IP Library Granted Patent US 12,333,497
Granted Patent B2
US 12,333,497 · App. 18/672,626 · Granted Jun 17, 2025

Searchable index encryption

Inventor: Dinesh Sundaram (Plano, TX)
Assignee: Capital One Services, LLC
G06Q10/10G06F9/44505G06F9/54G06F9/547G06F16/258G06F16/9558G06F16/9562G06F18/24G06F21/53G06F21/602G06F21/604G06F21/6227G06F21/6245G06F40/103G06F40/174G06F40/18G06N3/02G06N5/025G06N20/00G06Q20/382G06Q20/4014G06Q30/0185G06Q30/0206G06Q30/0601G06Q30/0613G06Q30/0619G06Q30/0637G06Q30/0643G06Q40/02G06Q40/03H04L9/0825H04L63/0435H04L63/08H04L63/0815H04L63/102H04L63/123H04L63/166H04L63/168H04L67/01G06F8/65G06F8/71G06F2221/2107G06K7/1417G06Q50/265G06Q2220/00H04L9/0822
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,333,497
App. No.
18/672,626
Granted
Jun 17, 2025
Kind
B2
Abstract

Auditing data containing sensitive data are stored in a data structure comprising data objects. Each data object comprises one or more pairs of a name and a value. Pairs that are flagged or identified as containing sensitive data are partially encrypted; the value is encrypted using an asymmetric key and the name corresponding to the encrypted value remains unencrypted. Some pairs that are not flagged or identified as containing sensitive data are left unencrypted. Unencrypted data may be stored in the partially encrypted auditing data as plain text. The auditing data may be analyzed to generate business metrics and identify application errors. The auditing data may also be queried, and data objects containing unencrypted pairs and/or partially encrypted pairs may be returned based on matching unencrypted names and/or values to the data query.

Claims (34)

1. A method of securing user data in a multi-user environment, the method comprising:

receiving partially encrypted auditing data comprising a data object that includes an identifier and a value,

wherein the auditing data is generated data based on a user-defined rule applied to input data, and the user-defined rule comprises at least one of a rule for prequalifying a user for a transaction, a rule for determining product eligibility, or a rule for determining a price for a product;

wherein the partially encrypted data is partially encrypted by:

encrypting the identifier of the data object using an encryption key, while leaving the value of the data object unencrypted;

receiving an indication of an operational error detected in the partially encrypted auditing data; and

outputting, based on the indication of the detected operational error, at least one of an identification of the detected operational error or confirmation of the detected operational error.

2. The method of claim 1 , wherein the receiving at least one of the indication of the operational error or the confirmation of the operational error comprises receiving at least one of the indication of the operational error or the confirmation of the operational error from an administrator device that monitors interaction with the auditing data.

3. The method of claim 1 , wherein at least one of the indication of the operational error or the confirmation of the operational error is based on decrypted values of the partially encrypted auditing data.

4. The method of claim 1 , wherein the auditing data is received based on interaction with a user interface associated with a user device that generates the encryption key.

5. The method of claim 1 , wherein the data object corresponds to at least a portion of sensitive user data generated by an entity associated with the encryption key.

6. A system comprising

a memory; and

at least one processor coupled to the memory and configured to perform operations comprising:

receiving partially encrypted auditing data comprising a data object that includes an identifier and a value,

wherein the auditing data is generated data based on a user-defined rule applied to input data, and the user-defined rule comprises at least one of a rule for prequalifying a user for a transaction, a rule for determining product eligibility, or a rule for determining a price for a product;

wherein the partially encrypted data is partially encrypted by:

encrypting the identifier of the data object using an encryption key, while leaving the value of the data object unencrypted;

receiving an indication of an operational error detected in the partially encrypted auditing data; and

outputting, based on the indication of the detected operational error, at least one of an identification of the detected operational error or confirmation of the detected operational error.

