IP Library › Granted Patent US 12,190,316
Granted Patent B2
US 12,190,316 · App. 17/741,353 · Granted Jan 7, 2025

Code transparency system operation

Inventors: Mark Eugene Russinovich (Bellevue, WA); Sylvan W. Clebsch (Cambridge, GB); Kahren Tevosyan (Kirkland, WA); Antoine Jean Denis Delignat-Lavaud (Cambridge, GB); Cédric Alain Marie Christophe Fournet (Cambridge, GB); Hervey Oliver Wilson (Bellevue, WA); Manuel Silverio Da Silva Costa (Cambridge, GB)
Assignee: Microsoft Technology Licensing, LLC
G06Q20/3829G06F16/182G06Q2220/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,190,316
App. No.
17/741,353
Granted
Jan 7, 2025
Kind
B2
Abstract

The disclosed technology is generally directed to code transparency. In one example of the technology, a claim associated with an application is received. The claim is a document that is signed with a claim signature and that includes evidence associated with a policy, and further includes an expected set of at least one binary measurement associated with the application. The evidence is cryptographically verifiable evidence associated with the application. A trusted execution environment (TEE) is used to provide a distributed ledger. The claim is verified. Verifying the claim includes verifying the expected set of at least one binary measurement associated with the application, verifying the claim signature, and, based at least on the evidence, verifying that the application meets the policy. Upon successful verification of the claim, the claim is appended to the distributed ledger. A ledger countersignature associated with the claim is generated.

Claims (43)

1. An apparatus, comprising:

a device including at least one memory having processor-executable code stored therein, and at least one processor that is adapted to execute the processor-executable code, wherein the processor-executable code includes processor-executable instructions that, in response to execution, enable the device to perform actions, including:

receiving a first claim that is associated with a first application, wherein the first claim is a document that is signed with a claim signature and that includes first evidence that is associated with a first policy, and further includes an expected set of at least one binary measurement associated with the first application, wherein the first evidence is cryptographically verifiable evidence that is associated with the first application;

using a first trusted execution environment (TEE) to:

provide a distributed ledger;

verify the first claim, wherein verifying the first claim includes verifying the expected set of at least one binary measurement associated with the first application, verifying the claim signature, and, based at least on the first evidence, verifying that the first application meets the first policy; and

upon successful verification of the first claim:

append the first claim to the distributed ledger; and

generate a first ledger countersignature that is associated with the first claim, wherein the first ledger countersignature includes a signature of a root of a tree of the distributed ledger.

2. The apparatus of claim 1 , wherein the first ledger countersignature includes a cryptographic construction that includes proof that at least the first evidence has been stored on the distributed ledger.

3. The apparatus of claim 1 , wherein the first ledger countersignature is associated with at least one guarantee, and wherein the at least one guarantee includes a guarantee of auditability of the first application.

4. The apparatus of claim 1 , wherein the first ledger countersignature is associated with at least one guarantee, and wherein the at least one guarantee includes a guarantee of detection of misbehavior of the first application.

5. The apparatus of claim 1 , wherein the first policy is a policy of archiving source code of the first application.

6. The apparatus of claim 1 , wherein the first policy is a policy of reproducibly building a binary of the first application.

7. The apparatus of claim 1 , wherein the first claim is signed with the claim signature using distributed identity key management.

8. The apparatus of claim 1 , the actions further including:

executing a first instance of a service that is associated with the first application; and

upgrading the first instance of the service to a second instance of the service, the upgrading including:

launching the second instance of the service;

causing a transfer at least one secret of the first instance from the first instance to the second instance;

causing the first instance to verify whether a claim that is associated with the second instance has been successfully verified by the first TEE;

upon successful verification by the first instance that the second instance has been successfully verified by the first TEE, causing the first instance to update a signing key that is associated with the first instance and to share the updated signing key with the second instance; and

recording information that is associated with the upgrade on the distributed ledger.

9. The apparatus of claim 1 , wherein the first claim further includes second evidence that is associated with a second policy, the second evidence is cryptographically verifiable evidence that is associated with the first application, and wherein verifying the first claim further includes, based at least on the second evidence, verifying that the first application meets the second policy.

10. The apparatus of claim 9 , wherein the first policy is a policy of archiving source code of the first application, and wherein the second policy is a policy of reproducibly building a binary of the first application.

11. A method, comprising:

at a first code transparency service (CTS) instance, receiving a first claim that is associated with a first application, wherein the first claim is a document that is signed with a claim signature and that includes first evidence that is associated with a first policy, and further includes an expected set of at least one binary measurement associated with the first application, wherein the first evidence is cryptographically verifiable evidence that is associated with the first application, and wherein the first policy is a policy of archiving source code of the first application;

using a first trusted execution environment (TEE) operating in the first CTS instance to:

provide a distributed ledger;

perform CTS validation of the first claim, wherein performing the CTS validation of the first claim includes verifying the expected set of at least one binary measurement associated with the first application, verifying the claim signature, and, based at least on the first evidence, verifying that the first application meets the first policy; and

upon successful CTS validation of the first claim:

store the first claim on the distributed ledger; and

provide a first ledger countersignature that is associated with the first claim.

12. The method of claim 11 , wherein the first policy is a policy of reproducibly building a binary of the first application.

13. The method of claim 11 , wherein the first claim further includes second evidence that is associated with a second policy, the second evidence is cryptographically verifiable evidence that is associated with the first application, and wherein performing CTS validation of the first claim further includes, based at least on the second evidence, verifying that the first application meets the second policy.

14. The method of claim 11 , wherein the first ledger countersignature is associated with at least one guarantee, and wherein the at least one guarantee includes a guarantee of auditability of the first application.

