IP Library › Granted Patent US 12,204,670
Granted Patent B2
US 12,204,670 · App. 17/656,673 · Granted Jan 21, 2025

Using smart contracts to manage hyper protect database as a service

Inventors: Peng Hui Jiang (Beijing, CN); Timo Kussmaul (Boeblingen, DE); Stefan Schmitt (Holzgerlingen, DE); Xiang Dong Hu (Beijing, CN)
Assignee: International Business Machines Corporation
G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,204,670
App. No.
17/656,673
Granted
Jan 21, 2025
Kind
B2
Abstract

Building and using a smart contract in order to resolve the isolation between database users and service operators for hyper-protect database as a service (DBaaS). The use of the smart contract in the hyper-protect DBaaS environment allows the service operator to perform operations on sensitive and secure data in the database owned by a user without necessarily revealing the content of the sensitive and secure data.

Claims (38)

1. A computer-implemented method (CIM) comprising:

providing a hyper-protect secure container, with the hyper-protect secure container including a plurality of access layers, with at least a first access layer being accessible by a database user and a second access layer being accessible by a service operator;

identifying a group of managed objects within the hyper-protect secure container that can be managed by a smart contract;

creating the smart contract, with the smart contract including information indicative of a set of user specified instructions for managing the group of managed objects within the hyper-protect secure container, wherein the smart contract includes additional instructions for various functions comprising performing a backup and restore function on data stored in the hyper-protect secure container and monitoring and alerting the database user with respect to meaningful changes to the data;

receiving an agreement between the database user and the service operator to deploy the smart contract to manage the hyper-protect secure container; and

performing, by the smart contract, the set of user specified instructions for the group of managed objects within the hyper-protect secure container.

2. The CIM of claim 1 wherein a first instruction of the set of user specified instructions for the group of managed objects is validating a first condition to execute the smart contract.

3. The CIM of claim 1 wherein a second instruction of the set of user specified instructions for the group of managed objects is validating a first input to execute the smart contract.

4. The CIM of claim 1 wherein a third instruction of the set of user specified instructions for the group of managed objects is validating a first output to execute the smart contract.

5. The CIM of claim 1 wherein a fourth instruction of the set of user specified instructions is generating a filtered output for the database user.

6. The CIM of claim 1 wherein a fifth instruction of the set of user specified instructions is generating a filtered output for the service operator.

7. A computer program product (CPP) comprising:

a machine readable storage device; and

computer code stored on the machine readable storage device, with the computer code including instructions and data for causing a processor(s) set to perform operations including the following:

providing a hyper-protect secure container, with the hyper-protect secure container including a plurality of access layers, with at least a first access layer being accessible by a database user and a second access layer being accessible by a service operator,

identifying a group of managed objects within the hyper-protect secure container that can be managed by a smart contract,

creating the smart contract, with the smart contract including information indicative of a set of user specified instructions for managing the group of managed objects within the hyper-protect secure container, wherein the smart contract includes additional instructions for various functions comprising performing a backup and restore function on data stored in the hyper-protect secure container and monitoring and alerting the database user with respect to meaningful changes to the data,

receiving an agreement between the database user and the service operator to deploy the smart contract to manage the hyper-protect secure container, and

performing, by the smart contract, the set of user specified instructions for the group of managed objects within the hyper-protect secure container.

8. The CPP of claim 7 wherein a first instruction of the set of user specified instructions for the group of managed objects is validating a first condition to execute the smart contract.

9. The CPP of claim 7 wherein a second instruction of the set of user specified instructions for the group of managed objects is validating a first input to execute the smart contract.

10. The CPP of claim 7 wherein a third instruction of the set of user specified instructions for the group of managed objects is validating a first output to execute the smart contract.

11. The CPP of claim 7 wherein a fourth instruction of the set of user specified instructions is generating a filtered output for the database user.

12. The CPP of claim 7 wherein a fifth instruction of the set of user specified instructions is generating a filtered output for the service operator.

