US2007136816A1PendingUtilityA1

Method to protect software against unwanted use with a detection and coercion principle

Assignee: SAS VALIDYPriority: Aug 1, 2001Filed: Jan 17, 2007Published: Jun 14, 2007
Est. expiryAug 1, 2021(expired)· nominal 20-yr term from priority
G06F 21/123
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The invention concerns a process to protect a vulnerable software working on a data processing system against its unauthorized usage using a processing and memorizing unit. The process comprises defining: 1) at least one software execution characteristic, liable to be monitored at least in part in a processing and memorizing unit 2) at least one criterion to abide by for at least one software execution characteristic 3) detection means to implement in a processing and memorizing unit and enabling to detect that at least one software execution characteristic does not abide by at least one associated criterion 4) coercion means to implement in a processing and memorizing unit and enabling to inform the data processing system and/or modify the execution of a software when at least one criterion is not abided by.

Claims

exact text as granted — not AI-modified
1 . A process to protect, using at least one blank unit ( 60 ) including at least memorization means ( 15 ) and processing means ( 16 ), a vulnerable software ( 2   v ) against its unauthorized usage, said vulnerable software ( 2   v ) being produced from a source ( 2   vs ) and working on a data processing system ( 3 ), said protection process comprising: 
 during a protection phase (P): 
 defining: 
 at least one software execution characteristic, liable to be monitored at least in part in a unit ( 6 ),  
 at least one criterion to abide by for at least one software execution characteristic,  
 detection means ( 17 ) to implement in a unit ( 6 ) and enabling to detect that at least one software execution characteristic does not abide by at least one associated criterion,  
 and coercion means ( 18 ) to implement in a unit ( 6 ) and enabling to inform the data processing system ( 3 ) and/or modify the execution of a software when at least one criterion is not abided by,  
 
 constructing exploitation means enabling to transform the blank unit ( 60 ) into a unit ( 6 ) able to implement the detection means ( 17 ) and the coercion means ( 18 ), creating a protected software ( 2   p ): 
 by choosing at least one software execution characteristic to monitor, among the software execution characteristics liable to be monitored,  
 by choosing at least one criterion to abide by for at least one chosen software execution characteristic,  
 by choosing, at least one algorithmic processing which, during the execution of the vulnerable software ( 2   v ), uses at least one operand and enables to obtain at least one result, and for which at least one chosen software execution characteristic, is to be monitored,  
 by choosing at least one portion of the source of the vulnerable software ( 2   vs ) containing, at least one chosen algorithmic processing,  
 by producing the source of the protected software ( 2   ps ) from the source of the vulnerable software ( 2   vs ), by modifying at least one chosen portion of the source of the vulnerable software ( 2   vs ) to obtain at least one modified portion of the source of the protected software ( 2   ps ), this modification being such that:  
 during the execution of the protected software ( 2   p ) a first execution part ( 2   pes ) is executed in the data processing system ( 3 ) and a second execution part ( 2   peu ) is executed in a unit ( 6 ), obtained from the blank unit ( 60 ) after upload of information,  
 the second execution part ( 2   peu ) executes at least the functionality of at least one chosen algorithmic processing,  
 and during the execution of the protected software ( 2   p ), at least one chosen execution characteristic is monitored by means of the second execution part ( 2   peu ) and the fact that a criterion is not abided by leads to a modification of the execution of the protected software ( 2   p ),  
 
 and by producing: 
 a first object part ( 2   pos ) of the protected software ( 2   p ), from the source of the protected software ( 2   ps ), said first object part ( 2   pos ) being such that during the execution of the protected software ( 2   p ), appears a first execution part ( 2   pes ) which is executed in the data processing system ( 3 ) and whose at least a portion takes into account that at least one chosen software execution characteristic is monitored,  
 and a second object part ( 2   pou ) of the protected software ( 2   p ), containing the exploitation means implementing the detection means ( 17 ) and the coercion means ( 18 ), said second object part ( 2   pou ) being such that, after upload to the blank unit ( 60 ) and during the execution of the protected software ( 2   p ), appears the second execution part ( 2   peu ) by means of which at least one chosen software execution characteristic is monitored and by means of which the fact that a criterion is not abided by leads to a modification of the execution of the protected software ( 2   p ),  
 
