IP Library Granted Patent US 12,481,786
Granted Patent B2
US 12,481,786 · App. 18/454,378 · Granted Nov 25, 2025

Tagging and auditing sensitive information in a database environment

Inventor: Karlotcha Hoa (San Francisco, CA)
Assignee: ZenPayroll, Inc.
G06F21/6245G06F9/542G06F16/221G06F16/24573G06F16/248G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,786
App. No.
18/454,378
Granted
Nov 25, 2025
Kind
B2
Abstract

Access to sensitive information in a database can be restricted to improve security and enable efficient auditing. A security engine receives a request from a requesting entity to access data in the database and determines that the requested data includes sensitive information. In response to the requesting entity being authorized to access the data, the security engine retrieves the requested data from the database and modifies the retrieved data by modifying metadata of the retrieved data to include a tag indicating that the retrieved data includes sensitive information. The security engine provides the modified data to the requesting entity and modifies a data access log to identify each attempted access to the modified data. When sensitive data is requested, an interface can include an obscuring element, requiring a user to manually select the element to view the data, enabling the logging of the explicit access request by the user.

Claims (44)

1 . A method comprising:

providing, by a security engine, access to data from a database requested by a requesting entity, wherein the security engine determines if the accessed data includes sensitive information or non-sensitive information based at least in part on a format of the accessed data, wherein the security engine, in response to determining that the accessed data includes non-sensitive information, accesses and displays the non-sensitive information within a corresponding set of data fields in a graphical user interface and, in response to determining that the accessed data includes sensitive information, modifies the accessed data to include a tag within metadata of the accessed data indicating that the accessed data includes sensitive information and responsive to determining the requesting entity is not authorized to access the modified data, preventing the requesting entity from accessing the data;

providing, by the security engine, the modified data to a client device of the requesting entity, the client device different from the security engine and the database, the client device configured to display selectable obscuring interface elements completely covering each of a plurality of data fields corresponding to the modified data wherein each selectable obscuring interface element, when selected, is removed such that the modified data is displayed within the corresponding data field if the requesting entity is authorized to view the modified data, and wherein all additional selectable obscuring elements that the requesting entity has not selected and that correspond to modified data that the requesting entity is authorized to view are also removed without being selected by the requesting entity such that the modified data corresponding to the additional selectable obscuring elements becomes visible and all selectable obscuring elements that correspond to modified data that the requesting entity is not authorized to view are not removed; and

receiving, by the security engine, a notification from the client device in response to a request from each of a plurality of accessing entities to access the modified data from the client device, wherein the client device provides the notification to the security engine in response to detecting the tag within the modified data when access is requested by each of the accessing entities, the security engine configured to modify a data access log based on the received notification to include 1) an identification of which selectable obscuring interface elements are selected by the requesting entity, 2) a personnel identification associated with the requesting entity, and 3) an authorization level associated with the requesting entity.

2 . The method of claim 1 , wherein the metadata of the accessed data comprises at least one of: a category of data, a type of data, a format of data, a sensitivity of data, and a required authorization level.

3 . The method of claim 1 , wherein the modified data access log identifies at least one of:

a user account associated with the requesting entity;

a hardware identifier for a device used by the requesting entity to access the modified data;

a software identifier for software used by the requesting entity to access the modified data; and

information indicating whether the attempt to access the modified data was successful.

4 . The method of claim 1 , wherein the modified data access log identifies one or more of: a web page used to access the modified data, a form used to access the modified data, and one or more fields displayed by a device of the requesting entity associated with the modified data.

5 . The method of claim 1 , wherein the sensitive information is personally identifiable information (PII).

6 . The method of claim 1 , wherein portions of the database including sensitive information are defined by a data security policy.

7 . The method of claim 1 , further comprising:

responsive to receiving a request from an auditing entity to audit the modified data access log for information associated with a potential data breach, accessing, by the security engine, access data associated with the potential data breach from the modified data access log; and

responsive to determining that the auditing entity is authorized to audit the modified data access log, providing, by the security engine, the accessed information to the auditing entity.

8 . The method of claim 7 , further comprising modifying, by the security engine, the data access log to identify the request to audit the modified data access log by the auditing entity.

9 . The method of claim 1 , further comprising:

responsive to determining that the requested data is not stored in one or more database columns corresponding to sensitive information, providing, by the security engine, the requested data from the database to the requesting entity.

10 . The method of claim 1 , further comprising:

in response to the requesting entity being unauthorized to access the data, modifying, by the security engine, the data access log to identify the request from the requesting entity to access the data in the database and to indicate that the requesting entity is not authorized to access the data.

11 . The method of claim 1 , further comprising:

responsive to determining that the modified data has been accessed by an unauthorized entity, by the security engine, sending a notification identifying the unauthorized access to a user.

