The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 15, 2015

Filed:

Nov. 22, 2013
Applicants:

Florian Kerschbaum, Karlsruhe, DE;

Martin Haerterich, Wiesloch, DE;

Mathias Kohler, Stutensee, DE;

Isabelle Hang, Karlsruhe, DE;

Andreas Schaad, Karlsruhe, DE;

Axel Schroepfer, Rheinstetten, DE;

Walter Tighzert, Heidelberg, DE;

Patrick Grofig, Karlsruhe, DE;

Inventors:

Florian Kerschbaum, Karlsruhe, DE;

Martin Haerterich, Wiesloch, DE;

Mathias Kohler, Stutensee, DE;

Isabelle Hang, Karlsruhe, DE;

Andreas Schaad, Karlsruhe, DE;

Axel Schroepfer, Rheinstetten, DE;

Walter Tighzert, Heidelberg, DE;

Patrick Grofig, Karlsruhe, DE;

Assignee:

SAP SE, Walldorf, DE (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 17/30 (2006.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 17/30864 (2013.01); G06F 21/6227 (2013.01);
Abstract

Embodiments relate to processing encrypted data, and in particular to identifying an appropriate layer of encryption useful for processing a query. Such identification (also known as the onion selection problem) is achieved utilizing an adjustable onion encryption procedure. Based upon defined requirements of policy configuration, alternative resolution, and conflict resolution, the adjustable onion encryption procedure entails translating a query comprising an expression in a database language (e.g. SQL) into an equivalent query on encrypted data. The onion may be configured in almost arbitrary ways directing the onion selection. An execution function introduces an execution split to allow local (e.g. client-side) query fulfillment that may otherwise not be possible in a secure manner on the server-side. A searchable encryption function may also be employed, and embodiments accommodate aggregation via homomorphic encryption. Embodiments may be implemented as an in-memory column store database system.


Find Patent Forward Citations

Loading…