IP Library Granted Patent US 12,425,376
Granted Patent B2
US 12,425,376 · App. 18/356,438 · Granted Sep 23, 2025

Mapping between user interface fields and protocol information

Inventors: Vichai Levy (Norwalk, CT); Yigal Rozenberg (Wilton, CT); Rajnish Jain (Fairfield, CT); Ulf Mattsson (Cos Cob, CT)
Assignee: PROTEGRITY US HOLDING, LLC
H04L63/04G06F21/6254G06F21/6263H04L63/0421H04L67/02H04L67/10H04L67/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,376
App. No.
18/356,438
Granted
Sep 23, 2025
Kind
B2
Abstract

A gateway device for implementing data security is described herein. The gateway device is coupled between a client device and a server device, and generates a mapping between portions of data received from a client device and interface fields or data elements of the client device. Upon receiving subsequent data from the client device, the gateway device can access the generated mapping to identify portions of the subsequent data corresponding to particular interface fields or data elements of the client device using the mapping, and can encode the identified portions of the subsequent data, for instance based on data protection techniques defined by a security policy. The encoded data can then be outputted by the gateway device to the server device.

Claims (31)

1. A gateway device coupled between a client device and a server, comprising:

a mapping generator configured to generate a unique mapping for each of a plurality of client devices that maps input fields within a web page to a byte range within a body of a payload generated by the web page;

an encoding engine configured to, in response to receiving the payload generated by the web page in response to entry of data entered within the input fields of the web page by the client device:

access a security policy corresponding to the web page and identifying, for each input field of the web page, an associated encoding operation;

identify, for each input field of the web page, an associated payload portion corresponding to the input field using the mapping unique to the client device; and

encode, for each input field of the web page, the associated payload portion using the encoding operation associated with the input field to produce an encoded payload portion, wherein a first payload portion associated with a first input field is left in plain text, wherein a second payload portion associated with a second input field is partially encoded such that some but not all of the second payload portion is encoded and a remainder is left in plain text, and wherein a third payload portion associated with a third input field is entirely encoded; and

an output configured to output the encoded payload portions to the server.

2. The gateway device of claim 1 , wherein the received payload comprises a data value entered into an input field of the web page.

3. The gateway device of claim 2 , wherein the data value comprises one or more of: a string, a numerical value, an alphanumerical value, an alphabetical value, a structured data value, a name, a location, a credit card number, a social security number, a bank account number, an age, a date, a time, a price, a monetary balance, an identifier, an address, a city, a state, a country, geographic coordinates, a school, an organization, or an employer.

4. The gateway device of claim 1 , wherein the gateway device comprises a unique value generator configured to generate one or more unique values and to enter the generated unique values into the input fields, and wherein the mapping generator generates the mapping based on training data associated with the web page produced in response to the entered generated unique values.

5. The gateway device of claim 4 , wherein the mapping generator is configured to identify the one or more unique values within the training data, and to identify portions of the training data corresponding to the identified unique values.

6. The gateway device of claim 1 , wherein the input fields comprise graphical user interface input field elements of a form or interface displayed within the web page.

7. The gateway device of claim 1 , wherein an identified portion of the received payload comprises one or more of: a location within the received payload, a word of the received payload, a location within a header or wrapper of the received payload, a location within the body of the received payload, and a graphical user interface input field element within the received payload.

8. The gateway device of claim 1 , wherein the mapping comprises a table, wherein each entry of the table is an association between a portion of a payload received from the client device and an input field of the web page.

9. The gateway device of claim 1 , wherein the mapping is generated in response to 1) identifying one or more format rules associated with the input fields, 2) submitting information within the input fields that satisfies the identified format rules, and 3) intercepting the payload, the mapping generator further configured to store the generated mapping within a non-transitory computer-readable storage medium.

10. The gateway device of claim 1 , wherein the encoding operations comprise one or more of: encryption, tokenization, data masking, hashing, and anonymization.

11. A method comprising:

generating, by a gateway device coupled between a client device and a server, a unique mapping for each of a plurality of client devices, such that each mapping maps input fields within a web page to a byte range within a body of a payload generated by the web page;

in response to receiving the payload generated by the web page responsive to entry of data within the input fields of the web page by a client device of the plurality of client devices, accessing, by the gateway device, a mapping unique to the client device, accessing a security policy corresponding to the web page and identifying, for each input field of the web page, an associated encoding operation;

identifying, by the gateway device and for each input field of the web page, an associated payload portion corresponding to the input field using the mapping;

encoding, by the gateway device and for each input field of the web page, the associated payload portion using the encoding operation associated with the input field to produce an encoded payload portion, wherein a first payload portion associated with a first input field is left in plain text, wherein a second payload portion associated with a second input field is partially encoded such that some but not all of the second payload portion is encoded and a remainder is left in plain text, and wherein a third payload portion associated with a third input field is entirely encoded; and

outputting, by the gateway device, the encoded payload portions to the server.

