Non-vault tokenization
Through vault-free tokenization technology, a unique token is generated using secure alphanumeric tokens and multiple rounds of random table shuffling, solving the problems of poor scalability and vulnerability in the existing technology, and an efficient and secure tokenization solution is achieved.
Patent Information
- Application Number
- CN202380076303.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-01
- Filing Date
- 2023-09-01
- Publication Date
- 2025-06-27
AI Technical Summary
Existing vault-based tokenization solutions are difficult to scale when processing large amounts of user data and high throughput, and are vulnerable to cyber attacks and malicious activity, resulting in the jeopardy of sensitive user data.
Using vault-free tokenization technology, a safe alphanumeric token that cannot be reverse engineered through brute force is used to form a token using completely random values, and a unique token is generated through multiple rounds of random table shuffling and searches.
It implements a tokenization solution that supports large amounts of user data and high throughput without vault storage, improves the scalability of the system, and makes it difficult to reverse engineer decryption by increasing the randomness of tokens.
Smart Images

Figure CN120226008A_ABST
Abstract
Description
BACKGROUND OF THE DISCLOSURE
[0001] Many services and platforms that support various users and / or client devices, such as banking as a service (BaaS) platforms, software as a service (SaaS) platforms, financial technology (FinTech) platforms, infrastructure as a service (IaaS) platforms, and platform as a service (PaaS) platforms, use tokenization as a means of protecting sensitive user information. Conventional tokenization schemes used by such services and platforms utilize vault-based security techniques, where sensitive user information is protected by mapping tokens to encrypted plaintext values representing the user information and storing the mapping in a database. As the number of users supported by such services and platforms increases, the databases used for conventional vault-based security cannot support the increasing volume of user data and high throughput requirements. Additionally, tokenization vaults are often subject to cyberattacks and other malicious activities, endangering sensitive user data. The encryption used to protect sensitive information stored in the vault (e.g., format-preserving encryption (FPE), etc.) may be reverse engineered and / or decrypted due to brute force attacks and other malicious activities. Similarly, vaultless tokenization schemes based on FPE (e.g., FF2, FF3, etc.) may be reverse engineered and / or decrypted due to brute force attacks and other malicious activities. BRIEF DESCRIPTION OF THE DRAWINGS
[0002] The accompanying drawings, which are incorporated herein and constitute a part of this specification, illustrate the disclosure and, together with the description, further serve to explain the principles of the disclosure and enable a person skilled in the relevant art to make and use the disclosure.
[0003] Figure 1 is a block diagram of an example system for vaultless tokenization in accordance with aspects of the present disclosure.
[0004] Figure 2 illustrates an example method for vaultless tokenization in accordance with aspects of the present disclosure.
[0005] Figure 3 is an example computer system for implementing aspects disclosed herein.
[0006] In the drawings, like reference numerals generally indicate like or similar elements. Additionally, generally, the leftmost (s) digit(s) of a reference numeral identifies the drawing in which the reference numeral first appears. DETAILED DESCRIPTION
[0007] Systems and / or platforms such as Banking as a Service (BaaS) platforms, Software as a Service (SaaS) platforms, Financial Technology (FinTech) platforms, Infrastructure as a Service (IaaS) platforms, Platform as a Service (PaaS) platforms, etc. can include, implement, and / or support vaultless tokenization to protect sensitive data / information. Secure alphanumeric tokens that cannot be reverse engineered by brute force can be generated and used to protect user information. The token output according to the embodiments of the systems, devices, apparatuses, methods, computer program products for vaultless tokenization described herein, and / or their combinations and subcombinations consists of completely random values (and / or characters, numbers, symbols, etc.) and has no association with the sensitive data to be tokenized. For example, the random values of the tokens generated by the systems, devices, apparatuses, methods, computer program products for vaultless tokenization described herein, and / or their combinations and subcombinations are determined based on input values randomly shuffled according to multiple (e.g., 2 62 etc.) randomly generated tables (e.g., alphanumeric tables, alphabet tables, symbol tables, number tables, etc.).
[0008] A computing device can determine an alphanumeric value based on a numeric value generated from a hash of digital user information shuffled through multiple randomly generated alphanumeric tables. A table index can be generated based on the alphanumeric value and at least a portion of the digital user information. The shuffled digital user information can be generated based on the table index and multiple randomly generated number tables. For example, based on format-preserving encryption applied to the shuffled digital user information, additive cryptographic information applied to the shuffled digital user information, etc., the shuffled digital user information can be converted into alphanumeric user information. Each character of the alphanumeric user information can be shuffled by a different alphanumeric table among multiple alphanumeric tables identified for that character based on the table index. Additionally, an alphanumeric token can be generated based on the shuffled characters of the alphanumeric user information.
[0009] According to some aspects, secure alphanumeric tokens can be algorithmically generated such that when de-tokenization is required, the secure alphanumeric tokens can be used to determine the original user information without the need to utilize a tokenization vault to look up and / or identify sensitive information. According to some aspects, embodiments of systems, methods, and computer program products for vaultless tokenization can generate secure alphanumeric tokens using multiple rounds of shuffling and lookups (e.g., via secure table indexing) through multiple randomly generated tables (e.g., 10M+ pre-generated tables, etc.), which are encrypted and securely stored via a hardware service module (HSM), etc. This shuffling and lookup method produces unique tokens that cannot be reverse engineered. According to some aspects, user information that has been shuffled through multiple randomly generated tables can be further protected by applying mathematical operations (e.g., XOR, division, modulus, etc.), string operations (e.g., reversal, splitting, rotation, etc.), and / or encryption algorithms. According to some aspects, encryption algorithms can include, but are not limited to, length-preserving encryption using a user-specific derived key (e.g., HCTR2, block ciphers, etc.), format-preserving encryption (e.g., FF1, etc.), homomorphic encryption (e.g., BFV, CKKS, FHEW, etc.), etc. According to some aspects, the user information can be shuffled before encryption and re-shuffled after encryption to generate alphanumeric tokens. According to some aspects, metadata associated with the user information (including, but not limited to, metadata describing character length, version number, field type, cyclic redundancy check (CRC) information, etc.) can also be shuffled through multiple randomly generated tables and used to modify the alphanumeric tokens to obtain additional randomness, security, and / or character set frequency distribution.
