IP Library Granted Patent US 12,248,607
Granted Patent B2
US 12,248,607 · App. 18/023,285 · Granted Mar 11, 2025

System and method for exchange of data without sharing personally identifiable information

Inventor: Collin Turney (Benton, AR)
Assignee: LiveRamp, Inc.
G06F21/6245G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,607
App. No.
18/023,285
Granted
Mar 11, 2025
Kind
B2
Abstract

A system provides for a client to receive enhancement data without having personally identifiable information leave its systems. The system receives access to a client configuration and a data graph to perform configuration defined filtering and aggregation steps to produce a set of client files. These files contain a hashed version of PII from the data graph. They are then used by the client to match the identity of its population of objects to keys, the keys also being included in the set of client files. The client associates corresponding keys with objects in its own data graph, then requests enhancement data using only the keys. The data is returned using the matched keys without the use of personally identifiable information.

Claims (37)

1. A method for sharing information without revealing personally identifiable information (PII) from a client computing system operating within a cloud-computing environment comprising a plurality of virtual machines, the method comprising the steps of:

at an information service provider computing system, constructing a configuration, wherein the configuration comprises a filter parameter, an output fields parameter, and an output files parameter;

performing a document filter, wherein a set of objects from a document table are partitioned into multiple document table partitions, each of which are filtered in parallel on a plurality of virtual machines executing simultaneously in the cloud-computing environment to omit restricted objects according to the filter parameter of the configuration to produce a set of filtered objects;

performing an entity summarizer, wherein the filtered objects in the multiple document table partitions are grouped based on a link associated with the object in the document table, and wherein a ranked summary of the requested fields is constructed based on the output fields parameter of the configuration;

performing an output formatter, wherein the ranked summary of the requested fields is applied to the filtered objects to produce formatted filtered objects based on the output files parameter of the configuration;

performing an output writer, wherein the formatted filtered objects are divided into a plurality of output file partitions according to the output files parameter of the configuration, wherein a size of each of the plurality of output file partitions is determined based on a file-size capability of the client system;

transmitting the plurality of output file partitions to the client system, the client system comprising a client data graph comprising a plurality of client objects;

at the client system, using the plurality of output file partitions to match client objects in the client data graph with corresponding client-specific keys; and

appending the client-specific keys to the corresponding client objects in the client data graph, wherein no PII is sent from the client system to the information service provider computing system, thereby preventing any inadvertent disclosure of PII outside of the client system.

2. The method of claim 1 , wherein the step of performing the output writer further comprises the step of compressing the formatted filtered objects.

3. The method of claim 1 , wherein the formatted filtered objects each comprise a client-specific key, wherein the set of client-specific keys comprises one and only one key for each object in the document table.

4. The method of claim 3 , further comprising the step of, after performing the output writer, constructing an XREF file comprising a table of internal keys and matched client-specific keys.

5. The method of claim 4 , wherein the output fields parameter further comprises a description of fields to be included in the formatted filtered objects.

6. The method of claim 5 , wherein the description of fields to be included in the formatted filtered objects comprises a number of at least one field type to be included in the formatted filtered objects.

7. The method of claim 5 , wherein the output fields parameter further comprises a type of encryption to be applied to the objects from within the set of objects.

8. The method of claim 5 , wherein the output fields parameter further comprises a description of keys to be included with the objects from within the set of objects.

9. The method of claim 8 , wherein the description of keys to be included comprises the internal keys.

10. The method of claim 9 , wherein the description of keys to be included comprises the client-specific keys.

11. The method of claim 4 , wherein the client-specific keys comprise a string concatenated with a salt.

12. The method of claim 1 , wherein the filter parameter further comprises a description of a population of objects to be selected from the document table.

13. The method of claim 12 , wherein the filter parameter comprises a restriction on objects approved only for distribution of hashed object representations.

14. The method of claim 1 , wherein the output file partitions comprise no unencrypted PII.

15. The method of claim 1 , further comprising the step of sending an enhancement request from the client system to the information provider system, wherein the request comprises a set of client-specific keys.

16. The method of claim 15 , further comprising the step of, at the information provider system, receiving the enhancement request and applying the XREF table to convert the client-specific keys to the corresponding internal keys.

