IP Library › Granted Patent US 11,604,857
Granted Patent B2
US 11,604,857 · App. 17/266,930 · Granted Mar 14, 2023

Anti cloning for white box protected data

Inventors: Michael Adjedj (Meudon, FR); Aline Gouget (Meudon, FR); Stéphane Grellier (Meudon, FR); Sylvain Leveque (Meudon, FR); Jan Vacek (Meudon, FR)
Assignee: THALES DIS FRANCE SAS
G06F21/14G06F21/53G06F21/73H04L9/0866H04L9/0869G06F2221/2149H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,604,857
App. No.
17/266,930
Filed
Feb 8, 2021
Granted
Mar 14, 2023
Kind
B2
Examiner
SONG, HEE K
Art Unit
2497
USPC
713/190
Abstract

Protection of a data file to be used by a white-box cryptography software application installed in memory of a device to prevent the malevolent use of a digital copy of the data file by a white-box cryptography (WBC) software application installed in memory of another device. The mechanism includes extracting an unique identifier for the device from the environment of the device and modifying data in the data file according to the unique identifier, the available white-box cryptography software application includes a software security layer to retrieve the unique identifier from the environment of the device in which the software application is installed and to use this unique identifier in combination with the stored data file when executing, the result of the execution being correct only in case where the correct unique identifier has been extracted by the executed WBC software application.

Claims (20)

1. A method to protect a data file to be used by a White-Box Cryptography (WBC) software application installed in memory of a device to prevent the malevolent use of a digital copy of the data file by a white-box cryptography software application installed in memory of another device, said method comprising the steps of:

extracting an unique identifier for the device from an environment related to the device

modifying data in the data file according to the unique identifier,

when the WBC software application is executed, retrieving the unique identifier from the environment of the device in which the WBC software application is installed, and

using this unique identifier in combination with the stored data file in the execution of the WBC software application, the result of the execution being correct only when a unique identifier extracted by the WBC software application when executing correctly matches the unique identifier used in modifying data in the data file.

2. The method according to claim 1 , wherein the unique identifier is different from the ones used in other anti-cloning features used in code of the available white-box cryptography software application.

3. The method according to claim 1 , wherein the access to provisioned data contained in data file of the WBC software application is modified depending on the unique identifier.

4. The method according to claim 1 , wherein the access to provisioned data contained in data file of the WBC software application is direct and the modification of the provisioned data contained in data file occurs only in volatile memory.

5. The method according to claim 1 , wherein the environment of the device is a companion secure environment.

6. The method according to claim 1 , wherein the unique identifier for the device is constructed using a random value generated by the environment of the device.

7. The method according to claim 1 , wherein the unique identifier for the device is computed on-the-fly using a combination of values chosen among: a confidential value stored in the environment of the device or a function applied to this confidential value, a MAC address, a CPU ID, a HDD serial number, an application instance ID or another value used in anti-cloning technique, a user data known by user such as PIN, passphrase, answer to questions, biometric data selected from fingerprint, face, voice, and a secret data coming from another application.

8. The method according to claim 1 , wherein the modification is chosen among a key based random permutation of data in the data file based on the unique identifier, a XOR operation with the unique identifier, a Pseudo Random Number Generation seeded with the unique identifier, an encryption mechanism keyed with the unique identifier.

9. The method according to claim 1 , wherein the step of modification of data in the data file according to the unique identifier every time the WBC software application is provisioned with new WBC data in the data file.

10. The method according to claim 1 , wherein the step of modification of data in the data file according to the unique identifier is performed by the WBC software application installed in the device.

11. The method according to claim 1 , said method comprising a step of, for the device, sending, in a secure channel, the unique identifier or elements as extracted to construct the unique identifier, to a data file provisioning back-end server, the step of modification of data in the data file to be provisioned according to the unique identifier is performed by the back-end server before sending the data file and the method further comprises a step of, for the data file provisioning back-end server, sending the modified data file to the device in a secure channel.

