IP Library Granted Patent US 10,210,334
Granted Patent B2
US 10,210,334 · App. 15/285,330 · Granted Feb 19, 2019

Systems and methods for software integrity assurance via validation using build-time integrity windows

Inventors: Ricardo L. Martinez (Leander, TX); Balasingh P. Samuel (Round Rock, TX); Garrett B. Oncale (Pflugerville, TX)
Assignee: Dell Products L.P.
G06F21/575
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,210,334
App. No.
15/285,330
Granted
Feb 19, 2019
Kind
B2
Abstract

In accordance with embodiments of the present disclosure, an article of manufacture may include a non-transitory computer readable medium and computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to receive software code for an executable file, receive a configuration file, output an executable file based on the software code and the configuration file, the executable file comprising one or more integrity windows of code embedded within the software code and not affecting operation of software code within the executable file, and output a map file setting forth metadata regarding the integrity windows.

Claims (34)

1. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

receive software code for an executable file;

receive a configuration file;

output the executable file based on the software code and the configuration file, the executable file comprising one or more integrity windows of code embedded within the software code and not affecting operation of software code within the executable file; and

output a map file setting forth metadata regarding the integrity windows, wherein the map file is usable by integrity assurance software to assure integrity of signature validation software by injecting data into the one or more integrity windows of the executable file and determining whether the signature validation software validates the executable file as modified by the injected data.

2. The article of claim 1 , wherein one or more integrity windows comprise no operation instructions.

3. The article of claim 1 , wherein the metadata comprises at least one of addresses for the one or more integrity windows and sizes of the one or more integrity windows.

4. The article of claim 1 , wherein the configuration file sets forth one or more parameters for creating the one or more integrity windows within the executable file, including at least one of sizes of the one or more integrity windows, address locations of the one or more integrity windows, and a number of the one or more integrity windows.

5. The article of claim 1 , wherein the executable file comprises a basic input/output system.

6. A method comprising:

receiving software code for an executable file;

receiving a configuration file;

outputting the executable file based on the software code and the configuration file, the executable file comprising one or more integrity windows of code embedded within the software code and not affecting operation of software code within the executable file; and

outputting a map file setting forth metadata regarding the integrity windows, wherein the map file is usable by integrity assurance software to assure integrity of signature validation software by injecting data into the one or more integrity windows of the executable file and determining whether the signature validation software validates the executable file as modified by the injected data.

7. The method of claim 6 , wherein the one or more integrity windows comprise no operation instructions.

8. The method of claim 6 , wherein the metadata comprises at least one of addresses for the one or more integrity windows and sizes of the one or more integrity windows.

9. The method of claim 6 , wherein the configuration file sets forth one or more parameters for creating the one or more integrity windows within the executable file, including at least one of sizes of the one or more integrity windows, address locations of the one or more integrity windows, and a number of the one or more integrity windows.

10. The method of claim 6 , wherein the executable file comprises a basic input/output system.

11. An article of manufacture comprising:

a non-transitory computer readable medium; and

computer-executable instructions carried on the computer readable medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

receive a map file setting forth metadata regarding one or more integrity windows of code embedded within software code of an executable file, wherein the code of the one or more integrity windows does not affect operation of software code within the executable file;

based on the map file, inject data into the one or more integrity windows of the executable file; and

determine whether signature validation software for validating the executable file validates the executable file as modified by the injected data.

12. The article of claim 11 , wherein the metadata comprises at least one of addresses for the one or more integrity windows and sizes of the one or more integrity windows.

13. The article of claim 11 , wherein the executable file comprises a basic input/output system.

14. A method comprising:

receiving a map file setting forth metadata regarding one or more integrity windows of code embedded within software code of an executable file, wherein the code of the one or more integrity windows does not affect operation of software code within the executable file;

based on the map file, injecting data into the one or more integrity windows of the executable file; and

determining whether signature validation software for validating the executable file validates the executable file as modified by the injected data.

15. The method of claim 14 , wherein the metadata comprises at least one of addresses for the one or more integrity windows and sizes of the one or more integrity windows.

16. The method of claim 14 , wherein the executable file comprises a basic input/output system.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040679/0386) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0666 →
RELEASE OF SECURITY INTEREST AT REEL 040633 FRAME 0799 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
Reel/Frame 058297/0427 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 23, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0386 →
SECURITY INTEREST Recorded Nov 16, 2016
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; WYSE TECHNOLOGY L.L.C.; EMC CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040633/0799 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2016
From: MARTINEZ, RICARDO L.; SAMUEL, BALASINGH P.; ONCALE, GARRETT B.
To: DELL PRODUCTS L.P.
Reel/Frame 039936/0714 →
Continuity (1)
Related Publication 20180096152A1 · Apr 5, 2018