Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

15 results about "Runtime verification" patented technology

Runtime verification is a computing system analysis and execution approach based on extracting information from a running system and using it to detect and possibly react to observed behaviors satisfying or violating certain properties . Some very particular properties, such as datarace and deadlock freedom, are typically desired to be satisfied by all systems and may be best implemented algorithmically. Other properties can be more conveniently captured as formal specifications. Runtime verification specifications are typically expressed in trace predicate formalisms, such as finite state machines, regular expressions, context-free patterns, linear temporal logics, etc., or extensions of these. This allows for a less ad-hoc approach than normal testing. However, any mechanism for monitoring an executing system is considered runtime verification, including verifying against test oracles and reference implementations. When formal requirements specifications are provided, monitors are synthesized from them and infused within the system by means of instrumentation. Runtime verification can be used for many purposes, such as security or safety policy monitoring, debugging, testing, verification, validation, profiling, fault protection, behavior modification (e.g., recovery), etc. Runtime verification avoids the complexity of traditional formal verification techniques, such as model checking and theorem proving, by analyzing only one or a few execution traces and by working directly with the actual system, thus scaling up relatively well and giving more confidence in the results of the analysis (because it avoids the tedious and error-prone step of formally modelling the system), at the expense of less coverage. Moreover, through its reflective capabilities runtime verification can be made an integral part of the target system, monitoring and guiding its execution during deployment.

Code auditing method and system

The invention relates to the technical field of code auditing, and discloses a code auditing method and system, and the method comprises the steps: based on code data uploaded by a user, analyzing an initial risk point fixed point, carrying out the operation simulation based on an initial risk positioning point, generating simulation execution path data, carrying out the potential path risk simulation, obtaining an extended risk point set, and carrying out the code auditing. Performing verification during actual operation on the extended risk point set, generating a dynamic verification result, performing cross comparison on the result and the initial risk positioning point set, generating a verified risk vulnerability list, performing vulnerability association analysis in combination with service logic and data flow context, generating associated vulnerability data, and performing code repair. According to the code auditing method and the code auditing device, the code auditing efficiency and the code auditing accuracy can be improved.
Owner:BEIJING QIUFENG CODE TECHNOLOGY CO LTD

A neural machine translation internet of things remote attestation method for data flow attacks

The application discloses a neural machine translation Internet of Things remote proof method for data flow attacks, which comprises an offline stage and a runtime verification stage. In the offline stage, a verifier and a prover first complete the negotiation of a symmetric key for subsequent remote proof, and at the same time, complete static plugging for a target program. A program control flow dataset is pre-constructed through fuzzy testing, a neural machine translation model is trained to establish the mapping of program input to an execution path, and a control flow graph is embedded to provide a structured prior for decoder attention. In the runtime verification stage, the verifier initiates a proof challenge to the prover, the prover provides the program input and the control flow path of the last execution, the verifier predicts a benign path from the program input by the neural machine translation model, and the difference between the benign predicted path and the actual path is used to judge the legitimacy of the prover. The application realizes accurate modeling of the program execution path, and shows effective detection capability for the abnormal path triggered by malicious input containing real vulnerabilities, and a good balance is achieved between detection coverage and running overhead.
Owner:NANJING UNIV OF SCI & TECH

A method and system for installing and running software packages based on digital signatures

The application relates to a software package installation and running control method and system based on digital signature, which comprises the following steps: S100, obtaining the unique identification of a target machine for software package installation and running; S200, submitting a software package use application by a terminal user; S300, auditing the application information by a server, and after passing, signing the software package and program files in the software package to obtain a signed software package and delivering the signed software package to the terminal user; S400, installing the signed software package by the terminal user, executing an installation verification process, and allowing installation after passing; and S500, executing a running verification process when the program runs after installation, and allowing execution after passing. The main purpose of the application is to bind the software package digital signature and the target machine, set a signature validity period, verify the software signature and the signature validity period during software package installation and running, and only the software package within the target machine binding range, the signature validity period and the signature verification can be installed and run.
Owner:KYLIN CORP

Deep learning operator vulnerability detection method based on constraint capture and refinement

A deep learning operator vulnerability detection method based on constraint capture and refinement belongs to the technical field of software security, focuses on automatic modeling and utilization of operator input constraint, and comprises the following steps: firstly, capturing effective input data transmitted from a Python API (Application Program Interface) front-end interface to operator implementation to generate an initial input constraint hypothesis; the input constraint is dynamically refined in combination with a runtime verification mechanism, so that a more accurate constraint model is obtained; on the basis, diversified and high-quality test input is automatically generated, and operator exploration is carried out by utilizing the test input so as to carry out vulnerability mining. The method can effectively improve the effectiveness and coverage of the test sample, remarkably improves the operator vulnerability detection efficiency, is suitable for various mainstream deep learning frameworks, and has good popularization and application values.
Owner:NANKAI UNIV +1

