IP Library › Granted Patent US 12,210,598
Granted Patent B2
US 12,210,598 · App. 18/471,941 · Granted Jan 28, 2025

System for improving data security when redeeming data

Inventors: Venkatesh Sarvottamrao Apsingekar (San Jose, CA); Sahil Vinod Motadoo (Sunnyvale, CA); Christopher John Schille (San Jose, CA); James Francis Lavine (Corte Madera, CA)
Assignee: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
G06F21/313G06F21/602G06F21/604G06F21/6245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,598
App. No.
18/471,941
Granted
Jan 28, 2025
Kind
B2
Abstract

When personally identifiable information (PII) is to be stored or updated, a system first seeks consent from the user for the PII store or update. If the user grants consent, then the system stores the PII in the user's personal device or updates the PII stored in the user's personal device. The system then retrieves that PII and generates a token representing that PII. Even if the token were taken by a malicious user, it would not be possible for the malicious user to determine the user's actual PII from the token. In this manner, the security of the PII is improved over conventional systems.

Claims (66)

1. A system for retrieving personally identifiable information, the system comprising:

a hardware processor;

a computing device of a user separate from the hardware processor, the computing device configured to:

store personally identifiable information encrypted using a first public encryption key;

establish a connection with the hardware processor;

after establishing the connection, request consent from the user to redeem the personally identifiable information;

in response to receiving the consent from the user:

encrypt, using a second public encryption key, the personally identifiable information encrypted using the first public encryption key to produce the personally identifiable information encrypted using the first public encryption key and the second public encryption key; and

communicate the personally identifiable information encrypted using the first public encryption key and the second public encryption key to the hardware processor.

2. The system of claim 1 , wherein:

the system further comprises a second system, the second system configured to:

retrieve, from the hardware processor, the personally identifiable information encrypted using the first public encryption key and the second public encryption key;

decrypt, using a first private encryption key, the personally identifiable information encrypted using the first public encryption key and the second public encryption key, to produce the personally identifiable information encrypted using the first public encryption key; and

communicate, to the hardware processor, the personally identifiable information encrypted using the first public encryption key; and

the hardware processor is further configured to:

decrypt, using a second private encryption key, the personally identifiable information encrypted using the first public encryption key to produce the personally identifiable information; and

provide the personally identifiable information to the second system.

3. The system of claim 2 , wherein the hardware processor is further configured to provide the personally identifiable information to the second system through a phone call.

4. The system of claim 2 , wherein:

the hardware processor is further configured to update a status of the request in response to receiving the personally identifiable information encrypted using the first public encryption key and the second public encryption key; and

the system further comprises the second system, the second system configured to retrieve the personally identifiable information encrypted using the first public encryption key and the second public encryption key from a cache associated with the hardware processor, in response to the update of the status of the request.

5. The system of claim 1 , wherein:

the computing device of the user is further configured to generate a salted passphrase of the user by:

receiving a passphrase from the user; and

hashing the passphrase with a phone number and an email address of the user to produce the salted passphrase; and

the hardware processor is further configured to generate the first public encryption key using a public encryption key for the computing device.

6. The system of claim 1 , wherein the hardware processor is further configured to, in response to receiving a token, wait for the computing device to establish the connection.

7. The system of claim 1 , wherein the hardware processor is further configured to:

receive, from the second system, a request for a portion of the personally identifiable information;

in response to receiving the request for the portion of the personally identifiable information, retrieve, from a repository in a cloud, the portion of the personally identifiable information encrypted using the first public encryption key and the second public encryption key; and

decrypt, using a first private encryption key, the portion of the personally identifiable information encrypted using the first public encryption key and the second public encryption key to produce the portion of the personally identifiable information encrypted using the second public encryption key.

8. The system of claim 1 , wherein the computing device is further configured to communicate a token to the hardware processor.

9. The system of claim 1 , wherein the hardware processor is further configured to:

retrieve, based on a token, the second public encryption key; and

communicate the second public encryption key to the computing device.

10. The system of claim 1 , wherein the system further comprises the second system, the second system configured to retrieve a token from a database associated with the second system.

11. A method for retrieving personally identifiable information, the method comprising:

storing, by a computing device separate from the hardware processor, personally identifiable information encrypted using a first public encryption key;

establishing, by the computing device, a connection with the hardware processor;

after establishing the connection, requesting, by the computing device, consent from a user to redeem the personally identifiable information;

in response to receiving the consent from the user:

encrypting, by the computing device, using a second public encryption key, the personally identifiable information encrypted using the first public encryption key to produce the personally identifiable information encrypted using the first public encryption key and the second public encryption key; and

communicating, by the computing device, the personally identifiable information encrypted using the first public encryption key and the second public encryption key to the hardware processor.

