IP Library Patent Application 18235846
Patent Application
App. No. 18/235,846

INTELLIGENT TRACING OF SENSITIVE DATA FLOW AND PRIVACY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/235,846
Abstract

A system that intelligently traces and identify sensitive data, tracks the flow of the sensitive data and is able to quickly and accurately identify privacy compliance issues. Tracing agents installed in a monitored system intercept API requests and responses, store the data, and process the data. Processing the data may include grouping APIs based on type and identifying user sessions. Baseline activity of a valid user is determined based on the analyze request and response data, and blocking rules can be applied at each individual tracing agent. The blocking rules can prevent unauthorized transmission of sensitive data, privacy violations, unauthorized users, and other improper access to data. The blocking rules may block all or a portion of an API request or response.

Claims (41)

1 . A method for tracing sensitive data flow, comprising:

intercepting API traffic between a client and a plurality of microservices, the API traffic including API requests and API responses associated with at least one user;

identifying API traffic that contains user data identified as sensitive user data at one of the plurality of microservices;

applying a blocking rule, at the one of the plurality of microservices, to the API traffic that contains user data identified as sensitive user data;

modifying a response to remove, based on the blocking rule, the identified sensitive user data from being included within the response to the identified API traffic; and

transmitting the modified response.

2 . The method of claim 1 , wherein intercepting API traffic is performed by a tracing agent installed at each of the plurality of microservices.

3 . The method of claim 2 , wherein the blocking rules are provided to each of the plurality of tracing agents by a remote application.

4 . The method of claim 2 , wherein the blocking rules are applied by the tracing agent at the one of the plurality of microservices.

5 . The method of claim 1 , wherein user data is identified as sensitive user data based on a predefined data type or by an administrator rule.

6 . The method of claim 1 , further comprising:

generating a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity; and

determining non-compliance of user sensitive data flow based on the user model and data compliance rules.

7 . The method of claim 1 , further comprising:

generating a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity; and

determining that a current user session is a breach of a user account based on the user model and intercepted API request and API response data.

8 . A non-transitory computer readable storage medium having embodied thereon a program, the program being executable by a processor to perform a method for tracing sensitive data flow, the method comprising:

intercepting API traffic between a client and a plurality of microservices, the API traffic including API requests and API responses associated with at least one user;

identifying API traffic that contains user data identified as sensitive user data at one of the plurality of microservices;

applying a blocking rule, at the one of the plurality of microservices, to the API traffic that contains user data identified as sensitive user data;

modifying a response to remove, based on the blocking rule, the identified sensitive user data from being included within the response to the identified API traffic; and

transmitting the modified response.

9 . The non-transitory computer readable storage medium of claim 8 , wherein intercepting API traffic is performed by a tracing agent installed at each of the plurality of microservices.

10 . The non-transitory computer readable storage medium of claim 9 , wherein the blocking rules are provided to each of the plurality of tracing agents by a remote application.

11 . The non-transitory computer readable storage medium of claim 9 , wherein the blocking rules are applied by the tracing agent at the one of the plurality of microservices.

12 . The non-transitory computer readable storage medium of claim 8 , wherein user data is identified as sensitive user data based on a predefined data type or by an administrator rule.

13 . The non-transitory computer readable storage medium of claim 8 , the method further comprising:

generating a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity; and

determining non-compliance of user sensitive data flow based on the user model and data compliance rules.

14 . The non-transitory computer readable storage medium of claim 8 , the method further comprising:

generating a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity; and

determining that a current user session is a breach of a user account based on the user model and intercepted API request and API response data.

15 . A system for tracing sensitive data flow, comprising:

one or more servers, wherein each server includes a memory and a processor; and

one or more modules stored in the memory and executed by at least one of the one or more processors to intercept API traffic between a client and a plurality of microservices, the API traffic including API requests and API responses associated with at least one user, identify API traffic that contains user data identified as sensitive user data at one of the plurality of microservices, apply a blocking rule, at the one of the plurality of microservices, to the API traffic that contains user data identified as sensitive user data, modify a response to remove, based on the blocking rule, the identified sensitive user data from being included within the response to the identified API traffic, and transmitting the modified response.

16 . The system of claim 15 , wherein intercepting API traffic is performed by a tracing agent installed at each of the plurality of microservices.

17 . The system of claim 16 , wherein the blocking rules are provided to each of the plurality of tracing agents by a remote application.

18 . The system of claim 16 , wherein the blocking rules are applied by the tracing agent at the one of the plurality of microservices.

19 . The system of claim 15 , wherein user data is identified as sensitive user data based on a predefined data type or by an administrator rule.

20 . The system of claim 15 , the one or more modules further executable to generate a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity, and determine non-compliance of user sensitive data flow based on the user model and data compliance rules.

21 . The system of claim 15 , the one or more modules further executable to generate a user model based on the intercepted API traffic, the user model including user geographic information, user typical API requests, and user API baseline activity, and determine that a current user session is a breach of a user account based on the user model and intercepted API request and API response data.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0062 →
RELEASE OF SECURITY INTEREST Recorded Aug 18, 2026
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
To: HARNESS INC.; HARNESS INTERNATIONAL, INC.
Reel/Frame 075689/0281 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 074240/0665 →
SECURITY INTEREST Recorded Mar 31, 2026
From: HARNESS INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY, AS AGENT
Reel/Frame 074240/0707 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2025
From: TRACEABLE INC.
To: HARNESS INC.
Reel/Frame 071911/0025 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2025
From: PADIYAR, SUDEEP; GUPTA, AMOD; NAGARAJ, SANJAY; GUNTUR, RAVINDRA; PIYUSH, ROSHAN; MITTAL, SATISH; GOYAL, ANUJ
To: TRACEABLE INC.
Reel/Frame 070477/0823 →