Distributed Tokenization System for Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online transaction systems are vulnerable to disruptions when global communications networks fail, as they rely on centralized databases for sensitive information processing, leading to potential exposure and inefficiencies in data management.

Innovation Solution

Implementing a distributed tokenization system with geographically diverse, redundant hardware platforms and fractional token tables, where each platform generates and stores partial tokens, allowing for the creation and recovery of full tokens using a Feistel network, thereby reducing reliance on centralized systems and enhancing data security and availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized database is used to store sensitive information and tokens, then data access and management are simplified, but the system becomes vulnerable to disruptions when global communications networks fail and creates a single point of failure

Engineering Contradiction:
Improvedata access and managementVSAvoidsystem availability during network failures
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The centralized database is segmented into multiple distributed regional databases, each storing a portion of the tokenization data. This allows the system to maintain data access capabilities locally even when global network communications fail, eliminating the single point of failure while preserving data management functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each regional database is configured with specific tokenization data appropriate for its geographical region, allowing local token generation and recovery operations to proceed independently without requiring constant communication with a central authority, thus improving reliability during network disruptions.

Inventive Principle:
Principle #3Local quality

2Productivity

If sensitive information is stored in a centralized location for easy retrieval, then data access is efficient, but the risk of exposure and security breaches increases

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoidsecurity risk and exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Sensitive information is segmented and distributed across multiple regional databases rather than stored in a single centralized location. This distribution reduces the security risk associated with any single point of failure or breach, while maintaining efficient local access to the data through the distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokenization as an intermediary mechanism between the sensitive data and the databases. Tokens are stored in the distributed databases instead of the actual sensitive information, providing an additional layer of security that reduces exposure risk while allowing efficient data retrieval through token-based access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If regional tokenization servers operate independently without constant connection to a central database, then system reliability improves during network failures, but the complexity of maintaining consistent tokenization across regions increases

Engineering Contradiction:
Improveoperational independence during network failuresVSAvoiddistributed system coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Regional databases are pre-configured with the necessary tokenization data and capabilities before network failures occur. This preliminary setup allows them to operate independently during disruptions without requiring complex real-time coordination, reducing the operational complexity while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11423504B2System for protecting sensitive data with distributed tokenization
Publication Date: 2022.08.23 MICRO FOCUS LLC
  • US11423504B2 patent drawing
  • US11423504B2 patent drawing
  • US11423504B2 patent drawing

AI summary

A token generating organization may include distributed tokenization systems for generating tokens corresponding to sensitive information. Sensitive information may include sensitive numbers such as social security numbers, credit card numbers or other private numbers. A tokenization system may include multiple physically distinct hardware platforms each having a tokenization server and a database. A tokenization server may run portions of a sensitive number through a predetermined number of rounds of a Feistel network. Each round of the Feistel network may include tokenizing portions of the sensitive number using a fractional token table stored an associated database and modifying the tokenized portions by reversibly adding portions of the sensitive number to the tokenized portions. The fractional token table may include partial sensitive numbers and corresponding partial tokens. A sensitive-information-recovery request including the token may be directed to the token generating organization from the token requestor to recover sensitive information.