IP Library Granted Patent US 9,323,818
Granted Patent B1
US 9,323,818 · App. 14/247,147 · Granted Apr 26, 2016

System and method to anonymize data transmitted to a destination computing device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,323,818
App. No.
14/247,147
Granted
Apr 26, 2016
Kind
B1
Abstract

A method and system for anonymizing data to be transmitted to a destination computing device is disclosed. An anonymization strategy module is executed on a computing device to store anonymization strategy for data anonymization in a data store. A logic configured to receive data from a user computer, to be stored in the destination computing device. An anonymization module is executed on the computing device to selectively anonymize data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored. Anonymized data is transmitted to the destination computing device for storage, over a network.

Claims (102)

1. An anonymization system to anonymize data transmitted to a destination computing device, comprising:

an anonymization strategy module executed on a computing device to store anonymization strategy for data anonymization in a data store for a data including a plurality of data fields, to be stored in the destination computing device;

a logic to receive data to be stored in the destination computing device, from a user computer; and

an anonymization module executed on the computing device to selectively anonymize one or more data fields of the data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored to generate anonymized data with one or more anonymized data fields and transmit the anonymized data with one or more anonymized data fields to the destination computing device for storage over a network,

wherein the anonymization strategy includes anonymization based on at least one or both of tokenization and encryption; and

wherein the anonymization based on tokenization includes at least one of random token anonymization, sortable token anonymization and case-insensitive searchable anonymization.

2. The system of claim 1 , further including storing anonymized data with one or more anonymized data fields at a data store in the destination computing device.

3. The system of claim 2 , wherein the destination computing device is configured to

receive a request for the stored anonymized data;

execute the request to selectively retrieve the stored anonymized data; and

return the selectively retrieved stored anonymized data in response to the request.

4. The system of claim 3 , wherein the system further including:

a de-anonymization module configured to

receive the selectively retrieved anonymized data in response to the request;

de-anonymize the retrieved stored anonymized data; and

return the de-anonymized data in response to the request.

5. The system of claim 1 further including a management console module executed on the computing device, configured to receive meta data for an application executed on the destination computing device, meta data indicative of one or more data fields of the application;

present at least one data field of the application along with a plurality of anonymization strategies for selection;

associate one of the anonymization strategy to the at least one data field of the application, based on the selection; and

store the associated anonymization strategy for the at least one data field of the application, using the anonymization strategy module.

6. The system of claim 5 , wherein the anonymization module retrieves stored anonymization strategy for one or more data fields of the data to be transmitted;

performs the anonymization of original data in one or more data fields based on the retrieved anonymization strategy for the one or more data fields; and

assemble data to be transmitted, using anonymized data fields.

7. The system of claim 6 , wherein the anonymized data is configured to preserve the order of the original data.

8. The system of claim 6 , wherein the anonymized data is configured to be searchable using anonymized keyword.

9. An anonymization system to anonymize data transmitted to a destination computing device, comprising:

an anonymization strategy module executed on a computing device to store anonymization strategy for data anonymization in a data store for a data including a plurality of data fields, to be stored in the destination computing device;

a logic to receive data to be stored in the destination computing device, from a user computer; and

an anonymization module executed on the computing device to selectively anonymize one or more data fields of the data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored to generate anonymized data with one or more anonymized data fields and transmit the anonymized data with one or more anonymized data fields to the destination computing device for storage over a network,

wherein the anonymization strategy includes anonymization based on at least one or both of tokenization and encryption; and

wherein the anonymization based on encryption includes at least one of encryption that permits exact word matching search, encryption that permits search and encryption that permits partial string and wild card searches.

10. The system of claim 9 , further including storing anonymized data with one or more anonymized data fields at a data store in the destination computing device.

11. The system of claim 10 , wherein the destination computing device is configured to

receive a request for the stored anonymized data;

execute the request to selectively retrieve the stored anonymized data; and

return the selectively retrieved stored anonymized data in response to the request.

12. The system of claim 11 , wherein the system further including:

a de-anonymization module configured to receive the selectively retrieved anonymized data in response to the request;

de-anonymize the retrieved stored anonymized data; and

return the de-anonymized data in response to the request.

13. The system of claim 9 further including a management console module executed on the computing device, configured to

receive meta data for an application executed on the destination computing device, meta data indicative of one or more data fields of the application;

present at least one data field of the application along with a plurality of anonymization strategies for selection;

associate one of the anonymization strategy to the at least one data field of the application, based on the selection; and

store the associated anonymization strategy for the at least one data field of the application, using the anonymization strategy module.

14. The system of claim 13 , wherein the anonymization module retrieves stored anonymization strategy for one or more data fields of the data to be transmitted;

performs the anonymization of original data in one or more data fields based on the retrieved anonymization strategy for the one or more data fields; and

assemble data to be transmitted, using anonymized data fields.

