EP2731041A1

Computer system for storing and retrieval of encrypted data items, client computer, computer program product and computer-implemented method

Abstract

The invention relates to a computer system comprising a client computer (10) and a database (30) stored on a server (22), the server (22) being coupled to the client computer (10) via a network (48; 114), wherein the database (30) comprises a first relation (36) and a second relation (32; 34), wherein the first relation (36) comprises first data items, wherein the first data items are encrypted with a first cryptographic key (18; 108) in the first relation (36), wherein the second relation (32; 34) comprises equivalence classes, wherein the equivalence classes are encrypted with a second cryptographic key (18; 108) in the second relation (32; 34), wherein each equivalence class is a functional value of one of the first data items, the functional value being obtainable by applying an equivalence relation to the one of the first data items, wherein the second relation (32; 34) comprises for each equivalence class a referential connection assigning the equivalence class to the first data item stored encrypted in the first relation (36) whose equivalence class is the functional value of said first data item, wherein the client computer (10) has installed thereon an application program (17), the application program (17) being operational to perform the steps of: - receiving a search criterion (19), - applying the equivalence relation to the search criterion (19) for obtaining a search equivalence class, - encrypting the search equivalence class with the second cryptographic key (18; 108), - generating a database query (20) using the encrypted search equivalence class, - entering the database query (20) into the database (30) stored on the server (22), - in response to the query, receiving an encrypted first data item matching the equivalence relation of the search criterion (19), - decrypting the received encrypted first data item using the first cryptographic key (18; 108).

EP2731041A1, drawing sheet 1
Sheet 1 of 10

Term

6.1 yearsto projected expiry

Projected expiry 9 November 2032, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

