US2023289810A1PendingUtilityA1

Systems and methods for data breach detection using virtual card numbers

Assignee: CAPITAL ONE SERVICES LLCPriority: Jan 29, 2021Filed: May 19, 2023Published: Sep 14, 2023
Est. expiryJan 29, 2041(~14.5 yrs left)· nominal 20-yr term from priority
G06N 3/09G06N 3/0442G06Q 20/4016G06Q 20/351G06Q 20/40G06N 3/08H04L 63/1416H04L 63/1425
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Disclosed are systems and methods for data breach identification. The method may include: generating virtual card number (VCN) data sets; storing the VCN data sets on a first database; receiving one or more compromised VCN data sets stored on a second database and obtained from a scan of unindexed websites; comparing the compromised VCN data sets with the VCN data set stored on the first database to determine whether the VCN data sets have been compromised; for each compromised VCN data set, training the recurrent neural network (RNN) to associate the compromised VCN data sets with one or more sequential patterns found within the compromised VCN data sets to generate a trained RNN; receiving a first VCN data set from the first database; determining whether the first VCN data set matches a compromised VCN data set; and transmitting a message indicating the determination to a user or provider device.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A computer-implemented method for data breach identification, the method comprising:
 generating, by a processor, a plurality of virtual card numbers associated with a security data set of a user;   storing, by the processor, the plurality of virtual card numbers on a first database;   receiving, by the processor at a second database, one or more compromised virtual card number data sets;   determining, by the processor and a neural network, an exposed virtual card number of the plurality of virtual card numbers by comparing the one or more compromised virtual card number sets with one or more sequential patterns found within the security data of the plurality of virtual card numbers; and   upon determining the exposed virtual card number, transmitting a regenerated virtual card number to a user device of the user.   
     
     
         22 . The method of  claim 21 , further comprising:
 receiving, by the one or more processors, a request to authenticate a transaction; and   declining to authenticate the transaction upon determining, by the one or more processors, that the transaction involves a compromised virtual card number data set.   
     
     
         23 . The method of  claim 21 , wherein the security data comprises one or more of a card verification value, a card verification code, a physical address number, or a personal identification number associated with a user device. 
     
     
         24 . The method of  claim 23 , wherein determining the exposed virtual card number further comprises determining whether the virtual card number and one or more of the user device, a provider device, or the security data of the first virtual card number data set is similar to the virtual card number and one or more of the user device, the provider device, or the security data of the compromised virtual card number data sets stored on the second database. 
     
     
         25 . The method of  claim 24 , wherein the determining the first virtual card number data set matches a compromised virtual card number data set stored on the second database further comprises determining, by the one or more processors, whether a pre-determined threshold is satisfied. 
     
     
         26 . The method of  claim 21 , further comprising:
 upon parsing one or more virtual card number data sets from the compromised data on the second database, storing, by the one or more processors, the parsed virtual card number data sets on a third database separate from the second database, wherein comparing the one or more compromised virtual card number data sets with the one or more virtual card number data sets stored on the first database comprises comparing the one or more compromised virtual card number data sets stored on the third database with the virtual card number data sets stored on the first database.   
     
     
         27 . The method of  claim 26 , wherein the third database is located at a physical location remote from the first and second databases. 
     
     
         28 . The method of  claim 21 , wherein the second database is located at a physical location remote from the first database. 
     
     
         29 . The method of  claim 21 , wherein transmitting the regenerated virtual card number includes causing presentation of a message via a user interface of the user or a provider device. 
     
     
         30 . The method of  claim 29 , wherein causing presentation of the message via the user interface includes presentation by at least one of a voice notification, application notification, tactile notification, or graphic notification. 
     
     
         31 . A system for data breach identification, the system comprising:
 at least one memory device having processor-readable instructions stored therein; and   at least one central processing unit including at least one processor configured to access the memory device and execute the processor-readable instructions, which when executed by the processor configures the processor to perform a plurality of functions, including functions for:
 generating a plurality of virtual card numbers associated with a security data set of a user device; 
 storing the plurality of virtual card numbers on a first database; 
 receiving one or more compromised virtual card number data sets, wherein the one or more compromised virtual card number data sets is parsed from compromised data stored on a second database isolated from communication with the first database, and wherein the compromised data is obtained from a scan of unindexed websites on a network; 
 determining by a neural network, an exposed virtual card number of the plurality of virtual card numbers by comparing the one or more compromised virtual card number sets with one or more sequential patterns found within the security data of the plurality of virtual card numbers; and 
 upon determining the exposed virtual card number, transmitting a regenerated virtual card number to a user device of the user. 
   
     
     
         32 . The system of  claim 31 , wherein the processor is further configured to perform functions for:
 receiving a request to authenticate a transaction; and   declining to authenticate the transaction upon determining that the transaction involves a compromised virtual card number data set.   
     
     
         33 . The system of  claim 31 , wherein the security data comprises one or more of a card verification value, a card verification code, a physical address number, or a personal identification number associated with a user device. 
     
     
         34 . The system of  claim 33 , wherein determining the exposed virtual card number further comprises determining whether the virtual card number and one or more of the user device, a second device, or security data of the first virtual card number data set is identical to the virtual card number and one or more of the user device, the second device, or the security data of the compromised virtual card number data sets stored on the second database. 
     
     
         35 . The system of  claim 34 , wherein the determining the first virtual card number data set matches a compromised virtual card number data set stored on the second database further comprises determining, by the one or more processors, whether a pre-determined threshold is met. 
     
     
         36 . The system of  claim 31 , wherein the processor is further configured to perform functions for:
 upon parsing one or more virtual card number data sets from the compromised data stored on the second database, storing the parsed virtual card number data sets on a third database separate from the second database, wherein comparing the one or more compromised virtual card number data sets with the one or more virtual card number data sets stored on the first database comprises comparing the one or more compromised virtual card number data sets stored on the third database with the virtual card number data sets stored on the first database.   
     
     
         37 . The system of  claim 36 , wherein the third database is located at a physical location remote from the first and second databases. 
     
     
         38 . The system of  claim 31 , wherein the processor is further configured to perform functions for:
 presenting, via a user interface of a user or provider device, a message indicating the compromised first virtual card number data set.   
     
     
         39 . The system of  claim 38 , wherein the message indicating the compromised first virtual card number data set is presented by at least one of a voice notification, application notification, tactile notification, or graphic notification. 
     
     
         40 . A computer-implemented method for using a recurrent neural network for data breach identification, the method comprising:
 generating, by one or more processors, a plurality of virtual card numbers associated with a security data set of a user device;   storing, by the one or more processors, the plurality of virtual card numbers on a first database;   receiving, by the one or more processors, one or more compromised virtual card number data sets, wherein the one or more compromised virtual card number data sets is parsed from compromised data stored on a second database isolated from communication with the first database, and wherein the compromised data is obtained from a scan of unindexed websites on a network;   determining by a neural network, an exposed virtual card number of the plurality of virtual card numbers by comparing the one or more compromised virtual card number sets with one or more sequential patterns found within the security data of the plurality of virtual card numbers;   upon determining the exposed virtual card number, taking an action including one or more of the following:
 transmitting a regenerated virtual card number to a user device of the user; 
 determining a potential data breach of an entity associated with the exposed virtual card number; or 
 alerting the entity.

Join the waitlist — get patent alerts

Track US2023289810A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.