IP Library › Granted Patent US 12,743,543
Granted Patent B2
US 12,743,543 · App. 19/008,773 · Granted Sep 22, 2026

Data lakehouse encryption

Inventors: Sudheesh S. Kairali (Kozhikode, IN); Binoy Thomas (Kozhikode, IN); Sarbajit Kumar Rakshit (Kolkata, IN); Vijay Kalangumvathakkal (Pathanamthitta, IN)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/6227G06F21/602
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,543
App. No.
19/008,773
Granted
Sep 22, 2026
Kind
B2
Abstract

Examples described herein provide a computer-implemented method for data lakehouse encryption that includes receiving a query for data stored in a data lakehouse. The method further includes determining whether the query is a frequent query by comparing a frequency of the query to a threshold. The method further includes, responsive to determining that the query is a frequent query, storing envelope encrypted data and a query index in a frequent data access database, the envelope encrypted data being data that relates to the query. The method further includes, responsive to receiving the query at a later time, returning, to a user, the envelope encrypted data from the frequent data access database without decrypting other data stored in the data lakehouse.

Claims (39)

1 . A computer-implemented method for data lakehouse encryption, the method comprising:

receiving a query for data stored in a data lakehouse;

determining whether the query is a frequent query by comparing a frequency of the query to a threshold;

responsive to determining that the query is a frequent query, storing envelope encrypted data and a query index in a frequent data access database, the envelope encrypted data being data that relates to the query;

responsive to receiving the query at a later time, returning, to a user, the envelope encrypted data from the frequent data access database without decrypting other data stored in the data lakehouse;

monitoring a rate at which the envelope encrypted data in the frequent data access database are queried, and, responsive to the rate being below a threshold rate, removing the envelope encrypted data from the frequent data access database; and

responsive to the rate being below the threshold rate, moving the envelope encrypted data from the frequent data access database and the data from the data lakehouse to an archive.

2 . The computer-implemented method of claim 1 , wherein it is determined that the query is a frequent query responsive to the frequency of the query satisfying the threshold.

3 . The computer-implemented method of claim 2 , wherein the threshold is based on a predefined number of repetitions of the query within a time period.

4 . The computer-implemented method of claim 1 , wherein the envelope encrypted data is encrypted by performing envelope encryption, which comprises encrypting the data with a data encryption key and then encrypting the data encryption key with a key encryption key to encrypt the data.

5 . The computer-implemented method of claim 1 , wherein the threshold is dynamically adjusted.

6 . The computer-implemented method of claim 1 , further comprising updating the frequent data access database in response to any updates or edits to the envelope encrypted data.

7 . A computer system comprising:

a processor set;

one or more computer-readable storage media; and

program instructions stored on the one or more computer-readable storage media to cause the processor set to perform operations comprising:

receiving a query for data stored in a data lakehouse;

determining whether the query is a frequent query by comparing a frequency of the query to a threshold;

responsive to determining that the query is a frequent query, storing envelope encrypted data and a query index in a frequent data access database, the envelope encrypted data being data that relates to the query;

responsive to receiving the query at a later time, returning, to a user, the envelope encrypted data from the frequent data access database without decrypting other data stored in the data lakehouse;

monitoring a rate at which the envelope encrypted data in the frequent data access database are queried, and, responsive to the rate being below a threshold rate, removing the envelope encrypted data from the frequent data access database; and

responsive to the rate being below the threshold rate, moving the envelope encrypted data from the frequent data access database and the data from the data lakehouse to an archive.

8 . The computer system of claim 7 , wherein it is determined that the query is a frequent query responsive to the frequency of the query satisfying the threshold.

9 . The computer system of claim 8 , wherein the threshold is based on a predefined number of repetitions of the query within a time period.

10 . The computer system of claim 7 , wherein the envelope encrypted data is encrypted by performing envelope encryption, which comprises encrypting the data with a data encryption key and then encrypting the data encryption key with a key encryption key to encrypt the data.

11 . The computer system of claim 7 , wherein the threshold is dynamically adjusted.

12 . The computer system of claim 7 , wherein the operations further comprise updating the frequent data access database in response to any updates or edits to the envelope encrypted data.

