Data storage server and client device for securely storing and retrieving data

By obfuscating security-sensitive data on client devices and updating database indexes using hash or HMAC values, the problems of sensitive data storage and range query in cloud storage systems are solved, and data privacy and query efficiency are improved.

CN120188154APending Publication Date: 2025-06-20HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101739.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

When existing cloud storage systems store and query security sensitive data, they may cause cloud storage providers to access sensitive data that users do not want to access, and cannot effectively support range queries for security sensitive data.

Method used

By obfuscating security-sensitive data on the client device (such as encryption and/or compression) and using hash or HMAC values ​​as index data, an insert data request is sent to the data storage server to store obfuscated data, and updating the database index to support range queries.

Benefits of technology

It realizes the secure storage and query of secure sensitive data without exposing the data content, ensuring data privacy and supporting scope query operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120188154A_ABST
    Figure CN120188154A_ABST
Patent Text Reader

Abstract

The invention relates to a client device (110) for storing data in a data storage server (120) and retrieving data from the data storage server (120). The client device (110) comprises a processor (111) configured to determine, based on an insertion data query comprising at least one data element, a digest value for one or more most significant bits of a binary representation of the at least one data element, and obfuscate, e.g., encrypt, the at least one data element. The client device (110) further comprises a communication interface (113) for sending an insertion data request to the data storage server (120) to store the at least one obfuscated data element, and updating a database index (125a) to locate the at least one obfuscated data element in the data storage server (120).
Need to check novelty before this filing date? Find Prior Art

Claims

1. A client device (110), characterized in that, For storing data in a data storage server (120) and retrieving data from the data storage server (120), the client device (110) includes: A processor (111) for determining, based on an insert data query including at least one data element (210), a digest value (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one data element (210), and obfuscating the at least one data element (210); A communication interface (113) for sending an insert data request to the data storage server (120) to store the at least one obfuscated data element (210'), and updating a database index (125a) to locate the at least one obfuscated data element (210) in the data storage server (120), wherein the insert data request includes the at least one obfuscated data element (210) and index data for updating the database index (125a), and wherein the index data includes: the digest value (220a to 220n) of the one or more most significant bits (201) of the binary representation of the at least one data element (210); one or more complementary least significant bits (203) of the binary representation of the at least one data element (210) and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one data element (210).

2. The client device (110) according to claim 1, characterized in that, The processor (111) is used to obfuscate the at least one data element (210) by encrypting and / or compressing the at least one data element (210), and the insert data request includes the encrypted and / or compressed at least one data element (210').

3. The client device (110) according to claim 1 or 2, characterized in that, The processor (111) is further used to determine, based on a select data query including at least one boundary value data element, a digest value (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one boundary value data element, wherein the at least one boundary value data element defines a boundary value of a value range; The communication interface (113) is further used to send a select data request to the data storage server (120) to retrieve one or more data elements (210) from the data storage server (120), wherein the select data request includes: the digest value (220a to 220n) of the one or more most significant bits (201) of the binary representation of the at least one boundary value data element, and one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element.

4. The client device (110) according to claim 3, characterized in that, In response to the selected data request, the communication interface (113) is further configured to receive from the data storage server (120) one or more obfuscated reply data elements (210'), wherein the processor (111) is configured to de-obfuscate the one or more obfuscated reply data elements (210').

5. The client device (110) according to claim 4, characterized in that, The one or more obfuscated reply data elements (210') include one or more encrypted reply data elements (210'), and the processor (111) is configured to decrypt the one or more encrypted reply data elements (210') from the data storage server (120) to obtain one or more plaintext reply data elements (210), and / or the one or more obfuscated reply data elements (210') include one or more compressed reply data elements (210'), and the processor (111) is configured to decompress the one or more compressed reply data elements (210') from the data storage server (120) to obtain one or more plaintext reply data elements (210).

6. The client device (110) according to any one of the above claims, characterized in that, The index data further includes additional digest values (221a to 221n) of one or more additional most significant bits of the binary representation of the at least one data element (210), wherein the one or more additional most significant bits of the binary representation of the at least one data element (210) include more or fewer bits than the one or more most significant bits (201) of the binary representation of the at least one data element (210).

7. The client device (110) according to any one of the above claims, characterized in that, The digest values (220a to 220n) of the one or more most significant bits (201) of the binary representation of the at least one data element (210) include a hash value and / or an HMAC value of the one or more most significant bits (201) of the binary representation of the at least one data element (210).

