IP Library › Granted Patent US 12,541,607
Granted Patent B2
US 12,541,607 · App. 17/540,747 · Granted Feb 3, 2026

Systems and methods to protect sensitive data at processing intermediaries

Inventors: Iyengar Sridhar Narayanan (Markham, CA); Ahamed Jalaldeen Shahul Hamid (Bangalore, IN)
Assignee: International Business Machines Corporation
G06F21/6209G06F21/602G06F21/6254G06F21/6263G06F21/78G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,607
App. No.
17/540,747
Granted
Feb 3, 2026
Kind
B2
Abstract

A system, platform, program product, and/or method for protecting sensitive data including decrypting an incoming message comprising a base message and the sensitive electronic data; removing the sensitive electronic data from the incoming message to create a stripped message; encrypting the sensitive electronic data; storing the encrypted sensitive electronic data in In-Memory Cache; and permitting the stripped message to be further processed without the sensitive electronic data. The system, platform, program product and/or method in an embodiment further includes: retrieving from the In-Memory Cache the encrypted sensitive electronic data; decrypting the encrypted sensitive electronic data retrieved from the In-Memory Cache; and injecting the sensitive electronic data into the stripped message. In a further aspect the system, platform, program product and/or method further includes encrypting the outbound message with the sensitive electronic data and permitting the encrypted outbound message with the sensitive electronic data to reach an external computing system.

Claims (48)

1 . A computer-implemented method for protecting sensitive electronic data, the method comprising:

decrypting an incoming message comprising a base message and the sensitive electronic data;

removing the sensitive electronic data from the incoming message to create a stripped message;

encrypting the sensitive electronic data removed from the incoming message;

storing the encrypted sensitive electronic data in In-Memory Cache; and

permitting the stripped message to be further processed without the sensitive electronic data.

2 . The method as recited in claim 1 , further comprising decrypting the incoming message with an Interceptor.

3 . The method recited in claim 2 , further comprising decrypting the incoming message using security keys exchanged with an external system that transmitted the incoming message.

4 . The method as recited in claim 1 , wherein the security keys are exchanged out of band with the incoming message.

5 . The method recited in claim 1 , further comprising storing the encrypted sensitive data in In-Memory Cache for a temporary time period that is at least one of a group consisting of: a fixed time period, a predefined time period, a predetermined time period, an adjustable time period, a programmable time period, and combinations thereof.

6 . The method as recited in claim 1 , wherein removing the sensitive electronic data from the incoming message comprises:

identifying sensitive electronic data to check for in the decrypted incoming message; and

checking the decrypted incoming message for the identified sensitive electronic data.

7 . The method as recited in claim 6 , further comprising using an attribute list to identify sensitive electronic data in the decrypted incoming messages.

8 . The method as recited in claim 7 , further comprising comparing the decrypted incoming message to sensitive electronic data identified in the attribute list.

9 . The method as recited in claim 7 , wherein the attribute list is a configurable JSON Attribute List where attributes can be at least one of a group consisting of an added attribute, a modified attribute, a removed attribute, and combinations thereof from the JSON Attribute List.

10 . The method as recited in claim 1 , wherein encrypting the sensitive electronic data comprises using a Hardware Security Module to encrypt the sensitive electronic data with an encryption key.

11 . The method as recited in claim 10 , further comprising supplying the encryption key by an external system that transmitted the incoming message.

12 . The method as recited in claim 1 , wherein an interceptor:

decrypts an incoming message comprising a base message and sensitive electronic data;

removes the sensitive electronic data from the incoming message to create a stripped message;

encrypts the sensitive electronic data;

stores the encrypted sensitive electronic data in In-Memory Cache; and

permits the stripped message to be further processed without the sensitive electronic data.

13 . The method as recited in claim 1 , further comprising invoking an intermediary computing system REST API.

