US2005262086A1PendingUtilityA1

Systems and methods for integrity certification and verification

Assignee: CONTENT GUARD HOLDINGS INCPriority: Aug 28, 2000Filed: Apr 29, 2005Published: Nov 24, 2005
Est. expiryAug 28, 2020(expired)· nominal 20-yr term from priority
H04L 63/0823H04L 63/104G06F 21/10G06F 21/00G06F 17/00
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system for integrity certification and verification in a computer environment based on characteristics and behaviors of one or more applications, systems or system components as compared with a profile of characteristics and behaviors, including determining a behavior integrity profile (BIP) specifying characteristics and behaviors of one or more applications, systems or system components; determining based on the BIP whether or not characteristics and behaviors of one or more applications, systems or system components are compliant with characteristics and behaviors defined in a behavior integrity profile specification; and determining access rights to the one or more applications, systems or system components based on the step of determining the compliance.

Claims

exact text as granted — not AI-modified
1 . A method for integrity certification and verification in a computer environment based on characteristics and behaviors of one or more applications, systems or system components as compared with a profile of characteristics and behaviors, the method comprising: 
 determining a behavior integrity profile (BIP) specifying characteristics and behaviors of one or more applications, systems or system components;    determining based on the BIP whether or not characteristics and behaviors of one or more applications, systems or system components are compliant with characteristics and behaviors defined in a behavior integrity profile specification; and    determining access rights to the one or more applications, systems or system components based on the step of determining the compliance.    
   
   
       2 . The method of  claim 1 , further comprising: 
 determining an application integrity profile (AIP);    determining, based on the AIP, authenticity of the one or more applications, systems or system components; and    determining the access rights based on the authenticity determination.    
   
   
       3 . The method of  claim 2 , further comprising utilizing one or more application integrity profiles and one or more behavior integrity profiles in a conjunctive manor.  
   
   
       4 . The method of  claim 2 , further comprising providing an integrity certification and verification device, the integrity certification and verification device having access to the application integrity profile for determining the authentication information about one or more applications, systems or system components.  
   
   
       5 . The method of  claim 1 , further comprising determining via a component registration device BIP compliance status by verifying the characteristics and behaviors of the one or more applications, systems or system components against the BIP specification.  
   
   
       6 . The method of  claim 2 , wherein the BIP includes at least one of a BIP identification, identification of registered applications, systems or system components, and compliance status.  
   
   
       7 . The method of  claim 6 , further comprising maintaining via a profile database a BIP with a BIP identification, and an identification of registered applications, systems or system components.  
   
   
       8 . The method of  claim 1 , further comprising verifying via a profile verification device proof of BIP compliance by checking compliance status of the applications, systems or system components to which the BIP has been issued.  
   
   
       9 . The method of  claim 1 , further comprising obtaining via a registration application device the authentication information about the one or more applications, systems or system components from an application, system or system component provider.  
   
   
       10 . The method of  claim 6 , further comprising using the BIP identification in conjunction with distributed information.  
   
   
       11 . The method of  claim 1 , further comprising distributing via a content provider content information associated with the BIP.  
   
   
       12 . The method of  claim 1 , further comprising providing an application, system or system component provider.  
   
   
       13 . The method of  claim 10 , wherein when the BIP identification is used in conjunction with the distributed information, if a profile verification device determines that the one or more applications, systems or system components are not authentic or are not compliant with the BIP specification, access to content associated with the one or more applications, systems or system components is denied.  
   
   
       14 . The method of  claim 1 , further comprising building via a BIP creation device the BIP by deriving compliance status and application identification information corresponding to the one or more applications, systems or system components from a component database.  
   
   
       15 . The method of  claim 1 , further comprising: 
 assessing the BIP for allowing the determination of whether or not the characteristics and behaviors of the one or more applications, systems or system components are compliant with the characteristics defined in the BIP specification; and    determining the access rights based on the assessment step.    
   
   
       16 . The method of  claim 15 , further comprising verifying the BIP compliance status of the one or more applications, systems or system components.  
   
   
       17 . The method of  claim 15 , wherein the access rights include rights for at least one of allowing or denying access to content associated with the one or more applications, systems or system components.  
   
   
       18 . The method of  claim 15 , further comprising obtaining authentication information about at least one of the one or more applications, systems or system components.  
   
   
       19 . The method of  claim 1 , further comprising digitally signing the BIP.  
   
   
       20 . The method of  claim 19 , further comprising forwarding the digitally signed BIP to a system of a consumer.  
   
   
       21 . The method of  claim 1 , further comprising verifying the integrity of an integrity authenticator associated with the one or more applications, systems or system components.  
   
   
       22 . The method of  claim 2 , further comprising: 
 providing an integrity certification and verification device having access to authentication information about the one or more applications, systems or system components; and    providing the AIP used to determine the authenticity of the one or more applications, systems or system components.    
   
