Unbreakable security: safeguarding customer sensitive data without storing

A system generates encrypted data on demand, ensuring sensitive data is never stored in clear form, addressing vulnerabilities and costs, while maintaining secure and compliant data usage.

WO2026123043A2PCT designated stage Publication Date: 2026-06-18KATTELA ANITHA

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
KATTELA ANITHA
Filing Date
2025-01-19
Publication Date
2026-06-18

AI Technical Summary

Technical Problem

Existing encryption technologies fail to ensure that sensitive customer data is never stored in clear form, are vulnerable to hacking, and incur high costs for security measures, while compliance and data usage for analytics are cumbersome.

Method used

Implement a system where sensitive data is never stored in clear form, using complex encryption processes to generate encrypted data on demand, ensuring it remains uncrackable, and maintaining unique client-specific keys to prevent data access and reduce security costs.

Benefits of technology

Ensures secure and cost-effective protection of sensitive data, preventing unauthorized access and simplifying compliance, while enabling secure day-to-day operations and data usage for analytics without storing the original data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGF000004_0001
    Figure IMGF000004_0001
  • Figure IMGF000010_0001
    Figure IMGF000010_0001
  • Figure IMGF000011_0001
    Figure IMGF000011_0001
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] TITLE OF INVENTION

[0003] Unbreakable Security: Safeguarding Customer Sensitive Data without Storing

[0004] Protect sensitive customer data and privacy with a revolutionary approach-ensuring it is never stored in clear form within applications, databases, or devices. Only encrypted, uncrackable data resides on the client side, enabling secure day-to-day operations while keeping hackers at bay. Sensitive data can be recovered on demand using encrypted data. Also, de-risk the organizations from hacking as they must breach 2 organizations (client and ours) to make any meaning out of the encrypted data.

[0005] TECHNICAL FIELD

[0006] Information Technology related innovation. Industry agnostic with broad application and can be used by anyone that is storing Customer's sensitive and private data to provide goods or services to Customers. This innovation can lead to a huge eco system of applications built using this novel concept. Every IT system known to humans can be modified using our technology to enhance security.

[0007] BACKGROUND OF THE INVENTION

[0008] Our phone numbers and email addresses have been leaked by an unknown organization for which we may be the customers. Now, every day brings a flood of anonymous calls from around the world, relentless scam calls, threatening calls, fraudulent emails, turning life into a constant nightmare. This relentless invasion of privacy extends to many of my friends and family members as well, leaving all of them overwhelmed and frustrated by this unknown data breach. We are forced to block all anonymous calls and allow only phone numbers defined in our phone book (whitelisting). For Emails we must stop using them as we still receive emails from all over the world unrelated to us and mostly marketing oriented or spam or Phishing. At least we have minimum knowledge on how to protect ourselves from scam calls but there are numerous vulnerable people who lost their life savings to the scammers / fraudsters, and it is common day to day news in media.

[0009] The above reason made us think of a unique way to make companies not store our personal data but still they are available on demand if required for compliance and verification purposes only.

[0010] Our solution does not aim to address gaps in existing encryption algorithms or technologies. Instead, it has been developed from the ground up, backed by years of research, and represents a completely new ideology and approach— redefining how we operate in today's digital landscape.

[0011] Some of the unique questions we asked ourselves before developing this solution are:

[0012] 1) Do we really need to store sensitive information related to customers?

[0013] 2) Can the underlying sensitive information be produced on demand without storing?

[0014] 3) How to make hacking worthless?

[0015] 4) How to de-risk the organizations i.e. Hacking one organization is not enough to extract any valuable data

[0016] 5) Encrypted information is short enough for practical use in organization day-to-day operations and still uncrackable with current technologies

[0017] 6) Stop abuse of our application in both forward direction (Encrypting) or backward direction / reverse engineering (Decrypting)

[0018] 7) No Encryption keys exchange with clients

[0019] 8) Reduce the cost of security as organizations spend massive amounts of money to safeguard their data

[0020] 9) How to make compliance process easy for the organizations 10) Facilitate research organizations to utilize data safely for analytics / Machine Learning without worrying about compromise (only if the organization has obtained consent from the customers)

[0021] 11)One Client cannot use another client Data or data demarcation

[0022] We are here to solve the above challenges-not just to answer questions, but to deliver solutions that matter. Each problem represents an opportunity to make an impact, to innovate, and to excel. Together, we are turning these objectives into realities and achieving meaningful results.

