IP Library Granted Patent US 9,143,329
Granted Patent B2
US 9,143,329 · App. 12/022,770 · Granted Sep 22, 2015

Content integrity and incremental security

Inventors: Kenneth Edward Feuerman (Fremont, CA); James Lewis Lester (Dublin, CA)
Assignee: Adobe Systems Incorporated
H04L9/3247H04L63/00H04L2209/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,143,329
App. No.
12/022,770
Granted
Sep 22, 2015
Kind
B2
Abstract

A media signer produces an array of hash values including a respective hash value for each of multiple different portions of content. The media signer applies a hash function and an encryption key to the array of hash values to create a digital signature associated with the content. Prior to playback of the content, a media verifier retrieves the array of hash values for the different portions of content. The media verifier produces a hash value result for the retrieved array. Based on the hash value result for the retrieved array and a hash value result of the array in the received digital signature, the media verifier verifies the integrity of the retrieved array. If the retrieved array of hash values is found to be trustworthy, the media verifier determines the integrity of a portion of the content by verifying the portion's corresponding hash value from the “trustworthy” array.

Claims (75)

1. A method comprising:

receiving, by a computing device, an array of hash values for respective portions of content, each of the portions being individual pages of a document or individual segments of audio or visual data;

applying, by the computing device, a hash function to the array of hash values to produce a hash value result for the array;

verifying, by the computing device, an integrity of the received array of hash values based on the hash value result produced for the received array of hash values; and

based on verifying the integrity of the received array of hash values:

retrieving a first portion of the content and a second portion of the content;

displaying the first portion of the content based on determining that a first hash value result generated by applying a hash function to the first portion of the content is equal to a first hash value from the array that corresponds to the first portion of the content; and

preventing display of the second portion of the content based on determining that a second hash value result generated by applying a hash function to the second portion of the content is different from a second hash value from the array that corresponds to the second portion of the content.

2. The method as in claim 1 , wherein verifying the integrity of the received array of hash values includes:

receiving an encrypted hash value result;

decrypting the encrypted hash value result to produce a decrypted hash value result; and

comparing the produced hash value result with the decrypted hash value result to determine an integrity of the received array of hash values.

3. The method as in claim 2 , wherein comparing the produced hash value result with the decrypted hash value result to determine the integrity of the array includes:

upon determining that the produced hash value result and the decrypted hash value result are equal, providing an indication that the array of hash values are valid for use in determining an integrity of the portions of content.

4. The method as in claim 3 , wherein determining an integrity of the portions of content includes:

receiving a portion of content;

applying a hash function to the portion of content to produce a hash value result for the portion of content;

extracting a hash value from the array that corresponds with the portion of content; and

comparing the produced hash value result for the portion of content with the hash value extracted from the array to determine an integrity of the received portion of content.

5. The method as in claim 1 , wherein receiving the array of hash values includes:

receiving the array of hash values in a set of preamble data associated with the content, the set of preamble data including a unique identifier for use in retrieval of advertising information associated with the content.

6. The method of claim 5 further comprising:

in response to detecting that a retrieved portion of the content has not been modified by an unauthorized source via use of a corresponding one of the array of hash values:

displaying the retrieved portion of the content;

extracting the unique identifier from the set of preamble data;

transmitting the unique identifier to a server, the server

storing at least one advertisement associated with the unique identifier;

receiving an advertisement from the server based on the unique identifier; and

displaying the advertisement with the retrieved portion of the content.

7. The method as in claim 1 , wherein

the first hash value is generated based on applying a hash function to the first portion of the content and

the second hash value is generated based on applying a hash function to the second portion of the content.

