System, Method, and Medium for Generating a Document Containing Confidential Information

A system and method for generating documents with confidential information using a high-trust network to replace tokens in a low-trust network, addressing theft and misuse risks and reducing liability and revenue loss.

JP7711233B2Active Publication Date: 2025-07-22INSTITUTIONAL CAPITAL NETWORK INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023579528
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-01-03
Filing Date
2022-03-01
Publication Date
2025-07-22
Estimated Expiration
2042-03-01

AI Technical Summary

Technical Problem

Organizations face risks of theft and misuse of confidential information when sharing it with external parties for document generation, leading to liability and revenue loss.

Method used

A system and method for generating documents with confidential information using a high-trust network to store and access sensitive data, replacing tokens with actual information in a low-trust network, and providing a URL to access the enriched document.

Benefits of technology

Protects confidential information from theft and misuse by ensuring it remains within a secure network, reducing liability and revenue loss for organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711233000001
    Figure 0007711233000001
  • Figure 0007711233000002
    Figure 0007711233000002
  • Figure 0007711233000003
    Figure 0007711233000003
Patent Text Reader

Abstract

An apparatus for generating a document having secret information, the apparatus having a memory; and a first set of at least one hardware processor coupled to the memory, the first set of at least one hardware processor configured to: receive a request for a first document having secret information from a user device; generate a second document corresponding to the first document having at least one token corresponding to the secret information; transmit the second document to a second set of at least one hardware processor in a trusted network that is entitled to access the secret information; receive a Uniform Resource Locator (URL) corresponding to the first document from the second set of at least one hardware processor in the trusted network; and transmit the URL to the user device. In some of these apparatuses, the user device is in the trusted network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims the benefit of U.S. Patent Application No. 17 / 356,097, filed on June 23, 2021; U.S. Patent Application No. 17 / 356,104, filed on June 23, 2021; U.S. Patent Application No. 17 / 356,109, filed on June 23, 2021; and U.S. Patent Application No. 17 / 567,640, filed on January 3, 2022, the benefits of each of which are incorporated herein by reference.

Background Art

[0002] Confidential information such as personally identifiable information (PII), medical information (e.g., protected health information regulated under the Health Insurance Portability and Accountability Act (HIPAA) in the United States), and customer information (e.g., customer information of financial service companies or law firms) needs to be protected from disclosure to those who should not have the information. In many cases, when an organization (e.g., a company) is collaborating with other parties (e.g., vendors) that generate documents related to confidential information, it is necessary to provide the confidential information to such other parties. Unfortunately, by providing confidential information to other parties, the organization is exposed to the risk that the confidential information may be stolen or misused, and may be exposed to liability (e.g., liability under the General Data Protection Regulation of the European Union) and loss of revenue.

Summary of the Invention

Problems to be Solved by the Invention

[0003] Therefore, it is desirable to provide a new mechanism for generating documents containing confidential information.

Means for Solving the Problems

[0004] According to some embodiments, a system, method, and medium for generating a document containing confidential information are provided.

[0005] In some embodiments, systems are provided for generating a document having secret information. The systems include a memory and a first set of at least one hardware processor coupled to the memory. The first set of hardware processors receives a request for a first document having secret information from a user device, generates a second document corresponding to the first document having at least one token corresponding to the secret information, transmits the second document to a second set of at least one hardware processor within a highly trusted network having access to the secret information, receives a uniform resource locator (URL) corresponding to the first document from the second set of at least one hardware processor within the highly trusted network, and is configured to transmit the URL to the user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the second set of at least one hardware processor within the highly trusted network is within a server. In some of these embodiments, the first document is stored on a server. In some of these embodiments, the second set of at least one hardware processor receives the second document from the first set of at least one hardware processor, generates the first document by replacing the at least one token within the second document, stores the first document, and is configured to transmit the URL to the first set of at least one hardware processor. In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to the user device. In some of these embodiments, the user device transmits the request for the first document to the first set of at least one hardware processor, receives the URL, uses the URL to request the first document, receives the first document, and is further configured to present the first document.

