IP Library › Patent Application 15300572
Patent Application
App. No. 15/300,572

SOFTWARE PROTECTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/300,572
Abstract

A method comprising: providing a protected item of software to a device, wherein the protected item of software is in a scripted language or an interpreted language or source code, wherein the protected item of software, when executed by the device, is arranged to perform a security-related operation for the device, wherein the security-related operation is implemented, at least in part, by at least one protected portion of code in the protected item of software, wherein the at least one protected portion of code is arranged so that (a) the at least one protected portion of code has resistance against a white-box attack and/or (b) the at least one protected portion of code may only be executed on one or more predetermined devices.

Claims (48)

1 . A method comprising:

providing a protected item of software to a device, wherein the protected item of software is in a scripted language or an interpreted language or source code, wherein the protected item of software, when executed by the device, is arranged to perform a security-related operation for the device, wherein the security-related operation is implemented, at least in part, by at least one protected portion of code in the protected item of software, wherein the at least one protected portion of code is arranged so that (a) the at least one protected portion of code has resistance against a white-box attack and/or (b) the at least one protected portion of code may only be executed on one or more predetermined devices.

2 . The method of claim 1 , comprising:

obtaining an initial item of software, wherein the security-related operation is implemented, at least in part, by at least one initial portion of code in the initial item of software;

generating the protected item of software, said generating comprising modifying at least the at least one initial portion of code to form the at least one protected portion of code.

3 . The method of claim 2 , wherein said modifying comprises applying one or more white-box protection techniques to the at least one initial portion of code.

4 . The method of claim 2 or 3 , wherein said modifying comprises applying one or more node-locking techniques to the at least one initial portion of code.

5 . A method comprising:

obtaining at a device a protected item of software, wherein the protected item of software is in a scripted language or an interpreted language or source code, wherein the protected item of software, when executed by the device, is arranged to perform a security-related operation for the device, wherein the security-related operation is implemented, at least in part, by at least one protected portion of code in the protected item of software, wherein the at least one protected portion of code is arranged so that (a) the at least one protected portion of code has resistance against a white-box attack and/or (b) the at least one protected portion of code may only be executed on one or more predetermined devices; and

executing, on the device, the at least one protected portion of code of the obtained protected item of software.

6 . The method of any one of the preceding claims, wherein the security-related operation uses secret data and wherein the at least one protected portion of code is in an obfuscated form to thereby protect the secret data against the white-box attack.

7 . The method of any one of the preceding claims, wherein the security-related operation comprises one or more of:

(i) a cryptographic operation;

(ii) a conditional access operation;

(iii) a digital rights management operation;

(iv) concealing the destination of a communication;

(v) a key management operation;

(vi) a communication operation to establish a link to a server without using a lower level security sensitive primitive.

8 . The method of claim 7 , wherein the cryptographic operation comprises one or more of: an encryption operation; a decryption operation; a digital signature generation operation; a digital signature verification operation.

9 . The method of any one of the preceding claims, wherein the language is one or more of:

(i) JavaScript;

(ii)

(iii) Python;

(iv) asm.js;

(v) Ruby.

10 . The method of any one of the preceding claims, wherein the protected item of software is for execution in a browser on the device.

11 . The method of any one of the preceding claims, wherein the protected item of software is a web app.

12 . An apparatus arranged to carry out a method according to any one of claims 1 to 11 .

13 . A computer program which, when executed by a processor, causes the processor to carry out a method according to any one of claims 1 to 11 .

14 . A computer-readable medium storing a computer program according to claim 13 .

15 . A protected item of software for execution by a device, wherein the protected item of software is in a scripted language or an interpreted language or source code, when executed by the device, is arranged to perform a security-related operation for the device, wherein the security-related operation is implemented, at least in part, by at least one protected portion of code in the protected item of software, wherein the at least one protected portion of code is arranged so that (a) the at least one protected portion of code has resistance against a white-box attack and/or (b) the at least one protected portion of code may only be executed on one or more predetermined devices.

16 . The protected item of software of claim 15 , wherein the security-related operation uses secret data and wherein the at least one protected portion of code is in an obfuscated form to thereby protect the secret data against the white-box attack.

17 . The protected item of software of claim 15 or 16 , wherein the security-related operation comprises one or more of:

(i) a cryptographic operation;

(ii) a conditional access operation;

(iii) a digital rights management operation;

(iv) concealing the destination of a communication;

(v) a key management operation;

(vi) a communication operation to establish a link to a server without using a lower level security sensitive primitive.

18 . The protected item of software of claim 17 , wherein the cryptographic operation comprises one or more of: an encryption operation; a decryption operation; a digital signature generation operation; a digital signature verification operation.

19 . The protected item of software of any one of claims 15 to 18 , wherein the language is one or more of:

(i) JavaScript;

(ii) PHP;

(iii) Python;

(iv) asm.js;

(v) Ruby.

20 . The protected item of software of any one of claims 15 to 19 , wherein the protected item of software is for execution in a browser on the device.

21 . The protected item of software of any one of claims 15 to 20 , wherein the protected item of software is a web app.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2016
From: IRDETO TECHNOLOGY (BEIJING) CO., LTD.
To: IRDETO B.V.
Reel/Frame 040758/0901 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2016
From: IRDETO CANADA CORPORATION
To: IRDETO B.V.
Reel/Frame 040485/0149 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2016
From: MOOIJ, WIM; WAJS, ANDREW AUGUSTINE; DEKKER, HANS; CIORDAS, CALIN
To: IRDETO B.V.
Reel/Frame 040453/0042 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2016
From: ZHANG, FAN
To: IRDETO TECHNOLOGY (BEIJING) CO., LTD.
Reel/Frame 040453/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2016
From: GU, YUAN XIANG; JOHNSON, HAROLD
To: IRDETO CANADA CORPORATION
Reel/Frame 040453/0745 →