WO2005017809A2 - Method and apparatus for authentication of data streams with adaptively controlled losses - Google Patents

Method and apparatus for authentication of data streams with adaptively controlled losses Download PDF

Info

Publication number
WO2005017809A2
WO2005017809A2 PCT/US2004/025513 US2004025513W WO2005017809A2 WO 2005017809 A2 WO2005017809 A2 WO 2005017809A2 US 2004025513 W US2004025513 W US 2004025513W WO 2005017809 A2 WO2005017809 A2 WO 2005017809A2
Authority
WO
WIPO (PCT)
Prior art keywords
data stream
blocks
receiver
values
hash
Prior art date
Application number
PCT/US2004/025513
Other languages
French (fr)
Other versions
WO2005017809A3 (en
Inventor
Craig B. Gentry
Alejandro Hevia
Ravi Kumar Jain
Toshiro Kawahara
Zulfikar Amin Ramzan
Original Assignee
Docomo Communications Laboratories Usa, Inc.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Docomo Communications Laboratories Usa, Inc. filed Critical Docomo Communications Laboratories Usa, Inc.
Priority to JP2006523251A priority Critical patent/JP4809766B2/en
Priority to US10/543,640 priority patent/US20060136728A1/en
Publication of WO2005017809A2 publication Critical patent/WO2005017809A2/en
Publication of WO2005017809A3 publication Critical patent/WO2005017809A3/en
Priority to US12/560,959 priority patent/US8256015B2/en
Priority to US12/560,963 priority patent/US20100005310A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3236Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
    • H04L9/3242Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/50Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
    • GPHYSICS
    • G11INFORMATION STORAGE
    • G11BINFORMATION STORAGE BASED ON RELATIVE MOVEMENT BETWEEN RECORD CARRIER AND TRANSDUCER
    • G11B20/00Signal processing not specific to the method of recording or reproducing; Circuits therefor
    • G11B20/00086Circuits for prevention of unauthorised reproduction or copying, e.g. piracy
    • GPHYSICS
    • G11INFORMATION STORAGE
    • G11BINFORMATION STORAGE BASED ON RELATIVE MOVEMENT BETWEEN RECORD CARRIER AND TRANSDUCER
    • G11B20/00Signal processing not specific to the method of recording or reproducing; Circuits therefor
    • G11B20/00086Circuits for prevention of unauthorised reproduction or copying, e.g. piracy
    • G11B20/0021Circuits for prevention of unauthorised reproduction or copying, e.g. piracy involving encryption or decryption of contents recorded on or reproduced from a record carrier
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/30Compression, e.g. Merkle-Damgard construction
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/34Encoding or coding, e.g. Huffman coding or error correction
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/80Wireless
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/167Systems rendering the television signal unintelligible and subsequently intelligible
    • H04N7/1675Providing digital key or authorisation information for generation or regeneration of the scrambling sequence

