IP Library › Granted Patent US 9,380,050
Granted Patent B2
US 9,380,050 · App. 14/310,074 · Granted Jun 28, 2016

Scan image authentication

Inventors: Gavan L. Tredoux (Penfield, NY); Premkumar Rajendran (Webster, NY); Roger T. Kramer (Rochester, NY); Peter J. Zehler (Penfield, NY)
Assignee: Xerox Corporation
H04L63/0823H04L9/3247H04L63/123H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,380,050
App. No.
14/310,074
Granted
Jun 28, 2016
Kind
B2
Abstract

Methods and systems receive an electronic scanned image generated by activity of an application running on a portable computerized device, and calculate a cryptographic digest from data of the electronic scanned image using a second computerized device. Also, such methods and systems encrypt the cryptographic digest using an encryption key stored on the portable computerized device to create a content signature of the cryptographic digest, and send the content signature to the second computerized device. The authenticity of a copy of the electronic scanned image provided by the second computerized device is verified by recalculating the content signature (based on the copy of the electronic scanned image) using the encryption key from the portable device.

Claims (97)

1. A method of verifying authenticity of a scan using a system comprising: an application running on a portable computerized device; and a second computerized device separate from said portable computerized device, said method comprising:

obtaining, by said application, a token from said second computerized device;

supplying, by said application, a certificate;

signing, by said application, said token using said certificate to create a counter-signed token;

causing, by said application, said counter-signed token to be added to metadata of an electronic scanned image generated by activity of said application;

receiving, by said second computerized device, said electronic scanned image and said metadata;

calculating, by said second computerized device, a cryptographic digest from data of said electronic scanned image and said metadata;

receiving, by said application, from said second computerized device, said cryptographic digest;

encrypting, by said application, said cryptographic digest using an encryption key stored on said portable computerized device to create a content signature of said cryptographic digest;

sending, by said application, said content signature to said second computerized device; and

verifying authenticity of a copy of said electronic scanned image provided by said second computerized device by recalculating said content signature for said copy of said electronic scanned image said using said encryption key.

2. The method according to claim 1 , further comprising:

receiving, by said application, a time stamp from said second computerized device; and

adding, by said application, said time stamp to metadata of said electronic scanned image before said receiving said electronic scanned image by said second computerized device,

said calculating said cryptographic digest being based on said data from said electronic scanned image and said metadata.

3. The method according to claim 1 , further comprising, before said encrypting said cryptographic digest:

receiving, by said application, a stored version of said electronic scanned image from said second computerized device;

displaying, by said application, said stored version of said electronic scanned image on a display of said portable computerized device for approval by a user;

receiving, by said application, said approval from said user through said portable computerized device; and

performing said encrypting said cryptographic digest only if said approval is received from said user.

4. The method according to claim 1 , said second computerized device comprising a plurality of computerized devices comprising a location service computerized device and a delivery service computerized device, said method further comprising:

receiving, by said application, from said location service computerized device scanner location information; and

verifying, by said application, a location of a scanning machine used to create said electronic scanned image based on said location information.

5. A method of verifying authenticity of a scan using a system comprising: an application running on a portable computerized device; and a second computerized device separate from said portable computerized device, said method comprising:

receiving, by said application, a token from a scanning machine;

signing, by said portable computerized device, said token using a certificate of said portable computerized device to create a counter-signed token;

causing said scanning machine to scan a physical item to generate an electronic scanned image;

sending, by said application, said counter-signed token to said scanning machine to cause said scanning machine to include said counter-signed token in metadata of said electronic scanned image;

causing, by said application, said scanning machine to transmit said electronic scanned image and said metadata to said second computerized device;

calculating, by said second computerized device, a cryptographic digest by applying a cryptographic hash function to data of said electronic scanned image and said metadata;

receiving, by said application, from said second computerized device, said cryptographic digest;

encrypting, by said application, said cryptographic digest using an encryption key stored on said portable computerized device to create an original content signature of said cryptographic digest;

sending, by said application, said original content signature to said second computerized device;

after said application sends said original content signature to said second computerized device, receiving, by said second computerized device, a request to a download a copy of said electronic scanned image from a requestor;

in response to said request to download said copy of said electronic scanned image, recalculating a current cryptographic digest by applying said cryptographic hash function to data of said copy of said electronic scanned image;

encrypting said current cryptographic digest using said encryption key stored on said portable computerized device to create a current content signature of said current cryptographic digest; and

comparing said current content signature with said original content signature to verify whether said copy of said electronic scanned image is identical to said electronic scanned image.

6. The method according to claim 5 , further comprising:

receiving, by said application, a time stamp from said second computerized device; and

adding, by said application, said time stamp to metadata of said electronic scanned image before said receiving said electronic scanned image by said second computerized device,

said calculating said cryptographic digest being based on said data from said electronic scanned image and said metadata.

7. The method according to claim 5 , further comprising, before said encrypting said cryptographic digest:

receiving, by said application, a stored version of said electronic scanned image from said second computerized device;

displaying, by said application, said stored version of said electronic scanned image on a display of said portable computerized device for approval by a user;

receiving, by said application, said approval from said user through said portable computerized device; and

performing said encrypting said cryptographic digest only if said approval is received from said user.

