Dynamic Operational Watermarks for Software Tamper Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing anti-tampering techniques are ineffective against interface-based attacks on modern computing assets, which can compromise systems without physical intrusion, and rely on static methods that can be vulnerable to multiple attacks.

Innovation Solution

Implementing dynamic operational watermarks that continuously monitor systems for anomalies, using both logical and physical parameters, and taking defensive actions when deviations are detected, such as scrubbing data or initiating self-damage, to prevent proprietary technology extraction and ensure system integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static anti-tampering techniques are used, then implementation is simple, but they are vulnerable to multiple attacks and interface-based tampering

Engineering Contradiction:
Improveanti-tampering effectivenessVSAvoidresistance to multiple attack types
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic operational watermarks that continuously change and adapt during system execution, rather than using static protection mechanisms. The watermarks are injected into runtime variables and executed code, allowing the protection to evolve and respond to different attack scenarios, thereby resolving the contradiction between reliability and adaptability to multiple attack types.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of the protected code by injecting watermarks into runtime variables, memory addresses, and execution flow. These parameter changes make the protection mechanism adaptable to different attack vectors while maintaining reliability, as the watermarks can be positioned and configured to defend against various tampering attempts.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If executable comparisons are used for software integrity, then implementation is straightforward, but they cannot defend against real-time attacks

Engineering Contradiction:
Improveintegrity check implementationVSAvoidreal-time attack defense
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent embeds watermarks into the executable code and runtime variables during the software build or deployment phase. This preliminary action ensures that the integrity checks are already in place before the software runs, enabling real-time detection of attacks without adding complex runtime implementation overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The operational watermarks continuously monitor the system during execution, providing ongoing integrity verification rather than periodic checks. This continuous monitoring enables real-time detection of attacks while maintaining straightforward implementation through the embedded watermark mechanism.

Inventive Principle:
Principle #20Continuity of useful action

3Device complexity

If host-based assurance techniques are used, then system integration is simple, but they rely on the integrity of the system being defended

Engineering Contradiction:
Improveassurance system integrationVSAvoidindependence from system integrity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces operational watermarks as an intermediary layer between the trusted foundation and the protected software. These watermarks are embedded in the software itself and can verify integrity independently of the host system's trustworthiness, resolving the contradiction by providing a mediator that maintains simple integration while achieving independence from system integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If dynamic operational watermarks are implemented, then real-time tamper detection is achieved, but system complexity increases

Engineering Contradiction:
Improvereal-time tamper detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The operational watermarks are self-executing code fragments that automatically monitor and detect tampering without requiring complex external monitoring systems. The watermarks use the system's own execution environment to perform detection, thereby achieving real-time tamper detection while minimizing the addition of external complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9081957B2Dynamic operational watermarking for software and hardware assurance
Publication Date: 2015.07.14 RTX BBN TECH INC
  • US9081957B2 patent drawing
  • US9081957B2 patent drawing
  • US9081957B2 patent drawing

AI summary

This disclosure addresses systems and methods for the protection of proprietary information by monitoring operational watermarks of an apparatus. A monitoring device may receive logical or physical watermark data from a defended apparatus. Watermark data may include any operational or environmental variable related to the defended apparatus. The monitoring device may maintain a baseline profile for the defended apparatus that includes watermark data. During monitoring of the defended apparatus by the monitor device, changes in the watermark data may be analyzed to determine if the baseline should be dynamically updated, or if the change indicates an anomaly. Anomalies may indicate an attempt to tamper with the defended apparatus. In response to the change that indicates an anomaly, the monitoring device may scrub the contents of the defended apparatus. In an embodiment, the monitoring device may also scrub its own memory in response to an anomaly.