IP Library Patent Application 13931847
Patent Application
App. No. 13/931,847

Efficient Assurance of Database Server Integrity

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/931,847
Abstract

An apparatus, e.g. a database verifier, includes an instruction memory and a processor operatively coupled to the instruction memory. The processor is configured by instructions in the memory to verify that a record set is authorized to be transmitted by comparing a received first authenticator value to a calculated second authenticator value determined from the record set and a received verification key.

Claims (30)

1 . An apparatus, comprising:

an instruction memory; and

a processor operatively coupled to the instruction memory and configured thereby to verify that a record set is authorized to be transmitted by comparing a received first authenticator value to a calculated second authenticator value determined from the record set and a received verification key.

2 . The apparatus of claim 1 , wherein the second authenticator value is an aggregated message authentication code (MAC).

3 . The apparatus of claim 2 , wherein the aggregated MAC is a modulo sum of a plurality of MACs each determined for a single record of a database from which the record set is extracted.

4 . The apparatus of claim 1 , wherein if the record set is not determined to be authorized the processor blocks transmission of the record set.

5 . The apparatus of claim 1 , wherein the determination of the second authenticator value by the processor includes computing MAC tokens of each record in the record set, and determining the aggregated MAC from the recomputed MAC tokens.

6 . The apparatus of claim 1 , wherein the memory is not modifiable.

7 . The apparatus of claim 1 , wherein the processor is configured to receive the verification key via a network path different from the network path over which the database record set is received.

8 . A method, comprising:

receiving a database record set, a first authenticator value, and a verification key; and

computing a second authenticator value from the record set and the verification key; and

transmitting the record set only on the condition that the second authenticator value is equal to the first authenticator value.

9 . The method of claim 8 , wherein the second authenticator value is an aggregated message authentication code (MAC).

10 . The method of claim 9 , further comprising computing the aggregated MAC as a modulo sum of a plurality of MACs each determined for a single record of a database from which the record set is extracted.

11 . The method of claim 8 , wherein the determination of the second authenticator value includes computing MAC tokens of each record in the record set, and determining the aggregated MAC from the recomputed MAC tokens.

12 . The method of claim 8 , further comprising determining MAC tokens for each database record by indexing over a number of requestors authorized to receive that database record.

13 . The method of claim 8 , further comprising receiving the verification key via a network path different from the network path over which the database record set is received.

14 . A method, comprising:

placing memory in operable communication with a processor;

configuring the memory with instructions adapted to implement a method, the method comprising:

receiving a database record set, a first authenticator value, and a verification key;

computing a second authenticator value from the record set and the verification key; and

comparing the second authenticator value with the first authenticator value.

15 . The method of claim 14 , wherein the first and second authenticator values are each an aggregated message authentication code (MAC).

16 . The method of claim 15 , wherein the aggregated MAC is a modulo sum of a plurality of MACs each determined for a single record of a database from which the record set is extracted.

17 . The method of claim 14 , wherein the instructions are further adapted to configure the processor to transmit the record set only on the condition that the first and second authenticator values are equal.

18 . The method of claim 14 , wherein the determination of the second authenticator value by the processor includes computing MAC tokens of each record in the record set, and determining the aggregated MAC from the recomputed MAC tokens.

19 . The method of claim 14 , further comprising configuring the memory as an unmodifiable memory.

20 . The method of claim 14 , wherein the processor is configured to receive the verification key is received via a network path different from the network path over which the database record set is received.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Aug 28, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA
Reel/Frame 033647/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2014
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 033543/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2013
From: KOLESNIKOV, VLADIMIR; TENTES, ARISTEIDIS
To: ALCATEL-LUCENT USA INC.
Reel/Frame 031213/0001 →
SECURITY AGREEMENT Recorded Jul 22, 2013
From: ALCATEL LUCENT USA, INC.
To: CREDIT SUISSE AG
Reel/Frame 030851/0364 →