IP Library › Granted Patent US 10,313,315
Granted Patent B2
US 10,313,315 · App. 15/686,762 · Granted Jun 4, 2019

Ensuring information security in data transfers by utilizing proximity keys

Inventor: Manu Kurian (Dallas, TX)
Assignee: Bank of America Corporation
H04L63/0464H04L9/08H04L9/14H04L63/08H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,313,315
App. No.
15/686,762
Granted
Jun 4, 2019
Kind
B2
Abstract

Aspects of the disclosure relate to ensuring information security in data transfers by utilizing proximity keys. A computing platform may receive a data collection comprising one or more data sets to be transferred to one or more remote recipient systems, as well as one or more transfer path specifications defining a specific sequence of hop points via which the data collection is to be transferred. Subsequently, the computing platform may receive, from a quorum of authorization devices, a plurality of authorization keys. Based on validating the plurality of authorization keys, the computing platform may encrypt the data collection using the plurality of authorization keys. Then, the computing platform may send the encrypted data collection to a first hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications, so as to initiate a transfer of the data collection to a decryption platform.

Claims (56)

1. A computing platform, comprising:

at least one hardware processor;

a communication interface communicatively coupled to the at least one hardware processor; and

memory storing computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to:

receive, via the communication interface, from a first data source user computing device, a data collection comprising one or more data sets to be transferred to one or more remote recipient computer systems;

receive, via the communication interface, from the first data source user computing device, one or more transfer path specifications defining a specific sequence of hop points via which the data collection comprising the one or more data sets is to be transferred to the one or more remote recipient computer systems;

receive, via the communication interface, from a quorum of authorization devices, a plurality of authorization keys;

validate the plurality of authorization keys received from the quorum of authorization devices;

based on validating the plurality of authorization keys received from the quorum of authorization devices, encrypt the data collection comprising the one or more data sets using the plurality of authorization keys received from the quorum of authorization devices to produce an encrypted data collection; and

send, via the communication interface, to a first hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications, the encrypted data collection to initiate a transfer of the data collection comprising the one or more data sets to a data decryption computing platform comprising one or more computing devices.

2. The computing platform of claim 1 , wherein the first data source user computing device is linked to a first user associated with a first organization, and wherein the quorum of authorization devices comprises the first data source user computing device and at least one other registered user computing device linked to a second user associated with the first organization.

3. The computing platform of claim 2 , wherein the quorum of authorization devices comprises at least half of all available authorization devices associated with the first organization.

4. The computing platform of claim 2 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one hardware processor, cause the computing platform to:

prior to receiving the plurality of authorization keys from the quorum of authorization devices:

identify one or more available authorization devices associated with the first organization;

generate one or more authorization prompts for the one or more available authorization devices associated with the first organization; and

send, via the communication interface, to the one or more available authorization devices associated with the first organization, the one or more authorization prompts generated for the one or more available authorization devices associated with the first organization.

5. The computing platform of claim 4 , wherein a first authorization key of the plurality of authorization keys received from the quorum of authorization devices is a biometric authorization key encoded with biometric information specific to a first authorization device that returned the first authorization key in response to a first authorization prompt.

6. The computing platform of claim 5 , wherein a second authorization key of the plurality of authorization keys received from the quorum of authorization devices is a geo-location authorization key encoded with geo-location information specific to a second authorization device that returned the second authorization key in response to a second authorization prompt.

7. The computing platform of claim 6 , wherein a third authorization key of the plurality of authorization keys received from the quorum of authorization devices is a device-signature authorization key encoded with device-signature information specific to a third authorization device that returned the third authorization key in response to a third authorization prompt.

8. The computing platform of claim 1 , wherein the first hop point is configured to:

apply a first alternating encryption method to the encrypted data collection using a first proximity key associated with a location of the first hop point to produce a first re-encrypted data collection; and

send the first re-encrypted data collection to a second hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications.

9. The computing platform of claim 8 , wherein the second hop point is configured to:

apply a second alternating encryption method to the first re-encrypted data collection using a second proximity key associated with a location of the second hop point to produce a second re-encrypted data collection; and

send the second re-encrypted data collection to the data decryption computing platform.

10. The computing platform of claim 9 , wherein the data decryption computing platform is configured to decrypt the second re-encrypted data collection using a third proximity key associated with a location of the data decryption computing platform to reproduce the data collection comprising the one or more data sets.

