IP Library Granted Patent US 7,620,625
Granted Patent B2
US 7,620,625 · App. 11/133,836 · Granted Nov 17, 2009

Method and apparatus for communication efficient private information retrieval and oblivious transfer

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,620,625
App. No.
11/133,836
Granted
Nov 17, 2009
Kind
B2
Abstract

A method, article of manufacture and apparatus for performing private retrieval of information from a database is disclosed. In one embodiment, the method comprising obtaining an index corresponding to information to be retrieved from the database and generating a query that does not reveal the index to the database. The query is an arithmetic function of the index and a secret value, wherein the arithmetic function includes a multiplication group specified by a modulus of a random value whose order is divisible by a prime power, such that the prime power is an order of the random value. The secret value is an arithmetic function of the index that comprises a factorization into prime numbers of the modulus. The method further comprises communicating the query to the database for execution of the arithmetic function against the entirety of the database.

Claims (39)

1. A method of privately retrieving information from a database, the method comprising:

obtaining, by a client, an index corresponding to information to be retrieved from the database;

generating a query that avoids revealing the index to the database, the query being an arithmetic function of the index and a secret value that is an arithmetic function of the index, wherein the arithmetic function includes a multiplication group specified by a modulus of a random value whose order is divisible by a prime power, such that the prime power is an order of the random value, and wherein the secret value comprises the factorization into prime numbers of the modulus;

communicating the query to the database for execution of the arithmetic function against the entirety of the database; and

receiving, by the client, results from the database of the execution of the arithmetic function by the database.

2. The method defined in claim 1 further comprising applying a mapping to the database to obtain the prime power.

3. The method defined in claim 1 further comprising:

sampling the modulus according to a distribution function from a set of values that Φ-hide the prime power; and

generating the random value with an order being the prime power in the multiplicative group taken modulo the modulus.

4. The method defined in claim 1 further comprising:

applying a mapping to the index to obtain a prime power;

sampling a sufficiently large modulus according to a distribution function from a set of values that Φ-hide the prime power; and

generating a random value whose order is the prime power in the multiplicative group taken modulo the modulus.

5. The method defined in claim 1 wherein the query comprises O(log m) bits, wherein m equals the number of elements stored in the database.

6. The method defined in claim 1 further comprising:

decoding the results, wherein the total amount of information exchanged with the database is less than the total amount of information stored in the database.

7. An article of manufacture having one or more recordable media storing instructions thereon which, when executed by a system, cause the system to perform a method comprising:

obtaining an index corresponding to information to be retrieved from the database;

generating a query that avoids revealing the index to the database, the query being an arithmetic function of the index and a secret value, wherein the arithmetic function includes a multiplication group specified by a modulus of a random value whose order is divisible by a prime power, such that the prime power is an order of the random value, and wherein the secret value is an arithmetic function of the index and comprises the factorization into prime numbers of the modulus;

communicating the query to the database for execution of the arithmetic function against the entirety of the database; and

receiving results from the database of the execution of the arithmetic function by the database.

8. The article of manufacture defined in claim 7 wherein the method further comprises applying a mapping to the database to obtain the prime power.

9. The article of manufacture defined in claim 7 wherein the method further comprises:

sampling the modulus according to a distribution function from a set of values that Φ-hide the prime power; and

generating the random value with an order being the prime power in the multiplicative group taken modulo the modulus.

10. The article of manufacture defined in claim 7 wherein the method further comprises:

applying a mapping to the index to obtain a prime power;

sampling a sufficiently large modulus according to a distribution function from a set of values that Φ-hide the prime power; and

generating a random value whose order is the prime power in the multiplicative group taken modulo the modulus.

11. The article of manufacture defined in claim 7 wherein the query comprises O(log m) bits, wherein m equals the number of elements stored in the database.

12. The article of manufacture defined in claim 7 wherein the method further comprises:

decoding the results, wherein the total amount of information exchanged with the database is less than the total amount of information stored in the database.

13. An apparatus comprising: an external network interface

through which a request for information is made; a memory; and a processor, coupled to the external network interface and the memory, to:

obtain an index corresponding to the information to be retrieved from the database;

generate a query that avoids to reveal the index to the database, the query being an arithmetic function of the index and a secret value that is an arithmetic function of the index, wherein the arithmetic function includes a multiplication group specified by a modulus of a random value whose order is divisible by a prime power, such that the prime power is an order of the random value, and wherein the secret value comprises the factorization into prime numbers of the modulus; and

communicate the query to the database for execution of the arithmetic function against the entirety of the database; and

receive results from the database of the execution of the arithmetic function by the database.

14. The apparatus defined in claim 13 wherein the processor applies a mapping to the index to obtain a prime power, samples a sufficiently large modulus according to a distribution function from a set of values that Φ-hide the prime power, and generates a random value whose order is the prime power in the multiplicative group taken modulo the modulus.

Assignments (4)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044101/0610 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2016
From: NTT DOCOMO, INC.
To: GOOGLE INC
Reel/Frame 039885/0615 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2005
From: DOCOMO COMMUNICATIONS LABORATORIES, USA, INC.
To: NTT DOCOMO, INC.
Reel/Frame 017237/0313 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2005
From: RAMZAN, ZULFIKAR AMIN; GENTRY, GRAIG B
To: DOCOMO COMMUNICATIONS LABORATORIES USA, INC.
Reel/Frame 016589/0089 →