IP Library Granted Patent US 10,025,941
Granted Patent B1
US 10,025,941 · App. 15/244,915 · Granted Jul 17, 2018

Data element tokenization management

Inventors: Phillip H. Griffin (Raleigh, NC); Jeffrey J. Stapleton (Arlington, TX)
Assignee: WELLS FARGO BANK, N.A.
G06F21/6209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,025,941
App. No.
15/244,915
Granted
Jul 17, 2018
Kind
B1
Abstract

Systems and methods to manage a tokenization manifest that can be used for managing a redaction through tokenization of a set of field level tokenization values applied to an arbitrary information object of an arbitrary file (e.g., database cells, XML and other document elements, areas of graphics images, etc.). The methods and system extend the use of tokenization to the protection of arbitrary fields or information objects of any type or format. This allows the tokenized components of the information object to be located and provided to a Tokenization Service Provider that can recover, for an authorized requestor, the original content protected by the token. The tokenization schema processes the unrestricted content into a corresponding restricted token. The token can include an embedded URL, where the URL is a link to submit a request to the Tokenization Service Provider to view the token as the unrestricted content.

Claims (45)

1. A method comprising:

receiving, by a tokenization service provider computing system, a file and a redaction service call, the redaction service call including selected file content and access information;

generating, by the computing system, a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema;

tokenizing, by the computing system, the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token,

wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier;

receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content;

retrieving, by the computing system, the access information associated with each requested token;

comparing, by the computing system, the authentication information to the access information;

extracting, by the computing system, the value of tokenSet in the nested token; and

detokenizing, by the computing system, the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet.

2. The method of claim 1 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization schema includes a user determining the selected file content and an output for the selected file content.

3. The method of claim 1 , wherein the tokenization schema is a random tokenization schema, wherein the random tokenization schema includes a random determination of the selected file content and an output for the selected file content.

4. The method of claim 1 , further comprising:

receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content;

retrieving, by the computing system, the access information associated with the token;

comparing, by the computing system, the authentication information to the access information; and

detokenizing, by the computing system, the token in the file.

5. The method of claim 1 , further comprising, transmitting, by the computing system, a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token.

6. The method of claim 1 , wherein the access information includes a user identifier and a password for each generated token in the file.

7. The method of claim 1 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link.

8. The method of claim 1 , the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized.

9. A system, comprising:

a network interface;

a redaction tokenization system comprising a processor and instructions stored in non-transitory machine-readable media, the instructions configured to cause the redaction tokenization system to:

receive a file and a redaction service call, the redaction service call including selected file content and access information;

generate a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema;

tokenize the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token,

wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier;

receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content;

retrieve, the access information associated with each requested token;

compare the authentication information to the access information;

extract the value of tokenSet in the nested token; and

detokenize the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet.

10. The system of claim 9 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization includes a user determining the selected file content and an output for the selected file content.

11. The system of claim 9 , wherein redaction service call further includes, a random tokenization schema, wherein the random tokenization includes a random determination of the selected file content and an output for the selected file content.

12. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to:

receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content;

retrieve the access information associated with the token;

compare the authentication information to the access information; and

detokenize the token in the file.

13. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to:

transmit a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token.

14. The system of claim 9 , wherein the access information includes a user identifier and a password for each generated token in the file.

15. The system of claim 9 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link.

16. The system of claim 9 , wherein the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2017
From: GRIFFIN, PHILLIP H.; STAPLETON, JEFFREY J.
To: WELLS FARGO BANK, N.A.
Reel/Frame 041018/0376 →
Cited By (30)
US 12,192,371 US 12,200,107 US 12,210,984 US 12,217,197 US 12,225,107 US 12,231,535 US 12,231,566 US 12,254,427 US 12,272,432 US 12,284,285 US 12,341,906 US 12,400,154 US 12,412,120 US 12,412,131 US 12,412,132 US 12,423,454 US 12,423,455 US 12,476,964 US 12,488,332 US 12,511,314 US 12,519,848 US 12,524,820 US 12,530,823 US 12,547,991 US 12,561,679 US 12,580,782 US 12,597,066 US 12,647,291 US 12,651,275 US 12,694,143