A control logic runtime verification and security recovery method for embedded real-time systems

PendingCN122308328AOperational systemSafety property
This invention discloses a method for runtime verification and safety recovery of control logic in embedded real-time systems, relating to the fields of embedded real-time control and functional safety technology. This invention constructs an independent safety monitoring layer outside the operating system kernel, defines runtime contracts containing safety invariance and timing logic constraints for critical control tasks, and performs real-time contract verification through periodic data collection. When a contract violation is detected, a layered recovery mechanism is initiated according to fault levels, including output clamping, task rollback and restart, and algorithm degradation switching. A memory protection unit is used to achieve spatiotemporal isolation protection for tasks. This invention achieves non-intrusive real-time monitoring and hierarchical safety recovery of critical control tasks, improving the functional safety and operational stability of embedded real-time systems. The monitoring overhead is controllable and does not affect real-time system scheduling, making it widely applicable to safety-critical scenarios such as vehicle control and industrial robots.
Owner:CHINA YANGTZE POWER

Software package installation and operation control method and system based on digital signature

The invention relates to a digital signature-based software package installation and operation control method and system. The method comprises the following steps: S100, obtaining a unique identifier of a target machine for software package installation and operation; s200, submitting a software package use application by a terminal user; s300, the server side audits the application information, after the application information passes the auditing, signature processing is carried out on the software package and the program file in the software package, and a signed software package is obtained and issued to the terminal user; s400, the terminal user installs the signed software package and executes an installation verification process, and if the installation verification process passes, installation is allowed; and S500, when the installed program runs, executing the running verification process, and if the running verification process passes, allowing the running verification process to be executed. The main purpose of the invention is to bind a software package digital signature with a target machine, set a signature validity period, verify a software signature and the signature validity period when the software package is installed and operated, and only the software package which is within the binding range of the target machine and within the signature validity period and passes the signature verification can be installed and operated.
Owner:KYLIN CORP

System and method for validating a signature of a virtual workload image in runtime

A method and system for deploying signed software images in a computing environment is presented. The method includes selecting a signed software image for deployment in a computing environment; accessing a public cryptographic key corresponding to a private cryptographic key, wherein the private cryptographic key is utilized in signing software images; configuring an admission controller of a software container cluster deployed in the computing environment to verify the signed software image utilizing the public cryptographic key; configuring the admission controller to deploy the signed software image in the software container cluster in response to verifying the signed software image with the public cryptographic key; and configuring an admission controller to deny deployment of the signed software image, in response to determining that the signed software image is not verified with the public cryptographic key.
Owner:WIZ INC

Virtual power plant optimization scheduling method based on blockchain system and related device

ActiveCN116108946BForecastingArtificial lifeRuntime verificationVirtual power plant
A virtual power plant optimization scheduling method based on a blockchain system and related devices, including the following steps: step 1, a distributed particle swarm optimization algorithm based on a blockchain is proposed; step 2, the consensus algorithm used in the process of verifying the block by the distributed particle swarm optimization algorithm based on the blockchain in step 1 is improved, and an optimized computing proof of work consensus algorithm is proposed; step 3, the algorithm proposed in steps 1 and 2 is used to improve the blockchain system, and an optimized computing blockchain system is proposed to match the structure and operation requirements of the virtual power plant; step 4, an OCB-VPP model is established based on the optimized computing blockchain system OCB proposed in step 3; step 5, a scheduling strategy is established according to the characteristics of the OCB-VPP model proposed in step 4. The present application can effectively improve the VPP scheduling efficiency and information security level, reduce the VPP operation cost, improve the renewable energy consumption level, and reduce carbon dioxide emissions.
Owner:XINJIANG UNIVERSITY

A database-based LLVM bitcode management method, device and medium

ActiveCN122432116BProgramming languageRuntime verification
The application discloses a database-based LLVM bitcode management method, device and medium, and belongs to the database field, and solves the problem that the intermediate code (that is, bitcode) product and the shared library, LLVM version and server ABI lack unified life cycle management when PostgreSQL is built by Meson and enabled with LLVM / JIT. The method comprises the following steps: acquiring a dependency relationship from a Meson build graph; generating metadata for each intermediate code compilation unit; comparing the current metadata with historical metadata to determine a unit to be rebuilt; generating an intermediate code file and incrementally updating an index file; and verifying the consistency of the metadata, the intermediate code file, the index file, the shared library, the LLVM version and the server ABI in the installation stage. The incremental construction, version binding and runtime verification of the intermediate code product are realized, and the system reliability and construction efficiency are improved.
Owner:HIGHGO SOFTWARE

OTA service communication method for forcing TLS protocol configuration and binding session token

