IP Library Patent Application 12052032
Patent Application
App. No. 12/052,032

METHOD AND SYSTEM TO PROVIDE FINE GRANULAR INTEGRITY TO DIGITAL DATA

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/052,032
Abstract

A method and system to generate fine granular integrity to huge volumes of data in real time at a very low computational cost. The invention proposes a scalable system that can receive different digital data from multiple sources and generates integrity streams associated to the original data. This invention provides full guarantees for data integrity; the order of data logged cannot be altered and content cannot be modified added or deleted without detection.

Claims (32)

1 . A method to generate fine granular integrity to huge volumes of data in real time at a very low computational cost for use with a computer the method comprising:

receiving original data from multiple sources ( 310 , 600 ), over a communication way or network using predetermined protocols;

processing the original data by cryptographic means ( 510 , 610 ) for generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and

communicating ( 515 , 620 ) said digital chains to a receiver, said receiver being one of: the same as the sender of the original data ( 312 ), a different receiver ( 311 ) or a storage media ( 320 , 640 ),

wherein the generating the immutable digital chains comprises:

a) establishing at least one symmetric session key K;

b) securely destroying an old previous session key, if any;

c) encrypting said at least one symmetric session key K using an asymmetric public key of an authorized receiver P Aud , thus obtaining K′=P Aud (K) and also digitally sign it obtaining K″=DSs(K′);

d) creating at least one of the digital chains with said K′ and K″ values with a timestamp and a digital signature of previous values all together; or add to at least one of the digital chains said K′ and K″ values with a timestamp and a digital signature of previous values all together, and

e) every time a new unit m i of original data is received, a new link entry i is created to at least one of the digital chains according the formula entry i =(timestamp, MAC K (m i ,timestamp,MAC i-1 )), where MAC relates to Message Authentication Codes.

2 . The method according to claim 1 wherein metronome entries are added to at least one digital chain at predefined regular intervals, even if no new units of original data are received.

3 . The method according to claim 1 further comprising adding a last link to digital chains to securely close them when a shutdown of the system occurs.

4 . The method according to claim 1 wherein the new link entry generated every time a new unit m i of original data is received also contains the content of the new unit m i of original data, according the formula entry i =(m i , timestamp, MAC K (m i ,timestamp,MAC i-1 ))

5 . The method according claim 4 wherein the content of the new unit m i of original data including at the new link entry generated is symmetrically encrypted, according the formula entry=(E(m i ), timestamp, MAC K (E(m i ), timestamp,MAC i-1 )) using the same symmetrical session key K.

6 . The method according claim 5 wherein the session key used for encryption is different than the session key used for message authentication codes.

7 . The method according to claim 1 wherein an industry standard Hardware Security Module (HSM) or a smart card or a USB crypto-token is used to generate at least one private key, keep it always secret, and use it to carry out the asymmetric encryption and digital signatures related at least to one of said one or more immutable digital chains.

8 . The method according to claim 7 wherein the Hardware Security Module (HSM) or smart card or USB crypto-token ( 650 ) is also used to execute the method to generate said one or more immutable digital chains.

9 . A system to generate fine granular integrity to huge volumes of data in real time at a very low computational cost comprising at least one independent server hosting a software program, platform independent implementation that can run on standard hardware, comprising:

multiple sources ( 310 , 600 ) for receiving original data over a communication way or network ( 405 ) using predetermined protocols;

cryptographic means ( 510 , 610 ) processing the original data and generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and

a receiver to which said digital chains are communicated, said receiver being one of the same as the sender of the original data ( 312 ), a different receiver or a storage media ( 320 , 640 ).

10 . The system according to claim 9 , wherein a device selected among an industry standard Hardware Security Module (HSM), a smart card or a USB crypto-token ( 650 ) is used to generate at least one private key, keep it always secret, and use it to carry out cryptographic operations.

11 . A computer readable medium adapted to instruct a general purpose computer to generate fine granular integrity to huge volumes of data in real time at a very low computational cost, the method comprising:

receiving original data from multiple sources ( 310 , 600 ), over a communication way or network ( 405 ) using predetermined protocols;

processing the original data by cryptographic means ( 510 , 610 ) for generating one or more immutable digital chains that contain at least integrity information related to the original data including timestamps; and

communicating ( 515 , 620 ) said digital chains to a receiver, said receiver being one of: the same as the sender of the original data ( 312 ), a different receiver ( 311 ) or a storage media ( 320 , 640 ),

wherein generating the immutable digital chains comprises:

a) generating at least one symmetric session key K;

b) securely destroying an old previous session key, if any;

c) encrypting said at least one symmetric session key K using an asymmetric public key of an authorized receiver P Aud , thus obtaining K′=P Aud (K) and also digitally sign it obtaining K″=DSs(K′);

d) creating at least one of the digital chains with said K′ and K″ values with a timestamp and a digital signature of previous values all together; or add to at least one of the digital chains said K′ and K″ values with a timestamp and a digital signature of previous values all together; and

e) every time a net unit m i of original data is received, a new link entry i is created to at least one of the digital chains according the formula entry i =(timestamp, MAC K (m i , timestamp, MAC i-1 )), where MAC relates to Message Authentication Codes.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2015
From: VENTURE LENDING & LEASING VI, INC.
To: SCYTL SECURE ELECTRONIC VOTING S.A.
Reel/Frame 036378/0561 →
TRANSFER STATEMENT Recorded Feb 10, 2015
From: KINAMIK DATA INTEGRITY, INC.
To: VENTURE LENDING & LEASING VI, INC.; VENTURE LENDING & LEASING VI, INC.
Reel/Frame 034928/0136 →
SECURITY AGREEMENT Recorded Jan 9, 2012
From: KINAMIK DATA INTEGRITY, INC.
To: VENTURE LENDING & LEASING VI, INC.
Reel/Frame 027500/0946 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2008
From: BARDERA BOSCH, JOAN MIQUEL; DEMIRKIRAN, CEVAHIR; PRIMAULT, CHRISTOPHE
To: KINAMIK DATA INTEGRITY, S.L.
Reel/Frame 020977/0254 →