IP Library › Granted Patent US 12,452,074
Granted Patent B2
US 12,452,074 · App. 18/193,798 · Granted Oct 21, 2025

Systems and methods for validating authenticity of databases

Inventor: Mark Edward Scott, Jr. (Waco, TX)
Assignee: Dell Products, L.P.
H04L9/3239G06F16/211G06F16/284H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,074
App. No.
18/193,798
Granted
Oct 21, 2025
Kind
B2
Abstract

Systems and methods for validating the authenticity of databases are described. In an illustrative, non-limiting embodiment, an Information Handling System (IHS) may include: a processor, and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the processor to: calculate a first hash of schema objects for a relational database; compare the calculated first hash of the schema objects with an expected second hash of the schema objects for the relational database; determine whether to validate of the relational database based, at least in part, on the comparison; and provide an indication of the determination to a recipient.

Claims (54)

1. An Information Handling System (IHS) comprising:

a processor; and

a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution, cause the processor to:

calculate a first hash of schema objects for a relational database;

compare the calculated first hash of the schema objects with an expected second hash of the schema objects for the relational database;

determine whether to validate the relational database based, at least in part, on the comparison;

determine a cryptographic signature of the first hash using a private encryption key;

combine data retained by the relational database, the first hash and the cryptographic signature into a package; and

provide the package and an indication of the determination whether to validate the relational database to a network-based recipient via a communication network, wherein the package enables the recipient to validate the relational database using the first hash and the cryptographic signature, and wherein the validation of the relational database certifies that the relational database has not been modified thereby ensuring authenticity of the relational database.

2. The IHS of claim 1 , wherein to calculate the first hash of the schema objects for the relational database, the program instructions further cause the processor to:

enumerate the schema objects for the relational database into string values;

determine a cryptographic hash the string values using a cryptographic algorithm; and

convert the cryptographic hash into a hexadecimal string, wherein the hexadecimal string of the cryptographic hash is the first hash of the schema objects.

3. The IHS of claim 2 , wherein the cryptographic algorithm is a SHA-256 cryptographic hash algorithm.

4. The IHS of claim 1 , wherein to calculate the first hash of the schema objects for the relational database, the program instructions further cause the processor to:

select a subset of fewer than all schema objects as the schema objects for the first hash of the schema objects based, at least in part, on one or more of: a size of one or more of the schema objects, a date of creation of one or more of the schema objects, or a type of one or more of the schema objects.

5. The IHS of claim 1 , wherein the second hash identifies fewer than all schema objects usable to calculate the first hash.

6. The IHS of claim 5 , wherein the expected second hash comprises a cryptographic signature from a software or hardware manufacturer, and wherein to determine the validation of the relational database, the program instructions further cause the processor to:

determine a validation of the cryptographic signature of the expected second hash using a public key of the software or hardware manufacturer; and

determine the validation of the relational database based, at least in part, on the comparison and the validation of the cryptographic signature of the expected second hash.

7. The IHS of claim 1 , wherein the calculated first hash of the schema objects does not compare with the expected second hash of the schema objects,

wherein to determine a validation of the relational database, the program instructions further cause the processor to:

determine that the relational database is not valid; and

wherein to provide the validation determination to the recipient, the program instructions further cause the processor to:

provide an error to the recipient.

8. The IHS of claim 1 , wherein the calculation, the comparison, the determination whether to validate the relational database, and the providing are performed subsequent to one or more of:

a start of the relational database;

a schema change for the relational database;

a transaction log file rotation; or

one or more database logins added, removed, or altered.

9. The IHS of claim 1 , wherein the recipient comprises an application layer.

10. The IHS of claim 1 , wherein the relational database is a component of a virtual appliance, and wherein the recipient comprises a system administrator.

11. The IHS of claim 1 , wherein the relational database is a component of an embedded software package associated with a hardware component of the IHS, and wherein the recipient comprises an administrator of the IHS.

12. The IHS of claim 1 , wherein the relational database is provided by a provider network, and wherein the recipient comprises a software application that accesses the relational database.

13. The IHS of claim 1 , wherein the expected second hash is stored in a filesystem of the IHS that has been validated by a kernel for the IHS using dm-verity.

14. A method for providing a relational database with a capability to be validated, comprising:

calculating a hash of schema objects for the relational database;

determining a cryptographic signature of the hash using a private encryption key of a software or hardware manufacturer;

combining data retained by the relational database, the hash, and the cryptographic signature into a package; and

providing the package to a network-based recipient via a communication network, wherein the package enables the recipient to validate the relational database using the hash and the cryptographic signature, and wherein the validation of the relational database certifies that the relational database has not been modified thereby ensuring authenticity of the relational database.

15. The method of claim 14 , wherein calculating the hash of the schema objects for the relational database further comprises:

enumerating the schema objects for the relational database into string values;

determining a cryptographic hash the string values using a cryptographic algorithm; and

converting the cryptographic hash into a hexadecimal string, wherein the hexadecimal string of the cryptographic hash is the calculated hash of the schema objects.

16. The method of claim 15 , wherein the cryptographic algorithm is a SHA-256 cryptographic hash algorithm.

17. The method of claim 14 , wherein calculating the hash of the schema objects for the relational database further comprises:

selecting a subset of fewer than all schema objects as the schema objects for the hash of the schema objects based, at least in part, on one or more of: a size of one or more of the schema objects, a date of creation of one or more of the schema objects, or a type of one or more of the schema objects.

18. The method of claim 14 , wherein the recipient is a virtual appliance.

19. The method of claim 14 , wherein the recipient is an application provided by the software or hardware manufacturer.

20. A memory storage device having program instructions stored thereon that, upon execution by one or more processors of one or more Information Handling Systems (IHSs), cause the one or more IHSs to:

determine whether to validate a database based, at least in part, upon a comparison between a first hash of schema objects of the database against an expected second hash of the schema objects;

determine a cryptographic signature of the first hash using a private encryption key;

combine data retained by the database, the first hash and the cryptographic signature into a package; and

provide the package and an indication of the determination whether to validate the database to a network-based recipient via a communication network, wherein the package enables the recipient to validate the database using the first hash and the cryptographic signature, and wherein the validation of the database certifies that the database has not been modified thereby ensuring authenticity of the database.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2023
From: SCOTT, MARK EDWARD, JR.
To: DELL PRODUCTS, L.P.
Reel/Frame 063184/0490 →
Continuity (1)
Related Publication 20240333517A1 · Oct 3, 2024
References Cited (8)
US 9659040B1 · Bellingan · 2017 [cited by examiner]
US 11709808B1 · Dageville · 2023 [cited by examiner]
US 20010018664A1 · Jacoves · 2001 [cited by examiner]
US 20040150519A1 · Husain · 2004 [cited by examiner]
US 20060067525A1 · Hartlage · 2006 [cited by examiner]
US 20190147170A1 · Keselman · 2019 [cited by examiner]
US 20210157921A1 · Brown · 2021 [cited by examiner]
Martínez et al. “Robust hashing for models.” Proceedings of the 21th ACM/IEEE International Conference on Model Driven Engineering Languages and Systems. 2018. (Year: 2018). [cited by examiner]