IP Library Granted Patent US 9,641,519
Granted Patent B2
US 9,641,519 · App. 14/958,712 · Granted May 2, 2017

Table-connected tokenization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,641,519
App. No.
14/958,712
Granted
May 2, 2017
Kind
B2
Abstract

A tokenization system tokenizes sensitive data to prevent unauthorized entities from accessing the sensitive data. The tokenization system accesses sensitive data, and retrieves an initialization vector (IV) from an IV table using a first portion of the sensitive data. A second portion of the sensitive data is modified using the accessed initialization vector. A token table is selected from a set of token tables using a third portion of the sensitive data. The modified second portion of data is used to query the selected token table, and a token associated with the value of the modified second portion of data is accessed. The second portion of the sensitive data is replaced with the accessed token to form tokenized data.

Claims (41)

1. A method for improving the security of data in a tokenization environment, comprising:

receiving data to be tokenized;

selecting a first token table from a first set of token tables using a first portion of the received data;

selecting a second token table from a second set of token tables different than the first set of token tables using a second portion of the received data different than the first portion of the received data, each of the first set of token tables and the second set of token tables mapping each of a plurality of input values to a different token value; and

after selecting the first token table and the second token table, transforming the received data to produce tokenized data by:

querying, by a hardware processor, the first token table with a third portion of the received data to identify a first token value mapped to a value of the third portion of the received data by the first token table;

querying, by the hardware processor, the second token table with the first token value to identify a second token value mapped to the first token value by the second token table; and

replacing, by the hardware processor, the third portion of the received data with the second token value to produce the tokenized data.

2. The method of claim 1 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.

3. The method of claim 1 , wherein the third portion of the received data is modified based on an initialization vector accessed from an initialization vector table before being replaced with the second token value.

4. The method of claim 1 , wherein the first set of token tables and the second set of token tables are each stored on a different server.

5. The method of claim 1 , wherein the first portion, the second portion, and the third portion of the received data do not overlap.

6. The method of claim 1 , wherein the first token table is associated with a value of the first portion of the received data, and wherein the second token table is associated with a value of the second portion of the received data.

7. A tokenization system for improving the security of data in a tokenization environment, comprising:

a non-transitory computer-readable storage medium storing executable computer instructions that, when executed by a processor, perform steps comprising:

receiving data to be tokenized;

selecting a first token table from a first set of token tables using a first portion of the received data;

selecting a second token table from a second set of token tables different than the first set of token tables using a second portion of the received data different than the first portion of the received data, each of the first set of token tables and the second set of token tables mapping each of a plurality of input values to a different token value; and

transforming the received data to product tokenized data by:

querying the first token table with a third portion of the received data to identify a first token value mapped to a value of the third portion of the received data by the first token table;

querying the second token table with the first token value to identify a second token value mapped to the first token value by the second token table; and

replacing the third portion of the received data with the second token value to produce the tokenized data; and

a hardware processor configured to execute the instructions.

8. The system of claim 7 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.

9. The system of claim 7 , wherein the third portion of the received data is modified based on an initialization vector accessed from an initialization vector table before being replaced with the second token value.

10. The system of claim 7 , wherein the first set of token tables and the second set of token tables are each stored on a different server.

11. The system of claim 7 , wherein the first portion, the second portion, and the third portion of the received data do not overlap.

12. The system of claim 7 , wherein the first token table is associated with a value of the first portion of the received data, and wherein the second token table is associated with a value of the second portion of the received data.

13. A non-transitory computer-readable storage medium storing executable instructions that, when executed by a hardware processor, perform steps comprising:

receiving data to be tokenized;

selecting a first token table from a first set of token tables using a first portion of the received data;

selecting a second token table from a second set of token tables different than the first set of token tables using a second portion of the received data different than the first portion of the received data, each of the first set of token tables and the second set of token tables mapping each of a plurality of input values to a different token value; and

after selecting the first token table and the second token table, transforming the received data to produce tokenized data by:

querying, by a hardware processor, the first token table with a third portion of the received data to identify a first token value mapped to a value of the third portion of the received data by the first token table;

querying, by the hardware processor, the second token table with the first token value to identify a second token value mapped to the first token value by the second token table; and

replacing, by the hardware processor, the third portion of the received data with the second token value to produce the tokenized data.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the third portion of the received data is modified based on an initialization vector accessed from an initialization vector table before being replaced with the second token value.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the first set of token tables and the second set of token tables are each stored on a different server.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the first portion, the second portion, and the third portion of the received data do not overlap.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the first token table is associated with a value of the first portion of the received data, and wherein the second token table is associated with a value of the second portion of the received data.

Assignments (3)
SECURITY INTEREST Recorded Aug 2, 2024
From: PROTEGRITY USA, INC.; PROTEGRITY LIMITED HOLDING, LLC; PROTEGRITY US HOLDING, LLC; PROTEGRITY CORPORATION; KAVADO, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 068326/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PROTEGRITY CORPORATION
To: PROTEGRITY US HOLDING, LLC
Reel/Frame 067566/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2016
From: MATTSSON, ULF; ROZENBERG, YIGAL; LEVY, VICHAI
To: PROTEGRITY CORPORATION
Reel/Frame 037888/0798 →