IP Library Granted Patent US 11,361,099
Granted Patent B2
US 11,361,099 · App. 16/547,738 · Granted Jun 14, 2022

Encrypting data records and processing encrypted records without exposing plaintext

Inventors: Aviad Lahav (Tel-Aviv, IL); Lev Rosenblit (Shoam, IL)
Assignee: RingCentral, Inc.
G06F21/6227G06F16/901G06F16/9038G06F16/90348G06F21/602G06F21/64H04L9/0643H04L9/0825H04L9/0891H04L9/0894H04L9/3239H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,361,099
App. No.
16/547,738
Granted
Jun 14, 2022
Kind
B2
Abstract

A computer implemented method of applying a unified search for a match of one or more features in a plurality of encrypted records, comprising using one or more processors of a server associated with a database comprising a plurality of encrypted records. The processor(s) is adapted for receiving a query for searching one or more plaintext features in the plurality of encrypted, searching for a match of the one or more plaintext features using a first search methodology and a second search methodology and outputting an indication of matching encrypted records according to the match. Wherein the second search methodology is asymptotically faster than the first search methodology and wherein the first search methodology is used for searching a subset of the plurality of encrypted records selected based on status indication associated with each encrypted record.

Claims (20)

1. A computer implemented method of re-encrypting encrypted records stored in a database for distribution to a plurality of clients, comprising:

storing in the database at least one encrypted record received from a first client, the at least one encrypted record is encrypted by the first client using a first key;

receiving, from a second client, a request to provide the at least one encrypted record;

retrieving from a repository of re-encryption keys a second key associated with the second client;

re-encrypting the at least one encrypted record by applying at least one proxy, re-encryption algorithm using the second key;

providing the at least one re-encrypted record to the second client, the second client decrypts the at least one re-encrypted record using a decryption key;

receiving a revocation request for removing the second client from a list of trusted computing nodes; and

removing the second key from the repository of re-encryption keys based on the received revocation request.

2. The computer implemented method of claim 1 , further comprising re-encrypting the at least one encrypted record stored in the database using a rotation key generated from the first key and the second key.

3. The computer implemented method of claim 1 , further comprising re-encrypting the at least one encrypted record stored in the database using a rotation key generated from a new first key and the second key, as a backup mechanism.

4. The computer implemented method of claim 1 , further comprising re-encrypting the at least one encrypted record stored in the database using a rotation key generated from the first key and a new second key, as a backup mechanism.

5. A computer implemented method of providing fine-grained control over access to data by re-encrypting encrypted records stored in a database for distribution between a plurality of clients, comprising:

storing in the database at least one encrypted record received from a first client, the at least one encrypted record is encrypted by the first client using a first key;

receiving, from a second client, a request to provide the at least one encrypted record;

performing fine-grained control by cryptographically permitting access to data encrypted by the first client with the first key to the second client with a second key;

retrieving from a repository of re-encryption keys the second key associated with the second client;

re-encrypting the at least one encrypted record by applying at least one proxy re-encryption algorithm using the second key; and

providing the at least one re encrypted record to the second client, the second client decrypts the at least one re-encrypted record using a decryption key;

receiving a revocation request for removing the second client from a list of trusted computing nodes; and

removing the second key from the repository of re-encryption keys based on the received revocation request.

Assignments (4)
SECURITY INTEREST Recorded Feb 14, 2023
From: RINGCENTRAL, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062973/0194 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: ROSENBLIT, LEV
To: RINGCENTRAL, INC.
Reel/Frame 059868/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: KINDITE LTD.
To: RINGCENTRAL, INC.
Reel/Frame 056272/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2019
From: LAHAV, AVIAD
To: KINDITE LTD.
Reel/Frame 050130/0124 →
Continuity (3)
Continuation PCTIL2018050210 · Feb 22, 2018
Provisional Application 62461808 · Feb 22, 2017
Related Publication 20190384931A1 · Dec 19, 2019