IP Library Granted Patent US 11,886,581
Granted Patent B1
US 11,886,581 · App. 16/926,546 · Granted Jan 30, 2024

Rapid verification of executing processes

Inventor: Bjorn Markus Jakobsson (New York, NY)
Assignee: Security Technology, LLC
G06F21/56H04L63/145G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,581
App. No.
16/926,546
Granted
Jan 30, 2024
Kind
B1
Abstract

Rapid verification of executing processes includes receiving a seed from a verification unit. A checksum is generated at least in part by using a processor. The processor is coupled to a hierarchical memory, the hierarchical memory comprising an instruction cache, a data cache, and a shared memory accessible by both the instruction cache and the data cache. The shared memory is configured to store an executing program. A size of at least one of the instruction cache and the data cache is insufficient to store the entire executing program. The checksum is transmitted to the verification unit.

Claims (50)

1. A system, comprising:

a memory;

one or more processors coupled to the memory; and

a verifier configured to:

receive (1) a first checksum value generated by at least one processor of a target entity executing first checksum code, and (2) an identity value associated with the target entity, wherein the target entity is in communication with the verifier;

compute, at least in part by the verifier executing second checksum code, a second checksum value;

wherein the first checksum code and the second checksum code executed, respectively, by the target entity and the verifier each comprise an accumulator portion and a control portion, and wherein the accumulator portion comprises a non-linear accumulator that modifies a checksum state, and wherein the control portion performs an action based at least in part on the modified checksum state;

perform a security determination based on:

(1) a time elapsed between communication of a seed and communication of the first checksum value,

(2) the identity value, and

(3) a comparison between the first checksum value and the second checksum value; and

subsequent to completion of a verification based at least in part on one or more digital signatures, perform a set of security actions based at least in part on the security determination, wherein the set of security actions comprises (1) enabling the at least one processor of the target entity to access a resource, and (2) causing the at least one processor of the target entity to obtain access to a cryptographic key.

2. The system of claim 1 wherein the action comprises a branch.

3. The system of claim 1 wherein at least one of the target entity or the verifier comprises a split cache.

4. The system of claim 1 wherein the target entity comprises at least one of a server, a desktop computer, or a wireless device.

5. The system of claim 1 wherein the non-linear accumulator comprises a cryptographic hash function.

6. The system of claim 1 wherein the non-linear accumulator comprises two non-commutative operations.

7. The system of claim 1 wherein the first checksum code executed on the at least one processor of the target entity is written to be larger than an L1 cache associated with the at least one processor of the target entity.

8. The system of claim 1 wherein the first checksum value is based at least in part on a challenge value sent by the verifier.

9. The system of claim 1 wherein in response to the security determination, the at least one processor of the target entity receives a result of an operation.

10. The system of claim 1 wherein based at least in part on the security determination, the target entity is configured to verify another target entity.

11. The system of claim 1 wherein executing of the first checksum code causes flushing of an L1 cache.

12. A method, comprising:

receiving, at a verifier, (1) a first checksum value generated by at least one processor of a target entity executing first checksum code, and (2) an identity value associated with the target entity, wherein the target entity is in communication with the verifier;

computing, at least in part by the verifier executing second checksum code using one or more processors, a second checksum value;

wherein the first checksum code and the second checksum code executed, respectively, by the target entity and the verifier each comprise an accumulator portion and a control portion, and wherein the accumulator portion comprises a non-linear accumulator that modifies a checksum state, and wherein the control portion performs an action based at least in part on the modified checksum state;

performing a security determination based on:

(1) a time elapsed between communication of a seed and communication of the first checksum value,

(2) the identity value, and

(3) a comparison between the first checksum value and the second checksum value; and

subsequent to completion of a verification based at least in part on one or more digital signatures, performing a set of security actions based at least in part on the security determination, wherein the set of security actions comprises (1) enabling the at least one processor of the target entity to access a resource, and (2) causing the at least one processor of the target entity to obtain access to a cryptographic key.

13. The method of claim 12 wherein the action comprises a branch.

14. The method of claim 12 wherein at least one of the target entity or the verifier comprises a split cache.

15. The method of claim 12 wherein the target entity comprises at least one of a server, a desktop computer, or a wireless device.

16. The method of claim 12 wherein the non-linear accumulator comprises a cryptographic hash function.

17. The method of claim 12 wherein the non-linear accumulator comprises two non-commutative operations.

18. The method of claim 12 wherein the first checksum code executed on the at least one processor of the target entity is written to be larger than an L1 cache associated with the at least one processor of the target entity.

19. The method of claim 12 wherein the first checksum value is based at least in part on a challenge value sent by the verifier.

20. The method of claim 12 wherein in response to the security determination, the at least one processor of the target entity receives a result of an operation.

21. The method of claim 12 wherein based at least in part on the security determination, the target entity is configured to verify another target entity.

22. The method of claim 12 wherein executing of the first checksum code causes flushing of an L1 cache.

23. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving, at a verifier, (1) a first checksum value generated by at least one processor of a target entity executing first checksum code, and (2) an identity value associated with the target entity, wherein the target entity is in communication with the verifier;

computing, at least in part by the verifier executing second checksum code using one or more processors, a second checksum value;

wherein the first checksum code and the second checksum code executed, respectively, by the target entity and the verifier each comprise an accumulator portion and a control portion, and wherein the accumulator portion comprises a non-linear accumulator that modifies a checksum state, and wherein the control portion performs an action based at least in part on the modified checksum state;

performing a security determination based on:

(1) a time elapsed between communication of a seed and communication of the first checksum value,

(2) the identity value, and

(3) a comparison between the first checksum value and the second checksum value; and

subsequent to completion of a verification based at least in part on one or more digital signatures, performing a set of security actions based at least in part on the security determination, wherein the set of security actions comprises (1) enabling the at least one processor of the target entity to access a resource, and (2) causing the at least one processor of the target entity to obtain access to a cryptographic key.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2023
From: SECURITYINNOVATION LLC
To: SECURITY TECHNOLOGY, LLC
Reel/Frame 064664/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2023
From: SECURITYINNOVATION LLC
To: SECURITY TECHNOLOGY, LLC
Reel/Frame 064668/0754 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2022
From: RIGHTQUESTION, LLC
To: SECURITYINNOVATION LLC
Reel/Frame 062191/0684 →
Continuity (2)
Continuation 15727089 · Oct 6, 2017
Provisional Application 62405745 · Oct 7, 2016