System and method for securing personal data elements
Abstract
A system and method may obtain a connection profile, the connection profile including at least one rule related to at least one PII data element; associate the connection profile with a network connection; receive a data unit transmitted over the network connection, the data unit including at least a portion of the PII data element; and, based on the rule, perform at least one of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit. A system and method may associate the connection profile with a set of connection. A system and method may automatically modify a set of connection profiles based on an event.
Claims
exact text as granted — not AI-modified1 . A method of managing sharing of personally identifiable information (PII) data units, the method comprising:
associating a policy with a network connection, the network connection enabling sharing of PII data units between a protected system and an external system; intercepting transmission of a PII data unit transmitted over the network connection; and based on data in the policy, performing at least one action selected from the group consisting of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit.
2 . The method of claim 1 comprising:
obtaining a data unit including a set of PII data elements; and
based on the policy, selecting to perform the at least one action for at least one PII data element included in the data unit.
3 . The method of claim 1 , comprising:
selecting to share a data element included in the data unit with a first external system; and selecting to prevent sharing of the data element with a second external system.
4 . The method of claim 1 , comprising:
obtaining a data unit including first and second PII data elements; selecting to share the first data element with an external system; and selecting to prevent sharing of the second data element with the external system.
5 . The method of claim 1 , wherein a PII data element included in the data unit includes at least one of: person-specific data, asset-specific data, personal data, contact info, customer demographics, financial info, purchase info, an opinion, a field of interest, a driving license, a social security number and an image.
6 . The method of claim 1 , comprising associating the policy with a set of connections.
7 . The method of claim 1 , comprising automatically modifying the policy based on an event.
8 . The method of claim 1 , comprising graphically presenting a map of flows of data elements.
9 . The method of claim 1 , comprising associating a data element with a token and performing an action based on a token identified in the data unit.
10 . The method of claim 1 , comprising modifying a data element in the data unit based on the policy.
11 . The method of claim 1 , wherein a data element in the data unit includes un-structured data.
12 . The method of claim 1 , comprising:
obtaining a user profile, the user profile including at least one rule related to at least one data element; associating the user profile with a set of network connections; and performing the at least one action based on a rule included in the user profile.
13 . The method of claim 1 , wherein rules included in the policy are related to at least one of:
a request related to the PII data element, a response related to the PII data element, a source of a request related to the PII data element, a method or system used for accessing the PII data element, a time when the PII data element was accessed, a frequency of accessing the PII data element, a user accessing the PII data element, an application accessing the PII data element, a storage system or location of the PII data element, a flow that includes accessing the PII data element, and a pattern related to accessing the PII data element.
14 . The method of claim 1 , the method comprising:
storing metadata related to a transaction, from a protected system to an external system, of at least a portion a PII data element included in the protected system; and presenting to a user a flow of PII data between the protected system and the external system based on the metadata.
15 . The method of claim 1 , the method comprising:
presenting to a user data include in a PII data unit obtained by the external system; receiving from a user indication of restricted PII data; and preventing the restricted PII data from being transferred to the external system.
16 . The method of claim 1 , comprising:
storing metadata related to a transaction, from the external system to a second external system, of at least a portion the PII data element; and presenting to a user a flow of PII data across a plurality of external systems based on the metadata.
17 . A system for managing sharing of personally identifiable information (PII) data units, the method comprising:
a memory; and a controller configured to: associate a connection profile with a network connection, the network connection enabling sharing of PII data units between a protected system and an external system; intercept transmission of a PII data unit transmitted over the network connection; and based on data in the connection profile, perform at least one action selected from the group consisting of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit.
18 . The system of claim 17 , wherein the controller is further configured to:
obtain a data unit including a set of PII data elements; and based on the connection profile, select to perform the at least one action for at least one PII data element included in the data unit.
19 . The system of claim 17 , wherein the controller is further configured to:
select to share a data element included in the data unit with a first external system; and select to prevent sharing of the data element with a second external system.
20 . The system of claim 17 , wherein the controller is further configured to:
obtain a data unit including first and second PII data elements; select to share the first data element with an external system; and select to prevent sharing of the second data element with the external system.Join the waitlist — get patent alerts
Track US2018121676A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.