IP Library Granted Patent US 9,122,880
Granted Patent B2
US 9,122,880 · App. 13/829,638 · Granted Sep 1, 2015

Sensitive personal information data protection

Inventor: Siddhartha Kumar Arya (Cumming, GA)
Assignee: Cellco Partnership
G06F21/60G06F21/6245G06F7/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,122,880
App. No.
13/829,638
Granted
Sep 1, 2015
Kind
B2
Abstract

A computing device may be configured to provide operations related to providing additional security for sensitive personal information (SPI) in data records of an enterprise. The SPI is extract from the data records and mask sequence values associated with the SPI are generated. A master translation table is updated with the association of the mask sequence values to the entries of SPI and the mask sequence values are merged into the data records to be used in place of the SPI to safeguard the SPI. The table containing the mask sequence values is stored separately.

Claims (54)

1. A computing device configured to provide operations comprising:

receiving a plurality of entries of sensitive personal information extracted from data records;

sorting the plurality of entries into an ordering;

for each of the plurality of entries, beginning with a first one of the plurality of entries in the ordering and proceeding sequentially through the ordering, determining a mask sequence value that is a next available value in a predetermined sequence of values and assigning the mask sequence value to the entry;

updating a master translation table that stores mask sequence values in association with entries of sensitive personal information such that the master translation table includes the plurality of entries of sensitive personal information in association with their respective assigned mask sequence values; and

merging the determined mask sequence values into the data records to be used in place of the respective entries of sensitive personal information to which the mask sequence values have been assigned to safeguard the sensitive personal information.

2. The computing device of claim 1 , further configured to provide operations comprising purging particular entries of sensitive personal information from being assigned mask sequence values according to whether the particular entries of sensitive personal information already are included in the master translation table.

3. The computing device of claim 1 , further configured to provide operations comprising:

receiving the data records from at least one data source;

extracting the sensitive personal information and primary key information from the data records for inclusion in the data records; and

merging the mask sequence values into the data records according to the primary key information.

4. The computing device of claim 1 , further configured to provide operations comprising removing the sensitive personal information from the data records prior to merging the mask sequence values into the data records.

5. The computing device of claim 1 , further configured to provide operations comprising including an identifier in the mask sequence value indicative of the type of sensitive personal information with which the mask sequence value is associated.

6. The computing device of claim 1 , wherein the ordering is a random ordering.

7. The computing device of claim 6 , wherein the sorting the plurality of entries into the ordering comprises:

generating a set of random values;

randomly assigning the random values to the entries of sensitive personal information; and

sorting the plurality of entries of sensitive personal information such that their respective assigned random values are in numerical order.

8. A method, comprising:

receiving, at an encryption platform executing a masking engine, a plurality of entries of sensitive personal information extracted from data records;

sorting, by the encryption platform, the plurality of entries into an ordering;

for each of the plurality of entries, beginning with a first one of the plurality of entries in the ordering and proceeding sequentially through the ordering, determining, by the encryption platform, a mask sequence value that is a next available value in a predetermined sequence of values and assigning the mask sequence value to the entry;

updating, by the encryption platform, a master translation table that stores mask sequence values in association with entries of sensitive personal information such that the master translation table includes the plurality of entries of sensitive personal information in association with their respective assigned mask sequence values; and

merging, by the encryption platform, the determined mask sequence values into the data records to be used in place of the respective entries of sensitive personal information to which the mask sequence values have been assigned to safeguard the sensitive personal information.

9. The method of claim 8 , further comprising purging particular entries of sensitive personal information from being assigned mask sequence values according to whether the particular entries of sensitive personal information already are included in the master translation table.

10. The method of claim 8 , further comprising:

receiving the data records from at least one data source;

extracting the sensitive personal information and primary key information from the data records for inclusion in the data records; and

merging the mask sequence values into the data records according to the primary key information.

11. The method of claim 8 , further comprising removing the sensitive personal information from the data records prior to merging the mask sequence values into the data records.

12. The method of claim 8 , further comprising including an identifier in the mask sequence value indicative of the type of sensitive personal information with which the mask sequence value is associated.

13. The method of claim 8 , wherein the ordering is a random ordering.

14. The method of claim 13 , wherein the sorting the plurality of entries into the ordering comprises:

generating a set of random values;

randomly assigning the random values to the entries of sensitive personal information and

sorting the plurality of entries of sensitive personal information such that their respective assigned random values are in numerical order.

15. A non-transitory computer readable medium storing a software program, the software program being executable by a processor of a computing device to provide operations comprising:

receiving, at an encryption platform executing a masking engine, a plurality of entries of sensitive personal information extracted from data records;

sorting, by the encryption platform, the plurality of entries into an ordering;

for each of the plurality of entries, beginning with a first one of the plurality of entries in the ordering and proceeding sequentially through the ordering, determining, by the encryption platform, a mask sequence value that is a next available value in a predetermined sequence of values and assigning the mask sequence value to the entry;

updating, by the encryption platform, a master translation table that stores mask sequence values in association with entries of sensitive personal information such that the master translation table includes the plurality of entries of sensitive personal information in association with their respective assigned mask sequence values; and

merging, by the encryption platform, the determined mask sequence values into the data records to be used in place of the respective entries of sensitive personal information to which the mask sequence values have been assigned to safeguard the sensitive personal information.

16. The non-transitory computer readable medium of claim 15 , further providing for operations comprising purging particular entries of sensitive personal information from being assigned mask sequence values according to whether the particular entries of sensitive personal information already are included in the master translation table.

17. The non-transitory computer readable medium of claim 15 , further providing for operations comprising:

receiving the data records from at least one data source;

extracting the sensitive personal information and primary key information from the data records for inclusion in the data records; and

merging the mask sequence values into the data records according to the primary key information.

18. The non-transitory computer readable medium of claim 15 , further providing for operations comprising removing the sensitive personal information from the data records prior to merging the mask sequence values into the data records.

19. The non-transitory computer readable medium of claim 15 , further providing for operations comprising including an identifier in the mask sequence value indicative of the type of sensitive personal information with which the mask sequence value is associated.

20. The non-transitory computer readable medium of claim 15 , wherein the ordering is a random ordering.

21. The non-transitory computer readable medium of claim 20 , wherein the sorting the plurality of entries into the ordering comprises:

generating a set of random values;

randomly assigning the random values to the entries of sensitive personal information and

sorting the plurality of entries of sensitive personal information such that their respective assigned random values are in numerical order.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2013
From: ARYA, SIDDHARTHA KUMAR
To: CELLCO PARTNERSHIP D/B/A VERIZON WIRELESS
Reel/Frame 030005/0542 →
Continuity (1)
Related Publication 20140283089A1 · Sep 18, 2014