IP Library Granted Patent US 11,568,078
Granted Patent B2
US 11,568,078 · App. 16/934,415 · Granted Jan 31, 2023

Obfuscation of queries and responses in a security data search system

Inventor: Pulleswararao Naga Vandanapu (Redwood City, CA)
Assignee: Constella Intelligence, Inc.
G06F21/6227G06F21/31G06F21/602G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,568,078
App. No.
16/934,415
Granted
Jan 31, 2023
Kind
B2
Abstract

A method comprises: generating a first partial hash of the user identity information, transmitting a first query to a server computer, in response to transmitting the first query, receiving query metrics that indicate a set of counts of expected results, determining whether a count of expected results of the first partial hash satisfies a threshold count of expected results, in response to determining that the count of expected results of the first partial hash satisfies the threshold: generating and transmitting a second query, and in response, receiving and storing a set of user identity records that match at least the first partial hash, querying the set of user identity records using the user identity information and in response, receiving a result set of user identity records, the result set of user identity records comprising one or more user identity records that match the user identity information.

Claims (56)

1. A computer-implemented method providing an improvement in computer security by partial obfuscation of data records in result sets resulting from search queries, the method comprising:

based on user identity information that forms a target of a computer database search strategy, generating a first partial hash of the user identity information, the first partial hash comprising a plurality of characters;

generating and transmitting a first query to a server computer, the first query comprising a subset of characters of the plurality of characters of the first partial hash;

in response to transmitting the first query to the server computer, receiving query metrics that indicate a set of counts of expected results associated with the subset of characters, the set of counts of expected results including a plurality of partial hashes and corresponding values of expected results, the plurality of partial hashes including the first partial hash;

determining, based on the query metrics, whether a count of expected results of the first partial hash satisfies a threshold count of expected results;

in response to determining that the count of expected results of the first partial hash satisfies the threshold count of expected results: generating and transmitting a second query to a server computer, the second query being based on the first partial hash, and in response, receiving and storing a set of user identity records that match at least the first partial hash;

querying the set of user identity records using the user identity information and in response, receiving a result set of user identity records, the result set of user identity records comprising one or more user identity records that match the user identity information.

2. The method of claim 1 , further comprising:

in response to determining that the count of expected results of the first partial hash does not satisfy the threshold count of expected results:

selecting a second partial hash from the set of counts of expected results associated with the subset of characters;

determining, based on the query metrics, whether a total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results.

3. The method of claim 2 , further comprising:

in response to determining that the total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results:

generating and transmitting a third query to the server computer based on the first partial hash and the second partial hash and in response, receiving and storing the set of user identity records that match at least the first partial hash and the second partial hash.

4. The method of claim 2 , wherein the second partial hash comprises the subset of characters of the first partial hash and at least one other character.

5. The method of claim 1 , wherein the user identity information comprises at least one of: a username, an email address, a password, a credit card number, or a geolocation.

6. The method of claim 1 , wherein the result set of user identity records is unhashed.

7. The method of claim 1 , wherein the set of user identity records includes one or more user identity records that match the user identity information and includes one or more user identity records that do not do not match the user identity information.

8. The method of claim 1 , wherein the set of user identity records is stored in memory.

9. A computer-implemented method providing an improvement in computer security by partial obfuscation of data records in result sets resulting from search queries comprising:

storing, in one or more digital data repositories, query metrics that indicate a set of counts of expected results for a plurality of partial hashes;

based on user identity information that forms a target of a computer database search strategy, generating a first partial hash of the user identity information, the first partial hash comprising a plurality of characters;

generating and submitting a local query to the one or more digital data repositories, the local query comprising a subset of characters of the plurality of characters of the first partial hash;

in response to submitting the local query to the one or more digital data repositories, receiving query metrics that indicate a set of counts of expected results associated with the subset of characters, the set of counts of expected results including a plurality of partial hashes and corresponding values of expected results, the plurality of partial hashes including the first partial hash;

determining, based on the query metrics, whether a count of expected results of the first partial hash satisfies a threshold count of expected results;

in response to determining that the count of expected results of the first partial hash satisfies the threshold count of expected results: generating and transmitting a remote query to a server computer based on the first partial hash and in response, receiving and storing a set of user identity records that match at least the first partial hash;

querying the set of user identity records using the user identity information and in response, receiving a result set of user identity records, the result set of user identity record comprising one or more user identity records that match the user identity information.

