Method and system for protecting sensitive information and preventing unauthorized use of identity information
Abstract
This invention features a method and system for protecting sensitive information and preventing the unauthorized use of identity information by third parties. Virtual identifiers that identify an information holder whose sensitive information is involved in the process, are dynamically created by an entity called processing entity. The virtual identifiers are usually linked to a static identity of the information holder through a data management mechanism, such as a database system. A virtual identifier could serve for multiple functions. Usually, validity attributes that indicate when and for how long a virtual identifier is valid for the different functions, are associated with the virtual identifier. When the information holder interacts with a third party in a process that involves the information holder's sensitive information, the information holder uses virtual identifiers. Then, through a device connected to a network including wireless devices, telephone or a mail service, the party either passes along the virtual identifiers to other parties or submits requests along with the virtual identifiers to the processing entity which could map the virtual identifiers to the static identity information and uses the static information to realize the requests.
Claims
exact text as granted — not AI-modified1 . A method of protecting a static identifier of an information holder, comprising:
a) receiving a request for one or a plurality of virtual identifiers by a processing entity computer system; b) creating one or a plurality of virtual identifiers by said processing entity computer system with each of said one or a plurality of virtual identifiers uniquely identifies said information holder; c) linking said one or a plurality of virtual identifiers to said static identifier by said processing entity computer system; d) issuing said one or a plurality of virtual identifiers to said information holder; e) receiving a message comprising a request for service with a virtual identifier by said processing entity computer system from a first device of a requesting party, said requesting party being a party that received said virtual identifier from said information holder or from a non-information-destination and submitted said request for service to said processing entity computer system; f) processing said request for service from said requesting party by said processing entity computer system; g) transmitting the result of step f) to said first device of said requesting party or a second device of said requesting party;
whereby the creation and issuance of the virtual identifiers are independent of those of the static identifier since the format of the virtual identifier is independent of that of the static identifier.
2 . The method as recited in claim 1 further comprising:
a) receiving said static identifier of said information holder from a device of said information holder by said processing entity computer system; b) transmitting said static identifier to a data management system.
3 . The method as recited in claim 2 wherein the step of receiving said static identifier from a device of said information holder is conducted through a public network.
4 . The method as recited in claim 3 wherein said public network is the Internet.
5 . The method as recited in claim 2 wherein step e) is conducted through a public network.
6 . The method as recited in claim 5 wherein said public network is the Internet.
7 . The method as recited in claim 5 , further comprising:
validating said virtual identifier by said processing entity computer system.
8 . The method as recited in claim 7 , further comprising:
identifying by said processing entity computer system said static identifier of said information holder using said virtual identifier.
9 . The method as recited in claim 8 wherein step f) is conducted through transmitting a message comprising a request for sensitive information of said information holder with said static identifier to an information source and receiving the requested sensitive information from said information source.
10 . The method as recited in claim 8 wherein the result of step f) comprises said static identifier.
11 . The method as recited in claim 8 further comprising:
updating said virtual identifier's validity status by said processing entity computer system.
12 . The method as recited in claim 11 wherein said static identifier is a social security number.
13 . The method as recited in claim 9 wherein said virtual identifier is valid for one-time or multiple-time for requesting said sensitive information.
14 . The method as recited in claim 8 wherein said virtual identifier comprises validity attributes.
15 . A system of protecting a static identifier of an information holder, comprising:
a data management system to store and retrieve data; a processing entity to receive a request for one or a plurality of virtual identifiers, to create one or a plurality of virtual identifiers with each of said one or a plurality of virtual identifiers uniquely identifies said information holder, to link said one or a plurality of virtual identifiers to said static identifier, to issue said one or a plurality of virtual identifiers to said information holder, to receive a message comprising a request for service with a virtual identifier from a first device of a requesting party, said requesting party being a party that received said virtual identifier from said information holder or from a non-information-destination and submitted said request for service to said processing entity, to process said request for service from said requesting party, to transmit the result of the above processing to said first device of said requesting party or a second device of said requesting party, said processing entity residing in a computer system; and wherein said processing entity sends data to and gets data from said data management system.
16 . The system as recited in claim 15 wherein said processing entity receives said message comprising a request for service through a public network.
17 . The system as recited in claim 16 wherein said public network is the Internet.
18 . The system as recited in claim 15 wherein said data management system comprises a database system.
19 . The system as recited in claim 15 wherein said processing entity processes said request for service through transmitting a message comprising a request for obtaining sensitive information of said information holder to an information source.
20 . The system as recited in claim 19 wherein said virtual identifier is limited to be valid for one-time or multiple-time.Join the waitlist — get patent alerts
Track US2010043064A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.