Log Integrity Verification Using Cryptographic Hashing and Rolling Checksums

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current document management systems face challenges in operating across organizational boundaries and ensuring synchronization and verification, particularly in auditing processes, where the integrity and trustworthiness of electronic logs are critical but difficult to verify.

Innovation Solution

A method and apparatus for analyzing risk associated with published logs by accessing and estimating the probability of verification failure, using cryptographic hash functions and rolling checksums to create a sequence of entries that are difficult to modify without detection, and entangling logs to increase trustworthiness through publication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic hash functions and rolling checksums are used to ensure log integrity, then verification reliability is improved, but computational complexity increases

Engineering Contradiction:
Improvelog verification reliabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-computes and stores cryptographic hash values and rolling checksums for log entries before verification is needed. This preliminary action allows rapid verification without performing complex cryptographic computations at verification time, thus improving reliability while managing computational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The log verification process is divided into separate modular components: hash computation, checksum verification, and integrity validation. Each component handles a specific aspect of verification independently, making the complex verification process more manageable and efficient.

Inventive Principle:
Principle #1Segmentation

2Reliability

If logs are synchronized across multiple organizational boundaries, then accountability and trustworthiness are improved, but system complexity increases

Engineering Contradiction:
ImproveaccountabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal log synchronization framework that can operate across multiple organizational boundaries using the same cryptographic protocols and verification mechanisms. This multi-functional system handles different log types, organizational structures, and verification requirements through a unified approach, improving accountability without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces intermediary verification nodes that facilitate log synchronization between different organizations. These intermediaries handle the complex tasks of cryptographic verification and log entanglement, allowing organizations to participate in cross-boundary log sharing without each organization needing to implement the full complexity of the synchronization protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If log entries are entangled through publication protocols, then verification trustworthiness is improved, but processing time increases

Engineering Contradiction:
Improveverification trustworthinessVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic publication protocols where log entries are entangled at regular intervals rather than continuously. This periodic approach maintains verification trustworthiness by ensuring logs are regularly synchronized and verified, while reducing processing time by avoiding continuous entanglement operations.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies partial entanglement where only critical or suspicious log entries undergo full cryptographic entanglement verification, while routine entries use simplified verification. This selective approach maintains trustworthiness for important entries while reducing overall processing time by avoiding excessive verification on all entries.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8255340B2Method and apparatus for risk analysis of published logs
Publication Date: 2012.08.28 RICOH CO LTD
  • US8255340B2 patent drawing
  • US8255340B2 patent drawing
  • US8255340B2 patent drawing

AI summary

A method and apparatus for analyzing risk associated with published logs are described. In one embodiment, the method comprises accessing a first log published to one or more logs. In one embodiment, the method may also comprise estimating a probability that an entry within the first log will not be verifiable from a second entry selected from one o the one or more logs.