[0023] Even though it is not our motive or intension to compare existing technologies with deficiencies, we made reasonable comparison on how we fare with the most powerful symmetric encryption algorithms like AES 256, which is literally uncrackable SUMMARY OF THE INVENTION

[0024] Our Innovation main concept is do not store Customer Sensitive data in clear form at all.

[0025] Encryption and Decryption Process:

[0026] The detailed solution steps that can be used for simulating both the encryption and decryption process with our methodology are outlined in the DETAILED DESCRIPTION OF EMBODIMENTS section of the document covering various data aspects under the below headings.

[0027] • Item 1 - Number Encryption

[0028] • Item 2 - Number Decryption

[0029] • Item 3 - Alpha Numeric Encryption

[0030] • Item 4 - Alpha Numeric Decryption

[0031] First, we try to answer the questions outlined by us in the Background section and how our solution solves them. Also provide reference to encryption and Decryption process if applicable.

[0032] 1) Do we really need to store sensitive information related to customers?

[0033] As per our solution, no need to store Customer sensitive data in clear form. Send clear information to our application and obtain encrypted data and store only encrypted data and use it for majority of the operations. Organizations reduce Sensitive data footprint drastically or eliminate if possible

[0034] Reference: As per the full process outlined in the DETAILED DESCRIPTION OF EMBODIMENTS for both Encryption and Decryption there is no step that require actual storage of Sensitive Data

[0035] 2) Can the underlying sensitive information be produced on demand without storing?

[0036] Yes, Send the encrypted data to our application, we will return you the clear data behind it. Our application neither stores Sensitive Data nor the Encrypted Data. All are created on the fly without storage.

[0037] Reference: As per the full process outlined in DETAILED DESCRIPTION OF EMBODIMENTS the original data is recovered using only Encrypted data ) How to make hacking worthless?

[0038] Our application Encrypted Data is created using a complex unique multi step process and we believe it is impossible to crack current or future technologies. The Encrypted data obtained by hackers is useless and they can never recover or know the actual data behind it

[0039] Reference: Out of the various steps outlined in the DETAILED DESCRIPTION OF EMBODIMENTS section there are numerous complex security steps that it is almost impossible to crack without our application and corresponding client security keys Some of the complex operations are

[0040] • Double XOR operations

[0041] • Unique double sorting operation using a super large matrix and reduce to the size of the data

[0042] • FF3 algorithm using a large 256 bit key and 8-digit cipher and radix

[0043] • Perform Custom Base64 encoding

[0044] • Apply HMAC SHA256 algorithm using a large 256 bit key and calculate Sum of the HMAC SHA256 hex

[0045] Some of the above individual operations alone are not breakable with current technology, but with various combined complex algorithms it is impossible to know the sensitive data behind the encrypted data

[0046] ) How to de-risk the organizations i.e. Hacking one organization is not enough to extract any valuable data

[0047] Once the hackers enter the organization network with appropriate credentials, there is no stopping, and they can catch hold of the entire data and cause agony to both the innocent organization and customers with detrimental effects.

[0048] With our solution Organization has only encrypted data, unless they hack us and put all the encrypted data through our application the sensitive information for them is worthless.

[0049] Reference:

[0050] Same as question 3 ) Encrypted information is short enough for practical use in organization day-to-day operations and still uncrackable with current technologies

[0051] Our Encrypted information is of reasonable length and can be used by Organizations in day-to-day operations without worrying about compromise.

[0052] Reference:

[0053] 16-digit BSB / Account number 0123451234567890 encrypted output is k2BH-ilaznccn- PL, which is of length 14, which is less than input length and is practical to use in day-to- day operations. ) Stop abuse of our application in both forward direction (Encrypting) or backward direction / reverse engineering (Decrypting) Encryption Abuse: Even though we expect and force our clients to do the right things, in addition we are also monitoring their usage patterns, data (part hash non-reversible) to see if they are using same data again and again for malicious reasons (mostly done by hackers rather than clients). The tracking data has no relevance to original data, even our application does not know what the underlying sensitive data was involved in client operation.