12. The method of claim 11 , wherein the received payload comprises a data value entered into an input field of the web page.

13. The method of claim 12 , wherein the data value comprises one or more of: a string, a numerical value, an alphanumerical value, an alphabetical value, a structured data value, a name, a location, a credit card number, a social security number, a bank account number, an age, a date, a time, a price, a monetary balance, an identifier, an address, a city, a state, a country, geographic coordinates, a school, an organization, or an employer.

14. The method of claim 11 , further comprising generating one or more unique values to enter into the input fields, and wherein the mapping is generated based on payload produced in response to the entered generated unique values.

15. The method of claim 14 , wherein generating the mapping comprises identifying the one or more unique values within the payload and identifying portions of the payload corresponding to the identified unique values.

16. The method of claim 11 , wherein the input fields comprise graphical user interface input field elements of a form or interface displayed within the web page.

17. The method of claim 11 , wherein an identified portion of the received payload comprises one or more of: a location within the received payload, a word of the received payload, a location within a header or wrapper of the received payload, a location within the body of the received payload, and a graphical user interface input field element within the received payload.

18. The method of claim 11 , wherein the mapping comprises a table, wherein each entry of the table is an association between a portion of a payload received from the client device and an input field of the web page.

19. The method of claim 11 , wherein the mapping is generated in response to 1) identifying one or more format rules associated with the input fields, 2) submitting information within the input fields that satisfies the identified format rules, and 3) intercepting the payload, the mapping generator further configured to store the generated mapping within a non-transitory computer-readable storage medium.

20. The method of claim 11 , wherein the encoding operations comprise one or more of: encryption, tokenization, data masking, hashing, and anonymization.

Assignments (3)
SECURITY INTEREST Recorded Aug 2, 2024
From: PROTEGRITY USA, INC.; PROTEGRITY LIMITED HOLDING, LLC; PROTEGRITY US HOLDING, LLC; PROTEGRITY CORPORATION; KAVADO, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 068326/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PROTEGRITY CORPORATION
To: PROTEGRITY US HOLDING, LLC
Reel/Frame 067566/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 25, 2023
From: LEVY, VICHAI; ROZENBERG, YIGAL; RAJNISH, JAIN; MATTSSON, ULF
To: PROTEGRITY CORPORATION
Reel/Frame 064375/0430 →
Continuity (5)
Continuation 17492589 · Oct 2, 2021
Continuation 16158302 · Oct 12, 2018
Continuation 14814311 · Jul 30, 2015
Provisional Application 62031869 · Aug 1, 2014
Related Publication 20230370516A1 · Nov 16, 2023
References Cited (19)
US 8898272B1 · Young et al. · 2014 [cited by applicant]
US 9703967B1 · Kothari · 2017 [cited by examiner]
US 20030023604A1 · O'Brien et al. · 2003 [cited by applicant]
US 20050114367A1 · Serebrennikov · 2005 [cited by applicant]
US 20100169311A1 · Tengli et al. · 2010 [cited by applicant]
US 20110307710A1 · McGuire et al. · 2011 [cited by applicant]
US 20120159637A1 · Dove et al. · 2012 [cited by applicant]
US 20130103685A1 · Preneel et al. · 2013 [cited by applicant]
US 20130238330A1 · Casella dos Santos · 2013 [cited by applicant]
US 20140101774A1 · Armington · 2014 [cited by examiner]
US 20140115710A1 · Hughes · 2014 [cited by examiner]
US 20140365372A1 · Ross · 2014 [cited by examiner]
Extended European Search Report, European Patent Office Application No. 15828098.2, Nov. 29, 2017, 7 pages. [cited by applicant]
International Search Report and Written Opinion, Patent Cooperation Treaty Application No. PCT/US2015/043301, Nov. 2, 2015, 15 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 14/814,311, filed May 4, 2018, 33 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 14/814,311, filed Nov. 28, 2017, 33 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/158,302, filed Aug. 25, 2021, 17 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 16/158,302, filed Jul. 21, 2021, 14 pages. [cited by applicant]
United States Office Action, U.S. Appl. No. 17/492,589, filed Apr. 13, 2023, 7 pages. [cited by applicant]