Invention Grant
- Patent Title: Tamper-resistant software development lifecycle provenance
-
Application No.: US16208407Application Date: 2018-12-03
-
Publication No.: US11212117B2Publication Date: 2021-12-28
- Inventor: Richard Harrington
- Applicant: T-Mobile USA, Inc.
- Applicant Address: US WA Bellevue
- Assignee: T-Mobile USA, Inc.
- Current Assignee: T-Mobile USA, Inc.
- Current Assignee Address: US WA Bellevue
- Agency: Han Santos, PLLC
- Main IPC: H04L9/32
- IPC: H04L9/32 ; G06F8/70 ; G06F21/64

Abstract:
A validation record chain that is generated for a particular version of a software package may be used to verify the legitimacy of the particular version. A hash that is generated by a software building platform for a particular version of a software package is received. A validation record chain for the particular version is then generated that includes a plurality of certificates such that a first certificate in the validation record chain contains the hash, and each of one or more subsequent certificates is signed with a corresponding hash signature of a corresponding certifier application and contains a prior hash signature of a previous certificate in the validation record chain. The validation record chain is stored for validation of the particular version of the software package via the plurality of certificates.
Public/Granted literature
- US20200177397A1 TAMPER-RESISTANT SOFTWARE DEVELOPMENT LIFECYCLE PROVENANCE Public/Granted day:2020-06-04
Information query