IP Library Granted Patent US 9,317,715
Granted Patent B2
US 9,317,715 · App. 13/594,158 · Granted Apr 19, 2016

Data protection compliant deletion of personally identifiable information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,317,715
App. No.
13/594,158
Granted
Apr 19, 2016
Kind
B2
Abstract

The disclosure generally describes computer-implemented methods, software, and systems for modeling and deploying decision services. One computer-implemented method includes encrypting, by operation of a computer, personally-identifiable information (PII) data using a first cryptographic key, wherein the PII data is associated with non-encrypted associated data, encrypting the encrypted first cryptographic key with a second cryptographic key, determining that the occurrence of a PII data disassociation event associated with the second cryptographic key has occurred, and rendering the PII data inaccessible by disassociating the second cryptographic key from the encrypted first cryptographic key.

Claims (41)

1. A computer-implemented method, comprising:

encrypting, by operation of a computer, personally-identifiable information (PII) data using a first cryptographic key, wherein the PII data is associated with non-encrypted associated data, and wherein the first cryptographic key is a record key of a data record storing the PII data;

encrypting the first cryptographic key with a second cryptographic key, wherein the second cryptographic key is a purpose key associated with a particular purpose providing a justification for the use of the second cryptographic key to encrypt the first cryptographic key, wherein the second cryptographic key is associated with a cryptographic key record used to associate the second cryptographic key with a purpose key identifier, the particular purpose, and one or more conditions, wherein the purpose key identifier provides a mapping between the particular purpose and the second cryptographic key, and wherein the condition determines whether the second cryptographic key has expired;

determining that the occurrence of a PII data disassociation event associated with the second cryptographic key has occurred; and

rendering the PII data inaccessible by disassociating the second cryptographic key from the encrypted first cryptographic key.

2. The computer-implemented method of claim 1 , further comprising analyzing the second cryptographic key using at least one of a condition associated with the second cryptographic key or a decision rule.

3. The computer-implemented method of claim 1 , wherein the PII data disassociation event includes at least one of exceeding a chronological retention period deadline, a security alert, or a PII data destruction request.

4. The computer-implemented method of claim 1 , wherein the disassociation of the second cryptographic key from the first cryptographic key is performed by at least one of permanently erasing the second cryptographic key, expiring the second cryptographic key, or encrypting the second cryptographic key with a third cryptographic key.

5. The computer-implemented method of claim 4 , wherein the second cryptographic key expires based on a chronological value.

6. The computer-implemented method of claim 4 , wherein the second cryptographic key expires based on a data value.

7. The computer-implemented method of claim 1 , wherein the disassociation of the second cryptographic key from the encrypted first cryptographic key preserves a referential integrity between the encrypted PII data and the non-encrypted associated data.

8. A computer-program product, comprising computer-readable instructions embodied on tangible, non-transitory, computer-readable media, the instructions operable when executed to perform operations to:

encrypt personally-identifiable information (PII) data using a first cryptographic key, wherein the PII data is associated with non-encrypted associated data, and wherein the first cryptographic key is a record key of a data record storing the PII data;

encrypt the first cryptographic key with a second cryptographic key, wherein the second cryptographic key is a purpose key associated with a particular purpose providing a justification for the use of the second cryptographic key to encrypt the first cryptographic key, wherein the second cryptographic key is associated with a cryptographic key record used to associate the second cryptographic key with a purpose key identifier, the particular purpose, and one or more conditions, wherein the purpose key identifier provides a mapping between the particular purpose and the second cryptographic key, and wherein the condition determines whether the second cryptographic key has expired;

determine that the occurrence of a PII data disassociation event associated with the second cryptographic key has occurred; and

render the PII data inaccessible by disassociating the second cryptographic key from the encrypted first cryptographic key.

9. The computer-program product of claim 8 , further comprising analyzing the second cryptographic key using at least one of a condition associated with the second cryptographic key or a decision rule.

10. The computer-program product of claim 8 , wherein the PII data disassociation event includes at least one of exceeding a chronological retention period deadline, a security alert, or a PII data destruction request.

