IP Library › Granted Patent US 12,346,430
Granted Patent B1
US 12,346,430 · App. 17/688,878 · Granted Jul 1, 2025

Systems and methods for implementing cybersecurity using trust binaries

Inventors: Henry Tumblin (Castine, ME); Gary Southwell (Leander, TX)
Assignee: CSP Inc.
G06F21/51G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,430
App. No.
17/688,878
Granted
Jul 1, 2025
Kind
B1
Abstract

The various implementations described herein include methods and devices for creating and using trust binaries. In one aspect, a method includes executing a trust agent and detecting, via the trust agent, upcoming execution of a program. In response to the detection, a trust binary for the program is obtained from a trust store and authenticity of the program is confirmed by comparing executable code of the program with the obtained trust binary. Execution of the program is allowed in accordance with the confirmed authenticity. The method also includes identifying upcoming execution of a function in the program by monitoring execution of the program and obtaining, from the trust binary, a function digest corresponding to the function. Authenticity of the function is confirmed by comparing executable code of the function with the obtained function digest. Execution of the function is allowed in accordance with the confirmed authenticity.

Claims (82)

1. A method performed at a computing device having memory and one or more processors, the method comprising:

executing a trust agent;

detecting, via the trust agent, upcoming execution of a program on the computing device;

in response to the detection, obtaining a trust binary for the program from a trust store in the memory;

confirming authenticity of the program by comparing executable code of the program with the obtained trust binary for the program;

allowing execution of the program in accordance with the confirmed authenticity of the program;

identifying upcoming execution of an executable function in the program by monitoring execution of the program;

in response to identifying the upcoming execution of the executable function, obtaining, from the trust binary, a function digest corresponding to the executable function, wherein the function digest comprises a hash of static portions of the executable function, omitting portions of the executable function that require dynamic linking when loaded into memory;

confirming authenticity of the executable function by comparing executable code of the executable function with the obtained function digest; and

allowing execution of the executable function in accordance with the confirmed authenticity of the executable function.

2. The method of claim 1 , wherein detecting upcoming execution of the program comprises identifying a memory request corresponding to the program.

3. The method of claim 1 , wherein identifying upcoming execution of the executable function of the program comprises intercepting a library function call made by the program.

4. The method of claim 1 , wherein the trust agent comprises a kernel-level driver.

5. The method of claim 1 , wherein the trust agent comprises a communications service, a file monitor, an installer, and a dashboard manager.

6. The method of claim 1 , further comprising:

detecting, via the trust agent, upcoming execution of a second program; determining that the trust store does not contain a trust binary corresponding to the second program; and

initiating a remedial action in accordance with the determination.

7. The method of claim 6 , wherein the remedial action comprises one or more of:

preventing the second program from executing on the computing device;

storing information about the second program in a forensic log; and

generating a provisional trust binary for the second program.

8. The method of claim 6 , wherein the remedial action comprises generating a provisional trust binary, and the method further comprises sending executable code for the second program to a trust center for validation.

9. The method of claim 6 , wherein the remedial action comprises applying one or more countermeasures.

10. The method of claim 6 , wherein the remedial action comprises sending a query to a trust center for a trust binary for the second program.

11. The method of claim 6 , further comprising obtaining a trust policy for the computing device, wherein the initiated remedial action is selected according to the trust policy.

12. The method of claim 1 , further comprising:

detecting, via the trust agent, upcoming execution of a second program;

in response to the detection, obtaining a second trust binary for the second program from the trust store;

identifying one or more changes in executable code of the second program based on a comparison with the second trust binary; and

initiating a remedial action in accordance with the identification of the one or more changes.

13. The method of claim 1 , further comprising:

while monitoring execution of the program, identifying upcoming execution of a second executable function of the program;

in response to identifying the upcoming execution of the second executable function, determining that the trust binary does not contain a function digest for the second executable function; and

initiating a remedial action in accordance with the determination.

14. The method of claim 13 , wherein the remedial action comprises one or more of:

preventing execution of the second executable function;

stopping execution of the program;

storing information about the second executable function in a forensic log; and

generating a provisional function digest for the second executable function.

15. The method of claim 1 , further comprising:

identifying upcoming execution of a second executable function of the program;

in response to identifying the upcoming execution of the second executable function, obtaining, from the trust binary, a second function digest corresponding to the second executable function;

identifying one or more changes in the second executable function based on a comparison with the second function digest; and

initiating a remedial action in accordance with the identification of the one or more changes in the second executable function.

