IP Library › Granted Patent US 12,210,645
Granted Patent B1
US 12,210,645 · App. 18/783,300 · Granted Jan 28, 2025

Information compartmentalizing data store

Inventors: Suryakant Brahmbhatt (East Windsor, NJ); Sanjit Mehta (Bengaluru, IN); Mehak Mehta (Jersey City, NJ); Rahul Suresh (Bengaluru, IN)
Assignee: MORGAN STANLEY SERVICES GROUP INC.
G06F21/6218G06F21/1014
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,210,645
App. No.
18/783,300
Filed
Jul 24, 2024
Granted
Jan 28, 2025
Kind
B1
Art Unit
2433
USPC
726/26
Abstract

A computer-implemented method for extracting data from separate databases and loading the data into a central data store without introducing additional security vulnerabilities is disclosed. The method begins by receiving a configuration comprising one or more transformation functions to be applied to one or more data fields. Values of the one or more data fields are extracted from the databases for a plurality of records, the values being previously tagged with metadata indicating at least a datatype for the values. Based at least in part on the configuration and the metadata tagging, a function from the one or more transformation functions is selected for each value. A second database with a central data store is populated with transformed data. Requestors are not permitted to access to pre-transformed data in the first one or more databases while being allowed access to at least some post-transformed data in the central data store.

Claims (34)

1. A system for extracting data from separate databases and loading the data into a central data store without introducing additional security vulnerabilities, comprising:

a first one or more databases containing one or more data fields;

an extract transform and load server comprising one or more processors;

a second database acting as a central data store for data from the first one or more databases; and

non-transitory memory storing instructions that, when executed by the one or more processors, cause the one or more processors to:

receive a configuration comprising one or more transformation functions to be applied to the one or more data fields;

extract, from the first one or more databases, values of the one or more data fields for a plurality of records, the values being previously tagged with metadata indicating at least a datatype for the values;

based at least in part on the configuration and the metadata tagging, select for each value a function from the one or more transformation functions to be performed on that value;

populate the central data store with transformed data; and

enforce, by limiting query access, a constraint that a requestor is not permitted to access to pre-transformed data in the first one or more databases while allowing access to at least some post-transformed data in the central data store.

2. The system of claim 1 , further comprising one or more servers that host microservices, such that when the requestor makes a second query for access, the second query does not obtain data from the central data store, but rather receives information through a microservice that delineates a subset of data to be provided to the requestor.

3. The system of claim 1 , wherein the one or more transformation functions include a function for obfuscating data by masking.

4. The system of claim 1 , wherein the one or more transformation functions include a function for obfuscating data by tokenization.

5. The system of claim 1 , wherein the one or more transformation functions include a function for transforming data by bucketing.

6. The system of claim 1 , wherein the one or more transformation functions include a function for transforming data by a change in datatype.

7. The system of claim 1 , wherein the one or more transformation functions include a function for transforming data by aggregation.

8. The system of claim 1 , wherein the one or more transformation functions include a function for transforming data by deletion.

9. The system of claim 1 , wherein an application programming interface is provided to authenticate requests to access data from the data store and to provide a subset of data from the data store to an authenticated requestor.

10. The system of claim 1 , wherein the configuration comprises a first transformation function to be used on values of a first datatype when those values originate from a first application, and the configuration comprises a second transformation to be used on values of the first datatype when those values originate from a second application different from the first application.

11. A computer-implemented method for extracting data from separate databases and loading the data into a central data store without introducing additional security vulnerabilities, comprising:

receiving a configuration comprising one or more transformation functions to be applied to one or more data fields;

extracting, from a first one or more databases, values of the one or more data fields for a plurality of records, the values being previously tagged with metadata indicating at least a datatype for the values;

based at least in part on the configuration and the metadata tagging, selecting for each value a function from the one or more transformation functions to be performed on that value;

populating a second database with a central data store with transformed data; and

enforcing, by limiting query access, a constraint that a requestor is not permitted to access to pre-transformed data in the first one or more databases while allowing access to at least some post-transformed data in the central data store.

12. The method of claim 11 , wherein when the requestor makes a second query for access, the second query does not obtain data from the central data store, but rather receives information through a microservice that delineates a subset of data to be provided to the requestor.

13. The method of claim 11 , wherein the one or more transformation functions include a function for obfuscating data by masking.

14. The method of claim 11 , wherein the one or more transformation functions include a function for obfuscating data by tokenization.

15. The method of claim 11 , wherein the one or more transformation functions include a function for transforming data by bucketing.

16. The method of claim 11 , wherein the one or more transformation functions include a function for transforming data by a change in datatype.

17. The method of claim 11 , wherein the one or more transformation functions include a function for transforming data by aggregation.

18. The method of claim 11 , wherein the one or more transformation functions include a function for transforming data by deletion.

19. The method of claim 11 , wherein an application programming interface is provided to authenticate requests to access data from the data store and to provide a subset of data from the data store to an authenticated requestor.

20. The method of claim 11 , wherein the configuration comprises a first transformation function to be used on values of a first datatype when those values originate from a first application, and the configuration comprises a second transformation to be used on values of the first datatype when those values originate from a second application different from the first application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2024
From: BRAHMBHATT, SURYAKANT; MEHTA, SANJIT; MEHTA, MEHAK; SURESH, RAHUL
To: MORGAN STANLEY SERVICES GROUP INC.
Reel/Frame 068075/0988 →
References Cited (21)
US 9288184B1 · Kvamme et al. · 2016 [cited by applicant]
US 10685139B2 · Harp · 2020 [cited by examiner]
US 11522697B2 · Zimmer et al. · 2022 [cited by applicant]
US 20080270802A1 · Ashley et al. · 2008 [cited by applicant]
US 20150213288A1 · Bilodeau et al. · 2015 [cited by applicant]
US 20170126681A1 · Barrett · 2017 [cited by examiner]
US 20180285599A1 · Praveen et al. · 2018 [cited by applicant]
US 20190379642A1 · Simons et al. · 2019 [cited by applicant]
US 20200193057A1 · Yu et al. · 2020 [cited by applicant]
US 20210097197A1 · Kulkarni et al. · 2021 [cited by applicant]
US 20210165907A1 · Mann et al. · 2021 [cited by applicant]
US 20210173854A1 · Wilshinsky · 2021 [cited by applicant]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210391040A1 · Dormer et al. · 2021 [cited by applicant]
US 20220019687A1 · Poutra · 2022 [cited by examiner]
US 20220129582A1 · Lange · 2022 [cited by applicant]
US 20220138345A1 · Krishnan et al. · 2022 [cited by applicant]
US 20220156406A1 · Yang · 2022 [cited by applicant]
US 20220164478A1 · Fleck · 2022 [cited by applicant]
US 20220207181A1 · Ng · 2022 [cited by applicant]
US 20220300651A1 · Mondal et al. · 2022 [cited by applicant]
Cited By (1)
US 12,717,953