IP Library › Granted Patent US 12,368,603
Granted Patent B1
US 12,368,603 · App. 18/094,329 · Granted Jul 22, 2025

Code-sign white listing (CSWL)

Inventor: Jeff J. Stapleton (Arlington, TX)
Assignee: Wells Fargo Bank, N.A.
H04L9/3265H04L9/3242H04L9/3247H04L9/3268H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,603
App. No.
18/094,329
Granted
Jul 22, 2025
Kind
B1
Abstract

A system and method for verifying code bundles. One method includes receiving, from a client device, a request for information to verify an authorization of a code bundle, the code bundle associated with a first signed code segment and a second signed code segment. The method further includes generating a list of certificates associated with the code bundle and including a first certificate associated with the first signed code segment and a second certificate associated with the second signed code segment. The method further includes transmitting, to the client device, a message comprising the list of certificates, the list of certificates generated by a code sign management system (CSMS) and associated with the code bundle. The method further includes verifying, from the message causing the client device to verify the code bundle and based on the list of certificates, the code bundle.

Claims (45)

1. A method for verifying code bundles, comprising:

receiving, by one or more processors from a client device, a request for information to verify an authorization of a code bundle, the code bundle associated with a first signed code segment from a first developer and signed by the first developer, and a second signed code segment from a second developer and signed by the second developer, the first signed code segment different from the second signed code segment;

generating, by the one or more processors, a list of certificates associated with the code bundle and including a first certificate associated with the first signed code segment and a second certificate associated with the second signed code segment;

transmitting, by the one or more processors and to the client device, a message comprising the list of certificates, the list of certificates generated by a code sign management system (CSMS) and associated with the code bundle, including the first certificate associated with the first signed code segment, and including the second certificate associated with the second signed code segment; and

verifying, by the one or more processors from the message causing the client device to verify the code bundle and based on the list of certificates, the code bundle by verifying the first signed code segment with the first certificate and the second signed code segment with the second certificate.

2. The method of claim 1 , wherein the message further causes the client device to extract a public key associated with the one or more processors from the list of certificates and verify an authentication of the list of certificates.

3. The method of claim 1 , wherein the message causes the client device to verify a digital signature on the code bundle, and wherein the digital signature is separate from the list of certificates.

4. The method of claim 1 , further comprises:

hashing, by the one or more processors, the code bundle using a hash function to generate a hash value of the code bundle.

5. The method of claim 4 , wherein verifying the code bundle based on the list of certificates comprises generating a second hash value based on the list of certificates and comparing the hash value and the second hash value.

6. The method of claim 1 , wherein a digital signature on the code bundle is generated based on a message authentication code (MAC) or a hash-based message authentication code (HMAC), and wherein the digital signature is associated with a time-stamp token (TST).

7. The method of claim 1 , further comprising:

receiving, by the one or more processors and from the first developer, a first identifier to the first certificate associated with the first signed code segment;

receiving, by the one or more processors and from the second developer, a second identifier to the second certificate associated with the second signed code segment; and

updating, by the one or more processors, a database based on the first identifier and the second identifier.

8. A system for verifying code bundles comprising:

a processing circuit comprising memory and one or more processors to:

receive, from a client device, a request for information to verify an authorization of a code bundle, the code bundle associated with a first signed code segment from a first developer and signed by the first developer, and a second signed code segment from a second developer and signed by the second developer, the first signed code segment different from the second signed code segment;

generate a list of certificates associated with the code bundle and including a first certificate associated with the first signed code segment and a second certificate associated with the second signed code segment;

transmit, to the client device, a message comprising the list of certificates, the list of certificates generated by a code sign management system (CSMS) and associated with the code bundle, including the first certificate associated with the first signed code segment, and including the second certificate associated with the second signed code segment; and

verify, from the message causing the client device to verify the code bundle and based on the list of certificates, the code bundle by verifying the first signed code segment with the first certificate and the second signed code segment with the second certificate.

9. The system of claim 8 , wherein the message further causes the client device to extract a public key associated with the one or more processors from the list of certificates and verify an authentication of the list of certificates.

10. The system of claim 8 , wherein the message causes the client device to verify a digital signature on the code bundle, and wherein the digital signature is separate from the list of certificates.

11. The system of claim 8 , the one or more processors further to:

hash the code bundle using a hash function to generate a hash value of the code bundle.

12. The system of claim 11 , wherein verifying the code bundle based on the list of certificates comprises generating a second hash value based on the list of certificates and comparing the hash value and the second hash value.

13. The system of claim 8 , wherein a digital signature on the code bundle is generated based on a message authentication code (MAC) or a hash-based message authentication code (HMAC), and wherein the digital signature is associated with a time-stamp token (TST).

14. The system of claim 8 , the one or more processors further to:

receive, from the first developer, a first identifier to the first certificate associated with the first signed code segment;

receive, from the second developer, a second identifier to the second certificate associated with the second signed code segment; and

update a database based on the first identifier and the second identifier.

