IP Library Granted Patent US 11,586,754
Granted Patent B2
US 11,586,754 · App. 17/114,693 · Granted Feb 21, 2023

Database system for protecting and securing stored data using a privacy switch

Inventors: Shamim A. Naqvi (Morristown, NJ); Robert F. Raucci (New York, NY); John Henry Friedman (New York, NY)
Assignee: Safelishare, Inc.
G06F21/6218G06F21/602G06F21/645H04L9/321H04L9/3218H04L9/3231H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,754
App. No.
17/114,693
Granted
Feb 21, 2023
Kind
B2
Abstract

Applications of the privacy switch technology are shown for handling data breaches in database systems, thereby providing fundamental improvements to the security and utility of database technology.

Claims (17)

1. A method for providing user data to a third party while maintaining user privacy, comprising:

establishing a session in a computing environment to execute a first executable computer code in a virtual machine, the first executable computer code being associated with a database provider;

causing a second executable computer code to be inserted into the session, the second executable computer code being associated with a verifying entity;

receiving a request from a third party from outside of the session to obtain user data for a user having a user data record maintained by the database provider, the request identifying the user by a designated identifier stored in the user data record, the designated identifier replacing at least one private attribute of the user data record, the at least one private attribute including one or more key attributes of the user data record, the user data record including an encrypted data object in which said at least one private attribute is encrypted;

responsive to the request, causing a third executable code to be inserted into the session, the third executable code being associated with a user communication device associated with the user;

further responsive to the request, causing the third executable code to send a credential to the second executable code within the session, the credential being associated with said at least one private attribute of the user data record;

upon verification of the credential by the second executable code, receiving in the session, from the third executable code, said at least one private attribute and the designated identifier; and

in response to receipt in the session of said at least one private attribute and the designated identifier, accessing the user data record stored in the database and verifying said at least one private attribute using the encrypted data object and, if verified, sending the user data record to the third party outside of the session without including said at least one private attribute.

2. The method of claim 1 , wherein the at least one private attribute that is replaced by the designated identifier is stored in the user communication device.

3. The method of claim 2 , wherein verification of the credential ensures that said at least one private attribute has not been altered by the user communication device.

4. The method of claim 3 , wherein verification of the credential further ensures that the user who stored the at least one private attribute in the user communication device is also the user who created the credential.

5. The method of claim 4 , wherein ensuring the user who stored the at least one private attribute in the user communication device is also the user who created the credential is accomplished using biometric data of the user and a user defined dataset.

6. The method of claim 1 , wherein the second and third executable computer codes are each executed in a virtual machine.

7. The method of claim 1 , wherein the second and third executable computer codes are executed in a common virtual machine.

8. The method of claim 1 , wherein the second and third executable computer codes are executed in different virtual machines.

9. The method of claim 1 , wherein the at least one private attribute includes a key attribute of the user data record.

10. The method of claim 1 , wherein sending the user data record to the third party without including said at least one private attribute includes sending the user data record to the third party of a communications network.

Continuity (4)
Division 15877527 · Jan 23, 2018
Continuation In Part 15671021 · Aug 7, 2017
Provisional Application 62371403 · Aug 5, 2016
Related Publication 20210192066A1 · Jun 24, 2021