IP Library › Granted Patent US 12,542,667
Granted Patent B2
US 12,542,667 · App. 18/169,030 · Granted Feb 3, 2026

Systems and methods for modifying cryptographic token related data

Inventors: Christopher Vito Covalucci (Herndon, VA); Michael Mossoba (Great Falls, VA)
Assignee: Capital One Services, LLC
H04L9/3213H04L9/30H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,667
App. No.
18/169,030
Granted
Feb 3, 2026
Kind
B2
Abstract

Systems and methods for modifying cryptographic token related data. In some aspects, the system accesses a unique cryptographic token associated with a user. The token is associated with a digital asset and is encrypted using a public key for the user. The system receives a request from the user to allow a third-party server to modify the asset. The request includes a public key for the third-party server. The system obtains and decrypts the asset using a private key for the user. The system encrypts the asset using the public key for the third-party server and transmits the asset and the public key for the user to the third-party server. The system receives, from the third-party server, an updated digital asset encrypted using the public key for the user. The system decrypts the updated asset using the private key for the user and replaces the asset with the updated asset.

Claims (100)

1 . A system for enabling modification of data associated with a unique cryptographic token, comprising:

one or more processors; and

a non-transitory, computer-readable medium comprising instructions that, when executed by the one or more processors, cause operations comprising:

accessing a unique cryptographic token associated with a user, wherein the unique cryptographic token includes a link to a digital asset stored at a management server, wherein the digital asset is encrypted using a public key for the user;

receiving a request from the user to allow a third-party server to modify the digital asset linked by the unique cryptographic token, wherein the request includes a public key for the third-party server;

obtaining the digital asset from the management server and decrypting the digital asset using a private key for the user;

encrypting, to obtain an encrypted digital asset, the digital asset using the public key for the third-party server;

transmitting the encrypted digital asset and the public key for the user to the third-party server;

receiving, from the third-party server and after transmitting the encrypted digital asset to the third-party server, an updated digital asset that has been encrypted by the third-party server using the public key for the user;

decrypting the updated digital asset using the private key for the user and validating the updated digital asset with respect to a format for the digital asset; and

in response to the validating being successful and after receiving the updated digital asset from the third-party server, transmitting the updated digital asset to the management server to replace the digital asset linked by the unique cryptographic token.

2 . A method for enabling modification of a digital asset associated with a unique cryptographic token, the method comprising:

accessing a unique cryptographic token associated with a user, wherein the unique cryptographic token is associated with a digital asset stored at a management server, wherein the digital asset is encrypted using a public key for the user;

receiving a request from the user to allow a third-party server to modify the digital asset associated with the unique cryptographic token, wherein the request includes a public key for the third-party server;

obtaining the digital asset and decrypting the digital asset using a private key for the user;

encrypting, to obtain an encrypted digital asset, the digital asset using the public key for the third-party server;

transmitting the encrypted digital asset and the public key for the user to the third-party server;

receiving, from the third-party server and after transmitting the encrypted digital asset to the third-party server, an updated digital asset that has been encrypted by the third-party server using the public key for the user;

decrypting the updated digital asset using the private key for the user; and

replacing the digital asset associated with the unique cryptographic token with the updated digital asset.

3 . The method of claim 2 , further comprising validating the updated digital asset with respect to a format for the digital asset.

4 . The method of claim 2 , further comprising:

accessing an on-chain program associated with the unique cryptographic token;

based on the unique cryptographic token, generating a new unique cryptographic token and a new on-chain program associated with the new unique cryptographic token, wherein the new unique cryptographic token includes a link to the digital asset stored at the management server; and

rendering the unique cryptographic token invalid by associating the unique cryptographic token with an inaccessible address.

5 . The method of claim 2 , further comprising enforcing a data retention policy on the digital asset by:

accessing an on-chain program comprising the data retention policy, wherein the on-chain program is associated with the unique cryptographic token, and wherein the on-chain program comprises a trigger; and

in response to the trigger being activated, modifying the digital asset to remove one or portions that violate the data retention policy.

