IP Library Granted Patent US 12,412,152
Granted Patent B2
US 12,412,152 · App. 18/380,839 · Granted Sep 9, 2025

Securing lender output data

Inventors: Dinesh Sundaram (Plano, TX); Trent Jones (Mckinney, TX)
Assignee: Capital One Services, LLC
G06Q10/10G06F9/44505G06F9/54G06F9/547G06F16/258G06F16/9558G06F16/9562G06F18/24G06F21/53G06F21/602G06F21/604G06F21/6227G06F21/6245G06F40/103G06F40/174G06F40/18G06N3/02G06N5/025G06N20/00G06Q20/382G06Q20/4014G06Q30/0185G06Q30/0206G06Q30/0601G06Q30/0613G06Q30/0619G06Q30/0637G06Q30/0643G06Q40/02G06Q40/03H04L9/0825H04L63/0435H04L63/08H04L63/0815H04L63/102H04L63/123H04L63/166H04L63/168H04L67/01G06F8/65G06F8/71G06F2221/2107G06K7/1417G06Q50/265G06Q2220/00H04L9/0822
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,412,152
App. No.
18/380,839
Granted
Sep 9, 2025
Kind
B2
Abstract

A multi-lender architecture is configured to provide a loan applicant with automated pre-qualification and automobile loan eligibility evaluation for multiple candidate lenders. Lender output data may include sensitive data. The lender output data is stored in a data object of a first format and one or more fields of the data object are encrypted at the field level. The encrypted data object may be transmitted through multiple application layers or terminals. The encrypted data object may be reformatted at one or more application layers or terminals without decryption. A reformatted encrypted data object containing the lender output data may be decrypted at the last layer before forwarding the lender output data to the loan applicant.

Claims (47)

1. A method for decrypting data, the method comprising:

receiving, a data object comprising encrypted sensitive data, unencrypted non-sensitive data, a first path identifying a first data element in a first format, and an encrypted data key, wherein the encrypted sensitive data of the data object is encrypted using an unencrypted data key and the unencrypted data key is discarded after encryption of the encrypted sensitive data;

generating a new data object of a second format by:

capturing the first path identifying the first data element of the data object and a second path of a second data element of the new data object via a dynamic proxy; and

copying the encrypted sensitive data and the encrypted data key from the data object to the new data object in response to capturing the first and second path; and

decrypting the encrypted sensitive data of the new data object using the encrypted data key.

2. The method of claim 1 , further comprising:

retrieving the encrypted data key from first encryption metadata of the new data object;

receiving, based on the encrypted data key sent to an encryption service, a decrypted data key from the encryption service.

3. The method of claim 2 , wherein the encrypted sensitive data is copied from second encryption metadata of the data object to the first encryption metadata of the new data object.

4. The method of claim 2 , wherein the first encryption metadata comprises the second path identifying the second data element of the new data object, the encrypted sensitive data, and the encrypted data key.

5. The method of claim 4 , wherein at least one of: the first path is different from the second path, or a path identifying the second data element of the data object is different from a new path identifying the corresponding data element in the new data object of the second format.

6. The method of claim 1 , further comprising mapping the data object to the new data object to generate the dynamic proxy.

7. The method of claim 1 , wherein at least one of the encrypted sensitive data or the unencrypted non-sensitive data indicates an approval or rejection for an automobile loan.

8. The method of claim 1 , further comprising:

identifying, based on a decryption identifier appended to the encrypted data key, a master key; and

decrypting, based on the master key, the encrypted data key.

9. A system for decrypting data, the system comprising:

a memory; and

a processor coupled to the memory, the processor configured to perform operations comprising:

receiving, a data object comprising encrypted sensitive data, unencrypted non-sensitive data, a first path identifying a first data element in a first format, and an encrypted data key, wherein the encrypted sensitive data of the data object is encrypted using an unencrypted data key and the unencrypted data key is discarded after encryption of the encrypted sensitive data;

generating a new data object of a second format by:

capturing the first path identifying the first data element of the data object and a second path of a second data element of the new data object via a dynamic proxy; and

copying the encrypted sensitive data and the encrypted data key from the data object to the new data object in response to capturing the first and second path; and

decrypting the encrypted sensitive data of the new data object using the encrypted data key.

