IP Library › Granted Patent US 12,032,720
Granted Patent B2
US 12,032,720 · App. 17/531,881 · Granted Jul 9, 2024

Real time pseudonymization of personally identifiable information (PII) for secure remote processing

Inventors: Shirish Netke (Cupertino, CA); Upendra Mardikar (Cupertino, CA)
Assignee: Amberoon, Inc.
G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,032,720
App. No.
17/531,881
Granted
Jul 9, 2024
Kind
B2
Abstract

An approach for real time, round trip pseudonymization (a.k.a. anonymization or tokenization) of data on the fly, in real time, enabling remote secure processing of sensitive data such as by a cloud service. Sensitive data remains on premises with the client at all times. A user may thus run extensive queries that return sensitive data without noticing that such data was pseudonymized in transit.

Claims (32)

1. A computer-implemented method comprising:

at an intercept component,

receiving an original data set from a client;

identifying fields within the data set that contain protected information;

generating a pseudonymized data set by replacing fields containing protected information with substituted data;

maintaining a map relating the protected information to the substituted data in a local data store that is local to the intercept component;

forwarding the pseudonymized data set to a remote system; and

subsequently, at the intercept component,

intercepting a command from the client intended for processing by the remote system;

pseudonymizing one or more fields within the command, by accessing the map as stored in the local data store, to generate a pseudonymized command, in real time;

forwarding the pseudonymized command to the remote system; and

subsequently, at the remote system,

receiving the pseudonymized command without indication as to which fields contain protected information;

processing the pseudonymized command and the pseudonymized data set, to generate a pseudonymized response having one or more pseudonymized response data fields;

returning the pseudonymized response to the intercept component; and subsequently, at the intercept component;

receiving the pseudonymized response from the remote system including the one or more pseudonymized response data fields;

de-pseudonymizing, in real time, the one or more pseudonymous response data fields within the pseudonymized response, by accessing the map stored in the local data store to generate a de-pseudonymized response having the protected information; and

transmitting the de-pseudonymized response with the protected information to the client.

2. The method of claim 1 wherein the protected information further comprises one or more selected fields that contain personally identifiable information.

3. The method of claim 1 additionally comprising, at the intercept component:

intercepting the command from the client via a browser component; and

displaying the de-pseudonymized response via the browser component.

4. The method of claim 1 wherein the processing the pseudonymized command further comprises one or more of search, data analytics, machine learning logic, or artificial intelligence logic.

5. The method of claim 1 wherein the processing the pseudonymized command further comprises an anti-money laundering algorithm.

6. The method of claim 1 wherein processing the pseudonymized command further comprises detecting anomalies in the pseudonymized command or the pseudonymized data set using machine learning logic or artificial intelligence.

7. The method of claim 1 wherein processing the pseudonymized command further comprises performing analytics on the pseudonymized data set.

8. The method of claim 1 wherein the remote system is a cloud service.

9. The method of claim 1 additionally wherein the intercept component uses an Application Programming Interface (API) for performing one or more of:

receiving the original data set from the client;

forwarding the pseudonymized command to the remote system;

receiving the pseudonymized response from the remote system; or

transmitting the de-pseudonymized response to the client.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2024
From: NETKE, SHIRISH; MARDIKAR, UPENDRA
To: AMBEROON, INC.
Reel/Frame 067640/0556 →
Continuity (2)
Provisional Application 63117319 · Nov 23, 2020
Related Publication 20220164474A1 · May 26, 2022