IP Library Granted Patent US 10,803,204
Granted Patent B2
US 10,803,204 · App. 15/879,588 · Granted Oct 13, 2020

Systems and methods for defining and securely sharing objects in preventing data breach or exfiltration

Inventors: Shreemathi Atreya (Cupertino, CA); Niranjan Koduri (Pleasanton, CA); Wai Tung Yim (San Jose, CA); Emanoel Daryoush (San Jose, CA)
Assignee: Digital Guardian LLC
G06F21/64G06F21/10G06F21/556G06F21/6218H04L63/10H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,803,204
App. No.
15/879,588
Granted
Oct 13, 2020
Kind
B2
Abstract

Provided herein are systems and methods for defining and securely sharing objects for use in preventing data breach or exfiltration. Memory may be configured to store a plurality of objects for use in preventing data breach or exfiltration. A validation engine can validate the objects, incorporate into each object an object identifier and a signature, and generate a subset of the objects for use by a first user. The validation engine can store, in the memory, the plurality of objects as a superset of objects corresponding to the generated subset. An evaluation engine may, responsive to identifying that one or more object identifiers and signatures in a received set of objects belong to the subset corresponding to the stored superset, verify whether any object in the received set has been tampered with.

Claims (36)

1. A system for defining and securely sharing objects for use in preventing data breach or exfiltration, the system comprising:

memory configured to store a plurality of objects for use in preventing data breach or exfiltration;

a validation engine executable on one or more processors, the validation engine configured to:

validate the plurality of objects for use in preventing data breach or exfiltration;

incorporate, into each respective object of the plurality of objects, an object identifier and a signature for the respective object;

generate a subset of the plurality of objects for use by a first user in managing data loss prevention, each object in the subset maintaining the corresponding object identifier and signature;

store, in the memory, the plurality of objects as a superset of objects corresponding to the generated subset; and

an evaluation engine executable on the one or more processors, the evaluation engine configured to:

responsive to identifying that one or more object identifiers and signatures in a received set of objects belong to the subset of objects corresponding to the stored superset, verify whether any object in the received set has been tampered with, by checking whether each object identifier and signature of each object in the received set matches that of a corresponding object in the stored superset, wherein the received set of objects is accompanied with content to be evaluated; and

evaluate the content using the stored superset of objects, responsive to verifying that none of the objects in the received set has been tampered with.

2. The system of claim 1 , wherein the memory is further configured to store a plurality of supersets of objects corresponding to a plurality of subsets of objects, each of the subsets having at least one object identifier or signature different from those of another of the subsets.

3. The system of claim 1 , wherein each object of the plurality of objects comprises a pattern, a term, a dictionary of words or phrases, an entity definition, or a classifier.

4. The system of claim 1 , wherein the signature of a corresponding object comprises a signature corresponding to a most recent update made to the corresponding object.

5. The system of claim 1 , wherein the validation engine is further configured to incorporate, into each respective object of the plurality of objects, a status of the respective object.

6. The system of claim 5 , wherein the status of the respective object comprises an indication of at least one of: whether the respective object is ready to be published for usage, whether the respective object is still in development, whether the respective object is deprecated, whether the respective object can be visible in a user interface, whether the status is for internal use, or whether the status is for external use or can be published.

7. The system of claim 1 , wherein the validation engine is configured to generate the subset of the plurality of objects by at least one of: removing or hiding at least a portion of an object to be included in the subset.

8. The system of claim 1 , wherein the evaluation engine is further configured to check that each object identifier and signature of each object in the received set matches that of a corresponding object in the retrieved superset, before evaluating the content.

9. The system of claim 1 , wherein the evaluation engine is further configured to, responsive to detecting that a signature of a first object in the received set does not match that of a corresponding object in the retrieved superset, determine that the first object has been tampered with since the generation of the subset.

10. The system of claim 1 , wherein the evaluation engine is configured to detect an issue or potential issue in the operation of the superset of objects during evaluation of the content.

11. A method for defining and securely sharing objects for use in preventing data breach or exfiltration, the method comprising:

validating, by a validation engine executable on one or more processors, a plurality of objects for use in preventing data breach or exfiltration;

incorporating, by the validation engine into each respective object of the plurality of objects, an object identifier and a signature for the respective object;

generating, by the validation engine, a subset of the plurality of objects for use by a first user in managing data loss prevention, each object in the subset maintaining the corresponding object identifier and signature;

storing, by the validation engine in memory, the plurality of objects as a superset of objects corresponding to the generated subset;

retrieving, by an evaluation engine executable on the one or more processors, the superset of objects from the memory, responsive to identifying that one or more object identifiers and signatures in a received set of objects belong to the subset of objects corresponding to the superset, the received set of objects accompanied with content to be evaluated;

responsive to identifying that one or more object identifiers and signatures in a received set of objects belong to the subset of objects corresponding to the stored superset, verifying, by the evaluation engine, whether any object in the received set has been tampered with by checking whether each object identifier and signature of each object in the received set matches that of a corresponding object in the stored superset, wherein the received set of objects is accompanied with content to be evaluated; and

evaluating, by the evaluation engine, the content using the stored superset of objects, responsive to verifying that none of the objects in the received set has been tampered with.

12. The method of claim 11 , further comprising storing, in the memory, a plurality of supersets of objects corresponding to a plurality of subsets of objects, each of the subsets having at least one object identifier or signature different from those of another of the subsets.

13. The method of claim 11 , wherein each object of the plurality of objects comprises a pattern, a term, a dictionary of words or phrases, an entity definition, or a classifier.

14. The method of claim 11 , wherein the signature of a corresponding object comprises a signature corresponding to a most recent update made to the corresponding object.

15. The method of claim 11 , further comprising incorporating, by the validation engine into each respective object of the plurality of objects, a status of the respective object.

16. The method of claim 15 , wherein the status of the respective object comprises an indication of at least one of: whether the respective object is ready to be published for usage, whether the respective object is still in development, whether the respective object is deprecated, whether the respective object can be visible in a user interface, whether the status is for internal use, or whether the status is for external use or can be published.

17. The method of claim 11 , wherein generating the subset of the plurality of objects further comprises at least one of: removing or hiding at least a portion of an object to be included in the subset.

18. The method of claim 11 , further comprising checking, by the evaluation engine, that each object identifier and signature of each object in the received set matches that of a corresponding object in the retrieved superset, before evaluating the content.

19. The method of claim 11 , further comprising detecting, by the evaluation engine, that a signature of a first object in the received set does not match that of a corresponding object in the retrieved superset, and determining that the first object has been tampered with since the generation of the subset.

20. The method of claim 11 , further comprising detecting, by the evaluation engine, an issue or potential issue in the operation of the superset of objects during evaluation of the content.

Assignments (11)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded May 3, 2022
From: GOLUB CAPITAL LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 059802/0303 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2021
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 055207/0012 →
AMENDED AND RESTATED INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 29, 2019
From: DIGITAL GUARDIAN LLC
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 050305/0418 →
CHANGE OF NAME Recorded May 21, 2019
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 049240/0514 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 23, 2018
From: DIGITAL GUARDIAN, INC.
To: GOLUB CAPITAL LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 046419/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2018
From: ATREYA, SHREEMATHI; KODURI, NIRANJAN; YIM, WAI TUNG; DARYOUSH, EMANOEL
To: DIGITAL GUARDIAN, INC.
Reel/Frame 044725/0841 →
Continuity (1)
Related Publication 20190228186A1 · Jul 25, 2019