IP Library Granted Patent US 12,425,442
Granted Patent B2
US 12,425,442 · App. 18/453,447 · Granted Sep 23, 2025

Systems and methods for tracing data across file-related operations

Inventors: Jaimen Dee Hoopes (Lehi, UT); Christian J Weibell (Lindon, UT)
Assignee: DIGITAL GUARDIAN LLC
G06F21/6218G06F16/168G06F16/1734G06T11/206G06F21/6245G06T2200/24H04L63/1433H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,442
App. No.
18/453,447
Granted
Sep 23, 2025
Kind
B2
Abstract

Provided herein are systems and methods of tracing data. A tracing engine may receive, via the user interface, a selection of a target file or an event involving the target file. The tracing engine may generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data. Each of the plurality of file instances may be related to at least the target file or another of the plurality of file instances via at least one file operation or data operation. The tracing engine may render, via a user interface, the generated trace.

Claims (34)

1. A system for tracing data, the system comprising:

a user interface; and

a tracing engine executable on at least one processor, the tracing engine configured to:

receive, via the user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances;

determine that a first file instance of the plurality of file instances was generated in a way that violates a security policy; and

render, via the user interface, a graphical icon indicative of the violated security policy and at least a portion of the generated trace that includes the first file instance.

2. The system of claim 1 , wherein the at least one file operation or data operation performed on the target file or the another of the plurality of file instances comprises at least one of: a file open, file write, file move, file copy, network upload, file rename, file content edit, file permission update, copy and paste, email, copy to storage, or print operation.

3. The system of claim 1 , wherein the trace comprises a backward trace of the first data to a source of the first data in the network.

4. The system of claim 1 , wherein the trace comprises a forward trace of the first data to at least one destination file instance.

5. The system of claim 1 , wherein the first data comprises classified or sensitive data.

6. The system of claim 1 , wherein the tracing engine is further configured to provide, for two adjacent file instances of the plurality of file instances along a portion of the trace, a corresponding file operation or data operation relating the two adjacent file instances.

7. The system of claim 1 , wherein the tracing engine is further configured to render the generated trace by displaying a graph of the generated trace.

8. The system of claim 1 , wherein the tracing engine is further configured to render a first portion of the trace linking two adjacent file instances of the plurality of file instances, by a directional arrow corresponding to a type of file operation or data operation relating the two adjacent file instances.

9. The system of claim 1 , wherein the generated trace represents a timeline of events corresponding to the at least one file operation or data operation.

10. The system of claim 1 , wherein the tracing engine is further configured to generate statistics of types of file operations or data operations associated with the generated trace.

11. A method of tracing data, the method comprising:

receiving, by a tracing engine via a user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generating, by the tracing engine responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances; and

determining, by the tracing engine, that a first file instance of the plurality of file instances was generated in a way that violates a security policy; and

rendering, by the tracing engine in the user interface, a graphical icon indicative of the violated security policy and at least a portion of the generated trace that includes the first file instance.

12. The method of claim 11 , wherein the at least one file operation or data operation performed on the target file or the another of the plurality of file instances comprises at least one of: a file open, file write, file move, file copy, network upload, file rename, file content edit, file permission update, copy and paste, email, copy to storage, or print operation.

13. The method of claim 11 , wherein the trace comprises a backward trace of the first data to a source of the first data in the network.

14. The method of claim 11 , wherein the trace comprises a forward trace of the first data to at least one destination file instance.

15. The method of claim 11 , wherein the first data comprises classified or sensitive data.

16. The method of claim 11 , further comprising providing, by the tracing engine, for two adjacent file instances of the plurality of file instances along a portion of the trace, a corresponding file operation or data operation relating the two adjacent file instances.

17. The method of claim 11 , comprising rendering the generated trace by displaying a graph of the generated trace.

18. The method of claim 11 , further comprising rendering, by the tracing engine, a first portion of the trace linking two adjacent file instances of the plurality of file instances, by a directional arrow corresponding to a type of file operation or data operation relating the two adjacent file instances.

19. The method of claim 11 , wherein the generated trace represents a timeline of events corresponding to the at least one file operation or data operation.

20. A non-transitory computer readable medium storing program instructions for causing one or more processors to:

receive, via a user interface, a selection of a target file or an event involving the target file, wherein the target file is of a particular file format which an application running on the system may access contents of the target file;

generate, responsive to receiving the selection, a trace of first data in the target file to a plurality of file instances in a network each having at least one version of the first data, each of the plurality of file instances related to at least the target file or another of the plurality of file instances via at least one file operation or data operation performed on the target file or the another of the plurality of file instances, the trace having a plurality of branches each corresponding to a generation of a new file instance of the target file resulting from a file operation or data operation performed on one or more of the target file or the another of the plurality of file instances;

determine that a first file instance of the plurality of file instances was generated in a way that violates a security policy; and

render, via the user interface, a graphical icon indicative of the violated security policy and at least a portion of the generated trace that includes the first file instance.