 and uploading the second object part ( 2   pou ) to the blank unit ( 60 ), with the intention of obtaining the unit ( 6 ),  
   and during a usage phase (U) during which the protected software ( 2   p ) is executed: 
 in the presence of the unit ( 6 ): 
 and as long as all the criteria corresponding to all the monitored execution characteristics of all the modified portions of the protected software ( 2   p ) are abided by, enabling said portions of the protected software ( 2   p ) to work nominally and consequently enabling the protected software ( 2   p ) to work nominally,  
 and if at least one of the criteria corresponding to a monitored execution characteristic of a portion of the protected software ( 2   p ) is not abided by, informing the data processing system ( 3 ) of it and/or modifying the functioning of the portion of the protected software ( 2   p ), so that the functioning of the protected software ( 2   p ) is modified,  
 
   and in the absence of the unit ( 6 ), in spite of the request by a portion of the first execution part ( 2   pes ) to trigger the execution in the unit ( 6 ), of the functionality of a chosen algorithmic processing, in not being able to fulfill said request correctly, so that at least said portion is not executed correctly and that, consequently, the protected software ( 2   p ) is not completely functional,    wherein during the protection phase (P): 
 defining: 
 as software execution characteristic liable to be monitored, a profile of software usage,  
 and as criterion to abide by, at least one feature of software execution,  
 
 and modifying the protected software ( 2   p ): 
 by choosing as software execution characteristic to monitor at least one profile of software usage,  
 by choosing at least one feature of execution by which at least one chosen profile of usage must abide,  
 and by modifying at least one chosen portion of the source of the protected software ( 2   ps ), this modification being such that, during the execution of the protected software ( 2   p ), the second execution part ( 2   peu ) abides by all the chosen features of execution,  
 
   and during the usage phase (U) in the presence of the unit ( 6 ), and in the case where it is detected that at least one feature of execution is not abided by, informing the data processing system ( 3 ) of it and/or modifying the functioning of the portion of the protected software ( 2   p ), so that the functioning of the protected software ( 2   p ) is modified,    wherein during the protection phase (P): 
 defining: 
 an instructions set whose instructions are liable to be executed in the unit ( 6 ),  
 a set of instructions commands for said instructions set, said instructions commands being liable to be executed in the data processing system ( 3 ) and to trigger in the unit ( 6 ) the execution of the instructions,  
 as profile of usage, the chaining of the instructions,  
 as feature of execution, an expected chaining for the execution of the instructions,  
 as detection means ( 17 ), means enabling to detect that the chaining of the instructions does not correspond to the expected one,  
 and as coercion means ( 18 ), means enabling to inform the data processing system ( 3 ) and/or to modify the functioning of the portion of protected software ( 2   p ) when the chaining of the instructions does not correspond to the expected one,  
 
 constructing the exploitation means also enabling the unit ( 6 ) to execute the instructions of the instructions set, the execution of said instructions being triggered by the execution in the data processing system ( 3 ), of the instructions commands,  
 and modifying the protected software ( 2   p ): 
 by modifying at least one chosen portion of the source of the protected software ( 2   ps ), this modification being such that: 
 at least one chosen algorithmic processing is split so that during the execution of the protected software ( 2   p ), said algorithmic processing is executed by means of the second execution part ( 2   peu ), using instructions,  
 for at least one chosen algorithmic processing, instructions commands are integrated to the source of the protected software ( 2   ps ), so that during the execution of the protected software ( 2   p ), each instruction command is executed by the first execution part ( 2   pes ) and triggers in the unit ( 6 ), the execution by means of the second execution part ( 2   peu ), of an instruction,  
 a sequence of the instructions commands is chosen among the set of sequences allowing the execution of the protected software ( 2   p ),  
 and the chaining by which must abide at least some of the instructions during their execution in the unit ( 6 ) is specified,  
 
