IP Library › Granted Patent US 11,954,230
Granted Patent B2
US 11,954,230 · App. 18/299,134 · Granted Apr 9, 2024

System for improving data security through key management

Inventors: Venkatesh Sarvottamrao Apsingekar (San Jose, CA); Sahil Vinod Motadoo (Sunnyvale, CA); Christopher John Schille (San Jose, CA); James Francis Lavine (Corte Madera, CA)
Assignee: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
G06F21/6245H04L9/0825H04L9/0827H04L9/088H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,954,230
App. No.
18/299,134
Granted
Apr 9, 2024
Kind
B2
Abstract

A system protects personally identifiable information (PII) by implementing an unconventional key management scheme. In this scheme, the system uses a set of keys rather than an individual key for encrypting PII. Different portions of the PII are encrypted using different keys from the set of keys. In this manner, even if a malicious user were to access a key, that key would not give the malicious user the ability to decrypt all of the PII. Additionally, the system generates a new set of keys periodically (e.g., once a month). The system also deletes sets of keys that are too old (e.g., six months old). As a result, even if a malicious user were to access a key, the usefulness of that key would be time limited.

Claims (60)

1. A token handler for securing personally identifiable information, the token handler comprising a memory and a hardware processor communicatively coupled to the memory, the hardware processor configured to:

generate a set of public encryption keys of the token handler;

communicate the set of public encryption keys of the token handler to a data originator;

receive, from the data originator, a request to store a user's personally identifiable information, the request to store comprising a first portion of the user's personally identifiable information encrypted using a first public encryption key of the token handler from the set and a second portion of the user's personally identifiable information encrypted using a second public encryption key of the token handler from the set;

add, to an encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key;

receive, from the data originator, a token indicating a request for redemption of the first and second portions of the user's personally identifiable information;

select, based on the encryption schedule, a first private encryption key of the token handler corresponding to the first public encryption key;

decrypt, using the first private encryption key, the first portion of the user's personally identifiable information encrypted using the first public encryption key to produce the first portion of the user's personally identifiable information;

select, based on the encryption schedule, a second private encryption key of the token handler corresponding to the second public encryption key;

decrypt, using the second private encryption key, the second portion of the user's personally identifiable information encrypted using the second public encryption key to produce the second portion of the user's personally identifiable information; and

store a key vault comprising the set of public encryption keys and an ordinal assigned to each key of the set of public encryption keys, wherein the encryption schedule identifies the first public encryption key using the ordinal assigned to the first public encryption key in the key vault.

2. The token handler of claim 1 , wherein the processor is configured to:

determine that an age of the set of public encryption keys exceeds a predetermined time threshold;

in response to determining that the age of the set of public encryption keys exceeds the predetermined time threshold, generate a second set of public encryption keys of the token handler;

encrypt, using a first public encryption key from the second set, the first portion of the user's personally identifiable information;

encrypt, using a second public encryption key from the second set, the second portion of the user's personally identifiable information; and

add, to the encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key from the second set and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key from the second set.

3. The token handler of claim 1 , wherein the processor is further configured to:

determine that an age of the set of public encryption keys exceeds a predetermined time threshold;

in response to determining that the age of the set of public encryption keys exceeds the predetermined time threshold, delete the set of public encryption keys; and

remove, from the encryption schedule, the indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key and the indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key.

4. The token handler of claim 3 , wherein the processor is further configured to:

after determining that the age of the set of public encryption keys exceeds the predetermined time threshold, receive a token indicating a second request for redemption of the first and second portions of the user's personally identifiable information; and

reject the second request based on the determination that the age of the set of public encryption keys exceeds the predetermined time threshold.

5. The token handler of claim 1 , wherein processor is further configured to:

determine that a device separate from the token handler has established a connection with the token handler after receiving the token from the data originator;

in response to determining that the device has established the connection, communicate the encryption schedule to the device.

6. The token handler of claim 5 , wherein the processor is further configured to communicate the set of public encryption keys to the device.

