IP Library Granted Patent US 12,619,784
Granted Patent B2
US 12,619,784 · App. 18/301,656 · Granted May 5, 2026

Systems and methods of determining compromised identity information

Inventors: Lester Leland Lockhart, III (Austin, TX); David Hugh Munson (Waterville, ME); Gregor R. Bonin (Austin, TX); Michael Cook (Wimberley, TX)
Assignee: Early Warning Services, LLC
G06F21/6263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,784
App. No.
18/301,656
Filed
Apr 17, 2023
Granted
May 5, 2026
Kind
B2
Art Unit
2435
USPC
726/4
Abstract

A compromised data exchange system extracts data from websites using a crawler, detects portions within the extracted data that resemble personally identifying information (PII) data based on PII data patterns using a risk assessment module, and compares a detected portion to data within a database of disassociated compromised PII data to determine a match using the risk assessment module. A risk score may be assigned to a data item within the database in response to determining the match. In some embodiments, URL data may also be detected in the extracted data. The detected URL data represents further websites that can be automatically crawled by the system to detect further PII data.

Claims (52)

1 . A compromised data exchange system, comprising:

a network interface;

one or more processors; and

a memory coupled with the one or more processors, the memory storing instructions thereon that, when executed, cause the one or more processors to:

extract data from one or more websites;

detect portions of the data that resemble personally identifying information (PII) data based on PII data patterns;

compare a detected portion of the data to data within a database of disassociated compromised PII data to determine a match, wherein the disassociated compromised PII data comprises PII data elements that are disconnected from one another and cannot be re-associated to correlate the PII data elements to an actual consumer identity by anyone other than a data originator of the PII data elements; and

assign a risk score to a data item within the database in response to determining the match.

2 . The compromised data exchange system of claim 1 , wherein the instructions further cause the one or more processors to:

provide the detected portions of the data to one or both of an administrator and an artificial intelligence engine.

3 . The compromised data exchange system of claim 1 , wherein the instructions further cause the one or more processors to:

encrypt the portions of the data that resemble PII data, wherein the data within the database of disassociated compromised PII data is encrypted.

4 . The compromised data exchange system of claim 3 , wherein:

the portions of the data that resemble PII data are encrypted using a same set of one or more encryption keys as used to encrypt the data within the database of disassociated compromised PII data.

5 . The compromised data exchange system of claim 4 , wherein:

the one or more encryption keys comprise different encryption keys for each field of PII data.

6 . The compromised data exchange system of claim 1 , wherein the instructions further cause the one or more processors to:

assign a risk score to each piece of disassociated data within the database of disassociated compromised PII data associated with a particular data breach event in response to determining multiple matches between the portions and the disassociated data.

7 . The compromised data exchange system of claim 1 , wherein the instructions further cause the one or more processors to:

increase a risk score for a piece of disassociated data within the database of disassociated compromised PII data in response to determining the match.

8 . A method of analyzing compromised data, comprising:

extracting data from one or more websites;

detecting portions of the data that resemble personally identifying information (PII) data based on PII data patterns;

comparing a detected portion of the data to data within a database of disassociated compromised PII data to determine a match, wherein the disassociated compromised PII data comprises PII data elements that are disconnected from one another and cannot be re-associated to correlate the PII data elements to an actual consumer identity by anyone other than a data originator of the PII data elements; and

assigning a risk score to a data item within the database in response to determining the match.

9 . The method of analyzing compromised data of claim 8 , wherein:

at least one website of the one or more websites is a website that is not indexed on search engines.

10 . The method of analyzing compromised data of claim 9 , wherein:

the at least one website associated with the dark web.

11 . The method of analyzing compromised data of claim 8 , further comprising:

ranking the one or more websites based on a metric of comprised information associated with each of the one or more websites.

12 . The method of analyzing compromised data of claim 11 , wherein:

ranking the one or more websites comprises combining and quantifying extracted patterns within the data from each of the one or more websites.

13 . The method of analyzing compromised data of claim 8 , further comprising:

deploying new data patterns of interested based on changed in breached data posting behavior.

14 . The method of analyzing compromised data of claim 11 , wherein:

the data is extracted using a crawler.

15 . A non-transitory computer-readable medium having instructions stored thereon that, when executed by one or more processors, cause the one or more processors to:

extract data from one or more websites;

detect portions of the data that resemble personally identifying information (PII) data based on PII data patterns;

compare a detected portion of the data to data within a database of disassociated compromised PII data to determine a match, wherein the disassociated compromised PII data comprises PII data elements that are disconnected from one another and cannot be re-associated to correlate the PII data elements to an actual consumer identity by anyone other than a data originator of the PII data elements; and

assign a risk score to a data item within the database in response to determining the match.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions further cause the one or more processors to:

identify at least one website associated with one or both of a uniform resource locator and a link from the extracted data.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the one or more processors to:

extract data from the at least one website.

18 . The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the one or more processors to:

rank websites of the one or more websites from which the one or both of the uniform resource locator and the link associated with each of the at least one website was found.

19 . The non-transitory computer-readable medium of claim 18 , wherein:

ranking the websites of the one or more websites is performed based on a number of different sets of PII data at each of the websites of the one or more websites.