Definitions

  • the present invention relates to data stream authentication, and more specifically to authentication schemes with adaptively controlled packet loss.
  • the key is split into two parts: a secret signing key and a public verification key.
  • the public verification key can be used to verify anything signed using the secret signing key.
  • the key is split in such a way that it is not possible to derive the private portion from the public portion.
  • the sender applies a mathematical transformation involving the original data and secret signing key, and produces a signature.
  • the recipient can then apply a similar transformation with the data, the signature, and the public verification key to ascertain the identity of the sender and the integrity of the data.
  • Digital signatures have a non-repudiation property that MACs do not. Namely, the signer cannot later deny having signed the document since the signing key is secret and was in the signer's possession. Of course, the signature owner can always claim that the secret signing key was stolen by some adversary.
  • the splicing situation can be considered a special case of a lossy situation where the quality of signal transmission is poor or otherwise is degraded, for example, by viewing the three data streams as one huge layered stream and imagining that two out of three frames are being discarded.
  • a source may include in a given slot a number of advertisements that can be displayed. An intermediary can then choose from among these choices which advertisement it would like to display. The choice can, for example, be based upon what the intermediary thinks will be the best advertisement for the target audience.
  • the advertisements themselves can be created by an intermediary or some other party, and can be provided to the source either in their original form or may be hashed. The source would then include them when signing the stream. [13]
  • signature schemes that can handle these types of losses in a secure manner are needed.
  • "secure” means that the ultimate end receiver can determine with Sughrue Docket No. CF104822 overwhelmingly high confidence that the data it receives comes from a stream that was originally signed validly, but for which certain portions were removed.
  • each packet contains authentication information.
  • is the size, in bytes, of a Merkle tree node
  • h is the height of the Merkle tree
  • each data element transmitted must be accompanied by
  • the present invention addresses the following problems: 1. adaptive loss (subsequence) authentication, wherein data chunks are removed arbitrarily; 2. simulcast authentication, wherein several data streams are intertwined and only one data chunk is taken at a time from a given stream, and the data from the other streams is dropped; and 3. adaptively lossy simulcast authentication, wherein sometimes the entire data chunk is dropped altogether.
  • the present invention provides the following schemes: 1. Linear Scheme for Subsequence Authentication; 2. Linear Scheme for Simulcast Authentication; 3. Tree Scheme for Subsequence Authentication; and 4. Tree Scheme for Simulcast Authentication.
  • Each of the above schemes may incorporate either a digital signature or a MAC.
  • the schemes use cryptographic hash functions to process the blocks of the original stream and create a short digest.
  • a digital signature or MAC is then applied to the digest, thereby providing authentication information. If the receiver is given the entire stream, then it can recompute the digest and verify the signature. When specific portions of the stream need to be removed, the remover sends information that allows the receiver to efficiently compute the digest.
  • the amount of information provided to the receiver in this setting is Sughrue Docket No. CF104822 related to the output size of the cryptographic hash function and is otherwise independent of the actual data stream.
  • the intermediary or source can remove arbitrary blocks (irrespective of their location) while still permitting the receiver to authenticate information.
  • the scheme involves computing a two-layer hash chain and providing the recipient with various values in this chain. The scheme is online for the receiver in the sense that the receiver does not have to incur any delay in verifying the authentication information.
  • several first-layer hashes are aggregated before performing the second-layer hash. Consequently, fewer second-layer hashes need to be performed.
  • the intermediary or source is provided with multiple streams and can arbitrarily switch among which stream it transmits while still permitting the receiver to authenticate information.
  • the scheme involves computing a multi-layer hash chain and providing the recipient with various values in this chain. The scheme is online for the receiver in the sense that the receiver does not have to incur any delay in verifying the authentication information.
  • the intermediary or source can remove arbitrary blocks (irrespective of their location) while still permitting the receiver to authenticate information.
  • the scheme involves computing a hash tree and providing the recipient with various values in this tree.
  • the hashed scheme is more efficient with respect to bandwidth than the corresponding linear scheme.
  • the scheme is not online for the receiver in the sense that the receiver must wait for all blocks before being able to verify the authentication information.
  • Tree Scheme for Simulcast Authentication the intermediary or source is provided with multiple streams and can arbitrarily switch among which stream it transmits while still permitting the receiver to authenticate information.
  • the scheme involves computing a hash tree and providing the receiver with various values in this tree. The scheme is not online for the receiver in the sense that the receiver must wait for all blocks before being able to verify the authentication information.
  • Both the linear and tree-based schemes can take advantage of correlation among blocks of data. For example, in the tree-based scheme, if a given subset of blocks has the behavior that all will be dropped or all will be kept, then these blocks can be placed as all the leaves of the same subtree. In the event that all packets in the given subset are dropped, only the root has to be transmitted. However, this concept applies even if the correlation is probabilistic. For example, if a given block being dropped makes it more likely that another block will be dropped, then these blocks should also be clustered. Likewise, in the linear schemes, if a given sequence of frames are to be all kept or dropped, these frames can be treated as a single block unit to be hashed. Then, if the entire sequence of frames is dropped only a single hash value needs to be sent.
  • Fig. 1 shows a high-level depiction of a scalable coder.
  • Fig. 2 shows a block diagram of a sender or source.
  • Fig. 3 shows a block diagram of a receiver.
  • FIG. 4 shows a block diagram of an intermediary.
  • FIG. 5 shows a block diagram of a system including a sender, a receiver, and an intermediary.
  • Sughrue Docket No. CF104822 [37]
  • Fig. 6 illustrates a Merkle Tree with eight leaves.
  • Fig. 7 illustrates a basic linear subsequence authentication scheme according to one embodiment of the present invention.
  • Fig. 9 illustrates a basic linear simulcast authentication scheme according to one embodiment of the present invention.
  • Fig. 10 illustrates a tree-based subsequence authentication scheme according to one embodiment of the present invention.
  • Fig. 11 illustrates a tree-based simulcast authentication scheme according to one embodiment of the present invention.
  • an initial sender 200 in Fig. 2 is responsible for authenticating the data stream.
  • each sender 200 includes a processor 201 in bidirectional communication with a memory 202.
  • the processor 201 executes program code for carrying out the schemes of the present invention to generate, transmit or receive data streams.
  • the memory 202 stores cryptographic keys, program codes, as well as intermediate results and other information used during execution of the schemes.
  • a communications network 203 is provided over which the sender may communicate with receivers.
  • Fig. 3 shows a block diagram of a receiver which receives data streams from the sender or server or an intermediary over a communication network according to one embodiment of the present invention.
  • the system of the present invention includes a number of receivers, which verify the received data.
  • Each receiver 300 includes a processor 301 in Sughrue Docket No. CF104822 bidirectional communication with a memory 302.
  • the processor 301 executes program code for carrying out the schemes of the present invention to generate, transmit, and receive data streams.
  • Program code may be created according to methods known in the art.
  • the memory 302 stores cryptographic keys and the program code, as well as intermediate results and other information used during execution of the schemes.
  • a communications network 303 is provided over which the sender and the receivers may communicate.
  • the communications network may be of various common forms, including, for example, a local area network (LAN), a wide area network (WAN), and/or a mobile telephone network.
  • the network may permit either wired or wireless communications.
  • Fig. 4 shows a block diagram of an intermediary.
  • the data for the sender may pass through one or more intermediaries shown in Fig. 4 on its way to the sender or receiver.
  • the intermediaries may choose to perform certain transformations on the data.
  • Each intermediary 400 includes a processor 401 in bidirectional communication with a memory 402.
  • the processor 401 executes program code for carrying out the schemes of the present invention to generate, transmit, and receive data streams.
  • the memory 402 may store cryptographic keys.
  • Fig. 5 shows a block diagram of a system according to one embodiment of the present invention, including a sender 501, an intermediary 503, a receiver 505, and communication networks 502 and 504.
  • the sender 501 transmits an original data stream with signature and optional helper information to the intermediary 503 via the communication Sughrue Docket No. CF104822 network 502, which then transmits a reduced data stream with signature and relevant helper information to receiver 505 via communication network 504.
  • an intermediary modifies the data stream, it will determine what information, if any, is required by the receiver to verify the authentication information associated with the stream.
  • H denotes a cryptographic compression function that takes as input a b-bit payload as well as a v-bit initialization vector or IV, and produces a v-bit output where typically v ⁇ b.
  • IV there is a standard IV, called IVo, that is fixed and publicly known.
  • IVo a standard IV
  • the description below will not explicitly list the IV as an argument in the hash function - though it should be thought of as being there implicitly.
  • the compression function in SHA-1 has an output and IV size of 160-bits whereas the compression function in MD5 works with 128-bit values. Both allow for a 512-bit payload size.
  • application of the compression function is repeated.
  • Functions that operate as such while still retaining the collision resistance property are termed cryptographic hash functions. For simplicity, this term is used below even if a data block that fits within the payload is dealt with.
  • the schemes of the present invention make use of conventional constructs involving cryptographic compression functions.
  • One such construct is an iterated hash function which is built from cryptographic compression functions as follows. Suppose a message M can be broken up into n blocks of length b, and H is a cryptographic compression function with a b- bit payload and a v-bit output.
  • the iterated hash function defined by H is the value x n where:
  • Xn H(Xn-l, M n )
  • n is a power of 2.
  • the schemes of the present invention can incorporate powers other than 2.
  • the Merkle tree associated with M under hash function H is a binary tree in which each node is associated with a specific value. There are n leaves, and each leaf ., • takes on the hash of ; - that is, H(IVo, Mi). Each interior (non-leaf) node then takes on the value associated with the hash of the concatenations of the values of its two children. That is, if vertex v has children vj and v where v_ has value xj and v has value x , then the value associated with v is H(IVo, xi xX).
  • Merkle trees are often used in digital signatures whereby the value assigned to the root of the tree associated with the message M forming the digest is signed. If the underlying compression or hash function is collision resistant, then it will be hard to find two different messages whose Merkle root value is identical.
  • the present invention also makes use of the notion of the co-nodes for a given vertex in a Merkle tree.
  • the co-nodes of a vertex v consist of the direct siblings of the vertices on the path from v to the root. Given a vertex v and its co-nodes, one can compute the sequence of hash functions that lead from v to the root.
  • the linear subsequence authentication scheme of the present invention allows stream authentication even when arbitrary blocks from the message are removed. As long as the Sughrue Docket No. CF104822 blocks sent by an intermediate node are a proper subsequence of the original message, the receiver can authenticate the stream.
  • Fig. 7 illustrates a basic linear subsequence authentication scheme according to one embodiment of the present invention. Given a message M, signature generation follows a similar paradigm to an iterated hash, except that it uses "two hashing layers".
  • auxiliary hash values gi,..., g n which are not sent.
  • the initial sender S transmits (M, ⁇ s k (h n )).
  • the value of IVo can be used as the IV for the computation of all the gi values.
  • the sender S may decide to transmit the hash values hi along with the
  • the intermediate node computes
  • the intermediate node transmits
  • the receiver can verify the signature by computing h n from Mi ',...,M k ' and h n . t as
  • the receiver can then verify the signature on h n as normal using the verification algorithm v. Sughrue Docket No. CF104822 [70]
  • the iterated hash construction is collision resistant so long as the underlying hash function H is as well.
  • the underlying hash function H is as well.
  • an adversary can come up with a non-subsequence forgery (that is, a message/signature pair that is not obtained by merely talcing a subsequence of the original message), then it is possible to show that one can demonstrate either a collision in the hash function or a forgery on the underlying signature scheme. Therefore, as long as the signature scheme is not easily susceptible to forgery and the hash function is not easily susceptible to collisions, the scheme presented above is secure.
  • the intermediary When the intermediary removes blocks, it only needs to compute the hash of the block being removed. This computation does not involve any public-key steps and is fairly efficient. In fact, the throughput of algorithms like S ⁇ A-1 is on the order of a few hundred megabits per second. Moreover, if the intermediate nodes are resource bounded with respect to computation, the source can follow the alternative approach and include the intermediate hi Sughrue Docket No. CF104822 values. In the case of SHA-1, each such value is 20-bytes long, so the bandwidth overhead will likely be quite small.
  • the computations of this embodiment do not require storing the entire stream in memory since only a single input block to the hash function is needed at any given time.
  • the scheme of the first embodiment permits the role of an intermediary which can adaptively and intelligently choose to remove any number of blocks without requiring knowledge of any cryptographic keying material. Moreover, the intermediary can be proximate to the receiver and can control the loss (and therefore the amount of hash information) dynamically. Furthermore, the authentication information can be verified in an online manner by the receiver. That is, the receiver can verify the authentication information as it receives the stream, and will not be required to do any form of extensive buffering. Also, the first layer hash computations are not required for any block that will not be dropped.
  • an MPEG I-frame or the base layer of a scalable coding scheme will not be intentionally dropped.
  • the second layer is required.
  • the above scheme is even more advantageous since it can cluster these as a single block before hashing.
  • the second embodiment of the present invention provides an efficiency improvement to the basic linear subsequence authentication, by aggregating several first layer hashes before performing the second layer hashes. As a result, the method according to the second embodiment performs fewer second layer hashes. For a typical compression function, such as the one accompanying SHA-1, the payload size is 64 bytes whereas the digest size is 20 bytes. As a result, in this situation, three digests can be concatenated together before the second layer function is called. In the second embodiment, it is assumed that r hashes are
  • ⁇ a ⁇ ⁇ denotes the largest integer less or equal than a
  • a message M For a message M, signature generation according to the second embodiment follows a similar paradigm to the scheme of the first embodiment, and uses "two hashing layers". However, the scheme of the second embodiment involves fewer hashes than that of the first embodiment.
  • the scheme of the second embodiment computes auxiliary hash values gi,..., g n which are not sent.
  • the initial sender transmits (M, ⁇ s k (h m )), and the value of IVo can be used as the IV for the computation of all the g t values.
  • the sender may decide to transmit the hash value h, along with every r-
  • the intermediate node computes
  • M n _ M M n -i + ⁇ , if block M . is forwarded, or gi, if block M ⁇ is dropped (7)
  • the receiver can then verify the signature on h m as normal using the verification algorithm v.
  • the receiver of the second embodiment can verify the authentication information after receiving every r blocks.
  • r will be fairly small - on the order of 2 or 3, thus reducing the number of the second layer hashes.
  • Fig. 9 shows a basic linear simulcast authentication scheme according to one embodiment of the present invention. Given a message M, signature generation follows the same approach as in the first and second embodiments, i.e., reverse iterated hash, but computing partial hashes of every block in each stream.
  • the initial sender transmits ⁇ s k (h n ) and then sends M ⁇ 1) ,...,M (k) simultaneously.
  • the message blocks of the different streams will be interleaved in the transmission.
  • an intermediate node wants to select a possibly different stream (message) for each message block received. For instance, if each message encodes a video stream of different quality, the intermediate node may want to select a lower or higher quality depending on network congestion. It generates a "resulting message" M', comprising "chunks" (consecutive message blocks) of the different streams. The intermediate node may pick a single stream (message) at each moment. It should be understood that the present invention allows for the possibility of layered streams. The receiver needs to be able to authenticate M'. Sughrue Docket No. CF104822 [99] Given the received n-block messages M (1> ,.., M" k ⁇ , the intermediate node computes
  • the intermediate node finally transmits (M v ..M n , ⁇ Sk ( « spirit) .
  • the intermediate node transmits
  • the receiver can then verify the signature on h n as normal using the verification algorithm v.
  • the hash step of the scheme of the third embodiment can be iterated using a compression function with either the linear chaining scheme or a Merkle scheme.
  • the fourth embodiment of the present invention is a scheme for authenticating subsequences using Merkle Trees.
  • the tree-based scheme allows stream authentication even when arbitrary blocks from the message are removed. As long as the blocks sent by the intermediate node are a proper subsequence of the original message, the receiver can authenticate the stream.
  • the tree scheme is more efficient with respect to bandwidth than the linear scheme.
  • Fig. 10 illustrates a tree-based subsequence authentication scheme according to one embodiment of the present invention.
  • M M]M 2 ...M n
  • the scheme of the fourth embodiment generates a Merkle tree shown in Fig. 6. If v denotes the root of the tree and x denotes the value associated with the root, then the initial sender transmits (M, ⁇ s k (x))-
  • the receiver can verify the signature it receives.
  • the Merkle hash construction is collision resistant so long as the underlying hash function H is collision resistant.
  • the underlying hash function H is collision resistant.
  • an adversary can come up with a non-subsequence forgery (that is, come up with a message/signature pair that is not obtained by merely taking a subsequence of Sughrue Docket No. CF104822 the original message), then one can demonstrate either a collision in the hash function or a forgery on the underlying signature scheme. Therefore, as long as the signature scheme is not easily susceptible to forgery and the hash function is not easily susceptible to collisions, the scheme of the fourth embodiment is secure.
  • the intermediary When the intermediary removes blocks, it needs to provide the receiver with a sufficient number of internal hashes to compute the Merkle root of the tree without those message blocks.
  • the intermediary will require k hashes for each of the blocks to be dropped and then at most k - I hashes when replacing pairs of hashes with a single hash (since a single hash results in replacing two values with a single one, thereby reducing the net number by one).
  • the total computation is therefore at most 2k-I hashes.
  • the total hashes computed by the intermediary are denoted by t.
  • the fifth embodiment of the present invention is a tree-based scheme for authenticating multiple parallel streams in which one data block is selected from one stream at each step of the transmission.
  • the original sender S transmits k different streams M (1> , M (2> ,..., f k) simultaneously.
  • This scheme allows the intermediate node not only to select one stream and retransmit it in an authenticated fashion, but also to "switch" to some other stream adaptively (at any point during block transmission). Of course, the receiver is able to authenticate the resulting stream.
  • the scheme of the fifth embodiment exploits certain aspects of the tree stmcture, so as to be more efficient with respect to bandwidth than the analogous linear scheme.
  • the scheme of the fifth embodiment does not readily lend itself to online verification. Instead, the receiver has to wait for all packets before it can verify. In practice, the delay can be reduced by splitting the stream into segments of reasonable size and authenticating each segment separately.
  • an intermediate node wants to select a possibly different stream (message) for each message block received. For instance, if each message encodes a video stream of different quality, the intermediate node may want to select a lower or higher quality depending on network congestion. It generates a resulting "message" M', comprising "chunks" (consecutive message blocks) of the different streams. The receiver needs to be able to authenticate M'.
  • the intermediary simply has to provide the user with the information necessary to compute these values.
  • the intermediary can compute the set of required values as it did in the Merkle scheme of the fourth embodiment.
  • the intermediary transmits these values to the receiver which can then compute the x . values and in-turn verify the authentication information.
  • M (l let d[ l) ,..., dj ) denote the indices of the blocks that will be dropped.
  • the cryptographic hash function is globally computable.
  • the receiver verifies the signature by first computing the values of the roots of each of the Merkle trees - after that it hashes these values and verifies the signature. It achieves this goal using the following algorithm which is run for each i:
  • FIG. 11 illustrates the signing and verification of the fifth embodiment of the invention, an example with four streams and four message blocks.
  • each of the four streams M (1) , M (2> , M ⁇ 3) , M (4) consists of four blocks.
  • the black leaves denote the message blocks that are actually sent. The remaining ones are dropped.
  • the shaded vertices represent the cover; that is, the values corresponding to these vertices are sent to the receiver.
  • the roots of the four Merkle trees are x (1> , x (2) , x ⁇ .and x ⁇ 4) respectively.
  • the final root value x is computed by hashing the Merkle roots x (1> , x (2> , x (3> , x (4> .
  • This hash can be also be performed in a Merkle-like fashion.
  • the value x is actually signed. In this scheme only six hash values are sent to the receiver. In the linear simulcast scheme, twelve hashes (three per each block transmitted) would have been transmitted. Thus, savings is achieved whenever dropped blocks are clustered. For example, in Fig. 11, all blocks in the stream M (4> are dropped. As a result, one only needs to send the root x (4> of the associated Merkle tree. [135] Also, because the Merkle roots are themselves hashed in a Merkle-like construction, there is room for further optimization. In particular, suppose that all blocks are dropped for two entire subtrees whose Merkle roots are siblings in the even larger tree. Then, instead of sending the two Merlde roots, their hash could be sent.
  • the fifth embodiment is secure as long as the signature scheme is not easily susceptible to forgery, and the hash function is not easily susceptible to collisions.
  • the invention presented above is secure.
  • the performance of the fifth embodiment can be analyzed by extending the analysis for the tree-based subsequence scheme and the linear simulcast scheme.
  • a hash function with a specific payload size and a specific IV is used.
  • the chaining constructions tend to take some existing output and use that as the IV of the next block.
  • the current output instead of loading the current output as an IV, the current output can be concatenated to the next payload.
  • a scheme starts by splitting each stream M (l> into segments of length b blocks. Then, a tree scheme is applied on the first segment of all streams to compute the Merkle root xj, then the root on the second
  • the roots are obtained. Instead of signing each one of these roots, as in the tree schemes described above, the roots are combined using the linear scheme. Hence, if the receiver can buffer b blocks, then verification can be done "on-line". Moreover, the communication overhead is decreased compared to the plain linear scheme since for each segment of b blocks, the number of transmitted hashes may be much less than the number of dropped blocks (although equal on the worst case). A similar approach can be taken for subsequence authentication.
  • a linear scheme is applied to each stream, and then a Merkle tree is computed on the results.
  • the Merkle tree construction could be optimized.
  • one of the streams will more likely be used than the others, it is advantageous to use a lopsided Merkle tree in which the priority stream is close to the root (e.g., perhaps right below it).
  • the streams are prioritized, so that the high priority streams are closer to the final value in the chain. This ordering particularly makes sense when layered streams are used. In such cases, the verification requires fewer hash steps to reach the root.
  • the schemes of the present invention can be interpreted as having two phases. In the first phase, it finds a convenient way to hash each data block. In the second phase, it signs the hashes. The reason for doing so is that if a block is dropped, it is not necessary to retransmit it in its entirety. Instead, only the hash computed in the first phase is transmitted.
  • This information is sufficient to allow the receiver to verify, since the signature can be viewed as being performed on the hashes.
  • the present invention deals with a case of controlled loss - that is, the sender drops particular blocks on purpose.
  • Sughrue Docket No. CF104822 one may have to deal with uncontrolled loss situations. These situations may occur, for example, if the transport protocol is not reliable such as the case with UDP, or if the environment is subject to lossy behavior such as is the case with wireless networks.
  • the present invention can be used to deal with the uncontrolled loss by replicating the hashes that would be sent if the packet were dropped.
  • EEC Forward Error Correction
  • schemes of the present invention involve an intermediary which can adaptively choose the amount of forward error correction to the authentication information (i.e., hash outputs).
  • the source can choose not to include authentication forward error correction information at all, and instead allow an intermediary to include the authentication forward error correction information dynamically to further increase the probability that the stream can be authenticated.
  • the intermediary becomes an integral part of a scheme which considers both uncontrolled losses handled through forward error correction as well as adaptive and intelligent controlled losses. For example, in the Merlde tree constructions, it may suffice for the recipient to recover intermediate nodes (as opposed to just leaf nodes). In such a case, the Sughrue Docket No. CF104822 intermediary can choose to supply forward error correction information to allow recovery of the (possibly interior) nodes necessary to authenticate, thus requiring possibly less forward error correction information.
  • the intermediary can recycle the work effort.
  • the intermediary can store and reuse any first-layer hash. As a result, it will need to compute at most one full set of first-layer hashes.
  • the source can provide the intermediary with any necessary hash computations for assisting with authentication. Then, the intermediary is not required to perform any work of a cryptographic nature. Instead, it can choose which blocks to drop and select the corresponding authentication information to be transmitted.
  • Another application of the present invention is insertion and selection of advertisements in a stream.
  • the intermediary or some other party provides advertisements or a hash of advertisements, for example hashed using a Merlde tree, to the source.
  • the source then includes the Merkle hash in its stream as a placeholder, allowing the intermediary to choose which advertisement it would like to use.
  • this concept is not necessarily limited to advertisers.
  • CBC chaining or feedback modes
  • OFB output feed back
  • ECB ECB mode

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Power Engineering (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Storage Device Security (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

Methods, components, and systems for efficient authentication, either through a digital signature or message authentication codes, and verification of a digital stream sent from a source (505) to a receiver via zero or more intermediaries (503), such that the source (501) or intermediary (503) (or both) can remove certain portions of the data stream without inhibiting the ability of the ultimate receiver to verify the authenticity and integrity of the data received. According to the invention, a source (501) may sign an entire data stream once, but may permit either itself or an intermediary to efficiently remove certain portions of the stream before transmitting the stream to the ultimate recipient (505), without having to re-sign the entire stream. Applications may include the signing of media streams which often need to be further processed to accommodate the resource requirements of a particular environment. Another application allows an intermediary to choose an advertisement to include in a given slot.

