Apparatus and method for generating and using random values

By determining different canary values ​​for each thread and iteratively modifying the random values, the problem of insufficient random stack canary values ​​caused by the lack of true random number generator in embedded systems is solved, and higher security and attack resistance are achieved.

CN120197167APending Publication Date: 2025-06-24INTEL CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411651318.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-11-19
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In embedded systems lacking true random number generators, the challenge of generating and using sufficiently random stack canary values ​​to prevent buffer overflows, especially in the face of brute force cracking and BORE attacks.

Method used

Ensure its randomness and unpredictability by determining different canary values ​​for each thread and iteratively modifying the random values ​​at each startup. This method uses a non-true random number generator, combined with simulated or physical noise sources, to dynamically regenerate canary values ​​to improve their randomness and attack resistance.

Benefits of technology

It effectively improves the randomness and security of stack canary, reduces the risks of brute-force cracking and BORE attacks, and is suitable for embedded systems lacking true random number generators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197167A_ABST
    Figure CN120197167A_ABST
Patent Text Reader

Abstract

Various examples of the present disclosure relate to apparatuses and methods for generating and using random values. Some aspects of the present disclosure relate to an apparatus for a computer system that includes a memory circuit, machine-readable instructions, and a processor circuit that executes the machine-readable instructions to determine different canary values for respective different threads of a program, and launch the threads of the program, wherein the determined canary value is used as a stack canary for the thread of the program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to apparatuses, methods, computer systems, and computer-readable media for generating and using random values. Background Art

[0002] Stack canaries (so named because of their similarity to canaries in coal mines) are used to detect stack buffer overflows before the execution of malicious code can occur. The stack canary method works by placing a small random value at the beginning of each function, just before the stack return pointer (expected to be randomly selected at program startup), and performing a check during the end of the stack pointer's return to the caller function in memory to detect whether the random value has been overwritten. Most buffer overflows overwrite memory from lower to higher memory addresses in order to overwrite the return pointer (and thus gain control of the process). Since the canary memory location is part of this area, it is overwritten. Checking the canary value upon return verifies that a memory write has not occurred, so the routine can be trusted and the return pointer on the stack can be used. This technique can greatly increase the difficulty of exploiting stack buffer overflows because it forces an attacker to gain control of the instruction pointer through some non-traditional means (such as corrupting other important variables on the stack).

[0003] There are two main ways to bypass canaries: by leaking it through an information leakage vulnerability, or by brute-forcing the canary value - which is possible and sometimes inevitable on systems with 32 bits or fewer (however, currently it is not feasible on 64-bit systems). A brute-force attack attempts to overwrite the canary location with random values until the correct value is guessed, at which point the return address is used. If the canary is reused across different products, then once the canary value is guessed, that value can be reused, making this attack a BORE (Break Once, Reuse Everywhere) attack.

[0004] When developing firmware IP (Intellectual Property) blocks integrated in a SoC (System on Chip) or used as stand-alone IP for a product, this poses a challenge in protecting such IP blocks from buffer overflows. One mechanism to prevent buffer overflows is to use a stack canary. If the IP lacks a TRNG (True Random Number Generator) or system TRNG access, the stack canary mechanism may not be properly implemented. In an embedded environment where different IP blocks are used but there is no dedicated TRNG, there may be a lack of the ability to generate canaries (which prevent backtracking and are anti-predictable) that are random enough to protect the embedded system stack from buffer overflows. Without a true pseudo-random generator, the canaries used by the stack canary mechanism may be inferred or predicted. Even if an externally generated fixed (platform-level) true random canary is used, it may be brute-forced, and if it is reused for all systems, it is vulnerable to the BORE attack (crack once, reuse everywhere). Even randomly generated canaries that are unique to each system may be leaked by brute-forcing, especially for the small-sized canary values commonly used in embedded systems that are typically set to a length of no more than 32 bits (usually 24 bits). Current known processes for extracting TRNG-based randomness from a running system are slow in practice, and the added latency creates a significant overhead in the startup execution phase of an embedded system, making this solution impractical. SUMMARY OF THE INVENTION

[0005] According to an embodiment of the present disclosure, a device for a computer system is provided, the device comprising: a memory circuit, machine-readable instructions, and a processor circuit, the processor being configured to execute the machine-readable instructions to: determine different canary values for respective different threads of a program; and start a thread of the program, wherein the determined canary values are used as stack canaries for the thread of the program.

[0006] According to an embodiment of the present disclosure, a method for a computer system is provided, the method comprising: for each start of a thread of a program, obtaining a canary value, wherein the canary value obtained for the thread of the program is different from previously used canary values of the respective threads of the program in at least 20% of the starts of the thread of the program; and starting the thread of the program, wherein the obtained canary value is used as a stack canary for the thread of the program.

[0007] According to an embodiment of the present disclosure, there is provided a non-transitory computer-readable medium including program code that, when executed on a processor, a computer, or a programmable hardware component, causes the processor, computer, or programmable hardware component to: determine different canary values for respective different threads of a program; and start the threads of the program, wherein the determined canary values are used as stack canaries for the threads of the program.

[0008] According to an embodiment of the present disclosure, there is provided a computer program having program code for performing the above method. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Next, some examples of the apparatus and / or method will be described by way of example only with reference to the accompanying drawings, in which:

[0010] Figure 1a A schematic diagram showing an example of an apparatus or device for a computer system and a computer system including such an apparatus or device is shown;

[0011] Figure 1b A flowchart showing an example of a method for a computer system is shown;

[0012] Figure 2a A schematic diagram showing an example of an apparatus or device for a computer system and a computer system including such an apparatus or device is shown;

[0013] Figure 2b A flowchart showing an example of a method for a computer system is shown;

[0014] Figure 3a A flowchart showing an example of generating a canary value in the absence of a true random number generator is shown;

[0015] Figure 3b A flowchart showing another example of generating a canary value according to the proposed concept, with dynamic regeneration (moving target scheme);

[0016] Figure 4a A schematic diagram showing an example of a simulated noise source is shown;

[0017] Figure 4b A schematic diagram showing an example of a physical noise source; and

[0018] Figure 4c A schematic diagram showing an example of a non-physical noise source is shown. DETAILED DESCRIPTION

[0019] Some examples will now be described in more detail with reference to the accompanying drawings. However, other possible examples are not limited to the features of these embodiments described in detail. Other examples may include modifications of these features, as well as equivalents and alternatives of these features. In addition, the terms used herein to describe certain examples should not limit additional possible examples.

[0020] Throughout the description of the accompanying drawings, like or similar reference numerals refer to like or similar elements and / or features, which may be the same or may be implemented in a modified form while providing the same or similar functions. The thicknesses of lines, layers, and / or regions in the drawings may also be exaggerated for clarity.

[0021] When two elements A and B are combined using "or", this should be understood to disclose all possible combinations, i.e., only A, only B, and A and B, unless otherwise explicitly defined in an individual case. As an alternative wording for the same combination, "at least one of A and B" or "A and / or B" may be used. This equivalently applies to combinations of more than two elements.