6 . The method of claim 2 , further comprising:

receiving a data retention policy from the third-party server;

generating an on-chain program, wherein the on-chain program comprises the data retention policy, wherein the on-chain program is associated with the unique cryptographic token, and wherein the on-chain program comprises a trigger; and

in response to the trigger being activated, modifying the digital asset to remove one or portions that violate the data retention policy.

7 . The method of claim 2 , further comprising:

inputting the unique cryptographic token into a smart contract on a first blockchain network;

verifying the unique cryptographic token and digitally signing the unique cryptographic token;

generating a second unique cryptographic token on a second blockchain network, wherein the second unique cryptographic token is a duplicate of the unique cryptographic token; and

rendering the unique cryptographic token invalid by associating the unique cryptographic token with an inaccessible address.

8 . The method of claim 2 , further comprising:

receiving, from a user device, a request to access the digital asset stored on a management server in an unencrypted format, wherein the request to access the digital asset comprises a provided unique cryptographic token identifier and a provided user identification number;

verifying that a user identification number associated with the provided unique cryptographic token identifier is equivalent to the provided user identification number; and

in response to verifying that the user identification number associated with the provided unique cryptographic token identifier is equivalent to the provided user identification number, transmitting the digital asset from the management server to the user device.

9 . The method of claim 2 , wherein the third-party server attempts to access the digital asset linked by the unique cryptographic token, and wherein the method further comprises:

receiving a request from the third-party server to view the digital asset linked by the unique cryptographic token;

transmitting an approval request to a user device;

determining that the user granted the approval request;

decrypting the digital asset using the private key for the user;

encrypting the digital asset with the public key of the third-party server; and

transmitting the digital asset to the third-party server.

10 . The method of claim 2 , wherein a user device attempts to access the digital asset that is confidential, linked by the unique cryptographic token, and wherein the method further comprises:

receiving a request from the user device to view the digital asset linked by the unique cryptographic token;

transmitting an approval request to the third-party server;

determining that the third-party server granted the approval request; and

transmitting the digital asset to the user device.

11 . The method of claim 2 , wherein a user device attempts to access the digital asset that is non-confidential, linked by the unique cryptographic token, and wherein the method further comprises:

receiving a request from the user device to view the digital asset linked by the unique cryptographic token; and

transmitting the digital asset to the user device.

12 . A non-transitory, computer-readable medium having instructions recorded thereon, that, when executed by one or more processors, causes operations comprising:

accessing a unique cryptographic token associated with a user, wherein the unique cryptographic token includes a link to a digital asset stored at a management server, wherein the digital asset is encrypted using a public key for the user;

receiving a request from the user to allow a third-party server to modify the digital asset linked by the unique cryptographic token, wherein the request includes a public key for the third-party server;

obtaining the digital asset from the management server and decrypting the digital asset using a private key for the user;

encrypting, to obtain an encrypted digital asset, the digital asset using the public key for the third-party server;

transmitting the encrypted digital asset and the public key for the user to the third-party server;

receiving, from the third-party server and after transmitting the encrypted digital asset to the third-party server, an updated digital asset that has been encrypted by the third-party server using the public key for the user;

decrypting the updated digital asset using the private key for the user; and

transmitting the updated digital asset to the management server to replace the digital asset linked by the unique cryptographic token.

13 . The non-transitory, computer-readable medium of claim 12 , the operations further comprising:

accessing an on-chain program associated with the unique cryptographic token;

based on the unique cryptographic token, generating a new unique cryptographic token and a new on-chain program associated with the new unique cryptographic token, wherein the new unique cryptographic token includes a link to the digital asset stored at the management server; and

rendering the unique cryptographic token invalid by associating the unique cryptographic token with an inaccessible address.

14 . The non-transitory, computer-readable medium of claim 12 , the operations further comprising enforcing a data retention policy on the digital asset by:

accessing an on-chain program comprising the data retention policy, wherein the on-chain program is associated with the unique cryptographic token, and wherein the on-chain program comprises a trigger; and

in response to the trigger being activated, modifying the digital asset to remove one or portions that violate the data retention policy.

