IP Library Granted Patent US 12,417,434
Granted Patent B2
US 12,417,434 · App. 18/595,786 · Granted Sep 16, 2025

Jailed environment restricting programmatic access to multi-tenant data

Inventors: Dinesh Sundaram (Plano, TX); Raman Bajaj (Frisco, CA); Jacques Morel (Colleyville, TX); Sanjiv Yajnik (Dallas, TX); Trent Jones (Mckinney, TX); Alan Ilango (Mckinney, TX); Jacob Creech (Mckinney, TX); Avijit Sarkar (Mckinney, TX); Rajaboopathy Vijayaraghavan (Carrollton, TX); Ishu Gupta (Mckinney, TX); Thomas Sickert (Plano, TX)
Assignee: Capital One Services, LLC
G06Q10/10G06F9/44505G06F9/54G06F9/547G06F16/258G06F16/9558G06F16/9562G06F18/24G06F21/53G06F21/602G06F21/604G06F21/6227G06F21/6245G06F40/103G06F40/174G06F40/18G06N3/02G06N5/025G06N20/00G06Q20/382G06Q20/4014G06Q30/0185G06Q30/0206G06Q30/0601G06Q30/0613G06Q30/0619G06Q30/0637G06Q30/0643G06Q40/02G06Q40/03H04L9/0825H04L63/0435H04L63/08H04L63/0815H04L63/102H04L63/123H04L63/166H04L63/168G06F8/65G06F8/71G06F2221/2107G06K7/1417G06Q50/265G06Q2220/00H04L9/0822
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,417,434
App. No.
18/595,786
Granted
Sep 16, 2025
Kind
B2
Abstract

The system and methods described herein allow users to give their applicant information to at least one entity when seeking to submit an inquiry associated with an item, and have various lender microservices run in parallel, segregated by entity, in a jailed environment. The result of these microservices may be returned as a response to the inquiry, being determined autonomously for each respective entity based on one or more respective rule sets or executable logic for each respective entity. Payloads for multiple entities may be combined in a single output from the jailed environment due to outputs from the environment being encrypted in a universal format.

Claims (73)

1. A method comprising:

identifying a self-contained network, wherein a plurality of entities, including both a first entity and second entity, manage their own separate accounts on the self-contained network, wherein each of the plurality of entities stores confidential information on the self-contained network accessible only to a respective entity through their own entity-specific key;

receiving a first rule from the first entity and a second rule from the second entity;

storing the first rule being encrypted with a first entity-specific key for the first entity and the second rule being encrypted with a second entity-specific key for the second entity in the self-contained network that restricts an entity from accessing any entity-specific rules that are not associated with the entity;

receiving, from a user device, an inquiry associated with a user;

requesting, for an item, an entity response to the inquiry for each of the first entity and the second entity;

decrypting, in response to the inquiry and within the the self-contained network, the first rule for the first entity via the first entity-specific key and the second rule for the second entity via the second entity-specific key;

generating, as the entity responses, a first response based on the decrypted first rule for the first entity and a second response based on the decrypted second rule for the second entity;

generating, within the the self-contained network, a universally encrypted entity-agnostic composite payload comprising the first response and the second response;

sending the universally encrypted entity-agnostic composite payload to the user device;

retrieving host and infrastructure metrics regarding a performance of one or more devices of the self-contained network, wherein the host and infrastructure metrics exclude the confidential information; and

providing a dashboard regarding a health of the self-contained network based on the host and infrastructure metrics.

2. The method of claim 1 , further comprising:

receiving, at a server, one or more rule sets or executable logic from each of at least one entity;

storing the one or more rule sets or executable logic in the self-contained network environment in the server, the one or more rule sets or executable logic being encrypted with an entity-specific key upon receipt of the one or more rule sets or executable logic for each such entity, or encrypted at a predetermined later time for each such entity, with the entity-specific key, wherein the one or more rule sets or executable logic for each such entity are accessible in the self-contained network environment by at least one entity-specific routing component dedicated for each such entity.

