Patent Issued for System for improving data security when storing data (USPTO 11321489): The Prudential Insurance Company of America - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
May 24, 2022 Newswires
Share
Share
Post
Email

Patent Issued for System for improving data security when storing data (USPTO 11321489): The Prudential Insurance Company of America

Insurance Daily News

2022 MAY 24 (NewsRx) -- By a News Reporter-Staff News Editor at Insurance Daily News -- A patent by the inventors Apsingekar, Venkatesh Sarvottamrao (San Jose, CA, US), Lavine, James Francis (Corte Madera, CA, US), Motadoo, Sahil Vinod (Sunnyvale, CA, US), Schille, Christopher John (San Jose, CA, US), filed on March 3, 2020, was published online on May 3, 2022, according to news reporting originating from Alexandria, Virginia, by NewsRx correspondents.

Patent number 11321489 is assigned to The Prudential Insurance Company of America (Newark, New Jersey, United States).

The following quote was obtained by the news editors from the background information supplied by the inventors: “Users provide their information (e.g., name, address, telephone number, email address, social security number, etc.) in a variety of contexts (e.g., mortgage applications, credit card applications, financial account applications, air travel ticket orders, medical office visits, etc.). If this information were exposed to or taken by a malicious user, then the malicious user would be able to use this information to impersonate the users to conduct undesired or unwanted transactions.”

In addition to the background information obtained for this patent, NewsRx journalists also obtained the inventors’ summary information for this patent: “Users provide information (e.g., name, address, telephone number, email address, social security number, etc.) in a variety of contexts (e.g., mortgage applications, credit card applications, financial account applications, air travel ticket orders, medical office visits, etc.). If this information were exposed to or taken by a malicious user, then the malicious user would be able to use this information to impersonate the users to conduct undesired or unwanted transactions.

“In conventional systems, the users have very little control over this information. The users provide their information to a provider to gain access to goods or services from the provider. The provider maintains the information (e.g., on a server). If that server were to be breached by a malicious user, the information would be exposed to the malicious user. Additionally, some providers even sell the information to other providers, often unbeknownst to the users. This sale and movement of the information further exposes the information to malicious users and lessens the control that the users have over such information.

“This disclosure contemplates an unconventional system for securing information (e.g., a user’s personally identifiable information (PII)). Generally, the system allows the user to store his PII on a personal device, such as a smartphone. When a third party wants to access the user’s PII (e.g., to update the PII or to retrieve the PII), a notification will be presented to the user on the personal device seeking consent to the access. The notification may inform the user as to what information is being requested and which entity is requesting the access. The requested access will be denied unless the user consents to the access. In this manner, the user is given control over the dissemination of his PII. Additionally, the system alters or adjusts the PII that is stored in third-party servers so that even if these servers are breached, the user’s actual PII is not exposed.

“According to an embodiment, a system includes a device of a user and a token handler separate from the device. The device receives personally identifiable information the user and encrypts the personally identifiable information to produce first encrypted personally identifiable information. The token handler receives the first encrypted personally identifiable information from the device of the user, decrypts the first encrypted personally identifiable information to produce the personally identifiable information, generates a token representing the personally identifiable information, and receives the token indicating a request for the personally identifiable information. The device receives consent from the user to provide the personally identifiable information in response to the request for the personally identifiable information, in response to receiving the consent from the user, encrypts the personally identifiable information to produce second encrypted personally identifiable information, and communicates the second encrypted personally identifiable information to the token handler.

“When PII is to be stored or updated, the system first seeks consent from the user for the PII store or update. If the user grants consent, then the system stores the PII in the user’s personal device or updates the PII stored in the user’s personal device. The system then generates a token representing the PII. The token can be presented at a later time to redeem or access the PII, subject to the user’s consent. Even if the token were taken by a malicious user, it would not be possible for the malicious user to determine the user’s actual PII from the token. In this manner, the security of the PII is improved over conventional systems.”

