IP Library › Granted Patent US 10,476,662
Granted Patent B2
US 10,476,662 · App. 15/483,052 · Granted Nov 12, 2019

Method for operating a distributed key-value store

Inventors: Xingliang Yuan (New Territories, HK); Yu Guo (Shatin, HK); Xinyu Wang (New Territories, HK); Cong Wang (New Territories, HK)
Assignee: CITY UNIVERSITY OF HONG KONG
H04L9/06G06F12/1408G06F21/602G06F21/6227H04L9/0618H04L9/0894H04L9/3213G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,662
App. No.
15/483,052
Granted
Nov 12, 2019
Kind
B2
Abstract

A method for operating a distributed key-value store includes processing a data set comprised of data records each associated with a unique identifier and having one or more values associated with one or more attributes using a private key provided at a client device, thereby partitioning each of the data records based on the identifier and forming a plurality of encrypted identifier-value pairs for distributed storage across a plurality of server nodes operably connectable to the client device. The method also includes building, at the client device, encrypted indexes based on the type of query; and executing a query protocol in response to receiving a query from the client device so as to identify, using the built encrypted indexes, data distributively stored in the server nodes which matches the query. The invention also provides a related system for operating a distributed key-value store.

Claims (55)

1. A method for operating a NoSQL database with distributed key-value store, comprising:

(a) processing a data set comprised of data records, each of the data records having a unique identifier and including a respective value associated with one or more attributes using a private key provided at a client;

(b) partitioning the data records based on the identifier and forming a plurality of encrypted identifier-value pairs for distributed storage across a plurality of servers operably connected to the client device;

(c) storing the encrypted identifier-value pairs at the servers, wherein the distribution of the encrypted identifier-value pairs to the servers based on a consistent hashing ring maintained at the client device and which indicates a range of identifiers associated with each of the servers;

(d) building, at the client device, encrypted indexes for the encrypted identifier-value pairs;

(e) storing, at the servers, the respective built encrypted indexes, wherein each server stores local indexes associated with the local encrypted identifier-value pairs and not with encrypted identifier-value pairs in other servers;

(f) executing a query protocol in response to receiving a query from the client device so as to identify, using the built encrypted indexes, data distributively stored in the servers and which matches the query, wherein the execution comprises:

generating, at the client device, a token set including a plurality of tokens based on a condition attribute of the query;

transmitting the token set to each of the servers;

processing the tokens at each of the servers using local indexes associated with each respective server;

providing one or more encrypted identifiers of encrypted matched record to the client device;

decrypting, at the client device, the one or more encrypted identifiers; and

generating, at the client device, labels for obtaining the matched record.

2. The method of claim 1 , wherein the encrypted indexes are exact-match indexes which index the identifiers which respectively matches a same value for a corresponding attribute.

3. The method of claim 2 , wherein step (b) comprises tracking the values and recording a count for each of the values on the servers.

4. The method of claim 2 , wherein step (b) utilizes a searchable symmetric encryption method.

5. The method of claim 1 , further comprising storing the encrypted indexes at the client device.

6. The method of claim 1 , wherein the encrypted indexes are range-match indexes.

7. The method of claim 6 , wherein step (b) comprises tracking the values, recording a count for each of the values on the servers, and tracking order information of the values.

8. The method of claim 7 , wherein the order information is randomized.

9. The method of claim 7 , wherein

the token set further includes a token containing encrypted order information.

10. The method of claim 1 , wherein the identifiers are stored in the form of ciphertext at the client device.

11. The method of claim 1 , wherein the identifiers are stored in the form of ciphertext in the plurality of servers.

12. The method of claim 1 , further comprising inserting dummy identifier-value pairs into the plurality of servers.

13. The method of claim 1 , wherein step (c) is performed in at least two batches for the data distributively stored in the servers.

14. The method of claim 1 , wherein the servers are arranged in a cloud computing network.

15. A system for operating a NoSQL database with distributed key-value store, comprising:

a client device with a processor and a memory, configured to:

process a data set comprised of data records, each of the data records having a unique identifier and including a respective value associated with one or more attributes using a private key provided at the client device;

partition the data records based on the identifier and form a plurality of encrypted identifier-value pairs for distributed storage across a plurality of servers operably connected to the client device; and

build encrypted indexes for the encrypted identifier-value pairs;

a plurality of servers each having a processor and a memory, configured to:

store the encrypted identifier-value pairs, wherein the encrypted identifier-value pairs are distributively stored at the servers based on a consistent hashing ring maintained at the client device and which indicates a range of identifiers associated with each of the servers;

store the respective built encrypted indexes; wherein each server stores indexes associated with the local encrypted identifier-value pairs and not with encrypted identifier-value pairs in other servers;

wherein the client device and the servers are arranged to execute a query protocol in response to receiving a query from the client device so as to identify, using the built encrypted indexes, data distributively stored in the servers and which matches the query,

wherein the client device is arranged to:

generate a token set including a plurality of tokens based on a condition attribute of the query;

transmit the token set to each of the servers;

decrypt one or more encrypted identifiers of encrypted matched record provided from the servers; and

generate labels for obtaining the matched record; and

wherein each of the servers are arranged to:

process the tokens using local indexes associated with each respective server; and provide one or more encrypted identifiers of encrypted matched record to the client device.

16. The system of claim 15 , wherein the encrypted indexes are exact-match indexes which index the identifiers which respectively matches a same value for a corresponding attribute.

17. The system of claim 15 , wherein the encrypted indexes are range-match indexes.

18. An apparatus for operating a NoSQL database with distributed key-value store, comprising a processor and a memory, operably connected with a plurality of servers, the apparatus being configured to:

process a data set comprised of data records, each of the data records having a unique identifier and including a respective value associated with one or more attributes using a private key provided at the client device, wherein the encrypted identifier-value pairs are distributively stored at the servers based on a consistent hashing ring maintained at the client device and which indicates a range of identifiers associated with each of the servers;

partition the data records based on the identifier and form a plurality of encrypted identifier-value pairs for distributed storage across a plurality of servers operably connected to the client device; and

build encrypted indexes for the encrypted identifier-value pairs for storage at the servers, wherein each server stores indexes associated with the local encrypted identifier-value pairs and not with encrypted identifier-value pairs in other servers;

wherein the client device is arranged to cooperate with the servers to execute a query protocol in response to receiving a query from the client device so as to identify, using the build encrypted indexes, data distributively stored in the servers and which matches the query,

wherein the client device is arranged to:

generate a token set including a plurality of tokens based on a condition attribute of the query;

transmit the token set to each of the servers for processing at the servers using local indexes associated with each respective server;

decrypt one or more encrypted identifiers of encrypted matched record provided from the servers; and

generate labels for obtaining the matched record.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2017
From: YUAN, XINGLIANG; GUO, YU; WANG, XINYU; WANG, CONG
To: CITY UNIVERSITY OF HONG KONG
Reel/Frame 041979/0219 →
Continuity (1)
Related Publication 20180294952A1 · Oct 11, 2018
Cited By (1)
US 12,335,254