IP Library Granted Patent US 8,578,174
Granted Patent B2
US 8,578,174 · App. 12/818,163 · Granted Nov 5, 2013

Event log authentication using secure components

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,578,174
App. No.
12/818,163
Granted
Nov 5, 2013
Kind
B2
Abstract

Some embodiments provide a system that facilitates use of a computing device. During operation, the system obtains an event description of an event on the computing device. Next, the system computes a message authentication code (MAC) for the event description using a secure component associated with the computing device. Finally, the system uses the MAC to maintain the integrity of an event log containing the event description.

Claims (65)

1. A method for facilitating use of a computing device, comprising:

obtaining, by the computing device, an event description for an event that has occurred on the computing device, wherein the event description includes a description for one or more of: an application event; a system event; a network event; or a security event;

responsive to obtaining the event description, computing a message authentication code (MAC) for the event description using a secure component associated with the computing device, wherein the secure component includes a secure key that is inaccessible to the computing device at which the event description and MAC are stored, and wherein the MAC facilitates authenticating the event description using the secure key;

storing the MAC, in a log entry of an event log, in association with the event description; and

maintaining the integrity of the event log, which contains one or more event descriptions, based on the associated MACs.

2. The method of claim 1 , further comprising:

incrementing a counter associated with the event log upon obtaining the event description; and

storing the counter in the log entry.

3. The method of claim 1 , wherein the event log is stored on the computing device or on an external storage device.

4. The method of claim 1 , wherein computing the MAC for the event description using the secure component involves:

providing the event description to the secure component;

computing the MAC using a key from the secure component, wherein the key is inaccessible to the computing device; and

obtaining the MAC from the secure component.

5. The method of claim 4 , wherein using the MAC to maintain the integrity of the event log involves:

sending the event log to an auditing apparatus with access to the key; and

authenticating the event log using the auditing apparatus.

6. The method of claim 5 , wherein the auditing apparatus authenticates the event log to detect corruption of the event log.

7. The method of claim 1 , wherein the secure component is at least one of a smart card, an external computing device, and a secure software component.

8. A method for processing an event log for a computing device, comprising:

receiving a log entry, from the event log, for an event that has occurred on the computing device, wherein the log entry indicates an event description for the event, and indicates a message authentication code (MAC) associated with the event description;

responsive to receiving the log entry:

obtaining a key for the log entry, wherein the key is stored on a secure component associated with the computing device, wherein the secure component includes a secure key that is inaccessible to the computing device at which the event description and the associated MAC are stored; and

computing a MAC for the log entry using the key, wherein the MAC facilitates authenticating the event description using the secure key; and

using the computed MAC to authenticate the log entry.

9. The method of claim 8 , further comprising:

using a counter associated with the log entry to further authenticate the log entry.

10. The method of claim 8 , wherein using the computed MAC to authenticate the log entry involves:

comparing the computed MAC to a stored MAC for the log entry, wherein the stored MAC is computed by the secure component;

verifying an integrity of the log entry if the computed MAC is identical to the stored MAC; and

detecting corruption of the log entry if the computed MAC differs from the stored MAC.

11. The method of claim 8 , wherein the event log is stored on the computing device or on an external storage device.

12. A system for facilitating use of a computing device, comprising:

a secure component configured to:

obtain an event description of an event that has occurred on the computing device, wherein the event description includes a description for one or more of: an application event; a system event; a network event; or a security event; and

compute a message authentication code (MAC) for the event description in response to obtaining the event description of the event, wherein the secure component includes a secure key that is inaccessible to the computing device at which the event description and MAC are stored, and wherein the MAC facilitates authenticating the event description using the secure key;

a storage mechanism configured to store the MAC and the event description in a log entry of an event log for the computing device, wherein the MAC is stored in association with the event description; and

an auditing apparatus configured to maintain the integrity of the event log, which contains one or more event descriptions, based on the associated MACs.

13. The system of claim 12 ,

wherein the secure component is further configured to increment a counter associated with the event log upon obtaining the event description, and

wherein the storage mechanism is further configured to store the counter in the event log.

14. The system of claim 12 , wherein the secure component computes the MAC using a key that is inaccessible to the computing device.

15. The system of claim 14 ,

wherein the key is accessible to the auditing apparatus, and

wherein the auditing apparatus uses the MAC to maintain the integrity of the event log by:

obtaining a log entry containing the MAC and the event description from the event log; and

re-computing the MAC using the key and the event description.

16. The system of claim 12 , wherein the event log is stored on the computing device or on an external storage device.

17. The system of claim 12 , wherein the secure component is at least one of a smart card, an external computing device, and a secure software component.

18. A non-transitory computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for facilitating use of a computing device, the method comprising:

obtaining an event description for an event that has occurred on the computing device, wherein the event description includes a description for one or more of: an application event; a system event; a network event; or a security event;

responsive to obtaining the event description, computing a message authentication code (MAC) for the event description using a secure component associated with the computing device, wherein the secure component includes a secure key that is inaccessible to the computing device at which the event description and MAC are stored, and wherein the MAC facilitates authenticating the event description using the secure key;

storing the MAC, in a log entry of an event log, in association with the event description; and

maintaining the integrity of the event log, which contains one or more event descriptions, based on the associated MACs.

19. The computer-readable storage medium of claim 18 , the method further comprising:

incrementing a counter associated with the event log upon obtaining the event description; and

storing the counter in the log entry.

20. The computer-readable storage medium of claim 18 , wherein computing the MAC for the event description using the secure component involves:

providing the event description to the secure component;

computing the MAC using a key from the secure component, wherein the key is inaccessible to the computing device; and

obtaining the MAC from the secure component.

21. The computer-readable storage medium of claim 20 , wherein using the MAC to maintain the integrity of the event log involves:

sending the event log to an auditing apparatus with access to the key; and

authenticating the event log using the auditing apparatus.

22. The computer-readable storage medium of claim 21 , wherein the auditing apparatus authenticates the event log to detect corruption of the event log.

23. The computer-readable storage medium of claim 18 , wherein the secure component is at least one of a smart card, an external computing device, and a secure software component.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2025
From: XEROX CORPORATION
To: GENESEE VALLEY INNOVATIONS, LLC
Reel/Frame 073842/0479 →
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT RF 064760/0389 Recorded Feb 13, 2024
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: XEROX CORPORATION
Reel/Frame 068261/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF US PATENTS 9356603, 10026651, 10626048 AND INCLUSION OF US PATENT 7167871 PREVIOUSLY RECORDED ON REEL 064038 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 28, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064161/0001 →
SECURITY INTEREST Recorded Jun 22, 2023
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 064760/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064038/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2010
From: JAKOBSSON, BJORN MARKUS
To: PALO ALTO RESEARCH CENTER INCORPORATED
Reel/Frame 024655/0043 →