EP2645291A1

System and method enabling parallel processing of hash functions using authentication checkpoint hashes

Abstract

Systems and methods allowing parallel processing of hash functions when carrying out integrity verification of executable code and/or data authentication. A data string including a plurality of pieces arranged in an order is initially hashed using a hash function to determine a plurality of reference authentication checkpoint hashes associated with the pieces. To subsequently verify the integrity of the data string, the pieces are grouped into sets. The reference authentication checkpoint hash associated with the piece following all other pieces of each set in the order is associated with that set. The system performs, in parallel, a separate verification process on each set, wherein the pieces of the set are first hashed to determine a result hash, which is then compared with the reference authentication checkpoint hash associated with the set. The initial input to the hash function for the hash process for each set includes one of the pieces and either a default seed or an authentication checkpoint hash.

EP2645291A1, drawing sheet 1
Sheet 1 of 10

Term

Projected expiry 25 March 2033.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

12 claims: 2 independent, 10 dependent

  1. 1
    A system comprising:at least one processor;at least one display device;andat least one memory device storing a plurality of instructions which, when executed by the at least one processor, cause the at least one processor to operate with the at least one display device to: (a) for a first piece of a program code, the program code including a plurality of pieces: (i) hash the first piece of the program code and a default seed to obtain a first result hash;(ii) determine whether the first result hash is the same as a first authentication checkpoint hash;(iii) if the first result hash is the same as the first authentication checkpoint hash, authorize the first piece of the program code for execution;and(iv) if the first result hash is not the same as the first authentication checkpoint hash, do not authorize the first piece of the program code for execution;(b) for a second different piece of the program code: (i) hash the second piece of the program code and the first authentication checkpoint hash to obtain a second result hash;(ii) determine whether the second result hash is the same as a second authentication checkpoint hash;(iii) if the second result hash is the same as the second authentication checkpoint hash, authorize the second piece of the program code for execution;and(iv) if the second result has is not the same as the second authentication checkpoint hash, do not authorize the second piece of the program code for execution;and(c) if each of the pieces of the program code are authorized for execution, execute the program code and display an image generated by the executed program code.
  2. 6
    A method comprising:(a) for a first piece of a program code, the program code including a plurality of pieces, causing at least one processor to execute a plurality of instructions stored in at least one memory device to: (i) hash the first piece of the program code and a default seed to obtain a first result hash;(ii) determine whether the first result hash is the same as a first authentication checkpoint hash;(iii) if the first result hash is the same as the first authentication checkpoint hash, authorize the first piece of the program code for execution;and(iv) if the first result hash is not the same as the first authentication checkpoint hash, do not authorize the first piece of the program code for execution;(b) for a second different piece of the program code, causing the at least one processor to execute the plurality of instructions to: (i) hash the second piece of the program code and the first authentication checkpoint hash to obtain a second result hash;(ii) determine whether the second result hash is the same as a second authentication checkpoint hash;(iii) if the second result hash is the same as the second authentication checkpoint hash, authorize the second piece of the program code for execution;and(iv) if the second result has is not the same as the second authentication checkpoint hash, do not authorize the second piece of the program code for execution;and(c) if each of the pieces of the program code are authorized for execution, causing the at least one processor to execute the plurality of instructions to execute the program code and operate with at least one display device to display an image generated by the executed program code.
Independent claims2