发明名称 Data protection hub
摘要 Embodiments of the invention broadly described, introduce systems and methods for protecting data at a data protection hub using a data protection policy. One embodiment of the invention discloses a method for protecting unprotected data. The method comprises receiving a data protection request message comprising unprotected data and one or more policy parameters, determining a data protection transformation using the policy parameters, performing the data protection transformation on the unprotected data to generate protected data, and sending the protected data.
申请公布号 US9547769(B2) 申请公布日期 2017.01.17
申请号 US201313935311 申请日期 2013.07.03
申请人 Visa International Service Association 发明人 Aissi Selim;Nagasundaram Sekhar
分类号 H04L29/06;G06F21/60;G06F21/85;G06F7/04;G06F17/30;H04N7/16 主分类号 H04L29/06
代理机构 Kilpatrick Townsend & Stockton LLP 代理人 Kilpatrick Townsend & Stockton LLP
主权项 1. A data protection hub, comprising: a hardware random number generator configured to generate random numbers; a cryptoprocessor configured to perform cryptographic operations; a processor coupled to the hardware random number generator and the cryptoprocessor and configured for executing code; networking apparatus configured to receive from a client computer, a data protection request message comprising unprotected data, a data protection policy file and one or more policy parameters; a non-transitory computer-readable storage medium, comprising code executable by the processor for: determining a data protection transformation by parsing the data protection policy file, wherein the data protection policy file is used to determine the data protection transformation based on the one or more policy parameters;selecting one or more of the hardware random number generator or the cryptoprocessor based on the determined data protection transformation;performing, using the selected one or more of the hardware random number generator or the cryptoprocessor, the data protection transformation on the unprotected data to generate protected data, wherein the data protection transformation comprises: hashing the unprotected data using one of a plurality of hashing algorithms, based on the determined data protection transformation; andmasking sensitive data fields of the unprotected data based on further determining that the sensitive data fields includes unprotected data; and the networking apparatus further configured to send the protected data, to the client computer.
地址 San Francisco CA US