17. The method of claim 1 , wherein the configuration comprises an entity resolution file (ERF) data file.

18. A system for providing enhancement data in a data graph at a client system, the system comprising an information service provider computer system operating within a cloud-computing environment comprising a plurality of virtual machines, the information service provider computer system comprising one or more processors and a non-transitory computer readable medium having stored thereon software instructions that, when executed by the one or more processors, cause the one or more processors to:

construct a configuration, wherein the configuration comprises a filter parameter, an output fields parameter, and an output files parameter;

perform a document filter, wherein a set of objects from the data graph are partitioned into multiple document table partitions, each of which are filtered in parallel on a plurality of virtual machines executing simultaneously in the cloud-computing environment to omit restricted objects according to the filter parameter of the configuration to produce a set of filtered objects;

execute an entity summarizer, wherein the filtered objects in the multiple document table partitions are grouped based on a link associated with the object in the data graph, and wherein a ranked summary of the requested fields is constructed based on the output fields parameter of the configuration;

execute an output formatter, wherein the ranked summary of the requested fields is applied to the filtered objects to produce formatted filtered objects based on the output files parameter of the configuration;

execute an output writer, wherein the formatted filtered objects are divided into a plurality of output file partitions according to the output files parameter of the configuration, further wherein a size of each of the plurality of output file partitions is determined based on a file-size capability of the client system, and further wherein the output file partitions comprise no unencrypted personally identifiable information; and

transmit the plurality of output file partitions to the client system,

wherein the information service provider computer system is configured to not receive PII from the client system, thereby preventing any inadvertent disclosure of PII outside of the client system.

19. The system of claim 18 , wherein the software instructions, when executed by the one or more processors, further cause the one or more processors to construct a cross-reference file comprising a set of internal keys and a corresponding set of client keys, and apply the cross-reference file to the output file partitions to match a set of client objects in a client data graph with the set of client keys.

20. The system of claim 18 , wherein the client system operates within a cloud-computing environment comprising a plurality of virtual machines, the client system comprising one or more processors and a non-transitory computer readable medium having stored thereon software instructions that, when executed by the one or more processors, cause the one or more processors to:

use the plurality of output file partitions to match client objects in the client data graph with corresponding client-specific keys; and

append the client-specific keys to the corresponding client objects in the client data graph.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: TURNEY, COLLIN
To: LIVERAMP, INC.
Reel/Frame 062801/0237 →
Continuity (2)
Provisional Application 63074295 · Sep 3, 2020
Related Publication 20230315901A1 · Oct 5, 2023
References Cited (30)
US 6523041B1 · Morgan et al. · 2003 [cited by applicant]
US 8639920B2 · Stack et al. · 2014 [cited by applicant]
US 8838629B2 · Dedeoglu et al. · 2014 [cited by applicant]
US 9037637B2 · Jaye et al. · 2015 [cited by applicant]
US 9288184B1 · Kvamme et al. · 2016 [cited by applicant]
US 9355273B2 · Stevens et al. · 2016 [cited by applicant]
US 9608810B1 · Ghetti · 2017 [cited by examiner]
US 9760697B1 · Walker · 2017 [cited by applicant]
US 10044654B2 · Papa et al. · 2018 [cited by applicant]
US 10055747B1 · Sherman et al. · 2018 [cited by applicant]
US 10496847B2 · Fineman et al. · 2019 [cited by applicant]
US 11120144B1 · Kassam-Adams · 2021 [cited by examiner]
US 11620673B1 · Paquette · 2023 [cited by examiner]
US 20060080554A1 · McDonald · 2006 [cited by examiner]
US 20100036884A1 · Brown · 2010 [cited by applicant]
US 20130125202A1 · Sprague · 2013 [cited by examiner]
US 20130318347A1 · Moffat · 2013 [cited by examiner]
US 20140041047A1 · Jaye et al. · 2014 [cited by applicant]
US 20140177833A1 · Helms · 2014 [cited by examiner]
US 20150081562A1 · Roullier et al. · 2015 [cited by applicant]
US 20160342738A1 · Stalling et al. · 2016 [cited by applicant]
US 20170140174A1 · Lacey · 2017 [cited by examiner]
US 20230059328A1 · Roberts · 2023 [cited by examiner]
EP 3040898A1 · 2016 [cited by applicant]
NPL Search Terms (Year: 2024). [cited by examiner]
NPL Search Terms (Year: 2025). [cited by examiner]
Gibson, Neal et al., “TrustEd: A Dual-Database Trusted Broker for Multi-Agency Data,” 2013 Int'l Conf. on Social Computing, pp. 999-1004 (Sep. 2013). [cited by applicant]
Li, Yibin et al., “Intelligent Cryptography Approach for Secure Distributed Big Data Storage in Cloud Computing,” Information Sciences (2016). [cited by applicant]
Chadwick, David W., “Federated Identity Management,” Foundations of Security Analysis and Design V, pp. 96-120 (Aug. 30, 2009). [cited by applicant]
Extended European Search Report for application No. 21864872.3 (issued Aug. 8, 2024). [cited by applicant]
Cited By (1)
US 12,418,515