[0010] Thus, the embodiments of systems, apparatuses, devices, methods, computer program products, and / or combinations and sub-combinations thereof for vaultless tokenization described herein overcome the challenges of conventional vault-based tokenization systems, where sensitive user information is protected by mapping tokens to encrypted plaintext values representing the user information and storing the mapping in a database. The embodiments of systems, apparatuses, devices, methods, computer program products, and / or combinations and sub-combinations thereof for vaultless tokenization support scalability such that as the number of users supported by the vaultless tokenization described herein increases, there is no longer a need for the storage media (e.g., vaults) that have traditionally been used to store sensitive information and / or key-value mappings to such sensitive information. The embodiments of systems, apparatuses, devices, methods, computer program products, and / or combinations and sub-combinations thereof for vaultless tokenization described herein output tokens (e.g., secure alphanumeric tokens, etc.) that cannot be reverse engineered and / or decrypted through brute force and other malicious activities.
[0011] The systems, apparatuses, devices, methods, computer program product embodiments, and / or combinations and sub - combinations thereof described herein for vaultless tokenization support the continuous increase in user data and / or tokenization requests without the data management and / or storage constraints associated with conventional tokenization systems. For conventional tokenization systems, in order to protect sensitive data / information, each tokenization request and / or transaction through the tokenization system must utilize certain functions provided by the HSM and is thus limited by the performance capacity of the HSM. Since no vault / HSM is used to store and / or generate tokens and the tokens are generated on - demand based on requests for tokenization, the systems, apparatuses, devices, methods, computer program product embodiments, and / or combinations and sub - combinations thereof described herein for vaultless tokenization minimize the involvement of the HSM. For example, during the processing of tokenization requests, the involvement of the HSM during runtime (e.g., any time / period during which an application, program, etc. is operating / running, etc.) is minimized, and thus any performance bottlenecks caused by the HSM are alleviated. These and other advantages are described herein.
[0012] Figure 1 is a block diagram of an example system 100 for vaultless tokenization according to some aspects of the present disclosure. According to some aspects of the present disclosure, system 100 may include and / or be a component of a business platform, a banking - as - a - service (BaaS) platform, a software - as - a - service (SaaS) platform, a financial technology (FinTech) platform, an infrastructure - as - a - service (IaaS) platform, a platform - as - a - service (PaaS) platform, etc.
[0013] According to some aspects, system 100 may include a user device 102 (e.g., a mobile device, a smart device, a client device, a computer, an Internet of Things (IoT) device, a content access / receiving device, etc.), a computing device 110 (e.g., a server, a cloud computing device, a token management device, etc.), and a computing system 118 (e.g., a cloud - based computing system, a service system, a token management system, etc.), which communicate via a network 108. The devices and / or components of system 100 may be connected and / or communicate via a wired connection, a wireless connection, a combination thereof, etc. According to some aspects, computing device 110 may reside entirely or partially on computing system 118.
[0014] According to some aspects, network 108 may include a packet-switched network (e.g., an Internet Protocol-based network), a non-packet-switched network (e.g., an Orthogonal Amplitude Modulation-based network), etc. Network 108 may include network adapters, switches, routers, modems, etc. connected via wireless links (e.g., radio frequency, satellite) and / or physical links (e.g., fiber optic cables, coaxial cables, Ethernet cables, or combinations thereof). Network 108 may include public networks, private networks, wide area networks (e.g., the Internet), local area networks, etc. Network 108 may include content access networks, content distribution networks, etc. Network 108 may provide and / or support communication from telephones, cellular phones, modems, and / or other electronic devices to system 100 and throughout system 100.
[0015] According to some aspects, user device 102 may include interface module 104. According to some aspects, interface module 104 enables a user to interact with user device 102, network 108, computing device 110, computing system 118, and / or any other device / component of system 100. Interface module 104 may include any interface for presenting information to the user and / or receiving information from the user. According to some aspects, interface module 104 may include a web browser, a user interface, etc.
[0016] According to some aspects, interface module 104 may include one or more input devices and / or components, such as a keyboard, a pointing device (e.g., a computer mouse, a remote control), a microphone, a joystick, a tactile input device (e.g., a touch screen, a glove, etc.). According to some aspects, interaction with the input devices and / or components may enable the user to view, access, request, and / or navigate data / information.
[0017] According to some aspects, user device 102 may include and / or be configured with application 106. Application 106 may include one or more application programming interfaces (APIs) that enable user device 102 to access, view, communicate with the devices / components of system 100, etc. For example, according to some aspects, application 106 may support, facilitate, and / or be used as part of an online transaction, where a security token (e.g., a secure alphanumeric token, etc.) may be generated to ensure the security of the online transaction. For example, an online transaction may include the exchange of sensitive information (e.g., a virtual card number generated in place of an actual card number of a physical credit card, digital wallet information, user identification information, transaction-related information, etc.).
[0018] According to some aspects, the computing system 118 can be a cloud-based computing system or the like. The computing system 118 can support various applications, devices, and / or services, including but not limited to banking as a service (BaaS), software as a service (SaaS), fintech services, infrastructure as a service (IaaS), platform as a service (PaaS), and the like. The computing system 118 can include a backend platform 120 and / or be supported by the backend platform 120.
