IP Library Granted Patent US 9,785,938
Granted Patent B2
US 9,785,938 · App. 14/563,076 · Granted Oct 10, 2017

Tokenizing sensitive data

Inventors: Bryan T. Bailey (Florence, KY); John Romer (Wilmington, OH); Chris Doyle (Alexandria, KY); Jeremy Gifford (Mason, OH); Kevin Zibart (Pewee Valley, KY)
Assignee: Vantiv, LLC
G06Q20/3829G06F21/60G06Q20/12G06Q20/3823G06Q20/38215H04L9/0891H04L9/3234H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,785,938
App. No.
14/563,076
Granted
Oct 10, 2017
Kind
B2
Abstract

Included are systems and methods for tokenizing sensitive data. Some of the systems and/or methods are configured to receive sensitive data from a vendor, determine a token key for the vendor, and utilize a proprietary algorithm, based on the token key to generate a vendor-specific token that is associated with the sensitive data. Some systems and/or methods include creating a token identifier that comprises data related to the token key sending the vendor-specific token and the token identifier to the vendor.

Claims (67)

1. A method for tokenization of sensitive data, comprising:

receiving, by a tokenization computing device, sensitive data from a vendor computing device associated with a vendor;

determining, by the tokenization computing device, a token key and a token identifier for the sensitive data, wherein the token key is unique to the vendor;

generating, by the tokenization computing device, a vendor-specific token that is associated with the sensitive data, wherein the vendor-specific token is based on at least in part on the token key;

storing, by the tokenization computing device, the vendor-specific token and the token identifier, the token identifier configured to provide token generation data, token version data, token key data, and a validation value;

receiving, by the tokenization computing device, a request to change the vendor-specific token;

generating, by the tokenization computing device, a new token for associating with the sensitive data, wherein the new token is generated utilizing a new token key for a particular vendor;

updating, by the tokenization computing device, the token identifier for the new token, the updated token identifier configured to provide updated token generation data, token version data, token key data, and the validation value;

updating, by the tokenization computing device, the token key to include the updated token version data and the validation value;

generating, by the tokenization computing device, a rollup identifier associated with the vendor-specific token, wherein the rollup identifier provides a pointer to the token key, wherein the token key is common to a plurality of entities; and

sending, by the tokenization computing device, the token identifier and the new token to the vendor computing device using wireless communication.

2. The method of claim 1 , further comprising decrypting, by the tokenization computing device, the sensitive data from the vendor computing device.

3. The method of claim 1 , wherein the sensitive data includes at least one of the following: a credit card number, a card number, and a prepaid card number, a bank account number, a social security number, a telephone number, and an address.

4. The method of claim 1 , further comprising:

receiving, by the tokenization computing device, a request to rotate the new token;

accessing, by the tokenization computing device, a table to determine whether the new token is associated with a rollup identifier;

in response to determining that the new token is associated with the rollup identifier, determining, by the tokenization computing device, a new token key that is utilized for entities in a predetermined group;

updating, by the tokenization computing device, the new token according to the new token key; and

sending, by the tokenization computing device, the updated new token and the token identifier to the vendor.

5. The method of claim 1 , further comprising:

receiving, by the tokenization computing device, an indication of joining of the vendor with a second entity, wherein the indication includes a request to associate the new token with another token from the second entity;

updating, by the tokenization computing device, the token identifier to generate a rollup identifier that points to a common token key for the vendor and the second entity; and

sending, by the tokenization computing device, the updated token and the token identifier to the vendor.

6. A system for tokenization of sensitive data, comprising:

a processor; and

a memory component that is coupled to the computing device and stores logic that when executed by the processor, causes the system to perform at least the following:

receive from a vendor computing device a request to change a vendor-specific token that is associated with sensitive data, wherein the vendor computing device is associated with a vendor, wherein the vendor-specific token is generated based at least in part on a token key that is unique to the vendor, wherein the request is accompanied by a token identifier that is associated with the vendor-specific token, and wherein the vendor-specific token and the token identifier are linked in a database, wherein the token identifier configured to provide token generation data, token version data, token key data, and a validation value;

utilize the token identifier to determine a location of the sensitive data;

retrieve the sensitive data;

generate a new token for associating with the sensitive data, wherein the new token is generated utilizing a new token key for a particular vendor;

update the token identifier for the new token, the updated token identifier configured to provide updated token generation data, token version data, token key data, and the validation value;

update the token key to include the updated token version data and the validation value;

generate a rollup identifier associated with the vendor-specific token, wherein the rollup identifier provides a pointer to the token key, wherein the token key is common to a plurality of entities; and

send the new token and the token identifier to the vendor computing device using wireless communication.

