IP Library Granted Patent US 12,130,933
Granted Patent B2
US 12,130,933 · App. 17/457,700 · Granted Oct 29, 2024

Authentication of files

Inventor: Daniel Arthur Ujvari (Hauppauge, NY)
Assignee: Microchip Technology Incorporated
G06F21/6209G06F21/575H04L9/0643H04L9/0825H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,130,933
App. No.
17/457,700
Granted
Oct 29, 2024
Kind
B2
Abstract

Systems for authenticating a file are disclosed. A system may include one or more physical devices. The one or more physical devices may select, based on an identifier, a subset of data segments of a computer file for generating a first digest with a cryptographic function. The one or more physical devices may also execute the cryptographic function on the selected subset of data segments of the computer file to generate the first digest. Further, the one or more physical devices may generate an authenticator based on the first digest and a private key. The one or more physical devices may further send the computer file, the identifier, and the authenticator to a secure node. Associated methods and non-transitory machine-readable medium are also disclosed.

Claims (40)

1. A system, comprising:

one or more physical devices to:

determine a subset selection identifier, said subset selection identifier to identify how a subset of data segments of a computer file is selected, upon determining an identification of a repeatable pattern of data segments of the computer file in a form of one (1) data segment selected for every N data segments, wherein N is a positive integer;

select, via the subset selection identifier, the subset of data segments of the computer file for generating a first digest with a cryptographic function;

execute the cryptographic function on the selected subset of data segments of the computer file to generate the first digest, which said first digest is signed by a private key;

generate an authenticator using the first digest and the private key; and

send the computer file, the subset selection identifier, and the authenticator to a same secure node.

2. The system of claim 1 , further comprising the secure node, the secure node to:

receive the computer file, the subset selection identifier, and the authenticator;

determine the subset of data segments of the computer file based on the subset selection identifier;

execute the cryptographic function on the subset of data segments of the computer file to generate a second digest; and

authenticate the computer file via verification of the authenticator based on the second digest and a public key.

3. The system of claim 1 , wherein the subset selection identifier identifies a pseudorandom distribution of data segments of the computer file.

4. The system of claim 1 , wherein the subset selection identifier includes, or is determined via, an algorithm.

5. The system of claim 1 , wherein the subset selection identifier includes, or is determined by, a randomly generated number.

6. The system of claim 5 , wherein the randomly generated number is represented by a binary number, wherein each bit of the binary number corresponds to a data segment within either the subset of data segments or another subset of data segments of the computer file not selected for generating the first digest.

7. The system of claim 1 , wherein the one or more physical devices are to select the subset of data segments of the computer file based on contents of the computer file.

8. A method, comprising:

determining a subset selection identifier, the subset selection identifier to identify how a subset of data segments of a computer file is selected, upon determining a repeatable pattern of data segments of the computer file in a form of one (1) data segment selected for every N data segments, wherein N is a positive integer;

selecting, via the subset selection identifier, the subset of data segments of the computer file;

executing a cryptographic function on only the subset of data segments of the computer file to generate a first digest, which said first digest is signed by a private key;

generating an authenticator using the first digest and the private key; and

conveying the computer file, the subset selection identifier, and the authenticator to a same cryptography element.

9. The method of claim 8 , further comprising;

executing, via the cryptography element, the cryptographic function on the subset of data segments of the computer file to generate a second digest; and

authenticating, via the cryptography element, the computer file via verification of the authenticator based on the second digest and a public key.

10. The method of claim 8 , wherein the determining the subset selection identifier comprises determining the subset selection identifier via one of an algorithm and a randomly generated number.

11. A non-transitory machine-readable medium storing instructions that, in response to being executed by at least one processor of a system, are to enable the system to perform operations comprising:

determining a subset selection identifier, the subset selection identifier to identify how a subset of data segments of a computer file is selected, upon determining a repeatable pattern of data segments of the computer file in a form of one (1) data segment selected for every N data segments, wherein N is a positive integer;

selecting, via the subset selection identifier, the subset of data segments of the computer file;

executing a cryptographic function on only the subset of data segments of the computer file to generate a first digest, which said first digest is signed by a private key;

generating an authenticator using the first digest and the private key; and

conveying, via a secure message, at least the subset of data segments, the subset selection identifier, and the authenticator to a same secure node.

12. The non-transitory machine-readable medium of claim 11 , further comprising:

executing a second hash operation on the subset of data segments of the computer file to generate a second digest; and

authenticating the computer file via verification of the authenticator using the second digest and a public key.

13. The non-transitory machine-readable medium of claim 12 , wherein the executing the second hash operation comprises executing the second hash operation on a secure cryptography element.

14. The non-transitory machine-readable medium of claim 11 , the operations further comprising determining the subset selection identifier based on at least one of a repeatable pattern, a random number, or an algorithm.

15. The non-transitory machine-readable medium of claim 11 , wherein the executing the cryptographic function comprises executing a hash operation on a microcontroller.

16. The non-transitory machine-readable medium of claim 11 , wherein the executing the cryptographic function comprises executing the cryptographic function responsive to at least one of a firmware update or a secure boot up.

Continuity (3)
Continuation 16221037 · Dec 14, 2018
Provisional Application 62719250 · Aug 17, 2018
Related Publication 20220092201A1 · Mar 24, 2022