IP Library › Granted Patent US 8,732,473
Granted Patent B2
US 8,732,473 · App. 12/791,305 · Granted May 20, 2014

Claim based content reputation service

Inventors: Robert Bisso (Saint James, NY); Vadim Ismailov (Holtsville, NY); Lingling Liu (Commack, NY); Robert Saccone (Glen Head, NY); Mukeshkumar Beher (Smithtown, NY)
Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,473
App. No.
12/791,305
Granted
May 20, 2014
Kind
B2
Abstract

In some embodiments, a system may comprise a database and one or more servers. The database may, for example, store a plurality of content claims for previously evaluated data items, with each of the plurality of content claims being associated in the database with a corresponding stored digital fingerprint of a previously evaluated data item. The server(s) may, for example, be configured to receive a determined digital fingerprint of a data item from a client device on another network node, to submit a query to the database using the determined digital fingerprint as a primary key, and to transmit one or more content claims returned by the query to the client device. In some embodiments, the server(s) may be further configured to receive the content claim(s) and the digital fingerprint associated therewith from one or more computers on another network node, and to cause the received content claim(s) and digital fingerprint associated therewith to be stored in the database.

Claims (72)

1. A method comprising:

receiving, by a server, a plurality of content claims for a data item, the plurality of content claims for the data item including content claims submitted by a plurality of different issuers that scanned the data item for malicious content, wherein each content claim of the plurality of content claims for the data item identifies an issuer that submitted the content claim, indicates timing and results of a scan performed by the issuer, and is submitted with a digital fingerprint of the data item calculated by the issuer using a hash function;

storing, by the server, the plurality of content claims for the data item in a database that associates each content claim of the plurality of content claims for the data item with a digital signature of the data item that was submitted with the content claim;

grouping, by the server, multiple content claims of the plurality of content claims for the data item that were submitted by different issuers with a same digital fingerprint of the data item, wherein the same digital fingerprint of the data item was calculated by the different issuers using a particular hash function;

receiving, by the server from a computing device, a request to retrieve existing content claims associated with a piece of data, the request including a determined digital fingerprint of the piece of data calculated by the computing device using the particular hash function;

retrieving, by the server in response to the request, a content claim set including the multiple content claims of the plurality of content claims for the data item that were submitted by different issuers upon determining that:

the determined digital fingerprint of the piece of data matches the same digital fingerprint of the data item associated with each of the multiple content claims, and

each of the multiple content claims was issued within a predetermined time period; and

returning, by the server to the computing device, the content claim set for allowing the computing device to determine whether to scan the piece of data for malicious content.

2. The method of claim 1 , further comprising:

receiving, by the server, a new content claim for the data item; and

evaluating, by the server, the new content claim for the data item against any stored content claims for the data item that are associated with a digital fingerprint of the data item submitted with the new content claim.

3. The method of claim 2 , wherein:

each content claim of the plurality of content claims for the data item further identifies an antivirus application used to perform the scan and a version of the antivirus application,

the new content claim for the data item indicates timing and results of a scan performed by the computing device on the piece of data using a more recent version of an antivirus application identified by at least one of the multiple content claims.

4. The method of claim 1 , further comprising:

verifying, by the server, that each content claim of the plurality of content claims for the data item was submitted by a trusted issuer.

5. The method of claim 1 , further comprising:

digitally signing a message used to transmit the content claim set to the computing device that sent the request.

6. The method of claim 1 , further comprising:

receiving, by the server, a content certificate for each content claim of the plurality of content claims for the data item, wherein each content certificate is signed by a trusted certificate authority and identifies a product used to create the content claim.

7. The method of claim 1 , wherein the content claim set comprises:

a content claim indicating results of an antivirus scan performed by a first issuer, and

a content claim indicating results of a malware scan performed by a second issuer.

8. A computer-readable storage device storing computer-executable instructions that, when executed by a computer, cause the computer to perform a method comprising:

receiving a plurality of content claims for a data item, the plurality of content claims for the data item including content claims submitted by a plurality of different issuers that evaluated the data item for malicious content, wherein each content claim of the plurality of content claims for the data item identifies an issuer that submitted the content claim, indicates timing and results of a scan performed by the issuer, and is submitted with a digital fingerprint of the data item calculated by the issuer using a hash function;

storing the plurality of content claims for the data item in a database that associates each content claim of the plurality of content claims for the data item with a digital signature of the data item that was submitted with the content claim;

grouping multiple content claims of the plurality of content claims for the data item that were submitted by different issuers with a same digital fingerprint of the data item, wherein the same digital fingerprint of the data item was calculated by the different issuers using a particular hash function;

receiving, from a computing device, a request to retrieve existing content claims associated with a piece of data, the request including a determined digital fingerprint of the piece of data calculated by the computing device using the particular hash function;

retrieving, in response to the request, a content claim set including the multiple content claims of the plurality of content claims for the data item that were submitted by different issuers upon determining that:

the determined digital fingerprint of the piece of data matches the same digital fingerprint of the data item associated with each of the multiple content claims, and

each of the multiple content claims was issued within a predetermined time period; and

returning, to the computing device, the content claim set for allowing the computing device to determine whether to scan the piece of data for malicious content.

