IP Library › Granted Patent US 11,222,134
Granted Patent B2
US 11,222,134 · App. 17/191,177 · Granted Jan 11, 2022

System and methods for data encryption and application-agnostic querying of encrypted data

Inventors: Purandar Gururaj Das (Lexington, MA); Shanthi Boppana (Boxborough, MA)
Assignee: Sotero, Inc.
G06F21/6227G06F16/248G06F16/24526G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,222,134
App. No.
17/191,177
Granted
Jan 11, 2022
Kind
B2
Abstract

A method for performing data encryption and application-agnostic querying of encrypted data includes identifying, via a processor, selected data for encryption. Encryption is applied to the selected data, to produce encrypted data. A query is received at the processor, the query originating from a software application. The query is translated into a modified query compatible with the encrypted data. The processor causes execution of the modified query, to produce query results. The query results include a subset of the encrypted data. The query results are sent to the software application without decrypting the subset of the encrypted data.

Claims (60)

1. A method, comprising:

identifying, via a processor, selected data for encryption by detecting tagged data within a data repository accessible by the processor;

applying, via the processor, encryption to the selected data, to produce encrypted data;

receiving, at the processor, a query originating from a software application, the query including a LIKE operator;

translating the query, via the processor, into a modified query compatible with the encrypted data, the modified query including a custom match function call configured to retrieve ngram-matched portions of the encrypted data;

causing, via the processor, execution of the modified query, thereby producing query results, the query results including a subset of the encrypted data; and

sending, via the processor, the query results to the software application without decrypting the subset of the encrypted data.

2. The method of claim 1 , wherein the query is a range query.

3. The method of claim 1 , wherein the encryption is a deterministic encryption.

4. The method of claim 1 , wherein the encryption is an order-preserving encryption.

5. The method of claim 1 , wherein the encryption is a numeric encryption.

6. The method of claim 1 , wherein the software application is a first software application, the query is a first query, the modified query is a first modified query, the query results are first query results, and the subset of the encrypted data is a first subset of the encrypted data, the method further comprising:

receiving, at the processor, a second query, from a second software application different from the first software application;

translating the second query, via the processor, into a second modified query compatible with the encrypted data;

causing, via the processor, execution of the second modified query, thereby producing second query results, the second query results including a second subset of the encrypted data; and

sending, via the processor, the second query results to the second software application without decrypting the second subset of the encrypted data.

7. The method of claim 1 , wherein the software application is a first software application, the query is a first query, the modified query is a first modified query, the query results are first query results, and the subset of the encrypted data is a first subset of the encrypted data, the method further comprising:

receiving a second query, from a second software application, the second query having a second protocol different from a first protocol;

translating the second query, via the processor, into a second modified query compatible with the encrypted data;

causing, via the processor, execution of the second modified query, thereby producing second query results, the second query results including a second subset of the encrypted data; and

sending, via the processor, the second query results to the second software application without decrypting the second subset of the encrypted data.

8. The method of claim 1 , wherein the tagged data includes at least one of personally identifiable information (PII) or personal health information (PHI).

9. The method of claim 1 , wherein the causing the execution of the modified query includes generating a token based on the query originating from the software application.

10. A method, comprising:

identifying, via a processor, selected data for encryption by detecting tagged data within a data repository accessible by the processor;

applying, via the processor, encryption to the selected data, to produce encrypted data;

receiving, at the processor, a query originating from a software application, the query including a LIKE operator;

translating the query, via the processor, into a modified query compatible with the encrypted data, the modified query including a custom match function call configured to retrieve ngram-matched portions of the encrypted data;

causing, via the processor, execution of the modified query, thereby producing query results, the query results including a subset of the encrypted data; and

sending, via the processor, the query results to the software application without re-encrypting the subset of the encrypted data.

11. The method of claim 10 , wherein the query is a range query.

12. The method of claim 10 , wherein the encryption is a deterministic encryption.

13. The method of claim 10 , wherein the encryption is an order-preserving encryption.

14. The method of claim 10 , wherein the encryption is a numeric encryption.

15. The method of claim 10 , wherein the software application is a first software application, the query is a first query, the modified query is a first modified query, the query results are first query results, and the subset of the encrypted data is a first subset of the encrypted data, the method further comprising:

receiving, at the processor, a second query, from a second software application different from the first software application;

translating the second query, via the processor, into a second modified query compatible with the encrypted data;

causing, via the processor, execution of the second modified query, thereby producing second query results, the second query results including a second subset of the encrypted data; and

sending, via the processor, the second query results to the second software application without re-encrypting the second subset of the encrypted data.

16. The method of claim 10 , wherein the software application is a first software application, the query is a first query, the modified query is a first modified query, the query results are first query results, and the subset of the encrypted data is a first subset of the encrypted data, the method further comprising:

receiving a second query, from a second software application, the second query having a second protocol different from a first protocol;

translating the second query, via the processor, into a second modified query compatible with the encrypted data;

causing, via the processor, execution of the second modified query, thereby producing second query results, the second query results including a second subset of the encrypted data; and

sending, via the processor, the second query results to the second software application without re-encrypting the second subset of the encrypted data.

17. The method of claim 10 , wherein the tagged data includes at least one of personally identifiable information (PII) or personal health information (PHI).

18. The method of claim 10 , wherein the causing the execution of the modified query includes generating a token based on the query originating from the software application.

19. A non-transitory, processor-readable medium storing processor-readable instructions to cause a processor to:

identify selected data for encryption by detecting tagged data within a data repository accessible by the processor;

apply encryption to the selected data, to produce encrypted data;

receive a query originating from a software application, the query including a LIKE operator;

translate the query into a modified query compatible with the encrypted data, the modified query including a custom match function call configured to retrieve ngram-matched portions of the encrypted data;

cause execution of the modified query, to produce query results, the query results including a subset of the encrypted data; and

send the query results to the software application without decrypting the subset of the encrypted data.

20. A non-transitory, processor-readable medium storing processor-readable instructions to cause a processor to:

identify selected data for encryption by detecting tagged data within a data repository accessible by the processor;

apply encryption to the selected data, to produce encrypted data;

receive a query originating from a software application, the query including a LIKE operator;

translate the query into a modified query compatible with the encrypted data, the modified query including a custom match function call configured to retrieve ngram-matched portions of the encrypted data;

cause execution of the modified query, to produce query results, the query results including a subset of the encrypted data; and

send the query results to the software application without re-encrypting the subset of the encrypted data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2021
From: BOPPANA, SHANTHI; DAS, PURANDAR GURURAJ
To: SOTERO, INC.
Reel/Frame 057690/0409 →
Continuity (2)
Provisional Application 62984978 · Mar 4, 2020
Related Publication 20210279357A1 · Sep 9, 2021
Cited By (3)
US 12,223,075 US 12,346,440 US 12,639,470