[0022] If singular forms such as "a" and "the" are used and are not explicitly or implicitly limited to using only a single element as mandatory, additional examples may also implement the same function using several elements. If a function is described hereinafter as being implemented using multiple elements, additional examples may implement the same function using a single element or a single processing entity. It is also to be understood that the terms "comprises" and / or "comprising", when used, describe the presence of the specified features, integers, steps, operations, processes, elements, components, and / or groups thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, processes, elements, components, and / or groups thereof.

[0023] In the following description, specific details are set forth, but examples of the techniques described herein may be implemented without these specific details. Well-known circuits, structures, and techniques are not shown in detail to avoid obscuring the understanding of this specification. An "example" or "examples", "various examples", "some examples", etc. may include a feature, a structure, or a characteristic, but not every example necessarily includes that particular feature, structure, or characteristic.

[0024] Some examples may have some, all, or none of the features described for other examples. Descriptions such as "first", "second", "third", etc. describe common elements and indicate that different instances of similar elements are being referred to. Such adjectives do not imply that the element items so described must be in a given sequence, whether in time, in space, in ranking, or in any other way. "Connected" may indicate that elements have direct physical or electrical contact with each other, while "coupled" may indicate that elements cooperate or interact with each other, but they may or may not have direct physical or electrical contact.

[0025] As used herein, the terms "operate", "execute", or "run" are used interchangeably when they relate to software or firmware associated with a system, device, platform, or resource, and can refer to software or firmware stored in one or more computer-readable storage media accessible by the system, device, platform, or resource, even if the instructions contained in the software or firmware are not being actively executed by the system, device, platform, or resource.

[0026] Descriptions may use the phrases "in an example", "in examples", "in some examples", and / or "in various examples", each of which may refer to one or more identical or different examples. Additionally, the terms "comprising", "including", "having", etc. used for examples of the present disclosure are synonymous.

[0027] Figure 1a A schematic diagram showing an example of apparatus 10 or device 10 for a computer system 100 and a computer system 100 including such apparatus 10 or device 10 is shown. Apparatus 10 includes circuitry for providing the functionality of apparatus 10. For example, the circuitry of apparatus 10 may be configured to provide the functionality of apparatus 10. For example, Figure 1a Apparatus 10 includes optional interface circuitry 12, processor circuitry 14, and memory circuitry 16. For example, processor circuitry 14 may be coupled to interface circuitry 12 and to memory circuitry 16. For example, processor circuitry 14 may provide the functionality of the apparatus in conjunction with interface circuitry 12 (for exchanging information, such as with other components internal or external to computer system 100 that includes apparatus 10 or device 10) and memory or storage circuitry 16 (for storing information, such as machine-readable instructions). Similarly, device 10 may include means for providing the functionality of device 10. For example, these means may be configured to provide the functionality of device 10. The components of device 10 are defined as component means, which may correspond to or be implemented by the respective structural components of apparatus 10. For example, Figure 1aDevice 10 includes: means 14 for processing, which may correspond to or be implemented by processor circuitry 14; (optional) means 12 for communication, which may correspond to or be implemented by interface circuitry 12; and means 16 for storing information, which may correspond to or be implemented by memory circuitry 16. Generally, the functions of processor circuitry 14 or means 14 for processing may be implemented by processor circuitry 14 or means 14 for processing executing machine-readable instructions. Thus, any feature ascribed to processor circuitry 14 or means 14 for processing may be defined by one or more of a plurality of machine-readable instructions. Device 10 or apparatus 10 may include machine-readable instructions, for example, within memory circuitry 16, storage circuitry (not shown), or means 16 for storing information.

[0028] Processor circuitry 14 or means 14 for processing determines different canary values for respective different threads of a program. For example, processor circuitry 14 or means 14 for processing may determine a canary value for each start of a thread of a program, where the canary values determined for each start of a thread of a program are different. For example, processor circuitry 14 or means 14 for processing starts the thread of the program, where the determined canary value is used as the stack canary for the thread of the program. For example, processor circuitry may, as a rule, provide a new canary value for a different thread of the program. For example, processor circuitry may obtain a canary value for each start of a thread of a program, and the canary value obtained for a thread of a program may be different from the canary values of the respective threads of the program previously used in at least 20% (or at least 10%, or at least 50%) of the starts of the thread of the program, and use the obtained canary value as the stack canary for the thread of the program.

[0029] Figure 1b A flowchart illustrating an example of a corresponding method for a computer system (e.g., for computer system 100) is shown. The method includes determining 110 different canary values for respective different threads of a program. The method includes starting 120 a thread of the program, where the determined canary value is used as the stack canary for the thread of the program. For example, the method may be executed by computer system 100, e.g., by device 10 or apparatus 10 of computer system 100. For example, the method may include obtaining a canary value for each start of a thread of a program, where the canary value obtained for a thread of a program may be different from the canary values of the respective threads of the program previously used in at least 20% (or at least 10%, or at least 50%) of the starts of the thread of the program; and using the obtained canary value as the stack canary for the thread of the program.

[0030] Next, the functions of apparatus 10, device 10, computer system 100, method, and corresponding computer program will be described in more detail with reference to apparatus 10. Features described in connection with apparatus 10 may also be included in the corresponding device 10, computer system 100, method, and computer program.

[0031] Various embodiments of the present disclosure are based on the following findings: In low-complexity computer systems such as, for example, embedded devices, protection against buffer overflows with the help of stack canaries may be hindered because the bit width used for stack canaries (which may depend on the bit width of the computer system, e.g., 32 bits or even 16 bits) may be vulnerable to brute-force attacks. Similarly, many lower-complexity computer systems lack the presence of a true random number generator, such that the generated values are either not completely random and may be easily guessed, or are externally generated random values that are then used for a long time (possibly for multiple devices), making these devices more vulnerable to attacks.

[0032] In the proposed concept, these drawbacks are overcome by using two mechanisms. On the one hand, different stack canaries are used for different threads of a program, such that a guessed stack canary does not compromise other threads, thereby limiting the impact of an attack. On the other hand, to facilitate the generation of strong stack canary values with a high level of randomness (or more generally, random values, which will be described more generally in connection with Figure 2a and 2b ), the random values used as stack canaries can be iteratively modified based on a source of randomness / entropy, such that the randomness of the modified random value can be increased with each iteration, so that even a relatively weak non-true random number generator can be used to generate random values with a sufficient level of randomness over time. As will be described in connection with Figure 2a and 2b , in addition to being used as stack canaries, such random values can also be used for other purposes.

[0033] When applied to generate canary values used as stack canaries, the proposed concept first determines different canary values for the respective different threads of a program. This canary value can be derived from an initial seed (i.e., an initial canary value), which can be iteratively modified over time. In other words, the processor circuit can determine the initial canary value and then iteratively modify the canary value to determine different canary values. Thus, as Figure 1bAs further shown in [0], the method may include determining 112 an initial canary value and iteratively modifying 116 the canary value to determine different canary values. For example, in some cases, the initial canary value may be determined using a true random number generator (e.g., the true random number generator of device 10 or computer system 100). Alternatively, the initial canary value may be determined using a non-true random number generator (e.g., the non-true random number generator of device 10 or computer system 100). In the latter case, a predefined number of iterative modifications may be made before using the canary value to ensure a desired level of randomness is achieved.

