IP Library › Granted Patent US 11,316,848
Granted Patent B2
US 11,316,848 · App. 16/841,982 · Granted Apr 26, 2022

System and method for protecting specified data combinations

Inventors: Ratinder Paul Singh Ahuja (Saratoga, CA); William J. Deninger (San Mateo, CA)
Assignee: McAfee, LLC
H04L63/0853H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,316,848
App. No.
16/841,982
Granted
Apr 26, 2022
Kind
B2
Abstract

A method in one example implementation includes extracting a plurality of data elements from a record of a data file, tokenizing the data elements into tokens, and storing the tokens in a first tuple of a registration list. The method further includes selecting one of the tokens as a token key for the first tuple, where the token is selected because it occurs less frequently in the registration list than each of the other tokens in the first tuple. In specific embodiments, at least one data element is an expression element having a character pattern matching a predefined expression pattern that represents at least two words and a separator between the words. In other embodiments, at least one data element is a word defined by a character pattern of one or more consecutive essential characters. Other specific embodiments include determining an end of the record by recognizing a predefined delimiter.

Claims (50)

1. At least one non-transitory, computer readable medium comprising instructions that, when executed, cause one or more processors to perform a method comprising:

identifying an object including a plurality of data elements;

generating a plurality of object tokens for the plurality of data elements;

searching an index for a token key corresponding to at least one of the plurality of object tokens;

identifying a tuple or record based at least in part on the token key, wherein the tuple or record includes a plurality of object tokens;

determining that a number of the plurality of object tokens in the tuple or record at least satisfies a predetermined threshold to validate an event; and

preventing a transmission of the object, recording the event in a list, providing a notification of information retrieved upon the event, or locking down a database or a storage repository that triggered the event.

2. The at least one computer readable medium of claim 1 , the method further comprising:

tokenizing the plurality of data elements by converting each of the data elements to a respective hash value, wherein the object is a data file, document, or storage repository.

3. The at least one computer readable medium of claim 2 , further comprising:

generating an index table through a modulus operation applied to the token key, in which the boundary is defined by a prime number.

4. The at least one computer readable medium of claim 2 , the method further comprising:

determining, for each object token of the plurality of object tokens, whether a bit is set in a respective bit position of a hash table.

5. The at least one computer readable medium of claim 1 , the method further comprising:

using an offset related to the token key to identify a beginning of the tuple or record.

6. The at least one computer readable medium of claim 1 , the method further comprising:

performing a determination of the token key, wherein the tuple or record is one of a plurality of tuples or records, and the determination determines the token key, based at least in part on the token key occurring with less frequency across the plurality of tuples or records than frequencies at which the other object tokens of the tuple or record occur across the plurality of tuples or records.

7. The at least one computer readable medium of claim 1 , wherein, if another tuple or record is indexed by the token key, an index includes two or more offsets indicating respective locations of the tuple or record and the other tuple or record.

8. An apparatus, comprising:

a memory device including instructions; and

a processor that, when executing the set of instructions,

identifies an object including a plurality of data elements,

generates a plurality of object tokens for the plurality of data elements,

searches an index for a token key corresponding to at least one of the plurality of object tokens,

identifies a tuple or record based at least in part on the token key, wherein the tuple or record includes a plurality of object tokens,

determines that a number of the plurality of object tokens in the tuple or record at least satisfies a predetermined threshold to validate an event; and

prevents a transmission of the object, records the event in a list, provides a notification of information retrieved upon the event, or locks down a database or a storage repository that triggered the event.

9. The apparatus of claim 8 , wherein the processor, when executing the instructions, tokenizes the plurality of data elements by converting each of the data elements to a respective hash value, and the object is a data file, document, or storage repository.

10. The apparatus of claim 9 , wherein the processor, when executing the instructions, generates an index table through a modulus operation applied to the token key, in which the boundary is defined by a prime number.

11. The apparatus of claim 9 , wherein the processor, when executing the instructions, determines, for each object token of the plurality of object tokens, whether a bit is set in a respective bit position of a hash table.

12. The apparatus of claim 8 , wherein the processor, when executing the instructions, uses an offset related to the token key to identify a beginning of the tuple or record.

13. The apparatus of claim 8 , wherein the processor, when executing the instructions, performs a determination of the token key, the tuple or record is one of a plurality of tuples or records, and the determination determines the token key, based at least in part on the token key occurring with less frequency across the plurality of tuples or records than frequencies at which the other object tokens of the tuple or record occur across the plurality of tuples or records.

14. The apparatus of claim 8 , wherein, if another tuple or record is indexed by the token key, an index includes two or more offsets indicating respective locations of the tuple or record and the other tuple or record.

15. A method, comprising:

identifying an object including a plurality of data elements;

generating a plurality of object tokens for the plurality of data elements;

searching an index for a token key corresponding to at least one of the plurality of object tokens;

identifying a tuple or record based, at least in part, on the token key, wherein the tuple or record includes a plurality of object tokens;

determining that a number of the plurality of object tokens in the tuple or record at least satisfies a predetermined threshold to validate an event; and

preventing a transmission of the object, recording the event in a list, providing a notification of information retrieved upon the event, or locking down a database or a storage repository that triggered the event.

16. The method of claim 15 , further comprising:

tokenizing the plurality of data elements by converting each of the data elements to a respective hash value, wherein the object is a data file, document, or storage repository.

17. The method of claim 16 , further comprising:

generating an index table through a modulus operation applied to the token key, in which the boundary is defined by a prime number.

18. The method of claim 16 , further comprising:

determining, for each object token of the plurality of object tokens, whether a bit is set in a respective bit position of a hash table.

19. The method of claim 15 , further comprising:

using an offset related to the token key to identify a beginning of the tuple or record.

20. The method of claim 15 , further comprising:

performing a determination of the token key, wherein the tuple or record is one of a plurality of tuples or records, and the determination determines the token key, based at least in part on the token key occurring with less frequency across the plurality of tuples or records than frequencies at which the other object tokens of the tuple or record occur across the plurality of tuples or records.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (5)
Continuation 16365812 · Mar 27, 2019
Continuation 15700826 · Sep 11, 2017
Continuation 14457038 · Aug 11, 2014
Continuation 12939340 · Nov 4, 2010
Related Publication 20200236106A1 · Jul 23, 2020