IP Library › Granted Patent US 10,503,931
Granted Patent B2
US 10,503,931 · App. 15/589,976 · Granted Dec 10, 2019

Method and apparatus for dynamic executable verification

Inventor: Lex Aaron Anderson (Auckland, NZ)
Assignee: ARRIS Enterprises LLC
G06F21/64G06F9/44521G06F16/2255G06F21/121G06F21/125G06F21/44G06F21/51G06F21/54H04L9/3236H04L9/0631
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,503,931
App. No.
15/589,976
Filed
May 8, 2017
Granted
Dec 10, 2019
Kind
B2
Art Unit
2436
USPC
713/189
Abstract

A method and apparatus for Dynamic Executable Verification (DEV) is disclosed that includes a random prefix of functions of a binary application, a check function for at least a subset of the functions and a jump table for at least a subset of the functions. DEV provides low-impact dynamic integrity protection to applications that is compatible with standard code signing and verification methods, and ensures that software cannot be tampered with either statically or dynamically without detection.

Claims (64)

1. A method of generating a dynamically verifiable application executable having a plurality of functions, comprising:

at build time:

prepending a random prefix to at least a subset of the plurality of functions ƒ of a binary of the application;

generating a check function for each function of the at least a subset of the plurality of functions;

injecting each of the generated check functions into random locations in the binary of the application;

generating a jump table J, the jump table J having, for each function in the subset of the plurality of functions:

a mapping between the respective function and the generated check function;

wherein the mapping between the respective function and generated check function is associated with a identifier o and is randomly injected into the jump table J; and

injecting a call to the jump table having the identifier into a bootstrap of the binary of the application to generate a protected binary of the application;

at link time:

linking the protected binary of the application to generate the application executable; and

at activation time:

generating hash table data using the bootstrap.

2. The method of claim 1 , wherein generating the hash table data using the bootstrap comprises:

receiving a certificate;

validating the certificate; and

generating the hash table data only if the certificate is valid.

3. The method of claim 2 , further comprising:

at build time, automatically injecting a call to the bootstrap into the dynamically verifiable application executable.

4. The method of claim 2 , further comprising:

at activation time, calling by a developer of the dynamically verifiable application executable bootstrap at activation time.

5. The method of claim 1 , wherein generating the hash table data only if the certificate is valid comprises:

calling each checking function ƒ c via the jump table to generate hash table data.

6. The method of claim 1 , further comprising:

at runtime:

verifying the protected binary of the application according to the hash table data.

7. A method of generating a dynamically verifiable application executable having a plurality of functions, comprising:

at build time:

prepending a random prefix to at least a subset of the plurality of functions ƒ of a binary of the application;

generating a check function for each function of the at least a subset of the plurality of functions;

injecting each of the generated check functions into random locations in the binary of the application;

generating a jump table J, the jump table J having, for each function in the subset of the plurality of functions:

a mapping between the respective function and the generated check function;

wherein the mapping between the respective function and generated check function is associated with a identifier o and is randomly injected into the jump table J; and

injecting a call to the jump table having the identifier into a bootstrap of the binary of the application to generate a protected binary of the application,

wherein generating a check function for at least one function of the at least a subset of the plurality of functions comprises automatically generating a check function for each function of a selected group of the at least a subset of the plurality of functions, and wherein each of the check functions are randomly selected.

8. The method of claim 7 , wherein the selected group of the at least a subset of the plurality of functions is randomly selected.

9. The method of claim 8 , wherein the selected group of the at least a subset of the plurality of functions is randomly selected according to a percentage parameter.

10. An apparatus for generating a dynamically verifiable application executable having a plurality of functions, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions including processor instructions for, at build time:

prepending a random prefix to at least a subset of the plurality of functions ƒ of a binary of the application;

generating a check function for at least one function of the at least a subset of the plurality of functions;

injecting each of the generated check functions into random locations in the binary of the application;

generating a jump table J, the jump table J having, for each function in the subset of the plurality of functions:

a mapping between the respective function and the generated check function;

wherein the mapping between the respective function and generated check function is associated with a random opaque identifier o and is randomly injected into the jump table J; and

injecting a call to the jump table having the identifier into a bootstrap of the binary of the application to generate a protected binary of the application,

wherein the application executable is activated by generating hash table data using the bootstrap.

11. The apparatus of claim 10 , further comprising:

a second processor;

a second memory, storing instructions including second processor instructions for: generating the hash table data using the bootstrap, comprising second processor instructions for:

receiving a certificate;

validating the certificate; and

generating the hash table data only if the certificate is valid.

12. The apparatus of claim 11 , wherein the second processor instructions for generating the hash table only if the certificate is valid comprises second processor instructions for calling each checking function ƒ c via the jump table to generate hash table data.

13. The apparatus of claim 11 , further comprising:

a third processor;

a third memory, storing instructions including third processor instructions for:

verifying the protected binary of the application according to the hash table data.

14. The apparatus of claim 10 , wherein the instructions for generating a check function for at least one function of the at least a subset of the plurality of functions comprises instructions for:

automatically generating a check function for each function of a selected group of the at least a subset of the plurality of functions.

15. The apparatus of claim 14 , wherein the selected group of the at least a subset of the plurality of functions is randomly selected.

16. The apparatus of claim 15 , wherein the selected group of the at least a subset of the plurality of functions is randomly selected according to a percentage parameter.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2017
From: ANDERSON, LEX AARON
To: ARRIS ENTERPRISES LLC
Reel/Frame 042559/0022 →
Continuity (2)
Provisional Application 62333332 · May 9, 2016
Related Publication 20170323120A1 · Nov 9, 2017