Methods and systems for encoding and protecting data using digital signature and watermarking techniques
    1.
    发明授权
    Methods and systems for encoding and protecting data using digital signature and watermarking techniques 有权
    使用数字签名和水印技术编码和保护数据的方法和系统

    公开(公告)号:US08099601B2

    公开(公告)日:2012-01-17

    申请号:US12788118

    申请日:2010-05-26

    IPC分类号: G06F21/00

    摘要: Systems and methods are provided for protecting and managing electronic data signals that are registered in accordance with a predefined encoding scheme, while allowing access to unregistered data signals. In one embodiment a relatively hard-to-remove, easy-to-detect, strong watermark is inserted in a data signal. The data signal is divided into a sequence of blocks, and a digital signature for each block is embedded in the signal via a watermark. The data signal is then stored and distributed on, e.g., a compact disc, a DVD, or the like. When a user attempts to access or use a portion of the data signal, the signal is checked for the presence of a watermark containing the digital signature for the desired portion of the signal. If the watermark is found, the digital signature is extracted and used to verify the authenticity of the desired portion of the signal. If the signature-containing watermark is not found, the signal is checked for the presence of the strong watermark. If the strong watermark is found, further use of the signal is inhibited, as the presence of the strong watermark, in combination with the absence or corruption of the signature-containing watermark, provides evidence that the signal has been improperly modified. If, on the other hand, the strong mark is not found, further use of the data signal can be allowed, as the absence of the strong mark indicates that the data signal was never registered with the signature-containing watermark.

    摘要翻译: 提供了系统和方法,用于保护和管理根据预定编码方案注册的电子数据信号,同时允许访问未注册的数据信号。 在一个实施例中,相对难以移除的易于检测的强水印被插入到数据信号中。 数据信号被分成块序列,每个块的数字签名通过水印被嵌入在信号中。 然后将数据信号存储并分布在例如光盘,DVD等上。 当用户尝试访问或使用数据信号的一部分时,检查信号是否存在包含用于信号的期望部分的数字签名的水印。 如果发现水印,则提取数字签名并用于验证信号所需部分的真实性。 如果没有找到包含签名的水印,则检查该信号是否存在强水印。 如果发现强水印,则抑制了信号的进一步使用,因为强水印的存在与含签名的水印的不存在或破坏相结合,提供了信号被不正确地修改的证据。 另一方面,如果没有发现强标记,则可以允许进一步使用数据信号,因为没有强标记表示数据信号从未向含有签名的水印注册。

    Trust management systems and methods
    2.
    发明授权
    Trust management systems and methods 有权
    信托管理体系和方法

    公开(公告)号:US07971055B2

    公开(公告)日:2011-06-28

    申请号:US12147264

    申请日:2008-06-26

    IPC分类号: H04L9/00

    摘要: The present invention provides systems and methods for making efficient trust management decisions. A trust management engine is provided that processes requests for system resources, authorizations or certificates, and the identity of one or more root authorities that are ultimately responsible for granting or denying the requests. To determine whether a request should be granted, the trust management engine identifies a set principals from whom authorization may flow, and interprets each of the certificates as a function of the state of one or more of the principals. The processing logic iteratively evaluates the functions represented by the certificates, updates the states of the principals, and repeats this process until a reliable determination can be made as to whether the request should be granted or denied. The certificates may be evaluated until the state of the root authority indicates that the request should be granted, or until further evaluation of the certificates is ineffective in changing the state of the principals.

    摘要翻译: 本发明提供了用于进行有效信任管理决策的系统和方法。 提供了一个信任管理引擎来处理对系统资源,授权或证书的请求以及最终负责授予或拒绝请求的一个或多个root权限的身份。 为了确定是否应该授予请求,信任管理引擎识别从其授权可能流动的集合主体,并且将每个证书解释为一个或多个主体的状态的函数。 处理逻辑迭代地评估由证书表示的功能,更新主体的状态,并重复该过程,直到可以确定是否应该请求被授予或被拒绝为止。 可以评估证书,直到根管理员的状态表明该请求应被授予,或者直到进一步评估证书在改变主体状态方面无效时。

    Systems and Methods for Authenticating and Protecting the Integrity of Data Streams and Other Data
    3.
    发明申请
    Systems and Methods for Authenticating and Protecting the Integrity of Data Streams and Other Data 有权
    用于认证和保护数据流和其他数据完整性的系统和方法

