IP Library Granted Patent US 9,294,284
Granted Patent B1
US 9,294,284 · App. 14/020,319 · Granted Mar 22, 2016

Systems and methods for validating application signatures

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,294,284
App. No.
14/020,319
Granted
Mar 22, 2016
Kind
B1
Abstract

A computer-implemented method for validating application signatures may include maintaining a signature-validation database that associates application publishers with signature keys by, for each application in a set of applications, (1) identifying a key used to sign the application, (2) determining that the application claims to be provided by a publisher, (3) verifying that the claimed publisher provides the application, and (4) maintaining, in response to verifying that the claimed publisher provides the application, an association that indicates that the publisher of the application is authorized to use the key. Various other methods, systems, and computer-readable media are also disclosed.

Claims (51)

1. A computer-implemented method for validating application signatures, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

maintaining a signature-validation database that associates application publishers with signature keys by, for each application in a set of applications:

identifying a key used to sign the application;

determining that the application claims to be provided by a publisher;

verifying that the claimed publisher provides the application;

in response to verifying that the claimed publisher provides the application, maintaining an association that indicates that the publisher of the application is authorized to use the key;

querying the signature-validation database to determine whether a particular publisher claimed by an unverified application is associated with a key used to sign the unverified application;

determining, based on a response from the signature-validation database, that the particular publisher is not associated with the key used to sign the unverified application;

concluding, based on the determination that the particular publisher is not associated with the key used to sign the unverified application, that a signature of the unverified application is not legitimate.

2. The computer-implemented method of claim 1 , wherein querying the signature-validation database to determine whether the particular publisher claimed by the unverified application is associated with the key used to sign the unverified application comprises:

identifying the application that has the signature that has not been verified;

determining that the unverified application claims to be provided by the particular publisher.

3. The computer-implemented method of claim 1 , further comprising, upon concluding that the signature of the unverified application is not legitimate, performing a security action.

4. The computer-implemented method of claim 1 , wherein identifying the key used to sign the application comprises identifying a digital signature that was created with the key.

5. The computer-implemented method of claim 1 , wherein determining that the application claims to be provided by the publisher comprises determining that the application appears to claim a domain name owned by the publisher.

6. The computer-implemented method of claim 5 , wherein determining that the application appears to claim the domain name comprises identifying the domain name within the application.

7. The computer-implemented method of claim 1 , wherein verifying that the claimed publisher provides the application comprises determining that the application is available for download from the publisher.

8. The computer-implemented method of claim 1 , wherein verifying that the claimed publisher provides the application comprises determining, based on reputation data of the application that indicates that the application is trusted, that the application is legitimate.

9. The computer-implemented method of claim 1 , wherein maintaining the association that indicates that the publisher of the application is authorized to use the key comprises maintaining an association between a certificate created by the key and the publisher.

10. A system for validating application signatures, the system comprising:

an identification module identifies a key used to sign an application;

a determination module that determines that the application claims to be provided by a publisher;

a verification module that verifies that the claimed publisher provides the application;

an association module that, in response to verifying that the claimed publisher provides the application, creates an association that indicates that the publisher of the application is authorized to use the key;

a signature-validation database that stores the association between the publisher of the application and the key;

a querying module that queries the signature-validation database to determine whether a particular publisher claimed by an unverified application is associated with a key used to sign the unverified application;

an association module that determines, based on a response from the signature-validation database, that the particular publisher is not associated with the key used to sign the unverified application;

a conclusion module that concludes, based on the determination that the particular publisher is not associated with the key used to sign the unverified application, that a signature of the unverified application is not legitimate;

at least one processor configured to execute the association module, the identification module, the determination module, the verification module, the querying module, the association module, and the conclusion module.

11. The system of claim 10 , wherein the querying module queries the signature-validation database to determine whether the particular publisher claimed by the unverified application is associated with a key used to sign the unverified application by:

identifying the application that has the signature that has not been verified;

determining that the unverified application claims to be provided by the particular publisher.

12. The system of claim 10 , further comprising a security module that, upon concluding that the signature of the unverified application is not legitimate, performs a security action.

13. The system of claim 10 , wherein the identification module identifies the key used to sign the application by identifying a digital signature that was created with the key.

14. The system of claim 10 , wherein the determination module determines that the application claims to be provided by the publisher by determining that the application appears to claim a domain name owned by the publisher.

15. The system of claim 14 , wherein the determination module determines that the application appears to claim the domain name by identifying the domain name within the application.

16. The system of claim 10 , wherein the verification module verifies that the claimed publisher provides the application by determining that the application is available for download from the publisher.

17. The system of claim 10 , wherein the verification module verifies that the claimed publisher provides the application by determining, based on reputation data of the application that indicates that the application is trusted, that the application is legitimate.

18. The system of claim 10 , wherein the association module maintains the association that indicates that the publisher of the application is authorized to use the key by maintaining an association between a certificate created by the key and the publisher.

19. A non-transitory computer-readable-storage medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

maintain a signature-validation database that associates application publishers with signature keys by, for each application in a set of applications:

identifying a key used to sign the application;

determining that the application claims to be provided by a publisher;

verifying that the claimed publisher provides the application;

maintaining, in response to verifying that the claimed publisher provides the application, an association that indicates that the publisher of the application is authorized to use the key;

query the signature-validation database to determine whether a particular publisher claimed by an unverified application is associated with a key used to sign the unverified application;

determine, based on a response from the signature-validation database, that the particular publisher is not associated with the key used to sign the unverified application;

conclude, based on the determination that the particular publisher is not associated with the key used to sign the unverified application, that a signature of the unverified application is not legitimate.

20. The non-transitory computer-readable-storage medium of claim 19 , wherein the one or more computer-readable instructions, when executed by the processor, cause the computing device to query the signature-validation database to determine whether the particular publisher claimed by the unverified application is associated with the key used to sign the unverified application by:

identifying the application that has the signature that has not been verified;

determining that the unverified application claims to be provided by the particular publisher.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2013
From: MAO, JUN
To: SYMANTEC CORPORATION
Reel/Frame 031153/0415 →