Data element tokenization management

US10025941B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-10025941-B1
Application numberUS-201615244915-A
CountryUS
Kind codeB1
Filing dateAug 23, 2016
Priority dateAug 23, 2016
Publication dateJul 17, 2018
Grant dateJul 17, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods to manage a tokenization manifest that can be used for managing a redaction through tokenization of a set of field level tokenization values applied to an arbitrary information object of an arbitrary file (e.g., database cells, XML and other document elements, areas of graphics images, etc.). The methods and system extend the use of tokenization to the protection of arbitrary fields or information objects of any type or format. This allows the tokenized components of the information object to be located and provided to a Tokenization Service Provider that can recover, for an authorized requestor, the original content protected by the token. The tokenization schema processes the unrestricted content into a corresponding restricted token. The token can include an embedded URL, where the URL is a link to submit a request to the Tokenization Service Provider to view the token as the unrestricted content.

First claim

Opening claim text (preview).

What is claimed: 1. A method comprising: receiving, by a tokenization service provider computing system, a file and a redaction service call, the redaction service call including selected file content and access information; generating, by the computing system, a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema; tokenizing, by the computing system, the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token, wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier; receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content; retrieving, by the computing system, the access information associated with each requested token; comparing, by the computing system, the authentication information to the access information; extracting, by the computing system, the value of tokenSet in the nested token; and detokenizing, by the computing system, the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet. 2. The method of claim 1 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization schema includes a user determining the selected file content and an output for the selected file content. 3. The method of claim 1 , wherein the tokenization schema is a random tokenization schema, wherein the random tokenization schema includes a random determination of the selected file content and an output for the selected file content. 4. The method of claim 1 , further comprising: receiving, by the computing system, an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content; retrieving, by the computing system, the access information associated with the token; comparing, by the computing system, the authentication information to the access information; and detokenizing, by the computing system, the token in the file. 5. The method of claim 1 , further comprising, transmitting, by the computing system, a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token. 6. The method of claim 1 , wherein the access information includes a user identifier and a password for each generated token in the file. 7. The method of claim 1 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link. 8. The method of claim 1 , the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized. 9. A system, comprising: a network interface; a redaction tokenization system comprising a processor and instructions stored in non-transitory machine-readable media, the instructions configured to cause the redaction tokenization system to: receive a file and a redaction service call, the redaction service call including selected file content and access information; generate a tokenization manifest, the tokenization manifest including the selected file content, and a tokenization schema; tokenize the selected file content using the tokenization schema, the tokenization schema replacing the unrestricted file content into a corresponding restricted token, wherein the selected file content is a previously tokenized value, wherein the tokenization process generates a nested token, and the nested token has a tokenSet value, the tokenSet value being a number of nested tokens for the information object identifier; receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and one or more requested tokens to be converted to the unrestricted file content; retrieve, the access information associated with each requested token; compare the authentication information to the access information; extract the value of tokenSet in the nested token; and detokenize the nested token for a number of iterations, the number of iterations being equal to the tokenSet, and wherein an output of the detokenization for each iteration is an input for the subsequent iteration of detokenization until the number of iterations equals tokenSet. 10. The system of claim 9 , wherein the tokenization schema is a user-specified tokenization schema, wherein the user-specified tokenization includes a user determining the selected file content and an output for the selected file content. 11. The system of claim 9 , wherein redaction service call further includes, a random tokenization schema, wherein the random tokenization includes a random determination of the selected file content and an output for the selected file content. 12. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to: receive an access request, the access request a result of accessing a URL embedded in the token, the access request comprising authentication information, the file, and a token to be converted to the unrestricted file content; retrieve the access information associated with the token; compare the authentication information to the access information; and detokenize the token in the file. 13. The system of claim 9 , wherein the processor is further configured to cause the redaction tokenization system to: transmit a digitally signed message, the digitally signed message including a cryptographic binding of a hash of the file and the restricted token. 14. The system of claim 9 , wherein the access information includes a user identifier and a password for each generated token in the file. 15. The system of claim 9 , wherein the token is an output of at least one of: blurred, blocked out, a replacement string, a token number, or a clickable request link. 16. The system of claim 9 , wherein the selected file content is a coordinate system being X-axis and Y-axis coordinates that define a boundary of an area to be tokenized.

Assignees

Inventors

Classifications

  • Protecting data integrity, e.g. using checksums, certificates or signatures · CPC title

  • to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10025941B1 cover?
Systems and methods to manage a tokenization manifest that can be used for managing a redaction through tokenization of a set of field level tokenization values applied to an arbitrary information object of an arbitrary file (e.g., database cells, XML and other document elements, areas of graphics images, etc.). The methods and system extend the use of tokenization to the protection of arbitrar…
Who is the assignee on this patent?
Wells Fargo Bank Na, Wells Fargo Bank Na
What technology area does this patent fall under?
Primary CPC classification G06F21/6209. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 17 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).