[0019] According to some aspects, the backend platform 120 can include a server or a group of servers. According to some aspects, the backend platform 120 can be hosted in the computing system 118. It should be understood that the backend platform 120 can be non-cloud-based or can be partially cloud-based. The computing device 110 can include one or more devices and / or components configured to interface with the backend platform 120.
[0020] According to some aspects, the computing system 118 can include an environment for delivering computing as a service, whereby shared resources, services, etc. can be provided to the backend platform 120. The computing system 118 can provide computing, software, data access, storage, and / or other services that do not require the end user to know the physical location and configuration of the system and / or device delivering the service. According to some aspects, the computing system 118 can include computer resources 124a-d.
[0021] According to some aspects, each of the computer resources 124a-d can include one or more personal computers, workstations, computers, server devices, or other types of computing and / or communication devices. The (multiple) computer resources 124a-d can host the backend platform 120. Cloud resources can include computing instances executed in the computer resources 124a-d. The computer resources 124a-d can communicate with other computer resources 124a-d via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection.
[0022] The computer resources 124a-d can include a cloud resource group, such as one or more applications ("APP") 124-1, one or more virtual machines ("VM") 124-2, virtualized storage devices ("VS") 124-3, and one or more hypervisors ("HYP") 124-4.
[0023] Application 124-1 may include one or more software applications (e.g., instances of Application 106, etc.), which may be provided to and / or accessed by computing device 110 and / or user device 102. Alternatively, Application 124-1 may eliminate the need to install and execute software applications on user device 102. Application 124-1 may include software associated with backend platform 120 and / or any other software configured to be provided across system 100. Application 124-1 may send / receive information from one or more other Applications 124-1 via virtual machine 124-2.
[0024] Virtual machine 124-2 may include a software implementation of a machine (e.g., a computer) that executes programs like a physical machine. Virtual machine 124-2 may be a system virtual machine or a process virtual machine, depending on the usage of virtual machine 124-2 and its correspondence to any real machine. A system virtual machine may provide a complete system platform that supports the execution of a complete operating system (OS). A process virtual machine may execute a single program and support a single process. Virtual machine 124-2 may execute on behalf of a user and / or on behalf of one or more other backend platforms 225, and may manage the infrastructure of computing system 118, such as data management, synchronization, or long-duration data transfer.
[0025] Virtualized storage device 124-3 may include one or more storage systems and / or one or more devices that use virtualization technology in the storage systems or devices of computing resources 124a-d. Regarding storage systems, the types of virtualization may include block virtualization and file virtualization. Block virtualization may refer to abstracting (or separating) logical storage from physical storage so that the storage system can be accessed without regard to the physical storage or heterogeneous structure. The separation may permit the administrator of the storage system to flexibly manage the storage devices for end users. File virtualization may eliminate the dependency between the data accessed at the file level and the location of the files physically stored. This may enable optimization of storage usage, server consolidation, and / or performance of non-disruptive file migration.
[0026] Hypervisor 124-4 may provide hardware virtualization technology that allows multiple operating systems (e.g., "guest operating systems") to execute simultaneously on a host computer (such as computing resources 124a-d). Hypervisor 124-4 may present a virtual operating platform to the guest operating systems, and may manage the execution of guest operating systems in multiple instances of various operating systems, and may share virtualized hardware resources.
[0027] According to some aspects, computing device 110 may support and / or facilitate secure exchange of sensitive data / information among the devices and / or components of system 100. According to some aspects, computing device 110 may support and / or facilitate secure exchange of sensitive data / information among the devices and / or components of system 100 by generating and processing tokens associated with the sensitive information.
[0028] According to some aspects, computing device 110 may include a tokenization module 112. According to some aspects, tokenization module 112 may provide, support, and / or facilitate a vaultless tokenization service (e.g., tokenize and detokenize data, etc.) to securely communicate sensitive information to computing system 118, etc. Tokenization involves replacing sensitive information (such as a social security number, an account number, etc.) with an encrypted generated replacement value or token. According to some aspects, a request for tokenization may be included in a request from a device and / or application attempting to protect sensitive information, access secure resources, etc. According to some aspects, a tokenization request may include a user object to be tokenized, such as user data / information (e.g., sensitive data). According to some aspects, user data / information may include a username / password associated with a user account, a social security number, financial information, bank account information, authentication information used to authenticate a user's identity, etc. According to some aspects, a token may enable access to a resource, e.g., within a defined time period (e.g., during a communication session, etc.).
[0029] According to some aspects, tokenization module 112 may authenticate and / or authorize any tokenization requests received from user device 102 and / or computing system 118 (e.g., received via a web service, a RESTful service, a secure hypertext transfer protocol (HTTPS) uniform resource locator (URL) via the transport layer security (TLS) protocol, etc.).
[0030] According to some aspects, computing device 110 may generate a security token (e.g., in response to a tokenization request), which can be used to access electronically restricted resources (e.g., computing resources 124a-d, etc.) and / or access / enable resources, functions, and actions within specific applications and / or domains of system 100. For example, according to some aspects, each computing resource 124a-d may be associated with a different domain of a multi-domain application. For example, computing resource 124a may be associated with an electronic banking domain, computing resource 124b may be associated with a digital wallet and / or card management domain, computing resource 124c may be associated with a fintech-related domain, computing resource 124c may be associated with a social networking domain, etc. According to some aspects, each domain (e.g., computing resources 124a-d, etc.) may be associated with a single sign-on (SSO) and / or single sign-out (SLO) application / platform, and different security tokens may be used to access different domains. For example, tokenization module 112 may generate tokens specified for a domain and / or security / token level. The domain indicated for the token may be a domain of a multi-domain application, etc., and the security token is used to enable access to that domain. The security / token level may be an indication of the resources, functions, and actions available to user device 102 within the domain, for the computing resource and / or the backend platform components for which the security token is prepared.
