Hardware-Bound Split-Key Framework for Software Protection Against Reverse Engineering
DOI:
https://doi.org/10.37943/ZHXT2203%20Keywords:
cryptography, data security, key generation, trusted platform module, platform’s configuration registersAbstract
Software piracy and reverse engineering cause significant damage to intellectual property: the commercial value of unlicensed software installed worldwide has been estimated at over USD 46 billion. Traditional protection methods rely on static encryption keys or on obfuscation, and they are not resistant to modern analysis techniques such as differential computation analysis (DCA). This study addresses the single point of failure in software protection systems by developing a new key management architecture. The paper introduces a distributed split-key software-hardware framework. A deterministic decryption key is divided into three parts: a local key derived from the unique properties of the machine's hardware (hardware fingerprint), a server key issued after authenticated online activation, and a key sealed in a Trusted Platform Module (TPM) and bound to the platform's Platform Configuration Registers (PCRs). The final key is assembled exclusively in RAM during program execution through an XOR operation and is erased immediately after use. A C#/.NET 8 reference implementation was evaluated on a single Windows platform with a discrete TPM 2.0 module. Changing any of the five hardware identifiers or the PCR state prevented decryption, the assembled key remained in memory for a median of 15.6 µs, key assembly took 0.3 µs, and the one-time TPM sealing took about 67 ms. The runtime overhead stayed below 5% for typical protected functions. The analysis also identifies the remaining limitations of the design: code harvesting through legitimate decryption, binary patching that does not affect PCR 0 and PCR 7, clock rollback during the offline grace period, and loss of access after legitimate firmware or Secure Boot updates. The framework binds execution to authorized hardware and raises the cost of reverse engineering.
References
BSA | The Software Alliance. (2018). Software management: Security imperative, business opportunity (BSA Global Software Survey). https://www.bsa.org/files/reports/2018_BSA_GSS_Report_en.pdf
Bradley, W. A., & Kolev, J. (2023). How does digital piracy affect innovation? Evidence from software firms. Research Policy, 52(3), 104701. https://doi.org/10.1016/j.respol.2022.104701
Canavese, D., Regano, L., & Lioy, A. (2023). Computer-aided reverse engineering of protected software. In A. Skarmeta, D. Canavese, A. Lioy, & S. Matheu (Eds.), Digital sovereignty in cyber security: New challenges in future vision (Communications in Computer and Information Science, Vol. 1807, pp. 3–15). Springer. https://doi.org/10.1007/978-3-031-36096-1_1
Galissant, P., & Goubin, L. (2025). Introduction to white-box cryptography. In E. Prouff, G. Renault, M. Rivain, & C. O'Flynn (Eds.), Embedded cryptography 3 (pp. 1–22). ISTE; Wiley. https://doi.org/10.1002/9781394351930.ch1
Karthik, J., Amritha, P. P., & Sethumadhavan, M. (2020). Video game DRM: Analysis and paradigm solution. In 2020 11th International Conference on Computing, Communication and Networking Technologies (ICCCNT) (pp. 1–4). IEEE. https://doi.org/10.1109/ICCCNT49239.2020.9225560
Volckmann, W. M., II. (2025). Revenue effects of Denuvo digital rights management on PC video games. Entertainment Computing, 52, 100885. https://doi.org/10.1016/j.entcom.2024.100885
Trusted Computing Group. (2026). Trusted Platform Module 2.0 library specification (Version 185). https://trustedcomputinggroup.org/resource/tpm-library-specification/
