Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

24 results about "Runtime verification" patented technology

Runtime verification is a computing system analysis and execution approach based on extracting information from a running system and using it to detect and possibly react to observed behaviors satisfying or violating certain properties . Some very particular properties, such as datarace and deadlock freedom, are typically desired to be satisfied by all systems and may be best implemented algorithmically. Other properties can be more conveniently captured as formal specifications. Runtime verification specifications are typically expressed in trace predicate formalisms, such as finite state machines, regular expressions, context-free patterns, linear temporal logics, etc., or extensions of these. This allows for a less ad-hoc approach than normal testing. However, any mechanism for monitoring an executing system is considered runtime verification, including verifying against test oracles and reference implementations. When formal requirements specifications are provided, monitors are synthesized from them and infused within the system by means of instrumentation. Runtime verification can be used for many purposes, such as security or safety policy monitoring, debugging, testing, verification, validation, profiling, fault protection, behavior modification (e.g., recovery), etc. Runtime verification avoids the complexity of traditional formal verification techniques, such as model checking and theorem proving, by analyzing only one or a few execution traces and by working directly with the actual system, thus scaling up relatively well and giving more confidence in the results of the analysis (because it avoids the tedious and error-prone step of formally modelling the system), at the expense of less coverage. Moreover, through its reflective capabilities runtime verification can be made an integral part of the target system, monitoring and guiding its execution during deployment.

Code auditing method and system

The invention relates to the technical field of code auditing, and discloses a code auditing method and system, and the method comprises the steps: based on code data uploaded by a user, analyzing an initial risk point fixed point, carrying out the operation simulation based on an initial risk positioning point, generating simulation execution path data, carrying out the potential path risk simulation, obtaining an extended risk point set, and carrying out the code auditing. Performing verification during actual operation on the extended risk point set, generating a dynamic verification result, performing cross comparison on the result and the initial risk positioning point set, generating a verified risk vulnerability list, performing vulnerability association analysis in combination with service logic and data flow context, generating associated vulnerability data, and performing code repair. According to the code auditing method and the code auditing device, the code auditing efficiency and the code auditing accuracy can be improved.
Owner:BEIJING QIUFENG CODE TECHNOLOGY CO LTD

A method for preventing repeated use of an application system database

ActiveCN114065279BDigital data protectionHospital serviceRuntime verification
The present invention discloses a scheme for preventing the reuse of application system databases, which includes the following steps: S1, generating a fingerprint file; S2, program startup verification; S3, configuring and binding fingerprints; S4, runtime verification. The step S1 includes the following sub-steps: A1, reading the machine code of the hospital server; A2, encrypting the server machine code and a random string to generate a fingerprint file; A3, when deploying the background program, it is necessary to manually place the fingerprint file in the program directory. Among them, the encryption method in the step A2 is a reversible algorithm, such as AE. In addition, the fingerprint file is used to decrypt the server machine code and the random string, and the random string is used as the database serial number. Through the settings of the corresponding system, the present invention can technically avoid the situation where implementers copy databases between projects, causing economic losses and adverse effects, standardize the on-site implementation steps, and reduce the error rate of projects.
Owner:CLP XIANGJIANG DATA SERVICE CO LTD

A neural machine translation internet of things remote attestation method for data flow attacks

The application discloses a neural machine translation Internet of Things remote proof method for data flow attacks, which comprises an offline stage and a runtime verification stage. In the offline stage, a verifier and a prover first complete the negotiation of a symmetric key for subsequent remote proof, and at the same time, complete static plugging for a target program. A program control flow dataset is pre-constructed through fuzzy testing, a neural machine translation model is trained to establish the mapping of program input to an execution path, and a control flow graph is embedded to provide a structured prior for decoder attention. In the runtime verification stage, the verifier initiates a proof challenge to the prover, the prover provides the program input and the control flow path of the last execution, the verifier predicts a benign path from the program input by the neural machine translation model, and the difference between the benign predicted path and the actual path is used to judge the legitimacy of the prover. The application realizes accurate modeling of the program execution path, and shows effective detection capability for the abnormal path triggered by malicious input containing real vulnerabilities, and a good balance is achieved between detection coverage and running overhead.
Owner:NANJING UNIV OF SCI & TECH

A method and system for installing and running software packages based on digital signatures

