IP Library Granted Patent US 9,886,585
Granted Patent B2
US 9,886,585 · App. 13/918,234 · Granted Feb 6, 2018

Multi-layer data security

Inventors: Marek Piotr Zielinski (Pretoria, ZA); Jan Harm Petrus Eloff (Pretoria, ZA)
Assignee: SAP SE
G06F21/602G06F21/60G06F21/62G06F21/6209G06F2221/2107G06F2221/2111G06F2221/2113G06F2221/2137
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,886,585
App. No.
13/918,234
Granted
Feb 6, 2018
Kind
B2
Abstract

Data may be encrypted using a public key. From a plurality of functions executable on the data, one or more functions may be selected. The selected one or more functions may be associated with the encrypted data. The selected one or more functions may provide exclusive access to the data. A data structure specifying conditions for access to the one or more functions may be created. An exclusive interface to provide access to the one or more functions may be created. The interface, upon determining that one or more conditions from the conditions are satisfied, may grant access to the one or more functions. The encrypted data, the associated one or more functions, the data structure, and the interface may be included into an object.

Claims (18)

1. A computer-implemented method comprising: encrypting, by a computer processor, data using a key; from a plurality of functions executable on the data, selecting at least one function; associating the selected at least one function with the encrypted data, wherein the selected at least one function provides exclusive access to the data, and wherein the selected at least one function is executable only on the data; creating a data structure specifying conditions for access to the at least one function with the encrypted data; creating an exclusive interface to provide access to the at least one function, wherein, upon determining that at least one condition from the conditions is satisfied, grants access to the at least one function, and wherein the interface, upon determining that no conditions are satisfied, denies access to the at least one function, wherein the determining comprises checking a context in which the at least one function is being invoked by based on at least one of: (i) a computing environment in which the at least one function is invoked, (ii) a number of times the at least one function is invoked, and (iii) whether any conflicts of interest arise between an owner of the data structure and a consumer of the data structure when the at least one function is invoked; and including the encrypted data, the associated at least one function, software necessary to execute the at least one function, the data structure, and the interface into an object; wherein executable software necessary to determine whether the conditions are satisfied is included in the object, wherein the software necessary to determine whether the conditions are satisfied is only accessible by the interface.

2. The method of claim 1 , wherein the at least one condition specifies an authorized user with access to the at least one function.

3. The method of claim 1 , wherein the at least one condition specifies a time period for accessing the at least one function.

4. The method of claim 1 , wherein the at least one condition specifies a maximum number of times that the at least one function can be executed.

5. The method of claim 1 , wherein the at least one condition specifies a conflict of interest arising from execution of the at least one function.

6. The method of claim 1 , wherein the interface grants access to the at least one function upon determining that all the conditions are satisfied.

7. An apparatus comprising: a computer processing device to: encrypt data using a key; from a plurality of functions executable on the data, select at least one function; associate the selected at least one function with the encrypted data, wherein the selected at least one function provides exclusive access to the data, and wherein the selected at least one function is executable only on the data; create a data structure specifying conditions for access to the at least one function with the encrypted data; create an exclusive interface to provide access to the at least one function, wherein, upon determining that at least one condition from the conditions is satisfied, grants access to the at least one function, and wherein the interface, upon determining that no conditions are satisfied, denies access to the at least one function, wherein the determining comprises checking a context in which the at least one function is being invoked by based on at least one of: (i) a computing environment in which the at least one function is invoked, (ii) a number of times the at least one function is invoked, and (iii) whether any conflicts of interest arise between an owner of the data structure and a consumer of the data structure when the at least one function is invoked; and include the encrypted data, the associated at least one function, software necessary to execute the at least one function, the data structure, and the interface into an object; wherein executable software necessary to determine whether the conditions are satisfied is included in the object, wherein the software necessary to determine whether the conditions are satisfied is only accessible by the interface.

8. The apparatus of claim 7 , wherein the at least one condition specifies an authorized user with access to the at least one function.

9. The apparatus of claim 7 , wherein the at least one condition specifies a time period for accessing the at least one function.

10. The apparatus of claim 7 , wherein the at least one condition specifies a maximum number of times that the at least one function can be executed.

11. The apparatus of claim 7 , wherein the at least one condition specifies any conflicts of interest arising from execution of the at least one function.

12. The apparatus of claim 7 , wherein the interface grants access to the at least one function upon determining that all the conditions are satisfied.

13. A non-transitory computer-readable medium embodied with computer-executable instructions for causing a computer to execute instructions, the computer instructions comprising: encrypting, by a computer processor, data using a key; from a plurality of functions executable on the data, selecting at least one function; associating the selected at least one function with the encrypted data, wherein the selected at least one function provides exclusive access to the data, and wherein the selected at least one function is executable only on the data; creating a data structure specifying conditions for access to the at least one function with the encrypted data; creating an exclusive interface to provide access to the at least one function, wherein, upon determining that at least one condition from the conditions is satisfied, grants access to the at least one function, and wherein the interface, upon determining that no conditions are satisfied, denies access to the at least one function, wherein the determining comprises checking a context in which the at least one function is being invoked by based on: (i) a computing environment in which the at least one function is invoked, (ii) a number of times the at least one function is invoked, and (iii) whether any conflicts of interest arise between an owner of the data structure and a consumer of the data structure when the at least one function is invoked; and including the encrypted data, the associated at least one function, software necessary to execute the at least one function, the data structure, and the interface into an object; wherein executable software necessary to determine whether the conditions are satisfied is included in the object, wherein the software necessary to determine whether the conditions are satisfied is only accessible by the interface.

14. The computer-readable medium of claim 13 , wherein the at least one condition specifies an authorized user with access to the at least one function.

15. The computer-readable medium of claim 13 , wherein the at least one condition specifies a time period for accessing the at least one function.

16. The computer-readable medium of claim 13 , wherein the at least one condition specifies a maximum number of times that the at least one function can be executed.

17. The computer-readable medium of claim 13 , wherein the at least one condition specifies any conflicts of interest arising from execution of the at least one function.

18. The computer-readable medium of claim 13 , wherein the interface grants access to the at least one function upon determining that all the conditions are satisfied.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2013
From: ZIELINSKI, MAREK PIOTR; ELOFF, JAN HARM PETRUS
To: SAP AG
Reel/Frame 030616/0820 →
Continuity (1)
Related Publication 20140372768A1 · Dec 18, 2014