13 . A computer program product comprising:

one or more computer-readable storage media; and

program instructions stored on the one or more computer-readable storage media to perform operations comprising:

receiving a query for data stored in a data lakehouse;

determining whether the query is a frequent query by comparing a frequency of the query to a threshold;

responsive to determining that the query is a frequent query, storing envelope encrypted data and a query index in a frequent data access database, the envelope encrypted data being data that relates to the query;

responsive to receiving the query at a later time, returning, to a user, the envelope encrypted data from the frequent data access database without decrypting other data stored in the data lakehouse;

monitoring a rate at which the envelope encrypted data in the frequent data access database are queried, and, responsive to the rate being below a threshold rate, removing the envelope encrypted data from the frequent data access database; and

responsive to the rate being below the threshold rate, moving the envelope encrypted data from the frequent data access database and the data from the data lakehouse to an archive.

14 . The computer program product of claim 13 , wherein it is determined that the query is a frequent query responsive to the frequency of the query satisfying the threshold.

15 . The computer program product of claim 14 , wherein the threshold is based on a predefined number of repetitions of the query within a time period.

16 . The computer program product of claim 13 , wherein the envelope encrypted data is encrypted by performing envelope encryption, which comprises encrypting the data with a data encryption key and then encrypting the data encryption key with a key encryption key to encrypt the data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 3, 2025
From: KAIRALI, SUDHEESH S.; THOMAS, BINOY; RAKSHIT, SARBAJIT KUMAR; KALANGUMVATHAKKAL, VIJAY
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 069731/0558 →
Continuity (1)
Related Publication 20260195475A1 · Jul 9, 2026
References Cited (17)
US 10528557B1 · Chmil et al. · 2020 [cited by applicant]
US 11567936B1 · Jindal · 2023 [cited by examiner]
US 12019631B1 · Chaubey et al. · 2024 [cited by applicant]
US 20160330180A1 · Egorov · 2016 [cited by examiner]
US 20180351921A1 · Sharifi Mehr · 2018 [cited by examiner]
US 20190361888A1 · Das · 2019 [cited by examiner]
US 20220292092A1 · Brown · 2022 [cited by examiner]
Pradeep Rao Vennamaneni, Delta Lake Optimization Techniques for Scalable Lakehouse, International Journal of Sustainability and Innovation in Engineering (IJSIE) (Oct. 19, 2024) (Year: 2024). [cited by examiner]
Antony et al., “Multidimensional Bucketization for Frequent Queries over Encrypted Data”, IJIRCCE, https://ijircce.com/admin/main/storage/app/pdf/FpUZ5azU3w0cM7CKuwMRYTTAtDzC8v4Mwa514Qfc.pdf, Nov. 2015, 6 pages. [cited by applicant]
Authors et. al., Disclosed Without Attribution, Intelligent Log Management in Data Lakehouses, IPCOM000274422D, May 17, 2024, 5 pages. [cited by applicant]
Dorneanu et al., “Build secure encrypted data lakes with AWS Lake Formation”, https://aws.amazon.com/blogs/big-data/build-secure-encrypted-data-lakes-with-aws-lake-formation/, Jun. 4, 2021, 17 pages. [cited by applicant]
IBM, “Data lake solutions”, retrieved from web https://www.ibm.com/data-lake, dated Feb. 27, 2025, 5 pages. [cited by applicant]
IBM, “What is a data lake?”, retrieved from web https://www.ibm.com/think/topics/data-lake, Jan. 16, 2025, 5 pages. [cited by applicant]
L'Esteve, “Advanced Databricks Lakehouse Capabilities”, Azure Databricks, https://www.mssqltips.com/sqlservertip/7244/advanced-databricks-lakehouse-encryption-security-query-plans-cdc/, May 10, 2022, 11 pages. [cited by applicant]
Lukichev, “Enhancing Query Efficiency in Lakehouses”, Telmai, Apr. 16, 2024, 5 pages. [cited by applicant]
Mellor et al., “Dell enhances data lakehouse with faster query speeds and more”, Blocks&Files, https://blocksandfiles.com/2024/07/24/queries-data-lakehouse-upgrade/, Jul. 24, 2024, 4 pages. [cited by applicant]
Tang et al., “Separation Is for Better Reunion: Data Lake Storage at Huawei”, 2024 IEEE 40th International Conference on Data Engineering (ICDE), https://ieeexplore.ieee.org/document/10598130, Jul. 23, 2024, 14 pages. [cited by applicant]