The application relates to a software package installation and running control method and system based on digital signature, which comprises the following steps: S100, obtaining the unique identification of a target machine for software package installation and running; S200, submitting a software package use application by a terminal user; S300, auditing the application information by a server, and after passing, signing the software package and program files in the software package to obtain a signed software package and delivering the signed software package to the terminal user; S400, installing the signed software package by the terminal user, executing an installation verification process, and allowing installation after passing; and S500, executing a running verification process when the program runs after installation, and allowing execution after passing. The main purpose of the application is to bind the software package digital signature and the target machine, set a signature validity period, verify the software signature and the signature validity period during software package installation and running, and only the software package within the target machine binding range, the signature validity period and the signature verification can be installed and run.
Owner:KYLIN CORP

Data security function verification system oriented to Internet of Things and based on data driving

The invention provides a data security function verification system based on data driving for the Internet of Things, and the system mainly comprises a security policy management module which is used for defining a variable name and a data security label mode, and a data security rule verification model; the security policy labeling AOP module is used for adding security labels for all variable names and data in the application program to be verified and analyzed, and the security labels are used as entry points of the aspect-oriented programming AOP data security verification aspect; the AOP section code module is used for generating a section-oriented programming AOP data security verification section code, and the AOP data security verification section code is configured to execute an enhanced logic of a data security rule verification model and a log record according to an activation state and a path of a security label; and the runtime verification module is used for executing the enhanced logic of the data security rule verification model and the log record by the AOP data security verification section code according to the activation state and the path of the security label during runtime so as to realize data security rule verification.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

Real-time threat monitoring and defending method and system for digital infrastructure

The invention relates to the technical field of computer network security, and discloses a digital infrastructure real-time threat monitoring and defending method and system.The method comprises the steps that a WASM module and a dynamic code module are segmented, codes are divided into a static segment, a performance key segment and a dynamic loading segment, and differential protection strategies are generated; a double-layer control flow protection system is constructed, and the security of function calling and returning is ensured in combination with a shadow stack technology and runtime verification; a hardware acceleration verification technology is utilized, verification is executed in parallel through a special core and a main application, and verification overhead is reduced; dynamic code isolation and authority control are realized, and the dynamically loaded code is prevented from executing border crossing operation and unauthorized access; and constructing a self-adaptive security control system, and dynamically adjusting a verification strategy according to the security sensitivity and the execution frequency of the code block. According to the method, comprehensive safety guarantee is provided with extremely low performance overhead, and the method is particularly suitable for key digital infrastructures with strict requirements for performance and safety.
Owner:ZHEJIANG COMM SERVICES

Deep learning operator vulnerability detection method based on constraint capture and refinement

A deep learning operator vulnerability detection method based on constraint capture and refinement belongs to the technical field of software security, focuses on automatic modeling and utilization of operator input constraint, and comprises the following steps: firstly, capturing effective input data transmitted from a Python API (Application Program Interface) front-end interface to operator implementation to generate an initial input constraint hypothesis; the input constraint is dynamically refined in combination with a runtime verification mechanism, so that a more accurate constraint model is obtained; on the basis, diversified and high-quality test input is automatically generated, and operator exploration is carried out by utilizing the test input so as to carry out vulnerability mining. The method can effectively improve the effectiveness and coverage of the test sample, remarkably improves the operator vulnerability detection efficiency, is suitable for various mainstream deep learning frameworks, and has good popularization and application values.
Owner:NANKAI UNIV +1

A control logic runtime verification and security recovery method for embedded real-time systems

This invention discloses a method for runtime verification and safety recovery of control logic in embedded real-time systems, relating to the fields of embedded real-time control and functional safety technology. This invention constructs an independent safety monitoring layer outside the operating system kernel, defines runtime contracts containing safety invariance and timing logic constraints for critical control tasks, and performs real-time contract verification through periodic data collection. When a contract violation is detected, a layered recovery mechanism is initiated according to fault levels, including output clamping, task rollback and restart, and algorithm degradation switching. A memory protection unit is used to achieve spatiotemporal isolation protection for tasks. This invention achieves non-intrusive real-time monitoring and hierarchical safety recovery of critical control tasks, improving the functional safety and operational stability of embedded real-time systems. The monitoring overhead is controllable and does not affect real-time system scheduling, making it widely applicable to safety-critical scenarios such as vehicle control and industrial robots.
Owner:CHINA YANGTZE POWER

Software package installation and operation control method and system based on digital signature

The invention relates to a digital signature-based software package installation and operation control method and system. The method comprises the following steps: S100, obtaining a unique identifier of a target machine for software package installation and operation; s200, submitting a software package use application by a terminal user; s300, the server side audits the application information, after the application information passes the auditing, signature processing is carried out on the software package and the program file in the software package, and a signed software package is obtained and issued to the terminal user; s400, the terminal user installs the signed software package and executes an installation verification process, and if the installation verification process passes, installation is allowed; and S500, when the installed program runs, executing the running verification process, and if the running verification process passes, allowing the running verification process to be executed. The main purpose of the invention is to bind a software package digital signature with a target machine, set a signature validity period, verify a software signature and the signature validity period when the software package is installed and operated, and only the software package which is within the binding range of the target machine and within the signature validity period and passes the signature verification can be installed and operated.
Owner:KYLIN CORP

