IP Library Granted Patent US 12,632,880
Granted Patent B2
US 12,632,880 · App. 18/431,411 · Granted May 19, 2026

System and method for loading secure data in multiparty secure computing environment

Inventors: Edison U. Ortiz (Orlando, FL); David Ian McKay (Toronto, CA); Christoph Knoess (Sag Harbor, NY); Seung Bong Baek (Toronto, CA); Ravi Khandavilli (Orlando, FL); Adel Ai Nabulsi (Toronto, CA); Arnold Badal-Badalian (Toronto, CA); Justin Simonelis (Toronto, CA)
Assignee: ROYAL BANK OF CANADA
G06Q30/0224
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,880
App. No.
18/431,411
Granted
May 19, 2026
Kind
B2
Abstract

A computational approach is proposed herein for controlling a user interface for rendering of interactive graphical control elements representing offers and coupons that are inserted into a computational payment process. In particular, the offers and coupons can interact with stored payment information resident (or tokens thereof) on a digital wallet data structure. The approach can be implemented as a computing system, a computing method operable on a computing system, or a computer program product affixed in the form of a non-transitory computer readable medium storing machine-interpretable instructions.

Claims (37)

1 . A computer system for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process privacy preserving cross-data table analysis, the computer system comprising:

a processor operating in conjunction with computer memory and storing data on a non-transitory computer readable storage medium, the processor configured to:

receive, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more promotional offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;

aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;

in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions;

validate or compare the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device;

in response to a detected triggering event associated with a user in the modified audience list, transmit, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;

wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.

2 . The computer system of claim 1 , wherein the set of logical conditions includes a threshold score established through a plurality of weighted logical conditions to be met, and wherein the computing device is not provided individual scores contributing to the threshold score.

3 . The computer system of claim 1 , wherein the at least two data tables of the plurality of data tables is joined together in a temporal aggregate data table for processing the query message request, and the temporal aggregate data table is discarded after processing the query message request.

4 . The computer system of claim 1 , wherein the query message request is communicated by the computing device along with a consent data structure representing consent tokens provided by at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and wherein the validation of the query message request for adherence to one or more privacy policy requirements includes validating the consent data structure.

5 . The computer system of claim 4 , wherein the consent data structure includes cryptographic keys, each corresponding to at least one of the at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and each of the cryptographic keys are validated against a corresponding cryptographic key validation portion stored on or accessible by an always protected database system.

6 . The computer system of claim 1 , wherein the audience list is utilized for automatic provisioning of offers or promotions and a list of users of the audience list is not otherwise accessible.

7 . The computer system of claim 1 , wherein the audience list is utilized for coordinating eligibility for multiple campaigns to prevent provisioning overlapping promotions to a same user on the audience list.

8 . The computer system of claim 1 , wherein the audience list is utilized for automatic eligibility for promotions based on user attributes.

9 . The computer system of claim 1 , wherein the computer system is a computing server appliance residing within a data center, the computing server appliance connected through a message bus to receive the query message request across a network from the campaign management process coupled through an interface.

10 . A computer method for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process, the computer method comprising:

receiving, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;

aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;

in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions;

validating or comparing the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device,

in response to a detected triggering event associated with a user in the modified audience list, transmitting, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;

wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.

11 . The computer method of claim 10 , wherein the set of logical conditions includes a threshold score established through a plurality of weighted logical conditions to be met, and wherein the computing device is not provided individual scores contributing to the threshold score.

12 . The computer method of claim 10 , wherein the at least two data tables of the plurality of data tables are joined together in a temporal aggregate data table for processing the query message request, and the temporal aggregate data table is discarded after processing the query message request.

13 . The computer method of claim 10 , wherein the query message request is communicated by the computing device along with a consent data structure representing consent tokens provided by at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and wherein the validation of the query message request for adherence to one or more privacy policy requirements includes validating the consent data structure.

14 . The computer method of claim 13 , wherein the consent data structure includes cryptographic keys, each corresponding to at least one of the at least one of a user or data sources corresponding to the plurality of data tables to be loaded, and each of the cryptographic keys are validated against a corresponding cryptographic key validation portion stored on or accessible by an always protected database system.

