Secure database backup and recovery

US10554403B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10554403-B2
Application numberUS-201916412629-A
CountryUS
Kind codeB2
Filing dateMay 15, 2019
Priority dateNov 6, 2014
Publication dateFeb 4, 2020
Grant dateFeb 4, 2020

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

As disclosed herein a computer system for secure database backup and recovery in a secure database network has N distributed data nodes. The computer system includes program instructions that include instructions to receive a database backup file, fragment the file using a fragment engine, and associate each fragment with one node, where the fragment is not stored on the associated node. The program instructions further include instructions to encrypt each fragment using a first encryption key, and store, randomly, encrypted fragments on the distributed data nodes. The program instructions further include instructions to retrieve the encrypted fragments, decrypt the encrypted fragments using the first encryption key, re-encrypt the decrypted fragments using a different encryption key, and store, randomly, the re-encrypted fragments on the distributed data nodes. A computer program product and method corresponding to the above computer system are also disclosed herein.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for secure database backup and recovery in a secure database network comprising a plurality of distributed data nodes, the method comprising: receiving a database backup file from a database system; fragmenting the database backup file into a plurality of fragments using a fragment engine; associating each fragment of the plurality of fragments with a node of the plurality of distributed data nodes, respectively, wherein the associating comprises specifying that each fragment is not to be stored on the node with which the fragment is associated; encrypting each fragment of the plurality of fragments using a first encryption key, thereby providing a plurality of encrypted fragments; storing, randomly, the plurality of encrypted fragments on the plurality of distributed data nodes; retrieving, after a determined duration, the plurality of encrypted fragments; decrypting the plurality of encrypted fragments using the first encryption key, thereby providing a plurality of decrypted fragments; re-encrypting the plurality of decrypted fragments using a different encryption key, thereby providing a plurality of re-encrypted fragments; and storing, randomly, the plurality of re-encrypted fragments on the plurality of distributed data nodes. 2. The method of claim 1 , wherein the database system is unaware of a location of a stored fragment. 3. The method of claim 2 , wherein storing and retrieving the stored fragment is performed by database agents and sensors corresponding to the plurality of distributed data nodes. 4. The method of claim 1 , wherein each fragment of the plurality of re-encrypted fragments is stored on a different node than that from which an encrypted fragment was retrieved. 5. The method of claim 1 , further comprising: fragmenting the first encryption key and the different encryption key using an encryption key generator and key store; encrypting each key fragment; and storing, randomly, each encrypted key fragment on the plurality of distributed data nodes. 6. The method of claim 5 , further comprising adding database metadata to a key fragment, thereby providing fragmented and distributed metadata. 7. The method of claim 6 , wherein the database metadata includes at least one of a network configuration, a database node location, and a backup image expiration. 8. The method of claim 1 , wherein encrypting uses public key and private key encryption. 9. The method of claim 1 , wherein a coordination engine associates each fragment with a node. 10. A computer program product comprising: one or more computer readable storage media and program instructions stored on the one or more computer readable storage media, the program instructions comprising instructions to: receive a database backup file from a database system; fragment the database backup file into a plurality of fragments using a fragment engine; associate each fragment of the plurality of fragments with a node of a plurality of distributed data nodes, respectively, wherein the associating comprises specifying that each fragment is not to be stored on the node with which the fragment is associated; encrypt each fragment of the plurality of fragments using a first encryption key, thereby providing a plurality of encrypted fragments; store, randomly, the plurality of encrypted fragments on the plurality of distributed data nodes; retrieve, after a determined duration, the plurality of encrypted fragments; decrypt the plurality of encrypted fragments using the first encryption key, thereby providing a plurality of decrypted fragments; re-encrypt the plurality of decrypted fragments using a different encryption key, thereby providing a plurality of re-encrypted fragments; and store, randomly, the plurality of re-encrypted fragments on the plurality of distributed data nodes. 11. The computer program product of claim 10 , wherein the database system is unaware of a location of a stored fragment. 12. The computer program product of claim 11 , wherein the program instructions to store and retrieve the stored fragment are performed by database agents and node sensors corresponding to the plurality of distributed data nodes. 13. The computer program product of claim 10 , wherein each fragment of the plurality of re-encrypted fragments is stored on a different node than that from which an encrypted fragment was retrieved. 14. The computer program product of claim 10 , wherein the program instructions comprise instructions to: use an encryption key generator and key store to fragment the first encryption key and the different encryption key; encrypt each key fragment; and store, randomly, each key fragment on the plurality of distributed data nodes. 15. The computer program product of claim 14 , wherein the program instructions comprise instructions to add database metadata to a key fragment, thereby providing fragmented and distributed metadata. 16. The computer program product of claim 15 , wherein the database metadata includes at least one of a network configuration, a database node location, and a backup image expiration. 17. The computer program product of claim 10 , wherein the program instructions to encrypt comprise instructions to use public key and private key encryption. 18. The computer program product of claim 10 , wherein a coordination engine associates each fragment with a node.

Assignees

Inventors

Classifications

  • Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy · CPC title

  • Management of the data involved in backup or backup restore · CPC title

  • Computing aids in which the computing members form at least part of the displayed result and are manipulated directly by hand, e.g. abacuses or pocket adding devices · CPC title

  • File encryption · CPC title

  • Secret sharing or secret splitting, e.g. threshold schemes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10554403B2 cover?
As disclosed herein a computer system for secure database backup and recovery in a secure database network has N distributed data nodes. The computer system includes program instructions that include instructions to receive a database backup file, fragment the file using a fragment engine, and associate each fragment with one node, where the fragment is not stored on the associated node. The pr…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L9/0891. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 04 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).