20 . The non-transitory computer-readable medium of claim 15 , wherein:

the risk score is determined at least in part based on a ranking of a webpage from which the data item was extracted.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2023
From: XOR DATA EXCHANGE, INC.
To: EARLY WARNING SERVICES, LLC
Reel/Frame 065278/0016 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: LOCKHART, LESTER L, III; MUNSON, DAVID HUGH; BONIN, GREGOR R.; COOK, MICHAEL
To: XOR DATA EXCHANGE, INC.
Reel/Frame 065252/0078 →
Continuity (4)
Continuation 16563341 · Sep 6, 2019
Continuation In Part 16267297 · Feb 4, 2019
Continuation 15237519 · Aug 15, 2016
Related Publication 20230385451A1 · Nov 30, 2023
References Cited (53)
US 7240363B1 · Ellingson · 2007 [cited by applicant]
US 7617393B2 · Betz et al. · 2009 [cited by applicant]
US 7676834B2 · Camaisa et al. · 2010 [cited by applicant]
US 7870608B2 · Shraim et al. · 2011 [cited by applicant]
US 7913302B2 · Shraim et al. · 2011 [cited by applicant]
US 7962962B2 · Adler et al. · 2011 [cited by applicant]
US 8019689B1 · Nachenberg · 2011 [cited by applicant]
US 8285656B1 · Chang et al. · 2012 [cited by applicant]
US 8359651B1 · Wu et al. · 2013 [cited by applicant]
US 8429545B2 · Dixon et al. · 2013 [cited by applicant]
US 8561185B1 · Muthusrinivasan et al. · 2013 [cited by applicant]
US 8566726B2 · Dixon et al. · 2013 [cited by applicant]
US 8683031B2 · Green et al. · 2014 [cited by applicant]
US 8713450B2 · Garbow et al. · 2014 [cited by applicant]
US 8752181B2 · Grzymala-Busse et al. · 2014 [cited by applicant]
US 8800027B1 · Ackerman · 2014 [cited by examiner]
US 8875284B1 · Newstadt et al. · 2014 [cited by applicant]
US 8898086B2 · Downing et al. · 2014 [cited by applicant]
US 8898183B2 · Nickell et al. · 2014 [cited by applicant]
US 9172706B2 · Krishnamurthy et al. · 2015 [cited by applicant]
US 9203648B2 · Shraim et al. · 2015 [cited by applicant]
US 9392008B1 · Michel et al. · 2016 [cited by applicant]
US 9449178B2 · Prem et al. · 2016 [cited by applicant]
US 10268840B2 · Lockhart, III et al. · 2019 [cited by applicant]
US 10296918B1 · Cohen · 2019 [cited by examiner]
US 10599872B2 · Lockhart, III · 2020 [cited by examiner]
US 11556671B2 · Lockhart, III · 2023 [cited by examiner]
US 11630918B2 · Lockhart, III · 2023 [cited by examiner]
US 20080147554A1 · Stevens et al. · 2008 [cited by applicant]
US 20100293090A1 · Domenikos et al. · 2010 [cited by applicant]
US 20130111220A1 · Friedlander et al. · 2013 [cited by applicant]
US 20130238600A1 · Kindler et al. · 2013 [cited by applicant]
US 20130262867A1 · Evancich et al. · 2013 [cited by applicant]
US 20140059355A1 · Schuette · 2014 [cited by examiner]
US 20140129844A1 · Johnson et al. · 2014 [cited by applicant]
US 20140250526A1 · Khanna et al. · 2014 [cited by applicant]
US 20150088756A1 · Makhotin et al. · 2015 [cited by applicant]
US 20150134971A1 · Park et al. · 2015 [cited by applicant]
US 20150278550A1 · Lin · 2015 [cited by applicant]
US 20160012561A1 · Lappenbusch et al. · 2016 [cited by applicant]
US 20160044054A1 · Stiansen et al. · 2016 [cited by applicant]
US 20160147945A1 · MacCarthy et al. · 2016 [cited by applicant]
US 20170161746A1 · Cook et al. · 2017 [cited by applicant]
U.S. Appl. No. 14/960,288, Non-Final Office Action, Mailed On May 30, 2019, 10 pages. [cited by applicant]
U.S. Appl. No. 14/960,288, Non-Final Office Action, Mailed On Dec. 11, 2019, 17 pages. [cited by applicant]
U.S. Appl. No. 14/960,288, “Restriction Requirement”, Dec. 11, 2018, 6 pages. [cited by applicant]
U.S. Appl. No. 16/267,297, Non-Final Office Action, Mailed On Jun. 24, 2019, 11 pages. [cited by applicant]
U.S. Appl. No. 16/267,297, Notice of Allowance, Mailed On Oct. 2, 2019, 7 pages. [cited by applicant]
U.S. Appl. No. 16/563,341, Final Office Action, Mailed On Sep. 2, 2022, 7 pages. [cited by applicant]
U.S. Appl. No. 16/563,341, Non-Final Office Action, Mailed On Mar. 4, 2022, 27 pages. [cited by applicant]
U.S. Appl. No. 16/563,341, Notice of Allowance, Mailed On Dec. 7, 2022, 6 pages. [cited by applicant]
U.S. Appl. No. 17/009,401, Notice of Allowance, Mailed On Sep. 15, 2022, 9 pages. [cited by applicant]
Romanosky et al., “Do Data Breach Disclosure Laws Reduce Identity Theft?”, Seventh Workshop on the Economics of Information Security, Jun. 25-28, 2008, 20 pages. [cited by applicant]