US2013060705A1PendingUtilityA1
Method and system to securely store customer data in a network-based commerce system
Est. expiryJul 28, 2024(expired)· nominal 20-yr term from priority
Inventors:Liam Sean Lynch
H04L 9/14G06Q 30/0251
46
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system and method for securely storing customer data in a network-based commerce system. Customer data is received via a network connection through an application interface. A symmetric key is generated and the customer data is encoded with the symmetric key. The symmetric key is encoded with an asymmetric key to generate an encoded symmetric key. The encoded customer data and the encoded symmetric key are stored.
Claims
exact text as granted — not AI-modified1 . A system includes:
a customer data application to accept the customer data and, connected to a symmetric key generator, to generate a symmetric key; a data encryptor to encrypt the customer data with the symmetric key to form encrypted customer data; a key encryptor to encrypt the symmetric key with a public key to form an encrypted symmetric key; and a secure container module to store the encrypted customer data.
2 . The system of claim 1 , further includes a keystore for storing the public key.
3 . The system of claim 1 , further includes a database to store the encrypted customer data and the encrypted symmetric key.
4 . The system of claim 1 , wherein the secure container module is to store the encrypted customer data in a self-describing data structure, and wherein the self-describing data structure is an XML document.
5 . The system of claim 4 , further includes a database to store the XML document.
6 . The system of claim 5 , wherein the XML document is to store an indexed field in a database table.
7 . A system includes:
means for receiving customer data from the client; means for generating a symmetric key; means for encrypting the customer data with the symmetric key to form encrypted customer data; means for encrypting the symmetric key with a public key to form an encrypted symmetric key; and means for storing the encrypted customer data and the encrypted symmetric key.
8 . The system of claim 7 wherein the means for storing further includes storing the encrypted customer data and the encrypted symmetric key in a self-describing container in a database.
9 . The system of claim 7 further including means for storing the encrypted symmetric key and the encrypted customer data in a database.
10 . A computer readable medium comprising instructions, which when executed on a processor, cause the processor to perform a method comprising:
receiving customer data via a network connection; generating a symmetric key; encoding the customer data with the symmetric key to generate encoded customer data; encoding the symmetric key with an asymmetric key to generate an encoded symmetric key; and storing the encoded customer data and the encoded symmetric key.
11 . A method including:
receiving customer data via a network connection; generating a symmetric key; encoding the customer data with the symmetric key to generate encoded customer data; encoding the symmetric key with an asymmetric key to generate an encoded symmetric key; and storing the encoded customer data and the encoded symmetric key.
12 . The method of claim 11 , including obtaining the asymmetric key from a keystore.
13 . The method of claim 11 , wherein the receiving the customer data via the network connection includes receiving the customer data via an application interface, and wherein the application interface is a payment application interface.
14 . The method of claim 13 , wherein the receiving the customer data via the application interface includes receiving a national identification.
15 . The method of claim 13 , wherein the customer data received via the application interface includes billing information.
16 . The method of claim 13 , wherein the customer data received via the application interface includes direct debit information.
17 . The method of claim 11 , wherein the customer data includes credit card information.
18 . The method of claim 11 , wherein the network connection is an HTTPS connection.
19 . The method of claim 11 , wherein the encoded customer data and the encoded symmetric key are stored in separate fields of a single table in a database.
20 . The method of claim 19 , wherein the encoded customer data and the encoded symmetric key are stored in separate tables in the database.
21 . The method of claim 11 , wherein the encoded customer data is stored in a database as an XML element.
22 . The method of claim 11 , wherein the encoded symmetric key is stored in a database as an XML element.
23 . The method of claim 11 , wherein the encoded customer data is stored in an indexed field in a database table.
24 . The method of claim 11 , further including:
placing the encoded customer data and the encoded symmetric key in a self-describing data-structure and wherein the self-describing data structure is an XML document.
25 . The method of claim 24 , wherein the XML document is stored in a database.
26 . The method of claim 24 , wherein the XML document is stored in an indexed field of a database table.Join the waitlist — get patent alerts
Track US2013060705A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.