Table-Connected Tokenization
Abstract
A tokenization system tokenizes sensitive data to prevent unauthorized entities from accessing the sensitive data. The tokenization system accesses sensitive data, and retrieves an initialization vector (IV) from an IV table using a first portion of the sensitive data. A second portion of the sensitive data is modified using the accessed initialization vector. A token table is selected from a set of token tables using a third portion of the sensitive data. The modified second portion of data is used to query the selected token table, and a token associated with the value of the modified second portion of data is accessed. The second portion of the sensitive data is replaced with the accessed token to form tokenized data.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for improving the security of data in a tokenization environment, comprising:
receiving data to be tokenized; accessing two or more token tables stored at a plurality of token servers by querying the token servers with two or more portions of the received data such that each accessed token table is associated with an index value equal to a value of one of the two or more portions of the received data; and tokenizing the received data by:
modifying, the received data using a value corresponding to two or more bits of the received data to produce modified data; and
for each token table of the accessed token tables, replacing, by a hardware processor, a portion of the modified received data with a token value mapped by the token table to a value of the portion of the modified received data to produce tokenized data.
2 . The method of claim 1 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.
3 . The method of claim 1 , wherein modifying the received value comprises modifying the received value using an initialization vector, and wherein the initialization vector is received from an initialization vector table server.
4 . The method of claim 3 , wherein modifying the received data comprises adding a value of the initialization vector to a value of a portion of the received data.
5 . The method of claim 3 , wherein the initialization value is received from the initialization vector table server in response to querying the initialization vector table with the value corresponding to the two or more bits of the received data.
6 . The method of claim 1 , wherein the two or more portions of the received data do not overlap.
7 . The method of claim 1 , wherein the two or more portions of the received data overlap at least in part.
8 . A tokenization system for improving the security of data in a tokenization environment, comprising:
a non-transitory computer-readable storage medium storing executable instructions that, when executed by a processor, perform steps comprising:
receiving data to be tokenized;
accessing two or more token tables stored at a plurality of token servers by querying the token servers with two or more portions of the received data such that each accessed token table is associated with an index value equal to a value of one of the two or more portions of the received data; and
tokenizing the received data by:
modifying, the received data using a value corresponding to two or more bits of the received data to produce modified data; and
for each token table of the accessed token tables, replacing, by a hardware processor, a portion of the modified received data with a token value mapped by the token table to a value of the portion of the modified received data to produce tokenized data; and
a hardware processor configured to execute the instructions.
9 . The tokenization system of claim 8 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.
10 . The tokenization system of claim 8 , wherein modifying the received value comprises modifying the received value using an initialization vector, and wherein the initialization vector is received from an initialization vector table server.
11 . The tokenization system of claim 10 , wherein modifying the received data comprises adding a value of the initialization vector to a value of a portion of the received data.
12 . The tokenization system of claim 10 , wherein the initialization value is received from the initialization vector table server in response to querying the initialization vector table with the value corresponding to the two or more bits of the received data
13 . The tokenization system of claim 8 , wherein the two or more portions of the received data do not overlap.
14 . The tokenization system of claim 8 , wherein the two or more portions of the received data overlap at least in part.
15 . A non-transitory computer-readable storage medium storing executable computer instructions that when executed by a hardware processor perform steps for improving the security of data in a tokenization environment, comprising:
receiving data to be tokenized; accessing two or more token tables stored at a plurality of token servers by querying the token servers with two or more portions of the received data such that each accessed token table is associated with an index value equal to a value of one of the two or more portions of the received data; and tokenizing the received data by:
modifying, the received data using a value corresponding to two or more bits of the received data to produce modified data; and
for each token table of the accessed token tables, replacing, by a hardware processor, a portion of the modified received data with a token value mapped by the token table to a value of the portion of the modified received data to produce tokenized data.
16 . The non-transitory computer-readable storage medium of claim 15 , wherein the received data is one of: a password, an account number, a social security number, a driver's license number, information associated with a transaction, or date information.
17 . The non-transitory computer-readable storage medium of claim 15 , wherein modifying the received value comprises modifying the received value using an initialization vector, and wherein the initialization vector is received from an initialization vector table server.
18 . The non-transitory computer-readable storage medium of claim 17 , wherein modifying the received data comprises adding a value of the initialization vector to a value of a portion of the received data.
19 . The non-transitory computer-readable storage medium of claim 17 , wherein the initialization value is received from the initialization vector table server in response to querying the initialization vector table with the value corresponding to the two or more bits of the received data
20 . The non-transitory computer-readable storage medium of claim 15 , wherein the two or more portions of the received data do not overlap.Join the waitlist — get patent alerts
Track US2022070158A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.