13. A computer system (CS) comprising:

a processor(s) set;

a machine readable storage device; and

computer code stored on the machine readable storage device, with the computer code including instructions and data for causing the processor(s) set to perform operations including the following:

providing a hyper-protect secure container, with the hyper-protect secure container including a plurality of access layers, with at least a first access layer being accessible by a database user and a second access layer being accessible by a service operator,

identifying a group of managed objects within the hyper-protect secure container that can be managed by a smart contract,

creating the smart contract, with the smart contract including information indicative of a set of user specified instructions for managing the group of managed objects within the hyper-protect secure container, wherein the smart contract includes additional instructions for various functions comprising performing a backup and restore function on data stored in the hyper-protect secure container and monitoring and alerting the database user with respect to meaningful changes to the data,

receiving an agreement between the database user and the service operator to deploy the smart contract to manage the hyper-protect secure container, and

performing, by the smart contract, the set of user specified instructions for the group of managed objects within the hyper-protect secure container.

14. The CS of claim 13 wherein a first instruction of the set of user specified instructions for the group of managed objects is validating a first condition to execute the smart contract.

15. The CS of claim 13 wherein a second instruction of the set of user specified instructions for the group of managed objects is validating a first input to execute the smart contract.

16. The CS of claim 13 wherein a third instruction of the set of user specified instructions for the group of managed objects is validating a first output to execute the smart contract.

17. The CS of claim 13 wherein a fourth instruction of the set of user specified instructions is generating a filtered output for the database user.

18. The CS of claim 13 wherein a fifth instruction of the set of user specified instructions is generating a filtered output for the service operator.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2022
From: JIANG, PENG HUI; KUSSMAUL, TIMO; SCHMITT, STEFAN; HU, XIANG DONG
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 059409/0401 →
Continuity (1)
Related Publication 20230315880A1 · Oct 5, 2023
References Cited (26)
US 7353180B1 · Silverstone · 2008 [cited by applicant]
US 10715339B1 · Wei · 2020 [cited by examiner]
US 11042400B1 · Holsman · 2021 [cited by applicant]
US 11049099B2 · Yan · 2021 [cited by examiner]
US 11418511B2 · Fang · 2022 [cited by examiner]
US 11640546B2 · Corning · 2023 [cited by examiner]
US 20190050855A1 · Martino · 2019 [cited by examiner]
US 20190058696A1 · Bowman · 2019 [cited by examiner]
US 20190158275A1 · Beck · 2019 [cited by applicant]
US 20190370358A1 · Nation · 2019 [cited by examiner]
US 20200034353A1 · Innocenti · 2020 [cited by applicant]
US 20200151708A1 · Sui · 2020 [cited by examiner]
US 20200167503A1 · Wei · 2020 [cited by examiner]
US 20200322129A1 · Wei · 2020 [cited by examiner]
US 20210004794A1 · Kumar Kumaresan · 2021 [cited by applicant]
US 20210126777A1 · Mash · 2021 [cited by examiner]
US 20210232662A1 · Corning · 2021 [cited by examiner]
CN 106775619A · 2017 [cited by applicant]
CN 108681943A · 2018 [cited by applicant]
CN 112035090A · 2020 [cited by applicant]
WO 2017153495A1 · 2017 [cited by applicant]
WO WO2020058993A1 · 2020 [cited by examiner]
Chinese Patent CN 112035090 A with English language translation (Year: 2020). [cited by examiner]
“Patent Cooperation Treaty PCT International Search Report”, Applicant's File Reference: EIE230086PCT, International Application No. PCT/CN2023/074955, International Filing Date: Feb. 8, 2023, Date of Mailing: May 17, 2… [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, NIST National Institute of Standards and Technology U.S. Department of Commerce, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Vizitei, Yuri, “Lacero Combines Policy Enforcement with Blockchain to Deliver Unprecedented Security”, IBM Cloud Blog, Blockchain, Aug. 2, 2021, 7 pages, <https://www.IBM.com/cloud/blog/lacero-combines-policy-enforcemen… [cited by applicant]