System and method for validating a signature of a virtual workload image in runtime

A method and system for deploying signed software images in a computing environment is presented. The method includes selecting a signed software image for deployment in a computing environment; accessing a public cryptographic key corresponding to a private cryptographic key, wherein the private cryptographic key is utilized in signing software images; configuring an admission controller of a software container cluster deployed in the computing environment to verify the signed software image utilizing the public cryptographic key; configuring the admission controller to deploy the signed software image in the software container cluster in response to verifying the signed software image with the public cryptographic key; and configuring an admission controller to deny deployment of the signed software image, in response to determining that the signed software image is not verified with the public cryptographic key.
Owner:WIZ INC

Program authorization method, system and equipment based on confusion encryption program key and medium

The invention provides a program authorization method, system and device based on a confusion encryption program key and a medium, and belongs to the technical field of information security. An initial program key is generated through a random number generation algorithm; performing confusion processing on the initial program key by adopting a dynamic character string confusion technology to obtain a program key; performing encryption processing on the program key by using a block cipher algorithm; establishing a runtime verification mode comprising a decryption module and a verification module; and obtaining the decrypted original key based on the decryption module, executing feature verification and integrity verification of the original key by the verification module, and authorizing the program to run when a verification result meets a predefined security policy. And confusion and encryption processing is performed on the program key through a confusion technology and an encryption algorithm, so that the security of the program key is improved.
Owner:INSPUR GENERSOFT CO LTD

Virtual power plant optimization scheduling method based on blockchain system and related device

ActiveCN116108946BForecastingArtificial lifeRuntime verificationVirtual power plant
A virtual power plant optimization scheduling method based on a blockchain system and related devices, including the following steps: step 1, a distributed particle swarm optimization algorithm based on a blockchain is proposed; step 2, the consensus algorithm used in the process of verifying the block by the distributed particle swarm optimization algorithm based on the blockchain in step 1 is improved, and an optimized computing proof of work consensus algorithm is proposed; step 3, the algorithm proposed in steps 1 and 2 is used to improve the blockchain system, and an optimized computing blockchain system is proposed to match the structure and operation requirements of the virtual power plant; step 4, an OCB-VPP model is established based on the optimized computing blockchain system OCB proposed in step 3; step 5, a scheduling strategy is established according to the characteristics of the OCB-VPP model proposed in step 4. The present application can effectively improve the VPP scheduling efficiency and information security level, reduce the VPP operation cost, improve the renewable energy consumption level, and reduce carbon dioxide emissions.
Owner:XINJIANG UNIVERSITY

A method and system for real-time threat monitoring and defense of digital infrastructure

The present invention relates to the field of computer network security technology, and discloses a real-time threat monitoring and defense method and system for digital infrastructure, the method comprising: segmenting WASM modules and dynamic code modules, dividing the code into static segments, performance-critical segments, and dynamically loaded segments, and generating differentiated protection strategies; building a two-layer control flow protection system, combining shadow stack technology with runtime verification to ensure the security of function calls and returns; utilizing hardware accelerated verification technology to perform verification in parallel with the main application through a dedicated core to reduce verification overhead; achieving dynamic code isolation and permission control to prevent dynamically loaded code from performing out-of-bounds operations and unauthorized access; building an adaptive security control system to dynamically adjust the verification strategy according to the security sensitivity and execution frequency of the code block. The present invention provides comprehensive security protection with extremely low performance overhead, and is particularly suitable for critical digital infrastructures that have strict requirements on both performance and security.
Owner:ZHEJIANG COMM SERVICES

Large-scale program runtime verification method and device based on TRACE

PendingCN120540961AHardware monitoringPathPingRuntime verification
The invention discloses a TRACE-based large-scale program runtime verification method and device. The method comprises the following steps: analyzing and obtaining an atomic proposition in a to-be-verified property of a to-be-verified program; generating a test case for the to-be-verified program based on the symbolic execution mode, and starting to run the to-be-verified program as initial input; generating a runtime monitor of the to-be-verified program so as to record the position of the variable obtained by the atomic proposition and the actual assignment in a program execution log; obtaining a program state of the to-be-verified program according to the program execution log; the program state is converted into a TRACE path model; and verifying the to-be-verified property of the to-be-verified program by using the TRACE path model. Compared with an existing method, the method does not need to consider a complete program state space in single verification especially for a large-scale program, so that the verification efficiency is remarkably improved, and the method is directly realized based on a source program without complex abstract modeling work.
Owner:XIDIAN UNIV

