IP Library Patent Application 11646827
Patent Application
App. No. 11/646,827

Selective secure database communications

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/646,827
Abstract

Techniques for selective secure database communications are presented. Communications directed to a database are inspected to determine the originators and the origins for those communications. Policy is evaluated in response to the originators and the origins of the communications. When dictated by the policy, the communications are redirected to an encryption service to be encrypted before being forwarded to the database for subsequent processing.

Claims (30)

1 . A method, comprising:

identifying a user attempting to communicate with a database;

acquiring policy; and

directing the user to an encryption mechanism for use when communicating with the database in response to directives associated with the policy.

2 . The method of claim 1 , wherein acquiring policy further includes identifying the policy in response to an Internet Protocol (IP) address associated with the user.

3 . The method of claim 1 , wherein acquiring policy further includes identifying the policy in response to an authenticated identity associated with the user.

4 . The method of claim 1 , wherein acquiring policy further includes identifying the policy in response to an assigned role associated with the user after the user authenticates to the database.

5 . The method of claim 1 , wherein directing further includes identifying a type of encryption to use with the encryption mechanism in response to a number of the directives included in the policy.

6 . The method of claim 1 , wherein identifying further includes detecting the user attempting to access the database from an external network connection outside a firewall environment associated with the database.

7 . The method of claim 1 further comprising:

ensuring first information sent from the user to the database is encrypted; and

ensuring second information sent from the database to the user is also encrypted.

8 . A method, comprising:

detecting external user attempts to communicate with a database;

acquiring policy in response to one or more of the following: an identity associated with the user, an Internet Protocol (IP) address being used by the user, and a resource associated with the database; and

ensuring communications between the user and the database are encrypted when directed by the policy.

9 . The method of claim 8 , wherein detecting further includes, intercepting the user attempts at a reverse proxy service or gateway that acts as a front end access to the database for external access requests to the database.

10 . The method of claim 8 , wherein acquiring further includes using the policy to determine that encryption is to be used for the user when the user is located outside a firewall environment of the database and that encryption is unnecessary when the user is located inside the firewall environment of the database.

11 . The method of claim 8 , wherein acquiring further includes recognizing directives within the policy that direct encryption to be used in response to an assigned access role associated with the user when the user authenticates to the database.

12 . The method of claim 8 , wherein acquiring further includes recognizing directives within the policy that direct encryption to be used in response to an electronic mail (email) address associated with the user.

13 . The method of claim 8 , wherein acquiring further includes recognizing directives within the policy that direct encryption to be used in response to a portion of the IP address.

14 . The method of claim 8 , wherein ensuring further includes redirecting user communications to an encryption service before forwarding the user communications to the database and redirecting database communications to the encryption service before forwarding to the database communications to the user.

15 . A system comprising:

a database accessible within a machine-readable medium; and

a encryption policy service to be processed by a machine within the machine-readable medium, wherein the encryption policy service is to inspect communications from users directed to the database and is to determine whether the communications are to be encrypted or not encrypted on behalf of the database.

16 . The system of claim 15 , wherein the encryption policy service is to determine whether to encrypt or not encrypt in response to policy, and wherein the policy is associated with the users or the database.

17 . The system of claim 15 , wherein the encryption policy service is operated on the machine as a reverse proxy of the database to handle external network requests that attempt to access the database outside a firewall environment.

18 . The system of claim 15 , wherein the encryption policy service is operated as a front-end service of the database to handle both internal and external requests that attempt to access the database from within a firewall environment and from outside the firewall environment.

19 . The system of claim 15 , wherein the encryption policy service is to direct the communications, which are to use encryption, to an encryption service to be encrypted before being sent to the database.

20 . The system of claim 19 , wherein the encryption policy service is to direct responses from the database to the encryption service before being sent to the users.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2008
From: NCR CORPORATION
To: TERADATA US, INC.
Reel/Frame 020666/0438 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2007
From: HANSON, RICHARD
To: NCR CORPORATION
Reel/Frame 018971/0730 →