10. The method of claim 9 , further comprising:

in response to determining that the count of expected results of the first partial hash does not satisfy the threshold count of expected results:

selecting a second partial hash from the set of counts of expected results associated with the subset of characters;

determining, based on the query metrics, whether a total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results.

11. The method of claim 10 , further comprising:

in response to determining that the total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results:

generating and transmitting a remote query to the server computer based on the first partial hash and the second partial hash and in response, receiving and storing the set of user identity records that match at least the first partial hash and the second partial hash.

12. The method of claim 10 , wherein the second partial hash comprises the subset of characters of the first partial hash and at least one other character.

13. The method of claim 9 , wherein the query metrics are received in a compressed format with an implicit index.

14. The method of claim 9 , wherein the query metrics are received and stored periodically.

15. The method of claim 9 , wherein the set of user identity records is stored in memory.

16. The method of claim 9 , wherein the set of user identity records includes one or more user identity records that match the user identity information and includes one or more user identity records that do not do not match the user identity information.

17. A computer system comprising:

one or more processors;

one or more memories storing instructions which, when executed by the one or more processors, cause the one or more processors to perform:

based on user identity information that forms a target of a computer database search strategy, generating a first partial hash of the user identity information, the first partial hash comprising a plurality of characters;

generating and transmitting a first query to a server computer, the first query comprising a subset of characters of the plurality of characters of the first partial hash;

in response to transmitting the first query to the server computer, receiving query metrics that indicate a set of counts of expected results associated with the subset of characters, the set of counts of expected results including a plurality of partial hashes and corresponding values of expected results, the plurality of partial hashes including the first partial hash;

determining, based on the query metrics, whether a count of expected results of the first partial hash satisfies a threshold count of expected results;

in response to determining that the count of expected results of the first partial hash satisfies the threshold count of expected results: generating and transmitting a second query to a server computer, the second query being based on the first partial hash, and in response, receiving and storing a set of user identity records that match at least the first partial hash;

querying the set of user identity records using the user identity information and in response, receiving a result set of user identity records, the result set of user identity records comprising one or more user identity records that match the user identity information.

18. The system of claim 17 , further comprising:

in response to determining that the count of expected results of the first partial hash does not satisfy the threshold count of expected results:

selecting a second partial hash from the set of counts of expected results associated with the subset of characters;

determining, based on the query metrics, whether a total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results.

19. The system of claim 18 , further comprising:

in response to determining that the total count of expected results of the first partial hash and the second partial hash satisfies the threshold count of expected results:

generating and transmitting a third query to the server computer based on the first partial hash and the second partial hash and in response, receiving and storing the set of user identity records that match at least the first partial hash and the second partial hash.

20. The system of claim 18 , wherein the second partial hash comprises the subset of characters of the first partial hash and at least one other character.

Assignments (3)
SECURITY INTEREST Recorded Jun 4, 2024
From: CONSTELLA INTELLIGENCE, INC.
To: COMERICA BANK
Reel/Frame 067620/0001 →
CHANGE OF NAME Recorded Jul 15, 2021
From: 4IQ, INC.
To: CONSTELLA INTELLIGENCE, INC.
Reel/Frame 056889/0937 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2020
From: VANDANAPU, PULLESWARARAO NAGA
To: 4IQ, INC.
Reel/Frame 053266/0690 →
Continuity (1)
Related Publication 20220027497A1 · Jan 27, 2022
Cited By (2)
US 12,468,621 US 12,475,109