IP Library Granted Patent US 8,484,476
Granted Patent B2
US 8,484,476 · App. 12/696,725 · Granted Jul 9, 2013

Computer-implemented method and system for embedding and authenticating ancillary information in digitally signed content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,484,476
App. No.
12/696,725
Granted
Jul 9, 2013
Kind
B2
Abstract

A computer-implemented system and method for embedding and authenticating ancillary information in digitally signed content are disclosed. The method and system include loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and erasing any non-authenticated regions of the digital content by zeroing out or value-filling memory locations corresponding to the non-authenticated regions.

Claims (44)

1. A method comprising:

loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable;

identifying, by use of a processor, an existing digital signature block and an existing digital signature size block in a digitally signed file header of the executable;

obtaining a digital signature size value from the digital signature size block, the digital signature size value corresponding to the size of the digital signature block plus the length of an ancillary data block plus a pre-determined pad;

authenticating the integrity of the executable using the digital signature prior to execution of the executable;

virtualizing access to the digital content of the digitally signed executable; and

erasing, by use of the processor, the ancillary data block and the pre-determined pad by zeroing out or value-filling memory locations corresponding to the ancillary data block and the pre-determined pad, the erasing being performed without invalidating the digital signature.

2. The method as claimed in claim 1 wherein the ancillary data block and the pre-determined pad regions of the digital content include regions past the end of the last section of the digital content.

3. The method as claimed in claim 1 including verifying that as checksum field in a header of the digital content matches an image file checksum.

4. The method as claimed in claim 1 including verifying that the attribute certificate table contains one single entry and does not contain padding.

5. The method as claimed in claim 1 including verifying that the digital signature actually tills the whole space allocated to the digital signature in an attribute certificate table.

6. The method as claimed in claim 1 wherein the digital content is a file.

7. The method as claimed in claim 1 wherein the digital content is a digital transmission.

8. The method as claimed in claim 1 wherein the erasing is performed by a loader.

9. The method as claimed in claim 1 wherein the erasing is performed by the executable.

10. An article of manufacture embodied in a non-transitory machine storage medium including data that, when accessed by a machine, causes the machine to:

load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable;

identify an existing digital signature block and an existing digital signature size block in a digitally signed file header of the executable;

obtain a digital signature size value from the digital signature size block, the digital signature size value corresponding to the size of the digital signature block plus the length of an ancillary data block plus a pre-determined pad;

authenticate the integrity of the executable using the digital signature prior to execution of the executable;

virtualize access to the digital content of the digitally signed executable; and

erase the ancillary data block and the pre-determined pad by zeroing out or value-filling memory locations corresponding to the ancillary data block and the pre-determined pad, the erasing being performed without invalidating the digital signature.

11. The article of manufacture as claimed in claim 10 wherein the ancillary data block and the pre-determined pad regions of the digital content include regions past the end of the last section of the digital content.

12. The article of manufacture as claimed in claim 10 being further operable to verify that a checksum field in a header of the digital content matches an image file checksum.

13. The article of manufacture as claimed in claim 10 being further operable to verify that the attribute certificate table contains one single entry and does not contain padding.

14. The article of manufacture as claimed in claim 10 being further operable to verify that the digital signature actually fills the whole space allocated to the digital signature in an attribute certificate table.

15. The article of manufacture as claimed in claim 10 wherein the digital content is a file.

16. The article of manufacture as claimed in claim 10 wherein the digital content is a digital transmission.

17. The article of manufacture as claimed in claim 10 wherein the erasing is performed by a loader.

18. The article of manufacture as claimed in claim 10 wherein the erasing is performed by the executable.

19. A method comprising:

loading digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and

performing, by use of a processor, verification operations on the executable to verify integrity of the executable, the verification operations being performed on the executable prior to execution of the executable, the verification operations including identifying an existing digital signature block and an existing digital signature size block in a digitally signed file header of the executable, obtaining a digital signature size value from the digital signature size block, the digital signature size value coir to the size of the digital signature block plus the length of an ancillary data block plus a pre-determined pad, and authenticating the integrity of the executable using the digital signature prior to execution of the executable, the verification operations further including virtualizing access to the digital content of the digitally signed executable, the verification operations further including erasing the ancillary data block and the pre-determined pad by zeroing out or value-filling memory locations corresponding to the ancillary data block and the pre-determined pad, the erasing being performed without invalidating the digital signature.

20. The method as claimed in claim 19 wherein the verification operations include a checksum verification.

21. The method as claimed in claim 19 wherein the verification operations include verifying that there is no information past the end of the last section of the executable.

