Patents by Inventor Qingji Zheng
Qingji Zheng has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 11606203Abstract: A method for implementing a secure multiparty inner product computation between two parties using an SPDZ protocol involves having a first party and a second party compute, for i=1, . . . , k, a vector (I)=(II) based on a vector (x={x1, . . . , xN}), and a vector (w={W1, WN}), respectively, where (I)=(X2i-1X2i) (III)=W2i-1W2i, N is the total number of elements in the vectors k=N/2. The vectors (I), and (III) are securely shared between the parties. The parties then jointly compute SPDZ protocol Add([w2i], [x2i-1]) and Add([w2i], [x2i-1]) to determine shares [w2i-1+x2i] and [w2i+x2i-1] respectively, and then compute, for i=1, . . . , k, inner product shares [di] by performing SPDZ protocol Mult([w2i-1+x2i], [w2i+x2i-1]). SPDZ protocol ([Add d1], . . . , [dk], -(IV), . . . , -(V), -(VI), -, (VII)) is then performed to determine the inner product.Type: GrantFiled: December 13, 2018Date of Patent: March 14, 2023Assignee: Robert Bosch GmbHInventors: Xinxin Fan, Qingji Zheng, Jorge Guajardo Merchan
-
Patent number: 11405192Abstract: A searchable symmetric encryption (SSE) system and method of processing inverted index is provided. The SSE system includes genKey, buildSecureIndex, genToken, and search operations. A compress X is integrated into at least one of the buildSecureIndex and search operations. The compress then X takes each entry of an encrypted index, compresses entry of the encrypted index into a compressed entry, and then processes the compressed entry with a function. The function comprises a linked list function and on array function. The search operation decompresses the processed entry and output the decompressed entry. The SSE comprises a client device and a server. The genKey, buildSecureIndex, and genToken operations are integrated into the client device and the search operation is integrated into the server.Type: GrantFiled: August 24, 2017Date of Patent: August 2, 2022Assignee: Robert Bosch GmbHInventors: Qingji Zheng, Xinxin Fan, Jorge Guajardo Merchan
-
Patent number: 11323444Abstract: A method for secure multiparty computation of an inner product includes performing multiparty additions to generate a first sum share and a second sum share between two shares of alternating elements from corresponding pairs of elements in a first vector and a second vector, performing multiparty multiplications with at least one other node to generate inner product pair shares corresponding to products of the first sum shares and the second sum shares corresponding to pairs of elements in the first and second vectors, and performing another multiparty addition of each inner product pair share with a first negated shares of pair products corresponding to pairs of elements in the first vector and a second negated shares of pair products corresponding to pairs of elements in the second vector to generate a share of an inner product of the first and second vectors.Type: GrantFiled: September 25, 2018Date of Patent: May 3, 2022Assignee: Robert Bosch GmbHInventors: Xinxin Fan, Qingji Zheng, Jorge Guajardo Merchan
-
Patent number: 11222136Abstract: A DSSE architecture network enables multi-user such as data owners and data users to conduct privacy-preserving search on the encrypted PHIs stored in a cloud network and verify the correctness and completeness of retrieved search results simultaneously is provided. The data owners and data users may be patients, HSPs, or combination thereof. An IoT gateway aggregates periodically collected data into a single PHI file, extract keywords, build an encrypted index, and encrypt the PHI files before the encrypted index and PHI files are transmitted to a cloud network periodically for storage thus enable the DSSE architecture network to achieve a sub-linear search efficiency and forward privacy by maintaining an increasing counter for each keyword at the IoT gateway. Since the PHI files are always transmitted and added/stored into the cloud storage over the cloud network, file deletion, file modification is eliminated.Type: GrantFiled: July 25, 2017Date of Patent: January 11, 2022Assignee: Robert Bosch GmbHInventors: Xinxin Fan, Qingji Zheng, Lei Yang
-
