IP Library Granted Patent US 10,903,979
Granted Patent B2
US 10,903,979 · App. 16/205,977 · Granted Jan 26, 2021

Batched execution of encryption operations

Inventors: Michael J. Jordan (Woodstock, NY); Tamas Visegrady (Zurich, CH); John C. Dayka (New Paltz, NY); Michael C. Osborne (Richterswil, CH)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L9/0631G06F21/602G09C1/00H04L9/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,903,979
App. No.
16/205,977
Granted
Jan 26, 2021
Kind
B2
Abstract

Batched execution of encryption operations is performed. A batched set of data for which format-preserving encryption is to be performed is obtained. The batched set of data includes a plurality of fields of data, which are independent of one another. Multiple rounds of format-preserving encryption are performed on the plurality of fields of data to provide an output of format-preserved encrypted data. A round of format-preserving encryption includes calling an encryption function to perform one or more encryption operations on the plurality of fields of data in parallel.

Claims (45)

1. A computer program product for facilitating processing within a computing environment, the computer program product comprising:

a non-transitory computer readable storage medium readable by a processing circuit and storing instructions for performing a method comprising:

identifying a batch size which maximizes throughput of an underlying hardware engine to be used in performing format-preserving encryption;

based on the identified batch size which maximizes throughput of the underlying hardware engine, determining a number of fields of data to be included in batched sets of data;

obtaining, by the processing circuit, a batched set of data of the batched sets of data for which format-preserving encryption is to be performed, the batched set of data including a plurality of fields of data, the plurality of fields of data being independent of one another;

performing multiple rounds of format-preserving encryption on the plurality of fields of data of the batched set of data to provide an output of format-preserved encrypted data, wherein a round of format-preserving encryption includes calling an encryption function to perform one or more encryption operations on the plurality of fields of data in parallel; and

wherein the method further comprises deserializing the output of format-preserved encrypted data to provide a plurality of format-preserved encrypted fields of data.

2. The computer program product of claim 1 , wherein the plurality of fields of data are of one or more records of a database.

3. The computer program product of claim 1 , wherein the round of format-preserving encryption includes using a shared key of the plurality of fields of data in the format-preserving encryption of the plurality of fields of data.

4. The computer program product of claim 1 , wherein at least one field of data of the plurality of fields of data is diversified with respect to other fields of data of the plurality of fields of data.

5. The computer program product of claim 1 , wherein the obtaining the batched set of data includes:

issuing one or more select statements to a database to obtain the plurality of fields of data; and

collating the plurality of fields of data into the batched set of data.

6. The computer program product of claim 1 , wherein the obtaining the batched set of data includes:

determining which fields of data of a database are to be processed through format-preserving encryption; and

grouping the fields of data to be processed through format-preserving encryption into one or more groups of fields of data based on one or more criteria, wherein the plurality of fields of data are selected from a group of fields of data of the one or more groups of fields of data.

7. The computer program product of claim 6 , wherein the one or more criteria include at least one criterion selected from a group of criteria consisting of: same type of field, shared keys, and a same number of format-preserving encryption iterations to be performed.

8. The computer program product of claim 6 , wherein the grouping further includes grouping the fields of data based on whether the fields of data are in a same record of the database, wherein the plurality of fields of data selected from the group of fields of data are of the same record.

9. The computer program product of claim 1 , wherein:

the round of format-preserving encryption includes using a shared key of the plurality of fields of data in format-preserving encryption of the plurality of fields of data; and

at least one field of data of the plurality of fields of data is diversified with respect to other fields of data of the plurality of fields of data.

10. A computer system for facilitating processing within a computing environment, the computer system comprising:

a processing circuit;

a storage device including a format-preserving engine, wherein the computer system is configured to perform a method comprising:

identifying a batch size which maximizes throughput of an underlying hardware engine to be used in performing format-preserving encryption;

based on the identified batch size which maximizes throughput of the underlying hardware engine, determining a number of fields of data to be included in batched sets of data;

obtaining, by the processing circuit executing the format-preserving engine, a batched set of data of the batched sets of data for which format-preserving encryption is to be performed, the batched set of data including a plurality of fields of data, the plurality of fields of data being independent of one another;

performing multiple rounds of format-preserving encryption on the plurality of fields of data of the batched set of data to provide an output of format-preserved encrypted data, wherein a round of format-preserving encryption includes calling an encryption function to perform one or more encryption operations on the plurality of fields of data in parallel; and

wherein the method further comprises deserializing the output of format-preserved encrypted data to provide a plurality of format-preserved encrypted fields of data.

11. The computer system of claim 10 , wherein the plurality of fields of data are of one or more records of a database.

12. The computer system of claim 10 , wherein the round of format-preserving encryption includes using a shared key of the plurality of fields of data in the format-preserving encryption of the plurality of fields of data.

13. The computer system of claim 10 , wherein the obtaining the batched set of data includes:

issuing one or more select statements to a database to obtain the plurality of fields of data; and

collating the plurality of fields of data into the batched set of data.

14. A computer-implemented method of facilitating processing within a computing environment, the computer-implemented method comprising:

identifying a batch size which maximizes throughput of an underlying hardware engine to be used in performing format-preserving encryption;

based on the identified batch size which maximizes throughput of the underlying hardware engine, determining a number of fields of data to be included in batched sets of data;

obtaining a batched set of data of the batched sets of data for which format-preserving encryption is to be performed, the batched set of data including a plurality of fields of data, the plurality of fields of data being independent of one another;

performing multiple rounds of format-preserving encryption on the plurality of fields of data of the batched set of data to provide an output of format-preserved encrypted data, wherein a round of format-preserving encryption includes calling an encryption function to perform one or more encryption operations on the plurality of fields of data in parallel; and

wherein the method further comprises the output of format-preserved encrypted data to provide a plurality of format-preserved encrypted fields of data.

15. The computer-implemented method of claim 14 , wherein the plurality of fields of data are of one or more records of a database.

16. The computer-implemented method of claim 14 , wherein the round of format-preserving encryption includes using a shared key of the plurality of fields of data in the format-preserving encryption of the plurality of fields of data.

17. The computer-implemented method of claim 14 , wherein the obtaining the batched set of data includes:

issuing one or more select statements to a database to obtain the plurality of fields of data; and

collating the plurality of fields of data into the batched set of data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2018
From: JORDAN, MICHAEL J.; VISEGRADY, TAMAS; DAYKA, JOHN C.; OSBORNE, MICHAEL C.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047641/0352 →
Continuity (1)
Related Publication 20200177370A1 · Jun 4, 2020