7. The system of claim 6 , wherein the sensitive data includes at least one of the following: a credit card number, a debit card number, a prepaid card number, a social security number, a bank account number, a telephone number, and an address.

8. The system of claim 6 , wherein the logic further causes the system to store the new token and the token identifier.

9. The system of claim 6 , wherein the logic further causes the system to perform at least the following:

receive sensitive data from the vendor computing device;

determine the token key for the vendor;

link the vendor-specific token and the token identifier in the database;

generate the vendor-specific token; and

create the token identifier that comprises data related to the token key.

10. The system of claim 6 , wherein the logic further causes the system to perform at test the following:

Receive a request to rotate the new token;

access a table to determine whether the new token is associated with a rollup identifier;

in response to determining that the new token is associated with a rollup identifier, determine a new token key that is utilized for entities in a predetermined group;

update the new token according to the new token key; and

send the updated new token and the token identifier to the vendor computing device.

11. A non-transitory computer-readable medium for tokenization of sensitive data that stores a program that when executed by a computing device, causes the computing device to perform at least the following:

receive a request to change a token that is associated with sensitive data, wherein the token is generated based at least in part on a token key that is unique to a vendor, wherein the request is accompanied by a token identifier that is associated with the token, and wherein the token and the token identifier are linked in a database, and the token identifier configured to provide token generation data, token version data, token key data, and a validation value:

identify the token key and a version for the token from the token identifier;

generate a new token for associating with the sensitive data, wherein the new token is generated utilizing a new token key for a particular vendor;

update the token identifier, for the new token to reflect a new version of the token, the updated token identifier configured to provide updated token generation data, token version data, token key data, and the validation value;

update the token key to include the updated token version data and the validation value;

generate a rollup identifier associated with the new token, wherein the rollup identifier provides a pointer to a common token key for a plurality of entities; and

send the new token and the token identifier to a vendor computing device using wireless communication.

12. The non-transitory computer-readable medium of claim 11 , wherein the sensitive data includes at least one of the following: a credit card number, a debit card number, a prepaid card number, a bank account number, a social security number, a telephone number, and an address.

13. The non-transitory computer-readable medium of claim 11 , wherein the program further causes the computing device to perform at least the following:

receive a request to rotate the token;

access a table to determine whether the token is associated with a rollup identifier;

in response to determining that the token is associated with a rollup identifier, determine a new token key that is utilized for entities in a predetermined group; and

update the token according to the new token key.

14. The non-transitory computer-readable medium of claim 11 , wherein the program further causes the computing device to store the new token and the token identifier.

15. The non-transitory compute readable medium of claim 11 , wherein the program further causes the computing device to perform at least the following:

receive an indication of joining of the vendor with a second entity, wherein the indication includes a request to associate the token with another token from the second entity;

update the token identifier to generate a rollup identifier that points to a common token key to the vendor and the second entity; and

send the updated token and the token identifier to the vendor computing device.

Assignments (7)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
CHANGE OF NAME Recorded Aug 6, 2018
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 046723/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: BAILEY, BRYAN T.; ROMER, JOHN; DOYLE, CHRIS; GIFFORD, JEREMY; ZIBART, KEVIN
To: FIFTH THIRD PROCESSING SOLUTIONS, LLC
Reel/Frame 039613/0941 →
CHANGE OF NAME Recorded Sep 1, 2016
From: FIFTH THIRD PROCESSING SOLUTIONS, LLC
To: VANTIV, LLC
Reel/Frame 039900/0025 →
Continuity (2)
Continuation 13117599 · May 27, 2011
Related Publication 20150088759A1 · Mar 26, 2015