[0031] According to some aspects, computing device 110 may include a storage module 114. Storage module 114 may include physical storage devices, virtual storage devices, local storage devices, and / or remote storage media. According to some aspects, storage module 114 may store user objects associated with a user (e.g., a user of user device 102, etc.), such as sensitive data (e.g., credit card numbers, account numbers, personal information). According to some aspects, storage module 114 may store user objects in hash form, encrypted form, and / or encrypted hash form.
[0032] According to some aspects, storage module 114 may store data / information used for vaultless tokenization. According to some aspects, storage module 114 may store data / information used for generating security tokens, including but not limited to multiple randomly generated tables (e.g., alphabet tables, number tables, alphanumeric tables, etc.). According to some aspects, storage module 114 may store key-value pairs and / or related information (e.g., various data structures, hashes, access control lists, data sets, token definitions, etc.).
[0033] According to some aspects, computing device 110 may include a Hardware Security Module (HSM) 116 and / or communicate with a Hardware Security Module (HSM) 116. According to some aspects, HSM 116 may generate, store, and / or provide encryption keys (and / or secrets, hash keys, etc.) to computing device 110. According to some aspects, any additional data / information used by tokenization module 112 for vaultless tokenization (e.g., starting variables, token parameters, keys, etc. used for token generation) may be stored. For example, HSM 116 may store indications for generating, storing, and / or providing unique keys, hash algorithms, salt values, iteration counts, token layouts, token types (e.g., alphanumeric, numeric, alphabetic, string, etc.), substitution values, padding values, token ranges, formats, etc. According to some aspects, computing device 110 may communicate with HSM 116 as a dedicated module and / or partition for vaultless tokenization and / or encryption services. According to some aspects, computing device 110 may communicate with HSM 116 to access, retrieve, and / or receive encryption keys and / or any other data / information required for runtime tokenization and / or encryption.
[0034] According to some aspects, computing device 110 (e.g., tokenization module 112) may initiate a vaultless tokenization process by generating multiple random tables (e.g., 10M+ alphanumeric tables, alphabet tables, numeric tables, symbol tables, etc.). According to some aspects, as described herein, increasing the number of multiple random tables used for vaultless tokenization increases the randomness of the output tokens, such that malicious actors attempting to decrypt and / or reverse engineer the generated tokens will not be able to discern which characters, values, symbols, numbers, etc. of the tokens represent the original data / information and which characters, values, symbols, numbers, etc.
[0035] According to some aspects, computing device 110 may generate various types of tables, such as a numeric table with a value range of 0 - 9, an alphabet table including lowercase and uppercase letter characters, an alphanumeric table combining numeric values with lowercase and uppercase letter characters, and / or a table including other characters (such as special / non - ASCII characters). According to some aspects, multiple randomly generated tables may be stored. For example, multiple randomly generated tables may be serialized into an encrypted file stored by storage module 114. For example, the file containing the serialized multiple randomly generated tables may be encrypted using a file encryption key, and the file encryption key may be decrypted using a key encryption key (KEK) from HSM116, etc.
[0036] According to some aspects, multiple randomly generated tables can be used later to map and shuffle portions (e.g., characters, digits, symbols, etc.) of information (e.g., sensitive information / data, digital user information, etc.). For example, each of the multiple randomly generated tables can include a specific number of characters to map information (e.g., sensitive information / data, digital user information, etc.) based on a partitioning and / or segmentation manner of the information. According to some aspects, additional metadata (e.g., metadata indicating and / or describing user data / information length, version number, field type, CRC, etc.) can be shuffled via the multiple randomly generated tables and used to further protect any generated tokens via data padding, appending, prepending, token modification, etc. For example, the shuffled additional metadata can be added to portions of the generated tokens. Malicious actors attempting to decrypt and / or reverse engineer tokens generated as described herein will not be able to discern which characters, values, symbols, digits, etc. of the token represent the original data / information and which characters, values, symbols, digits, etc. have been added to the encrypted form of the original data / information by data padding, appending, prepending, token modification, etc.
[0037] According to some aspects, the tokenization module 112 can generate an encryption key, which can be used when generating random tables and / or facilitating related processes. According to some aspects, an encryption key can be generated for each user device (e.g., user device 102, etc.) of the system 100, e.g., during a user / client registration process, etc. For example, the system 100 can include any number of user devices, and each user device (e.g., user device 102, etc.) can be associated with an identifier (e.g., customer identifier, user identifier, device identifier, etc.). The tokenization module 112 can generate a data encryption key, a hash function key for generating CRC (e.g., HMAC / hash key, etc.), and an initialization vector (IV) (e.g., starting variable (SV), etc.) based on the identifier of the user device, and encrypt them using the KEK. According to some aspects, the tokenization module 112 can use any encryption technique.
[0038] According to some aspects, the computing device 110 can generate any type of table to be used for the vaultless tokenization described herein. According to some aspects, the computing device 110 can generate a table with 10M+ rows, where each row includes a pair of encrypted and randomly shuffled character sets to achieve vaultless tokenization and / or detokenization. According to some aspects, the computing device 110 can utilize a large set of randomly generated tables to increase the randomness of token generation - thus preventing reverse engineering efforts.
[0039] According to some aspects, computing device 110 can generate a table index from one or more pre-configured secrets (e.g., confidential information, passwords, credentials, keys, etc.), input value characters (numbers, characters, symbols, etc.), and matching operations (e.g., HMAC, etc.). The table index can be used to identify an initial table among multiple tables for use when shuffling different input value characters through different tables among the multiple tables to generate a token. According to some aspects, computing device 110 can also generate an increment value from one or more pre-configured secrets, input value characters (numbers, characters, symbols, etc.), and matching operations (e.g., HMAC, etc.). The increment value can be used to determine the next table to select after the initial table, and to shuffle the next value of the input value characters after the initial table among the multiple tables is used to shuffle the initial value of the input value. According to some aspects, the increment value can be used to determine a table index for each character in the input value, which results in different tables being selected for each character. According to some aspects, to increase the randomness of the generated token value, the input value characters can be shuffled according to a randomly determined number of rounds (an indication of which can be stored in HSM 116) and used to generate different table indexes to be used for the next input value character determined after each input value character shuffle round. According to some aspects, computing device 110 can use any shuffling scheme to shuffle the input value characters according to the systems, apparatuses, devices, methods, computer program product embodiments, and / or combinations and sub-combinations thereof for vaultless tokenization described herein.
