IP Library › Granted Patent US 10,671,756
Granted Patent B2
US 10,671,756 · App. 16/392,127 · Granted Jun 2, 2020

Detection of sensitive personal information in a storage device

Inventors: Rajesh M. Desai (San Jose, CA); Mu Qiao (Belmont, CA); Roger C. Raphael (San Jose, CA); Ramani Routray (San Jose, CA)
Assignee: International Business Machines Corporation
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,671,756
App. No.
16/392,127
Granted
Jun 2, 2020
Kind
B2
Abstract

A method, system and computer program product for detecting sensitive personal information in a storage device. A block delta list containing a list of changed blocks in the storage device is processed. After identifying the changed blocks from the block delta list, a search is performed on those identified changed blocks for sensitive personal information using a character scanning technique. After identifying a changed block deemed to contain sensitive personal information, the changed block is translated from the block level to the file level using a hierarchical reverse mapping technique. By only analyzing the changed blocks to determine if they contain sensitive personal information, a lesser quantity of blocks needs to be processed in order to detect sensitive personal information in the storage device in near real-time. In this manner, sensitive personal information is detected in the storage device using fewer computing resources in a shorter amount of time.

Claims (19)

1. A method for detecting sensitive personal information in a storage device, the method comprising:

conducting an initial scan of blocks in a storage device;

identifying any changed blocks in said storage device, wherein a block is a contiguous set of bits or bytes that forms an identifiable unit of data, wherein a changed block is said block with an identifiable unit of data that has changed over a period of time, wherein said block is changed due to a storing of sensitive information;

adding said identified changed blocks to a block delta list, wherein said block delta list is a list of changed blocks in said storage device, wherein said block delta list includes deltas associated with said changed blocks that indicate differences in said changed blocks from a first point of time to a second point of time;

processing said block delta list;

identifying changed blocks from said block delta list;

searching said identified changed blocks for sensitive personal information using a character scanning technique comprising a convolutional neural network, a recurrent neural network or a regular expression;

identifying a changed block deemed to contain said sensitive personal information; and

translating, by a processor, said identified changed block from a block level to a file level using a hierarchical reverse mapping technique, wherein said hierarchical reverse mapping technique uses block level translations and file system inode translations.

2. The method as recited in claim 1 , wherein said identified changed block is translated from said block level to said file level using said hierarchical reverse mapping technique in response to said sensitive personal information being located in a middle of said identified changed block, wherein said block level translations comprise attributes and location of a block, wherein said file system inode translations comprise attributes and block locations of a file's data.

3. The method as recited in claim 1 further comprising:

searching blocks in said storage device to locate one or more adjacent blocks to said identified changed block in response to said sensitive personal information being located at an edge of said identified changed block.

4. The method as recited in claim 3 further comprising:

combining said one or more adjacent blocks to said identified changed block to form a new single block.

5. The method as recited in claim 4 further comprising:

determining whether said sensitive personal information is located in a middle of said new single block.

6. The method as recited in claim 1 further comprising:

queuing said block delta list in a queue.

7. The method as recited in claim 2 , wherein said attributes of said block level translations and said attributes of said file system inode translations comprise metadata indicating a time of a last change, access or modification, wherein said block level translations and said file system inode translations are used to translate said identified changed block from said block level to said file level.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2019
From: DESAI, RAJESH M.; QIAO, MU; RAPHAEL, ROGER C.; ROUTRAY, RAMANI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 048972/0830 →
Continuity (2)
Continuation 15789525 · Oct 20, 2017
Related Publication 20190251286A1 · Aug 15, 2019