8. The method according to claim 5 , said second computerized device comprising a plurality of computerized devices comprising a location service computerized device and a delivery service computerized device, said method further comprising:

receiving, by said application, from said location service computerized device scanner location information; and

verifying, by said application, a location of a scanning machine used to create said electronic scanned image based on said location information.

9. A method of verifying authenticity of a scan using a system comprising: an application running on a portable computerized device; and a second computerized device separate from said portable computerized device, said method comprising:

sending, by said portable computerized device, a token to a wireless scanning machine identification code device of a scanning machine while said portable computerized device is positioned at a first location that is within a first distance from said scanning machine to cause said scanning machine identification code device to create a counter-signed token;

receiving, by said application, said counter-signed token from said wireless machine identification code device while said portable computerized device is positioned at said first location;

signing, by said portable computerized device, said counter-signed token using a certificate of said portable computerized device to create a counter-counter-signed token;

causing said scanning machine to scan a physical item to generate an electronic scanned image;

sending, by said application, said counter-counter-signed token to said scanning machine to cause said scanning machine to include said counter-counter-signed token in metadata of said electronic scanned image;

receiving, by said second computerized device, said electronic scanned image and said metadata from said scanning machine;

calculating, by said second computerized device, a cryptographic digest from said metadata and said electronic scanned image;

receiving, by said application, from said second computerized device, said cryptographic digest;

encrypting, by said application, said cryptographic digest using an encryption key stored on said portable computerized device to create a content signature of said cryptographic digest;

sending, by said application, said content signature to said second computerized device; and

verifying authenticity of a copy of said electronic scanned image provided by said second computerized device by recalculating said content signature for said copy of said electronic scanned image said using said encryption key.

10. The method according to claim 9 , further comprising, before said receiving said electronic scanned image by said second computerized device obtaining, by said application, said token from said second computerized device.

11. The method according to claim 9 , further comprising:

receiving, by said application, a time stamp from said second computerized device; and

adding, by said application, said time stamp to said metadata of said electronic scanned image before said receiving said electronic scanned image by said second computerized device.

12. The method according to claim 9 , further comprising, before said encrypting said cryptographic digest:

receiving, by said application, a stored version of said electronic scanned image from said second computerized device;

displaying, by said application, said stored version of said electronic scanned image on a display of said portable computerized device for approval by a user;

receiving, by said application, said approval from said user through said portable computerized device; and

performing said encrypting said cryptographic digest only if said approval is received from said user.

13. The method according to claim 9 , said second computerized device comprising a plurality of computerized devices comprising a location service computerized device and a delivery service computerized device, said method further comprising:

receiving, by said application, from said location service computerized device scanner location information; and

verifying, by said application, a location of a scanning machine used to create said electronic scanned image based on said location information.

14. A system comprising:

an application running on a portable computerized device; and

a second computerized device separate from said portable computerized device,

said application receiving a token from a scanning machine,

said portable computerized device signing said token using a certificate of said portable computerized device to create a counter-signed token,

said scanning machine scanning a physical item to generate an electronic scanned image,

said application sending said counter-signed token to said scanning machine to cause said scanning machine to include said counter-signed token in metadata of said electronic scanned image,

said application causing said scanning machine to transmit said electronic scanned image and said metadata to said second computerized device,

said second computerized device calculating a cryptographic digest from data of said electronic scanned image and said metadata,

said application receiving, from said second computerized device, said cryptographic digest,

said application encrypting said cryptographic digest using an encryption key stored on said portable computerized device to create a content signature of said cryptographic digest,

said application sending said content signature to said second computerized device, and

authenticity of a copy of said electronic scanned image provided by said second computerized device being verified by recalculating said content signature for said copy of said electronic scanned image said using said encryption key.

15. The system according to claim 14 , said application receiving a time stamp from said second computerized device,

said application adding said time stamp to metadata of said electronic scanned image before said electronic scanned image is received by said second computerized device,

said calculating said cryptographic digest being based on said data from said electronic scanned image and said metadata.

16. The system according to claim 14 , before said encrypting said cryptographic digest:

said application receiving a stored version of said electronic scanned image from said second computerized device;

said application displaying said stored version of said electronic scanned image on a display of said portable computerized device for approval by a user;

said application receiving said approval from said user through said portable computerized device; and

said encrypting said cryptographic digest only being performed if said approval is received from said user.

17. The system according to claim 14 , said second computerized device comprising a plurality of computerized devices comprising a location service computerized device and a delivery service computerized device,

said application receiving, from said location service computerized device, scanner location information, and

said application verifying a location of a scanning machine used to create said electronic scanned image based on said location information.

Assignments (7)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT RF 064760/0389 Recorded Feb 13, 2024
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: XEROX CORPORATION
Reel/Frame 068261/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
SECURITY INTEREST Recorded Jun 22, 2023
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 064760/0389 →
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 062740/0214 Recorded May 18, 2023
From: CITIBANK, N.A., AS AGENT
To: XEROX CORPORATION
Reel/Frame 063694/0122 →
SECURITY INTEREST Recorded Nov 10, 2022
From: XEROX CORPORATION
To: CITIBANK, N.A., AS AGENT
Reel/Frame 062740/0214 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2014
From: TREDOUX, GAVAN L.; RAJENDRAN, PREMKUMAR; KRAMER, ROGER T.; ZEHLER, PETER J.
To: XEROX CORPORATION
Reel/Frame 033146/0445 →
Continuity (1)
Related Publication 20150372988A1 · Dec 24, 2015