    公开(公告)号:US20110126084A1

    公开(公告)日:2011-05-26

    申请号:US13018274

    申请日:2011-01-31

    IPC分类号: G06F21/24 G06F11/07

    摘要: Systems and methods are disclosed for enabling a recipient of a cryptographically-signed electronic communication to verify the authenticity of the communication on-the-fly using a signed chain of check values, the chain being constructed from the original content of the communication, and each check value in the chain being at least partially dependent on the signed root of the chain and a portion of the communication. Fault tolerance can be provided by including error-check values in the communication that enable a decoding device to maintain the chain's security in the face of communication errors. In one embodiment, systems and methods are provided for enabling secure quasi-random access to a content file by constructing a hierarchy of hash values from the file, the hierarchy deriving its security in a manner similar to that used by the above-described chain. The hierarchy culminates with a signed hash that can be used to verify the integrity of other hash values in the hierarchy, and these other hash values can, in turn, be used to efficiently verify the authenticity of arbitrary portions of the content file.

    摘要翻译: 公开了系统和方法,用于使密码签名的电子通信的接收者能够使用签署的检查值链来验证通信的真实性,该链由正在通信的原始内容构成,并且每个 检查链中的值至少部分地取决于链的签名根和通信的一部分。 可以通过在通信中包括错误检查值来提供容错,使得解码设备能够在面对通信错误时保持链的安全性。 在一个实施例中,提供了系统和方法,用于通过从文件中构建散列值的层级来实现对内容文件的安全准随机访问,层级以与上述链类似的方式导出其安全性。 层次结构最终得到一个可用于验证层次结构中其他哈希值的完整性的签名散列,而这些哈希值又可用于有效地验证内容文件的任意部分的真实性。

    Systems and methods for authenticating and protecting the integrity of data streams and other data
    4.
    发明授权
    Systems and methods for authenticating and protecting the integrity of data streams and other data 有权
    用于认证和保护数据流和其他数据完整性的系统和方法

    公开(公告)号:US07882351B2

    公开(公告)日:2011-02-01

    申请号:US12038664

    申请日:2008-02-27

    IPC分类号: H04L29/06

    摘要: Systems and methods are disclosed for enabling a recipient of a cryptographically-signed electronic communication to verify the authenticity of the communication on-the-fly using a signed chain of check values, the chain being constructed from the original content of the communication, and each check value in the chain being at least partially dependent on the signed root of the chain and a portion of the communication. Fault tolerance can be provided by including error-check values in the communication that enable a decoding device to maintain the chain's security in the face of communication errors. In one embodiment, systems and methods are provided for enabling secure quasi-random access to a content file by constructing a hierarchy of hash values from the file, the hierarchy deriving its security in a manner similar to that used by the above-described chain. The hierarchy culminates with a signed hash that can be used to verify the integrity of other hash values in the hierarchy, and these other hash values can, in turn, be used to efficiently verify the authenticity of arbitrary portions of the content file.

    摘要翻译: 公开了系统和方法,用于使密码签名的电子通信的接收者能够使用签署的检查值链来验证通信的真实性,该链由正在通信的原始内容构成,并且每个 检查链中的值至少部分地取决于链的签名根和通信的一部分。 可以通过在通信中包括错误检查值来提供容错,使得解码设备能够在面对通信错误时保持链的安全性。 在一个实施例中,提供了系统和方法,用于通过从文件中构建散列值的层级来实现对内容文件的安全准随机访问,层级以与上述链类似的方式导出其安全性。 层次结构最终得到一个可用于验证层次结构中其他哈希值的完整性的签名散列,而这些哈希值又可用于有效地验证内容文件的任意部分的真实性。

    Methods and systems for encoding and protecting data using digital signature and watermarking techniques
    7.
    发明授权
    Methods and systems for encoding and protecting data using digital signature and watermarking techniques 失效
    使用数字签名和水印技术编码和保护数据的方法和系统

    公开(公告)号:US06961854B2

    公开(公告)日:2005-11-01

    申请号:US10897001

    申请日:2004-07-23

    摘要: Systems and methods are provided for protecting and managing electronic data signals that are registered in accordance with a predefined encoding scheme, while allowing access to unregistered data signals. In one embodiment a relatively hard-to-remove, easy-to-detect, strong watermark is inserted in a data signal. The data signal is divided into a sequence of blocks, and a digital signature for each block is embedded in the signal via a watermark. The data signal is then stored and distributed on, e.g., a compact disc, a DVD, or the like. When a user attempts to access or use a portion of the data signal, the signal is checked for the presence of a watermark containing the digital signature for the desired portion of the signal. If the watermark is found, the digital signature is extracted and used to verify the authenticity of the desired portion of the signal. If the signature-containing watermark is not found, the signal is checked for the presence of the strong watermark. If the strong watermark is found, further use of the signal is inhibited, as the presence of the strong watermark, in combination with the absence or corruption of the signature-containing watermark, provides evidence that the signal has been improperly modified. If, on the other hand, the strong mark is not found, further use of the data signal can be allowed, as the absence of the strong mark indicates that the data signal was never registered with the signature-containing watermark.

