Systems and methods for authenticating and protecting the integrity of data streams and other data
Abstract
Systems and methods are disclosed for enabling a recipient of a cryptographically-signed electronic communication to verify the authenticity of the communication on-the-fly using a signed chain of check values, the chain being constructed from the original content of the communication, and each check value in the chain being at least partially dependent on the signed root of the chain and a portion of the communication. Fault tolerance can be provided by including error-check values in the communication that enable a decoding device to maintain the chain's security in the face of communication errors. In one embodiment, systems and methods are provided for enabling secure quasi-random access to a content file by constructing a hierarchy of hash values from the file, the hierarchy deriving its security in a manner similar to that used by the above-described chain. The hierarchy culminates with a signed hash that can be used to verify the integrity of other hash values in the hierarchy, and these other hash values can, in turn, be used to efficiently verify the authenticity of arbitrary portions of the content file.
Claims
exact text as granted — not AI-modified1 .- 18 . (canceled)
19 . A method for securely accessing a data stream comprising:
receiving a first portion of the data stream; accessing a root verification value; accessing one or more check values in a hierarchy of check values; verifying the integrity of the one or more check values using, at least in part, the root verification value to identify the one or more check values as one or more verified check values; securely storing said one or more verified check values; generating a calculated check value by performing a transformation on the first portion of the data stream; accessing a first verified check value of the one or more securely stored verified check values; comparing the calculated check value with the first verified check value; and determining whether the first portion of the data stream should be released for use based at least in part on whether the calculated check value matches the first verified check value.
20 . The method of claim 19 , wherein the hierarchy of check values is derived, at least in part, from an uncorrupted version of the data stream.
21 . The method of claim 19 , wherein the root verification value is obtained by decrypting a digital signature associated with the data stream.
22 . The method of claim 19 , wherein the root verification value is derived, at least in part, from the check values in the hierarchy of check values.
23 . The method of claim 19 , wherein at least the step of verifying is performed within a protected processing environment.
24 . The method of claim 19 , wherein at least the step of generating is performed within a protected processing environment.
25 . The method of claim 19 , wherein at least the step of comparing is performed within a protected processing environment.
26 . The method of claim 19 , wherein at least the steps of verifying, generating, and comparing are performed within a protected processing environment.
27 . The method of claim 19 , wherein accessing the first verified check value comprises accessing the verified check values from a tamper resistant memory unit.
28 . The method of claim 19 , wherein the hierarchy of check values comprises a tree data structure.
29 . The method of claim 28 , wherein the tree data structure is symmetric.
30 . The method of claim 29 , wherein the tree data structure has a branching factor of four.
31 . The method of claim 19 , wherein determining whether the first portion of the data should be released for use comprises:
determining that the calculated check value is not equal to the first verified check value; and inhibiting at least one use of the first portion of the data stream.
32 . The method of claim 31 , wherein the method further comprises terminating receipt of further portions of the data stream.
33 . The method of claim 31 , wherein the method further comprises generating a report indicating that the calculated check value is not equal to the first verified check value.
34 . The method of claim 31 , wherein the method further comprises updating a running total of errors associated with the data stream based on determining that the calculated check value is not equal to the first verified check value.
35 . The method of claim 31 , wherein the method further comprises:
comparing the updated running total of errors with a threshold; and implementing at least one defensive action based on determining that the updated running total of errors exceeds the threshold.
36 . The method of claim 31 , wherein the method further comprises updating a pattern of detected errors associated with the data stream based on determining that the calculated check value is not equal to the first verified check value.
37 . The method of claim 36 , wherein the method further comprises:
identifying in the updated pattern of detected errors a number of errors in consecutive portions of the data stream exceeding a threshold; and implementing at least one defensive action based on determining that the number of errors in consecutive portions of the data stream exceeds the threshold.
38 . The method of claim 36 , wherein the method further comprises:
identifying in the updated pattern of detected errors that a number of errors exceeding a threshold occur in similar positions within the data stream; and implementing at least one defensive action based on determining that the number of errors in consecutive portions of the data stream exceeds the threshold.
39 . The method of claim 19 , wherein determining whether the first portion of the data should be released for use comprises:
determining that the calculated check value is equal to the first verified check value; and releasing the first portion of data stream for use.
40 . The method of claim 39 , wherein the method further comprises generating a report indicating that the calculated check value is equal to the first verified check value.Join the waitlist — get patent alerts
Track US2019042794A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.