[0006] In some embodiments, a method for generating a document with secret information is provided. The method includes receiving, from a user device, a request for a first document with secret information; using a first set of at least one hardware processor to generate a second document corresponding to the first document, the second document having at least one token corresponding to the secret information; using the first set of at least one hardware processor to transmit the second document to a second set of at least one hardware processor within a highly trusted network that is authorized to access the secret information; receiving, from the second set of at least one hardware processor within the highly trusted network, a uniform resource locator (URL) corresponding to the first document; and transmitting the URL to the user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the second set of at least one hardware processor within the highly trusted network is within a server. In some of these embodiments, the first document is stored in a server. In some of these embodiments, the second set of at least one hardware processor is configured to receive the second document from the first set of at least one hardware processor, generate the first document by replacing the at least one token in the second document, store the first document, and transmit the URL to the first set of at least one hardware processor. In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to the user device. In some of these embodiments, the user device is further configured to transmit the request for the first document to the first set of at least one hardware processor, receive the URL, request the first document using the URL, receive the first document, and present the first document.

[0007] In some embodiments, a non-transitory computer-readable medium is provided that includes computer-executable instructions that, when executed by a first set of at least one hardware processor, cause a method to be performed of generating a document having secret information with the first set of at least one hardware processor. The method includes receiving, from a user device, a request for a first document having secret information; generating a second document corresponding to the first document, the second document having at least one token corresponding to the secret information; sending the second document to a second set of at least one hardware processor within a highly trusted network having access to the secret information; receiving, from the second set of at least one hardware processor within the highly trusted network, a uniform resource locator (URL) corresponding to the first document; and sending the URL to the user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the second set of at least one hardware processor within the highly trusted network is within a server. In some of these embodiments, the first document is stored on the server. In some of these embodiments, the second set of at least one hardware processor is configured to receive the second document from the first set of at least one hardware processor; generate the first document by replacing the at least one token within the second document; store the first document; and send the URL to the first set of at least one hardware processor. In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to the user device. In some of these embodiments, the user device is further configured to send the request for the first document to the first set of at least one hardware processor; receive the URL; request the first document using the URL; receive the first document; and present the first document.

[0008] In some embodiments, systems for generating documents with secret information are provided. The systems have a memory and a first set of at least one hardware processor coupled to the memory. The first set of hardware processors receives a first document from a second set of at least one hardware processor, generates a second document by replacing at least one token in the first document, stores the second document, and transmits a uniform resource locator (URL) corresponding to the second document to the second set of at least one hardware processor. In some of these embodiments, the first set of at least one hardware processor is further configured to provide the first document to a user device. In some of these embodiments, the user device transmits a request for the first document to the first set of at least one hardware processor, receives the URL, requests the first document using the URL, receives the first document, and is configured to present the first document. In some of these embodiments, the second set of at least one hardware processor generates the first document corresponding to the second document having at least one token corresponding to secret information, transmits the first document to the first set of at least one hardware processor within a highly trusted network having access to the secret information, receives the uniform resource locator (URL) corresponding to the second document from the first set of at least one hardware processor within the highly trusted network, and is configured to transmit the URL to the user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the first set of at least one hardware processor is within a server. In some of these embodiments, the second document is stored on the server.

[0009] In some embodiments, a method for generating a document with secret information is provided, the method comprising using a first set of at least one hardware processor to receive a first document from a second set of at least one hardware processor; using the first set of at least one hardware processor to replace at least one token in the first document to generate a second document; storing the second document; and transmitting a uniform resource locator (URL) corresponding to the second document to the second set of at least one hardware processor. In some of these embodiments, the method further comprises providing the first document to a user device. In some of these embodiments, the user device transmits a request for the first document to the first set of at least one hardware processor; receives the URL; uses the URL to request the first document; receives the first document; and is configured to present the first document. In some of these embodiments, the second set of at least one hardware processor generates the first document corresponding to the second document with at least one token corresponding to secret information; transmits the first document to the first set of at least one hardware processor within a highly trusted network having access to the secret information; receives a uniform resource locator (URL) corresponding to the second document from the first set of at least one hardware processor within the highly trusted network; and is configured to transmit the URL to the user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the first set of at least one hardware processor is within a server. In some of these embodiments, the second document is stored on the server.

[0010] In some embodiments, a non-transitory computer-readable medium is provided that includes computer-executable instructions that, when executed by a first set of at least one hardware processor, cause the first set of at least one hardware processor to execute a method for generating a document with secret information. The method includes receiving a first document from a second set of at least one hardware processor; generating a second document by replacing at least one token in the first document; storing the second document; and sending a uniform resource locator (URL) corresponding to the second document to the second set of at least one hardware processor. In some of these embodiments, the method further includes providing the first document to a user device. In some of these embodiments, the user device sends a request for the first document to the first set of at least one hardware processor; receives the URL; requests the first document using the URL; receives the first document; and is configured to present the first document. In some of these embodiments, the second set of at least one hardware processor generates the first document corresponding to the second document with at least one token corresponding to the secret information; sends the first document to the first set of at least one hardware processor within a highly trusted network having access to the secret information; receives a uniform resource locator (URL) corresponding to the second document from the first set of at least one hardware processor within the highly trusted network; and is configured to send the URL to a user device. In some of these embodiments, the user device is within the highly trusted network. In some of these embodiments, the first set of at least one hardware processor is within a server. In some of these embodiments, the second document is stored on the server.