7. The system of claim 6 , wherein the receiving at least one of the indication of the operational error or the confirmation of the operational error comprises receiving at least one of the indication of the operational error or the confirmation of the operational error from an administrator device that monitors interaction with the auditing data.

8. The system of claim 6 , wherein at least one of the indication of the operational error or the confirmation of the operational error is based on decrypted values of the partially encrypted auditing data.

9. The system of claim 6 , wherein the auditing data is received based on interaction with a user interface associated with a user device that generates the encryption key.

10. The system of claim 6 , wherein the data object corresponds to at least a portion of sensitive user data generated by an entity associated with the encryption key.

11. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, causes the at least one computing device to perform operations comprising:

receiving partially encrypted auditing data comprising a data object that includes an identifier and a value,

wherein the auditing data is generated data based on a user-defined rule applied to input data, and the user-defined rule comprises at least one of a rule for prequalifying a user for a transaction, a rule for determining product eligibility, or a rule for determining a price for a product;

wherein the partially encrypted data is partially encrypted by:

encrypting the identifier of the data object using an encryption key, while leaving the value of the data object unencrypted;

receiving an indication of an operational error detected in the partially encrypted auditing data; and

outputting, based on the indication of the detected operational error, at least one of an identification of the detected operational error or confirmation of the detected operational error.

12. The non-transitory computer-readable medium of claim 11 , wherein the receiving at least one of the indication of the operational error or the confirmation of the operational error comprises receiving at least one of the indication of the operational error or the confirmation of the operational error from an administrator device that monitors interaction with the auditing data.

13. The non-transitory computer-readable medium of claim 11 , wherein at least one of the indication of the operational error or the confirmation of the operational error is based on decrypted values of the partially encrypted auditing data.

