Polymorphic Machine Code Execution via Block-Level Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for executing polymorphic machine code by a microprocessor are vulnerable to side channel attacks and disassembly attacks, as the instruction stream can be observed and disassembled, compromising security.

Innovation Solution

The method generates and executes polymorphic machine code with varying instruction streams, where each basic block is encrypted with a unique initialization vector, ensuring the instruction stream remains encrypted in memory and is decrypted only when executed, thereby preventing systematic decryption and enhancing security against side channel and disassembly attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the instruction stream is stored in encrypted form in main memory, then security against disassembly attacks is improved, but execution speed deteriorates due to systematic decryption requirements

Engineering Contradiction:
Improvesecurity against disassembly attacksVSAvoidexecution speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The instruction stream is segmented into multiple basic blocks, each encrypted independently with a unique initialization vector. This allows selective decryption of only the currently executed basic block rather than systematic decryption of the entire instruction stream, thereby improving execution speed while maintaining security against disassembly attacks.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If the same initialization vector is used for encrypting the entire instruction stream, then encryption simplicity is improved, but cryptanalysis resistance deteriorates

Engineering Contradiction:
Improveencryption complexityVSAvoidcryptanalysis resistance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Each basic block within the instruction stream is encrypted with a unique initialization vector specific to that block. This local differentiation in encryption parameters enhances cryptanalysis resistance while maintaining manageable encryption complexity through the structured approach of block-based encryption.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the instruction stream is decrypted before execution, then execution flexibility is improved, but security against side channel attacks deteriorates

Engineering Contradiction:
Improveexecution flexibilityVSAvoidsecurity against side channel attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The instruction stream is prepared in encrypted form in advance and stored in main memory. During execution, only the specific basic block that needs to be executed is decrypted on-demand, maintaining both execution flexibility and security against side channel attacks by avoiding premature decryption of the entire stream.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If all basic blocks are decrypted systematically, then execution completeness is improved, but performance deteriorates due to unnecessary decryption overhead

Engineering Contradiction:
Improveexecution completenessVSAvoidexecution performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of decrypting all basic blocks systematically, the system decrypts only the partial portion (specific basic block) that is currently needed for execution. This on-demand decryption approach eliminates unnecessary decryption overhead while ensuring execution completeness through dynamic selection and decryption of required blocks during runtime.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11157659B2Method for executing a polymorphic machine code of a predetermined function by a microprocessor
Publication Date: 2021.10.26 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • US11157659B2 patent drawing
  • US11157659B2 patent drawing
  • US11157659B2 patent drawing

AI summary

A method for executing a polymorphic machine code, wherein: for each branching address at which a base block of a flow of generated instructions starts, the microprocessor automatically adds, in the generated flow of instructions, a renewal instruction suitable, when it is executed, for triggering the renewal of an initialization vector of a module for decryption by flow with a specific value associated with this branching address, then a flow encryption module encrypts the flow of instructions as it is generated and, during this encryption, each base block is encrypted using a specific value associated with the branching address at which it starts. Only the instruction flow encrypted in this way is recorded in the main memory. During execution of the encrypted instruction flow, the added renewal instructions are executed as they are encountered.