IP Library › Granted Patent US 12,445,307
Granted Patent B1
US 12,445,307 · App. 18/598,790 · Granted Oct 14, 2025

Cryptographic authentication signatures for verification of streaming data

Inventors: Timothy Glenn Suter (Melbourne, AU); Harvey Edward Phillips (London, GB); Bryce Edward Case (Colorado Springs, CO)
Assignee: Amazon Technologies, Inc.
H04L9/3247G06T7/20H04L9/0825H04L9/3236H04L9/3297G06T2207/30196
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,307
App. No.
18/598,790
Granted
Oct 14, 2025
Kind
B1
Abstract

Systems and techniques are described for signing and verifying a data stream with an encryption signature. An example method includes determining, for a data block group, an initialization vector. The example method also includes generating, based at least in part on the data block group, encrypted hash data. The example method also includes determining an encryption signature based at least in part on the encrypted hash data, a private key, and the initialization vector. The example method also includes inserting the encryption signature into the data block group. The example method also includes causing transmission, by a network interface to a media server, of the data block group and the encryption signature. Finally, the example method includes causing verification, via the media server using a public key and synchronized data, that the data block group was generated by the computing device.

Claims (171)

1. An electronic device comprising:

a camera;

a microphone;

one or more processors; and

one or more computer readable media storing processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

generating first image data using the camera,

generating, based on encoding the first image data, a plurality of blocks,

determining a first set of blocks of the plurality of blocks,

determining a first hash value based on

a first block of the first set of blocks, and

authentication data,

determining a second hash value based on

a second block of the first set of blocks, and

a hash value determined based on a block of the first set of blocks other than the second block,

generating encrypted data based on

the second hash value, and

a key stored at the electronic device,

determining signature data comprising the authentication data and the encrypted data,

transmitting to a remote system

data representing the first set of blocks, and

the signature data.

2. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining a third hash value based on

a third block of the first set of blocks, and

the first hash value,

determining a fourth hash value based on

a fourth block of the first set of blocks, and

the third hash value.

3. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining, for each respective block of the first set of blocks other than the first block and the second block, a respective hash value based on

the respective block, and

a determined hash value for another block of the first set of blocks other than the second block,

wherein the determining of the second hash value comprises determining the second hash value based on a last determined hash value of the determined respective hash values.

4. The electronic device of claim 1 , wherein the authentication data comprises one or more timestamps associated with the first image data.

5. The electronic device of claim 1 , wherein the authentication data comprises a first identifier associated with the electronic device.

6. The electronic device of claim 1 , wherein the authentication data comprises a serial number, medium access control (MAC) address, or internet protocol (IP) address.

7. The electronic device of claim 1 , wherein the authentication data comprises a timestamp corresponding to a start time of the first block.

8. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

generating a first random code associated with the first image data; and

wherein the determining of the first hash value comprises determining the first hash value based on

the first block of the first set of blocks,

the authentication data, and

the first random code.

9. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

generating a first random code associated with the first image data; and

wherein the determining of the first hash value comprises determining the first hash value based on

the first block of the first set of blocks,

the authentication data, and

the first random code; and

wherein the generating of the encrypted data comprises generating the encrypted data based on

the second hash value,

the key stored at the electronic device, and

the first random code.

10. The electronic device of claim 9 , wherein the first random code is generated using a pseudorandom approach.

11. The electronic device of claim 9 , first random code is generated using a true random approach.

12. The electronic device of claim 1 , wherein the electronic device comprises a secure element, and wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising accessing the key from the secure element.

13. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining a second set of blocks of the plurality of blocks,

determining a third hash value based on

a third block of the second set of blocks, and

second authentication data,

determining a fourth hash value based on

a fourth block of the second set of blocks, and

a hash value that was determined based on a block of the second set of blocks other than the fourth block,

generating second encrypted data based on

the fourth hash value, and

the key stored at the electronic device,

determining second signature data comprising the second authentication data and the second encrypted data,

transmitting to the remote system

data representing the second set of blocks, and

the second signature data.

14. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining a second set of blocks of the plurality of blocks,

determining a third hash value based on

a third block of the second set of blocks, and

the authentication data,

determining a fourth hash value based on

a fourth block of the second set of blocks, and

a hash value that was determined based on a block of the second set of blocks other than the fourth block,

generating second encrypted data based on

the fourth hash value, and

the key stored at the electronic device,

determining second signature data comprising the authentication data and the second encrypted data,

transmitting to the remote system

data representing the second set of blocks, and

the second signature data.

15. The electronic device of claim 14 , wherein the transmitting to the remote system of data representing the second set of blocks comprises transmitting data representing one or more network abstract layer units (NALUs), and wherein the transmitting to the remote system of the second signature data comprises transmitting data representing a supplemental enhancement information (SEI) type NALU that includes the second signature data.

