Hardware-Bound Split-Key Framework for Software Protection Against Reverse Engineering

Authors

DOI:

https://doi.org/10.37943/ZHXT2203%20

Keywords:

cryptography, data security, key generation, trusted platform module, platform’s configuration registers

Abstract

Software piracy and reverse engineering cause significant damage to intellectual property: the commercial value of unlicensed software installed worldwide has been estimated at over USD 46 billion. Traditional protection methods rely on static encryption keys or on obfuscation, and they are not resistant to modern analysis techniques such as differential computation analysis (DCA). This study addresses the single point of failure in software protection systems by developing a new key management architecture. The paper introduces a distributed split-key software-hardware framework. A deterministic decryption key is divided into three parts: a local key derived from the unique properties of the machine's hardware (hardware fingerprint), a server key issued after authenticated online activation, and a key sealed in a Trusted Platform Module (TPM) and bound to the platform's Platform Configuration Registers (PCRs). The final key is assembled exclusively in RAM during program execution through an XOR operation and is erased immediately after use. A C#/.NET 8 reference implementation was evaluated on a single Windows platform with a discrete TPM 2.0 module. Changing any of the five hardware identifiers or the PCR state prevented decryption, the assembled key remained in memory for a median of 15.6 µs, key assembly took 0.3 µs, and the one-time TPM sealing took about 67 ms. The runtime overhead stayed below 5% for typical protected functions. The analysis also identifies the remaining limitations of the design: code harvesting through legitimate decryption, binary patching that does not affect PCR 0 and PCR 7, clock rollback during the offline grace period, and loss of access after legitimate firmware or Secure Boot updates. The framework binds execution to authorized hardware and raises the cost of reverse engineering.

Author Biographies

Zhaksylyk Kozhakhmet, Astana IT University, Kazakhstan

Master’s Degree, Junior Researcher, CyberTech Research Center

Alissa Ryzhova, Ca’Foscari University of Venice, Italy

Master’s Student, Department of Environmental Sciences, Informatics and Statistics

Gul Jussupova, Ministry of Science and Higher Education of the Republic of Kazakhstan, Kazakhstan

PhD, Department of Digitalization and Public Services

References

BSA | The Software Alliance. (2018). Software management: Security imperative, business opportunity (BSA Global Software Survey). https://www.bsa.org/files/reports/2018_BSA_GSS_Report_en.pdf

Bradley, W. A., & Kolev, J. (2023). How does digital piracy affect innovation? Evidence from software firms. Research Policy, 52(3), 104701. https://doi.org/10.1016/j.respol.2022.104701

Canavese, D., Regano, L., & Lioy, A. (2023). Computer-aided reverse engineering of protected software. In A. Skarmeta, D. Canavese, A. Lioy, & S. Matheu (Eds.), Digital sovereignty in cyber security: New challenges in future vision (Communications in Computer and Information Science, Vol. 1807, pp. 3–15). Springer. https://doi.org/10.1007/978-3-031-36096-1_1

Galissant, P., & Goubin, L. (2025). Introduction to white-box cryptography. In E. Prouff, G. Renault, M. Rivain, & C. O'Flynn (Eds.), Embedded cryptography 3 (pp. 1–22). ISTE; Wiley. https://doi.org/10.1002/9781394351930.ch1

Karthik, J., Amritha, P. P., & Sethumadhavan, M. (2020). Video game DRM: Analysis and paradigm solution. In 2020 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT) (pp. 1–4). IEEE. https://doi.org/10.1109/ICCCNT49239.2020.9225560

Volckmann, W. M., II. (2025). Revenue effects of Denuvo digital rights management on PC video games. Entertainment Computing, 52, 100885. https://doi.org/10.1016/j.entcom.2024.100885

Trusted Computing Group. (2026). Trusted Platform Module 2.0 library specification (Version 185). https://trustedcomputinggroup.org/resource/tpm-library-specification/

National Security Agency. (2024, November). Trusted Platform Module (TPM) use cases [Cybersecurity information sheet]. https://media.defense.gov/2024/Nov/06/2003579882/-1/-1/0/CSI-TPM-USE-CASES.PDF

Sankalagere Ramesh, V. K., Mewundi, S. V., Honnavalli, P. B., Kenchaiah, S. T., & Krishna Murthy, V. M. (2026). The hardware isolation gap: A systematic survey of BitLocker forensics in the TPM 2.0 era. Electronics, 15(9), 1959. https://doi.org/10.3390/electronics15091959

Wilke, L., Wichelmann, J., Morbitzer, M., & Eisenbarth, T. (2020). SEVurity: No security without integrity: Breaking integrity-free memory encryption with minimal assumptions. In 2020 IEEE Symposium on Security and Privacy (SP) (pp. 1483–1496). IEEE. https://doi.org/10.1109/SP40000.2020.00080