[0011] In some embodiments, a system for generating a document containing secret information is provided. The system includes a user device, which: sends a request for a first document having secret information to a first set of at least one hardware processor in a low-trust network that does not have access to the secret information; receives a uniform resource locator (URL) corresponding to the first document from the first set of at least one hardware processor; uses the URL to request the first document from a second set of at least one hardware processor in a high-trust network that has access to the secret information; receives the first document; and is configured to present the first document. In some of these embodiments, the user device is within the high-trust network. In some of these embodiments, the second set of at least one hardware processor in the high-trust network is within a server. In some of these embodiments, the first document is stored in the server. In some of these embodiments, the first set of at least one hardware processor: receives the request for the first document from the user device; generates a second document corresponding to the first document having at least one token corresponding to the secret information; sends the second document to the second set of at least one hardware processor; receives the uniform resource locator (URL) corresponding to the first document from the second set of at least one hardware processor; and is configured to send the URL to the user device. In some of these embodiments, the second set of at least one hardware processor: receives the second document from the first set of at least one hardware processor; generates the first document by replacing at least one token in the second document; stores the first document; and is configured to send the URL to the first set of at least one hardware processor. In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to the user device.

[0012] In some embodiments, a method for generating a document with secret information is provided. The method includes sending a request for a first document with secret information to a first set of at least one hardware processor within a low-trust network that does not have access to the secret information; receiving, at the user device, a uniform resource locator (URL) corresponding to the first document from the first set of at least one hardware processor; requesting, from the user device, the first document to a second set of at least one hardware processor within a high-trust network that has access to the secret information using the URL; receiving, at the user device, the first document; and presenting the first document. In some of these embodiments, the user device is within the high-trust network. In some of these embodiments, the second set of at least one hardware processor within the high-trust network is within a server. In some of these embodiments, the first document is stored in a server. In some of these embodiments, the first set of at least one hardware processor is configured to receive a request for the first document from the user device; generate a second document corresponding to the first document with at least one token corresponding to the secret information; send the second document to the second set of at least one hardware processor; receive a uniform resource locator (URL) corresponding to the first document from the second set of at least one hardware processor; and send the URL to the user device. In some of these embodiments, the second set of at least one hardware processor is configured to receive the second document from the first set of at least one hardware processor; generate the first document by replacing at least one token in the second document; store the first document; and send the URL to the first set of at least one hardware processor. In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to the user device.

[0013] In some embodiments, a non - transitory computer - readable medium is provided that includes computer - executable instructions that, when executed by at least one processor, cause the at least one processor to execute a method for generating a document with secret information. The method includes: sending a request for a first document with secret information to a first set of at least one hardware processor within a low - trust network that does not have access to the secret information; receiving a Uniform Resource Locator (URL) corresponding to the first document from the first set of at least one hardware processor; using the URL to request the first document from a second set of at least one hardware processor within a high - trust network that has access to the secret information; receiving the first document; and presenting the first document. In some of these embodiments, the user device is within the high - trust network. In some of these embodiments, the second set of at least one hardware processor within the high - trust network is within a server. In some of these embodiments, the first document is stored on the server. In some of these embodiments, the first set of at least one hardware processor receives the request for the first document from a user device, generates a second document corresponding to the first document with at least one token corresponding to the secret information, sends the second document to the second set of at least one hardware processor, receives the Uniform Resource Locator (URL) corresponding to the first document from the second set of at least one hardware processor, and is configured to send the URL to the user device. In some of these embodiments, the second set of at least one hardware processor receives the second document from the first set of at least one hardware processor, generates the first document by replacing at least one token in the second document, stores the first document, and is configured to send the URL to the first set of at least one hardware processor.In some of these embodiments, the second set of at least one hardware processor is further configured to provide the first document to a user device.

Brief Description of the Drawings

[0014]

Figure 1

[0015]

Figure 2

[0016]

Figure 3

[0017]

Figure 4

[0018]

Figure 5

[0019]

Figure 6

[0020]

Figure 7

[0021]

Figure 8

[0022]

Figure 9

DETAILED DESCRIPTION OF THE INVENTION

[0023] According to some embodiments, a mechanism (which can include a system, method, and medium) for generating a document containing secret information is provided.

