Systems and methods for flexibly securing data

US10313309B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10313309-B2
Application numberUS-201615357191-A
CountryUS
Kind codeB2
Filing dateNov 21, 2016
Priority dateNov 19, 2015
Publication dateJun 4, 2019
Grant dateJun 4, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A mechanism for flexibly securing data is discussed. A data entry device analyzes data from a user with respect to a security industry whitelist and an originator list and an analysis result controls a masking level of the data. The security industry whitelist references types of data that is not subject to industry-defined encryption standards. The originator list references data originators that produce data requiring non-standard handling. The data from the user is transmitted to and further examined for non-compliance with a pre-defined criteria at a computing device.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for flexibly securing data, the system comprising: a data entry device (DED) in communication with a computing device and configured to: receive a security industry whitelist and an originator list, the security industry whitelist referencing types of data not subject to industry-defined security standards, the originator list referencing data originators that produce data requiring non-standard handling; acquire data from a user; analyze the data from the user using at least one of the security industry whitelist and the originator list, a result of the analyzing controlling a masking level of the data; and transmit the data with the controlled masking level to the computing device; and the computing device configured to: examine the data from the user for non-compliance with a pre-defined criteria; and transmit the data to an external server for authorization after analysis, and wherein the DED: receives a signed shutdown request for the DED that was generated in response to a signed alert generated by the computing device, the signed alert indicating that the received data from the user is possibly non-compliant with a pre-defined criteria; verifies the digital signature for the signed shutdown request; and disables the DED in response to verification of the signed shutdown request. 2. The system of claim 1 , wherein the data from the user is analyzed at the DED using the security industry whitelist, and the DED is further configured to: determine that the type of the user data is referenced by the security industry whitelist; and generate, in response to the determining, a message containing the user data in clear form. 3. The system of claim 1 , wherein the data from the user is analyzed at the DED using the security industry whitelist, and the DED is further configured to: determine that the type of data is not referenced by the security industry whitelist; and analyze the data from the user using the originator list in response to the determination that the type of the user data is not referenced by the security industry whitelist. 4. The system of claim 3 , wherein the DED is further configured to: determine that an originator of the user data is referenced by the originator list; and generate, in response to determining that the originator of the user data is referenced by the originator list, a message containing the data from the user, the message including an account number from the data that is at least partially masked, a reference ID indicative of a card issuer of a card on which the data is encoded and an Issuer Identification Number (IIN) from the data that is at least partially masked. 5. The system of claim 3 , wherein the DED is further configured to: determine that the originator of the user data is not present on the originator list; and generate, in response to determining that the originator is not on the originator list, a message containing the data from the user, the message including a masked account number from the data that is at least partially masked and a completely unmasked IIN number. 6. The system of claim 1 , wherein prior to the DED receiving the signed shutdown request, the computing device is further configured to: receive at the computing device a message including at least some of the data from the user; inspect the received data for non-compliance with the pre-defined criteria; and generate the signed alert indicating that the received data from the user is possibly non-compliant with the pre-defined criteria based on the inspection, the signed alert transmitted to the DED. 7. The system of claim 1 , wherein the DED is further configured to: receive a maintenance file containing a signed security industry whitelist and a signed originator list; validate the maintenance file based on signatures included in the maintenance file; and replace an existing security industry whitelist and originator list on the DED with the security industry whitelist and the originator list included in the maintenance file. 8. A method for flexibly securing data, comprising: receiving at a data entry device (DED) a security industry whitelist and an originator list, the security industry whitelist referencing types of data not subject to industry-defined security standards, the originator list referencing data originators that produce data requiring non-standard handling; acquiring data from a user via the DED, the DED in communication with a computing device; analyzing the data from the user at the DED using at least one of the security industry whitelist and the originator list, a result of the analyzing controlling a masking level of the data; transmitting the data with the controlled masking level to the computing device; examining the data from the user for non-compliance with a pre-defined criteria at the computing device; transmitting the data to an external server for authorization after the analyzing; receiving, via the DED, a signed shutdown request for the DED that was generated in response to a signed alert generated by the computing device, the signed alert indicating that the received data from the user is possibly non-compliant with a pre-defined criteria; verifying, via the DED, the digital signature for the signed shutdown request; and disabling, via the DED, the DED in response to verification of the signed shutdown request. 9. The method of claim 8 , wherein the data from the user is analyzed at the DED using the security industry whitelist and, further comprising: determining that the type of data is referenced by the security industry whitelist; and generating, in response to the determining, a message containing the user data in clear form. 10. The method of claim 8 , wherein the data from the user is analyzed at the DED using the security industry whitelist and further comprising: determining that the type of the data is not referenced by the security industry whitelist; and analyzing the data from the user at the DED using the originator list in response to the determination that the type of the user data is not referenced by the security industry whitelist. 11. The method of claim 10 , further comprising: determining that the originator of the data is referenced by the originator list; and generating, in response to determining that the originator of the user data is referenced by the originator list, a message containing the data from the user, the message including an account number from the data that is at least partially masked, a reference ID indicative of an issuer of a card on which the data is encoded and an Issuer Identification Number (IIN) number from the data that is at least partially masked. 12. The method of claim 10 , further comprising: determining that the originator of the user data is not referenced by the originator list; and generating, in response to determining that the originator of the user data is not referenced by the originator list, a message containing the data from the user, the message including an account number from the data that is at least partially masked and a completely unmasked IIN number. 13. The method of claim 8 , wherein prior to the DED receiving the signed shutdown request, the method further comprises: receiving at the computing device a message including at least some of the data from the user; inspecting the received data for non-compliance with the pre-defined criteria; and generating, at the computing device, based on the inspecting, the signed alert indicating that the received data from the user is possibly non-compliant with the pre-defined criteria, the

Assignees

Inventors

Classifications

  • G06Q20/34Primary

    using cards, e.g. integrated circuit [IC] cards or magnetic cards · CPC title

  • Payment architectures, schemes or protocols (apparatus for performing or posting payment transactions G07F7/08, G07F19/00; electronic cash registers G07G1/12) · CPC title

  • Specific details related to card security · CPC title

  • H04L63/04Primary

    for providing a confidential data exchange among entities communicating through data packet networks · CPC title

  • Point-of-sale [POS] network systems · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10313309B2 cover?
A mechanism for flexibly securing data is discussed. A data entry device analyzes data from a user with respect to a security industry whitelist and an originator list and an analysis result controls a masking level of the data. The security industry whitelist references types of data that is not subject to industry-defined encryption standards. The originator list references data originators t…
Who is the assignee on this patent?
Walmart Apollo Llc
What technology area does this patent fall under?
Primary CPC classification G06Q20/34. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jun 04 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).