×

Electronic discovery system and method

  • US 7,809,686 B2
  • Filed: 10/06/2006
  • Issued: 10/05/2010
  • Est. Priority Date: 10/06/2005
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for conducting investigations of one or more target devices in a data communications network, the method comprising:

  • defining, under control of a computer, one or more filter conditions for culling one or more files stored in the one or more target devices;

    grouping the one or more filter conditions into a single investigation subject;

    automatically generating, under control of the computer, at least one global unique identifier uniquely identifying the investigation subject;

    locking the investigation subject and the at least one global unique identifier for preventing modification of the filter conditions and the global unique identifier;

    storing in memory the locked investigation subject and the locked global unique identifier, in association with each other;

    generating an evidence container file on an examining machine;

    applying by the examining machine the locked investigation subject to a plurality of files stored in the one or more target devices during an investigation session;

    receiving from the one or more target devices at least metadata of one or more of the plurality of files matching the plurality of filter conditions of the applied investigation subject, wherein the matching files is only a subset of the plurality of files stored in the one or more target devices and the one or more target devices transmit at least the metadata for only the matching filesstoring in the evidence container file at least the received metadata of the matching files without modification to the received metadata due to the storing;

    storing by the examining machine in the evidence container file or attaching to one or more of the matching files in the evidence container file, the locked global unique identifier, wherein the locked global unique identifier associates the matching files to the applied investigation subject thereby evidencing that the matching files resulted from the investigation session that applied the investigation subject.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×