[0034] In the proposed concept, the requirements for the source of randomness used in the iterative modification of the canary value are relatively low because as the canary value is iteratively updated, the entropy (entropy is a measure of the disorder or randomness present in a system) or the level of randomness increases iteratively over time. For example, in various examples of the proposed concept, a random value is obtained from a source of randomness (referred to Figure 2a and 2b represented as a second random value, referred to Figures 4a to 4c represented as the original data), and then it is used to modify the canary value. In other words, the processor circuit may obtain a random value from the source of randomness for each (every) modification of the canary value and use that random value to modify the canary value. Thus, as Figure 1b further shown in [0], the method may include, for each (every) modification of the canary value, obtaining 114 a random value from the source of randomness and using that random value to modify 116 the canary value. Since the iterative scheme is the main guarantee of the level of randomness, different types of (weak) sources of randomness may be used for this purpose. Specifically, the source of randomness may be a non-true random generator, i.e., not a hardware true random number generator (TRNG). In other words, the processor circuit may obtain a random value from a non-true random value generator. For example, the non-true random value generator may be based on the clock drift between two clocks. For example, the random value may represent the clock drift between two clocks. Additionally, or alternatively, as Figure 4a shown, the non-true random value generator may be based on analog noise, e.g., based on a physical noise source (e.g., as Figure 4b shown in [0]). For example, the non-true random number generator may provide a random value based on one of the following: radioactive decay, thermal noise, shot noise, avalanche noise in a Zener diode, clock drift, the timing of the actual movement of a hard disk read / write head, and radio noise. Or, as Figure 4cAs shown, the non-true random value generator can be based on a non-physical noise source, which is based on the operation of a computer system. In this case, the non-true random value generator can use the timing of keyboard input, the movement of a pointer input device (e.g., a mouse), interrupt request (IRQ) noise, hard disk activity, etc. as noise sources. In some cases, multiple randomness sources (i.e., multiple entropy sources) can be combined. In other words, the non-true random value generator can be based on multiple randomness sources.

[0035] Since the canary value is modified for different threads (hundreds or thousands of different threads are started within a short time span), the latency caused by generating and obtaining random values can be kept low. Therefore, the processor circuit can obtain a random value from a randomness source that can provide a random value within a predefined maximum time interval. For this reason, the random value may not be obtained from a true random number generator, which may cause significant latency.

[0036] To apply the random value when modifying the canary value, different action schemes can be selected depending on the bit length of the random value. For example, if the random value has the same number of bits (or even more) as the canary value, the canary value and the random value can be XORed together. If the random value has fewer bits (e.g., only a few bits) than the canary value, other schemes can be selected. For example, the processor circuit can select one or more bits of the canary value to flip based on the random value, and flip the selected bits to modify the canary value. Therefore, the method can include selecting one or more bits of the canary value to flip based on the random value, and flipping the selected bits to modify the canary value.

[0037] For example, if the random value has two bits, four different cases can be addressed: if the two bits are 00, all bits are flipped; if they are 01, every other bit is flipped; if they are 10, every second bit is flipped; if they are 11, every third bit is flipped, looping back at the end of the variable, etc. This scheme can be extended according to the number of bits included in the random value.

[0038] The generated canary value can then be applied as a stack canary when starting a new thread. In other words, the processor circuit can start a thread of a program, where the determined canary value is used as the stack canary for that thread of the program. In other words, the respective canary values can be placed at the beginning of the function(s) of the thread, just before the stack return pointer, to serve as the stack canary for that thread.

[0039] This concept can be used in different scenarios. For example, in computer system firmware, the main loop is repeated again and again. In the proposed concept, in each iteration or at least some iterations of the loop, the canary value can be modified, and different canary values can be used as stack canaries. In other words, the program may be part of the firmware of a computer system, where the firmware uses the main loop during operation. For example, this is shown in Figure 3a . For subsequent iterations of the main loop, different canary values are determined and used as stack canaries. For example, before or when entering an iteration of the main loop, when starting a thread within the main loop, the canary value can be modified and used as a stack canary. As the main loop is repeated again and again (e.g., thousands of times per second), the window of opportunity for using a canary value guessed by brute force is very small, thus improving the security of the firmware.

[0040] However, the proposed concept of making stack canaries more secure is not limited to firmware applications. For example, it can also be used in user space. For example, different stack canaries can be used for different threads of a user space application (e.g., using different canary values for each thread) (similarly, it can be used for different threads of different user space applications). In other words, the program can be a user space application. Different threads of the program can be started with different canary values as stack canaries. For example, to further improve security, different canary values can be based on different initial canary values (i.e., based on different starting seeds).

[0041] The interface circuit 12 or the device 12 for communication may correspond to one or more inputs and / or outputs for receiving and / or sending information, which can be digital (bit) values according to a specified code within a module, between modules, or between modules of different entities. For example, the interface circuit 12 or the device 12 for communication may include a circuit configured to receive and / or send information.

[0042] For example, one or more processing units, one or more processing devices, any device for processing, such as a processor, a computer, or a programmable hardware component that can operate with appropriately adapted software, can be used to implement the processor circuit 14 or the device 14 for processing. In other words, the functions of the processor circuit 14 or the device for processing can also be implemented by software, which is then executed on one or more programmable hardware components. Such hardware components may include general-purpose processors, digital signal processors (DSPs), microcontrollers, and so on.

[0043] For example, the memory circuit 16 or the device 16 for storing information may include a volatile memory, such as a random access memory, such as a dynamic random-access memory (DRAM).

[0044] For example, the computer system 100 can be any kind of system including a processor, such as a laptop computer, a desktop computer, a server computer, an embedded computer, an Internet of Things node, a tablet computer, a mobile device, a smart phone, and so on.

[0045] In connection with the proposed concept or one or more examples described above or below (e.g., FIGS. 2 to Figure 4c ), more details and aspects of the device 10, the apparatus 10, the computer system 100, the method, and the computer program are mentioned. The device 10, the apparatus 10, the computer system 100, the method, and the computer program may include one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.

[0046] Figure 2a A schematic diagram showing an example of the device 20 or the apparatus 20 for the computer system 200 and the computer system 200 including such a device 20 or apparatus 20 is shown. For example, the implementation of the device 20 or the apparatus 20 may be similar to Figure 1a the device 10 or the apparatus 10. The device 20 includes circuits for providing the functions of the device 20. For example, the circuits of the device 20 may be configured to provide the functions of the device 20. For example, Figure 2a the device 20 includes an optional interface circuit 22, a processor circuit 24, and a memory circuit 26. For example, the processor circuit 24 may be coupled to the interface circuit 22 and to the memory circuit 26. For example, the processor circuit 24 may provide the functions of the device in conjunction with the interface circuit 22 (for exchanging information, such as with other components inside or outside the computer system 200 including the device 20 or the apparatus 20) and the memory or storage circuit 26 (for storing information, such as machine-readable instructions). Similarly, the apparatus 20 may include means for providing the functions of the apparatus 20. For example, these means may be configured to provide the functions of the apparatus 20. The components of the apparatus 20 are defined as component means, which may correspond to or be implemented by the respective structural components of the device 20. For example, Figure 2aDevice 20 includes: means 24 for processing, which may correspond to or be implemented by processor circuit 24; (optional) means 22 for communication, which may correspond to or be implemented by interface circuit 22; means 26 for storing information, which may correspond to or be implemented by memory circuit 26. Generally speaking, the functions of processor circuit 24 or means 24 for processing can be implemented by processor circuit 24 or means 24 for processing executing machine-readable instructions. Therefore, any feature given to processor circuit 24 or means 24 for processing can be defined by one or more of a plurality of machine-readable instructions. Device 20 or equipment 20 may include machine-readable instructions, for example, within memory circuit 26, storage circuit (not shown), or means 26 for storing information.