15. The system of claim 14 , wherein the anonymized data is configured to preserve the order of the original data.

16. The system of claim 15 , wherein the anonymized data is configured to be searchable using anonymized keyword.

17. A method for anonymizing data to be transmitted to a destination computing device, comprising:

providing anonymization strategy for data anonymization for a data to be stored in the destination computing device, the data including a plurality of data fields, the anonymization strategy provided on a data store in a computing device;

receiving the data to be stored in the destination computing device, from a user computer;

performing selective anonymization of one or more data fields of the data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored, using an anonymization module to generate anonymized data with one or more anonymized data fields; and

transmitting anonymized data with one or more anonymized data fields to the destination computing device for storage, over a network,

wherein the anonymization strategy includes anonymization based on at least one or both of tokenization and encryption; and

wherein the anonymization based on tokenization includes at least one of random token anonymization, sortable token anonymization and case-insensitive searchable anonymization.

18. The method of claim 17 , further including:

storing anonymized data with one or more anonymized data fields at a data store in the destination computing device.

19. The method of claim 18 , further including:

receiving a request at the destination computing device for the stored anonymized data;

executing the request at the destination computing device to selectively retrieve stored anonymized data; and

returning the selectively retrieved stored anonymized data, in response to the request.

20. The method of claim 19 , further including:

receiving selectively retrieved anonymized data in response to the request;

de-anonymizing the retrieved stored anonymized data using a de-anonymization module; and

returning the de-anonymized data in response to the request.

21. The method of claim 17 , wherein providing anonymization strategy for data anonymization in the computing device further including:

receiving meta data for an application executed on the destination computing device, meta data indicative of one or more data fields of the application;

presenting at least one data field of the application along with a plurality of anonymization strategies for selection;

associating one of the anonymization strategy to the at least one data field of the application, based on the selection; and

storing the associated anonymization strategy for the at least one data field of the application.

22. The method of claim 21 , wherein performing selective anonymization further including:

retrieving stored anonymization strategy for one or more data fields of the data to be transmitted;

performing the anonymization of one or more data fields based on the retrieved anonymization strategy for the one or more data fields; and

assembling data to be transmitted, using anonymized data fields.

23. A method for anonymizing data to be transmitted to a destination computing device, comprising:

providing anonymization strategy for data anonymization for a data to be stored in the destination computing device, the data including a plurality of data fields, the anonymization strategy provided on a data store in a computing device;

receiving the data to be stored in the destination computing device, from a user computer;

performing selective anonymization of one or more data fields of the data to be stored in the destination computing device, based on the anonymization strategy for the data to be stored, using an anonymization module to generate anonymized data with one or more anonymized data fields; and

transmitting anonymized data with one or more anonymized data fields to the destination computing device for storage, over a network,

wherein the anonymization strategy includes anonymization based on at least one or both of tokenization and encryption; and

wherein the anonymization based on encryption includes at least one of encryption that permits exact word matching search, encryption that permits search and encryption that permits partial string and wild card searches.

24. The method of claim 23 , further including:

storing anonymized data with one or more anonymized data fields at a data store in the destination computing device.

25. The method of claim 24 , further including:

receiving a request at the destination computing device for the stored anonymized data;

executing the request at the destination computing device to selectively retrieve stored anonymized data; and

returning the selectively retrieved stored anonymized data, in response to the request.

26. The method of claim 25 , further including:

receiving selectively retrieved anonymized data in response to the request;

de-anonymizing the retrieved stored anonymized data using a de-anonymization module; and

returning the de-anonymized data in response to the request.

27. The method of claim 23 , wherein providing anonymization strategy for data anonymization in the computing device further including:

receiving meta data for an application executed on the destination computing device, meta data indicative of one or more data fields of the application;

presenting at least one data field of the application along with a plurality of anonymization strategies for selection;

associating one of the anonymization strategy to the at least one data field of the application, based on the selection; and

storing the associated anonymization strategy for the at least one data field of the application.

28. The method of claim 27 , wherein performing selective anonymization further including:

retrieving stored anonymization strategy for one or more data fields of the data to be transmitted;

performing the anonymization of one or more data fields based on the retrieved anonymization strategy for the one or more data fields; and

assembling data to be transmitted, using anonymized data fields.

Assignments (14)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2025
From: LOOKOUT, INC.
To: FORTRA, LLC
Reel/Frame 071659/0726 →
RELEASE OF SECURITY INTEREST Recorded May 14, 2025
From: MIDCAP FINANCIAL TRUST
To: LOOKOUT, INC.
Reel/Frame 071115/0227 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: CIPHERCLOUD, LLC.
To: LOOKOUT, INC.
Reel/Frame 059522/0738 →
MERGER AND CHANGE OF NAME Recorded Apr 6, 2022
From: CIPHERCLOUD, INC.; CIPHERCLOUD ACQUISITION, LLC
To: CIPHERCLOUD, LLC.
Reel/Frame 059522/0690 →
SECURITY INTEREST Recorded Mar 16, 2021
From: CIPHERCLOUD, INC.
To: SILICON VALLEY BANK
Reel/Frame 055606/0608 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2021
From: KOTHARI, PRAVIN; TOCK, THERON; SOUNG, YUH-WEN; DASH, DEBABRATA
To: CIPHERCLOUD, INC.
Reel/Frame 054831/0001 →