[0024] As will be described in more detail below, in some embodiments, to protect secret information from theft and / or misuse, the secret information is stored in and can be accessed from a high-trust network. Devices within the high-trust network are considered to be qualified to access that secret information. Tokens, or other suitable proxies for the secret information, can be generated and associated with the secret information. These tokens can be provided to devices within the low-trust network that are not qualified to access the secret information. Then, the devices within the low-trust network can generate documents (which may be referred to herein as non-enriched documents) in which those tokens are embedded, and the devices within the high-trust network can receive the documents, replace the tokens with the appropriate secret information (create enriched documents), and present those documents to users using user devices on the high-trust network.

[0025] As described above and below, these mechanisms provide important technical solutions to the problem of securely generating documents containing sensitive information without incurring the risk of exposing sensitive information in a low-trust network. With this mechanism, an organization can use a vendor to ultimately generate a document containing sensitive information without providing the sensitive information to the vendor. Since the vendor cannot access the sensitive information, the organization and the vendor do not need to worry about the sensitive information being stolen or misused from the vendor's computer. As a result, the organization and the vendor are protected from the liabilities and revenue losses associated with such theft or misuse.

[0026] Referring to FIG. 1, an example 100 of a system for generating a document containing sensitive information according to some embodiments is shown. As illustrated, system 100 includes a low-trust server 104 within a low-trust network 102, a communication network 106, a high-trust server 110 within a high-trust network 108, one or more user devices 112 within the high-trust network, and a communication link 114. Any other suitable components can be included in system 100.

[0027] The low-trust server 104 can be any suitable computing device that does not have access to certain types of sensitive information. In some embodiments, the low-trust server 104 can provide and / or generate a document to be enriched with sensitive information and / or perform any other suitable functions. Although only one low-trust server 104 is shown in FIG. 1, any suitable number of low-trust servers can be used in some embodiments.

[0028] As shown in FIG. 1, the low-trust server 104 can be part of a low-trust network 102 that has devices that do not have access to certain types of sensitive information. For example, the low-trust network 102 can be a network maintained by a vendor that does not have access to the organization's sensitive information.

[0029] The highly reliable server 110 can be any suitable computing device qualified to access certain types of secret information. In some embodiments, the highly reliable server 110 can enrich documents with secret information and / or perform any other suitable functions. Only one highly reliable server 110 is shown in FIG. 1, but in some embodiments, any suitable number of highly reliable servers can be used.

[0030] The user device 112 can be any suitable device for accessing certain types of secret information as part of an enriched document. An example of how such an enriched document is requested and provided will be described below in connection with FIG. 8. Two user devices 112 are shown in FIG. 1, but in some embodiments, any suitable number of user devices can be used.

[0031] In some embodiments, the user device 112 can be any device suitable for requesting and presenting an enriched document and / or performing any other suitable functions. For example, in some embodiments, the user device 112 can include mobile devices such as mobile phones, tablet computers, wearable computers, laptop computers, and / or other suitable mobile devices. As another example, in some embodiments, the user device 112 can include non-mobile devices such as televisions, projector devices, game consoles, desktop computers, and / or other suitable non-mobile devices.

[0032] As shown in FIG. 1, the highly reliable server 110 and the user device 112 can be part of a highly reliable network 108 having devices qualified to access certain types of secret information. For example, the highly reliable network 108 can be a network maintained by an organization qualified to access secret information.

[0033] In some embodiments, communication network 106 can be any suitable combination of one or more wired and / or wireless networks. For example, communication network 106 can include the Internet, an intranet, a wide area network (WAN), a local area network (LAN), a wireless network, a digital subscriber line (DSL) network, a frame relay network, an asynchronous transfer mode (ATM) network, a virtual private network (VPN), and / or any one or more of any other suitable communication networks.

[0034] Servers 104 and 110 and user device 112 can be connected to communication network 106 by one or more communication links 114. The communication link can be any communication link suitable for communicating data between servers 104 and 110 and user device 112, such as a network link, a dial-up link, a wireless link, a wired link, any other suitable communication link, or any suitable combination of such links. In some embodiments, the connection to communication network 106 may be through any suitable device, such as a router, a switch, a gateway, and / or any other suitable device (not shown).