12. The method of claim 11 , further comprising:

retrieving, by the external system, from the hardware processor, the personally identifiable information encrypted using the first public encryption key and the second public encryption key;

decrypting, by the external system, using a first private encryption key, the personally identifiable information encrypted using the first public encryption key and the second public encryption key, to produce the personally identifiable information encrypted using the first public encryption key;

communicating, by the external system, to the hardware processor, the personally identifiable information encrypted using the first public encryption key;

decrypting, by the hardware processor, using a second private encryption key, the personally identifiable information encrypted using the first public encryption key to produce the personally identifiable information; and

providing, by the hardware processor, the personally identifiable information to the external system.

13. The method of claim 12 , wherein providing, by the hardware processor, the personally identifiable information to the external system comprises providing the personally identifiable information to the external system through a phone call.

14. The method of claim 12 , further comprising updating, by the hardware processor, a status of the request in response to receiving the personally identifiable information encrypted using the first public encryption key and the second public encryption key, wherein the external system retrieves the personally identifiable information encrypted using the first public encryption key and the second public encryption key from a cache associated with the hardware processor in response to the update of the status of the request.

15. The method of claim 11 , further comprising:

generating, by the computing device of the user, a salted passphrase of the user by:

receiving a passphrase from the user; and

hashing the passphrase with a phone number and an email address of the user to produce the salted passphrase; and

generating, by the hardware processor, the first public encryption key using a public encryption key for the computing device.

16. The method of claim 11 , further comprising, in response to receiving a token, waiting, by the hardware processor, for the computing device to establish the connection.

17. The method of claim 11 , further comprising:

receiving, by the hardware processor, from the external system, a request for a portion of the personally identifiable information;

in response to receiving the request for the portion of the personally identifiable information, retrieving, by the hardware processor, from a repository in a cloud, the portion of the personally identifiable information encrypted using the first public encryption key and the second public encryption key; and

decrypting, by the hardware processor, using a first private encryption key, the portion of the personally identifiable information encrypted using the first public encryption key and the second public encryption key to produce the portion of the personally identifiable information encrypted using the second public encryption key.

18. The method of claim 11 , further comprising communicating, by the computing device, a token to the hardware processor.

19. The method of claim 11 , further comprising:

retrieving, by the hardware processor, based on a token, the second public encryption key; and

communicating, by the hardware processor, the second public encryption key to the computing device.

20. The method of claim 11 , further comprising retrieving, by the external system, a token from a database of the external system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2023
From: APSINGEKAR, VENKATESH SARVOTTAMRAO; MOTADOO, SAHIL VINOD; SCHILLE, CHRISTOPHER JOHN; LAVINE, JAMES FRANCIS
To: THE PRUDENTIAL INSURANCE COMPANY OF AMERICA
Reel/Frame 064987/0743 →
Continuity (3)
Continuation 17693648 · Mar 14, 2022
Continuation 16807646 · Mar 3, 2020
Related Publication 20240086504A1 · Mar 14, 2024
References Cited (28)
US 7194618B1 · Suominen · 2007 [cited by examiner]
US 10552637B1 · Phillips · 2020 [cited by examiner]
US 20020010679A1 · Felsher · 2002 [cited by examiner]
US 20140013452A1 · Aissi · 2014 [cited by examiner]
US 20150149362A1 · Baum · 2015 [cited by examiner]
US 20150332029A1 · Coxe · 2015 [cited by examiner]
US 20160098577A1 · Lacey · 2016 [cited by examiner]
US 20160147945A1 · MacCarthy · 2016 [cited by examiner]
US 20170132431A1 · Gonzalez Blanco · 2017 [cited by examiner]
US 20170140174A1 · Lacey · 2017 [cited by examiner]
US 20170148014A1 · Bouse · 2017 [cited by examiner]
US 20170193249A1 · Luria · 2017 [cited by examiner]
US 20190036708A1 · Fregly · 2019 [cited by examiner]
US 20190108255A1 · Tabak · 2019 [cited by examiner]
US 20190109706A1 · Peterson · 2019 [cited by examiner]
US 20190109830A1 · McFarland · 2019 [cited by examiner]
US 20200145498A1 · Grayson · 2020 [cited by examiner]
US 20200311299A1 · Amar · 2020 [cited by examiner]
US 20200327540A1 · Chavarria · 2020 [cited by examiner]
US 20200374129A1 · Dilles · 2020 [cited by examiner]
US 20200387623A1 · Bayon · 2020 [cited by examiner]
US 20200396221A1 · Shaffer · 2020 [cited by examiner]
US 20210224788A1 · Kurylko · 2021 [cited by examiner]
US 20210390196A1 · Lavine · 2021 [cited by examiner]
US 20220311597A1 · Goel · 2022 [cited by examiner]
U.S. Appl. No. 16/807,574, filed Mar. 3, 2020 (Apsingekar). [cited by applicant]
U.S. Appl. No. 16/807,733, filed Mar. 3, 2020 (Apsingekar). [cited by applicant]
U.S. Appl. No. 16/807,809, filed Mar. 3, 2020 (Apsingekar). [cited by applicant]