8. A method (600) for storing and retrieving data from a data storage server (120), characterized in that, The method (600) includes: Determining (601) digest values (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one data element (210) based on an insert data query including the at least one data element (210); Obfuscating (602) the at least one data element (210); Send an insert data request (603) to the data storage server (120) to store the at least one obfuscated data element (210) in the data storage server (120) and update the database index (125a), wherein the insert data request includes the at least one obfuscated data element (210') and index data for updating the database index (125a), and wherein the index data includes: the digest values (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one data element (210), and one or more complementary least significant bits (203) of the binary representation of the at least one data element (210) and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one data element (210).

9. A data storage server (120), characterized in that, For storing data from a client device (110), the data storage server (120) includes: A communication interface (123) for receiving an insert data request from the client device (110), the insert data request including at least one data element (210') in an obfuscated form and index data, and wherein the index data includes: the digest values (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one data element (210), and one or more complementary least significant bits (203) of the binary representation of the at least one data element (210) and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one data element (210); A memory (125) for implementing a database, wherein the database is used to store the at least one data element (210') in the obfuscated form at a memory location and update the database index (125a) based on the index data to locate the at least one data element (210') in the obfuscated form at the memory location.

10. The data storage server (120) according to claim 9, characterized in that, The database is further used to obtain a tuple identifier (205), the tuple identifier (205) indicating the memory location of the at least one data element (210') in the obfuscated form, and update the database index (125a) based on the index data and the tuple identifier (205).

11. The data storage server (120) according to claim 9 or 10, characterized in that, The at least one data element (210') in the obfuscated form includes at least one encrypted and / or compressed data element (210'), and the database is used to store the at least one encrypted and / or compressed data element (210') at the memory location.

12. The data storage server (120) according to any one of claims 9 to 11, characterized in that, The communication interface (123) is further configured to receive a selection data request from the client device (110) based on a selection data query including at least one boundary value data element that defines a boundary value of a value range, wherein the selection data request includes: a digest value (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one boundary value data element, and one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element. The database is further configured to retrieve, from the memory (125), one or more reply data elements (210') in an obfuscated form based on the digest value (220a to 220n) of one or more most significant bits (201) of the binary representation of the at least one boundary value data element, and the one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element and / or the bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one boundary value data element.

13. The data storage server (120) according to claim 12, characterized in that, The communication interface (123) is further configured to send the one or more reply data elements (210') in the obfuscated form to the client device (110).

14. The data storage server (120) according to claim 12 or 13, characterized in that The one or more reply data elements (210') in the obfuscated form include one or more encrypted and / or compressed reply data elements (210').

15. The data storage server (120) according to any one of claims 9 to 14, characterized in that The index data further includes additional digest values (221a to 221n) of one or more additional most significant bits of the binary representation of the at least one data element (210), wherein the one or more additional most significant bits of the binary representation of the at least one data element (210) include more or fewer bits than the one or more most significant bits (201) of the binary representation of the at least one data element (210).

16. The data storage server (120) according to any one of claims 9 to 15, characterized in that The digest value (220a to 220n) of the one or more most significant bits (201) of the binary representation of the at least one data element (210) includes a hash value and / or an HMAC value of the one or more most significant bits (201) of the binary representation of the at least one data element (210).

17. A method (700), characterized in that For storing data from a client device (110), the method (700) includes: Receive (701) an insert data request from the client device (110), the insert data request including at least one data element (210’) in an obfuscated form and index data, wherein the index data includes: a digest value (220a to 220n) of one or more most significant bits (201) of a binary representation of the at least one data element (210), and one or more complementary least significant bits (203) of the binary representation of the at least one data element (210) and / or a bit sequence (203*) based on the one or more complementary least significant bits (203) of the binary representation of the at least one data element (210); Store (703) the at least one data element (210’) in the obfuscated form at a memory location in the memory (125); Update (705) a database index (125a) based on the index data to locate the at least one data element (210’) in the obfuscated form at the memory location.

18. The method (700) according to claim 17, characterized in that The method (700) further includes: obtaining a tuple identifier (205) that indicates the memory location of the at least one data element (210’) in the obfuscated form, and updating (705) the database index (125a) based on the index data and the tuple identifier (205).

19. A computer program product, characterized in that A computer-readable storage medium including program code which, when executed by a computer or a processor, causes the computer or the processor to perform the method (600) according to claim 8 or the method (700) according to claim 17 or 18.