IP Library Granted Patent US 10,375,077
Granted Patent B1
US 10,375,077 · App. 15/235,900 · Granted Aug 6, 2019

Systems and methods for mediating information requests

Inventors: Ilya Sokolov (Boston, MA); Keith Newstadt (West Newton, MA)
Assignee: Symantec Corporation
H04L63/101G06F21/6245H04B1/3827H04L63/08H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,375,077
App. No.
15/235,900
Granted
Aug 6, 2019
Kind
B1
Abstract

The disclosed computer-implemented method for mediating information requests may include (1) detecting, at the information-managing device, a request for the information-managing device to provide at least one element of personal information to a requesting device that is within physical proximity of the information-managing device, (2) evaluating, based at least in part on an attribute of the request, whether the request for the element of personal information is appropriate, and (3) performing a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information. Various other methods, systems, and computer-readable media are also disclosed.

Claims (71)

1. A computer-implemented method for mediating information requests, at least a portion of the method being performed by an information-managing device comprising at least one processor, the method comprising:

detecting, at the information-managing device, a request for the information-managing device to provide a plurality of elements of personal information to a requesting device that is within physical proximity of the information-managing device;

identifying at least one attribute of the request that describes a context in which the information-managing device detected the request, wherein the at least one attribute comprises a device type of the requesting device;

evaluating each requested element of personal information in the plurality of elements of personal information, based at least in part on determining whether the requested element of personal information matches the context in which the information-managing device detected the request, for whether the request for the requested element of personal information is an appropriate request for the requested element of personal information; and

preventing the information-managing device from providing elements of personal information to requesting devices that requested the elements of personal information in an inappropriate context by performing, at the information-managing device, a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information wherein the security action comprises:

in response to determining that a first portion of the request represents an inappropriate request for a first element of personal information in the plurality of elements of personal information, preventing the information-managing device at least from providing the first element of personal information to the requesting device; and

in response to determining that an additional portion of the request represents an appropriate request for an additional element of personal information in the plurality of elements of personal information, providing the additional element of personal information to the requesting device.

2. The method of claim 1 , wherein preventing the information-managing device from providing the element of personal information comprises providing a partial response to the requesting device.

3. The method of claim 1 , wherein the security action further comprises at least one of:

notifying a user of the information-managing device of the request;

providing a security vendor with a report that contains details about the request; and

generating a log entry that describes the request.

4. The method of claim 1 , wherein evaluating whether the request for the plurality of elements of personal information is appropriate comprises determining whether the request exceeds user-privacy preferences specified by a user of the information-managing device.

5. The method of claim 1 , wherein evaluating whether the request for the plurality of elements of personal information is appropriate comprises determining whether the requesting device is listed on:

a whitelist that identifies approved requesting devices; or

a blacklist that identifies disapproved requesting devices.

6. The method of claim 1 , wherein the attribute of the request further comprises at least one of:

a time of day when the request was received;

the physical location of the requesting device;

a manufacturer of the requesting device;

a unique identifier associated with the requesting device;

a reputation score associated with the requesting device;

a third-party verification certificate, included within the request, that digitally verifies the identity of the requesting device by a third party; and

at least one characteristic of the element of personal information specified in the request.

7. The method of claim 6 , wherein the reputation score is calculated based on at least one of:

prior requests issued by the requesting device; and

prior requests issued by other requesting devices.

8. The method of claim 6 , wherein the reputation score is calculated by at least one of:

a third-party security vendor; and

the information-managing device.

9. The method of claim 1 , further comprising, prior to responding to the request, providing a user of the information-managing device with a security challenge that verifies the identity of the user.

10. The method of claim 1 , wherein the information-managing device comprises at least one of:

a mobile device;

a smart phone; and

a smart badge.

11. A system for mediating information requests, the system comprising:

a detecting module, stored in memory, that detects, at an information-managing device, a request for the information-managing device to provide a plurality of elements of personal information to a requesting device that is within physical proximity of the information-managing device;

an evaluating module, stored in memory, that:

identifies at least one attribute of the request that describes a context in which the information-managing device detected the request, wherein the at least one attribute comprises a device type of the requesting device; and

evaluates each requested element of personal information in the plurality of elements of personal information, based at least in part on determining whether the requested element of personal information matches the context in which the information-managing device detected the request, for whether the request for the requested element of personal information is an appropriate request for the requested element of personal information;

a performing module, stored in memory, that prevents the information-managing device from providing elements of personal information to requesting devices that requested the elements of personal information in an inappropriate context by performing, at the information-managing device, a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information, wherein the security action comprises:

in response to determining that a first portion of the request represents an inappropriate request for a first element of personal information in the plurality of elements of personal information, preventing the information-managing device at least from providing the first element of personal information to the requesting device; and

in response to determining that an additional portion of the request represents an appropriate request for an additional element of personal information in the plurality of elements of personal information, providing the additional element of personal information to the requesting device; and

at least one physical processor configured to execute the detecting module, the evaluating module, and the performing module.

12. The system of claim 11 , wherein the performing module prevents the information-managing device from providing the element of personal information by providing a partial response to the requesting device.

13. The system of claim 11 , wherein the security action further comprises at least one of:

notifying a user of the information-managing device of the request;

providing a security vendor with a report that contains details about the request; and

generating a log entry that describes the request.

14. The system of claim 11 , wherein the evaluating module evaluates whether the request for the plurality of elements of personal information is appropriate by determining whether the request exceeds user-privacy preferences specified by a user of the information-managing device.

15. The system of claim 11 , wherein the evaluating module evaluates whether the request for the plurality of elements of personal information is appropriate by determining whether the requesting device is listed on:

a whitelist that identifies approved requesting devices; or

a blacklist that identifies disapproved requesting devices.

16. The system of claim 11 , wherein the attribute of the request further comprises at least one of:

a time of day when the request was received;

the physical location of the requesting device;

a manufacturer of the requesting device;

a unique identifier associated with the requesting device;

a reputation score associated with the requesting device;

a third-party verification certificate, included within the request, that digitally verifies the identity of the requesting device by a third party; and

at least one characteristic of the element of personal information specified in the request.

17. The system of claim 16 , wherein the reputation score is calculated based on at least one of:

prior requests issued by the requesting device; and

prior requests issued by other requesting devices.

18. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

detect, at the information-managing device, a request for the information-managing device to provide a plurality of elements of personal information to a requesting device that is within physical proximity of the information-managing device;

identify at least one attribute of the request that describes a context in which the information-managing device detected the request, wherein the at least one attribute comprises a device type of the requesting device;

evaluate each requested element of personal information in the plurality of elements of personal information, based at least in part on determining whether the requested element of personal information matches the context in which the information-managing device detected the request, for whether the request for the requested element of personal information is an appropriate request for the requested element of personal information; and

prevent the information-managing device from providing elements of personal information to requesting devices that requested the elements of personal information in an inappropriate context by performing, at the information-managing device, a security action that responds to the request in a manner that is commensurate to the appropriateness of the request for the element of personal information, wherein the security action comprises:

in response to determining that a first portion of the request represents an inappropriate request for a first element of personal information in the plurality of elements of personal information, preventing the information-managing device at least from providing the first element of personal information to the requesting device; and

in response to determining that an additional portion of the request represents an appropriate request for an additional element of personal information in the plurality of elements of personal information, providing the additional element of personal information to the requesting device.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2016
From: SOKOLOV, ILYA; NEWSTADT, KEITH
To: SYMANTEC CORPORATION
Reel/Frame 039423/0009 →