18 claims: 12 independent, 6 dependent

  1. 1
    A computer system comprising a client computer (10) and a database (30) stored on a server (22), the server (22) being coupled to the client computer (10) via a network (48; 114), wherein the database (30) comprises a first relation (36) and a second relation (32; 34), wherein the first relation (36) comprises first data items, wherein the first data items are encrypted with a first cryptographic key (18; 108) in the first relation (36), wherein the second relation (32; 34) comprises equivalence classes, wherein the equivalence classes are encrypted with a second cryptographic key (18; 108) in the second relation (32; 34), wherein each equivalence class is a functional value of one of the first data items, the functional value being obtainable by applying an equivalence relation to the one of the first data items, wherein the second relation (32; 34) comprises for each equivalence class a referential connection assigning the equivalence class to the first data item stored encrypted in the first relation (36) whose equivalence class is the functional value of said first data item, wherein the client computer (10) has installed thereon an application program (17), the application program (17) being operational to perform the steps of:- receiving a search criterion (19), - applying the equivalence relation to the search criterion (19) for obtaining a search equivalence class, - encrypting the search equivalence class with the second cryptographic key (18;108), - generating a database query (20) using the encrypted search equivalence class, - entering the database query (20) into the database (30) stored on the server (22), - in response to the query, receiving an encrypted first data item matching the equivalence relation of the search criterion (19), - decrypting the received encrypted first data item using the first cryptographic key (18;108), wherein the database (30) is operational to perform the steps of: - receiving the database query (20), - applying the query to the second relation (32;34) for obtaining a matching equivalence class, - determining in the first relation (36) the encrypted first data item assigned to the matching equivalence class using the referential connection of the matching equivalence class, - providing the determined encrypted first data item (24) to the client computer (10).
  2. 4
    The system of any of the previous claims, wherein the equivalence relation comprises a text normalization function.
  3. 5
    The system of any of the previous claims, wherein the equivalence relation comprises a truncation function for truncating a predefined portion of each of the first data items.
  4. 6
    The system of any of the previous claims, wherein database (30) further comprises an index of the second relation (32;34), wherein the database (30) is operational to apply the query to the second relation (32;34) using the index of the second relation (32;34).
  5. 7
    The system of any of the previous claims, wherein the database (30) is a relational database (30).
  6. 8
    The system of any of the previous claims, wherein the first and the second cryptographic key are identical.
  7. 9
    The system of any of the previous claims, wherein the client computer (10) is a client computer (10) of a multiple sets (S1, S2,...,Si,...,SI-1, SI) of client computers (Ci1, Ci2,...,Cij,...CiJ), each client computer (10) having installed thereon the application program (104), the application program comprising client computer (10) specific log-in information (Lij), wherein the system further comprises:- a database system (22;112), the database system (22;112) comprising the database (30), the database system having a log-in component (118) for logging-in the client computers, the database system being partitioned into multiple relational databases (DB1, DB2, ... DBi,... DBI), each one of the databases being assigned to one set of the sets of client computers, each database storing encrypted data items, wherein the first data items are comprised in said data items, each data item being encrypted with a user or user-group specific cryptographic key, wherein the first cryptographic key corresponds to said user or user-group specific cryptographic key. the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, the log-in component comprising assignment information (118) indicative of the assignment of the databases to the set of client computers, each one of the application programs being operational to perform the steps of: h) establishing a network session (122) with the database system over the network, i) transmitting the client computer specific log-in information to the database system via the session, j) receiving the key and the key identifier by the client computer for use of the key by the client computer and without transmitting the key to the database system;k) entry of a search criterion into the client computer, l) generating a database query (124) using the search criterion and the key identifier, the key identifier limiting the query to encrypted data items that have an attribute matching the key identifier, m) in response to the query, receiving at least one encrypted data item (126) matching the search criterion from the database system, n) decrypting the encrypted data item using the cryptographic key, the database system being operational to perform the steps of : iv) receiving the client computer specific log-in information via the session by the log-in component of the database system, v) determining one of the databases of the database system that is assigned to the client computer on which the application program is installed using the assignment information, by the log-in component of the database system, vi) entering the query received from the application program via the session into the database that has been determined using the log-in information for processing the query by that database.
  8. 11
    The computer system of claims 9 or 10, wherein the received key is erased from a memory (108) of the client computer if any one of the following events occurs:- the application program which has received the key is closed;- the user is logged out from the client computer by a client log-in component (148, 150) after a timeout condition has been fulfilled;- the user session with the application program is timed out or closed by the user;- switching off a power supply of the client computer, - exhausting the storage capacity of a battery that powers the client computer;- entry of a user command in response to which the key is erased.
  9. 13
    A client computer (10) for updating a database (30) stored on a server (22) via a network (48; 114), wherein the database (30) comprises a first relation (36) and a second relation (32; 34), wherein the client computer (10) has installed thereon an application program (17), the application program being operational to perform the steps of:- receiving a first data item, - applying an equivalence relation to the first data item for obtaining a functional value, the functional value describing an equivalence class of the first data item, - encrypting the equivalence class using a second cryptographic key (18;108), - encrypting the first data item using a first cryptographic key (18;108), - sending the encrypted first data item to the database (30) for storage with a first relation (36), - sending the encrypted equivalence class to the database (30) for storage with a second relation (32;34), - instructing the database (30) to add a referential connection to the stored encrypted equivalence class, the referential connection assigning the encrypted equivalence class to the stored encrypted first data item.
  10. 15
    A method of querying by a client computer (10) a database (30) stored on a server (22), the server (22) being coupled to the client computer (10) via a network (48; 114), wherein the database (30) comprises a first relation (36) and a second relation (32; 34), wherein the first relation (36) comprises first data items, wherein the first data items are encrypted with a first cryptographic key (18; 108) in the first relation (36), wherein the second relation (32; 34) comprises equivalence classes, wherein the equivalence classes are encrypted with a second cryptographic key (18; 108) in the second relation (32; 34), wherein each equivalence class is a functional value of one of the first data items, the functional value being obtainable by applying an equivalence relation to the one of the first data items, wherein the second relation (32; 34) comprises for each equivalence class a referential connection assigning the equivalence class to the first data item stored encrypted in the first relation (36) whose equivalence class is the functional value of said first data item, the method comprising at the client computer (10):- receiving a search criterion (19), - applying the equivalence relation to the search criterion (19) for obtaining a search equivalence class, - encrypting the search equivalence class with the second cryptographic key (18;108), - generating a database query (20) using the encrypted search equivalence class, - entering the database query (20) into the database (30) stored on the server (22), - in response to the query, receiving an encrypted first data item matching the equivalence relation of the search criterion (19), - decrypting the received encrypted first data item using the first cryptographic key (18;108), the method further comprising at the server (22): - receiving the database query (20), - applying the query to the second relation (32;34) for obtaining a matching equivalence class, - determining in the first relation (36) the encrypted first data item assigned to the matching equivalence class using the referential connection of the matching equivalence class, - providing the determined encrypted first data item (24) to the client computer (10).
  11. 16
    A method of updating a database (30) stored on a server (22), wherein the database (30) comprises a first relation (36) and a second relation (32; 34), wherein the method comprises at a client computer (10):- receiving a first data item, - applying an equivalence relation to the first data item for obtaining a functional value, the functional value describing an equivalence class of the first data item, - encrypting the equivalence class using a second cryptographic key (18;108), - encrypting the first data item using the first cryptographic key (18;108), - sending the encrypted first data item to the database (30) for storage with a first relation (36), - sending the encrypted equivalence class to the database (30) for storage with a second relation (32;34), - instructing the database (30) to add a referential connection to the stored encrypted equivalence class, the referential connection assigning the encrypted equivalence class to the stored encrypted first data item.
  12. 18
    A computer program product comprising computer executable instructions to perform the method steps as claimed in any of the previous method claims.