System and method for improved researcher privacy in a distributed ledger-based query logging system

JP2024528667A5Pending Publication Date: 2025-07-15KONINKLIJKE PHILIPS NV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024503443
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-10-04
Filing Date
2022-07-08
Publication Date
2025-07-15

AI Technical Summary

Technical Problem

Existing data systems fail to protect the privacy of researchers by exposing their identities and query intentions due to unrestricted access to query logs, even with permissioned blockchains, as they do not adequately address the risk of identity exposure in distributed ledger systems.

Method used

Implementing a method and system that receives and logs encrypted queries using a Camenisch-Lysyanskaya signature (CLS) digital signature scheme, anonymizes queries through de-identification, and allows only authorized enforcers to access and identify queries for security review, using cryptographic authentication schemes like zk-SNARK or zk-STARK.

Benefits of technology

Ensures researcher privacy by maintaining query anonymity and integrity, allowing only authorized entities to access and identify potential security breaches without revealing identities, thus enhancing data system security and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A method 100 for logging queries made to a data system 200, the method 100 comprising receiving (120) an encrypted query at the data system from a legitimate query entity, the encrypted query being digitally signed by the legitimate query entity using a digital signature scheme, the digital signature further being encrypted using a cryptographic authentication scheme, and logging (130) at least a portion of the encrypted query in a query logging database of the data system.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] FIELD OF THE DISCLOSURE

[0001] The present disclosure is generally directed to methods and systems for protecting the privacy of researchers when making and logging queries using a ledger-based query logging system. [Background technology]

[0002]

[0002] Many data systems comprise data that is distributed across multiple stakeholders, such as a distributed cohort. The data system comprises multiple databases, each of which contains a portion of the system's data. A query interface of the data system allows a formal researcher to query the distributed data to identify and / or obtain data relevant to the researcher's query.

[0003]

[0003] However, a malicious researcher, or someone who has fraudulently obtained the credentials of a legitimate researcher, can use a set of carefully designed queries to perform inference attacks, such as re-identification attacks, on the data system. Therefore, logging the queries received by the data system is crucial if an attack is suspected and a query needs to be performed. One way to log queries is to use blockchain, which allows different stakeholders to track transactions (e.g., queries) and store them in an immutable distributed ledger, where each stakeholder can optionally have a full copy of the ledger. Therefore, blockchain is an attractive solution. Summary of the Invention [Problem to be solved by the invention]

[0004]

[0004] However, logging queries in a data system creates at least one privacy problem, namely, the problem of identifying the researcher or other legitimate querying entity making the query. Typically, all participants in the data system (in addition to the researcher or other legitimate querying entity) have full access to and can view all data in the system. Thus, these participants can read all logged data in the ledger, which may allow for the leakage of entity information about the identity, interests, and / or intent of the researcher or other legitimate querying entity. Restricting access to the ledger to authorized users, such as through a permissioned blockchain, is one option, but this approach relies entirely on trust in authorized users. Existing security solutions for distributed logging focus on ensuring aspects such as authenticity and secure storage. However, these solutions are insufficient because they do not address the concern that the queries and identities of the researcher or other legitimate querying entity making the query remain public in the data system.

[0005]

[0005] There is a continuing need for secure data systems and methods that authenticate a legitimate querying entity without revealing the identity of the legitimate querying entity. The present disclosure is directed to an inventive method and system for receiving, authenticating, and logging an encrypted query using a query system. Various embodiments and implementations herein are directed to a data system comprising a distributed data and query ledger. The data system receives an encrypted query from a legitimate querying entity, the encrypted query being digitally signed by the legitimate querying entity using a Camenisch-Lysyanskaya signature (CLS) digital signature scheme, and the digital signature is further encrypted using a cryptographic authentication scheme. The data system logs at least a portion of the encrypted query in a query logging database (ledger or log) of the data system. According to one embodiment, the data system can review one or more received queries for potential security breaches and / or the data system can verify that the legitimate querying entity is a legitimate querying entity using de-identification via the cryptographic authentication scheme and the CLS digital signature scheme, where the verification does not reveal the identity of the legitimate querying entity. According to one embodiment, the data system can modify received encrypted queries to remove identifying information, thereby generating modified encrypted queries, and can log the modified encrypted queries in a query logging database. According to one embodiment, an enforcer of the data system can access one or more logged queries in the query logging database and identify the accessed logged queries using a cryptographic authentication scheme and a CLS digital signature scheme, where the identification reveals the identity of the accessed logged queries for security review or other purposes. According to one embodiment, the data system is a distributed genomic data system, although many other systems are possible. [Means for solving the problem]

