IP Library › Granted Patent US 12,248,612
Granted Patent B2
US 12,248,612 · App. 17/678,568 · Granted Mar 11, 2025

Data aggregation and anonymization in multi-tenant networks

Inventors: Joe Shea (Feasterville-Trevose, PA); Reddy Vijay Karthik Tummala (Pleasanton, CA); Muthanna Nischal Ammatanda (Fremont, CA); Abraham Benjamin de Waal (San Jose, CA)
Assignee: Hint, Inc.
G06F21/6254G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,612
App. No.
17/678,568
Granted
Mar 11, 2025
Kind
B2
Abstract

In some examples, a data aggregator and anonymizer is provided for selective encryption of test data. An example data aggregator and anonymizer can perform operations including receiving first order data from a first data source, the first order data including a mix of sensitive and non-sensitive information, the sensitive information including one or more of Personally Identifiable Information (PII), Protected Health Information (PHI) and Payment Card Industry (PCI) information; receiving second order data from a second data source, the second order data including a different mix of sensitive and non-sensitive information, the sensitive information including one or more of PII, PHI, and PCI information; combining and storing the first and second order data into an aggregated data structure, the aggregated data structure including layers in which stored data resides; identifying the sensitive information; encrypting identified sensitive information stored in at least one layer of the aggregated data structure to create an anonymous body of test data; storing the anonymous body of test data in a database; and providing access to the anonymous body of test data to the first or second data source or a third-party data analyzer.

Claims (44)

1. A data aggregator and anonymizer for selective encryption of test data, the data aggregator and anonymizer comprising:

a processor; and

a memory storing instructions that, when executed by the processor, configure the data aggregator and anonymizer to perform operations including:

receiving first order data from a first data source, the first order data including a mix of sensitive and non-sensitive information, the sensitive information including one or more of Personally Identifiable Information (PII), Protected Health Information (PHI) and Payment Card Industry (PCI) information;

receiving second order data from a second data source, the second order data including a different mix of sensitive and non-sensitive information, the sensitive information including one or more of PII, PHI, and PCI information;

wherein the first and second data sources are first and second tenants each comprising multiple users in a multitenant network, and wherein the data aggregator and anonymizer resides at a subscription service to which the first and second tenants subscribe;

combining and storing the first and second order data into an aggregated data structure, the aggregated data structure including layers in which stored data resides;

identifying the sensitive information in the first and second order data;

encrypting identified sensitive information stored in at least one layer of the aggregated data structure to create an anonymous body of test data;

storing the anonymous body of test data in a database; and

providing access to the anonymous body of test data to the first or second tenant, wherein providing access to the first or second tenant includes providing a decryption key to unlock a portion of the aggregated test data sourced from the first or second tenant supplying that portion, the decryption key disallowing decryption of any other portion of the aggregated test data.

2. The data aggregator and anonymizer of claim 1 , wherein encrypting the identified sensitive information includes applying an encryption to a first layer of the aggregated data structure, rendering sensitive data included in the first layer anonymous.

3. The data aggregator and anonymizer of claim 2 , wherein the first layer of the aggregated data structure is lower than a higher second layer in the aggregated data structure; and

wherein a user access to the lower first layer is wider than user access to the higher second layer.

4. The data aggregator and anonymizer of claim 3 , wherein sensitive data residing in the second layer in the aggregated data structure is not encrypted in the second layer and user access thereto is unrestricted.

5. The data aggregator and anonymizer of claim 1 , wherein the operations further comprise decrypting a processed portion of the anonymous body of test data when delivering or presenting the processed portion to one of the first and second data sources.

6. A method of data aggregation and anonymization for selective encryption of test data, the method comprising:

receiving first order data from a first data source, the first order data including a mix of sensitive and non-sensitive information, the sensitive information including one or more of Personally Identifiable Information (PII), Protected Health Information (PHI) and Payment Card Industry (PCI) information;

receiving second order data from a second data source, the second order data including a different mix of sensitive and non-sensitive information, the sensitive information including one or more of PII, PHI, and PCI information;

wherein the first and second data sources are first and second tenants each comprising multiple users in a multitenant network, and wherein the data aggregator and anonymizer resides at a subscription service to which the first and second tenants subscribe;

combining and storing the first and second order data into an aggregated data structure, the aggregated data structure including layers in which stored data resides;

identifying the sensitive information in the first and second order data;

encrypting identified sensitive information stored in at least one layer of the aggregated data structure to create an anonymous body of test data;

storing the anonymous body of test data in a database; and

providing access to the anonymous body of test data to the first or second tenant, wherein providing access to the first or second tenant includes providing a decryption key to unlock a portion of the aggregated test data sourced from the first or second tenant supplying that portion, the decryption key disallowing decryption of any other portion of the aggregated test data.

7. The method of claim 6 , wherein encrypting the identified sensitive information includes applying an encryption to a first layer of the aggregated data structure, rendering sensitive data included in the first layer anonymous.

8. The method of claim 7 , wherein the first layer of the aggregated data structure is lower than a higher second layer in the aggregated data structure; and

wherein a user access to the lower first layer is wider than user access to the higher second layer.

9. The method of claim 8 , wherein sensitive data residing in the second layer in the aggregated data structure is not encrypted in the second layer and user access thereto is unrestricted.

10. The method of claim 6 , further comprising decrypting a processed portion of the anonymous body of test data when delivering or presenting the processed portion to one of the first and second data sources.