[0035] Server 104 and / or 110 and / or user device 112 can be implemented using any suitable hardware in some embodiments. For example, in some embodiments, server 104 and / or 110 and / or user device 112 can be implemented using any suitable general-purpose computer or special-purpose computer. For example, a mobile phone can be implemented using a special-purpose computer. Such general-purpose computers or special-purpose computers can include any suitable hardware. For example, as shown in the exemplary hardware 200 of FIG. 2, such hardware can include a hardware processor 202, memory and / or storage 204, an input device controller 206, an input device 208, a display / audio driver 210, a display and audio output circuit 212, a communication interface 214, an antenna 216, and a bus 218.

[0036] Hardware processor 202 can include any suitable hardware processor such as a microprocessor, a microcontroller, a digital signal processor, dedicated logic, and / or any other suitable circuit for controlling the functions of a general-purpose computer or special-purpose computer in some embodiments. In some embodiments, hardware processor 202 can be controlled by a computer program stored in memory and / or storage 204. For example, in some embodiments, the computer program can cause hardware processor 202 to perform the functions described herein.

[0037] Memory and / or storage 204 can be any suitable memory and / or storage for storing programs, data, documents, and / or other appropriate information in some embodiments. For example, memory and / or storage 204 can include random access memory, read-only memory, flash memory, hard disk storage, optical media, and / or any other suitable memory.

[0038] Input device controller 206 can be any suitable circuitry for controlling and receiving input from one or more input devices 208 in some embodiments. For example, input device controller 206 can be circuitry for receiving input from a touch screen, keyboard, mouse, one or more buttons, speech recognition circuitry, microphone, camera, optical sensor, accelerometer, temperature sensor, proximity field sensor, and / or any other type of input device.

[0039] Display / audio driver 210 can be any suitable circuitry for controlling and driving output to one or more display / audio output devices 212 in some embodiments. For example, display / audio driver 210 can be circuitry for driving a touch screen, flat panel display, cathode ray tube display, projector, speaker(s), and / or any other suitable display and / or presentation device.

[0040] Communication interface 214 can be any suitable circuitry for interfacing with one or more communication networks, such as network 106 as shown in FIG. 1, in some embodiments. For example, interface 214 can include a network interface card circuitry, wireless communication circuitry, and / or any other suitable type of communication network circuitry.

[0041] Antenna 216 can be any suitable one or more antennas for wireless communication with a communication network (e.g., communication network 106) in some embodiments. In some embodiments, antenna 216 can be omitted.

[0042] Bus 218 can be any suitable mechanism for communication between two or more components 202, 204, 206, 210, and 214 in some embodiments.

[0043] Any other suitable components can be included in hardware 200 according to some embodiments.

[0044] Referring to FIGS. 3 and 4, examples 300 and 400 of a non-enriched document and an enriched document are shown according to some embodiments, respectively.

[0045] FIG. 3 shows an example of a non-enriched document 300 for a "CAPITAL CALL NOTICE". It should be understood that document 300 can be for any suitable purpose and can have any suitable content in some embodiments. Also shown, document 300 includes a token 302 that identifies secret information that can be used to enrich the document. Document 300 includes only one token, but in some embodiments, any suitable number and any suitable type of tokens can be used. In some embodiments, token 302 can include two pieces of information: (1) an identifier of a record ("93c31348-2535-4b36-927e-25b6ee37ffad"); and (2) an identifier of a field within the record ("account_name"). The identified record and field can be used to place secret information in the non-enriched document. For example, as shown in document 400 of FIG. 4, token 302 has been replaced with secret information ("John J Smith") 402.

[0046] Referring to FIG. 5, an example 500 of a record for storing secret information of an entity (in this case, a person's secret information, although the secret information can be stored for any suitable type of entity in some embodiments), and an anonymized record 502 for linking to such secret information are shown according to some embodiments.

[0047] As shown, record 500 includes fields for an entity identifier ("93c31348-2535-4b36-927e-25b6ee37ffad"), an account name ("John J Smith"), a first name ("John"), a middle name ("J"), a last name ("Smith"), one or more address identifiers ("a4d42459-3646-5c47-a38f-36c7ff4800be"), one or more phone numbers ("212-555-1212;646-555-1212"), one or more account identifiers ("aea9d156-e7fe-4494-a94a-86d8c983c25f"), a tax identification number ("999-99-9999"), and a net worth ("$1,000,000.00"). Record 500 can be stored in a high-trust server 110 in some embodiments.

[0048] Although FIG. 5 shows specific fields for illustration purposes, it should be understood that any suitable number and type of fields can be used in some embodiments.

[0049] The entity identifier ("93c31348-2535-4b36-927e-25b6ee37ffad") can be used to uniquely identify the record for "John J Smith" in a non-enriched document.