15 . The computer method of claim 10 , wherein the audience list is utilized for automatic provisioning of offers or promotions and a list of users of the audience list is not otherwise accessible.

16 . The computer method of claim 10 , wherein the audience list is utilized for coordinating eligibility for multiple campaigns to prevent provisioning overlapping promotions to a same user on the audience list.

17 . The computer method of claim 15 , wherein the audience list is utilized for automatic eligibility for promotions based on user attributes.

18 . A non-transitory computer readable medium storing machine interpretable instruction sets, which when executed by a processor, cause the processor to perform a method for controlling a user interface for rendering of interactive graphical control elements representing offers or coupons that are inserted into a computational payment process, the method comprising:

receiving, through a network from a computing device, a query message request representing a set of logical conditions for establishing eligibility for one or more promotional offers or coupons, said logical conditions requiring cross-table connections between at least two tables of a plurality of data tables associated with at least two different data sources or entities, each logical condition of the set of logical conditions representing a user characteristic, each data table of the plurality of data tables including at least a field representing unique user identifiers used as a primary key for identifying a user across the plurality of data tables, a first corresponding field representing the user characteristic for each unique user identifier of the unique user identifiers, and a second corresponding field representing a consent field for each unique user identifier of the unique user identifiers;

aggregate the at least two data tables of the plurality of data tables for the cross-table connections, wherein the aggregated at least two data tables of the plurality of data tables is not accessible external to a trusted execution environment;

in response to receiving the query message request, generate an audience list representing one or more users within the aggregated at least two data tables satisfying the set of logical conditions; and

validating or comparing the query message request in accordance with or for adherence to one or more privacy policy requirements by validating or comparing the query message request against the second corresponding field representing the consent field of the one or more users in the audience list and modifying the audience list in adherence to the one or more privacy policy requirements without use of cookies on a webpage or computing device;

in response to a detected triggering event associated with a user in the modified audience list, transmitting, across the network to a computing device corresponding to the user, one or more promotional offers or coupons of the promotional offers or coupons in accordance or in adherence with the privacy policy requirements;

wherein the audience list is maintained on an always protected database system encrypted using one or more encryption keys and configured for interaction through a limited application programming interface having sole access to the one or more encryption keys, and the computing device does not have direct access to the audience list or the aggregated data tables.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2024
From: ORTIZ, EDISON U.; MCKAY, DAVID IAN; KNOESS, CHRISTOPH; BAEK, SEUNG BONG; KHANDAVILLI, RAVI; NABULSI, ADEL AL; BADAL-BADALIAN, ARNOLD; SIMONELIS, JUSTIN
To: ROYAL BANK OF CANADA
Reel/Frame 067828/0392 →
Continuity (5)
Continuation 17746926 · May 17, 2022
Continuation In Part 17701612 · Mar 22, 2022
Provisional Application 63189611 · May 17, 2021
Provisional Application 63164444 · Mar 22, 2021
Related Publication 20240177187A1 · May 30, 2024
References Cited (9)
US 11593506B2 · Lilly · 2023 [cited by examiner]
US 20130246141A1 · Liberty · 2013 [cited by examiner]
US 20140074623A1 · Mohammadi et al. · 2014 [cited by applicant]
US 20180096166A1 · Rogers · 2018 [cited by examiner]
US 20200193485A1 · Field · 2020 [cited by applicant]
US 20210165786A1 · Halstead · 2021 [cited by examiner]
E. Krishna Krishnan, “Blockchain's Disruption of Marketing”, retrieved from https://www.ideas2it.com/blogs/blockchains-disruption-marketing/, available on Mar. 6, 2018 (Year: 2018). [cited by examiner]
United States Patent & Trademark Office (USPTO), Non Final Rejection issued to U.S. Appl. No. 17/746,926, Mar. 8, 2023. [cited by applicant]
Supplementary European Search Report for EP 22803502 dated Apr. 14, 2025. [cited by applicant]