IP Library Granted Patent US 10,089,493
Granted Patent B2
US 10,089,493 · App. 15/697,029 · Granted Oct 2, 2018

Decentralized token table generation

Inventors: Yigal Rozenberg (Wilton, CT); Ulf Mattsson (Cos Cob, CT)
Assignee: Protegrity Corporation
G06F21/6254G06F17/30339G06F17/30424H04L9/083H04L63/0428H04L63/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,089,493
App. No.
15/697,029
Granted
Oct 2, 2018
Kind
B2
Abstract

New tokenization tables are derived at intervals in order to increase the security of tokenized data that is transferred between two endpoints. Generation of the new tokenization tables is based on previous tokenization tables, which advantageously allows the generation process to be performed locally at the two endpoints independently of an external tokenization table provider. New tokenization tables can periodically be distributed to the endpoints as a new starting point for derivation.

Claims (30)

1. A method for tokenizing data, comprising:

generating, by a transmitting endpoint configured to tokenize data using a first token table accessible to both the transmitting endpoint and a receiving endpoint communicatively coupled to the transmitting endpoint, a second token table based on the first token table and a seed value, the second token table mapping one or more input values to different token values than the first token table;

tokenizing, by the transmitting endpoint, input data by replacing a portion of the input data with the token value mapped to the portion of the input data by the second token table to produce tokenized data; and

providing, by the transmitting endpoint, the tokenized data and the seed value to a receiving endpoint, the receiving endpoint configured to generate the second token table based on the first token table and the seed value, wherein the receiving endpoint does not have access to the seed value before receiving the seed value from the transmitting endpoint.

2. The method of claim 1 , wherein generating the second token table comprises performing a shuffle algorithm to generate a permutation of the token values in the first token table, the permutation generated with the pseudo-random number generator and the seed value.

3. The method of claim 2 , wherein the pseudo-random number generator is seeded using the seed value.

4. The method of claim 1 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted tokenized data a threshold number of times to the receiving endpoint.

5. The method of claim 1 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted a threshold amount of tokenized data to the receiving endpoint.

6. The method of claim 1 , wherein the transmitting endpoint is configured to also provide an identity of the first token table to the receiving endpoint.

7. The method of claim 1 , wherein at least one token value of the second token table is not included in the first token table.

8. A system for tokenizing data, the system comprising a non-transitory computer-readable storage medium storing executable computer instructions and a processor configured to execute the instructions to perform steps comprising:

generating, by a transmitting endpoint configured to tokenize data using a first token table accessible to both the transmitting endpoint and a receiving endpoint communicatively coupled to the transmitting endpoint, a second token table based on the first token table and a seed value, the second token table mapping one or more input values to different token values than the first token table;

tokenizing, by the transmitting endpoint, input data by replacing a portion of the input data with the token value mapped to the portion of the input data by the second token table to produce tokenized data; and

providing, by the transmitting endpoint, the tokenized data and the seed value to a receiving endpoint, the receiving endpoint configured to generate the second token table based on the first token table and the seed value, wherein the receiving endpoint does not have access to the seed value before receiving the seed value from the transmitting endpoint.

9. The system of claim 8 , wherein generating the second token table comprises performing a shuffle algorithm to generate a permutation of the token values in the first token table, the permutation generated with the pseudo-random number generator and the seed value.

10. The system of claim 9 , wherein the pseudo-random number generator is seeded using the seed value.

11. The system of claim 8 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted tokenized data a threshold number of times to the receiving endpoint.

12. The system of claim 8 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted a threshold amount of tokenized data to the receiving endpoint.

13. The system of claim 8 , wherein the transmitting endpoint is configured to also provide an identity of the first token table to the receiving endpoint.

14. The system of claim 8 , wherein at least one token value of the second token table is not included in the first token table.

15. A non-transitory computer-readable storage medium storing executable computer instructions for tokenizing data, the instructions, when executed, configured to perform steps comprising:

generating, by a transmitting endpoint configured to tokenize data using a first token table accessible to both the transmitting endpoint and a receiving endpoint communicatively coupled to the transmitting endpoint, a second token table based on the first token table and a seed value, the second token table mapping one or more input values to different token values than the first token table;

tokenizing, by the transmitting endpoint, input data by replacing a portion of the input data with the token value mapped to the portion of the input data by the second token table to produce tokenized data; and

providing, by the transmitting endpoint, the tokenized data and the seed value to a receiving endpoint, the receiving endpoint configured to generate the second token table based on the first token table and the seed value, wherein the receiving endpoint does not have access to the seed value before receiving the seed value from the transmitting endpoint.

16. The non-transitory computer-readable storage medium of claim 15 , wherein generating the second token table comprises performing a shuffle algorithm to generate a permutation of the token values in the first token table, the permutation generated with the pseudo-random number generator and the seed value.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the pseudo-random number generator is seeded using the seed value.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted tokenized data a threshold number of times to the receiving endpoint.

19. The non-transitory computer-readable storage medium of claim 15 , wherein the second token table is generated in response to determining that the transmitting endpoint has transmitted a threshold amount of tokenized data to the receiving endpoint.

20. The non-transitory computer-readable storage medium of claim 15 , wherein the transmitting endpoint is configured to also provide an identity of the first token table to the receiving endpoint.

21. The non-transitory computer-readable storage medium of claim 15 , wherein at least one token value of the second token table is not included in the first token table.

Assignments (3)
SECURITY INTEREST Recorded Aug 2, 2024
From: PROTEGRITY USA, INC.; PROTEGRITY LIMITED HOLDING, LLC; PROTEGRITY US HOLDING, LLC; PROTEGRITY CORPORATION; KAVADO, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 068326/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PROTEGRITY CORPORATION
To: PROTEGRITY US HOLDING, LLC
Reel/Frame 067566/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2017
From: ROZENBERG, YIGAL; MATTSSON, ULF
To: PROTEGRITY CORPORATION
Reel/Frame 043600/0117 →
Continuity (5)
Continuation 15344583 · Nov 7, 2016
Continuation 14611204 · Jan 31, 2015
Continuation 13851865 · Mar 27, 2013
Provisional Application 61618621 · Mar 30, 2012
Related Publication 20180012040A1 · Jan 11, 2018
Cited By (2)
US 12,541,605 US 12,542,671