US2022245278A1PendingUtilityA1

Detecting and preventing storage of unsolicited sensitive personal information

Assignee: AT & T IP I LPPriority: Mar 13, 2019Filed: Apr 20, 2022Published: Aug 4, 2022
Est. expiryMar 13, 2039(~12.6 yrs left)· nominal 20-yr term from priority
H04L 67/535G06F 3/0481H04L 63/0421G06F 21/6245G06F 40/174G06F 40/279H04L 67/55G06F 21/6263G06F 3/04895H04L 67/26
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A sensitive personal information detection and prevention system can receive a text string based on a user input into a field of a graphical user interface associated with a server. The system can, prior to storage of the text string by the server device, determine whether the text string comprises sensitive personal information, wherein the determining can comprise referring to a configurable map that can be updated. The system can, in response to determining that the text string comprises the sensitive personal information, prevent the storage of the text string by the server. It can facilitate providing a message for display on the graphical user interface comprising an indication that the text string comprises the sensitive personal information, and an instruction to re-submit the text string without the sensitive personal information, or a notification that the sensitive personal information has been masked.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 receiving, by a first network device comprising a processor, a text string based on a user input into a field of a graphical user interface associated with a second network device;   prior to storage of the text string by the second network device, determining, by the first network device, whether the text string comprises sensitive personal information, wherein the determining comprises inputting the text string to a sensitive personal information tool for analysis of whether the text string comprises the sensitive personal information; and   in response to determining a defined period of time has expired without receiving a confirmation from the sensitive personal information tool that the text string does not comprise the sensitive personal information, facilitating, by the first network device, discarding the text string, by the second network device.   
     
     
         2 . The method of  claim 1 , wherein the user input into the field comprises entry of the text string into the field prior to submission of the user input to the second network device. 
     
     
         3 . The method of  claim 1 , wherein inputting the text string to the sensitive personal information tool occurs prior to receipt of the text string by the second network device. 
     
     
         4 . The method of  claim 1 , further comprising, in response to receiving an indication, within the defined period of time, from the sensitive personal information tool that the text string comprises the sensitive personal information, facilitating, by the first network device, preventing the storage of the text string by the second network device. 
     
     
         5 . The method of  claim 4 , wherein facilitating the preventing of the storage of the text string by the second network device comprises:
 removing the sensitive personal information from the text string to generate a filtered text string, and   sending the filtered text string to the second network device.   
     
     
         6 . The method of  claim 1 , further comprising, in response to determining the defined period of time has expired without receiving the confirmation from the sensitive personal information tool that the text string does not comprise the sensitive personal information, facilitating, by the first network device, providing an alert message for display on the graphical user interface comprising an indication that the text string has been discarded by the second network device. 
     
     
         7 . The method of  claim 1 , further comprising, in response to receiving an indication, within the defined period of time, from the sensitive personal information tool that the text string comprises the sensitive personal information, facilitating, by the first network device, providing an alert message for display on the graphical user interface indicating that the sensitive personal information in the text string has not been stored. 
     
     
         8 . A device, comprising:
 a processor; and   a memory that stores executable instructions that, when executed by the processor, facilitate performance of operations, comprising:
 receiving a text string based on a user input into a field of a graphical user interface associated with a server device; 
 prior to storage of the text string by the server device, determining whether the text string comprises sensitive personal information, wherein the determining comprises sending the text string to a sensitive personal information tool for analysis of whether the text string comprises the sensitive personal information; and 
 in response to not receiving, within a time period, a verification from the sensitive personal information tool that the text string does not comprise the sensitive personal information, instructing the server device to discard the text string. 
   
     
     
         9 . The device of  claim 8 , wherein the user input into the field comprises entry of the text string into the field prior to submission of the user input to the server device. 
     
     
         10 . The device of  claim 8 , wherein sending the text string to the sensitive personal information tool occurs prior to receipt of the text string by the server device. 
     
     
         11 . The device of  claim 8 , wherein the operations further comprise, in response to receiving a confirmation, within the time period, from the sensitive personal information tool that the text string comprises the sensitive personal information, preventing the storage of the text string by the server device. 
     
     
         12 . The device of  claim 11 , wherein preventing the storage of the text string by the server device, comprises:
 removing the sensitive personal information from the text string to generate a filtered text string, and   sending the filtered text string to the server device.   
     
     
         13 . The device of  claim 8 , wherein the operations further comprise, in response to not receiving, within the time period, the verification from the sensitive personal information tool that the text string does not comprise the sensitive personal information, sending an alert message for display via the graphical user interface comprising an indication that the text string has been discarded by the server device. 
     
     
         14 . The device of  claim 8 , wherein the operations further comprise in response to receiving a confirmation, within the time period, from the sensitive personal information tool that the text string comprises the sensitive personal information, sending an alert message for display via the graphical user interface comprising an indication that the sensitive personal information in the text string has not been stored. 
     
     
         15 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a device comprising a processor, facilitate performance of operations, comprising:
 receiving a text string based on a user input into a portion of a graphical user interface associated with a server device;   prior to storage of the text string by the server device, determining whether the text string comprises sensitive personal information, wherein the determining comprises inputting the text string to a sensitive personal information tool for determination of whether the text string comprises the sensitive personal information; and   in response to not receiving, within a defined amount of time, an output from the sensitive personal information tool indicating that the text string does not comprise the sensitive personal information, causing the server device to discard the text string.   
     
     
         16 . The non-transitory machine-readable medium of  claim 15 , wherein the user input into the portion comprises entry of the text string into the portion prior to submission of the user input to the server device. 
     
     
         17 . The non-transitory machine-readable medium of  claim 15 , wherein inputting the text string to the sensitive personal information tool occurs prior to receipt of the text string by the server device. 
     
     
         18 . The non-transitory machine-readable medium of  claim 15 , wherein the operations further comprise, in response to receiving a warning, within the defined amount of time, from the sensitive personal information tool that the text string comprises the sensitive personal information, preventing the storage of the text string by the server device. 
     
     
         19 . The non-transitory machine-readable medium of  claim 18 , wherein preventing the storage of the text string by the server device, comprises:
 removing the sensitive personal information from the text string to generate a filtered text string, and   sending the filtered text string to the server device.   
     
     
         20 . The non-transitory machine-readable medium of  claim 15 , wherein the operations further comprise, in response to not receiving, within the defined amount of time, the output from the sensitive personal information tool indicating that the text string does not comprise the sensitive personal information, sending an alert message for display on the graphical user interface indicating that the text string has been discarded by the server device.

Join the waitlist — get patent alerts

Track US2022245278A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.