Description

Sughrue Docket No. CF104822
METHOD AND APPARATUS FOR AUTHENTICATION OF DATA STREAMS WITH ADAPTIVELY CONTROLLED LOSSES
CROSS-REFERENCE TO RELATED APPLICATIONS
[01] This application claims the benefit of Provisional Application No. 60/495,787, filed August 15, 2003. The present application incorporates the disclosure of this provisional application by reference.
BACKGROUND OF THE INVENTION FIELD OF THE INVENTION
[02] The present invention relates to data stream authentication, and more specifically to authentication schemes with adaptively controlled packet loss.
DESCRIPTION OFTHE RELATED ART
[03] In many cases, it is desirable to append authentication information to a stream of data to assure a recipient that the data came from a specific source and was not modified en-route. For example, if the data is being provided to an application, then it would be important for the application that the data has not been corrupted either maliciously or by accident. [04] In cryptography, there are two traditional mechanisms for permitting such authentication: 1. Message Authentication Codes (MAC) 2. Digital Signatures
[05] With a MAC, both the original source and the ultimate receiver must possess knowledge of a shared secret key. The sender applies a mathematical transformation involving the original data and secret key, and produces a tag. The receiver can then apply a Sughrue Docket No. CF104822 similar transformation with the data, the tag, and the secret key to verify the origin and the integrity of the data.
[06] With Digital Signatures, the key is split into two parts: a secret signing key and a public verification key. The public verification key can be used to verify anything signed using the secret signing key. The key is split in such a way that it is not possible to derive the private portion from the public portion. The sender applies a mathematical transformation involving the original data and secret signing key, and produces a signature. The recipient can then apply a similar transformation with the data, the signature, and the public verification key to ascertain the identity of the sender and the integrity of the data. [07] Digital signatures have a non-repudiation property that MACs do not. Namely, the signer cannot later deny having signed the document since the signing key is secret and was in the signer's possession. Of course, the signature owner can always claim that the secret signing key was stolen by some adversary.
[08] Because of their nature, traditional authentication schemes do not tolerate any transformations to the data made by the source or by an intermediate. If a document is modified after it is signed, the verification step will so indicate, and will fail. [09] But for many applications, it is not only convenient, but sometimes necessary, to permit some specific types of modifications. For example, scalable video coding schemes, a high-level picture of the principle of which is shown in Fig. 1, have the property that a subset of the stream can be decoded and the quality is commensurate with the amount decoded. These schemes may encode video into a base layer and then zero or more "enhancement" layers. Just the base layer alone would be sufficient to view the stream. Enhancement layers are utilized to improve the overall quality. Sughrue Docket No. CF104822 [10] Now, in an environment that is resource constrained, one might want to strip the enhancement layers and only send the base layers. If the entire stream has been digitally signed or authenticated in conventional ways, then by removing the enhancement layers, the original tag or signature becomes invalid. Thus the entire stream would have to be re- authenticated.
[11] Alternatively, one may want to splice several streams of different qualities as in a simulcast situation. There may be one high-quality version of the stream, one medium- quality version of the stream, and one low-quality version of the stream. If network resources are available, then the high-quality stream may be sent, but if the network congestion goes up, then one may want to shift to the medium or low quality streams. In an alternate scenario, it could be the case that the receiver is mobile and is leaving one network environment and entering another that has different resource restrictions. The splicing situation can be considered a special case of a lossy situation where the quality of signal transmission is poor or otherwise is degraded, for example, by viewing the three data streams as one huge layered stream and imagining that two out of three frames are being discarded. [12] Yet another application is dynamic advertising. A source may include in a given slot a number of advertisements that can be displayed. An intermediary can then choose from among these choices which advertisement it would like to display. The choice can, for example, be based upon what the intermediary thinks will be the best advertisement for the target audience. The advertisements themselves can be created by an intermediary or some other party, and can be provided to the source either in their original form or may be hashed. The source would then include them when signing the stream. [13] Thus, signature schemes that can handle these types of losses in a secure manner are needed. Here, "secure" means that the ultimate end receiver can determine with Sughrue Docket No. CF104822 overwhelmingly high confidence that the data it receives comes from a stream that was originally signed validly, but for which certain portions were removed. In addition, there is also a need for an intermediary that can adaptively and intelligently decide which blocks to drop.
[14] One conventional solution to the controlled loss authentication problem is to authenticate each packet individually. This solution has two substantial drawbacks. First, in the case of using digital signatures, a fairly expensive computation must be performed for each packet. Second, in both the digital signature and MAC case, authentication information must be appended to each packet, which may not be feasible in consideration of efforts to remove portions of the stream stem to meet bandwidth constraints.
[15] In C.K. Wong and S.S. Lam, Digital Signatures for Flows and Multicasts -
IEEE/ACM Transactions on Networking, 7(4):502:513, August 1999, the authors propose a solution in which each data element is hashed, and then the resulting hashes are digested using a Merkle-tree. The root of the Merkle tree is authenticated. Then, with each data element, the co-nodes are sent, thereby allowing the receiver to authenticate without it. Since
Wong and Lam deal with per-packet authentication, each packet contains authentication information. In particular, if |v| is the size, in bytes, of a Merkle tree node, h is the height of the Merkle tree, then each data element transmitted must be accompanied by |v| x \h\ bytes.
Thus, this approach does not deal with the controlled loss authentication problem, and is not bandwidth efficient.
[16] In R. Johnson, D. Molnar, D. Song, and D. Wagner, Homomorphic Signature
Schemes - RSA 2002, Cryptographer's Track, the authors propose a redactable signature scheme. It permits certain specific transformations on the data while still allowing the receiver to verify. It also allows arbitrary deletion of substrings in a signed document and has Sughrue Docket No. CF104822 applications for censoring. Suppose n message blocks m = mi,..., mn are to be signed, and assume that n is a power of 2. The scheme starts with an initial secret key k and uses it to generate n keys &_,..., kn with the aid of a tree-like construction such as that of Goldreich, Goldwasser, and Micali (GGM), O. Goldreich, S. Goldwasser, and S. Micali, How to Construct Random Functions, Journal of the ACM, vol. 33, No. 4, 1986, pages 210-217. Then, to sign message m, the triplets (0, mj, &;),..., (0, mn, kn) are hashed in a Merkle-like tree and the root r is signed to produce the signature 5. The difference between this tree and a regular Merkle tree is that the value 1 is pre-pended before the internal hashes are computed. With knowledge of k, anyone can verify s. However, in order to censor the data stream, the value of k is never published. Instead, only certain intermediate values of the GGM tree are published. These values correspond to the information needed to derive the final keys /q corresponding to the data elements which are not censored. With uncensored blocks, the intermediate GGM values, and the co-nodes in the Merkle-like tree, the signature can be verified. However, the above Homomorphic Signature Scheme takes precautions, via a GGM tree, to protect the confidentiality of censored data and requires all uncensored message blocks, all co-nodes, and all keying information in order to permit verification, and thus is not efficient.
[17] Accordingly, there has been a need for a secure authentication scheme that permits controlled removal of certain blocks in a stream without weakening the receiver's ability to verify the authentication information, and without requiring confidentiality of censored data.
SUMMARY OF THE INVENTION
[18] In view of the foregoing, it is an object of the present invention to provide schemes for secure authentication under adaptive data loss both in the symmetric setting (with MAC) Sughrue Docket No. CF104822 or in the asymmetric setting (with digital signatures), which are efficient with respect to the computation requirements of the sender, receiver, and intermediary, as well as the bandwidth requirements of the channels over which these parties communicate. [19] Briefly, the present invention addresses the following problems: 1. adaptive loss (subsequence) authentication, wherein data chunks are removed arbitrarily; 2. simulcast authentication, wherein several data streams are intertwined and only one data chunk is taken at a time from a given stream, and the data from the other streams is dropped; and 3. adaptively lossy simulcast authentication, wherein sometimes the entire data chunk is dropped altogether.
[20] The present invention provides the following schemes: 1. Linear Scheme for Subsequence Authentication; 2. Linear Scheme for Simulcast Authentication; 3. Tree Scheme for Subsequence Authentication; and 4. Tree Scheme for Simulcast Authentication.
[21] Each of the above schemes may incorporate either a digital signature or a MAC.
Therefore, the present invention implicitly provides 8 (= 4 x 2) schemes.
[22] The schemes use cryptographic hash functions to process the blocks of the original stream and create a short digest. A digital signature or MAC is then applied to the digest, thereby providing authentication information. If the receiver is given the entire stream, then it can recompute the digest and verify the signature. When specific portions of the stream need to be removed, the remover sends information that allows the receiver to efficiently compute the digest. The amount of information provided to the receiver in this setting is Sughrue Docket No. CF104822 related to the output size of the cryptographic hash function and is otherwise independent of the actual data stream.
[23] According to one aspect of this invention, Linear Scheme for Subsequence Authentication, the intermediary or source can remove arbitrary blocks (irrespective of their location) while still permitting the receiver to authenticate information. The scheme involves computing a two-layer hash chain and providing the recipient with various values in this chain. The scheme is online for the receiver in the sense that the receiver does not have to incur any delay in verifying the authentication information. In an optimization and generalization to this scheme, one second layer-hash is computed for every bundle of r first- layer hashes. When r = 1, the scheme is the original linear scheme for subsequence authentication. In an improvement to this scheme, several first-layer hashes are aggregated before performing the second-layer hash. Consequently, fewer second-layer hashes need to be performed.
[24] According to a second aspect of this invention, Linear Scheme for Simulcast Authentication, the intermediary or source is provided with multiple streams and can arbitrarily switch among which stream it transmits while still permitting the receiver to authenticate information. The scheme involves computing a multi-layer hash chain and providing the recipient with various values in this chain. The scheme is online for the receiver in the sense that the receiver does not have to incur any delay in verifying the authentication information.
[25] According to a third aspect of this invention, Tree Scheme for Subsequence Authentication, the intermediary or source can remove arbitrary blocks (irrespective of their location) while still permitting the receiver to authenticate information. The scheme involves computing a hash tree and providing the recipient with various values in this tree. In the case Sughrue Docket No. CF104822 that some subset (of size greater than one) of dropped blocks constitute a subtree of the hash tree, the hashed scheme is more efficient with respect to bandwidth than the corresponding linear scheme. The scheme is not online for the receiver in the sense that the receiver must wait for all blocks before being able to verify the authentication information. [26] According to a fourth aspect of this invention, Tree Scheme for Simulcast Authentication, the intermediary or source is provided with multiple streams and can arbitrarily switch among which stream it transmits while still permitting the receiver to authenticate information. The scheme involves computing a hash tree and providing the receiver with various values in this tree. The scheme is not online for the receiver in the sense that the receiver must wait for all blocks before being able to verify the authentication information.
[27] In all aspects of this invention, it is assumed that the sender has possession of all data to be signed at the onset. In most cases, such as when media is pre-recorded, this will not be a concern. In the case of a live stream, the present invention breaks the stream into smaller chunks and applies the schemes specified herein. Those skilled in the art will recognize that variations and modifications can be made without departing from the spirit of the invention. [28] The present invention permits a situation in which an intermediary may adaptively and intelligently decide which blocks are to be dropped. The schemes of the present invention readily adapt to any model for dropping blocks. Moreover, the intermediary is not required to know of any cryptographic keying material. Furthermore, if the source provides the intermediary with various hash values, then the intermediary can avoid having to do any cryptographic related computation. Instead, it just has to forward the blocks it desired together with the hash information for those blocks that are dropped. Sughrue Docket No. CF104822 [29] All of the inventive schemes have the property that, given knowledge ahead of time that a given block will not be dropped, then the first layer hash on that block will not be performed. That is, the first layer hash for just that block can be replaced with the identity function (h(x) = x).
[30] Both the linear and tree-based schemes can take advantage of correlation among blocks of data. For example, in the tree-based scheme, if a given subset of blocks has the behavior that all will be dropped or all will be kept, then these blocks can be placed as all the leaves of the same subtree. In the event that all packets in the given subset are dropped, only the root has to be transmitted. However, this concept applies even if the correlation is probabilistic. For example, if a given block being dropped makes it more likely that another block will be dropped, then these blocks should also be clustered. Likewise, in the linear schemes, if a given sequence of frames are to be all kept or dropped, these frames can be treated as a single block unit to be hashed. Then, if the entire sequence of frames is dropped only a single hash value needs to be sent.
BRIEF DESCRIPTION OF THE DRAWINGS
[31] The present invention is described herein with reference to the accompanying drawings, similar reference numbers being used to indicate functionally similar elements.
[32] Fig. 1 shows a high-level depiction of a scalable coder.
[33] Fig. 2 shows a block diagram of a sender or source.