10. The system of claim 9 , the operations further comprising:

retrieving the encrypted data key from first encryption metadata of the new data object;

receiving, based on the encrypted data key sent to an encryption service, a decrypted data key from the encryption service.

11. The system of claim 10 , wherein the encrypted sensitive data is copied from second encryption metadata of the data object to the first encryption metadata of the new data object.

12. The system of claim 10 , wherein the first encryption metadata comprises the second path identifying the second data element of the new data object, the encrypted sensitive data, and the encrypted data key.

13. The system of claim 12 , wherein at least one of: the first path is different from the second path, or a path identifying the second data element of the data object is different from a new path identifying the corresponding data element in the new data object of the second format.

14. The system of claim 9 , the operations further comprising mapping the data object to the new data object to generate the dynamic proxy.

15. The system of claim 9 , wherein at least one of the encrypted sensitive data or the unencrypted non-sensitive data indicates an approval or rejection for an automobile loan.

16. The system of claim 9 , the operations further comprising:

identifying, based on a decryption identifier appended to the encrypted data key, a master key; and

decrypting, based on the master key, the encrypted data key.

17. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

receiving, a data object comprising encrypted sensitive data, unencrypted non-sensitive data, a first path identifying a first data element in a first format, and an encrypted data key, wherein the encrypted sensitive data of the data object is encrypted using an unencrypted data key and the unencrypted data key is discarded after encryption of the encrypted sensitive data;

generating a new data object of a second format by:

capturing the first path identifying the first data element of the data object and a second path of a second data element of the new data object via a dynamic proxy; and

copying the encrypted sensitive data and the encrypted data key from the data object to the new data object in response to capturing the first and second path; and

decrypting the encrypted sensitive data of the new data object using the encrypted data key.

18. The non-transitory computer-readable medium of claim 17 , the operations further comprising:

retrieving the encrypted data key from first encryption metadata of the new data object;

receiving, based on the encrypted data key sent to an encryption service, a decrypted data key from the encryption service.

19. The non-transitory computer-readable medium of claim 18 , wherein the encrypted sensitive data is copied from second encryption metadata of the data object to the first encryption metadata of the new data object.

