IP Library › Granted Patent US 11,533,182
Granted Patent B2
US 11,533,182 · App. 16/811,435 · Granted Dec 20, 2022

Identity-based security platform and methods

Inventors: Ran Ilany (Hod Hasharon, IL); Alexei Kravtsov (Petah Tikva, IL); Ophir Setter (Ramat Gan, IL)
Assignee: CISCO TECHNOLOGY, INC.
H04L9/3247G06F8/61G06F9/45558G06F21/602H04L9/3242G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,533,182
App. No.
16/811,435
Granted
Dec 20, 2022
Kind
B2
Abstract

A method and system for securing instantiates. The method includes determining at least one signable file among a plurality of files of an instantiate, wherein determining the at least one signable file further comprises classifying each of the plurality of files with respect to whether the file is changed at runtime; signing each of the at least one signable file to create at least one first signature, wherein signing the plurality of files further comprises computing a cryptographic hash for each file, wherein each encrypted hash is signed using a private key; and verifying an identity of the instantiate using the at least one first signature, wherein verifying the identity of the instantiate further comprises comparing the at least one first signature to the at least one second signature, wherein each of the at least one second signature is a signature of one of the at least one signable file at runtime.

Claims (38)

1. A method for securing instantiates, comprising:

determining at least one signable file among a plurality of files of an instantiate, wherein determining the at least one signable file further comprises classifying each of the plurality of files with respect to whether the file is changed at runtime;

signing each of the at least one signable file to create at least one first signature, wherein signing the plurality of files further comprises computing a cryptographic hash for each file, wherein each cryptographic hash is signed using a private key; and

verifying an identity of the instantiate using the at least one first signature, wherein verifying the identity of the instantiate further comprises comparing the at least one first signature to the at least one second signature, wherein each of the at least one second signature is a signature of one of the at least one signable file at runtime.

2. The method of claim 1 , wherein the at least one signable file includes at least one operating system file, wherein the at least one operating system file is of an operating system image of a virtual machine that would execute the instantiate.

3. The method of claim 2 , wherein the operating system image corresponds to an operating system, wherein determining the at least one signable file further comprises:

installing the operating system image in the virtual machine; and

analyzing execution of the operating system, wherein each of the at least one operating system file is classified based on the analysis.

4. The method of claim 3 , wherein each of the at least one signable file is any of: changed at least a threshold number of times during execution of the operating system, and allowed to be changed during execution of the operating system.

5. The method of claim 1 , wherein the at least one signable file includes at least one artifact.

6. The method of claim 5 , wherein determining the at least one signable file further comprises:

installing a signed operating system image, wherein the signed operating system image corresponds to an operating system, wherein the at least one artifact is associated with the operating system; and

analyzing execution of the operating system, wherein each of the at least one artifact is classified based on the analysis.

7. The method of claim 6 , wherein signed operating system image is executed using at least one signed operating system file, wherein each of the at least one signed operating system file is one of the plurality of files that is classified as signable.

8. The method of claim 1 , wherein the plurality of files is classified based on at least one of: software packages received from external systems, a library defining types of files, executable permissions of the plurality of files, and whether each of the plurality of files was opened for reading or for writing.

9. The method of claim 1 , wherein the plurality of files is signed offline, wherein the identity of the instantiate is verified at runtime.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

determining at least one signable file among a plurality of files of an instantiate, wherein determining the at least one signable file further comprises classifying each of the plurality of files with respect to whether the file is changed at runtime;

signing each of the at least one signable file to create at least one first signature, wherein signing the plurality of files further comprises computing a cryptographic hash for each file, wherein each cryptographic hash is signed using a private key; and

verifying an identity of the instantiate using the at least one first signature, wherein verifying the identity of the instantiate further comprises comparing the at least one first signature to the at least one second signature, wherein each of the at least one second signature is a signature of one of the at least one signable file at runtime.

11. A system for securing instantiates, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

determining at least one signable file among a plurality of files of an instantiate, wherein determining the at least one signable file further comprises classifying each of the plurality of files with respect to whether the file is changed at runtime;

signing each of the at least one signable file to create at least one first signature, wherein signing the plurality of files further comprises computing a cryptographic hash for each file, wherein each cryptographic hash is signed using a private key; and

verifying an identity of the instantiate using the at least one first signature, wherein verifying the identity of the instantiate further comprises comparing the at least one first signature to the at least one second signature, wherein each of the at least one second signature is a signature of one of the at least one signable file at runtime.

12. The system of claim 11 , wherein the at least one signable file includes at least one operating system file, wherein the at least one operating system file is of an operating system image of a virtual machine that would execute the instantiate.

13. The system of claim 12 , wherein the operating system image corresponds to an operating system, wherein the system is further configured to:

install the operating system image in the virtual machine; and

analyze execution of the operating system, wherein each of the at least one operating system file is classified based on the analysis.

14. The system of claim 13 , wherein each of the at least one signable file is any of: changed at least a threshold number of times during execution of the operating system, and allowed to be changed during execution of the operating system.

15. The system of claim 11 , wherein the at least one signable file includes at least one artifact.

16. The system of claim 15 , wherein the system is further configured to:

install a signed operating system image, wherein the signed operating system image corresponds to an operating system, wherein the at least one artifact is associated with the operating system; and

analyze execution of the operating system, wherein each of the at least one artifact is classified based on the analysis.

17. The system of claim 16 , wherein signed operating system image is executed using at least one signed operating system file, wherein each of the at least one signed operating system file is one of the plurality of files that is classified as signable.

18. The system of claim 11 , wherein the plurality of files is classified based on at least one of: software packages received from external systems, a library defining types of files, executable permissions of the plurality of files, and whether each of the plurality of files was opened for reading or for writing.

19. The system of claim 11 , wherein the plurality of files is signed offline, wherein the identity of the instantiate is verified at runtime.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2022
From: PORTSHIFT SOFTWARE TECHNOLOGIES LTD
To: CISCO TECHNOLOGY, INC.
Reel/Frame 060489/0578 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2020
From: ILANY, RAN; KRAVTSOV, ALEXEI; SETTER, OPHIR
To: PORTSHIFT SOFTWARE TECHNOLOGIES LTD.
Reel/Frame 052118/0451 →
Continuity (2)
Provisional Application 62814434 · Mar 6, 2019
Related Publication 20200287723A1 · Sep 10, 2020