[0047] Processor circuit 24 or means 24 for processing determines an initial random value. Processor circuit 24 or means 24 for processing iteratively modifies the initial random value based on a second random value obtained from a randomness source. Processor circuit 24 or means 24 for processing uses the iteratively modified random value for tasks that require a random value.

[0048] Figure 2b A flowchart showing an example of a corresponding method for a computer system (e.g., for computer system 200) is presented. The method includes determining 210 an initial random value. The method includes iteratively modifying 230 the initial random value based on a second random value obtained 220 from a randomness source. The method includes using 240 the iteratively modified random value for tasks that require a random value. For example, the method can be executed by computer system 200, such as by device 20 or equipment 20 of computer system 200.

[0049] Below, the functions of device 20, equipment 20, computer system 200, method, and corresponding computer program are introduced in more detail with reference to device 20. The features introduced in connection with device 20 can also be included in the corresponding equipment 20, computer system 200, method, and computer program.

[0050] In connection with Figure 1a and 1b , a specific use case of the random value is introduced: using the random value as a stack canary. However, in connection with Figure 1a and 1b The techniques described are not limited to being used for quickly generating stack canaries - this is just one application of the technique. In other words, the iteratively modified random value can be used as a stack canary for a thread of a program. For example, different iteratively modified random values can be used as stack canaries for different threads of a program or threads of different programs.

[0051] Alternative uses include being part of address space layout randomization (ASLR). In other words, iteratively modified random values can be used for address space layout randomization. Address space layout randomization (ASLR) is a security technique that helps defend against buffer overflow attacks by randomizing the locations in memory where system and application code are loaded. Each time an application starts, ASLR loads the application's executable file and dynamic libraries at different memory locations rather than always at the same address. In this way, ASLR adds a layer of unpredictability, making it more difficult for an attacker to execute arbitrary code through a carefully crafted exploit because these exploits rely on knowing the memory addresses of specific instructions or data structures. On platforms with 32 bits or fewer, ASLR also suffers the same challenges. Data ASLR and KASLR (kernel ASLR) are additional mechanisms that are not always available in embedded systems due to address memory space or limited sources of randomness.

[0052] In ASLR, various random values are used. For example, iteratively modified random values can be used to determine the location in memory where an executable file is loaded when starting an application that includes the executable file. Additionally, or alternatively, iteratively modified random values can also be used to determine the location in memory where libraries used by the application are loaded. Additionally, or alternatively, iteratively modified random values can be used to determine the memory region for the heap (heap randomization). Additionally, or alternatively, iteratively modified random values can be used to determine the starting location in the stack (stack randomization). Additionally, or alternatively, iteratively modified random values can be used to determine the base address of memory mapped files and shared memory regions (address space randomization).

[0053] The techniques used are the same as those associated with Figure 1a and 1b described: The process first determines an initial random value (using a TRNG or non-TRNG), and then iteratively modifies that initial random value based on a second random value obtained from a source of randomness. Then, for example, the individually iteratively modified random values are used as stack canaries or for ASLR.

[0054] For example, as outlined in Figure 1a and 1b a second random value is obtained from a source of randomness ( Figure 1a and 2b represented as a random value, Figures 4a to 4crepresented as raw data), and then it is used to modify the initial random value. In other words, for each modification of the random value, the processor circuit can obtain a second random value from a source of randomness and use this random value to modify the random value. Since the iterative scheme is the main guarantee of the randomness level, different types of (weak) sources of randomness can be used for this purpose. Specifically, the source of randomness can be a non-true random generator, i.e., not a hardware true random number generator (TRNG). In other words, the processor circuit can obtain the second random value from a non-true second random value generator. For example, the non-true second random value generator can be based on the clock drift between two clocks. For example, the second random value can represent the clock drift between two clocks. Additionally, or alternatively, as Figure 4a shown, the non-true second random value generator can be based on analog noise, for example, based on a physical noise source (such as Figure 4b shown). For example, the non-true random number generator can provide the second random value based on one of the following: radioactive decay, thermal noise, shot noise, avalanche noise in a Zener diode, clock drift, the timing of the actual movement of a hard disk read / write head, and radio noise. Or, as Figure 4c shown, the non-true second random value generator can be based on a non-physical noise source that is based on the operation of a computer system. In this case, the non-true second random value generator can use the timing of keyboard input, the movement of a pointer input device (e.g., a mouse), interrupt request (IRQ) noise, hard disk activity, etc. as noise sources. In some cases, multiple sources of randomness (i.e., multiple entropy sources) can be combined. In other words, the non-true random value generator can be based on multiple sources of randomness.

[0055] Since the random value is modified for different startups of a thread (which can occur hundreds or thousands of times in a short time span), the latency caused by generating and obtaining the second random value can be kept low. Therefore, the processor circuit can obtain the second random value from a source of randomness that is capable of providing the second random value within a predefined maximum time interval. For this reason, the second random value may not be obtained from a true random number generator, which may cause significant latency.

[0056] To apply the second random value when modifying the random value, different action schemes can be selected depending on the bit length of the second random value. For example, if the second random value has the same number of bits as (or even more than) the random value, the random value and the second random value can be XORed together. If the second random value has fewer bits than the random value (e.g., only a few bits), other schemes can be selected. For example, the processor circuit can select one or more bits of the random value to be flipped based on the second random value, and flip the selected bits to modify the random value. Thus, the method can include selecting one or more bits of the iteratively modified random value to be flipped based on the second random value, and flipping the selected bits to modify the random value.

[0057] For example, if the second random value has two bits, four different cases can be addressed - if the two bits are 00, all bits are flipped; if they are 01, every other bit is flipped; if they are 10, every second bit is flipped; if they are 11, every third bit is flipped, looping back at the end of the variable, and so on. This scheme can be extended according to the number of bits included in the second random value.

[0058] The interface circuit 22 or the device 22 for communication can correspond to one or more inputs and / or outputs for receiving and / or sending information, which can be digital (bit) values according to a specified code within a module, between modules, or between modules of different entities. For example, the interface circuit 22 or the device 22 for communication can include a circuit configured to receive and / or send information.

[0059] For example, one or more processing units, one or more processing devices, any device for processing, such as a processor, a computer, or a programmable hardware component operable with appropriately adapted software, can be used to implement the processor circuit 24 or the device 24 for processing. In other words, the functions of the processor circuit 24 or the device for processing can also be implemented by software, which is then executed on one or more programmable hardware components. Such hardware components can include general-purpose processors, digital signal processors (DSPs), microcontrollers, and so on.

[0060] For example, the memory circuit 26 or the device 26 for storing information can include volatile memory, such as random access memory, such as dynamic random-access memory (DRAM).

[0061] For example, the computer system 200 can be any kind of system including a processor, such as a laptop computer, a desktop computer, a server computer, an embedded computer, an Internet of Things node, a tablet computer, a mobile device, a smart phone, and so on.

