Log Integrity Verification Using Cryptographic Hashing and Rolling Checksums
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current document management systems face challenges in operating across organizational boundaries and ensuring synchronization and verification, particularly in auditing processes, where the integrity and trustworthiness of electronic logs are critical but difficult to verify.
Innovation Solution
A method and apparatus for analyzing risk associated with published logs by accessing and estimating the probability of verification failure, using cryptographic hash functions and rolling checksums to create a sequence of entries that are difficult to modify without detection, and entangling logs to increase trustworthiness through publication protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic hash functions and rolling checksums are used to ensure log integrity, then verification reliability is improved, but computational complexity increases
Solution Approach 1:
The system pre-computes and stores cryptographic hash values and rolling checksums for log entries before verification is needed. This preliminary action allows rapid verification without performing complex cryptographic computations at verification time, thus improving reliability while managing computational complexity.
Solution Approach 2:
The log verification process is divided into separate modular components: hash computation, checksum verification, and integrity validation. Each component handles a specific aspect of verification independently, making the complex verification process more manageable and efficient.
2Reliability
If logs are synchronized across multiple organizational boundaries, then accountability and trustworthiness are improved, but system complexity increases
Solution Approach 1:
The patent implements a universal log synchronization framework that can operate across multiple organizational boundaries using the same cryptographic protocols and verification mechanisms. This multi-functional system handles different log types, organizational structures, and verification requirements through a unified approach, improving accountability without proportionally increasing system complexity.
Solution Approach 2:
The system introduces intermediary verification nodes that facilitate log synchronization between different organizations. These intermediaries handle the complex tasks of cryptographic verification and log entanglement, allowing organizations to participate in cross-boundary log sharing without each organization needing to implement the full complexity of the synchronization protocol.
3Reliability
If log entries are entangled through publication protocols, then verification trustworthiness is improved, but processing time increases
Solution Approach 1:
The system implements periodic publication protocols where log entries are entangled at regular intervals rather than continuously. This periodic approach maintains verification trustworthiness by ensuring logs are regularly synchronized and verified, while reducing processing time by avoiding continuous entanglement operations.
Solution Approach 2:
The patent applies partial entanglement where only critical or suspicious log entries undergo full cryptographic entanglement verification, while routine entries use simplified verification. This selective approach maintains trustworthiness for important entries while reducing overall processing time by avoiding excessive verification on all entries.
Data Source
AI summary
A method and apparatus for analyzing risk associated with published logs are described. In one embodiment, the method comprises accessing a first log published to one or more logs. In one embodiment, the method may also comprise estimating a probability that an entry within the first log will not be verifiable from a second entry selected from one o the one or more logs.