   
       23 . The method of  claim 22 , further comprising determining via a component registration device the AIP from the authentication information, the AIP including at least one of verifiable information and an identification of registered applications, systems or system components.  
   
   
       24 . The method of  claim 22 , further comprising maintaining via a profile database the AIP and an identification of registered applications, systems or system components.  
   
   
       25 . The method of  claim 22 , further comprising verifying via a profile verification device authenticity by comparing one or more of application, system or system component identifications, the one or more applications, systems or system components, the AIP, and/or an AIP identification.  
   
   
       26 . The method of  claim 22 , further comprising obtaining via a registration application device the authentication information about the one or more applications, systems or system components from an application, system or system component provider.  
   
   
       27 . The method of  claim 22 , wherein the AIP comprises an identification of the one or more applications, systems or system components that can be used in conjunction with distributed information.  
   
   
       28 . The method of  claim 22 , further comprising distributing via a content provider content information associated with the one or more applications, systems or system components.  
   
   
       29 . The method of  claim 22 , further comprising providing an application, system or system component provider.  
   
   
       30 . The method of  claim 22 , wherein if a profile verification device determines that the one or more applications, systems or system components are not authentic, access to one or more documents associated with the one or more applications, systems or system components is denied.  
   
   
       31 . The method of  claim 22 , further comprising determining via a profile creation device the AIP based on verifiable information about the one or more applications, systems or system components.  
   
   
       32 . The method of  claim 2 , further comprising certifying the AIP.  
   
   
       33 . The method of  claim 2 , further comprising verifying the authenticity of one or more applications, systems or system components.  
   
   
       34 . The method of  claim 2 , wherein the access rights include rights for at least one of allowing or denying access to content associated with the one or more applications, systems or system components.  
   
   
       35 . The method of  claim 2 , further comprising obtaining authentication information about the at least one application, system or system component.  
   
   
       36 . The method of  claim 2 , further comprising digitally signing the AIP.  
   
   
       37 . The method of  claim 36 , further comprising forwarding the digitally signed integrity profile to a system of a consumer.  
   
   
       38 . The method of  claim 2 , further comprising verifying the integrity of an integrity authenticator associated with the AIP.  
   
   
       39 . The method of  claim 1 , further comprising establishing a tamper resistant environment associated with the one or more applications, systems or system components.  
   
   
       40 . The method of  claim 2 , further comprising verifying the AIP.  
   
   
       41 . The method of  claim 2 , further comprising loading a valid AIP.  
   
   
       42 . The method of  claim 38 , wherein the verifying step comprises establishing that the integrity authenticator is not being at least one of monitored, controlled or recorded.  
   
   
       43 . The method of  claim 1 , wherein said method is implemented as one or more computer readable instructions embedded on a computer readable medium and configured to cause one or more computer processors to perform the steps recited in the method.  
   
   
       44 . The method of  claim 1 , wherein said method is implemented as one or more computer software and/or hardware devices configured to perform the steps recited in the method.  
   
   
       45 . A system for integrity certification and verification in a computer environment based on characteristics and behaviors of one or more applications, systems or system components as compared with a profile of characteristics and behaviors, the system comprising: 
 means for determining a behavior integrity profile (BIP) specifying characteristics and behaviors of one or more applications, systems or system components;    means for determining based on the BIP whether or not characteristics and behaviors of one or more applications, systems or system components are compliant with characteristics and behaviors defined in a behavior integrity profile specification; and    means for determining access rights to the one or more applications, systems or system components based on the determining of the compliance.    
   
   
       46 . The system of  claim 45 , further comprising: 
 means for determining an application integrity profile (AIP);    means for determining, based on the AIP, authenticity of the one or more applications, systems or system components; and    means for determining the access rights based on the authenticity determination.    
   
   
       47 . The system of  claim 46 , further comprising means for utilizing one or more application integrity profiles and one or more behavior integrity profiles in a conjunctive manor.  
   
   
       48 . The system of  claim 46 , further comprising an integrity certification and verification device, the integrity certification and verification device having access to the application integrity profile for determining the authentication information about one or more applications, systems or system components.  
   
   
       49 . The system of  claim 45 , further comprising a component registration device for determining BIP compliance status by verifying the characteristics and behaviors of the one or more applications, systems or system components against the BIP specification.  
   
   
       50 . The system of  claim 46 , wherein the BIP includes at least one of a BIP identification, identification of registered applications, systems or system components, and compliance status.  
   
   
       51 . The system of  claim 6 , further comprising a profile database for maintaining a BIP with a BIP identification, and an identification of registered applications, systems or system components.  
   
   
       52 . The system of  claim 45 , further comprising a profile verification device for verifying proof of BIP compliance by checking compliance status of the applications, systems or system components to which the BIP has been issued.  
   
   
       53 . The system of  claim 45 , further comprising a registration application device for obtaining the authentication information about the one or more applications, systems or system components from an application, system or system component provider.  
   