16. The method of claim 1 , wherein comparing executable code of the executable function with the obtained function digest comprises comparing (1) a hash of static portions of the executable function with (2) the obtained function digest.

17. A computing device, comprising:

one or more processors;

memory;

a display; and

one or more programs stored in the memory and configured for execution by the one or more processors, the one or more programs comprising instructions for:

executing a trust agent;

detecting, via the trust agent, upcoming execution of a program on the computing device;

in response to the detection, obtaining a trust binary for the program from a trust store in the memory;

confirming authenticity of the program by comparing executable code of the program with the obtained trust binary for the program;

allowing execution of the program in accordance with the confirmed authenticity of the program;

identifying upcoming execution of an executable function in the program by monitoring execution of the program;

in response to identifying the upcoming execution of the executable function, obtaining, from the trust binary, a function digest corresponding to the executable function, wherein the function digest comprises a hash of static portions of the executable function, omitting portions of the executable function that require dynamic linking when loaded into memory;

confirming authenticity of the executable function by comparing executable code of the executable function with the obtained function digest; and

allowing execution of the executable function in accordance with the confirmed authenticity of the executable function.

18. The computing device of claim 17 , wherein the one or more programs further comprise instructions for:

detecting, via the trust agent, upcoming execution of a second program;

determining that the trust store does not contain a trust binary corresponding to the second program; and

initiating a remedial action in accordance with the determination.

19. The computing device of claim 17 , wherein the one or more programs further comprise instructions for:

detecting, via the trust agent, upcoming execution of a second program;

in response to the detection, obtaining a second trust binary for the second program from the trust store;

identifying one or more changes in executable code of the second program based on a comparison with the second trust binary; and

initiating a remedial action in accordance with the identification of the one or more changes.

20. A non-transitory computer-readable storage medium storing one or more programs configured for execution by a computing device having one or more processors, memory, and a display, the one or more programs comprising instructions for:

executing a trust agent;

detecting, via the trust agent, upcoming execution of a program on the computing device;

in response to the detection, obtaining a trust binary for the program from a trust store in the memory;

confirming authenticity of the program by comparing executable code of the program with the obtained trust binary for the program;

allowing execution of the program in accordance with the confirmed authenticity of the program;

identifying upcoming execution of an executable function in the program by monitoring execution of the program;

in response to identifying the upcoming execution of the executable function, obtaining, from the trust binary, a function digest corresponding to the executable function, wherein the function digest comprises a hash of static portions of the executable function, omitting portions of the executable function that require dynamic linking when loaded into memory;

confirming authenticity of the executable function by comparing executable code of the executable function with the obtained function digest; and

allowing execution of the executable function in accordance with the confirmed authenticity of the executable function.

21. The non-transitory computer-readable storage medium of claim 20 , wherein the one or more programs further comprise instructions for:

while monitoring execution of the program, identifying upcoming execution of a second executable function of the program;

in response to identifying the upcoming execution of the second executable function, determining that the trust binary does not contain a function digest for the second executable function; and

initiating a remedial action in accordance with the determination.

