IP Library Granted Patent US 12,254,085
Granted Patent B2
US 12,254,085 · App. 18/519,542 · Granted Mar 18, 2025

Software integrity checking systems and methods

Inventor: Marko Caklovic (Palo Alto, CA)
Assignee: Intertrust Technologies Corporation
G06F21/54G06F21/51G06F21/57G06F21/64G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,254,085
App. No.
18/519,542
Granted
Mar 18, 2025
Kind
B2
Abstract

This disclosure relates to systems and methods generating and distributing protected software applications. In certain embodiments, integrity checking mechanisms may be implemented using integrity checking code in software code prior to compilation into machine code. Following compilation and execution of the application, the introduced code may check the integrity of the application by determining whether the application behaves and/or otherwise functions as expected. By introducing integrity checking in this manner, integrity checking techniques may be injected into the application prior to compilation into machine code and/or independent of the particular manner in which the application is compiled.

Claims (25)

1. A non-transitory computer-readable medium storing instructions that, when executed by at least one processor of a system, cause the system to perform a method comprising:

detecting an initial execution of an application on the system, the application having been received from an application store system, the application comprising one or more functional integrity checks;

executing, at least in part in response to the detection of the initial execution, the one or more functional integrity checks of the application to verify that one or more portions of the application associated with the one or more functional integrity checks function according to a defined behavior, wherein executing the one or more functional integrity checks comprises verifying that one or more resource calls associated with the one or more portions of the application correspond with an expected resource call behavior;

generating, based on verifying that the one or more portions of the application function according to the defined behavior, one or more first integrity check values;

storing the one or more first integrity check values on a user device; and

allowing, based on the verifying that the one or more portions of the application function according to the defined behavior, the initial execution of the application to proceed.

2. The non-transitory computer-readable medium of claim 1 , wherein the one or more resource calls comprise one or more function calls and the expected resource call behavior comprises an expected function call behavior.

3. The non-transitory computer-readable medium of claim 1 , wherein the one or more functional integrity checks comprise code appended to the application.

4. The non-transitory computer-readable medium of claim 1 , wherein the one or more functional integrity checks comprise code injected into a plurality of locations in the application.

5. The non-transitory computer-readable medium of claim 1 , wherein the one or more functional integrity checks comprise obfuscated code.

6. The non-transitory computer-readable medium of claim 1 , wherein storing the one or more first integrity check values on the user device comprises storing the one or more first integrity check values in a secure storage space of the user device.

7. The non-transitory computer-readable medium of claim 1 , wherein storing the one or more first integrity check values on the user device comprises inserting the one or more first integrity check values in one or more locations of the application.

8. The non-transitory computer-readable medium of claim 1 , wherein the application further comprises one or more comparison integrity checks.

9. The non-transitory computer-readable medium of claim 8 , wherein the one or more first integrity check values comprise at least one result of a first operation performed on at least one portion of the one or more portions of the application.

10. The non-transitory computer-readable medium of claim 9 , wherein the first operation comprises a hashing operation and the one or more first integrity check values comprise one or more hash values.

11. The non-transitory computer-readable medium of claim 9 , wherein the method further comprises:

detecting a subsequent execution of the application; and

in response to detecting the subsequent execution of the application, executing the one or more comparison integrity checks.

12. The non-transitory computer-readable medium of claim 11 , wherein executing the one or more comparison integrity checks comprises:

generating one or more second integrity check values;

determining that the one or more second integrity check values match corresponding values of the one or more first integrity check values; and

allowing, based on determining that the one or more second integrity check values match corresponding values of the one or more first integrity check values, the subsequent execution of the application to proceed.

13. The non-transitory computer-readable medium of claim 12 , wherein generating the one or more second integrity check values comprises performing a second operation on the at least one portion of the one or more portions of the application.

14. The non-transitory computer-readable medium of claim 13 , wherein the one or more first integrity check values and the one or more second integrity check values comprise hash values, and wherein determining that the one or more second integrity check values match corresponding values of the one or more first integrity check values comprises comparing the hash values.

15. The non-transitory computer-readable medium of claim 1 , wherein the application is compiled by the application store system.

Assignments (2)
PATENT ASSIGNMENT Recorded May 27, 2025
From: INTERTRUST TECHNOLOGIES CORPORATION
To: INNOVATION TECHNOLOGIES PARTNERS LP
Reel/Frame 071408/0320 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2023
From: CAKLOVIC, MARKO
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 065667/0060 →
Continuity (6)
Continuation 18063960 · Dec 9, 2022
Continuation 17112612 · Dec 4, 2020
Continuation 16670701 · Oct 31, 2019
Continuation 15452319 · Mar 7, 2017
Provisional Application 62304771 · Mar 7, 2016
Related Publication 20240095343A1 · Mar 21, 2024
References Cited (28)
US 5359659A · Rosenthal · 1994 [cited by applicant]
US 5421006A · Jablon · 1995 [cited by examiner]
US 5598530A · Nagae · 1997 [cited by applicant]
US 5978484A · Apperson et al. · 1999 [cited by applicant]
US 6006328A · Drake · 1999 [cited by applicant]
US 6195587B1 · Hruska et al. · 2001 [cited by applicant]
US 6742121B1 · Safadi · 2004 [cited by applicant]
US 7757284B1 · Viljoen · 2010 [cited by applicant]
US 10496814B2 · Caklovic · 2019 [cited by applicant]
US 10872146B2 · Caklovic · 2020 [cited by applicant]
US 11531751B2 · Caklovic · 2022 [cited by applicant]
US 11829469B2 · Caklovic · 2023 [cited by examiner]
US 20020038428A1 · Safa · 2002 [cited by applicant]
US 20020138748A1 · Hung · 2002 [cited by applicant]
US 20030023856A1 · Horne et al. · 2003 [cited by applicant]
US 20030159036A1 · Walmsley et al. · 2003 [cited by applicant]
US 20030188231A1 · Cronce · 2003 [cited by applicant]
US 20030191942A1 · Sinha et al. · 2003 [cited by applicant]
US 20080140537A1 · Powell · 2008 [cited by applicant]
US 20080276314A1 · Wollnik et al. · 2008 [cited by applicant]
US 20090172814A1 · Khosravi et al. · 2009 [cited by applicant]
US 20130247016A1 · Sharma · 2013 [cited by examiner]
US 20160094552A1 · Durham et al. · 2016 [cited by applicant]
US 20160132667A1 · Freitas Fortuna Dos Santos et al. · 2016 [cited by applicant]
US 20170006057A1 · Perez Lafuente et al. · 2017 [cited by applicant]
US 20210089646A1 · Caklovic · 2021 [cited by applicant]
US 20240095343A1 · Caklovic · 2024 [cited by examiner]
WO WO0219598A2 · 2002 [cited by applicant]