   
       54 . The system of  claim 50 , further comprising means for using the BIP identification in conjunction with distributed information.  
   
   
       55 . The system of  claim 45 , further comprising a content provider for distributing content information associated with the BIP.  
   
   
       56 . The system of  claim 45 , further comprising an application, system or system component provider.  
   
   
       57 . The system of  claim 54 , further comprising a profile verification device, wherein when the BIP identification is used in conjunction with the distributed information, if the profile verification device determines that the one or more applications, systems or system components are not authentic or are not compliant with the BIP specification, access to content associated with the one or more applications, systems or system components is denied.  
   
   
       58 . The system of  claim 45 , further comprising a BIP creation device for building the BIP by deriving compliance status and application identification information corresponding to the one or more applications, systems or system components from a component database.  
   
   
       59 . The system of  claim 45 , further comprising: 
 means for assessing the BIP for allowing the determination of whether or not the characteristics and behaviors of the one or more applications, systems or system components are compliant with the characteristics defined in the BIP specification; and    means for determining the access rights based on the assessment.    
   
   
       60 . The system of  claim 59 , further comprising means for verifying the BIP compliance status of the one or more applications, systems or system components.  
   
   
       61 . The system of  claim 59 , wherein the access rights include rights for at least one of allowing or denying access to content associated with the one or more applications, systems or system components.  
   
   
       62 . The system of  claim 59 , further comprising means for obtaining authentication information about at least one of the one or more applications, systems or system components.  
   
   
       63 . The system of  claim 45 , further comprising means for digitally signing the BIP.  
   
   
       64 . The system of  claim 63 , further comprising means for forwarding the digitally signed BIP to a system of a consumer.  
   
   
       65 . The system of  claim 45 , further comprising means for verifying the integrity of an integrity authenticator associated with the one or more applications, systems or system components.  
   
   
       66 . The system of  claim 46 , further comprising: 
 an integrity certification and verification device having access to authentication information about the one or more applications, systems or system components; and    means for providing the AIP used to determine the authenticity of the one or more applications, systems or system components.    
   
   
       67 . The system of  claim 66 , further comprising a component registration device for determining the AIP from the authentication information, the AIP including at least one of verifiable information and an identification of registered applications, systems or system components.  
   
   
       68 . The system of  claim 66 , further comprising a profile database for maintaining the AIP and an identification of registered applications, systems or system components.  
   
   
       69 . The system of  claim 66 , further comprising a profile verification device for verifying authenticity by comparing one or more of application, system or system component identifications, the one or more applications, systems or system components, the AIP, and/or an AIP identification.  
   
   
       70 . The system of  claim 66 , further comprising a registration application device for obtaining the authentication information about the one or more applications, systems or system components from an application, system or system component provider.  
   
   
       71 . The system of  claim 66 , wherein the AIP comprises an identification of the one or more applications, systems or system components that can be used in conjunction with distributed information.  
   
   
       72 . The system of  claim 66 , further comprising a content provider for distributing content information associated with the one or more applications, systems or system components.  
   
   
       73 . The system of  claim 66 , further comprising an application, system or system component provider.  
   
   
       74 . The system of  claim 66 , further comprising a profile verification device, wherein if the profile verification device determines that the one or more applications, systems or system components are not authentic, access to one or more documents associated with the one or more applications, systems or system components is denied.  
   
   
       75 . The system of  claim 66 , further comprising a profile creation device for determining the AIP based on verifiable information about the one or more applications, systems or system components.  
   
   
       76 . The system of  claim 46 , further comprising means for certifying the AIP.  
   
   
       77 . The system of  claim 46 , further comprising means for verifying the authenticity of one or more applications, systems or system components.  
   
   
       78 . The system of  claim 46 , wherein the access rights include rights for at least one of allowing or denying access to content associated with the one or more applications, systems or system components.  
   
   
       79 . The system of  claim 46 , further comprising means for obtaining authentication information about the at least one application, system or system component.  
   
   
       80 . The system of  claim 46 , further comprising means for digitally signing the AIP.  
   
   
       81 . The system of  claim 80 , further comprising means for forwarding the digitally signed integrity profile to a system of a consumer.  
   
   
       82 . The system of  claim 46 , further comprising means for verifying the integrity of an integrity authenticator associated with the AIP.  
   
   
       83 . The system of  claim 45 , further comprising means for establishing a tamper resistant environment associated with the one or more applications, systems or system components.  
   
   
       84 . The system of  claim 46 , further comprising means for verifying the AIP.  
   
   
       85 . The system of  claim 46 , further comprising means for loading a valid AIP.  
   
   
       86 . The system of  claim 82 , wherein the means for verifying comprises means for establishing that the integrity authenticator is not being at least one of monitored, controlled or recorded.  
   
   
       87 . The system of  claim 45 , wherein said system is implemented as one or more computer software and/or hardware devices.

Join the waitlist — get patent alerts

Track US2005262086A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.