Method of verifying origin of a signed file
Methods are provided for generating a certificate, signing files with the certificate and verifying the signing. A first aspect provides, in an electronic data processing device, a method of processing a data file. The method comprises associating a certificate to a data file, the certificate comprising at least one reputation service identifier, signing the data file using a private key associated with the certificate, generating a file identifier based on data comprised by the data file and sending the file identifier to a trusted data vault associated with the certificate. The method further comprises generating a data file token based on the file identifier, signing the data file token with the private key and sending the token to the reputation service for publication associated with the reputation service identifier.
1 . A method of registering a certificate in an electronic data processing device, the method comprising:
generating the certificate and associating the certificate with a public key;
adding at least one reputation service identifier of a reputation service provider to the certificate, the reputation service identifier comprising data, which identifies the reputation service provider;
obtaining a blockchain alias identifying a blockchain account;
sending, by the electronic data processing device, certificate data including the public key to the blockchain account; and
embedding the blockchain alias in the certificate, such that the certificate data in the blockchain account is identifiable to a party receiving the certificate, wherein the method further comprises:
associating the certificate to a data file;
signing the data file using a private key, the private key being associated with the certificate and being associated with the public key;
generating a file identifier, which identifies the data file based on data contained in the data file;
sending the file identifier to the blockchain account;
generating a data file token based on the file identifier;
signing the data file token with the private key; and
sending the data file token to the reputation service provider for publication associated with the reputation service identifier.
2 . The method according to claim 1 , the method further comprising:
retrieving the certificate from the data file, the certificate comprising the reputation service identifier;
retrieving the data file token from the reputation service provider, the data file token being associated with the reputation service identifier;
retrieving the public key from the blockchain account associated with the certificate; and
verifying the data file token with the public key.
3 . The method according to claim 2 , further comprising:
generating a first file identifier based on data comprised by the data file;
wherein retrieving the data file token further comprises searching the reputation service provider for the first file identifier.
4 . The method according to claim 3 , wherein the first file identifier is at least one of the following: a hash of the data file; a checksum of the data file; and a fingerprint of the data file.
5 . The method according to claim 3 , further comprising:
retrieving a second file identifier from the blockchain account, the second file identifier being associated with the data file; and
comparing the first file identifier with the second file identifier.
6 . The method according to claim 2 , further comprising:
retrieving a further reputation service identifier from the blockchain account.
7 . The method according to claim 2 , wherein the data file token from the reputation service provider comprises a reputation service time stamp, the method further comprising:
retrieving, from the blockchain account, a time stamp associated with registering the certificate in the blockchain account; and
comparing the reputation service time stamp with the time stamp associated with registering the certificate in the blockchain account.
8 . The method according to claim 2 , further comprising:
retrieving a second certificate from the blockchain account associated with the certificate; and comparing the certificate with the second certificate.
9 . The method according to claim 2 , further comprising:
retrieving, from the reputation service provider, a reputation strength value associated with the reputation service identifier.
10 . The method according to claim 1 , further comprising:
appending the certificate to the data file, prior to at least one of signing the data file and generating the file identifier.
11 . The method according to claim 10 , further comprising:
sending the public key to the reputation service provider.
12 . The method according to claim 1 , wherein the public key is associated with the private key.
13 . The method according to claim 1 , further comprising:
associating a timestamp with the data file token.
14 . The method according to claim 13 , further comprising:
sending at least one of the file identifier and the data file token to the blockchain account;
receiving, in response to the sending, a transaction timestamp; and
associating the transaction timestamp with the data file token.
15 . The method according to claim 1 , further comprising:
sending the certificate to the blockchain account.
16 . The method according to claim 1 , further comprising: sending the reputation service identifier to the blockchain account.
17 . The method according to claim 1 , wherein the reputation service provider is at least one of the following: a social media service; a network address associated with an entity associated with a private key; and a database managed by a government service.
18 . A data processing device comprising:
a memory; and
a processor, coupled to the memory, configured to perform a method comprising:
generating a certificate and associating the certificate with a public key;
adding at least one reputation service identifier of a reputation service provider to the certificate, the reputation service identifier comprising data, which identifies the reputation service provider;
obtaining a blockchain alias identifying a blockchain account;
sending, by the electronic data processing device, certificate data including the public key to the blockchain account; and
embedding the blockchain alias in the certificate, such that the certificate data in the blockchain account is identifiable to a party receiving the certificate, wherein the processor is further configured to perform the method comprising:
associating the certificate to a data file;
signing the data file using a private key, the private key being associated with the certificate and being associated with the public key;
generating a file identifier, which identifies the data file based on data contained in the data file;
sending the file identifier to the blockchain account;
generating a data file token based on the file identifier;
signing the data file token with the private key; and
sending the data file token to the reputation service provider for publication associated with the reputation service identifier.
19 . A non-transitory computer readable medium comprising a program of instructions that, when executed by a processor, cause the processor to perform a method comprising:
generating a certificate and associating the certificate with a public key;
adding at least one reputation service identifier of a reputation service provider to the certificate, the reputation service identifier comprising data, which identifies the reputation service provider;
obtaining a blockchain alias identifying a blockchain account;
sending, by the electronic data processing device, certificate data including the public key to the blockchain account; and
embedding the blockchain alias in the certificate, such that the certificate data in the blockchain account is identifiable to a party receiving the certificate, wherein the program instructions further cause the processor to perform the method comprising:
associating the certificate to a data file;
signing the data file using a private key, the private key being associated with the certificate and being associated with the public key;
generating a file identifier, which identifies the data file based on data contained in the data file;
sending the file identifier to the blockchain account;
generating a data file token based on the file identifier;
signing the data file token with the private key; and
sending the data file token to the reputation service provider for publication associated with the reputation service identifier.