User-specific watermark for maintaining security of data files
US-12153654-B2 · Nov 26, 2024 · US
US10025941B1 · US · B1
| Field | Value |
|---|---|
| Publication number | US-10025941-B1 |
| Application number | US-201615244915-A |
| Country | US |
| Kind code | B1 |
| Filing date | Aug 23, 2016 |
| Priority date | Aug 23, 2016 |
| Publication date | Jul 17, 2018 |
| Grant date | Jul 17, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Systems and methods to manage a tokenization manifest that can be used for managing a redaction through tokenization of a set of field level tokenization values applied to an arbitrary information object of an arbitrary file (e.g., database cells, XML and other document elements, areas of graphics images, etc.). The methods and system extend the use of tokenization to the protection of arbitrary fields or information objects of any type or format. This allows the tokenized components of the information object to be located and provided to a Tokenization Service Provider that can recover, for an authorized requestor, the original content protected by the token. The tokenization schema processes the unrestricted content into a corresponding restricted token. The token can include an embedded URL, where the URL is a link to submit a request to the Tokenization Service Provider to view the token as the unrestricted content.
Opening claim text (preview).
What is claimed: 1. A method comprising: receiving, by a tokenization service provider computing system, a file and a redaction service call, the redaction service call including selected file content and access information; generating, by the computing system, a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema; tokenizing, by the computing system, the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token, wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier; receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content; retrieving, by the computing system, the access information associated with each requested token; comparing, by the computing system, the authentication information to the access information; extracting, by the computing system, the value of tokenSet in the nested token; and detokenizing, by the computing system, the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet. 2. The method of claim 1 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization schema includes a user determining the selected file content and an output for the selected file content. 3. The method of claim 1 , wherein the tokenization schema is a random tokenization schema, wherein the random tokenization schema includes a random determination of the selected file content and an output for the selected file content. 4. The method of claim 1 , further comprising: receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content; retrieving, by the computing system, the access information associated with the token; comparing, by the computing system, the authentication information to the access information; and detokenizing, by the computing system, the token in the file. 5. The method of claim 1 , further comprising, transmitting, by the computing system, a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token. 6. The method of claim 1 , wherein the access information includes a user identifier and a password for each generated token in the file. 7. The method of claim 1 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link. 8. The method of claim 1 , the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized. 9. A system, comprising: a network interface; a redaction tokenization system comprising a processor and instructions stored in non-transitory machine-readable media, the instructions configured to cause the redaction tokenization system to: receive a file and a redaction service call, the redaction service call including selected file content and access information; generate a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema; tokenize the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token, wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier; receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content; retrieve, the access information associated with each requested token; compare the authentication information to the access information; extract the value of tokenSet in the nested token; and detokenize the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet. 10. The system of claim 9 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization includes a user determining the selected file content and an output for the selected file content. 11. The system of claim 9 , wherein redaction service call further includes, a random tokenization schema, wherein the random tokenization includes a random determination of the selected file content and an output for the selected file content. 12. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to: receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content; retrieve the access information associated with the token; compare the authentication information to the access information; and detokenize the token in the file. 13. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to: transmit a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token. 14. The system of claim 9 , wherein the access information includes a user identifier and a password for each generated token in the file. 15. The system of claim 9 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link. 16. The system of claim 9 , wherein the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized.
Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title
to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.