IP Library Granted Patent US 8,458,792
Granted Patent B2
US 8,458,792 · App. 13/106,519 · Granted Jun 4, 2013

Secure method and system for computer protection

Inventors: Stanley T. Chow (Ottawa, CA); Harold T. Johnson (Ottawa, CA); Alexander Main (Ottawa, CA); Yuan Xiang Gu (Ottawa, CA)
Assignee: Irdeto Canada Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,458,792
App. No.
13/106,519
Granted
Jun 4, 2013
Kind
B2
Abstract

Attacks by computer viruses, worm programs, and other hostile software (‘malware’), have become very serious problems for computer systems connected to large communication networks such as the Internet. One potential defense against such attacks is to employ diversity—that is, making each copy of the attacked software different. However, existing diversity techniques do not offer sufficient levels of protection. The invention provides an effective diversity solution by applying tamper resistant software (TRS) encoding techniques, to the communications that take place between software components, with corresponding changes to the code handling those communications. These communications may include, for example, data passed between software routines via parameters or mutually accessible variables, light-weight messages, signals and semaphores passed between threads, and messages passed between software processes. Effective TRS encoding techniques include data-flow encoding and mass-data encoding techniques.

Claims (28)

1. A method of protecting a software application against malicious attack, the method comprising:

identifying portions of the software application that effect first and second communications between components of the software application, the first and second communications being vulnerable to malicious attack;

determining that at least one of the first or second communication one of has limited vulnerability to attack and is vulnerable only to attacks of limited security concern;

selecting a light-weight, low-overhead TRS encoding as the corresponding first or second TRS encoding and is vulnerable only to attacks of limited security concern;

selecting a first tamper-resistant software (TRS) encoding to render the first communication resistant to malicious attack;

selecting a second TRS encoding to render the second communication resistant to malicious attack, the second TRS encoding differing from the first TRS encoding; and

generating an instance of the software application by applying the first TRS encoding to the portion of the software application that effects the first communication and applying the second TRS encoding to the portion of the software application that effects the second communication, such that data representations used in the first and second communications are mutually incomprehensible.

2. A method of protecting a software application against malicious attack, the method comprising:

identifying portions of the software application that effect first and second communications between components of the software application, the first and second communications being vulnerable to malicious attack;

determining that at least one of the first or second communication, one of, has a high degree of vulnerability to attack and is vulnerable to attacks of serious security concern; and

selecting a heavy-weight, higher-overhead TRS encoding as the corresponding first or second TRS encoding

selecting a first tamper-resistant software (TRS) encoding to render the first communication resistant to malicious attack;

selecting a second TRS encoding to render the second communication resistant to malicious attack, the second TRS encoding differing from the first TRS encoding; and

generating an instance of the software application by applying the first TRS encoding to the portion of the software application that effects the first communication and applying the second TRS encoding to the portion of the software application that effects the second communication, such that data representations used in the first and second communications are mutually incomprehensible.

3. A method of providing diverse instances of a software application resistant to malicious attack, the method comprising:

identifying portions of the software application that effect first and second communications between components of the software application, the first and second communications being vulnerable to malicious attack;

determining that at least one of the first or second communication, one of, has limited vulnerability to attack and is vulnerable to attacks of limited security concern;

selecting a light-weight, higher-overhead TRS encoding as the corresponding first or second TRS encoding.

selecting a first tamper-resistant software (TRS) encoding to render the first communication resistant to malicious attack;

selecting a second TRS encoding to render the second communication resistant to malicious attack, the second TRS encoding differing from the first TRS encoding; and

generating diverse instances of the software application by applying different instances of the first TRS encoding and different instances of the second TRS encoding to the portions of the software application that respectively effect the first and second communications, such that, for a given instance of the software application, data representations used in the first and second communications differ, and the data representations differ among instances.

4. A method of providing diverse instances of a software application resistant to malicious attack, the method comprising:

identifying portions of the software application that effect first and second communications between components of the software application, the first and second communications being vulnerable to malicious attack;

determining that at least one of the first or second communication, one of, has a high degree of vulnerability to attack and is vulnerable to attacks of serious security concern;

selecting a heavy-weight, higher-overhead TRS encoding as the corresponding first or second TRS encoding;

selecting a first tamper-resistant software (TRS) encoding to render the first communication resistant to malicious attack;

selecting a second TRS encoding to render the second communication resistant to malicious attack, the second TRS encoding differing from the first TRS encoding; and

generating diverse instances of the software application by applying different instances of the first TRS encoding and different instances of the second TRS encoding to the portions of the software application that respectively effect the first and second communications, such that, for a given instance of the software application, data representations used in the first and second communications differ, and the data representations differ among instances.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2015
From: IRDETO CANADA CORPORATION
To: IRDETO B.V.
Reel/Frame 035186/0825 →
CHANGE OF NAME Recorded May 18, 2012
From: CLOAKWARE CORPORATION
To: IRDETO CANADA CORPORATION
Reel/Frame 028236/0587 →
Priority Claims (1)
CA 2363795 · Nov 26, 2001 · national
Continuity (3)
Continuation 10851131 · May 24, 2004
Continuation PCTCA0201806 · Nov 26, 2002
Related Publication 20110214179A1 · Sep 1, 2011