Li, M., Wilke, L., Wichelmann, J., Eisenbarth, T., Teodorescu, R., & Zhang, Y. (2022). A systematic look at ciphertext side channels on AMD SEV-SNP. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 337–351). IEEE. https://doi.org/10.1109/SP46214.2022.9833768

Cassano, L., Iamundo, M., Lopez, T. A., Nazzari, A., & Di Natale, G. (2022). DETON: Defeating hardware Trojan horses in microprocessors through software obfuscation. Journal of Systems Architecture, 129, 102592. https://doi.org/10.1016/j.sysarc.2022.102592

Mohammad, S., & Farahmandi, F. (2024). DyFORA: Dynamic firmware obfuscation and remote attestation using hardware signatures. In Proceedings of the Great Lakes Symposium on VLSI 2024 (pp. 471–476). ACM. https://doi.org/10.1145/3649476.3658715

Saleh, K., Darweesh, D., Darwish, O., Hammad, E., & Amsaad, F. (2025). Hardware and software methods for secure obfuscation and deobfuscation: An in-depth analysis. Computers, 14(7), 251. https://doi.org/10.3390/computers14070251

Zhou, J., & Zhang, X. (2021). Generalized SAT-attack-resistant logic locking. IEEE Transactions on Information Forensics and Security, 16, 2581–2592. https://doi.org/10.1109/TIFS.2021.3059271

Quarta, D., Ianni, M., Machiry, A., Fratantonio, Y., Gustafson, E., Balzarotti, D., Lindorfer, M., Vigna, G., & Kruegel, C. (2021). Tarnhelm: Isolated, transparent & confidential execution of arbitrary code in ARM's TrustZone. In Proceedings of the 2021 Research on Offensive and Defensive Techniques in the Context of Man At The End (MATE) Attacks (pp. 43–57). ACM. https://doi.org/10.1145/3465413.3488571

McDonald, J. T., Manikyam, R., Bardin, S., Bonichon, R., & Andel, T. R. (2021). Program protection through software-based hardware abstraction. In Proceedings of the 18th International Conference on Security and Cryptography (SECRYPT 2021) (pp. 247–258). SciTePress. https://doi.org/10.5220/0010557502470258

Sisejkovic, D., & Leupers, R. (2023). Logic locking: A practical approach to secure hardware. Springer. https://doi.org/10.1007/978-3-031-19123-7

Rivain, M. (2025). White-box cryptography. In S. Jajodia, P. Samarati, & M. Yung (Eds.), Encyclopedia of cryptography, security and privacy (3rd ed., pp. 2780–2786). Springer. https://doi.org/10.1007/978-3-030-71522-9_1793

Bogdanov, A., Isobe, T., & Tischhauser, E. (2016). Towards practical whitebox cryptography: Optimizing efficiency and space hardness. In J. H. Cheon & T. Takagi (Eds.), Advances in cryptology – ASIACRYPT 2016 (Lecture Notes in Computer Science, Vol. 10031, pp. 126–158). Springer. https://doi.org/10.1007/978-3-662-53887-6_5

Tang, Y., Gong, Z., Li, B., & Zhao, L. (2023). Revisiting the computation analysis against internal encodings in white-box implementations. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(4), 493–522. https://doi.org/10.46586/tches.v2023.i4.493-522

Bos, J. W., Hubain, C., Michiels, W., & Teuwen, P. (2016). Differential computation analysis: Hiding your white-box designs is not enough. In B. Gierlichs & A. Y. Poschmann (Eds.), Cryptographic hardware and embedded systems – CHES 2016 (Lecture Notes in Computer Science, Vol. 9813, pp. 215–236). Springer. https://doi.org/10.1007/978-3-662-53140-2_11

Lu, J., Wang, M., Wang, C., & Yang, C. (2024). Collision-based attacks on white-box implementations of the AES block cipher. In B. Smith & H. Wu (Eds.), Selected areas in cryptography (SAC 2022) (Lecture Notes in Computer Science, Vol. 13742, pp. 328–352). Springer. https://doi.org/10.1007/978-3-031-58411-4_15

Microsoft. (2026, August 18). Trusted Platform Module technology overview. Microsoft Learn. https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview

Galloro, N., Polino, M., Carminati, M., Continella, A., & Zanero, S. (2022). A systematical and longitudinal study of evasive behaviors in Windows malware. Computers & Security, 113, 102550. https://doi.org/10.1016/j.cose.2021.102550

x64dbg. (n.d.). ScyllaHide: Advanced usermode anti-anti-debugger [Computer software]. GitHub. https://github.com/x64dbg/ScyllaHide

Downloads

Published

2026-09-30

How to Cite

Kozhakhmet, Z. ., Myrzatay, A. ., Ryzhova, A., & Jussupova, G. . (2026). Hardware-Bound Split-Key Framework for Software Protection Against Reverse Engineering. Scientific Journal of Astana IT University, 27(3), 280–299. https://doi.org/10.37943/ZHXT2203

Issue

Section

Cybersecurity