IP Library Granted Patent US 8,966,250
Granted Patent B2
US 8,966,250 · App. 13/062,696 · Granted Feb 24, 2015

Appliance, system, method and corresponding software components for encrypting and processing data

Inventors: Ofer Shochet (Tel Aviv, IL); David Movshovitz (Raanana, IL)
Assignee: salesforce.com, inc.
H04L63/0471G06F21/6209H04L9/0662H04L63/105H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,250
App. No.
13/062,696
Granted
Feb 24, 2015
Kind
B2
Abstract

Disclosed is an appliance, system, method and corresponding software application for encrypting and processing data. A symbol based encryption module may be adapted to encrypt data on a symbol basis such that some or all of the encrypted data remains processable.

Claims (32)

1. A system comprising:

a symbol based encryption module adapted to encrypt on a per symbol basis some or all of the data within a data record, data file or document, wherein the encryption is invariant on a per symbol basis and at least some of the data in the file or document remains processable in a Software as a Service (SaaS) environment, and wherein search terms to be used to search the some or all of the data within the data record are converted using the symbol based encryption module and searching is performed utilizing the converted symbols within the SaaS environment, wherein symbols to be encrypted are first converted into lower case letters, encrypted, and then case format information relating to the unencrypted symbols is then encoded onto the encrypted data;

a sensitivity module communicatively coupled with the symbol based encryption module to evaluate the data to determine a sensitivity level for multiple components of the data, wherein encryption of the multiple components is performed based on the sensitivity level corresponding to the component.

2. The system according to claim 1 , wherein said encryption module utilizes either a symbol based mapping table or a encryption algorithm adapted for symbol encryption.

3. The system according to claim 2 , wherein the mapping table or the key for the encryption algorithm is user or organization specific.

4. The system according to claim 2 , further comprising a symbol based decryption module adapted to utilize a mapping table or a decryption algorithm associated with the table or algorithm used for encryption by said encryption module, and wherein the term associated means either the same or the inverse of, or derived from.

5. The system according to claim 4 , wherein said decryption module is integral or otherwise functionally associated with an application adapted to generate, view, process or edit the data file, record or document.

6. The system according to claim 4 , wherein said decryption module is integral or otherwise functionally associated peripheral hardware connected to a computational platform of an application adapted to generate, view, process or edit the data file, record or document.

7. The system according to claim 4 , wherein said decryption module is integral or otherwise functionally associated with an organizational data file system or record/document repository.

8. The system according to claim 4 , wherein said decryption module is integral or otherwise functionally associated with a gateway to an extra-organizational data file system or record/document repository.

9. The system according to claim 4 , wherein said decryption module is integral or otherwise functionally associated with an application provided as software as a service server or with a gateway to an application provided as software as a service server.

10. The system according to claim 2 , further comprising a search engine/utility adapted to search one or more encrypted files, records or documents by converting search terms into encrypted versions of the search terms.

11. The system according to claim 10 , wherein said search engine/utility is functionally associated with a relational database and searchable encrypted files, records or documents are stored on the relational database.

12. The system according to claim 2 , further comprising a data processing module adapted to read and process encrypted and unencrypted data from one or more data files, records or documents eby said encryption module.

13. The system according to claim 12 , wherein said data processing module is further adapted to read and process encrypted data from one or more data fields of files, records or documents encrypted by said encryption module.

14. The system according to claim 2 , where said encryption module is adapted to encrypt at least a portion of one or more fields of a data file, record or document stored to a relational database.

15. The system according to claim 14 , wherein one or more relational database processes are performed on unencrypted portions of fields of one or more files, records or documents stored on the relational database.

16. The system according to claim 14 , wherein one or more relational database processes are performed on encrypted portions of fields of one or more files, records or documents stored on the relational database.

17. The system according to claim 1 , wherein encryption of a symbol or group of symbols is selective and based on a sensitivity evaluation of the symbol(s).

18. The system according to claim 17 , further comprising a data sensitivity evaluation module adapted to determine a sensitivity level of some or all symbols or groups of symbols within the data record, data file or document.

19. The system according to claim 18 , wherein sensitivity classification of symbols is determined based on one or more parameters selected from the group consisting of symbol title, symbol data format and a user selected security level.

20. The system according to claim 1 , wherein said encryption module is integral or otherwise functionally associated with an application adapted to generate, view, process or edit the data file, record or document.

21. The system according to claim 1 , wherein said encryption module is integral or otherwise functionally associated peripheral hardware connected to a computational platform of an application adapted to generate, view, process or edit the data file, record or document.

22. The system according to claim 1 , wherein said encryption module is integral or otherwise functionally associated with an organizational data file system or record/document repository.

23. The system according to claim 1 , wherein said encryption module is integral or otherwise functionally associated with a gateway to an extra-organizational data file system or record/document repository.

24. The system according to claim 1 , wherein said encryption module is integral or otherwise functionally associated with an application provided as software as a service server or with a gateway to an application software provided as a service server.

25. The system according to claim 1 , wherein the data record is an HTTP, HTTPS, SMTP, IMAP, POP3, or WAP request.

26. The system according to claim 1 , wherein the data record is an HTTP, HTTPS, SMTP, IMAP, POP3, or WAP related transaction.

27. A non-transitory computer-readable medium having instructions that, when executed by one or more processors, are capable of causing a data processing system to implement:

a symbol based encryption module adapted to encrypt on a per symbol basis some or all of the data within a data record, data file or document, wherein the encryption is invariant on a per symbol basis and at least some of the data in the file or document remains processable in a Software as a Service (SaaS) environment, and wherein letter case format information is encoded on the encrypted data, and wherein search terms to be used to search the some or all of the data within the data record are converted using the symbol based encryption module and searching is performed utilizing the converted symbols within the SaaS environment, wherein symbols to be encrypted are first converted into lower case letters, encrypted, and then case format information relating to the unencrypted symbols is then encoded onto the encrypted data;

a sensitivity module communicatively coupled with the symbol based encryption module to evaluate the data to determine a sensitivity level for multiple components of the data, wherein encryption of the multiple components is performed based on the sensitivity level corresponding to the component.

28. The computer-readable medium according to claim 27 , further comprising a decryption module adapted to read the case format information from the encrypted symbols, decrypt the encrypted symbols back into lower case decrypted symbols and apply the case format information to the decrypted symbols.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2012
From: SALESFORCE.COM ISRAEL LTD.
To: SALESFORCE.COM, INC.
Reel/Frame 028743/0434 →
CHANGE OF NAME Recorded Aug 6, 2012
From: CONFIDATO SECURITY SOLUTIONS LTD
To: SALESFORCE.COM ISRAEL LTD.
Reel/Frame 028731/0704 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2012
From: SHOCHET, OFER; MOVSHOVITZ, DAVID
To: CONFIDATO SECURITY SOLUTIONS LTD
Reel/Frame 028703/0895 →
Continuity (2)
Provisional Application 61094985 · Sep 8, 2008
Related Publication 20130067225A1 · Mar 14, 2013