IP Library Granted Patent US 12,619,401
Granted Patent B2
US 12,619,401 · App. 18/413,088 · Granted May 5, 2026

Protecting and attesting program executions through shadow programs

Inventor: Felix Klaedtke (Heidelberg, DE)
Assignee: NEC CORPORATION
G06F8/36G06F8/433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,619,401
App. No.
18/413,088
Granted
May 5, 2026
Kind
B2
Abstract

A computer-implemented method for remotely attesting program executions includes obtaining, by a verifier computing entity, a program associated with an original program, for example a shadow program. The method further includes obtaining, by the verifier computing entity, collected information associated with control-flow operations executed by an instrumented program, wherein the instrumented program is a variation of the original program. The verifier computing entity executes the program associated with the original program based on the collected information, and checks an output of the program associated with the original program.

Claims (47)

1 . A computer-implemented method for remotely attesting program executions, comprising:

obtaining, by a verifier computing entity, a program associated with an original program;

obtaining, by the verifier computing entity, collected information associated with control-flow operations executed by an instrumented program, wherein the instrumented program is a variation of the original program;

executing, by the verifier computing entity, the program associated with the original program based on the collected information; and

checking, by the verifier computing entity, an output of the program associated with the original program.

2 . The computer-implemented method of claim 1 , wherein obtaining the program associated with the original program comprises obtaining a shadow program that mimics a control flow of the original program, and wherein executing the program associated with the original program comprises executing the shadow program based on the collected information.

3 . The computer-implemented method of claim 2 , wherein a prover computing entity comprises a first execution environment and a second execution environment, wherein the first execution environment executes the instrumented program and invokes a tracer from the second execution environment to collect the collected information in an attestation blob, and wherein the prover computing entity provides the attestation blob comprising the collected information to the verifier computing entity.

4 . The computer-implemented method of claim 2 , further comprising:

building the instrumented program by incorporating one or more trampolines into the original program, wherein each of the one or more trampolines is associated with the control-flow operations of the original program; and

building the shadow program by modifying the control-flow operations of the original program.

5 . The computer-implemented method of claim 4 , wherein building the instrumented program comprises:

including a new initialization step within the original program, wherein the new initialization step is configured to establish a connection to a tracer of a trusted environment of a prover computing entity;

including one or more attestation steps within the original program, wherein the one or more attestation steps are configured to notify the tracer of a request and notify the tracer of completion of the request; and

modifying a server request step by incorporating the one or more trampolines.

6 . The computer-implemented method of claim 5 , wherein the one or more trampolines is associated with a conditional branch instruction from the original program, and wherein the collected information indicates a truth value of the conditional branch that is obtained based on the one or more trampolines calling a first library function and invoking the tracer.

7 . The computer-implemented method of claim 5 , wherein the one or more trampolines is associated with an indirect call or jump instruction from the original program and a return instruction from the original program, and wherein the collected information indicates a target address that is obtained based on the one or more trampolines a second library function and invoking the tracer and a return address that is obtained based on the one or more trampolines a third library function and invoking the tracer.

8 . The computer-implemented method of claim 2 , wherein executing the shadow program comprises:

initializing one or more memory address mappings between the shadow program and the instrumented program;

awaiting an attestation blob comprising the collected information; and

based on receiving the attestation blob from the verifier computing entity, attesting execution of the instrumented program by a prover computing entity.

9 . The computer-implemented method of claim 8 , wherein initializing the one or more memory address mappings comprises:

obtaining a first mapping that translates target addresses of indirect calls and jumps of the instrumented program to corresponding target addresses of the shadow program; and

obtaining a second mapping that translates return addresses of the shadow program to corresponding return addresses of the instrumented program.

10 . The computer-implemented method of claim 9 , wherein attesting the execution of the instrumented program comprises: translating one or more addresses between the shadow program and the original program based on at least one of the first mapping and the second mapping, and wherein checking the output of the shadow program is based on translating the one or more addresses.

11 . The computer-implemented method of claim 8 , wherein attesting the execution of the instrumented program comprises:

based on detecting a conditional branch instruction, executing a first call function to obtain a truth value associated with the conditional branch instruction from the attestation blob;

performing a test-and-branch instruction based on the truth value to test the conditional branch; and

determining a result of the test of the conditional branch, wherein the output of the shadow program indicates the result of the test.

