IP Library › Granted Patent US 12,293,172
Granted Patent B2
US 12,293,172 · App. 18/032,050 · Granted May 6, 2025

Tamper detection feature embedding device, tamper detection feature embedding method, and computer readable medium

Inventors: Yuto Hayaki (Tokyo, JP); Norio Yamagaki (Tokyo, JP)
Assignee: NEC CORPORATION
G06F8/433G06F21/54G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,293,172
App. No.
18/032,050
Granted
May 6, 2025
Kind
B2
Abstract

A device inputs a first source code, which is source code of the software to be monitored; builds the first source code to generate a first binary; generates a first CFG based on the first binary; embeds a tamper detection feature and tamper detection feature calling functions in a first source code based on the first CFG to generate a second source code, builds a second source code to generate a second binary; generates a second CFG based on the second binary; creates an allowed list based on the second binary and the second CFG, and outputs the second binary and the allowed list. Here, in creating the allowed list, the monitoring range for the tamper detection feature calling functions is determined based on the second CFG, and a list of hash values of the monitoring range for the tamper detection feature calling functions is created as an allowed list.

Claims (46)

1. A tamper detection feature embedding device configured to embed an allowed list type tamper detection feature using hash values in a software to be monitored, the tamper detection feature embedding device comprising:

at least one memory storing instructions, and

at least one processor configured to execute the instructions to:

receive input of a first source code, which is the source code of the software;

build the first source code to generate a first binary;

generate a first control flow graph (CFG) based on the first binary;

determine embedding points to embed tamper detection feature calling functions in the first source code based on the first CFG, embed the tamper detection feature calling functions in the determined embedding points in the first source code, and embed the tamper detection feature in the first source code;

build a second source code, which is the source code in which the tamper detection feature and the tamper detection feature calling functions are embedded in the first source code, to generate a second binary;

generate a second CFG based on the second binary;

create an allowed list based on the second binary and the second CFG, and

output the second binary and the allowed list,

wherein the at least one processor is further configured to execute the instructions to determine a monitoring range for the tamper detection feature calling functions based on the second CFG, and create a list of hash values of the monitoring range for the tamper detection feature calling functions as the allowed list.

2. The tamper detection feature embedding device according to claim 1 , wherein

the at least one processor is further configured to execute the instructions to

sequentially select the tamper detection feature calling functions on the second CFG, and

trace nodes that do not contain the tamper detection feature calling functions among all descendant nodes of a node containing the selected tamper detection feature calling functions, and determine the range from the node containing the selected tamper detection feature calling functions to a node immediately before the next node containing the tamper detection feature calling functions as the monitoring range for the selected tamper detection feature calling functions.

3. The tamper detection feature embedding device according to claim 1 , wherein

the at least one processor is further configured to execute the instructions to

create the allowed list in file format, and

output the allowed list in file format.

4. The tamper detection feature embedding device according to claim 1 , wherein

the at least one processor is further configured to execute the instructions to

create the allowed list in source code format and embeds the created allowed list in source code format in the second source code,

build the second source code in which the allowed list is embedded to generate the second binary in which the allowed list is embedded, and

output the second binary in which the allowed list is embedded.

5. The tamper detection feature embedding device according to claim 1 , wherein, when a device on which the software operates has a specific memory area to which external access is restricted by hardware, the at least one processor is further configured to execute the instructions to embed the tamper detection feature in the source code disposed on the specific memory area.

6. A tamper detection feature embedding method executed by a tamper detection feature embedding device configured to embed an allowed list type tamper detection feature using hash values in a software to be monitored, the tamper detection feature embedding method comprising:

an input step of inputting a first source code, which is the source code of the software;

a first build step of building the first source code to generate a first binary;

a first CFG generation step of generating a first control flow graph (CFG) based on the first binary;

a tamper detection feature embedding step of determining embedding points to embed tamper detection feature calling functions in the first source code based on the first CFG, embedding the tamper detection feature calling functions in the determined embedding points in the first source code, and embedding the tamper detection feature in the first source code;

a second build step of building a second source code, which is the source code in which the tamper detection feature and the tamper detection feature calling functions are embedded in the first source code, to generate a second binary;

a second CFG generation step of generating a second CFG based on the second binary;

an allowed list creation step of creating an allowed list based on the second binary and the second CFG, and

an output step of outputting the second binary and the allowed list,

wherein the allowed list creation step determines a monitoring range for the tamper detection feature calling functions based on the second CFG, and creates a list of hash values of the monitoring range for the tamper detection feature calling functions as the allowed list.

7. A non-transitory computer readable medium storing a program that causes a computer to execute processing of embedding an allowed list type tamper detection feature using hash values in a software to be monitored, the program comprising:

an input step of inputting a first source code, which is the source code of the software;

a first build step of building the first source code to generate a first binary;

a first CFG generation step of generating a first control flow graph (CFG) based on the first binary;

a tamper detection feature embedding step of determining embedding points to embed tamper detection feature calling functions in the first source code based on the first CFG, embedding the tamper detection feature calling functions in the determined embedding points in the first source code, and embedding the tamper detection feature in the first source code;

a second build step of building a second source code, which is the source code in which the tamper detection feature and the tamper detection feature calling functions are embedded in the first source code, to generate a second binary;

a second CFG generation step of generating a second CFG based on the second binary;

an allowed list creation step of creating an allowed list based on the second binary and the second CFG, and

an output step of outputting the second binary and the allowed list,

wherein the allowed list creation step determines the monitoring range for the tamper detection feature calling functions based on the second CFG, and creates a list of hash values of the monitoring range for the tamper detection feature calling functions as the allowed list.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2023
From: HAYAKI, YUTO; YAMAGAKI, NORIO
To: NEC CORPORATION
Reel/Frame 063328/0624 →
Continuity (1)
Related Publication 20230393822A1 · Dec 7, 2023
References Cited (14)
US 11003464B2 · Black · 2021 [cited by examiner]
US 11403388B2 · Kanei · 2022 [cited by examiner]
US 20080184041A1 · Jakubowski · 2008 [cited by examiner]
US 20200042695A1 · Kanei · 2020 [cited by examiner]
US 20230401339A1 · Hayaki · 2023 [cited by examiner]
JP 2008084275A · 2008 [cited by applicant]
WO 2011033773A1 · 2011 [cited by applicant]
WO 2018150619A1 · 2018 [cited by applicant]
Chaudhari et al., “Stream Cipher Hash based Execution Monitoring (SCHEM) Framework for Intrusion Detection on Embedded Processors”, 2012, IEEE, pp. 162-167. (Year: 2012). [cited by examiner]
Biondo et al., “Back To The Epilogue: Evading Control Flow Guard via Unaligned Targets”, 2018, Network and Distributed Systems Security, 15 pages. (Year: 2018). [cited by examiner]
International Search Report for PCT Application No. PCT/JP2020/040338, mailed on Jan. 19, 2021. [cited by applicant]
Toshiki Kobayashi, Takayuki Sasaki, Astha Jada, Daniele E. Asoni, Adrian Perrig, “SAFES; Sand-boxed Architecture for Frequent Environment Self-measurement”, Proceedings of the 3rd Workshop on System Software for Trusted… [cited by applicant]
Yuto Hayaki, Takayuki Sasaki, Seng Pel Liew, Koki Tomita, Norio Yamagaki, “Proposal of proof of trust by tampering detection system for IoT devices”, SCIS2020, 2020, pp. 1-6. [cited by applicant]
NEC Digital Platform Operations, “Lightweight program tampering detection development kit for detecting unlawful manipulation of IoT devices”, C&C User Forum & EXPO, Oct. 2019. [cited by applicant]