[0040] According to some aspects, in a scenario where a malicious actor gains access to the encrypted random tables generated by computing device 110, the malicious actor is still unable to reverse engineer any tokens generated according to the systems, apparatuses, devices, methods, computer program product embodiments, and / or combinations and sub-combinations thereof for vaultless tokenization described herein. For example, the malicious actor lacks the necessary encryption keys, hash keys, and other confidential values stored by HSM 116. Additionally, the malicious actor does not know the logic for deriving any runtime values from the encryption keys, hash keys, and other confidential values stored by HSM 116, nor the exact algorithm / shuffling logic for replicating the multiple random tables used by computing device 110.
[0041] According to some aspects, computing device 110 may generate a token based on a vaultless tokenization process. According to some aspects, the processes for token generation described below may be used to generate a security token that cannot be reverse engineered, for example, by brute force. According to some aspects, the processes for token generation are provided as examples. The system, apparatus, device, method, and / or computer program product embodiments for vaultless tokenization, and / or combinations and sub-combinations thereof are not limited to the token generation process, and other steps may be used according to the aspects described herein.
[0042] Token Generation
[0043] Steps:
[0044] 1. Verify the input data / information (e.g., digital user information, etc.) via a checksum formula to distinguish valid digits, characters, symbols, etc. from incorrect input / incorrect digits, characters, symbols, etc.
[0045] For example:
[0046] Input value = 0123456789
[0047] 2. Calculate digital and alphanumeric checksums. The alphanumeric checksum is shuffled through a randomly generated table.
[0048] For example:
[0049] a. Calculate CRC7 of the input value length to output a digital checksum = 19
[0050] b. Convert the digital checksum to base62 = J
[0051] c. Use a randomly generated alphanumeric table to shuffle the converted digital checksum to output an alphanumeric checksum = 4
[0052] 3. Generate a table index (table lookup index) from the digital checksum. Optionally, to increase security, the table index is generated from one or more pre-configured secrets, characters (digits, characters, symbols, etc.) from the input value, and / or matching operations.
[0053] 4. Shuffle the data / information using a randomly generated table (e.g., shuffle the characters of digital user information through a randomly generated numeric table, etc.). Shuffle each digit, character, symbol, etc. of the input data / information from different tables. Use the table index to identify which table to use.
[0054] For example:
[0055] Shuffled input value = 6516589042
[0056] 5. Perform one or more operations (e.g., format-preserving Feistel-based encryption mode (FF1), XOR, inversion, splitting, shuffling indices, etc.) at runtime (e.g., when an application / system requests and / or needs to use a token to start, etc.) to change the value of the input data / information. According to some aspects, selectively perform one or more operations at runtime to change the value of the input data / information, e.g., based on pre-configurations, system settings, and / or preferences (e.g., security preferences of tokenized entities and / or services, etc.). According to some aspects, randomly perform one or more operations at runtime to change the value of the input data / information. Perform one or more operations with multiple rounds in different orders at runtime.
[0057] For example:
[0058] Apply one or more operations (e.g., format-preserving Feistel-based encryption mode (FF1), XOR, inversion, splitting, shuffling indices, etc.) to the input value = 2691294559
[0059] 6. Transform the value of the changed input data / information. For example, convert any numerical value to alphanumeric (e.g., according to base52, base62, base64, etc.).
[0060] For example:
[0061] Convert the format-preserving encryption (FPE) value u128 to Base62 = 2w8Oel
[0062] 7. Generate a token value by shuffling the value of the transformed input data / information through a random table (e.g., an alphanumeric table, etc.) in multiple rounds. Shuffle each digit, character, symbol, etc. of the transformed input data / information from different tables. Use table indices to identify which table to use.
[0063] For example:
[0064] Shuffle the value from step 6 (e.g., 2w8Oel) using a randomly generated alphanumeric table = oXZslN
[0065] 8. Output the token value.
[0066] For example:
[0067] Alphanumeric token = oXZslN
[0068] According to some aspects, the computing device 110 can modify any token generated as described herein (e.g., a token output from the token generation process, etc.) based on a vaultless tokenization algorithm to obtain additional security. According to some aspects, the processes for token modification described below can be used to modify any token generated as described herein to obtain additional security. Tokens modified according to the processes for token modification cannot be reverse engineered, for example, by brute force. According to some aspects, the processes for token modification are provided as examples. Systems, apparatuses, devices, methods, and / or computer program product embodiments for vaultless tokenization, and / or combinations and subcombinations thereof are not limited to the processes for token modification, and other steps can be used according to the aspects described herein.
[0069] Token Modification
[0070] Steps:
[0071] 1. Determine whether the length of the input data / information should be included in the generated token (output of the token generation process, etc.). (If so, shuffle the length using a randomly generated table. Use the table index from the token generation process to identify which table to use).
[0072] For example:
[0073] a. Calculate the length of the input value (0123456789) = 10
[0074] b. Use a lookup based on the table index to convert to a letter = k
[0075] c. Shuffle the length (10) using a randomly generated alphabet = o
[0076] 2. Modify the token (e.g., oXZslN) to include the value determined from step 1.