12 . The computer-implemented method of claim 8 , wherein attesting the execution of the instrumented program comprises:

based on detecting an indirect call or jump instruction, executing a second call function to read a next target address into a register from the attestation blob, translate the next target address into a corresponding target address of the shadow program, and return the corresponding target address in a register;

based on detecting a return instruction, executing a third call function to translate a return address of the shadow program into a corresponding return address of the instrumented program, update a hash value with the corresponding return address, and comparing the hash value with a hash value from the attestation blob; and

determining one or more results of the indirect call or jump instruction and the return instruction based on executing the second call function and the third call function.

13 . The computer-implemented method of claim 2 , wherein the verifier computing entity is a controller that coordinates operation of at least one of: a plurality of robotic devices, a plurality of internet of things (IoT) devices, and a cloud server, and wherein, based on the output of the shadow program, one or more instructions are provided to reset the at least one of: the plurality of robotic devices, the plurality of IoT devices, and the cloud server.

14 . The computer-implemented method of claim 1 , wherein obtaining the program associated with the original program comprises:

obtaining the original program or the instrumented program; and

using an interpreter that directly uses the original program or the instrumented program, and

wherein executing the program associated with the original program comprises using the interpreter that replays and checks an execution of the instrumented program based on the collected information.

15 . A computer system for remotely attesting program executions, the system comprising one or more hardware processors, which, alone or in combination, are configured to provide for execution of the following steps:

obtaining a program associated with an original program;

obtaining collected information associated with control-flow operations executed by an instrumented program, wherein the instrumented program is a variation of the original program;

executing the program associated with the original program based on the collected information; and

checking an output of the program associated with the original program.

16 . A tangible, non-transitory computer-readable medium having instructions thereon which, upon being executed by one or more processors, alone or in combination, provide for execution of a method for remotely attesting program executions comprising the following steps:

obtaining a program associated with an original program;

obtaining collected information associated with control-flow operations executed by an instrumented program, wherein the instrumented program is a variation of the original program;

executing the program associated with the original program based on the collected information; and

checking an output of the program associated with the original program.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2026
From: NEC LABORATORIES EUROPE GMBH
To: NEC CORPORATION
Reel/Frame 074241/0349 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2024
From: KLAEDTKE, FELIX
To: NEC LABORATORIES EUROPE GMBH
Reel/Frame 066131/0090 →
Continuity (2)
Provisional Application 63602669 · Nov 27, 2023
Related Publication 20250173129A1 · May 29, 2025
References Cited (20)
US 9092569B2 · Vechev · 2015 [cited by examiner]
US 10482262B2 · Sharma · 2019 [cited by examiner]
US 11640352B2 · Moondhra · 2023 [cited by examiner]
US 20190121979A1 · Chari · 2019 [cited by examiner]
US 20200143043A1 · Hong · 2020 [cited by examiner]
US 20220215098A1 · Li · 2022 [cited by examiner]
US 20250173129A1 · Klaedtke · 2025 [cited by examiner]
CN 219246099U · 2023 [cited by applicant]
Chowdhary, “Parallel Shadow Execution to Accelerate the Debugging of Numerical Errors”, 2021, ACM (Year: 2021). [cited by examiner]
Abadi, “Control-Flow Integrity Principles, Implementations, and Applications”, 2009, ACM (Year: 2009). [cited by examiner]
Abera, Tigist et al.; “C-Flat: Control-Flow Attestation for Embedded Systems Software”; [cited by applicant]
Ahmad, Adil; “Defeating Critical Threats to Cloud User Data in Trusted Execution Environments”; [cited by applicant]
Chowdhary, Sangeeta; “Fast Methods to Detect and Debug Numerical Errors with Shadow Execution”; [cited by applicant]
Chowdhary, Sangeeta et al.; “Parallel Shadow Execution to Accelerate the Debugging of Numerical Errors”; [cited by applicant]
Christophe, Laurent et al.; “Linvail: A General-Purpose Platform for Shadow Execution of JavaScript”; [cited by applicant]
Kuchta, Tomasz et al.; “Shadow Symbolic Execution for Testing Software Patches”; [cited by applicant]
Morbitzer, Mathias et al.; “GuaranTEE: Introducing Control-Flow Attestation for Trusted Execution Environments”; [cited by applicant]
Sun, Zhichuang et al.; “OAT: Attesting Operation Integrity of Embedded Devices”; [cited by applicant]
Wang, Yuxin et al.; “Proving Differential Privacy with Shadow Execution”; [cited by applicant]
Zhang, Yumei et al.; “ReCFA: Resilient Control-Flow Attestation”; [cited by applicant]