IP Library Granted Patent US 7,103,910
Granted Patent B1
US 7,103,910 · App. 09/483,726 · Granted Sep 5, 2006

Method and apparatus for verifying the legitimacy of an untrusted mechanism

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,103,910
App. No.
09/483,726
Granted
Sep 5, 2006
Kind
B1
Abstract

The legitimacy of an untrusted mechanism is verified by submitting a first set of information and a second set of information to the untrusted mechanism in an unpredictable sequence. For each submission of either the first set or the second set of information, a response is received from the untrusted mechanism. Each response is tested to determine if the response is correct for the information set submitted. If any of the responses from the untrusted mechanism is incorrect, then it is determined that the untrusted mechanism is not legitimate. Because the submission sequence is unpredictable, it is highly difficult if not impossible for an illegitimate untrusted mechanism to “fake” proper responses. As a result, this verification process provides an effective means for testing and verifying the legitimacy of the untrusted mechanism.

Claims (33)

1. A method for verifying the legitimacy of an untrusted signature verification mechanism, comprising:

submitting a first signature and a second signature to an untrusted signature verification mechanism in a sequence that is unpredictable to the untrusted mechanism, said first signature being known to be verifiable, and said second signature being known to be unverifiable;

receiving a response from the untrusted mechanism for each submission of either said first signature or said second signature;

determining whether each response received from the untrusted mechanism is a correct response; and

in response to a determination that any of the responses from the untrusted mechanism is an incorrect response, determining the untrusted mechanism to not be legitimate.

2. The method of claim 1 , wherein said sequence is generated randomly.

3. The method of claim 2 , wherein said sequence is generated using a random number generator.

4. The method of claim 1 , wherein said sequence includes at least one submission of said first signature and at least one submission of said second signature.

5. The method of claim 1 , wherein determining whether each response received from the untrusted mechanism is a correct response comprises:

where the signature submitted to the untrusted mechanism was said first signature, determining whether the response from the untrusted mechanism is that said first signature is verified; and

where the signature submitted to the untrusted mechanism was said second signature, determining whether the response from the untrusted mechanism is that said second signature is not verified.

6. An apparatus for verifying the legitimacy of an untrusted signature verification mechanism, comprising:

a mechanism for submitting a first signature and a second signature to an untrusted signature verification mechanism in a sequence that is unpredictable to the untrusted mechanism, said first signature being known to be verifiable, and said second signature being known to be unverifiable;

a mechanism for receiving a response from the untrusted mechanism for each submission of either said first signature or said second signature;

a mechanism for determining whether each response received from the untrusted mechanism is a correct response; and

a mechanism for determining, in response to a determination that any of the responses from the untrusted mechanism is an incorrect response, the untrusted mechanism to not be legitimate.

7. The apparatus of claim 6 , wherein said sequence is generated randomly.

8. The apparatus of claim 7 , wherein the mechanism for submitting comprises a random number generator.

9. The apparatus of claim 6 , wherein said sequence includes at least one submission of said first signature and at least one submission of said second signature.

10. The apparatus of claim 6 , wherein the mechanism for determining whether each response received from the untrusted mechanism is a correct response comprises:

a mechanism for determining, where the signature submitted to the untrusted mechanism was said first signature, whether the response from the untrusted mechanism is that said first signature is verified; and

a mechanism for determining, where the signature submitted to the untrusted mechanism was said second signature, whether the response from the untrusted mechanism is that said second signature is not verified.

11. A computer readable medium having stored thereon instructions which, when executed by one or more processors, cause the one or more processors to verify the legitimacy of an untrusted signature verification mechanism, said computer readable medium comprising:

instructions for causing one or more processors to submit a first signature and a second signature to an untrusted signature verification mechanism in a sequence that is unpredictable to the untrusted mechanism, said first signature being known to be verifiable, and said second signature being known to be unverifiable;

instructions for causing one or more processors to receive a response from the untrusted mechanism for each submission of either said first signature or said second signature;

instructions for causing one or more processors to determine whether each response received from the untrusted mechanism is a correct response; and

instructions for causing one or more processors to determine, in response to a determination that any of the responses from the untrusted mechanism is an incorrect response, the untrusted mechanism to not be legitimate.

12. The computer readable medium of claim 11 , wherein said sequence is generated randomly.

13. The computer readable medium of claim 12 , wherein said sequence is generated using a random number generator.

14. The computer readable medium of claim 11 , wherein said sequence includes at least one submission of said first signature and at least one submission of said second signature.

15. The computer readable medium of claim 11 , wherein the instructions for causing one or more processors to determine whether each response received from the untrusted mechanism is a correct response comprises:

instructions for causing one or more processors to determine, where the signature submitted to the untrusted mechanism was said first signature, whether the response from the untrusted mechanism is that said first signature is verified; and

instructions for causing one or more processors to determine, where the signature submitted to the untrusted mechanism was said second signature, whether the response from the untrusted mechanism is that said second signature is not verified.

Assignments (1)
MERGER AND CHANGE OF NAME Recorded Dec 16, 2015
From: ORACLE USA, INC.; SUN MICROSYSTEMS, INC.; ORACLE AMERICA, INC.
To: ORACLE AMERICA, INC.
Reel/Frame 037302/0616 →