A database-based LLVM bitcode management method, device and medium

ActiveCN122432116BProgramming languageRuntime verification
The application discloses a database-based LLVM bitcode management method, device and medium, and belongs to the database field, and solves the problem that the intermediate code (that is, bitcode) product and the shared library, LLVM version and server ABI lack unified life cycle management when PostgreSQL is built by Meson and enabled with LLVM / JIT. The method comprises the following steps: acquiring a dependency relationship from a Meson build graph; generating metadata for each intermediate code compilation unit; comparing the current metadata with historical metadata to determine a unit to be rebuilt; generating an intermediate code file and incrementally updating an index file; and verifying the consistency of the metadata, the intermediate code file, the index file, the shared library, the LLVM version and the server ABI in the installation stage. The incremental construction, version binding and runtime verification of the intermediate code product are realized, and the system reliability and construction efficiency are improved.
Owner:HIGHGO SOFTWARE

Modeling, Simulation, Formal Verification Method and Application for Micro-ROS Communication Middleware

The present invention discloses a method for modeling, simulation and formal verification of the Micro-ROS communication middleware. First, from the open-source code of the Micro-ROS communication middleware MicroXRCE-DDS, combined with the XRCE-DDS specification, each module included in the communication process, as well as the behaviors and functions of each module, are extracted to establish a timed automata model for each module. Then, using modeling and simulation tools, the abstract timed automata model is implemented, and combined with specific Micro XRCE-DDS communication application scenarios to complete the implementation and simulation of the model. According to the natural language description of the protocol part in the XRCE-DDS specification for the communication process, the key and important properties are abstracted, and a signal temporal logic STL with a lower bound of 0 applicable to these properties is proposed. inf=0 These properties are formally expressed; combined with runtime verification tools, the key properties described by STL inf=0 are verified at runtime, and the model or source code is corrected according to the verification results to ensure the correctness and reliability of the model simulation and source code.
Owner:EAST CHINA NORMAL UNIV

OTA service communication method for forcing TLS protocol configuration and binding session token

The invention relates to an OTA service communication method for forcing a TLS protocol to configure and bind a session token, and the method comprises the steps: building a configuration file template based on the constraint condition of the TLS protocol, and recording the content of the configuration file template: a server configuration instruction of the TLS protocol; the configuration file template is written into an operation configuration file of a server of OTA service communication, and the server operates the operation configuration file to generate a TLS channel for performing OTA service communication with the user; the server receives a login instruction and a request session instruction sent by a user based on the TLS channel, the login instruction is bound with a session token, and the server verifies the request session instruction based on the session token; the session token is generated based on the information of the user, the environmental information, and the random number. Transport layer security risks such as TLS protocol degradation and weak cryptographic algorithm use are completely eradicated; the session token is prevented from being attacked by application layers such as eavesdropping, tampering and remote multiplexing; automatic deployment of security policies, verification during operation and abnormity self-repairing are realized, and the manual operation and maintenance cost is reduced.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

A Method for Detecting DoS Attacks on Edge Servers Based on Runtime Verification

The present invention belongs to the technical field of program running verification, and discloses a method for detecting DoS attacks on edge servers based on runtime verification. The method for detecting DoS attacks on edge servers based on runtime verification includes: formally describing the expected behavior of edge servers in the form of PPTL formulas; formally describing the characteristics of DoS attacks on edge servers in the form of PPTL formulas; instrumenting the running programs of edge servers for the program variables and program functions involved in the PPTL formulas; for the dynamic execution traces of edge server programs, using a parallel runtime verification framework to detect the running status of the programs, and judging whether the edge servers are being subjected to DoS attacks according to the detection results. The parallel runtime verification framework provided by the present invention can make full use of the idle computing and storage resources of edge servers, improve the verification efficiency, detect attacks in a timely manner, and enable each state of program execution to be reliably verified, effectively ensuring the security of edge servers.
Owner:XIAN SPACE PERCEPTION INTELLIGENT TECHNOLOGY CO LTD

Safety verification method of BSW layer calibration variable under AUTOSAR CP platform and control unit thereof

