Compiler Data-Flow Graph Homogeneity for Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing compilers face security risks when inserting encoding and decoding operations, particularly in sub-graphs with mixed outputs, leading to easily analyzable situations that can be exploited by attackers, especially in copy-phi networks where encoding operations cannot be merged with subsequent nodes.
Innovation Solution
The compiler identifies and modifies data-flow graphs to create homogeneous sub-graphs by duplicating and splitting copy-phi networks, ensuring all outputs are either encoded or non-encoded, and using back-propagation to merge encoding operations with adjacent nodes, thereby reducing security risks and making reverse engineering more difficult.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encoding and decoding operations are inserted in existing software, then security protection is improved, but dangerous situations are created that can be exploited by attackers
Solution Approach 1:
The patent segments the data-flow graph into homogeneous sub-graphs where all outputs are either encoded or non-encoded. This segmentation prevents the creation of dangerous mixed-output sub-graphs that could lead to exploitable security vulnerabilities, while still allowing encoding operations to be applied for protection.
Solution Approach 2:
The patent performs preliminary analysis and modification of the data-flow graph before compilation, identifying and resolving potential security issues in advance. By detecting mixed-output sub-graphs beforehand and transforming them into homogeneous ones, the compiler prevents security vulnerabilities from being introduced in the first place.
2Stability of the object's composition
If encoding operations are followed by phi or copy operations, then data flow is maintained, but encoding operations cannot be merged with subsequent nodes
Solution Approach 1:
The patent inverts the traditional approach by not allowing encoding operations to be followed immediately by phi or copy operations. Instead, it transforms the data-flow graph structure so that encoding operations are separated into homogeneous sub-graphs, eliminating the need for immediate merging while maintaining data flow continuity through proper graph transformation.
3Adaptability or versatility
If mixed-output sub-graphs are present in the data-flow graph, then coding flexibility is maintained, but easily analyzable situations are created that aid reverse engineering
Solution Approach 1:
The patent enforces homogeneity within sub-graphs by ensuring all outputs are either encoded or non-encoded, not mixed. This homogeneity prevents the creation of easily analyzable patterns that could aid reverse engineering, while the overall data-flow graph structure maintains the necessary flexibility for various coding scenarios.
Data Source
AI summary
Some embodiments are directed to a compiler device (100) configured to identify a sub-graph (210) in a data flow graph having one or more output nodes marked as encoded and one or more output nodes marked as non-encoded, and to replace the sub-graph by an encoded first sub-graph (210.1), and a non-encoded second sub-graph (210.2), wherein the first sub-graph has only encoded output nodes, and the second sub-graph has only non-encoded output nodes.