    摘要翻译: 提供了系统和方法,用于保护和管理根据预定编码方案注册的电子数据信号,同时允许访问未注册的数据信号。 在一个实施例中,相对难以移除的易于检测的强水印被插入到数据信号中。 数据信号被分成块序列,每个块的数字签名通过水印被嵌入在信号中。 然后将数据信号存储并分布在例如光盘,DVD等上。 当用户尝试访问或使用数据信号的一部分时,检查信号是否存在包含用于信号的期望部分的数字签名的水印。 如果发现水印,则提取数字签名并用于验证信号所需部分的真实性。 如果没有找到包含签名的水印,则检查该信号是否存在强水印。 如果发现强水印,则抑制了信号的进一步使用,因为强水印的存在与含签名的水印的不存在或破坏相结合,提供了信号被不正确地修改的证据。 另一方面,如果没有发现强标记,则可以允许进一步使用数据信号,因为没有强标记表示数据信号从未向含有签名的水印注册。

    Systems and methods for authenticating and protecting the integrity of data streams and other data

    公开(公告)号:US06959384B1

    公开(公告)日:2005-10-25

    申请号:US09543750

    申请日:2000-04-05

    IPC分类号: G06F21/00 H04L9/00 H04L9/32

    摘要: Systems and methods are disclosed for enabling a recipient of a cryptographically-signed electronic communication to verify the authenticity of the communication on-the-fly using a signed chain of check values, the chain being constructed from the original content of the communication, and each check value in the chain being at least partially dependent on the signed root of the chain and a portion of the communication. Fault tolerance can be provided by including error-check values in the communication that enable a decoding device to maintain the chain's security in the face of communication errors. In one embodiment, systems and methods are provided for enabling secure quasi-random access to a content file by constructing a hierarchy of hash values from the file, the hierarchy deriving its security in a manner similar to that used by the above-described chain. The hierarchy culminates with a signed hash that can be used to verify the integrity of other hash values in the hierarchy, and these other hash values can, in turn, be used to efficiently verify the authenticity of arbitrary portions of the content file.

    Methods and systems for encoding and protecting data using digital signature and watermarking techniques
    9.
    发明授权
    Methods and systems for encoding and protecting data using digital signature and watermarking techniques 有权
    使用数字签名和水印技术编码和保护数据的方法和系统

    公开(公告)号:US06785815B1

    公开(公告)日:2004-08-31

    申请号:US09588652

    申请日:2000-06-07

    IPC分类号: G06F126

    摘要: Systems and methods are provided for protecting and managing electronic data signals that are registered in accordance with a predefined encoding scheme, while allowing access to unregistered data signals. In one embodiment a relatively hard-to-remove, easy-to-detect, strong watermark is inserted in a data signal. The data signal is divided into a sequence of blocks, and a digital signature for each block is embedded in the signal via a watermark. The data signal is then stored and distributed on, e.g., a compact disc, a DVD, or the like. When a user attempts to access or use a portion of the data signal, the signal is checked for the presence of a watermark containing the digital signature for the desired portion of the signal. If the watermark is found, the digital signature is extracted and used to verify the authenticity of the desired portion of the signal. If the signature-containing watermark is not found, the signal is checked for the presence of the strong watermark. If the strong watermark is found, further use of the signal is inhibited, as the presence of the strong watermark, in combination with the absence or corruption of the signature-containing watermark, provides evidence that the signal has been improperly modified. If, on the other hand, the strong mark is not found, further use of the data signal can be allowed, as the absence of the strong mark indicates that the data signal was never registered with the signature-containing watermark.

    摘要翻译: 提供了系统和方法,用于保护和管理根据预定编码方案注册的电子数据信号,同时允许访问未注册的数据信号。 在一个实施例中,相对难以移除的易于检测的强水印被插入到数据信号中。 数据信号被分成块序列,每个块的数字签名通过水印被嵌入在信号中。 然后将数据信号存储并分布在例如光盘,DVD等上。 当用户尝试访问或使用数据信号的一部分时,检查信号是否存在包含用于信号的期望部分的数字签名的水印。 如果发现水印,则提取数字签名并用于验证信号所需部分的真实性。 如果没有找到包含签名的水印,则检查该信号是否存在强水印。 如果发现强水印,则抑制了信号的进一步使用,因为强水印的存在与含签名的水印的不存在或破坏相结合,提供了信号被不正确地修改的证据。 另一方面,如果没有发现强标记,则可以允许进一步使用数据信号,因为没有强标记表示数据信号从未向含有签名的水印注册。