Patent number: 11201734Abstract: A method for implementing a secure multiparty computation protocol between a plurality of parties for a multiparty computation includes performing an offline phase of an SPDZ protocol for each of the parties participating in the multiparty computation. A secret share redistribution phase is then performed wherein the secret shares of the parties are redistributed to a subset of the parties. A secret share recombination phase is performed during which the subset of the parties recombines the redistributed secret shares to recover the secret shares of the parties not in the subset. An online phase of the SPDZ protocol is then performed during which the function is computed with respect to the private inputs of the parties and using the secret shares of all the parties.Type: GrantFiled: January 31, 2019Date of Patent: December 14, 2021Assignee: Robert Bosch GmbHInventors: Qingji Zheng, Shalabh Jain, Jorge Guajardo Merchan, Sebastian Becker, Sven Trieflinger
-
Patent number: 11023477Abstract: A method for performing a fuzzy search in encrypted data includes receiving an encrypted search token corresponding to a search keyword with an untrusted server computing device and generating inner product values based on a function-hiding inner product encryption operation of the encrypted query vectors encrypted node vectors in an encrypted tree stored in the memory of the untrusted server computing device. The method further includes transmitting, with the untrusted server computing device, the encrypted keyword stored in the leaf node to a client computing device in response to the first inner product value exceeding a first predetermined similarity threshold corresponding to a similarity of the first query vector to the leaf node vector, the fuzzy search not revealing plaintext contents for any of a keyword stored in the leaf node, the search keyword, or a fuzziness parameter.Type: GrantFiled: December 27, 2017Date of Patent: June 1, 2021Assignee: Robert Bosch GmbHInventors: Xinxin Fan, Qingji Zheng
-
Publication number: 20200228325Abstract: A method for implementing a secure multiparty inner product computation between two parties using an SPDZ protocol involves having a first party and a second party compute, for i=k, a vector (I)=(II) based on a vector (x={1, . . . , xN}), and a vector (w={W1, WN}), respectively, where (I)=(X2i?X2i) (III)=W2i?1W2i, N is the total number of elements in the vectors k=N/2. The vectors (I), and (III) are securely shared between the parties. The parties then jointly compute SPDZ protocol Add([w2i], [x2i?1]) and Add([w2i], [x2i?1]) to determine shares [w2i?1+x2i] and [w2i+x2i?1] respectively, and then compute, for i=1, . . . , k, inner product shares [di] by performing SPDZ protocol Mult([w2i31 1+x2i], [w2i+x2i?1]). SPDZ protocol ([Add d1],. . . , [dk], ?(IV), . . .Type: ApplicationFiled: December 13, 2018Publication date: July 16, 2020Inventors: Xinxin FAN, Qingji ZHENG, Jorge GUAJARDO MERCHAN
-
Publication number: 20200186528Abstract: A method for secure multiparty computation of an inner product includes performing multiparty additions to generate a first sum share and a second sum share between two shares of alternating elements from corresponding pairs of elements in a first vector and a second vector, performing multiparty multiplications with at least one other node to generate inner product pair shares corresponding to products of the first sum shares and the second sum shares corresponding to pairs of elements in the first and second vectors, and performing another multiparty addition of each inner product pair share with a first negated shares of pair products corresponding to pairs of elements in the first vector and a second negated shares of pair products corresponding to pairs of elements in the second vector to generate a share of an inner product of the first and second vectors.Type: ApplicationFiled: September 25, 2018Publication date: June 11, 2020Inventors: Xinxin Fan, Qingji Zheng, Jorge Guajardo Merchan
-
Publication number: 20200125563Abstract: A method for performing a fuzzy search in encrypted data includes receiving an encrypted search token corresponding to a search keyword with an untrusted server computing device and generating inner product values based on a function-hiding inner product encryption operation of the encrypted query vectors encrypted node vectors in an encrypted tree stored in the memory of the untrusted server computing device. The method further includes transmitting, with the untrusted server computing device, the encrypted keyword stored in the leaf node to a client computing device in response to the first inner product value exceeding a first predetermined similarity threshold corresponding to a similarity of the first query vector to the leaf node vector, the fuzzy search not revealing plaintext contents for any of a keyword stored in the leaf node, the search keyword, or a fuzziness parameter.Type: ApplicationFiled: December 27, 2017Publication date: April 23, 2020Inventors: Xinxin Fan, Qingji Zheng
-