 
   and during the usage phase (U), in the presence of the unit ( 6 ), in the case where it is detected that the chaining of the instructions executed in the unit ( 6 ) does not correspond to the expected one, informing the data processing system ( 3 ) of it and/or modifying the functioning of the portion of the protected software ( 2   p ), so that the functioning of the protected software ( 2   p ) is modified,    wherein during the protection phase (P): 
 defining: 
 as instructions set, an instructions set whose at least some instructions work with registers and use at least one operand with the intention of returning a result,  
 for at least some of the instructions working with registers: 
 a part (PF) defining the functionality of the instruction,  
 and a part defining the expected chaining for the execution of the instructions and including bits fields corresponding to: 
 an identification field of the instruction (CII),  
 and for each operand of the instruction:  
  a flag field (CD k ),  
  and an expected identification field (CIP k ) of the operand,  
 
 
 
 for each register belonging to the exploitation means and used by the instructions set, a generated identification field (CIG v ) in which is automatically memorized the identification of the last instruction which has returned its result in said register,  
 as detection means ( 17 ), means enabling, during the execution of an instruction, for each operand, when the flag field (CD k ) imposes it, to check the equality of the generated identification field (CIG v ) corresponding to the register used by said operand, and the expected identification field (CIP k ) of the origin of said operand,  
 and as coercion means ( 18 ), means enabling to modify the result of the instructions, if at least one of the checked equalities is false, and  
   wherein for each said operand, said flag field (CD k ) abd saud expected identification field (CIP k ) are merged into a tag field and at least one value of each said tag field is used to indicate that equality with said generated identification field (CIG v ) shall not be checked.    
   
   
       2 . A method to protect software comprising: 
 storing a first portion of the software on a first unit, wherein the first unit comprises a memory and a processor;    storing a second portion of the software on a second unit, wherein the second unit comprises a secure processor and a secure memory, wherein the second portion of the software is secret, and wherein the first and second portions of the software form a single executable program; and 
 executing the program,  
 wherein operations performed during the execution comprise: 
 the first portion provides input to the second portion,  
 the second portion provides a result to the first portion  
 
 wherein the second unit comprises a detection module that detects a software execution characteristic of said operations performed during the execution that does not abide to an associated criterion, and  
 wherein, when the detection module detects the none abiding software execution characteristic, a coercion module of the second unit informs the first unit of the none abiding software execution characteristic and modifies the executed program.  
   
   
   
       3 . The method according to  claim 2 , wherein the modification of the executed program comprises stopping the execution of the program.  
   
   
       4 . The method according to  claim 2 , wherein the second unit is a chip medium configured to attach and detach to the first unit.  
   
   
       5 . The method according to  claim 2 , wherein the processor of the second unit is a coprocessor of the processor of the first unit.  
   
   
       6 . The method according to  claim 2 , wherein the second unit is a token.  
   
   
       7 . The method according to  claim 2 , wherein, when the detection module of the second unit detects that the result obtained by the second portion does not abide to the associated criterion, the coercion module of the second unit modifies the executed program to stop the execution of the program.  
   
   
       8 . A method to protect a vulnerable software working on a data processing system against its unauthorized usage using a unit comprising a processor and a memory and is configured to attach and detach to the processing system, the method comprising: 
 defining a software execution characteristic liable to be monitored at least in part in the unit;    defining a criterion to abide by for said software execution characteristic;    detecting, in the unit, that the defined software execution characteristic does not abide by the defined associated criterion; and    informing the data processing system by the unit when the defined associated criterion is not abided.    
   
   
       9 . The method according to  claim 8 , further comprising modifying the execution of a software when the defined associated criterion is not abided by.

Join the waitlist — get patent alerts

Track US2007136816A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.