Library Digest Tracking via Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, clients face challenges in tracking the common libraries used by software programs, which can lead to security vulnerabilities and execution errors due to outdated or tampered versions, especially when the software programs are opaque and difficult to verify.

Innovation Solution

A method involving a server computing system that calculates digests of common libraries, obtains digital signatures for tracking information, and returns this information with responses to client computing systems for verification against reference digests, ensuring the integrity and authenticity of the tracking information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software programs use common libraries in cloud environments, then functionality and reuse are improved, but security vulnerabilities and execution errors increase due to outdated or tampered versions

Engineering Contradiction:
Improvesoftware functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by calculating and signing digests of common libraries in advance before deployment. The server computing system calculates digests of common libraries used by software programs and obtains digital signatures of tracking information containing these digests. This allows clients to verify the authenticity and version status of libraries before execution, preventing security vulnerabilities from outdated or tampered versions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If clients verify tracking information of common libraries, then security and authenticity are improved, but verification complexity and computational overhead increase

Engineering Contradiction:
Improveauthenticity verificationVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a server computing system that acts as a trusted mediator between software providers and clients. The server calculates digests, obtains digital signatures from trusted sources, and returns signed tracking information with responses. Clients only need to verify the digital signature and compare digests, which simplifies their verification process while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If software programs declare common libraries used, then tracking information is provided, but verification of genuineness becomes difficult without additional logic in software

Engineering Contradiction:
Improvelibrary tracking informationVSAvoidsoftware development effort
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The patent applies self-service by enabling the server computing system to automatically calculate digests of common libraries and obtain digital signatures without requiring additional verification logic in the software programs. The system retrieves tracking information, calculates current digests, verifies them against signed references, and returns verification results automatically, reducing development effort while ensuring genuineness.

Inventive Principle:
Principle #25Self-service

4Stability of the object's composition

If previous versions of common libraries remain in use, then backward compatibility is maintained, but functional obsolescence and security exposures increase

Engineering Contradiction:
Improvebackward compatibilityVSAvoidsecurity exposure
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent uses feedback by implementing a verification mechanism where clients send requests to the server with tracking information, and the server responds with verification results indicating whether the common library versions are current and authentic. This feedback loop allows systems to identify and update outdated libraries while maintaining backward compatibility for verified versions, reducing security exposures from obsolete libraries.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11954007B2Tracking usage of common libraries by means of digitally signed digests thereof
Publication Date: 2024.04.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11954007B2 patent drawing
  • US11954007B2 patent drawing
  • US11954007B2 patent drawing

AI summary

Tracking software usage through the following operations: calculating current digests of common libraries used by software programs and obtaining digital signatures of tracking information of the software programs comprising identifiers of their common libraries and the corresponding current digests; responses are returned to calls for the software programs in association with the corresponding tracking information and digital signatures. A corresponding method under the control of a client comprises receiving a response to a call for a software program in association with the corresponding tracking information and digital signature. The common libraries of the software program are tracked according to a verification of the digital signature and of the current digests against corresponding reference digests. Computer programs and computer program products for performing the methods are proposed. Moreover, corresponding server computing system, client computing system and computing infrastructure are proposed.