IP Library Granted Patent US 12,278,844
Granted Patent B2
US 12,278,844 · App. 18/461,920 · Granted Apr 15, 2025

Protecting contents and accounts using scan operation

Inventors: Ryan M. Noon (Mountain View, CA); Abhishek Agrawal (San Francisco, CA); Christopher J. Park (San Jose, CA)
Assignee: Material Security Inc.
H04L63/20G06F21/31G06F21/604G06F21/606G06F21/6245H04L63/102H04L63/105G06Q10/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,844
App. No.
18/461,920
Granted
Apr 15, 2025
Kind
B2
Abstract

An example method comprises receiving, by a secure content system, an email from a sender to a recipient, scanning the contents of the email, evaluating the contents of the email based on a plurality of security rules, storing the sensitive data within a secure storage, generating a replacement email including a security link and not including at least the sensitive data, the security link providing a requester access to the sensitive data providing that a security function is satisfied, sending the replacement email including the security link to the recipient, receiving a request to access the sensitive data, the request being related to the security function challenging the requester using the security function, receiving, from the requester, a response to the security function, determining if the security function is satisfied by the response, and if the security function is satisfied, providing access to the sensitive data to the requester.

Claims (46)

1. A non-transitory computer-readable medium comprising memory with instructions encoded thereon, the instructions, when executed by one or more processors, caused to perform operations, the instructions comprising instructions to:

perform, by a secure content system, a scan of a plurality of electronic messages of an electronic repository of a user for sensitive data;

for each electronic message of a subset of the plurality of electronic messages found to have sensitive data as a result of the scan, generate, by the secure content system, a replacement electronic message including a security link and not including at least the sensitive data, wherein the security link, when selected by a requester, leads to a security function being provided to the requester that, if satisfied, unlocks access by the requester to the sensitive data;

replace, in the electronic repository, each electronic message of the subset with its respective replacement electronic message while maintaining original copies of the subset in a secure location separate from the electronic repository of the user;

receive, based on the user interacting with the security link within a given replacement electronic message by way of a client device of the user, a request to access given sensitive data within an original copy of the given replacement electronic message;

determine that the security function is satisfied; and

responsive to determining that the security function is satisfied, send, by the secure content system, the original copy of the given replacement electronic message from the secure location to the electronic repository of the user, thereby enabling the user to access the original copy of the given replacement electronic message by a retrieval operation performed by the client device.

2. The non-transitory computer-readable medium of claim 1 , wherein contents of the original copy of the given replacement electronic message include textual components, and wherein the instructions to perform the scan comprise instructions to perform a text matching operation on the textual components.

3. The non-transitory computer-readable medium of claim 1 , the instructions further comprising instructions to, after sending the original copy of the given replacement electronic message, delete the sensitive data from the secure location.

4. The non-transitory computer-readable medium of claim 1 , wherein the instructions to perform the scan further comprise instructions to:

select one or more security categories based on contents of a given electronic message of the plurality of electronic messages; and

scan the contents of the given electronic message to determine whether one or more of a plurality of security rules associated with the selected one or more security categories are satisfied.

5. The non-transitory computer-readable medium of claim 1 , wherein the sensitive data is searchable by the user regardless of whether a replacement electronic message or a corresponding copy of an original electronic message is within the electronic repository of the user.

6. The non-transitory computer-readable medium of claim 1 , wherein the scan yields a determination of given sensitive data for a given original electronic message based on a sender having marked at least a portion of the given original electronic message sensitive.

7. The non-transitory computer-readable medium of claim 1 , the instructions further comprising instructions to remove, from the electronic repository of the user, the original copy of the given replacement electronic message responsive to determining that a threshold amount of time has elapsed from a time at which the original copy of the given replacement electronic message was sent to the electronic repository of the user.

8. A method comprising:

performing, by a secure content system, a scan of a plurality of electronic messages of an electronic repository of a user for sensitive data;

for each electronic message of a subset of the plurality of electronic messages found to have sensitive data as a result of the scan, generating, by the secure content system, a replacement electronic message including a security link and not including at least the sensitive data, wherein the security link, when selected by a requester, leads to a security function being provided to the requester that, if satisfied, unlocks access by the requester to the sensitive data;

replacing, in the electronic repository, each electronic message of the subset with its respective replacement electronic message while maintaining original copies of the subset in a secure location separate from the electronic repository of the user;

receiving, based on the user interacting with the security link within a given replacement electronic message by way of a client device of the user, a request to access given sensitive data within an original copy of the given replacement electronic message;

determining that the security function is satisfied; and

responsive to determining that the security function is satisfied, sending, by the secure content system, the original copy of the given replacement electronic message from the secure location to the electronic repository of the user, thereby enabling the user to access the original copy of the given replacement electronic message by a retrieval operation performed by the client device.

9. The method of claim 8 , wherein contents of the original copy of the given replacement electronic message include textual components, and wherein performing the scan comprises performing a text matching operation on the textual components.

10. The method of claim 8 , further comprising, after sending the original copy of the given replacement electronic message, deleting the sensitive data from the secure location.

