IP Library Granted Patent US 12,260,227
Granted Patent B2
US 12,260,227 · App. 17/687,896 · Granted Mar 25, 2025

Binary image publication by firmware

Inventors: Eugene Khoruzhenko (Redmond, WA); Jeffrey Michael Bush (Wylie, TX)
Assignee: Absolute Software Corporation
G06F9/44505G06F9/4406G06F9/4401G06F9/4408G06F11/1417G06F21/572
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,260,227
App. No.
17/687,896
Granted
Mar 25, 2025
Kind
B2
Abstract

Multiple binary images stored in the firmware of an electronic device are written to the device's configuration tables during booting of the device, where one of the binary images is a manager binary. During booting, the manager binary is saved to the file system of the operating system such that it automatically executes upon completion of booting. The manager binary then deploys the other binary images.

Claims (39)

1. A method for publishing multiple binary images from firmware in an electronic device to an operating system in the electronic device, the method comprising:

during booting of the electronic device, the steps of:

installing a first binary image, which is stored in the firmware, into a configuration table in the electronic device;

installing a second binary image, which is stored in the firmware, into the configuration table; and

saving a copy of the first binary image in a file system of the operating system; and

after the operating system has started loading, the step of executing the copy of the first binary image to deploy the secondary binary image.

2. The method of claim 1 , wherein the first binary image deploys the second binary image by:

copying the second binary image to the file system; and

launching the second binary image.

3. The method of claim 2 , wherein the first binary image launches the second binary image as a child process of the first binary image.

4. The method of claim 1 , wherein the first binary image deploys the second binary image by launching the second binary image from the configuration table.

5. The method of claim 4 , wherein the first binary image launches the second binary image as a child process of the first binary image.

6. The method of claim 1 , wherein the configuration table is in firmware.

7. The method of claim 1 , wherein the configuration table is on a disk.

8. The method of claim 1 , wherein the deployed second binary image runs until the electronic device is switched off or rebooted.

9. The method of claim 1 comprising, during the booting of the electronic device, installing one or more further binary images, which are stored in the firmware, into the configuration table.

10. The method of claim 1 , wherein the first binary image allocates memory for execution, copies the second binary image into the allocated memory, and executes the second binary image.

11. The method of claim 10 , wherein the first binary image executes the second binary image by requesting the operating system to start the second binary image as a process.

12. The method of claim 1 , wherein the second binary image has a Data memory attribute in the configuration table.

13. The method of claim 1 comprising, when the second binary image is deployed, the second binary image initiates a network connection from the electronic device to a server.

14. The method of claim 13 , wherein the server uses one or more remote procedure calls to:

load a third binary image from the server to the electronic device; and

launch the third binary image.

15. The method of claim 1 , wherein the second binary image is a script.

16. The method of claim 1 , wherein the second binary image comprises one or more registry entries.

17. The method of claim 1 , wherein the second binary image is configuration data.

18. The method of claim 1 , wherein the first binary image executed while the operating system is loading, by:

saving the first binary image to a file;

loading the first binary image into memory; and

executing the first binary image as a process.

19. An electronic device that publishes multiple binary images, the electronic device comprising:

a processor;

an operating system; and

firmware storing computer readable instructions, which, when executed by the processor cause the electronic device, during booting of the electronic device, to:

install a first binary image, which is stored in the firmware, into a configuration table in the electronic device;

install a second binary image, which is stored in the firmware, into the configuration table; and

save a copy of the first binary image in a file system of the operating system;

and, after the operating system has started loading, execute the copy of the first binary image to deploy the secondary binary image.

20. The electronic device of claim 19 , wherein the first binary image deploys the second binary image by launching the second binary image from the configuration table.

Assignments (1)
SECURITY INTEREST Recorded Jul 31, 2023
From: ABSOLUTE SOFTWARE CORPORATION; MOBILE SONIC, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 064434/0284 →
Continuity (4)
Continuation In Part 16769185
Provisional Application 62598319 · Dec 13, 2017
Provisional Application 62598095 · Dec 13, 2017
Related Publication 20220197673A1 · Jun 23, 2022
References Cited (30)
US 6615404B1 · Garfunkel et al. · 2003 [cited by applicant]
US 9612846B2 · Puthillathe et al. · 2017 [cited by applicant]
US 9721101B2 · Jones et al. · 2017 [cited by applicant]
US 10402204B1 · Yakovlev et al. · 2019 [cited by applicant]
US 10664262B2 · Zimmermann et al. · 2020 [cited by applicant]
US 10740109B2 · Roszak et al. · 2020 [cited by applicant]
US 20090327741A1 · Zimmer et al. · 2009 [cited by applicant]
US 20100122077A1 · Durham · 2010 [cited by applicant]
US 20110131447A1 · Prakash et al. · 2011 [cited by applicant]
US 20120124357A1 · Zimmer et al. · 2012 [cited by applicant]
US 20150242221A1 · Tsirkin · 2015 [cited by applicant]
US 20170024313A1 · Tsirkin · 2017 [cited by examiner]
US 20180276000A1 · Roszak · 2018 [cited by examiner]
US 20180276001A1 · Roszak · 2018 [cited by examiner]
US 20180276002A1 · Roszak et al. · 2018 [cited by applicant]
US 20180276386A1 · Roszak · 2018 [cited by examiner]
US 20190005058A1 · Oganezov et al. · 2019 [cited by applicant]
US 20190065171A1 · Zimmerman et al. · 2019 [cited by applicant]
WO 0106360A2 · 2001 [cited by applicant]
Arturo M. Garcia, Firmware Modification Analysis in Programmable Logic Controllers, 2014, [Retrieved on Sep. 12, 2024]. Retrieved from the internet: <URL: https://scholar.afit.edu/cgi/viewcontent.cgi?article=1602&contex… [cited by examiner]
Kruegal, C. et al.; “Detecting Kernel-Level Rootkits Through Binary Analysis”; Proceedings of the 20th Annual Computer Security Applications Conference (ACSAC'04); IEEE 2004; retrieved Oct. 27, 2021 from the internet ht… [cited by applicant]
Hoffman, Chris; “Zombie Crapware: How the Windows Platform Binary Table Works”; Aug. 19, 2015; retrieved Mar. 20, 2019 from howtogeek.com. [cited by applicant]
Xu, Herbert; git.kernel.org; 2016. [cited by applicant]
Ionescu, Alex; “ACPI 5.0 Rootkit Attacks “Againts” Windows 8”; SyScan; 2012; Crowd Strike. [cited by applicant]
Yosifovich et al.; “Part 1 System Architecture, Processes, Threads, Memory Management and More”; 2017; Microsoft. [cited by applicant]
Weksteen; ACPI Table Implants; Google; available at least as early as Jun. 2020. [cited by applicant]
Windows Platform Binary Table (WPBT); Jul. 9, 2015; Microsoft. [cited by applicant]
Office Action issued in connection with Japanese Application No. 2020-531623; Feb. 2022. [cited by applicant]
Office Action issued in connection with Japanese Application No. 2022-82910; May 2023. [cited by applicant]
MacKinnon, David; International Search Report issued in connection with PCT Application No. PCT/CA2018/051575; search completed Jan. 16, 2019. [cited by applicant]