12 . The method of claim 1 , further comprising:

determining that the modified data has been accessed by an unauthorized accessing entity that is unauthorized to access the modified data; and

responsive to the determining that the modified data has been accessed by the unauthorized entity, preventing, by the security engine, the unauthorized entity from subsequently accessing the modified data.

13 . A non-transitory computer readable storage medium storing executable instructions that, when executed by one or more processors, cause the processor to perform steps comprising:

providing, by a security engine, access to data from a database requested by a requesting entity, wherein the security engine determines if the accessed data includes sensitive information or non-sensitive information based at least in part on a format of the accessed data, wherein the security engine, in response to determining that the accessed data includes non-sensitive information, accesses and displays the non-sensitive information within a corresponding data field in a graphical user interface and, in response to determining that the accessed data includes sensitive information, modifies the accessed data to include a tag within metadata of the accessed data indicating that the accessed data includes sensitive information and responsive to determining the requesting entity is not authorized to access the modified data, preventing the requesting entity from accessing the data;

providing, by the security engine, the modified data to a client device of the requesting entity, the client device different from the security engine and the database, the client device configured to display selectable obscuring interface elements completely covering each of a plurality of data fields corresponding to the modified data wherein each selectable obscuring interface element, when selected, is removed such that the modified data is displayed within the corresponding data field if the requesting entity is authorized to view the modified data, and wherein all additional selectable obscuring elements that the requesting entity has not selected and that correspond to modified data that the requesting entity is authorized to view are also removed without being selected by the requesting entity such that the modified data corresponding to the additional selectable obscuring elements becomes visible and all selectable obscuring elements that correspond to modified data that the requesting entity is not authorized to view are not removed; and

receiving, by the security engine, a notification from the client device in response to a request from each of a plurality of accessing entities to access the modified data from the client device, wherein the client device provides the notification to the security engine in response to detecting the tag within the modified data when access is requested by each of the accessing entities, the security engine configured to modify a data access log based on the received notification to include 1) an identification of which selectable obscuring interface elements are selected by the requesting entity, 2) a personnel identification associated with the requesting entity, and 3) an authorization level associated with the requesting entity.

14 . The non-transitory computer readable storage medium of claim 13 , wherein the sensitive information is personally identifiable information (PII).

15 . The non-transitory computer readable storage medium of claim 13 , wherein the steps further comprise:

responsive to receiving a request from an auditing entity to audit the modified data access log for information associated with a potential data breach, accessing, by the security engine, access data associated with the potential data breach from the modified data access log; and

responsive to determining that the auditing entity is authorized to audit the modified data access log, providing, by the security engine, the accessed information to the auditing entity.

16 . The non-transitory computer readable storage medium of claim 13 , wherein the steps further comprise modifying, by the security engine, the data access log to identify the request to audit the modified data access log by the auditing entity.

17 . The non-transitory computer readable storage medium of claim 2 , wherein the metadata of the retrieved data comprises at least one of: a category of data, a type of data, a format of data, a sensitivity of data, and a required authorization level.

18 . The non-transitory computer readable storage medium of claim 13 , wherein the modified data access log identifies at least one of:

a user account associated with the requesting entity;

a hardware identifier for a device used by the requesting entity to access the modified data;

a software identifier for software used by the requesting entity to access the modified data; and

information indicating whether the attempt to access the modified data was successful.

19 . The non-transitory computer readable storage medium of claim 13 , wherein the modified data access log further one or more of: a web page used to access the modified data, a form used to access the modified data, and one or more fields displayed by a device of the requesting entity associated with the modified data.

20 . The non-transitory computer readable storage medium of claim 13 , wherein the steps further comprise:

in response to the requesting entity being unauthorized to access the data, modifying, by the security engine, the data access log to identify the request from the requesting entity to access the data in the database and to indicate that the requesting entity is not authorized to access the data.

