IP Library Granted Patent US 12,292,995
Granted Patent B2
US 12,292,995 · App. 18/190,870 · Granted May 6, 2025

Systems and methods for tokenization of personally identifiable information (PII)

Inventor: Tim M. Watkins (Chesterfield, MO)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
G06F21/6245G06F16/2379H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,995
App. No.
18/190,870
Filed
Mar 27, 2023
Granted
May 6, 2025
Kind
B2
Art Unit
2431
USPC
726/26
Abstract

Described herein is a data security system for enabling tokenized access to sensitive data, including a token provider configured to connect to a remote client computing device over a secure communication channel, and cause display, at the remote client computing device, of a token request user interface including a selection form listing sensitive data elements associated with a first data subject. The token provider is also configured to receive a request for an access token, including a user selection of a subset of the sensitive data elements and one or more access authorization parameters, and generate an access token that enables access to only the subset of the sensitive data elements according to the authorization parameters. The token provider also stores the access token in a token database with the one or more authorization parameters, and transmits, to the remote client computing device, a response including the access token.

Claims (59)

1. A data security system for enabling tokenized access to sensitive data, the data security system comprising a token provisioning computing device including a processor communicatively coupled to a memory device, the processor programmed to:

communicatively connect to a remote client computing device over a secure communication channel, the remote client computing device operated by a first data subject;

based on a subject identifier of the first data subject, determine a plurality of sensitive data elements about the first data subject stored in the memory device;

cause to display on the remote client computing device a token request user interface populated with a list of the plurality of sensitive data elements;

receive, from the remote client computing device, a request for an access token, the request including a user selection of a subset of the sensitive data elements selected by the first data subject on the token request user interface and one or more access authorization parameters;

generate an access token that enables access to only the subset of the sensitive data elements by an entity other than the first data subject or the remote computing device, according to the one or more authorization parameters;

store the access token in a token database with the one or more authorization parameters; and

transmit, to the remote client computing device, a response including the access token.

2. The data security system of claim 1 , wherein the processor is further programmed to receive, upon communicatively connecting to the remote client computing device, a subject identifier associated with the first data subject.

3. The data security system of claim 2 , wherein the processor is further programmed to:

access one or more data sources using the subject identifier to identify any sensitive data elements associated with the first data subject that are respectively stored at and available from the one or more data sources; and

generate the selection form based on all sensitive data elements available from the one or more data sources.

4. The data security system of claim 1 , wherein the one or more authorization parameters include at least one of a validity time/date parameter or an authorized service provider parameter.

5. The data security system of claim 1 , wherein the processor is further programmed to:

receive, from a service provider computing device separate from the remote client computing device, a data access request including an inputted access token;

compare the inputted access token to the access token stored in the token database; and

when the inputted access token matches the stored access token, transmit, to the service provider computing device, the subset of sensitive data elements associated with the stored access token.

6. The data security system of claim 1 , wherein the processor is further programmed to:

receive, from the remote client computing device, data subject input indicating a revocation of the access token; and

in response to receiving the data subject input, at least one of delete the stored access token or disable the stored access token to prevent further access to the sensitive data by a service provider.

7. The data security system of claim 1 , wherein the one or more authorization parameters include a validity date after which access to the sensitive data is revoked, and wherein the processor is further programmed to:

upon reaching the validity date, at least one of delete the stored access token or disable the stored access token to prevent further access to the sensitive data by a service provider.

8. The data security system of claim 1 , wherein the access token is one of alphanumeric code, a bar code, and a QR code.

9. The data security system of claim 1 , wherein the request further includes an authentication data element indicating the first data subject was successfully authenticated at the remote client computing device.

