IP Library Granted Patent US 12664308
Granted Patent B2
US 12664308 · App. 18/263,736 · Granted Jun 23, 2026

Personal data anonymization system (PDAS) with customized token

Inventors: Thomas Doerr (Berlin, DE); Dominic Wist (Berlin, DE)
Assignee: BIOTRONIK SE & Co. KG
G06F21/6254H04L9/3213H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12664308
App. No.
18/263,736
Granted
Jun 23, 2026
Kind
B2
Abstract

The invention relates to a device and method for protecting sensitive personal data held in a public storage, comprising a trusted tokenization system having at least one trusted interface to an instance that may provide, process, possess, and/or retrieve sensitive personal data, and at least one interface to a public storage not containing sensitive personal data, wherein the tokenization system is configured to replace a sensitive personal reference of the data in the public storage with a non-sensitive data element and to store an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element can be processed in an existing infrastructure of a user without adaptation of said infrastructure.

Claims (23)

1 . A device for protecting sensitive personal data held in a public storage, comprising:

a transmitter and a receiver;

at least one trusted interface to a secured trusted access computing device that provides, processes, possesses, and/or retrieves sensitive personal data; and

at least one interface to a public storage not containing sensitive personal data, wherein the device is configured to replace a sensitive personal reference of the sensitive personal data in the public storage with a non-sensitive data element and to store an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element is processed in an existing infrastructure of a user without adaptation of said infrastructure, wherein the device further comprises or is connected to a database in the secure environment, wherein when data is queried from the database, requested non-sensitive data elements are provided with a cryptographic checksum for which a certificate is issued externally together with the query result, wherein the device is configured to send, for a specific transaction, the sensitive personal data, the non-sensitive data element, an associated data element ID, and a security code, wherein the security code is valid for a predetermined period of time and is encrypted with a token key that is unique for the transaction and only valid for the predetermined period, wherein the token key includes: a Token data element IDs of data to be sent, time stamp to the minute, IP address of a person that the sensitive personal data belongs to, and transaction-specific details.

2 . The device of claim 1 , wherein the sensitive personal data is health data and/or patient data.

3 . The device of claim 1 , further comprising a configurable, rights system for data access.

4 . The device of claim 1 , wherein the device is configured to manage distributed data elements of the user and/or assign distributed data elements to the user.

5 . The device of claim 1 , wherein the device is configured to generate plural non-sensitive data elements as tokens for different use cases.

6 . The device of claim 1 , wherein the device is configured to encrypt and/or sign the sensitive personal data.

7 . The device of claim 1 , wherein the device is configured to prevent falsification of the sensitive personal data.

8 . The device of claim 1 , wherein the device is configured to prevent incorrect assignment of the sensitive personal data.

9 . The device of claim 1 , wherein the device is configured to include the user as a central data release instance.

10 . The device of claim 1 , wherein the device is configured to allow the user, anonymized by the non-sensitive data element, to authorize a release of the sensitive personal data to a cloud service provider.

11 . The device of claim 10 , wherein the device is configured to perform a two-factor authentication to confirm the sensitive personal data release, said two-factor authentication comprising at least one of a fingerprint, a face ID, an implanted ID readable via smartphone nearfield communication and an authorization server interface.

12 . The device of claim 1 , wherein the device is configured to allow the user to authorize predetermined uses of the sensitive personal data by feeding the sensitive personal data to a machine learning system and/or not storing it in clinical trial databases.

13 . The device of claim 1 , wherein the device further comprises or is connected to a database in the secure environment, wherein when data is queried from the database, requested non-sensitive data elements are provided with a cryptographic checksum for which a certificate is issued externally together with the query result.

14 . A computer implemented method for protecting sensitive personal data held in a public storage, comprising the steps of:

Providing, processing, possessing, and/or retrieving sensitive personal data by means of a device having a transmitter, a receiver, and at least one trusted interface to a secured trusted access device;

Providing at least one interface to a public storage not containing sensitive personal data;

Replacing a sensitive personal reference of the sensitive personal data in the public storage with a non-sensitive data element by means of the device;

Storing an association between the sensitive personal reference and the non-sensitive data element in a secure environment, wherein the non-sensitive data element is generated in a user-specific manner such that the non-sensitive data element is processed in an existing infrastructure of a user without adaptation of said infrastructure;

Querying data and providing requested non-sensitive data elements with a cryptographic checksum for which a certificate is issued externally together with the query result;

Sending, for a specific transaction, the sensitive personal data, the non-sensitive data element, an associated data element ID, and a security code, wherein the security code is valid for a predetermined period of time and is encrypted with a token key that is unique for the transaction and only valid for the predetermined period, wherein the token key includes: a Token, data element IDs of data to be sent, time stamp to the minute, IP address of a person that the sensitive personal data belongs to, and transaction-specific details.