IP Library Granted Patent US 11,295,034
Granted Patent B2
US 11,295,034 · App. 17/157,411 · Granted Apr 5, 2022

System and methods for privacy management

Inventors: Nimrod Vax (Tel Aviv, IL); Eyal Sacharov (Herzliya, IL); Dimitri Sirota (Mamaroneck, NY)
Assignee: BigID Inc.
G06F21/6245G06F16/2457G06F16/285G06F21/577G06Q30/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,295,034
App. No.
17/157,411
Filed
Jan 25, 2021
Granted
Apr 5, 2022
Kind
B2
Art Unit
2437
USPC
706/26
Abstract

Exemplary privacy management platforms are described herein. Such platforms may be embodied in systems, computer-implemented methods, apparatuses and/or software applications. The described privacy management platform may be configured to scan identity, primary and/or secondary data sources in order to provide users with visibility into stored personal information, risk associated with storing such information and usage activity relating to such information. The platform may correlate personal information to specific data subjects to provide an indexed inventory across multiple data sources.

Claims (70)

1. A computer-implemented method of locating personal information in a plurality of data sources and correlating the personal information to one or more data subjects, the method comprising:

storing, by a computer, an identity graph comprising a plurality of data subject profiles, the identity graph comprising:

a first attribute field comprising first attribute values, each associated with one of the data subject profiles; and

a second attribute field comprising second attribute values, each associated with one of the data subject profiles;

calculating, by the computer, a first identifiability score for the first attribute field and a second identifiability score for the second attribute field,

wherein the first identifiability score meets a minimum identifiability score, and

wherein the second identifiability score does not meets the minimum identifiability score;

searching, by the computer, a scanned data source comprising scanned values;

determining, by the computer, a plurality of personal information findings comprising:

a first set of personal information findings determined by comparing the first attribute values to the scanned values; and

a second set of personal information findings determined by comparing the second attribute values to the scanned values;

correlating, by the computer, each of the first set of personal information findings to the data subjects;

determining, by the computer, whether each of the second set of personal information findings is located within a proximity of one of the first set of personal information findings such that one or more proximity rules is satisfied;

correlating, by the computer, only the personal information findings of the second set of personal information findings that satisfy the one or more proximity rules to the data subjects;

creating, by the computer, personal information records corresponding to the correlated personal information findings and the data subject profiles;

associating, by the computer, the personal information records with the data subject profiles; and

providing, by the computer, the data subject profiles to a user.

2. A computer-implemented method according to claim 1 further comprising:

updating, by the computer, the one or more of the proximity rules, based on the personal information records created from the second set of personal information findings; and

searching, by the computer, based on the updated proximity rules, a second location of the scanned data source.

3. A computer-implemented method according to claim 1 further comprising:

updating, by the computer, the first and second identifiability scores based on the personal information records.

4. A computer-implemented method according to claim 1 further comprising:

determining, by the computer, that at least one of the first set of personal information findings constitutes a false positive finding,

wherein, based on the determination, a personal information record is not created for the false positive finding.

5. A computer-implemented method according to claim 1 , wherein each of the personal information records comprises metadata associated with the respective, corresponding personal information finding, the metadata selected from the group consisting of: an attribute type, an attribute value, a data source, a location within the data source and a data subject.

6. A computer-implemented method according to claim 5 , wherein the attribute type associated with the personal information records is selected from the group consisting of: a name, a social security number, a phone number, an address, an email address, a license number, a passport number, a credit card number, a username, a date of birth, personal health information, educational information and combinations thereof.

7. A computer-implemented method according to claim 1 , wherein the identity graph is crated from an identity data source.

8. A computer-implemented method according to claim 7 , wherein the scanned data source is a primary or secondary data source.

9. A computer-implemented method according to claim 1 , wherein the minimum identifiability score is received from a user.

10. A computer-implemented method according to claim 1 further comprising:

calculating, by the computer, a record risk score for each of the personal information records;

calculating, by the computer, a data subject risk score for each of the data subject profiles, based on the record risk scores; and

associating, by the computer, the data subject risk scores with the data subject profiles.

11. A computer-implemented method according to claim 10 further comprising:

calculating, by the computer, a data source risk score for the scanned data source;

calculating, by the computer, an aggregate risk score, based on the record risk scores, the data subject risk scores and the data source risk scores; and

providing the aggregate risk score to the user.

12. A computer-implemented method according to claim 1 further comprising:

monitoring, by the computer, the scanned data source;

determining, by the computer, that an activity relating to the scanned values has occurred;

determining, by the computer, that the activity violates one or more compliance rules; and

providing a notification to the user relating to the activity.

13. A system comprising one or more computers and one or more storage devices storing instructions that when executed by the one or more computers cause the one or more computers to perform operations comprising:

storing an identity graph comprising a plurality of data subject profiles, the identity graph comprising:

a first attribute field comprising first attribute values, each associated with one of the data subject profiles; and

a second attribute field comprising second attribute values, each associated with one of the data subject profiles;

calculating a first identifiability score for the first attribute field and a second identifiability score for the second attribute field,

wherein the first identifiability score meets a minimum identifiability score, and

wherein the second identifiability score does not meets the minimum identifiability score;

searching a scanned data source comprising scanned values;

determining a plurality of personal information findings comprising:

a first set of personal information findings determined by comparing the first attribute values to the scanned values; and

a second set of personal information findings determined by comparing the second attribute values to the scanned values;

correlating each of the first set of personal information findings to the data subjects;

determining whether each of the second set of personal information findings is located within a proximity of one of the first set of personal information findings such that one or more proximity rules is satisfied;

correlating only the personal information findings of the second set of personal information findings that satisfy the one or more proximity rules to the data subjects;

creating personal information records corresponding to the correlated personal information findings and the data subject profiles;

associating the personal information records with the data subject profiles; and

providing the data subject profiles to a user.

14. A system according to claim 13 , wherein the one or more operations further comprise:

calculating a record risk score for each of the personal information records;

calculating a data subject risk score for each of the data subject profiles, based on the record risk scores; and

associating the data subject risk scores with the data subject profiles.

15. A system according to claim 13 , wherein the one or more operations further comprise:

monitoring the scanned data source;

determining that an activity relating to the scanned values has occurred;

determining that the activity violates one or more compliance rules; and

providing a notification to the user relating to the activity.

16. A system according to claim 15 , wherein the compliance rules are based on one or more of: an attribute type, an attribute location, data subject consent, data subject residency, user access privileges, application type, application location, application privileges, activity type and an activity pattern.

Assignments (1)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 11, 2024
From: BIGID INC.; BIGID GOVERNMENT OPERATIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069163/0599 →
Continuity (6)
Continuation 15626258 · Jun 19, 2017
Provisional Application 62458546 · Feb 13, 2017
Provisional Application 62404264 · Oct 5, 2016
Provisional Application 62385559 · Sep 9, 2016
Provisional Application 62351911 · Jun 17, 2016
Related Publication 20210150056A1 · May 20, 2021