EP0845733A2

Implementing digital signatures for data streams and data archives

Abstract

Methods, apparatuses and products are provided for establishing and verifying the authenticity of data within one or more data files. In accordance with one aspect of the present invention, a method for verifying the authenticity of data involves providing at least one data file which includes an identifier and a signature file which includes the identifier for the data file as well as a digital signature. The digital signature is then verified using a computer system, and the identifier in the data file is compared with the identifier in the signature file using the computer system. In one embodiment, the identifier for the data file includes at least one certificate authority, site certificate, software publisher identifier, or a site name, and verifying the authenticity of data involves setting a security level for at least one of the certificate authority, said site certificate, said software publisher identifier, and said site name.

EP0845733A2, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 24 November 2017, 8.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

21 claims: 12 independent, 9 dependent

  1. 1
    A computer-implemented method for verifying the authenticity of data, the method comprising:receiving at least one data file and a signature file, wherein the data file and the signature file are separate, the data file including an identifier, the signature file including the identifier for the data file and a digital signature;and processing the signature file using a computer system to determine the authenticity of the signature file.
  2. 4
    The method as recited in one of claims 2 and 3 wherein when the identifiers in the data and signature files do not match, the method further includes at least one selected from the group of ignoring the data file, aborting the loading of the data file, and alerting a user, when the identifiers in the data and signature files do not match.
  3. 5
    A computer-implemented method for verifying the authenticity of data as recited in one of claims 2-4 wherein comparing the identifier in the data file with the identifier in the signature file using the computer system is repeated for a second data file.
  4. 6
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein processing the digital signature further includes verifying the digital signature with a signature algorithm, the signature algorithm being a keyed algorithm, wherein the signature algorithm is selected from a group consisting of a DSA algorithm, and a combined Message Digest and RSA algorithm.
  5. 7
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein the identifier is generated using one of a one-way hash function algorithm and a cyclic redundancy checksum algorithm.
  6. 8
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein comparing the identifier in the data file with the identifier in the signature file further includes generating one or more of the identifiers with a one-way hash function algorithm.
  7. 9
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein comparing the identifier in the data file with the identifier in the signature file further includes checking one or more of the identifiers with a cyclic redundancy checksum algorithm.
  8. 10
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein receiving the data file and the signature file further includes transferring the data file and the signature file among networked computers.
  9. 11
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims wherein:the identifier in the data file includes at least one of a certificate authority, a site certificate, a software publisher identifier, and a site name;and the method includes setting a security level for at least one of said certificate authority, said site certificate, said software publisher identifier, and said site name.
  10. 16
    A computer-implemented method for verifying the authenticity of data as recited in any one of the preceding claims, further including establishing a data communication connection with a remote site using the computer system, determining whether the site requires a secure connection, and determining whether a site certificate for the site is valid in response to a determination that a secure connection is required.
  11. 17
    An apparatus for verifying the authenticity of at least one data file and a signature file, the data file including an identifier, the signature file including the identifier for the data file and a digital signature, the apparatus comprising:a processor for processing the digital signature to determine the authenticity of the signature file;and a comparator for comparing the identifier in the data file with the identifier in the signature file using the computer system to determine the authenticity of the data file, wherein the processor is further arranged to process the digital signature using the computer system to determine the authenticity of the signature file.
  12. 19
    A computer program product including a computer-usable medium having computer-readable program code embodied thereon for use in verifying the authenticity of data, the computer program product including computer-readable program code for effecting the following with a computer system:a) receiving at least one data file and a signature file, the data file including an identifier, the signature file including the identifier for the data file and a digital signature;and b) processing the signature file using a computer system to determine the authenticity of the signature file.
Independent claims12