Polymorphic Machine Code Execution via Block-Level Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for executing polymorphic machine code by a microprocessor are vulnerable to side channel attacks and disassembly attacks, as the instruction stream can be observed and disassembled, compromising security.
Innovation Solution
The method generates and executes polymorphic machine code with varying instruction streams, where each basic block is encrypted with a unique initialization vector, ensuring the instruction stream remains encrypted in memory and is decrypted only when executed, thereby preventing systematic decryption and enhancing security against side channel and disassembly attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the instruction stream is stored in encrypted form in main memory, then security against disassembly attacks is improved, but execution speed deteriorates due to systematic decryption requirements
Solution Approach 1:
The instruction stream is segmented into multiple basic blocks, each encrypted independently with a unique initialization vector. This allows selective decryption of only the currently executed basic block rather than systematic decryption of the entire instruction stream, thereby improving execution speed while maintaining security against disassembly attacks.
2Device complexity
If the same initialization vector is used for encrypting the entire instruction stream, then encryption simplicity is improved, but cryptanalysis resistance deteriorates
Solution Approach 1:
Each basic block within the instruction stream is encrypted with a unique initialization vector specific to that block. This local differentiation in encryption parameters enhances cryptanalysis resistance while maintaining manageable encryption complexity through the structured approach of block-based encryption.
3Ease of operation
If the instruction stream is decrypted before execution, then execution flexibility is improved, but security against side channel attacks deteriorates
Solution Approach 1:
The instruction stream is prepared in encrypted form in advance and stored in main memory. During execution, only the specific basic block that needs to be executed is decrypted on-demand, maintaining both execution flexibility and security against side channel attacks by avoiding premature decryption of the entire stream.
4Reliability
If all basic blocks are decrypted systematically, then execution completeness is improved, but performance deteriorates due to unnecessary decryption overhead
Solution Approach 1:
Instead of decrypting all basic blocks systematically, the system decrypts only the partial portion (specific basic block) that is currently needed for execution. This on-demand decryption approach eliminates unnecessary decryption overhead while ensuring execution completeness through dynamic selection and decryption of required blocks during runtime.
Data Source
AI summary
A method for executing a polymorphic machine code, wherein: for each branching address at which a base block of a flow of generated instructions starts, the microprocessor automatically adds, in the generated flow of instructions, a renewal instruction suitable, when it is executed, for triggering the renewal of an initialization vector of a module for decryption by flow with a specific value associated with this branching address, then a flow encryption module encrypts the flow of instructions as it is generated and, during this encryption, each base block is encrypted using a specific value associated with the branching address at which it starts. Only the instruction flow encrypted in this way is recorded in the main memory. During execution of the encrypted instruction flow, the added renewal instructions are executed as they are encountered.