[0054] Reference:

[0055] For both Encryption and Decryption process we are capturing only the first 12 chars of HMAC SHA 256 Hash data of client provided Input Data. This will help to identify if the same data is sent again and again to reveal all combinations of the encrypted outputs. Also, this can be used for rate limiting, throttling etc.

[0056] Decryption Abuse: We are employing a different methodology to stop reverse engineering completely. Any variations or manipulation made to our encrypted data we detect and respond with security violation Reference:

[0057] In DETAILED DESCRIPTION OF EMBODIMENTS section, there is matching steps for decryption process, which will stop from reverse engineering of our outputs ) No Encryption keys exchange with clients

[0058] As part of Client setup, we create all Keys relevant to the client and it is not revealed to outside world including clients. Clients do not need to know what keys are used, how they are is used and no key exchange required with them.

[0059] Reference:

[0060] All keys involved in the Encryption / Decryption are maintained by our application only. ) Reduce the cost of security as organizations spend massive amounts of money to safeguard their data

[0061] As per Gartner, the average spend by companies on data security and privacy is around $215 billion dollars.

[0062] Optimal use of our solution can reduce substantial data security costs

[0063] Reference:

[0064] Not applicable ) How to make compliance process easy for the organizations

[0065] Now a days organizations are governed by multiple local regulations from their respective countries. By using our solution obtaining compliance from various organizations will ease as no sensitive data storage is required

[0066] Reference:

[0067] Not applicable 0) Facilitate research organizations to utilize data safely for analytics / Machine Learning without worrying about compromise (only if the organization has obtained consent from the customers)

[0068] Even after consent from Customers, organizations face challenges for using their data for research purposes as they have either Mask or omit sensitive data. With our solution the encrypted data can be used, and no one can understand the underlying data behind it.

[0069] Reference: Not applicable ll)One Client cannot use another client Data or data demarcation

[0070] Each Client Keys are different so any client can encrypt their own data, but they can only decrypt their own encrypted data only. Any attempts to decrypt other client's data will cause Security violation and application does not allow that.

[0071] Reference:

[0072] As part of client setup, we create the following keys

[0073] • FF3 Key (256 bit key)

[0074] • FF3 Cipher (8-digit number)

[0075] • HMAC Key (256 bit key)

[0076] Every client will have their own set of keys that prevents them from using usage

[0077] For completeness, the drawbacks of the best encryption algorithms outlined earlier are addressed by our application in the below fashion

[0078] BRIEF DESCRIPTION OF THE DRAWINGS

[0079] Below are the brief descriptions of each drawing outlined in the ePCT-ln no-Patent Drawings

[0080] V1.0 document

[0081] Figure 1 / 7:

[0082] The diagram shows on how one Sensitive data Input leads to multiple Encrypted Outputs, which makes it hard to do one to one mapping

[0083] Figure 2 / 7:

[0084] The diagram shows that multiple Encrypted Outputs leads to original Sensitive data element.

[0085] Figure 3 / 7:

[0086] The diagram shows that any attempts to reverse engineer the encrypted outputs results in

[0087] Security violation

[0088] Figure 4 / 7:

[0089] The diagram shows that every client data is unique and usable by them only. Any attempts to decrypt the output produced by another client will result in Security violation error

[0090] Figure 4 / 7:

[0091] The diagram shows that every client data is unique and usable by them only. Any attempts to decrypt the output produced by another client will result in Security violation error

[0092] Figure 5 / 7:

[0093] The diagram shows how the sensitive data is stored in applications without storing the underlying clear data

[0094] Figure 6 / 7:

[0095] The diagram shows how client can retrieve and validate the sensitive data again without storing the sensitive data in clear

[0096] Figure 7 / 7:

[0097] The diagram shows how client can retrieve sensitive information on demand to comply with government regulations or compliance etc REAL WORLD APPLICATION OF OUR SOLUTION

[0098] The area of real-world usage is too broad to cover in this document as every known IT application or Domain can utilize our solution to safeguard their sensitive data.