The claims supplied by the inventors are:

“1. A system for securing personally identifiable information, the system comprising: a token handler configured to: receive, from a data originator, a request to store a user’s personally identifiable information, the request to store comprising the user’s personally identifiable information encrypted using a public encryption key of the token handler; and insert into a first queue the request to store; and a device of the user separate from the token handler, the device configured to: establish a connection with the token handler, the token handler further configured to update a status of the request to store in a second queue in response to determining that the device has established the connection; in response to the updated status of the request to store in the second queue and after establishing the connection, present a notification message to the user seeking consent to store the user’s personally identifiable information; in response to receiving the consent from the user: encrypt, using a salted passphrase of the user, the user’s personally identifiable information encrypted using the public encryption key of the token handler to produce the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase; and store the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase in a local repository; the token handler is further configured to: in response to determining that the device has stored the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase, generate a token representing the personally identifiable information; and further update the status of the request to store in the second queue.

“2. The system of claim 1, wherein the data originator is configured to: in response to the further updated status of the request to store in the second queue, retrieve, from the token handler, the token; and store the token in a database.

“3. The system of claim 1, wherein: the device of the user is further configured to generate the salted passphrase by: receiving a passphrase from the user; and hashing the passphrase with a phone number and an email address of the user to produce the salted passphrase; and the token handler is further configured to generate the public encryption key for the token handler using a public encryption key for the device.

“4. The system of claim 1, wherein the token handler is further configured to, in response to receiving the request to store, wait for the device to establish the connection with the token handler.

“5. The system of claim 1, wherein the token handler is further configured to: encrypt a portion of the user’s personally identifiable information using a public encryption key of the data originator and the public encryption key of the token handler; and store, in a cloud, the portion of the personally identifiable information encrypted using the public encryption key of the data originator and the public encryption key of the token handler.

“6. The system of claim 5, wherein the device is further configured to store, in a local repository, the portion of the personally identifiable information encrypted using the public encryption key of the data originator and the public encryption key of the token handler.

“7. The system of claim 1, wherein the device is further configured to: in response to the further updated status of the request to store in the second queue, retrieve, from the token handler, the token; and store the token in a local repository.

“8. The system of claim 1, wherein the device is further configured to push the local repository to a cloud after storing the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase in the local repository.

“9. The system of claim 1, wherein the data originator is configured to initiate redemption of the user’s personally identifiable information by presenting the token to the token handler.

“10. The system of claim 1, wherein the token handler is further configured to: adjust the user’s personally identifiable information to produce anonymized data; and generate an identifier for a ledger storing the anonymized data.

“11. A method for securing personally identifiable information, the method comprising: receiving, by a token handler, from a data originator, a request to store a user’s personally identifiable information, the request to store comprising the user’s personally identifiable information encrypted using a public encryption key of the token handler; inserting, by the token handler, into a first queue the request to store; establishing, by a device separate from the token handler, a connection with the token handler, the token handler further configured to update a status of the request to store in a second queue in response to determining that the device has established the connection; in response to the updated status of the request to store in the second queue and after establishing the connection, presenting, by the device, a notification message to the user seeking consent to store the user’s personally identifiable information; in response to receiving the consent from the user: encrypting, by the device, using a salted passphrase of the user, the user’s personally identifiable information encrypted using the public encryption key of the token handler to produce the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase; and storing, by the device, the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase in a local repository; in response to determining that the device has stored the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase, generating, by the token handler, a token representing the personally identifiable information; and further updating, by the token handler, the status of the request to store in the second queue.

“12. The method of claim 11, further comprising: in response to the further updated status of the request to store in the second queue, retrieving, by the data originator, from the token handler, the token; and storing, by the data originator, the token in a database.

“13. The method of claim 11, further comprising: generating, by the device of the user, the salted passphrase by: receiving a passphrase from the user; and hashing the passphrase with a phone number and an email address of the user to produce the salted passphrase; and generating, by the token handler, the public encryption key for the token handler using a public encryption key for the device.