10. A computer-implemented method for enabling tokenized access to sensitive data, the method implemented using a data security system including a token provisioning computing device including a processor communicatively coupled to a memory device, the method comprising:

communicatively connecting to a remote client computing device over a secure communication channel, the remote client computing device operated by a first data subject;

based on a subject identifier of the first data subject, determining a plurality of sensitive data elements about the first data subject stored in the memory device;

causing to display on the remote client computing device a token request user interface populated with a list of the plurality of sensitive data elements;

receiving, from the remote client computing device, a request for an access token, the request including a user selection of a subset of the sensitive data elements selected by the first data subject on the token request user interface and one or more access authorization parameters;

generating an access token that enables access to only the subset of the sensitive data elements by an entity other than the first data subject or the remote computing device, according to the one or more authorization parameters;

storing the access token in a token database with the one or more authorization parameters; and

transmitting, to the remote client computing device, a response including the access token.

11. The computer-implemented method of claim 10 , further comprising receiving, upon communicatively connecting to the remote client computing device, a subject identifier associated with the first data subject.

12. The computer-implemented method of claim 11 , further comprising:

accessing one or more data sources using the subject identifier to identify any sensitive data elements associated with the first data subject that are respectively stored at and available from the one or more data sources; and

generating the selection form based on all sensitive data elements available from the one or more data sources.

13. The computer-implemented method of claim 10 , further comprising:

receiving, from a service provider computing device separate from the remote client computing device, a data access request including an inputted access token;

comparing the inputted access token to the access token stored in the token database; and

when the inputted access token matches the stored access token, transmitting, to the service provider computing device, the subset of sensitive data elements associated with the stored access token.

14. The computer-implemented method of claim 10 , further comprising:

receiving, from the remote client computing device, data subject input indicating a revocation of the access token; and

in response to receiving the data subject input, at least one of deleting the stored access token or disabling the stored access token to prevent further access to the sensitive data by a service provider.

15. The computer-implemented method of claim 10 , wherein the one or more authorization parameters include a validity date after which access to the sensitive data is revoked, the method further comprising:

upon reaching the validity date, at least one of deleting the stored access token or disabling the stored access token to prevent further access to the sensitive data by a service provider.

16. The computer-implemented method of claim 10 , wherein receiving the request comprises receiving the request further including an authentication data element indicating the first data subject was successfully authenticated at the remote client computing device.

17. A non-transitory computer-readable storage medium having computer-executable instructions stored thereon, wherein when executed by a processor of a token provisioning computing device of a data security computing system, the computer-executable instructions cause the processor to:

communicatively connect to a remote client computing device over a secure communication channel, the remote client computing device operated by a first data subject;

based on a subject identifier of the first data subject, determine a plurality of sensitive data elements about the first data subject stored in the memory device;

cause to display on the remote client computing device a token request user interface populated with a list of the plurality of sensitive data elements;

receive, from the remote client computing device, a request for an access token, the request including a user selection of a subset of the sensitive data elements selected by the first data subject on the token request user interface and one or more access authorization parameters;

generate an access token that enables access to only the subset of the sensitive data elements by an entity other than the first data subject or the remote computing device, according to the one or more authorization parameters;

store the access token in a token database with the one or more authorization parameters; and

transmit, to the remote client computing device, a response including the access token.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the computer-executable instructions further cause the processor to receive, upon communicatively connecting to the remote client computing device, a subject identifier associated with the first data subject.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the computer-executable instructions further cause the processor to:

access one or more data sources using the subject identifier to identify any sensitive data elements associated with the first data subject that are respectively stored at and available from the one or more data sources; and

generate the selection form based on all sensitive data elements available from the one or more data sources.