[0006] In general, in one aspect, there is provided a method for logging queries made to a data system, the method comprising: (i) receiving, at the data system, an encrypted query from a legitimate query entity, the encrypted query being digitally signed by the legitimate query entity using a digital signature scheme, the digital signature further being encrypted using a cryptographic authentication scheme, and (ii) logging at least a portion of the encrypted query in a query logging database of the data system.

[0007] According to one embodiment, the digital signature scheme is the Camenisch-Lysyanskaya Signature (CLS) digital signature scheme.

[0008]

[0008] According to one embodiment, the cryptographic authentication scheme is a zero-knowledge succinct non-interactive proof of knowledge (zk-SNARK) scheme or a zero-knowledge scalable transparent proof of knowledge (zk-STARK) scheme.

[0009]

[0009] According to one embodiment, the encrypted query further comprises (i) a public key for digital signature and (ii) a public key for cryptographic authentication. According to one embodiment, the encrypted query further comprises (iii) an encrypted unique identifier for the legitimate querying entity and (iv) an encrypted timestamp for the encrypted query.

[0010]

[0010] According to one embodiment, the method further includes a step of verifying, by the data system, that the legitimate query entity is a legitimate query entity, wherein the verifying step includes analysis of an encrypted digital signature using a cryptographic authentication scheme and de-identification via a digital signature scheme, wherein the verifying step does not reveal the identity of the legitimate query entity.

[0011]

[0011] According to one embodiment, the method further includes a step of modifying, by the data system, the received encrypted query to remove identifying information, thereby generating a modified encrypted query, at least a portion of the modified encrypted query being logged in a query logging database of the data system.

[0012]

[0012] According to one embodiment, the method further includes a step of accessing, by an enforcer of the data system, one or more logged queries logged in the data system's query logging database, and a step of identifying, by the enforcer, the one or more logged queries using a cryptographic authentication scheme and a digital signature scheme, wherein the identifying step reveals the identity of each of the one or more logged queries.

[0013]

[0013] According to one embodiment, the data system is a distributed genomic data system.

[0014]

[0014] According to another aspect, the data system is a distributed database system for logging queries made, the distributed database system comprising: a query logging database configured to store at least a portion of queries made to the distributed database system by authorized query entities; a plurality of distributed databases; and a processor configured to (i) receive an encrypted query from an authorized query entity, the encrypted query being digitally signed by the authorized query entity using a digital signature scheme, the digital signature being further encrypted using a cryptographic authentication scheme; and (ii) cause the received encrypted query to be stored in the query logging database.

[0015] In various implementations, the processor or controller is associated with one or more storage media (e.g., volatile and non-volatile computer memory, such as RAM, PROM, EPROM, and EEPROM, floppy disks, compact disks, optical disks, magnetic tapes, etc., collectively referred to herein as "memory"). In some implementations, the storage media is encoded with one or more programs that, when executed by one or more processors and / or controllers, perform at least a portion of the functions described herein. The various storage media may be fixed within the processor or controller or may be made portable, such that one or more programs stored on the storage media can be loaded into the processor or controller to implement the various aspects described herein. As used herein, the term "program" or "computer program" is used in a generic sense to refer to any type of computer code (e.g., software or microcode) that can be employed to program one or more processors or controllers.

[0016]

[0016] It should be appreciated that all combinations of the above-mentioned concepts and additional concepts described in more detail below (provided such concepts are not mutually inconsistent) are contemplated as part of the inventive subject matter disclosed herein. In particular, all combinations of claimed subject matter appearing at the end of this disclosure are contemplated as part of the inventive subject matter disclosed herein. It should also be appreciated that the technical terms explicitly employed in this specification, which also appear in any disclosure incorporated by reference, should be given the meaning most consistent with the specific concepts disclosed herein.

[0017]

[0017] These and other aspects of various embodiments will be apparent from and elucidated with reference to the embodiments described hereinafter.

[0018]

[0018] In the drawings, like reference characters generally refer to the same parts throughout the various views and the drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of various embodiments. [Brief description of the drawings]

[0019] [Figure 1] 1 is a flowchart of a method for logging queries made to a data system, according to one embodiment. [Diagram 2]

[0020] 1 is a schematic diagram of a data system, according to one embodiment. [Diagram 3]

[0021] 1 is a schematic diagram of a data system, according to one embodiment. [Figure 4]

[0022] 1 is a schematic diagram of a data system, according to one embodiment. [Diagram 5]

[0023] 1 is a schematic diagram of a data system, according to one embodiment. [Figure 6]

[0024] 1 is a schematic diagram of a data system, according to one embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0020]

[0025] This disclosure describes various embodiments of systems and methods for making and logging queries using a ledger-based query logging system. It is recognized and appreciated that it would be beneficial to provide a method and system that protects the privacy of a legitimate query entity when the legitimate query entity uses a ledger-based query logging system. A data system receives an encrypted query from the legitimate query entity, the encrypted query being digitally signed by the legitimate query entity using a Camenisch-Lysyanskaya signature (CLS) digital signature scheme, and the digital signature is further encrypted using a cryptographic authentication scheme. The data system logs at least a portion of the encrypted query in a query logging database (ledger or log) of the data system. According to one embodiment, the data system can review one or more received queries for potential security breaches and / or the data system can verify that the legitimate query entity is a legitimate query entity using de-identification via the cryptographic authentication scheme and the CLS digital signature scheme, where the verification does not reveal the identity of the legitimate query entity. According to one embodiment, the data system can modify received encrypted queries to remove identifying information, thereby generating modified encrypted queries, and can log the modified encrypted queries in a query logging database. According to one embodiment, an enforcer of the data system can access one or more logged queries in the query logging database and identify the accessed logged queries using a cryptographic authentication scheme and a CLS digital signature scheme, where the identification reveals the identity of the accessed logged queries for security review or other purposes. According to one embodiment, the data system is a distributed genomic data system, although many other systems are possible.

[0021]

[0026] Referring to Figure 1, in one embodiment, there is shown a flow chart of a method 100 for logging queries made to a distributed data system. It should be understood that the method described with respect to the figure is provided by way of example only and is not intended to limit the scope of the present disclosure. The distributed data system may be any of the systems described or otherwise contemplated herein. The distributed data system may be a single system or multiple different systems.

[0022]

[0027] In step 110 of the method, a distributed data system is provided. For example, referring to one embodiment of distributed data system 200 shown in FIG. 2, the system comprises one or more of a processor 220, a memory 230, a user interface 240, a communication interface 250, and storage 260 interconnected via one or more system buses 212. It will be understood that FIG. 2 constitutes an abstraction in some respects, and the actual organization of the components of system 200 may be different and more complex than that illustrated. Also, distributed data system 200 may be any of the systems described or otherwise contemplated herein. Other elements and components of distributed data system 200 are disclosed and / or contemplated elsewhere herein.

[0023]

[0028] According to one embodiment, the distributed data system comprises data distributed across multiple databases. Authorized users (querying entities) can query the distributed data system to identify and / or obtain data from one or more of the multiple databases. According to one embodiment, the distributed data system is a distributed genomic data system and the queries are for genomic data, although many other systems are possible.

[0024]

[0029] In step 120 of the method, the distributed data system receives a query from an authorized user. To protect the identity and privacy of the authorized user, the query is digitally signed and encrypted. According to one embodiment, the encrypted query is digitally signed by the querying entity using the Camenisch-Lysyanskaya Signature (CLS) digital signature scheme, although other digital signature schemes are possible. According to one embodiment, the encrypted query is encrypted using a cryptographic authentication scheme.

[0025]

[0030] According to one embodiment, the Camenisch-Lysyanskaya signature (CLS) digital signature scheme is utilized for the secure digital signature. The CLS scheme is described, for example, in "Signature schemes and anonymous credentials from bilinear maps," Camenisch and Lysyanskaya, Advances in Cryptology Vol. 3152:56-72 (Springer Verlag, 2004). According to one embodiment, the cryptographic authentication scheme is a zero-knowledge succinct non-interactive proof of knowledge (zk-SNARK) scheme, which is a cryptographic proof technique for establishing knowledge or ownership in a manner that preserves confidentiality while minimizing the amount of bandwidth used for communication. With zk-SNARKs, a party with access to a proof key can create a cryptographic proof that is verifiable by a party in possession of a verification key. Alternatively, a zero-knowledge scalable transparent proof of knowledge (zk-STARK) scheme can be utilized as well.

[0026]

[0031] According to one embodiment, the method anonymizes both the identity of the researcher and the logged queries, thereby limiting each participant in the system to the minimum information they need to access to enable the system's functionality. Referring to FIG. 3, this is a schematic diagram of a data system 300 in one embodiment. In this example, the system is a genomic data system, but many other data systems are possible. In this system, a genomic database (beacon) receives an anonymous query. The beacon knows the content of the query and that it was sent by a researcher with permission to send it, but does not know which researcher of all possible authorized researchers sent the query. In this system, the anonymous query is further stripped of any possible personally identifiable information in the query itself before being stored in the database, so that other databases connected to the logging system can only see fully de-identified queries. In this system, the rule enforcers are the only party able to determine the identity of the researcher to be able to expel or punish researchers who break the rules.

[0027]

[0032] Referring to Figure 4, in one embodiment, this is a schematic diagram of an encrypted query from an authorized user of the system to a beacon of the distributed data system. To protect the identity and privacy of the authorized user, the query is digitally signed and encrypted. According to one embodiment, the encrypted query is digitally signed by the querying entity using the CLS digital signature scheme, although other digital signature schemes are possible. According to one embodiment, the encrypted query is encrypted using a cryptographic authentication scheme.

[0028]

[0033] According to one embodiment, the data system enables: (i) an authorized researcher / entity signs a query using a CLS signature scheme for a private key x, where the corresponding public key R is included in the query, and the researcher / entity encrypts its (its) unique ID (UUID) and a timestamp (Ti) with Y, where Y is the rule enforcer's public key. The data system also enables: (ii) the authorized researcher / entity has a zk-SNARK (or zk-STARK) proof that the encryption is a correct encryption, and the authorized researcher / entity signs at least the public key R and the encryption with an anonymizing signature scheme such as ring signatures.

[0029]

[0034] This digital signature and encryption process allows a researcher / entity to hide their (its) identity. The method also allows the data system to process the query to de-identify some parts of the query in such a way that its integrity is preserved. For example, the data system believes, understands, or suspects that the query may reveal information sensitive to data inferences. In particular, the data system is not primarily concerned about what a single query may reveal (since responses are not logged), but is primarily concerned about successive queries, since certain patterns may reveal personally identifiable information in the database to a knowledgeable reader. In effect, the continuation suggests a positive response to the previous request.

[0030]

[0035] In step 130 of the method, some or all of the encrypted query is logged in a ledger, such as a query logging database, of the distributed data system. The encrypted query can be stored in the query logging database using any method for storing encrypted data. Logging the query data allows for future retrieval of the query data, such as identifying the querying entity, in the event of a potential or known security or privacy issue. However, because the query remains encrypted, only an enforcer of the distributed data system can access and utilize the encrypted query data after it is decrypted. An enforcer can be, for example, an entity responsible for ensuring the security and / or privacy of the distributed data system and / or the system's query logging database. For example, an enforcer may need to access and utilize the decrypted query data if there is a concern or suspicion that a malicious legitimate user or someone who has fraudulently obtained the credentials of a legitimate user has accessed the distributed data system, potentially for non-legitimate purposes.

[0031]

[0036] In optional step 140, the distributed data system verifies that the querying entity is an authorized user of the distributed data system without revealing the identity of the querying entity. According to one embodiment, verifying includes analysis of an encrypted digital signature using a cryptographic authentication scheme and de-identification via a digital signature scheme.

[0032]

[0037] Referring to FIG. 5, in one embodiment, this is a schematic diagram of partial identification or authentication of a received query, in a manner that authenticates but does not reveal protected personally identifiable information of the person(s) or entities performing the query. For example, the system enables the query to be an exact representation of the original query submitted by the researcher. To do this, the system utilizes the public key R and the CLS signature provided by the researcher when submitting the query. Given these two elements, the system can create an inverse CLS zk-proof that proves that the less specific object (the query to be verified) is an exact subset of the original object, i.e., the original query, without disclosing the original object.

[0033]

[0038] According to one embodiment, the distributed data system may log the query in a query logging database of the distributed data system at step 130 of the method before or after verifying that the querying entity is a legitimate user of the system.

[0034]

[0039] In an optional step 150 of the method, the distributed data system modifies the received encrypted query to remove identifying information, thereby generating a modified encrypted query. According to one embodiment, after the distributed data system modifies the encrypted query and creates the modified encrypted query, in step 130 of the method, the modified encrypted query may be logged in a query logging database of the distributed data system.

[0035]

[0040] In an optional step 160 of the method, the distributed data system or a user of the distributed data system reviews one or more encrypted queries, such as one or more logged encrypted queries, for potential security breaches. This analysis or review may be performed without decrypting the queries and without knowing the identity of the querying entity that made each of the one or more encrypted queries. For example, a user or algorithm may review the encrypted queries to identify flags or identifiers, such as patterns, that indicate potential privacy or security concerns or breaches. These flags or identifiers may indicate that a malicious legitimate user or someone who has fraudulently obtained the credentials of a legitimate user has accessed the distributed data system, potentially for non-legitimate purposes. If a flag or identifier, such as a pattern, is found, the user or distributed data system may alert an enforcer or other entity responsible for ensuring the security and / or privacy of the distributed data system and / or the system's query logging database.

[0036]

[0041] In step 170 of the method, an enforcer of the distributed data system accesses one or more queries logged in the system's query logging database. According to one embodiment, an enforcer is any entity responsible for ensuring security and / or privacy of the distributed data system and / or the system's query logging database. The system has a limited number of enforcers with extensive security and / or other authentication protocols to ensure limited and secure access to the system's query logging database. Only the enforcer of the distributed data system can access and utilize the encrypted query data. The enforcer is required to access and utilize the decrypted query data when there is a concern or suspicion that a malicious user or an entity with fraudulent acquisition of a legitimate user's credentials has accessed the distributed data system, potentially for non-legitimate purposes. According to one embodiment, the enforcer is required to access and utilize the encrypted query data when a flag or identifier, such as a pattern, is identified that indicates a potential privacy or security concern or violation. The flag or identifier, such as a pattern, indicates that a malicious user or an entity with fraudulent acquisition of a legitimate user's credentials has accessed the distributed data system, potentially for non-legitimate purposes. The enforcer can access the data locally or remotely.

[0037]

[0042] In step 180 of the method, the enforcer identifies the person(s) or querying entities associated with the accessed logged query(s) using cryptographic authentication and digital signature schemes. Of course, this identification will reveal the person(s) or entities that made each of the logged query(s).

[0038]

[0043] Referring to FIG. 6, in one embodiment, this is a schematic diagram of the identification by an enforcer of one (1) or more entities associated with one (1) logged queries that have been accessed. The enforcer uses public key encryption techniques. The entity (1) or entities encrypt their (its) identity along with a timestamp using the rule enforcer's public key. The rule enforcer then decrypts that information, allowing only the rule enforcer to track whether the querying entity (1) or entities, whose identities remain hidden from all databases in the system, are following the desired goals and policies.

[0039]

[0044] According to one embodiment, a system may implement the proposed zk-SNARK using a library such as MIT's libsnark in combination with a high-level logic compiler such as xjSNARK. The combination of xjSNARK and libsnark compiles the high-level proofs into a quadratic arithmetic program. This quadratic span program is input into a zk-SNARK generator along with a random secret element. The result is a public proof key and a verification key. The verification key is shared with regulators, auditors, or other parties. The proof key may be shared freely, such as on a public forum.

[0040]

[0045] According to one embodiment, an implementation of the CLS scheme uses an elliptic curve pairing function e. The implementation of the scheme utilizes type 3 elliptic curve pairing, such as pairing on a 256-bit Barreto-Naehrig (BN) curve. The pairing on the BN curve can be formally expressed as follows: e:G1×G2→G t

[0041]

[0046] The generator is the generator of G1 generated by nothing-up-my-sleeve (hashing the base generator of G1 until a point is reached). Under this Barreto-Naehrig curve, the signature is 32 bytes in size. The public encryption key used by the proof of rule enforcer can be achieved by elliptic curve cryptography, for example the secp256r1 curve to implement the asymmetric encryption key pair, using ECDSA for signing documents and agreements. Alternatively, traditional RSA and DSA can be used to achieve similar results.

[0042]

[0047] Reference is now made to Figure 2, which is a schematic diagram of a distributed data system 200. System 200 may be any of the systems described or otherwise contemplated herein and may include any of the components described or otherwise contemplated herein. It will be appreciated that Figure 2 constitutes in some respects an abstraction, and that the actual organization of the components of system 200 may differ from that illustrated and may be more complex.

[0043]

[0048] According to one embodiment, the system 200 comprises a processor 220 capable of executing instructions or otherwise processing data stored in the memory 230 or storage 260, for example to perform one or more steps of the method. The processor 220 is formed of one or more modules. The processor 220 may take any suitable form, including, but not limited to, a microprocessor, a microcontroller, multiple microcontrollers, circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a single processor, multiple processors.

[0044]

[0049] The memory 230 may take any suitable form, including non-volatile memory and / or RAM. The memory 230 may include various memories, such as, for example, L1, L2, or L3 caches or system memory. As such, the memory 230 may include static random access memory (SRAM), dynamic RAM (DRAM), flash memory, read-only memory (ROM), or other similar memory devices. The memory may store, among other things, an operating system. The RAM is used by the processor for temporary storage of data. According to one embodiment, the operating system includes code that, when executed by the processor, controls the operation of one or more components of the system 200. It will be apparent that in embodiments in which the processor implements one or more of the functions described herein in hardware, software that is described as corresponding to such functions in other embodiments may be omitted.

[0045]

[0050] User interface 240 includes one or more devices for enabling communication with a user. The user interface may be any device or system that enables communication and / or reception of information, including a display, a mouse, and / or a keyboard for receiving user commands. In some embodiments, user interface 240 includes a command line interface or a graphical user interface that is presented to a remote terminal via communication interface 250. The user interface may be located with one or more components of the system or may be located remotely from the system and communicate via a wired and / or wireless communication network.

[0046]

[0051] The communication interface 250 includes one or more devices for enabling communication with other hardware devices. For example, the communication interface 250 includes a network interface card (NIC) configured to communicate according to an Ethernet protocol. The communication interface 250 may also implement a TCP / IP stack for communicating according to a TCP / IP protocol. Various alternative or additional hardware or configurations for the communication interface 250 will be apparent.

[0047]

[0052] Storage 260 includes one or more machine-readable storage media, such as read-only memory (ROM), random access memory (RAM), magnetic disk storage media, optical storage media, flash memory devices, or other storage media. In various embodiments, storage 260 stores instructions for execution by processor 220 or data on which processor 220 operates. For example, storage 260 stores operating system 261 for controlling various operations of system 200.

[0048]

[0053] It will be apparent that various information described as being stored in storage 260 may additionally or alternatively be stored in memory 230. In this regard, memory 230 may also be considered to constitute a storage device, and storage 260 may be considered a memory. Various other arrangements may also be apparent. Moreover, both memory 230 and storage 260 may be considered to be non-transitory machine-readable media. As used herein, the term non-transitory may be understood to exclude transitory signals, but to include all forms of storage, including both volatile and non-volatile memory.

[0049]

[0054] Although system 200 is shown as including one of each of the described components, in various embodiments, various components may be duplicated. For example, processor 220 may include multiple microprocessors, which may be configured to independently perform the methods described herein, or the multiple processors may be configured to cooperate to achieve the functions described herein by performing steps or subroutines of the methods described herein. Furthermore, when one or more components of system 200 are implemented in a cloud computing system, various hardware components may reside in separate physical systems. For example, processor 220 may include a first processor located on a first server and a second processor located on a second server. Many other variations and configurations are possible.

[0050]

[0055] According to one embodiment, system 200 includes multiple databases, i.e., distributed database system 270, that contain some or all of the data stored by the data system. The data system allows for searching of the multiple databases in distributed database system 270. In the case of a genomic data system, each of the distributed databases contains some genomic data.

[0051]

[0056] According to one embodiment, storage 260 of system 200 stores one or more algorithms, modules, and / or instructions for performing one or more functions or steps of methods described or otherwise contemplated herein. For example, the system includes logging instructions 262, review instructions 263, verification instructions 264, remediation instructions 265, and / or a query logging database 266, among other instructions or data.

[0052]

[0057] According to one embodiment, logging instructions 262 instruct the system to log some or all of the encrypted query in a ledger of the distributed data system, such as query logging database 266. The encrypted query may be stored in query logging database 266 using any method for storing encrypted data. Logging the query data allows for future retrieval of the query data, such as identification of the querying entity, in the event of a potential or known security or privacy issue.

[0053]

[0058] According to one embodiment, review instructions 263 instruct the system to review one or more encrypted queries, such as one or more logged encrypted queries, for potential security breaches. This analysis or review may be performed without decrypting the queries and without knowing the identity of the querying entity that made each of the one or more encrypted queries. For example, an algorithm may review the encrypted queries to identify flags or identifiers, such as patterns, that indicate potential privacy or security concerns or breaches. These flags or identifiers may indicate that a malicious legitimate user or someone who has fraudulently obtained the credentials of a legitimate user has accessed the distributed data system, potentially for non-legitimate purposes. If a flag or identifier, such as a pattern, is found, the user or the distributed data system may alert an enforcer or other entity responsible for ensuring the security and / or privacy of the distributed data system and / or the system's query logging database.

[0054]

[0059] According to one embodiment, verification instructions 264 instruct the system to verify that the querying entity is a legitimate user of the distributed data system without revealing the identity of the querying entity. According to one embodiment, verifying includes analysis of an encrypted digital signature using cryptographic authentication schemes and de-identification via digital signature schemes.

[0055]

[0060] According to one embodiment, modification instructions 265 instruct the system to modify a received encrypted query to remove identifying information, thereby generating a modified encrypted query. Modification may be performed using any method for modifying an encrypted query.

[0056]

[0061] All definitions and those used herein should be understood to take precedence over dictionary definitions, definitions in documents incorporated by reference, and / or common meanings of the defined terms.

[0057]

[0062] As used herein, in the specification and claims, the indefinite articles "a" and "an" should be understood to mean "at least one," unless expressly indicated otherwise.

[0058]

[0063] The term "and / or" as used herein, both in the specification and in the claims, should be understood to mean "either or both" of the elements so conjoined, i.e., elements that are conjointly present in some cases and disjointly present in other cases. Multiple elements listed with "and / or" should be construed in the same manner, i.e., as "one or more" of the elements so conjoined. Other elements may optionally be present other than the elements specifically identified by the "and / or" clause, whether related or unrelated to such elements specifically identified.

[0059]

[0064] In the specification and claims, when used herein, "or" should be understood to have the same meaning as "and / or" as defined above. For example, when separating items in a list, "or" or "and / or" should be interpreted as being inclusive, i.e., including at least one of several elements or a list of elements, but also including two or more of them, and optionally including additional items not in the list. Only when a term clearly indicates otherwise, such as "only one of" or "exactly one of," or "consisting of" is used in the claims, does it refer to the inclusion of exactly one element of several elements or a list of elements. In general, the term "or" as used herein should be interpreted as indicating exclusive alternatives (i.e., "one or the other, but not both") only when preceded by a term of exclusivity, such as "either," "one of," "only one of," or "exactly one of."

[0060]

[0065] As used herein in the specification and claims, the phrase "at least one" in reference to a list of one or more elements should be understood to mean selected from any one or more of the elements in the list of elements, but not necessarily including at least one of each element specifically listed in the list of elements, and not excluding any combination of elements in the list of elements. This definition also allows for the optional presence of elements other than those specifically identified in the list of elements to which the phrase "at least one" refers, whether related or unrelated to such specifically identified elements.

[0061]

[0066] Also, unless expressly stated otherwise, it should be understood that in any method claimed herein that includes two or more steps or actions, the order of the method steps or actions is not necessarily limited to the order in which the method steps or actions are described.

