IP Library Granted Patent US 9,722,973
Granted Patent B1
US 9,722,973 · App. 13/939,577 · Granted Aug 1, 2017

System and method to anonymize data transmitted to a destination computing device

Inventors: Pravin Kothari (San Jose, CA); Debabrata Dash (San Jose, CA)
Assignee: CIPHERCLOUD, INC.
H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,722,973
App. No.
13/939,577
Granted
Aug 1, 2017
Kind
B1
Abstract

A method and system for a distributed anonymization system is disclosed. A master anonymization system is provided. A slave anonymization system is configured to communicate with the master anonymization system, wherein the master anonymization system permits the slave anonymization system to perform one or more functions. The slave anonymization system is configured receives a request from a user computer that requires slave anonymization system to perform a function. The performance of the function requires either storage of data to a data store in a destination computing device or retrieval of data from the data store in the destination computing device, wherein the data is stored or retrieved in an anonymized form. The slave anonymization system verifies if the function to be performed is a permitted function. If it is a permitted function, the function is performed.

Claims (69)

1. A method for anonymizing data to be stored in a destination computing device, comprising:

receiving data to be stored in the destination computing device from a user computer;

providing a communication link between a master anonymization system and a slave anonymization system, wherein the master anonymization system configured to perform selective anonymization of the received data and wherein the slave anonymization system configured to perform selective anonymization of the received data, if permitted;

permitting slave anonymization system to perform one or more functions, permitting enabled by the master anonymization system;

receiving data to be stored by the slave anonymization system, the data including a plurality of fields of data;

selecting one or more fields of data for anonymization by the slave anonymization system;

verifying if anonymizing one or more selected fields of data is a permitted function of the slave anonymization system;

anonymizing the selected one or more fields of data by the slave anonymization system, if permitted;

transmitting data with anonymized one or more fields of data, to the destination computing device for storage in the destination computing device;

receiving a selectively retrieved anonymized data by the slave anonymization system in response to a request;

de-anonymizing the retrieved anonymized data by the slave anonymization system; and

returning the de-anonymized data by the slave anonymization system, in response to the request.

2. The method of claim 1 , wherein if anonymizing the selected one or more fields of data is not a permitted function of the slave anonymization system, sending received data to be stored in the destination computer to the master anonymization system for anonymization.

3. The method of claim 1 , wherein anonymizing the selected one or more fields of data further including,

requesting assignment of a function module by the slave anonymization system to perform the permitted function; and

performing the anonymization by the slave anonymization system using the assigned function module.

4. The method of claim 3 , wherein the assigned function module of the slave anonymization system communicates with the master anonymization system to perform the anonymization.

5. The method of claim 1 , wherein selecting one or more fields further including:

determining a format for the received data by a transmit data parser executed in the slave anonymization system; and

identifying one or more fields of data based on determined format by the transmit data parser.

6. The method of claim 5 , wherein the format for the received data indicates a message to a database.

7. The method of claim 5 , wherein the format for the received data indicates an email message.

8. The method of claim 1 , further including:

determining a value of a field of data; and

determining a type of anonymization for the data, based on the value of the field of data.

9. The method of claim 1 , further including:

determining a type of a field of data; and

determining a type of anonymization for the data, based on the type of the field of data.

10. The method of claim 8 , further including scanning the data in the field of data for malware, based on the value of the field of data.

11. The method of claim 9 , further including scanning the data in the field of data for malware, based on the type of the field of data.

12. The method of claim 8 , wherein the value of the field of data is indicative of a selective group and a set of anonymization strategy associated with the selective group is selected for anonymization.

13. The method of claim 9 , wherein determining the type of anonymization further including selecting a different destination computing device for storing a portion of the received data.

14. The method of claim 2 , further including

receiving data with anonymized one or more fields of data from the destination computing device; and

de-anonymizing the received data with anonymized one or more fields of data by the master anonymization system.

