IP Library Granted Patent US 7,210,134
Granted Patent B1
US 7,210,134 · App. 10/237,515 · Granted Apr 24, 2007

Deterring reverse-engineering of software systems by randomizing the siting of stack-based data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,210,134
App. No.
10/237,515
Granted
Apr 24, 2007
Kind
B1
Abstract

A given software process is composed on one or more threads of execution. Each thread possesses its own stack, a region of memory set aside by the operating system for that thread to store data. Popular programming languages rely heavily on stack-based data (frequently referred to as “local” or “automatic” data). It is a characteristic of deterministic machines like computers that, given the same problem to process with the same data, the same results, both intermediate and final, will result. This even extends to the sequence the software running on the computer will take to process the problem or data. This in turn means that for each thread making up the program, the data layout in the thread's stack will be relatively consistent each time the program gets to a similar point in the processing of the problem and/or data. This represents a potential “point of repeatability” that a hacker can take advantage of. Embodiments of the current invention address this by introducing random amounts of “padding” into a thread's stack, such that all data objects that exist “below” that point in the stack are offset by the amount of this random padding. A thread could have several points in its stack where the padding is introduced, resulting in better (more difficult to hack) randomization.

Claims (15)

1. A method of managing memory for a thread of execution of a protected application in a computer system having at least one stack, the method comprising:

allocating a first amount of stack space for use by a first set of data adapted for use by the thread;

allocating a second amount of stack space, wherein the size of the second amount of stack space is randomly determined at runtime of the thread, wherein the second amount of stack space is not adapted for use by the thread, and wherein the allocation of the second amount of stack space occurs at runtime of the thread; and

allocating a third amount of stack space for use by a second set of data adapted for use by the thread, wherein the step of allocating the second amount of stack space occurs prior to one of the step of allocating the first amount of stack space and the step of allocating the third amount of stack space,

wherein the size of the second amount of stack space is randomly determined by using a recursive function that calls itself a random number of times.

2. The method of claim 1 wherein the recursive function introduces a frame each time that the recursive function calls itself thereby storing a plurality of frames in the stack, and wherein the plurality of frames is not adapted for use by the thread.

3. A computer system comprising:

a memory adapted to store a stack;

a processor coupled to the memory and adapted to execute a software routine of a protected application; and

programming logic adapted to be executed by the processor, said programming logic comprising:

means for allocating a first amount of stack space for use by a first set of data adapted for use by the software routine;

means for allocating a second amount of stack space, wherein the size of the second amount of stack space is randomly determined at runtime of the software routine, wherein the second amount of stack space is not adapted for use by the software routine, and wherein the allocation of the second amount of stack space occurs at runtime of the thread; and

means for allocating a third amount of stack space for use by a second set of data adapted for use by the software routine wherein the means for allocating the second amount of stack space allocates the second amount of stack space prior to a point in time when one of the first amount of stack space is allocated and the third amount of stack space is allocated,

wherein the size of the second amount of stack space is randomly determined by using a recursive function that calls itself a random number of times.

4. The system of claim 3 wherein the recursive function introduces a frame each time that the recursive function calls itself thereby storing a plurality of frames in the stack, and wherein the plurality of frames is not adapted for use by the software routine.

Assignments (14)
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053481/0790 →
RELEASE OF SECURITY INTEREST Recorded Jun 5, 2020
From: HPS INVESTMENT PARTNERS, LLC
To: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
Reel/Frame 053458/0749 →
SECURITY INTEREST Recorded Jun 1, 2020
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS INC.; VEVEO, INC.; INVENSAS CORPORATION; INVENSAS BONDING TECHNOLOGIES, INC.; TESSERA, INC.; TESSERA ADVANCED TECHNOLOGIES, INC.; DTS, INC.; PHORUS, INC.; IBIQUITY DIGITAL CORPORATION
To: BANK OF AMERICA, N.A.
Reel/Frame 053468/0001 →
PATENT SECURITY AGREEMENT Recorded Nov 25, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 051110/0006 →
RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 25, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: APTIV DIGITAL INC.; GEMSTAR DEVELOPMENT CORPORATION; INDEX SYSTEMS INC.; ROVI GUIDES, INC.; ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; SONIC SOLUTIONS LLC; STARSIGHT TELECAST, INC.; UNITED VIDEO PROPERTIES, INC.; VEVEO, INC.
Reel/Frame 051145/0090 →
SECURITY INTEREST Recorded Nov 22, 2019
From: ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; ROVI GUIDES, INC.; TIVO SOLUTIONS, INC.; VEVEO, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 051143/0468 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA PREVIOUSLY RECORDED AT REEL: 038388 FRAME: 0915. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 16, 2016
From: SONIC SOLUTIONS, LLC
To: ROVI TECHNOLOGIES CORPORATION
Reel/Frame 038711/0547 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2016
From: SONIC SOLUTIONS, INC.
To: ROVI TECHNOLOGIES CORPORATION
Reel/Frame 038388/0915 →
PATENT SECURITY AGREEMENT Recorded Jul 24, 2014
From: APTIV DIGITAL, INC.; GEMSTAR DEVELOPMENT CORPORATION; INDEX SYSTEMS INC.; ROVI GUIDES, INC.; ROVI SOLUTIONS CORPORATION; ROVI TECHNOLOGIES CORPORATION; SONIC SOLUTIONS LLC; STARSIGHT TELECAST, INC.; UNITED VIDEO PROPERTIES, INC.; VEVEO, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 033407/0035 →
PATENT RELEASE Recorded Jul 22, 2014
From: JPMORGAN CHASE BANK N.A., AS COLLATERAL AGENT
To: ALL MEDIA GUIDE, LLC; DIVX, LLC; SONIC SOLUTIONS LLC
Reel/Frame 033378/0685 →
RELEASE OF SECURITY INTEREST Recorded Jun 11, 2013
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ALL MEDIA GUDE, LLC; DIVX, LLC; SONIC SOLUTIONS LLC
Reel/Frame 030591/0534 →
MERGER Recorded Mar 12, 2012
From: SONIC SOLUTIONS
To: SONIC SOLUTIONS LLC
Reel/Frame 027848/0774 →
SECURITY AGREEMENT Recorded Mar 25, 2011
From: ALL MEDIA GUIDE, LLC; DIVX, LLC; SONIC SOLUTIONS LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 026026/0111 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2002
From: LANGER, RANDY
To: SONIC SOLUTIONS
Reel/Frame 013553/0196 →