IP Library › Granted Patent US 12,367,314
Granted Patent B1
US 12,367,314 · App. 18/058,821 · Granted Jul 22, 2025

Dynamic database redaction using protected secret material

Inventors: Dmytro Bogatov (Boston, MA); Kiran Kumar Chinta (Fremont, CA); Todd Jeffrey Green (Davis, CA); Yanzhu Ji (Sunnyvale, CA); James Claiborne Moore (Boston, MA); Gaurav Saxena (Cupertino, CA); Abhishek Rai Sharma (Sunnyvale, CA)
Assignee: Amazon Technologies, Inc.
G06F21/6254H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,367,314
App. No.
18/058,821
Granted
Jul 22, 2025
Kind
B1
Abstract

Techniques for dynamic database redaction using protected encryption secret material are described. A masking policy is defined that includes a reference to a secret material stored by a secrets manager service. The masking policy further identifies a pseudonymous redaction function that utilizes a cryptographic function requiring such a secret material. The secrets manager service is configured to grant access to the secret material by an entity of the database service that executes queries, such as a leader node of a cluster. For a particular query, the cluster obtains the secret material from the secrets manager service in a secure manner, uses the secret material for applying the cryptographic function to values for redaction purposes, and deletes any copies of secret material thereafter.

Claims (55)

1. A computer-implemented method comprising:

receiving, at a database service, a request to create a masking policy, the request identifying a pseudonymous redaction function implemented by the database service, the request further including an identifier of a secret material that is stored in a separate system that is separate from the database service;

receiving, at the database service, a request to attach the masking policy to a column of a table of a database;

receiving, at the database service, a request to execute a query involving at least a column of a relation of the database; and

executing the query to generate a result, comprising modifying values of the column based on use of the secret material and the pseudonymous redaction function of the masking policy to yield modified values for the result, wherein executing the query comprises:

obtaining a copy of the secret material from the separate system, by a leader node of a cluster of the database service, via use of the identifier of the secret material;

transmitting the copy of the secret material to each of one or more compute nodes of the cluster, via an encrypted channel or message, for use in modifying values of the column;

deleting the copy of the secret material by the leader node; and

deleting the copies of the secret material by the one or more compute nodes.

2. The computer-implemented method of claim 1 , wherein:

the separate system comprises a secrets manager service implemented within a multi-tenant service provider network; and

a user stored the secret material with the secrets manager service and configured a permission for the leader node to access the secret material.

3. The computer-implemented method of claim 1 , wherein:

the pseudonymous redaction function includes use of a hash-based message authentication code (HMAC) function;

the secret material itself is not within the masking policy; and

the secret material is not directly accessible by a user that issued the query.

4. A computer-implemented method comprising:

receiving, at a database service, a request to execute a query involving at least a column of a relation of a database; and

executing the query to generate a result, comprising modifying values of the column based on use of secret material and a pseudonymous redaction function implemented by the database service to yield modified values for the result, wherein executing the query comprises obtaining a copy of the secret material, from a separate system that is separate from the database service, via use of an identifier of the secret material.

5. The computer-implemented method of claim 4 , wherein the separate system comprises a secrets manager service implemented within a multi-tenant service provider network.

6. The computer-implemented method of claim 5 , further comprising:

receiving, at the secrets manager service, a request to store the secret material or to generate and store the secret material;

encrypting, by the secrets manager service, the secret material; and

storing the encrypted secret material in a non-volatile storage medium.

7. The computer-implemented method of claim 6 , further comprising configuring, by the secrets manager service, an entity of the database service to have permission to access the secret material, wherein the entity is one of a leader node of a cluster of the database service, the cluster of the database service, or a compute node of the database service.

8. The computer-implemented method of claim 7 , wherein obtaining the copy of the secret material comprises:

determining, based on a context of the query, an identity or credential to use to obtain the secret material, and

wherein the obtaining the copy of the secret material includes sending a request, by the leader node of the cluster to the secrets manager service, for the secret material via use of the determined identity or credential.

