US2009238365A1PendingUtilityA1

Method and system to provide fine granular integrity to digital data

Assignee: KINAMIK DATA INTEGRITY S LPriority: Mar 20, 2008Filed: Mar 20, 2008Published: Sep 24, 2009
Est. expiryMar 20, 2028(~1.6 yrs left)· nominal 20-yr term from priority
G06F 21/645
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and system to generate fine granular integrity to huge volumes of data in real time at a very low computational cost. The invention proposes a scalable system that can receive different digital data from multiple sources and generates integrity streams associated to the original data. This invention provides full guarantees for data integrity; the order of data logged cannot be altered and content cannot be modified added or deleted without detection.

Claims

exact text as granted — not AI-modified
1 . A method to generate fine granular integrity to huge volumes of data in real time at a very low computational cost for use with a computer the method comprising:
 receiving original data from multiple sources ( 310 ,  600 ), over a communication way or network using predetermined protocols;   processing the original data by cryptographic means ( 510 ,  610 ) for generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and   communicating ( 515 , 620 ) said digital chains to a receiver, said receiver being one of: the same as the sender of the original data ( 312 ), a different receiver ( 311 ) or a storage media ( 320 ,  640 ),   
     wherein the generating the immutable digital chains comprises:
 a) establishing at least one symmetric session key K; 
 b) securely destroying an old previous session key, if any; 
 c) encrypting said at least one symmetric session key K using an asymmetric public key of an authorized receiver P Aud , thus obtaining K′=P Aud (K) and also digitally sign it obtaining K″=DSs(K′); 
 d) creating at least one of the digital chains with said K′ and K″ values with a timestamp and a digital signature of previous values all together; or add to at least one of the digital chains said K′ and K″ values with a timestamp and a digital signature of previous values all together, and 
 e) every time a new unit m i  of original data is received, a new link entry i  is created to at least one of the digital chains according the formula entry i =(timestamp, MAC K (m i ,timestamp,MAC i-1 )), where MAC relates to Message Authentication Codes. 
 
   
   
       2 . The method according to  claim 1  wherein metronome entries are added to at least one digital chain at predefined regular intervals, even if no new units of original data are received. 
   
   
       3 . The method according to  claim 1  further comprising adding a last link to digital chains to securely close them when a shutdown of the system occurs. 
   
   
       4 . The method according to  claim 1  wherein the new link entry generated every time a new unit m i  of original data is received also contains the content of the new unit m i  of original data, according the formula entry i =(m i , timestamp, MAC K (m i ,timestamp,MAC i-1 )) 
   
   
       5 . The method according  claim 4  wherein the content of the new unit m i  of original data including at the new link entry generated is symmetrically encrypted, according the formula entry=(E(m i ), timestamp, MAC K (E(m i ), timestamp,MAC i-1 )) using the same symmetrical session key K. 
   
   
       6 . The method according  claim 5  wherein the session key used for encryption is different than the session key used for message authentication codes. 
   
   
       7 . The method according to  claim 1  wherein an industry standard Hardware Security Module (HSM) or a smart card or a USB crypto-token is used to generate at least one private key, keep it always secret, and use it to carry out the asymmetric encryption and digital signatures related at least to one of said one or more immutable digital chains. 
   
   
       8 . The method according to  claim 7  wherein the Hardware Security Module (HSM) or smart card or USB crypto-token ( 650 ) is also used to execute the method to generate said one or more immutable digital chains. 
   
   
       9 . A system to generate fine granular integrity to huge volumes of data in real time at a very low computational cost comprising at least one independent server hosting a software program, platform independent implementation that can run on standard hardware, comprising:
 multiple sources ( 310 ,  600 ) for receiving original data over a communication way or network ( 405 ) using predetermined protocols;   cryptographic means ( 510 ,  610 ) processing the original data and generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and   a receiver to which said digital chains are communicated, said receiver being one of the same as the sender of the original data ( 312 ), a different receiver or a storage media ( 320 ,  640 ).   
   
   
       10 . The system according to  claim 9 , wherein a device selected among an industry standard Hardware Security Module (HSM), a smart card or a USB crypto-token ( 650 ) is used to generate at least one private key, keep it always secret, and use it to carry out cryptographic operations. 
   
   
       11 . A computer readable medium adapted to instruct a general purpose computer to generate fine granular integrity to huge volumes of data in real time at a very low computational cost, the method comprising:
 receiving original data from multiple sources ( 310 ,  600 ), over a communication way or network ( 405 ) using predetermined protocols;   processing the original data by cryptographic means ( 510 ,  610 ) for generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and   communicating ( 515 ,  620 ) said digital chains to a receiver, said receiver being one of: the same as the sender of the original data ( 312 ), a different receiver ( 311 ) or a storage media ( 320 ,  640 ),   wherein generating the immutable digital chains comprises:   a) generating at least one symmetric session key K;   b) securely destroying an old previous session key, if any;   c) encrypting said at least one symmetric session key K using an asymmetric public key of an authorized receiver P Aud , thus obtaining K′=P Aud (K) and also digitally sign it obtaining K″=DSs(K′);   d) creating at least one of the digital chains with said K′ and K″ values with a timestamp and a digital signature of previous values all together; or add to at least one of the digital chains said K′ and K″ values with a timestamp and a digital signature of previous values all together; and   e) every time a net unit m i  of original data is received, a new link entry i  is created to at least one of the digital chains according the formula entry i =(timestamp, MAC K (m i , timestamp, MAC i-1 )), where MAC relates to Message Authentication Codes.

Join the waitlist — get patent alerts

Track US2009238365A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.