IP Library Granted Patent US 12671711
Granted Patent B2
US 12671711 · App. 18/235,246 · Granted Jun 30, 2026

Systems and methods for analysis and classification of data security measures and data integrity

Inventor: Molly Bonney (Mabank, TX)
Assignee: STATE FARM MUTUAL AUTOMOBILE INSURANCE COMPANY
H04L63/1433G06F21/6245G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12671711
App. No.
18/235,246
Filed
Aug 17, 2023
Granted
Jun 30, 2026
Kind
B2
Art Unit
2432
USPC
726/25
Abstract

The present aspects may relate to techniques for a reliable and trusted evaluation and rating of an entity's (e.g., company) data security and ethical use of user's data. The novel methods and systems of evaluation and rating of data security and ethical use of user's data discussed herein improve user experience (whether individual or organizational) by giving customers an objective evaluation that private or sensitive data is being handled correctly. The method may include (i) receiving a request to evaluate data security operations of one or more computer systems of an entity that have access to private data of one or more users; (ii) determining one or more data security factors for the entity describing storage, security, and sharing of the private data by the entity; (iii) generating a data security score based upon the data security factors using a data security model; and/or (iv) outputting the data security score.

Claims (57)

1 . A computer-implemented method for evaluating data security, the computer-implemented method comprising:

receiving, by one or more processors, a request to evaluate data security operations of one or more computer systems of an entity that have access to private data of one or more users;

masking, by the one or more processors, owners of the private data from a user requesting to evaluate the data security operations of the entity;

determining, by the one or more processors, one or more data security factors for the entity describing storage, security, and sharing of the private data by the entity;

generating, by the one or more processors, a data security score based upon the data security factors using a data security model having a security layer and an ethics layer, wherein the data security model is trained to i) generate, via the security layer, a security rating representing a likelihood the entity is subject to a data breach using known security ratings for entities assigned to sets of security protocols for the entities, ii) generate, via the ethics layer, an ethics rating representing a likelihood the entity retains, stores, or shares the private data without consent using known ethics ratings for the entities assigned to sets of data sharing, retention, and storage protocols for the entities, and iii) combine the security rating and ethics rating to generate the data security score by assigning weights to the security rating and the ethics rating according to importance; and

outputting, by the one or more processors using a large language model (LLM), a natural language response to the request to evaluate the data security operations of the entity including an explanation of the data security score and a recommendation on how to improve the data security score, wherein the LLM is fine-tuned by training the LLM using historical data security scores and ranked lists of explanations of each historical data security score.

2 . The computer-implemented method of claim 1 , wherein the data security factors comprise one or more of a history of data breaches for the entity, a history of compliance with data security standards, a vulnerability scan of the one or more computer systems having access to the private data of the one or more users, data security protocols of the entity, and sensitive of the private data.

3 . The computer-implemented method of claim 2 , further comprising:

performing a vulnerability scan of the one or more computer systems having access to the private data.

4 . The computer-implemented method of claim 2 , further comprising:

requesting the data security protocols of a third-party security firm; and

requesting that the third-party security firm perform the vulnerability scan of the one or more computer systems having access to the private data.

5 . The computer-implemented method of claim 2 , further comprising:

searching publicly available information sources for the history of data breaches for the entity.

6 . The computer-implemented method of claim 2 , further comprising:

requesting, for a third-party organization, the history of compliance with data security standards.

7 . The computer-implemented method of claim 1 , further comprising:

generating a network link to the data security score.

8 . A computer system for evaluating data security, the computer system comprising:

one or more processors;

a communication unit; and

a non-transitory computer-readable medium coupled to the one or more processors and the communication unit and storing instructions thereon that, when executed by the one or more processors, cause the computer system to:

receive a request to evaluate data security operations of one or more computer systems of an entity that have access to private data of one or more users;

mask owners of the private data from a user requesting to evaluate the data security operations of the entity;

determine one or more data security factors for the entity, wherein the one or more data security factors describe storage, security, and sharing of the private data by the entity;

