IP Library Granted Patent US 11,625,498
Granted Patent B2
US 11,625,498 · App. 17/722,201 · Granted Apr 11, 2023

Cloud-based whitebox node locking

Inventors: Lex Aaron Anderson (Auckland, NZ); Rafie Shamsaasef (San Diego, CA); Alexander Medvinsky (San Diego, CA)
Assignee: ARRIS Enterprises LLC
G06F21/6227G06F21/44G06F21/602H04L9/085H04L2209/16H04L2209/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,498
App. No.
17/722,201
Granted
Apr 11, 2023
Kind
B2
Abstract

A secure cloud-based node-locking service with built-in attack detection to eliminate fuzzing, cloning and other attacks is disclosed. White-box base files are securely stored on the cloud service and are not vulnerable to accidental leakage. A secure cloud-based dynamic secret encoding service reduces the risk of exposure of unprotected secrets and other sensitive data.

Claims (68)

1. A method of enabling secure generation of an output in a run-time device, comprising:

receiving a request to register a whitebox implementation for generating an output in a cloud service from a build-time device, the request comprising:

a base file; and

a list of unlocked whitebox look up tables (LUTs);

registering the base file and the list of unlocked whitebox LUTs in the cloud service;

returning a surrogate whitebox implementation having a build identifier (ID) and a plurality of blank LUTs to the build-time device;

receiving a lock request from the run-time device upon execution of the surrogate whitebox implementation, the lock request comprising a fingerprint of the run-time device determined by the run-time device upon first execution of the surrogate whitebox implementation and the build ID;

generating a locked whitebox implementation according to the received fingerprint of the run-time device and the build identifier, the locked whitebox implementation having a plurality of run-time device specific locked whitebox LUTs;

transmitting a run-time device specific locked whitebox LUTs from the cloud service to the run-time device;

receiving a request for a secret from the run-time device, the request for the secret including the build ID; and

transmitting an encoded secret;

wherein:

the lock request is automatically transmitted from a first address; and

the method further comprises:

determining if a preceding node locking request having a same build ID was received from a second address; and

rejecting the lock request in response to the preceding node locking request having the same build ID was received from the second address.

2. A method of enabling secure generation of an output in a run-time device, comprising:

receiving a request to register a whitebox implementation for generating an output in a cloud service from a build-time device, the request comprising:

a base file; and

a list of unlocked whitebox look up tables (LUTs);

registering the base file and the list of unlocked whitebox LUTs in the cloud service;

returning a surrogate whitebox implementation having a build identifier (ID) and a plurality of blank LUTs to the build-time device;

receiving a lock request from the run-time device upon execution of the surrogate whitebox implementation, the lock request comprising a fingerprint of the run-time device determined by the run-time device upon first execution of the surrogate whitebox implementation and the build ID;

generating a locked whitebox implementation according to the received fingerprint of the run-time device and the build ID, the locked whitebox implementation having a plurality of run-time device specific locked whitebox LUTs;

transmitting a run-time device specific locked whitebox LUTs from the cloud service to the run-time device;

receiving a request for a secret from the run-time device, the request for the secret including the build ID; and

transmitting an encoded secret;

wherein:

the lock request is automatically transmitted from a first address and;

the method further comprises:

determining if a preceding node locking request having a different build ID was received from the first address; and

rejecting the lock request in response to the preceding node locking request having the different build ID was received from the first address.

3. An apparatus for enabling secure generation of an output in a runt-time device, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

receiving a request to register a whitebox implementation for generating an output in a cloud service from a build-time device, the request comprising:

a base file; and

a list of unlocked whitebox look up tables (LUTs);

registering the base file and the list of unlocked whitebox LUTs in the cloud service;

returning a surrogate whitebox implementation having a build identifier (ID) and a plurality of blank LUTs to the build-time device;

receiving a lock request from the run-time device upon execution of the surrogate whitebox implementation, the lock request comprising a fingerprint of the run-time device determined by the run-time device upon first execution of the surrogate whitebox implementation and the build ID;

generating a locked whitebox implementation according to the received fingerprint of the run-time device and the build ID, the locked whitebox implementation having a plurality of run-time device specific locked whitebox LUTs;

transmitting a run-time device specific locked whitebox LUTs from the cloud service to the run-time device;

receiving a request for a secret from the run-time device, the request for the secret including the build ID; and

transmitting an encoded secret;

wherein:

the lock request is automatically transmitted from a first address; and

the processor instructions further comprise processor instructions for:

determining if a preceding node locking request having a same build ID was received from a second address; and

rejecting the lock request in response to the preceding node locking request having the same build ID was received from the second address.

4. An apparatus for enabling secure generation of an output in a run-time device, comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing processor instructions comprising processor instructions for:

receiving a request to register a whitebox implementation for generating an output in a cloud service from a build-time device, the request comprising:

a base file; and

a list of unlocked whitebox look up tables (LUTs);

registering the base file and the list of unlocked whitebox LUTs in the cloud service;

returning a surrogate whitebox implementation having a build identifier (ID) and a plurality of blank LUTs to the build-time device;

receiving a lock request from the run-time device upon execution of the surrogate whitebox implementation, the lock request comprising a fingerprint of the run-time device determined by the run-time device upon first execution of the surrogate whitebox implementation and the build ID;

generating a locked whitebox implementation according to the received fingerprint of the run-time device and the build ID, the locked whitebox implementation having a plurality of run-time device specific locked whitebox LUTs;

transmitting a run-time device specific locked whitebox LUTs from the cloud service to the run-time device;

receiving a request for a secret from the run-time device, the request including the build ID; and

transmitting an encoded secret;

wherein:

the lock request is automatically transmitted from a first address;

the processor instructions further comprise processor instructions for:

determining if a preceding node locking request having a different build ID was received from the first address; and

rejecting the lock request in response to the preceding node locking request having the different build ID was received from the first address.

Assignments (7)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067252/0657 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074593/0348 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 067259/0697 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069790/0575 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
PATENT SECURITY AGREEMENT (TERM) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067259/0697 →
PATENT SECURITY AGREEMENT (ABL) Recorded Apr 29, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 067252/0657 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2022
From: ANDERSON, LEX AARON; SHAMSAASEF, RAFIE; MEDVINSKY, ALEXANDER
To: ARRIS ENTERPRISES LLC
Reel/Frame 060736/0001 →
Continuity (2)
Provisional Application 63181670 · Apr 29, 2021
Related Publication 20220366071A1 · Nov 17, 2022