IP Library Granted Patent US 7,243,348
Granted Patent B2
US 7,243,348 · App. 10/251,317 · Granted Jul 10, 2007

Computing apparatus with automatic integrity reference generation and maintenance

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,243,348
App. No.
10/251,317
Granted
Jul 10, 2007
Kind
B2
Abstract

An apparatus is equipped to automatically update one or more integrity references of a software entity, when the software entity is installed onto the apparatus. The apparatus is further equipped to periodically determine whether the integrity of the apparatus has been compromised based at least in part on the one or more integrity references of the software entity that are automatically updated during installation of the software entity.

Claims (53)

1. A computing device implemented method, comprising:

automatically updating one or more integrity references of a software entity during installation of the software entity onto the computing apparatus; and

automatically periodically determining, independent of the software entity's execution, whether integrity of the computer apparatus has been compromised, based at least in part on said one or more integrity references of the software entity that are automatically updated during installation of the software entity

wherein said automatic updating of the one or more integrity references of the software entity during installation of the software entity comprises automatically determining an integrity family for a component of the software entity during installation of the software entity;

wherein said automatic determining of an integrity family for a component of the software entity during installation of the software entity comprises

automatically determining during installation of the software entity, whether an integrity family is specified for the component of the software entity, and

if an integrity family is not specified for the component of the software entity, automatically assigning an integrity family for the component of the software entity.

2. The method of claim 1 , wherein said integrity family is a selected one of

privileged kernel of an operating system,

other privileged components of the operating system,

non-privileged components of the operated system,

privileged and non-shared library components,

privileged and shared library components,

non-privileged and non-shared library components, and

non-privileged and shared library components.

3. The method of claim 1 , wherein said automatic updating of the one or more integrity references of the software entity during installation of the software entity comprises automatically determining a signature for a component of the software entity during installation of the software installation.

4. The method of claim 3 , wherein said automatic determining of a signature for a component of the software entity during installation of the software entity comprises

automatically determining during installation of the software entity, whether a signature is provided for the component of the software entity, and

if a signature is not specified for the component of the software entity, automatically generating a signature for the component of the software entity.

5. The method of claim 3 , wherein said signature is a selected one of MD5 and SHA-1.

6. The method of claim 1 , wherein said periodic determining of whether integrity of the computing apparatus has been compromised comprises continuously determining whether integrity of the computing apparatus has been compromised, based at least in part on said one or more integrity references of the software entity that are automatically updated during installation of the software entity.

7. The method of claim 1 , wherein each of said periodic determining of whether integrity of the computing apparatus has been compromised comprises verifying a privileged kernel of an operating system of the computing apparatus has not been compromised, based at least in part on an integrity reference of the privileged kernel of the operating system that is automatically updated during installation of the privileged kernel of the operating system.

8. The method of claim 1 , wherein each of said periodic determining of whether integrity of the computing apparatus has been compromised comprises verifying other privileged software components of the computing apparatus have not been compromised, based at least in part on integrity references of the other privileged software components that are automatically updated during installation of the other privileged software components.

9. The method of claim 1 , wherein each of said periodic determining of whether integrity of the computing apparatus has been compromised comprises verifying shared non-privileged software components of the computing apparatus have not been compromised, based at least in part on integrity references of the shared non-privileged software components that are automatically updated during installation of the shared non-privileged software components.

10. The method of claim 1 , wherein each of said periodic determining of whether integrity of the computing apparatus has been compromised comprises verifying non-shared and non-privileged software components of the computing apparatus have not been compromised, based at least in part on integrity references of the non-shared and non-privileged software components that are automatically updated during installation of the non-shared and non-privileged software components.

11. The method of claim 1 , wherein each of said periodic determining of whether integrity of the computing apparatus has been compromised comprises verifying certain designated system data of the computing apparatus have not been compromised, based at least in part on integrity references of the designated system data that are automatically updated during installation of system software of the computing apparatus.

