IP Library Granted Patent US 10,769,293
Granted Patent B2
US 10,769,293 · App. 16/268,500 · Granted Sep 8, 2020

Privacy preserving data search

Inventors: Yigal Rozenberg (Wilton, CT); Ulf Mattsson (Cos Cob, CT)
Assignee: Protegrity Corporation
G06F21/6218G06F21/6227G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,769,293
App. No.
16/268,500
Granted
Sep 8, 2020
Kind
B2
Abstract

Database entries can be protected by indexing the entries using a plurality of indexes, each associated with a level of access rights. A level of access rights can be determined from a search query, and an index can be selected based on the determined level of access rights. A search key can be generated based on the received query, and the selected index can be searched using the search query. Database entries mapped to the values of the selected index returned in response to the search can be outputted. Each index is associated with a different granularity defining the number and/or ambiguity of search results returned in response to searching an index.

Claims (41)

1. A method for data protection in a computer system associated with a plurality of levels of access rights, the method comprising:

receiving, from a requesting entity, a query to search a database indexed with each of a plurality of indexes, each index associated with a different access rights level and including a plurality of values each mapped to a different set of database entries;

generating, by a hardware processor, a search key based on the received query;

hashing the generated search key using a hash table;

maintaining a leading portion of the hashed search key and discarding the remainder of the hashed search key to produce a shortened hashed search key;

searching, by the hardware processor, an index corresponding to an access rights level associated with the requesting entity by comparing the shortened hashed search key to a leading portion of hashed index values of the searched index to identify a set of index values; and

outputting database entries mapped to the identified set of index values.

2. The method of claim 1 , wherein each index of the plurality of indexes is associated with an index granularity defined by an average number of database entries mapped to the same index value.

3. The method of claim 2 , wherein a first access rights level associated with a first index of a first granularity is associated with a greater amount of permissible access to the database than a second access rights level associated with a second index of a second granularity lower than the first granularity.

4. The method of claim 3 , wherein the number of outputted database entries is on average lower if the requesting entity is associated with the first access rights level than if the requesting entity is associated with the second access rights level.

5. The method of claim 1 , wherein the database entries are encrypted, and further comprising:

decrypting the outputted database entries.

6. The method of claim 1 , wherein the generated search key is based on text included within the received query.

7. A information retrieval system comprising:

a non-transitory computer-readable storage medium storing executable computer instructions that, when executed, perform steps comprising:

receiving, from a requesting entity, a query to search a database indexed with each of a plurality of indexes, each index associated with a different access rights level and including a plurality of values each mapped to a different set of database entries;

generating a search key based on the received query;

hashing the generated search key using a hash table;

maintaining a leading portion of the hashed search key and discarding the remainder of the hashed search key to produce a shortened hashed search key;

searching an index corresponding to an access rights level associated with the requesting entity by comparing the shortened hashed search key to a leading portion of hashed index values of the searched index to identify a set of index values; and

outputting database entries mapped to the identified set of index values; and

a hardware processor configured to execute the computer instructions.

8. The system of claim 7 , wherein each index of the plurality of indexes is associated with an index granularity defined by an average number of database entries mapped to the same index value.

9. The system of claim 8 , wherein a first access rights level associated with a first index of a first granularity is associated with a greater amount of permissible access to the database than a second access rights level associated with a second index of a second granularity lower than the first granularity.

10. The system of claim 9 , wherein the number of outputted database entries is on average lower if the requesting entity is associated with the first access rights level than if the requesting entity is associated with the second access rights level.

11. The system of claim 7 , wherein the database entries are encrypted, and wherein the instructions, when executed, are further configured to perform steps comprising:

decrypting the outputted database entries.

12. The system of claim 7 , wherein the generated search key is based on text included within the received query.

13. A non-transitory computer-readable storage medium storing executable computer instructions that, when executed, are configured to perform steps comprising:

receiving, from a requesting entity, a query to search a database indexed with each of a plurality of indexes, each index associated with a different access rights level and including a plurality of values each mapped to a different set of database entries;

generating, by a hardware processor, a search key based on the received query;

hashing the generated search key using a hash table;

maintaining a leading portion of the hashed search key and discarding the remainder of the hashed search key to produce a shortened hashed search key;

searching, by the hardware processor, an index corresponding to an access rights level associated with the requesting entity by comparing the shortened hashed search key to a leading portion of hashed index values of the searched index to identify a set of index values; and

outputting database entries mapped to the identified set of index values.

14. The non-transitory computer-readable storage medium of claim 13 , wherein each index of the plurality of indexes is associated with an index granularity defined by an average number of database entries mapped to the same index value.

15. The non-transitory computer-readable storage medium of claim 14 , wherein a first access rights level associated with a first index of a first granularity is associated with a greater amount of permissible access to the database than a second access rights level associated with a second index of a second granularity lower than the first granularity.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the number of outputted database entries is on average lower if the requesting entity is associated with the first access rights level than if the requesting entity is associated with the second access rights level.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the database entries are encrypted, and wherein the instructions, when executed, are further configured to perform steps comprising:

decrypting the outputted database entries.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the generated search key is based on text included within the received query.

Assignments (3)
SECURITY INTEREST Recorded Aug 2, 2024
From: PROTEGRITY USA, INC.; PROTEGRITY LIMITED HOLDING, LLC; PROTEGRITY US HOLDING, LLC; PROTEGRITY CORPORATION; KAVADO, LLC
To: CANADIAN IMPERIAL BANK OF COMMERCE
Reel/Frame 068326/0020 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PROTEGRITY CORPORATION
To: PROTEGRITY US HOLDING, LLC
Reel/Frame 067566/0462 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2019
From: MATTSSON, ULF; ROZENBERG, YIGAL
To: PROTEGRITY CORPORATION
Reel/Frame 048256/0104 →
Continuity (4)
Continuation 15697031 · Sep 6, 2017
Continuation 14034470 · Sep 23, 2013
Provisional Application 61704667 · Sep 24, 2012
Related Publication 20190171839A1 · Jun 6, 2019