IP Library Granted Patent US 11,669,433
Granted Patent B2
US 11,669,433 · App. 17/744,765 · Granted Jun 6, 2023

Software protection from attacks using self-debugging techniques

Inventors: Laurent Dore (Thorigne-Fouillard, FR); Asfandyar Orakzai (Oslo, NO); Brecht Wyseur (Panthalaz, BE); Yihui Xu (Oslo, NO)
Assignee: Nagravision Sàrl
G06F11/3624G06F8/447G06F9/4856G06F11/3636G06F11/3644
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,669,433
App. No.
17/744,765
Granted
Jun 6, 2023
Kind
B2
Abstract

In overview, methods, computer programs products and devices for securing software are provided. In accordance with the disclosure, a method may comprise attaching a debugger process to a software process. During execution of the software process, operations relevant to the functionality of the code process are carried out within the debugger process. As a result, the debugger process cannot be replaced or subverted without impinging on the functionality of the software process. The software process can therefore be protected from inspection by modified or malicious debugging techniques.

Claims (21)

1. A method for securing software, comprising:

executing a debuggee process with an attached debugger process such that the debugger process is invoked at least once; and

performing a function within the debugger process in response to invoking the debugger process, the function output dependent on data associated with the debuggee process,

wherein, when an entry point to the function is reached while executing the debuggee process, serializing first parameters of the function into a state structure followed by executing an exception-inducing instruction and thereby causing an exception triggering the debugger process which identifies a debuggee location of the exception, and

wherein the debuggee process generates a data structure having second parameters required for execution of the function prior to invoking the debugger process.

2. The method as recited in claim 1 , wherein the function output includes a data output for use by the debuggee process.

3. The method as recited in claim 1 , wherein the data structure is a state structure.

4. The method as recited in claim 1 , wherein the debuggee process acts to debug the debugger process.

5. The method as recited in claim 1 , further comprising launching an additional process to debug the debugger process.

6. The method as recited in claim 1 , wherein output of a given function indicates multiple points of return within the debuggee process for continued execution.

7. The method as recited in claim 1 , wherein the debugger process provides memory support capabilities to enable the function to retrieve data from memory within address space of the debuggee process.

8. The method as recited in claim 1 , wherein the debugger process is invoked when a break point within the debuggee process is reached.

9. The method as recited in claim 1 , further comprising detaching the debugger process from the debuggee process when the debuggee process is complete.

10. The method as recited in claim 1 , wherein the debuggee process implements an executable such as an application.

11. The method as recited in claim 1 , wherein the debuggee process implements a library.

12. A computing device for securing software comprising:

a processor for executing code that implements the following steps on a computing device;

executing a debuggee process with an attached debugger process such that the debugger process is invoked at least once; and

performing a function within the debugger process in response to invoking the debugger process, the function output dependent on data associated with the debuggee process,

wherein, when an entry point to the function is reached while executing the debuggee process, serializing first parameters of the function into a state structure followed by executing an exception-inducing instruction and thereby causing an exception triggering the debugger process which identifies a debuggee location of the exception, and

wherein the debuggee process generates a data structure having second parameters required for execution of the function prior to invoking the debugger process.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: DORE, LAURENT; WYSEUR, BRECHT
To: NAGRAVISION S.A.
Reel/Frame 062958/0933 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: NAGRAVISION A.S.
To: NAGRAVISION S.A.
Reel/Frame 062959/0096 →
CHANGE OF NAME Recorded Jun 27, 2022
From: NAGRAVISION S.A.
To: NAGRAVISION SÀRL
Reel/Frame 060442/0238 →
Continuity (2)
Continuation 16766768
Related Publication 20220350728A1 · Nov 3, 2022