EP2731040A1

Computer system for storing and retrieval of encrypted data items, client computer, computer program product and computer-implemented method

Abstract

The present invention relates to a computer system comprising: - multiple sets (S1, S2,..., Si,..., SI-1, SI) of client computers (Ci1, Ci2,..., Cij,... CiJ), each client computer having installed thereon an application program (104), the application program comprising client computer specific log-in information (Lij), - a database system (112) being coupled to the set of client computers via a network (114), the database system having a log-in component (118) for logging-in the client computers, the database system being partitioned into multiple relational databases (DB1, DB2, ...DBi,...DBI), each one of the databases being assigned to one set of the sets of client computers, each database storing encrypted data items, each data item being encrypted with one of the user or user-group specific cryptographic keys, the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, the log-in component comprising assignment information (118) indicative of the assignment of the databases to the set of client computers.

EP2731040A1, drawing sheet 1
Sheet 1 of 5

Term

6.1 yearsto projected expiry

Projected expiry 8 November 2032, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

22 claims: 5 independent, 17 dependent

  1. 1
    A computer system comprising:- multiple sets (S1, S2,...,Si,...,SI-1, SI) of client computers (Ci1, Ci2,...,Cij,...CiJ), each client computer having installed thereon an application program (104), the application program comprising client computer specific log-in information (Lij), - a database system (112) being coupled to the set of client computers via a network (114), the database system having a log-in component (118) for logging-in the client computers, the database system being partitioned into multiple relational databases (DB1, DB2, ... DBi,... DBI), each one of the databases being assigned to one set of the sets of client computers, each database storing encrypted data items, each data item being encrypted with a user or user-group specific cryptographic key, the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, the log-in component comprising assignment information (118) indicative of the assignment of the databases to the set of client computers, each one of the application programs being operational to perform the steps of: a) establishing a network session (122) with the database system over the network, b) transmitting the client computer specific log-in information to the database system via the session, c) receiving the key and the key identifier by the client computer for use of the key by the client computer and without transmitting the key to the database system;d) entry of a search criterion into the client computer, e) generating a database query (124) using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier, f) in response to the query, receiving at least one encrypted data item (126) matching the search criterion from the database system, g) decrypting the encrypted data item using the cryptographic key, the database system being operational to perform the steps of : i) receiving the client computer specific log-in information via the session by the log-in component of the database system, ii) determining one of the databases of the database system that is assigned to the client computer on which the application program is installed using the assignment information, by the log-in component of the database system, iii) entering the query received from the application program via the session into the database that has been determined using the log-in information for processing the query by that database.
  2. 3
    The computer system of claims 1 or 2, wherein the received key is erased from a memory (108) of the client computer if any one of the following events occurs:- the application program which has received the key is closed;- the user is logged out from the client computer by a client log-in component (148, 150) after a timeout condition has been fulfilled;- the user session with the application program is timed out or closed by the user;- switching off a power supply of the client computer, - exhausting the storage capacity of a battery that powers the client computer;- entry of a user command in response to which the key is erased.
  3. 4
    The computer system of claims 1, 2 or 3, a first sub-set of the client computers of at least some of the sets of client computers being located in a separate access restricted environment (102.1, 102.2,...,102.i,...,102.I-1,102.I) a second sub-set of the client computers being located outside the access restricted environment.
  4. 18
    A client computer for storing a data item in and reading the data item from a database system (112) via a network (114), the client computer comprising:- an application program (104), the application program comprising client computer specific log-in information (Lij), - a communication interface (144) for receiving a user or user-group specific key (108) and a key identifier (110) of that cryptographic key, the communication interface (144) being operational for manual entry of user information specifying the user or user-group specific key (108) and a key identifier (110) and/or for communication with one security token (STik) of a set of security tokens, the security token being assigned to one authorized user, a user or user-group specific key (108) and a key identifier (110) of that cryptographic key being stored on the security token, - a network communication interface (164) for communication with a database system, the application program being operational to perform the following steps for writing the data item to the database system: - entry of the data item into the client computer, - encrypting the data item with the key that has been received by the client computer, - generating a database insert command, the insert command comprising the encrypted data item and the key identifier of the key with which the data item has been encrypted as an attribute of the encrypted data item for storing the encrypted data item in the database system with the key identifier as an attribute, - establishing a session (122) with the database system over the network by the network communication interface, - transmitting the insert command via the session to the database system for processing by the one of the databases that has been determined to be assigned to the client computer by the log-in component such that the encrypted data item with the key identifier is stored in that database, the application program being operational to perform the following steps for reading the data item: - establishing a session (122) with the database system over the network, - transmitting the client computer specific log-in information to the database system via the session, - entry of the key and the key identifier from one of the security tokens into the client computer for use of the key by the client computer and without transmitting the key to the database system;- entry of a search criterion into the client computer, - generating a database query (124) using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier, - in response to the query, receiving an encrypted data item (126) matching the search criterion from the database system, - decrypting the encrypted data item using the cryptographic key.
  5. 19
    A client computer system comprising a client computer in accordance with claim 18 and a security token (STik), the security token having a communication interface (142) for communication with the communication interface (144) of the client computer.
  6. 20
    A computer program product, in particular the digital storage medium, comprising instructions that are executable by a client computer (Cij), the computer program product being an application program (104), the application program being operational to perform the following steps for writing the data item to the database system:- entry of the data item into the client computer, - encrypting the data item with the key that has been entered into the client computer, - generating a database insert command, the insert command comprising the encrypted data item and the key identifier of the key with which the data item has been encrypted as an attribute of the encrypted data item for storing the encrypted data item in the database system with the key identifier as an attribute and an electronic signature, - establishing a session (122) with the database system over the network by the network communication interface, - transmitting the insert command via the session to the database system for processing by the one of the databases that has been determined to be assigned to the client computer by the log-in component such that the encrypted data item with the key identifier is stored in that database, the application program being operational to perform the following steps for reading the data item: - establishing a network session (122) with the database system over the network, - transmitting the client computer specific log-in information to the database system via the session, - entry of the key and the key identifier from one of the security tokens into the client computer for use of the key by the client computer and without transmitting the key to the database system;- entry of a search criterion into the client computer, - generating a database query (124) using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier, - in response to the query, receiving an encrypted data item (126) matching the search criterion from the database system, - decrypting the encrypted data item using the cryptographic key.