22. The method as claimed in claim 19 wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding with fixed data.

23. The method as claimed in claim 19 wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table.

24. An article of manufacture embodied in a non-transitory machine storage medium including data that, when accessed by a machine, causes the machine to:

load digital content containing a digitally signed executable into memory for execution, while checking for the integrity of a digital signature and the contents of the executable; and

perform verification operations on the executable to verify integrity of the executable, the verification operations being performed on the executable prior to execution of the executable, the verification operations including identifying an existing digital signature block and an existing digital signature size block in a digitally signed file header of the executable, obtaining a digital signature size value from the digital signature size block, the digital signature size value corresponding to the size of the digital signature block plus the length of an ancillary data block plus a pre-determined pad, and authenticating the integrity of the executable using the digital signature prior to execution of the executable, the verification operations further including virtualizing access to the digital content of the digitally signed executable, the verification operations further including erasing the ancillary data block and the pre-determined pad by zeroing out or value-filling memory locations corresponding to the ancillary data block and the pre-determined pad, the erasing being performed without invalidating the digital signature.

25. The article of manufacture as claimed in claim 24 wherein the verification operations include a checksum verification.

26. The article of manufacture as claimed in claim 24 wherein the verification operations include verifying that there is no information past the end of the last section of the executable.

27. The article of manufacture as claimed in claim 24 wherein the verification operations include verifying that an attribute certificate table contains one single entry and does not contain padding or padding, with fixed data.

28. The article of manufacture as claimed in claim 24 wherein the verification operations include verifying that a certificate actually fills the whole allocated space in an attribute certificate table.

Assignments (13)
CHANGE OF NAME Recorded Sep 25, 2024
From: ROVI SOLUTIONS CORPORATION
To: ROVI SOLUTIONS LLC
Reel/Frame 069047/0372 →
CHANGE OF NAME Recorded Sep 25, 2024
From: ROVI SOLUTIONS LLC
To: ADEIA SOLUTIONS LLC
Reel/Frame 069047/0464 →
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053481/0790 →
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: HPS INVESTMENT PARTNERS, LLC
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053458/0749 →
SECURITY INTEREST Recorded Jun 1, 2020
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS INC.; VEVEO, INC.; INVENSAS CORPORATION; INVENSAS BONDING TECHNOLOGIES, INC.; TESSERA, INC.; TESSERA ADVANCED TECHNOLOGIES, INC.; DTS, INC.; PHORUS, INC.; IBIQUITY DIGITAL CORPORATION
To: BANK OF AMERICA, N.A.
Reel/Frame 053468/0001 →
PATENT SECURITY AGREEMENT Recorded Nov 25, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 051110/0006 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 25, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: APTIV DIGITAL INC.; GEMSTAR DEVELOPMENT CORPORATION; INDEX SYSTEMS INC.; ROVI GUIDES, INC.; ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; SONIC SOLUTIONS LLC; STARSIGHT TELECAST, INC.; UNITED VIDEO PROPERTIES, INC.; VEVEO, INC.
Reel/Frame 051145/0090 →
SECURITY INTEREST Recorded Nov 22, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 051143/0468 →
PATENT RELEASE Recorded Jul 24, 2014
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ALL MEDIA GUIDE, LLC; APTIV DIGITAL, INC.; GEMSTAR DEVELOPMENT CORPORATION; INDEX SYSTEMS INC.; ROVI CORPORATION; ROVI GUIDES, INC.; ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; STARSIGHT TELECAST, INC.; TV GUIDE INTERNATIONAL, INC.; UNITED VIDEO PROPERTIES, INC.
Reel/Frame 033396/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 24, 2014
From: APTIV DIGITAL, INC.; GEMSTAR DEVELOPMENT CORPORATION; INDEX SYSTEMS INC.; ROVI GUIDES, INC.; ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; SONIC SOLUTIONS LLC; STARSIGHT TELECAST, INC.; UNITED VIDEO PROPERTIES, INC.; VEVEO, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 033407/0035 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2014
From: ROVI TECHNOLOGIES CORPORATION
To: ROVI SOLUTIONS CORPORATION
Reel/Frame 032968/0246 →
SECURITY INTEREST Recorded Sep 13, 2011
From: APTIV DIGITAL, INC., A DELAWARE CORPORATION; GEMSTAR DEVELOPMENT CORPORATION, A CALIFORNIA CORPORATION; INDEX SYSTEMS INC, A BRITISH VIRGIN ISLANDS COMPANY; ROVI CORPORATION, A DELAWARE CORPORATION; ROVI GUIDES, INC., A DELAWARE CORPORATION; ROVI SOLUTIONS CORPORATION, A DELAWARE CORPORATION; ROVI TECHNOLOGIES CORPORATION, A DELAWARE CORPORATION; STARSIGHT TELECAST, INC., A CALIFORNIA CORPORATION; UNITED VIDEO PROPERTIES, INC., A DELAWARE CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 027039/0168 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2010
From: TORRUBIA, ANDRES M.; SALVAT, JORDI
To: ROVI TECHNOLOGIES CORPORATION
Reel/Frame 023879/0866 →