[0050] The address identifier ("a4d42459-3646-5c47-a38f-36c7ff4800be") and the account identifier ("aea9d156-e7fe-4494-a94a-86d8c983c25f") can be used to identify the address record and the account record related to "John J Smith".

[0051] Once the record 500 is anonymized, it becomes as shown by the anonymized record 502. In some embodiments, the record 502 can be stored in the low-trust server 104.

[0052] As shown in the figure, the record 502 can replace the account name with "93c31348-2535-4b36-927e-25b6ee37ffad$$account_name", the first name with "93c31348-2535-4b36-927e-25b6ee37ffad$$first_name", the middle name with "93c31348-2535-4b36-927e-25b6ee37ffad$$middle_name", the last name with "93c31348-2535-4b36-927e-25b6ee37ffad$$last_name", the phone number(s) with "93c31348-2535-4b36-927e-25b6ee37ffad$$phone", the tax identification number with "93c31348-2535-4b36-927e-25b6ee37ffad$$tax_id", and the net worth with "93c31348-2535-4b36-927e-25b6ee37ffad$$net_worth".

[0053] Referring to FIG. 6, an example 600 of a record for storing the confidential information of an entity's address and an anonymized record 602 for linking to such confidential information are shown according to some embodiments.

[0054] As shown, record 600 includes fields for an address identifier (“a4d42459-3646-5c47-a38f-36c7ff4800be”), address line 1 (“123 Main Street”), address line 2 (“Apt 1A”), city (“New York”), state (“New York”), postal code (“10001”), and country (“US”). Record 600 can be stored in high-trust server 110 in some embodiments.

[0055] Although specific fields are provided in FIG. 6 for illustrative purposes, it should be understood that any suitable number and type of fields can be used in some embodiments.

[0056] The address identifier ("a4d42459-3646-5c47-a38f-36c7ff4800be") can be used to uniquely identify records for addresses within non-enriched documents.

[0057] Once record 600 is anonymized, the record becomes as shown by anonymized record 602. Record 602 can be stored in low-trust server 104 in some embodiments.

[0058] As shown, record 602 can replace address line 1 with "a4d42459-3646-5c47-a38f-36c7ff4800be$$addr1", address line 2 with "a4d42459-3646-5c47-a38f-36c7ff4800be$$addr2", city with "a4d42459-3646-5c47-a38f-36c7ff4800be$$city", state with "a4d42459-3646-5c47-a38f-36c7ff4800be$$state", postal code with "a4d42459-3646-5c47-a38f-36c7ff4800be$$postal", and country with "a4d42459-3646-5c47-a38f-36c7ff4800be$$country".

[0059] Referring to FIG. 7, according to some embodiments, an example 700 of a record for storing secret information of an entity's account and an anonymized record 702 for linking to such secret information are shown.

[0060] As shown, record 700 includes fields for an account identifier ("aea9d156-e7fe-4494-a94a-86d8c983c25f"), an account name ("John J Smith"), an account number ("123456789"), an entity identifier(s) ("93c31348-2535-4b36-927e-25b6ee37ffad"), an address identifier(s) ("a4d42459-3646-5c47-a38f-36c7ff4800be"), and a balance ("$50,000.00"). Record 700 can be stored in high-trust server 110 in some embodiments.

[0061] Although FIG. 7 provides specific fields for illustrative purposes, it should be understood that any suitable number and type of fields can be used in some embodiments.

[0062] The entity identifier(s) ("93c31348-2535-4b36-927e-25b6ee37ffad") can be used to uniquely identify the entity(ies) for the account in a non-enriched document. The address identifier(s) ("a4d42459-3646-5c47-a38f-36c7ff4800be") can be used to uniquely identify the address(es) for the account in a non-enriched document.

[0063] Once record 700 is anonymized, the record becomes as shown by anonymized record 702. Record 702 can be stored in low-trust server 104 in some embodiments.

[0064] As shown, record 702 can replace the account name with "aea9d156 - e7fe - 4494 - a94a - 86d8c983c25f$$account_name", the account number with "aea9d156 - e7fe - 4494 - a94a - 86d8c983c25f$$acct_no", and the country with "aea9d156 - e7fe - 4494 - a94a - 86d8c983c25f$$balance".

[0065] Referring to FIG. 8, an example 800 of a process for providing an enriched document to a user of a user device according to some embodiments is shown. As illustrated, process 800 can be implemented, in some embodiments, as three sub - processes 802, 804, and 806 that are executed on a low - trust server 104, a high - trust server 110, and a user device 112, respectively.

