Cloud Token Prefetching for Secure PCI Data Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributing sensitive data on public clouds increases the risk of inappropriate access and theft due to potential vulnerabilities.
Innovation Solution
Implementing a tokenization service in the cloud environment to generate and store tokens and co-relation indicators, allowing secure data protection by using tokens as surrogates for sensitive data, and enabling efficient prefetching and mapping of tokens to source values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive data is distributed on public cloud, then data accessibility and service delivery are improved, but security risk and vulnerability to theft increase
Solution Approach 1:
The patent introduces tokens as intermediary objects that replace sensitive data in cloud environments. Tokens serve as mediators between the need for data accessibility and security requirements, allowing systems to reference and process data without exposing actual sensitive information. The tokenization service acts as a mediator that manages the mapping between tokens and source data, enabling secure cloud operations.
Solution Approach 2:
The patent creates token copies that represent sensitive data without containing the actual sensitive information. These token copies can be freely distributed and accessed in cloud environments, while the original sensitive data remains protected. The copying principle is applied through generating tokens that replicate the functional needs of sensitive data while eliminating security risks.
2Reliability
If tokens are generated and mapped in real-time, then data security is maintained, but processing latency increases
Solution Approach 1:
The patent implements preliminary action by prefetching tokens before they are actually needed for data processing. The system anticipates future token requirements and retrieves tokens in advance, storing them in a token vault. This eliminates the need for real-time token generation and mapping operations, significantly reducing processing latency while maintaining security through pre-established token mappings.
Solution Approach 2:
The patent merges the token generation, storage, and mapping functions into a unified tokenization service infrastructure. By combining these operations and pre-establishing token mappings in a centralized token vault, the system eliminates sequential processing delays and enables faster token retrieval without compromising security controls.
3Productivity
If token prefetching is implemented, then service level agreement compliance is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal tokenization service that handles multiple functions: token generation, token storage, token mapping, and token prefetching. This multi-functional service can be reused across different applications and data types, standardizing security operations and actually reducing overall system complexity despite adding prefetching capabilities. The service level agreement compliance is achieved through this universal interface that abstracts away the complexity of individual operations.
Data Source
AI summary
Systems and methods for prefetching Payment Card Industry (PCI) data. A method may include a tokenization service in a cloud environment: (1) receiving a request to prefetch a plurality of tokens from a client application; (2) generating the plurality of tokens and a co-relation indicator for each of the plurality of tokens; (3) storing the plurality of tokens and the co-relation indicators in a token vault in the cloud environment; (4) returning the plurality of tokens and the co-relation indicators to the client electronic device; (5) receiving a mapping request comprising a source value and the co-relation indicator for one of the plurality of tokens; (6) identifying the token of the plurality of tokens associated with the co-relation indicator; (7) mapping the token to the source value; and (8) returning a message indicating successful mapping to the client application.


