IP Library › Granted Patent US 12,443,728
Granted Patent B2
US 12,443,728 · App. 18/341,241 · Granted Oct 14, 2025

Restricting data access to target databases

Inventors: Felix Beier (Haigerloch, DE); Eirini Kalogeiton (Stuttgart, DE); Vassil Radkov Dimov (Stuttgart, DE); Jens Müller (Stuttgart, DE); Johannes Severin Kern (Boeblingen, DE)
Assignee: International Business Machines Corporation
G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,443,728
App. No.
18/341,241
Granted
Oct 14, 2025
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for performing data synchronization between a source DBMS, comprising a trusted database, and a target DBMS, comprising an untrusted datastore and a trusted datastore, is disclosed. The present invention may include upon the source DBMS performing an update to an object in the trusted source database, sending the object change to a trusted data replication engine, encrypting the object change, sending the encrypted object change with a related decryption key to the target DBMS, upon receiving the encrypted object change and the related decryption key at the target DBMS, searching an object related to the object change in the untrusted target data store, identifying a decryption key for the searched object, replacing the identified decryption key by the received decryption key, and integrating the encrypted object change in encrypted form into the untrusted target data store.

Claims (48)

1. A computer-implemented method for performing data synchronization between a source database management system, comprising a trusted source database, and a target database management system, comprising a target database, comprising an untrusted target data store and a trusted target data store, the method comprising:

upon the source database management system performing an update to an object in the trusted source database, wherein the update to the object relates to an object change, sending the object change to a trusted data replication engine;

generating, at the trusted data replication engine, a new encryption key for the object change, wherein the new encryption key replaces a previous key in a key ring store;

encrypting the object change with the new encryption key;

sending the encrypted object change together with the new encryption key to the target database management system;

upon receiving the encrypted object change and the new encryption key the target database management system, replacing the previous key in its trusted data store key ring with the new encryption key;

and

integrating the encrypted object change in encrypted form into the untrusted target data store.

2. The method of claim 1 , wherein the encryption of the object change is performed by the trusted data replication engine.

3. The method of claim 2 , further comprising:

maintaining a set of decryption keys by the trusted data replication engine related to encryption keys used by the trusted data replication engine.

4. The method of claim 3 , wherein each decryption key of the set of decryption keys has a unique identifier compatible with an object identifier for objects in the trusted source database, such that each object is mappable to a related decryption key.

5. The method of claim 3 , wherein the set of decryption keys is implemented using a hash table; and wherein one or more decryption keys in the set of decryption keys has an automatic key expiration rule.

6. The method of claim 3 , wherein the set of decryption keys is stored in the trusted target data store.

7. The method of claim 1 , wherein the encryption of the object change is performed using the related encryption key.

8. The method of claim 1 , further comprising:

upon receiving a query for an object in the target database, retrieving a corresponding latest encrypted object version from the untrusted target data store;

retrieving a decryption key from its trusted data store key ring corresponding to the queried object; and

decrypting the latest encrypted object version using the retrieved decryption key.

9. A database management system for data synchronization between a source database management system, comprising a trusted source database, and a target database management system, comprising a target database, comprising an untrusted target data store and a trusted target data store, the database management system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the database management system is capable of performing a method comprising:

upon the source database management system performing an update to an object in the trusted source database, wherein the update to the object relates to an object change, sending the object change to a trusted data replication engine;

generating, at the trusted data replication engine, a new encryption key for the object change, wherein the new encryption key replaces a previous key in a key ring store;

encrypting the object change with the new encryption key;

sending the encrypted object change together with the new encryption key to the target database management system;

upon receiving the encrypted object change and the new encryption key the target database management system, replacing the previous key in its trusted data store key ring with the new encryption key;

and

integrating the encrypted object change in encrypted form into the untrusted target data store.

10. The database management system of claim 9 , further comprising:

a trusted data replication engine for the encryption of the object change.

11. The database management system of claim 10 , wherein the trusted data replication engine maintains a set of decryption keys, thereby relating to encryption keys used by the trusted data replication engine.

12. The database management system of claim 11 , wherein each decryption key of the set of decryption keys has a unique identifier compatible with an object identifier for objects in the trusted source database, such that each object is mappable to a related decryption key.

