US2002174352A1PendingUtilityA1

Data security system for a database

Assignee: ANONYMITY PROT IN SWEDEN ABPriority: Jun 20, 1996Filed: Apr 24, 2001Published: Nov 21, 2002
Est. expiryJun 20, 2016(expired)· nominal 20-yr term from priority
Inventors:Ulf Dahl
H04L 9/088G06F 21/6245G06F 21/6218H04L 9/0894G06F 2221/2141G06F 2221/2149G06F 21/6227G06F 2211/007Y10S707/99939H04K 1/00
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and an apparatus for processing data provides protection for the data. The data is stored as encrypted data element values (DV) in records (P) in a first database (O-DB), each data element value being linked to a corresponding data element type (DT). In a second database (IAM-DB), a data element protection catalogue (DC) is stored, which for each individual data element type (DT) contains one or more protection attributes stating processing rules for data element values (DV), which in the first database (O-DB) are linked to the individual data element type (DT). In each user-initiated measure which aims at processing a given data element value (DV) in the first database (O-DB), a calling is initially sent to the data element protection catalogue for collecting the protection attribute/attributes associated with the corresponding data element types. The user's processing of the given data element value is controlled in conformity with the collected protection attribute/attributes.

Claims

exact text as granted — not AI-modified
1 . A method for processing of data that is to be protected, comprising the measure of storing the data as encrypted data element values (DV) in records (P) in a first database (O-DB), each data element value being linked to a corresponding data element type (DT), characterised by the steps of 
 storing in a second database (IAM-DB) a data element protection catalogue (DC), which for each individual data element type (DT) contains one or more protection attributes stating processing rules for data element values (DV), which in the first database (O-DB) are linked to the individual data element type (DT),    for each user-initiated measure aiming at processing of a given data element value (DV) in the first database (O-DB), initially producing a compelling calling to the data element protection catalogue for collecting the protection attribute/attributes associated with the corresponding data element type, and    compellingly controlling the user's processing of the given data element value in conformity with the collected protection attribute/attributes.    
     
     
         2 . A method as claimed in  claim 1 , further comprising the measure of storing the protection attribute/attributes of the data element protection catalogue (DC) in encrypted form in the second database (IAM-DB) and, when collecting protection attribute/attributes from the data element protection catalogue (DC) effecting decryption thereof.  
     
     
         3 . A method as claimed in any one of the preceding claims, wherein each record (P) in the first database (O-DB) has a record identifier, and wherein the method further comprises the measure of storing the record identifier in encrypted form (SID) in the first database (O-DB).  
     
     
         4 . A method as claimed in any one of the preceding claims, wherein the encryption of data in the first database (O-DB) and/or the encryption of data in the second database (IAM-DB) is carried out in accordance with the PTY principle with floating storage identity.  
     
     
         5 . A method as claimed in any one of the preceding claims, wherein the protection attribute/attributes of the data element types comprise attributes stating rules for encryption of the corresponding data element values in the first database (O-DB).  
     
     
         6 . A method as claimed in any one of the preceding claims, wherein the protection attribute/attributes of the data element types comprise attributes stating rules for which program/programs or program versions is/are allowed to be used for managing the corresponding data element values in the first database (O-DB).  
     
     
         7 . A method as claimed in any one of the preceding claims, wherein the protection attribute/attributes of the data element values comprise attributes stating rules for logging the corresponding data element values in the first database (O-DB).  
     
     
         8 . An apparatus for processing data that is to be protected, comprising a first database (O-DB) for storing said data as encrypted data element values (DV) in records (P), each data element value being linked to a corresponding data element type (DT), characterised by 
 a second database (IAM-DB) for storing a data element protection catalogue (DC), which for each individual data element type (DT) contains one or more protection attributes stating processing rules for data element values (DV), which in the first database (O-DB) are linked to the individual data element type (DT),    means which are adapted, in each user-initiated measure aiming at processing a given data element value (DV) in the first database (O-DB), to initially produce a compelling calling to the data element protection catalogue for collecting the protection attribute/attributes associated with the corresponding data element types, and    means which are adapted to compellingly control the user's processing of the given data element value in conformity with the collected protection attribute/attributes.

Join the waitlist — get patent alerts

Track US2002174352A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.