15. One or more non-transitory computer-readable storage media having instructions stored thereon that, when executed by at least one processing circuit, cause the at least one processing circuit to:

receive, from a client device, a request for information to verify an authorization of a code bundle, the code bundle associated with a first signed code segment from a first developer and signed by the first developer, and a second signed code segment from a second developer and signed by the second developer, the first signed code segment different from the second signed code segment;

generate a list of certificates associated with the code bundle and including a first certificate associated with the first signed code segment and a second certificate associated with the second signed code segment;

transmit, to the client device, a message comprising the list of certificates, the list of certificates generated by a code sign management system (CSMS) and associated with the code bundle, including the first certificate associated with the first signed code segment, and including the second certificate associated with the second signed code segment; and

verify, from the message causing the client device to verify the code bundle and based on the list of certificates, the code bundle by verifying the first signed code segment with the first certificate and the second signed code segment with the second certificate.

16. The one or more non-transitory computer-readable storage media of claim 15 , wherein the message further causes the client device to extract a public key associated with the one or more processors from the list of certificates and verify an authentication of the list of certificates.

17. The one or more non-transitory computer-readable storage media of claim 15 , wherein the message causes the client device to verify a digital signature on the code bundle, and wherein the digital signature is separate from the list of certificates.

18. The one or more non-transitory computer-readable storage media of claim 15 , having additional instructions stored thereon that, when executed by the at least one processing circuit, cause the at least one processing circuit to:

hash the code bundle using a hash function to generate a hash value of the code bundle, wherein verifying the code bundle based on the list of certificates comprises generating a second hash value based on the list of certificates and comparing the hash value and the second hash value.

19. The one or more non-transitory computer-readable storage media of claim 15 , wherein a digital signature on the code bundle is generated based on a message authentication code (MAC) or a hash-based message authentication code (HMAC), and wherein the digital signature is associated with a time-stamp token (TST).

20. The one or more non-transitory computer-readable storage media of claim 15 , having additional instructions stored thereon that, when executed by the at least one processing circuit, cause the at least one processing circuit to:

receive, from the first developer, a first identifier to the first certificate associated with the first signed code segment;

receive, from the second developer, a second identifier to the second certificate associated with the second signed code segment; and

update a database based on the first identifier and the second identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2025
From: STAPLETON, JEFF J.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071538/0190 →
Continuity (2)
Continuation 16932428 · Jul 17, 2020
Continuation 16863600 · Apr 30, 2020
References Cited (37)
US 7103779B2 · Kiehtreiber · 2006 [cited by examiner]
US 8572368B1 · Deacon · 2013 [cited by applicant]
US 8589691B1 · Hackborn et al. · 2013 [cited by applicant]
US 8688997B2 · Das · 2014 [cited by examiner]
US 9338012B1 · Naik et al. · 2016 [cited by applicant]
US 9575768B1 · Kim · 2017 [cited by applicant]
US 9843451B2 · Pinder · 2017 [cited by examiner]
US 10135808B1 · Wasiq et al. · 2018 [cited by applicant]
US 10805087B1 · Allen · 2020 [cited by examiner]
US 20030078880A1 · Alley et al. · 2003 [cited by applicant]
US 20040162989A1 · Kirovski · 2004 [cited by applicant]
US 20040193872A1 · Saarepera et al. · 2004 [cited by applicant]
US 20050223363A1 · Black-Ziegelbein · 2005 [cited by examiner]
US 20100058317A1 · Braams · 2010 [cited by applicant]
US 20100185845A1 · Takayama et al. · 2010 [cited by applicant]
US 20100223469A1 · Hussain et al. · 2010 [cited by applicant]
US 20110258426A1 · Mujtaba et al. · 2011 [cited by applicant]
US 20160292066A1 · Stevens · 2016 [cited by examiner]
US 20160352521A1 · Choi et al. · 2016 [cited by applicant]
US 20160365981A1 · Medvinsky et al. · 2016 [cited by applicant]
US 20160365983A1 · Shahabuddin et al. · 2016 [cited by applicant]
US 20180131521A1 · Yang et al. · 2018 [cited by applicant]
US 20190156029A1 · Ashey et al. · 2019 [cited by applicant]
US 20190372786A1 · Ra et al. · 2019 [cited by applicant]
US 20190384586A1 · Jiang · 2019 [cited by applicant]
US 20200177397A1 · Harrington · 2020 [cited by applicant]
US 20200364344A1 · Liu · 2020 [cited by examiner]
US 20210014068A1 · Sandler et al. · 2021 [cited by applicant]
US 20210064723A1 · Drake · 2021 [cited by examiner]
US 20210334380A1 · Saluja · 2021 [cited by examiner]
CN 1541350A · 2004 [cited by examiner]
CN 104113416A · 2014 [cited by examiner]
CN 113168482A · 2021 [cited by examiner]
EP 1320795B · 2003 [cited by applicant]
EP 2116953A1 · 2009 [cited by examiner]
EP 3026559A1 · 2016 [cited by examiner]
FR 3023115A1 · 2016 [cited by examiner]