[34] Fig. 3 shows a block diagram of a receiver.
[35] Fig. 4 shows a block diagram of an intermediary.
[36] Fig. 5 shows a block diagram of a system including a sender, a receiver, and an intermediary. Sughrue Docket No. CF104822 [37] Fig. 6 illustrates a Merkle Tree with eight leaves.
[38] Fig. 7 illustrates a basic linear subsequence authentication scheme according to one embodiment of the present invention.
[39] Fig. 8 illustrates an optimized linear subsequence authentication scheme with r = 3 and with n a multiple of r, according to one embodiment of the present invention. [40] Fig. 9 illustrates a basic linear simulcast authentication scheme according to one embodiment of the present invention.
[41] Fig. 10 illustrates a tree-based subsequence authentication scheme according to one embodiment of the present invention.
[42] Fig. 11 illustrates a tree-based simulcast authentication scheme according to one embodiment of the present invention.
DETAILED DESCRIPTION OF EMBODIMENTS
[43] In the schemes of the present invention, an initial sender 200 in Fig. 2 is responsible for authenticating the data stream. As shown, each sender 200 includes a processor 201 in bidirectional communication with a memory 202. The processor 201 executes program code for carrying out the schemes of the present invention to generate, transmit or receive data streams. The memory 202 stores cryptographic keys, program codes, as well as intermediate results and other information used during execution of the schemes. A communications network 203 is provided over which the sender may communicate with receivers. [44] Fig. 3 shows a block diagram of a receiver which receives data streams from the sender or server or an intermediary over a communication network according to one embodiment of the present invention. The system of the present invention includes a number of receivers, which verify the received data. Each receiver 300 includes a processor 301 in Sughrue Docket No. CF104822 bidirectional communication with a memory 302. The processor 301 executes program code for carrying out the schemes of the present invention to generate, transmit, and receive data streams. Program code may be created according to methods known in the art. The memory 302 stores cryptographic keys and the program code, as well as intermediate results and other information used during execution of the schemes.
[45] A communications network 303 is provided over which the sender and the receivers may communicate. The communications network may be of various common forms, including, for example, a local area network (LAN), a wide area network (WAN), and/or a mobile telephone network. The network may permit either wired or wireless communications.
[46] Fig. 4 shows a block diagram of an intermediary. There may be more than one intermediary; alternatively, the source and intermediary may be identical. If the intermediary and source are not identical, then the intermediary needs not have any cryptographic keying material. The data for the sender may pass through one or more intermediaries shown in Fig. 4 on its way to the sender or receiver. The intermediaries may choose to perform certain transformations on the data. Each intermediary 400 includes a processor 401 in bidirectional communication with a memory 402. The processor 401 executes program code for carrying out the schemes of the present invention to generate, transmit, and receive data streams. The memory 402 may store cryptographic keys.
[47] Fig. 5 shows a block diagram of a system according to one embodiment of the present invention, including a sender 501, an intermediary 503, a receiver 505, and communication networks 502 and 504. As shown, the sender 501 transmits an original data stream with signature and optional helper information to the intermediary 503 via the communication Sughrue Docket No. CF104822 network 502, which then transmits a reduced data stream with signature and relevant helper information to receiver 505 via communication network 504.
[48] The above-mentioned transformations involve removing certain portions of the data.
If an intermediary modifies the data stream, it will determine what information, if any, is required by the receiver to verify the authentication information associated with the stream.
[49] M denotes a media stream that can be broken up into n blocks of length b: M = MjM
...M,b \Mi\ = b, 1 < i < n. H denotes a cryptographic compression function that takes as input a b-bit payload as well as a v-bit initialization vector or IV, and produces a v-bit output where typically v < b. These cryptographic compression functions are collision resistant, that is, it is hard to find two inputs mj and m2 with mi ≠ m such that H(IV,mι) = H(IV, m) for a fixed
IV . It is assumed that there is a standard IV, called IVo, that is fixed and publicly known. For notational simplicity, the description below will not explicitly list the IV as an argument in the hash function - though it should be thought of as being there implicitly.
[50] Examples of such cryptographic compression functions are found in SHA-1 or MD5.
The compression function in SHA-1 has an output and IV size of 160-bits whereas the compression function in MD5 works with 128-bit values. Both allow for a 512-bit payload size. When it is necessary to operate on data blocks that are larger than the payload size, application of the compression function is repeated. Functions that operate as such while still retaining the collision resistance property are termed cryptographic hash functions. For simplicity, this term is used below even if a data block that fits within the payload is dealt with.
[51] For the schemes involving digital signatures, it is assumed that a public-key infrastructure exists, and that the sender has a key pair (Pk, Sk). Sk is the sender's private signing key - which can be used for appending a digital signature to a message, and Pk is the Sughrue Docket No. CF104822 sender's public verification key which can be used to verify the authenticity of any signature issued using Pk. a(Sk, M) denotes the digital signature algorithm on message M under signing key Sk, and v(Pk, M, σ) denotes the verification algorithm. The intermediate does not need to know either the signing or the verification key. For the schemes involving MAC, it is assumed that both the initial sender S and the ultimate receiver R share knowledge of a symmetric key, which need not be known by the intermediaries.
[52] The schemes of the present invention make use of conventional constructs involving cryptographic compression functions. One such construct is an iterated hash function which is built from cryptographic compression functions as follows. Suppose a message M can be broken up into n blocks of length b, and H is a cryptographic compression function with a b- bit payload and a v-bit output. The iterated hash function defined by H is the value xn where:
x, = H(IV0, M,) x2 = H(xι, M2)
Xn = H(Xn-l, Mn)
[53] Assuming that it is hard to find collisions in the compression function H, it is then hard to find collisions in the iterated hash. Typically, when one wants to digitally sign a message, an iterated hash is applied to the message, and the resulting output is signed. The methods, systems, and components of the present invention will involve similar constructions, but intermediate values will be provided to aid in verification. Sughrue Docket No. CF104822 [54] Another conventional construct involving cryptographic compression functions is a Merkle tree. Fig. 6 shows a graphical depiction of a Merkle tree with eight leaves. Each leaf is the hash of the message below it. Each interior node represents the hash of its children. The root is signed. Suppose that M can be broken up into n blocks M = Mi ... Mn. For simplicity, assume that n is a power of 2. The schemes of the present invention can incorporate powers other than 2. The Merkle tree associated with M under hash function H is a binary tree in which each node is associated with a specific value. There are n leaves, and each leaf ., takes on the hash of ; - that is, H(IVo, Mi). Each interior (non-leaf) node then takes on the value associated with the hash of the concatenations of the values of its two children. That is, if vertex v has children vj and v where v_ has value xj and v has value x , then the value associated with v is H(IVo, xi xX).
[55] Merkle trees are often used in digital signatures whereby the value assigned to the root of the tree associated with the message M forming the digest is signed. If the underlying compression or hash function is collision resistant, then it will be hard to find two different messages whose Merkle root value is identical.
[56] The present invention also makes use of the notion of the co-nodes for a given vertex in a Merkle tree. The co-nodes of a vertex v consist of the direct siblings of the vertices on the path from v to the root. Given a vertex v and its co-nodes, one can compute the sequence of hash functions that lead from v to the root.
1. Subsequence Authentication
[57] The linear subsequence authentication scheme of the present invention allows stream authentication even when arbitrary blocks from the message are removed. As long as the Sughrue Docket No. CF104822 blocks sent by an intermediate node are a proper subsequence of the original message, the receiver can authenticate the stream.
1.1 Signing
[58] Fig. 7 illustrates a basic linear subsequence authentication scheme according to one embodiment of the present invention. Given a message M, signature generation follows a similar paradigm to an iterated hash, except that it uses "two hashing layers".
[59] Given a message M = M]M2 ... Mn, in one embodiment, the present invention generates partial hash computations hi,..., hn as follows: ho = IVo gi = H(h0, Mn) hi = H(h0, gi) g2 = H(h Mn-i) h2 = H(h], g2)
gtl = H(hn-ι, Mι)
Figure imgf000017_0001
[60] In the process of computing hj, ..., hn, the scheme shown in Fig. 7 computes auxiliary hash values gi,..., gn which are not sent. The initial sender S transmits (M, σsk(hn)). The value of IVo can be used as the IV for the computation of all the gi values. Sughrue Docket No. CF104822 [61] Alternatively, the sender S may decide to transmit the hash values hi along with the
message blocks ((Ml ,hn_l , σsk (hn)), (M2, hn_2),...(Mn ,h0j) .
1.2 Signature Update
[62] If an intermediate node wants to strip off k arbitrarily located message blocks, the node generates a resulting "message" M', identical to M but where k blocks have been removed. The receiver needs to be able to authenticate M'.
[63] Given the received n-block message M, the intermediate node computes "new" blocks
Mi ',... ,Mn '. For each message block ,._,+; (starting from the end, i = 1 to i = n), the intermediate node computes the corresponding auxiliary and partial hashes as follows:
gi = H(hi-ι, M„-M) ,
Figure imgf000018_0001
[64] Depending on whether the block will be forwarded or dropped, the intermediate node computes
Sughrue Docket No. CF104822
Mn '-i+ι ~ Mn-i+ι , if block , is forwarded, or gi, if block M{ is dropped (3)
[65] Let t be the index of the last message block that the intermediate node wants to send to the receiver, such that Mt'=Mt, and Mi'≠ Mi for all I > t. The intermediate node finally
transmits (Mx ' ,...Mn ' σSk (hn ), /.„_
[66] Some standard encoding is applied to the block contents to facilitate distinguishing between "message blocks" and "hashes". Skilled artisans would appreciate that there are numerous ways to perform this encoding.
[67] Alternatively, to enable on-line verification, the intermediate node transmits
((MJ,hn_1Sk (hnMM2 hn_2),...(Mn' ,h0))
1.3 Verification
[68] The receiver can verify the signature by computing hn from Mi ',...,Mk ' and hn.t as
follows: for each message block Mn_!H (starting from the end, i = 1 to i = ή), and depending
on whether the received block is a "message block" or a "hash", it computes
hi = H (/.,_, , H (/.,_, , M„'_M )) , if ,',_m is a "message block"
H (/*,_! , Mn '_M )) , if ,;_m is a "hash" (4)
[69] The receiver can then verify the signature on hn as normal using the verification algorithm v. Sughrue Docket No. CF104822 [70] The alternative on-line verification proceeds as follows: the receiver computes the partial hash h„ from (M'j, hn-ι) using relation (4) and then it verifies the signature on the partial hash hn. Afterwards, for i = 2,..., n, it computes the partial hash ., from (M',. /,„.,) using (4) and verifies that the so computed hash matches the hash value received in iteration i - I.
1.4 Security
[71] As mentioned above, the iterated hash construction is collision resistant so long as the underlying hash function H is as well. In particular, if one finds a collision in the iterated construction, then at some point there is an internal collision, which means one can find a collision on the hash function H. If an adversary can come up with a non-subsequence forgery (that is, a message/signature pair that is not obtained by merely talcing a subsequence of the original message), then it is possible to show that one can demonstrate either a collision in the hash function or a forgery on the underlying signature scheme. Therefore, as long as the signature scheme is not easily susceptible to forgery and the hash function is not easily susceptible to collisions, the scheme presented above is secure.
1.5 Performance
[72] When the intermediary removes blocks, it only needs to compute the hash of the block being removed. This computation does not involve any public-key steps and is fairly efficient. In fact, the throughput of algorithms like SΗA-1 is on the order of a few hundred megabits per second. Moreover, if the intermediate nodes are resource bounded with respect to computation, the source can follow the alternative approach and include the intermediate hi Sughrue Docket No. CF104822 values. In the case of SHA-1, each such value is 20-bytes long, so the bandwidth overhead will likely be quite small.
[73] A tradeoff between bandwidth usage and buffering/computation is possible by sending some intermediate /., values selectively. If the receiver can store up to b message blocks, then the intermediate node can send the hash value hn-b only after b message blocks. Authentication can be done as described above starting from hn.υ. Then, the intermediate node sends a second "bundle" (next b message blocks and hn.2b), which is authenticated by recomputing the partial hashes hn.b,..., hn.2b+ι and then verifying the recomputed hash value hn-b matching the one received in the first bundle.
[74] The computations of this embodiment do not require storing the entire stream in memory since only a single input block to the hash function is needed at any given time. [75] The scheme of the first embodiment permits the role of an intermediary which can adaptively and intelligently choose to remove any number of blocks without requiring knowledge of any cryptographic keying material. Moreover, the intermediary can be proximate to the receiver and can control the loss (and therefore the amount of hash information) dynamically. Furthermore, the authentication information can be verified in an online manner by the receiver. That is, the receiver can verify the authentication information as it receives the stream, and will not be required to do any form of extensive buffering. Also, the first layer hash computations are not required for any block that will not be dropped. For example, an MPEG I-frame or the base layer of a scalable coding scheme will not be intentionally dropped. For these blocks, only the second layer is required. In this instance, the first layer hash function for that block can be replaced with the identity function h(x) = x. In a similar spirit, if a given sequence of frames will either all be dropped or all be Sughrue Docket No. CF104822 kept, then the above scheme is even more advantageous since it can cluster these as a single block before hashing.
2. An Efficiency Improvement to the Subsequence Authentication [76] The second embodiment of the present invention provides an efficiency improvement to the basic linear subsequence authentication, by aggregating several first layer hashes before performing the second layer hashes. As a result, the method according to the second embodiment performs fewer second layer hashes. For a typical compression function, such as the one accompanying SHA-1, the payload size is 64 bytes whereas the digest size is 20 bytes. As a result, in this situation, three digests can be concatenated together before the second layer function is called. In the second embodiment, it is assumed that r hashes are
