IP Library Granted Patent US 7,418,600
Granted Patent B2
US 7,418,600 · App. 10/388,074 · Granted Aug 26, 2008

Secure database access through partial encryption

Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,418,600
App. No.
10/388,074
Granted
Aug 26, 2008
Kind
B2
Abstract

The present invention generally is directed to systems, methods, and articles of manufacture for securing sensitive information involved in database transactions. Embodiments of the present invention selectively encrypt only portions of transactions involving sensitive data, thereby reducing or eliminating the processing overhead resulting from wastefully encrypting non-sensitive data. The sensitive data may be identified by a document. The document may be accessed by a requesting entity to determine which portions of a query should be encrypted prior to sending the query to a database server over a network. The document may also be accessed by a database server to determine which portions of query results should be encrypted prior to sending the query results to the requesting entity over the network.

Claims (14)

1. A method for conducting a secure database transaction, comprising:

receiving a query from a requesting entity, wherein the query was processed by an encryption algorithm configured to selectively encrypt conditions of the query depending on whether the query conditions contained an identified sensitive field;

issuing the query against a database;

receiving results in response to issuing the query;

determining whether the results include data corresponding to one or more sensitive fields;

if so, encrypting the data corresponding to the one or more sensitive fields; and sending the query results to the requesting entity; and

prior to issuing the query against the database:

determining if the query comprises any encrypted conditions; and

if so, decrypting the encrypted conditions.

2. The method of claim 1 , wherein determining whether the results includes data corresponding to one or more sensitive fields comprises accessing a document identifying one or more fields as sensitive.

3. The method of claim 2 , wherein the document is an XML document.

4. The method of claim 2 , wherein:

the document contains abstract representations of physical fields of the database; and

issuing the query against a database comprises mapping, based on the abstract representations, logical fields contained in the query to physical fields of the database.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2018
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: WORKDAY, INC.
Reel/Frame 044721/0844 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2003
From: DETTINGER, RICHARD D.; KULACK, FREDERICK A.; STEVENS, RICHARD J.; WILL, ERIC W.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 013871/0532 →
Continuity (1)
Related Publication 20040181679A1 · Sep 16, 2004