IP Library › Granted Patent US 12,287,900
Granted Patent B2
US 12,287,900 · App. 18/448,865 · Granted Apr 29, 2025

System and method for secure database management

Inventors: Durga Prasad Kutthumolu (Hyderabad, IN); Venkata Karthik Ryali (Hyderabad, IN); Priyanka K (Chennai, IN); Veerendra Gupta (Hyderabad, IN)
Assignee: Bank of America Corporation
G06F21/6227H04L9/088
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,900
App. No.
18/448,865
Granted
Apr 29, 2025
Kind
B2
Abstract

A method includes encrypting a request received from a user device to generate an encrypted request. Encrypted data items are searched based on the encrypted request to identify desired encrypted data items. In response to determining that two or more encrypted data items of the desired encrypted data items have a same interaction identification, the two or more encrypted data items are locked and masked, and the masked two or more encrypted data items are removed. Algebraic operations are determined based on the encrypted request. An encrypted response is determined by performing the algebraic operations on the desired encrypted data items. The encrypted response is decrypted to obtain a decrypted response. An error is determined due to the algebraic operations performed on the desired encrypted data items. In response to determining that the error is less than an error threshold, the decrypted response is sent to the user device.

Claims (75)

1. A database management system communicatively coupled to a data storage system and a user device of a user, the system comprising:

a memory configured to store an error threshold; and

a processor communicatively coupled to the memory, wherein the processor is configured to:

receive a request from the user device;

encrypt the request to generate an encrypted request;

search a plurality of encrypted data items stored in the data storage system based on the encrypted request to identify a plurality of desired encrypted data items;

in response to determining that two or more encrypted data items of the plurality of desired encrypted data items have a same interaction identification:

lock the two or more encrypted data items;

mask the two or more encrypted data items; and

remove the masked two or more encrypted data items from the plurality of desired encrypted data items;

retrieve the plurality of desired encrypted data items from the data storage system;

determine one or more algebraic operations based on the encrypted request;

determine an encrypted response based on the encrypted request and the plurality of desired encrypted data items by performing the one or more algebraic operations on the plurality of desired encrypted data items;

decrypt the encrypted response to obtain a decrypted response;

determine an error for the decrypted response due to the one or more algebraic operations performed on the plurality of desired encrypted data items; and

in response to determining that the error is less than the error threshold, send the decrypted response to the user device.

2. The database management system of claim 1 , wherein the processor is further configured to, in response to determining that the error is not less than the error threshold:

perform an error correction process on the decrypted response to obtain a corrected decrypted response;

determine a second error for the corrected decrypted response; and

in response to determining that the second error is less than the error threshold, send the corrected decrypted response to the user device.

3. The database management system of claim 1 , wherein encrypting the request comprises executing a homomorphic encryption algorithm.

4. The database management system of claim 1 , wherein the one or more algebraic operations comprise addition or multiplication.

5. The database management system of claim 1 , wherein:

the processor is further configured to generate a public key; and

encrypting the request to generate the encrypted request comprises encrypting the request using the public key.

6. The database management system of claim 1 , wherein:

the processor is further configured to generate a secret key; and

decrypting the encrypted response to obtain the decrypted response comprises decrypting the encrypted response using the secret key.

7. The database management system of claim 1 , wherein locking the two or more encrypted data items comprises preventing updates to the two or more encrypted data items.

8. A method comprising:

receiving a request from a user device;

encrypting the request to generate an encrypted request;

searching a plurality of encrypted data items stored in a data storage system based on the encrypted request to identify a plurality of desired encrypted data items;

in response to determining that two or more encrypted data items of the plurality of desired encrypted data items have a same interaction identification:

locking the two or more encrypted data items;

masking the two or more encrypted data items; and

removing the masked two or more encrypted data items from the plurality of desired encrypted data items;

retrieving the plurality of desired encrypted data items from the data storage system;

determining one or more algebraic operations based on the encrypted request;

determining an encrypted response based on the encrypted request and the plurality of desired encrypted data items by performing the one or more algebraic operations on the plurality of desired encrypted data items;

decrypting the encrypted response to obtain a decrypted response;

determining an error for the decrypted response due to the one or more algebraic operations performed on the plurality of desired encrypted data items; and

in response to determining that the error is less than an error threshold, sending the decrypted response to the user device.

9. The method of claim 8 , further comprising, in response to determining that the error is not less than the error threshold:

performing an error correction process on the decrypted response to obtain a corrected decrypted response;

determining a second error for the corrected decrypted response; and

in response to determining that the second error is less than the error threshold, sending the corrected decrypted response to the user device.

10. The method of claim 8 , wherein encrypting the request comprises executing a homomorphic encryption algorithm.

11. The method of claim 8 , wherein the one or more algebraic operations comprise addition or multiplication.

12. The method of claim 8 , further comprising generating a public key, wherein encrypting the request to generate the encrypted request comprises encrypting the request using the public key.

