Digital file management and imaging system and method including secure file marking
Abstract
The digital file management and imaging system and method of the present invention record additional independent data with each stored image including: a “true date” which is gleaned from a secure clock which is not settable by the user (the Authentidate™); a number derived from a cyclic redundancy code (CRC) algorithm against the image data; this number is called the “image CRC”; and a CRC derived from the “true date”, called the “date CRC”. This additional data is recorded within each digital file as soon as possible after the file is acquired. If the file is altered in any way after the recording of the additional data, recalculation of the image CRC on the altered file will not match the original image CRC recorded within it. Thus, the fact that it has been altered can be detected. Likewise, if the true date is altered in any way, recalculation of the date CRC will similarly reveal this fact. The image and date CRCs can be checked and verified at any time. If the recalculated value matches the recorded value, it can be stated that the image presently recorded was recorded on the specified date and has not been altered in any way since then.
Claims
exact text as granted — not AI-modified1 - 32 . (canceled)
33 . A system for maintaining trust in the content of a digital data file, comprising:
a trusted time source to provide a certifiable time for an unalterable time stamp, wherein said certifiable time confirms at least one of said file's access creation, modification, receipt, or transmission; means for receiving a request to save the file from a user; first means for saving the file at a moment in time; means for retrieving from said trusted time source a date and a time corresponding to said moment in time, wherein said moment in time is substantially the current time at said trusted time source corresponding to receipt of said request; first means for appending said date and said time retrieved from said trusted time source to said saved file; first means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto; means for hashing said signed file to produce a digest; second means for signing said digest with a key to produce a certificate; second means for appending said certificate to said saved file; and second means for saving said saved file with said certificate appended thereto.
34 . The system according to claim 33 , wherein said first signing means comprises means for signing said saved file with said date and time retriever from said trusted time source appended thereto with a user identifier.
35 . The system according to claim 33 , wherein said first signing means comprises means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
36 . The system according to claim 33 , wherein said first signing means comprises:
first means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a user identifier; and second means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
37 . The system according to claim 33 , wherein said hashing function comprises a cryptographic key.
38 . A method of maintaining trust in the content of a digital data file, comprising:
providing a trusted time source to provide a certifiable time for an unalterable time stamp, wherein said certifiable time confirms at least one of said file's access, creation, modification, receipt, or transmission; receiving a request to save the file from a user; saving the file at a moment in time; retrieving from said trusted time source a date and a time corresponding to said moment in time, wherein said moment in time is substantially the current time at said trusted time source corresponding to receipt of said request; appending said date and said time retrieved from said trusted time source to said saved file; signing said saved file with said date and said time retrieved from said trusted time source appended thereto; hashing said signed file to produce a digest; signing said digest with a key to produce a certificate; appending said certificate to said saved file; and saving said file with said certificate appended thereto.
39 . The method according to claim 38 , wherein said first signing step comprises signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a user identifier.
40 . The method according to claim 38 , wherein said first signing step comprises signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
41 . The method according to claim 38 , wherein said first signing step comprises:
signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a user identifier; and signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
42 . The method according to claim 38 , wherein said hashing function comprises a cryptographic key.
43 . Apparatus for maintaining trust in the content of a digital data file, comprising:
computing means, including a central processing unit (CPU), means for storing an operating system that is adapted to control the CPU, the plurality of digital data files, one or more applications programs for accessing, creating, modifying, and transmitting the plurality of digital data files, and means for controlling storage and retrieval of the plurality of digital data files to and from said storage means; and fraud prevention means, operatively coupled to said computing means, said fraud prevention module including: a trusted time source to provide a certifiable time for an unalterable time stamD wherein said certifiable time confirms at least one of said file's access, creation, modification, receipt, or transmission; means for receiving a request to save the file from a user; first means for saving the file at a moment in time; means for retrieving from said trusted time source a date and a time corresponding to said moment in time, wherein said moment in time is substantially the current time at said trusted time source corresponding to receipt of said request; first means for appending said date and said time retrieved from said trusted time source to said saved file; first means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto; means for hashing said signed file to produce a digest; second means for signing said digest with a key to produce a certificate; second means for appending said certificate to said saved file; and second means for saving said file with said certificate appended thereto.
44 . The apparatus according to claim 43 , wherein said first signing means comprises means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a user identifier.
45 . The apparatus according to claim 43 , wherein said first signing means comprises means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
46 . The apparatus according to claim 43 , wherein said first signing means comprises:
first means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a user identifier; and second means for signing said saved file with said date and said time retrieved from said trusted time source appended thereto with a system identifier.