[0099] Below examples in the table cover a wide variety of industries from Insurance, Health,

[0100] Banking, government organizations, Telecommunications, Networking, Retail Industries, ECommerce Industry, Research and all other Industries who store or transmit sensitive data in their day-to-day activities

[0101] DETAILED DESCRIPTION OF EMBODIMENTS

[0102] The detailed steps on how our application encrypts data in real time and decrypt data in real time are outlined in the below sections

[0103] There are 4 sections

[0104] • Nu meric Encryption Pages 14 to 20

[0105] • Nu meric Decryption Pages 21 to 26

[0106] • Alpha Numeric Encryption Pages 27 to 33

[0107] • Alpha Numeric Decryption Pages 34 to 40

[0108]

[0109]

[0110]

Claims

CLAIMSAll Patent legal claims are all based on details outlined in ePCT-Inno-Description and Abstract Vl.O.pdf document under the section DETAILED DESCRIPTION OF EMBODIMENTS from pages 14 to 40Claim 1:A method for encrypting and securing sensitive numerical data using a custom encryption process, the method comprising 30 detailed steps as outlined in in "ePCT-Inno-Description and Abstract Vl.O.pdf" document under the section DETAILED DESCRIPTION OF EMBODIMENTS under subheading "Item 1 - Number Encryption" outlined in pages 14 to 20Claim 2:A method for decrypting encrypted numerical data using a custom decryption process, the method comprising 27 detailed steps outlined in in "ePCT-Inno-Description and Abstract Vl.O.pdf" document under the section DETAILED DESCRIPTION OF EMBODIMENTS under subheading "Item 2 - Number Decryption" outlined in pages 21 to 26Claim 3:A method for encrypting and securing sensitive Alphanumeric data using a custom encryption process, the method comprising 30 detailed steps outlined in in "ePCT-Inno- Description and Abstract Vl.O.pdf" document under the section DETAILED DESCRIPTION OF EMBODIMENTS under subheading "Item 3 - Alpha Numeric Encryption" outlined in pages 1 to 33Claim 4:A method for decrypting encrypted Alphanumeric data using a custom decryption process, the method comprising 29 detailed steps as outlined in in "ePCT-Inno-Description and Abstract Vl.O.pdf" document under the section DETAILED DESCRIPTION OF EMBODIMENTS under subheading "Item 4 - Alpha Numeric Decryption" outlined in pages 34 to 40Claim 5The method of Claim 1, wherein, in Step 3, each client is assigned separate and unique keys, with distinct types of keys, such that the specified key type combinations are proprietary and cannot be replicated, reused, or copied by others.Claim 6:The method of Claim 1, wherein, in Step 5, the number of random combinations of outputs is determined, with the flexibility to vary the combinations as needed.Claim 7:The method of Claim 1, wherein, in Step 9, the extraction process involving XOR part 1 is implemented in a unique and proprietary manner, such that it cannot be replicated, reused, or copied by othersClaim 8:The method of Claim 1, wherein, in Step 10, the extraction process involving XOR parts 2 is implemented in a unique and proprietary manner, such that it cannot be replicated, reused, or copied by othersClaim 9:The method of Claim 1, wherein, in Step 11, the extraction process involving sorting character is implemented in a unique and proprietary manner, such that it cannot be replicated, reused, or copied by othersClaim 10:The method of Claim 1, wherein, in Step 12, the process of condensing a large sort matrix into a smaller matrix, tailored to the length of the data to be sorted, is implemented in a unique and proprietary manner, preventing replication, reuse, or copying by othersClaim 11:The method of Claim 1, wherein, in Step 20, a custom Base64 process is executed in a distinctive and unique manner.Claim 12:The method of Claim 1, wherein, in Step 23, a custom HMAC SHA 256 is employed to sum the decimal values of HMAC SHA 256 hexadecimal characters, thereby shortening the output while utilizing the entire hexadecimal data in a distinctive and unique manner.Claim 13:The method of Claim 1, wherein, in Step 29, a HMAC SHA 256 character generated by hashing the input is inserted in a unique manner to prevent reverse engineeringClaim 14:The method of Claim 3, wherein, in Step 5, an input text shortening technique is applied in a unique manner to reduce the size of the textClaim 15:The method of Claim 3, wherein, in Step 6, a special positional numerical encoding technique is applied to convert text into big integer data in a unique and proprietary manner, preventing replication, reuse, copying, or any variations or adaptations of this technique by othersClaim 16:The method of Claim 3, wherein, in Step 17, a custom FF3 algorithm is used to split longer data into parts, perform calculations independently on each part, and combine the results, all in a unique and proprietary manner that prevents replication, reuse, copying, or any variations or adaptations of this technique by others.