IP Library Granted Patent US 11,228,566
Granted Patent B1
US 11,228,566 · App. 13/929,784 · Granted Jan 18, 2022

System and method to anonymize data transmitted to a destination computing device

Inventors: Pravin Kothari (San Jose, CA); Debabrata Dash (San Jose, CA)
Assignee: Ciphercloud, Inc.
H04L63/0421
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,228,566
App. No.
13/929,784
Granted
Jan 18, 2022
Kind
B1
Abstract

A method and system for anonymizing data to be transmitted to a destination computing device is disclosed. Anonymization strategy for data anonymization is provided. Data to be transmitted is received from a user computer. Selective anonymization of the data is performed, based on the anonymization strategy, using an anonymization module. The data includes a plurality of characters. An order indicator data indicative of the order of the received data is generated. The received data is anonymized to derive an anonymized data. The anonymized data and the order indicator data is transmitted to the destination computer over a network. In one embodiment, a portion of the anonymized data is selected as a search ID. A cross reference between a search key indicative of a portion of the received data and the corresponding search ID is stored.

Claims (63)

1. A method for anonymizing data to be transmitted to a destination computing device, comprising:

receiving data to be transmitted to the destination from a user computer, the data including a plurality of characters defining a clear data in a first base encoding scheme;

anonymizing the data using an anonymization module to derive an interim anonymized data in a different second base encoding scheme by at least using an initialization vector;

generating an order indicator data indicative of the order of the received clear data that corresponds to the anonymized data by using one or more order preserving anonymization functions such that the order indicator data preserves the order of the clear data after de-anonymizing the anonymized data using a regenerated initialization vector to derive the clear data; and

transmitting the order indicator data along with the anonymized data to the destination computing device over a network.

2. The method of claim 1 , wherein generating an order indicator data further including:

providing an order preserving hash function;

generating a hash value by hashing the received data and the order preserving hash function, wherein the hash value is indicative of the order of the received data; and

designating the hash value as the order indicator data.

3. The method of claim 1 , wherein generating an order indicator data further including:

generating an order preserving token that corresponds to the received data; and

designating the order preserving token as the order indicator data.

4. The method of claim 1 , wherein generating an order indicator data further including:

anonymizing the received data using an order preserving anonymization system to generate an anonymized data that is indicative of the order of the received data; and

designating the generated anonymized data that is indicative of the order of the received data as the order indicator data.

5. The method of claim 1 , further including:

receiving a request to sort the anonymized data stored at the destination computing device; and

sorting the anonymized data based on the corresponding order indicator data.

6. The method of claim 1 , further including:

selecting a portion of the anonymized data as a search ID;

storing in a data store, a cross reference between a search key indicative of a portion of the received data and the corresponding search ID.

7. The method of claim 6 , further including:

receiving a request to search the anonymized data stored at the destination computing device, using a search term;

retrieving search ID that corresponds to the search key matching the search term;

sending a search request to the destination computing device to retrieve selective anonymized data wherein the search ID matches with the portion of the anonymized data;

receiving selective anonymized data;

deanonymizing the received anonymized data; and

returning the deanonymized data that matches the search term as a response to the search request.

8. The method of claim 6 , further including:

providing a search ID field marker to indicate the beginning of the selected portion of the anonymized data; and

transmitting the search ID field marker along with the anonymized data to the destination computing device.

9. An anonymization system to anonymize data transmitted to a destination computing device, comprising:

an anonymization strategy module of the anonymization system executed on a computing device, the anonymization strategy module configured to store anonymization strategy for data anonymization in a memory storage;

a logic to receive data to be transmitted to the destination computing device from a user computer, wherein the received data including a plurality of characters defining a clear data in a first base encoding scheme;

an anonymization module to anonymize the data based on an anonymization strategy to derive an interim anonymized data in a different second base encoding scheme by at least using an initialization vector;

an order indicator generator to generate an order indicator data indicative of the order of the received data that corresponds to the anonymized data by using one or more order preserving anonymization functions such that the order indicator data preserves the order of the clear data after de-anonymizing the anonymized data using a regenerated initialization vector to derive the clear data; and

transmit the order indicator data along with the anonymized data to the destination computing device over a network.

10. The system of claim 9 , wherein the order indicator generator

receives an order preserving hash function;

generates a hash value by hashing the received data and an order preserving hash function; and

designates the generated hash value as the order indicator data for the received data.

11. The system of claim 9 , wherein the order indicator generator

generates an order preserving token that corresponds to the received data; and

designates the order preserving token as the order indicator data.

12. The system of claim 9 , wherein the order indicator generator

generates an order preserved anonymized data of the received data, wherein the generated order preserved anonymized data preserves the order of the received data; and

designates the order preserved anonymized data as the order indicator data.

13. The system of claim 9 , further including:

a request to sort the anonymized data stored at the destination computing device is received; and

the anonymized data is sorted based on the corresponding order indicator data.

14. The system of claim 9 , further including:

select a portion of the anonymized data as a search ID;

store in a data store, a cross reference between a search key indicative of a portion of the received data and the corresponding search ID.

15. The system of claim 14 , further configured to:

receive a request to search the anonymized data stored at the destination computing device, using a search term;

retrieve search ID that corresponds to the search key matching the search term;

send a search request to the destination computing device to retrieve selective anonymized data wherein the search ID matches with the portion of the anonymized data;

receive selective anonymized data;

deanonymize the received anonymized data; and

return the deanonymized data that matches the search term as a response to the search request.

16. The system of claim 14 , further configured to:

provide a search ID field marker to indicate the beginning of the selected portion of the anonymized data; and

transmit the search ID field marker along with the anonymized data to the destination computing device.

Assignments (12)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2025
From: LOOKOUT, INC.
To: FORTRA, LLC
Reel/Frame 071659/0726 →
RELEASE OF SECURITY INTEREST Recorded May 14, 2025
From: MIDCAP FINANCIAL TRUST
To: LOOKOUT, INC.
Reel/Frame 071115/0227 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: CIPHERCLOUD, LLC.
To: LOOKOUT, INC.
Reel/Frame 059522/0738 →
MERGER AND CHANGE OF NAME Recorded Apr 6, 2022
From: CIPHERCLOUD, INC.; CIPHERCLOUD ACQUISITION, LLC
To: CIPHERCLOUD, LLC.
Reel/Frame 059522/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 28, 2013
From: KOTHARI, PRAVIN; DASH, DEBABRATA
To: CIPHERCLOUD,INC.
Reel/Frame 030707/0233 →