Safe command execution and error recovery for storage devices
Abstract
Techniques for execution of commands securely within a storage device are disclosed. Integrity of a command interpreter is verified before allowing it to execute commands within the storage device. The integrity of the commands can also be checked to safeguard against various threats including, for example, malicious attacks, unintentional errors and defects that can adversely affect stored content and execution. Error recovery techniques can be used to reconstruct the command interpreter and/or commands that are found to be defective. In addition, secure techniques can be used to obtain trusted versions of the command interpreter and/or commands from an authenticated external source.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for providing trusted executable content, comprising:
receiving executable content; generating error-recoverable executable code by integrating error recovery code into said executable content; generating a digitally signed message digest for said error-recoverable executable code, wherein said digitally signed message digest comprises said error-recoverable executable code; and securely maintaining said digitally signed message digest in a storage device configured for executing said executable content; wherein said digitally signed message digest facilitates error recovery of said executable content.
2 . The method of claim 1 , wherein generating a digitally signed message digest for said error-recoverable executable code comprises:
computing a message digest for said error-recoverable executable code; and encrypting said message digest by digitally signing said message digest with an encryption key.
3 . The method of claim 1 , wherein said executable content is received from a trusted entity.
4 . The method of claim 1 , further comprising:
computing a first message digest for a current version of said executable content maintained in said storage device; and verifying an integrity of said current version by comparing said first message digest to said digitally signed message digest.
5 . The method of claim 4 , wherein:
said integrity of said current version is verified when said first message digest is equal to said digitally signed message digest.
6 . The method of claim 4 , further comprising:
executing said executable content only when said integrity of said current version is verified.
7 . The method of claim 4 , further comprising:
reconstructing said executable content when said integrity of said current version is not verified, wherein reconstructing said executable content comprises:
reconstructing said executable content using said error recovery code;
adding said error recovery code to said reconstructed executable content;
computing a second message digest for said reconstructed executable content; and
verifying an integrity of said reconstructed executable content by comparing said second message digest to said digitally signed message digest.
8 . The method of claim 7 , wherein:
said integrity of said reconstructed executable content is verified when said second message digest is equal to said digitally signed message digest.
9 . The method of claim 7 , wherein reconstructing said executable content further comprises:
replacing said current version with said reconstructed executable content when said integrity of said reconstructed executable content is verified.
10 . A system, comprising:
a storage medium for maintaining executable content; and a controller for securely maintaining a digitally signed message digest for said executable content; wherein said digitally signed message digest comprises error-recoverable executable code including error recovery code for said executable content; and wherein said digitally signed message digest facilitates error recovery of said executable content.
11 . The system of claim 10 , wherein said controller is further configured for:
computing a first message digest for a current version of said executable content maintained in said storage medium; and verifying an integrity of said current version by comparing said first message digest to said digitally signed message digest.
12 . The system of claim 11 , wherein:
said integrity of said current version is verified when said first message digest is equal to said digitally signed message digest.
13 . The system of claim 11 , wherein the system executes said executable content when said integrity of said current version is verified.
14 . The system of claim 11 , wherein said controller is further configured for:
reconstructing said executable content when said integrity of said current version is not verified, wherein reconstructing said executable content comprises:
reconstructing said executable content using said error recovery code;
adding said error recovery code to said reconstructed executable content;
computing a second message digest for said reconstructed executable content; and
verifying an integrity of said reconstructed executable content by comparing said second message digest to said digitally signed message digest.
15 . The system of claim 14 , wherein:
said integrity of said reconstructed executable content is verified when said second message digest is equal to said digitally signed message digest.
16 . The system of claim 14 , wherein reconstructing said executable content further comprises:
replacing said current version with said reconstructed executable content when said integrity of said reconstructed executable content is verified.
17 . A non-transitory computer-readable medium having instructions which when executed on a computer perform a method for providing trusted executable content, the method comprising:
receiving executable content; generating error-recoverable executable code by integrating error recovery code into said executable content; generating a digitally signed message digest for said error-recoverable executable code, wherein said digitally signed message digest comprises said error-recoverable executable code; and securely maintaining said digitally signed message digest in a storage device configured for executing said executable content; wherein said digitally signed message digest facilitates error recovery of said executable content.
18 . The computer-readable medium of claim 17 , wherein generating a digitally signed message digest for said error-recoverable executable code comprises:
computing a message digest for said error-recoverable executable code; and encrypting said message digest by digitally signing said message digest with an encryption key.
19 . The computer-readable medium of claim 17 , the method further comprising:
computing a first message digest for a current version of said executable content maintained in said storage device; and verifying an integrity of said current version by comparing said first message digest to said digitally signed message digest.
20 . The computer-readable medium of claim 19 , wherein:
said integrity of said current version is verified when said first message digest is equal to said digitally signed message digest.Join the waitlist — get patent alerts
Track US2014041027A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.