Continuity (1)
Continuation 17684363 · Mar 1, 2022
References Cited (68)
US 5757914A · McManis · 1998 [cited by applicant]
US 5835594A · Albrecht · 1998 [cited by examiner]
US 10977158B1 · Chen et al. · 2021 [cited by applicant]
US 10979440B1 · Kalika · 2021 [cited by applicant]
US 10983958B1 · Miller et al. · 2021 [cited by applicant]
US 10990678B2 · Tas et al. · 2021 [cited by applicant]
US 11449602B1 · Tumblin · 2022 [cited by examiner]
US 11605076B2 · Dunjic et al. · 2023 [cited by applicant]
US 11734681B2 · Gonzales, Jr. · 2023 [cited by applicant]
US 20020188849A1 · Kwan · 2002 [cited by examiner]
US 20090254756A1 · Kawakita · 2009 [cited by examiner]
US 20100031308A1 · Khalid · 2010 [cited by applicant]
US 20100274755A1 · Stewart · 2010 [cited by applicant]
US 20100281260A1 · Farrugia · 2010 [cited by examiner]
US 20140195575A1 · Haustein et al. · 2014 [cited by applicant]
US 20150019856A1 · Kim · 2015 [cited by examiner]
US 20170046806A1 · Haldenby et al. · 2017 [cited by applicant]
US 20180039667A1 · Pierce et al. · 2018 [cited by applicant]
US 20180063159A1 · Naughton-Green et al. · 2018 [cited by applicant]
US 20180173871A1 · Toth · 2018 [cited by examiner]
US 20180227119A1 · Bibera · 2018 [cited by applicant]
US 20180246717A1 · Martin · 2018 [cited by applicant]
US 20180260564A1 · Porteboeuf · 2018 [cited by applicant]
US 20180356236A1 · Lawrenson et al. · 2018 [cited by applicant]
US 20180365415A1 · Monastyrsky et al. · 2018 [cited by applicant]
US 20190005242A1 · Agarwal · 2019 [cited by examiner]
US 20190013948A1 · Mercuri et al. · 2019 [cited by applicant]
US 20190074968A1 · Liu et al. · 2019 [cited by applicant]
US 20190121984A1 · Rhee et al. · 2019 [cited by applicant]
US 20200045075A1 · Kliger et al. · 2020 [cited by applicant]
US 20200210413A1 · Quick et al. · 2020 [cited by applicant]
US 20200243205A1 · Sharma · 2020 [cited by examiner]
US 20200252410A1 · Casey et al. · 2020 [cited by applicant]
US 20200301892A1 · Florin et al. · 2020 [cited by applicant]
US 20200302065A1 · Lawson et al. · 2020 [cited by applicant]
US 20200320039A1 · Manningham et al. · 2020 [cited by applicant]
US 20200342129A1 · Chalken et al. · 2020 [cited by applicant]
US 20210012326A1 · Maxwell Zelocchi · 2021 [cited by applicant]
US 20210073209A1 · Loaiza et al. · 2021 [cited by applicant]
US 20210078512A1 · Ghannam et al. · 2021 [cited by applicant]
US 20210157915A1 · Pizano · 2021 [cited by examiner]
US 20210174432A1 · Gonnaud · 2021 [cited by examiner]
US 20210182423A1 · Padmanabhan · 2021 [cited by applicant]
US 20210209483A1 · Bose et al. · 2021 [cited by applicant]
US 20210248598A1 · Jain et al. · 2021 [cited by applicant]
US 20210263927A1 · Tang et al. · 2021 [cited by applicant]
US 20210264539A1 · Leise et al. · 2021 [cited by applicant]
US 20210334375A1 · Hu et al. · 2021 [cited by applicant]
US 20210397710A1 · Cohen et al. · 2021 [cited by applicant]
US 20220012341A1 · Sarkar · 2022 [cited by examiner]
US 20220058289A1 · Beardsworth et al. · 2022 [cited by applicant]
US 20220121429A1 · Haile et al. · 2022 [cited by applicant]
US 20220121757A1 · Winarski · 2022 [cited by applicant]
US 20220138315A1 · Meurant · 2022 [cited by examiner]
US 20220174540A1 · Paczkowski · 2022 [cited by examiner]
US 20220237290A1 · Villegas · 2022 [cited by examiner]
US 20230088104A1 · Grant · 2023 [cited by applicant]
US 20230129227A1 · Karlapalem et al. · 2023 [cited by applicant]
KR 102250779B1 · 2021 [cited by applicant]
Tumblin, Office Action, U.S. Appl. No. 17/684,363, May 24, 2022, 9 pgs. [cited by applicant]
Tumblin, Notice of Allowance, U.S. Appl. No. 17/684,363, Aug. 11, 2022, 7 pgs. [cited by applicant]
Tumblin, Office Action, U.S. Appl. No. 17/735,087, May 23, 2023, 9 pgs. [cited by applicant]
Tumblin, Notice of Allowance, U.S. Appl. No. 17/735,087, Jul. 13, 2023, 7 pgs. [cited by applicant]
Tumblin, Office Action, U.S. Appl. No. 17/735,101, Sep. 1, 2023, 12 pgs. [cited by applicant]
Tumblin, Notice of Allowance, U.S. Appl. No. 17/735,101, Nov. 22, 2023, 7 pgs. [cited by applicant]
CSP Inc., International Search Report and Written Opinion, PCT/US2024/037953, Sep. 10, 2024, 12 pgs. [cited by applicant]
CSP Inc., International Preliminary Report on Patentability, PCT/US2023/014301, Aug. 30, 2024, 7 pgs. [cited by applicant]
CSP Inc., International Search Report and Written Opinion, PCT/US2023/014301, Jun. 2, 2023, 9 pgs. [cited by applicant]