IP Library Granted Patent US 7,779,394
Granted Patent B2
US 7,779,394 · App. 11/128,097 · Granted Aug 17, 2010

Software self-defense systems and methods

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,779,394
App. No.
11/128,097
Granted
Aug 17, 2010
Kind
B2
Abstract

Systems and methods are disclosed for protecting a computer program from unauthorized analysis and modification. Obfuscation transformations can be applied to the computer program's local structure, control graph, and/or data structure to render the program more difficult to understand and/or modify. Tamper-resistance mechanisms can be incorporated into the computer program to detect attempts to tamper with the program's operation. Once an attempt to tamper with the computer program is detected, the computer program reports it to an external agent, ceases normal operation, and/or reverses any modifications made by the attempted tampering. The computer program can also be watermarked to facilitate identification of its owner. The obfuscation, tamper-resistance, and watermarking transformations can be applied to the computer program's source code, object code, or executable image.

Claims (24)

1. A method for resisting attempts to tamper with the structure or function of a computer program, the computer program running on a first computer system and being designed to carry out one or more specified tasks, the method including:

detecting an attempt to tamper with the structure or function of the computer program, including:

sending a message stamped with time-stamp information to a second computer system, the time-stamp information including a time offset, wherein the second computer system periodically receives the time-stamp information from the first computer system, and determines a difference between the time stamp information and a local time at the second computer system, and wherein a difference between the time stamp information and the local time at the second computer system greater than a predetermined amount is treated as an indication of an attempt to tamper with the structure or function of the first computer system;

receiving, at the first computer system, from the second computer system, an indication of attempted tampering;

delaying an additional response to detected tampering by at least a first predefined period of time following detection of attempted tampering;

responding to detected tampering by using one or more countermeasures.

2. A method as in claim 1 , in which the first predefined period of time comprises a minimum time necessary to execute a first predefined sequence of instructions.

3. A method as in claim 1 , in which sending an indication of attempted tampering is delayed at least a second predefined amount of time from detection of attempted tampering.

4. A method as in claim 1 , in which the one or more countermeasures include branching to code which performs no function necessary for carrying out the one or more specified tasks.

5. A method as in claim 1 , in which the one or more countermeasures include spoiling one or more cryptographic keys stored on the first computer system.

6. A method as in claim 1 , in which the one or more countermeasures include recording information regarding the status of the program for later use by an external agent.

7. A method as in claim 1 , in which the one or more countermeasures include setting one or more predetermined variables to a predefined value.

8. A method as in claim 1 , in which the one or more countermeasures including simulating an operating systems error.

9. A method as in claim 1 , in which the one or more countermeasures include simulating a system input/output error.

10. A method for resisting attempts to tamper with the structure or function of a computer program, the computer program being designed to carry out one or more specified tasks, the method including:

detecting an attempt to tamper with the structure or function of the computer program including:

transmitting, to an external agent, a message stamped with time-stamp information, the time-stamp information including a time offset wherein the external agent periodically receives the time-stamp information including the time offset from a computer system on which the computer program is running, and determines a difference between the time-stamp information and a local time at the external agent, wherein a difference between the time-stamp information and the local time at the external agent greater than a predetermined amount is treated as an indication of a attempt to tamper with the structure or function of the computer program;

receiving from the external agent, an indication that an attempt to tamper with the structure or function of the computer program was detected;

waiting at least a predefined period of time to respond to the attempt to tamper with the structure or function of the computer program; and responding to the attempt to tamper with the structure or function of the computer program.

11. A system for resisting attempts to tamper with the structure or function of a computer program, the system including:

means for detecting attempts to tamper with the structure or function of the computer program, including:

means for transmitting to an external agent a message stamped with time-stamp information, the time-stamp information including a time offset wherein the external agent periodically receives the time-stamp information including the time offset from the system, and determines a difference between the time stamp information and a local time at the external agent, wherein a difference between the time stamp information and the local time at the external agent greater than a predetermined amount is treated as an indication of an attempt to tamper with the structure or function of the computer program;

means for receiving an indication that an attempt to tamper with the structure or function of the computer program was detected; and

means for delaying transmission of the indication for a predefined period of time.

Assignments (4)
PATENT ASSIGNMENT Recorded May 27, 2025
From: INTERTRUST TECHNOLOGIES CORPORATION
To: INNOVATION TECHNOLOGIES PARTNERS LP
Reel/Frame 071408/0320 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
SECURITY INTEREST Recorded Mar 18, 2020
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 052189/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2005
From: HORNING, JAMES J.; SIBERT, W. OLIN; TARJAN, ROBERT E.; MAHESHWARI, UMESH; HOME, WILLIAM G.; WRIGHT, ANDREW K.; MATHESON, LESLEY R.; OWICKI, SUSAN S.
To: INTERTRUST TECHNOLOGIES CORP.
Reel/Frame 016563/0729 →