Methods and apparatus for encrypted indexing and searching encrypted data
In some embodiments, an apparatus includes a memory and a processor. The processor is configured to receive an index file that associates a characteristic in a set of documents with a set of information associated with the characteristic in the set of documents. The processor is further configured to generate an index identifier associated with the index file and calculate a set of pseudorandom logical block identifiers associated with a set of storage locations of a database based on the index identifier. The processor is then configured to parse the index file into a set of index data portions and send a signal to the database to write each index data portion from the set of index data portions at a different storage location within the database as indicated by a different identifier from the set of pseudorandom logical block identifiers.
1 . An apparatus, comprising:
a memory; and
a processor operatively coupled to the memory, the memory storing instructions configured to cause the processor to:
receive, at a security device, an index file from a plurality of index files;
parse each index file from the plurality of index files into a plurality of index data portions, each index data portion from the plurality of index data portions including a different index entry from remaining index data portions from the plurality of index data portions;
calculate a hash value for each index data portion from the plurality of index data portions, the hash value for each index data portion from the plurality of index data portions being an identifier that identifies a different storage location from a set of storage locations within a storage system having a plurality of databases; and
send a signal to store each index data portion from the plurality of index data portions at a different storage location from the set of storage locations within the storage system to cause (i) a first index data portion from the plurality of index data portions to be stored within a first database from the plurality of databases and (ii) a second index data portion from the plurality of index data portions to be stored within a second database from the plurality of databases.
2 . The apparatus of claim 1 , wherein the index file is associated with (1) a characteristic in a set of documents and (2) information associated with the characteristic in the set of documents, the information includes a hash value used to identify each document from the set of documents within the storage system.
3 . The apparatus of claim 1 , wherein the instructions are further configured to cause the processor to:
parse each index data portion from the plurality of index data portions into a set of secondary index data portions; and
send a signal to the storage system to store each secondary index data portion from the set of secondary index data portions at a different storage location from the set of storage locations within the storage system.
4 . The apparatus of claim 1 , wherein the instructions are further configured to cause the processor to:
send a signal to a third database to store each index data portion from the plurality of index data portions at a storage location from a set of storage locations within the third database.
5 . The apparatus of claim 1 , wherein the instructions are further configured to cause the processor to:
modify an initialization vector for each index data portion from the plurality of index data portions,
the instructions configured to cause the processor to send including instructions configured to cause the processor to send the signal to store each index data portion from the plurality of index data portions as modified by the initialization vector for that index data portion at a different storage location from the set of storage locations within the storage system.
6 . The apparatus of claim 1 , wherein a hash value is used with a cryptographic key to identify a storage location from the set of storage locations within the storage system.
7 . The apparatus of claim 1 , wherein each index file from the plurality of index files is an encrypted index file.
8 . The apparatus of claim 1 , wherein the hash value for each index data portion from the plurality of index data portions is not stored in long-term memory.
9 . The apparatus of claim 1 , wherein the hash value for each index data portion from the plurality of index data portions is calculated using a hash function.
10 . A non-transitory processor-readable medium storing instructions to cause one or more processors to:
receive, at a security device, an index file from a plurality of index files;
parse each index file from the plurality of index files into a plurality of index data portions, each index data portion from the plurality of index data portions including a different index entry from remaining index data portions from the plurality of index data portions;
calculate a hash value for each index data portion from the plurality of index data portions, the hash value for each index data portion used to identify a different storage location from a set of storage locations within a storage system having a plurality of databases; and
send a signal to store each index data portion from the plurality of index data portions at a different storage location from the set of storage locations within the storage system to cause (i) a first index data portion from the plurality of index data portions to be stored within a first database from the plurality of databases and (ii) a second index data portion from the plurality of index data portions to be stored within a second database from the plurality of databases.
11 . The non-transitory processor-readable medium of claim 10 , wherein the index file is associated with (1) a characteristic in a set of documents and (2) information associated with the characteristic in the set of documents, the information includes the hash value for each index data portion used to identify each document from the set of documents within the storage system.
12 . The non-transitory processor-readable medium of claim 10 , the instructions further comprising instructions to cause the one or more processors to:
parse each index data portion from the plurality of index data portions into a set of secondary index data portions; and
send a signal to the storage system to store each secondary index data portion from the set of secondary index data portions at a different storage location from the set of storage locations within the storage system.
13 . The non-transitory processor-readable medium of claim 10 , the instructions further comprising instructions to cause the one or more processors to:
send a signal to a third database to store each index data portion from the plurality of index data portions at a storage location from a set of storage locations within the third database.
14 . The non-transitory processor-readable medium of claim 10 , the instructions further comprising instructions to cause the one or more processors to:
modify an initialization vector for each index data portion from the plurality of index data portions,
the instructions configured to cause the one or more processors to send the signal including instructions configured to cause the one or more processors to send the signal to store each index data portion from the plurality of index data portions as modified by the initialization vector for that index data portion at a different storage location from the set of storage locations within the storage system.
15 . The non-transitory processor-readable medium of claim 10 , wherein the hash value for each index data portion is used with a cryptographic key to identify the different storage location from the set of storage locations within the storage system.
16 . The non-transitory processor-readable medium of claim 10 , wherein the hash value for each index data portion from the plurality of index data portions is calculated using a hash function.
17 . A method, comprising:
receiving, at a security device, an index file from a plurality of index files;
parsing each index file from the plurality of index files into a plurality of index data portions, each index data portion from the plurality of index data portions including a different index entry from remaining index data portions from the plurality of index data portions;
calculating a hash value for each index data portion from the plurality of index data portions, the hash value for each index data portion used to identify a different storage location from a set of storage locations within a storage system having a plurality of databases; and
sending a signal to store each index data portion from the plurality of index data portions at a different storage location from the set of storage locations within the storage system to cause (i) a first index data portion from the plurality of index data portions to be stored within a first database from the plurality of databases and (ii) a second index data portion from the plurality of index data portions to be stored within a second database from the plurality of databases.
18 . The method of claim 17 , wherein the index file is associated with (1) a characteristic in a set of documents and (2) information associated with the characteristic in the set of documents, the information includes the hash value for each index data portion used to identify each document from the set of documents within the storage system.
19 . The method of claim 17 , further comprising:
parsing each index data portion from the plurality of index data portions into a set of secondary index data portions; and
sending a signal to the storage system to store each secondary index data portion from the set of secondary index data portions at a different storage location from the set of storage locations within the storage system.
20 . The method of claim 17 , further comprising:
modifying an initialization vector for each index data portion from the plurality of index data portions,
the sending includes sending the signal to store each index data portion from the plurality of index data portions as modified by the initialization vector for that index data portion at a different storage location from the set of storage locations within the storage system.