11. The computer-program product of claim 8 , wherein the disassociation of the second cryptographic key from the first cryptographic key is performed by at least one of permanently erasing the second cryptographic key, expiring the second cryptographic key, or encrypting the second cryptographic key with a third cryptographic key.

12. The computer-program product of claim 11 , wherein the second cryptographic key expires based on a chronological value.

13. The computer-program product of claim 11 , wherein the second cryptographic key expires based on a data value.

14. The computer-program product of claim 8 , wherein the disassociation of the second cryptographic key from the encrypted first cryptographic key preserves a referential integrity between the encrypted PII data and the non-encrypted associated data.

15. A system, comprising:

memory operable to store at least personally-identifiable information (PII) data; and

at least one hardware processor interoperably coupled to the memory and operable to:

encrypt the PII data using a first cryptographic key, wherein the PII data is associated with non-encrypted associated data, and wherein the first cryptographic key is a record key of a data record storing the PII data;

encrypt the first cryptographic key with a second cryptographic key, wherein the second cryptographic key is a purpose key associated with a particular purpose providing a justification for the use of the second cryptographic key to encrypt the first cryptographic key, wherein the second cryptographic key is associated with a cryptographic key record used to associate the second cryptographic key with a purpose key identifier, the particular purpose, and one or more conditions, wherein the purpose key identifier provides a mapping between the particular purpose and the second cryptographic key, and wherein the condition determines whether the second cryptographic key has expired;

determine that the occurrence of a PII data disassociation event associated with the second cryptographic key has occurred; and

render the PII data inaccessible by disassociating the second cryptographic key from the encrypted first cryptographic key.

16. The system of claim 15 , further comprising analyzing the second cryptographic key using at least one of a condition associated with the second cryptographic key or a decision rule.

17. The system of claim 15 , wherein the PII data disassociation event includes at least one of exceeding a chronological retention period deadline, a security alert, or a PII data destruction request.

18. The system of claim 15 , wherein the disassociation of the second cryptographic key from the first cryptographic key is performed by at least one of permanently erasing the second cryptographic key, expiring the second cryptographic key, or encrypting the second cryptographic key with a third cryptographic key.

19. The system of claim 18 , wherein the second cryptographic key expires based on a chronological value.

20. The system of claim 18 , wherein the second cryptographic key expires based on a data value.

21. The system of claim 15 , wherein the disassociation of the second cryptographic key from the encrypted first cryptographic key preserves a referential integrity between the encrypted PII data and the non-encrypted associated data.

22. A computer-implemented method, comprising:

encrypting, by operation of a computer, personally-identifiable information (PII) data using a first cryptographic key, wherein the PII data is associated with non-encrypted associated data, and wherein the first cryptographic key is a record key of a data record storing the PII data;

encrypting the first cryptographic key with a second cryptographic key, wherein the second cryptographic key is a purpose key associated with a particular purpose providing a justification for the use of the second cryptographic key to encrypt the first cryptographic key, wherein the second cryptographic key is associated with a cryptographic key record used to associate the second cryptographic key with a purpose key identifier, the particular purpose, and one or more conditions, wherein the purpose key identifier provides a mapping between the particular purpose and the second cryptographic key, and wherein the condition determines whether the second cryptographic key has expired;

analyzing the second cryptographic key using at least one of a condition associated with the second cryptographic key or a decision rule;

determining that the occurrence of a PII data disassociation event associated with the second cryptographic key has occurred, wherein the PII data disassociation event includes at least one of exceeding a chronological retention period deadline, a security alert, or a PII data destruction request; and

rendering the PII data inaccessible by disassociating the second cryptographic key from the encrypted first cryptographic key, wherein the disassociation of the second cryptographic key from the first cryptographic key is performed by at least one of permanently erasing the second cryptographic key, expiring the second cryptographic key, or encrypting the second cryptographic key with a third cryptographic key, and wherein the disassociation of the second cryptographic key from the encrypted first cryptographic key preserves a referential integrity between the encrypted PII data and the non-encrypted associated data.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 24, 2012
From: SCHUETTE, MARK T.; SCHNEIDER, JUERGEN; KHOURY, PAUL EL
To: SAP AG, A GERMAN CORPORATION
Reel/Frame 028847/0441 →