IP Library › Granted Patent US 12,493,712
Granted Patent B2
US 12,493,712 · App. 17/566,039 · Granted Dec 9, 2025

Data owner controls in DLP

Inventor: Pooja Deshmukh (Sunnyvale, CA)
Assignee: Zscaler, Inc.
G06F21/6245G06F16/2272H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,712
App. No.
17/566,039
Granted
Dec 9, 2025
Kind
B2
Abstract

Systems and methods include receiving an index of data for exact data matching, wherein the index includes Personally Identifiable Information (PII); receiving policy related to actions to perform for any violations associated with the exact data matching; loading the index and the policy into memory; monitoring traffic for violations, wherein the violations include detection of any values in the index in the traffic; and performing an action responsive to any violations and associated policy. The action can be one of reporting the violation, blocking the traffic associated with the violation, reporting the violation and allowing the traffic associated with the violation when the violation is based on authenticated PII, allowing the traffic associated with the violation when the violation is based on authenticated PII, and a combination thereof.

Claims (62)

1 . A method comprising:

receiving an index of data for exact data matching, wherein the index includes Personally Identifiable Information (PII);

receiving policy related to actions to perform for any violations associated with the exact data matching;

loading the index and the policy into memory;

monitoring traffic for violations, wherein the violations include detection of any values in the index in the traffic, wherein the monitoring is continuous inline monitoring of the index in real-time; and

performing an action responsive to any violations and associated policy,

wherein the index is based on a one-way hash to transform the data into a digest, such that the data is unreadable by a cloud-based system, wherein the data is one or more look up tables is provided by a virtual appliance, and wherein the virtual appliance is auto-updated via a cloud feed node.

2 . The method of claim 1 , wherein the action is one of reporting the violation, blocking the traffic associated with the violation, and a combination thereof.

3 . The method of claim 1 , wherein the action is a combination of two or more of:

reporting the violation,

blocking the traffic associated with the violation,

reporting the violation and allowing the traffic associated with the violation when the violation is based on authenticated PII, and

allowing the traffic associated with the violation when the violation is based on authenticated PII.

4 . The method of claim 1 , further comprising

detecting a violation is authenticated PII of a user performing transmission of the traffic, and allowing the authenticated PII.

5 . The method of claim 1 , further comprising

detecting a violation is authenticated PII where the traffic is associated with a data owner of the authenticated PII, and allowing the authenticated PII; and

detecting a second violation is unauthenticated PII, and blocking the second violation.

6 . The method of claim 1 , wherein the index further includes a user identifier, and the policy is tenant-specific and defines access privileges for users, and further includes allowability of some or all of the PII that is authenticated PII, wherein the authenticated PII includes PII for a given user based on the user identifier.

7 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

receiving an index of data for exact data matching, wherein the index includes Personally Identifiable Information (PII);

receiving policy related to actions to perform for any violations associated with the exact data matching;

loading the index and the policy into memory;

monitoring traffic for violations, wherein the violations include detection of any values in the index in the traffic, wherein the monitoring is continuous inline monitoring of the index in real-time; and

performing an action responsive to any violations and associated policy,

wherein the index is based on a one-way hash to transform the data into a digest, such that the data is unreadable by a cloud-based system, wherein the data is one or more look up tables is provided by a virtual appliance, and wherein the virtual appliance is auto-updated via a cloud feed node.

8 . The non-transitory computer-readable medium of claim 7 , wherein the action is one of reporting the violation, blocking the traffic associated with the violation, and a combination thereof.

9 . The non-transitory computer-readable medium of claim 7 , wherein the action is one of

reporting the violation,

blocking the traffic associated with the violation,

reporting the violation and allowing the traffic associated with the violation when the violation is based on authenticated PII,

allowing the traffic associated with the violation when the violation is based on authenticated PII, and

a combination thereof.

10 . The non-transitory computer-readable medium of claim 7 , wherein the steps further include

detecting a violation is authenticated PII of a user performing transmission of the traffic, and allowing the authenticated PII.

