IP Library Granted Patent US 8,631,229
Granted Patent B2
US 8,631,229 · App. 13/633,106 · Granted Jan 14, 2014

Differential client-side encryption of information originating from a client

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,229
App. No.
13/633,106
Granted
Jan 14, 2014
Kind
B2
Abstract

A method may include allocating a number of public keys, where each respective public key is allocated to a respective entity of a number of entities; storing a number of private keys, where each respective private corresponds to a respective public key; storing one or more decryption algorithms, where each respective decryption algorithm is configured to decrypt data previously encrypted using at least one encryption algorithm of the encryption algorithms. Each respective encryption algorithm may be configured to encrypt data using at least one public key. Each respective decryption algorithm may be configured to decrypt data using at least one private key. The method may include receiving encrypted data, where the encrypted data is encrypted using a first public key and a first encryption algorithm, and the encrypted data is provided over a network.

Claims (36)

1. A method comprising:

allocating, by a processor of a first computing device, a plurality of public keys, wherein each respective public key of the plurality of public keys is allocated to a respective entity of a plurality of entities;

storing, in a memory of the first computing device, a plurality of private keys, wherein each respective private key of the plurality of private keys corresponds to a respective public key of the plurality of public keys;

storing, in the memory of the first computing device, one or more decryption algorithms, wherein

each respective decryption algorithm of the one or more decryption algorithms is configured to decrypt data previously encrypted using at least one encryption algorithm of one or more encryption algorithms, wherein each respective encryption algorithm of the one or more encryption algorithms is configured to encrypt data using at least one public key of the plurality of public keys, and

each respective decryption algorithm of the one or more decryption algorithms is configured to decrypt data using at least one private key of the plurality of private keys;

receiving encrypted data, wherein

the encrypted data is encrypted using a first public key of the plurality of public keys and a first encryption algorithm of the one or more encryption algorithms, and

the encrypted data is provided over a network;

determining, by the processor of the first computing device, a first private key of the plurality of private keys, wherein

the first private key corresponds to the first public key, and

the first public key is allocated to a first entity of the plurality of entities;

decrypting, by the processor of the first computing device, the encrypted data using the first private key and at least one decryption algorithm of the one or more decryption algorithms, wherein

decrypted data is obtained by decrypting the encrypted data;

providing a portion of the decrypted data for processing by a processing engine, wherein a second computing device comprises the processing engine;

receiving a processing result generated by the processing engine, wherein the processing result relates to the portion of the decrypted data; and

providing, over the network, the processing result to the first entity.

2. The method of claim 1 , further comprising, prior to providing the portion of the decrypted data for processing by the processing engine, queuing, by the processor of the first computing device, the decrypted data for processing.

3. The method of claim 1 , further comprising, prior to receiving the encrypted data:

receiving a download request for the first encryption algorithm, wherein the download request is received across the network from a third computing device; and

providing the first encryption algorithm, via the network to the third computing device.

4. The method of claim 3 , wherein the download request comprises a hypertext transfer protocol request.

5. The method of claim 3 , further comprising:

storing, in the memory of the first computing device, the one or more encryption algorithms as one or more encryption subprograms, wherein

providing the first encryption algorithm comprises providing a first encryption subprogram of the one or more encryption subprograms, wherein the first encryption subprogram comprises the first encryption algorithm.

6. The method of claim 5 , wherein the first encryption subprogram comprises runtime interpreted instructions.

7. The method of claim 1 , further comprising storing at least one of the decrypted data and the encrypted data in a storage archive accessible to the first computing device.

8. The method of claim 1 , further comprising:

receiving, over the network, unencrypted data, wherein the unencrypted data is related to the encrypted data; and

providing a portion of the unencrypted data for processing by the processing engine, wherein the portion of the unencrypted data is provided with the portion of the decrypted data.

9. The method of claim 1 , further comprising receiving, over the network, an indication of a type of processing to be performed on the encrypted data, wherein the indication of the type of processing is provided by a third computing device controlled by the first entity.

10. The method of claim 9 , wherein the type of processing comprises at least one of a credit card authorization and a background check.

11. The method of claim 9 , wherein the encrypted data comprises one or more of credit card information, medical history information, Social Security number, bank account number, and driver's license number.

12. The method of claim 1 , wherein

the encrypted data is provided over the network from a third computing device controlled by the first entity; and

the first entity is incapable of decrypting the encrypted data.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2015
From: EBAY INC.
To: PAYPAL, INC.
Reel/Frame 036170/0140 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2014
From: BRAINTREE PAYMENT SOLUTIONS, LLC
To: EBAY INC.
Reel/Frame 032328/0038 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2012
From: MANGES, DANIEL
To: BRAINTREE PAYMENT SOLUTIONS, LLC
Reel/Frame 029546/0180 →