IP Library Granted Patent US 12,287,897
Granted Patent B2
US 12,287,897 · App. 17/325,405 · Granted Apr 29, 2025

Field level encryption searchable database system

Inventor: Freeman Parks (Indianapolis, IN)
Assignee: Salesforce, Inc.
G06F21/6227G06F16/2282G06F16/288G06F21/602G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,897
App. No.
17/325,405
Granted
Apr 29, 2025
Kind
B2
Abstract

A request to search a database field in a database table for a query value may be received. The query value may be hashed with a designated hash function and a designated hash key to produce a designated keyed-hash value. A row in the database table may be identified based on the designated keyed-hash value. The identified row may include a keyed-hash field value that matches the designated keyed-hash value. The identified row may include an encrypted field value generated by encrypting an unencrypted field value matching the query value. One or more data values associated with the identified row may be transmitted in response to the request.

Claims (25)

1. A method comprising:

receiving via a communication interface a request to search a database field in a database table for a query value, the database table storing a plurality of rows including a corresponding plurality of keyed-hash values generated at the database system based on a plurality of cryptographic hash keys, and a plurality of cryptographic hash key identifiers identifying the plurality of cryptographic hash keys, wherein a first row in the database table includes a first initialization vector, and wherein a second row in the database table includes a second initialization vector different from the first initialization vector, and wherein the first row includes a first encrypted field value encrypted based on the first initialization vector and wherein the second row includes a second encrypted field value encrypted based on the second initialization vector;

identifying a designated encryption context based on the request, the designated encryption context indicating a designated cryptographic hash key of the plurality of cryptographic hash keys and a corresponding cryptographic hash key identifier of the plurality of cryptographic hash key identifiers based on the request, the designated encryption context being one of a plurality of encryption contexts associated with the database table, wherein the database table is a multitenant database table storing data owned by a plurality of entities, and wherein the designated encryption context is specific to a designated one of the plurality of entities;

hashing the query value via a processor with a designated keyed-hash function and the designated cryptographic hash key to produce a designated keyed-hash value;

identifying a row in the database table based on the encryption context and the designated keyed-hash value, the identified row including a keyed-hash field value that matches the designated keyed-hash value, the identified row further including a cryptographic hash key identifier that identifies the designated cryptographic hash key and that matches the corresponding cryptographic hash key identifier, the identified row including an encrypted field value generated by encrypting an unencrypted field value matching the query value; and

transmitting via the communication interface one or more data values associated with the identified row in response to the request.

2. The method recited in claim 1 , wherein the encrypted field is encrypted using a designated initialization vector stored in the identified row and an encryption key.

3. The method recited in claim 1 , wherein the database table includes a first value encrypted using a first cryptographic encryption key stored in a hardware security module and a second value encrypted using a second cryptographic encryption key stored in a storage location outside the hardware security module.

4. The method recited in claim 1 , wherein the identified row includes a cryptographic encryption key identifier that identifies an encryption key used to encrypt the encrypted field value.

5. The method recited in claim 1 , wherein the identified row includes a cryptographic hash key identifier that identifies the designated cryptographic hash key.

6. The method recited in claim 1 , wherein a first row in the database table includes a first encrypted field value encrypted via a first encryption algorithm, and wherein a second row in the database table includes a second encrypted field value encrypted via a second encryption algorithm, the first and second encryption algorithms being different.

7. The method recited in claim 1 , wherein the database table is a dynamic schema database table that is associated with a plurality of data object definitions, a first row in the database table being associated with a first data object definition, a second row in the database table being associated with a second data object definition.

8. The method recited in claim 7 , wherein the designated encryption context is specific to a designated one of the plurality of data object definitions.