aggregated. In addition, for any decimal number a,
Figure imgf000022_0001
denotes the smallest integer greater
or equal than a, and \a~\ denotes the largest integer less or equal than a.
2.1 Signing
[77] For a message M, signature generation according to the second embodiment follows a similar paradigm to the scheme of the first embodiment, and uses "two hashing layers". However, the scheme of the second embodiment involves fewer hashes than that of the first embodiment. Fig. 8 shows an improved linear subsequence authentication scheme according to one embodiment of the present invention, with r=3 and with n a multiple of r. In this scheme groups of r first-layer hashes are hashed in the second layer. Given a message M = M]M ... Mn, the scheme of the second embodiment generates the partial hash computations hm, where m = as follows:
Figure imgf000022_0002
Sughrue Docket No. CF104822 gi = H(IVo,Mn)
Figure imgf000023_0001
gr = H(IVo,Mn.(r-l)) hi = H(IV0, gl,..., gr) gr+ι = H(IV0,Mn.r) gr+2 = H(IVo,Mn-(r+l))
g2r = H(IV0, Mn.(2r.i))
ll2 = H(h], gr+i,..., g2r)
Figure imgf000023_0002
H(IV0,M -r+2 n-(. -r+1) Sughrue Docket No. CF104822
*fl = BW-M^ -i)
Figure imgf000024_0001
g ] n ] = H(IV0,M , )
gn = H(IV0, Mi) hm = H(hm_l, g , n , ,..., „) (5)
[78] Similarly to the scheme of the first embodiment, in the process of computing hi,..., hm, the scheme of the second embodiment computes auxiliary hash values gi,..., gn which are not sent. The initial sender transmits (M, σsk(hm)), and the value of IVo can be used as the IV for the computation of all the gt values.
[79] Alternatively, the sender may decide to transmit the hash value h, along with every r-
th message block {(Mλ , σSk (h ), (M2),..., (Mr, hm_ ), ( r+1 ),..., (M2r,hm_2),...(Mn,h0)} .
2.2 Signature Update
[80] Now, suppose an intermediate node wants to strip off n - k arbitrarily located message blocks. It generates a resulting "message" M', identical to M but where n - k blocks have been removed. The receiver needs to be able to authenticate M'. Sughrue Docket No. CF104822 [81] Given the received n-block message M, the intermediate node computes "new" blocks M'ι,..., M'n. For each message block Mn-i+ι (starting from the end, i = I to i - n), it computes the corresponding auxiliary and partial hashes
gi = H(IV0, Mn-i+i) (6)
[82] Depending on whether the block will be forwarded or dropped, the intermediate node computes
Mn_M = Mn-i+ι , if block M. is forwarded, or gi, if block M{ is dropped (7)
[83] The hash values .„„..., hi are computed as in the signing operation. The intermediary
finally transmits (MX '.. ,Mn ' , σsk (hm )) .
[84] The above transmission requires buffering r packets to perform verification. In practice r will be quite small. For a SHA-1 based scheme r = 3 and for an MD-5 based scheme, r = 4. [85] Alternatively, the intermediary may transmit the hash values /., along with the "new"
message blocks (( σam)), (M2 ,),...,
Figure imgf000025_0001
( 2/ ,Λra_2),..., ( / ))-
2.3 Verification Sughrue Docket No. CF104822 [86] The receiver can verify the signature by computing hm from '. , ..., M'n as follows. First, for each message block M'n-m (starting from the end, i = 1 to i = n), and depending on whether the received block is a "message block" or a "hash", the receiver computes
g = H(/ι,_1 , M„.1+1 ) , if Mn '_M is a "message block"
Mn→l , if ,^ is a "hash" (8)
[87] Finally, the receiver computes hm:
hi = H(IV0, g'ι,..., g'r) ll2 = H(llj, g'r+l, ..., g'2r )
Figure imgf000026_0001
[88] The receiver can then verify the signature on hm as normal using the verification algorithm v.
[89] To perform online verification, the receiver needs to be able to compute the intermediate hash /.,. To do so, the receiver needs to buffer r blocks so it can compute the appropriate g values. The online verification of this scheme is analogous to that of the first embodiment. Sughrue Docket No. CF104822
2.4 Security
[90] Similarly to the first embodiment, so long as the signature scheme is not easily susceptible to forgery and the hash function is not easily susceptible to collisions, the scheme of the second embodiment is secure.
2.5 Performance
[91] Similarly to the first embodiment, when the intermediary removes blocks, it only needs to compute the hash of the block being removed.
[92] It takes less time for the subsequence scheme of the second embodiment to both compute and verify the signature compared to the subsequence scheme of the first embodiment, since only one second-layer hash is performed for every r first layer hashes. If r is chosen carefully (for example, setting r - 3 for SHA-1 or r = 4 for MD-5), then each second-layer hash only requires a single call to the compression function. So, in the second
embodiment, only compression function calls are made in the second layer compared to
the n calls in the first embodiment.
[93] In addition to the advantages of the first embodiment, the receiver of the second embodiment can verify the authentication information after receiving every r blocks. In practice, r will be fairly small - on the order of 2 or 3, thus reducing the number of the second layer hashes.
3. Simulcast Authentication: the Multiplex Scheme
[94] Now, assume the original sender S transmits k different streams M(1>, M 2), ..., M<k> simultaneously. Each stream consists of n blocks of length b, M<j> = M ] ,...,Mn (j>. The Sughrue Docket No. CF104822 scheme of the third embodiment allows the intermediate node not only to select one stream and retransmit it in an authenticated fashion, but also to "switch" to some other stream adaptively (at any point during block transmission). Of course, the receiver should be able to authenticate the resulting stream.
3.1 Signing '
[95] Fig. 9 shows a basic linear simulcast authentication scheme according to one embodiment of the present invention. Given a message M, signature generation follows the same approach as in the first and second embodiments, i.e., reverse iterated hash, but computing partial hashes of every block in each stream.
[96] Given messages M 1*, N 2), ..., M(k> , where M(j> = M j> , M2 ϋ>, ...,Mn , the scheme of the third embodiment of the present invention generates the partial hash computations hi,..., hn as follows:
d^ = H(M^) d = H(M )
d[k) ^ H(M^) = H(lι0,d] (1) -,Λ Sughrue Docket No. CF104822
d^ = H(M\ dl)) d ( 2 ) H ( M ( 2 Δ }) )
) = H(Mχ « w>)>>
(i) = H(/ l,_i,^..., ^ (10)
[97] The initial sender transmits σsk(hn) and then sends M<1),...,M(k) simultaneously. In practice, the message blocks of the different streams will be interleaved in the transmission.
3.2 Signature Update
[98] Suppose an intermediate node wants to select a possibly different stream (message) for each message block received. For instance, if each message encodes a video stream of different quality, the intermediate node may want to select a lower or higher quality depending on network congestion. It generates a "resulting message" M', comprising "chunks" (consecutive message blocks) of the different streams. The intermediate node may pick a single stream (message) at each moment. It should be understood that the present invention allows for the possibility of layered streams. The receiver needs to be able to authenticate M'. Sughrue Docket No. CF104822 [99] Given the received n-block messages M(1>,.., M"k}, the intermediate node computes
"new" blocks M'h.., M'n . For each set of message blocks M^→l ,... , M[k + , (starting from
the end, i = I to i = n), it computes the partial hashes
d^=H M^ l) ^=H( ^+I)
Figure imgf000030_0001
[100] Then if stream I is chosen, 1< I < k, it computes
Figure imgf000030_0002
[101] The intermediate node finally transmits (Mv..Mn, σSk («„) .
[102] Alternatively, to enable on-line verification, the intermediate node transmits
(M,hn_,σsk(hn)),(M ,hn_2),...,(Mn ', )) (13) Sughrue Docket No. CF104822 3.3 Verification
[103] The receiver can verify the signature by computing hn from M'ι, ..., M and h0 = _V0 . For each message block M'n.l+ι (starting from the end, i = I to i = n) if M'n.l+ι is of the form
M = (dm d l~l) Mil) d ) dw)
[104] then, the receiver computes
dM = H MM+ι ) h, = H(\_ d[l ...,d?-l d *1 ...,dlk ) (14)
[105] The receiver can then verify the signature on hn as normal using the verification algorithm v.
[106] The alternative on-line verification procedure is straightforward. The receiver computes the partial hash hn from (M'ι, hn-ι) using relation (14) and then it verifies the signature on the partial hash /.„. Afterwards, for i = 2,..., n, it computes the partial hash h, from (M , /ι„.,) using (14) and verifies the so computed hash matches the hash value received in iteration i - 1.
3.4 Performance Sughrue Docket No. CF104822 [107] In addition to the advantages of the scheme of the first embodiment, the hash step of the scheme of the third embodiment can be iterated using a compression function with either the linear chaining scheme or a Merkle scheme.
[108] By using a Merkle tree-like construction to hash down each sequence of blocks J ),..., i (i) , bandwidth can be saved at the cost of more intensive computation (by the
intermediate node).
4. Tree Scheme for Subsequence Authentication
[109] The fourth embodiment of the present invention is a scheme for authenticating subsequences using Merkle Trees. Like the linear subsequence authentication scheme, the tree-based scheme allows stream authentication even when arbitrary blocks from the message are removed. As long as the blocks sent by the intermediate node are a proper subsequence of the original message, the receiver can authenticate the stream. By exploiting certain aspects of the tree structure, the tree scheme is more efficient with respect to bandwidth than the linear scheme.
4.1 Signing
[110] Fig. 10 illustrates a tree-based subsequence authentication scheme according to one embodiment of the present invention. Given a message M = M]M2...Mn, the scheme of the fourth embodiment generates a Merkle tree shown in Fig. 6. If v denotes the root of the tree and x denotes the value associated with the root, then the initial sender transmits (M, σsk(x))-
4.2 Signature Update Sughrue Docket No. CF104822 [111] If an intermediary wants to strip off k arbitrarily located message blocks, the intermediary generates a resulting "message" M', identical to M, but with k blocks removed. The receiver needs to be able to authenticate M'. Let di, ..., d denote the indices of the blocks that will be dropped and let _?_,..., sn-k denote the blocks that will stay. Given the received n- block message M, the intermediate node computes the corresponding authentication information as follows.
1) For all blocks Md ,..., Mdk that are to be dropped, the intermediary first determines
the set of vertices corresponding to leaves ld ,—lά. in the Merkle tree associated with these
blocks. 2) If any pair of vertices are siblings in the Merkle tree, the intermediary replaces these two vertices both with their parent. 3) The intermediary keeps repeating the above process until no two vertices in the set are siblings. 4) The intermediary takes this set of vertices, and computes the Merkle tree values X],..., xr associated with them. The intermediary can easily perform this step since the cryptographic hash function is globally computable.
[112] The intermediate node finally transmits
[113] Similarly to other embodiments of the present invention, applying standard encoding to the block contents facilitates distinguishing between "message blocks" and "hashes".
4.3 Verification Sughrue Docket No. CF104822 [114] The receiver verifies the signature by computing the value of the root of the Merkle tree, using the following algorithm:
1) For every actual message block Ms received, compute the value
y, = H(/V0, ) .
2) Consider the set of all hashes yi,..., yn-k, x_ , • • • , xr. Each of these corresponds to values of vertices in a Merlde tree. 3) For each pair of values, if they correspond to vertices who are siblings, then replace the pair with their hash (which corresponds to the parent node). 4) Repeat the above step until only one value remains - this value is the root. [115] If one has all the initial message blocks, then the above algorithm constitutes the standard algorithm for computing the root of a Merkle tree. Whenever the receiver receives some hashes xi,..., xr, these come from the intermediary running the same algorithm on the subset of missing blocks. Therefore, the intermediary and receiver have together n the algorithm on all n blocks which yield the value of the Merkle root. This is why the above computation yields the Merkle root.
[116] With the value of the Merkle root, the receiver can verify the signature it receives.
4.4 Security
[117] The Merkle hash construction is collision resistant so long as the underlying hash function H is collision resistant. In particular, if one finds a collision in the Merlde tree, then at some point there is a collision at an internal node, which means one can find a collision on the hash function H. If an adversary can come up with a non-subsequence forgery (that is, come up with a message/signature pair that is not obtained by merely taking a subsequence of Sughrue Docket No. CF104822 the original message), then one can demonstrate either a collision in the hash function or a forgery on the underlying signature scheme. Therefore, as long as the signature scheme is not easily susceptible to forgery and the hash function is not easily susceptible to collisions, the scheme of the fourth embodiment is secure.
4.5 Performance
[118] When the intermediary removes blocks, it needs to provide the receiver with a sufficient number of internal hashes to compute the Merkle root of the tree without those message blocks. The intermediary will require k hashes for each of the blocks to be dropped and then at most k - I hashes when replacing pairs of hashes with a single hash (since a single hash results in replacing two values with a single one, thereby reducing the net number by one). The total computation is therefore at most 2k-I hashes. The total hashes computed by the intermediary are denoted by t.
[119] When the receiver receives the stream, it needs to compute the root. If it has all the message blocks, this would require 2n - I hashes - n to initially hash each block, and then n
- 1 additional hashes when replacing pairs of hash values with a single hash (since a single function computation results in replacing two values with a single one, and at the end only one value is remaining). However, t of these hashes are computed by the intermediary. Therefore the receiver only has to compute 2n - 1 - t hashes.
[120] The total work in this scheme between the intermediary and the receiver is at most 2n
- 1 hashes. In the previous linear schemes 2n hashes were required.
[121] In terms of bandwidth, the tree based scheme may be much more efficient. Only r < k hashes are finally sent. In the best case, if all k blocks to be dropped entirely constitute all leaves of a subtree in the Merkle tree, then only the single value corresponding to the root of Sughrue Docket No. CF104822 this subtree is sent, that is r = I. In the worst case, if no pair of blocks are siblings, then the bandwidth requirements are the exact same as in the linear case, and k hash values need to be sent.
5. Tree Scheme for Simulcast Authentication
[122] The fifth embodiment of the present invention is a tree-based scheme for authenticating multiple parallel streams in which one data block is selected from one stream at each step of the transmission. As in the linear multiplex setting of the third embodiment, it is assumed that the original sender S transmits k different streams M(1>, M(2>,..., fk) simultaneously. Each stream consists of n blocks of length b, M(j> =
Figure imgf000036_0001
M„(j). This scheme allows the intermediate node not only to select one stream and retransmit it in an authenticated fashion, but also to "switch" to some other stream adaptively (at any point during block transmission). Of course, the receiver is able to authenticate the resulting stream. As in the tree-based scheme for subsequence authentication of the fourth embodiment, the scheme of the fifth embodiment exploits certain aspects of the tree stmcture, so as to be more efficient with respect to bandwidth than the analogous linear scheme. On the other hand, like the tree construct of the fourth embodiment, the scheme of the fifth embodiment does not readily lend itself to online verification. Instead, the receiver has to wait for all packets before it can verify. In practice, the delay can be reduced by splitting the stream into segments of reasonable size and authenticating each segment separately.
