IP Library › Granted Patent US 10,666,646
Granted Patent B2
US 10,666,646 · App. 16/365,812 · Granted May 26, 2020

System and method for protecting specified data combinations

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); William J. Deninger (San Mateo, CA)
Assignee: McAfee, LLC
H04L63/0853H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,646
App. No.
16/365,812
Granted
May 26, 2020
Kind
B2
Abstract

A method in one example implementation includes extracting a plurality of data elements from a record of a data file, tokenizing the data elements into tokens, and storing the tokens in a first tuple of a registration list. The method further includes selecting one of the tokens as a token key for the first tuple, where the token is selected because it occurs less frequently in the registration list than each of the other tokens in the first tuple. In specific embodiments, at least one data element is an expression element having a character pattern matching a predefined expression pattern that represents at least two words and a separator between the words. In other embodiments, at least one data element is a word defined by a character pattern of one or more consecutive essential characters. Other specific embodiments include determining an end of the record by recognizing a predefined delimiter.

Claims (39)

1. At least one non-transitory, computer readable medium comprising instructions that, when executed, cause one or more processors to perform a method comprising:

identifying an object including a plurality of data elements, wherein the plurality of data elements correspond to a plurality of object tokens;

identifying a tuple or record based, at least in part, on an identification of a token key associated with one of the plurality of object tokens, wherein the token key is one of a plurality of registered tokens included in the tuple; and

taking an action based on a determination that a number of the plurality of registered tokens corresponding to the plurality of object tokens at least satisfies a predetermined threshold, wherein the action includes preventing transmission of the object or locking down a database or a storage repository.

2. The at least one computer readable medium of claim 1 , the method further comprising:

tokenizing the plurality of data elements into the plurality of object tokens, wherein the object is a data file, document, or storage repository.

3. The at least one computer readable medium of claim 2 , wherein the plurality of data elements are tokenized by converting each of the data elements to a respective hash value.

4. The at least one computer readable medium of claim 1 , the method further comprising:

using an offset related to the token key to identify a beginning of the tuple or record.

5. The at least one computer readable medium of claim 1 , wherein the token key occurs with less frequency across a plurality of tuples in a registration list than frequencies at which other registered tokens of the tuple or record occur across the plurality of tuples.

6. The at least one computer readable medium of claim 1 , the method further comprising:

representing the plurality of object tokens in a bit hash table by setting a respective bit in the bit hash table for the plurality of object tokens; and

determining, for each registered token of the plurality of registered tokens, whether a bit is set in a bit position of the bit hash table that corresponds to the respective registered token.

7. The at least one computer readable medium of claim 1 , wherein, if two or more tuples of a registration list are indexed by the token key, an index includes two or more offsets indicating respective locations of the two or more tuples, each of the two or more tuples includes a respective set of data file tokens, and each of the respective sets of data file tokens includes the token key.

8. An apparatus, comprising:

a memory device including a set of instructions; and

a processor, coupled to the memory device, that, when executing the set of instructions,

identifies an object including a plurality of data elements, wherein the plurality of data elements correspond to a plurality of object tokens,

identifies a tuple or record based, at least in part, on an identification of a token key associated with one of the plurality of object tokens, wherein the token key is one of a plurality of registered tokens included in the tuple, and

takes an action based on a determination that a number of the plurality of registered tokens corresponding to the plurality of object tokens at least satisfies a predetermined threshold, wherein the action includes preventing transmission of the object or locking down a database or a storage repository.

9. The apparatus of claim 8 , wherein the processor, when executing the set of instructions, tokenizes the plurality of data elements into the plurality of object tokens, and the object is a data file, document, or storage repository.

10. The apparatus of claim 9 , wherein the plurality of data elements are tokenized by converting each of the data elements to a respective hash value.

11. The apparatus of claim 8 , wherein the processor, when executing the set of instructions, uses an offset related to the token key to identify a beginning of the tuple or record.

12. The apparatus of claim 8 , wherein the token key occurs with less frequency across a plurality of tuples in a registration list than frequencies at which other registered tokens of the tuple or record occur across the plurality of tuples.

13. The apparatus of claim 8 , wherein the processor, when executing the set of instructions, represents the plurality of object tokens in a bit hash table by setting a respective bit in the bit hash table for the plurality of object tokens, and determines, for each registered token of the plurality of registered tokens, whether a bit is set in a bit position of the bit hash table that corresponds to the respective registered token.

14. The apparatus of claim 8 , wherein, if two or more tuples of a registration list are indexed by the token key, an index includes two or more offsets indicating respective locations of the two or more tuples, each of the two or more tuples includes a respective set of data file tokens, and each of the respective sets of data file tokens includes the token key.

15. A method, comprising:

identifying an object including a plurality of data elements, wherein the plurality of data elements correspond to a plurality of object tokens;

identifying a tuple or record based, at least in part, on an identification of a token key associated with one of the plurality of object tokens, wherein the token key is one of a plurality of registered tokens included in the tuple; and

taking an action based on a determination that a number of the plurality of registered tokens corresponding to the plurality of object tokens at least satisfies a predetermined threshold, wherein the action includes preventing transmission of the object or locking down a database or a storage repository.

16. The method of claim 15 , further comprising:

tokenizing the plurality of data elements into the plurality of object tokens, wherein the object is a data file, document, or storage repository.

17. The method of claim 16 , wherein the plurality of data elements are tokenized by converting each of the data elements to a respective hash value.

18. The method of claim 15 , further comprising:

using an offset related to the token key to identify a beginning of the tuple or record.

19. The method of claim 15 , wherein the token key occurs with less frequency across a plurality of tuples in a registration list than frequencies at which other registered tokens of the tuple or record occur across the plurality of tuples.

20. The method of claim 15 , further comprising:

representing the plurality of object tokens in a bit hash table by setting a respective bit in the bit hash table for the plurality of object tokens; and

determining, for each registered token of the plurality of registered tokens, whether a bit is set in a bit position of the bit hash table that corresponds to the respective registered token.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (4)
Continuation 15700826 · Sep 11, 2017
Continuation 14457038 · Aug 11, 2014
Continuation 12939340 · Nov 4, 2010
Related Publication 20190230076A1 · Jul 25, 2019