Patent · US Active

Type-based database confidentiality using trusted computing

US10601593B2 · kind B2 · utility

8Cited by
11References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 23, 2016
Grant dateMar 24, 2020
Priority date
Expiry dateMay 20, 2037

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2107
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A “Database Confidentiality System” provides various techniques for using server-side trusted computing in combination with configurable type metadata and user- or system-definable rules associated with individual database fields to implement database confidentiality. In various implementations, type metadata and one or more rules are added to each database field. Metadata includes a domain, method of encryption, and a pointer to an encryption key used to encrypt the data in the corresponding field. The rules define one or more operations allowed on the corresponding data types. The type metadata and rules are optionally integrity protected and/or encrypted to avoid unauthorized changes or access. Various encryption techniques (e.g., probabilistic, Paillier, etc.) allow some computations to be performed in an untrusted environment without access to the encryption key. This enables the Database Confidentiality System to maintain database confidentiality while performing distributed computation and communications between the untrusted machine and the trusted machine.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.