摘要:
The invention relates to a computer implemented method for sending a message to a recipient user, wherein a recipient asymmetric cryptographic key pair is associated with the recipient user, said key pair comprising a public recipient key (118) and a private recipient key (116), the method comprising sending the message to said recipient user with the recipient address to which the message is sent comprising the public recipient key (118).
摘要:
The invention relates to a method for creating a second asymmetric cryptographic pair of keys (206), wherein a first private key (G 0 , 154) together with a first public key (O 0 , 126) forms a first asymmetric cryptographic pair of keys (K 0 , 218), wherein the method comprises the following steps: receiving a user identifier; calculating a second private key (G 1 ), wherein a random value (z) and the user identifier are considered in the calculation; calculating a second public key (O 1 ) from the second private key using an asymmetric cryptographic key creation method, wherein the second private key and the second public key form the second asymmetric cryptographic pair of keys (K 1 , 206); creating a first ciphertext (C_G 0 _O 1 , 212; 186) by encrypting the first private key (G 0 ) with the second public key (O 1 ); storing the first ciphertext (C_G 0 _O 1 , 212; 186).
摘要:
The present invention relates to a computer system comprising: - multiple sets (S1, S2,...,Si,...,SI-1, SI) of client computers (Ci1, Ci2,...,Cij,...CiJ), each client computer having installed thereon an application program (104), the application program comprising client computer specific log-in information (Lij), - a database system (1,12) being coupled to the set of client computers via a network (114), the database system having a log-in component (118) for logging-in the client computers, the database system being partitioned into multiple relational databases (DB1, DB2,... DBi,...DBI), each one of the databases being assigned to one set of the sets of client computers, each database storing encrypted data items, each data item being encrypted with one of the user or user-group specific cryptographic keys, the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, the log-in component comprising assignment information (118) indicative of the assignment of the databases to the set of client computers.
摘要翻译:本发明涉及一种计算机系统,包括: - 多组(S1,S2,...,硅,...,SI-1,SI)的客户端计算机(α1,CI2,...的,C IJ,.. .CiJ),具有安装在每个客户端计算机在其上以应用程序(104),所述应用程序包括客户计算机专用的登录信息(LIJ) - 一个数据库系统(1.12)被耦合到经由所述一组客户端计算机的 一个网络(114),具有用于登录部件(118)的数据库系统测井在客户端计算机,数据库系统被划分成多个关系数据库(DB1,DB2,... DB I ... DBI) 中,数据库中的每一个被分配给一个组的组的客户端计算机中的,每一个数据库存储加密的数据项,每个数据项与所述用户或用户组特定的密码密钥中的一个,所述加密密钥的密钥标识符加密 与该dataItems之一被加密被存储在作为属性加密的数据项中的所述一个,理论值的数据库 ê登录在组分,其包含分配信息(118)指示所述数据库到设定客户端计算机的分配的。
摘要:
The present invention relates to a computer system comprising: - multiple sets (S1, S2,...,Si,...,Sl-1, Sl) of client computers (Ci1, Ci2,...,Cij,...CiJ), each client computer having installed thereon an application program (104), the application program comprising client computer specific log-in information (Lij), - a database system (112) being coupled to the set of client computers via a network (114), the database system having a log-in component (118) for logging-in the client computers, the database system being partitioned into multiple relational databases (DB1, DB2, ...DBi,...DBI), each one of the databases being assigned to one set of the sets of client computers, each database storing encrypted data items, each data item being encrypted with one of the user or user-group specific cryptographic keys, the key identifier of the cryptographic key with which one of the data items is encrypted being stored in the database as an attribute of the one of the encrypted data items, the log-in component comprising assignment information (118) indicative of the assignment of the databases to the set of client computers.
摘要翻译:本发明涉及一种计算机系统,包括: - 多组(S1,S2,...,硅,...,S1,S)的客户端计算机(α1,CI2,...的,C IJ,.. .CiJ),具有安装在每个客户端计算机在其上,所述应用程序包括客户计算机专用的登录信息(LIJ)应用程序(104) - 在数据库系统(112),经由网络被耦合到该组的客户端计算机的 (114),具有用于登录部件(118)的数据库系统测井在客户端计算机,数据库系统被划分成多个关系数据库(DB1,DB2,... DB I ... DBI),每个 数据库中的一个被分配给一个组的组的客户端计算机中的,每一个数据库存储加密的数据项,每个数据项与所述用户或用户组特定的密码密钥中的一个,利用该加密密钥的密钥标识符加密 所述dataItems之一被加密被存储在作为属性加密的数据项中的一个的,在该数据库 登录在组分,其包含分配信息(118)指示所述数据库到设定客户端计算机的分配的。
摘要:
The invention relates to a client computer (10) for querying a database stored on a server (22) via a network (48), the server (22) being coupled to the client computer (10) via the network (48), wherein the database comprises a set of first relations (32; 34; 36), wherein each first relation (32; 34; 36) in the set of the first relations (32; 34; 36) comprises first data items, wherein for each first relation (32; 34; 36) the first data items are encrypted with a respective first cryptographic key (18) in the first relation, wherein the first data items form a partially ordered set in each first relation, in each first relation (32; 34; 36) the partial order being formed with respect to the first data items of said first relation (32; 34; 36) in non-encrypted form.
摘要:
Die Erfindung betrifft ein Computerprogrammprodukt (114; 116; 218; 220; 222) mit von einem Prozessor ausführbaren Instruktionen zur Durchführung von Verfahrensschritten zur Erzeugung eines asymmetrischen kryptografischen Schlüsselpaares, wobei das Verfahren die folgenden Schritte umfasst: - Empfang einer beliebig wählbaren Benutzerkennung, - Berechnen eines ersten Datenobjektschlüssels, wobei in die Berechnung ein Zufallswert (128) und die Benutzerkennung eingeht, und - Berechnen eines zweiten Datenobjektschlüssels aus dem ersten Datenobjektschlüssel, wobei der erste und der zweite Datenobjektschlüssel das asymmetrische kryptografische Schlüsselpaar bilden.