IP Library Granted Patent US 11,862,170
Granted Patent B2
US 11,862,170 · App. 17/951,657 · Granted Jan 2, 2024

Sensitive data control

Inventors: Vinaya Nadig (Bothell, WA); Shipra Agarwal Kanoria (Mountain View, CA); Elad Refael Kassis (Sunnyvale, CA); Ambika Babuji (Freemont, CA); Neelesh Deo Dani (Vancouver, CA); Rohan Mutagi (Redmond, WA)
Assignee: Amazon Technologies, Inc.
G10L15/26G06F9/542G06F21/6245G10L13/00G10L15/1815G10L17/22H04L67/306H04W4/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,862,170
App. No.
17/951,657
Granted
Jan 2, 2024
Kind
B2
Abstract

A system is provided for determining privacy controls for output including sensitive data. A user may subscribe to receive an output in the future based on the occurrence of an event. The system may determine when the event is occurred triggering the output, and determine that the output includes outputting sensitive data. The system may determine output data that does not include the sensitive data, send the output data to a device, and may request the user to provide an authentication input to receive the sensitive data.

Claims (74)

1. A computer-implemented method comprising:

receiving message data corresponding to a message to be output by a first recipient device associated with a user profile, the message data comprising first output data corresponding to message content and an indication of a first sender of the message;

determining that the first sender corresponds to stored data associated with the user profile;

based at least in part on the stored data, determining second output data corresponding to the message, wherein the second output data excludes a portion of the first output data, and wherein the second output data requests an input for user authentication processing;

causing the second output data to be presented using the first recipient device;

after causing the second output data to be presented, receiving authentication data from the first recipient device, the authentication data being based on an authentication action performed via the first recipient device;

determining that the authentication data satisfies a first privacy control; and

based at least in part on the authentication data satisfying the first privacy control, causing the portion of the first output data to be presented using the first recipient device.

2. The computer-implemented method of claim 1 , further comprising:

prior to receiving the message data:

receiving first input data corresponding to a first user input associated with the user profile,

determining, from the first input data, that the first user input requests a first notification be output when a first event occurs,

generating first trigger data representing the first notification is to be output when the first event occurs, and

storing the first trigger data as the stored data; and

after storing the first trigger data:

receiving event data corresponding to the message,

determining the event data corresponds to the first event represented by the first trigger data, and

determining, using the first trigger data, that the first notification is to be output by the first recipient device.

3. The computer-implemented method of claim 1 , further comprising:

processing, using semantic analysis, the first output data to determine that the portion includes a representation of sensitive data.

4. The computer-implemented method of claim 1 , further comprising:

determining stored user recognition data associated with the user profile; and

determining, using the stored user recognition data, that the authentication data satisfies the first privacy control.

5. The computer-implemented method of claim 1 , further comprising:

processing the first output data to determine that the portion includes information of a first data type corresponding to sensitive data.

6. The computer-implemented method of claim 5 , wherein the first data type corresponds to medical information.

7. The computer-implemented method of claim 5 , wherein the first data type corresponds to personal identification information.

8. The computer-implemented method of claim 1 , further comprising:

determining that the portion of the first output data corresponds to a first representation of sensitive data; and

using natural language generation, determining the second output data to include at least a second representation of the sensitive data in a non-sensitive manner.

9. The computer-implemented method of claim 1 , further comprising:

determining a second recipient device associated with the user profile;

determining, using the user profile, that the second recipient device is designated as a personal device; and

based at least in part on the second recipient device being designated as the personal device, causing the first output data to be presented using the second recipient device without previously presenting the second output data using the second recipient device.

10. The computer-implemented method of claim 9 , wherein causing presentation of the first output data using the second recipient device occurs after receiving the authentication data from the first recipient device.

11. A system comprising:

at least one processor; and

at least one memory comprising instructions that, when executed by the at least one processor, cause the system to:

receive notification data corresponding to an input notification to be output by a first recipient device associated with a user profile, the notification data comprising first output data corresponding to notification content;

determine that the notification content corresponds to a first data type corresponding to sensitive data;

based at least in part on the notification content corresponding to the first data type, determine second output data corresponding to the input notification, wherein the second output data excludes a portion of the first output data, and wherein the second output data requests an input for user authentication processing;

cause the second output data to be presented using the first recipient device;

after causing the second output data to be presented, receive authentication data from the first recipient device, the authentication data being based on an authentication action performed via the first recipient device;

determine that the authentication data satisfies a first privacy control; and

based at least in part on the authentication data satisfying the first privacy control, cause the portion of the first output data to be presented using the first recipient device.

12. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

prior to receipt of the notification data:

receive first input data corresponding to a first user input associated with the user profile,

determine, from the first input data, that the first user input requests a first notification be output when a first event occurs,

generate first trigger data representing the first notification is to be output when the first event occurs, and

store the first trigger data; and

after storage of the first trigger data:

receive event data corresponding to the input notification,

determine the event data corresponds to the first event represented by the first trigger data, and

determining, using the first trigger data, that the input notification is to be output by the first recipient device.

13. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

process, using semantic analysis, the first output data to determine that the portion includes a representation of sensitive data.

14. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

determine stored user recognition data associated with the user profile; and

determine, using the stored user recognition data, that the authentication data satisfies the first privacy control.

15. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

process the notification data to determine an indication of a first source of the notification data; and

determine that the first source corresponds to stored data associated with the user profile,

wherein determination of the second output data is based at least in part on the stored data.

16. The system of claim 11 , wherein the first data type corresponds to medical information.

17. The system of claim 11 , wherein the first data type corresponds to personal identification information.

18. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

determine that the portion of the first output data corresponds to a first representation of sensitive data; and

determine, using natural language generation, the second output data to include at least a second representation of the sensitive data in a non-sensitive manner.

19. The system of claim 11 , wherein the at least one memory further comprises instructions that, when executed by the at least one processor, further cause the system to:

determine a second recipient device associated with the user profile;

determine, using the user profile, that the second recipient device is designated as a personal device; and

based at least in part on the second recipient device being designated as the personal device, cause the first output data to be presented using the second recipient device without previously presenting the second output data using the second recipient device.

20. The system of claim 19 , wherein causing presentation of the first output data using the second recipient device occurs after receiving the authentication data from the first recipient device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2022
From: NADIG, VINAYA; KANORIA, SHIPRA AGARWAL; KASSIS, ELAD REFAEL; BABUJI, AMBIKA; DANI, NEELESH DEO; MUTAGI, ROHAN
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 061196/0147 →
Continuity (2)
Continuation 16834696 · Mar 30, 2020
Related Publication 20230120966A1 · Apr 20, 2023