CPE File Integrity Validation via Hash Ranges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrity check software struggles to identify malicious items across diverse firmware and software applications on customer premises equipment (CPE) of the same type or model due to variations in features and environments, making it difficult to ensure unaltered and secure operation.

Innovation Solution

A method involving the creation of a validated file system database from CPEs operating under different conditions, comparing file inventories and attributes of a test CPE to the database to identify suspicious files and attributes, and issuing notifications for any discrepancies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If integrity check software is provided to ensure firmware and software have not been tampered with, then security is improved, but the ability to identify malicious items deteriorates due to numerous differences in firmware and software applications across individual CPEs

Engineering Contradiction:
ImprovesecurityVSAvoiddetection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent changes the parameter of comparison from exact file matching to hash value matching within acceptable variance ranges. By allowing hash values to fall within a defined range rather than requiring exact matches, the system can identify malicious items even when firmware and software applications have minor legitimate variations across different CPEs.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by comparing only critical files and attributes that are essential for security validation, rather than requiring exact matching of all files and attributes. This selective approach allows the integrity check to focus on the most important security-relevant elements while tolerating legitimate variations in non-critical components.

Inventive Principle:
Principle #16Partial or excessive action

2Adaptability or versatility

If firmware and software applications are customized to support operation in different environments, then adaptability is improved, but the difficulty of providing universal integrity check software increases

Engineering Contradiction:
Improveenvironmental adaptabilityVSAvoidintegrity check software complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal integrity check mechanism that can validate CPEs across different environments and configurations. By using hash value ranges and selective attribute comparison, the same integrity check software can universally apply to multiple CPE variants without requiring customization for each specific configuration or environment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms the integrity check from a rigid exact-match approach to a flexible parameter-based approach using hash value ranges. This allows the universal integrity check software to accommodate environmental adaptations and configuration variations while maintaining security validation across all CPE instances.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11971988B2Detection of suspicious objects in customer premises equipment (CPE)
Publication Date: 2024.04.30 ARRIS ENTERPRISES LLC
  • US11971988B2 patent drawing
  • US11971988B2 patent drawing
  • US11971988B2 patent drawing

AI summary

A method is provided for validating an inventory of files in a file system of a customer premises equipment (CPE). The method includes developing a database containing a file system inventory of a validated CPE operating in different scenarios or under different operating conditions that may include different networks, different service provider configurations and different end user feature settings. The validated CPE will be allowed to operate in these different scenarios so that an inventory of files and their attributes may be obtained at different times, such as after a reboot, after a change in software feature configurations, and so on. A file system inventory of a CPE system under test is obtained and each entry in the inventory is compared to the entries in the validated file system database to identify unexpected discrepancies.