System and method for tracking data transferred in a distributed network via secured, layered data tagging

US12556519B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12556519-B2
Application numberUS-202318092609-A
CountryUS
Kind codeB2
Filing dateJan 3, 2023
Priority dateJan 3, 2023
Publication dateFeb 17, 2026
Grant dateFeb 17, 2026

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of the invention are directed to systems, computer program products, and methods for tracking data transferred in a distributed network via secured, layered data tagging. A checkpoint sensing engine collects data flow at a checkpoint device and verifies a match between a checkpoint tag of the transaction packet and a checkpoint identifier of the checkpoint device. If no match occurs, the transaction packet it transmitted to a quarantine unit. If a match occurs, a deconstruction engine then removes the checkpoint tag, exposing an underlying second checkpoint tag corresponding with a second checkpoint device. Thereafter, the transaction packet is transmitted to the second checkpoint device.

First claim

Opening claim text (preview).

What is claimed is: 1 . A system for tracking data transferred in a distributed network via secured, layered data tagging, the system comprising: at least one non-transitory storage device comprising instructions; and at least one processing device coupled to the at least one non-transitory storage device, wherein when executed by the processing device, the instructions cause the processing device to perform the steps of: collecting, by a checkpoint sensing engine, data flow at a first checkpoint device, the data flow relating to network traffic passing from the first checkpoint device to a second checkpoint device, wherein the data flow comprises at least one transaction packet, the at least one transaction packet comprising a checkpoint tag group, wherein the checkpoint tag group comprises at least one checkpoint tag; verifying, by the checkpoint sensing engine, a match between a first checkpoint tag of the at least one transaction packet and a checkpoint identifier of the first checkpoint device; transmitting a notification to an endpoint device, the notification comprising an identification of the match or no match, wherein if there is a match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, a removal of the first checkpoint tag; and reject, as a result of the second selection, the removal of the first checkpoint tag, and subsequently transmit the at least one transaction packet from the first checkpoint device to a quarantine unit; displaying the notification on a user interface of the endpoint device; removing, by a tag deconstruction engine, the first checkpoint tag of the at least one transaction packet upon a verification of a match between the first checkpoint tag and the checkpoint identifier, wherein the removing of the first checkpoint tag exposes a second checkpoint tag, the second checkpoint tag nested within the first checkpoint tag and corresponding to a checkpoint identifier of the second checkpoint device; and transmitting the at least one transaction packet to the second checkpoint device. 2 . The system of claim 1 , wherein the instructions further cause the processing device to perform the steps of: transmitting the at least one transaction packet from the first checkpoint device to a quarantine unit if there is a no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag. 3 . The system of claim 2 , wherein if there is no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit; and reject, as a result of the second selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit, and instead remove the first checkpoint tag and transmit the at least one transaction packet to the second checkpoint device. 4 . The system of claim 1 , wherein the at least one transaction packet further comprises at least one data scoring tag. 5 . The system of claim 4 , wherein the checkpoint sensing engine applies the at least one data scoring tag resulting from a match between a transaction object header and a data attribute table. 6 . A computer program product for tracking data transferred in a distributed network via secured, layered data tagging, the computer program product comprising a non-transitory computer-readable medium comprising code causing a first apparatus to: collect, by a checkpoint sensing engine, data flow at a first checkpoint device, the data flow relating to network traffic passing from the first checkpoint device to a second checkpoint device, wherein the data flow comprises at least one transaction packet, the at least one transaction packet comprising a checkpoint tag group, wherein the checkpoint tag group comprises at least one checkpoint tag; verify, by the checkpoint sensing engine, a match between a first checkpoint tag of the at least one transaction packet and a checkpoint identifier of the first checkpoint device; transmit a notification to an endpoint device, the notification comprising an identification of the match or no match, wherein if there is a match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, a removal of the first checkpoint tag; and reject, as a result of the second selection, the removal of the first checkpoint tag, and subsequently transmit the at least one transaction packet from the first checkpoint device to a quarantine unit; display the notification on a user interface of the endpoint device; remove, by a tag deconstruction engine, the first checkpoint tag of the at least one transaction packet upon a verification of a match between the first checkpoint tag and the checkpoint identifier, wherein the removing of the first checkpoint tag exposes a second checkpoint tag, the second checkpoint tag nested within the first checkpoint tag and corresponding to a checkpoint identifier of the second checkpoint device; and transmit the at least one transaction packet to the second checkpoint device. 7 . The computer program product of claim 6 , wherein the code further causes the first apparatus to: transmit the at least one transaction packet from the first checkpoint device to a quarantine unit if there is a no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag. 8 . The computer program product of claim 7 , wherein if there is no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit; and reject, as a result of the second selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit, and instead remove the first checkpoint tag and transmit the at least one transaction packet to the second checkpoint device. 9 . The computer program product of claim 6 , wherein the at least one transaction packet further comprises at least one data scoring tag. 10 . The computer program product of claim 9 , wherein the checkpoint sensing engine applies the at least one data scoring tag resulting from a match between a transaction object header and a data attribute table. 11 . A method for tracking data transferred in a distributed network via secured, layered data tagging, the method comprising: collecting, by a checkpoint sensing engine, data flow at a first checkpoint device, the data flow relating to network traffic passing from the first checkpoint device to a second checkpoint device, wherein the data flow comprises at least one transaction pac

Assignees

Inventors

Classifications

  • H04L63/20Primary

    for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • comprising specially adapted graphical user interfaces [GUI] · CPC title

  • during transmission, i.e. party's identity is protected against eavesdropping, e.g. by using temporary identifiers, but is known to the other party or parties involved in the communication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12556519B2 cover?
Embodiments of the invention are directed to systems, computer program products, and methods for tracking data transferred in a distributed network via secured, layered data tagging. A checkpoint sensing engine collects data flow at a checkpoint device and verifies a match between a checkpoint tag of the transaction packet and a checkpoint identifier of the checkpoint device. If no match occurs…
Who is the assignee on this patent?
Bank Of America
What technology area does this patent fall under?
Primary CPC classification H04L63/20. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 17 2026 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).