[0077] For example:
[0078] Modified alphanumeric token = ooXZslN
[0079] 3. For additional security, further modify the token (e.g., oXZslN) length to match the length of the input value. For example, if the token length is less than the expected output length, generate a random number checksum to base62 (e.g., J). Determine the position in the token where the random number is to be inserted from the table index. Optionally, determine the position in the token where the prefix of the checksum character is to be inserted from the table index.
[0080] For example:
[0081] Modified alphanumeric token with a prefixed random number checksum = JooXZslN4
[0082] In accordance with some aspects, the computing device 110 (tokenization module 112) may de-tokenize tokenized user data / information to determine, identify, and / or access the original user data / information. In accordance with some aspects, the tokenization module 112 may use multiple randomly generated tables (and in some instances, encryption keys from the HSM 116) in the reverse process of the token generation and modification process to de-tokenize any generated tokens.
[0083] Figure 2 An example computer-implemented method 200 for vaultless tokenization in accordance with some aspects of the present disclosure is shown. The method 200 may be executed by processing logic that may include hardware (e.g., circuitry, dedicated logic, programmable logic, microcode, etc.), software (e.g., instructions executed on a processing device), or a combination thereof. It should be understood that not all steps may be required to implement the disclosure provided herein. Additionally, as would be understood by one of ordinary skill in the art, some of the steps may be executed simultaneously or in an order different from the order Figure 2 shown. Method 200 will be described with reference to the elements of Figure 1 . However, method 200 is not limited to the specific aspects depicted in Figure 1 and, as would be understood by those skilled in the art, other systems may be used to execute the method.
[0084] In 210, the computing device 110 determines an alphanumeric value. In accordance with some aspects, the computing device 110 may determine the alphanumeric value in response to a request for tokenization (e.g., generating a token, etc.). Tokenization involves replacing sensitive information (such as a social security number, account number, etc.) with an encrypted generated replacement value or token.
[0085] In accordance with some aspects, the request for tokenization may be included in a request from a device and / or application attempting to protect sensitive information, access secure resources, etc. In accordance with some aspects, a token may enable access to a resource, e.g., within a defined time period. Determining the alphanumeric value may be performed at the beginning of the tokenization process.
[0086] According to some aspects, computing device 110 may determine an alphanumeric value based on a numeric value generated from a hash of digital user information shuffled through a plurality of randomly generated alphanumeric tables. For example, during a vaultless tokenization initialization process or the like, computing device 110 may generate and / or store a plurality of randomly generated tables, which include a plurality of randomly generated alphanumeric tables, a plurality of randomly generated numeric tables, and the like. According to some aspects, digital user information (with or without a preconfigured secret encryption key) may be hashed according to a hash function to output hashed digital information. According to some aspects, the hashed digital user information may be encrypted to output a numeric value. For example, according to some aspects, an additive cipher application and / or information may be used to modify the hash value of the digital user information, and the modified hash value may be shuffled through a plurality of randomly generated alphanumeric tables to output a numeric value, and so on.
[0087] In 220, computing device 110 generates a table index. According to some aspects, computing device 110 may generate a table index (such as a reverse lookup table, etc.) based on the alphanumeric value and at least a portion of the digital user information. According to some aspects, the table index may be encrypted and stored by an HSM (such as HSM 116, etc.) based on an encryption key (such as a user-specific encryption key, etc.). The table index may be accessed and / or used occasionally, such as during the generation of a token, and so on.
[0088] In 230, computing device 110 generates shuffled digital user information. According to some aspects, computing device 110 may generate shuffled digital user information based on the table index and a plurality of randomly generated numeric tables. For example, computing device 110 may generate shuffled digital user information by shuffling the digital user information through a plurality of randomly generated numeric tables. According to some aspects, each numeric character in the digital user information may be shuffled through a different one of the plurality of randomly generated numeric tables identified for that character based on the table index.
[0089] In 240, computing device 110 converts the shuffled digital user information into alphanumeric user information. According to some aspects, computing device 110 may convert the shuffled digital user information into alphanumeric user information based on format-preserving encryption applied to the shuffled digital user information, additive cipher information applied to the shuffled digital user information, and so on.
[0090] In 250, computing device 110 shuffles each character of the alphanumeric user information through a different alphanumeric table among a plurality of randomly generated alphanumeric tables. According to some aspects of the present disclosure, each different alphanumeric table may be identified for each character based on the table index.
[0091] In 260, computing device 110 generates an alphanumeric token. According to some aspects, computing device 110 can generate an alphanumeric token based on shuffled characters of alphanumeric user information.
[0092] According to some aspects of the present disclosure, method 200 may further include computing device 110 filling the alphanumeric token with randomly generated numeric characters. According to some aspects, computing device 110 can fill the alphanumeric token with randomly generated numeric characters based on an indication that indicates that numeric characters of numeric user information are removed according to shuffling of the numeric user information through a plurality of randomly generated numeric tables.
[0093] According to some aspects of the present disclosure, method 200 may further include computing device 110 filling the alphanumeric token with alphanumeric values.
[0094] According to some aspects of the present disclosure, method 200 may further include computing device 110 determining a numeric value indicating the amount of numeric characters of numeric user information. According to some aspects, computing device 110 can determine an alphabetic value indicating the amount of numeric characters of numeric user information based on an alphabetic representation of the numeric value shuffled through a plurality of randomly generated alphabets. According to some aspects, computing device 110 can append the alphabetic value to the alphanumeric token.
[0095] According to some aspects of the present disclosure, method 200 may further include computing device 110 sending the alphanumeric token to a user device, storage medium, application, etc. associated with the numeric user information to facilitate access to resources, etc.
[0096] Aspects of the present disclosure can be implemented, for example, using one or more computer systems (such as Figure 3 computer system 300 shown in). Any device and / or component described herein can be and / or include computing system 300. Computing system 300 can be used, for example, to implement any method described herein (e.g., method 200, etc.). Computing system 300 can be any computer capable of performing the functions described herein.
