IP Library Granted Patent US 11,734,441
Granted Patent B2
US 11,734,441 · App. 16/731,726 · Granted Aug 22, 2023

Systems and methods for tracing data across file-related operations

Inventors: Jaimen Dee Hoopes (Lehi, UT); Christian J Weibell (Lindon, UT)
Assignee: DIGITAL GUARDIAN LLC
G06F21/6218G06F16/168G06F16/1734G06T11/206G06F21/6245G06T2200/24H04L63/1433H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,734,441
App. No.
16/731,726
Granted
Aug 22, 2023
Kind
B2
Abstract

Provided herein are systems and methods of tracing data. A tracing engine may receive, via the user interface, a selection of a target file or an event involving the target file. The tracing engine may generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data. Each of the plurality of file instances may be related to at least the target file or another of the plurality of file instances via at least one file operation or data operation. The tracing engine may render, via a user interface, the generated trace.

Claims (31)

1. A system for tracing data, the system comprising:

a user interface; and

a tracing engine executable on at least one processor, the tracing engine configured to:

receive, via the user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances; and

render, via the user interface, the generated trace having the plurality of branches.

2. The system of claim 1 , wherein the at least one file operation or data operation performed on the target file or the another of the plurality of file instances comprises at least one of: a file open, file write, file move, file copy, network upload, file rename, file content edit, file permission update, copy and paste, email, copy to storage, or print operation.

3. The system of claim 1 , wherein the trace comprises a backward trace of the first data to a source of the first data in the network.

4. The system of claim 1 , wherein the trace comprises a forward trace of the first data to at least one destination file instance.

5. The system of claim 1 , wherein the first data comprises classified or sensitive data.

6. The system of claim 1 , wherein the tracing engine is further configured to provide, for two adjacent file instances of the plurality of file instances along a portion of the trace, a corresponding file operation or data operation relating the two adjacent file instances.

7. The system of claim 1 , wherein the tracing engine is further configured to render the generated trace by displaying a graph of the generated trace.

8. The system of claim 1 , wherein the tracing engine is further configured to render a first portion of the trace linking two adjacent file instances of the plurality of file instances, by a directional arrow corresponding to a type of file operation or data operation relating the two adjacent file instances.

9. The system of claim 1 , wherein the generated trace represents a timeline of events corresponding to the at least one file operation or data operation.

10. The system of claim 1 , wherein the tracing engine is further configured to generate statistics of types of file operations or data operations associated with the generated trace.

11. A method of tracing data, the method comprising:

receiving, by a tracing engine via a user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generating, by the tracing engine responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances; and

rendering, by the tracing engine in the user interface, the generated trace having the plurality of branches.

12. The method of claim 11 , wherein the at least one file operation or data operation performed on the target file or the another of the plurality of file instances comprises at least one of: a file open, file write, file move, file copy, network upload, file rename, file content edit, file permission update, copy and paste, email, copy to storage, or print operation.

13. The method of claim 11 , wherein the trace comprises a backward trace of the first data to a source of the first data in the network.

14. The method of claim 11 , wherein the trace comprises a forward trace of the first data to at least one destination file instance.

15. The method of claim 11 , wherein the first data comprises classified or sensitive data.

16. The method of claim 11 , further comprising providing, by the tracing engine, for two adjacent file instances of the plurality of file instances along a portion of the trace, a corresponding file operation or data operation relating the two adjacent file instances.

17. The method of claim 11 , comprising rendering the generated trace by displaying a graph of the generated trace.

18. The method of claim 11 , further comprising rendering, by the tracing engine, a first portion of the trace linking two adjacent file instances of the plurality of file instances, by a directional arrow corresponding to a type of file operation or data operation relating the two adjacent file instances.

19. The method of claim 11 , wherein the generated trace represents a timeline of events corresponding to the at least one file operation or data operation.

20. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

receive, via a user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances; and

render, via the user interface, the generated trace having the plurality of branches.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0766 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073783/0619 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 58892/0945 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL GUARDIAN LLC
Reel/Frame 073663/0411 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0766 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 28, 2022
From: DIGITAL GUARDIAN, LLC
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 058892/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2021
From: HOOPES, JAIMEN DEE; WEIBELL, CHRISTIAN J
To: DIGITAL GUARDIAN, INC.
Reel/Frame 057752/0251 →
CHANGE OF NAME Recorded Oct 11, 2021
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 057773/0151 →
Continuity (1)
Related Publication 20210200888A1 · Jul 1, 2021