5.1 Signing
[123] Given k different streams M11', M(2>,..., ^, the signature generation of the scheme of the fifth embodiment works as follows. Sughrue Docket No. CF104822 1) The signer first generates a separate Merkle tree for each stream. Let v(1>,..., v(k) denote the k roots of the tree, and let x(1>, ..., x(k> denote the respective values associated with these roots. 2) The signer then computes x = H(IV, x(1>,..., x(k>). Here the hash function H can be computed using a Merkle tree construction as well. 3) Finally, the signer transmits (M, σs (x))-
5.2 Signature Update
[124] Now, suppose an intermediate node wants to select a possibly different stream (message) for each message block received. For instance, if each message encodes a video stream of different quality, the intermediate node may want to select a lower or higher quality depending on network congestion. It generates a resulting "message" M', comprising "chunks" (consecutive message blocks) of the different streams. The receiver needs to be able to authenticate M'.
[125] If the receiver can accurately compute each of the xt values, then it can verify the signature. Therefore, the intermediary simply has to provide the user with the information necessary to compute these values. By treating each Merkle tree separately, the intermediary can compute the set of required values as it did in the Merkle scheme of the fourth embodiment. The intermediary transmits these values to the receiver which can then compute the x. values and in-turn verify the authentication information. [126] Specifically, for each i with 1 ≤ i ≤ k, let ks(i) denote the number of blocks that will
actually be sent from stream M(l). For the stream M(l), let s[l) ,..., sk^t) denote the indices of
the blocks that will be included. Let MM denote these blocks: Sughrue Docket No. CF104822
M\i) = Mχι, ...M (16)
[127] As to the indices of blocks that are to be dropped, for each i with I ≤ i ≤ k, let kd(i) denote the number of blocks that will actually be dropped from stream M^'K For the stream
M(l let d[l) ,..., dj ) denote the indices of the blocks that will be dropped.
[128] As in the tree scheme of the fourth embodiment, for each stream M^l) the intermediary computes the values necessary for the receiver to verify as follows:
1) For all blocks M(X ,...,M(X that are to be dropped, the intermediary first
determines the set of vertices corresponding to leaves I w ,...,. (1) in the Merkle tree
associated with these blocks. 2) Now, if any pair of vertices are siblings in the Merkle tree, the intermediary replaces these two vertices both with their parent, i.e., the hash of concatenation of the values associated with the siblings. 3) The intermediary keeps repeating the above process until no two vertices in the set are siblings. 4) The intermediary takes this set of vertices, and computes the Merkle tree values
X(,) = x[0 ,...,xr ('} associated with them. The intermediary can easily perform this step since
the cryptographic hash function is globally computable.
[129] The intermediate node finally transmits the following information:
({M'(1) ,...,M'w} σSk (x), Xm ,..., X ) (17) Sughrue Docket No. CF104822 [130] The stream is sent in the proper order, that is, blocks from each of the M(l) may be interleaved so that the receiver can view the stream. Some standard encoding is applied to the block contents so the receiver can distinguish between message blocks versus hash values.
5.3 Verification
[131] The receiver verifies the signature by first computing the values of the roots of each of the Merkle trees - after that it hashes these values and verifies the signature. It achieves this goal using the following algorithm which is run for each i:
1) First, for every actual message block M 1 ) received, the receiver computes the
value y = H(IV0,M^) .
2) Consider the set of all hashes computed above in the previous step as well the hash values contained in sets X(1>,..., X" > received in the transmissions. 3) For each pair of values, if the pair corresponds to vertices who are siblings, then replace the pair with their hash (which corresponds to the parent node in the Merlde tree). 4) Repeat the above step until only one value remains - this value is the root x ).
[132] If one has all the initial message blocks, then the above algorithm constitutes the standard algorithm for computing the root of a Merlde tree. Whenever the receiver receives
some hashes
Figure imgf000039_0001
,...,xr (l) , these come from the intermediary running the same algorithm on the
subset of missing blocks. Therefore, the intermediary and receiver have together run the algorithm on all n blocks which yield the value of the Merlde root. This is why the above computation yields the Merlde root. Sughrue Docket No. CF104822 [133] With the values of the Merlde roots, x(1>, ..., x(k>, the receiver can compute
x = H(IV, x ),...,x k) ) and verify the signature it receives.
[134] Fig. 11 illustrates the signing and verification of the fifth embodiment of the invention, an example with four streams and four message blocks. As shown, each of the four streams M(1), M(2>, M<3), M(4) consists of four blocks. The black leaves denote the message blocks that are actually sent. The remaining ones are dropped. The shaded vertices represent the cover; that is, the values corresponding to these vertices are sent to the receiver. The roots of the four Merkle trees are x(1>, x(2), x^.and x<4) respectively. The final root value x is computed by hashing the Merkle roots x(1>, x(2>, x(3>, x(4>. This hash can be also be performed in a Merkle-like fashion. Finally, the value x is actually signed. In this scheme only six hash values are sent to the receiver. In the linear simulcast scheme, twelve hashes (three per each block transmitted) would have been transmitted. Thus, savings is achieved whenever dropped blocks are clustered. For example, in Fig. 11, all blocks in the stream M(4> are dropped. As a result, one only needs to send the root x(4> of the associated Merkle tree. [135] Also, because the Merkle roots are themselves hashed in a Merkle-like construction, there is room for further optimization. In particular, suppose that all blocks are dropped for two entire subtrees whose Merkle roots are siblings in the even larger tree. Then, instead of sending the two Merlde roots, their hash could be sent.
5.4 Security
[136] Similarly to the fourth embodiment, the fifth embodiment is secure as long as the signature scheme is not easily susceptible to forgery, and the hash function is not easily susceptible to collisions. Thus the invention presented above is secure. Sughrue Docket No. CF104822 5.5 Performance
[137] The performance of the fifth embodiment can be analyzed by extending the analysis for the tree-based subsequence scheme and the linear simulcast scheme. [138] In all embodiments above, a hash function with a specific payload size and a specific IV is used. The chaining constructions tend to take some existing output and use that as the IV of the next block. In a further embodiment, instead of loading the current output as an IV, the current output can be concatenated to the next payload.
[139] The linear and tree schemes of the present invention can be combined to obtain hybrid solutions, giving rise to useful tradeoffs. In a further embodiment, a scheme starts by splitting each stream M(l> into segments of length b blocks. Then, a tree scheme is applied on the first segment of all streams to compute the Merkle root xj, then the root on the second
segment, and so on, until all segments are processed. In this way, Merkle roots , ,..., x\ n/b \
are obtained. Instead of signing each one of these roots, as in the tree schemes described above, the roots are combined using the linear scheme. Hence, if the receiver can buffer b blocks, then verification can be done "on-line". Moreover, the communication overhead is decreased compared to the plain linear scheme since for each segment of b blocks, the number of transmitted hashes may be much less than the number of dropped blocks (although equal on the worst case). A similar approach can be taken for subsequence authentication.
This hybrid approach allows trading buffer space for communication overhead.
[140] In a further embodiment, a linear scheme is applied to each stream, and then a Merkle tree is computed on the results.
[141] Although the embodiments described above use binary Merkle trees, the constructions can be applied to general trees. It may be more advantageous to group certain blocks together if they have. similar behavior; i.e., they either all will be dropped or all will be kept. Sughrue Docket No. CF104822
[142] If there are correlations among blocks, then it makes sense to cluster these blocks together in the tree-based schemes. For example, if a group of blocks will either all be dropped or all be kept, it is advantageous to have these blocks constitute all the leaves of a subtree. Then, if the packets are dropped, only the root of the subtree must be sent.
[143] In addition, the Merkle tree construction could be optimized. In one embodiment, if one of the streams will more likely be used than the others, it is advantageous to use a lopsided Merkle tree in which the priority stream is close to the root (e.g., perhaps right below it). In conjunction with the hybrid scheme mentioned previously, the streams are prioritized, so that the high priority streams are closer to the final value in the chain. This ordering particularly makes sense when layered streams are used. In such cases, the verification requires fewer hash steps to reach the root.
[144] There are blocks that should never be dropped, such as, an I frame in an MPEG stream, or the base layer in a scalably coded stream. The signer can avoid directly computing the initial first-layer hash on a block that will not be dropped. In the linear schemes, there are two hash layers. If a block will not be dropped, then there is no need to compute the hash in the first layer; instead only the second layer needs to be computed.
[145] The schemes of the present invention can be interpreted as having two phases. In the first phase, it finds a convenient way to hash each data block. In the second phase, it signs the hashes. The reason for doing so is that if a block is dropped, it is not necessary to retransmit it in its entirety. Instead, only the hash computed in the first phase is transmitted.
This information is sufficient to allow the receiver to verify, since the signature can be viewed as being performed on the hashes.
[146] As already mentioned, the present invention deals with a case of controlled loss - that is, the sender drops particular blocks on purpose. Of course, in many practical applications, Sughrue Docket No. CF104822 one may have to deal with uncontrolled loss situations. These situations may occur, for example, if the transport protocol is not reliable such as the case with UDP, or if the environment is subject to lossy behavior such as is the case with wireless networks. The present invention can be used to deal with the uncontrolled loss by replicating the hashes that would be sent if the packet were dropped.
[147] By applying Forward Error Correction (EEC) techniques such as Erasure Codes to the hashes of the present invention, it is possible to deal with the uncontrolled loss situation without having to replicate. This approach might be especially useful in a multicast setting where different receivers have lost different packets but can be provided with identical error- correcting information. One consideration of this approach is that the receiver must perform a decoding step so may have to compromise the ability to verify authentication information in an online manner.
[148] Moreover, schemes of the present invention involve an intermediary which can adaptively choose the amount of forward error correction to the authentication information (i.e., hash outputs). In other words, rather than having a source estimate how much loss will occur and include sufficient authentication forward error correction information to accommodate that, the source can choose not to include authentication forward error correction information at all, and instead allow an intermediary to include the authentication forward error correction information dynamically to further increase the probability that the stream can be authenticated.
[149] The intermediary becomes an integral part of a scheme which considers both uncontrolled losses handled through forward error correction as well as adaptive and intelligent controlled losses. For example, in the Merlde tree constructions, it may suffice for the recipient to recover intermediate nodes (as opposed to just leaf nodes). In such a case, the Sughrue Docket No. CF104822 intermediary can choose to supply forward error correction information to allow recovery of the (possibly interior) nodes necessary to authenticate, thus requiring possibly less forward error correction information.
[150] If the intermediary is sending different versions of the same stream to multiple receivers, because, for example, each has a different resource constraint with respect to the quality they view, the intermediary can recycle the work effort. In particular, the intermediary can store and reuse any first-layer hash. As a result, it will need to compute at most one full set of first-layer hashes.
[151] Along these lines, work can be recycled between the source and the intermediary.
That is, the source can provide the intermediary with any necessary hash computations for assisting with authentication. Then, the intermediary is not required to perform any work of a cryptographic nature. Instead, it can choose which blocks to drop and select the corresponding authentication information to be transmitted.
[152] Another application of the present invention is insertion and selection of advertisements in a stream. The intermediary or some other party provides advertisements or a hash of advertisements, for example hashed using a Merlde tree, to the source. The source then includes the Merkle hash in its stream as a placeholder, allowing the intermediary to choose which advertisement it would like to use. Of course, this concept is not necessarily limited to advertisers.
[153] Although the focus of the present invention is on authenticating information, the above scheme can also be used in conjunction with an encryption scheme provided that the scheme is designed to permit the recipient to decrypt a given block without requiring the decryption of or presence of many other blocks. Two block cipher encryption modes facilitate this approach. One is counter-mode encryption and the other is electronic code Sughrue Docket No. CF104822 book (ECB) encryption. Alternatively, it is possible to use a stream cipher, though a caveat is that the receiver may need to perform work that is proportional to the size of the original stream as opposed to the portion of it that he receives. One may be able to use chaining or feedback modes (cipher block chaining (CBC), output feed back (OFB), etc) provided that the receiver receives any intermediate information to decrypt. Such information may include intermediate IVs or actual ciphertext blocks. Yet another approach is to mix the modes, i.e., for large segments which will not be dropped, a chaining or feedback mode can be used; whereas for other blocks, a counter mode or ECB mode can be used. For example, in an MPEG stream, I-frames are never dropped intentionally, so they can be treated differently and encrypted using CBC mode. A similar remark applies to the base layer of any scalable coding scheme.
[154] While the invention has been described in detail above with respect to various embodiments, the ordinarily skilled artisan will appreciate that variations of these embodiments are possible without departing from the scope and spirit of the invention. Therefore, the invention should be considered as limited only by the scope of the appended claims.