12. An apparatus comprising:

a storage medium having stored therein a plurality of programming instructions designed to

automatically update one or more integrity references of a software entity during installation of the software entity onto a computing device, and

automatically periodically determine, independent of the software entity's execution, whether integrity of the computing device has been compromised, based at least in part on said one or more integrity references of the software entity that are automatically updated during installation of the software entity;

wherein said programming instructions are designed to perform said automatic updating of the one or more integrity references during installation of the software entity by automatically determining an integrity family for a component of the software entity during installation of the software entity;

wherein said programming instructions are designed to perform said automatic determining of an integrity family for a component of the software entity during installation of the software entity by automatically determining during installation of the software entity, and

if an integrity family is not specified for the component of the software entity, automatically assigning an integrity family for the component of the software entity; and

a processor coupled to the storage medium to execute the programming instructions.

13. The apparatus of claim 12 , wherein said integrity family is a selected one of

privileged kernel of an operating system,

other privileged components of the operating system,

non-privileged components of the operating system,

privileged and non-shared library components,

privileged and shared library components,

non-privileged and non-shared library components, and

non-privileged and shared library components.

14. The apparatus of claim 12 , wherein said programming instructions are designed to perform said automatic updating of the one or more integrity references during installation of the software entity by automatically determining a signature for a component of the software entity during installation of the software entity.

15. The apparatus of claim 14 , wherein said programming instructions are designed to perform said automatic determining of a signature for a component of the software entity during installation of the software entity by

automatically determining during installation of the software entity, whether a signature is provided for the component of the software entity, and

if a signature is not specified for the component of the software entity, automatically generating a signature for the component of the software entity.

16. The apparatus of claim 14 , wherein said signature is a selected one of MD5 and SHA-1.

17. The apparatus of claim 12 , wherein said programming instructions are designed to perform said periodic determining of whether integrity of the computing device has been compromised by continuously determining whether integrity of the computing device has been compromised, based at least in part on the one or more integrity references of the software entity that are automatically updated during installation of the software entity.

18. The apparatus of claim 12 , wherein said programming instructions are designed to perform each of said periodic determining of whether integrity of the computing device has been compromised by verifying a privileged kernel of an operating system of the computing device has not been compromised, based at least in part on one or more integrity references of the privileged kernel of the operating system that are automatically updated during installation of the privileged kernel of the operating system.

19. The apparatus of claim 12 , wherein said programming instructions are designed to perform each of said periodic determining of whether integrity of the computing device has been compromised by verifying other privileged software components of the computing device have not been compromised, based at least in part on one or more integrity references of the other privileged software components that are automatically updated during installation of the other privileged software components.

20. The apparatus of claim 12 , wherein said programming instructions are designed to perform each of said periodic determining of whether integrity of the computing device has been compromised by verifying shared non-privileged software components of the computing device have not been compromised.

21. The apparatus of claim 12 , wherein said programming instructions are designed to perform each of said periodic determining of whether integrity of the computing device has been compromised by verifying non-shared and non-privileged software components of the computing device have not been compromised, based at least in part on one or more integrity references of the non-shared and non-privileged software components that are automatically updated during installation of the non-shared and non-privileged software components.

22. The apparatus of claim 12 , wherein said programming instructions are designed to perform each of said periodic determining of whether integrity of the computing device has been compromised by verifying certain designated system data of the computing device have not been compromised, based at least in part on one or more integrity references of the designated system data that are automatically updated during installation of system software of the computing device.

Assignments (14)
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
RELEASE OF SECURITY INTEREST Recorded Feb 2, 2015
From: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
To: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY INC.
Reel/Frame 034874/0150 →
SECURITY AGREEMENT Recorded Apr 2, 2013
From: TRIPWIRE, INC.; NCIRCLE NETWORK SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 030132/0101 →
SECURITY AGREEMENT Recorded May 23, 2011
From: TRIPWIRE, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 026322/0580 →
RELEASE OF SECURITY INTEREST Recorded Mar 6, 2008
From: ORIX VENTURE FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 020609/0129 →
RELEASE Recorded Mar 3, 2008
From: SILICON VALLEY BANK
To: TRIPWIRE, INC.
Reel/Frame 020599/0634 →
SECURITY AGREEMENT Recorded Jun 21, 2004
From: TRIPWIRE, INC.
To: SILICON VALLEY BANK
Reel/Frame 015473/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2003
From: TRIPWIRE, INC.
To: ORIX VENTURE FINANCE LLC
Reel/Frame 013743/0870 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2002
From: GOOD, THOMAS E.; DIFALCO, ROBERT A.; KIM, GENE HO
To: TRIPWIRE, INC.
Reel/Frame 013313/0982 →