US2008133928A1PendingUtilityA1

A computer-implemented method and system for embedding and authenticating ancillary information in digitally signed content

Individually held — no corporate assignee on recordPriority: May 20, 2005Filed: Feb 14, 2008Published: Jun 5, 2008
Est. expiryMay 20, 2025(expired)· nominal 20-yr term from priority
G06F 21/64G06F 21/51G06F 21/10G06F 21/16
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer-implemented system and method for embedding and authenticating ancillary information in digitally signed content are disclosed. The method and system include loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and erasing any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and   erasing any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.   
     
     
         2 . The method as claimed in  claim 1  wherein the non-authenticated regions of the digital content include regions past the end of the last section of the digital content. 
     
     
         3 . The method as claimed in  claim 1  including verifying that a checksum field in a header of the digital content matches an image file checksum. 
     
     
         4 . The method as claimed in  claim 1  including verifying that the attribute certificate table contains one single entry and does not contain padding. 
     
     
         5 . The method as claimed in  claim 1  including verifying that the digital signature actually fills the whole space allocated to the digital signature in an attribute certificate table. 
     
     
         6 . The method as claimed in  claim 1  wherein the digital content is a file. 
     
     
         7 . The method as claimed in  claim 1  wherein the digital content is a digital transmission. 
     
     
         8 . The method as claimed in  claim 1  including virtualizing access to the digital content and erasing any non-authenticated regions of the virtualized digital content. 
     
     
         9 . The method as claimed in  claim 1  wherein the erasing is performed by a loader. 
     
     
         10 . The method as claimed in  claim 1  wherein the erasing is performed by the executable. 
     
     
         11 . An article of manufacture embodied in a machine storage medium including data that, when accessed by a machine, causes the machine to:
 load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and   erase any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.   
     
     
         12 . The article of manufacture as claimed in  claim 11  wherein the non-authenticated regions of the digital content include regions past the end of the last section of the digital content. 
     
     
         13 . The article of manufacture as claimed in  claim 11  being further operable to verify that a checksum field in a header of the digital content matches an image file checksum. 
     
     
         14 . The article of manufacture as claimed in  claim 11  being further operable to verify that the attribute certificate table contains one single entry and does not contain padding. 
     
     
         15 . The article of manufacture as claimed in  claim 11  being further operable to verify that the digital signature actually fills the whole space allocated to the digital signature in an attribute certificate table. 
     
     
         16 . The article of manufacture as claimed in  claim 11  wherein the digital content is a file. 
     
     
         17 . The article of manufacture as claimed in  claim 11  wherein the digital content is a digital transmission. 
     
     
         18 . The article of manufacture as claimed in  claim 11  being further operable to virtualize access to the digital content and erase any non-authenticated regions of the virtualized digital content. 
     
     
         19 . The article of manufacture as claimed in  claim 11  wherein the erasing is performed by a loader. 
     
     
         20 . The article of manufacture as claimed in  claim 11  wherein the erasing is performed by the executable. 
     
     
         21 . A method comprising:
 loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and   performing verification operations on the executable to verify integrity of the executable.   
     
     
         22 . The method as claimed in  claim 21  wherein the verification operations include a checksum verification. 
     
     
         23 . The method as claimed in  claim 21  wherein the verification operations include verifying that there is no information past the end of the last section of the executable. 
     
     
         24 . The method as claimed in  claim 21  wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding with fixed data. 
     
     
         25 . The method as claimed in  claim 21  wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table. 
     
     
         26 . An article of manufacture embodied in a machine storage medium including data that, when accessed by a machine, causes the machine to:
 load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and   perform verification operations on the executable to verify integrity of the executable.   
     
     
         27 . The article of manufacture as claimed in  claim 26  wherein the verification operations include a checksum verification. 
     
     
         28 . The article of manufacture as claimed in  claim 26  wherein the verification operations include verifying that there is no information past the end of the last section of the executable. 
     
     
         29 . The article of manufacture as claimed in  claim 26  wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding with fixed data. 
     
     
         30 . The article of manufacture as claimed in  claim 26  wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table.

Join the waitlist — get patent alerts

Track US2008133928A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.