Assignments (3)
CHANGE OF NAME Recorded Nov 25, 2025
From: ZENPAYROLL, INC.
To: GUSTO, INC.
Reel/Frame 073705/0640 →
SECURITY INTEREST Recorded Nov 3, 2025
From: GUSTO, INC.; SYMMETRY SOFTWARE, LLC
To: BLUE OWL CREDIT INCOME CORP., AS ADMINISTRATIVE AGENT
Reel/Frame 073529/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2023
From: HOA, KARLOTCHA
To: ZENPAYROLL, INC.
Reel/Frame 064715/0416 →
Continuity (3)
Continuation 17521817 · Nov 8, 2021
Continuation 16355491 · Mar 15, 2019
Related Publication 20230394175A1 · Dec 7, 2023
References Cited (66)
US 7069451B1 · Ginter et al. · 2006 [cited by applicant]
US 8621649B1 · Van Dijk et al. · 2013 [cited by applicant]
US 8843997B1 · Hare · 2014 [cited by applicant]
US 8930382B2 · Branish, II · 2015 [cited by examiner]
US 9250795B2 · Fadell et al. · 2016 [cited by applicant]
US 9600688B2 · Buck · 2017 [cited by applicant]
US 9965648B1 · Cheng et al. · 2018 [cited by applicant]
US 10049227B1 · Sampson · 2018 [cited by examiner]
US 10055611B2 · Patel et al. · 2018 [cited by applicant]
US 10382620B1 · Allen · 2019 [cited by examiner]
US 10521605B1 · Scuderi et al. · 2019 [cited by applicant]
US 10803197B1 · Liao et al. · 2020 [cited by applicant]
US 10943026B2 · Scuderi et al. · 2021 [cited by applicant]
US 11200338B2 · Hoa · 2021 [cited by applicant]
US 20020069363A1 · Winburn · 2002 [cited by applicant]
US 20050140572A1 · Kahan et al. · 2005 [cited by applicant]
US 20060075228A1 · Black et al. · 2006 [cited by applicant]
US 20080163379A1 · Robinson et al. · 2008 [cited by applicant]
US 20080300952A1 · Couper · 2008 [cited by applicant]
US 20090254572A1 · Redlich et al. · 2009 [cited by applicant]
US 20090287837A1 · Felsher · 2009 [cited by applicant]
US 20090313049A1 · Joao et al. · 2009 [cited by applicant]
US 20110055922A1 · Cohen et al. · 2011 [cited by applicant]
US 20110239293A1 · Perumal · 2011 [cited by examiner]
US 20130036370A1 · Ananthakrishnan · 2013 [cited by applicant]
US 20130042008A1 · Das et al. · 2013 [cited by applicant]
US 20140013437A1 · Anderson et al. · 2014 [cited by applicant]
US 20140040154A1 · Webb · 2014 [cited by applicant]
US 20140122436A1 · Brunswig et al. · 2014 [cited by applicant]
US 20140123303A1 · Shukla et al. · 2014 [cited by applicant]
US 20140283068A1 · Call et al. · 2014 [cited by applicant]
US 20140344900A1 · Das et al. · 2014 [cited by applicant]
US 20140365372A1 · Ross et al. · 2014 [cited by applicant]
US 20150067886A1 · Maman · 2015 [cited by applicant]
US 20150161397A1 · Cook et al. · 2015 [cited by applicant]
US 20150200922A1 · Eschbach et al. · 2015 [cited by applicant]
US 20150371611A1 · Raley et al. · 2015 [cited by applicant]
US 20150379303A1 · LaFever et al. · 2015 [cited by applicant]
US 20160132696A1 · Vidhani · 2016 [cited by examiner]
US 20160320943A1 · Kim et al. · 2016 [cited by applicant]
US 20180020001A1 · White et al. · 2018 [cited by applicant]
US 20180293403A1 · Cheng et al. · 2018 [cited by applicant]
US 20180314853A1 · Oliner · 2018 [cited by examiner]
US 20180352005A1 · Gaddam · 2018 [cited by examiner]
US 20180359282A1 · Roth et al. · 2018 [cited by applicant]
US 20190050600A1 · Sahoo · 2019 [cited by examiner]
US 20190073483A1 · McClintock et al. · 2019 [cited by applicant]
US 20190138625A1 · Umansky et al. · 2019 [cited by applicant]
US 20190182038A1 · Shanks et al. · 2019 [cited by applicant]
US 20190342088A1 · Eidson et al. · 2019 [cited by applicant]
US 20200074104A1 · Sommerville et al. · 2020 [cited by applicant]
US 20200074108A1 · Fox · 2020 [cited by examiner]
US 20200104539A1 · Liu · 2020 [cited by examiner]
US 20200175209A1 · Yost · 2020 [cited by applicant]
US 20200327252A1 · McFall et al. · 2020 [cited by applicant]
CA 2966285A1 · 2017 [cited by applicant]
CA 3067821A1 · 2019 [cited by applicant]
JP 2013152497A · 2013 [cited by applicant]
Innovation, Science and Economic Development Canada, Canadian Intellectual Property Office, Office Action, Canadian Patent Application 3,043,983, Jan. 8, 2021, seven pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/159,161, filed Apr. 22, 2022, 13 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/355,491, filed Jun. 30, 2021, 46 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/355,502, filed Jun. 7, 2019, 26 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/521,817, filed Jan. 25, 2023, 41 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/521,817, filed Oct. 31, 2022, 62 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/521,817, filed Sep. 29, 2022, 54 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/159,161, filed Jun. 13, 2022, 19 pages. [cited by applicant]