IP Library Granted Patent US 10,467,404
Granted Patent B2
US 10,467,404 · App. 15/715,626 · Granted Nov 5, 2019

Apparatus and method for secure module build

Inventor: Michael Brumlow (Houston, TX)
Assignee: CONTINUUM MANAGED SERVICES HOLDCO, LLC
G06F21/51G06F16/166G06F21/52G06F2221/033G06F2221/2145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,467,404
App. No.
15/715,626
Granted
Nov 5, 2019
Kind
B2
Abstract

An apparatus for securely building a module for a consumer computing system, including a coordination server and a build server. The coordination server receives configuration and makefile data associated with the consumer computing system, places the data in a queue, and provides the module to the consumer computing system. The build server corresponds to the configuration data. The build server receives the data from the queue, and builds the module based on commands within the makefile data, where the build server extracts whitelist commands from the makefile data within a public root of the build server, executes the whitelist commands within a secure root of the build server to generate named object files from proprietary source files, transfers the named object files to the public root, renames the object files into renamed object files according to the whitelist commands, and links the renamed object files to generate the module.

Claims (39)

1. An apparatus for securely building a module for a consumer computing system, the apparatus comprising:

a computer program product encoded in at least one non-transitory computer usable medium that, when executed, functions as:

a coordination server, configured to receive configuration and makefile data associated with the consumer computing system, and configured to place said data in a queue, and configured to provide the module to the consumer computing system; and

a build server, coupled to said coordination server and corresponding to said configuration data, configured to receive said data from said queue, and configured to build the module based on commands within said makefile data, wherein said build server extracts whitelist commands from said makefile data within a public root of said build server, executes said whitelist commands within a secure root of said build server to generate named object files from proprietary source files, transfers said named object files to said public root, renames said object files into renamed object files according to said whitelist commands, and links said renamed object files to generate the module.

2. The apparatus as recited in claim 1 , wherein the consumer computing system executes a Unix-based operating system, and wherein the module is loaded at run time with a kernel of said Unix-based operating system.

3. The apparatus as recited in claim 1 , wherein execution of said whitelist commands within said secure root precludes execution of malicious commands that are within said makefile data, thereby improving security of said build server.

4. The apparatus as recited in claim 1 , wherein said proprietary source files are stored exclusively in said secure root.

5. The apparatus as recited in claim 1 , wherein execution of said whitelist commands within said secure root transforms said proprietary source code files into named object files, and wherein said named object files are in binary form, and wherein said binary form does not reveal instructions in said proprietary source files.

6. The apparatus as recited in claim 1 , wherein said secure root comprises a compiler that is compatible with the consumer computing system.

7. The apparatus as recited in claim 6 , wherein said public root comprises a wrapper that appears to perform operations according to said compiler, but rather extracts said whitelist commands from said makefile data.

8. The apparatus as recited in claim 7 , wherein said wrapper generates an alternative module when said whitelist commands are insufficient to build the module.

9. An apparatus for securely building a module for a consumer computing system, the apparatus comprising:

a computer program product encoded in at least one non-transitory computer usable medium that, when executed, functions as:

a coordination server, configured to receive configuration and makefile data associated with the consumer computing system, and configured to place said data in a queue, and configured to provide the module to the consumer computing system; and

a build server, coupled to said coordination server and corresponding to said configuration data, configured to receive said data from said queue, and configured to build the module based on commands within said makefile data, said build server comprising:

a secure root, configured to execute whitelist commands to generate named object files from proprietary source files; and

a public root, configured to extract said whitelist commands from said makefile data, to transfer said whitelist commands to said secure root, to receive said named object files, to rename said object files into renamed object files according to said whitelist commands, and to links said renamed object files to generate the module.

10. The apparatus as recited in claim 9 , wherein the consumer computing system executes a Unix-based operating system, and wherein the module is loaded at run time with a kernel of said Unix-based operating system.

11. The apparatus as recited in claim 9 , wherein execution of said whitelist commands within said secure root precludes execution of malicious commands that are within said makefile data, thereby improving security of said build server.

