IP Library › Granted Patent US 11,831,776
Granted Patent B2
US 11,831,776 · App. 18/190,753 · Granted Nov 28, 2023

System for improving data security

Inventors: Venkatesh Sarvottamrao Apsingekar (San Jose, CA); Sahil Vinod Motadoo (Sunnyvale, CA); Christopher John Schille (San Jose, CA); James Francis Lavine (Corte Madera, CA)
Assignee: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
H04L9/3213G06F21/602G06F21/6245H04L9/30H04L9/3226H04L63/0414
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,776
App. No.
18/190,753
Granted
Nov 28, 2023
Kind
B2
Abstract

A system allows a user to store his personally identifiable information (PII) on a personal device. When a third party wants to access the user's PII (e.g., to update the PII or to retrieve the PII), a notification will be presented to the user on the personal device seeking consent to the access. The notification may inform the user as to what information is being requested and which entity is requesting the access. The requested access will be denied unless the user consents to the access. In this manner, the user is given control over the dissemination of his PII. Additionally, the system alters or adjusts the PII that is stored in third-party servers so that even if these servers are breached, the user's actual PII is not exposed.

Claims (83)

1. A system for protecting personally identifiable information, the system comprising:

a hardware device configured to:

generate a public encryption key of the hardware device;

receive, from a user, personally identifiable information of the user; and

a hardware processor separates from the hardware device, the hardware processor configured to generate, based on the public encryption key of the hardware device, a public encryption key of the hardware processor;

wherein the hardware device is further configured to encrypt the personally identifiable information to produce first encrypted personally identifiable information using at least the public encryption key of the hardware processor;

wherein the hardware processor is further configured to:

receive the first encrypted personally identifiable information from the hardware device;

decrypt the first encrypted personally identifiable information to produce the personally identifiable information;

generate a token representing the personally identifiable information; and

receive the token indicating a request for the personally identifiable information;

wherein the hardware device is further configured to:

establish a connection with the hardware processor;

in response to receiving an indication of receipt of the token from the hardware processor, encrypt the personally identifiable information to produce second encrypted personally identifiable information; and

communicate the second encrypted personally identifiable information to the hardware processor.

2. The system of claim 1 , wherein the hardware processor is further configured to delete the public encryption key of the hardware processor in response to a determination that the public encryption key of the hardware processor has been active for a period of time that exceeds a threshold.

3. The system of claim 1 , further comprising a second hardware device, the hardware processor further configured to:

receive, from the second hardware device, a public encryption key of the second hardware device;

generate a second public encryption key of the hardware processor based on the public encryption key of the second hardware device; and

link the second hardware device to the hardware device, wherein the second hardware device is configured to download the personally identifiable information from a cloud after being linked to the hardware device.

4. The system of claim 3 , wherein:

the hardware processor is further configured to receive, from the second hardware device, a salted passphrase associated with the hardware device; and

linking the second hardware device to the hardware device is accomplished using the salted passphrase.

5. The system of claim 3 , wherein the second hardware device is further configured to delete the personally identifiable information from the cloud after downloading the personally identifiable information from the cloud.

6. The system of claim 1 , wherein:

the hardware processor is further configured to communicate the token to the hardware device; and

the hardware device is further configured to:

create a local repository;

store the token in the local repository; and

push the local repository to a cloud.

7. The system of claim 6 , wherein the hardware processor is further configured to:

encrypt a portion of the personally identifiable information using a public encryption key of an external system and the public encryption key of the hardware processor;

store, in the cloud, the portion of the personally identifiable information encrypted using the public encryption key of the external system and the public encryption key of the hardware processor;

receive a request for the portion of the personally identifiable information;

in response to the request for the portion of the personally identifiable information, retrieve, from the cloud, the portion of the personally identifiable information encrypted using the public encryption key of the external system and the public encryption key of the hardware processor; and

decrypt the encrypted portion of the personally identifiable information using a private encryption key of the hardware processor to produce the portion of the personally identifiable information encrypted using the public encryption key of the external system.

8. The system of claim 1 , wherein the hardware processor is further configured to:

adjust the personally identifiable information to produce anonymized data; and

generate an identifier for a ledger storing the anonymized data.

