Access control value systems
US-2020162477-A1 · May 21, 2020 · US
US2024223536A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2024223536-A1 |
| Application number | US-202318092609-A |
| Country | US |
| Kind code | A1 |
| Filing date | Jan 3, 2023 |
| Priority date | Jan 3, 2023 |
| Publication date | Jul 4, 2024 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments of the invention are directed to systems, computer program products, and methods for tracking data transferred in a distributed network via secured, layered data tagging. A checkpoint sensing engine collects data flow at a checkpoint device and verifies a match between a checkpoint tag of the transaction packet and a checkpoint identifier of the checkpoint device. If no match occurs, the transaction packet it transmitted to a quarantine unit. If a match occurs, a deconstruction engine then removes the checkpoint tag, exposing an underlying second checkpoint tag corresponding with a second checkpoint device. Thereafter, the transaction packet is transmitted to the second checkpoint device.
Opening claim text (preview).
What is claimed is: 1 . A system for tracking data transferred in a distributed network via secured, layered data tagging, the system comprising: at least one non-transitory storage device; and at least one processing device coupled to the at least one non-transitory storage device, wherein the at least one processing device is configured to: collect, by a checkpoint sensing engine, data flow at a first checkpoint device, the data flow relating to network traffic passing from the first checkpoint device to a second checkpoint device, wherein the data flow comprises at least one transaction packet, the at least one transaction packet comprising a checkpoint tag group, wherein the checkpoint tag group comprises at least one checkpoint tag; verify, by the checkpoint sensing engine, a match between a first checkpoint tag of the at least one transaction packet and a checkpoint identifier of the first checkpoint device; transmit a notification to an endpoint device, the notification comprising an identification of the match or no match; and display the notification on a user interface of the endpoint device. 2 . The system of claim 1 , wherein the at least one processing device is further configured to: remove, by a tag deconstruction engine, the first checkpoint tag of the at least one transaction packet upon a verification of a match between the first checkpoint tag and the checkpoint identifier, wherein the removing of the first checkpoint tag exposes a second checkpoint tag, the second checkpoint tag nested within the first checkpoint tag and corresponding to a checkpoint identifier of the second checkpoint device; and transmit the at least one transaction packet to the second checkpoint device. 3 . The system of claim 1 , wherein the at least one processing device is further configured to: transmit the at least one transaction packet from the first checkpoint device to a quarantine unit if there is a no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag. 4 . The system of claim 1 , wherein the at least one transaction packet further comprises at least one data scoring tag. 5 . The system of claim 2 , wherein if there is a match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, a removal of the first checkpoint tag; and reject, as a result of the second selection, the removal of the first checkpoint tag, and subsequently transmit the at least one transaction packet from the first checkpoint device to a quarantine unit. 6 . The system of claim 3 , wherein if there is no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit; and reject, as a result of the second selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit, and instead remove the first checkpoint tag and transmit the at least one transaction packet to the second checkpoint device. 7 . The system of claim 4 , wherein the checkpoint sensing engine applies the at least one data scoring tag resulting from a match between a transaction object header and a data attribute table. 8 . A computer program product for tracking data transferred in a distributed network via secured, layered data tagging, the computer program product comprising a non-transitory computer-readable medium comprising code causing a first apparatus to: collect, by a checkpoint sensing engine, data flow at a first checkpoint device, the data flow relating to network traffic passing from the first checkpoint device to a second checkpoint device, wherein the data flow comprises at least one transaction packet, the at least one transaction packet comprising a checkpoint tag group, wherein the checkpoint tag group comprises at least one checkpoint tag; verify, by the checkpoint sensing engine, a match between a first checkpoint tag of the at least one transaction packet and a checkpoint identifier of the first checkpoint device; transmit a notification to an endpoint device, the notification comprising an identification of the match or no match; and display the notification on a user interface of the endpoint device. 9 . The computer program product of claim 8 , wherein the code further causes the first apparatus to: remove, by a tag deconstruction engine, the first checkpoint tag of the at least one transaction packet upon a verification of a match between the first checkpoint tag and the checkpoint identifier, wherein the removing of the first checkpoint tag exposes a second checkpoint tag, the second checkpoint tag nested within the first checkpoint tag and corresponding to a checkpoint identifier of the second checkpoint device; and transmit the at least one transaction packet to the second checkpoint device. 10 . The computer program product of claim 8 , wherein the code further causes the first apparatus to: transmit the at least one transaction packet from the first checkpoint device to a quarantine unit if there is a no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag. 11 . The computer program product of claim 8 , wherein the at least one transaction packet further comprises at least one data scoring tag. 12 . The computer program product of claim 9 , wherein if there is a match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, a removal of the first checkpoint tag; and reject, as a result of the second selection, the removal of the first checkpoint tag, and subsequently transmit the at least one transaction packet from the first checkpoint device to a quarantine unit. 13 . The computer program product of claim 10 , wherein if there is no match between the checkpoint identifier of the first checkpoint device and the first checkpoint tag, the notification comprises a disposition feature comprising a first selection and a second selection, the disposition feature configured to communicate with the checkpoint sensing engine to: accept, as a result of the first selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit; and reject, as a result of the second selection, the transmitting of the transaction packet from the first checkpoint device to a quarantine unit, and instead remove the first checkpoint tag and transmit the at least one transaction packet to the second checkpoint device. 14 . The computer program product of claim 11 , wherein the checkpoint sensing engine applies the at least one data scoring tag resulting from a match between a transaction object header and a data attribute table. 15 . A method for tracking data transferred in a distributed network via secured, layered data tagging, the method comprisin
comprising specially adapted graphical user interfaces [GUI] · CPC title
during transmission, i.e. party's identity is protected against eavesdropping, e.g. by using temporary identifiers, but is known to the other party or parties involved in the communication · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.