IP Library › Granted Patent US 11,657,181
Granted Patent B2
US 11,657,181 · App. 17/590,121 · Granted May 23, 2023

System for improving data security through key management

Inventors: Venkatesh Sarvottamrao Apsingekar (San Jose, CA); Sahil Vinod Motadoo (Sunnyvale, CA); Christopher John Schille (San Jose, CA); James Francis Lavine (Corte Madera, CA)
Assignee: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
G06F21/6245H04L9/088H04L9/0825H04L9/0827H04L9/3213
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,657,181
App. No.
17/590,121
Granted
May 23, 2023
Kind
B2
Abstract

A system protects personally identifiable information (PII) by implementing an unconventional key management scheme. In this scheme, the system uses a set of keys rather than an individual key for encrypting PII. Different portions of the PII are encrypted using different keys from the set of keys. In this manner, even if a malicious user were to access a key, that key would not give the malicious user the ability to decrypt all of the PII. Additionally, the system generates a new set of keys periodically (e.g., once a month). The system also deletes sets of keys that are too old (e.g., six months old). As a result, even if a malicious user were to access a key, the usefulness of that key would be time limited.

Claims (50)

1. A system for securing personally identifiable information, the system comprising a token handler comprising:

a memory configured to store an encryption schedule comprising:

an indication that a first portion of a user's personally identifiable information was encrypted using a first public encryption key of a set of public encryption keys; and

an indication that a second portion of the user's personally identifiable information was encrypted using a second public encryption key of the set of public encryption keys; and

a hardware processor communicatively coupled to the memory, the hardware processor configured to:

receive, from a second system, a token indicating a request for redemption of the first and second portions of the user's personally identifiable information;

select, based on the encryption schedule, a first private encryption key corresponding to the first public encryption key;

decrypt, using the first private encryption key, the first portion of the user's personally identifiable information encrypted using the first public encryption key to produce the first portion of the user's personally identifiable information;

select, based on the encryption schedule, a second private encryption key of the token handler conesponding to the second public encryption key;

decrypt, using the second private encryption key, the second portion of the user's personally identifiable information encrypted using the second public encryption key to produce the second portion of the user's personally identifiable information;

determine that an age of the set of public encryption keys exceeds a time threshold; and

in response to determining that the age of the set of public encryption keys exceeds the time threshold:

encrypt, using a first public encryption key of a second set of public encryption keys, the first portion of the user's personally identifiable information;

encrypt, using a second public encryption key of the second set of public encryption keys, the second portion of the user's personally identifiable information; and

add, to the encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key of the second set of public encryption keys and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key of the second set of public encryption keys.

2. The system of claim 1 , wherein, in response to determining that the age of the set of public encryption keys exceeds the time threshold, the processor is further configured to verify the first portion of the user's personally identifiable information and the second portion of the user's personally identifiable information.

3. The system of claim 1 , wherein, in response to determining that the age of the set of public encryption keys exceeds the time threshold, the processor is configured to generate the second set of public encryption keys.

4. The system of claim 1 , wherein the processor is further configured to:

after determining that the age of the set of public encryption keys exceeds the predetermined time threshold, receive a token indicating a second request for redemption of the first and second portions of the user's personally identifiable information; and

reject the second request based on the determination that the age of the set of public encryption keys exceeds the predetermined threshold.

5. The system of claim 1 , wherein the processor is further configured to:

determine that a device separate from the token handler has established a connection with the token handler after receiving the token from the second system; and

in response to determining that the device has established the connection, communicate the encryption schedule to the device.

6. The system of claim 5 , wherein the processor is further configured to communicate the set of public encryption keys to the device.

7. The system of claim 1 , wherein determining that the age of the set of public encryption keys exceeds the time threshold comprises determining, based on an ordinal assigned to a key of the set of public encryption keys and on a number of keys in the set of public encryption keys, that an age of the key exceeds the time threshold.

8. The system of claim 1 , wherein the memory is configured to store a key vault comprising the set of public encryption keys and an ordinal assigned to each key of the set of public encryption keys.

9. The system of claim 8 , wherein the encryption schedule identifies the first public encryption key using the ordinal assigned to the first public encryption key in the key vault.

10. The system of claim 1 , wherein the system further comprises the second system which is configured to randomly select the first and second public encryption keys from the set of public encryption keys.

11. A method for securing personally identifiable information, the method comprising:

receiving a token indicating a request for redemption of a first portion of a user's personally identifiable information and a second portion of the user's personally identifiable information;

selecting, based on an encryption schedule, a first private encryption key corresponding to a first public encryption key of a set of public encryption keys, wherein the encryption schedule comprises an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key of the set of public encryption keys;

decrypting, using the first private encryption key, the first portion of the user's personally identifiable information encrypted using the first public encryption key to produce the first portion of the user's personally identifiable information;

selecting, based on the encryption schedule, a second private encryption key of the token handler corresponding to a second public encryption key of the set of public encryption keys, wherein the encryption schedule comprises an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key of the set of public encryption keys;

decrypting, using the second private encryption key, the second portion of the user's personally identifiable information encrypted using the second public encryption key to produce the second portion of the user's personally identifiable information;

determining that an age of the set of public encryption keys exceeds a time threshold; and

in response to determining that the age of the set of public encryption keys exceeds the time threshold:

encrypting, using a first public encryption key of a second set of public encryption keys, the first portion of the user's personally identifiable information;

encrypting, using a second public encryption key of the second set of public encryption keys, the second portion of the user's personally identifiable information; and

adding, to the encryption schedule, an indication that the first portion of the user's personally identifiable information was encrypted using the first public encryption key of the second set of public encryption keys and an indication that the second portion of the user's personally identifiable information was encrypted using the second public encryption key of the second set of public encryption keys.

12. The method of claim 11 , wherein, in response to determining that the age of the set of public encryption keys exceeds the time threshold, the method further comprises verifying the first portion of the user's personally identifiable information and the second portion of the user's personally identifiable information.

13. The method of claim 11 , wherein, in response to determining that the age of the set of public encryption keys exceeds the time threshold, the method further comprises generating the second set of public encryption keys.

14. The method of claim 11 , further comprising:

after determining that the age of the set of public encryption keys exceeds the predetermined time threshold, receiving a token indicating a second request for redemption of the first and second portions of the user's personally identifiable information; and

rejecting the second request based on the determination that the age of the set of public encryption keys exceeds the predetermined threshold.

15. The method of claim 11 , further comprising communicating the encryption schedule to a device that has received the token.

16. The method of claim 15 , further comprising communicating the set of public encryption keys to the device.

17. The method of claim 11 , wherein determining that the age of the set of public encryption keys exceeds the time threshold comprises determining, based on an ordinal assigned to a key of the set of public encryption keys and on a number of keys in the set of public encryption keys, that an age of the key exceeds the time threshold.

18. The method of claim 11 , further comprising storing a key vault comprising the set of public encryption keys and an ordinal assigned to each key of the set of public encryption keys.

19. The method of claim 18 , wherein the encryption schedule identifies the first public encryption key using the ordinal assigned to the first public encryption key in the key vault.

20. The method of claim 11 , wherein the first and second public encryption keys were randomly selected from the set of public encryption keys.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2022
From: APSINGEKAR, VENKATESH SARVOTTAMRAO; MOTADOO, SAHIL VINOD; SCHILLE, CHRISTOPHER JOHN; LAVINE, JAMES FRANCIS
To: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
Reel/Frame 058844/0460 →
Continuity (2)
Continuation 16807809 · Mar 3, 2020
Related Publication 20220156405A1 · May 19, 2022
Cited By (2)
US 12,556,907 US 12,664,308