IP Library › Granted Patent US 12,572,630
Granted Patent B2
US 12,572,630 · App. 17/812,816 · Granted Mar 10, 2026

User-trusted executable execution environment

Inventors: Benjamin Santaus (Somerville, MA); Seth Jacob Rothschild (Littleton, MA)
Assignee: Dell Products L.P.
G06F21/12G06F21/44G06F21/53H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,572,630
App. No.
17/812,816
Granted
Mar 10, 2026
Kind
B2
Abstract

A user-trusted executable execution environment is disclosed. Using a trusted application, an executable that is generally untrusted by a computing environment, can be verified and executed. A signed executable is signed by a sending trust engine and transmitted to a receiving trust engine. The receiving trust engine can verify the executable when a public key of a sending user decrypts the signed executable and when a hash generated by the receiving trust engine matches a hash of the executable included in the signed executable. The verification is finalized when the receiving user knows the sending user and confirms that the sending user sent the signed executable by using the sending user's public key to decrypt the signed executable.

Claims (30)

1 . A method comprising:

generating a hash of an executable at a sending trust engine associated with a sending user, wherein the sending trust engine is a trusted application associated with a certificate issued a certificate authority;

signing the hash and the executable with a private key of the sending user to generate a signed executable;

sending the signed executable to a receiving trust engine associated with a receiving user, wherein the receiving trust engine is a trusted application associated with a certificate issued by a certificate authority;

verifying the signed executable using the public key of the sending user stored in the receiving trust engine, wherein the public key of the sending user is manually registered in the receiving trust engine by the receiving user;

generating a second hash of the executable included in the signed executable and comparing the second hash to the hash included in the signed executable;

verifying the executable when the second hash matches the hash included in the signed executable;

when the executable is initially untrusted, executing the executable in a sandbox environment to determine whether execution of the executable is trustworthy, and signing the executable with the private key of the sending user only upon determining that execution of the executable in the sandbox environment is trustworthy; and

executing the executable at a receiving client.

2 . The method of claim 1 , further comprising generating a key pair by the sending trust engine, wherein the key pair includes the private key and the public key.

3 . The method of claim 2 , further comprising distributing the public key to the receiving client for the receiving user.

4 . The method of claim 1 , further comprising compiling source code to generate the executable.

5 . The method of claim 1 , wherein the executable comprises an application, a script, a binary, or machine-readable code.

6 . The method of claim 1 , wherein the sending trust engine and the receiving trust engine are instances of a trusted application associated with a certificate issued by a certificate authority.

7 . The method of claim 6 , wherein the executable is verified without including a certificate in the signed executable.

8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

generating a hash of an executable at a sending trust engine associated with a sending user, wherein the sending trust engine is a trusted application associated with a certificate issued by a certificate authority;

signing the hash and the executable with a private key of the sending user to generate a signed executable;

sending the signed executable to a receiving trust engine associated with a receiving user, wherein the receiving trust engine is a trusted application associated with a certificate issued by a certificate authority;

decrypting the signed executable using the public key of the sending user stored in the receiving trust engine, wherein the public key of the sending user is manually registered in the receiving trust engine by the receiving user;

generating a second hash of the executable included in the signed executable and comparing the second hash to the hash included in the signed executable;

verifying the executable when the second hash matches the hash included in the signed executable;

when the executable is initially untrusted, executing the executable in a sandbox environment to determine whether execution of the executable is trustworthy, and signing the executable with the private key of the sending user only upon determining that execution of the executable in the sandbox environment is trustworthy; and

executing the executable at a receiving client.

9 . The non-transitory storage medium of claim 8 , further comprising generating a key pair by the sending trust engine, wherein the key pair includes the private key and the public key.

10 . The non-transitory storage medium of claim 9 , further comprising distributing the public key to the receiving client for the receiving user.

11 . The non-transitory storage medium of claim 8 , further comprising compiling source code to generate the executable.

12 . The non-transitory storage medium of claim 8 , wherein the executable comprises an application, a script, a binary, or machine-readable code.

13 . The non-transitory storage medium of claim 8 , wherein the sending trust engine and the receiving trust engine are instances of a trusted application associated with a certificate issued by a certificate authority.

14 . The non-transitory storage medium of claim 13 , wherein the executable is verified without including a certificate in the signed executable.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE LAST NAME OF THE FIRST CONVEYING PARTY PREVIOUSLY RECORDED ON REEL 60521 FRAME 226. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Feb 11, 2026
From: SANTAUS, BENJAMIN; ROTHSCHILD, SETH JACOB
To: DELL PRODUCTS L.P.
Reel/Frame 075145/0639 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 15, 2022
From: BENJAMIN, BENJAMIN; ROTHSCHILD, SETH JACOB
To: DELL PRODUCTS L.P.
Reel/Frame 060521/0226 →
Continuity (1)
Related Publication 20240020359A1 · Jan 18, 2024
References Cited (19)
US 9641340B2 · Wang · 2017 [cited by examiner]
US 9774610B2 · Zheng · 2017 [cited by examiner]
US 10656936B2 · Robison · 2020 [cited by examiner]
US 11983409B1 · Aiouaz · 2024 [cited by examiner]
US 12267437B2 · Kampanakis · 2025 [cited by examiner]
US 20090031141A1 · Pearson · 2009 [cited by examiner]
US 20130210519A1 · Gatto · 2013 [cited by examiner]
US 20170034186A1 · Zheng · 2017 [cited by examiner]
US 20190392115A1 · Yach · 2019 [cited by examiner]
US 20200073657A1 · Robison · 2020 [cited by examiner]
US 20210334358A1 · Medvinsky · 2021 [cited by examiner]
US 20230246845A1 · Peddada · 2023 [cited by examiner]
US 20230254154A1 · Kampanakis · 2023 [cited by examiner]
US 20230308289A1 · Yavuz · 2023 [cited by examiner]
US 20240020359A1 · Santaus · 2024 [cited by examiner]
AU 2018217323B2 · 2020 [cited by examiner]
Benton, Matthew. (2017). Epistemology Personalized. The Philosophical Quarterly. 67. 813-834. 10.1093/pq/pqx020. (Year: 2017). [cited by examiner]
Benton, Matthew. (2017). Epistemology Personalized—Abstract. The Philosophical Quarterly. 67. 813-834. 10.1093/pq/pqx020. (Year: 2017). [cited by examiner]
Hasan, Ali & Fumerton, Richard (2019). Knowledge by Acquaintance vs. Description. Stanford Encyclopedia of Philosophy. (Year: 2019). [cited by examiner]