Claims

Sughrue Docket No. CF104822 WHAT IS CLAIMED IS:
1. A method for communicating data between a server and a receiver, said method comprising: signing at least one original data stream which includes a plurality of blocks; generating an intermediate data stream for the signed data stream, with arbitrary blocks adaptively removed without censoring the blocks of the original data stream; communicating the intermediate data stream to the receiver; and authenticating the intermediate data stream at the receiver.
2. The method according to claim 1, wherein signing the original data stream further comprises generating a hash computation comprising auxiliary hash values and partial hash values.
3. The method according to claim 2, wherein generating the intermediate data stream further comprises computing the partial hash values and auxiliary hash values for each block of the signed data stream.
4. The method according to claim 2, wherein the intermediate data stream comprises: data stream blocks to be sent to the receiver; and auxiliary hash values for the blocks to be removed.
5. The method according to claim 4, further comprising determining, at the receiver, whether a received block is a data stream block.
Sughrue Docket No. CF104822 6. The method according to claim 4, further comprising recomputing, at the receiver, the partial hash value for the data stream block.
7. The method according to claim 6, further comprising verifying, at the receiver, the signature on the recomputed partial hash value.
8. The method according to claim 2, further comprising aggregating several auxiliary hash values before computing a partial hash value.
9. The method according to claim 1, wherein signing the original data stream further comprises generating a Merkle tree for the original data stream and computing a value associated with a root of the Merkle tree.
10. The method according to claim 9, wherein the intermediate data stream comprises: Merkle tree values for the receiver to recompute the root of the Merkle tree; and data stream blocks.
11. The method according to claim 9, wherein generating the intermediate data stream further comprises: determining a set of vertices corresponding to leaves in the Merlde tree associated with the blocks to be removed; if any pair of vertices are siblings in the Merkle tree, replacing these two vertices with their parent; and otherwise, computing the Merkle tree values associated with vertices.
Sughrue Docket No. CF104822 12. The method according to claim 11, further comprising recomputing, at the receiver, the value of the root of the Merkle tree.
13. The method according to claim 11, wherein the replacing step is repeated until there are no pair of vertices that are siblings remaining.
14. The method according to claim 12, further comprising verifying, at the receiver, the signature with the value of the root of the Merkle tree.
15. The method according to claim 1, wherein signing the original data stream further comprises computing partial hash values of each block of each original data stream to compute a multi-layer hash chain.
16. The method according to claim 15, wherein generating the intermediate data stream further comprises computing the partial hash values for each block of each signed data stream.
17. The method according to claim 15, wherein the intermediate data stream comprises data stream blocks adaptively selected from different data streams.
18. The method according to claim 15, further comprising recomputing, at the receiver, the partial hash value for each block of the intermediate data stream.
19. The method according to claim 18, further comprising verifying, at the receiver, the signature on the recomputed partial hash value.
20. The method according to claim 1, wherein signing the original data streams further comprises: Sughrue Docket No. CF104822 generating a Merkle tree for each of the original data streams; computing a value associated with a root of each of the Merkle trees; and generating a final root value by hashing the values of the roots of the Merkle trees.
21. The method according to claim 20, wherein the intermediate data stream comprises: data stream blocks; and Merkle tree values for the receiver to recompute the root of the Merkle tree.
22. The method according to claim 20, wherein generating the intermediate data stream further comprises: determining, for each signed data stream, a set of vertices corresponding to leaves in the Merkle tree associated with the blocks to be removed; if any pair of vertices are siblings in the Merkle tree, replacing these two vertices with their parent; and otherwise, computing the Merlde tree values associated with vertices.
23. The method according to claim 22, wherein the replacing step is repeated until there are no pair of vertices that are siblings remaining.
24. The method according to claim 20, further comprising recomputing, at the receiver, the values of the roots of each Merlde tree.
25. The method according to claim 24, further comprising recomputing, at the receiver, the final root value by hashing the values of the roots of the Merkle trees.
Sughrue Docket No. CF104822 26. The method according to claim 25, further comprising verifying, at the receiver, the signature with the final root value.
27. The method according to claim 25, wherein the final root value is recomputed by an iterated hash.
28. The method according to claim 25, wherein the final root value is recomputed by a Merkle hash.
29. The method according to claim 9, wherein the Merkle tree is lopsided.
30. The method according to claim 20, wherein the Merkle tree is lopsided.
31. The method according to claim 9, further comprising forming a subtree by a group of blocks which will all be removed.
32. The method according to claim 20, further comprising forming a subtree by a group of blocks which will all be removed.
33. The method according to claim 9, further comprising forming a subtree by a group of blocks which will all be sent.
34. The method according to claim 20, further comprising forming a subtree by a group of blocks which will all be sent.
35. The method according to claim 20, wherein the final root value is generated by an iterated hash.
Sughrue Docket No. CF104822 36. The method according to claim 20, wherein the final root value is generated by a Merkle hash.
37. The method according to claim 1, further comprising deteπnining blocks that will never be removed.
38. The method according to claim 37, further comprising applying identity function as a first layer hash when the blocks will never be removed.
39. The method according to claim 2, further comprising applying Forward Error Correction (FEC) techniques to the hash values.
40. The method according to claim 15, further comprising applying Forward Error Correction (FEC) techniques to the hash values.
41. The method according to claim 1, wherein signing the original data stream uses a digital signature.
42. The method according to claim 41, wherein the digital signature is applied to final hash values of the blocks of the original data stream.
43. The method according to claim 1, wherein signing the original data stream uses message authentication codes.
44. The method according to claim 43, wherein the message authentication codes are applied to final hash values of the blocks of the original data stream.
45. The method according to claim 1, wherein the removed data stream blocks include advertisements. Sughrue Docket No. CF104822 46. A system for communicating data between a server and a receiver,
comprising: a signer signing at least one original data stream which includes a plurality of blocks; a data stream generator generating an intermediate data stream for the signed data stream, with arbitrary blocks adaptively removed without censoring the blocks of the original data stream; a receiver authenticating the intermediate data stream.
47. The system according to claim 46, wherein the signer generates a hash computation comprising auxiliary hash values and partial hash values.
48. The system according to claim 47, wherein the data stream generator receives the signed data stream, and computes the partial hash values and auxiliary hash values for each block thereof.
49. The system according to claim 47, wherein the receiver receives the intermediate data stream and recomputes the partial hash value for the data stream block.
50. The system according to claim 47, wherein the signer aggregates several auxiliary hash values before computing a partial hash value.
51. The system according to claim 46, wherein the signer computes values associated with a root of a Merkle tree generated for an original data stream.
52. The system according to claim 51, wherein the data stream generator: receives the signed data stream; Sughrue Docket No. CF104822 determines a set of vertices corresponding to leaves in the Merkle tree associated with the blocks to be removed; if any pair of vertices are siblings in the Merkle tree, replaces these two vertices with their parent; and otherwise, computes the Merlde tree values associated with vertices.
53. The method according to claim 52, wherein the replacing step is repeated until there are no pair of vertices that are siblings remaining.
54. The system according to claim 51, wherein the receiver receives the intermediate data stream and recomputes the value of the root of the Merkle tree.
55. The system according to claim 46, wherein the signer computes partial hash values of each block of each data stream to compute a multi-layer hash chain.
56. The system according to claim 55, wherein the data stream generator receives the signed data stream and computes the partial hash values for each block of each signed data stream.
57. The system according to claim 55, wherein the receiver receives the intermediate data stream and recomputes the partial hash value for each block of the intermediate data stream.
58. The system according to claim 46, wherein the signer: generates a Merkle tree for each of the original data streams; computes a value associated with a root of each of the Merlde trees; and Sughrue Docket No. CF104822 generates a final root value by hashing the values of the roots of the Merlde trees.
59. The system according to claim 58, wherein the data stream generator: receives the signed data stream; determines, for each signed data stream, a set of vertices corresponding to leaves in the Merlde tree associated with the blocks to be removed; if any pair of vertices are siblings in the Merkle tree, replaces these two vertices with their parent; and otherwise, computes the Merkle tree values associated with vertices.
60. The method according to claim 59, wherein the replacing step is repeated until there are no pair of vertices that are siblings remaining.
61. The system according to claim 58, wherein the receiver receives the intermediate data stream and recomputes the values of the roots of each Merkle tree.
62. A computer program product containing program code for performing a method of signing an original data stream, the method comprising: decomposing at least one original data stream into a plurality of blocks; computing ancillary information selected from the group consisting of partial hash values of blocks of the signed data stream, values associated with a root of a Merlde tree generated for the original data stream, a multi-layer hash chain computed from partial hash values of each block of each data stream, and a final root value computed by hashing values of roots of Merkle trees, each of which corresponds to an original data stream; Sughrue Docket No. CF104822 computing authentication information for each block based on the ancillary information; generating a signed data stream comprising the original data stream and the authentication information; and generating an intermediate data stream by adaptively removing arbitrary blocks without censoring the original data stream, wherein the intermediate data stream can be authenticated by a receiver.
63. The computer program product according to claim 62, wherein a digital signature is used for authentication.
64. The method according to claim 63, wherein the digital signature is applied to final hash values of the blocks of the original data stream.
65. The computer program product according to claim 62, wherein message authentication codes are used for authentication.
66. The method according to claim 65, wherein the message authentication codes are applied to final hash values of the blocks of the original data stream.
67. The method according to claim 62, wherein the ancillary information is computed at a signer.
68. The method according to claim 62, wherein the ancillary information is computed at an intermediary.
Sughrue Docket No. CF104822 69. A computer program product containing program code for performing a method of adaptively removing arbitrary blocks from a signed data stream for an original data stream, the method comprising: determining to-be-sent data stream blocks in the signed data stream without censoring the original data stream; adaptively removing other blocks in the signed data stream by generating an intermediate data stream; and sending the intermediate data stream to a receiver for authentication.
70. The computer program product according to claim 69, wherein the method further comprises computing the partial hash values and auxiliary hash values for each block of the signed data stream.
71. The computer program product according to claim 70, wherein the intermediate data stream comprises to-be-sent data stream blocks and the auxiliary hash values for the blocks to be removed.
72. The method according to claim 70, further comprising transmitting the partial hash values and auxiliary hash values.
73. The computer program product according to claim 69, wherein the method further comprises: determining a set of vertices corresponding to leaves in the Merkle tree associated with the blocks to be removed; if any pair of vertices are siblings in the Merkle tree, replacing these two vertices with their parent; and Sughrue Docket No. CF104822 otherwise, computing the Merkle tree values associated with vertices.
74. The computer program product according to claim 73, wherein the intermediate data stream comprises to-be-sent data stream blocks and Merkle tree values associated with the blocks to be removed.
75. The method according to claim 73, wherein the replacing step is repeated until there are no pair of vertices that are siblings remaining.
76. The computer program product according to claim 69, wherein the intermediate data stream comprises data stream blocks adaptively selected from different data streams.
77. A computer program product containing program code for performing a method of authenticating an intermediate data stream, the method comprising: distinguishing data stream blocks in the intermediate data stream, which is derived from an original data stream, but has some data removed from it; computing ancillary information for blocks in the intermediate data stream, the ancillary information being selected from the group consisting of partial hash values of blocks of the intermediate data stream, values associated with a root of a Merkle tree generated for the original data stream, a multi-layer hash chain, and a final root value computed by hashing values of roots of Merkle trees generated for original data streams; and verifying authentication information.
78. The computer program product according to claim 77, wherein a digital signature is used for authentication.
Sughrue Docket No. CF104822 79. The computer program product according to claim 77, wherein message authentication codes are used for authentication.
80. A server in a data communication network, comprising a processor and the computer program product according to claim 62.
81. An intermediate node in a data communication network, comprising a processor and the computer program product according to claim 69.
82. A receiver in a data communication network, comprising a processor and the computer program product according to claim 77.
PCT/US2004/025513 2003-08-15 2004-08-04 Method and apparatus for authentication of data streams with adaptively controlled losses WO2005017809A2 (en)

Priority Applications (4)

Application Number Priority Date Filing Date Title
JP2006523251A JP4809766B2 (en) 2003-08-15 2004-08-04 Data stream authentication method and apparatus adaptively controlling loss
US10/543,640 US20060136728A1 (en) 2003-08-15 2004-08-04 Method and apparatus for authentication of data streams with adaptively controlled losses
US12/560,959 US8256015B2 (en) 2003-08-15 2009-09-16 Method and apparatus for authentication of data streams with adaptively controlled losses
US12/560,963 US20100005310A1 (en) 2003-08-15 2009-09-16 Method and apparatus for authenication of data streams with adaptively controlled losses

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US49578703P 2003-08-15 2003-08-15
US60/495,787 2003-08-15

Related Child Applications (3)

Application Number Title Priority Date Filing Date
US10543640 A-371-Of-International 2004-08-04
US12/560,959 Division US8256015B2 (en) 2003-08-15 2009-09-16 Method and apparatus for authentication of data streams with adaptively controlled losses
US12/560,963 Division US20100005310A1 (en) 2003-08-15 2009-09-16 Method and apparatus for authenication of data streams with adaptively controlled losses

Publications (2)

Publication Number Publication Date
WO2005017809A2 true WO2005017809A2 (en) 2005-02-24
WO2005017809A3 WO2005017809A3 (en) 2005-09-22

Family

ID=34193346

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2004/025513 WO2005017809A2 (en) 2003-08-15 2004-08-04 Method and apparatus for authentication of data streams with adaptively controlled losses

Country Status (3)

Country Link
US (3) US20060136728A1 (en)
JP (1) JP4809766B2 (en)
WO (1) WO2005017809A2 (en)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2007093946A1 (en) * 2006-02-14 2007-08-23 Koninklijke Philips Electronics N.V. Improved method of content protection
WO2007093925A1 (en) * 2006-02-14 2007-08-23 Koninklijke Philips Electronics N.V. Improved method of content protection
EP1944907A1 (en) * 2005-11-04 2008-07-16 NEC Corporation Message authentication device, message authentication method, message authentication program, and recording medium therefor
EP2107711A1 (en) * 2008-03-03 2009-10-07 Fujitsu Ltd. Method and apparatus for digital signature authentication, and computer product
US8037312B2 (en) 2007-01-22 2011-10-11 Fujitsu Limited Method and apparatus for digital signature authentication, and computer product
US8323087B2 (en) 2006-09-18 2012-12-04 Igt Reduced power consumption wager gaming machine
US8386785B2 (en) 2008-06-18 2013-02-26 Igt Gaming machine certificate creation and management
EP2073434B1 (en) * 2007-12-19 2013-11-27 Fujitsu Ltd. Digital signature system and digital signing method
US9621630B2 (en) 2014-02-24 2017-04-11 Fujitsu Limited Distribution method, distribution apparatus, and terminal apparatus