13. The database management system of claim 11 , wherein the set of decryption keys is implemented using a hash table.

14. The database management system of claim 13 , wherein the set of decryption keys is stored in the trusted target data store.

15. The database management system of claim 9 , wherein the encryption of the object change is performed using the related encryption key.

16. The database management system of claim 9 , further comprising:

upon receiving a query for an object in the target database, retrieving a corresponding latest encrypted object version from the untrusted target data store;

retrieving a decryption key from its trusted data store key ring corresponding to the queried object; and

decrypting the latest encrypted object version using the retrieved decryption key.

17. A computer program product for performing data synchronization between a source database management system, comprising a trusted source database, and a target database management system, comprising a target database, comprising an untrusted target data store and a trusted target data store, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor to cause the processor to perform a method comprising:

upon the source database management system performing an update to an object in the trusted source database, wherein the update to the object relates to an object change, sending the object change to a trusted data replication engine;

generating, at the trusted data replication engine, a new encryption key for the object change, wherein the new encryption key replaces a previous key in a key ring store;

encrypting the object change with the new encryption key;

sending the encrypted object change together with the new encryption key to the target database management system;

upon receiving the encrypted object change and the new encryption key the target database management system, replacing the previous key in its trusted data store key ring with the new encryption key;

and

integrating the encrypted object change in encrypted form into the untrusted target data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2023
From: BEIER, FELIX; KALOGEITON, EIRINI; DIMOV, VASSIL RADKOV; MÜLLER, JENS; KERN, JOHANNES SEVERIN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064059/0504 →
Continuity (1)
Related Publication 20240427909A1 · Dec 26, 2024
References Cited (17)
US 7200747B2 · Riedel · 2007 [cited by applicant]
US 8458451B2 · Shasha · 2013 [cited by applicant]
US 10706039B2 · Beier · 2020 [cited by applicant]
US 11003787B2 · Sion · 2021 [cited by applicant]
US 20060123250A1 · Maheshwari · 2006 [cited by examiner]
US 20100318812A1 · Auradkar · 2010 [cited by applicant]
US 20150178506A1 · Elovici · 2015 [cited by examiner]
US 20190121887A1 · Beier · 2019 [cited by examiner]
US 20190121892A1 · Beier · 2019 [cited by examiner]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty, Sep. 20, 2… [cited by applicant]
Amazon, “Replicating objects created with server-side encryption (SSE) using KMS keys,” Amazon Simple Storage Service—User Guide, Mar. 1, 2006 [accessed on Jun. 1, 2023], 9 pages, Retrieved from the Internet: <URL: http… [cited by applicant]
Hashicorp, “Manage Secrets & Protect Sensitive Data,” vaultproject.io [online], Datasheet, [accessed on Jun. 1, 2023], 4 pages, Retrieved from the Internet: <URL: Vault: https://www.vaultproject.io/>. [cited by applicant]
IBM Security, “IBM Security Guardium Key Lifecycle Manager,” IBM [online], [accessed on Jun. 1, 2023], 6 pages, Retrieved from the Internet: <URL: https://www.ibm.com/products/ibm-security-key-lifecycle-manager>. [cited by applicant]
IBM, “DB2 Analytics Accelerator for z/OS 7.5,” IBM [online], [accessed on Jun. 1, 2023], 2 pages, Retrieved from the Internet: <URL: https://www.ibm.com/docs/en/daafz/7.5>. [cited by applicant]
IBM, “Db2 Data Gate on Cloud Pak for Data,” IBM [online], May 26, 2022 [accessed on Jun. 1, 2023], 2 pages, Retrieved from the Internet: <URL: https://www.ibm.com/docs/en/cloud-paks/cp-data/4.0>. [cited by applicant]
IBM, “Making queries wait for incremental updates,” IBM [online], Dec. 14, 2022 [accessed on Jun. 1, 2023], 6 pages, Retrieved from the Internet: <URL: https://www.ibm.com/docs/en/daafz/7.5?topic=continually-making-quer… [cited by applicant]
IBM, “Making queries wait for synchronization updates,” IBM [online], Apr. 27, 2022 [accessed on Jun. 1, 2023], 4 pages, Retrieved from the Internet: <URL: https://www.ibm.com/docs/en/cloud-paks/cp-data/4.0?topic=gate-w… [cited by applicant]