11. The method of claim 8 , wherein performing the scan further comprises:

selecting one or more security categories based on contents of a given electronic message of the plurality of electronic messages; and

scanning the contents of the given electronic message to determine whether one or more of a plurality of security rules associated with the selected one or more security categories are satisfied.

12. The method of claim 8 , wherein the sensitive data is searchable by the user regardless of whether a replacement electronic message or a corresponding copy of an original electronic message is within the electronic repository of the user.

13. The method of claim 8 , wherein the scan yields a determination of given sensitive data for a given original electronic message based on a sender having marked at least a portion of the given original electronic message sensitive.

14. The method of claim 8 , further comprising removing, from the electronic repository of the user, the original copy of the given replacement electronic message responsive to determining that a threshold amount of time has elapsed from a time at which the original copy of the given replacement electronic message was sent to the electronic repository of the user.

15. A secure content system comprising:

memory with instructions encoded thereon; and

one or more processors that, when executing the instructions, cause the secure content system to perform operations comprising:

performing a scan of a plurality of electronic messages of an electronic repository of a user for sensitive data;

for each electronic message of a subset of the plurality of electronic messages found to have sensitive data as a result of the scan, generating a replacement electronic message including a security link and not including at least the sensitive data, wherein the security link, when selected by a requester, leads to a security function being provided to the requester that, if satisfied, unlocks access by the requester to the sensitive data;

replacing, in the electronic repository, each electronic message of the subset with its respective replacement electronic message while maintaining original copies of the subset in a secure location separate from the electronic repository of the user;

receiving, based on the user interacting with the security link within a given replacement electronic message by way of a client device of the user, a request to access given sensitive data within an original copy of the given replacement electronic message;

determining that the security function is satisfied; and

responsive to determining that the security function is satisfied, sending, by the secure content system, the original copy of the given replacement electronic message from the secure location to the electronic repository of the user, thereby enabling the user to access the original copy of the given replacement electronic message by a retrieval operation performed by the client device.

16. The secure content system of claim 15 , wherein contents of the original copy of the given replacement electronic message include textual components, and wherein performing the scan comprises performing a text matching operation on the textual components.

17. The secure content system of claim 15 , the operations further comprising, after sending the original copy of the given replacement electronic message, deleting the sensitive data from the secure location.

18. The secure content system of claim 15 , wherein performing the scan further comprises:

selecting one or more security categories based on contents of a given electronic message of the plurality of electronic messages; and

scanning the contents of the given electronic message to determine whether one or more of a plurality of security rules associated with the selected one or more security categories are satisfied.

19. The secure content system of claim 15 , wherein the sensitive data is searchable by the user regardless of whether a replacement electronic message or a corresponding copy of an original electronic message is within the electronic repository of the user.

20. The secure content system of claim 15 , wherein the scan yields a determination of given sensitive data for a given original electronic message based on a sender having marked at least a portion of the given original electronic message sensitive.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2023
From: NOON, RYAN M.; AGRAWAL, ABHISHEK; PARK, CHRISTOPHER J.
To: STELLARITE INC.
Reel/Frame 064815/0069 →
CHANGE OF NAME Recorded Sep 6, 2023
From: STELLARITE INC.
To: MATERIAL SECURITY INC.
Reel/Frame 064819/0127 →
Continuity (5)
Continuation 17378554 · Jul 16, 2021
Continuation 16034199 · Jul 12, 2018
Provisional Application 62531471 · Jul 12, 2017
Provisional Application 62568742 · Oct 5, 2017
Related Publication 20230412648A1 · Dec 21, 2023
References Cited (20)
US 6785810B1 · Lirov · 2004 [cited by examiner]
US 8935768B1 · Tyree · 2015 [cited by applicant]
US 9268958B1 · Kessler · 2016 [cited by examiner]
US 20050138353A1 · Spies et al. · 2005 [cited by applicant]
US 20060075228A1 · Black · 2006 [cited by examiner]
US 20120240238A1 · Gates · 2012 [cited by examiner]
US 20140366158A1 · Han · 2014 [cited by examiner]
US 20150082391A1 · Lerman · 2015 [cited by examiner]
US 20160210602A1 · Siddique et al. · 2016 [cited by applicant]
US 20160352695A1 · Kozolchyk et al. · 2016 [cited by applicant]
US 20170111325A1 · Maller et al. · 2017 [cited by applicant]
US 20170256008A1 · Hara · 2017 [cited by applicant]
US 20170331777A1 · Brisebois · 2017 [cited by examiner]
Extended European search report, European Patent Office Application No. EP18832232.5, Jun. 10, 2021, 12 pages. [cited by applicant]
International Search Report and Written Opinion, Patent Cooperation treaty Application No. PCT/US2018/041897, Nov. 20, 2018, 10 pages. [cited by applicant]
Partial supplementary European search report, European Patent Office Application No. EP18832232.5, Mar. 9, 2021, 13 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/034,199, filed Dec. 11, 2020, 11 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/034,199, filed Sep. 8, 2020, 10 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/378,554, filed Jan. 11, 2023, 11 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/378,554, filed Sep. 22, 2022, 13 pages. [cited by applicant]