47 . A personal computer system for maintaining trust in content of a digital data file, comprising:
a personal computer having installed therein a trusted time source to provide a certifiable time for an unalterable time stamp, wherein said certifiable time confirms at least one of said digital data file's access, creation, modification, receipt, or transmission; means for receiving a request to save said digital data file from a user; first means for saving said digital data file at a moment in time; means for retrieving from said trusted time source a date and a time corresponding to said moment in time, wherein said moment in time is substantially a current time of said trusted time source corresponding to receipt of said request; first means for appending said date and said time retrieved from said trusted time source to said digital data file; first means for signing said digital data file with said date and said time retrieved from said trusted time source appended thereto; means for hashing said digital data file to produce a digest; second means for signing said digest with a key to produce a certificate; second means for appending said certificate to said digital data file; second means for saving said digital data file with said certificate appended thereto; and means for verifying trust in the content of said digital data file with said certificate appended thereto.
48 . The personal computer system according to claim 47 , wherein said trusted time source includes a tamper-evident means.
49 . The personal computer system according to claim 47 , wherein said verification means includes a third means for signing said digital data file with said date and said time retrieved from said trusted time source appended thereto with an identifier.
50 . The personal computer system according to claim 49 , wherein said identifier is selected from the group consisting of an identifier corresponding to said user, an identifier corresponding to a system used by said user, and an identifier corresponding to an enterprise within which said user uses the personal computer system.
51 . The personal computer system according to claim 50 , wherein said user identifier is selected from the group consisting of a plurality of characters identifying said user, first data representing an iris scan of said user, second data representing a retina scan of said user, third data representing a finger scan of said user, fourth data representing said user's hand geometry, fifth data representing said user's voice, sixth data representing said user's signature, and combinations of said plurality of characters, first, second, third, fourth, fifth, and sixth data.
52 . The personal computer system according to claim 47 , wherein said trusted time source comprises:
a real time clock; and a battery coupled to and powering said real time clock.
53 . The personal computer system according to claim 52 , wherein said real time clock and said battery are installed on a motherboard of said personal computer.
54 . The personal computer system according to claim 52 , wherein said real time clock and said battery are installed on a baseboard of said personal computer.
55 . The personal computer system according to claim 52 , wherein said real time clock and said battery are installed on an expansion card adapted to be coupled to a motherboard of said personal computer.
56 . The personal computer system according to claim 52 , wherein said real time clock and said battery are installed on an expansion card adapted to be coupled to a baseboard of said personal computer.
57 . The personal computer system according to claim 52 , wherein said real time clock and said battery are installed on an external device adapted to be coupled to said personal computer.
58 . The personal computer system according to claim 57 , wherein said external device comprises a dongle.
59 . The personal computer system according to claim 57 , wherein said external device comprises a PCMCIA card.
60 . The personal computer system according to claim 57 , wherein said external device comprises a smart card.
61 . The personal computer system according to claim 57 , wherein said external device comprises a removable computer-readable medium.
62 . The personal computer system according to claim 61 , wherein said removable computer-readable medium is selected from the group consisting of a magnetic hard disk, a floppy disk, an optical disk, a CD-ROM, a CD-R, a CD-RW, a disk compliant with DVD standards, a magneto-optical disk, a magnetic tape, a memory chip, a carrier wave used to carry computer readable electronic data, such as are used in transmitting and receiving an e-mail or in accessing a network, including the Internet, intranets, extranets, virtual private networks (VPN), local area networks (LAN), and wide area networks (WAN), and any other storage device used for storing data accessible by a computer.
63 . A method of maintaining a digital data file in a personal computer, comprising:
providing a trusted time source in the personal computer, wherein said trusted time source provides a certifiable time for an unalterable time stamp, wherein said certifiable time confirms at least one of said digital data file's access, creation, modification, receipt, or transmission; receiving a request to save said digital data file from a user; saving said digital data file at a moment in time; retrieving from said trusted time source a date and a time corresponding to said moment in time, wherein said moment in time is substantially a current time of said trusted time source corresponding to receipt of said request; appending said date and said time retrieved from said trusted time source to said digital data file; signing said digital data file with said date and said time retrieved from said trusted time source appended thereto; hashing said digital data file to produce a digest; signing said digest with a key to produce a certificate; appending said certificate to said digital data file; saving said file with said certificate appended thereto; and verifying trust in the content of said digital data file with said certificate appended thereto.
64 . The method according to claim 63 , further comprising:
providing tamper-evident means for labeling said trusted time source.
65 . The method according to claim 63 , wherein said moment in time corresponds to an access of said digital data file.
66 . The method according to claim 63 , wherein said moment in time corresponds to a creation of said digital data file.
67 . The method according to claim 63 , wherein said moment in time corresponds to a modification of said digital data file.
68 . The method according to claim 63 , wherein said moment in time corresponds to a receipt of said digital data file.
69 . The method according to claim 63 , wherein said moment in time corresponds to a transmission of said digital data file.Join the waitlist — get patent alerts
Track US2006010501A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.