US2019042794A1PendingUtilityA1

Systems and methods for authenticating and protecting the integrity of data streams and other data

Assignee: INTERTRUST TECH CORPPriority: Dec 14, 1999Filed: Jun 15, 2018Published: Feb 7, 2019
Est. expiryDec 14, 2019(expired)· nominal 20-yr term from priority
G06F 21/53H04L 2209/30G06F 21/64H04L 2209/38G06F 2221/2149H04L 9/3236H04L 63/0428H04L 2209/603H04L 9/50
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are disclosed for enabling a recipient of a cryptographically-signed electronic communication to verify the authenticity of the communication on-the-fly using a signed chain of check values, the chain being constructed from the original content of the communication, and each check value in the chain being at least partially dependent on the signed root of the chain and a portion of the communication. Fault tolerance can be provided by including error-check values in the communication that enable a decoding device to maintain the chain's security in the face of communication errors. In one embodiment, systems and methods are provided for enabling secure quasi-random access to a content file by constructing a hierarchy of hash values from the file, the hierarchy deriving its security in a manner similar to that used by the above-described chain. The hierarchy culminates with a signed hash that can be used to verify the integrity of other hash values in the hierarchy, and these other hash values can, in turn, be used to efficiently verify the authenticity of arbitrary portions of the content file.

Claims

exact text as granted — not AI-modified
1 .- 18 . (canceled) 
     
     
         19 . A method for securely accessing a data stream comprising:
 receiving a first portion of the data stream;   accessing a root verification value;   accessing one or more check values in a hierarchy of check values;   verifying the integrity of the one or more check values using, at least in part, the root verification value to identify the one or more check values as one or more verified check values;   securely storing said one or more verified check values;   generating a calculated check value by performing a transformation on the first portion of the data stream;   accessing a first verified check value of the one or more securely stored verified check values;   comparing the calculated check value with the first verified check value; and   determining whether the first portion of the data stream should be released for use based at least in part on whether the calculated check value matches the first verified check value.   
     
     
         20 . The method of  claim 19 , wherein the hierarchy of check values is derived, at least in part, from an uncorrupted version of the data stream. 
     
     
         21 . The method of  claim 19 , wherein the root verification value is obtained by decrypting a digital signature associated with the data stream. 
     
     
         22 . The method of  claim 19 , wherein the root verification value is derived, at least in part, from the check values in the hierarchy of check values. 
     
     
         23 . The method of  claim 19 , wherein at least the step of verifying is performed within a protected processing environment. 
     
     
         24 . The method of  claim 19 , wherein at least the step of generating is performed within a protected processing environment. 
     
     
         25 . The method of  claim 19 , wherein at least the step of comparing is performed within a protected processing environment. 
     
     
         26 . The method of  claim 19 , wherein at least the steps of verifying, generating, and comparing are performed within a protected processing environment. 
     
     
         27 . The method of  claim 19 , wherein accessing the first verified check value comprises accessing the verified check values from a tamper resistant memory unit. 
     
     
         28 . The method of  claim 19 , wherein the hierarchy of check values comprises a tree data structure. 
     
     
         29 . The method of  claim 28 , wherein the tree data structure is symmetric. 
     
     
         30 . The method of  claim 29 , wherein the tree data structure has a branching factor of four. 
     
     
         31 . The method of  claim 19 , wherein determining whether the first portion of the data should be released for use comprises:
 determining that the calculated check value is not equal to the first verified check value; and   inhibiting at least one use of the first portion of the data stream.   
     
     
         32 . The method of  claim 31 , wherein the method further comprises terminating receipt of further portions of the data stream. 
     
     
         33 . The method of  claim 31 , wherein the method further comprises generating a report indicating that the calculated check value is not equal to the first verified check value. 
     
     
         34 . The method of  claim 31 , wherein the method further comprises updating a running total of errors associated with the data stream based on determining that the calculated check value is not equal to the first verified check value. 
     
     
         35 . The method of  claim 31 , wherein the method further comprises:
 comparing the updated running total of errors with a threshold; and   implementing at least one defensive action based on determining that the updated running total of errors exceeds the threshold.   
     
     
         36 . The method of  claim 31 , wherein the method further comprises updating a pattern of detected errors associated with the data stream based on determining that the calculated check value is not equal to the first verified check value. 
     
     
         37 . The method of  claim 36 , wherein the method further comprises:
 identifying in the updated pattern of detected errors a number of errors in consecutive portions of the data stream exceeding a threshold; and   implementing at least one defensive action based on determining that the number of errors in consecutive portions of the data stream exceeds the threshold.   
     
     
         38 . The method of  claim 36 , wherein the method further comprises:
 identifying in the updated pattern of detected errors that a number of errors exceeding a threshold occur in similar positions within the data stream; and   implementing at least one defensive action based on determining that the number of errors in consecutive portions of the data stream exceeds the threshold.   
     
     
         39 . The method of  claim 19 , wherein determining whether the first portion of the data should be released for use comprises:
 determining that the calculated check value is equal to the first verified check value; and   releasing the first portion of data stream for use.   
     
     
         40 . The method of  claim 39 , wherein the method further comprises generating a report indicating that the calculated check value is equal to the first verified check value.

Join the waitlist — get patent alerts

Track US2019042794A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.