20. The non-transitory computer-readable medium of claim 18 , wherein the first encryption metadata comprises the second path identifying the second data element of the new data object, the encrypted sensitive data, and the encrypted data key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2023
From: SUNDARAM, DINESH; JONES, TRENT
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 065250/0361 →
Continuity (4)
Continuation 17196738 · Mar 9, 2021
Continuation 16882274 · May 22, 2020
Provisional Application 62852202 · May 23, 2019
Related Publication 20240046212A1 · Feb 8, 2024
References Cited (66)
US 6029149A · Dykstra · 2000 [cited by examiner]
US 6208979B1 · Sinclair · 2001 [cited by examiner]
US 7107241B1 · Pinto · 2006 [cited by examiner]
US 7860767B1 · Vinci · 2010 [cited by examiner]
US 8099605B1 · Billsrom · 2012 [cited by examiner]
US 8666885B1 · Bramlage · 2014 [cited by examiner]
US 8924720B2 · Raghuram · 2014 [cited by examiner]
US 9137228B1 · Newstadt · 2015 [cited by applicant]
US 9646172B1 · Hahn · 2017 [cited by examiner]
US 9762616B2 · Nagaratnam · 2017 [cited by examiner]
US 9965911B2 · Wishne · 2018 [cited by examiner]
US 10033702B2 · Ford · 2018 [cited by examiner]
US 10171457B2 · Moore et al. · 2019 [cited by applicant]
US 10243945B1 · Kruse et al. · 2019 [cited by applicant]
US 11797932B2 · Sundaram et al. · 2023 [cited by applicant]
US 20020023051A1 · Kunzle · 2002 [cited by examiner]
US 20020033838A1 · Krueger et al. · 2002 [cited by applicant]
US 20020040339A1 · Dhar · 2002 [cited by examiner]
US 20020091629A1 · Danpour · 2002 [cited by examiner]
US 20030036993A1 · Parthasarathy · 2003 [cited by examiner]
US 20050086176A1 · Dahlgren et al. · 2005 [cited by applicant]
US 20050203834A1 · Prieston · 2005 [cited by examiner]
US 20060178983A1 · Nice · 2006 [cited by examiner]
US 20070061248A1 · Shavit · 2007 [cited by examiner]
US 20070250718A1 · Lee · 2007 [cited by examiner]
US 20080092240A1 · Sitrick · 2008 [cited by examiner]
US 20090327196A1 · Studer · 2009 [cited by examiner]
US 20120017008A1 · Carter et al. · 2012 [cited by applicant]
US 20120246061A1 · Ericksen · 2012 [cited by examiner]
US 20120254957A1 · Fork et al. · 2012 [cited by applicant]
US 20130191629A1 · Treinen · 2013 [cited by examiner]
US 20140006048A1 · Liberty · 2014 [cited by examiner]
US 20140189123A1 · Dodd et al. · 2014 [cited by applicant]
US 20140207571A1 · Hammock · 2014 [cited by examiner]
US 20140237236A1 · Kalinichenko et al. · 2014 [cited by applicant]
US 20140304170A1 · Spotanski · 2014 [cited by examiner]
US 20150026038A1 · Alsbrooks · 2015 [cited by examiner]
US 20150074407A1 · Palmeri et al. · 2015 [cited by applicant]
US 20150161364A1 · Makarov · 2015 [cited by examiner]
US 20150347770A1 · Whalley · 2015 [cited by examiner]
US 20170091231A1 · DiFranco · 2017 [cited by examiner]
US 20170244695A1 · Lund et al. · 2017 [cited by applicant]
US 20180053253A1 · Gokhale · 2018 [cited by examiner]
US 20180083931A1 · Baig · 2018 [cited by examiner]
US 20180108105A1 · Duesterwald · 2018 [cited by examiner]
US 20180158139A1 · Krajicek · 2018 [cited by examiner]
US 20180176192A1 · Davis · 2018 [cited by examiner]
US 20180218121A1 · Gassner et al. · 2018 [cited by applicant]
US 20180218159A1 · Smith, III · 2018 [cited by examiner]
US 20180260576A1 · Miguel · 2018 [cited by applicant]
US 20180332016A1 · Pandey et al. · 2018 [cited by applicant]
US 20190238321A1 · Park et al. · 2019 [cited by applicant]
US 20200067907A1 · Avetisov et al. · 2020 [cited by applicant]
US 20200153814A1 · Smolny et al. · 2020 [cited by applicant]
US 20200372175A1 · Sundaram · 2020 [cited by examiner]
US 20210004479A1 · Ithal · 2021 [cited by examiner]
EP 3723341A1 · 2020 [cited by applicant]
WO 2015136503A1 · 2015 [cited by applicant]
NPL Search History (Year: 2024). [cited by examiner]
NPL Search (Google Scholar) (Year: 2020). [cited by applicant]
Bluttman, Ken, Using the Excel IF Function: Testing on One Condition, published Mar. 22, 2019 (available at https://www.dummies.com/article/technology/software/microsoft-products/excel/using-the-excel-if-function-testin… [cited by applicant]
Cheusheva, “Excel IF function: nested IF formulas with multiple conditions, IFERROR, IFNA and more,” Apr. 27, 2017 (available at https ://web.archive .org/web/2017042003514 7 /https://www.ablebits.com/office-addi ns-blo… [cited by applicant]
Cheusheva, Using IF function in Excel: formula examples for numbers, text, dates, blank cells, Apr. 27, 2017 (available at https://web.archive.org/web/20170420035257 /https://www.ablebits.com/office-addins-blog/2014/11 … [cited by applicant]
N. Naik and P. Jenkins, “Securing digital identities in the cloud by selecting an apposite Federated Identity Management from SAML , OAuth and OpenID Connect,” 2017 11th International Conference on Research Challenges i… [cited by applicant]
OASIS. “Security Assertion Markup Language (SAML) V2.0 Technical Overview”, Sep. 2005. (Year: 2005). [cited by applicant]
NPL Search—Google Scholar (Year 2023). [cited by applicant]