Identity breach notification and remediation

US11822694B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11822694-B2
Application numberUS-202117445170-A
CountryUS
Kind codeB2
Filing dateAug 16, 2021
Priority dateApr 20, 2018
Publication dateNov 21, 2023
Grant dateNov 21, 2023

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system and method for improved security in a networked computing environment. The method includes receiving, from a user device, a registration request comprising a user identifier for a user; receiving, from the user device, user credentials to access one or more online accounts associated with the user; accessing the one or more online accounts to retrieve user activity data for the user; analyzing the retrieved user activity data to determine one or more merchants associated with the user; storing, in a database coupled to a server device, a mapping between the user and the one or more merchants; receiving, from a monitoring service, an indication that a first merchant of the one or more merchants has experienced a data breach; and sending a notification to the user in response to determining that the first merchant has experienced a data breach.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for improved security in a networked computing environment, the method comprising: identifying, by a computing system, a plurality of merchants; generating, by a machine learning model of the computing system, a risk classification for each merchant of the plurality of merchants based on historical breach information and fraudulent transaction rates; receiving, by the computing system, a plurality of transactions associated with an account of a user, determining, by the computing system, that a first merchant of the plurality of merchants has experienced a data breach; parsing, by the computing system, the plurality of transactions to determine whether the user transacted in an online transaction with the first merchant of the plurality of merchants; identifying, by the computing system, a first risk classification corresponding to the first merchant; determining, by the computing system, that the first risk classification of the first merchant exceeds a threshold classification level indicating that the first merchant is vulnerable to data breaches; and based on determining that the user has transacted with the first merchant in the online transaction, performing, by the computing system, one or more remedial actions to protect the user from the data breach in accordance with the first risk classification of the first merchant. 2. The method of claim 1 , further comprising: determining a preferred method of the user for receiving identity breach notifications; and sending a notification to the user in accordance with the preferred method for receiving identity breach notification. 3. The method of claim 2 , wherein sending the notification to the user comprises: sending a push notification to a banking app installed on a device of the user. 4. The method of claim 1 , wherein generating the risk classification for each merchant is further based on a fraudulent card present transaction rate and a fraudulent card-not-present transaction rate. 5. The method of claim 1 , wherein generating the risk classification for each merchant is further based on a type of personal data each merchant collects. 6. The method of claim 1 , wherein the one or more remedial actions comprises at least one of: sending a first request to the first merchant to delete personal information associated with the user, sending a second request to a financial service provider to revoke access to a financial account associated with the user, or sending a third request to the financial service provider to provision a new card number for the user. 7. A non-transitory computer-readable medium having programming instructions stored thereon, which, when executed by a processor, causes a computing system to perform operations comprising: identifying, by the computing system, a plurality of merchants; generating, by a machine learning model of the computing system, a risk classification for each merchant of the plurality of merchants based on historical breach information and fraudulent transaction rates; receiving, by the computing system, a plurality of online transactions associated with an account of a user; generating, by the computing system, a user-merchant map comprising merchant information for the user; determining, by the computing system, that a first merchant of the plurality of merchants has experienced a data breach; based on the determining, parsing, by the computing system, the user-merchant map to determine whether the user transacted in an online transaction with the first merchant; determining, by the computing system, that the first merchant is included in the user-merchant map; identifying, by the computing system, a first risk classification corresponding to the first merchant; determining, by the computing system, that the first risk classification of the first merchant exceeds a threshold classification level; and based on determining that the first merchant is in the user-merchant map, performing, by the computing system, one or more remedial actions to protect the user from the data breach in accordance with the first risk classification of the first merchant. 8. The non-transitory computer-readable medium of claim 7 , further comprising: determining a preferred method of the user for receiving identity breach notifications; and sending a notification to the user in accordance with the preferred method for receiving identity breach notification. 9. The non-transitory computer-readable medium of claim 8 , wherein sending the notification to the user comprises: sending a push notification to a banking app installed on a device of the user. 10. The non-transitory computer-readable medium of claim 7 , wherein generating the risk classification for each merchant is based on a fraudulent card present transaction rate and a fraudulent card-not-present transaction rate associated with each merchant. 11. The non-transitory computer-readable medium of claim 7 , wherein generating the risk classification for each merchant is based on a type of personal data each merchant collects. 12. The non-transitory computer-readable medium of claim 7 , wherein the one or more remedial actions comprises at least one of: sending a request to the first merchant to delete personal information associated with the user, sending a second request to a financial service provider to revoke access to a financial account associated with the user, or sending a third request to the financial service provider to provision a new card number for the user. 13. A system comprising: one or more processors; and a memory having programming instructions stored thereon, which, when executed by the one or more processors, causes the system to perform operations comprising: identifying a plurality of merchants; generating, by a machine learning model, a risk classification for each merchant of the plurality of merchants based on historical breach information and fraudulent transaction rates; receiving a plurality of online transactions associated with a plurality of accounts of a plurality of users; generating a merchant table based on the plurality of online transactions, wherein the merchant table comprises the plurality of merchants and each user of the plurality of users that transacted with a respective merchant; determining that a first merchant of the plurality of merchants has experienced a data breach; based on the determining, identifying a subset of users of the plurality of users that transacted in an online transaction with the first merchant based on the merchant table; identifying a first risk classification corresponding to the first merchant determining that the first risk classification of the first merchant exceeds a threshold classification level indicating that the first merchant is vulnerable to data breaches; and based on the identifying, performing one or more remedial actions to protect the subset of users from the data breach in accordance with the first risk classification of the first merchant. 14. The system of claim 13 , wherein the operations further comprise: determining a preferred method of each user of the subset of users for receiving identity breach notifications; and sending a notification to each user in accordance with the preferred method for receiving identity breach notification.

Assignees

Inventors

Classifications

  • Protecting personal data, e.g. for financial or medical purposes · CPC title

  • between heterogeneous systems · CPC title

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • Entity profiles · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11822694B2 cover?
A system and method for improved security in a networked computing environment. The method includes receiving, from a user device, a registration request comprising a user identifier for a user; receiving, from the user device, user credentials to access one or more online accounts associated with the user; accessing the one or more online accounts to retrieve user activity data for the user; a…
Who is the assignee on this patent?
Capital One Services Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/6245. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Nov 21 2023 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).