13. The method of claim 8 , further comprising generating a secret key, wherein decrypting the encrypted response to obtain the decrypted response comprises decrypting the encrypted response using the secret key.

14. The method of claim 8 , wherein locking the two or more encrypted data items comprises preventing updates to the two or more encrypted data items.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

receive a request from a user device;

encrypt the request to generate an encrypted request;

search a plurality of encrypted data items stored in a data storage system based on the encrypted request to identify a plurality of desired encrypted data items;

in response to determining that two or more encrypted data items of the plurality of desired encrypted data items have a same interaction identification:

lock the two or more encrypted data items;

mask the two or more encrypted data items; and

remove the masked two or more encrypted data items from the plurality of desired encrypted data items;

retrieve the plurality of desired encrypted data items from the data storage system;

determine one or more algebraic operations based on the encrypted request;

determine an encrypted response based on the encrypted request and the plurality of desired encrypted data items by performing the one or more algebraic operations on the plurality of desired encrypted data items;

decrypt the encrypted response to obtain a decrypted response;

determine an error for the decrypted response due to the one or more algebraic operations performed on the plurality of desired encrypted data items; and

in response to determining that the error is less than an error threshold, send the decrypted response to the user device.

16. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

in response to determining that the error is not less than the error threshold:

perform an error correction process on the decrypted response to obtain a corrected decrypted response;

determine a second error for the corrected decrypted response; and

in response to determining that the second error is less than the error threshold, send the corrected decrypted response to the user device.

17. The non-transitory computer-readable medium of claim 15 , wherein encrypting the request comprises executing a homomorphic encryption algorithm.

18. The non-transitory computer-readable medium of claim 15 , wherein the one or more algebraic operations comprise addition or multiplication.

19. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to generate a public key, wherein encrypting the request to generate the encrypted request comprises encrypting the request using the public key.

20. The non-transitory computer-readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to generate a secret key, wherein decrypting the encrypted response to obtain the decrypted response comprises decrypting the encrypted response using the secret key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2023
From: KUTTHUMOLU, DURGA PRASAD; RYALI, VENKATA KARTHIK; K, PRIYANKA; GUPTA, VEERENDRA
To: BANK OF AMERICA CORPORATION
Reel/Frame 064603/0504 →
Continuity (1)
Related Publication 20250053678A1 · Feb 13, 2025
References Cited (25)
US 8539241B2 · Fielder · 2013 [cited by applicant]
US 8812877B2 · Mori et al. · 2014 [cited by applicant]
US 8837734B2 · McCallum et al. · 2014 [cited by applicant]
US 9087212B2 · Balakrishnan et al. · 2015 [cited by applicant]
US 9118631B1 · Yung · 2015 [cited by examiner]
US 9137304B2 · Novotny et al. · 2015 [cited by applicant]
US 9213764B2 · Kerschbaum et al. · 2015 [cited by applicant]
US 9747456B2 · Arasu · 2017 [cited by examiner]
US 10027486B2 · Liu · 2018 [cited by applicant]
US 10089487B2 · Cash et al. · 2018 [cited by applicant]
US 10333696B2 · Ahmed · 2019 [cited by applicant]
US 10719567B2 · Antonopoulos et al. · 2020 [cited by applicant]
US 10735193B1 · Knas et al. · 2020 [cited by applicant]
US 20160344707A1 · Philipp · 2016 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20240152629A1 · Deshpande · 2024 [cited by examiner]
US 20240378596A1 · Singh · 2024 [cited by examiner]
EP 2778951B1 · 2017 [cited by applicant]
Goldreich, Oded. “Secure multi-party computation.” Foundations of computer science, 1986. FOCS'86.27th Annual Symposium on. IEEE, 1986. https://www.wisdom.weizmann.ac.il/˜oded/PSX/prot.pdf. [cited by applicant]
ISO 9241-11:2018. “Ergonomics of human-system interaction—Part 11: Guidance on usability.” https://www.iso.org/obp/ui/#iso:std:iso:9241:-11:ed-2:v1:en. [cited by applicant]
“Oracle Database Advanced Security Administrator's Guide” (https://docs.oracle.com/en/database/oracle/oracle-database/19/asoag/). [cited by applicant]
“SQL Server Integration Services (SSIS)” (https://learn.microsoft.com/en-us/sql/integration-services/sql-server-integration-services?view=sql-server-ver16). [cited by applicant]
“MySQL :: MySQL 5.7 Reference Manual :: 22.1 Introduction to the MySQL Plug-In API” (https://dev.mysql.com/doc/refman/5.7/en). [cited by applicant]
https://infostore.saiglobal.com/preview/is/en/2018/i.s.eniso9241-11-2018.pdf?sku=1980667. [cited by applicant]
https://www.sis.se/api/document/preview/80003410/. [cited by applicant]