IP Library Granted Patent US 12,314,438
Granted Patent B2
US 12,314,438 · App. 18/583,893 · Granted May 27, 2025

Tagging and auditing sensitive information in a database environment

Inventors: Christopher Joseph Scuderi (Daly City, CA); Edward Kim (San Francisco, CA)
Assignee: ZenPayroll, Inc.
G06F21/6245G06F3/04817G06F3/0482G06F16/24573G06F16/248G06F21/84G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,314,438
App. No.
18/583,893
Granted
May 27, 2025
Kind
B2
Abstract

Access to sensitive information in a database can be restricted to improve security and enable efficient auditing. A security engine receives a request from a requesting entity to access data in the database and determines that the requested data includes sensitive information. In response to the requesting entity being authorized to access the data, the security engine retrieves the requested data from the database and modifies the retrieved data by modifying metadata of the retrieved data to include a tag indicating that the retrieved data includes sensitive information. The security engine provides the modified data to the requesting entity and modifies a data access log to identify each attempted access to the modified data. When sensitive data is requested, an interface can include an obscuring element, requiring a user to manually select the element to view the data, enabling the logging of the explicit access request by the user.

Claims (40)

1. A method of restricting a display of data comprising:

displaying, by a security engine, an interface on a client device of a requesting entity for displaying sensitive information in a set of fields of the interface, the interface including a corresponding interface element that obscures each field, wherein the client device accesses information for display within the interface from a database that includes sensitive flags indicating columns of sensitive information;

after displaying the interface on the client device, receiving, by the security engine, a request from the requesting entity to view the sensitive information within a first field obscured by a corresponding interface element; and

in response to determining that the requesting entity is authorized to view the requested sensitive information, 1) accessing, by the security engine, the requested sensitive information from the database and removing the corresponding interface element such that the accessed sensitive information is displayed within the first field without the field being obscured, and 2) accessing, by the security engine, additional sensitive information that the requesting entity is authorized to view and removing corresponding interface elements such that the accessed additional sensitive information is displayed within additional fields of the set of fields without the additional fields being obscured.

2. The method of claim 1 , further comprising:

accessing, by the security engine, non-sensitive information from the database; and

displaying in the interface, by the security engine, the non-sensitive information within a corresponding non-sensitive data field of the interface.

3. The method of claim 1 , further comprising modifying, by the security engine, a data access log to identify the request to view the sensitive information, the modified data access log identifying the requesting entity, the sensitive information, and a time associated with the request to view the sensitive information.

4. The method of claim 3 , further comprising in response to determining that the requesting entity is not authorized to view the sensitive information, initiating by the security engine, an audit of the modified data access log.

5. The method of claim 3 , wherein the modified data access log further includes information representative of at least one of:

a user account associated with the requesting entity,

a hardware device used by the requesting entity to access the sensitive information in the database,

a software application used by the requesting entity to access the sensitive information in the database, and

an indication of whether a request to view the sensitive information was granted.

6. The method of claim 3 , wherein the modified data access log includes information identifying the interface.

7. The method of claim 3 , wherein the modified data access log further includes information identifying sensitive data fields located within the interface.

8. The method of claim 1 , further comprising:

in response to determining that the requesting entity is not authorized to view the sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the sensitive information.

9. The method of claim 8 , wherein the sensitive information is not accessed from the database in response to determining that the requesting entity is not authorized to view the sensitive information.

10. The method of claim 1 , wherein the interface element comprises an opaque or semi-opaque box obscuring the field corresponding to the sensitive information.

11. A non-transitory computer readable storage medium storing executable instructions that, when executed by one or more processors, cause the one or more processors to perform steps comprising:

displaying, by a security engine, an interface on a client device of a requesting entity for displaying sensitive information in a set of fields of the interface, the interface including a corresponding interface element that obscures each field, wherein the client device accesses information for display within the interface from a database that includes sensitive flags indicating columns of sensitive information;

after displaying the interface on the client device, receiving, by the security engine, a request from the requesting entity to view the sensitive information within a first field obscured by a corresponding interface element; and

in response to determining that the requesting entity is authorized to view the requested sensitive information, 1) accessing, by the security engine, the requested sensitive information from the database and removing the corresponding interface element such that the accessed sensitive information is displayed within the first field without the field being obscured, and 2) accessing, by the security engine, additional sensitive information that the requesting entity is authorized to view and removing corresponding interface elements such that the accessed additional sensitive information is displayed within additional fields of the set of fields without the additional fields being obscured.