16. The electronic device of claim 1 , wherein the first block represents a macroblock.

17. The electronic device of claim 1 , wherein the first block represents a network abstraction layer unit (NALU).

18. The electronic device of claim 1 , wherein the first block represents a slice.

19. The electronic device of claim 1 , wherein the electronic device is a security camera device or video doorbell device.

20. The electronic device of claim 1 , wherein the electronic device is a smartphone or tablet.

21. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining that a type of a network abstraction layer unit (NALU) matches a certain type;

wherein the determining of the first set of blocks of the plurality of blocks is based on the determining that the type of a network abstraction layer unit (NALU) matches the certain type.

22. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining that a type of a block matches a certain type;

wherein the determining of the first set of blocks of the plurality of blocks is based on the determining that the type of a block matches the certain type.

23. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining to delimit the first set of blocks from a second set of blocks based on detecting a block of a certain type.

24. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining to delimit the first set of blocks from a second set of blocks based on detecting a network abstraction layer unit (NALU) of a certain type.

25. The electronic device of claim 1 , wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

determining to delimit the first set of blocks from a second set of blocks based on detecting a video parameter set (VPS) network abstraction layer unit (NALU) type.

26. The electronic device of claim 1 , wherein the key is stored in encrypted storage.

27. The electronic device of claim 1 , wherein the electronic device comprises anti-fuse-based secure one-time programmable non-volatile memory, and wherein the one or more computer readable media store processor executable instructions which, when executed using the one or more processors, cause the electronic device to perform operations comprising

accessing the key from the anti-fuse-based secure one-time programmable non-volatile memory.

28. A method comprising:

generating first image data using a camera of an electronic device,

generating, based on encoding the first image data, a plurality of blocks,

determining a first set of blocks of the plurality of blocks,

determining a first hash value based on

a first block of the first set of blocks, and

authentication data,

determining a second hash value based on

a second block of the first set of blocks, and

a hash value that was determined based on a block of the first set of blocks other than the second block,

generating encrypted data based on

the second hash value, and

a key stored at the electronic device,

determining signature data comprising the authentication data and the encrypted data,

transmitting from the electronic device to a remote system

data representing the first set of blocks, and

the signature data.

29. The method of claim 28 , wherein encoding the first image data comprises encoding the first image data in accordance with H.264.

30. The method of claim 28 , wherein encoding the first image data comprises encoding the first image data in accordance with H.265.

31. The method of claim 28 , wherein the method comprises

generating a first random code associated with the first image data; and

wherein the determining of the first hash value comprises determining the first hash value based on

the first block of the first set of blocks,

the authentication data, and

the first random code.

32. The method of claim 28 , wherein the method comprises

generating a first random code associated with the first image data; and

wherein the determining of the first hash value comprises determining the first hash value based on

the first block of the first set of blocks,

the authentication data, and

the first random code; and

wherein the generating of the encrypted data comprises generating the encrypted data based on

the second hash value,

the key stored at the electronic device, and

the first random code.

33. A computer readable medium storing executable instructions which, when executed using a processor, cause an electronic device to

generate first image data,

generate, based on encoding the first image data, a plurality of blocks,

determine a first set of blocks of the plurality of blocks,

determine a first hash value based on

a first block of the first set of blocks, and

authentication data,

determine a second hash value based on

a second block of the first set of blocks, and

a hash value determined based on a block of the first set of blocks other than the second block,

generate encrypted data based on

the second hash value, and

a key stored at the electronic device,

determine signature data comprising the authentication data and the encrypted data,

transmit to a remote system

data representing the first set of blocks, and

the signature data.

34. The computer readable medium of claim 33 , wherein the executable instructions, cause the electronic device to

determine a third hash value based on

a third block of the first set of blocks, and

the first hash value,

determine a fourth hash value based on

a fourth block of the first set of blocks, and

the third hash value.

35. The computer readable medium of claim 33 , wherein the executable instructions, cause the electronic device to

determine, for each respective block of the first set of blocks other than the first block and the second block, a respective hash value based on

the respective block, and

a determined hash value for another block of the first set of blocks other than the second block,

wherein the determining of the second hash value comprises determining the second hash value based on a last determined hash value of the determined respective hash values.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNEE ADDRESS PREVIOUSLY RECORDED AT REEL: 67692 FRAME: 230. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 12, 2024
From: SUTER, TIMOTHY GLENN; PHILLIPS, HARVEY EDWARD; CASE, BRYCE EDWARD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 067712/0552 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2024
From: SUTER, TIMOTHY GLENN; PHILLIPS, HARVEY EDWARD; CASE, BRYCE EDWARD
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 067692/0230 →
References Cited (5)
US 20020176577A1 · Xu · 2002 [cited by examiner]
US 20080235517A1 · Ohmori · 2008 [cited by examiner]
US 20130159021A1 · Felsher · 2013 [cited by examiner]
US 20140149395A1 · Nakamura · 2014 [cited by examiner]
US 20150086014A1 · Adkins · 2015 [cited by examiner]
Cited By (2)
US 12,652,418 US 12,750,242