IP Library › Granted Patent US 11,393,046
Granted Patent B1
US 11,393,046 · App. 15/407,797 · Granted Jul 19, 2022

System and method for perpetual rekeying of various data columns with a frequency and encryption strength based on the sensitivity of the data columns

Inventors: Sean McCluskey (Redwood City, CA); Elangovan Shanmugam (Cupertino, CA); Narendra Dandekar (Dublin, CA); Rachit Lohani (Mountain View, CA)
Assignee: Intuit Inc.
G06Q40/123G06F21/602G06F21/6245G06Q2220/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,393,046
App. No.
15/407,797
Granted
Jul 19, 2022
Kind
B1
Abstract

A data management system stores data related to a plurality of users. The data management system initially stores the data in an encrypted format. The data management system automatically periodically re-encrypts the data in accordance with a re-encryption policy. The re-encryption policy includes re-encryption periodicity data defining a periodicity for automatically re-encrypting the data.

Claims (32)

1. A system comprising:

at least one processor; and

at least one memory storing instructions that, when executed by the at least one processor, cause the system to perform operations including:

retrieving data related to a plurality of individuals;

organizing the data into data columns each indicating a different type of information related to the plurality of individuals;

encrypting each of the data columns based on a sensitivity of the respective type of information, wherein a level of encryption strength used for the encrypting is higher for data columns indicating high-sensitivity information than for data columns indicating low-sensitivity information;

assigning, to each respective data column, a re-encryption periodicity that determines how often the system will re-encrypt the data indicated by the respective data column, wherein a less frequent re-encryption periodicity is assigned to data columns indicating low-sensitivity information than for data columns indicating high-sensitivity information, and wherein a more frequent re-encryption periodicity is assigned to data columns encrypted with a high level of encryption strength than for data columns encrypted with a low level of encryption strength; and

automatically and continuously re-encrypting each respective data column wherein the re-encrypting includes, for each respective data column:

retrieving the respective data column according to the respective data column's assigned re-encryption periodicity;

decrypting the respective data column based on the level of encryption strength used to encrypt the respective data column;

assigning a new encryption periodicity to the respective data column, wherein the new encryption periodicity specifies a maximum period of time that can elapse before the respective data column will again be re-encrypted;

selecting a unique encryption strength for the respective data column based on a selected threshold probability that a fraudster could break the unique encryption strength before the maximum period of time elapses, wherein the selected unique encryption strength is different than any previous encryption strength selected for the respective data column; and

re-encrypting the respective data column based on the new encryption periodicity and the unique encryption strength.

2. The system of claim 1 , wherein each of the data columns is encrypted using a number of encryption keys.

3. The system of claim 1 , wherein the different types of information include at least one of a user name, a date of birth, a government identification, a home address, a zip code, a home ownership status, a marital status, an income, a tax refund, a tax liability, a tax return, a job title, an employer, a tax deduction, a tax withholding, a retirement plan, a dependent child, a spouse, a financial asset, or a medical history.

4. The system of claim 1 , wherein each of the data columns relates to a financial management data type.

5. The system of claim 1 , wherein the system is at least one of a tax return preparation system, a payroll management system, a budgeting system, a book keeping system, or a financial transaction monitoring system.

6. A method performed by one or more processors of a system and comprising:

retrieving data related to a plurality of individuals;

organizing the data into data columns each indicating a different type of information related to the plurality of individuals;

encrypting each of the data columns based on a sensitivity of the respective type of information, wherein a level of encryption strength used for the encrypting is higher for data columns indicating high-sensitivity information than for data columns indicating low-sensitivity information;

assigning, to each respective data column, a re-encryption periodicity that determines how often the system will re-encrypt the data indicated by the respective data column, wherein a less frequent re-encryption periodicity is assigned to data columns indicating low-sensitivity information than for data columns indicating high-sensitivity information, and wherein a more frequent re-encryption periodicity is assigned to data columns encrypted with a high level of encryption strength than for data columns encrypted with a low level of encryption strength; and

automatically and continuously re-encrypting each respective data column, wherein the re-encrypting includes, for each respective data column:

retrieving the respective data column according to the respective data column's assigned re-encryption periodicity;

decrypting the respective data column based on the level of encryption strength used to encrypt the respective data column;

assigning a new encryption periodicity to the respective data column, wherein the new encryption periodicity specifies a maximum period of time that can elapse before the respective data column will again be re-encrypted;

selecting a unique encryption strength for the respective data column based on a selected threshold probability that a fraudster could break the unique encryption strength before the maximum period of time elapses, wherein the selected unique encryption strength is different than any previous encryption strength selected for the respective data column; and

re-encrypting the respective data column based on the new encryption periodicity and the unique encryption strength.

7. The method of claim 6 , wherein each of the data columns is encrypted using a number of encryption keys.

8. The method of claim 6 , wherein the different types of information include at least one of a user name, a date of birth, a government identification, a home address, a zip code, a home ownership status, a marital status, an income, a tax refund, a tax liability, a tax return, a job title, an employer, a tax deduction, a tax withholding, a retirement plan, a dependent child, a spouse, a financial asset, or a medical history.

9. The method of claim 6 , wherein each of the data columns relates to a financial management data type.

10. The method of claim 6 , wherein the system is at least one of a tax return preparation system, a payroll management system, a budgeting system, a book keeping system, or a financial transaction monitoring system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2017
From: MCCLUSKEY, SEAN; SHANMUGAM, ELANGOVAN; DANDEKAR, NARENDRA; LOHANI, RACHIT
To: INTUIT INC.
Reel/Frame 040988/0630 →
Cited By (1)
US 12,450,364