US 12,339,992 B2
Data security hub
Theodore Harris, San Francisco, CA (US); John F. Sheets, San Francisco, CA (US); Mark Nelsen, Oakland, CA (US); Yue Li, San Mateo, CA (US); and Craig O'Connell, San Mateo, CA (US)
Assigned to Visa International Service Association, San Francisco, CA (US)
Filed by Visa International Service Association, San Francisco, CA (US)
Filed on Jul. 29, 2022, as Appl. No. 17/864,287.
Application 17/864,287 is a continuation of application No. 16/759,453, granted, now 11,429,745, previously published as PCT/US2017/059124, filed on Oct. 30, 2017.
Prior Publication US 2022/0358242 A1, Nov. 10, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/62 (2013.01); G06F 21/45 (2013.01); H04L 9/40 (2022.01); H04W 12/02 (2009.01); H04W 12/06 (2021.01); H04W 12/67 (2021.01); G06F 16/24 (2019.01)
CPC G06F 21/6245 (2013.01) [G06F 21/45 (2013.01); H04L 63/083 (2013.01); H04W 12/02 (2013.01); H04W 12/06 (2013.01); H04W 12/67 (2021.01); G06F 16/24 (2019.01); G06F 2221/2113 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A data security hub for processing and routing access request messages, the data security hub comprising:
a computer readable storage medium storing a plurality of instructions; and
one or more processors for executing the instructions stored on the computer readable storage medium to:
receive an access request message from a client device, the access request message comprising a plurality of items of authentication information and requesting an access to a resource, the plurality of items of authentication information corresponding to one or more types of authentication information;
analyze the access request message to determine the one or more types of the plurality of items of authentication information included in the access request message;
determine sensitivity levels corresponding to the one or more types of authentication information;
restrict the one or more types of authentication information based on the sensitivity levels and a risk level of the resource to obtain a restricted set of authentication information, wherein the restricted set of authentication information comprises fewer items of authentication information than the plurality of items of authentication information or at least one item of authentication information that is at least partially obfuscated among the plurality of items;
identify a set of data processing servers capable of processing the restricted set of authentication information;
select a first data processing server from the set of data processing servers based on an evaluated trust level and a network condition of the first data processing server; and
send an authentication request including the restricted set of authentication information to the first data processing server.