IP Library Granted Patent US 8,719,576
Granted Patent B2
US 8,719,576 · App. 13/625,551 · Granted May 6, 2014

Document verification with distributed calendar infrastructure

Inventors: Ahto Buldas (Tallinn, EE); Märt Saarepera (Tallinn, EE)
Assignee: Guardtime IP Holdings, Ltd
G06F21/64H04L9/3265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,719,576
App. No.
13/625,551
Granted
May 6, 2014
Kind
B2
Abstract

Transformations of digital records are used as lowest level inputs to a tree data structure having a root in a core system and having nodes computed as digital combinations of child node values. A combination of root values is published in a permanent medium. Signature vectors are associated with the digital records and have parameters that enable recomputation upward through the tree data structure to either a current root value or to the published value. Recomputation yields the same value only if a candidate digital record is an exact version of the original digital record included in the original computation of the value.

Claims (26)

1. A method for enabling authentication of digital records, comprising:

receiving, at a core system on a core processing level, from each of at least one highest non-core processing system at a respective highest non-core processing level, a current highest-level combined output value that is formed as digital combinations of successively lower-level combined output values computed in lower non-core processing levels as node values of a tree data structure having lowest level inputs formed as digital transformations, computed in user-level systems, of digital input records;

computing a current calendar value as a digital combination of the current highest-level combined output values;

returning to at least the highest non-core processing level from the core system the current calendar value, whereupon recomputation parameters are distributed downward to the user-level systems for association with respective ones of the digital input records such that an arbitrary subsequent test digital record is considered authenticated relative to the corresponding digital input record if, applying the corresponding digital transformation to the test digital record and, using the recomputation parameters to recomputed the node values upward through the tree data structure and core, the same current calendar value is attained as when it was originally computed with the corresponding digital input record forming the lowest level input;

periodically computing and causing to be published in a substantially permanent form a composite calendar value computed as a function of at least the current calendar value; and

distributing downward to at least one non-core processing level recomputation parameters of the composite calendar value in addition to the recomputation parameters of the current calendar value, whereupon the arbitrary subsequent test digital record is considered trust-independently authenticated relative to the corresponding digital input record if, applying the corresponding digital transformation to the test digital record and, using the recomputation parameters of the current calendar value and the composite calendar value to recomputed the node values upward through the tree data structure and core, the same composite calendar value is attained as when it was originally computed.

2. A method as in claim 1 , further comprising computing the composite calendar value as a function of a plurality of current calendar values that have been computed over a publication period, including not only the current calendar value but also of at least one previous current calendar value.

3. A method as in claim 2 , further comprising computing the composite calendar value as the root value of a non-linking, non-chaining, Merkle tree structure having the current calendar values over the publication period as leaf nodes.

4. A method as in claim 1 , in which the digital combinations are cryptographic hashes.

5. A method as in claim 1 , in which the tree data structure is a hash tree data structure.

6. A method as in claim 1 , in which the digital combinations are of two input values such that the hash tree structure is binary.

7. A method as in claim 1 , in which the recomputation parameters include, for each digital input record, the sibling node values in a directed path in the tree data structure from the digital transformations of the digital input record up to the current calendar value.

8. A method as in claim 1 , in which the recomputation parameters include, for each digital input record, the sibling node values in a directed path in the tree data structure from the digital transformations of the digital input record up to the composite calendar value.

9. A method as in claim 8 , in which the recomputation parameters are keyless, such that, at latest upon publication of the composite calendar value, the recomputation parameters are independent of any trust authority parameters such as digital certificates or cryptographic keys.

10. A method as in claim 1 , further comprising publishing the composite calendar value in a publicly accessible medium.

11. A method for enabling authentication of digital records, comprising:

receiving, at a core system on a core processing level, from each of at least one highest non-core processing system at a respective highest non-core processing level, a current highest-level combined output value that is formed as digital combinations of successively lower-level combined output values computed in lower non-core processing levels as node values of a tree data structure having lowest level inputs formed as digital transformations, computed in user-level systems, of at least one digital input record;

computing within the core system a current root calendar value as a digital combination of the current highest-level combined output values and a function of at least one previous root value;

periodically computing and causing to be published in a substantially permanent form a composite calendar value computed as a function of at least the current calendar value;

distributing downward to at least one non-core processing level recomputation parameters of the composite calendar value in addition to recomputation parameters of the current calendar value, whereupon an arbitrary subsequent test digital record is considered permanently authenticated relative to the corresponding digital input record if, applying the corresponding digital transformation to the test digital record and, using the recomputation parameters of the current calendar value and the composite calendar value to recomputed the node values upward through the tree data structure and core, the same composite calendar value is attained as when it was originally computed;

computing the composite calendar value as a function of a plurality of current calendar values that have been computed over a publication period, including not only the current calendar value but also of at least one previous current calendar value;

in which:

the digital combinations are cryptographic hashes;

the tree data structure is a hash tree data structure;

the recomputation parameters include, for each digital input record, the sibling node values in a directed path in the tree data structure from the digital transformations of the digital input record up to the composite calendar value; and

the recomputation parameters are keyless, such that, at latest upon publication of the composite calendar value, the recomputation parameters are independent of any trust authority parameters such as digital certificates or cryptographic keys.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2019
From: GUARDTIME IP HOLDINGS LIMITED
To: GUARDTIME SA
Reel/Frame 049073/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2014
From: BULDAS, AHTO
To: GUARDTIME IP HOLDINGS LIMITED
Reel/Frame 032013/0248 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2014
From: SAAREPERA, MÄRT
To: GUARDTIME IP HOLDINGS LIMITED
Reel/Frame 032013/0283 →
Continuity (7)
Continuation In Part 12696623 · Jan 29, 2010
Division 11005838 · Dec 7, 2004
Division 13625551
Continuation In Part 12696640 · Jan 29, 2010
Division 11005838 · Dec 7, 2004
Provisional Application 60531865 · Dec 22, 2003
Related Publication 20130276058A1 · Oct 17, 2013