IP Library Granted Patent US 8,621,223
Granted Patent B2
US 8,621,223 · App. 12/164,814 · Granted Dec 31, 2013

Data security method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,621,223
App. No.
12/164,814
Granted
Dec 31, 2013
Kind
B2
Abstract

A method of verifying integrity of a digital file includes receiving the digital file subsequent to exposure to a foreign environment and validating the digital file. The received digital file has an appended signature label that includes one or both of a first hash value and a digital signature. Validating the digital file includes hashing the digital file to obtain a second hash value, retrieving the first hash value from the signature label, and comparing the first hash value and second hash value.

Claims (75)

1. A method of verifying integrity of a digital file comprising:

labeling, in a first network, the digital file prior to exposure to a foreign environment, the first network having a first security classification level, wherein labeling comprises:

creating a header label comprising an identification of the first security classification level;

appending the header label to the digital file;

hashing the digital file, together with the appended header label, to obtain a first hash value;

signing the first hash value to create a digital signature;

creating a signature label comprising one or both of the first hash value and the digital signature; and

appending the signature label to the digital file; and

validating, in a second network, the digital file subsequent to exposure to the foreign environment, the second network having a second security classification level that is different from the first security classification level, wherein validating comprises:

hashing the digital file to obtain a second hash value;

retrieving the first hash value from the signature label;

comparing the first hash value and second hash value; and

removing the signature label from the digital file.

2. The method of verifying integrity of a digital file of claim 1 , the validating the digital file subsequent to exposure to the foreign environment further comprising removing the header label from the digital file.

3. The method of verifying integrity of a digital file of claim 1 , further comprising:

performing a second labeling, in the first network, on the digital file prior to exposure to the foreign environment, wherein labeling comprises:

creating a second header label comprising an identification of a third security classification level;

appending the second header label to the digital file;

hashing the digital file, together with the second header label, to obtain a third hash value;

signing the third hash value to create a second digital signature;

creating a second signature label comprising one or both of the third hash value and the second digital signature; and

appending the second signature label to the digital file.

4. The method of verifying integrity of a digital file of claim 1 , further comprising:

verifying, before release to the foreign environment, that the digital file has been authorized for release to the foreign environment.

5. The method of verifying integrity of a digital file of claim 4 , wherein verifying comprises:

hashing the digital file to obtain a third hash value;

retrieving the first hash value from the signature label; and

comparing the first hash value and third hash value.

6. A method of verifying integrity of a digital file comprising:

labeling the digital file prior to exposure to a foreign environment, wherein labeling comprises:

creating a header label comprising an identification of a security classification level of a network;

appending the header label to the digital file;

hashing the digital file, together with the appended header label, to obtain a first hash value;

signing the first hash value to create a digital signature;

creating a signature label comprising one or both of the first hash value and the digital signature; and

appending the signature label to the digital file.

7. The method of verifying integrity of a digital file of claim 6 , further comprising:

validating the digital file subsequent to exposure to the foreign environment, wherein validating comprises:

hashing the digital file, together with the appended header label, to obtain a second hash value;

retrieving the first hash value from the signature label; and

comparing the first hash value and second hash value.

8. The method of verifying integrity of a digital file of claim 7 , further comprising removing the signature label from the digital file after validating the digital file.

9. The method of verifying integrity of a digital file of claim 7 , wherein validating the digital file subsequent to exposure to the foreign environment further comprises removing the header label from the digital file.

10. The method of verifying integrity of a digital file of claim 6 , wherein appending the signature label to the digital file renders the digital file unreadable until the signature label is removed from the digital file.

11. A method of verifying integrity of a digital file comprising:

receiving, in a first network, the digital file subsequent to exposure to a foreign environment, the first network having a first security classification level, the digital file comprising:

an appended header label comprising an identification of a second security classification level of a second network, the second security classification level being different from the first security classification level; and

an appended signature label comprising one or both of a first hash value and a digital signature; and

validating the digital file, wherein validating comprises:

hashing the digital file, together with the appended header label, to obtain a second hash value;

retrieving the first hash value from the signature label; and

comparing the first hash value and second hash value.

12. The method of verifying integrity of a digital file of claim 11 , further comprising:

labeling the digital file prior to exposure to the foreign environment, wherein labeling comprises:

hashing the digital file, together with the appended header label, to obtain the first hash value;

signing the first hash value to create the digital signature;

creating the signature label comprising one or both of the first hash value and the digital signature; and

appending the signature label to the digital file.

13. The method of verifying integrity of a digital file of claim 11 , further comprising removing the signature label from the digital file after validating the digital file.

14. The method of verifying integrity of a digital file of claim 13 , wherein appending the signature label to the digital file renders the digital file unreadable until the signature label is removed from the digital file.

15. Logic encoded in non-transitory computer-readable media operable, when executed on a processor, to:

label, in a first network, a digital file prior to exposure to a foreign environment, the first network having a first security classification level, wherein label comprises:

creating a header label comprising an identification of the first security classification level;

appending the header label to the digital file;

hashing the digital file, together with the appended header label, to obtain a first hash value;

signing the first hash value to create a digital signature;

creating a signature label comprising one or both of the first hash value and the digital signature; and

appending the signature label to the digital file; and

validate, in a second network, the digital file subsequent to exposure to the foreign environment, the second network having a second security classification level that is different from the first security classification level, wherein validate comprises:

hashing the digital file, together with the appended header label, to obtain a second hash value;

retrieving the first hash value from the signature label; and

comparing the first hash value and second hash value.

16. The logic encoded in computer-readable media of claim 15 , further operable, when executed on a processor, to remove the signature label from the digital file after validating the digital file.

17. The logic encoded in computer-readable media of claim 15 , wherein appending the signature label to the digital file renders the digital file unreadable until the signature label is removed from the digital file.

18. The logic encoded in computer-readable media of claim 15 , wherein validating the digital file subsequent to exposure to the foreign environment further comprises removing the header label from the digital file.

Assignments (12)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2008
From: MCDOUGAL, MONTY D.; OSTERMANN, JASON E.; SMITH, BRIAN N.
To: RAYTHEON COMPANY
Reel/Frame 021173/0181 →