US2008133928A1PendingUtilityA1
A computer-implemented method and system for embedding and authenticating ancillary information in digitally signed content
Individually held — no corporate assignee on recordPriority: May 20, 2005Filed: Feb 14, 2008Published: Jun 5, 2008
Est. expiryMay 20, 2025(expired)· nominal 20-yr term from priority
G06F 21/64G06F 21/51G06F 21/10G06F 21/16
40
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A computer-implemented system and method for embedding and authenticating ancillary information in digitally signed content are disclosed. The method and system include loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and erasing any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.
Claims
exact text as granted — not AI-modified1 . A method comprising:
loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and erasing any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.
2 . The method as claimed in claim 1 wherein the non-authenticated regions of the digital content include regions past the end of the last section of the digital content.
3 . The method as claimed in claim 1 including verifying that a checksum field in a header of the digital content matches an image file checksum.
4 . The method as claimed in claim 1 including verifying that the attribute certificate table contains one single entry and does not contain padding.
5 . The method as claimed in claim 1 including verifying that the digital signature actually fills the whole space allocated to the digital signature in an attribute certificate table.
6 . The method as claimed in claim 1 wherein the digital content is a file.
7 . The method as claimed in claim 1 wherein the digital content is a digital transmission.
8 . The method as claimed in claim 1 including virtualizing access to the digital content and erasing any non-authenticated regions of the virtualized digital content.
9 . The method as claimed in claim 1 wherein the erasing is performed by a loader.
10 . The method as claimed in claim 1 wherein the erasing is performed by the executable.
11 . An article of manufacture embodied in a machine storage medium including data that, when accessed by a machine, causes the machine to:
load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and erase any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.
12 . The article of manufacture as claimed in claim 11 wherein the non-authenticated regions of the digital content include regions past the end of the last section of the digital content.
13 . The article of manufacture as claimed in claim 11 being further operable to verify that a checksum field in a header of the digital content matches an image file checksum.
14 . The article of manufacture as claimed in claim 11 being further operable to verify that the attribute certificate table contains one single entry and does not contain padding.
15 . The article of manufacture as claimed in claim 11 being further operable to verify that the digital signature actually fills the whole space allocated to the digital signature in an attribute certificate table.
16 . The article of manufacture as claimed in claim 11 wherein the digital content is a file.
17 . The article of manufacture as claimed in claim 11 wherein the digital content is a digital transmission.
18 . The article of manufacture as claimed in claim 11 being further operable to virtualize access to the digital content and erase any non-authenticated regions of the virtualized digital content.
19 . The article of manufacture as claimed in claim 11 wherein the erasing is performed by a loader.
20 . The article of manufacture as claimed in claim 11 wherein the erasing is performed by the executable.
21 . A method comprising:
loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and performing verification operations on the executable to verify integrity of the executable.
22 . The method as claimed in claim 21 wherein the verification operations include a checksum verification.
23 . The method as claimed in claim 21 wherein the verification operations include verifying that there is no information past the end of the last section of the executable.
24 . The method as claimed in claim 21 wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding with fixed data.
25 . The method as claimed in claim 21 wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table.
26 . An article of manufacture embodied in a machine storage medium including data that, when accessed by a machine, causes the machine to:
load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and perform verification operations on the executable to verify integrity of the executable.
27 . The article of manufacture as claimed in claim 26 wherein the verification operations include a checksum verification.
28 . The article of manufacture as claimed in claim 26 wherein the verification operations include verifying that there is no information past the end of the last section of the executable.
29 . The article of manufacture as claimed in claim 26 wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding with fixed data.
30 . The article of manufacture as claimed in claim 26 wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table.Join the waitlist — get patent alerts
Track US2008133928A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.