[0097] Computing system 300 can be any well-known computer capable of performing the functions described herein.
[0098] Computing system 300 includes one or more processors (also referred to as central processing units or CPUs), such as processor 304. Processor 304 is connected to communication infrastructure 306 (bus, etc.).
[0099] One or more processors 304 may each be a graphics processing unit (GPU). According to some aspects, a GPU is a processor that is a specialized electronic circuit designed to handle mathematically intensive applications. A GPU may have a parallel architecture that is efficient for parallel processing of large blocks of data (such as the mathematically intensive data common in computer graphics applications, images, videos, etc.).
[0100] The computer system 300 also includes (a) user input / output device(s) 303, such as a monitor, keyboard, pointing device, etc., which communicate with the communication infrastructure 306 via (a) user input / output interface(s) 302.
[0101] The computer system 300 also includes a main memory or primary storage 308, such as random access memory (RAM). The main memory 308 may include one or more levels of cache. The main memory 308 stores control logic (e.g., computer software) and / or data therein.
[0102] The computer system 300 may also include one or more auxiliary storage devices or memories 310. The auxiliary memory 310 may include, for example, a hard disk drive 312 and / or a removable storage device or drive 314. The removable storage drive 314 may be a floppy disk drive, a tape drive, a compact disk drive, an optical storage device, a tape backup device, and / or any other storage device / drive.
[0103] The removable storage drive 314 may interact with a removable storage unit 318. The removable storage unit 318 includes a computer-usable or readable storage device on which computer software (control logic) and / or data is stored. The removable storage unit 318 may be a floppy disk, a tape, a compact disk, a DVD, an optical storage disk, and / or any other computer data storage device. The removable storage drive 314 reads from and / or writes to the removable storage unit 318 in a well-known manner.
[0104] According to an exemplary embodiment, the auxiliary memory 310 may include other devices, tools, or other methods for allowing the computer system 300 to access computer programs and / or other instructions and / or data. Such devices, tools, or other methods may include, for example, a removable storage unit 322 and an interface 320. Examples of the removable storage unit 322 and the interface 320 may include a program cartridge and a cartridge interface (such as the program cartridge and cartridge interface found in video game devices), a removable memory chip (such as an EPROM or PROM) and an associated socket, a memory stick and a USB port, a memory card and an associated memory card slot, and / or any other removable storage unit and associated interface.
[0105] The computer system 300 may also include a communication or network interface 324. The communication interface 324 enables the computer system 300 to communicate and interact with any combination of remote devices, remote networks, remote entities, etc. (collectively and individually represented by reference numeral 328). For example, the communication interface 324 may allow the computer system 300 to communicate with a remote device 328 via a communication path 326, which may be wired and / or wireless and may include any combination of LAN, WAN, the Internet, etc. Control logic and / or data may be transmitted to and from the computer system 300 via the communication path 326.
[0106] In accordance with some aspects, a tangible apparatus or article of manufacture that includes a tangible computer-usable or readable medium having control logic (software) stored therein is also referred to herein as a computer program product or a program storage device. This includes, but is not limited to, the computer system 300, the main memory 308, the secondary memory 310, and the removable storage units 318 and 322, as well as tangible articles of manufacture embodying any combination thereof. Such control logic, when executed by one or more data processing devices such as the computer system 300, causes such data processing devices to operate as described herein.
[0107] Based on the teachings contained in this disclosure, those of ordinary skill in the relevant art(s) will appreciate how to make and use embodiments of this disclosure using data processing devices, computer systems, and / or computer architectures other than those shown Figure 3 in this specification. Specifically, the embodiments may operate with software, hardware, and / or operating system implementations other than those described herein.
[0108] It should be understood that the detailed description section, rather than the summary and abstract sections (if any), is intended to be used to interpret the claims. The summary and abstract sections (if any) may set forth one or more, but not all, exemplary embodiments contemplated by the inventors, and thus are not intended to limit this disclosure or the appended claims in any way.
[0109] Although this disclosure has been described with reference to exemplary embodiments in exemplary fields and applications, it should be understood that this disclosure is not limited thereto. Other embodiments and modifications thereof are possible and within the scope and spirit of this disclosure. For example, without limiting the generality of this paragraph, the embodiments are not limited to the software, hardware, firmware, and / or entities illustrated in the figures and / or described herein. Additionally, the embodiments (whether or not explicitly described herein) have significant utility in fields and applications other than those exemplified herein.
[0110] Embodiments have been described herein with reference to functional building blocks that illustrate the implementation of specified functions and their relationships. For convenience of description, the boundaries of these functional building blocks have been arbitrarily defined herein. Alternative boundaries may be defined so long as the specified functions and relationships (or their equivalents) are appropriately performed. In addition, alternative embodiments may perform functional blocks, steps, operations, methods, etc. in an order different from those described herein.
[0111] References herein to "one embodiment", "an embodiment", "example embodiment", or similar phrases indicate that the described embodiment may include a particular feature, structure, or characteristic, but every embodiment may not necessarily include the particular feature, structure, or characteristic. Moreover, such phrases do not necessarily refer to the same embodiment. In addition, when a particular feature, structure, or characteristic is described in connection with an embodiment, incorporating such feature, structure, or characteristic into other embodiments (whether explicitly mentioned or described herein or not) will be within the knowledge of those of ordinary skill in the relevant art(s).
[0112] The breadth and scope of the present disclosure should not be limited by any of the embodiments described above in the exemplary embodiments, but should be defined only in accordance with the following claims and their equivalents.