11. A non-transitory, machine-readable medium including instructions which, when read by a machine, cause the machine to perform operations comprising:

receiving first order data from a first data source, the first order data including a mix of sensitive and non-sensitive information, the sensitive information including one or more of Personally Identifiable Information (PII), Protected Health Information (PHI) and Payment Card Industry (PCI) information;

receiving second order data from a second data source, the second order data including a different mix of sensitive and non-sensitive information, the sensitive information including one or more of PII, PHI, and PCI information;

wherein the first and second data sources are first and second tenants each comprising multiple users in a multitenant network, and wherein the data aggregator and anonymizer resides at a subscription service to which the first and second tenants subscribe;

combining and storing the first and second order data into an aggregated data structure, the aggregated data structure including layers in which stored data resides;

identifying the sensitive information in the first and second order data;

encrypting identified sensitive information stored in at least one layer of the aggregated data structure to create an anonymous body of test data;

storing the anonymous body of test data in a database; and

providing access to the anonymous body of test data to the first or second tenant, wherein providing access to the first or second tenant includes providing a decryption key to unlock a portion of the aggregated test data sourced from the first or second tenant supplying that portion, the decryption key disallowing decryption of any other portion of the aggregated test data.

12. The medium of claim 11 , wherein encrypting the identified sensitive information includes applying an encryption to a first layer of the aggregated data structure, rendering sensitive data included in the first layer anonymous.

13. The medium of claim 12 , wherein the first layer of the aggregated data structure is lower than a higher second layer in the aggregated data structure; and

wherein a user access to the lower first layer is wider than user access to the higher second layer.

14. The medium of claim 13 , wherein sensitive data residing in the second layer in the aggregated data structure is not encrypted in the second layer and user access thereto is unrestricted.

15. The medium of claim 14 , wherein the operations further comprise decrypting a processed portion of the anonymous body of test data when delivering or presenting the processed portion to one of the first and second data sources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2022
From: SHEA, JOE; TUMMALA, REDDY VIJAY KARTHIK; AMMATANDA, MUTHANNA NISCHAL; DE WAAL, ABRAHAM BENJAMIN
To: HINT, INC.
Reel/Frame 059079/0081 →
Continuity (1)
Related Publication 20230267229A1 · Aug 24, 2023
References Cited (51)
US 8566115B2 · Moore · 2013 [cited by examiner]
US 9202230B2 · Yarvis · 2015 [cited by examiner]
US 9619616B2 · Raduchel · 2017 [cited by examiner]
US 9665722B2 · Nagasundaram · 2017 [cited by examiner]
US 10007915B2 · Singh · 2018 [cited by examiner]
US 10204704B1 · Wurst · 2019 [cited by examiner]
US 10333901B1 · Bauman · 2019 [cited by examiner]
US 10404741B2 · Peteroy · 2019 [cited by examiner]
US 10614248B2 · Perkins · 2020 [cited by examiner]
US 11003793B2 · Gkoulalas-Divanis · 2021 [cited by examiner]
US 11106823B1 · Brook · 2021 [cited by examiner]
US 11297459B2 · Raduchel · 2022 [cited by examiner]
US 11301483B2 · Canel Lopez · 2022 [cited by examiner]
US 11431682B2 · Choudhury · 2022 [cited by examiner]
US 11875339B1 · Bunn · 2024 [cited by examiner]
US 20080005264A1 · Brunell · 2008 [cited by examiner]
US 20080040151A1 · Moore · 2008 [cited by examiner]
US 20100114920A1 · Srivastava · 2010 [cited by examiner]
US 20110161150A1 · Steffens · 2011 [cited by examiner]
US 20130325579A1 · Salmon · 2013 [cited by examiner]
US 20150278545A1 · Bigras · 2015 [cited by examiner]
US 20160050205A1 · Heller · 2016 [cited by examiner]
US 20160227438A1 · Bhanage · 2016 [cited by examiner]
US 20160283745A1 · LaFever · 2016 [cited by examiner]
US 20160321610A1 · Stein · 2016 [cited by examiner]
US 20160350481A1 · Wesemann · 2016 [cited by examiner]
US 20170124336A1 · Freudiger · 2017 [cited by examiner]
US 20180165702A1 · Ariff · 2018 [cited by examiner]
US 20190335326A1 · Al-Kabra · 2019 [cited by examiner]
US 20210126784A1 · Luce · 2021 [cited by examiner]
US 20210150269A1 · Choudhury · 2021 [cited by examiner]
US 20210182418A1 · Oqaily · 2021 [cited by examiner]
US 20210210160A1 · Shelton · 2021 [cited by examiner]
US 20210336938A1 · Karabatis · 2021 [cited by examiner]
US 20220050921A1 · LaFever · 2022 [cited by examiner]
US 20220131699A1 · Kimmel · 2022 [cited by examiner]
US 20230054446A1 · LaFever · 2023 [cited by examiner]
US 20230134781A1 · Senerth · 2023 [cited by examiner]
US 20230267229A1 · Shea · 2023 [cited by examiner]
US 20230316322A1 · Ammatanda · 2023 [cited by examiner]
AU 2013206026B2 · 2015 [cited by applicant]
“U.S. Appl. No. 17/711,283, Final Office Action mailed Jun. 2, 2023”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Response filed Jul. 24, 2023 to Final Office Action mailed Jun. 2, 2023”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Advisory Action mailed Aug. 15, 2023”, 3 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Response filed Sep. 5, 2023 to Advisory Action mailed Aug. 15, 2023”, 16 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Examiner Interview Summary mailed Sep. 11, 2023”, 2 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Notice of Allowance mailed Oct. 2, 2023”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Non Final Office Action mailed Sep. 2, 2022”, 13 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Non Final Office Action mailed Jan. 12, 2023”, 15 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Response filed Feb. 16, 2023 to Non Final Office Action mailed Jan. 12, 2023”, 17 pgs. [cited by applicant]
“U.S. Appl. No. 17/711,283, Response filed Oct. 28, 2022 to Non Final Office Action mailed Sep. 2, 2022”, 18 pgs. [cited by applicant]