IP Library Granted Patent US 9,098,730
Granted Patent B2
US 9,098,730 · App. 12/695,658 · Granted Aug 4, 2015

System and method for preserving electronically stored information

Inventor: Eric S. Shirk (Spring, TX)
Assignee: BDO USA, LLP
G06F21/87G06F21/305H04L67/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,098,730
App. No.
12/695,658
Granted
Aug 4, 2015
Kind
B2
Abstract

A system and method for collection of electronically stored information (ESI) from Windows based desktops and laptops is disclosed that are under the control of remote custodians. The system and method include an external persistent memory storage device and a software application tool that is loaded onto the persistent memory storage device. The external persistent memory storage device is connected to the computer system hosting the persistent memory storage device to be examined, for example, by way of a USB or Ethernet port. Once connected to the computer system hosting the persistent memory storage device to be examined, a Quick Start program, which, when opened, allows the required processing to be methodically performed. Documentation is provided for completing information regarding the chain of custody of the external persistent memory storage device. The documentation may be imprinted on a security receptacle for receiving the external persistent memory storage device. The security receptacle is configured to protect the persistent memory storage device from electrostatic discharge and to indicate if the bag or container was tampered with after it was sealed.

Claims (40)

1. A method for collecting electronically stored information of one or more source files including available deleted files stored on an internal persistent storage device in a target computer, the method comprising the steps of:

connecting an external persistent memory storage device to a target computer having an internal persistent storage device for storing an image of one or more source files including available deleted files;

loading a software application tool resident on the external persistent memory storage device into the memory of a target computer, said software application tool including instructions for causing said target computer to copy said one or more source files and available deleted files stored on said internal persistent storage device in target computer and create an image of said one or more source files and deleted files on said external persistent memory storage device defining one or more image files, wherein said image is created without changing any data or associated meta data stored on the source file;

verifying that said image file is an exact copy of said one or more source files and available deleted files by way of said software application tool comprising the steps;

determining a hash value of said one or more source files and available deleted files;

determining a hash value of said one or more image files;

comparing the hash value of said one or more source files including available deleted files with said hash value of said one or more image files;

based upon the comparison, determining that said one or more image files are an exact copy of said one or more source files and available deleted files;

after said image file is stored on said external persistent memory storage device, disconnecting said external persistent memory storage device from said target computer;

securing said external persistent memory storage device with said image file from said target computer stored thereon in a sealable secure container for receiving the external persistent memory storage device, configured to protect the external persistent memory storage device from electrostatic discharge and to indicate if the container has been tampered with after it has been sealed.

2. The method as recited in claim 1 further comprising:

displaying an instruction to create a disk image.

3. The method as recited in claim 1 , wherein said software application tool is configured to copy said one or more source files in different file formats includes the steps:

displaying different selectable file formats on the display of the target computer; and

determining which of the file formats was selected;

copying said one or more source files onto said external persistent memory storage device in a file format selected by the user.

4. The method as recited in claim 3 , wherein step comprises:

displaying Raw, Smart and E01 file formats on the display of the target computer, wherein said file formats are selectable; and

storing said one or more image files in the selected formats.

5. The method as recited in claim 1 , further including the step of identifying any partitions in said internal persistent storage device in said target computer from which said one or more image files and available deleted files were obtained and store identifications for said partitions along with said one or more image files under the control of said software application tool.

6. The method as recited in claim 5 , further including the step of identifying all of the partitions on the internal persistent storage device in the target computer to determine if the image file contains images from all partitions under the control of said software application tool.

7. A method for collecting electronically stored information of one or more source files including available deleted files stored on an internal persistent storage device associated with a target computer, the method comprising the steps of:

connecting an external persistent memory storage device to a target computer for storing one or more images of said one or more source files and available deleted files stored on said internal persistent storage device in said target computer;

copying said one or more source files and available deleted files stored on said target computer and creating one or more image files of said one or more source files and deleted files on said external persistent memory storage device wherein said one or more image files are created without changing any data or associated meta data stored on the source file;

verifying if said one or more image files are an exact copy of said one or more source files and available deleted files comprising the steps;

determining a hash value of said one or more source files;

determining a hash value of said one or more image files;

comparing the hash value of said one or more source files with said hash value of said one or more image files;

based upon the comparison, determining that said one or more image files are an exact copy of said one or more source files; and

storing the results of step (c) in said external persistent memory storage device;

after said image file is stored on said external persistent memory storage device, disconnecting said external persistent memory storage device from said target computer; and

securing said external persistent memory storage device with said image file from said target computer stored thereon in a sealable secure container for receiving the external persistent memory storage device, configured to protect the external persistent memory storage device from electrostatic discharge and to indicate if the container has been tampered with after it has been sealed.

8. The method as recited in claim 7 , further comprising:

determining the partitions in the said internal persistent memory storage device in the target computer to determine if said one or more image files include images of all of the partitions in the target computer.

9. The method as recited in claim 7 , further comprising:

storing the identification of the partition for the one or more imaged files and deleted files.

10. The method as recited in claim 7 , further comprising:

executing a software application tool resident on the external persistent memory storage device on the target computer, said software application tool including instructions for causing said target computer to copy one or more source files and deleted files stored in said internal persistent storage device in said target computer and create one or more image files of said one or more source files and deleted files on said external persistent memory storage device.

11. The method as recited in claim 7 , further including the step of:

storing the image file in one of a plurality of selectable formats on said external memory storage device.

Assignments (7)
SECURITY INTEREST Recorded Nov 3, 2025
From: BDO USA, P.C.
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 072764/0346 →
SECURITY INTEREST Recorded Aug 31, 2023
From: BDO USA, P.C.; BDO DIGITAL, LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 064764/0090 →
RELEASE OF SECURITY INTEREST Recorded Aug 30, 2023
From: BMO HARRIS BANK N.A.
To: BDO USA, LLP
Reel/Frame 064754/0945 →
PATENT COLLATERAL AGREEMENT Recorded Dec 29, 2015
From: BDO USA, LLP
To: BMO HARRIS BANK N.A., AS AGENT
Reel/Frame 037396/0922 →
SECURITY INTEREST Recorded Dec 8, 2014
From: BDO USA, LLP
To: COMERICA BANK, AS AGENT
Reel/Frame 034424/0378 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2014
From: UHY ADVISORS TX, LLC
To: BDO USA, LLP
Reel/Frame 034313/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2010
From: SHIRK, ERIC S.
To: UHY ADVISORS TX, LLC
Reel/Frame 024295/0392 →
Continuity (1)
Related Publication 20110184919A1 · Jul 28, 2011