IP Library Granted Patent US 11,729,002
Granted Patent B2
US 11,729,002 · App. 17/018,192 · Granted Aug 15, 2023

Code signing method and system

Inventor: Nicholas Alexander Allen (Kirkland, WA)
Assignee: AMAZON TECHNOLOGIES, INC.
H04L9/3247G06F8/65G06F21/64H04L9/30H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,002
App. No.
17/018,192
Granted
Aug 15, 2023
Kind
B2
Abstract

A computer system obtains a request to apply a signed patch to a piece of signed executable code. The computer system determines whether the signed patch is allowed to be applied to the signed executable based on a set of patch policies. If the patch policies allow the patch to be applied, the patch is applied to the signed executable code. The computer system generates a new digital signature for the modified executable code thereby allowing the resulting signed patched executable code to be verified and executed by the computer system.

Claims (73)

1. A computer-implemented method, comprising:

obtaining, at a host computer system, a request to apply a signed patch signed using a first cryptographic key to a piece of signed executable code signed using a second cryptographic key;

verifying an identity of a code author using a first indication of authenticity provided with the piece of signed executable code;

verifying an identity of a patch author using a second indication of authenticity provided with the signed patch;

at the host computer system, as a result of determining that applying the signed patch to the piece of signed executable code is permitted in accordance with a set of patch policies, causing the signed patch to be applied to the piece of signed executable code to produce a patched piece of executable code;

generating a first digital signature for the patched piece of executable code using a private third cryptographic key; and

generating a signed patched piece of executable code that includes the patched piece of executable code and the first digital signature.

2. The computer-implemented method of claim 1 , further comprising:

generating a third indication of authenticity for the signed patched piece of executable code,

wherein the third indication of authenticity is associated with the private third cryptographic key; and

the third indication of authenticity is included in the signed patched piece of executable code.

3. The computer-implemented method of claim 2 , further comprising:

validating a second digital signature on the piece of signed executable code using a first public key of the code author, the first public key being provided in the first indication of authenticity provided with the piece of signed executable code; and

validating a third digital signature on the signed patch using a second public key of the patch author, the second public key being provided in the second indication of authenticity provided with the signed patch.

4. The computer-implemented method of claim 1 , wherein:

a trust store accessible to a requesting entity stores a set of public cryptographic keys trusted by the requesting entity; and

the set of public cryptographic keys includes a public key that corresponds to the private third cryptographic key.

5. A system, comprising:

one or more processors;

memory that stores computer-executable instructions that, if executed, cause the system to:

obtain, from a user of the system, a request to apply a patch signed by a first private key to a piece of signed executable code signed by a second private key;

verify a first identity of a code author associated with the piece of signed executable code;

verify a second identity of a patch author associated with the patch;

evaluate a set of patch policies to determine that the patch is allowed to be applied to the piece of signed executable code;

apply the patch to the piece of signed executable code to produce modified executable code;

apply a digital signature to the modified executable code, the digital signature created using a third private key of a public-private key pair, the third private key not accessible by the user; and

store a piece of signed modified executable code that includes the digital signature.

6. The system of claim 5 , wherein the computer-executable instructions further cause the system to:

cryptographically verify that the digital signature is valid using a public key of the public-private key pair; and

wherein the public key is stored in a trusted platform module accessible to the system.

7. The system of claim 5 , wherein:

the piece of signed modified executable code includes a digital certificate;

the digital certificate includes authorship information extracted from the piece of signed executable code; and

the digital certificate includes authorship information extracted from the patch.

8. The system of claim 7 , wherein:

the authorship information extracted from the piece of signed executable code is stored in a first extension to the digital certificate; and

the authorship information extracted from the patch is stored in a second extension to the digital certificate.

9. The system of claim 5 , wherein:

the digital signature is a first digital signature;

the patch includes a second digital signature of the patch generated using the first private key; and

the patch is validated by verifying the second digital signature.

10. The system of claim 5 , wherein:

the set of patch policies identifies a set of patch authors that are allowed to produce patches that can be applied to the piece of signed executable code.

11. The system of claim 5 , wherein:

the computer-executable instructions further cause the system to generate a digital certificate for the modified executable code, the digital certificate including a public key of the public-private key pair, and the digital certificate signed using a fourth private key of a certificate authority trusted by the system; and

the piece of signed modified executable code includes the digital certificate.

12. The system of claim 5 , wherein the set of patch policies includes a policy that determines that the patch is allowed to be applied based on a characteristic of the user.

13. A non-transitory computer-readable storage medium storing executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:

in response to a request, verify a first identity of a first provider of a patch signed using first cryptographic information and a second identity of a second provider of a piece of signed executable code signed using second cryptographic information;

produce modified executable code by applying the patch to the piece of signed executable code;

determine that the modified executable code is allowed to be signed based on a patch policy;

generate a digital signature for the modified executable code using a private key of a public-private key pair that is available to the computer system; and

provide signed modified executable code corresponding to the modified executable code, the signed modified executable code including the digital signature.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the digital signature for the modified executable code is a first digital signature, and

the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to verify a second digital signature on the piece of signed executable code using a public cryptographic key stored in a trust store of the computer system, the trust store storing a set of public cryptographic keys associated with entities authorized to apply software patches.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the digital signature for the modified executable code is a first digital signature and the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:

validate a digital certificate provided with the patch; and

verify a second digital signature on the patch using a public cryptographic key included with the digital certificate.

16. The non-transitory computer-readable storage medium of claim 13 , wherein the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:

identify, using the patch policy, a set of public cryptographic keys based on the second identity of the second provider; and

as a result of determining that the first cryptographic information used to sign the patch comprises a key in the set of public cryptographic keys, allow the signed modified executable code to be provided.

17. The non-transitory computer-readable storage medium of claim 13 , wherein the executable instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:

identify, using the patch policy, a set of public cryptographic keys based on the piece of signed executable code; and

as a result of determining that the first cryptographic information used to sign the patch comprise a key in the set of public cryptographic keys, allow the signed modified executable code to be provided.

18. The non-transitory computer-readable storage medium of claim 13 , wherein:

the signed modified executable code includes information that identifies a provenance of the signed modified executable code; and

the provenance identifies the piece of signed executable code and the patch.

19. The non-transitory computer-readable storage medium of claim 13 , wherein:

the signed modified executable code includes a digital certificate issued by a local certificate authority operated by the computer system;

the local certificate authority is represented in a trust store maintained by the computer system; and

the trust store is a data store that identifies one or more certificate authorities capable of issuing trusted digital certificates.

20. The non-transitory computer-readable storage medium of claim 13 ,

wherein the first provider is different than the second provider.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2020
From: ALLEN, NICHOLAS ALEXANDER
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 053746/0534 →
Continuity (2)
Continuation 16147393 · Sep 28, 2018
Related Publication 20200412548A1 · Dec 31, 2020