9. The system of claim 1 , wherein the hardware processor is further configured to:

receive a request to lock out the user;

receive the token indicating a second request for the personally identifiable information after receiving the request to lock out the user; and

in response to receiving the request to lock out the user, reject the second request for the personally identifiable information.

10. A method for protecting personally identifiable information, the method comprising:

generating, by a hardware device, a public encryption key of the hardware device;

receiving, from a user, by the hardware device, personally identifiable information of the user;

generating, by a hardware processor separate from the hardware device, a public encryption key of the hardware processor, wherein the public encryption key of the hardware processor is generated based on the public encryption key of the hardware device;

encrypting, by the hardware, the personally identifiable information to produce first encrypted personally identifiable information using at least the public encryption key of the hardware processor;

receiving, by the hardware processor, the first encrypted personally identifiable information from the hardware device;

decrypting, by the hardware processor, the first encrypted personally identifiable information to produce the personally identifiable information;

generating a token representing the personally identifiable information;

receiving, by the hardware processor, the token indicating a request for the personally identifiable information;

establishing, by the hardware device, a connection with the hardware processor;

in response to receiving an indication of receipt of the token from the hardware processor, encrypting, by the hardware device, the personally identifiable information to produce second encrypted personally identifiable information; and

communicating, by the hardware device, the second encrypted personally identifiable information to the hardware processor.

11. The method of claim 10 , further comprising deleting, by the hardware processor, the public encryption key of the hardware processor in response to a determination that the public encryption key of the hardware processor has been active for a period of time that exceeds a threshold.

12. The method of claim 10 , further comprising:

receiving, by the hardware processor, from a second hardware device, a public encryption key of the second hardware device;

generating, by the hardware processor, a second public encryption key of the hardware processor based on the public encryption key of the second hardware device;

linking, by the hardware processor, the second hardware device to the hardware device; and

downloading, by the second hardware device, the personally identifiable information from a cloud after being linked to the hardware device.

13. The method of claim 12 , further comprising:

receiving, from the second hardware device, a salted passphrase associated with the hardware device; and

linking the second hardware device to the hardware device is performed using the salted passphrase.

14. The method of claim 12 , further comprising deleting, by the second hardware device, the personally identifiable information from the cloud after downloading the personally identifiable information from the cloud.

15. The method of claim 10 , further comprising:

communicating, by the hardware processor, the token to the hardware device;

creating, by the hardware device, a local repository;

storing the token in the local repository; and

pushing the local repository to a cloud.

16. The method of claim 15 , further comprising:

encrypting, by the hardware processor, a portion of the personally identifiable information using a public encryption key of an external system and the public encryption key of the hardware processor;

storing, by the hardware processor, in the cloud, the portion of the personally identifiable information encrypted using the public encryption key of the external system and the public encryption key of the hardware processor;

receiving, by the hardware processor, a request for the portion of the personally identifiable information;

in response to the request for the portion of the personally identifiable information, retrieving, by the hardware processor, from the cloud, the portion of the personally identifiable information encrypted using the public encryption key of the external system and the public encryption key of the hardware processor; and

decrypting, by the hardware processor, the encrypted portion of the personally identifiable information using a private encryption key of the hardware processor to produce the portion of the personally identifiable information encrypted using the public encryption key of the external system.

17. The method of claim 10 , further comprising:

adjusting, by the hardware processor, the personally identifiable information to produce anonymized data; and

generating, by the hardware processor, an identifier for a ledger storing the anonymized data.

18. The method of claim 10 , further comprising:

receiving, by the hardware processor, a request to lock out the user;

receiving, by the hardware processor, the token indicating a second request for the personally identifiable information after receiving the request to lock out the user; and

in response to receiving the request to lock out the user, rejecting, by the hardware processor, the second request for the personally identifiable information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: APSINGEKAR, VENKATESH SARVOTTAMRAO; MOTADOO, SAHIL VINOD; SCHILLE, CHRISTOPHER JOHN; LAVINE, JAMES FRANCIS
To: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
Reel/Frame 063131/0400 →
Continuity (3)
Continuation 17518821 · Nov 4, 2021
Continuation 16807574 · Mar 3, 2020
Related Publication 20230246838A1 · Aug 3, 2023
Cited By (2)
US 12,192,187 US 12,556,907