[0062] In connection with the proposed concept or one or more examples described above or below (e.g., Figures 1a to 1b , Figures 3a to 4c ), more details and aspects of the apparatus 20, device 20, method, and computer program are mentioned. The apparatus 20, device 20, method, and computer program may include one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.

[0063] Various embodiments of the present disclosure relate to mobile target defense against stack canary (random value) prediction attacks by utilizing continuous regeneration of predefined policies.

[0064] If an embedded system uses the stack canary mechanism, one of the following schemes is used in most cases. For example, the embedded system can use TRNG hardware (i.e., dedicated hardware IP). Adding a dedicated TRNG hardware block is the best option, but it is not always feasible or economical. Alternatively, the embedded system can generate true random values from operating system features (e.g., physically unclonable function PUF). However, deriving a TRNG from the operating system is very complex and usually introduces significant latency. Alternatively, the embedded system can use a random canary, which is generated externally and fixed from an external source in each embedded system power cycle. However, the externally generated fixed canary value is reusable and vulnerable to brute-force and BORE (break once, reuse everywhere) attacks, especially when the bit length of the canary is small, which is common in embedded systems. Alternatively, the embedded system can reuse the same random canary generated externally as part of an IP, which may result in weaker security and compromise the entire product set using the same value (BORE). Alternatively, the embedded system can use renew after fork StackSmashProtector (RAF-SSP), which provides new random generation of canaries on each new thread / fork and is used by Microsoft / Linux in user space - the proposed scheme gives a modification to the RAF SSP (renew after fork SSP) technique, which includes setting a new random value of the canary for each child process when the fork() system call is invoked. The weakness of this method is that it depends on the fork call and is applicable to each thread, so it is not effective when the execution time is long.

[0065] On an embedded system, the proposed solution involves starting the firmware main loop (most firmware runs in the main loop and reacts to different interrupts or parses commands through a management interface). Even if this mode is not applicable, the solution described here still applies. The only difference is that in multi-threaded execution, the canary is generated each time a child thread is created, or in the case of multi-process execution, for each process, e.g., generated in each execution cycle, where a PRNG (pseudo-random number generator) canary value is used, or a non-true RNG mechanism is used, regardless of the size required for the canary (which is derived from the architecture bit length). The actual canary may be derived from this seed in each execution loop cycle to generate a one-time canary by mixing a common root with system-specific (observed) entropy sources, which makes the canary dynamic and constantly changing, thus preventing BORE attacks. This solution is applicable to any system lacking TRNG resources and enables the use of the stack canary security defense mechanism against buffer overflows. It can also be used in systems with a low bit length, where a fixed canary (even generated by a TRNG) lasts too long, allowing brute-force attacks.

[0066] A non-true RNG source can be implemented by mixing different entropy sources, which may include radioactive decay, thermal noise, shot noise, avalanche noise in a Zener diode, clock drift, the timing of the actual movement of a hard disk read / write head, and radio noise. However, physical phenomena and the tools used to measure them generally have the characteristics of asymmetry and systematic bias, which makes their results not uniformly random - in our case, this is not a problem because the butterfly effect is applied by continuously pushing the source during system execution. The more the system runs, the more random it becomes. A randomness extractor (such as a cryptographic hash function) can be used to approximate uniformly distributed bits from a non-uniform random source, although the bit rate is low.

[0067] The proposed solution provides a mechanism applicable to all systems lacking TRNG (e.g., most embedded systems). On the other hand, using a TRNG also has performance implications. In addition to providing a way to use a PRNG (pseudo-random generator), the proposed concept also uses "moving target defense" suitable for low-bit-size architectures (e.g., 8 / 16 / 32 bits) to improve the stack canary mechanism. Many IP blocks lack this protection, resulting in a weak canary implementation and a risk of brute-force and BORE attacks. The proposed concept can improve the security of such IP blocks.

[0068] The proposed solution addresses the challenges of brute-force attacks (a challenge in firmware implementation) or leaking canaries. The proposed solution is applicable not only to firmware implementation but also to managed runtime environments (an improvement over other solutions). The solution further addresses the dependency on local or system TRNGs in the hardware domain, which can impose a cost on performance and thus cannot be used periodically. The proposed solution is based on dynamically changing the canary (a "moving target" scheme against attackers) on each fetch / call and is not currently in use. The proposed concept provides a solution for (incrementally) generating random values in software / firmware IP blocks when there is a lack of a true random entropy source or even when the random entropy source is not large enough. The proposed solution provides a solution for incrementally generating random numerical values based on predefined policies, using a low randomness source to ultimately achieve a random value with a desired level of randomness.

[0069] The following process describes the proposed solution for canary value generation. First, a PRNG or non-true RNG entropy source can be selected from existing SoC resources, e.g., on entry to the main loop, at clock drift. This source can provide pseudo-random numbers in a very short time. Next, the canary value can be seeded into a platform-specific set of random numbers during manufacturing. This number can be mixed with the previous canary value each time the firmware loop is entered (millions of times per second). The result can be used as the canary value for each new function call. This process can continue until execution is complete.

[0070] In the firmware, the canary can be generated in each firmware execution cycle and the generation is incrementally seeded in a very fast manner. This technique greatly increases the difficulty of brute-force and information leakage attacks in most systems (by several orders of magnitude). The proposed concept can rely on an entropy source that may not be random enough to be directly used as a stack canary, but it is constantly changing and evolving, providing a changing pseudo-random source for creating stack canaries. The resistance of the proposed process to brute-force guessing attacks is improved because the value detected during a brute-force cycle cannot be used later in a "real" attack in the next execution cycle, making brute-force attacks useless.

[0071] Figure 3a and 3b shows the current ( Figure 3a ) model and the new ( Figure 3b ) model. Figure 3aA flowchart showing an example of generating a canary value without a true random number generator (according to the current model). In the firmware initialization / start-up phase 300, the canary is initialized with a PRNG random value. Then the firmware enters 310 the main loop, and the main loop (with business logic, interrupts, and routine calls) is executed 330, and the loop returns to the main loop entry 310. Finally, the main loop exits 340. Figure 3b A flowchart showing another example of generating a canary value according to the proposed concept, with dynamic regeneration (moving target scheme). Compared with Figure 3a the scheme shown, when entering 310 the main loop, the canary is regenerated 320 based on the aggregated entropy of the PRNG or any other entropy source 325 before the main loop execution 330.

[0072] The proposed scheme solves the problem of reusing canary values between different systems of the same product line, as well as the problem of reusing canary values between firmware (or software) cycles in the same product. It limits or removes the ability to perform brute-force attacks offline, which is particularly important in systems with a low canary bit length size (e.g., below 64 bits). In a multi-threaded environment, the same scheme can be reused at the thread level, but with another starting seed to generate a random canary. If no physical entropy is available, or even no PRNG (software-based), a non-true RNG can be used. By iteratively modifying the canary value, the entropy can grow and change in each main loop cycle.

[0073] For example, the system entropy rate can be defined as follows:

[0074]

[0075] Using the proposed scheme, if the number of bits used at startup is lower than the existing entropy of the system, the system entropy rate will grow exponentially as the system operates more:

[0076]

[0077] The "system entropy" is fixed to the "number of bits", but the "system entropy rate" increases with each new FW execution cycle due to the regeneration that occurs in each execution cycle.