[0066] Process 800 can be started, in some embodiments, by making a request for a document containing sensitive information at 808. This request can be made, in some embodiments, in any suitable way. For example, in some embodiments, a user of user device 112 can click a link in a web browser to request a document, and the browser can send an appropriate request to low - trust server 104. As another example, in some embodiments, a user of user device 112 can click a menu option within an app, and the app can send an appropriate request to low - trust server 104. The request can then be received at 810.

[0067] Next, at 812, process 800 can generate the requested document using one or more tokens that satisfy any fields in the document containing the secret information. The document can have any suitable content, and any suitable number and type of tokens can be present in the document. As described above, an example of a document with tokens is shown in FIG. 3.

[0068] The generated document can be sent from the low-trust server 104 to the high-trust server 110 at 814. The high-trust server can receive the document at 816.

[0069] At 818, the high-trust server can generate an enriched document by replacing the tokens with the secret information. For example, the high-trust server scans the document to find the tokens, and for each token found, the server searches a database for the secret information corresponding to that token and can replace the token in the document with the secret information.

[0070] Next, at 820, process 800 can store the enriched document on a server. In some embodiments, this server can be the high-trust server or any other suitable server. In some embodiments, this server can be located on the high-trust network 108.

[0071] Thereafter, a uniform resource locator (URL) corresponding to the enriched document can be sent to the low-trust server 104 at 822. The low-trust server can receive the URL at 824.

[0072] And at 826, the low-trust server can send the URL to the user device 112 in response to the request made at 808. The URL can be received by the user device at 828.

[0073] Next, at 830, the user device can request the enriched document from the server where the document was stored at 820 using the URL.

[0074] At 832, the server where the document was stored at 820 can provide the document to the user device. In some embodiments, this server provides the document to the user device only if the user device is on the high-trust network 108. That is, if the user device is outside the high-trust network 108, in some embodiments, this server can skip providing the document to the user device.

[0075] Finally, at 834, the user device can receive the enriched document and present it in any suitable manner (e.g., by displaying it on a screen on the user device, by printing it using a printer coupled to the user device, etc.).

[0076] Referring to FIG. 9, an example 900 of a process for synchronizing secret information and tokens is shown in accordance with some embodiments. As shown, process 900 can be implemented as two sub-processes 902 and 904 that are executed on a high-trust server 110 and a low-trust server 104, respectively, in some embodiments.

[0077] Process 900 can be initiated by receiving secret information 906 at 908. Any suitable secret information can be received, and this secret information can be received from any suitable source in any suitable manner. For example, secret information such as entity information, address information, and account information described in connection with FIGS. 5-7 can be received in some embodiments. As another example, in some embodiments, this secret information can be received as an upload from a comma-separated values (CSV) file, as a Hypertext Transfer Protocol (http) post message, as a webhook, and / or in other suitable manners.

[0078] Next, at 910, process 900 can generate anonymized information. This anonymized information can be generated in any suitable manner. For example, the identifier of a record of secret information can be generated as a hash (e.g., MD5) of a portion of the secret information. As another example, the identifier of a record of secret information can be generated randomly or pseudo-randomly and can be confirmed to not duplicate an already generated identifier. Then, the generated identifier and field names can be used to anonymize the secret information as described above in connection with FIGS. 5-7.

[0079] And at 912, process 900 can send the anonymized information to untrusted server 104. And this anonymized information can be received by the untrusted server at 914.

[0080] Finally, at 916, the untrusted server can store the anonymized information in any suitable manner.

[0081] It should be understood that at least some of the above-described blocks of the processes of FIGS. 8 and 9 can be executed or performed in any order or sequence that is not limited to the order and sequence shown and described in connection with the figures. Also, some of the above-described blocks of the processes of FIGS. 8 and 9 can be executed or performed substantially simultaneously or in parallel, where appropriate, to reduce latency and processing time. Additionally or alternatively, some of the above-described blocks of the processes of FIGS. 8 and 9 can be omitted.

[0082] In some implementations, any suitable computer-readable medium can be used to store instructions for performing the functions and / or processes described herein. For example, in some implementations, the computer-readable medium can be transient or non-transient. For example, non-transient computer-readable media can include magnetic media in non-transitory form (such as hard disks, floppy disks, etc.), optical media in non-transitory form (such as compact disks, digital video disks, Blu-ray disks, etc.), semiconductor media in non-transitory form (such as flash memory, electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc.), any suitable media that is not transient or that leaves no permanent trace during transmission, and / or any suitable tangible media. As another example, transient computer-readable media can include signals on a network, wires, conductors, optical fibers, circuits, any suitable media that is transient and leaves no permanent trace, and / or any suitable intangible media.