“14. The method of claim 11, further comprising waiting, by the token handler, in response to receiving the request to store, for the device to establish the connection with the token handler.

“15. The method of claim 11, further comprising: encrypting, by the token handler, a portion of the user’s personally identifiable information using a public encryption key of the data originator and the public encryption key of the token handler; and storing, by the token handler, in a cloud, the portion of the personally identifiable information encrypted using the public encryption key of the data originator and the public encryption key of the token handler.

“16. The method of claim 15, further comprising storing, by the device, in a local repository, the portion of the personally identifiable information encrypted using the public encryption key of the data originator and the public encryption key of the token handler.

“17. The method of claim 11, further comprising: in response to the further updated status of the request to store in the second queue, retrieving, by the device, from the token handler, the token; and storing, by the device, the token in a local repository.

“18. The method of claim 11, further comprising pushing, by the device, the local repository to a cloud after storing the user’s personally identifiable information encrypted using the public encryption key of the token handler and the salted passphrase in the local repository.

“19. The method of claim 11, further comprising initiating, by the data originator, redemption of the user’s personally identifiable information by presenting the token to the token handler.

“20. The method of claim 11, further comprising: adjusting, by the token handler, the user’s personally identifiable information to produce anonymized data; and generating, by the token handler, an identifier for a ledger storing the anonymized data.”

URL and more information on this patent, see: Apsingekar, Venkatesh Sarvottamrao. System for improving data security when storing data. U.S. Patent Number 11321489, filed March 3, 2020, and published online on May 3, 2022. Patent URL: http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PALL&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.htm&r=1&f=G&l=50&s1=11321489.PN.&OS=PN/11321489RS=PN/11321489

(Our reports deliver fact-based news of research and discoveries from around the world.)

Older

“Methods of Pre-Generating Insurance Claims” in Patent Application Approval Process (USPTO 20220138861): State Farm Mutual Automobile Insurance Company

Newer

Studies from Union University in the Area of COVID-19 Described (The Impact of Covid-19 on the Business of Insurers and Reinsurers): Coronavirus – COVID-19

Advisor News

  • A rising retirement challenge: The license to spend
  • Financial stress leaves less room for retirement saving
  • Giving while you’re living: 3 frequently asked questions about gifting
  • Helping clients prepare for one of their biggest retirement expenses
  • Important year-end financial conversations every advisor must have
More Advisor News

Annuity News

  • A rising retirement challenge: The license to spend
  • What lower interest rates mean to annuity payouts
  • AM Best downgrades A-Cap insurers amid financial and regulatory troubles
  • Lawsuit claims Delaware Life hid billions in insurer-linked investments
  • AM Best to Deliver Presentation at 2026 ACLI Annual Conference
More Annuity News

Health/Employee Benefits News

  • The flawed logic of Medicare for All
  • Bailey pushes back on Abbott tax message
  • Commentary: Health coverage for all
  • Healthcare workers see rising insurance costs
  • Norwood Davis, former CEO of health insurance giant Trigon, dies at 86
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Study Results from Cornell University in the Area of Insurance Reported (Regulatory Competition In the Us Life Insurance Industry): Insurance
  • AM Best Comments on Issuer Credit Ratings of Pacific Life Insurance Company’s Commercial Paper Following Amendment to Program
  • AM Best Affirms Credit Ratings of Protective Life Corporation and Its Key Subsidiaries
  • ICICI Life Insurance names Sidharatha Mishra managing director, CEO
  • Lawsuit alleges companies collected $30 million in ‘illegal wager on human life’
Sponsor
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Lauren Sinnott Named to Ragan’s Top Women in Marketing Awards, Class of 2026 
  • Classic Car Insurer OpenRoad Insurance Expands to 40 U.S. States in Two Years
  • How Aspire General Turned an Early Technology Bet Into Claims Automation at Scale with Kyber
  • Adjusto launches AI-Native contents claims services powered by its technology platform
  • URL Insurance Group Celebrates 40 Years of Service, Growth, and Industry Leadership
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.