IP Library Granted Patent US 10,574,705
Granted Patent B2
US 10,574,705 · App. 16/404,405 · Granted Feb 25, 2020

Data processing and scanning systems for generating and populating a data inventory

Inventors: Kabir A. Barday (Atlanta, GA); Mihir S. Karanjkar (Marietta, GA); Steven W. Finch (Kennesaw, GA); Ken A. Browne (Johns Creek, GA); Nathan W. Heard (Marietta, GA); Aakash H. Patel (Norcross, GA); Jason L. Sabourin (Brookhaven, GA); Richard L. Daniel (Atlanta, GA); Dylan D. Patton-Kuhl (Atlanta, GA); Jonathan Blake Brannon (Smyrna, GA)
Assignee: OneTrust, LLC
H04L63/20G06Q10/06H04L63/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,574,705
App. No.
16/404,405
Granted
Feb 25, 2020
Kind
B2
Abstract

In particular embodiments, a data processing data inventory generation system is configured to: (1) generate a data model (e.g., a data inventory) for one or more data assets utilized by a particular organization; (2) generate a respective data inventory for each of the one or more data assets; and (3) map one or more relationships between one or more aspects of the data inventory, the one or more data assets, etc. within the data model. In particular embodiments, a data asset (e.g., data system, software application, etc.) may include, for example, any entity that collects, processes, contains, and/or transfers personal data (e.g., such as a software application, “internet of things” computerized device, database, website, data-center, server, etc.). The system may be configured to identify particular data assets and/or personal data in data repositories using any suitable intelligent identity scanning technique.

Claims (34)

1. A computer-implemented data processing method for scanning one or more data repositories to identify one or more attributes of data associated with one or more individuals, the method comprising:

connecting, by one or more processors, via one or more computer networks, to one or more databases;

scanning, by one of more processors, the one or more databases to generate a catalog of one or more individuals and one or more pieces of personal information associated with the one or more individuals;

storing the catalog in computer memory;

scanning one or more data repositories based at least in part on the generated catalog to identify one or more attributes of data associated with the one or more individuals by searching one or more data fields in the one or more databases for the one or more pieces of personal information;

analyzing and correlating the one or more attributes and metadata for the scanned one or more data repositories;

using one or more machine learning techniques to categorize one or more data elements from the generated catalog;

analyzing a flow of the one or more data elements between the one or more data repositories and at least one known data asset; and

modifying an existing data model of data assets to include an attribute defined by the one or more data elements; and

electronically linking the at least one known data asset and the attribute in the existing data model of data assets.

2. The computer-implemented data processing method of claim 1 , further comprising:

providing a software application for installation on a computing device that is networked with the one or more data repositories associated with an organization; and

providing a communication channel between one or more remote scanning servers and the software application, wherein:

the software application is configured to communicate with the one or more remote scanning servers through a firewall; and

the software application is configured to transmit the one or more attributes of data associated with the one or more individuals to the one or more remote scanning servers.

3. The computer-implemented data processing method of claim 2 , wherein the step of categorizing the one or more data elements is performed by the one or more remote scanning servers.

4. The computer-implemented data processing method of claim 2 , wherein the software application comprises at least one virtual machine configured to perform the step of scanning the one or more data repositories based at least in part on the generated catalog.

5. The computer-implemented data processing method of claim 4 , wherein the software application is configured to cause the computing device to perform the step of scanning the one or more data repositories during non-peak networking hours.

6. The computer-implemented data processing method of claim 1 , wherein using one or more machine learning techniques to categorize one or more data elements from the generated catalog comprises using the one or more machine learning techniques to determine whether the one or more data elements are associated with the one or more individuals.

7. The computer-implemented data processing method of claim 1 , further comprising analyzing the one or more data repositories to determine whether each particular data repository is part of the existing data model of data assets.

8. The computer-implemented data processing method of claim 7 , further comprising in response to determining that a particular repository of the one or more data repositories is not part of an existing data model:

generating a data inventory for the particular data repository;

populating the data inventory with the one or more data elements; and

storing the data inventory in computer memory.

9. The computer-implemented data processing method of claim 1 , wherein the catalog comprises one or more data fields selected from the group consisting of:

(1) name;

(2) address;

(3) telephone number;

(4) e-mail address;

(5) social security number;

(6) banking information; and

(7) location data.

10. The computer-implemented data processing method of claim 1 , the method further comprising performing the step of scanning the one or more data repositories during non-peak networking hours.

11. The computer-implemented data processing method of claim 1 , the method further comprising performing the step of scanning the one or more data repositories during non-peak processing hours.

Assignments (2)
SECURITY INTEREST Recorded Jul 5, 2022
From: ONETRUST LLC
To: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
Reel/Frame 060573/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 12, 2019
From: BARDAY, KABIR A.; KARANJKAR, MIHIR S.; FINCH, STEVEN W.; SABOURIN, JASON L.; BROWNE, KEN A.; HEARD, NATHAN W.; PATEL, AAKASH H.; DANIEL, RICHARD L.; PATTON-KUHL, DYLAN D.; BRANNON, JONATHAN BLAKE
To: ONETRUST, LLC
Reel/Frame 049445/0394 →
Cited By (18)
US 12,190,330 US 12,204,564 US 12,216,794 US 12,259,882 US 12,265,896 US 12,277,232 US 12,288,233 US 12,299,065 US 12,353,405 US 12,381,915 US 12,412,140 US 12,536,329 US 12,591,828 US 12,609,938 US 12,641,108 US 12,688,324 US 12,694,044 US 12,718,167