IP Library › Granted Patent US 11,139,960
Granted Patent B2
US 11,139,960 · App. 16/227,166 · Granted Oct 5, 2021

File redaction database system

Inventors: Karthik Nandakumar (Singapore, SG); Nalini K. Ratha (Yorktown Heights, NY); Sharathchandra Pankanti (Fairfield County, CT)
Assignee: International Business Machines Corporation
H04L9/0825G06F16/134G06F16/176H04L9/0618H04L9/3231H04L9/3236H04L9/3247H04L63/0428H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,139,960
App. No.
16/227,166
Granted
Oct 5, 2021
Kind
B2
Abstract

An example operation may include one or more of determining, by a file redaction device, redacted segments of a source file, receiving, by a signature update device, the redacted source file segments, a stored trapdoor key, and stored auxiliary data segments, determining modified auxiliary data from the redacted source file segments, the trapdoor key and the auxiliary data segments, executing chaincode to obtain a modified auxiliary data signature and identifiers of the redacted source file segments, and storing the modified auxiliary data signature and identifiers of the redacted source file segments to a shared ledger of a blockchain network. Each stored auxiliary data segment including a random string of data corresponding to a segment of the source file.

Claims (61)

1. A system, comprising:

a blockchain network comprising a shared ledger which stores a source file signature that is created by inputting a plurality of segments of a source file paired with a plurality auxiliary data segments, respectively, into a first Merkle tree of a chameleon hash function;

a file redaction device configured to redact a source file segment from among the plurality of segments of the source file;

a signature update device configured to:

receive the redacted source file segment and the plurality of auxiliary data segments paired with the plurality of segments of the source file in the chameleon hash function;

modify an auxiliary data segment that is paired with the redacted source file segment;

input the plurality of auxiliary data segments including the modified auxiliary data segment into a second Merkle tree of a cryptographic hash function which outputs a modified auxiliary data signature; and

store the modified auxiliary data signature to the shared ledger.

2. The system of claim 1 , wherein the file redaction device is further configured to perform biometric authentication on a user who redacted the source file segment.

3. The system of claim 2 , wherein the file redaction device is further configured to:

determine the user who redacted the source file segment has an approved identity; and

create an authentication blockchain transaction, the authentication transaction comprising biometric authentications of the user who redacted the source file segment;

wherein the blockchain network is configured to:

endorse the authentication transaction; and

store the authentication transaction to the shared ledger.

4. The system of claim 1 , wherein the plurality of auxiliary data segments are stored outside the blockchain network.

5. The system of claim 1 , wherein the source file signature previously stored to the shared ledger does not change in response to the modified auxiliary data signature and the source file signature corresponds to original source file content prior to redaction.

6. The system of claim 1 , wherein the signature update device is configured to input the plurality of auxiliary data segments including the modified auxiliary data segment into leaf nodes of the second Merkle tree.

7. The system of claim 1 , wherein the signature update device is further configured to:

create a blockchain transaction comprising the modified auxiliary data signature and an identifier of the redacted source file segment;

wherein the blockchain network is further configured to endorse the blockchain transaction.

8. A method, comprising:

storing a source file signature that is created by inputting a plurality of segments of a source file paired with a plurality auxiliary data segments, respectively, into a first Merkle tree of a chameleon hash function;

redacting, by a file redaction device, a source file segment from among the plurality of segments of the source file;

receiving, by a signature update device, the redacted source file segment and the plurality of auxiliary data segments paired with the plurality of source file segments in the chameleon hash function;

modifying an auxiliary data segment that is paired with the redacted source file segment;

inputting the plurality of auxiliary data segments including the modified auxiliary data segment into a second Merkle tree of a cryptographic hash function which outputs a modified auxiliary data signature; and

storing the modified auxiliary data signature to a shared ledger of a blockchain network.

9. The method of claim 8 , wherein the method further comprises:

performing, by the file redaction device, biometric authentication on a user who redacted the source file segment.

10. The method of claim 9 , wherein the method further comprises:

determining the user who redacted the source file segment has an approved identity; and

creating an authentication blockchain transaction, the authentication transaction comprising biometric authentications of the user who redacted the source file segment;

wherein the method further comprises:

endorsing the authentication transaction; and

storing the authentication transaction to the shared ledger.

11. The method of claim 8 , wherein the plurality of auxiliary data segments are stored outside the blockchain network.

12. The method of claim 8 , wherein the source file signature previously stored to the shared ledger does not change in response to the modified auxiliary data signature and the source file signature corresponds to original source file content prior to redaction.

13. The method of claim 8 , wherein the inputting comprises inputting the plurality of auxiliary data segments including the modified auxiliary data segment into leaf nodes of the second Merkle tree.

14. The method of claim 8 , wherein the storing comprises:

creating a blockchain transaction comprising the modified auxiliary data signature and an identifier of the redacted source file segment; and

endorsing the blockchain transaction.

15. A non-transitory computer readable medium comprising instructions, that when read by a processor, cause the processor to perform a method comprising:

storing a source file signature that is created by inputting a plurality of segments of a source file paired with a plurality auxiliary data segments, respectively, into a first Merkle tree of a chameleon hash function;

redacting, by a file redaction device, a source file segment from among the plurality of segments of the source file;

receiving, by a signature update device the redacted source file segment and the plurality of auxiliary data segments paired with the plurality of source file segments in the chameleon hash function;

modifying an auxiliary data segment that is paired with the redacted source file segment;

inputting the plurality of auxiliary data segments including the modified auxiliary data segment into a second Merkle tree of a cryptographic hash function which outputs a modified auxiliary data signature; and

storing the modified auxiliary data signature to a shared ledger of a blockchain network.

16. The non-transitory computer readable medium of claim 15 , wherein the method further comprises:

determining a user who redacted the source file segment has an approved identity; and

creating an authentication blockchain transaction, the authentication transaction comprising a biometric authentication of the user who redacted the source file segment;

wherein the method further comprises:

endorsing the authentication transaction; and

storing the authentication transaction to the shared ledger.

17. The non-transitory computer readable medium of claim 15 , wherein the plurality of auxiliary data segments are stored outside the blockchain network.

18. The non-transitory computer readable medium of claim 15 , wherein the source file signature previously stored to the shared ledger does not change in response to the modified auxiliary data signature and the source file signature corresponds to original source file content prior to redaction.

19. The non-transitory computer readable medium of claim 15 , wherein the inputting comprises inputting the plurality of auxiliary data segments including the modified auxiliary data segment into leaf nodes of the second Merkle tree.

20. The non-transitory computer readable medium of claim 15 , wherein the storing comprises:

creating a blockchain transaction comprising the modified auxiliary data signature and an identifier of the redacted source file segment; and

endorsing the blockchain transaction.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2018
From: NANDAKUMAR, KARTHIK; RATHA, NALINI K.; PANKANTI, SHARATHCHANDRA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 047829/0943 →
Continuity (1)
Related Publication 20200204358A1 · Jun 25, 2020