Publication number: 20190372760Abstract: A method for implementing a secure multiparty computation protocol between a plurality of parties for a multiparty computation includes performing an offline phase of an SPDZ protocol for each of the parties participating in the multiparty computation. A secret share redistribution phase is then performed wherein the secret shares of the parties are redistributed to a subset of the parties. A secret share recombination phase is performed during which the subset of the parties recombines the redistributed secret shares to recover the secret shares of the parties not in the subset. An online phase of the SPDZ protocol is then performed during which the function is computed with respect to the private inputs of the parties and using the secret shares of all the parties.Type: ApplicationFiled: January 31, 2019Publication date: December 5, 2019Inventors: Qingji Zheng, Shalabh Jain, Jorge Guajardo Merchan, Sebastian Becker, Sven Trieflinger
-
Publication number: 20190278939Abstract: A DSSE architecture network enables multi-user such as data owners and data users to conduct privacy-preserving search on the encrypted PHIs stored in a cloud network and verify the correctness and completeness of retrieved search results simultaneously is provided. The data owners and data users may be patients, HSPs, or combination thereof. An IoT gateway aggregates periodically collected data into a single PHI file, extract keywords, build an encrypted index, and encrypt the PHI files before the encrypted index and PHI files are transmitted to a cloud network periodically for storage thus enable the DSSE architecture network to achieve a sub-linear search efficiency and forward privacy by maintaining an increasing counter for each keyword at the IoT gateway. Since the PHI files are always transmitted and added/stored into the cloud storage over the cloud network, file deletion, file modification is eliminated.Type: ApplicationFiled: July 25, 2017Publication date: September 12, 2019Inventors: Xinxin Fan, Qingji Zheng, Lei Yang
-
Publication number: 20190190709Abstract: A searchable symmetric encryption (SSE) system and method of processing inverted index is provided. The SSE system includes genKey, buildSecureIndex, genToken, and search operations. A compress X is integrated into at least one of the buildSecureIndex and search operations. The compress then X takes each entry of an encrypted index, compresses entry of the encrypted index into a compressed entry, and then processes the compressed entry with a function. The function comprises a linked list function and on array function. The search operation decompresses the processed entry and output the decompressed entry. The SSE comprises a client device and a server. The genKey, buildSecureIndex, and genToken operations are integrated into the client device and the search operation is integrated into the server.Type: ApplicationFiled: August 24, 2017Publication date: June 20, 2019Inventors: Qingji Zheng, Xinxin Fan, Jorge Guajardo Merchan
-
Patent number: 10181949Abstract: A data device controls distribution of data to user devices through an edge router via an encryption scheme. The data device encrypts data using a first key and a public key, and sends the data to the edge router. The edge router encrypts the encrypted data with a second key and sends the re-encrypted data to a user device. The data device then authenticates the user device and issues a decryption key derived from a private key corresponding to the public key, the first key, and the second key to the user device. The user device uses the decryption key to decrypt and access the data.Type: GrantFiled: October 12, 2015Date of Patent: January 15, 2019Assignee: Futurewei Technologies, Inc.Inventors: Qingji Zheng, Guoqiang Wang, Ravishankar Ravindran
-
Publication number: 20180219871Abstract: Methods, apparatus, and systems are provided for lightweight integrity verification of fragmented chunks in an information centric network. One aspect provides a method of securely providing data. A data file is segmented into multiple chunks of data, and each of the multiple chunks is divided into virtual fragments based on a maximum transmission unit size. Hash values are calculated using the virtual fragments, and a manifest is created using the hash values. In various embodiments, the manifest is provided to a consumer based on a received interest for comparison and integrity verification of virtual fragments.Type: ApplicationFiled: February 1, 2017Publication date: August 2, 2018Inventors: Syed Obaid Amin, Qingji Zheng, Ravishankar Ravindran
-