Assignments (6)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0050 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: DIGITAL GUARDIAN LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0844 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2023
From: HOOPES, JAMIEN DEE; WEIBELL, CHRISTEN J
To: DIGITAL GUARDIAN, INC.
Reel/Frame 065437/0210 →
CHANGE OF NAME Recorded Nov 2, 2023
From: DIGITAL GUARDIAN, INC.
To: DIGITAL GUARDIAN LLC
Reel/Frame 065445/0345 →
Continuity (2)
Continuation 16731726 · Dec 31, 2019
Related Publication 20240386123A1 · Nov 21, 2024
References Cited (73)
US 5867160A · Kraft, IV · 1999 [cited by examiner]
US 6493868B1 · Dasilva et al. · 2002 [cited by applicant]
US 7047279B1 · Beams · 2006 [cited by examiner]
US 7124164B1 · Chemtob · 2006 [cited by examiner]
US 7197638B1 · Grawrock · 2007 [cited by examiner]
US 7280991B1 · Beams · 2007 [cited by examiner]
US 7590941B2 · Wee · 2009 [cited by examiner]
US 8484578B2 · Gordner · 2013 [cited by examiner]
US 8621287B1 · Ethington · 2013 [cited by examiner]
US 9418356B2 · Crevier · 2016 [cited by examiner]
US 9473532B2 · Pearl · 2016 [cited by examiner]
US 9652741B2 · Goldberg · 2017 [cited by examiner]
US 9715534B2 · Beausoleil · 2017 [cited by examiner]
US 10007405B2 · D'Amore · 2018 [cited by examiner]
US 10394691B1 · Cole · 2019 [cited by examiner]
US 11573971B1 · Cannon · 2023 [cited by examiner]
US 20020002562A1 · Moran · 2002 [cited by examiner]
US 20020163548A1 · Chiu · 2002 [cited by examiner]
US 20030023686A1 · Beams · 2003 [cited by examiner]
US 20030088854A1 · Wygodny · 2003 [cited by examiner]
US 20040169683A1 · Chiu · 2004 [cited by examiner]
US 20040201602A1 · Mody · 2004 [cited by examiner]
US 20050257160A1 · DeBellis · 2005 [cited by examiner]
US 20060190391A1 · Cullen, III · 2006 [cited by examiner]
US 20060206370A1 · Skopal · 2006 [cited by examiner]
US 20060253542A1 · McCausland · 2006 [cited by examiner]
US 20070078930A1 · Ludwig · 2007 [cited by examiner]
US 20070100712A1 · Kilpatrick · 2007 [cited by examiner]
US 20070156670A1 · Lim · 2007 [cited by examiner]
US 20070191979A1 · Zeng · 2007 [cited by examiner]
US 20080091656A1 · Charnock et al. · 2008 [cited by applicant]
US 20080098295A1 · Nelson · 2008 [cited by examiner]
US 20080120126A1 · Bone · 2008 [cited by examiner]
US 20080263629A1 · Anderson · 2008 [cited by examiner]
US 20090089625A1 · Kannappan · 2009 [cited by examiner]
US 20100070970A1 · Hu · 2010 [cited by examiner]
US 20100138756A1 · Saund · 2010 [cited by examiner]
US 20100180213A1 · Karageorgos · 2010 [cited by examiner]
US 20100205537A1 · Knighton · 2010 [cited by examiner]
US 20100228750A1 · Solin · 2010 [cited by examiner]
US 20100229085A1 · Nelson · 2010 [cited by examiner]
US 20100235750A1 · Noland · 2010 [cited by examiner]
US 20100241972A1 · Spataro · 2010 [cited by examiner]
US 20100332980A1 · Sun · 2010 [cited by examiner]
US 20110167353A1 · Grosz · 2011 [cited by examiner]
US 20110239129A1 · Kummerfeld · 2011 [cited by examiner]
US 20110239135A1 · Spataro · 2011 [cited by examiner]
US 20120089610A1 · Agrawal · 2012 [cited by examiner]
US 20120233205A1 · McDermott · 2012 [cited by examiner]
US 20120240061A1 · Hillenius · 2012 [cited by examiner]
US 20120260195A1 · Hon · 2012 [cited by examiner]
US 20120296790A1 · Robb · 2012 [cited by examiner]
US 20120331394A1 · Trombley-Shapiro · 2012 [cited by examiner]
US 20130019028A1 · Myers · 2013 [cited by examiner]
US 20130080919A1 · Kiang · 2013 [cited by examiner]
US 20140068550A1 · Simitsis · 2014 [cited by examiner]
US 20140082071A1 · Rexer · 2014 [cited by examiner]
US 20150309915A1 · Ajith Kumar et al. · 2015 [cited by applicant]
US 20150310188A1 · Ford · 2015 [cited by examiner]
US 20150331549A1 · Legris · 2015 [cited by examiner]
US 20160196198A1 · Ajith Kumar et al. · 2016 [cited by applicant]
US 20170063897A1 · Muddu et al. · 2017 [cited by applicant]
US 20170270022A1 · Moresmau · 2017 [cited by examiner]
US 20180023959A1 · Ivanov et al. · 2018 [cited by applicant]
US 20180089561A1 · Oliner · 2018 [cited by examiner]
US 20190207969A1 · Brown · 2019 [cited by examiner]
US 20190294720A1 · Beringer et al. · 2019 [cited by applicant]
US 20190303349A1 · Burshteyn · 2019 [cited by examiner]
US 20200007554A1 · Vincent · 2020 [cited by examiner]
US 20200104518A1 · Parker · 2020 [cited by examiner]
US 20200326823A1 · Duffield et al. · 2020 [cited by applicant]
US 20200335064A1 · Greco · 2020 [cited by examiner]
US 20200389313A1 · Singh · 2020 [cited by examiner]