8. A non-transitory computer readable medium comprising executable instructions encoded thereon operable on a computerized device to perform processing comprising:

instructions for receiving an array of hash values respective portions of content comprising non-executable data that is displayable by a computing device;

instructions for applying a hash function to the array of hash values to produce a hash value result for the array;

instructions for verifying an integrity of the received array of hash values based on the hash value result produced for the received array of hash values; and

instructions for performing, based on verifying the integrity of the received array of hash values, operations comprising:

retrieving a first portion of the content and a second portion of the content;

displaying the first portion of the content based on determining that a first hash value result generated by applying a hash function to the first portion of the content is equal to a first hash value from the array that corresponds to the first portion of the content; and

preventing display of the second portion of the content based on determining that a second hash value result generated by applying a hash function to the second portion of the content is different from a second hash value from the array that corresponds to the second portion of the content.

9. The computer readable medium as in claim 8 , wherein the instructions for verifying the integrity of the received array of hash values include:

instructions for receiving an encrypted hash value result;

instructions for decrypting the encrypted hash value result to produce a decrypted hash value result; and

instructions for comparing the produced hash value result with the decrypted hash value result to determine an integrity of the received array of hash values.

10. The computer readable medium as in claim 9 , wherein the instructions for comparing the produced hash value result with the decrypted hash value result to determine the integrity of the array of hash values include:

instructions for, upon determining that the produced hash value result for the array and the decrypted hash value result are not equal, providing an indication that the array is untrustworthy to prevent access to the portions of content.

11. The computer readable medium as in claim 9 , wherein the instructions for comparing the produced hash value result with the decrypted hash value result to determine the integrity of the array include:

instructions for, upon determining that the produced hash value result and the decrypted hash value result are equal, providing an indication that the array of hash values are valid for use in determining an integrity of the portions of content.

12. The computer readable medium as in claim 11 , wherein the instructions for determining an integrity of the portions of content include:

instructions for receiving a portion of content; instructions for applying a hash function to the portion of content to produce a hash value result for the portion of content;

instructions for extracting a hash value from the array that corresponds with the portion of content; and

instructions for comparing the produced hash value result for the portion of content with the hash value extracted from the array to determine an integrity of the received portion of content.

13. The computer readable medium as in claim 8 , wherein the instructions for receiving the array of hash values include:

instructions for receiving the array of hash values in a set of preamble data associated with the content, the set of preamble data including a unique identifier for use in retrieval of advertising information associated with the content.

14. The computer readable medium of claim 13 further comprising;

instructions for, in response to detecting that a retrieved portion of the content has not been modified by an unauthorized source via use of a corresponding one of the array of hash values;

displaying the retrieved portion of the content;

extracting the unique identifier from the set of preamble data;

transmitting the unique identifier to a server, the server storing at least one advertisement associated with the unique identifier;

receiving an advertisement from the server based on the unique identifier; and

displaying the advertisement with the retrieved portion of the content.

15. The computer readable medium as in claim 8 , wherein

the first hash value is generated based on applying a hash function to the first portion of the content and

the second hash value is generated based on applying a hash function to the second portion of the content.

16. A computer system comprising:

a processor;

a memory unit that stores instructions associated with an application executed by the processor; and

an interconnect coupling the processor and the memory unit and enabling the computer system to execute the application and perform operations of:

obtaining an array of hash values for respective portions of content, each of the portions being individual pages of a document or individual segments of audio or visual data;

applying a hash function to the array of hash values to produce a hash value result;

verifying an integrity of the received array of hash values based on the hash value result produced for the received array of hash values; and

based on verifying the integrity of the received array of hash values:

retrieving a first portion of the content and a second portion of the content;

displaying the first portion of the content based on determining that a first hash value result generated by applying a hash function to the first portion of the content is equal to a first hash value from the array that corresponds to the first portion of the content; and

preventing display of the second portion of the content based on determining that a second hash value result generated by applying a hash function to the second portion of the content is different from a second hash value from the array that corresponds to the second portion of the content.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2008
From: FEUERMAN, KENNETH EDWARD; LESTER, JAMES LEWIS
To: ADOBE SYSTEMS INCORPORATED
Reel/Frame 020439/0584 →
Continuity (1)
Related Publication 20140304515A1 · Oct 9, 2014