Patent number: 9774610Abstract: A method comprises accessing, by a processor of a machine, an encrypted data packet from a first source, the encrypted data packet being accompanied by a signature of the first source. The processor further accesses parameters from a second source and verifies, based on the signature of the first source and the parameters, that the encrypted data packet was generated by the first source. The method further comprises decrypting, based on the verification that the encrypted data packet was generated by the first source, by the processor, the encrypted data packet.Type: GrantFiled: July 28, 2015Date of Patent: September 26, 2017Assignee: Futurewei Technologies, Inc.Inventors: Qingji Zheng, Guoqiang Wang
-
Publication number: 20170201375Abstract: A network enabled computer system includes a processor and a dual stack communication module to couple to a network. The dual stack communication module includes information centric network layers and a secure network connection layer, each coupled to an IP connection layer to couple to a network. A storage device is coupled to the processor to cause the processor to execute operations to route IP packets. The operations include establishing a secure connection using the secure connection layer, performing authentication via the secure connection using the secure connection layer, exchanging an encryption key via the secure connection using the secure connection layer, and transferring encrypted chunks of data using information centric network IP-content packets via the information centric network layers.Type: ApplicationFiled: January 8, 2016Publication date: July 13, 2017Inventors: Syed Obaid Amin, Ravishankar Ravindran, Qingji Zheng
-
Publication number: 20170034186Abstract: A method comprises accessing, by a processor of a machine, an encrypted data packet from a first source, the encrypted data packet being accompanied by a signature of the first source. The processor further accesses parameters from a second source and verifies, based on the signature of the first source and the parameters, that the encrypted data packet was generated by the first source. The method further comprises decrypting, based on the verification that the encrypted data packet was generated by the first source, by the processor, the encrypted data packet.Type: ApplicationFiled: July 28, 2015Publication date: February 2, 2017Inventors: Qingji Zheng, Guoqiang Wang
-
Publication number: 20160105279Abstract: A data device controls distribution of data to user devices through an edge router via an encryption scheme. The data device encrypts data using a first key and a public key, and sends the data to the edge router. The edge router encrypts the encrypted data with a second key and sends the re-encrypted data to a user device. The data device then authenticates the user device and issues a decryption key derived from a private key corresponding to the public key, the first key, and the second key to the user device. The user device uses the decryption key to decrypt and access the data.Type: ApplicationFiled: October 12, 2015Publication date: April 14, 2016Applicant: Futurewei Technologies, Inc.Inventors: Qingji ZHENG, Guoqiang WANG, Ravishankar RAVINDRAN
-
Patent number: 9252942Abstract: One embodiment of the present invention provides a system for performing secure multiparty cloud computation. During operation, the system receives multiple encrypted datasets from multiple clients. An encrypted dataset associated with a client is encrypted from a corresponding plaintext dataset using a unique, client-specific encryption key. The system re-encrypts the multiple encrypted datasets to a target format, evaluates a function based on the re-encrypted multiple datasets to produce an evaluation outcome, and sends the evaluation outcome to the multiple clients, which are configured to cooperatively decrypt the evaluation outcome to obtain a plaintext evaluation outcome.Type: GrantFiled: April 17, 2012Date of Patent: February 2, 2016Assignee: Futurewei Technologies, Inc.Inventors: Xinwen Zhang, Qingji Zheng, Antontius Kalker, Guoqiang Wang
-
Publication number: 20130275752Abstract: One embodiment of the present invention provides a system for performing secure multiparty cloud computation. During operation, the system receives multiple encrypted datasets from multiple clients. An encrypted dataset associated with a client is encrypted from a corresponding plaintext dataset using a unique, client-specific encryption key. The system re-encrypts the multiple encrypted datasets to a target format, evaluates a function based on the re-encrypted multiple datasets to produce an evaluation outcome, and sends the evaluation outcome to the multiple clients, which are configured to cooperatively decrypt the evaluation outcome to obtain a plaintext evaluation outcome.Type: ApplicationFiled: April 17, 2012Publication date: October 17, 2013Applicant: FUTUREWEI TECHNOLOGIES, INC.Inventors: Xinwen Zhang, Qingji Zheng, Antontius Kalker, Guoqiang Wang