Families Citing this family (75)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8086697B2 (en) 2005-06-28 2011-12-27 Claria Innovations, Llc Techniques for displaying impressions in documents delivered over a computer network
US7475404B2 (en) 2000-05-18 2009-01-06 Maquis Techtrix Llc System and method for implementing click-through for browser executed software including ad proxy and proxy cookie caching
US8521827B2 (en) * 2001-10-18 2013-08-27 Carhamm Ltd., Llc Presentation of information to end-users
US7603341B2 (en) 2002-11-05 2009-10-13 Claria Corporation Updating the content of a presentation vehicle in a computer network
WO2005017809A2 (en) * 2003-08-15 2005-02-24 Docomo Communications Laboratories Usa, Inc. Method and apparatus for authentication of data streams with adaptively controlled losses
US9020854B2 (en) 2004-03-08 2015-04-28 Proxense, Llc Linked account system using personal digital key (PDK-LAS)
US8078602B2 (en) 2004-12-17 2011-12-13 Claria Innovations, Llc Search engine for a computer network
US8255413B2 (en) 2004-08-19 2012-08-28 Carhamm Ltd., Llc Method and apparatus for responding to request for information-personalization
US7406597B2 (en) * 2004-10-29 2008-07-29 International Business Machines Corporation Methods for efficiently authenticating multiple objects based on access patterns
AU2005319019A1 (en) 2004-12-20 2006-06-29 Proxense, Llc Biometric personal data key (PDK) authentication
US7693863B2 (en) 2004-12-20 2010-04-06 Claria Corporation Method and device for publishing cross-network user behavioral data
US8073866B2 (en) 2005-03-17 2011-12-06 Claria Innovations, Llc Method for providing content to an internet user based on the user's demonstrated content preferences
WO2007002727A2 (en) * 2005-06-28 2007-01-04 Claria Corporation Method for providing advertising content to an internet user based on the user's demonstrated content preferences
JP4827468B2 (en) * 2005-07-25 2011-11-30 キヤノン株式会社 Information processing apparatus, information processing apparatus control method, computer program, and computer-readable storage medium
US8078867B2 (en) * 2005-08-12 2011-12-13 Research In Motion Limited System and method for authenticating streamed data
JP4622811B2 (en) * 2005-11-04 2011-02-02 株式会社日立製作所 Electronic document authenticity guarantee system
US8219129B2 (en) 2006-01-06 2012-07-10 Proxense, Llc Dynamic real-time tiered client access
US11206664B2 (en) 2006-01-06 2021-12-21 Proxense, Llc Wireless network synchronization of cells and client devices on a network
WO2007085763A1 (en) * 2006-01-25 2007-08-02 France Telecom Burn-in system for multicast data transmission
US8832466B1 (en) * 2006-01-27 2014-09-09 Trustwave Holdings, Inc. Methods for augmentation and interpretation of data objects
US7904718B2 (en) 2006-05-05 2011-03-08 Proxense, Llc Personal digital key differentiation for secure transactions
US20090210715A1 (en) * 2006-08-01 2009-08-20 Fujitsu Limited Document verification apparatus, document verification method, and computer product
US9269221B2 (en) 2006-11-13 2016-02-23 John J. Gobbi Configuration of interfaces for a location detection system and application
JP4270276B2 (en) * 2006-12-27 2009-05-27 株式会社日立製作所 Electronic data authenticity guarantee method and program
US8381062B1 (en) * 2007-05-03 2013-02-19 Emc Corporation Proof of retrievability for archived files
JP2008294596A (en) * 2007-05-23 2008-12-04 Hitachi Ltd Authenticity assurance system for spreadsheet data
US7885427B2 (en) * 2007-08-04 2011-02-08 International Business Machines Corporation System and method for solving the “birthday” problem with watermarking
US8659427B2 (en) 2007-11-09 2014-02-25 Proxense, Llc Proximity-sensor supporting multiple application services
US8171528B1 (en) 2007-12-06 2012-05-01 Proxense, Llc Hybrid device having a personal digital key and receiver-decoder circuit and methods of use
US9251332B2 (en) 2007-12-19 2016-02-02 Proxense, Llc Security system and method for controlling access to computing resources
GB0802585D0 (en) * 2008-02-12 2008-03-19 Mtld Top Level Domain Ltd Determining a property of communication device
KR101426270B1 (en) * 2008-02-13 2014-08-05 삼성전자주식회사 Method and apparatus for generating and verifying electronic signature of software, and computer readable medium thereof
US8508336B2 (en) 2008-02-14 2013-08-13 Proxense, Llc Proximity-based healthcare management system with automatic access to private information
US11120449B2 (en) 2008-04-08 2021-09-14 Proxense, Llc Automated service-based order processing
US8122501B2 (en) * 2008-06-20 2012-02-21 International Business Machines Corporation Traitor detection for multilevel assignment
US8108928B2 (en) * 2008-06-20 2012-01-31 International Business Machines Corporation Adaptive traitor tracing
US8595504B2 (en) * 2008-08-12 2013-11-26 Industrial Technology Research Institute Light weight authentication and secret retrieval
US8422684B2 (en) * 2008-08-15 2013-04-16 International Business Machines Corporation Security classes in a media key block
KR20110091041A (en) * 2008-09-19 2011-08-10 인터디지탈 패튼 홀딩스, 인크 Authentication for secure wireless communication
GB2465138B (en) * 2008-10-10 2012-10-10 Afilias Technologies Ltd Transcoding web resources
US8108544B2 (en) 2008-12-10 2012-01-31 At&T Intellectual Property I, Lp System and method for content validation
US20110246779A1 (en) 2008-12-11 2011-10-06 Isamu Teranishi Zero-knowledge proof system, zero-knowledge proof device, zero-knowledge verification device, zero-knowledge proof method and program therefor
US8571209B2 (en) 2009-01-19 2013-10-29 International Business Machines Recording keys in a broadcast-encryption-based system
US20100212017A1 (en) * 2009-02-18 2010-08-19 International Business Machines Corporation System and method for efficient trust preservation in data stores
US8627184B2 (en) * 2009-03-31 2014-01-07 Qualcomm Incorporated Systems and methods for protecting a multi-part broadcast control message
US8132073B1 (en) * 2009-06-30 2012-03-06 Emc Corporation Distributed storage system with enhanced security
TWI501580B (en) * 2009-08-07 2015-09-21 Dolby Int Ab Authentication of data streams
US9418205B2 (en) 2010-03-15 2016-08-16 Proxense, Llc Proximity-based system for automatic application or data access and item tracking
US9141724B2 (en) 2010-04-19 2015-09-22 Afilias Technologies Limited Transcoder hinting
GB2481843A (en) 2010-07-08 2012-01-11 Mtld Top Level Domain Ltd Web based method of generating user interfaces
US8918854B1 (en) 2010-07-15 2014-12-23 Proxense, Llc Proximity-based system for automatic application initialization
US8538938B2 (en) * 2010-12-02 2013-09-17 At&T Intellectual Property I, L.P. Interactive proof to validate outsourced data stream processing
US9265450B1 (en) 2011-02-21 2016-02-23 Proxense, Llc Proximity-based system for object tracking and automatic application initialization
US8671299B2 (en) 2011-05-26 2014-03-11 Google Inc. Delaying the initiation of transitioning to a lower power mode by placing a computer system into an intermediate power mode between a normal power mode and the lower power mode
GB2508343A (en) * 2012-11-28 2014-06-04 Ibm Replacing a hash function if a second hash function is more effective
US9536016B2 (en) * 2013-01-16 2017-01-03 Google Inc. On-disk multimap
US9405898B2 (en) 2013-05-10 2016-08-02 Proxense, Llc Secure element as a digital pocket
JP2014241465A (en) * 2013-06-11 2014-12-25 株式会社東芝 Signature generating apparatus, signature generating method, signature generation program, and power usage calculation system
US10200199B2 (en) * 2013-08-05 2019-02-05 Guardtime Holdings Limited Strengthened entity identity for digital record signature infrastructure
WO2015024603A1 (en) * 2013-08-23 2015-02-26 Nec Europe Ltd. Method and system for authenticating a data stream
US11968292B1 (en) * 2014-12-18 2024-04-23 Amazon Technologies, Inc. Incremental authenticated data encodings
US10333696B2 (en) 2015-01-12 2019-06-25 X-Prime, Inc. Systems and methods for implementing an efficient, scalable homomorphic transformation of encrypted data with minimal data expansion and improved processing efficiency
WO2016116999A1 (en) 2015-01-19 2016-07-28 三菱電機株式会社 Packet transmission device, packet-receiving device, packet transmission program, and packet-receiving program
US10447812B2 (en) * 2015-06-05 2019-10-15 Apple Inc. On demand resources
US10044583B2 (en) 2015-08-21 2018-08-07 Barefoot Networks, Inc. Fast detection and identification of lost packets
US20180262551A1 (en) * 2015-09-21 2018-09-13 Dolby Laboratories Licensing Corporation Efficient delivery of customized content over intelligent network
KR101977109B1 (en) * 2015-11-17 2019-08-28 (주)마크애니 Large simultaneous digital signature service system based on hash function and method thereof
US9960920B2 (en) 2016-01-26 2018-05-01 Stampery Inc. Systems and methods for certification of data units and/or certification verification
US9679276B1 (en) * 2016-01-26 2017-06-13 Stampery, Inc. Systems and methods for using a block chain to certify the existence, integrity, and/or ownership of a file or communication
WO2019157227A1 (en) * 2018-02-07 2019-08-15 Safetraces, Inc. Source and sanitation assurance testing of foodstuffs and sensitive applications
CA3051762A1 (en) * 2018-12-13 2019-04-18 Alibaba Group Holding Limited Data isolation in a blockchain network
US12099997B1 (en) 2020-01-31 2024-09-24 Steven Mark Hoffberg Tokenized fungible liabilities
US11431476B2 (en) * 2020-04-30 2022-08-30 Dell Products L.P. Install time creation of forward error correction data and integrity checksums
US10951404B1 (en) * 2020-06-09 2021-03-16 Quantropi Inc. Methods and systems for digital message encoding and signing
WO2022187959A1 (en) 2021-03-10 2022-09-15 Quantropi Inc. Quantum-safe cryptographic methods and systems

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6065008A (en) * 1997-10-01 2000-05-16 Microsoft Corporation System and method for secure font subset distribution

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5953506A (en) * 1996-12-17 1999-09-14 Adaptive Media Technologies Method and apparatus that provides a scalable media delivery system
US6970602B1 (en) * 1998-10-06 2005-11-29 International Business Machines Corporation Method and apparatus for transcoding multimedia using content analysis
US6959384B1 (en) * 1999-12-14 2005-10-25 Intertrust Technologies Corporation Systems and methods for authenticating and protecting the integrity of data streams and other data
US6886098B1 (en) * 1999-08-13 2005-04-26 Microsoft Corporation Systems and methods for compression of key sets having multiple keys
JP3434251B2 (en) * 1999-11-02 2003-08-04 日本電信電話株式会社 Message recovery type signature system and program recording medium thereof
US6640294B2 (en) * 2001-12-27 2003-10-28 Storage Technology Corporation Data integrity check method using cumulative hash function
US20030123546A1 (en) * 2001-12-28 2003-07-03 Emblaze Systems Scalable multi-level video coding
US7313814B2 (en) * 2003-04-01 2007-12-25 Microsoft Corporation Scalable, error resilient DRM for scalable media
WO2005017809A2 (en) * 2003-08-15 2005-02-24 Docomo Communications Laboratories Usa, Inc. Method and apparatus for authentication of data streams with adaptively controlled losses

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6065008A (en) * 1997-10-01 2000-05-16 Microsoft Corporation System and method for secure font subset distribution

Cited By (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8589688B2 (en) 2005-11-04 2013-11-19 Nec Corporation Message authentication device, message authentication method, message authentication program and storage medium therefor
EP1944907A1 (en) * 2005-11-04 2008-07-16 NEC Corporation Message authentication device, message authentication method, message authentication program, and recording medium therefor
EP1944907A4 (en) * 2005-11-04 2011-08-31 Nec Corp Message authentication device, message authentication method, message authentication program, and recording medium therefor
WO2007093925A1 (en) * 2006-02-14 2007-08-23 Koninklijke Philips Electronics N.V. Improved method of content protection
WO2007093946A1 (en) * 2006-02-14 2007-08-23 Koninklijke Philips Electronics N.V. Improved method of content protection
US8845411B2 (en) 2006-09-18 2014-09-30 Igt Reduced power consumption wager gaming machine
US8323087B2 (en) 2006-09-18 2012-12-04 Igt Reduced power consumption wager gaming machine
US8037312B2 (en) 2007-01-22 2011-10-11 Fujitsu Limited Method and apparatus for digital signature authentication, and computer product
EP2073434B1 (en) * 2007-12-19 2013-11-27 Fujitsu Ltd. Digital signature system and digital signing method
EP2107711A1 (en) * 2008-03-03 2009-10-07 Fujitsu Ltd. Method and apparatus for digital signature authentication, and computer product
US8386785B2 (en) 2008-06-18 2013-02-26 Igt Gaming machine certificate creation and management
US8713308B2 (en) 2008-06-18 2014-04-29 Igt Gaming machine certificate creation and management
US9621630B2 (en) 2014-02-24 2017-04-11 Fujitsu Limited Distribution method, distribution apparatus, and terminal apparatus

Also Published As

Publication number Publication date
JP2007503134A (en) 2007-02-15
JP4809766B2 (en) 2011-11-09
US20100005309A1 (en) 2010-01-07
US8256015B2 (en) 2012-08-28
US20060136728A1 (en) 2006-06-22
WO2005017809A3 (en) 2005-09-22
US20100005310A1 (en) 2010-01-07

Similar Documents

Publication Publication Date Title
US8256015B2 (en) Method and apparatus for authentication of data streams with adaptively controlled losses
CN109559122B (en) Block chain data transmission method and block chain data transmission system
Krohn et al. On-the-fly verification of rateless erasure codes for efficient content distribution
US7558954B2 (en) Method and apparatus for ensuring the integrity of data
CN100576916C (en) Media data encoding device
US7555656B2 (en) Exclusive encryption
RU2638639C1 (en) Encoder, decoder and method for encoding and encrypting input data
WO2015024603A1 (en) Method and system for authenticating a data stream
CN1186580A (en) Computer-assisted method for exchange of crytographic keys between user computer and network computer unit
CN100571388C (en) The scalable data sequence of encrypting is gradually carried out the method for stretching
CN1805337A (en) Secret shared key mechanism based user management method
CN114710558B (en) Asynchronous secure transmission channel construction method based on cloud storage
CN118337498A (en) Data transmission method based on symmetric key pool
CN114793167A (en) Network coding method, system and equipment based on block encryption and threshold sharing
Sun et al. Quality-optimized and secure end-to-end authentication for media delivery
JP2000250408A (en) File authentication system, system and method for signature, system and method for authentication, and recording medium
CN117528149A (en) Key updating method, code stream encryption method, code stream decryption method and related devices
Gentry et al. End-to-end security in the presence of intelligent data adapting proxies: The case of authenticating transcoded streaming media
CN112954388A (en) Data file acquisition method and device, terminal equipment and storage medium
Habib et al. Verifying data integrity in peer-to-peer media streaming
Abouhogail New multicast authentication protocol for entrusted members using advanced encryption standard
Deng et al. A study of content authentication in proxy-enabled multimedia delivery systems: Model, techniques, and applications
CN112163171B (en) Data chaining method based on terminal signature
Gong et al. U-EPS: An Ultra-small and Efficient Post-quantum Signature Scheme
KR20230050221A (en) Signed video data with salted hashes

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A2

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW

AL Designated countries for regional patents

Kind code of ref document: A2

Designated state(s): GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
ENP Entry into the national phase

Ref document number: 2006136728

Country of ref document: US

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 10543640

Country of ref document: US

WWE Wipo information: entry into national phase

Ref document number: 2006523251

Country of ref document: JP

WWP Wipo information: published in national office

Ref document number: 10543640

Country of ref document: US

122 Ep: pct application non-entry in european phase