[0062]

[0067] In the claims, as well as in the above specification, all transitional phrases such as "comprising," "including," "carrying," "having," "containing," "involving," "holding," "comprising," and the like, are to be understood as being open-ended, i.e., meaning including but not limited to. Only the transitional phrases "consisting of" and "consisting essentially of" shall be closed or semi-closed transitional phrases, respectively.

[0063]

[0068] While several inventive embodiments have been described and illustrated, those skilled in the art will readily envision various other means and / or structures for performing the functions and / or obtaining the results and / or one or more of the advantages described herein, and each such variation and / or modification is deemed to be within the scope of the inventive embodiments described herein. More generally, those skilled in the art will readily appreciate that all parameters, dimensions, materials, and configurations described herein are exemplary, and that the actual parameters, dimensions, materials, and / or configurations will depend on the particular application or applications in which the inventive teachings are used. Those skilled in the art will recognize, or be able to ascertain with no more than routine experimentation, many equivalents to the specific inventive embodiments described herein. Thus, the above embodiments are presented by way of example only, and it should be understood that within the scope of the appended claims and their equivalents, the inventive embodiments may be practiced otherwise than as specifically described and claimed. The inventive embodiments of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. Furthermore, any combination of two or more such features, systems, articles, materials, kits, and / or methods is included within the inventive scope of the present disclosure, if such systems, articles, materials, kits, and / or methods are not mutually inconsistent.

Claims

1. A method for logging queries made to a data system, the method comprising: receiving, in the data system, an encrypted query from a query entity, the encrypted query being digitally signed by the query entity using a digital signature scheme, and further, the digital signature being encrypted using an authentication scheme, the digital signature scheme being a Camenisch-Lysyanskaya signature (CLS) digital signature scheme, and further, the authentication scheme being a zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) scheme or a zero-knowledge scalable transparent argument of knowledge (zk-STARk) scheme; verifying, by the data system, that the query entity is a legitimate query entity, the verifying step comprising analyzing the encrypted digital signature using non-specification via the authentication scheme and the digital signature scheme, the verifying step not revealing the identity of the query entity; logging, in a query logging database of the data system, at least a portion of the encrypted query; and a method.

2. The method of claim 1, wherein the encrypted query further comprises (i) a public key for the digital signature and (ii) a public key for authentication.

3. The method of claim 2, wherein the encrypted query further comprises (iii) an encrypted unique identifier for the legitimate query entity and (iv) an encrypted timestamp for the encrypted query.

4. The method of claim 1, further comprising generating, by the data system, a modified encrypted query by modifying the received encrypted query to remove identity-specifying information, wherein at least a portion of the modified encrypted query is logged in the query logging database of the data system.

5. The step of accessing, by an implementer of the data system, one or more logged queries logged in the query logging database of the data system; The method further comprising the step of identifying, by the implementer, the one or more logged queries using the cryptographic authentication method and the digital signature method; The method according to claim 1, wherein the identifying step reveals the identity of each of the one or more logged queries.

6. The method according to claim 1, wherein the data system is a distributed genomic data system.

7. A distributed database system for logging queries performed, the distributed database system comprising: A query logging database that stores at least a portion of the queries performed on the distributed database system by a query entity; A plurality of distributed databases; A processor that performs: (i) receiving an encrypted query from the query entity, the encrypted query being digitally signed by the query entity using a digital signature method, and further, the digital signature being encrypted using a cryptographic authentication method, the digital signature method being a Camenisch-Lysyanskaya signature (CLS) digital signature method, and further, the cryptographic authentication method being a zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) method or a zero-knowledge scalable transparent argument of knowledge (zk-STAR) method; (ii) verifying that the query entity is a legitimate query entity, the verifying having an analysis of the encrypted digital signature using de-identification via the cryptographic authentication method and the digital signature method, the verifying not revealing the identity of the query entity; and (iii) storing the received encrypted query in the query logging database. A distributed database system comprising.

8. The distributed database system according to claim 7, wherein the encrypted query further comprises (i) a public key for the digital signature and (ii) a public key for the cryptographic authentication.

9. The distributed database system according to claim 8, wherein the encrypted query further comprises (iii) an encrypted unique identifier for the regular query entity and (iv) an encrypted timestamp for the encrypted query. **Claim 10** The distributed database system according to claim 7, which is a distributed genomic data system.