IP Library Granted Patent US 12,353,589
Granted Patent B1
US 12,353,589 · App. 17/208,952 · Granted Jul 8, 2025

Method and apparatus for protecting sensitive data

Inventors: Patrick Brown (Parker, CO); James Mitch (Lone Tree, CO); Michael Verlare (Centennial, CO)
Assignee: INTRANEXT SOFTWARE, INC.
G06F21/6245G06Q20/10H04M3/5183H04M2203/6009
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,589
App. No.
17/208,952
Granted
Jul 8, 2025
Kind
B1
Abstract

In accordance with one embodiment, an apparatus is provided that includes a computer processor coupled with a call center device positioned to receive an input communication containing PII data and originating from a telephone caller, wherein the computer processor implements code to suppress at least a portion of the received PII data without requiring a physical interrupt of the input communication so that the received PII data is not conveyed to a call center agent or to a computer of the call center agent.

Claims (50)

1. A method comprising:

establishing a hardware connection between a telephone caller and a call center agent;

then, receiving at a call center a triggering signal indicating that Personally Identifiable Information (PII) data is about to be sent from the telephone caller and wherein the triggering signal does not signal that a physical interruption of the hardware connection should be implemented;

receiving at a call center an input communication originating from the telephone caller and comprising PII data;

in response to the triggering signal, detecting the PII data in the received input communication by analyzing the received input communication;

suppressing at least a portion of the received PII data in response to the detecting the PII data in the received input communication without altering the hardware connection between the telephone caller and the call center agent.

2. The method of claim 1 and further comprising:

maintaining a voice connection between the telephone caller and the call center agent while the PII data is suppressed.

3. The method of claim 1 and further comprising:

conveying a remainder of the input communication to the call center agent or to a computer of the call center agent.

4. The method of claim 1 and further comprising:

determining that the input communication includes PII data before the suppressing of the PII data.

5. The method of claim 4 wherein the determining that the input communication includes PII data comprises:

receiving an input signal that a payment web page has been served to the computer of a call center agent.

6. The method of claim 4 wherein the determining that the input communication includes PII data comprises:

receiving an input signal that the call center agent has activated a payment interface.

7. The method of claim 4 wherein the determining that the input communication includes PII data comprises:

determining that the call center agent is using a cursor in a payment graphical user interface.

8. The method of claim 1 and further comprising:

preventing physical storage of transient PII data before handing off the PII data to an adjunct process.

9. The method of claim 1 wherein suppressing the PII data from the input communication comprises:

suppressing at least a portion of the received PII data without pausing call monitoring of the input communication.

10. The method of claim 1 wherein suppressing the PII data comprises:

removing the PII data from the communication.

11. The method of claim 1 wherein suppressing the PII data comprises:

replacing the PII data with proxy tone data.

12. The method of claim 1 wherein suppressing the PII data comprises:

intercepting and manipulating Voice Over IP (VOIP) packets containing PII data.

13. The method of claim 1 and further comprising:

providing a visual proxy for a PII data number on a computer of the call center agent to indicate an entry of the PII data number by the telephone caller.

14. The method of claim 1 and further comprising:

muting a connection between the telephone caller and the call center agent for a portion of the time that PII data is entered by the telephone caller;

unmuting the connection between the telephone caller and the call center agent for a remaining portion of the time that the PII data is entered by the telephone caller.

15. The method of claim 1 wherein the suppressing of the PII data is implemented without having to hardware-terminate and regenerate the input communication in order to suppress the PII data.

16. An apparatus comprising:

a computer processing unit (CPU),

wherein the CPU is configured to respond to a triggering signal received at a call center indicating that Personally Identifiable Information (PII) data is about to be sent from a telephone caller and wherein the triggering signal does not signal that a physical interruption of a hardware connection between the telephone caller and the call center should be implemented; and

wherein the CPU is coupled with a call center device positioned to receive an input communication containing the PII data and originating from a telephone caller;

wherein the CPU is configured to detect the PII data in the received input communication by analyzing the received input communication;

wherein the CPU is configured to suppress at least a portion of the PII data in response to the detecting of the PII data in the received input communication.

17. The apparatus of claim 16 wherein the CPU is configured to implement code to cause a voice connection between the telephone caller and the call center agent to be maintained while the PII data is suppressed.

18. The apparatus of claim 16 wherein the CPU is configured to implement code to cause the call center device to convey a remainder of the input communication to the call center agent or to the computer of the call center agent.

19. The apparatus of claim 16 wherein the CPU implements code to cause a determination that the input communication includes Personally Identifiable Information (PII) data before the suppressing of the PII data.

20. A method comprising:

receiving at a Personally Identifiable Information Data Suppression server disposed within a physically secure facility in compliance with the Payment Card Industry-Data Security Standard (PCI-DSS) a triggering signal indicating that Personally Identifiable Information (PII) data is about to be sent from a telephone caller and wherein the triggering signal does not signal that a physical interruption of a hardware connection between the telephone caller and a call center should be implemented;

receiving at the call center an input communication originating from the telephone caller and comprising PII data;

in response to the triggering signal, detecting the PII data in the received input communication by analyzing the received input communication;

suppressing at least a portion of the received PII data without requiring a physical interrupt of the input communication;

conveying the PII data to the Personally Identifiable Information Data Suppression server;

conveying the PII data from the Personally Identifiable Information Data Suppression server to a payment gateway.

