EP1069745A1

Server computer providing integrity of files stored in it

Abstract

The problem of the vulnerability of electronic content stored on server computers to alteration by unauthorised third parties is one which has become much exacerbated with the advent of the Internet and the World Wide Web. Present day approaches, including approaches based on digital signature techniques, allow for the checking of content transmitted over communications networks to, for example, client computers, to establish if tampering by unauthorised third parties has occurred. Such approaches all suffer from the disadvantage that any content which has been tampered with is still transmitted over the network to the client computer before such a check takes place. According to the invention however, a server computer storing computer files, each computer file having an associated unique digital signature, receiving requests for access to one or more such computer files, only allows access to the or each computer file if their associated digital signatures are valid. Thus, if a computer file has been tampered with by an unauthorised third party, the digital signature associated with that computer file will prove to be invalid when checked and the server computer will not serve the computer file at all. In this way, a computer file that has been tampered with can never leave the server computer, much improving the security of the stored computer files.

EP1069745A1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 13 July 2019, 7.2 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

6 claims: 4 independent, 2 dependent

  1. 1
    A server computer comprising:means arranged to store one or more computer files;means arranged to store one or more digital signatures;each computer file having an associated digital signature;means arranged to allow a connection between the file server computer and at least one other computer;means arranged to receive requests from another computer for access to at least one computer file stored on said server computer;means arranged to retrieve the or each requested computer file;means arranged to retrieve the digital signature associated with the or each requested computer file;means arranged to validate the digital signature associated with the or each requested computer file;and means arranged to provide said other computer with access to the or each requested computer file only when the digital signature associated with the or each respective requested computer file is valid.
  2. 4
    A server computer as claimed in any one of claims 1 to 3 further comprising a clock, wherein the or each computer file stored on said server computer has an associated expiry date; such that:said means arranged to validate the digital signature associated with the or each requested computer file only validates said digital signature if the expiry date associated with the or each computer file is later than the current clock date.
  3. 5
    A server computer arranged to store one or more computer files, one or more digital signatures, each computer file having an associated digital signature, said server computer being arranged to perform the operation of:receiving a connection from another computer;receiving a request from said other computer for access to at least one computer file stored on said server computer;retrieving the or each requested computer file;retrieving the digital signature associated with the or each requested computer file;validating the digital signature associated with the or each requested computer file;and providing said other computer with access to the or each requested computer file only if the digital signature associated with the or each requested computer file is valid.
  4. 6
    A method of operating a server computer comprising:receiving a connection from another computer;receiving a request from said other computer for access to at least one computer file stored on said file server computer;each said computer file having an associated unique digital signature stored on said file server computer;retrieving the or each requested computer file;retrieving the digital signature associated with the or each requested computer file;validating the unique digital signature associated with the or each requested computer file;and providing said other computer with access to the or each requested computer file only if the digital signature associated with the or each requested computer file is valid.