14. The non-transitory computer-readable medium of claim 11 , wherein the auditing data is received based on interaction with a user interface associated with a user device that generates the encryption key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2024
From: SUNDARAM, DINESH
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 067509/0819 →
Continuity (4)
Continuation 18141637 · May 1, 2023
Continuation 16881938 · May 22, 2020
Provisional Application 62852202 · May 23, 2019
Related Publication 20240411924A1 · Dec 12, 2024
References Cited (64)
US 6029149A · Dykstra et al. · 2000 [cited by applicant]
US 6208979B1 · Sinclair · 2001 [cited by applicant]
US 7107241B1 · Pinto · 2006 [cited by applicant]
US 7860767B1 · Vinci et al. · 2010 [cited by applicant]
US 8099605B1 · Billsröm et al. · 2012 [cited by applicant]
US 8666885B1 · Bramlage et al. · 2014 [cited by applicant]
US 8924720B2 · Raghuram et al. · 2014 [cited by applicant]
US 9137228B1 · Newstadt · 2015 [cited by applicant]
US 9646172B1 · Hahn et al. · 2017 [cited by applicant]
US 9762616B2 · Nagaratnam et al. · 2017 [cited by applicant]
US 9965911B2 · Wishne · 2018 [cited by applicant]
US 10033702B2 · Ford et al. · 2018 [cited by applicant]
US 10171457B2 · Moore et al. · 2019 [cited by applicant]
US 10243945B1 · Kruse et al. · 2019 [cited by applicant]
US 20020023051A1 · Kunzle et al. · 2002 [cited by applicant]
US 20020033838A1 · Krueger et al. · 2002 [cited by applicant]
US 20020040339A1 · Dhar et al. · 2002 [cited by applicant]
US 20020067907A1 · Ameres · 2002 [cited by applicant]
US 20020091629A1 · Danpour · 2002 [cited by applicant]
US 20030036993A1 · Parthasarathy · 2003 [cited by applicant]
US 20050086176A1 · Dahlgren et al. · 2005 [cited by applicant]
US 20050203834A1 · Prieston · 2005 [cited by applicant]
US 20060178983A1 · Nice et al. · 2006 [cited by applicant]
US 20070061248A1 · Shavit et al. · 2007 [cited by applicant]
US 20070250718A1 · Lee et al. · 2007 [cited by applicant]
US 20080092240A1 · Sitrick et al. · 2008 [cited by applicant]
US 20090327196A1 · Studer et al. · 2009 [cited by applicant]
US 20120017085A1 · Carter et al. · 2012 [cited by applicant]
US 20120246061A1 · Ericksen · 2012 [cited by applicant]
US 20120254957A1 · Fork et al. · 2012 [cited by applicant]
US 20130191629A1 · Treinen et al. · 2013 [cited by applicant]
US 20140006048A1 · Liberty · 2014 [cited by applicant]
US 20140189123A1 · Dodd et al. · 2014 [cited by applicant]
US 20140207571A1 · Hammock et al. · 2014 [cited by applicant]
US 20140237236A1 · Kalinichenko et al. · 2014 [cited by applicant]
US 20140304170A1 · Spotanski et al. · 2014 [cited by applicant]
US 20150026038A1 · Alsbrooks · 2015 [cited by applicant]
US 20150074407A1 · Palmeri et al. · 2015 [cited by applicant]
US 20150161364A1 · Makarov et al. · 2015 [cited by applicant]
US 20150347770A1 · Whalley et al. · 2015 [cited by applicant]
US 20150356314A1 · Kumar · 2015 [cited by examiner]
US 20170091231A1 · DiFranco et al. · 2017 [cited by applicant]
US 20170244695A1 · Lund et al. · 2017 [cited by applicant]
US 20180053253A1 · Gokhale et al. · 2018 [cited by applicant]
US 20180083931A1 · Baig et al. · 2018 [cited by applicant]
US 20180108105A1 · Duesterwald et al. · 2018 [cited by applicant]
US 20180158139A1 · Krajicek et al. · 2018 [cited by applicant]
US 20180218121A1 · Gassner et al. · 2018 [cited by applicant]
US 20180218159A1 · Smith, III et al. · 2018 [cited by applicant]
US 20180260576A1 · Miguel · 2018 [cited by applicant]
US 20180332016A1 · Pandey et al. · 2018 [cited by applicant]
US 20190238321A1 · Park et al. · 2019 [cited by applicant]
US 20200153814A1 · Smolny et al. · 2020 [cited by applicant]
US 20200372169A1 · Sundaram · 2020 [cited by applicant]
US 20210004479A1 · Ithal · 2021 [cited by examiner]
US 20230267415A1 · Sundaram · 2023 [cited by applicant]
EP 3723341A1 · 2020 [cited by applicant]
WO 2015136503A1 · 2015 [cited by applicant]
NPL Search (Google Scholar) (Year: 2020). [cited by applicant]
Bluttman, Ken, Using the Excel IF Function: Testing on One Condition, published Mar. 22, 2019 (available at https://www.dummies.com/article/technology/software/microsoft-products/excel/using-the-excel-if-function-testin… [cited by applicant]
Cheusheva, “Excel IF function: nested IF formulas with multiple conditions, IFERROR, IFNA and more,” Apr. 27, 2017 (available at https ://web.archive .org/web/2017042003514 7 /https://www.ablebits.com/office-addi ns-blo… [cited by applicant]
Cheusheva, Using IF function in Excel: formula examples for Nos., text, dates, blank cells, Apr. 27, 2017 (available at https://web.archive.org/web/20170420035257 /https://www.ablebits.com/office-addins-blog/2014/11 /26… [cited by applicant]
N. Naik and P. Jenkins, “Securing digital identities in the cloud by selecting an apposite Federated Identity Management from SAML, OAuth and OpenID Connect,” 2017 11th International Conference on Research Challenges in… [cited by applicant]
OASIS. “Security Assertion Markup Language (SAML) V2.0 Technical Overview”, Sep. 2005. (Year: 2005). [cited by applicant]