IP Library Granted Patent US 10,277,396
Granted Patent B2
US 10,277,396 · App. 15/184,739 · Granted Apr 30, 2019

Watermarking for data integrity

Inventors: Luis Ramos (San Ramon, CA); Venkatesh Sivasubramanian (San Ramon, CA); Sriramakrishna Yelisetti (San Ramon, CA)
Assignee: General Electric Company
H04L9/0861H04L9/0637H04L9/0894H04L2209/608H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,277,396
App. No.
15/184,739
Granted
Apr 30, 2019
Kind
B2
Abstract

Methods, systems, and apparatus for ensuring data integrity are disclosed. A data container structure is obtained, the data container structure containing data and a source identifier of a first hardware component. The data container structure is modified, using a header processing device, to include a component signature and an identifier of a second hardware component.

Claims (38)

1. A method comprising:

receiving, at an intermediate hardware component, a data container structure comprising a payload including time-series data acquired by a source hardware component from an operation performed by an industrial asset, and a header that includes a source identifier of the source hardware component that uniquely identifies the source hardware component, and an asset identifier that uniquely identifies the industrial asset;

generating, by the intermediate hardware component, a hash of the payload including the time-series data acquired from the operation performed by the industrial asset;

watermarking, by the intermediate hardware component, the data container structure by inserting a signature of the intermediate hardware component based on the hash of the payload generated by the intermediate hardware component, and an identifier of the intermediate hardware component that uniquely identifies the intermediate hardware component into the header, wherein the asset identifier, the source identifier, and the identifier of the intermediate hardware component combine to provide an indication of an Industrial Internet of Things (IIoT) network path traveled by the data container structure; and

transmitting, at the intermediate hardware component, the modified data container structure to a next hardware component within the IIoT network.

2. The method of claim 1 , wherein the data container structure further includes a source signature based on the data and a source key.

3. The method of claim 1 , further comprising modifying the data container structure to include a timestamp generated by the intermediate hardware component.

4. The method of claim 1 , further comprising modifying the data in the data container structure.

5. The method of claim 4 , wherein the inserted signature is based on the modified data and a component key.

6. The method of claim 1 , wherein the inserted signature is based on a component key and the data contained in the data container structure.

7. The method of claim 1 , further comprising:

obtaining an identification of an expected path of the data container structure through the IIoT network, the expected path being defined by one or more component identifiers;

parsing a header of the data container structure to extract a list of one or more component identifiers;

comparing the list of one or more component identifiers and the expected path of the data container structure; and

issuing a notification based on a result of the comparison.

8. An apparatus comprising:

a processor;

memory to store instructions that, when executed by the processor cause the processor to perform operations comprising:

receiving, at an intermediate hardware component, a data container structure comprising a payload including time-series data acquired by a source hardware component from an operation performed by an industrial asset, and a header that includes a source identifier of the source hardware component that uniquely identifies the source hardware component, and an asset identifier that uniquely identifies the industrial asset;

generating, by the intermediate hardware component, a hash of the payload including the time-series data acquired from the operation performed by the industrial asset;

watermarking, by the intermediate hardware component, the data container structure by inserting a signature of the intermediate hardware component based on the hash of the payload generated by the intermediate hardware component, and an identifier of the intermediate hardware component that uniquely identifies the intermediate hardware component into the header, wherein the asset identifier, the source identifier, and the identifier of the intermediate hardware component combine to provide an indication of an Industrial Internet of Things (IIoT) network path traveled by the data container structure; and

transmitting, at the intermediate hardware component, the modified data container structure to a next hardware component within the IIoT network.

9. The apparatus of claim 8 , wherein the data container structure further includes a source signature based on the data and a source key.

10. The apparatus of claim 8 , wherein the operations further comprise modifying the data container structure to include a timestamp generated by the intermediate hardware component.

11. The apparatus of claim 8 , wherein the operations further comprise modifying the data in the data container structure.

12. The apparatus of claim 11 , wherein the inserted signature is based on the modified data and a component key.

13. The apparatus of claim 8 , wherein the inserted signature is based on a component key and the data contained in the obtained data container structure.

14. A non-transitory machine-readable storage medium comprising instructions that, when executed by one or more processors of a machine, cause the machine to perform operations comprising:

receiving, at an intermediate hardware component, a data container structure comprising a payload including time-series data acquired by a source hardware component from an operation performed by an industrial asset, and a header that includes a source identifier of the source hardware component that uniquely identifies the source hardware component, and an asset identifier that uniquely identifies the industrial asset;

generating, by the intermediate hardware component, a hash of the payload including the time-series data acquired from the operation performed by the industrial asset;

watermarking, by the intermediate hardware component, the data container structure by inserting a signature of the intermediate hardware component based on the hash of the payload generated by the intermediate hardware component, and an identifier of the intermediate hardware component that uniquely identifies the intermediate hardware component into the header, wherein the asset identifier, the source identifier, and the identifier of the intermediate hardware component combine to provide an indication of an Industrial Internet of Things (IIoT) network path traveled by the data container structure; and

transmitting, at the intermediate hardware component, the modified data container structure to a next hardware component within the IIoT network.

15. The non-transitory machine-readable storage medium of claim 14 , wherein the data container structure further includes a source signature based on the data and a source key.

16. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise modifying the data container structure to include a timestamp generated by the intermediate hardware component.

17. The non-transitory machine-readable storage medium of claim 14 , wherein the operations further comprise modifying the data in the data container structure.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the inserted signature is based on the modified data and a component key.

19. The non-transitory machine-readable storage medium of claim 14 , wherein the inserted signature is based on a component key and the data contained in the obtained data container structure.

20. The method of claim 1 , wherein the source hardware component comprises a sensor which senses time series data generated by operation of the industrial asset, the source identifier comprises a unique identifier of the sensor within the IIoT network, and the asset identifier comprises a unique identifier of the industrial asset within the IIoT network.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2023
From: GENERAL ELECTRIC COMPANY
To: GE DIGITAL HOLDINGS LLC
Reel/Frame 065612/0085 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2017
From: RAMOS, LUIS; SIVASUBRAMANIAN, VENKATESH; YELISETTI, SRIRAMAKRISHNA
To: GENERAL ELECTRIC COMPANY
Reel/Frame 041747/0591 →
Continuity (1)
Related Publication 20170366356A1 · Dec 21, 2017