The invention relates to an OTA service communication method for forcing a TLS protocol to configure and bind a session token, and the method comprises the steps: building a configuration file template based on the constraint condition of the TLS protocol, and recording the content of the configuration file template: a server configuration instruction of the TLS protocol; the configuration file template is written into an operation configuration file of a server of OTA service communication, and the server operates the operation configuration file to generate a TLS channel for performing OTA service communication with the user; the server receives a login instruction and a request session instruction sent by a user based on the TLS channel, the login instruction is bound with a session token, and the server verifies the request session instruction based on the session token; the session token is generated based on the information of the user, the environmental information, and the random number. Transport layer security risks such as TLS protocol degradation and weak cryptographic algorithm use are completely eradicated; the session token is prevented from being attacked by application layers such as eavesdropping, tampering and remote multiplexing; automatic deployment of security policies, verification during operation and abnormity self-repairing are realized, and the manual operation and maintenance cost is reduced.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

Safety verification method of BSW layer calibration variable under AUTOSAR CP platform and control unit thereof

The invention relates to a safety verification method for a BSW layer calibration variable under an AUTOSAR CP platform, and belongs to the field of automobile electronic control unit (ECU) embedded software safety. According to the method, an independent real-time verification module is arranged on an ECU end basic software layer (BSW), and dual verification is carried out on a target address and a data length before an XCP calibration instruction is executed. And the verification module automatically generates a runtime verification table based on the compiling chain information to realize absolute synchronization with a software version. If the verification is passed, releasing the instruction; and if the verification fails, discarding the instruction, returning an error code and recording an error log. According to the method, the problem of memory cross-border tampering caused by A2L file errors, communication interference or version inconsistency is effectively solved, the safety and reliability of the calibration process are improved, and the method is suitable for various calibration scenes such as XCP on CAN and XCP on ETH.
Owner:DONGFENG ELECTRONICS TECH

Security code generation method and device, computer device, and storage medium

This application discloses a method, apparatus, computer device, and storage medium for generating secure code. In financial business scenarios or medical data management scenarios, a target code generation model processes and generates code from generated instructions. During the training of the target code generation model, no differential privacy noise is injected. The training data comes from the first synthesized code generated by the model that has learned the syntax structure of the private domain source code. Differential privacy noise is injected during model learning. The first synthesized code that passes verification is selected as the training data. Verification items include runtime verification and semantic consistency verification. In this application, the constraints on the code structure are explicitly strengthened during differential privacy training, effectively offsetting the damage to code syntax caused by privacy noise. A dual filtering mechanism of verification and semantic verification is used to perform verification on synthesized data without privacy risks, ensuring code reliability. This solves the problem of incompatibility between security and usability in generated code.
Owner:PING AN TECH (SHENZHEN) CO LTD

System and method for validating a signature of a virtual workload image in runtime

In some aspects, a device includes selecting a signed software image for deployment in a computing environment, the software image signed utilizing a private cryptographic key of an asymmetrical cryptography scheme. Also, the device may include accessing a public cryptographic key corresponding to the private cryptographic key. Furthermore, the device may include configuring an admission controller of a software container cluster deployed in the computing environment to verify the signed software image utilizing the public cryptographic key. In addition, the device may include deploying the signed software image in the software container cluster in response to verifying the signed software image. Moreover, the device may include denying deployment of the signed software image, in response to determining that the signed software image is signed with a key which is not the private cryptographic key.
Owner:WIZ INC

Docker-based internet of things program runtime verification method

ActiveCN117034258BProgram validationTrusted Platform Module
The application discloses a kind of based on Docker's Internet of Things program runtime verification method, it is related to program verification technical field, the method includes: based on integrity measurement architecture, container image is hashed and is measured and is written into measurement list;The measurement value in the measurement list corresponding to target container is stored to the vPCR module corresponding to target container;vPCR module is extended into trusted platform module;The identity information and state information of the host platform where target container is located are verified, and the container is successfully started if the verification is passed;According to container ID, target container inner process pid and acquisition time, the memory binary information of corresponding process runtime is acquired, and memory event is constructed;The memory event corresponding to the verification of business flow on Internet of Things program of the memory event on the state machine end received by inter-state flow is realized. The application improves the security of Internet of Things program running.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Safety management monitoring system for port vehicle traffic management based on big data

PendingCN121982936AMarine craft traffic controlRuntime verificationData acquisition
The invention relates to the technical field of port automation, and discloses a safety management monitoring system for port vehicle traffic management based on big data. Comprising a data acquisition module, an event extraction module, an event system modeling module, a safety specification modeling module, a controllable observable event boundary identification module, a specification projection module, a supervision permission control module and a runtime verification and control execution module. Event modeling is carried out on multi-source traffic data, a safety specification is projected to a controllable and observable event subset, an executable safety specification and a corresponding permission control strategy are constructed, and specification consistency verification and dynamic permission control of traffic control events such as gate release, road section entry and intersection pass are realized. By introducing the controllable and observable event boundary recognition module and the standard projection module, the problem of control mismatch caused by direct participation of uncontrollable events or unobservable events in safety judgment is avoided.
Owner:ZHANJIANG PORT (GRP) CO LTD