12. The non-transitory computer readable storage medium of claim 11 , wherein the instructions, when executed, cause the one or more processors to perform additional steps comprising:

accessing, by the security engine, non-sensitive information from the database; and

displaying in the interface, by the security engine, the non-sensitive information within a corresponding non-sensitive data field of the interface.

13. The non-transitory computer readable storage medium of claim 11 , wherein the instructions, when executed, cause the one or more processors to perform additional steps comprising modifying, by the security engine, a data access log to identify the request to view the sensitive information, the modified data access log identifying the requesting entity, the sensitive information, and a time associated with the request to view the sensitive information.

14. The non-transitory computer readable storage medium of claim 13 , wherein the instructions, when executed, cause the one or more processors to perform additional steps comprising in response to determining that the requesting entity is not authorized to view the sensitive information, initiating by the security engine, an audit of the modified data access log.

15. The non-transitory computer readable storage medium of claim 13 , wherein the modified data access log further includes information representative of at least one of:

a user account associated with the requesting entity,

a hardware device used by the requesting entity to access the sensitive information in the database,

a software application used by the requesting entity to access the sensitive information in the database, and

an indication of whether a request to view the sensitive information was granted.

16. The non-transitory computer readable storage medium of claim 13 , wherein the modified data access log includes information identifying the interface.

17. The non-transitory computer readable storage medium of claim 13 , wherein the modified data access log further includes information identifying sensitive data fields located within the interface.

18. The non-transitory computer readable storage medium of claim 11 , wherein the instructions, when executed, cause the one or more processors to perform additional steps comprising:

in response to determining that the requesting entity is not authorized to view the sensitive information, displaying a message in the interface indicating that the requesting entity is not authorized to view the sensitive information.

19. The non-transitory computer readable storage medium of claim 18 , wherein the sensitive information is not accessed from the database in response to determining that the requesting entity is not authorized to view the sensitive information.

20. The non-transitory computer readable storage medium of claim 11 , wherein the interface element comprises an opaque or semi-opaque box obscuring the field corresponding to the sensitive information.