11. The computing platform of claim 10 , wherein the data decryption computing platform is configured to provide one or more data recipient user computing devices with selective access to the data collection comprising the one or more data sets.

12. A method, comprising:

at a computing platform comprising at least one hardware processor, memory, and a communication interface:

receiving, by the at least one hardware processor, via the communication interface, from a first data source user computing device, a data collection comprising one or more data sets to be transferred to one or more remote recipient computer systems;

receiving, by the at least one processor hardware processor, via the communication interface, from the first data source user computing device, one or more transfer path specifications defining a specific sequence of hop points via which the data collection comprising the one or more data sets is to be transferred to the one or more remote recipient computer systems;

receiving, by the at least one hardware processor, via the communication interface, from a quorum of authorization devices, a plurality of authorization keys;

validating, by the at least one hardware processor, the plurality of authorization keys received from the quorum of authorization devices;

based on validating the plurality of authorization keys received from the quorum of authorization devices, encrypting, by the at least one hardware processor, the data collection comprising the one or more data sets using the plurality of authorization keys received from the quorum of authorization devices to produce an encrypted data collection; and

sending, by the at least one hardware processor, via the communication interface, to a first hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications, the encrypted data collection to initiate a transfer of the data collection comprising the one or more data sets to a data decryption computing platform comprising one or more computing devices.

13. The method of claim 12 , wherein the first data source user computing device is linked to a first user associated with a first organization, and wherein the quorum of authorization devices comprises the first data source user computing device and at least one other registered user computing device linked to a second user associated with the first organization.

14. The method of claim 13 , wherein the quorum of authorization devices comprises at least half of all available authorization devices associated with the first organization.

15. The method of claim 13 , comprising:

prior to receiving the plurality of authorization keys from the quorum of authorization devices:

identifying, by the at least one hardware processor, one or more available authorization devices associated with the first organization;

generating, by the at least one hardware processor, one or more authorization prompts for the one or more available authorization devices associated with the first organization; and

sending, by the at least one hardware processor, via the communication interface, to the one or more available authorization devices associated with the first organization, the one or more authorization prompts generated for the one or more available authorization devices associated with the first organization.

16. The method of claim 15 , wherein a first authorization key of the plurality of authorization keys received from the quorum of authorization devices is a biometric authorization key encoded with biometric information specific to a first authorization device that returned the first authorization key in response to a first authorization prompt.

17. The method of claim 16 , wherein a second authorization key of the plurality of authorization keys received from the quorum of authorization devices is a geo-location authorization key encoded with geo-location information specific to a second authorization device that returned the second authorization key in response to a second authorization prompt.

18. The method of claim 17 , wherein a third authorization key of the plurality of authorization keys received from the quorum of authorization devices is a device-signature authorization key encoded with device-signature information specific to a third authorization device that returned the third authorization key in response to a third authorization prompt.

19. The method of claim 12 , wherein the first hop point is configured to:

apply a first alternating encryption method to the encrypted data collection using a first proximity key associated with a location of the first hop point to produce a first re-encrypted data collection; and

send the first re-encrypted data collection to a second hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one hardware processor, memory, and a communication interface, cause the computing platform to:

receive, via the communication interface, from a first data source user computing device, a data collection comprising one or more data sets to be transferred to one or more remote recipient computer systems;

receive, via the communication interface, from the first data source user computing device, one or more transfer path specifications defining a specific sequence of hop points via which the data collection comprising the one or more data sets is to be transferred to the one or more remote recipient computer systems;

receive, via the communication interface, from a quorum of authorization devices, a plurality of authorization keys;

validate the plurality of authorization keys received from the quorum of authorization devices;

based on validating the plurality of authorization keys received from the quorum of authorization devices, encrypt the data collection comprising the one or more data sets using the plurality of authorization keys received from the quorum of authorization devices to produce an encrypted data collection; and

send, via the communication interface, to a first hop point associated with the specific sequence of hop points defined by the one or more transfer path specifications, the encrypted data collection to initiate a transfer of the data collection comprising the one or more data sets to a data decryption computing platform comprising one or more computing devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2017
From: KURIAN, MANU
To: BANK OF AMERICA CORPORATION
Reel/Frame 043405/0240 →
Continuity (1)
Related Publication 20190068563A1 · Feb 28, 2019