generate a data security score based upon the data security factors using a data security model having a security layer and an ethics layer, wherein the data security model is trained to i) generate, via the security layer, a security rating representing a likelihood the entity is subject to a data breach using known security ratings for entities assigned to sets of security protocols for the entities, ii) generate, via the ethics layer, an ethics rating representing a likelihood the entity retains, stores, or shares the private data without consent using known ethics ratings for the entities assigned to sets of data sharing, retention, and storage protocols for the entities, and iii) combine the security rating and ethics rating to generate the data security score by assigning weights to the security rating and the ethics rating according to importance; and

output, using a large language model (LLM), a natural language response to the request to evaluate the data security operations of the entity including an explanation of the data security score and a recommendation on how to improve the data security score, wherein the LLM is fine-tuned by training the LLM using historical data security scores and ranked lists of explanations of each historical data security score.

9 . The computer system of claim 8 , wherein the data security factors comprise one or more of a history of data breaches for the entity, a history of compliance with data security standards, a vulnerability scan of the one or more computer systems having access to the private data of the one or more users, data security protocols of the entity, and sensitive of the private data.

10 . The computer system of claim 9 , wherein the instructions, when executed by the one or more processors, cause the computer system to:

perform vulnerability scan of the one or more computer systems having access to the private data.

11 . The computer system of claim 9 , wherein the instructions, when executed by the one or more processors, cause the computer system to:

request the data security protocols of a third-party security firm; and

request that the third-party security firm perform the vulnerability scan of the one or more computer systems having access to the private data.

12 . The computer system of claim 9 , wherein the instructions, when executed by the one or more processors, cause the computer system to:

search publicly available information sources for the history of data breaches for the entity.

13 . The computer system of claim 9 , wherein the instructions, when executed by the one or more processors, cause the computer system to:

request, for a third-party organization, the history of compliance with data security standards.

14 . The computer system of claim 8 , wherein the instructions, when executed by the one or more processors, cause the computer system to:

generate a network link to the data security score.

15 . A tangible, non-transitory computer-readable medium storing instructions for data security evaluation that, when executed by one or more processors of a computing device, cause the computing device to:

receive a request to evaluate data security operations of one or more computer systems of an entity that have access to private data of one or more users;

mask owners of the private data from a user requesting to evaluate the data security operations of the entity;

determine one or more data security factors for the entity, wherein the one or more data security factors describe storage, security, and handling of the private data by the entity;

generate a data security score based upon the data security factors using a data security model having a security layer and an ethics layer, wherein the data security model is trained to i) generate, via the security layer, a security rating representing a likelihood the entity is subject to a data breach using known security ratings for entities assigned to sets of security protocols for the entities, ii) generate, via the ethics layer, an ethics rating representing a likelihood the entity retains, stores, or shares the private data without consent using known ethics ratings for the entities assigned to sets of data sharing, retention, and storage protocols for the entities, and iii) combine the security rating and ethics rating to generate the data security score by assigning weights to the security rating and the ethics rating according to importance; and

output, using a large language model (LLM), a natural language response to the request to evaluate the data security operations of the entity including an explanation of the data security score and a recommendation on how to improve the data security score, wherein the LLM is fine-tuned by training the LLM using historical data security scores and ranked lists of explanations of each historical data security score.

16 . The tangible, non-transitory computer-readable medium of claim 15 , wherein the data security factors comprise one or more of a history of data breaches for the entity, a history of compliance with data security standards, a vulnerability scan of the one or more computer systems having access to the private data of the one or more users, data security protocols of the entity, and sensitive of the private data.

17 . The tangible, non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the computer device to:

perform vulnerability scan of the one or more computer systems having access to the private data.

18 . The tangible, non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the computer device to:

request the data security protocols of a third-party security firm; and

request that the third-party security firm perform the vulnerability scan of the one or more computer systems having access to the private data.

19 . The tangible, non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the computer device to:

search publicly available information sources for the history of data breaches for the entity.

20 . The tangible, non-transitory computer-readable medium of claim 16 , wherein the instructions, when executed by the one or more processors, cause the computer device to:

request, for a third-party organization, the history of compliance with data security standards.

21 . The tangible, non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, cause the computer device to:

generate a network link to the data security score.