of security; however, ’169 treats data at a granular level, ensuring that even if one storage node is compromised, the attacker only obtains an incoherent fragment of the whole. By integrating random parsing with algorithmic dispersal, the invention forces a 'digital bureaucracy' that requires multiple successful authentications across a distributed network to recover any meaningful information.

How does this patent fit in bigger picture?

Technical Landscape

In the late 2000s when ’169 was filed, enterprise information management was characterized by a sharp divide between structured data stored in relational databases and a growing volume of unstructured content residing in disparate office documents and email systems. At a time when data security was typically implemented using perimeter-based firewalls and simple keyword indexing, systems commonly relied on manual classification or static directory structures rather than automated semantic analysis. Hardware and software constraints of the era made the real-time monitoring and granular decomposition of complex, multi-layered document object models non-trivial, often resulting in a lack of visibility into the sensitive metadata and revision histories embedded within portable files.

Prosecution Position

The disclosed invention represents a technical advancement through the integration of a dynamic, multi-tiered filtering architecture that automatically categorizes and manages unstructured data across a distributed computing system. By shifting from monolithic file handling to a granular data control model, the system enables the extraction of security-sensitive content into isolated stores while maintaining the remainder data in a functional state. This architectural shift overcomes the technical constraint of 'all-or-nothing' document access, enabling a capability for controlled, multi-level security releases and automated sanitization. The technical effect achieved is a transformation of raw data into aggregated select content that can be actively managed according to enterprise policies, ensuring that sensitive information is protected even within open ecosystems involving third-party partners.

Claims

The patent contains a total of 2 claims, with claim 1 serving as the sole independent claim. This independent claim focuses on a method for organizing and processing data within a distributed cloud-based system by extracting sensitive information into secured data stores while randomly and algorithmically parsing the remaining data into granular stores, ensuring that all data retrieval is governed by specific access controls. The dependent claim serves to further specify the process by incorporating a monetization algorithm that assigns financial or risk-release values to the secured data based on its availability.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Access controls
(Claim 1)
A system of information rights management should control who can open, print or edit a document or information file. The controlled release of corresponding extracted security sensitive data from the respective extract stores is permitted with associated security clearances. This may include n-factor authentication or encryption keys split in a secret splitting scheme.Mechanisms, including security clearances, identification profiles, or encryption keys, that regulate the ability to open, edit, print, or withdraw data from the secure stores.
Granular data stores
(Claim 1)
The invention splits a data stream into granular pieces, replicates those pieces, and disperses them to distributed storage. A small granular piece does not convey all the substance of the original document or data stream. If the replicated piece is small enough, the attacker will find it useless because it is out of context.Distributed storage locations used to hold small, parsed pieces of a data stream (remainder data) to minimize security risks by ensuring no single location contains the full context of the original information.
Randomly parsing
(Claim 1)
The configuration of granular data streams transport to storage may include a selection of what type of data streams will be sent to which storage. The selection may be done randomly to enhance security. Shuttling data between distributed storage locations causes chaos which increases security against attackers.A method of breaking down data into smaller components without a fixed pattern to enhance security through chaos and unpredictability.
Remainder data
(Claim 1)
The system extracts security sensitive content from a data input to obtain extracted security sensitive data and remainder data. Remainder data is stored in the distributed computer system. A granular data stream is defined as the extract and/or remainder data filtered from an original data stream.The portion of an original data stream or document that remains after the security sensitive or select content has been extracted.
SC data stores
(Claim 1)
The computing system has a plurality of select content data stores for respective ones of a plurality of enterprise designated categorical filters. In this manner, security sensitive content is separately stored apart from the select content, which is stored in select content data stores. The system translates the sec-con or SC data and then stores the same in certain locations or secure stores.Secure storage repositories within a distributed system specifically designed to hold extracted select content or security sensitive data, each governed by distinct access controls.
SEC designated data
(Claim 1)
The system provides tools for securing secret or security sensitive sec-con data in the enterprise computer system. It extracts security sensitive content from a data input to obtain extracted security sensitive data for a corresponding security level. This extracted data is stored in a respective security sensitive extract store while remainder data is stored elsewhere in the distributed system.Security sensitive content or 'sec-con' data identified within a data stream (such as documents, images, or audio) that requires protection, masking, or extraction based on enterprise security policies and classification levels.
Select content (SC) data stores
(Claim 1)
The computing system has a plurality of select content data stores for respective ones of a plurality of enterprise designated categorical filters. Aggregated select content is stored in the corresponding select content data store. In this manner, security sensitive content is separately stored apart from the remainder data.Specific storage repositories within a distributed system designed to hold aggregated and categorized data elements that have been identified as important or sensitive to an enterprise.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00595Apr 18, 2025Digitaldoors, Inc. v. SouthPoint Bank
8:25-cv-00002Jan 1, 2025Digital Doors, Inc. v. Sandy Spring Bank

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9734169

Application Number
US13900728A
Filing Date
May 23, 2013
Publication Date
Aug 15, 2017
External Links
Slate, USPTO , Google Patents