15 . The non-transitory, computer-readable medium of claim 12 , the operations further comprising:

receiving a data retention policy from the third-party server;

generating an on-chain program, wherein the on-chain program comprises the data retention policy, wherein the on-chain program is associated with the unique cryptographic token, and wherein the on-chain program comprises a trigger; and

in response to the trigger being activated, modifying the digital asset to remove one or portions that violate the data retention policy.

16 . The non-transitory, computer-readable medium of claim 12 , the operations further comprising:

inputting the unique cryptographic token into a smart contract on a first blockchain network;

verifying the unique cryptographic token and digitally signing the unique cryptographic token;

generating a second unique cryptographic token on a second blockchain network, wherein the second unique cryptographic token is a duplicate of the unique cryptographic token; and

rendering the unique cryptographic token invalid by associating the unique cryptographic token with an inaccessible address.

17 . The non-transitory, computer-readable medium of claim 12 , the operations further comprising:

receiving, from a user device, a request to access the digital asset stored on a management server in an unencrypted format, wherein the request to access the digital asset comprises a provided unique cryptographic token identifier and a provided user identification number;

verifying that a user identification number associated with the provided unique cryptographic token identifier is equivalent to the provided user identification number; and

in response to verifying that the user identification number associated with the provided unique cryptographic token identifier is equivalent to the provided user identification number, transmitting the digital asset from the management server to the user device.

18 . The non-transitory, computer-readable medium of claim 12 , wherein the third-party server attempts to access the digital asset linked by the unique cryptographic token, and wherein the operations further comprise:

receiving a request from the third-party server to view the digital asset linked by the unique cryptographic token;

transmitting an approval request to a user device;

determining that the user granted the approval request;

decrypting the digital asset using the private key for the user;

encrypting the digital asset with the public key of the third-party server; and

transmitting the digital asset to the third-party server.

19 . The non-transitory, computer-readable medium of claim 12 , wherein a user device attempts to access the digital asset that is confidential, linked by the unique cryptographic token, and wherein the operations further comprise:

receiving a request from the user device to view the digital asset linked by the unique cryptographic token;

transmitting an approval request to the third-party server;

determining that the third-party server granted the approval request; and

transmitting the digital asset to the user device.

20 . The non-transitory, computer-readable medium of claim 12 , wherein a user device attempts to access the digital asset that is non-confidential, linked by the unique cryptographic token, and wherein the operations further comprise:

receiving a request from the user device to view the digital asset linked by the unique cryptographic token; and

transmitting the digital asset to the user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2023
From: COVALUCCI, CHRISTOPHER VITO; MOSSOBA, MICHAEL
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 062696/0471 →
Continuity (1)
Related Publication 20240275597A1 · Aug 15, 2024
References Cited (7)
US 12321924B1 · Kurani · 2025 [cited by examiner]
US 20230214128A1 · Srivastava · 2023 [cited by examiner]
US 20250184163A1 · Rakic · 2025 [cited by examiner]
R. Akkaoui, X. Hei and W. Cheng, “EdgeMediChain: A Hybrid Edge Blockchain-Based Framework for Health Data Exchange,” in IEEE Access, vol. 8, pp. 113467-113486 (IEEE 2020) (Year: 2020). [cited by examiner]
G. Ateniese, R. Pietro, L. Mancini, Scalable and efficient provable data possession, Proceedings of the 4th international conference on security and privacy in communication networks, 9 (ACM 2008) (Year: 2008). [cited by examiner]
Jayapriya Jayabalan, N. Jeyanthi, Scalable blockchain model using off-chain IPFS storage for healthcare data security and privacy, Journal of Parallel and Distributed Computing, vol. 164, pp. 152-167, ScienceDirect (202… [cited by examiner]
Ken Miyachi, Tim K. Mackey, hOCBS: A privacy-preserving blockchain framework for healthcare data leveraging an on-chain and off-chain system design, Information Processing & Management, vol. 58, Issue 3, 102535 (Science… [cited by examiner]