The invention relates to a safety verification method for a BSW layer calibration variable under an AUTOSAR CP platform, and belongs to the field of automobile electronic control unit (ECU) embedded software safety. According to the method, an independent real-time verification module is arranged on an ECU end basic software layer (BSW), and dual verification is carried out on a target address and a data length before an XCP calibration instruction is executed. And the verification module automatically generates a runtime verification table based on the compiling chain information to realize absolute synchronization with a software version. If the verification is passed, releasing the instruction; and if the verification fails, discarding the instruction, returning an error code and recording an error log. According to the method, the problem of memory cross-border tampering caused by A2L file errors, communication interference or version inconsistency is effectively solved, the safety and reliability of the calibration process are improved, and the method is suitable for various calibration scenes such as XCP on CAN and XCP on ETH.
Owner:DONGFENG ELECTRONICS TECH

Security code generation method and device, computer device, and storage medium

This application discloses a method, apparatus, computer device, and storage medium for generating secure code. In financial business scenarios or medical data management scenarios, a target code generation model processes and generates code from generated instructions. During the training of the target code generation model, no differential privacy noise is injected. The training data comes from the first synthesized code generated by the model that has learned the syntax structure of the private domain source code. Differential privacy noise is injected during model learning. The first synthesized code that passes verification is selected as the training data. Verification items include runtime verification and semantic consistency verification. In this application, the constraints on the code structure are explicitly strengthened during differential privacy training, effectively offsetting the damage to code syntax caused by privacy noise. A dual filtering mechanism of verification and semantic verification is used to perform verification on synthesized data without privacy risks, ensuring code reliability. This solves the problem of incompatibility between security and usability in generated code.
Owner:PING AN TECH (SHENZHEN) CO LTD

System and method for validating a signature of a virtual workload image in runtime

In some aspects, a device includes selecting a signed software image for deployment in a computing environment, the software image signed utilizing a private cryptographic key of an asymmetrical cryptography scheme. Also, the device may include accessing a public cryptographic key corresponding to the private cryptographic key. Furthermore, the device may include configuring an admission controller of a software container cluster deployed in the computing environment to verify the signed software image utilizing the public cryptographic key. In addition, the device may include deploying the signed software image in the software container cluster in response to verifying the signed software image. Moreover, the device may include denying deployment of the signed software image, in response to determining that the signed software image is signed with a key which is not the private cryptographic key.
Owner:WIZ INC

Docker-based internet of things program runtime verification method

The application discloses a kind of based on Docker's Internet of Things program runtime verification method, it is related to program verification technical field, the method includes: based on integrity measurement architecture, container image is hashed and is measured and is written into measurement list;The measurement value in the measurement list corresponding to target container is stored to the vPCR module corresponding to target container;vPCR module is extended into trusted platform module;The identity information and state information of the host platform where target container is located are verified, and the container is successfully started if the verification is passed;According to container ID, target container inner process pid and acquisition time, the memory binary information of corresponding process runtime is acquired, and memory event is constructed;The memory event corresponding to the verification of business flow on Internet of Things program of the memory event on the state machine end received by inter-state flow is realized. The application improves the security of Internet of Things program running.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Safety management monitoring system for port vehicle traffic management based on big data

PendingCN121982936AMarine craft traffic controlRuntime verificationData acquisition
The invention relates to the technical field of port automation, and discloses a safety management monitoring system for port vehicle traffic management based on big data. Comprising a data acquisition module, an event extraction module, an event system modeling module, a safety specification modeling module, a controllable observable event boundary identification module, a specification projection module, a supervision permission control module and a runtime verification and control execution module. Event modeling is carried out on multi-source traffic data, a safety specification is projected to a controllable and observable event subset, an executable safety specification and a corresponding permission control strategy are constructed, and specification consistency verification and dynamic permission control of traffic control events such as gate release, road section entry and intersection pass are realized. By introducing the controllable and observable event boundary recognition module and the standard projection module, the problem of control mismatch caused by direct participation of uncontrollable events or unobservable events in safety judgment is avoided.
Owner:ZHANJIANG PORT (GRP) CO LTD

LTLf-based program runtime verification method

The application discloses a program runtime verification method based on LTLf and relates to the technical field of electric digital data processing.The program runtime verification method based on LTLf comprises the following steps: timeliness evaluation, fault verification, data analysis and formal verification.The application obtains a runtime timeliness evaluation value through network data and judges whether to perform runtime timeliness adjustment, then obtains a fault verification safety evaluation value through network data and a runtime timeliness evaluation value meeting a timeliness condition and judges whether to perform fault safety adjustment, then obtains an analysis accuracy evaluation value through data analysis on encapsulated network data, finally judges whether to perform accuracy adjustment based on the analysis accuracy evaluation value, and performs formal verification on LTLf constraint data, so that the effect of improving the timeliness of program runtime verification is achieved, and the problem of low timeliness of program runtime verification in the prior art is solved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV