PROTECTING CUSTOMER PERSONAL INFORMATION IN APPLICATION PIPELINE

    公开(公告)号:US20240098069A1

    公开(公告)日:2024-03-21

    申请号:US18523476

    申请日:2023-11-29

    IPC分类号: H04L9/40 H04L9/32

    CPC分类号: H04L63/0407 H04L9/3213

    摘要: Techniques are described that include detecting customer personal information within any appropriate set of data, such as customer communications produced by customer-facing services offered by an organization. Once detected, the customer personal information may be tokenized within the customer communications, making the data appropriate for external systems, such as cloud-hosted applications. The disclosed techniques include a masking service that may be plugged into an on-premises pipeline of any customer-facing service that makes requests to an off-premises, cloud-hosted application. The masking service may apply rule-based detection and/or machine learning-based detection to detect both structured and unstructured customer personal information included in customer communications. The masking service may further tokenize or otherwise obfuscate or replace the detected customer personal information. The tokenized customer communications may then be included in the requests to the cloud-hosted application or otherwise transmitted to external systems without exposing the customer personal information.

    Login and authentication methods and systems

    公开(公告)号:US11831648B1

    公开(公告)日:2023-11-28

    申请号:US18079211

    申请日:2022-12-12

    IPC分类号: H04L9/40 G06F21/31

    摘要: Systems, methods, and apparatuses for authenticating requests to access one or more accounts over a network using authenticity evaluations of two or more automated decision engines are discussed. A login request for access to a user account may be submitted to multiple decision engines that each apply different rulesets for authenticating the login request, and output an evaluation of the authenticity of the login request. Based on evaluations from multiple automated decision engines, the login request may be allowed to proceed to validation of user identity and, if user identity is validated, access to the user account may be authorized. Based on the evaluations, the login attempt may also be rejected. One or more additional challenge question may be returned to the computing device used to request account access, and the login request allowed to proceed to validation of identity if the response to the challenge question is deemed acceptable.

    DISTRIBUTED DEVICE TRUST DETERMINATION
    6.
    发明公开

    公开(公告)号:US20240129309A1

    公开(公告)日:2024-04-18

    申请号:US18488771

    申请日:2023-10-17

    IPC分类号: H04L9/40

    摘要: Techniques described herein include performing a distributed device trust determination that includes determining trust scores for customer devices across multiple organizations. In one example, this disclosure describes a method that includes receiving data of a user device event including an organization confidence level for a user device associated with the user device event; updating common data in an entry for the user device in a device registry based on the received data of the user device event and the organization confidence level for the user device; determining a common confidence level for the user device based on the common data in the entry for the user device in the device registry; and outputting the common confidence level for the user device for use by the computing device of the first organization to determine how to handle an access request from the user device.

    Protecting customer personal information in application pipeline

    公开(公告)号:US11870757B1

    公开(公告)日:2024-01-09

    申请号:US17457384

    申请日:2021-12-02

    IPC分类号: H04L9/40 H04L9/32

    CPC分类号: H04L63/0407 H04L9/3213

    摘要: Techniques are described that include detecting customer personal information within any appropriate set of data, such as customer communications produced by customer-facing services offered by an organization. Once detected, the customer personal information may be tokenized within the customer communications, making the data appropriate for external systems, such as cloud-hosted applications. The disclosed techniques include a masking service that may be plugged into an on-premises pipeline of any customer-facing service that makes requests to an off-premises, cloud-hosted application. The masking service may apply rule-based detection and/or machine learning-based detection to detect both structured and unstructured customer personal information included in customer communications. The masking service may further tokenize or otherwise obfuscate or replace the detected customer personal information. The tokenized customer communications may then be included in the requests to the cloud-hosted application or otherwise transmitted to external systems without exposing the customer personal information.