Token Vault Proxy for Secure Network Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network systems face security risks and quality of service issues due to the exposure of sensitive data during storage, processing, and communication, particularly in complex systems with multiple access points, leading to increased vulnerabilities.

Innovation Solution

A system and method that uses an encrypted identifier in place of sensitive data, integrated as a proxy, resolver, and authenticator within network systems to minimize data exposure and access, thereby reducing security threats and improving data integrity and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sensitive data is stored and communicated during network service operations, then service functionality is enabled, but security vulnerabilities increase due to data exposure

Engineering Contradiction:
Improveservice functionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive data element from the communication process by replacing it with a non-sensitive identifier. The actual sensitive data (e.g., payment card information) is removed from circulation and stored only in encrypted form in a token vault, while a placeholder identifier is used in all network communications and processing operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a tokenization intermediary layer that sits between the sensitive data storage and the network processing systems. This token vault acts as a mediator that receives sensitive data, converts it to tokens, and manages the mapping between tokens and actual data, thereby isolating the sensitive data from potential security threats in the network environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If sensitive data is accessed by multiple entities for service delivery, then service quality improves, but data integrity risks increase

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The patent removes sensitive data from the service delivery chain by replacing it with identifiers. Multiple entities can access and process these identifiers without risking the integrity of the actual sensitive data, since the identifiers are non-sensitive and cannot be compromised to reveal the underlying information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the data handling process into two distinct parts: sensitive data storage (encrypted in token vault) and service processing (using identifiers). This segmentation allows service entities to operate on identifiers while the sensitive data remains isolated and protected, maintaining both service efficiency and data integrity.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If encrypted identifiers are used instead of sensitive data, then security threats are reduced, but system complexity increases

Engineering Contradiction:
Improvesecurity threatsVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a token vault as an intermediary component that manages the complexity of encryption and token mapping. While this adds a system component, it centralizes the cryptographic operations and token management in a single secure location, allowing the rest of the system to work with simple identifiers rather than complex encrypted data structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates simplified copies (tokens/identifiers) of the sensitive data that can be used throughout the system without the security risks of the original data. These token copies are structurally simple and can be processed by existing systems with minimal modification, reducing the overall complexity burden.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12052269B2Secure network communications apparatus for communicating sensitive data
Publication Date: 2024.07.30 BANK OF AMERICA CORP
  • US12052269B2 patent drawing
  • US12052269B2 patent drawing
  • US12052269B2 patent drawing

AI summary

A system for performing a network service between a user device, an entity server, and a designated server that uses user sensitive data in the performance of a service subscribed to by the user and offered by the first entity server. The user sensitive data is provided to the designated server. The designated server generates a subscription identifier by encrypting the sensitive data using a public key of a public and private key pair, generated using a public key infrastructure, and issues the encrypted subscription identifier to the user device and the entity server for use in place of the sensitive data. The user device and the entity server use the designated entity server as a proxy for operations that rely upon the actual sensitive data. In these operations, the designated entity server resolves the subscription identifier by decrypting the subscription identifier using a private key of the key pair.