12. The apparatus as recited in claim 9 , wherein said proprietary source files are stored exclusively in said secure root.

13. The apparatus as recited in claim 9 , wherein execution of said whitelist commands within said secure root transforms said proprietary source code files into named object files, and wherein said named object files are in binary form, and wherein said binary form does not reveal instructions in said proprietary source files.

14. The apparatus as recited in claim 9 , wherein said secure root comprises a compiler that is compatible with the consumer computing system.

15. The apparatus as recited in claim 14 , wherein said public root comprises a wrapper that appears to perform operations according to said compiler, but rather extracts said whitelist commands from said makefile data.

16. The apparatus as recited in claim 15 , wherein said wrapper generates an alternative module when said whitelist commands are insufficient to build the module.

17. A method for securely building a module for a consumer computing system, the method comprising:

via a coordination server, receiving configuration and makefile data associated with the consumer computing system, and placing the data in a queue, and returning the module to the consumer computing system; and

via a build server, receiving the data from the queue, and building the module based on commands within the makefile data, said building comprising:

extracting whitelist commands from the makefile data within a public root of the build server;

executing the whitelist commands within a secure root of the build server to generate named object files from proprietary source files;

transferring the named object files to the public root;

renaming the object files into renamed object files according to the whitelist commands; and

linking the renamed object files to generate the module.

18. The method as recited in claim 17 , wherein the consumer computing system executes a Unix-based operating system, and wherein the module is loaded at run time with a kernel of the Unix-based operating system.

19. The method as recited in claim 17 , wherein said executing of the whitelist commands within the secure root precludes execution of malicious commands that are within the makefile data, thereby improving security of the build server.

20. The method as recited in claim 17 , wherein the proprietary source files are stored exclusively in the secure root.

21. The method as recited in claim 17 , wherein said executing of the whitelist commands in the secure root comprises transforming the proprietary source code files into named object files, and wherein the named object files are in binary form, and wherein the binary form does not reveal instructions in the proprietary source files.

22. The method as recited in claim 17 , wherein the secure root comprises a compiler that is compatible with the consumer computing system.

23. The method as recited in claim 22 , wherein the public root comprises a wrapper that appears to perform operations according to the compiler, but rather extracts the whitelist commands from the makefile data.

24. The method as recited in claim 23 , wherein the wrapper generates an alternative module when the whitelist commands are insufficient to build the module.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2024
From: CONTINUUM MANAGED SERVICES HOLDCO, LLC
To: CONNECTWISE, LLC
Reel/Frame 069622/0116 →
RELEASE OF SECURITY INTEREST Recorded Oct 6, 2021
From: OWL ROCK CAPITAL CORPORATION
To: CONNECTWISE, LLC; CONTINUUM MANAGED SERVICES HOLDCO, LLC
Reel/Frame 057718/0617 →
SECURITY INTEREST Recorded Dec 2, 2019
From: CONTINUUM MANAGED SERVICES HOLDCO, LLC
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 051153/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED AT REEL: 43979 FRAME: 641. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jul 10, 2019
From: BRUMLOW, MICHAEL
To: CONTINUUM MANAGED SERVICES HOLDCO, LLC
Reel/Frame 049716/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE NAME OF THE ASSIGNOR WAS RECORDED AS CONTINUUM MANAGED SERVICES PREVIOUSLY RECORDED ON REEL 043979 FRAME 0641. ASSIGNOR(S) HEREBY CONFIRMS THE THE CORRECT NAME OF THE ASSIGNOR IS CONTINUUM MANAGED SERVICES HOLDCO, LLC. Recorded Jul 10, 2019
From: BRUMLOW, MICHAEL
To: CONTINUUM MANAGED SERVICES HOLDCO, LLC
Reel/Frame 051532/0173 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2017
From: BRUMLOW, MICHAEL
To: CONTINUUM MANAGED SERVICES
Reel/Frame 043979/0641 →
Continuity (1)
Related Publication 20190095611A1 · Mar 28, 2019