US2017286685A1PendingUtilityA1

Method and system for verifying authenticity of at least part of an execution environment for executing a computer module

Assignee: IRDETO CORP B VPriority: Jul 12, 2006Filed: Jun 5, 2017Published: Oct 5, 2017
Est. expiryJul 12, 2026(expired)· nominal 20-yr term from priority
G06F 21/57G06F 2221/0755H04L 2209/16H04L 9/002G06F 21/10G06F 21/107
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system for verifying authenticity of at least part of an execution environment for executing a computer program module. The system includes a processor and a storage for storing the computer program module and the execution environment. The computer program module is operative to cause the processor to process digital input data in dependence on a plurality of predetermined digital parameters. The system includes means for deriving at least part of one of the plurality of predetermined digital parameters from the at least part of the execution environment.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of verifying authenticity of at least part of an execution environment for executing a computer program module, where the computer program module is operative to cause processing of digital input data in dependence on a plurality of predetermined digital parameters; the method including using a predetermined algorithm to derive at least part of one of the plurality of predetermined digital parameters from the at least part of the execution environment. 
     
     
         2 . A method as claimed in  claim 1 , including only executing the computer program module if the plurality of parameters meets a predetermined criterion. 
     
     
         3 . A method as claimed in  claim 2 , including verifying whether the plurality of parameters meet the predetermined criterion by performing at least one run of at least part of the computer program module on predetermined digital input data using the plurality of parameters and verifying whether an output of the run meets a predetermined criterion. 
     
     
         4 . A method as claimed in  claim 3 , including receiving the predetermined digital input data from a server as a challenge; and providing the output of the run to the server, enabling the server to perform the verification. 
     
     
         5 . A method as claimed in  claim 1 , wherein the predetermined algorithm is implemented using computer executable instructions for converting a representation of the execution environment to the at least one parameter. 
     
     
         6 . A method as claimed in  claim 1 , wherein a part of a bit representation of the plurality of parameters is equal to at least a part of a bit representation of computer executable instructions of the execution environment; and wherein instructions of the computer program module are arranged for, during an execution, using at least one memory address holding the part of the bit representation of the instructions of the execution environment also for reading the equal part of the bit representation of the parameters by reference. 
     
     
         7 . A method as claimed in  claim 1 , wherein a part of a bit representation of the plurality of parameters is equal to at least a part of a bit representation of computer executable instructions of the computer program module; and wherein the instructions are arranged for, during an execution of the instructions, using at least one memory address holding the part of the bit representation of the instructions also for reading the equal part of the bit representation of the parameters by reference. 
     
     
         8 . A method as claimed in  claim 1 , wherein the predetermined algorithm causes at least one data element of the execution environment to be used as one or more or part of the plurality of parameters. 
     
     
         9 . A method as claimed in  claim 1 , wherein the plurality of digital parameters include a representation of at least one of the following: cryptographic data, such as a cryptographic key and/or cryptographic algorithm; digital content encoding/decoding data, such as a coding table and/or coding algorithm; digital content scrambling/descrambling data, such as a scrambling table and/or scrambling algorithm. 
     
     
         10 . A method as claimed in  claim 8 , wherein the digital input data is digital content encrypted, encoded and/or scrambled under control of a content-specific key; the method including receiving a representation of the content specific key for controlling decryption, decoding and/or descrambling, respectively, and deriving at least part of one of the plurality of predetermined digital parameters from the received representation of the content-specific key. 
     
     
         11 . A method as claimed in  claim 8 , wherein the derived part of the digital parameters includes a network of obfuscated look-up tables where at least one table has been obfuscated in dependence on the at least part of the execution environment and the algorithm is arranged to derive at least one compensating element from the at least part of the execution environment and insert the at least one compensating element in another one of the obfuscated look-up tables such that the network of obfuscated look-up tables is functionally equivalent to the network of look-up tables. 
     
     
         12 . A system for verifying authenticity of at least part of an execution environment for executing a computer program module; the system including a processor and a storage for storing the computer program module and the execution environment, wherein the computer program module is operative to cause the processor to process digital input data in dependence on a plurality of predetermined digital parameters; and wherein the system includes means for deriving at least part of one of the plurality of predetermined digital parameters from the at least part of the execution environment. 
     
     
         13 . A computer program product for causing a processor to perform the method according to  claim 1 .

Join the waitlist — get patent alerts

Track US2017286685A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.