Anonymized interface for ticket based authentication
Method, system, and programs provide automatic anonymization of protected data items when a request is associated with authentication via a ticket. Ticket authentication includes sending a ticket to a recipient address. The ticket is included in a request for information. Responsive to receiving a request with a ticket, an example system may determine if the ticket is still valid and, if so, generate mock identifiers for any identifiers in information provided back to the requestor, replace the identifiers with their corresponding mock identifiers, as well as delete any protected information from the information provided back to the requestor. The system may store a mapping of the identifiers with their mock identifiers by session id. These mappings may be deleted after a predetermined time, so that the mapping is valid only for a particular session for a limited time.
1 . A system comprising:
at least one processor; and
memory storing instructions that, when executed by the at least one processor, cause the system to:
identify results responsive to a query;
determine whether a quantity of the results is at least a minimum number; and
responsive to determining that the quantity of the results is at least the minimum number:
generate a session identifier,
for each protected identifier of at least one protected identifier in the results:
generate a respective mock identifier for the protected identifier,
add an entry to an identifier map for the protected identifier, the entry associating the session identifier with the protected identifier and its respective mock identifier, and
replace the protected identifier with its respective mock identifier in the results,
remove protected information from the results, and
provide a user interface configured to provide the session identifier and to provide access to the results to a requestor of the query, wherein the mock identifier is valid during a non-expired session associated with the session identifier.
2 . The system of claim 1 , the memory storing instructions that further cause the system to associate the session identifier with a level of authorization that indicates access is based on ticket presentation.
3 . The system of claim 2 , the memory storing instructions that further cause the system to:
determine that the session identifier has the association with the level of authorization that indicates access based on ticket presentation,
wherein, for each protected identifier of the at least one protected identifier, adding the entry to the identifier map is performed responsive to determining that the session identifier has the association with the level of authorization that indicates access based on ticket presentation.
4 . The system of claim 1 , the memory storing instructions that further cause the system to:
determine whether the query is not associated with a successful login,
wherein determining whether the quantity of the results is at least the minimum number occurs responsive to determining that the query is not associated with a successful login, and
wherein the user interface is configured to display the results with the protected information responsive to determining that the session identifier is associated with a successful login.
5 . The system of claim 1 , the memory storing instructions that further cause the system to, responsive to determining that the quantity of the results is at least the minimum number, return an error indicating the query is too specific.
6 . The system of claim 1 , wherein the at least one protected identifier is an identifier linked to a person that is in the results provided to the requestor.
7 . The system of claim 1 , the memory storing instructions that further cause the system to:
receive an interaction with a mock identifier identified in the results, the interaction including the session identifier;
locate the entry in the identifier map for the session identifier and the mock identifier; and
responsive to locating the entry:
use the protected identifier in the entry to obtain second information that is responsive to the interaction,
remove protected information from the second information, and
initiate display of the second information.
8 . A method comprising:
identifying results responsive to a query;
determining whether a quantity of the results is at least a minimum number; and
responsive to determining that the quantity of the results is at least the minimum number:
for each protected identifier of at least one protected identifier in the results:
generating a session identifier,
generating a respective mock identifier for the protected identifier,
adding an entry to an identifier map for the protected identifier, the entry associating the session identifier with the protected identifier and its respective mock identifier, and
replacing the protected identifier with its respective mock identifier in the results,
removing protected information from the results, and
providing a user interface configured to provide the session identifier and to provide access to the results to a requestor of the query, wherein the mock identifier is valid during a non-expired session associated with the session identifier.
9 . The method of claim 8 , further comprising associating the session identifier with a level of authorization that indicates access is based on ticket presentation.
10 . The method of claim 9 , further comprising:
determining that the session identifier has the association with the level of authorization that indicates access based on ticket presentation,
wherein, for each protected identifier of the at least one protected identifier, adding the entry to the identifier map is performed responsive to determining that the session identifier has the association with the level of authorization that indicates access based on ticket presentation.
11 . The method of claim 8 , further comprising:
determining whether the query is not associated with a successful login,
wherein determining whether the quantity of the results is at least the minimum number occurs responsive to determining that the query is not associated with a successful login, and
wherein the user interface is configured to display the results with the protected information responsive to determining that the session identifier is associated with a successful login.
12 . The method of claim 8 , further comprising, in response to determining that the quantity of the results is at least the minimum number, returning an error indicating the query is too specific.
13 . The method of claim 8 , wherein the at least one protected identifier is an identifier linked to a person that is in the results provided to the requestor.
14 . A non-transitory computer-readable medium storing instructions that, when executed by at least one processor, cause a computing system to perform operations comprising:
identifying results responsive to a query;
determining whether a quantity of the results is at least a minimum number; and
responsive to determining that the quantity of the results is at least the minimum number:
generating a session identifier,
for each protected identifier of at least one protected identifier in the results:
generating a respective mock identifier for the protected identifier,
adding an entry to an identifier map for the protected identifier, the entry associating the session identifier with the protected identifier and its respective mock identifier, and
replacing the protected identifier with its respective mock identifier in the results,
removing protected information from the results, and
providing a user interface configured to provide the session identifier and to provide access to the results to a requestor of the query, wherein the mock identifier is valid during a non-expired session associated with the session identifier.
15 . The non-transitory computer-readable medium of claim 14 , the operations further comprising associating the session identifier with a level of authorization that indicates access is based on ticket presentation.
16 . The non-transitory computer-readable medium of claim 15 , the operations comprising:
determining that the session identifier has the association with the level of authorization that indicates access based on ticket presentation,
wherein, for each protected identifier of the at least one protected identifier, adding the entry to the identifier map is performed responsive to determining that the session identifier has the association with the level of authorization that indicates access based on ticket presentation.
17 . The non-transitory computer-readable medium of claim 14 , the operations comprising:
determining whether the query is not associated with a successful login,
wherein determining whether the quantity of the results is at least the minimum number occurs responsive to determining that the query is not associated with a successful login, and
wherein the user interface is configured to display the results with the protected information responsive to determining that the session identifier is associated with a successful login.
18 . The non-transitory computer-readable medium of claim 14 , the operations further comprising, in response to determining that the quantity of the results is at least the minimum number, returning an error indicating the query is too specific.
19 . The non-transitory computer-readable medium of claim 14 , wherein the at least one protected identifier is an identifier linked to a person that is in the results provided to the requestor.
20 . The non-transitory computer-readable medium of claim 14 , the operations further comprising:
receiving an interaction with a mock identifier identified in the results, the interaction including the session identifier;
locating the entry in the identifier map for the session identifier and the mock identifier; and
responsive to locating the entry:
using the protected identifier in the entry to obtain second information that is responsive to the interaction,
removing protected information from the second information, and
initiating display of the second information.