[0078] Below, examples of initial seed generation and reseeding strategies are given. In systems with a random source TRNG / PRNG, these mechanisms can be used for the initial seed. In systems without a TRNG / PRNG random source, a non-true RNG can be used (e.g., according to the examples listed below).

[0079] In the previous strategy, a random entropy source of at least two bits may be sufficient. These bits can be used to flip one bit from a random variable (e.g., a canary) every XX bits, where XX is determined from the two generated bits (e.g., 00 flips all, 01 flips every other bit, 10 flips every second bit, 11 flips every third bit, looping back at the end of the variable). This can be applied to each cycle and the desired entropy will be reached in just a few cycles.

[0080] In the second strategy, a random entropy source of at least two bits may be sufficient. These bits can be used to perform an exclusive OR operation on two bits from a random variable (e.g., a canary). A counter can be used for each cycle. The counter can be used to shift to the next bits (after the previous two bits), cycling through all the bits on the desired random variable. This process may occur in each cycle and the desired entropy will be reached in just a few cycles.

[0081] Additional strategies exist and can be defined based on the random source size, desired random values, and system requirements.

[0082] Below, some examples of non-true RNG sources are given that can be used with the proposed concept, e.g., integrated within various devices.

[0083] For example, two clocks (e.g., a phase-locked loop and an oscillator) can be operated and the clock drift between the two clocks can be used as an entropy source (e.g., 1000 cycles, 0.05% drift...).

[0084] Figure 4a A schematic diagram showing an example where an analog noise source is used as an entropy source is presented. The output of the analog noise source is digitized to provide a digital noise source. The digitized output (i.e., the digital noise source) can be further conditioned. A health test can be performed on the digitized output.

[0085] Figure 4b A schematic diagram showing an example of a physical noise source is presented. In Figure 4b , two sequential combinations of inverters operating at different clock frequencies are fed into a black box at a sampling rate different from the two clock frequencies. The black box processes the output of the two sequential combinations of inverters to provide raw random data.

[0086] Figure 4c A schematic diagram showing an example of a non-physical noise source is presented. In Figure 4c 's non-physical noise source, random inputs such as hard disk access, keyboard input, or mouse input are used as an entropy pool, e.g., in the form of or in combination with interrupt request noise to provide raw data.

[0087] relate to the proposed concept or one or more examples described above or below (e.g., Figures 1a to 2b ) that mention more details and aspects of moving target defense. Moving target defense may include one or more additional optional features corresponding to one or more aspects of the proposed concept or one or more examples described above or below.

[0088] In the following, some examples of the proposed concept are given:

[0089] One example (e.g., Example 1) relates to an apparatus (10, 20) for a computer system, the apparatus including memory circuits (16, 26), machine-readable instructions, and processor circuits (14, 24), the processor circuits being configured to execute the machine-readable instructions to: determine different canary values for respective different threads of a program, and start the threads of the program, wherein the determined canary values are used as stack canaries for the threads of the program. For example, the processor circuits may execute the machine-readable instructions to, for each start of a thread of the program, obtain a canary value, wherein the canary value obtained for the thread of the program is different from the previously used canary value of each thread of the program in at least 20% of the starts of the thread of the program, and use the obtained canary value as the stack canary for the thread of the program.

[0090] Another example (e.g., Example 2) relates to the previous example (e.g., Example 1) or any other example, and further includes that the program is part of the firmware of the computer system, the firmware using a main loop during operation, wherein, for subsequent iterations of the main loop, different canary values are determined and used as stack canaries.

[0091] Another example (e.g., Example 3) relates to the previous example (e.g., one of Example 1 or 2) or any other example, and further includes that the program is a user space application, wherein different threads of the program are started with different canary values as stack canaries.

[0092] Another example (e.g., Example 4) relates to the previous example (e.g., Example 3) or any other example, and further includes that the different canary values are based on different initial canary values and / or based on different starting seeds.

[0093] Another example (e.g., Example 5) relates to the previous example (e.g., one of Example 1 to 4) or any other example, and further includes that the processor circuits execute the machine-readable instructions to: determine an initial canary value, and iteratively modify the canary value to determine the different canary values.

[0094] Another example (e.g., Example 6) relates to a previous example (e.g., Example 5) or any other example, and further includes the processor circuit executing the machine-readable instructions to: for each modification of the canary value, obtain a random value from a source of randomness, and use the random value to modify the canary value.

[0095] Another example (e.g., Example 7) relates to a previous example (e.g., Example 6) or any other example, and further includes the processor circuit executing the machine-readable instructions to: based on the random value, select one or more bits of the canary value to be flipped, and flip the selected bits to modify the canary value.

[0096] Another example (e.g., Example 8) relates to a previous example (e.g., one of Example 6 or 7) or any other example, and further includes the processor circuit executing the machine-readable instructions to: obtain the random value from a non-true random value generator.

[0097] Another example (e.g., Example 9) relates to a previous example (e.g., Example 8) or any other example, and further includes the non-true random value generator being based on the clock drift between two clocks.

[0098] Another example (e.g., Example 10) relates to a previous example (e.g., one of Example 8 or 9) or any other example, and further includes the non-true random value generator being based on analog noise.

[0099] Another example (e.g., Example 11) relates to a previous example (e.g., one of Example 8 to 10) or any other example, and further includes the non-true random value generator being based on a physical noise source.

[0100] Another example (e.g., Example 12) relates to a previous example (e.g., one of Example 8 to 11) or any other example, and further includes the non-true random value generator being based on a non-physical noise source that is based on the operation of the computer system.

[0101] Another example (e.g., Example 13) relates to a previous example (e.g., one of Example 8 to 12) or any other example, and further includes the non-true random value generator being based on multiple sources of randomness.

[0102] Another example (e.g., Example 14) relates to a previous example (e.g., one of Example 6 to 13) or any other example, and further includes the processor circuit executing the machine-readable instructions to: obtain the random value from a source of randomness that can provide the random value within a predefined maximum time interval.

[0103] Another example (e.g., Example 15) relates to a previous example (e.g., one of Examples 5 to 14) or any other example, and further includes the processor circuit executing the machine-readable instructions to: use a true random number generator to determine the initial canary value.

[0104] Another example (e.g., Example 16) relates to a previous example (e.g., one of Examples 5 to 15) or any other example, and further includes the processor circuit executing the machine-readable instructions to: use a non-true random number generator to determine the initial canary value.

[0105] One example (e.g., Example 17) relates to a device (10, 20) for a computer system, the device including a memory circuit (16, 26), machine-readable instructions, and a processor circuit (14, 24), the processor circuit being configured to execute the machine-readable instructions to: determine an initial random value, iteratively modify the initial random value based on a second random value obtained from a randomness source, and use the iteratively modified random value for a task that requires a random value.

[0106] Another example (e.g., Example 18) relates to a previous example (e.g., Example 17) or any other example, and further includes the iteratively modified random value being used as a stack canary for a thread of a program.

[0107] Another example (e.g., Example 19) relates to a previous example (e.g., Example 18) or any other example, and further includes different iteratively modified random values being used as stack canaries for different threads of the program or threads of different programs.

[0108] Another example (e.g., Example 20) relates to a previous example (e.g., one of Examples 17 to 19) or any other example, and further includes the iteratively modified random value being used for address space layout randomization.

