×

Encryption and tokenization architectures

  • US 10,026,080 B2
  • Filed: 03/13/2015
  • Issued: 07/17/2018
  • Est. Priority Date: 10/23/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method for using a unique token in an online transaction on a website to control access to sensitive information, the method comprising:

  • in response to receipt of the sensitive information from a merchant device, generating, by a server entity, a unique token for use in lieu of the sensitive information in online transactions, wherein the sensitive information comprises a character string stored as encrypted data;

    directly associating, by the server entity, a unique token with a sub-string of a character string, wherein (a) a direct association does not exist between the unique token and the character string, (b) the character string comprises the sensitive information and (c) the sub-string is configured to identify the character string without revealing the sensitive information;

    saving, by the server entity, a record for the online transaction comprising information for the online transaction and the unique token, wherein any steps performed after saving the record and prior to retrieving the character string utilize the unique token in lieu of the sensitive information;

    retrieving, by the server entity, the character string stored as encrypted data from a storage memory using the unique token to complete the online transaction using the saved record and the sensitive information after transmission of a request for the sensitive information from a registered entity associated with a subscription level associated with a privilege to receive the requested sensitive information.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×