20. The non-transitory computer-readable storage medium of claim 17 , wherein the one or more authorization parameters include at least one of a validity time/date parameter or an authorized service provider parameter.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2023
From: WATKINS, TIM M.
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 063128/0457 →
Continuity (2)
Continuation 16936136 · Jul 22, 2020
Related Publication 20230237194A1 · Jul 27, 2023
References Cited (51)
US 9430652B1 · Mattsson et al. · 2016 [cited by applicant]
US 9430787B2 · Dezelak · 2016 [cited by examiner]
US 9684800B2 · Mattsson et al. · 2017 [cited by applicant]
US 9769159B2 · Bikkula · 2017 [cited by examiner]
US 9953171B2 · Saxena et al. · 2018 [cited by applicant]
US 10489784B2 · Bailey et al. · 2019 [cited by applicant]
US 10558963B2 · Desai et al. · 2020 [cited by applicant]
US 10635828B2 · Lin · 2020 [cited by applicant]
US 11004548B1 · Austin et al. · 2021 [cited by applicant]
US 11070980B1 · Hohler · 2021 [cited by examiner]
US 11494765B2 · Tadiparti · 2022 [cited by examiner]
US 20140020070A1 · Angal · 2014 [cited by examiner]
US 20140090027A1 · Tamura · 2014 [cited by examiner]
US 20160080364A1 · Karimzadeh et al. · 2016 [cited by applicant]
US 20170048221A1 · Melton et al. · 2017 [cited by applicant]
US 20170053139A1 · Schenk et al. · 2017 [cited by applicant]
US 20170068490A1 · Viswanathan · 2017 [cited by examiner]
US 20170076109A1 · Kaditz et al. · 2017 [cited by applicant]
US 20170076281A1 · Dawkins et al. · 2017 [cited by applicant]
US 20170344704A1 · Chu et al. · 2017 [cited by applicant]
US 20180032757A1 · Michael · 2018 [cited by applicant]
US 20180089461A1 · Williams · 2018 [cited by examiner]
US 20180108008A1 · Chumbley · 2018 [cited by examiner]
US 20180114036A1 · Spodak et al. · 2018 [cited by applicant]
US 20180139192A1 · Pishinov · 2018 [cited by examiner]
US 20180211055A1 · Balijepalli · 2018 [cited by examiner]
US 20190109830A1 · McFarland et al. · 2019 [cited by applicant]
US 20190295700A1 · Weinstock et al. · 2019 [cited by applicant]
US 20190304574A1 · Weinstock et al. · 2019 [cited by applicant]
US 20200145820A1 · Hoyer · 2020 [cited by applicant]
US 20200202996A1 · Rastogi · 2020 [cited by applicant]
US 20200211002A1 · Steinberg · 2020 [cited by examiner]
US 20200273017A1 · Mossoba et al. · 2020 [cited by applicant]
US 20200286607A1 · Abuzeni · 2020 [cited by applicant]
US 20200311299A1 · Amar · 2020 [cited by applicant]
US 20200327540A1 · Chavarria et al. · 2020 [cited by applicant]
US 20210058404A1 · D'Agostino et al. · 2021 [cited by applicant]
US 20210089667A1 · Kadiyala et al. · 2021 [cited by applicant]
US 20210099300A1 · Kurian · 2021 [cited by examiner]
US 20210168129A1 · Edwards · 2021 [cited by examiner]
US 20210281409A1 · Apsingekar et al. · 2021 [cited by applicant]
US 20210295280A1 · Blakesley et al. · 2021 [cited by applicant]
US 20220158987A1 · Kurian · 2022 [cited by examiner]
CN 103327002A · 2013 [cited by applicant]
CN 104641613B · 2018 [cited by examiner]
DE 102018103278A1 · 2019 [cited by applicant]
PCT International Search Report and Written Opinion, Application No. PCT/US2021/034496, dated Sep. 6, 2021, 10 pps. [cited by applicant]
Mitu Kumar Debnath et al., “A secure revocable personal health record system with policy-based fine-grained access control”, 2015 13th Annual Conference on Privacy, Security and Trust (PST), Sep. 3, 2015, 9 pages. [cited by applicant]
Roderick L B Neame, “Privacy protection for personal health information and shared care records”, Informatics in Primary Care, vol. 21, No. 2, Feb. 2014, pp. 84-91. [cited by applicant]
Hao Wang et al., “Secure Cloud-Based EHR System Using Attribute-Based Cryptosystem and Blockchain”, J. Med. Syst., vol. 42:152, 2018, 9 pages. [cited by applicant]
Axin Wu et al., “Efficient and privacy-preserving traceable attribute-based encryption in blockchain”, Annals of Telecommunications, vol. 74, 2019, pp. 401-411. [cited by applicant]