IP Library Granted Patent US 11,768,934
Granted Patent B2
US 11,768,934 · App. 17/080,556 · Granted Sep 26, 2023

Data breach system and method

Inventors: James Van Dyke (Pleasanton, CA); Alphonse Pascual (Benicia, CA)
Assignee: Sontiq, Inc.
G06F21/554G06F21/552G06F21/566G06F21/6245G06F21/6272G06F21/31G06Q40/03
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,768,934
App. No.
17/080,556
Granted
Sep 26, 2023
Kind
B2
Abstract

A method and system for generating a consumer breach history profile of a consumer over an electronic network includes receiving via the network consumer profile information including at least one consumer information element corresponding to the consumer, generating a consumer breach history profile in a database using the consumer profile information, and associating the consumer breach history profile with the consumer profile information in the database. The database includes breach events, each breach event associated with at least one breached information element. Consumer profile information is matched to a respective breach event by determining a match between the consumer information element and the breached information element associated with the respective breach event. The respective breach event is associated in the database with the consumer breach history profile and a mitigation action. A notification to the consumer of the breach event and mitigation action is generated.

Claims (91)

1. A method of generating a consumer breach history profile of a consumer over an electronic network via a computer server, comprising:

receiving, via a network, consumer profile information corresponding to a consumer;

generating, in a first database and using the consumer profile information, the consumer breach history profile;

associating, in the first database, the consumer breach history profile with the consumer profile information;

accessing, via a network, an electronic transaction account associated with the consumer;

wherein the electronic transaction account is configured to execute a consumer transaction between the consumer and a party to the consumer transaction;

generating, via the electronic transaction account, electronic transaction information associated with the consumer transaction;

retrieving, via the network, the electronic transaction information;

wherein the electronic transaction information includes:

a consumer identifier corresponding to the consumer;

a party identifier corresponding to the party; and

a transaction time corresponding to the time the consumer transaction was executed;

associating, in a second database, the electronic transaction information with the consumer;

wherein the second database includes breach information corresponding to a plurality of data breaches;

comparing the electronic transaction information with the breach information of the plurality of data breaches;

wherein comparing the electronic transaction information includes:

determining a match between the electronic transaction information and the breach information of a respective data breach;

appending the consumer breach history profile with each match; and

wherein appending the consumer breach history profile includes:

associating, in the second database, the respective data breach with the consumer breach history profile;

identifying the data breach for each match within a breach listing, the breach listing being accessible for display to the consumer through an interface; and

displaying an accumulated harm risk score with the breach listing, the accumulated harm risk score providing a relative indicator of risk accumulated for the consumer as result of the data breaches; and

generating a breach notification to apprise the consumer of the appending to the consumer breach history profile.

2. The method of claim 1 , wherein the transaction time includes the date on which the consumer transaction occurred.

3. The method of claim 1 , wherein the consumer profile information includes account credentials corresponding to the electronic transaction account;

the method further comprising:

accessing the electronic transaction account using the account credentials.

4. The method of claim 1 , wherein accessing the electronic transaction account includes:

receiving, via the network, an account plug-in for accessing the electronic transaction account;

executing the account plug-in to transmit the transaction account information via the network; and

retrieving, via the account plug-in, the electronic transaction information from the account.

5. The method of claim 1 , wherein:

the electronic transaction account is an email account;

the consumer transaction is an email transaction between an email sender and an email recipient; and

the party to the consumer transaction is one of the email sender and the email recipient.

6. The method of claim 5 , wherein comparing the electronic transaction information with the breach information includes:

determining a match between the breach information of the respective data breach and at least one of the email sender or the email recipient.

7. The method of claim 5 , wherein the consumer identifier is an email address associated with the consumer.

8. The method of claim 1 , wherein:

the electronic transaction account is an electronic payment account;

the consumer transaction is an electronic payment transaction between a payor and a payee; and

the party to the consumer transaction is one of the payor and the payee.

9. The method of claim 8 , wherein comparing the electronic transaction information with the breach information includes:

determining a match between the breach information of the respective data breach and at least one of the payor and the payee.

10. The method of claim 8 , wherein the consumer identifier is a payment account number associated with the consumer.

11. The method of claim 10 , wherein the payment account number is a payment card number.

12. A method of generating a consumer breach history profile of a consumer over an electronic network via a computer server, comprising:

receiving, via a network, consumer profile information including at least one consumer information element corresponding to the consumer;

generating, in a database and using the consumer profile information, a consumer breach history profile;

associating, in the database, the consumer breach history profile with the consumer profile information;

wherein the database includes a plurality of breach events, each breach event associated with at least one breached information element;

matching the consumer profile information to a respective breach event of the plurality of breach events;

wherein matching the consumer profile information to the respective breach event includes:

determining a plurality of matches between the at least one consumer information element and the at least one breached information element associated with the respective breach event;

associating, in the database, the consumer breach history profile with the respective breach events;

selecting, via the server, at least one mitigation actions defined by the at least one breached information element;

associating, in the database, the at least one mitigation action with the consumer breach history profile;

generating a notification to the consumer, wherein the notification includes the at least one mitigation action; and

displaying, via a user device, a breach system interface, including displaying with the breach system interface an accumulated harm risk score and a plurality of data breach scores, the accumulated harm risk score providing the consumer a relative indicator of overall risk accumulated as result of a total harm of the breach events, each data breach score being associated with one of the matches and providing the consumer a relative indicator of risk for the corresponding breach event.

