Method to prevent root level access attack and measurable sla security and compliance platform
US-2024338440-A1 · Oct 10, 2024 · US
US9754104B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9754104-B2 |
| Application number | US-200913133530-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 9, 2009 |
| Priority date | Dec 9, 2008 |
| Publication date | Sep 5, 2017 |
| Grant date | Sep 5, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The invention relates to a virtual machine. The virtual machine is set to recognize, in addition to a set of conventional bytecodes, at least one secure bytecode functionally equivalent to one of the conventional bytecodes. It is set to process secure bytecodes with increased security, while it is set to process conventional bytecodes with increased speed. The invention also relates to a computing device comprising such a virtual machine, to a procedure for generating bytecode executable by such a virtual machine, and to an applet development tool comprising such procedure.
Opening claim text (preview).
The invention claimed is: 1. A computing device comprising a virtual machine operable to recognize, in addition to an instruction set of conventional bytecode instructions each corresponding to a conventional instruction, at least one secure instruction functionally equivalent to one of the conventional bytecode instructions, wherein the virtual machine causes the computing device to recognize a secure bytecode instruction based on a prefix prepended to the corresponding conventional bytecode opcode, said virtual machine causing said computing device: to process secure bytecode instructions with increased security by, when executing a secure bytecode instruction, performing an attack-countermeasure operation selected from adding random delays, performing checks to avoid branching attacks, checking data consistency, checking data integrity, adding traps in response to detecting an attack, performing a response such as muting the device or destroying the device, while operable to process conventional bytecode instructions with increased speed by, when executing a conventional bytecode instruction, not performing countermeasure operations. 2. A computing device according to claim 1 , wherein the computing device is a smart card. 3. A procedure for providing a security device with improved capability for balancing security and execution performance tailored to security and performance requirements of applets executed on the security device, comprising: loading, on the security device, a virtual machine, said virtual machine causing said computing device to process secure bytecode instructions with increased security by, when executing a secure bytecode instruction, performing an attack-countermeasure operation selected from adding random delays, performing checks to avoid branching attacks, checking data consistency, checking data integrity, adding traps in response to detecting an attack, performing a response such as muting the device or destroying the device, while causing said computing device, and to process conventional bytecode instructions with increased speed by, when executing a conventional bytecode instruction, not performing countermeasure operations; processing an applet using an applet development tool operable to process security tagged applet methods, the development tool comprising conversion means for converting an applet comprising methods tagged as secure into a file comprising bytecode opcodes, the conversion means including a procedure for generating a executable file comprising bytecode opcodes wherein each bytecode opcode corresponds to an instruction, the executable file being executable by a computing device, the executable file corresponding to an applet, the procedure comprising when processing a subset of the methods of the applet being defined as methods to be secured, the procedure automatically generates, for the methods to be secured, secure bytecode opcodes instead of conventional bytecodes by prepending a conventional bytecode opcode to be secured with a prefix code, wherein a secure bytecode instruction is encoded using the opcode corresponding to the conventional bytecode instruction except that encoding of the secure bytecode instruction has an additional prefix, thereby reducing vulnerability to attacks on computing devices executing the file; and loading, on said security device, said executable file whereby upon execution of said executable file by said virtual machine methods of the applet tagged for secured execution are executed with at least one of said attack-countermeasure operations whereas methods not tagged for secured execution are executed by said security device with increased speed by not performing such countermeasure operations. 4. The procedure according to claim 3 , wherein the applet is a javacard applet. 5. The procedure according to claim 4 , wherein the specific prefix is the byte OxFF. 6. The procedure according to claim 3 wherein the name of the methods to be secured is formatted differently so that the procedure can identify methods to be secured from their name. 7. The procedure according to claim 6 , wherein the formatting consists in adding a prefix to the name of the method to be secured.
Related publications grouped by family.
Answers are generated from the same data shown on this page.