[0109] Another example (e.g., Example 21) relates to a previous example (e.g., one of Examples 17 to 20) or any other example, and further includes the processor circuit executing the machine-readable instructions to: based on the second random value obtained from the randomness source, select one or more bits of the random value being modified and flip the selected bits of the random value.

[0110] Another example (e.g., Example 22) relates to a previous example (e.g., one of Examples 17 to 21) or any other example, and further includes the processor circuit executing the machine-readable instructions to: obtain the second random value from a non-true random value generator.

[0111] Another example (e.g., Example 23) relates to a previous example (e.g., Example 22) or any other example, and further includes that the pseudo-random value generator is based on the clock drift between two clocks.

[0112] Another example (e.g., Example 24) relates to a previous example (e.g., one of Examples 22 or 23) or any other example, and further includes that the pseudo-random value generator is based on analog noise.

[0113] Another example (e.g., Example 25) relates to a previous example (e.g., one of Examples 22 to 24) or any other example, and further includes that the pseudo-random value generator is based on a physical noise source.

[0114] Another example (e.g., Example 26) relates to a previous example (e.g., one of Examples 22 to 25) or any other example, and further includes that the pseudo-random value generator is based on a non-physical noise source, and the non-physical noise source is based on the operation of the computer system.

[0115] Another example (e.g., Example 27) relates to a previous example (e.g., one of Examples 22 to 26) or any other example, and further includes that the pseudo-random value generator is based on multiple randomness sources.

[0116] Another example (e.g., Example 28) relates to a previous example (e.g., one of Examples 17 to 27) or any other example, and further includes that the processor circuit executes the machine-readable instructions to: obtain the second random value from a randomness source, and the randomness source can provide the random value within a predefined maximum time interval.

[0117] An example (e.g., Example 29) relates to a method for a computer system, the method includes: determining (110) different canary values for respective different threads of a program, and starting (120) the threads of the program, and the determined canary values are used as stack canaries for the threads of the program. For example, the method may include, for each start of a thread of the program, obtaining a canary value, where the canary value obtained for the thread of the program is different from the previously used canary values of the respective threads of the program in at least 20% of the starts of the threads of the program, and using the obtained canary value as a stack canary for the thread of the program.

[0118] Another example (e.g., Example 30) relates to a previous example (e.g., one of Examples 29 to 32) or any other example, and further includes that the method includes determining (112) an initial canary value, and iteratively modifying (116) the canary value to determine the different canary values.

[0119] Another example (e.g., Example 31) relates to a previous example (e.g., Example 33) or any other example, and further includes that the method includes, for each modification of the canary value, obtaining (114) a random value from a source of randomness and using the random value to modify (116) the canary value.

[0120] Another example (e.g., Example 32) relates to a previous example (e.g., Example 34) or any other example, and further includes that the method includes selecting, based on the random value, one or more bits of the canary value to be flipped and flipping the selected bits to modify the canary value.

[0121] One example (e.g., Example 33) relates to a method (10, 20) for a computer system, the method including: determining (210) an initial random value, iteratively modifying (230) the initial random value based on a second random value obtained (220) from a source of randomness, and using the iteratively modified random value for (240) a task that requires a random value.

[0122] Another example (e.g., Example 34) relates to a previous example (e.g., one of Examples 45 to 48) or any other example, and further includes that the method includes: selecting (232) one or more bits of the random value being modified to be flipped based on the second random value obtained from the source of randomness, and flipping (234) the bits of the selected random value.

[0123] One example (e.g., Example 35) relates to a device (10, 20) for a computer system, the device including a processor circuit (14, 24) configured to: determine different canary values for respective different threads of a program and start the threads of the program, wherein the determined canary values are used as stack canaries for the threads of the program. For example, the processor circuit may obtain a canary value for each start of a thread of the program, wherein the canary value obtained for the thread of the program is different from the previously used canary values of the respective threads of the program in at least 20% of the starts of the threads of the program, and use the obtained canary value as a stack canary for the thread of the program.

[0124] One example (e.g., Example 36) relates to a device (10, 20) for a computer system, the device including a processor circuit (14, 24) configured to: determine an initial random value, iteratively modify the initial random value based on a second random value obtained from a source of randomness, and use the iteratively modified random value for a task that requires a random value.

[0125] One example (e.g., Example 37) relates to an apparatus (10, 20) for a computer system, the apparatus including means for processing (14, 24) for: determining different canary values for respective different threads of a program and starting the threads of the program, wherein the determined canary values are used as stack canaries for the threads of the program. For example, the means for processing can obtain a canary value for each start of a thread of a program, wherein the canary value obtained for the thread of the program is different from the previously used canary value of each thread of the program in at least 20% of the starts of the threads of the program, and using the obtained canary value as a stack canary for the thread of the program.

[0126] One example (e.g., Example 38) relates to an apparatus (10, 20) for a computer system, the apparatus including means for processing (14, 24) for determining an initial random value, iteratively modifying the initial random value based on a second random value obtained from a randomness source, and using the iteratively modified random value for a task that requires a random value.

[0127] Another example (e.g., Example 39) relates to a non-transitory computer-readable medium including program code that, when executed on a processor, computer, or programmable hardware component, causes the processor, computer, or programmable hardware component to perform at least one of the methods described in one of Examples 29 to 32 (or according to any other example) and the methods described in one of Examples 33 or 34 (or according to any other example).

[0128] Another example (e.g., Example 40) relates to a non-transitory machine-readable storage medium including program code that, when executed, causes a machine to perform the method described in one of Examples 29 to 32 (or according to any other example) and / or the method described in one of Examples 33 or 34 (or according to any other example).

[0129] Another example (e.g., Example 41) relates to a computer program having program code for, when the computer program is executed on a computer, processor, or programmable hardware component, performing at least one of the methods described in one of Examples 29 to 32 (or according to any other example) and the methods described in one of Examples 33 or 34 (or according to any other example).

[0130] Another example (e.g., Example 42) relates to a machine-readable storage device including machine-readable instructions that, when executed, implement the method claimed in any of the preceding claims or implement the apparatus claimed in any of the preceding claims.

[0131] Aspects and features described in connection with a particular one of the previous examples can also be combined with one or more additional examples to replace the same or similar features of the additional example or to introduce features additionally into the additional example.

[0132] The examples can also be or can relate to a (computer) program which includes program code to perform one or more of the above methods when the program is executed on a computer, a processor or other programmable hardware component. Thus, the steps, operations or processes of the different methods described above can also be performed by a programmed computer, processor or other programmable hardware component. The examples can also cover program storage devices, such as digital data storage media, which are machine-readable, processor-readable or computer-readable and encode and / or contain machine-executable, processor-executable or computer-executable instructions and programs. The program storage devices can include or can be, for example, digital storage devices, magnetic storage media such as disks and tapes, hard disk drives, or optically readable digital data storage media. Other examples can also include a computer, a processor, a control unit, a (field) programmable logic array ((F)PLA), a (field) programmable gate array ((F)PGA), a graphics processor unit (GPU), an application-specific integrated circuit (ASIC), an integrated circuit (IC) or a system-on-a-chip (SoC) system programmed to perform the steps of the above methods.