9. The computer-implemented method of claim 8 , wherein executing the query comprises transmitting the secret material by the leader node to one or more compute nodes of the cluster via one or more encrypted channels or messages.

10. The computer-implemented method of claim 9 , further comprising deleting the secret material, by the leader node, after the transmitting of the secret material by the leader node.

11. The computer-implemented method of claim 10 , wherein each of the one or more compute nodes utilizes the secret material to execute the pseudonymous redaction function and thereafter deletes the secret material.

12. The computer-implemented method of claim 7 , further comprising rotating the secret material, by the secrets manager service, to instead designate an updated secret material for use by the entity of the database service.

13. The computer-implemented method of claim 4 , wherein the modifying of the values of the column occurs based on a selected masking policy, wherein the secret material itself is not within the masking policy, and wherein the secret material is not directly accessible by a user that issued the query.

14. The computer-implemented method of claim 4 , further comprising:

receiving a request to create a masking policy, the request identifying the pseudonymous redaction function implemented by the database service, the request further including an identifier of the secret material that is stored in the separate system;

receive a request to attach the masking policy to the relation of a database; and

attaching the masking policy to the relation, comprising updating one or more data structures to associate the masking policy with the relation.

15. A system comprising:

a first one or more electronic devices to implement a secrets manager service in a multi-tenant service provider network; and

a second one or more electronic devices to implement a database service in the multi-tenant service provider network, the database service including instructions that upon execution cause the database service to:

receive a request to execute a query involving at least a column of a relation of a database; and

execute the query to generate a result, comprising modifying values of the column based on use of a secret material and a pseudonymous redaction function to yield modified values for the result, wherein to execute the query the database service is at least to obtain a copy of the secret material, from the secrets manager service that is separate from the database service, via use of an identifier of the secret material.

16. The system of claim 15 , wherein the secret manager service is to:

receive a request to store the secret material or to generate and store the secret material;

encrypt the secret material; and

store the encrypted secret material in a non-volatile storage medium.

17. The system of claim 16 , wherein the secret manager service is further to configure an entity of the database service to have permission to access the secret material, wherein the entity is one of a leader node of a cluster of the database service, the cluster of the database service, or a compute node of the database service.

18. The system of claim 17 , wherein the database service, to obtain the copy of the secret material, is to:

send a request, by the leader node of the cluster to the secrets manager service, for the secret material, wherein the request is sent with an identity of the leader node that allows the secrets manager service to authorize the leader node as having permission to access the secret material; and

receive, by the leader node from the secrets manager service, the secret material via an encrypted channel or message.

19. The system of claim 18 , wherein the database service, to execute the query, is to transmit the secret material by the leader node to one or more compute nodes of the cluster via one or more encrypted channels or messages.

20. The system of claim 15 , wherein the database service further includes instructions that when executed cause the database service to:

receive a request to create a masking policy, the request identifying the pseudonymous redaction function implemented by the database service, the request further including an identifier of the secret material that is stored in the secret manager service but not including the secret material itself;

receive a request to attach the masking policy to the relation of a database; and

