IP Library Granted Patent US 12,505,076
Granted Patent B2
US 12,505,076 · App. 18/710,247 · Granted Dec 23, 2025

Method for using an ORAM database by a terminal equipment, corresponding computer program product and device

Inventors: Tommaso Gagliardoni (Cheseaux-sur-Lausanne, CH); Nils Amiet (Cheseaux-sur-Lausanne, CH)
Assignee: NAGRAVISION SARL
G06F16/211G06F16/27G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,505,076
App. No.
18/710,247
Granted
Dec 23, 2025
Kind
B2
Abstract

A method for using, by a terminal equipment, an Oblivious Random-Access Memory (ORAM) database created in a remote server. A third-party device is connected to the terminal equipment and to the remote server through a communications network and executes receiving a request, sent by the terminal equipment, for having the third-party device to initiate the creation of the ORAM database in the remote server, initializing the creation of the ORAM database in the remote server by sending to the remote server ORAM database elements, generating metadata associated to the ORAM database created in the remote server, and sending, to the terminal equipment, the metadata for allowing the terminal equipment to use the ORAM database created in the remote server without going through the third-party device.

Claims (45)

1 . A method of implementing, by a terminal equipment, an Oblivious Random-Access Memory, hereafter ORAM, database created in a remote server, the method comprising:

executing, by a third-party device being connected to the terminal equipment and to the remote server through a communications network, receiving a request, sent by the terminal equipment through the communications network, for having the third-party device to initiate creation of the ORAM database in the remote server; and

responsive to said receiving the request and by the third-party device:

initializing the creation of the ORAM database in the remote server by sending to the remote server, through the communications network, ORAM database elements,

generating metadata associated to the ORAM database created in the remote server, and

sending, to the terminal equipment through the communications network, the metadata for allowing the terminal equipment to use the ORAM database created in the remote server without going through the third-party device.

2 . The method according to claim 1 , wherein said initializing the creation of the ORAM database further comprises:

generating a temporary symmetric encryption key;

encrypting initial data blocks of the ORAM database with the temporary symmetric encryption key; and

sending, to the remote server through the communications network, the encrypted initial data blocks as part of the ORAM database elements.

3 . The method according to claim 2 , wherein said metadata comprise said temporary symmetric encryption key.

4 . The method according to claim 3 , further comprising: by the third-party device and responsive to said sending to the terminal equipment the metadata, deleting the metadata stored in the third-party device.

5 . The method according to claim 3 , further comprising: by the third-party device and after said sending to the terminal equipment the metadata, receiving, from the terminal equipment through the communications network, the metadata associated to the ORAM database in an encrypted form based on a secret encryption key different from the temporary symmetric encryption key.

6 . The method according to claim 2 , further comprising: by the third-party device and responsive to said sending to the terminal equipment the metadata, deleting the metadata stored in the third-party device.

7 . The method according to claim 2 , further comprising: by the third-party device and after said sending to the terminal equipment the metadata, receiving, from the terminal equipment through the communications network, the metadata associated to the ORAM database in an encrypted form based on a secret encryption key different from the temporary symmetric encryption key.

8 . The method according to claim 1 , further comprising: by the third-party device and responsive to said sending to the terminal equipment the metadata, deleting the metadata stored in the third-party device.

9 . The method according to claim 1 , further comprising: by the third-party device and after said sending to the terminal equipment the metadata, receiving, from the terminal equipment through the communications network, the metadata associated to the ORAM database in an encrypted form based on a secret encryption key different from a temporary symmetric encryption key.

10 . A non-transitory computer-readable storage medium comprising program code instructions for implementing the method according to claim 1 .

11 . A method of implementing, by a terminal equipment, an Oblivious Random-Access Memory, hereafter ORAM, database created in a remote server, the method comprising:

executing, by the terminal equipment being connected to a third-party device and to the remote server through a communications network:

sending a request, to the third-party device through the communications network, for having the third-party device to initiate creation of the ORAM database in the remote server, and

receiving, from the third-party device through the communications network, metadata allowing the terminal equipment to use the ORAM database created in the remote server without going through the third-party device.

12 . The method according to claim 11 , wherein said metadata comprise a temporary symmetric encryption key used by the third-party device to encrypt initial blocks of the ORAM database stored in the remote server.

13 . The method according to claim 12 , further comprising, by the terminal equipment, sending, to the third-party device through the communications network, an access token so that the third-party device can access the remote server for initializing the creation of the ORAM database in the remote server.

14 . The method according to claim 11 , further comprising, by the terminal equipment, sending, to the third-party device through the communications network, an access token so that the third-party device can access the remote server for initializing the creation of the ORAM database in the remote server.

