IP Library › Granted Patent US 12,526,145
Granted Patent B2
US 12,526,145 · App. 18/359,725 · Granted Jan 13, 2026

Secure forensic data collection on mobile devices

Inventors: Matthew Rasmussen (Tustin, CA); Jason Purviance (Overland Park, KS); Ryan Frye (Olathe, KS); William Baldisser (Maldonado, UY)
Assignee: ModeOne Technologies Inc.
H04L9/3213G06F21/6218H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,526,145
App. No.
18/359,725
Granted
Jan 13, 2026
Kind
B2
Abstract

Embodiments of the inventive subject matter are directed to systems and methods designed to facilitate data collection from a target device. By installing software on a target device and then granting that application system-level access to the target device, embodiments of the inventive subject matter can safely, and cryptographically securely, grant access to files on the target device via uniquely generated uniform resource locators.

Claims (48)

1 . A method of data collection, comprising the steps of:

presenting, on a first device, a dialogue requesting user permission for privileged file system access;

in response to receiving the user permission, sending, by the first device, a request to a server for generation of a handshake token;

receiving, on the first device, the handshake token generated by the server;

displaying, on the first device, the handshake token;

presenting, on a second device, a request to input the handshake token;

wherein the first device is separate from the second device;

authenticating an associated session using the handshake token;

determining, on the first device, available data collection sources;

presenting, on the second device, a user-interface to select one or more data sources for collection from the first device;

determining, on the first device, a count and size of files associated with the one or more data sources;

generating a cryptographically signed token;

generating a first uniform-resource locator using the cryptographically signed token and using a first file identifier;

on the first device, using the first uniform-resource locator, sending to the server a second file identifier and data associated with the second file identifier; and

validating, on the server, that the second file identifier matches the first file identifier.

2 . The method of claim 1 , wherein the step of determining, on the first device, available data collection sources further comprises sending information regarding the available data collection sources to the server.

3 . The method of claim 1 , wherein the step of presenting, on the second device, a user-interface to select one or more data sources for collection from the first device further comprises excluding data sources determined to be unavailable for collection from the first device.

4 . The method of claim 1 , wherein the step of generating the first uniform-resource locator using the cryptographically signed token is performed by the server.

5 . The method of claim 1 , wherein the step of authenticating the associated session using the handshake token is performed by the server.

6 . The method of claim 1 , further comprising the step of sending the first file identifier to the server.

7 . A method data collection from a target device, comprising the steps of:

receiving user permission for privileged file system access on the target device;

sending, by the target device to a server, a handshake token request;

receiving, by the target device, a handshake token generated by the server in response to the handshake token request;

receiving, by the target device, a message indicating authentication of a session based on the handshake token;

determining, on the target device, available data collection sources;

receiving, by the target device, a selection of data collection sources from the server;

receiving, by the target device, a first uniform-resource locator generated by the server using a cryptographically signed token;

on the target device, using the first uniform-resource locator, sending to the server a first file identifier and data associated with a second file identifier; and

receiving, on the target device, a message from the server indicating that the second file identifier matches the first file identifier.

8 . The method of claim 7 , wherein the first uniform-resource locator generated by the server is generated using the cryptographically signed token and the first file identifier.

9 . The method of claim 8 , wherein the first file identifier is associated with a file from one of the available data collection sources.

10 . The method of claim 7 , further comprising the step of determining, on the target device, a count and size of files associated with each of the available data collection sources.

11 . A method data collection from a target device, comprising the steps of:

receiving user permission for privileged file system access on the target device;

sending, by the target device to a server, a handshake token request;

receiving, by the target device, a handshake token generated by the server in response to the handshake token request;

authenticating, on a second device, a session using the handshake token;

wherein the target device is separate from the second device;

presenting, on the second device, a user-interface to select one or more data collection sources for collection on the target device;

generating, by the server, a first uniform-resource locator using a cryptographic token and a first file identifier;

on the first device, using the first uniform-resource locator, sending to the server a second file identifier and data associated with the second file identifier; and

validating, on the server, that the second file identifier matches the first file identifier.

12 . The method of claim 11 , further comprising the step of determining, on the target device, available data collection sources and transmitting a list of available data collection sources to the server.

13 . The method of claim 12 , further comprising the step of determining, on the target device, available data collection sources and transmitting a list of available data collection sources to the server.

14 . The method of claim 13 , wherein the step of presenting, on the second device, the user-interface to select one or more data collection sources for collection on the target device, further comprises excluding from possible selection data collection sources that are determined not to be available.

15 . The method of claim 11 , further comprising the step of determining, on the target device, a count and size of files associated with each of the one or more data collection sources.

16 . The method of claim 15 , further comprising, based on the size and type of a first file associated with the second file identifier, the step of compressing the first file before sending to the server data associated with the second file identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2023
From: RASMUSSEN, MATTHEW; PURVIANCE, JASON; FRYE, RYAN; BALDISSER, WILIAM
To: MODEONE TECHNOLOGIES INC.
Reel/Frame 064394/0070 →
Continuity (1)
Related Publication 20250038980A1 · Jan 30, 2025
References Cited (2)
US 11025272B2 · Dawood · 2021 [cited by examiner]
US 20200007531A1 · Koottayi · 2020 [cited by examiner]