Selector Derived Encryption for Database Confidentiality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption methods, such as hash-based private information retrieval (HPIR), face issues with hash collisions, where multiple database entries are returned instead of a single entry, leading to potential unauthorized disclosure of data, which is undesirable or prohibited in certain scenarios.
Innovation Solution
The implementation of selector derived encryption (SDE) using a commutative encryption scheme, where a hashed and encrypted database is created, and an encrypted selector exchange protocol ensures that only data corresponding to the requested selector can be decrypted, mitigating hash collisions by using responder and querier keys to manage access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hash-based private information retrieval (HPIR) is used to encrypt database entries, then data confidentiality is improved, but hash collisions cause multiple entries to be returned instead of a single entry, leading to potential unauthorized disclosure of data
Solution Approach 1:
The database is segmented into multiple encrypted buckets based on hash values, with each bucket containing only entries that hash to the same value. This segmentation isolates hash collisions to specific buckets, preventing unauthorized access to entire database sections.
Solution Approach 2:
The patent implements nested encryption where entries are first encrypted with a bucket key, then the bucket itself is encrypted with a derived key from the selector. This multi-layer nesting ensures that even if hash collisions occur, only the specific colliding entries are accessible, not other data.
2Loss of information
If multiple encrypted rows are returned to handle hash collisions, then completeness of data retrieval is improved, but the risk of exposing unintended data increases
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the system returns multiple encrypted rows but provides a decryption key only for the matching entry. This intermediary key distribution ensures complete retrieval of intended data while preventing access to unintended data from hash collisions.
Solution Approach 2:
Different security properties are applied locally to different data rows. The matching row receives a decryption key with specific properties that allow decryption, while colliding rows maintain encryption properties that prevent decryption by the same key, ensuring selective access.
3Device complexity
If traditional encryption methods are used, then implementation simplicity is maintained, but they cannot prevent unauthorized disclosure in cases of hash collisions
Solution Approach 1:
The system performs preliminary encryption of database entries with bucket keys before storing them, and pre-computes hash bucket assignments. This preliminary action ensures that when queries are made, the system can quickly identify and securely handle hash collisions without complex runtime processing.
Solution Approach 2:
The patent changes the encryption parameters dynamically based on the query selector. Different derived keys are generated for different selectors, and the encryption/decryption parameters are adjusted accordingly, allowing the system to maintain simplicity while providing selective access control.
Data Source
AI summary
Example selector derived encryption methods and systems include creating a hashed and encrypted database, as well as performing a query against the hashed and encrypted database using an encrypted selector exchange protocol to prevent the exposure of extraneous data from the hashed and encrypted database.