15. A processor-readable storage medium, having stored thereon processor-executable code that, upon execution by at least one processor, enables actions, comprising:

on a first trusted execution environment (TEE) that is operating on a first code transparency service (CTS) instance, verifying a first claim, wherein the first claim is a document that is signed with a claim signature and that includes first evidence that is associated with a first policy; wherein the first claim includes an expected set of at least one binary measurement associated with a first application; wherein the first evidence is cryptographically verifiable evidence that is associated with the first application; wherein the first policy is a policy of reproducibly binding a binary of the first application; and wherein verifying the first claim includes: verifying the expected set of at least one binary measurement associated with the first application, verifying the claim signature, and, based at least on the first evidence, verifying that the first application meets the first policy; and

via the first TEE, upon successful verification of the first claim:

appending the first claim to a distributed ledger that is provided by the first TEE; and

generating a first ledger countersignature that is associated with the first claim.

16. The processor-readable storage medium of claim 15 , wherein the first policy is a policy of archiving source code of the first application.

17. The processor-readable storage medium of claim 15 , wherein the first claim further includes second evidence that is associated with a second policy, the second evidence is cryptographically verifiable evidence that is associated with the first application, and wherein verifying the first claim further includes, based at least on the second evidence, verifying that the first application meets the second policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2022
From: RUSSINOVICH, MARK EUGENE; CLEBSCH, SYLVAN W.; TEVOSYAN, KAHREN; DELIGNAT-LAVAUD, ANTOINE JEAN DENIS; FOURNET, CÉDRIC ALAIN MARIE CHRISTOPHE; WILSON, HERVEY OLIVER; COSTA, MANUEL SILVERIO DA SILVA
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 061903/0260 →
Continuity (1)
Related Publication 20230368193A1 · Nov 16, 2023
References Cited (47)
US 10735397B2 · Ronda · 2020 [cited by applicant]
US 20040044739A1 · Ziegler · 2004 [cited by applicant]
US 20060259763A1 · Cooperstein · 2006 [cited by applicant]
US 20070209073A1 · Corby · 2007 [cited by applicant]
US 20090126011A1 · Downen · 2009 [cited by applicant]
US 20180189732A1 · Kozloski et al. · 2018 [cited by applicant]
US 20180225661A1 · Russinovich et al. · 2018 [cited by applicant]
US 20180309567A1 · Wooden · 2018 [cited by applicant]
US 20190020480A1 · Camenisch · 2019 [cited by applicant]
US 20190109877A1 · Samuel · 2019 [cited by applicant]
US 20190303541A1 · Reddy et al. · 2019 [cited by applicant]
US 20190303579A1 · Reddy et al. · 2019 [cited by applicant]
US 20190303623A1 · Reddy et al. · 2019 [cited by applicant]
US 20190306173A1 · Reddy · 2019 [cited by applicant]
US 20200019706A1 · Zhu · 2020 [cited by applicant]
US 20200019707A1 · Zhu · 2020 [cited by applicant]
US 20200142693A1 · Neugschwandtner · 2020 [cited by applicant]
US 20200241929A1 · Arrasjid · 2020 [cited by applicant]
US 20200302562A1 · Trim · 2020 [cited by applicant]
US 20200364346A1 · Gourisetti · 2020 [cited by applicant]
US 20210056501A1 · Ravindranathan · 2021 [cited by applicant]
US 20210360031A1 · Novotny · 2021 [cited by applicant]
US 20220083683A1 · Murck · 2022 [cited by applicant]
US 20220108026A1 · Ortiz · 2022 [cited by applicant]
US 20220200787A1 · Kostman · 2022 [cited by applicant]
US 20220237565A1 · Dzierzanowski · 2022 [cited by applicant]
US 20220360450A1 · Brandenburger · 2022 [cited by applicant]
US 20230022112A1 · Beveridge · 2023 [cited by applicant]
US 20230057898A1 · Androulaki · 2023 [cited by applicant]
US 20230062434A1 · Wagner · 2023 [cited by applicant]
US 20230100342A1 · Smith · 2023 [cited by applicant]
US 20230117628A1 · Giffard-Burley · 2023 [cited by examiner]
US 20230205929A1 · Vincent · 2023 [cited by applicant]
US 20230208644A1 · Fitzpatrick · 2023 [cited by applicant]
US 20230245117A1 · Higgins · 2023 [cited by applicant]
US 20230245118A1 · Zhu · 2023 [cited by applicant]
US 20230370273A1 · Russinovich · 2023 [cited by applicant]
EP 3598333A1 · 2020 [cited by applicant]
Non-Final Office Action mailed on Feb. 15, 2024, in U.S. Appl. No. 17/741,348, 14 pages. [cited by applicant]
“Application as Filed in U.S. Appl. No. 17/741,348”, filed May 10, 2022, 34 Pages. (MS# 411372- JS-NP). [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US23/013369”, Mailed Date: Jun. 12, 2023, 13 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US23/013578”, Mailed Date: Jun. 16, 2023, 15 Pages. [cited by applicant]
Russinovich, et al., “Toward Confidential Cloud Computing”, In Journal of Queue, vol. 19, Issue 1, Jan. 2021, 28 Pages. [cited by applicant]
Singh, et al., “Enclaves in The Clouds”, In Journal of Queue, vol. 18, Issue 6, Nov. 2020, 37 Pages. [cited by applicant]
U.S. Appl. No. 17/741,348, filed May 10, 2022. [cited by applicant]
U.S. Appl. No. 17/741,353, filed May 10, 2022. [cited by applicant]
Notice of Allowance mailed on Jul. 10, 2024, in U.S. Appl. No. 17/741,348, 09 pages. [cited by applicant]