IP Library › Granted Patent US 11,775,662
Granted Patent B2
US 11,775,662 · App. 17/117,078 · Granted Oct 3, 2023

Searching using encrypted client and server maintained indices

Inventor: Duncan MacDougall Greatwood (Palo Alto, CA)
G06F21/6209G06F16/248G06F16/2455G06F16/27G06F21/602G06F21/6218G06F21/6227G06F21/6263H04L9/0643H04L9/0822H04L9/0861H04L9/0894H04L63/0428H04L63/083H04L63/123H04L2209/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,775,662
App. No.
17/117,078
Filed
Dec 9, 2020
Granted
Oct 3, 2023
Kind
B2
Art Unit
2436
USPC
713/167
Abstract

A method and apparatus of a device searches encrypted objects stored in a secure virtual storage space is described. In an exemplary embodiment, the device receives a search query that includes a set of tokens and encrypts the set of tokens. The device further creates a hashed set of encrypted tokens using a second hash function. In addition, the device sends the hashed set of encrypted tokens to a first search server as a query. Furthermore, the device receives, from the first search server, a first set of encrypted object names as a search result. The device additionally determines a set of client-side indexes to search by hashing at least some of the first set of encrypted object names using a first hash function. The device further decrypts the set of encrypted object names. The additionally searches the set of client-side indexes using the set of decrypted object names.

Claims (32)

1. A non-transitory machine-readable medium having executable instructions to cause one or more processing units to perform a method to index an object in a client-side index, the method comprising:

receiving an object;

encrypting an object name of the object using a client private key;

computing a hash of the encrypted object name using a first hash function;

selecting one of a plurality of first indexes using the hashed encrypted object name; and

indexing, with a first device, the object in the selected one of the plurality of the first indexes.

2. The non-transitory machine-readable medium of claim 1 , wherein the first hash function maps one hash result to a plurality of the encrypted object names.

3. The non-transitory machine-readable medium of claim 1 , wherein a distribution of first hash function values substantially evenly distributed among the plurality of first indexes.

4. The non-transitory machine-readable medium of claim 1 , wherein the plurality of first indexes are divided by time.

5. The non-transitory machine-readable medium of claim 4 , wherein the time sub-division is based on at least a document update time.

6. The non-transitory machine-readable medium of claim 1 , wherein the object contents are indexed in a second index.

7. The non-transitory machine-readable medium of claim 6 , wherein the object contents are tokenized and indexed in the second index by a second device.

8. The non-transitory machine-readable medium of claim 1 , wherein the indexing of the object further comprises:

storing the encrypted object name in an index entry of the selected one of the plurality of the first indexes.

9. The non-transitory machine-readable medium of claim 8 , wherein metadata for the object is associated with the index entry.

10. The non-transitory machine-readable medium of claim 8 , wherein the metadata is stored on the client.

11. A method to index an object in a client-side index, the method comprising:

receiving an object;

encrypting an object name of the object using a client private key;

computing a hash of the encrypted object name using a first hash function;

selecting one of a plurality of client-side indexes using the hashed encrypted object name; and

indexing, with a client, the object in the selected one of the plurality of the client-side indexes.

12. The method of claim 11 , wherein the first hash function maps one hash result to a plurality of the encrypted object names.

13. The method of claim 11 , wherein a distribution of first hash function values substantially evenly distributed among the plurality of client-side indexes.

14. The method of claim 11 , wherein the plurality of client-side indexes are divided by time.

15. The method of claim 14 , wherein the time sub-division is based on at least a document update time.

16. The method of claim 11 , wherein the object contents are indexed in a server.

17. The method of claim 16 , wherein the object contents are tokenized and indexed in a server-side index by the server.

18. The method of claim 11 , wherein the indexing of the object further comprises:

storing the encrypted object name in an index entry of the selected one of the plurality of the client-side indexes.

19. The method of claim 18 , wherein metadata for the object is associated with the index entry.

20. The method of claim 18 , wherein the metadata is stored on the client.

Continuity (3)
Division 15811643 · Nov 13, 2017
Provisional Application 62424357 · Nov 18, 2016
Related Publication 20210256146A1 · Aug 19, 2021