15. An anonymization system to anonymize data to be stored in a destination computing device, comprising:

a master anonymization system executed on a computing device and configured to perform selective anonymization of the data received from a user computer for storage in the destination computing device;

a slave anonymization system configured to communicate with the master anonymization system, the slave anonymization system configured to perform selective anonymization of the received data, wherein the master anonymization system selectively permits the slave anonymization system to perform one or more functions,

wherein the slave anonymization system is configured to

receive data to be stored in the destination computing device, the data including a plurality of fields of data;

select one or more fields of data for anonymization;

verify if anonymization of one or more selected fields of data is a permitted function of the slave anonymization system;

anonymize the selected one or more fields of data by the slave anonymization system if permitted;

transmit data with anonymized one or more fields of data, to the destination computing device for storage in the destination computing device: and

wherein the slave anonymization system further configured to receive a selectively retrieved anonymized data in response to a request;

de-anonymize the retrieved anonymized data; and

return the de-anonymized data, in response to the request.

16. The system of claim 15 , wherein if anonymization of the selected one or more fields of data is not a permitted function of the slave anonymization system, received data to be stored in the destination computer is sent to the master anonymization system for anonymization.

17. The system of claim 15 , further including,

slave anonymization system requests assignment of a function module from the master anonymization system to perform the permitted function; and

perform the anonymization using the assigned function module.

18. The system of claim 17 , wherein the assigned function module of the slave anonymization system communicates with the master anonymization system to perform the anonymization.

19. The system of claim 15 , wherein the slave anonymization system is configured to determine a format for the received data by a transmit data parser executed in the slave anonymization system; and

identify one or more fields of data based on the determined format by the transmit data parser.

20. The system of claim 15 , wherein

the slave anonymization system is configured to

determine a value of a field of data; and

determine a type of anonymization for the data, based on the value of the field of data.

21. The system of claim 15 , wherein

the slave anonymization system is configured to

determine a type of a field of data; and

determine a type of anonymization for the data, based on the type of the field of data.

22. The system of claim 20 , wherein, based on the value of the field of data, the data in the field of data is selectively scanned for malware by a malware detection program.

23. The system of claim 20 , wherein the value of the field of data is indicative of a selective group and a set of anonymization strategy associated with the selective group is selected for anonymization.

24. The system of claim 21 , wherein the slave anonymization system selects a different destination computing device to store a portion of the received data, based on the type of the field of data.

25. The system of claim 16 , wherein the master anonymization system further configured to receive a selectively retrieved anonymized data in response to a request;

de-anonymize the retrieved anonymized data; and

return the de-anonymized data, in response to the request.

26. The system of claim 15 , wherein the anonymized data is configured to be searchable using anonymized keyword.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2025
From: LOOKOUT, INC.
To: FORTRA, LLC
Reel/Frame 071659/0726 →
RELEASE OF SECURITY INTEREST Recorded May 14, 2025
From: MIDCAP FINANCIAL TRUST
To: LOOKOUT, INC.
Reel/Frame 071115/0227 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: CIPHERCLOUD, LLC.
To: LOOKOUT, INC.
Reel/Frame 059522/0738 →
MERGER AND CHANGE OF NAME Recorded Apr 6, 2022
From: CIPHERCLOUD, INC.; CIPHERCLOUD ACQUISITION, LLC
To: CIPHERCLOUD, LLC.
Reel/Frame 059522/0690 →
SECURITY INTEREST Recorded Mar 16, 2021
From: CIPHERCLOUD, INC.
To: SILICON VALLEY BANK
Reel/Frame 055606/0608 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2013
From: KOTHARI, PRAVIN; DASH, DEBABRATA
To: CIPHERCLOUD, INC.
Reel/Frame 030778/0661 →
Continuity (3)
Continuation In Part 13843925 · Mar 15, 2013
Continuation In Part 13042459 · Mar 8, 2011
Continuation In Part 13323821 · Dec 13, 2011