IP Library Granted Patent US 8,751,788
Granted Patent B2
US 8,751,788 · App. 12/482,231 · Granted Jun 10, 2014

Payment encryption accelerator

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,751,788
App. No.
12/482,231
Granted
Jun 10, 2014
Kind
B2
Abstract

Embodiments of the invention provide a system for encrypting web session data which may include a session management module adapted to receive data from a web application module and provide a token that represents the data in encrypted form to the web application, wherein the web application is adapted to use the token to represent the data. The system may also include a tokenizer module communicably coupled to the session management module, wherein the tokenizer module is adapted to receive the data and generate the token. Further, the system may include a database communicably coupled to the session management module, wherein the database is adapted to receive the token and the data, associate the token with the data, and store the token and the data.

Claims (27)

1. In a computer management encryption system comprising one or more hardware and software modules in communication with an encryption proxy, a method for protecting sensitive data, comprising the steps of:

receiving a request for a subscription identifier at the computer management encryption system from a web application, wherein the web application requests the subscription identifier based on anticipation of the receipt of sensitive data, and wherein the subscription identifier relates to a particular data type and a particular tokenization session;

generating via the computer management encryption system a unique subscription identifier for association with the web application and the particular tokenization session;

providing the unique subscription identifier from the computer management encryption system to the web application;

receiving sensitive data at the computer management encryption system from a web browser presenting the web application, via the encryption proxy, wherein the sensitive data comprises the particular data type and a plurality of data values, and wherein the sensitive data is associated with the unique subscription identifier;

generating via the computer management encryption system a token that is representative of the sensitive data in encrypted form, the token comprising a token format dependent on the particular data type of the sensitive data, and wherein the token format further comprises a plurality of token data values, wherein each token data value is dependent upon the data values in the sensitive data;

associating via the computer management encryption system the token with the sensitive data and the unique subscription identifier;

storing the token and the sensitive data and the unique subscription identifier in a database at the computer management encryption system; and

providing the token from the computer management encryption system to the web browser presenting the web application for use in replacing the sensitive data with the token.

2. The method of claim 1 , further comprising the steps of:

receiving a client certificate from the web application at the computer management encryption system, wherein the certificate identifies the web application; and

associating the unique subscription identifier with the client certificate at the computer management encryption system.

3. The method of claim 1 , wherein the step of receiving sensitive data at the computer management encryption system includes validating the unique subscription identifier received from the web application, the method further comprising:

performing the generating, associating, storing, and providing steps only if the unique subscription identifier is valid.

4. The method of claim 1 , wherein the unique subscription identifier has a time-limited validity.

5. The method of claim 1 , further comprising the steps of:

associating, at the computer management encryption system, the unique subscription identifier with a tokenizer certificate;

receiving the subscription identifier at the computer management encryption system from the web application;

determining, at the computer management encryption system, whether the tokenizer certificate is valid; and

performing the generating, associating, storing, and providing steps only if the tokenizer certificate is valid.

6. The method of claim 1 , wherein the sensitive data is selected from the group comprising: credit card data, social security number data, employee-identification number.

7. The method of claim 1 , wherein the token includes a portion of the sensitive data in unencrypted form.

8. The method of claim 1 , further comprising the step of prior to generating the token, receiving from the web application a definition of an application-defined token format to be used by the computer management encryption system in connection with generating the token.

9. The method of claim 8 , wherein the application-defined token format corresponds to a social security number.

10. The method of claim 8 , wherein the application-defined token format corresponds to a credit card number.

11. The method of claim 8 , wherein the application-defined token format corresponds to an employee-identification number.

12. The method of claim 1 , wherein the web application includes a plurality of additional web applications communicably coupled to the web application and that share the token with the web application for purposes of utilizing the sensitive data.

Assignments (11)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
SECURITY INTEREST Recorded Feb 19, 2024
From: PAYMETRIC, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066625/0347 →
SECURITY INTEREST Recorded Feb 19, 2024
From: PAYMETRIC, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066625/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS (RELEASES RF 42951/0315) Recorded Aug 1, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS SUCCESSOR-IN-INTEREST TO JPMORGAN CHASE BANK, N.A.
To: PAYMETRIC, INC.
Reel/Frame 049943/0094 →
NOTICE OF ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Oct 11, 2017
From: JPMORGAN CHASE BANK, N.A., AS RESIGNING AGENT
To: MORGAN STANLEY SENIOR FUNDING, INC., AS SUCCESSOR AGENT
Reel/Frame 044171/0585 →
SECURITY INTEREST Recorded Jul 10, 2017
From: PAYMETRIC, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 042951/0315 →
RELEASE OF SECURITY INTEREST Recorded May 25, 2017
From: SILICON VALLEY BANK
To: PAYMETRIC, INC.
Reel/Frame 042507/0105 →
SECURITY AGREEMENT Recorded Sep 19, 2013
From: PAYMETRIC, INC.
To: SILICON VALLEY BANK
Reel/Frame 031246/0472 →
RELEASE OF SECURITY INTEREST Recorded May 16, 2012
From: SQUARE 1 BANK
To: PAYMETRIC, INC.
Reel/Frame 028219/0358 →
SECURITY AGREEMENT Recorded Apr 19, 2012
From: PAYMETRIC, INC
To: SQUARE 1 BANK
Reel/Frame 028071/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2009
From: LEACH, NATHAN P.
To: PAYMETRIC, INC.
Reel/Frame 023403/0789 →