11 . The non-transitory computer-readable medium of claim 7 , wherein the steps further include

detecting a violation is authenticated PII where the traffic is associated with a data owner of the authenticated PII, and allowing the authenticated PII; and

detecting a second violation is unauthenticated PII, and blocking the second violation.

12 . The non-transitory computer-readable medium of claim 7 , wherein the index further includes a user identifier, and the policy further includes allowability of some or all of the PII that is authenticated PII, wherein the authenticated PII includes PII for a given user based on the user identifier.

13 . A node in a cloud-based system comprising

a network interface;

a processor communicatively coupled to the network interface; and

memory storing instructions that, when executed, cause the processor to:

receive an index of data for exact data matching, wherein the index includes Personally Identifiable Information (PII),

receive policy related to actions to perform for any violations associated with the exact data matching,

load the index and the policy into memory,

monitor traffic for violations, wherein the violations include detection of any values in the index in the traffic, wherein the monitoring is continuous inline monitoring of the index in real-time; and

perform an action responsive to any violations and associated policy,

wherein the index is based on a one-way hash to transform the data into a digest, such that the data is unreadable by the cloud-based system, wherein the data is one or more look up tables is provided by a virtual appliance, and wherein the virtual appliance is auto-updated via a cloud feed node.

14 . The node of claim 13 , wherein the action is one of reporting the violation, blocking the traffic associated with the violation, and a combination thereof.

15 . The node of claim 13 , wherein the action is one of

reporting the violation,

blocking the traffic associated with the violation,

reporting the violation and allowing the traffic associated with the violation when the violation is based on authenticated PII,

allowing the traffic associated with the violation when the violation is based on authenticated PII, and

a combination thereof.

16 . The node of claim 13 , wherein the instructions that, when executed, further cause the processor to

detect a violation is authenticated PII where the traffic is associated with a data owner of the authenticated PII, and allowing the authenticated PII.

17 . The node of claim 13 , wherein the instructions that, when executed, further cause the processor to

detect a violation is authenticated PII where the traffic is associated with a data owner of the authenticated PII, and allowing the authenticated PII, and

detect a second violation is unauthenticated PII, and blocking the second violation.

18 . The node of claim 13 , wherein the index further includes a user identifier, and the policy further includes allowability of some or all of the PII that is authenticated PII, wherein the authenticated PII includes PII for a given user based on the user identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2021
From: DESHMUKH, POOJA
To: ZSCALER, INC.
Reel/Frame 058509/0126 →
Continuity (2)
Continuation In Part 17132499 · Dec 23, 2020
Related Publication 20220198055A1 · Jun 23, 2022
References Cited (14)
US 7996373B1 · Zoppas · 2011 [cited by examiner]
US 9401926B1 · Dubow · 2016 [cited by examiner]
US 9654510B1 · Pillai · 2017 [cited by examiner]
US 10412102B1 · Fridman · 2019 [cited by examiner]
US 20170346804A1 · Beecham · 2017 [cited by examiner]
US 20180181769A1 · Vora · 2018 [cited by examiner]
US 20180189517A1 · Larson · 2018 [cited by examiner]
US 20200260287A1 · Hendel · 2020 [cited by examiner]
US 20200311304A1 · Parthasarathy · 2020 [cited by examiner]
US 20210326460A1 · Zhang et al. · 2021 [cited by applicant]
US 20210336934A1 · Deshmukh et al. · 2021 [cited by applicant]
US 20230224377A1 · Bathla · 2023 [cited by examiner]
Schiff et al, PRI: Privacy Preserving Inspection of Encrypted Network Traffic, May 26, 2016, IEEE, pp. 296-303. (Year: 2016). [cited by examiner]
Corin et al. Dynamic and Application-Aware Provisioning of Chained Virtual Security Network Functions, Sep. 12, 2019, IEEE, pp. 294-307. (Year: 2019). [cited by examiner]
Cited By (1)
US 12,706,934