IP Library Granted Patent US 10,181,954
Granted Patent B2
US 10,181,954 · App. 15/159,506 · Granted Jan 15, 2019

Cloud-based code signing service—hybrid model to avoid large file uploads

Inventor: Alok Naik (Bangalore, IN)
Assignee: DigiCert, Inc.
H04L9/3247G06F21/51G06F21/64H04L63/0823H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,181,954
App. No.
15/159,506
Granted
Jan 15, 2019
Kind
B2
Abstract

Techniques are disclosed for reducing the amount of data associated with code signing files in a cloud-based computing environment. In one embodiment, a cloud-based code signing component receives a request to sign a current version of a file. The request includes differences between the current version of the file and a previous version of the file. The cloud-based code signing component reconstructs the current version of the file based on the differences between the current version of the file and the previous version of the file. The cloud-based code signing component signs the reconstructed file, and determines differences between the signed file and the reconstructed file. The cloud-based code signing component transfers the differences between the signed file and the reconstructed file to a user.

Claims (45)

1. A method, comprising:

receiving, at a code signing computing system, a request to sign a current version of a file from a client computing device, wherein the request is received via a data communications network and comprises differences between a prior version of the file and the current version;

reconstructing, at the code signing computing system, the current version of the file based on the differences between the prior version and the current version of the file;

signing, at the code signing computing system, the reconstructed file;

determining, at the code signing computing system, differences between the reconstructed file and the signed file; and

transferring, by the code signing computing system, the differences between the reconstructed file and the signed file to the client computing device via the data communications network, wherein the differences between the reconstructed and the signed file comprise a signature.

2. The method of claim 1 , further comprising identifying the prior version of the file from a plurality of different versions of the file based on an indication of the prior version of the file included in the request.

3. The method of claim 2 , further comprising:

receiving the current version of the file if a number of the differences between the current version of the file and the prior version of the file is greater than a threshold; and

adding the current version of the file to the plurality of different versions of the file.

4. The method of claim 1 , wherein the prior version of the file is a base version of the file.

5. The method of claim 1 , wherein determining the differences between the signed file and the reconstructed file comprises using a diff tool to determine the differences between the signed file and the reconstructed file.

6. The method of claim 1 , wherein the reconstructed file is signed using a private key selected from a plurality of private keys.

7. The method of claim 1 , wherein the code signing computer system comprises an online code signing service exposed to users over the data communications network.

8. A computer-readable non-transitory storage medium storing instructions, which, when executed by a processor, perform an operation, the operation comprising:

receiving, code signing computing system, a request to sign a current version of a file from a client computing device, wherein the request is received via a data communications network and comprises differences between a prior version of the file and the current version;

reconstructing, at the code signing computing system, the current version of the file based on the differences between the prior version and the current version of the file;

signing, at the code signing computing system, the reconstructed file;

determining, at the code signing computing system, differences between the reconstructed file and the signed file; and

transferring, by the code signing computing system, the differences between the reconstructed file and the signed file to the client computing device via the data communications network, wherein the differences between the reconstructed and the signed file comprise a signature.

9. The computer-readable non-transitory storage medium of claim 8 , the operation further comprising:

identifying the prior version of the file from a plurality of different versions of the file based on an indication of the prior version of the file included in the request.

10. The computer-readable non-transitory storage medium of claim 9 , the operation further comprising:

receiving the current version of the file if a number of the differences between the current version of the file and the prior version of the file is greater than a threshold; and

adding the current version of the file to the plurality of different versions of the file.

11. The computer-readable non-transitory storage medium of claim 8 , wherein the prior version of the file is a base version of the file.

12. The computer-readable non-transitory storage medium of claim 8 , wherein determining the differences between the signed file and the reconstructed file comprises using a diff tool to determine the differences between the signed file and the reconstructed file.

13. The computer-readable non-transitory storage medium of claim 8 , wherein the reconstructed file is signed using a private key selected from a plurality of private keys.

14. The computer-readable non-transitory storage medium of claim 8 , wherein the code signing computer system comprises an online code signing service exposed to users over the data communications network.

15. A system, comprising:

a processor; and

a memory containing a program, which when executed by the processor, performs an operation, the operation comprising:

receiving, at a code signing computing system, a request to sign a current version of a file from a client computing device, wherein the request is received via a data communications network and comprises differences between a prior version of the file and the current version;

reconstructing, at the code signing computing system, the current version of the file based on the differences between the prior version and the current version of the file;

signing, at the code signing computing system, the reconstructed file;

determining, at the code signing computing system, differences between the reconstructed file and the signed file; and

transferring, by the code signing computing system, the differences between the reconstructed file and the signed file to the client computing device via the data communications network, wherein the differences between the reconstructed and the signed file comprise a signature.

16. The system of claim 15 , the operation further comprising:

identifying the prior version of the file from a plurality of different versions of the file based on an indication of the prior version of the file included in the request.

17. The system of claim 16 , the operation further comprising:

receiving the current version of the file if a number of the differences between the current version of the file and the prior version of the file is greater than a threshold; and

adding the current version of the file to the plurality of different versions of the file.

18. The system of claim 15 , wherein the prior version of the file is a base version of the file.

19. The system of claim 15 , wherein determining the differences between the signed file and the reconstructed file comprises using a diff tool to determine the differences between the signed file and the reconstructed file.

20. The system of claim 15 , wherein the reconstructed file is signed using a private key selected from a plurality of private keys.

Assignments (11)
ASSIGNMENT OF SECURITY INTERESTS IN INTELLECTUAL PROPERTY (FIRST LIEN), RECORDED ON OCTOBER 16, 2019 AT REEL 050741 FRAME 0918 Recorded Sep 24, 2025
From: UBS AG, STAMFORD BRANCH, AS SUCCESSOR TO CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS RESIGNING AGENT
To: HPS INVESTMENT PARTNERS, LLC, AS SUCCESSOR AGENT
Reel/Frame 072947/0157 →
SECOND LIEN NOTICE OF SUCCESSION OF AGENCY Recorded Jul 30, 2025
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS PRIOR AGENT
To: UBS AG, STAMFORD BRANCH, AS SUCCESSOR AGENT
Reel/Frame 072300/0068 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 19, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS SUCCESSOR AGENT
Reel/Frame 055345/0042 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050746/0973 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Oct 17, 2019
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: DIGICERT, INC.; GEOTRUST, LLC
Reel/Frame 050747/0001 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 050741/0899 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 16, 2019
From: DIGICERT, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 050741/0918 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044681/0556 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 3, 2017
From: DIGICERT, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 044710/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: SYMANTEC CORPORATION
To: DIGICERT, INC.
Reel/Frame 044344/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2016
From: NAIK, ALOK
To: SYMANTEC CORPORTATION
Reel/Frame 038655/0622 →
Priority Claims (1)
IN 201641010511 · Mar 28, 2016 · national
Continuity (1)
Related Publication 20170279615A1 · Sep 28, 2017