15 . The method according to claim 14 , further comprising, by the terminal equipment and after said receiving from the third-party device the metadata, revoking the access token sent to the third-party device so that the third-party device cannot access any more the ORAM database in the remote server.

16 . The method according to claim 11 , further comprising, by the terminal equipment, a writing at least one data block in the ORAM database by:

encrypting the at least one data block of the ORAM database with a secret encryption key different from a temporary symmetric encryption key,

sending, to the remote server through the communications network, the encrypted at least one data block for storing in the ORAM database, and

updating the metadata for taking into account the sending of the encrypted at least one data block.

17 . The method according to claim 11 , further comprising, by the terminal equipment, a reading of at least one encrypted data block of the ORAM database by:

receiving, from the remote server through the communications network, the at least one encrypted data block of the ORAM database, and

decrypting the encrypted data block based on a temporary symmetric encryption key if the metadata indicates that the encrypted data block is an initial block of the ORAM database encrypted by the third-party device or based on a secret encryption key if the metadata indicates that the encrypted data block is a data block of the ORAM database encrypted by the terminal equipment.

18 . The method according to claim 11 , further comprising, by the terminal equipment, sending, to the third-party device through the communications network, the metadata in an encrypted form based on a secret encryption key.

19 . A device implementing, by a terminal equipment, an Oblivious Random-Access Memory, hereafter ORAM, database created in a remote server, the device comprising:

a processor or a dedicated computing machine configured to:

receive a request, sent by the terminal equipment through a communications network, for having a third-party device to initiate the creation of the ORAM database in the remote server, and

responsive to said receiving the request:

initialize the creation of the ORAM database in the remote server by sending to the remote server, through the communications network, ORAM database elements,

generate metadata associated to the ORAM database created in the remote server, and

send, to the terminal equipment through the communications network, the metadata for allowing the terminal equipment to use the ORAM database created in the remote server without going through the third-party device.

20 . A device implementing, by a terminal equipment, an Oblivious Random-Access Memory, hereafter ORAM, database created in a remote server, the device comprising:

a processor or a dedicated computing machine configured to:

send a request, to a third-party device through a communications network, for having the third-party device to initiate creation of the ORAM database in the remote server, and

receive, from the third-party device through the communications network, metadata allowing the terminal equipment to use the ORAM database created in the remote server without going through the third-party device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2024
From: GAGLIARDONI, TOMMASO; AMIET, NILS
To: NAGRAVISION SARL
Reel/Frame 068321/0774 →
Priority Claims (1)
EP 21209186 · Nov 19, 2021 · regional
Continuity (1)
Related Publication 20250005000A1 · Jan 2, 2025
References Cited (18)
US 9904793B2 · Chow · 2018 [cited by examiner]
US 10248324B2 · Pass · 2019 [cited by examiner]
US 10592685B2 · Yeo · 2020 [cited by examiner]
US 10922340B1 · Yu · 2021 [cited by examiner]
US 11250159B2 · Kramer · 2022 [cited by examiner]
US 11593516B2 · Patel · 2023 [cited by examiner]
US 11669624B2 · Yeo · 2023 [cited by examiner]
US 11727124B2 · Yeo · 2023 [cited by examiner]
US 20140053099A1 · Groten · 2014 [cited by examiner]
US 20180314847A1 · Yeo · 2018 [cited by examiner]
US 20200175192A1 · Yeo · 2020 [cited by examiner]
US 20210390202A1 · Yeo · 2021 [cited by examiner]
US 20250005000A1 · Gagliardoni · 2025 [cited by examiner]
International Search Report and Written Opinion issued Feb. 20, 2023, in PCT/EP2022/082420, 12 pages. [cited by applicant]
Sajin Sasy et al: “ZeroTrace : Oblivious Memory Primitives from Intel SGX”, Proceedings 2018 Network and Distributed System Security Symposium, Jan. 1, 2018, XP055571240, Reston, VA DOI: 10.14722/ ndss.2018.23239 ISBN: … [cited by applicant]
Emil Stefanov et al: “Path ORAM: An Extremely Simple Oblivious RAM Protocol”, IACR, International Association for Cryptologic Research, vol. 20140114:010337, Jan. 13, 2014, pp. 1-25, XP061015309. [cited by applicant]
Sahin Cetin et al: “TaoStore: Overcoming Asynchronicity in Oblivious Data Storage”, 2016 IEEE Symposium on Security and Privacy (SP), IEEE, May 22, 2016 (May 22, 2016), pp. 198-217, XP032945700, DOI: 10.1109/SP.2016.20. [cited by applicant]
Thang Hoang et al: “MACAO: A Maliciously-Secure and Client-Efficient Active ORAM Framework”, IACR, International Association for Cryptologic Research, vol. 20200221 :223029, Feb. 18, 2020, pp. 1-18, XP061035333, Retriev… [cited by applicant]