IP Library Patent Application 11129231
Patent Application
App. No. 11/129,231

Tamper-proof electronic messaging

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/129,231
Abstract

A messaging system treats a set of related messages, such as an email string between two or more people, as a message container ( 200 ) having relational references to one or more submessages ( 210, 212, 214 ). A messaging server ( 112 ) stores the messages and submessages as discrete message components within a message database ( 416 ). The messaging server ( 112 ) generates ( 714 ) tamper-detection data, such as hashes, for the message components and stores the data in an audit information database ( 418 ). The messaging server ( 112 ) authenticates ( 627 ) a message component by generating new tamper-detection data for the component, and comparing the new data with the stored data. In addition, the messaging server ( 112 ) can distribute the tamper-detection information to other entities, such as messaging clients ( 116 ), by signing the data using a digital signature. The messaging system thus allows distributed entities to verify the authenticity of messages and components sent via the system.

Claims (43)

1 . A computerized messaging server in an electronic messaging system, comprising:

a messaging module adapted to control a message database storing messages exchanged in the messaging system, each message comprising one or more message components;

an interface module adapted to receive a message component from a messaging client; and

an audit module adapted to interact with an audit information database storing audit information describing usage of the messaging system, and further adapted to generate tamper-detection data for the message component received from the messaging client and store the generated tamper-detection data in the audit information database.

2 . The messaging server of claim 1 , wherein the tamper-detection data comprises a hash computed responsive to one or more items of data selected from the group consisting of: a date that the message component was created; an author of the message component; a set of recipients of the message component; and content of the message component.

3 . The messaging server of claim 1 , wherein the interface module is further adapted receive a request from the messaging client for the message component in the message database and wherein the audit module is further adapted to utilize the tamper-detection data to authenticate the message component responsive to receiving the request for the message component from the messaging client.

4 . The messaging server of claim 3 , wherein the audit module is adapted to authenticate the message component by generating new tamper-detection data for the message component and comparing the new tamper-detection data with previously-generated tamper-detection data.

5 . The messaging server of claim 3 , wherein the interface module is further adapted to provide the tamper-detection data to the messaging client, and wherein the messaging client is adapted to utilize the tamper-detection data to authenticate the message component.

6 . The messaging server of claim 5 , wherein the tamper-detection data provided to the messaging client are signed with a digital signature and wherein the messaging client is adapted to utilize the digital signature to authenticate the tamper-detection data.

7 . The messaging server of claim 1 , wherein a message in the message database comprises:

a message container containing relational references to one or more message components.

8 . The messaging server of claim 1 , wherein a message in the message database comprises:

a current submessage specifying a most recent submessage in the message; and

a history submessage specifying a previous current submessage.

9 . A computer program product having a computer-readable medium having embodied thereon program code for use in an electronic messaging system, the program code comprising:

a messaging module adapted to control a message database storing messages exchanged in the messaging system, each message comprising one or more message components;

an interface module adapted to receive a message component from a messaging client; and

an audit module adapted to interact with an audit information database storing audit information describing usage of the messaging system, and further adapted to generate tamper-detection data for the message component received from the messaging client and store the generated tamper-detection data in the audit information database.

10 . The computer program product of claim 9 , wherein the tamper-detection data comprises a hash computed responsive to one or more items of data selected from the group consisting of: a date that the message component was created; an author of the message component; a set of recipients of the message component; and content of the message component.

11 . The computer program product of claim 9 , wherein the interface module is further adapted receive a request from the messaging client for the message component in the message database and wherein the audit module is further adapted to utilize the tamper-detection data to authenticate the message component responsive to receiving the request for the message component from the messaging client.

12 . The computer program product of claim 11 , wherein the audit module is adapted to authenticate the message component by generating new tamper-detection data for the message component and comparing the new tamper-detection data with previously-generated tamper-detection data.

13 . The computer program product of claim 11 , wherein the interface module is further adapted to provide the tamper-detection data to the messaging client, and wherein the messaging client is adapted to utilize the tamper-detection data to authenticate the message component.

14 . The computer program product of claim 13 , wherein the tamper-detection data provided to the messaging client are signed with a digital signature and wherein the messaging client is adapted to utilize the digital signature to authenticate the tamper-detection data.

15 . The computer program product of claim 9 , wherein a message in the message database comprises:

a message container containing relational references to one or more message components.

16 . The computer program product of claim 9 , wherein a message in the message database comprises:

a current submessage specifying a most recent submessage in the message; and

a history submessage specifying a previous current submessage.

17 . A computer-implemented method of authenticating messages in an electronic messaging system, comprising:

receiving a message component identified as a relational reference in a message container;

receiving tamper-detection data for the message component; and

authenticating the message component using the tamper-detection data.

18 . The method of claim 17 , wherein authenticating the message component comprises:

generating new tamper-detection data for authenticating the message component;

comparing the new tamper-detection data with the received tamper-detection data; and

determining whether the message component is authentic responsive to the comparison.

19 . The method of claim 17 , further comprising:

generating new tamper-detection data by computing a hash responsive to one or more items of data selected from the group consisting of: a date that the message component was created; an author of the message component; a set of recipients of the message component; and content of the message component.

20 . The method of claim 17 , wherein the message container identifies a plurality of message components, and further comprising:

obtaining the plurality of message components through interactions with a plurality of messaging servers, wherein each of the plurality of messaging servers provides at least one message component.

21 . The method of claim 17 , further comprising:

providing the message component to an audit server;

wherein the tamper-detection data is received from the audit server in response to the provided message component.

Assignments (3)
SECURITY AGREEMENT Recorded Sep 16, 2008
From: BLUESPACE SOFTWARE CORP.
To: SILICON VALLEY BANK
Reel/Frame 021538/0090 →
CERTIFICATE OF DOMESTICATION Recorded Jul 20, 2006
From: BLUESPACE GROUP LTD.
To: BLUESPACE SOFTWARE CORP.
Reel/Frame 017966/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2005
From: MARSTON, JUSTIN; HATCH, ANDREW S.
To: BLUESPACE GROUP LTD.
Reel/Frame 016759/0993 →