Assignments (3)
CHANGE OF NAME Recorded Nov 25, 2025
From: ZENPAYROLL, INC.
To: GUSTO, INC.
Reel/Frame 073705/0640 →
SECURITY INTEREST Recorded Nov 3, 2025
From: GUSTO, INC.; SYMMETRY SOFTWARE, LLC
To: BLUE OWL CREDIT INCOME CORP., AS ADMINISTRATIVE AGENT
Reel/Frame 073529/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2024
From: SCUDERI, CHRISTOPHER JOSEPH; KIM, EDWARD
To: ZENPAYROLL, INC.
Reel/Frame 066676/0566 →
Continuity (5)
Continuation 17891138 · Aug 19, 2022
Continuation 17159161 · Jan 27, 2021
Continuation 16676438 · Nov 7, 2019
Continuation 16355502 · Mar 15, 2019
Related Publication 20240193301A1 · Jun 13, 2024
References Cited (67)
US 7069451B1 · Ginter et al. · 2006 [cited by applicant]
US 7240360B1 · Phan · 2007 [cited by examiner]
US 8621649B1 · Van Dijk et al. · 2013 [cited by applicant]
US 8843997B1 · Hare · 2014 [cited by applicant]
US 8930382B2 · Branish et al. · 2015 [cited by applicant]
US 9088551B2 · Bauchot · 2015 [cited by examiner]
US 9250795B2 · Fadell et al. · 2016 [cited by applicant]
US 9600688B2 · Buck · 2017 [cited by applicant]
US 9965648B1 · Cheng et al. · 2018 [cited by applicant]
US 10055611B2 · Patel et al. · 2018 [cited by applicant]
US 10701079B1 · Ledet · 2020 [cited by examiner]
US 10803197B1 · Liao · 2020 [cited by examiner]
US 11200338B2 · Hoa · 2021 [cited by applicant]
US 20020069363A1 · Winburn · 2002 [cited by applicant]
US 20050140572A1 · Kahan et al. · 2005 [cited by applicant]
US 20060075228A1 · Black · 2006 [cited by examiner]
US 20080163379A1 · Robinson et al. · 2008 [cited by applicant]
US 20080300952A1 · Couper · 2008 [cited by applicant]
US 20090254572A1 · Redlich et al. · 2009 [cited by applicant]
US 20090287837A1 · Felsher · 2009 [cited by applicant]
US 20090313049A1 · Joao et al. · 2009 [cited by applicant]
US 20110055922A1 · Cohen et al. · 2011 [cited by applicant]
US 20130036370A1 · Ananthakrishnan · 2013 [cited by examiner]
US 20130042008A1 · Das et al. · 2013 [cited by applicant]
US 20140013437A1 · Anderson et al. · 2014 [cited by applicant]
US 20140040154A1 · Webb · 2014 [cited by applicant]
US 20140122436A1 · Brunswig et al. · 2014 [cited by applicant]
US 20140123303A1 · Shukla · 2014 [cited by examiner]
US 20140283068A1 · Call et al. · 2014 [cited by applicant]
US 20140344900A1 · Das et al. · 2014 [cited by applicant]
US 20140365372A1 · Ross et al. · 2014 [cited by applicant]
US 20150067886A1 · Maman · 2015 [cited by applicant]
US 20150161397A1 · Cook et al. · 2015 [cited by applicant]
US 20150200922A1 · Eschbach et al. · 2015 [cited by applicant]
US 20150371611A1 · Raley et al. · 2015 [cited by applicant]
US 20150379303A1 · LaFever et al. · 2015 [cited by applicant]
US 20160057168A1 · Reddock · 2016 [cited by examiner]
US 20160320943A1 · Kim et al. · 2016 [cited by applicant]
US 20180020001A1 · White et al. · 2018 [cited by applicant]
US 20180293403A1 · Cheng et al. · 2018 [cited by applicant]
US 20180314853A1 · Oliner et al. · 2018 [cited by applicant]
US 20180352005A1 · Gaddam et al. · 2018 [cited by applicant]
US 20180359282A1 · Roth et al. · 2018 [cited by applicant]
US 20190073483A1 · McClintock et al. · 2019 [cited by applicant]
US 20190138625A1 · Umansky et al. · 2019 [cited by applicant]
US 20190182038A1 · Shanks et al. · 2019 [cited by applicant]
US 20190342088A1 · Eidson et al. · 2019 [cited by applicant]
US 20200074104A1 · Sommerville et al. · 2020 [cited by applicant]
US 20200074108A1 · Fox et al. · 2020 [cited by applicant]
US 20200104539A1 · Liu et al. · 2020 [cited by applicant]
US 20200175209A1 · Yost · 2020 [cited by applicant]
US 20200327252A1 · Mcfall et al. · 2020 [cited by applicant]
CA 2966285A1 · 2017 [cited by applicant]
CA 3067821A1 · 2019 [cited by applicant]
JP 2013152497A · 2013 [cited by applicant]
United States Office Action, U.S. Appl. No. 18/454,378, Apr. 2, 2024, 58 pages. [cited by applicant]
Innovation, Science and Economic Development Canada, Canadian Intellectual Property Office, Office Action, Canadian Patent Application 3,043,983, Jan. 8, 2021, 7 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/355,491, Jun. 30, 2021, 46 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/355,502, Jun. 7, 2019, 26 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/159,161, Apr. 22, 2022, 13 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/159,161, Jun. 13, 2022, 19 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/521,817, Jan. 25, 2023, 41 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/521,817, Oct. 31, 2022, 62 pages. [cited by applicant]
United States Patent Office, Office Action, U.S. Appl. No. 18/454,378, filed Jun. 18, 2024, 63 pages. [cited by applicant]
United States Patent Office, Office Action, U.S. Appl. No. 18/454,378, filed Aug. 27, 2024, 56 pages. [cited by applicant]
United States Patent Office, Office Action, U.S. Appl. No. 18/454,378, filed Dec. 31, 2024, 45 pages. . [cited by applicant]
United States Office Action, U.S. Appl. No. 18/454,378, filed Feb. 13, 2025, 45 pages. [cited by applicant]