12. The method according to claim 1 , wherein the WBC software application uses a combination of data modified using at least two unique identifiers of the device, one, named back-end calculated unique identifier, being constructed by a data file provisioning back-end server and one, named device calculated unique identifier, being constructed by the WBC software application, combined operations consecutively performed by the data file provisioning back-end server and by the device using back-end and device calculated unique identifiers respectively corresponding to the operation performed by the device during the running time using combined back-end and device calculated unique identifier.

13. A non-transitory memory containing a White Box Cryptography (WBC) software application comprising a code anti-cloning feature to be activated when the WBC software application is installed on a device having an environment, said WBC software application further comprising a data anti-cloning feature to be activated at each WBC data provisioning in a data file, said data anti-cloning feature being adapted to, each time a WBC data provisioning is triggered, retrieve a unique identifier from the environment of the device, modifying the provisioned data using the unique identifier before storage of the data file, said WBC software application being adapted to, when it is executed, extract the unique identifier from the environment of the device in which it is installed and to use this unique identifier in combination with the stored WBC data in the data file in its execution, the result of the execution being correct only when a unique identifier extracted by the WBC software application when executing correctly matches the unique identifier used in modifying data in the data file.

14. A non-transitory memory containing a White Box Cryptography software application comprising a code anti-cloning feature to be activated when the WBC software application is installed on a device having an environment, said WBC software application further comprising a data anti-cloning feature to be activated at each WBC data provisioning in a data file, said data anti-cloning feature being adapted to, each time a WBC data provisioning is triggered, retrieve a unique identifier from the environment of the device sending said unique identifier to a data file back-end provisioning server for it to modify data to be provisioned in the data file using said unique identifier, receiving and storing the provisioned modified data in the data file, said WBC software application being adapted to, when it is executed, extract the unique identifier from the environment of the device in which it is installed and to use this unique identifier in combination with the stored WBC data in the data file in its execution, the result of the execution being correct only in case where the correct unique identifier has been extracted by the executed WBC software application.

15. A device having an environment and comprising a non-transitory memory where a White Box Cryptography software application comprising a code anti-cloning feature to be activated when the WBC software application is installed, said WBC software application further comprising a data anti-cloning feature to be activated at each WBC data provisioning in a data file, said data anti-cloning feature being adapted to, each time a WBC data provisioning is triggered, retrieve a unique identifier from the environment of the device, modifying the provisioned data in the data file using the unique identifier before storage, said WBC software application being adapted to, when it is then executed, extract the unique identifier from the environment of the device in which it is installed and to use this unique identifier in combination with the stored WBC data in the data file in its execution, the result of the execution being correct only in case where the correct unique identifier has been extracted by the executed WBC software application.

16. The device having an environment and comprising a non-transitory memory where a White Box Cryptography software application comprising a code anti-cloning feature to be activated when the WBC software application is installed, said WBC software application further comprising a data anti-cloning feature to be activated at each WBC data provisioning in a data file, said data anti-cloning feature being adapted to, each time a WBC data provisioning is triggered, retrieve a unique identifier from the environment of the device sending said unique identifier to a data file back-end provisioning device for it to modify data to be provisioned in the data file using said unique identifier, receiving and storing the provisioned modified data in the data file, said WBC software application being adapted to, when it is executed, extract the unique identifier from the environment of the device in which it is installed and to use this unique identifier in combination with the stored WBC data in the data file in its execution, the result of the execution being correct only in case where the correct unique identifier has been extracted by the executed WBC software application.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2023
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 062661/0661 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2023
From: THALES DIS SRO
To: THALES DIS FRANCE SA
Reel/Frame 062622/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: VACEK, JAN
To: THALES DIS SRO
Reel/Frame 062517/0954 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: ADJEDJ, MICHAEL; GOUGET, ALINE; GRELLIER, STEPHANE; LEVEQUE, SYLVAIN
To: THALES DIS FRANCE SA
Reel/Frame 062414/0660 →
Priority Claims (1)
EP 18306094 · Aug 9, 2018 · regional
Continuity (1)
Related Publication 20210312018A1 · Oct 7, 2021
Cited By (1)
US 12,445,269