EP3149651A2

System and method for secure review of audit logs

Abstract

This record has no abstract on file.

Term

8.7 yearsto projected expiry

Projected expiry 2 June 2035, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 2 independent, 18 dependent

  1. 1
    Claims of equivalent WO 2015187640 A2 What is claimed:1 . A method for searching encrypted log data comprising: generating with a logging machine a first log message include first plaintext content;identifying with the logging machine at least one keyword in the first log message;encrypting with the logging machine the first log message using a first cryptographic key to produce a first encrypted log message;generating with the logging machine a first encrypted searchable representation of the first message including the at least one keyword using a second cryptographic key, the second cryptographic key being different than the first cryptographic key;transmitting with the logging machine the first encrypted searchable representation to an auditor;performing with the auditor a search to identify at least one search keyword in the first encrypted searchable representation, the auditor using the second cryptographic key to access the first encrypted searchable representation;and generating with the auditor a first output indicating presence or absence of the at least one search keyword from the first log message, the first output not including the first plaintext content of the first log message.
  2. 11
    1 1 . An encrypted log generation and audit system comprising:a logging machine communicatively coupled to an auditor, the logging machine being configured to: generate a first log message include first plaintext content;identify at least one keyword in the first log message;encrypt the first log message using a first cryptographic key to produce a first encrypted log message;generate a first encrypted searchable representation of the first message including the at least one keyword using a second cryptographic key, the second cryptographic key being different than the first cryptographic key;and transmit the first encrypted searchable representation to the auditor;and the auditor being configured to: perform a search to identify at least one search keyword in the first encrypted searchable representation, the auditor using the second cryptographic key to access the first encrypted searchable representation;and generate a first output indicating presence or absence of the at least one search keyword from the first log message, the first output not including the first plaintext content of the first log message.