9. A database system implemented on a computer system, the database system comprising:

a communication interface operable to receive a request to search a database field in a database table for a query value, the database table storing a plurality of rows including a corresponding plurality of keyed-hash values generated at the database system based on a plurality of cryptographic hash keys, and a plurality of cryptographic hash key identifiers identifying the plurality of cryptographic hash keys, wherein a first row in the database table includes a first initialization vector, and wherein a second row in the database table includes a second initialization vector different from the first initialization vector, and wherein the first row includes a first encrypted field value encrypted based on the first initialization vector and wherein the second row includes a second encrypted field value encrypted based on the second initialization vector;

a processor operable to a designated encryption context based on the request, the designated encryption context indicating a designated cryptographic hash key of the plurality of cryptographic hash keys and a corresponding cryptographic hash key identifier of the plurality of cryptographic hash key identifiers based on the request, the designated encryption context being one of a plurality of encryption contexts associated with the database table, wherein the database table is a multitenant database table storing data owned by a plurality of entities, and wherein the designated encryption context is specific to a designated one of the plurality of entities; and

a query engine operable to identify a row in the database table based on the encryption context and the designated keyed-hash value, the identified row including a keyed-hash field value that matches the designated keyed-hash value, the identified row further including a cryptographic hash key identifier that identifies the designated cryptographic hash key and that matches the corresponding cryptographic hash key identifier, the identified row including an encrypted field value generated by encrypting an unencrypted field value matching the query value.

10. The database system recited in claim 9 , wherein the encrypted field is encrypted using a designated initialization vector stored in the identified row and an encryption key.

11. The database system recited in claim 9 , wherein the database table is a dynamic schema database table that is associated with a plurality of data object definitions, a first row in the database table being associated with a first data object definition, a second row in the database table being associated with a second data object definition.

12. One or more non-transitory computer readable media having instructions stored thereon for performing a method, the method comprising:

receiving via a communication interface a request to search a database field in a database table for a query value, the database table storing a plurality of rows including a corresponding plurality of keyed-hash values generated at the database system based on a plurality of cryptographic hash keys, and a plurality of cryptographic hash key identifiers identifying the plurality of cryptographic hash keys, wherein a first row in the database table includes a first initialization vector, and wherein a second row in the database table includes a second initialization vector different from the first initialization vector, and wherein the first row includes a first encrypted field value encrypted based on the first initialization vector and wherein the second row includes a second encrypted field value encrypted based on the second initialization vector;

identifying a designated encryption context based on the request, the designated encryption context indicating a designated cryptographic hash key of the plurality of cryptographic hash keys and a corresponding cryptographic hash key identifier of the plurality of cryptographic hash key identifiers based on the request, the designated encryption context being one of a plurality of encryption contexts associated with the database table, wherein the database table is a multitenant database table storing data owned by a plurality of entities, and wherein the designated encryption context is specific to a designated one of the plurality of entities;

hashing the query value via a processor with a designated keyed-hash function and the designated cryptographic hash key to produce a designated keyed-hash value;

identifying a row in the database table based on the encryption context and the designated keyed-hash value, the identified row including a keyed-hash field value that matches the designated keyed-hash value, the identified row further including a cryptographic hash key identifier that identifies the designated cryptographic hash key and that matches the corresponding cryptographic hash key identifier, the identified row including an encrypted field value generated by encrypting an unencrypted field value matching the query value; and

transmitting via the communication interface one or more data values associated with the identified row in response to the request.

Assignments (2)
CHANGE OF NAME Recorded Mar 27, 2025
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 070665/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2021
From: PARKS, FREEMAN
To: SALESFORCE.COM, INC.
Reel/Frame 056299/0224 →
Continuity (1)
Related Publication 20220374540A1 · Nov 24, 2022
References Cited (14)
US 9246686B1 · Holland · 2016 [cited by examiner]
US 11507283B1 · Olson · 2022 [cited by examiner]
US 11671251B1 · Copparapu · 2023 [cited by examiner]
US 20050223022A1 · Weissman · 2005 [cited by examiner]
US 20070136279A1 · Zhou · 2007 [cited by examiner]
US 20120016999A1 · Kieselbach · 2012 [cited by examiner]
US 20170222804A1 · Dewitt · 2017 [cited by examiner]
US 20180109378A1 · Fu · 2018 [cited by examiner]
US 20180337778A1 · Scheiblauer · 2018 [cited by examiner]
US 20190121892A1 · Beier · 2019 [cited by examiner]
US 20190149320A1 · Keselman · 2019 [cited by examiner]
US 20190236156A1 · Fanghaenel · 2019 [cited by examiner]
US 20200045037A1 · Parks et al. · 2020 [cited by applicant]
WO WO0146826A1 · 2001 [cited by examiner]