14 . The method as recited in claim 1 , further comprising:

retrieving from the In-Memory Cache the encrypted sensitive electronic data;

decrypting the encrypted sensitive electronic data retrieved from the In-Memory Cache using a Hardware Security Module; and

injecting the sensitive electronic data into the stripped message.

15 . The method as recited in claim 1 , further comprising encrypting the outbound message with the sensitive electronic data and permitting the encrypted outbound message with the sensitive electronic data to reach an external computing system.

16 . The method as recited in claim 15 , wherein an inceptor encrypts the outbound message with a security key exchanged with an external system that transmitted the incoming message.

17 . The method as recited in claim 1 , further comprising an interceptor using a Hardware Security Module (HSM) to decrypt the encrypted sensitive electronic data retrieved from the In-Memory Cache.

18 . The method as recited in claim 14 , further comprising:

permitting the encrypted outbound message with the sensitive electronic data to reach an external computing system; and

permitting at least one of the stripped message without containing the sensitive electronic data or an enriched stripped message comprising the stripped message to be further processed but without containing the sensitive electronic data to reach a different external computing system.

19 . A computer program product for protecting sensitive electronic data, the computer program product comprising a non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to:

decrypt an incoming message comprising a base message and the sensitive electronic data;

remove the sensitive electronic data from the incoming message to form a stripped message;

encrypt the sensitive electronic data removed from the incoming message;

store the encrypted sensitive electronic data in In-Memory Cache; and

permit the stripped message to be further processed without the sensitive electronic data.

20 . The computer program product as recited in claim 19 , further comprising programming instructions that when executed by the processor cause the processor to:

retrieve from the In-Memory Cache the encrypted sensitive electronic data;

decrypt the encrypted sensitive electronic data retrieved from the In-Memory Cache using a Hardware Security Module (HSM);

inject the sensitive electronic data into the stripped message to form an outbound message with the electronic sensitive data;

encrypt the outbound message with the sensitive electronic data;

permit the encrypted outbound message with the sensitive electronic data to reach an external computing system; and

permit the base message that is further processed without the sensitive electronic data to reach the external computing system or a different external computing system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2021
From: NARAYANAN, IYENGAR SRIDHAR; SHAHUL HAMID, AHAMED JALALDEEN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058271/0272 →
Continuity (1)
Related Publication 20230177181A1 · Jun 8, 2023
References Cited (20)
US 9547769B2 · Aissi et al. · 2017 [cited by applicant]
US 10289868B2 · Jagadish · 2019 [cited by examiner]
US 10333899B2 · Kilgallon · 2019 [cited by applicant]
US 10425388B2 · Zhao · 2019 [cited by applicant]
US 10541975B2 · Rajnish · 2020 [cited by applicant]
US 10904218B2 · Muttik · 2021 [cited by applicant]
US 20020111920A1 · Tresser · 2002 [cited by applicant]
US 20090169010A1 · Dodd · 2009 [cited by examiner]
US 20150213288A1 · Bilodeau · 2015 [cited by examiner]
US 20160132696A1 · Vidhani et al. · 2016 [cited by applicant]
US 20170220818A1 · Nagasundaram et al. · 2017 [cited by applicant]
US 20210366585A1 · Molapo et al. · 2021 [cited by applicant]
US 20220070666A1 · Hua · 2022 [cited by examiner]
US 20220245283A1 · Springer · 2022 [cited by examiner]
CN 116226875A · 2023 [cited by applicant]
DE 102012106081A1 · 2014 [cited by applicant]
JP 2023082700A · 2023 [cited by applicant]
WO WO2014142996A1 · 2014 [cited by examiner]
Yadav, V., “Ensuring the Security of Your APIs”, DZONE, Jul. 2019, 12 pages, https://dzone.com/articles/how-do-you-ensure-security. [cited by applicant]
Burnside, M., et al., “F3ildCrypt: End-to-End Protection of Sensitive Information in Web Services”, Information Security: 12th International Conference, ISC 2009, 15 pages, https://angelosk.github.io/Papers/2009/f3ildcr… [cited by applicant]