9. The computer-readable storage device of claim 8 , wherein the method further comprises:

receiving a new content claim for the data item; and

evaluating the new content claim for the data item against any stored content claims for the data item that are associated with a digital fingerprint of the data item submitted with the new content claim.

10. The computer-readable storage device of claim 9 , wherein:

each content claim of the plurality of content claims for the data item further identifies an antivirus application used to perform the scan and a version of the antivirus application,

the new content claim for the data item indicates timing and results of a scan performed by the computing device on the piece of data using a more recent version of an antivirus application identified by at least one of the multiple content claims.

11. The computer-readable storage device of claim 8 , wherein the content claim set comprises:

a content claim indicating results of an antivirus scan performed by a first issuer, and

a content claim indicating results of a malware scan performed by a second issuer.

12. The computer-readable storage device of claim 8 , wherein the method further comprises:

digitally signing a message used to transmit the content claim set to the computing device that sent the request.

13. The computer-readable storage device of claim 8 , wherein the method further comprises:

receiving a content certificate for each content claim of the plurality of content claims for the data item, wherein each content certificate is signed by a trusted certificate authority and identifies a product used to create the content claim.

14. The computer-readable storage device of claim 8 , wherein the method further comprises:

verifying that each content claim of the plurality of content claims for the data item was submitted by a trusted issuer.

15. A system, comprising:

a processor configured to execute computer-executable instructions; and

memory storing computer-executable instructions for:

receiving a plurality of content claims for a data item, the plurality of content claims for the data item including content claims submitted by a plurality of different issuers that evaluated the data item for malicious content, wherein each content claim of the plurality of content claims for the data item identifies an issuer that submitted the content claim, indicates timing and results of a scan performed by the issuer, and is submitted with a digital fingerprint of the data item calculated by the issuer using a hash function;

storing the plurality of content claims for the data item in a database that associates each content claim of the plurality of content claims for the data item with a digital signature of the data item that was submitted with the content claim;

grouping multiple content claims of the plurality of content claims for the data item that were submitted by different issuers with a same digital fingerprint of the data item, wherein the same digital fingerprint of the data item was calculated by the different issuers using a particular hash function;

receiving, from a computing device, a request to retrieve existing content claims associated with a piece of data, the request including a determined digital fingerprint of the piece of data calculated by the computing device using the particular hash function;

retrieving, in response to the request, a content claim set including the multiple content claims of the plurality of content claims for the data item that were submitted by different issuers upon determining that:

the determined digital fingerprint of the piece of data matches the same digital fingerprint of the data item associated with each of the multiple content claims, and

each of the multiple content claims was issued within a predetermined time period; and

returning, to the computing device, the content claim set for allowing the computing device to determine whether to scan the piece of data for malicious content.

16. The system of claim 15 , wherein the memory further stores computer-executable instructions for:

receiving a new content claim for the data item; and

evaluating the new content claim for the data item against any stored content claims for the data item that are associated with a digital fingerprint of the data item submitted with the new content claim.

17. The system of claim 16 , wherein:

each content claim of the plurality of content claims for the data item further identifies an antivirus application used to perform the scan and a version of the antivirus application,

the new content claim for the data item indicates timing and results of a scan performed by the computing device on the piece of data using a more recent version of an antivirus application identified by at least one of the multiple content claims.

18. The system of claim 15 , wherein the content claim set comprises:

a content claim indicating results of an antivirus scan performed by a first issuer, and

a content claim indicating results of a malware scan performed by a second issuer.

19. The system of claim 15 , wherein the memory further stores computer-executable instructions for:

digitally signing a message used to transmit the content claim set to the computing device that sent the request.

20. The system of claim 15 , wherein the memory further stores computer-executable instructions for:

receiving a content certificate for each content claim of the plurality of content claims for the data item, wherein each content certificate is signed by a trusted certificate authority and identifies a product used to create the content claim.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2010
From: BISSO, ROBERT; ISMAILOV, VADIM; LIU, LINGLING; SACCONE, ROBERT; BEHER, MUKESHKUMAR
To: MICROSOFT CORPORATION
Reel/Frame 024774/0667 →
Continuity (1)
Related Publication 20110296187A1 · Dec 1, 2011