Claims
1. A computer-implemented method, comprising: Determining an alphanumeric value based on a numeric value generated from a hash of digital user information shuffled through a plurality of randomly generated alphanumeric tables; Generating a table index based on the alphanumeric value and at least a portion of the digital user information; Generating shuffled digital user information based on the table index and a plurality of randomly generated numeric tables; Converting the shuffled digital user information into alphanumeric user information based on at least one of a format-preserving encryption applied to the shuffled digital user information or additive cryptographic information applied to the shuffled digital user information; Shuffling each character of the alphanumeric user information through different alphanumeric tables among the plurality of randomly generated alphanumeric tables, wherein each different alphanumeric table is identified for each character based on the table index; And Generating an alphanumeric token based on the shuffled characters of the alphanumeric user information.
2. The computer-implemented method according to claim 1, further comprising filling the alphanumeric token with randomly generated numeric characters based on an indication that numeric characters of the digital user information are removed as the digital user information is shuffled through the plurality of randomly generated numeric tables.
3. The computer-implemented method according to claim 1, further comprising: Determining a numeric value indicative of an amount of numeric characters of the digital user information; Determining an alphabetic value indicative of the amount of numeric characters of the digital user information based on an alphabetic representation of the numeric value shuffled through a plurality of randomly generated alphabetic tables; and Appending the alphabetic value to the alphanumeric token.
4. The computer-implemented method according to claim 1, further comprising filling the alphanumeric token with the alphanumeric value.
5. The computer-implemented method according to claim 1, further comprising: Hashing the digital user information and a key to output the hashed digital user information; And Encrypting the hashed digital user information to output the numeric value.
6. The computer-implemented method according to claim 1, wherein generating the shuffled digital user information comprises shuffling the digital user information through the plurality of randomly generated numeric tables, wherein each numeric character of the digital user information is shuffled through a different numeric table among the plurality of randomly generated numeric tables identified for the numeric character based on the table index.
7. The computer-implemented method according to claim 1, further comprising sending the alphanumeric token to at least one of a user device, a storage medium, or an application associated with the digital user information to facilitate access to a resource.
8. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations including the following: Determining an alphanumeric value based on a numeric value generated from a hash of digital user information shuffled through a plurality of randomly generated alphanumeric tables; Generate a table index based on at least a portion of the alphanumeric value and the digital user information; Generate shuffled digital user information based on the table index and a plurality of randomly generated digital tables; Convert the shuffled digital user information into alphanumeric user information based on at least one of format-preserving encryption applied to the shuffled digital user information or additive cipher information applied to the shuffled digital user information; Shuffle each character of the alphanumeric user information through different alphanumeric tables among the plurality of randomly generated alphanumeric tables, wherein each different alphanumeric table is identified for each character based on the table index; And Generate an alphanumeric token based on the shuffled characters of the alphanumeric user information.
9. The non-transitory computer-readable medium according to claim 8, wherein the operations further include filling the alphanumeric token with randomly generated digital characters based on an indication that digital characters of the digital user information are removed as the digital user information is shuffled through the plurality of randomly generated digital tables.
10. The non-transitory computer-readable medium according to claim 8, wherein the operations further include: Determine a digital value indicating the amount of digital characters of the digital user information; Determine an alphabetic value indicating the amount of digital characters of the digital user information based on an alphabetic representation of the digital value being shuffled through a plurality of randomly generated alphabetic tables; and Append the alphabetic value to the alphanumeric token.
11. The non-transitory computer-readable medium according to claim 8, wherein the operations further include filling the alphanumeric token with the alphanumeric value.
12. The non-transitory computer-readable medium according to claim 8, wherein the operations further include: Hash the digital user information and a key to output the hashed digital user information; And Encrypt the hashed digital user information to output the digital value.
13. The non-transitory computer-readable medium according to claim 12, wherein generating the shuffled digital user information includes shuffling the digital user information through the plurality of randomly generated digital tables, wherein each digital character of the digital user information is shuffled through a different digital table among the plurality of randomly generated digital tables identified for the digital character based on the table index.
14. The non-transitory computer-readable medium according to claim 8, wherein the operations further include sending the alphanumeric token to at least one of a user device, a storage medium, or an application associated with the digital user information to facilitate access to a resource.
15. A system, comprising: A memory; And At least one processor coupled to the memory and configured to perform operations including: Determine an alphanumeric value based on a digital value generated from a hash of digital user information shuffled through a plurality of randomly generated alphanumeric tables; Generate a table index based on the alphanumeric value and at least a portion of the digital user information; Generate a shuffled digital user information based on the table index and multiple randomly generated digital tables; Convert the shuffled digital user information into alphanumeric user information based on at least one of format-preserving encryption applied to the shuffled digital user information or additive cipher information applied to the shuffled digital user information; And Shuffle each character of the alphanumeric user information through different alphanumeric tables among the multiple randomly generated alphanumeric tables, wherein each different alphanumeric table is identified for each character based on the table index; And Generate an alphanumeric token based on the shuffled characters of the alphanumeric user information.
16. The system according to claim 15, wherein the operation further includes filling the alphanumeric token with randomly generated digital characters based on an indication that digital characters of the digital user information are removed as the digital user information is shuffled through the multiple randomly generated digital tables.
17. The system according to claim 15, wherein the operation further includes: Determine a numerical value indicating the amount of digital characters of the digital user information; Determine an alphabetic value indicating the amount of digital characters of the digital user information based on an alphabetic representation of the numerical value being shuffled through multiple randomly generated alphabetic tables; and Append the alphabetic value to the alphanumeric token.
18. The system according to claim 15, wherein the operation further includes filling the alphanumeric token with the alphanumeric value.
19. The system according to claim 15, wherein the operation further includes: Hash the digital user information and a key to output the hashed digital user information; And Encrypt the hashed digital user information to output the numerical value.
20. The system according to claim 19, wherein generating the shuffled digital user information includes shuffling the digital user information through the multiple randomly generated digital tables, wherein each digital character of the digital user information is shuffled through a different digital table among the multiple randomly generated digital tables identified for the digital character based on the table index.