IP Library › Granted Patent US 11,440,190
Granted Patent B1
US 11,440,190 · App. 16/822,346 · Granted Sep 13, 2022

Detecting unsecure data flow in automation task programs

Inventors: Federico Maggi (Vimercate, IT); Marcello Pogliani (Monza, IT); Davide Quarta (Amsterdam, NL); Martino Vittone (Vallauris, FR); Stefano Zanero (Milan, IT)
Assignee: TREND MICRO INCORPORATED
B25J9/1674B25J9/1658G06F16/9024G06F16/9027G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,440,190
App. No.
16/822,346
Granted
Sep 13, 2022
Kind
B1
Abstract

An automation task program is inspected for unsecure data flow. The task program is parsed to generate a parse tree, which is visited to generate control flow graphs of functions of the task program. The control flow graphs have nodes, which have domain-agnostic intermediate representations. The control flow graphs are connected to form an intermediate control flow graph. The task program is deemed to have an unsecure data flow when data is detected to flow from a data source to a data sink, with the data source and the data sink forming a source-sink pair that is indicative of an unsecure data flow.

Claims (37)

1. A method of detecting unsecure data flows in task programs, the method comprising:

receiving a task program for controlling motion of an industrial robot, the task program being written in an industrial robot programming language;

parsing the task program to generate a parse tree;

generating a plurality of separate control flow graphs for functions of the task program, each of the control flow graphs comprising a plurality of basic blocks, each of the basic blocks comprising domain-agnostic intermediate representations;

generating an intermediate control flow graph that connects the control flow graphs together;

detecting data flow from a data source to a data sink in the intermediate control flow graph, the data source and the data sink forming a predetermined source-sink pair that is indicative of an unsecure data flow; and

in response to detecting the data flow from the data source to the data sink in the intermediate control flow graph, deeming the task program to have the unsecure data flow.

2. The method of claim 1 , wherein generating the plurality of separate control flow graphs includes visiting the parse tree.

3. The method of claim 1 , wherein the data source is an instruction for receiving an external input to the task program and the data sink is an instruction for moving a moveable member of the industrial robot.

4. The method of claim 3 , wherein the moveable member of the industrial robot is a robot arm.

5. The method of claim 1 , further comprising:

preventing the task program from being executed by the industrial robot in response to deeming the task program to have the unsecure data flow.

6. A system for detecting unsecure data flows in task programs, the system comprising at least one processor and a memory, the memory storing instructions that when executed by the at least one processor cause the system to:

receive a task program, the task program being written in a programming language for a special-purpose device;

parse the task program to generate a parse tree of the task program;

visit the parse tree to generate a first control flow graph for a first function of the task program and a second control flow graph for a second function of the task program;

detect data flow from a data source to a data sink between the first and second control flow graphs, the data source and the data sink forming a predetermined source-sink pair that is indicative of an unsecure data flow; and

in response to detecting the data flow from the data source to the data sink, prevent execution of the task program by the special-purpose device,

wherein the special-purpose device is an industrial robot.

7. The system of claim 6 , wherein the data source is an instruction for receiving an external input to the task program and the data sink is an instruction for moving a moveable member of the industrial robot.

8. The system of claim 6 , wherein the instructions stored in the memory, when executed by the at least one processor, further cause the system to:

generate an intermediate control flow graph that connects the first control flow graph to the second control flow graph; and

detect the unsecure data flow in the intermediate control flow graph.

9. The system of claim 6 , wherein each of the first and second control flow graphs comprises a plurality of basic blocks, and each of the basic blocks comprises domain-agnostic intermediate representations.

10. A method of detecting unsecure data flows in task programs, the method comprising:

receiving a task program, the task program being written in a programming language for a special-purpose device;

parsing the task program to generate a parse tree of the task program;

visiting the parse tree to generate a first control flow graph for a first function of the task program and a second control flow graph for a second function of the task program;

detecting data flow from a data source to a data sink between the first and second control flow graphs, the data source and the data sink forming a predetermined source-sink pair that is indicative of an unsecure data flow; and

in response to detecting the data flow from the data source to the data sink in the intermediate control flow graph, deeming the task program to have the unsecure data flow,

wherein the special-purpose device is an industrial robot.

11. The method of claim 10 , wherein the data source is an instruction for receiving an external input to the task program and the data sink is an instruction for moving a moveable member of the industrial robot.

12. The method of claim 10 , wherein the programming language is an industrial robot programming language.

13. The method of claim 10 , wherein each of the first and second control flow graphs comprises a plurality of basic blocks, with each of the basic blocks comprising domain-agnostic intermediate representations.

14. The method of claim 10 , further comprising:

generating an intermediate control flow graph that connects the first control flow graph to the second control flow graph; and

detecting the unsecure data flow in the intermediate control flow graph.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2020
From: THE POLITECNICO DI MILANO
To: TREND MICRO INCORPORATED
Reel/Frame 052601/0110 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2020
From: MAGGI, FEDERICO; POGLIANI, MARCELLO; QUARTA, DAVIDE; VITTONE, MARTINO; ZANERO, STEFANO
To: TREND MICRO INCORPORATED
Reel/Frame 052406/0143 →
Continuity (1)
Provisional Application 62981953 · Feb 26, 2020
Cited By (2)
US 12,189,786 US 12,572,448