IP Library Granted Patent US 9,996,690
Granted Patent B2
US 9,996,690 · App. 14/583,620 · Granted Jun 12, 2018

Binary translation of a trusted binary with input tagging

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,996,690
App. No.
14/583,620
Granted
Jun 12, 2018
Kind
B2
Abstract

In an example, a computing device includes a trusted execution environment (TEE), including an enclave. The enclave may include both a binary translation engine (BTE) and an input verification engine (IVE). In one embodiment, the IVE receives a trusted binary as an input, and analyzes the trusted binary to identify functions, classes, and variables that perform input/output operations. To ensure the security of these interfaces, those operations may be performed within the enclave. The IVE tags the trusted binary and provides the binary to the BTE. The BTE then translates the trusted binary into a second format, including designating the tagged portion for execution within the enclave. The BTE may also sign the new binary in the second format and export it out of the enclave.

Claims (53)

1. A computing apparatus comprising:

a trusted execution environment (TEE);

one or more logic elements comprising an input verification engine (IVE) within the TEE, the IVE operable for:

receiving a trusted first binary object in a first format, the first binary object being a signed binary object;

analyzing the trusted first binary object to identify portions that perform input/output operations comprising signed and validated input from a peripheral;

tagging the portions to create a tagged trusted binary object with tagged portions; and

providing the portions to a binary translation engine (BTE);

one or more logic elements comprising the (BTE) within the TEE, the BTE operable for:

receiving the tagged trusted binary object in the first format, the first format not suitable for use on the computing apparatus;

translating the tagged trusted binary object into a second binary object in a second format suitable for use on the computing apparatus, wherein translating comprises reserving the tagged portions for execution within an enclave;

signing the second binary object in the second format; and

consulting a certificate expiration or revocation list before signing the second binary object.

2. The computing apparatus of claim 1 , wherein the IVE is further operable for: provisioning an enclave within the TEE; and

performing at least some of the IVE's functions within the enclave.

3. The computing apparatus of claim 2 , wherein the IVE is further operable for provisioning the BTE within the enclave.

4. The computing apparatus of claim 3 , wherein the BTE comprises a binary translator selected from the group consisting of a runtime engine, an interpreter, a just-in-time compiler, ahead-of-time compiler, a virtual machine, a compiler, a linker, and a toolchain utility.

5. The computing apparatus of claim 3 , wherein the BTE comprises a Java Virtual Machine, and wherein the IVE is at least partly implemented in Java and configured to operate within the BTE.

6. The computing apparatus of claim 1 , wherein the IVE is further operable for performing input verification.

7. The computing apparatus of claim 6 , wherein the IVE comprises a module selected from the group consisting of a secure network stack, a secure graphics engine, a secure human input device interface engine, a secure audio engine, a secure image processing engine, a secure telemetry engine, a secure global positioning system receiver, and a binary input analyzer.

8. The computing apparatus of claim 1 , wherein the BTE is further operable for signing the trusted first binary object.

9. The computing apparatus of claim 8 , wherein the trusted first binary object is to be signed by a key, and wherein signing the second binary object comprises signing the second binary object with the key.

10. The computing apparatus of claim 8 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key signed by a common issuer of the first key.

11. The computing apparatus of claim 8 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key provided by a vendor of the trusted binary object.

12. The computing apparatus of claim 8 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key having a common provenance with the first key.

13. One or more non-transitory, computer-readable mediums having stored thereon instructions that, when executed, instruct a processor for:

providing an input verification engine (IVE) within a TEE, the IVE operable for:

receiving a trusted first binary object in a first format, the first binary object being a signed binary object;

analyzing the trusted first binary object to identify portions that perform input/output operations comprising signed and validated input from a peripheral;

tagging the portions to create a tagged trusted binary object with tagged portions; and

providing the portions to a binary translation engine (BTE);

providing the (BTE) within the TEE, the BTE operable for:

receiving the tagged trusted binary object in the first format, the first format not suitable for use on a target platform of the trusted binary;

translating the tagged trusted binary object into a second binary object in a second format suitable for use on the target platform, wherein translating comprises reserving the tagged portions for execution within an enclave;

signing the second binary object in the second format; and

consulting a certificate expiration or revocation list before signing the second binary object.

14. The one or more non-transitory, computer-readable mediums of claim 13 , wherein the IVE is further operable for:

provisioning an enclave within the TEE; and

performing at least some of the IVE's functions within the enclave.

15. The one or more non-transitory, computer-readable mediums of claim 14 , wherein the IVE is further operable for provisioning the BTE within the enclave.

16. The one or more non-transitory, computer-readable mediums of claim 15 , wherein the BTE comprises a Java Virtual Machine, and wherein the IVE is at least partly implemented in Java and configured to operate within the BTE.

17. The one or more non-transitory, computer-readable mediums of claim 13 , wherein the IVE is further operable for performing input verification.

18. The one or more non-transitory, computer-readable mediums of claim 13 , wherein the BTE is further operable for signing the second binary object.

19. The one or more non-transitory, computer-readable mediums of claim 18 , wherein the trusted first binary object is to be signed by a key, and wherein signing the second binary object comprises signing the second binary object with the key.

20. The one or more non-transitory, computer-readable mediums of claim 18 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key signed by a common issuer of the first key.

21. The one or more non-transitory, computer-readable mediums of claim 18 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key provided by a vendor of the trusted binary object.

22. The one or more non-transitory, computer-readable mediums of claim 18 , wherein the trusted first binary object is to be signed with a first key, and wherein signing the second binary object comprises signing the second binary object with a second key having a common provenance with the first key.

23. A computer-implemented method for execution within a trusted execution environment (TEE), comprising:

receiving a trusted first binary object in a first format, the first binary object being a signed binary object;

analyzing the trusted first binary object to identify portions that perform input/output operations comprising signed and validated input from a peripheral;

tagging the portions to create a tagged trusted binary object with tagged portions;

translating the tagged trusted binary object into a second binary object in a second format suitable for use on the target platform, wherein translating comprises reserving the tagged portions for execution within an enclave;

signing the second binary object in the second format; and

consulting a certificate expiration or revocation list before signing the second binary object.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2015
From: SMITH, NED M.; RUBAKHA, DMITRI; SHAH, SAMIR; MARTIN, JASON; SHELLER, MICAH J.; CHAKRABARTI, SOMNATH; XING, BIN
To: MCAFEE, INC.
Reel/Frame 035130/0351 →