US2014281511A1PendingUtilityA1

Secure data processing on sensitive data using trusted hardware

Assignee: MICROSOFT CORPPriority: Mar 15, 2013Filed: Aug 27, 2013Published: Sep 18, 2014
Est. expiryMar 15, 2033(~6.6 yrs left)· nominal 20-yr term from priority
H04L 63/062H04L 2463/062G06F 21/602H04L 63/045H04L 63/0428G06F 21/6245
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The subject disclosure is directed towards using trusted hardware to achieve secure data processing over a network. For a given set of data store operations, some operations are directed to sensitive data (e.g., encrypted data fields). These operations are compiled into a set of expressions invoking trusted hardware code configured to evaluate these expressions using corresponding data centric primitive programs. Because the trusted hardware is configured to maintain key data for encrypting/decrypting the sensitive data, the sensitive data is not accessible by an untrusted component while the sensitive data is decrypted.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . In a computing environment, a method performed at least in part on at least one processor, comprising, providing secure data processing over a network, including, identifying a set of expressions corresponding to encrypted data, transforming the set of expressions and the encrypted data into an execution plan invoking data centric primitive logic within trusted hardware, the trusted hardware is configured to maintain key data for decrypting the encrypted data, and communicating the execution plan to the trusted hardware over a network. 
     
     
         2 . The method of  claim 1  further comprising encrypting an application encryption key using a public key associated with the trusted hardware. 
     
     
         3 . The method of  claim 1 , wherein identifying the set of expressions further comprises translating a set of queries into the set of expressions. 
     
     
         4 . The method of  claim 1  further comprising generating a bitstream representing custom trusted hardware code for execution by a stack machine. 
     
     
         5 . The method of  claim 1  further comprising communicating the execution plan to an untrusted component running a database management system. 
     
     
         6 . The method of  claim 1 , wherein identifying the set of expressions further comprises compiling a set of data store operations into the execution plan in which each expression corresponds to trusted hardware code implementing at least one data centric primitive. 
     
     
         7 . The method of  claim 1 , wherein identifying the set of expressions further comprises partitioning a plurality of data store operations into a set of data store operations involving sensitive data and a second set of other data store operations, and generating the execution plan directing the set of data store operations to the trusted hardware and the other data store operations for execution on an untrusted database management system. 
     
     
         8 . In a computing environment, a system, comprising, a trusted component coupled to an untrusted component and configured to maintain key data for evaluating expressions on sensitive data, the untrusted component is configured to communicate the expressions to the trusted component, the trusted component is further configured to interpret an expression as a set of data centric primitives, to instruct trusted hardware to execute code implementing the set of data centric primitives, including decrypting or encrypting the sensitive data using the key data, and to return secure results to the untrusted component. 
     
     
         9 . The system of  claim 8 , wherein the trusted component is further configured to authenticate configuration data using a device encryption key. 
     
     
         10 . The system of  claim 8 , wherein the trusted component is further configured to encrypt application encryption keys with a device encryption key, and store the encrypted application encryption keys in memory. 
     
     
         11 . The system of  claim 8 , wherein the trusted component is further configured to decrypt application encryption keys using a private encryption key. 
     
     
         12 . The system of  claim 8 , wherein the trusted component is further configured to store in memory a stack machine program implementing a custom data centric primitive. 
     
     
         13 . The system of  claim 8 , wherein the trusted component is further configured to communicate a secure bitstream comprising the secure results to the untrusted component, including encrypting a bitstream with an application encryption key. 
     
     
         14 . The system of  claim 8 , wherein the trusted hardware comprises a plurality of secure processing units in which each secure processing unit is configured to execute at least one data centric primitive program. 
     
     
         15 . The system of  claim 8 , wherein the trusted hardware is further configured to couple to a client machine via a device identifier. 
     
     
         16 . The system of  claim 8 , wherein the trusted hardware comprises at least one Field Programmable Gate Array. 
     
     
         17 . One or more computer-readable media having computer-executable instructions, which when executed perform steps, comprising:
 interpreting an execution plan comprising a first set of expressions and a second set of expressions in which the first set of expressions correspond to non-sensitive data and the second set of expressions correspond to sensitive data, including executing the first set of expressions, and communicating the second set of expressions to trusted hardware for execution; and   generating secure results in response to executing the execution plan.   
     
     
         18 . The one or more computer-readable media of  claim 17  having further computer-executable instructions comprising:
 instructing a plurality of secure processing units to execute concurrent operations over the sensitive data. 
 
     
     
         19 . The one or more computer-readable media of  claim 17  having further computer-executable instructions comprising:
 instructing a stack machine within the trusted hardware to execute a data centric primitive program. 
 
     
     
         20 . The one or more computer-readable media of  claim 17  having further computer-executable instructions comprising:
 returning the secure results to a client machine over the network.

Join the waitlist — get patent alerts

Track US2014281511A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.