Continuity (5)
Continuation 15882388 · Jan 29, 2018
Continuation 15170723 · Jun 1, 2016
Provisional Application 62331938 · May 4, 2016
Provisional Application 62291288 · Feb 4, 2016
Provisional Application 62221964 · Sep 22, 2015
References Cited (69)
US 5790798A · Beckett · 1998 [cited by applicant]
US 5870464A · Brewster · 1999 [cited by examiner]
US 5953332A · Miloslavsky · 1999 [cited by examiner]
US 6871213B1 · Graham · 2005 [cited by applicant]
US 7130800B1 · Currey et al. · 2006 [cited by applicant]
US 8275115B1 · Everingham · 2012 [cited by examiner]
US 8315867B1 · Blair · 2012 [cited by examiner]
US 8582764B2 · Van Volkenburgh · 2013 [cited by applicant]
US 8619951B2 · Johansen et al. · 2013 [cited by applicant]
US 8639920B2 · Stack · 2014 [cited by examiner]
US 8706486B1 · Devarajan et al. · 2014 [cited by applicant]
US 8750417B2 · Zhu et al. · 2014 [cited by applicant]
US 8750471B2 · Tew et al. · 2014 [cited by applicant]
US 8831204B1 · Pycko · 2014 [cited by examiner]
US 8958557B2 · Watson et al. · 2015 [cited by applicant]
US 9100484B1 · Kleck · 2015 [cited by examiner]
US 9160853B1 · Daddi · 2015 [cited by applicant]
US 9178974B2 · Ross et al. · 2015 [cited by applicant]
US 9307084B1 · Pycko · 2016 [cited by applicant]
US 9699317B1 · Pycko · 2017 [cited by applicant]
US 9858573B2 · Tew et al. · 2018 [cited by applicant]
US 9881178B1 · Brown et al. · 2018 [cited by applicant]
US 10402826B2 · Tew et al. · 2019 [cited by applicant]
US 10956605B1 · Brown et al. · 2021 [cited by applicant]
US 11049108B2 · Tew et al. · 2021 [cited by applicant]
US 11445363B1 · Brown et al. · 2022 [cited by applicant]
US 12126991B1 · Brown · 2024 [cited by applicant]
US 20030069804A1 · Barry · 2003 [cited by examiner]
US 20040213390A1 · Lazarus · 2004 [cited by applicant]
US 20050246242A1 · Proctor · 2005 [cited by examiner]
US 20050273842A1 · Wright · 2005 [cited by examiner]
US 20060190263A1 · Finke · 2006 [cited by applicant]
US 20070106892A1 · Engberg · 2007 [cited by examiner]
US 20070174390A1 · Silvain · 2007 [cited by applicant]
US 20070242658A1 · Rae · 2007 [cited by applicant]
US 20080224906A1 · Plamondon · 2008 [cited by examiner]
US 20080291901A1 · Stratton · 2008 [cited by applicant]
US 20090046841A1 · Hodge · 2009 [cited by applicant]
US 20090199015A1 · Krishnapuram · 2009 [cited by applicant]
US 20090310774A1 · Hendricks · 2009 [cited by applicant]
US 20100167692A1 · Haynes · 2010 [cited by applicant]
US 20100202611A1 · Watson · 2010 [cited by examiner]
US 20100241844A1 · Hussain · 2010 [cited by applicant]
US 20100257612A1 · McGuire · 2010 [cited by applicant]
US 20110228919A1 · Tew · 2011 [cited by applicant]
US 20110317828A1 · Corfield · 2011 [cited by applicant]
US 20120027195A1 · Shaffer · 2012 [cited by applicant]
US 20120288082A1 · Segall · 2012 [cited by examiner]
US 20130024368A1 · Scammell · 2013 [cited by examiner]
US 20130067245A1 · Horovitz · 2013 [cited by applicant]
US 20130244632A1 · Spence · 2013 [cited by examiner]
US 20130266127A1 · Schachter · 2013 [cited by examiner]
US 20140032219A1 · Lerner · 2014 [cited by applicant]
US 20140100975A1 · Van · 2014 [cited by applicant]
US 20140115710A1 · Hughes · 2014 [cited by applicant]
US 20150073951A1 · Ladd · 2015 [cited by applicant]
US 20150195406A1 · Dwyer · 2015 [cited by applicant]
US 20150281446A1 · Milstein · 2015 [cited by applicant]
US 20150324592A1 · Dutta · 2015 [cited by applicant]
US 20160196440A1 · O'Hare · 2016 [cited by applicant]
US 20160234175A1 · Zhao · 2016 [cited by applicant]
US 20160379010A1 · Farkash · 2016 [cited by examiner]
US 20170026516A1 · Westlake · 2017 [cited by applicant]
US 20170162187A1 · Ohtani · 2017 [cited by applicant]
US 20210194939A1 · Forsyth et al. · 2021 [cited by applicant]
GB 2473376A · 2009 [cited by applicant]
Faruquie et al., “Protecting Sensitive Customer Imnformation in Call Center Recordings”, Sep. 2009, IEEE International Comnfernce on Services Computing, pp. 81-88 (Year: 2009). [cited by examiner]
Faruquie et al., Protecting Sensitive Customer Information in Call Center Recordings, Oct. 2009, IEEE International Conference on Services Computing, pp. 81-88 (Year 2009). [cited by applicant]
Blackwell, Clive, The management of online credit card data using the Payment Card Industry Data Security Standard, Nov. 2008, Third International Conference on Digital Information Management, pp. 838-843 (Year 2008). [cited by applicant]