IP Library Granted Patent US 9,489,376
Granted Patent B2
US 9,489,376 · App. 13/732,501 · Granted Nov 8, 2016

Identifying confidential data in a data item by comparing the data item to similar data items from alternative sources

Inventors: Michael Scott Thomason (Raleigh, NC); Jai S. Arun (Morrisville, NC); Benjamin L. Myers (Durham, NC); Chad C. Rotermund (Willamsburg, VA); Ajit J. Jariwala (Cary, NC)
Assignee: International Business Machines Corporation
G06F17/2775G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,489,376
App. No.
13/732,501
Granted
Nov 8, 2016
Kind
B2
Abstract

A method, apparatus and computer program product to identify confidential information in a document. To examine a document for inclusion of confidential information, the document is compared against documents having similar structure and content from one or more other sources. When comparing documents (of similar structure and content) from different sources, confidential information is then made to stand out by searching for terms (from the sources) that are not shared between or among them. In contrast, common words or terms that are shared across the sources are ignored as likely being non-confidential information; what remains as not shared may then be classified as confidential information and protected accordingly (e.g., by omission, redaction, substitution or the like). Using this technique, non-confidential information may be safely segmented from confidential information in a dynamic, automated manner.

Claims (36)

1. A method of identifying potential confidential information in a data item, the data item associated with a source, comprising:

obtaining, from each of a set of alternative sources, a data item of a same type and format as the data item;

comparing, using a hardware element, the data item to the data item(s) obtained from the set of alternative sources to identify occurrences of particular pieces of information in the data item, wherein multiple occurrences of a particular piece of information within a data item from each alternative source are treated as a single occurrence; and

based on the occurrences of particular pieces of information in the data item and a given sensitivity criteria, and without knowledge that the particular pieces of information are considered by the source to be confidential, segmenting one or more pieces of information in the data item as representing the potential confidential information.

2. The method as described in claim 1 further including highlighting the one or more pieces of information.

3. The method as described in claim 2 further including taking a given action with respect to the one or more pieces of information that have been highlighted.

4. The method as described in claim 3 wherein the given action is one of: removing the piece of information, redacting the piece of information, and substituting non-confidential data for the piece of information.

5. The method as described in claim 3 further including outputting the data item without the one or more pieces of information.

6. The method as described in claim 1 wherein the data item is one of: a document, a report, a file, a log, a message, an email, and a communication.

7. The method as described in claim 1 wherein the given sensitivity criteria is a configurable threshold.

8. Apparatus, comprising:

a processor;

computer memory holding computer program instructions that when executed by the processor perform a method of identifying potential confidential information in a data item, the data item associated with a source, the method comprising:

obtaining, from each of a set of alternative sources, a data item of a same type and format as the data item;

comparing the data item to the data item(s) obtained from the set of alternative sources to identify occurrences of particular pieces of information in the data item, wherein multiple occurrences of a particular piece of information within a data item from each alternative source are treated as a single occurrence; and

based on the occurrences of particular pieces of information in the data item and a given sensitivity criteria, and without knowledge that the particular pieces of information are considered by the source to be confidential, segmenting one or more pieces of information in the data item as representing the potential confidential information.

9. The apparatus as described in claim 8 wherein the method further includes highlighting the one or more pieces of information.

10. The apparatus as described in claim 9 wherein the method further includes taking a given action with respect to the one or more pieces of information that have been highlighted.

11. The apparatus as described in claim 10 wherein the given action is one of: removing the piece of information, redacting the piece of information, and substituting non-confidential data for the piece of information.

12. The apparatus as described in claim 10 wherein the method further includes outputting the data item without the one or more pieces of information.

13. The apparatus as described in claim 8 wherein the data item is one of: a document, a report, a file, a log, a message, an email, and a communication.

14. The apparatus as described in claim 8 wherein the given sensitivity criteria is a configurable threshold.

15. A computer program product in a non-transitory computer-readable storage medium in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, perform a method of identifying potential confidential information in a data item, the data item associated with a source, the method comprising:

obtaining, from each of a set of alternative sources, a data item of a same type and format as the data item;

comparing the data item to the data item(s) obtained from the set of alternative sources to identify occurrences of particular pieces of information in the data item, wherein multiple occurrences of a particular piece of information within a data item from each alternative source are treated as a single occurrence; and

based on the occurrences of particular pieces of information in the data item and a given sensitivity criteria, and without knowledge that the particular pieces of information are considered by the source to be confidential, segmenting one or more pieces of information in the data item as representing the potential confidential information.

16. The computer program product as described in claim 15 wherein the method further includes highlighting the one or more pieces of information.

17. The computer program product as described in claim 16 wherein the method further includes taking a given action with respect to the one or more pieces of information that have been highlighted.

18. The computer program product as described in claim 17 wherein the given action is one of: removing the piece of information, redacting the piece of information, and substituting non-confidential data for the piece of information.

19. The computer program product as described in claim 17 wherein the method further includes outputting the data item without the one or more pieces of information.

20. The computer program product as described in claim 15 wherein the data item is one of: a document, a report, a file, a log, a message, an email, and a communication.

21. The computer program product as described in claim 15 wherein the given sensitivity criteria is a configurable threshold.

22. Apparatus, comprising:

a display interface;

a processor;

computer memory holding computer program instructions executed by the processor to identify potential confidential information in a data item, the data item associated with a source, by (i) comparing the data item to data items of a similar type and format received from a set of alternative sources to identify occurrences of particular pieces of information in the data item, and (ii) based on the occurrences of particular pieces of information in the data item, and without knowledge that the particular pieces of information are considered by the source to be confidential, identifying one or more pieces of information in the data item as representing the potential confidential information, wherein multiple occurrences of a particular piece of information within a data item from at least one particular alternative source are treated as a single occurrence, and (iii) outputting, on the display interface, a representation of the data item with the one or more pieces of information representing potential confidential information highlighted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2013
From: THOMASON, MICHAEL SCOTT; ARUN, JAI S.; MYERS, BENJAMIN L.; ROTERMUND, CHAD C.; JARIWALA, AJIT J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 029560/0425 →
Continuity (1)
Related Publication 20140188921A1 · Jul 3, 2014