IP Library Granted Patent US 10,904,001
Granted Patent B2
US 10,904,001 · App. 16/421,658 · Granted Jan 26, 2021

Data format-preserving encryption, tokenization, and access control for vaultless systems and methods

Inventors: Justin Stanley (Bixby, OK); Jacob Burcham (Brooklyn, NY); Ulf Mattsson (Westport, CT)
Assignee: TOKENEX, INC.
H04L9/3213H04L9/0618G06F3/0619
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,904,001
App. No.
16/421,658
Granted
Jan 26, 2021
Kind
B2
Abstract

Embodiments of the present disclosure relate to vaultless format-preserving tokenization systems and methods. Some methods include encoding a first data set to produce encoded input data; generating a secure tweak for the encoded input data based on a token format schema by: encoding a tweak input to produce an encoded tweak input; and hashing the encoded tweak input along with a unique hashing key to generate the secure tweak; applying a format preserving encryption algorithm that utilizes the encoded input data, the secure tweak, and a unique encryption key to generate ciphertext output; and generating a token from the ciphertext output.

Claims (49)

1. A method, comprising:

receiving a cleartext input;

encoding a first data set to produce encoded input data, wherein the first data set is a part of the cleartext input, wherein the first data set is encoded into the encoded input data using a first lookup table, the first lookup table being unique to an entity that provided the cleartext input;

generating a secure tweak for the encoded input data based on a token format schema by:

encoding a tweak input using a second lookup table to produce an encoded tweak input, wherein the tweak input comprises another part of the cleartext input; and

hashing the encoded tweak input along with a unique hashing key to generate the secure tweak, the secure tweak being created from one or more portions of the cleartext input that are not tokenized which are a value provided by the entity;

applying a format preserving encryption algorithm that utilizes the encoded input data, the secure tweak, and a unique encryption key to generate ciphertext output; and

encoding the ciphertext output into token.

2. The method according to claim 1 , wherein generating the token from the ciphertext output includes using a third lookup table to convert the ciphertext output into the token.

3. The method according to claim 2 , wherein generating the token from the ciphertext output further comprises assembling an assembled token as a concatenation of the one or more portions of the cleartext input that are not tokenized and the token, as specified in the token format schema.

4. The method according to claim 2 , wherein the third lookup table comprises alphabetic characters, whereas the first lookup table and the second lookup table comprise numeric characters.

5. The method according to claim 1 , further comprising:

decoding the ciphertext output from the token;

regenerating the encoded tweak input;

recovering the secure tweak by hashing the encoded tweak input along with the unique hashing key;

decrypting the encoded input data by applying the format preserving encryption algorithm that utilizes the ciphertext output, the secure tweak, and the unique encryption key;

decoding the first data set from the encoded input data; and

reassembling the cleartext input using the first data set.

6. A system, comprising:

a processor; and

memory for storing executable instructions, the processor being configured to execute the instructions to:

receive a cleartext input;

encode a first data set to produce encoded input data, wherein the first data set is a part of the cleartext input, wherein the first data set is encoded into the encoded input data using a first lookup table, the first lookup table being unique to an entity that provided the cleartext input;

generate a secure tweak for the encoded input data based on a token format schema by:

encode a tweak input using a second lookup table to produce an encoded tweak input, wherein the tweak input comprises another part of the cleartext input; and

hash the encoded tweak input along with a unique hashing key to generate the secure tweak, the secure tweak being created from one or more portions of the cleartext input that are not tokenized which are a value provided by the entity;

apply a format preserving encryption algorithm that utilizes the encoded input data, the secure tweak, and a unique encryption key to generate ciphertext output;

generate a token from the ciphertext output; and

discard the first data set or a cleartext input that comprises the first data set.

7. The system according to claim 6 , wherein the processor is further configured to

decode the ciphertext output from the token using the lookup table;

regenerate the encoded tweak input;

recover the secure tweak by hashing the encoded tweak input along with the unique hashing key;

decrypt the encoded input data by applying the format preserving encryption algorithm that utilizes the ciphertext output, the secure tweak, and the unique encryption key;

decode the first data set from the encoded input data; and

reassemble the cleartext input using the first data set.

8. A method, comprising:

encoding a first data set of a cleartext input to produce encoded input data, wherein the first data set is encoded into the encoded input data using a first lookup table, the first lookup table being unique to an entity that provided the cleartext input;

encoding a tweak input using a second lookup table to produce an encoded tweak input, wherein the tweak input comprises another part of the cleartext input;

hashing the encoded tweak input along with a unique hashing key to generate a secure tweak, the secure tweak being created from one or more portions of the cleartext input that are not tokenized which are a value provided by the entity;

applying a format preserving encryption algorithm that utilizes the encoded input data, the secure tweak, and a unique encryption key to generate ciphertext output;

generating a token from the ciphertext output;

receiving a request to obtain the cleartext input;

decoding the ciphertext output from the token;

regenerating the encoded tweak input;

recovering the secure tweak by hashing the encoded tweak input along with the unique hashing key;

decrypting the encoded input data by applying the format preserving encryption algorithm that utilizes the ciphertext output, the secure tweak, and the unique encryption key;

decoding the first data set from the encoded input data; and

reassembling the cleartext input using the first data set.

Assignments (8)
SECURITY INTEREST Recorded Mar 6, 2025
From: IXOPAY, INC.
To: CRESTLINE DIRECT FINANCE, L.P. AS COLLATERAL AGENT
Reel/Frame 070430/0260 →
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: IXOPAY, INC. (F/K/A TOKENEX, INC.)
Reel/Frame 070316/0833 →
CHANGE OF NAME Recorded Feb 19, 2025
From: TOKENEX, INC.
To: IXOPAY, INC.
Reel/Frame 070268/0826 →
SECURITY INTEREST Recorded May 5, 2023
From: TOKENEX, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 063549/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2021
From: TOKENEX, INC.
To: TOKENEX, INC.
Reel/Frame 058212/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: BURCHAM, JACOB
To: TOKENEX, INC.
Reel/Frame 052716/0086 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: ULF MATTSSON
To: TOKENEX, INC.
Reel/Frame 052716/0329 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: STANLEY, JUSTIN
To: TOKENEX, INC.
Reel/Frame 052716/0138 →
Continuity (1)
Related Publication 20200374120A1 · Nov 26, 2020