3. The method of claim 2 , wherein each entity corresponds to a lender; each entity-specific routing component corresponds to a lender-specific broker dedicated for a particular lender; each entity-specific key corresponds to a lender-specific key dedicated for a particular lender; the item is a loan provided by a lender; the requesting is a request for lender prequalification relating to an inquiry associated with the item; the inquiry to which the request relates is for applicant financing of a commodity with at least one lender; the one or more rule sets or executable logic for each entity comprise one or more rule sets or executable logic for prequalifying an applicant, which are stored inside of the self-contained network in a lender confidential data repository; and wherein to determine a respective response to the inquiry, the lender-specific broker for each respective lender applies the one or more rule sets or executable logic to applicant information which is submitted along with the inquiry to assess applicant prequalification for each lender of the at least one lender of the inquiry and product eligibility for an applicant in lending from the at least one lender to purchase a particular product, and to further, if the applicant is found to prequalify for a lender and the particular product is eligible under a product eligibility process for the lender, assess pricing information to determine terms for a loan offer.

4. The method of claim 3 , wherein each lender may access and manipulate or edit only their respective one or more rule sets or executable logic within the self-contained network, and not that of any other lender, for prequalifying an applicant through a lender portal application user interface, wherein once any editing by a lender of their respective one or more rule sets or executable logic takes place in the lender portal application user interface, a lender confidential data service is automatically called to make corresponding changes to rules or executable logic in the lender confidential data repository for that lender.

5. The method of claim 3 , further comprising:

logging details of the one or more rule sets or executable logic that are executed in an audit repository stored inside of the self-contained network.

6. The method of claim 3 , further comprising:

wherein the one or more rule sets or executable logic is applied to the applicant information to assess applicant prequalification or product eligibility for each lender of the at least one lender within the lender-specific broker corresponding to each said lender, within the self-contained network.

7. The method of claim 3 , further comprising:

wherein the one or more rule sets or executable logic is applied to the lender prequalification request and applicant information within the lender-specific broker to, at least for one lender, modify the applicant information and lender prequalification request to match required lender parameters for an application protocol interface of a lender-based loan origination system which is in communication with the lender-specific broker; and sending the lender prequalification request and applicant information to the lender-based loan origination system for the at least one lender having said lender-based loan origination system.

8. The method of claim 7 , further comprising:

assessing applicant prequalification for the at least one lender having said lender-based loan origination system; and

returning an output response to the lender-specific broker in the self-contained network.

9. The method of claim 8 , further comprising:

transforming the returned output response by the lender-specific broker from the parameters matching the application protocol interface of the lender-based loan origination system to a non-lender specific universal format used in the self-contained network; and

encrypting said returned output response in a universal non-lender specific format to be decrypted in a particular user session.

10. The method of claim 2 , wherein the one or more rule sets or executable logic may comprise at least one of boolean logic or machine-learning logic.

11. A system comprising:

a memory;

a server;

a processor coupled to said memory, the processor configured to:

identify a self-contained network, wherein a plurality of entities, including both a first entity and second entity, manage their own separate accounts on the self-contained network, wherein each of the plurality of entities stores confidential information on the self-contained network accessible only to a respective entity through their own entity-specific key;

receive a first rule from the first entity and a second rule from the second entity;

store the first rule being encrypted with a first entity-specific key for the first entity and the second rule being encrypted with a second entity-specific key for the second entity in the self-contained network that restricts an entity from accessing any entity-specific rules that are not associated with the entity;

receive, at the server, through an application user interface, from a user device, an inquiry associated with a user;

request, for an item, an entity response to the inquiry for each of the first entity and the second entity;

decrypt, in response to the inquiry and within the self-contained network, the first rule for the first entity via the first entity-specific key and the second rule for the second entity via the second entity-specific key;

generate, as the entity responses, a first response based on the decrypted first rule for the first entity and a second response based on the decrypted second rule for the second entity;

generate, within the self-contained network, a universally encrypted entity-agnostic composite payload comprising the first response and the second response;

send the universally encrypted entity-agnostic composite payload to the user device;

retrieve host and infrastructure metrics regarding a performance of one or more devices of the self-contained network, wherein the host and infrastructure metrics exclude the confidential information; and

provide a dashboard regarding a health of the self-contained network based on the host and infrastructure metrics.