attach the masking policy to the relation, comprising updating one or more data structures to associate the masking policy with the relation.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2025
From: BOGATOV, DMYTRO; CHINTA, KIRAN KUMAR; JI, YANZHU; MOORE, JAMES CLAIBORNE; SAXENA, GAURAV; SHARMA, ABHISHEK RAI; GREEN, TODD JEFFREY
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 071242/0521 →
References Cited (54)
US 4825391A · Merz · 1989 [cited by applicant]
US 5751967A · Raab et al. · 1998 [cited by applicant]
US 8473410B1 · Haggerty et al. · 2013 [cited by applicant]
US 10867063B1 · Avanes et al. · 2020 [cited by applicant]
US 11341270B2 · Reeve · 2022 [cited by examiner]
US 11567943B1 · Blum et al. · 2023 [cited by applicant]
US 11593521B1 · Balakrishnan et al. · 2023 [cited by applicant]
US 11783078B1 · Li et al. · 2023 [cited by applicant]
US 20030014394A1 · Fujiwara et al. · 2003 [cited by applicant]
US 20060238799A1 · Kidokoro · 2006 [cited by applicant]
US 20110029473A1 · Van Lunteren · 2011 [cited by applicant]
US 20120054095A1 · Lesandro et al. · 2012 [cited by applicant]
US 20120197919A1 · Chen et al. · 2012 [cited by applicant]
US 20130019276A1 · Biazetti · 2013 [cited by examiner]
US 20130060820A1 · Bulusu et al. · 2013 [cited by applicant]
US 20130117313A1 · Miao et al. · 2013 [cited by applicant]
US 20140032928A1 · Taskaya · 2014 [cited by examiner]
US 20140096184A1 · Zaitsev · 2014 [cited by applicant]
US 20150095647A1 · Lachterman · 2015 [cited by examiner]
US 20150150075A1 · Vahlis et al. · 2015 [cited by applicant]
US 20150358433A1 · Parthasarathy et al. · 2015 [cited by applicant]
US 20150358434A1 · Parthasarathy et al. · 2015 [cited by applicant]
US 20160164679A1 · Song · 2016 [cited by examiner]
US 20170005788A1 · Irvine · 2017 [cited by examiner]
US 20170039387A1 · Leonardi et al. · 2017 [cited by applicant]
US 20170272472A1 · Adhar · 2017 [cited by applicant]
US 20180060365A1 · Mujumdar et al. · 2018 [cited by applicant]
US 20180307859A1 · Lafever et al. · 2018 [cited by applicant]
US 20190229905A1 · Fan et al. · 2019 [cited by applicant]
US 20190319925A1 · Chalvadi et al. · 2019 [cited by applicant]
US 20200301917A1 · Niu et al. · 2020 [cited by applicant]
US 20200311304A1 · Parthasarathy · 2020 [cited by applicant]
US 20200327252A1 · McFall et al. · 2020 [cited by applicant]
US 20200396210A1 · Taylor · 2020 [cited by examiner]
US 20210157948A1 · Avanes et al. · 2021 [cited by applicant]
US 20210286894A1 · Avanes et al. · 2021 [cited by applicant]
US 20220092213A1 · Hou · 2022 [cited by applicant]
US 20220100900A1 · Baldwin et al. · 2022 [cited by applicant]
US 20220164477A1 · Patodia · 2022 [cited by applicant]
US 20220215107A1 · Wong et al. · 2022 [cited by applicant]
US 20220405420A1 · Tommasi · 2022 [cited by examiner]
US 20220407861A1 · Beecham et al. · 2022 [cited by applicant]
US 20220414601A1 · Shek et al. · 2022 [cited by applicant]
US 20230005391A1 · Sharma et al. · 2023 [cited by applicant]
US 20230130637A1 · Hosudurg et al. · 2023 [cited by applicant]
US 20230169198A1 · Blum et al. · 2023 [cited by applicant]
US 20230281326A1 · Magalsky · 2023 [cited by applicant]
US 20240111896A1 · McGrath · 2024 [cited by examiner]
US 20240134660A1 · Eberlein et al. · 2024 [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/058,816, Oct. 25, 2024, 25 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/058,820, Sep. 24, 2024, 43 pages. [cited by applicant]
Peter et al. “Query-Driven Enforcement of Rule-Based Policies for Data-Privacy Compliance”—Published—2019 (Peter hereinafter) (Year: 2019). [cited by applicant]
Final Office Action, U.S. Appl. No. 18/058,816, Feb. 28, 2025, 29 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/058,819, Dec. 18, 2024, 16 pages. [cited by applicant]
Cited By (2)
US 12,657,344 US 12,743,530