[0133] It should also be understood that the disclosure of several steps, processes, operations or functions in the specification or claims should not be construed as implying that these operations must follow the described order, unless explicitly stated in an individual case or necessary for technical reasons. Thus, the previous description does not limit the execution of several steps or functions to a certain order. In addition, in other examples, a single step, function, process or operation can include and / or be decomposed into several sub-steps, sub-functions, sub-processes or sub-operations.

[0134] If aspects are described in connection with a device or system, those aspects should also be understood as a description of the corresponding method. For example, the block, device, or functional aspects of the device or system may correspond to features of the corresponding method, such as method steps. Thus, aspects described in connection with a method should also be understood as a description of the corresponding blocks, corresponding elements, properties, or functional features of the corresponding device or corresponding system.

[0135] As used herein, the term "module" refers to logic that can be implemented in a hardware component or device, software or firmware running on a processing unit, or a combination thereof, to perform one or more operations in accordance with the present disclosure. Software and firmware can be embodied as instructions and / or data stored on a non-transitory computer-readable storage medium. As used herein, the term "circuit" can include, alone or in any combination, non-programmable (hardwired) circuits, programmable circuits (such as processing units), state machine circuits, and / or firmware that stores instructions executable by the programmable circuit. The modules described herein can be collectively or individually embodied as a circuit forming part of a computing system. Thus, any module can be implemented as a circuit. A computing system that is said to be programmed to perform a method can be programmed to perform the method via software, hardware, firmware, or a combination thereof.

[0136] Any disclosed method (or a part thereof) can be implemented as computer-executable instructions or a computer program product. Such instructions can cause a computing system or one or more processing units capable of executing computer-executable instructions to perform any disclosed method. As used herein, the term "computer" refers to any computing system or device described or referred to herein. Thus, the term "computer-executable instructions" refers to instructions that can be executed by any computing system or device described or referred to herein.

[0137] Computer-executable instructions can be, for example, part of an operating system of a computing system, an application stored locally on the computing system, or a remote application accessible to the computing system (e.g., accessed via a web browser). Any method described herein can be performed by computer-executable instructions executed by a single computing system or by one or more networked computing systems operating in a network environment. Computer-executable instructions and updates to the computer-executable instructions can be downloaded to the computing system from a remote server.

[0138] In addition, it is to be understood that the implementation of the disclosed technology is not limited to any specific computer language or program. For example, the disclosed technology can be implemented by software written in C++, C#, Java, Perl, Python, JavaScript, Adobe Flash, C#, assembly language, or any other programming language. Similarly, the disclosed technology is not limited to any specific computer system or any specific type of hardware.

[0139] In addition, any software-based examples (such as those including computer-executable instructions for causing a computer to perform any of the disclosed methods) can be uploaded, downloaded, or remotely accessed via appropriate communication means. Such appropriate communication means include, for example, the Internet, the World Wide Web, an intranet, cables (including fiber optic cables), magnetic communication, electromagnetic communication (including RF, microwave, ultrasonic, and infrared communication), electronic communication, or other such communication means.

[0140] The disclosed methods, apparatuses, and systems should not be construed as limiting in any way. Instead, this disclosure is directed to all novel and non-obvious features and aspects of the various disclosed examples, whether alone or in various combinations and sub-combinations with each other. The disclosed methods, apparatuses, and systems are not limited to any particular aspect or feature or combination thereof, and the disclosed examples do not require that any one or more particular advantages must exist or that any one or more particular problems must be solved.

[0141] The operational theories, scientific principles, or other theoretical descriptions presented herein in reference to the disclosed apparatuses or methods are provided for better understanding and are not intended to be limiting in scope. The apparatuses and methods in the appended claims are not limited to those that operate in the manner described by such operational theories.

[0142] The appended claims are hereby incorporated into the detailed description, where each claim can stand alone as a separate example. It should also be noted that although in the claims, dependent claims refer to specific combinations with one or more other claims, other examples can also include combinations of that dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby expressly contemplated, unless a particular combination is stated to be undesirable in an individual case. In addition, the features of one claim should also be included for any other independent claim, even if that claim is not directly defined as being dependent on that other independent claim.

Claims

1. A device for a computer system, the device comprising: memory circuitry, machine-readable instructions, and processor circuitry, the processor being operable to execute the machine-readable instructions to: determining different canary values ​​for corresponding different threads of the program; and A thread of the program is started, wherein the determined canary value is used as a stack canary for the thread of the program.

2. The device according to claim 1, wherein: The program is part of firmware of the computer system, the firmware using a main loop during operation, wherein for subsequent iterations of the main loop, different canary values ​​are determined and used as stack canaries.

3. The device according to claim 1, wherein: The program is a user space application, wherein different threads of the program are started with different canary values ​​as stack canaries.

4. The device according to claim 3, wherein: The different canary values ​​are based on different initial canary values ​​and / or based on different starting seeds.

5. The device according to claim 1, wherein: The processor circuit executes the machine-readable instructions to determine an initial canary value, and iteratively modify the canary value to determine the different canary value.

6. The device according to claim 5, wherein: The processor circuit executes the machine-readable instructions to: for modification of the canary value, obtain a random value from a source of randomness, and modify the canary value using the random value.

7. The device according to claim 6, wherein: The processor circuit executes the machine-readable instructions to: select one or more bits of the canary value to flip based on the random value, and flip the selected bits to modify the canary value.

8. The device according to claim 6, wherein: The processor circuit executes the machine-readable instructions to obtain the random value from a non-true random value generator.

9. The device according to claim 8, wherein: The non-true random value generator is based on a clock drift between two clocks.

10. The device according to claim 8, wherein: The non-true random value generator is based on simulated noise.

11. The device according to claim 8, wherein: The non-true random value generator is based on a physical noise source.

12. The device according to claim 8, wherein: The non-true random value generator is based on a non-physical noise source that is based on the operation of the computer system.

13. The device according to claim 8, wherein: The non-true random value generator is based on multiple sources of randomness.

14. The device according to claim 6, wherein: The processor circuit executes the machine-readable instructions to obtain the random value from a source of randomness capable of providing the random value within a predefined maximum time interval.

15. The device according to claim 5, wherein: The processor circuit executes the machine-readable instructions to determine the initial canary value using a true random number generator.

16. The device according to claim 5, wherein: The processor circuit executes the machine-readable instructions to determine the initial canary value using a non-true random number generator.

17. A method for a computer system, the method comprising: for each launch of a thread of a program, obtaining a canary value, wherein the canary value obtained for the thread of the program is different from a previously used canary value for each thread of the program in at least 20% of the launches of the thread of the program; and The thread of the program is started, wherein the obtained canary value is used as a stack canary for the thread of the program.

18. The method according to claim 17, wherein: The method includes determining an initial canary value, and iteratively modifying the canary value to obtain the different canary value.

19. The method according to claim 18, wherein: The method includes, for modification of the canary value, obtaining a random value from a randomness source, and modifying the canary value using the random value.

20. A non-transitory computer readable medium comprising program code, which, when executed on a processor, a computer or a programmable hardware component, causes the processor, the computer or the programmable hardware component to: determining different canary values ​​for corresponding different threads of the program; and A thread of the program is started, wherein the determined canary value is used as a stack canary for the thread of the program.

21. A computer program having a program code for executing the method according to any one of claims 17 to 19.