Nova Patents
EP0884670A1

Secure database

Abstract

A secure database system comprises a server having a database including at least one personal information table and at least one further table containing information relating to the persons whose details are stored in the personal information table. The keys of the tables in the database are unrelated, so that it is impossible to determine solely from information in the server which record in the further table corresponds to which record in the personal information table. Thus, even if a hacker obtains access to the database, the hacker will not be able to relate information in the different tables. Each legitimate client uses an encryption process to convert a personal identifier value, which identifies the record relating to a particular person in the personal information table, into a pseudo-identifier value, which identifies a record relating to the same person in the further table.

EP0884670A1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 6 May 2018, 8.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

10 claims: 4 independent, 6 dependent

  1. 1
    A computer system comprising:(a) a server having a database including at least one personal information table and at least one further table containing information relating to persons whose details are stored in the personal information table;and (b) a plurality of clients, for accessing said database;characterised in that (c) said tables in said database have keys that are unrelated to each other, whereby it is impossible to determine solely from information in the server which record in said further table corresponds to which record in said personal information table;and (d) each client includes an encryption process for converting a personal identifier value, which identifies a record relating to a particular person in said personal information table, into a pseudo-identifier value, which identifies a record relating to the same person in said further table.
  2. 6
    A method of securely storing data in a database, comprising:(a) storing in a server a database including at least one personal information table and at least one further table containing information relating to persons whose details are stored in the personal information table;(b) providing said tables with keys that are unrelated to each other, whereby it is impossible to determine solely from information in the server which record in said further table corresponds to which record in said personal information table;(c) operating a plurality of clients to access said database;and (d) performing, in each said client, an encryption process which converts a personal identifier value, identifying a record relating to a particular person in said personal information table, into a pseudo-identifier value, which identifies a record relating to the same person in said further table.
  3. 9
    A method according to any of Claims 6 to 8 wherein said database includes at least one free text table containing free text information, and wherein each said client encrypts text before writing it into said free text table and decrypts text when read from said free text table.
  4. 10
    A method according to any of Claims 6 - 9 wherein information is encrypted while in transit between said client and said server.