US2018121676A1PendingUtilityA1

System and method for securing personal data elements

Assignee: PRIFENDER LTDPriority: Jan 5, 2016Filed: Dec 25, 2017Published: May 3, 2018
Est. expiryJan 5, 2036(~9.4 yrs left)· nominal 20-yr term from priority
Inventors:Nimrod Luria
G06F 21/604H04W 12/02G06F 21/6263H04L 63/0245H04L 63/0263G06F 21/6245H04L 63/04
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system and method may obtain a connection profile, the connection profile including at least one rule related to at least one PII data element; associate the connection profile with a network connection; receive a data unit transmitted over the network connection, the data unit including at least a portion of the PII data element; and, based on the rule, perform at least one of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit. A system and method may associate the connection profile with a set of connection. A system and method may automatically modify a set of connection profiles based on an event.

Claims

exact text as granted — not AI-modified
1 . A method of managing sharing of personally identifiable information (PII) data units, the method comprising:
 associating a policy with a network connection, the network connection enabling sharing of PII data units between a protected system and an external system;   intercepting transmission of a PII data unit transmitted over the network connection; and   based on data in the policy, performing at least one action selected from the group consisting of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit.   
     
     
         2 . The method of  claim 1  comprising:
 obtaining a data unit including a set of PII data elements; and 
 based on the policy, selecting to perform the at least one action for at least one PII data element included in the data unit. 
 
     
     
         3 . The method of  claim 1 , comprising:
 selecting to share a data element included in the data unit with a first external system; and   selecting to prevent sharing of the data element with a second external system.   
     
     
         4 . The method of  claim 1 , comprising:
 obtaining a data unit including first and second PII data elements;   selecting to share the first data element with an external system; and   selecting to prevent sharing of the second data element with the external system.   
     
     
         5 . The method of  claim 1 , wherein a PII data element included in the data unit includes at least one of: person-specific data, asset-specific data, personal data, contact info, customer demographics, financial info, purchase info, an opinion, a field of interest, a driving license, a social security number and an image. 
     
     
         6 . The method of  claim 1 , comprising associating the policy with a set of connections. 
     
     
         7 . The method of  claim 1 , comprising automatically modifying the policy based on an event. 
     
     
         8 . The method of  claim 1 , comprising graphically presenting a map of flows of data elements. 
     
     
         9 . The method of  claim 1 , comprising associating a data element with a token and performing an action based on a token identified in the data unit. 
     
     
         10 . The method of  claim 1 , comprising modifying a data element in the data unit based on the policy. 
     
     
         11 . The method of  claim 1 , wherein a data element in the data unit includes un-structured data. 
     
     
         12 . The method of  claim 1 , comprising:
 obtaining a user profile, the user profile including at least one rule related to at least one data element;   associating the user profile with a set of network connections; and   performing the at least one action based on a rule included in the user profile.   
     
     
         13 . The method of  claim 1 , wherein rules included in the policy are related to at least one of:
 a request related to the PII data element,   a response related to the PII data element,   a source of a request related to the PII data element,   a method or system used for accessing the PII data element,   a time when the PII data element was accessed,   a frequency of accessing the PII data element,   a user accessing the PII data element,   an application accessing the PII data element,   a storage system or location of the PII data element,   a flow that includes accessing the PII data element, and   a pattern related to accessing the PII data element.   
     
     
         14 . The method of  claim 1 , the method comprising:
 storing metadata related to a transaction, from a protected system to an external system, of at least a portion a PII data element included in the protected system; and   presenting to a user a flow of PII data between the protected system and the external system based on the metadata.   
     
     
         15 . The method of  claim 1 , the method comprising:
 presenting to a user data include in a PII data unit obtained by the external system;   receiving from a user indication of restricted PII data; and   preventing the restricted PII data from being transferred to the external system.   
     
     
         16 . The method of  claim 1 , comprising:
 storing metadata related to a transaction, from the external system to a second external system, of at least a portion the PII data element; and   presenting to a user a flow of PII data across a plurality of external systems based on the metadata.   
     
     
         17 . A system for managing sharing of personally identifiable information (PII) data units, the method comprising:
 a memory; and   a controller configured to:   associate a connection profile with a network connection, the network connection enabling sharing of PII data units between a protected system and an external system;   intercept transmission of a PII data unit transmitted over the network connection; and   based on data in the connection profile, perform at least one action selected from the group consisting of: blocking transmission of the data unit, modifying the data unit, forwarding at least a portion of the data unit to a selected destination, storing the data unit, storing metadata related to the data unit, and reporting an event related to the data unit.   
     
     
         18 . The system of  claim 17 , wherein the controller is further configured to:
 obtain a data unit including a set of PII data elements; and   based on the connection profile, select to perform the at least one action for at least one PII data element included in the data unit.   
     
     
         19 . The system of  claim 17 , wherein the controller is further configured to:
 select to share a data element included in the data unit with a first external system; and   select to prevent sharing of the data element with a second external system.   
     
     
         20 . The system of  claim 17 , wherein the controller is further configured to:
 obtain a data unit including first and second PII data elements;   select to share the first data element with an external system; and   select to prevent sharing of the second data element with the external system.

Join the waitlist — get patent alerts

Track US2018121676A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.