12. The system of claim 11 , wherein the system further comprises a graphic user interface (GUI), wherein the processor is configured to receive applicant information through said GUI, by the application user interface, wherein said application user interface comprises an application protocol interface (API).

13. The system of claim 11 , wherein the system further comprises a graphic user interface (GUI), wherein encrypted outputs corresponding to the universally encrypted entity-agnostic composite payload are displayed on the GUI by an application protocol interface (API) through which the encrypted outputs are transmitted.

14. The system of claim 12 , wherein encrypted outputs corresponding to the universally encrypted entity-agnostic composite payload are displayed on the GUI by the API through which the encrypted outputs are transmitted.

15. The system of claim 11 , the processor further configured to:

store one or more rule sets or executable logic for prequalifying an applicant inside of the self-contained network in a database of a lender confidential data respitory.

16. The system of claim 15 , wherein the one or more rule sets may comprise at least one of boolean logic or machine-learning logic.

17. The system of claim 11 , wherein the processor is further configured to:

receive, at the server, through the application user interface, applicant information with respect to an application for applicant financing associated with the user for the item with at least one entity;

apply one or more rule sets or executable logic to the applicant information to assess applicant prequalification or product eligibility for each entity within the self-contained network for generating the universally encrypted entity-agnostic composite payload.

18. The system of claim 11 , wherein the processor is further configured to:

receive, at the server, through the application user interface, applicant information with respect to an application for applicant financing associated with the user for the item with at least one entity, along with a prequalification request;

apply one or more rule sets or executable logic to the inquiry and the applicant information within a lender-specific broker to modify the applicant information and prequalification request to match required lender parameters for an application protocol interface of a lender-based loan origination system which is in communication with the lender-specific broker; and send the inquiry and the applicant information to the lender-based loan origination system for at least one lender having said lender-based loan origination system.

19. The system of claim 18 , wherein the processor is further configured to:

receive a returned output response from the lender-based loan origination system;

transform the returned output response via the lender-specific broker, from the parameters matching the application protocol interface of the lender-based loan origination system to a non-lender specific universal format used in the self-contained network of the server; and

encrypt said returned output response to the universally encrypted entity-agnostic composite payload.

20. A non-transitory computer readable medium storing instructions that when executed by one or more processors of a device cause the one or more processors to:

identify a self-contained network, wherein a plurality of entities, including both a first entity and second entity, manage their own separate accounts on the self-contained network, wherein each of the plurality of entities stores confidential information on the self-contained network accessible only to a respective entity through their own entity-specific key;

receive a first rule from the first entity and a second rule from the second entity;

store the first rule being encrypted with a first entity-specific key for the first entity and the second rule being encrypted with a second entity-specific key for the second entity in the self-contained network that restricts an entity from accessing any entity-specific rules that are not associated with the entity;

receive, at a server, through an application user interface, from a user device, an inquiry associated with a user;

request, for an item, an entity response to the inquiry for each of the first entity and the second entity;

decrypt, in response to the inquiry and within the self-contained network, the first rule for the first entity via the first entity-specific key and the second rule for the second entity via the second entity-specific key;

generate, as the entity responses, a first response based on the decrypted first rule for the first entity and a second response based on the decrypted second rule for the second entity;

generate, within the self-contained network, a universally encrypted entity-agnostic composite payload comprising the first response and the second response;

send the universally encrypted entity-agnostic composite payload to the user device;

retrieve host and infrastructure metrics regarding a performance of one or more devices of the self-contained network, wherein the host and infrastructure metrics exclude the confidential information; and

