IP Library Granted Patent US 8,788,427
Granted Patent B2
US 8,788,427 · App. 13/475,494 · Granted Jul 22, 2014

Limiting data exposure in authenticated multi-system transactions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,788,427
App. No.
13/475,494
Granted
Jul 22, 2014
Kind
B2
Abstract

The limiting of data exposure in authenticated multi-system transactions is disclosed. A client system authenticates and requests secured data and unsecured data with an initial system. The initial system transmits to an external system a token request that corresponds to the request for the secured data. A token is generated and passed to the initial system, which relays the same to the client system. The client system uses the token to access the secured data on the external system, while also retrieving the unsecured data on the initial system. The initial system thus does not have access to the secured data, while the request therefor is known.

Claims (31)

1. A method for limiting exposure of secured data in an authenticated transaction over multiple systems, the method comprising:

receiving a transaction request from an authenticated user of a client system on an initial system;

deriving from the transaction request a first request for the secured data stored on an external system independent of the initial system and a second request for unsecured data stored on the initial system, the first request and the second request being combined in the transaction request;

transmitting to the external system a token request corresponding to the first request for the secured data, the external system being configured to generate a token associated with the token request;

receiving on the initial system the generated token from the external system; and

transmitting from the initial system to the client system the token and the requested unsecured data stored on the initial system;

wherein the token is presentable by the client system to the external system to retrieve the secured data stored on the external system independently of the transmission of the unsecured data upon validation of the token thereby by the external system.

2. The method of claim 1 , further comprising:

transmitting a location identifier for the external system to the client system;

wherein the client system initiates a request for the secured data based upon the provided location identifier for the external system.

3. The method of claim 1 , further comprising:

storing in an audit log on the initial system the token and the token request corresponding to the first request for the secured data.

4. The method of claim 1 , further comprising:

establishing a secured trusted data communications link between the initial system and the external system.

5. The method of claim 1 , further comprising:

establishing a secured trusted data communications link between the initial system and the client system.

6. The method of claim 1 , wherein the requested unsecured data includes a placeholder for the requested secured data.

7. The method of claim 1 , further comprising:

receiving a validation request from the external system generated in response to the client system presenting the token to the external system, the validation request including the token as received by the external system from the client system;

confirming the validation request; and

transmitting a transaction validity response to the external system upon confirmation of the validation request.

8. The method of claim 1 , wherein the token is single-use and newly generated for each token request.

9. The method of claim 1 , wherein the user has a first account established on the initial system independently of the external system.

10. The method of claim 9 , wherein the user has a second account established on the external system, the token being presentable by the client system to the external system upon authentication of the user to the second account, and the token request including an identifier of the second account.

11. An article of manufacture comprising a non-transitory program storage medium readable by a computer, the medium tangibly embodying one or more programs of instructions executable by the computer to perform a method for limiting exposure of secured data in an authenticated transaction over multiple systems, the method comprising:

receiving a transaction request from an authenticated user of a client system on an initial system;

deriving from the transaction request a first request for the secured data stored on an external system independent of the initial system and a second request for unsecured data stored on the initial system, the first request and the second request being combined in the transaction request;

transmitting to the external system a token request corresponding to the first request for the secured data, the external system being configured to generate a token associated with the token request;

receiving on the initial system the generated token from the external system; and

transmitting from the initial system to the client system the token and the requested unsecured data stored on the initial system;

wherein the token is presentable by the client system to the external system to retrieve the secured data stored on the external system independently of the transmission of the unsecured data upon validation of the token by the external system.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Sep 17, 2019
From: BANK OF AMERICA, N.A.
To: GLOBAL PAYMENTS INC.; ACTIVE NETWORK, LLC; ADVANCEDMD, INC.; DEBITEK, INC.; XENIAL, INC. (F/K/A HEARTLAND COMMERCE, INC.); HEARTLAND PAYMENT SYSTEMS, LLC; NEXTEP SYSTEMS INC.; NUEIP, LLC; NUESOFT TECHNOLOGIES INC.; TOUCHNET INFORMATION SYSTEMS, INC.
Reel/Frame 050406/0851 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Apr 2, 2019
From: ACTIVE NETWORK, LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 048764/0575 →
RELEASE OF SECOND LIEN SECURITY INTEREST Recorded Nov 30, 2016
From: BANK OF AMERICA, N.A.
To: LANYON SOLUTIONS, INC. (F/K/A THE ACTIVE NETWORK, INC.); LANYON, INC.
Reel/Frame 040546/0816 →
RELEASE OF FIRST LIEN SECURITY INTEREST Recorded Nov 29, 2016
From: BANK OF AMERICA, N.A.
To: LANYON SOLUTIONS, INC.(F/K/A THE ACTIVE NETWORK, INC.); LANYON, INC.
Reel/Frame 040978/0461 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2014
From: THE ACTIVE NETWORK, INC.
To: ACTIVE NETWORK, LLC
Reel/Frame 032803/0562 →
SECOND LIEN SECURITY AGREEMENT Recorded Nov 18, 2013
From: THE ACTIVE NETWORK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031664/0835 →
FIRST LIEN SECURITY AGREEMENT Recorded Nov 15, 2013
From: THE ACTIVE NETWORK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031645/0514 →
RELEASE OF SECURITY INTEREST Recorded Nov 15, 2013
From: BANK OF AMERICA, N.A.
To: THE ACTIVE NETWORK, INC.
Reel/Frame 031646/0745 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Aug 21, 2013
From: THE ACTIVE NETWORK, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031058/0355 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2012
From: JOHNSON, DOUG
To: THE ACTIVE NETWORK, INC.
Reel/Frame 028235/0641 →