IP Library Granted Patent US 9,246,926
Granted Patent B2
US 9,246,926 · App. 13/953,339 · Granted Jan 26, 2016

Packet validation using watermarks

Inventors: Ulfar Erlingsson (San Francisco, CA); Xavier Boyen (Palo Alto, CA); Darrell Anderson (Durham, NC); Wayne Gray (Sunnyvale, CA)
Assignee: Google Inc.
H04L63/12G06Q20/401H04L63/123H04N1/32144G06F21/10G06F21/60H04L63/08H04L63/20H04L2209/608H04N21/8358
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,246,926
App. No.
13/953,339
Granted
Jan 26, 2016
Kind
B2
Abstract

Methods and systems are disclosed for providing secure transmissions across a network comprising a transmitting device and a receiving device. At the transmitting device, a stream of watermark bits is generated. Next, a plurality of watermarks is generated, each of the plurality of watermarks comprising an index number and a portion of the stream of watermark bits. The watermarks are inserted, into each header of a plurality of outgoing packets. At the receiving device, the plurality of outgoing packets are received and it is determined if a received packet is valid based on the watermark in the header of the received packet. The stream of watermark bits may be generated using a stream cipher such as RC4, a block cipher such as 3DES in CBC mode, or other equivalent pseudo-random stream generating techniques.

Claims (36)

1. A method for secure transmissions between a client device and a server, comprising:

receiving, at the server, a packet from the client device, wherein the packet includes a watermark comprising a portion of a stream of watermark bits and an index number associated with the portion of the stream of watermark bits, and the stream of watermark bits generated from an authorization and synchronization packet previously exchanged between the client and the server; and

determining whether the received packet is valid based on the watermark of the received packet, wherein said determining comprises comparing the watermark to a set of expected watermarks in a first window and a set of expected watermarks in a second window, the set of expected watermarks in the first window generated from the stream of watermark bits based on index numbers preceding a pivotal index number, and the set of expected watermarks in the second window generated from the stream of watermark bits based on index numbers succeeding the pivotal index number.

2. The method of claim 1 , further comprising:

determining the received packet as valid when the watermark matches one of the expected watermarks in the first or second window.

3. The method of claim 1 , further comprising:

discarding the packet when the watermark does not match any of the expected watermarks in the first or second window.

4. The method of claim 1 , further comprising:

exchanging the authorization and synchronization packet with the client device to activate a session with the client device.

5. The method of claim 1 , wherein comparing the watermark comprises:

maintaining at the server a record of the pivotal index number, wherein the pivotal index number represents a index number of a highest-numbered valid watermark received from the client device.

6. The method of claim 5 , further comprising:

when the watermark matches one of the expected watermarks in the second window, increasing the pivotal index number and deleting the matching expected watermark from the second window.

7. A server for secure transmissions with a client device, comprising:

a memory; and

at least one processor device coupled to the memory and configured to:

receive a packet from the client device, wherein the packet includes a watermark comprising a portion of a stream of watermark bits and an index number associated with the portion of the stream of watermark bits, and the stream of watermark bits generated from an authorization and synchronization packet previously exchanged between the client and the server; and

determine whether the received packet is valid based on the watermark of the received packet, wherein the determining comprises comparing the watermark of the received packet to a set of expected watermarks in a first window and a set of expected watermarks in a second window, the set of expected watermarks in the first window generated from the stream of watermark bits based on index numbers preceding a pivotal index number, and the set of expected watermarks in the second window generated from the stream of watermark bits based on index numbers succeeding the pivotal index number.

8. The server of claim 7 , wherein the processor device is further configured to determine whether the received packet is valid based on whether the watermark matches one of the expected watermarks in the first or second window.

9. The server of claim 7 , wherein the processor device is further configured to discard the packet when the watermark does not match any of the expected watermarks in the first or second window.

10. The server of claim 7 , wherein the processor device is further configured to exchange the authorization and synchronization packet with the client device to activate a session with the client device.

11. The server of claim 7 , wherein the processor device is further configured to:

maintain a record of the pivotal index number, where the pivotal index number represents a index number of a highest-numbered valid watermark received from the client device.

12. The server of claim 11 , wherein the processor device is further configured to, when the watermark matches one of the expected watermarks in the second window, increase the pivotal index number and delete the matching expected watermark from the second window.

13. A non-transitory computer program product comprising a tangible computer useable medium including control logic stored therein, the control logic when executed by one or more processors enables a method for secure transmissions between a server and a client device, the method comprising:

receiving, at the server, a packet from the client device, wherein the packet includes a watermark comprising a portion of a stream of watermark bits and an index number associated with the portion of the stream of watermark bits, and the stream of watermark bits generated from an authorization and synchronization packet previously exchanged between the client and the server; and

determining whether the received packet is valid based on the watermark of the received packet, wherein said determining comprises comparing the watermark of the received packet to a set of expected watermarks in a first window and a set of expected watermarks in a second window, the set of expected watermarks in the first window generated from the stream of watermark bits based on index numbers preceding a pivotal index number, and the set of expected watermarks in the second window generated from the stream of watermark bits based on index numbers succeeding the pivotal index number.

14. The non-transitory computer program product of claim 13 , further comprising:

determining the received packet as valid when the watermark matches one of the expected watermarks in the first or second window.

15. The non-transitory computer program product of claim 13 , further comprising:

discarding the packet when the watermark does not match any of the expected watermarks in the first or second window.

16. The non-transitory computer program product of claim 13 , further comprising:

exchanging the authorization and synchronization packet with the client device to activate a session with the client device.

17. The non-transitory computer program product of claim 13 , wherein comparing the watermark comprises:

maintaining at the server a record of the pivotal index number, wherein the pivotal index number represents a index number of a highest-numbered valid watermark received from the client device; and

when the watermark matches one of the expected watermarks in the second window, increasing the pivotal index number and deleting the matching expected watermark from the second window.

Assignments (3)
CHANGE OF NAME Recorded Oct 5, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044129/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2013
From: ERLINGSSON, ULFAR; BOYEN, XAVIER; ANDERSON, DARRELL; GRAY, WAYNE
To: GREEN BORDER TECHNOLOGIES
Reel/Frame 030897/0481 →
MERGER Recorded Jul 29, 2013
From: GREEN BORDER TECHNOLOGIES
To: GOOGLE INC.
Reel/Frame 030897/0539 →
Continuity (4)
Continuation 13213943 · Aug 19, 2011
Continuation 10627270 · Jul 25, 2003
Provisional Application 60398564 · Jul 26, 2002
Related Publication 20130311782A1 · Nov 21, 2013