Relational Database Fingerprinting for Data Leak Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data-as-a-Service (DaaS) platforms face challenges in ensuring data privacy and security, particularly in trusted systems where users rely on service providers for encryption, and in non-trusted systems where users must manage complex cryptographic protocols, while also lacking mechanisms to track unauthorized data distribution.

Innovation Solution

A semi-trusted system and method that embeds a fingerprint in relational databases using a unique identifier, allowing data owners to track unauthorized data distribution without relying on service providers for encryption management, and provides a fingerprinting mechanism that can be applied to various data types, including float, double, decimal, and geographic locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a trusted system is used where service providers manage encryption, then ease of operation is improved, but reliability of data privacy is worsened due to potential internal attacks

Engineering Contradiction:
Improveease of cryptographic managementVSAvoiddata privacy security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the cryptographic management responsibilities between the service provider (who manages the system) and the data owner (who retains control through fingerprinting capabilities). This segmentation allows the service provider to offer convenient encryption management while the data owner maintains independent verification and tracking abilities, thus resolving the contradiction between ease of operation and reliability of data privacy.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a non-trusted system is used where users manage encryption, then reliability of data privacy is improved, but device complexity is worsened due to complex cryptographic protocols

Engineering Contradiction:
Improvedata privacy securityVSAvoidcryptographic management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary fingerprinting mechanism that mediates between the user and the cryptographic system. Instead of requiring users to directly manage complex cryptographic protocols, the system embeds fingerprints in the data that automatically track and verify unauthorized distribution, thus maintaining reliability while reducing the complexity of cryptographic management for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If traditional watermarking is applied to relational databases, then measurement precision is improved for tracking data distribution, but device complexity is worsened due to limited data type support

Engineering Contradiction:
Improvedata distribution tracking accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal fingerprinting system for relational databases that supports multiple data types including float, double, decimal, and geographic locations. This multi-functional approach allows the same fingerprinting mechanism to work across different data types without requiring separate complex systems for each type, thus improving measurement precision while managing system complexity through a unified solution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9646161B2Relational database fingerprinting method and system
Publication Date: 2017.05.09 GENESEE VALLEY INNOVATIONS LLC
  • US9646161B2 patent drawing
  • US9646161B2 patent drawing
  • US9646161B2 patent drawing

AI summary

Disclosed is a relational database fingerprinting system and method to identify a user of the relational database, the fingerprint provided by an originator of the relational database. According to an exemplary method, a fingerprint bit string is generated including a data user identification code and a secret key unknown to the user, and the fingerprint bit string is embedded in a plurality of pseudorandomly selected values based on a pseudorandom function seeded with primary keys associated with the relational database.