IP Library › Granted Patent US 12,743,542
Granted Patent B2
US 12,743,542 · App. 18/966,309 · Granted Sep 22, 2026

Encrypting existing databases with zero downtime and zero storage overhead

Inventors: Alexander French (Toronto, CA); Walid Rjaibi (Markham, CA); Kirby Chin (Richmond Hill, CA); Kamran Mirshahi (Holland Landing, CA); Junseo Hwang (London, CA)
Assignee: International Business Machines Corporation
G06F21/6227G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,542
App. No.
18/966,309
Granted
Sep 22, 2026
Kind
B2
Abstract

Systems, methods are provided for encrypting, decrypting, re-encrypting an existing database with neither downtime nor storage overhead. Create a list of tables to be processed. Identify status of each table by an indicator in a database catalog. Store a second status in each data page. Select a table to process from list of tables. Issue a table lock against the selected table. Select a configurable number of data pages to process during the duration of the table lock. Following the processing, flush the data pages to storage. If there are no more data pages to encrypt for the selected table, remove the selected table from the list of tables to be processed. Release the table lock. If there are more data pages to process in the selected table, and there are waiters for the selected table, release the table lock; select another table from the list of tables to process.

Claims (42)

1 . A method comprising:

creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;

selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;

selecting a configurable number of data pages to encrypt during a duration of the table lock;

flushing the configurable number of data pages to storage following the processing encrypting of the configurable number of data pages;

based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.

2 . The method of claim 1 , wherein the list of tables is preserved in permanent storage between system activations.

3 . The method of claim 1 , wherein encrypting the table comprises encrypting the configurable number of data pages.

4 . The method of claim 1 , wherein encrypting the table comprises decrypting the selected table.

5 . The method of claim 1 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.

6 . The method of claim 1 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.

7 . The method of claim 1 , further comprising:

based on there being more data pages to encrypt in the selected table, and there being waiters to access the selected table, releasing the table lock; and

select another table from the list of tables to encrypt.

8 . A computer program product, the computer program product comprising one or more computer-readable storage media having program code embodied therewith, the program code, when executed by a processor of a computer to perform a method, the method comprising:

creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;

selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;

selecting a configurable number of data pages to encrypt during a duration of the table lock;

flushing the configurable number of data pages to storage following the encrypting of the configurable number of data pages;

based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.

9 . The computer program product of claim 8 , wherein the list of tables is preserved in permanent storage between system activations.

10 . The computer program product of claim 8 , wherein encrypting the table comprises encrypting the configurable number of data pages.

11 . The computer program product of claim 8 , wherein encrypting the table comprises decrypting the selected table.

12 . The computer program product of claim 8 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.

13 . The computer program product of claim 8 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.

14 . A computer system the computer system, comprising:

one or more processors;

a memory coupled to at least one of the processors;

a set of computer program instructions stored in the memory and executed by at least one of the processors in order to perform actions of:

creating a list of tables to be encrypted, wherein a status of a table to be encrypted is identified by an indicator in a database catalog, and a second status is stored in each data page;

selecting a table to encrypt from the list of tables, wherein a table lock is issued against the selected table to encrypt;

selecting a configurable number of data pages to encrypt during a duration of the table lock;

flushing the configurable number of data pages to storage following the encrypting of the configurable number of data pages;

based on there being no more data pages to encrypt for the selected table, removing the selected table from the list of tables to be encrypted and releasing the table lock.

15 . The computer system of claim 14 , wherein the list of tables is preserved in permanent storage between system activations.

16 . The computer system of claim 14 , wherein encrypting the table comprises encrypting the configurable number of data pages.

17 . The computer system of claim 14 , wherein encrypting the table comprises decrypting the selected table.

18 . The computer system of claim 14 , wherein encrypting the table comprises re-encrypting the selected table by re-encrypting the configurable number of data pages.

19 . The computer system of claim 14 , wherein the table to encrypt is selected based on data pages belonging to the table not being in a database buffer pool.

20 . The computer system of claim 14 , further comprising:

based on there being more data pages to encrypt in the selected table, and there being waiters to access the selected table, releasing the table lock; and

selecting another table from the list of tables to encrypt.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2024
From: FRENCH, ALEXANDER; RJAIBI, WALID; CHIN, KIRBY; MIRSHAHI, KAMRAN; HWANG, JUNSEO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 069463/0160 →
Continuity (1)
Related Publication 20260154442A1 · Jun 4, 2026
References Cited (24)
US 5717919A · Kodavalla · 1998 [cited by examiner]
US 8122196B2 · Chang · 2012 [cited by examiner]
US 8171307B1 · Chang · 2012 [cited by applicant]
US 8477932B1 · Plotkin et al. · 2013 [cited by applicant]
US 8522041B2 · Hsu et al. · 2013 [cited by applicant]
US 10659225B2 · Surla · 2020 [cited by examiner]
US 11188674B2 · Dageville et al. · 2021 [cited by applicant]
US 11537724B2 · Kaul et al. · 2022 [cited by applicant]
US 20070299843A1 · Deshpande · 2007 [cited by applicant]
US 20140188821A1 · Zhou et al. · 2014 [cited by applicant]
US 20150310221A1 · Lietz et al. · 2015 [cited by applicant]
US 20180032447A1 · Kaplan et al. · 2018 [cited by applicant]
US 20190392166A1 · Awad · 2019 [cited by examiner]
US 20230008874A1 · Stabrawa · 2023 [cited by examiner]
US 20240134840A1 · Kong et al. · 2024 [cited by applicant]
US 20240184766A1 · Ng et al. · 2024 [cited by applicant]
CN 115599872A · 2023 [cited by applicant]
KR 1020090067342A · 2009 [cited by applicant]
“CipherTrust Live Data Transformation Zero-Downtime Encryption and Key Rotation”, Thales, Sep. 2022, 2 pages. [cited by applicant]
“Data Encryption and Rekeying Made Easy”, Entrust-Securing a world in motion, 2022, 9 pages. [cited by applicant]
“Database Administrator's Guide”, Oracle, retrieved from web dated Jan. 10, 2025, 80 pages. [cited by applicant]
“Oracle Advanced Security, Transparent Data Encryption (TDE)”, Oracle Database, Mar. 2018, 10 pages. [cited by applicant]
Rjaibi Walid. “Holistic Database Encryption”, IBM Canada Lab, 8200 Warden Avenue, Markham, Ontario, Canada, 2018, 6 pages. [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty, Apr. 29, 2… [cited by applicant]