provide a dashboard regarding a health of the self-contained network based on the host and infrastructure metrics.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: SUNDARAM, DINESH; BAJAJ, RAMAN; MOREL, JACQUES; YAJNIK, SANJIV; JONES, TRENT; ILANGO, ALAN; CREECH, JACOB; SARKAR, AVIJIT; VIJAYARAGHAVAN, RAJABOOPATHY; GUPTA, ISHU; SICKERT, THOMAS
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066653/0212 →
Continuity (3)
Continuation 16882163 · May 22, 2020
Provisional Application 62852202 · May 23, 2019
Related Publication 20240202364A1 · Jun 20, 2024
References Cited (52)
US 7461080B1 · Tucker · 2008 [cited by applicant]
US 7565313B2 · Waelbroeck et al. · 2009 [cited by applicant]
US 7620597B2 · Eze · 2009 [cited by applicant]
US 7630933B2 · Peterson et al. · 2009 [cited by applicant]
US 7908210B2 · Huber et al. · 2011 [cited by applicant]
US 8392294B2 · MacInnis · 2013 [cited by applicant]
US 8909551B2 · Pawlusiak et al. · 2014 [cited by applicant]
US 10033702B2 · Ford et al. · 2018 [cited by applicant]
US 10210570B2 · Bennett et al. · 2019 [cited by applicant]
US 10243743B1 · Madisetti et al. · 2019 [cited by applicant]
US 11132653B1 · Bolt et al. · 2021 [cited by applicant]
US 11210687B2 · Kesiboyana et al. · 2021 [cited by applicant]
US 11935003B2 · Sundaram et al. · 2024 [cited by applicant]
US 11948128B2 · Kesiboyana et al. · 2024 [cited by applicant]
US 20050187860A1 · Peterson et al. · 2005 [cited by applicant]
US 20060178983A1 · Nice · 2006 [cited by examiner]
US 20070244808A1 · Eze · 2007 [cited by applicant]
US 20080071640A1 · Nguyen · 2008 [cited by applicant]
US 20100023448A1 · Eze · 2010 [cited by applicant]
US 20110112946A1 · Porter · 2011 [cited by applicant]
US 20110270659A1 · Crites · 2011 [cited by applicant]
US 20110313884A1 · Eze · 2011 [cited by applicant]
US 20120179753A1 · Welingkar et al. · 2012 [cited by applicant]
US 20130218752A1 · Pawlusiak · 2013 [cited by examiner]
US 20140020068A1 · Desai et al. · 2014 [cited by applicant]
US 20140164774A1 · Nord · 2014 [cited by examiner]
US 20140279399A1 · Shidler et al. · 2014 [cited by applicant]
US 20150025950A1 · Yu · 2015 [cited by applicant]
US 20150170233A1 · Lisitsa · 2015 [cited by applicant]
US 20160042451A1 · Raessler et al. · 2016 [cited by applicant]
US 20160050272A1 · Raduchel · 2016 [cited by examiner]
US 20160125041A1 · Smith et al. · 2016 [cited by applicant]
US 20160232546A1 · Ranft et al. · 2016 [cited by applicant]
US 20160253753A1 · Bennett et al. · 2016 [cited by applicant]
US 20160314487A1 · Martin et al. · 2016 [cited by applicant]
US 20160350850A1 · Shields et al. · 2016 [cited by applicant]
US 20180040064A1 · Grigg et al. · 2018 [cited by applicant]
US 20180041338A1 · Nighswander et al. · 2018 [cited by applicant]
US 20180158139A1 · Krajicek et al. · 2018 [cited by applicant]
US 20190087847A1 · Peasley et al. · 2019 [cited by applicant]
US 20190102835A1 · Bjonerud et al. · 2019 [cited by applicant]
US 20190102836A1 · Wales et al. · 2019 [cited by applicant]
US 20190114705A1 · Wong et al. · 2019 [cited by applicant]
US 20190130480A1 · Brewbacker et al. · 2019 [cited by applicant]
US 20190333142A1 · Thomas · 2019 [cited by examiner]
US 20200043066A1 · Obaidi · 2020 [cited by applicant]
US 20200311808A1 · Srivastava · 2020 [cited by examiner]
US 20200372499A1 · Sundaram et al. · 2020 [cited by applicant]
US 20200372574A1 · Sundaram et al. · 2020 [cited by applicant]
US 20200372575A1 · Kesiboyana et al. · 2020 [cited by applicant]
US 20200372576A1 · Sundaram et al. · 2020 [cited by applicant]
WO 2015136503A1 · 2015 [cited by applicant]