13. The method of claim 12 , further comprising:

displaying, via the breach system interface, the at least one mitigation action; and

associating, in the breach system interface, the at least one mitigation action with an interface element, wherein the interface element is actuable to complete the at least one mitigation action.

14. The method of claim 13 , further comprising:

displaying, in the breach system interface, a visual indicator configured to indicate whether the at least one mitigation action is completed or incomplete; and

removing the at least one mitigation action from the breach system interface when the mitigation action is completed.

15. The method of claim 12 , further comprising:

indicating, in the breach system interface, a completion status of the mitigating action;

indicating, in the breach system interface, a consumer identity score, the consumer identity score defined by a combination of the at least one breached information element and the one or more mitigation actions associated with the consumer breach history profile; and

indicating, in the breach system interface, a plurality of harms, the harms each describing potential harm for the consumer from the breach event of a corresponding one of the matches.

16. A method of generating a consumer breach history profile of a consumer over an electronic network via a computer server, comprising:

receiving, via a network, consumer profile information corresponding to a consumer;

generating, in a database and using the consumer profile information, a consumer breach history profile;

associating, in the database, the consumer breach history profile with the consumer profile information;

retrieving, via the network, breach event information from a breach information source;

comparing the breach event information with the consumer profile information;

wherein comparing the breach event information includes:

determining a plurality of breach events associated with a plurality of matches between the breach event information and the consumer profile information;

appending the consumer breach history profile when each match is determined; and

wherein appending the consumer breach history profile includes:

associating, in the database, the breach event information with the consumer breach history profile; and

identifying the breach event information for each match within a breach listing, the breach listing presenting each of the breach events and being accessible for display to the consumer through an interface; and

generating a breach notification to apprise the consumer of the appending to the consumer breach history profile.

17. The method of claim 16 , wherein the breach information source is the consumer.

18. The method of claim 16 , wherein the breach information source is a dark web service provider, the method further comprising:

identifying, via the dark web service provider, dark web content including a breached information element;

retrieving, via the network, the dark web content; and

excerpting from the dark web content, the breached information element.

19. The method of claim 16 , further comprising:

displaying an accumulated harm risk score within the breach listing, the accumulated harm risk score providing the consumer a relative indicator of overall risk accumulated as result of the breach events.

20. The method of claim 19 , further comprising:

displaying a plurality of data breach scores within the breach listing, each of the data breach scores providing the consumer a relative indicator of risk for a corresponding one of the breach events.

Assignments (6)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NO. 16/990,698 PREVIOUSLY RECORDED ON REEL 058294 FRAME 0010. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 21, 2022
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 059846/0157 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 058294, FRAME 0161 Recorded Dec 27, 2021
From: JPMORGAN CHASE BANK, N.A.
To: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
Reel/Frame 058593/0852 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Dec 1, 2021
From: TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; NEUSTAR DATA SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: DEUTSCHE BANK AG NEW YORK BRANCH
Reel/Frame 058294/0010 →
GRANT OF SECURITY INTEREST IN UNITED STATES PATENTS Recorded Dec 1, 2021
From: EBUREAU, LLC; IOVATION, INC.; SIGNAL DIGITAL, INC.; TRANS UNION LLC; TRANSUNION HEALTHCARE, INC.; TRANSUNION INTERACTIVE, INC.; TRANSUNION RENTAL SCREENING SOLUTIONS, INC.; TRANSUNION TELEDATA LLC; AGGREGATE KNOWLEDGE, LLC; TRU OPTIK DATA CORP.; NEUSTAR INFORMATION SERVICES, INC.; TRUSTID, INC.; NEUSTAR, INC.; NEUSTAR IP INTELLIGENCE, INC.; MARKETSHARE PARTNERS, LLC; SONTIQ, INC.
To: JPMORGAN CHASE BANK, N.A
Reel/Frame 058294/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2021
From: BREACH CLARITY, INC.
To: SONTIQ, INC.
Reel/Frame 055580/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: VAN DYKE, JAMES; PASCUAL, ALPHONSE
To: BREACH CLARITY, INC.
Reel/Frame 054169/0873 →