[0083] Although the invention has been described and illustrated in the above exemplary embodiments, it is to be understood that the present disclosure has been made by way of example only, and that numerous changes in the details of the implementation of the invention can be made without departing from the spirit and scope of the invention, which is limited only by the claims. The features of the disclosed embodiments can be combined and rearranged in various ways.

Claims

1. a memory; and a first set of at least one hardware processor coupled to the memory and having no access to the secret information, for a system for generating a document having secret information, wherein the first set of at least one hardware processor: receives a request for a first document having the secret information from a user device; generates a second document corresponding to the first document, having at least one token corresponding to the secret information; transmits the second document to a second set of at least one hardware processor within a highly trusted network having access to the secret information; receives a uniform resource locator (URL) corresponding to the first document from the second set of at least one hardware processor within the highly trusted network; is configured to transmit the URL to the user device, a system.

2. The system according to claim 1, wherein the user device is within the highly trusted network.

3. The system according to claim 1, wherein the second set of at least one hardware processor within the highly trusted network is within a server.

4. The system according to claim 3, wherein the first document is stored in the server.

5. The second set of at least one hardware processor: receives the second document from the first set of at least one hardware processor; generates the first document by replacing the at least one token in the second document; stores the first document; is configured to transmit the URL to the first set of at least one hardware processor, the system according to claim 1.

6. The system according to claim 5, wherein the second set of at least one hardware processor is further configured to provide the first document to the user device.

7. The user device: transmits the request for the first document to the first set of at least one hardware processor; receives the URL; requests the first document using the URL; receives the first document; is further configured to present the first document, the system according to claim 1.

8. a memory; Having a first set of at least one hardware processor coupled to the memory, A system for generating a document with secret information, Said first set of at least one hardware processor is: Receiving a first document from a second set of at least one hardware processor not qualified to access the secret information; Generating a second document by replacing at least one token in said first document; Storing said second document; Configured to send a Uniform Resource Locator (URL) corresponding to said second document to said second set of at least one hardware processor, System.

9. The system according to claim 8, wherein said first set of at least one hardware processor is further configured to provide said first document to a user device.

10. Said user device is: Sending a request for said first document to said first set of at least one hardware processor; Receiving said URL; Requesting said first document using said URL; Receiving said first document; Configured to present said first document, The system according to claim 9.

11. Said second set of at least one hardware processor is: Generating said first document corresponding to said second document having at least one token corresponding to said secret information; Sending said first document to said first set of at least one hardware processor within a highly trusted network qualified to access said secret information; Receiving a Uniform Resource Locator (URL) corresponding to said second document from said first set of at least one hardware processor within said highly trusted network; Configured to send said URL to a user device, The system according to claim 8.

12. The system according to claim 11, wherein said user device is within a highly trusted network.

13. The system according to claim 8, wherein said first set of at least one hardware processor is within a server.

14. The system according to claim 13, wherein said second document is stored in said server.

15. A system for generating a document containing secret information, including a user device, wherein said user device is: Send a request for a first document having secret information to a first set of at least one hardware processor within a low-trust network that does not have access to the secret information; Receive a Uniform Resource Locator (URL) corresponding to the first document from the first set of at least one hardware processor; Use the URL to request the first document from a second set of at least one hardware processor within a high-trust network that has access to the secret information; Receive the first document; A system configured to present the first document. System.

16. The system according to claim 15, wherein the user device is within the high-trust network.

17. The system according to claim 15, wherein the second set of at least one hardware processor within the high-trust network is within a server.

18. The system according to claim 17, wherein the first document is stored in the server.

19. The first set of at least one hardware processor: Receives a request for the first document from the user device; Generates a second document corresponding to the first document with at least one token corresponding to the secret information; Sends the second document to the second set of at least one hardware processor; Receives a Uniform Resource Locator (URL) corresponding to the first document from the second set of at least one hardware processor: Configured to send the URL to the user device. The system according to claim 18.

20. The second set of at least one hardware processor: Receives the second document from the first set of at least one hardware processor; Generates the first document by replacing the at least one token in the second document; Stores the first document; Configured to send the URL to the first set of at least one hardware processor. The system according to claim 19.

21. The system according to claim 20, wherein the second set of at least one hardware processor is further configured to provide the first document to the user device.

Citation Information

Patent Citations

  • Information presentation system and device

    JP2002041347A

  • Data encoder, data encoding method, and program

    JP2016133729A

  • Automatic operation detection on protected field with support for federated search

    JP2021064388A