7. The token handler of claim 1 , wherein the processor is further configured to determine, based on an ordinal assigned to a key of the set of public encryption keys and on a number of keys in the set of public encryption keys, that an age of the key exceeds a predetermined time threshold.

8. The token handler of claim 1 , wherein the data originator randomly selected the first and second public encryption keys from the set.

9. A method for securing personally identifiable information, the method comprising:

generating, by a token handler, a set of public encryption keys of the token handler;

communicating, by the token handler, the set of public encryption keys of the token handler to a data originator;

receiving, by the token handler, from the data originator, a request to store a user's personally identifiable information, the request to store comprising a first portion of the user's personally identifiable information encrypted using a first public encryption key of the token handler from the set and a second portion of the user's personally identifiable information encrypted using a second public encryption key of the token handler from the set;

adding, by the token handler, to an encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key;

receiving, by the token handler, a token indicating a request for redemption of the first and second portions of the user's personally identifiable information;

selecting, by the token handler, based on the encryption schedule, a first private encryption key of the token handler corresponding to the first public encryption key;

decrypting, by the token handler, using the first private encryption key, the first portion of the user's personally identifiable information encrypted using the first public encryption key to produce the first portion of the user's personally identifiable information;

selecting, by the token handler, based on the encryption schedule, a second private encryption key of the token handler corresponding to the second public encryption key;

decrypting, by the token handler, using the second private encryption key, the second portion of the user's personally identifiable information encrypted using the second public encryption key to produce the second portion of the user's personally identifiable information; and

storing, by the token handler, a key vault comprising the set of public encryption keys and an ordinal assigned to each key of the set of public encryption keys, wherein the encryption schedule identifies the first public encryption key using the ordinal assigned to the first public encryption key in the key vault.

10. The method of claim 9 , further comprising:

determining, by the token handler, that an age of the set of public encryption keys exceeds a predetermined time threshold;

in response to determining that the age of the set of public encryption keys exceeds the predetermined time threshold, generating, by the token handler, a second set of public encryption keys of the token handler;

encrypting, by the token handler, using a first public encryption key from the second set, the first portion of the user's personally identifiable information;

encrypting, by the token handler, using a second public encryption key from the second set, the second portion of the user's personally identifiable information; and

adding, by the token handler, to the encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key from the second set and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key from the second set.

11. The method of claim 9 , further comprising:

determining, by the token handler, that an age of the set of public encryption keys exceeds a predetermined time threshold;

in response to determining that the age of the set of public encryption keys exceeds the predetermined time threshold, deleting, by the token handler, the set of public encryption keys; and

removing, by the token handler, from the encryption schedule, the indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key and the indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key.

12. The method of claim 11 , further comprising:

after determining that the age of the set of public encryption keys exceeds the predetermined time threshold, receiving, by the token handler, a token indicating a second request for redemption of the first and second portions of the user's personally identifiable information; and

rejecting, by the token handler, the second request based on the determination that the age of the set of public encryption keys exceeds the predetermined time threshold.

13. The method of claim 9 , further comprising:

determining, by the token handler, that a device separate from the token handler has established a connection with the token handler after receiving the token from the data originator;

in response to determining that the device has established the connection, communicating, by the token handler, the encryption schedule to the device.

14. The method of claim 13 , further comprising communicating, by the token handler, the set of public encryption keys to the device.

15. The method of claim 9 , further comprising determining, by the token handler, based on an ordinal assigned to a key of the set of public encryption keys and on a number of keys in the set of public encryption keys, that an age of the key exceeds a predetermined time threshold.

16. The method of claim 9 , wherein the data originator randomly selected the first and second public encryption keys from the set.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2023
From: APSINGEKAR, VENKATESH SARVOTTAMRAO; MOTADOO, SAHIL VINOD; SCHILLE, CHRISTOPHER JOHN; LAVINE, JAMES FRANCIS
To: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
Reel/Frame 063297/0465 →
Continuity (3)
Continuation 17590121 · Feb 1, 2022
Continuation 16807809 · Mar 3, 2020
Related Publication 20230252188A1 · Aug 10, 2023
Cited By (1)
US 12,556,907