National Security Agency. (2024, November). Trusted Platform Module (TPM) use cases [Cybersecurity information sheet]. https://media.defense.gov/2024/Nov/06/2003579882/-1/-1/0/CSI-TPM-USE-CASES.PDF
Sankalagere Ramesh, V. K., Mewundi, S. V., Honnavalli, P. B., Kenchaiah, S. T., & Krishna Murthy, V. M. (2026). The hardware isolation gap: A systematic survey of BitLocker forensics in the TPM 2.0 era. Electronics, 15(9), 1959. https://doi.org/10.3390/electronics15091959
Wilke, L., Wichelmann, J., Morbitzer, M., & Eisenbarth, T. (2020). SEVurity: No security without integrity: Breaking integrity-free memory encryption with minimal assumptions. In 2020 IEEE Symposium on Security and Privacy (SP) (pp. 1483–1496). IEEE. https://doi.org/10.1109/SP40000.2020.00080
Li, M., Wilke, L., Wichelmann, J., Eisenbarth, T., Teodorescu, R., & Zhang, Y. (2022). A systematic look at ciphertext side channels on AMD SEV-SNP. In 2022 IEEE Symposium on Security and Privacy (SP) (pp. 337–351). IEEE. https://doi.org/10.1109/SP46214.2022.9833768
Cassano, L., Iamundo, M., Lopez, T. A., Nazzari, A., & Di Natale, G. (2022). DETON: Defeating hardware Trojan horses in microprocessors through software obfuscation. Journal of Systems Architecture, 129, 102592. https://doi.org/10.1016/j.sysarc.2022.102592
Mohammad, S., & Farahmandi, F. (2024). DyFORA: Dynamic firmware obfuscation and remote attestation using hardware signatures. In Proceedings of the Great Lakes Symposium on VLSI 2024 (pp. 471–476). ACM. https://doi.org/10.1145/3649476.3658715
Saleh, K., Darweesh, D., Darwish, O., Hammad, E., & Amsaad, F. (2025). Hardware and software methods for secure obfuscation and deobfuscation: An in-depth analysis. Computers, 14(7), 251. https://doi.org/10.3390/computers14070251
Zhou, J., & Zhang, X. (2021). Generalized SAT-attack-resistant logic locking. IEEE Transactions on Information Forensics and Security, 16, 2581–2592. https://doi.org/10.1109/TIFS.2021.3059271
Quarta, D., Ianni, M., Machiry, A., Fratantonio, Y., Gustafson, E., Balzarotti, D., Lindorfer, M., Vigna, G., & Kruegel, C. (2021). Tarnhelm: Isolated, transparent & confidential execution of arbitrary code in ARM's TrustZone. In Proceedings of the 2021 Research on Offensive and Defensive Techniques in the Context of Man At The End (MATE) Attacks (pp. 43–57). ACM. https://doi.org/10.1145/3465413.3488571
McDonald, J. T., Manikyam, R., Bardin, S., Bonichon, R., & Andel, T. R. (2021). Program protection through software-based hardware abstraction. In Proceedings of the 18th International Conference on Security and Cryptography (SECRYPT 2021) (pp. 247–258). SciTePress. https://doi.org/10.5220/0010557502470258
Sisejkovic, D., & Leupers, R. (2023). Logic locking: A practical approach to secure hardware. Springer. https://doi.org/10.1007/978-3-031-19123-7
Rivain, M. (2025). White-box cryptography. In S. Jajodia, P. Samarati, & M. Yung (Eds.), Encyclopedia of cryptography, security and privacy (3rd ed., pp. 2780–2786). Springer. https://doi.org/10.1007/978-3-030-71522-9_1793
Bogdanov, A., Isobe, T., & Tischhauser, E. (2016). Towards practical whitebox cryptography: Optimizing efficiency and space hardness. In J. H. Cheon & T. Takagi (Eds.), Advances in cryptology – ASIACRYPT 2016 (Lecture Notes in Computer Science, Vol. 10031, pp. 126–158). Springer. https://doi.org/10.1007/978-3-662-53887-6_5
Tang, Y., Gong, Z., Li, B., & Zhao, L. (2023). Revisiting the computation analysis against internal encodings in white-box implementations. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2023(4), 493–522. https://doi.org/10.46586/tches.v2023.i4.493-522
Bos, J. W., Hubain, C., Michiels, W., & Teuwen, P. (2016). Differential computation analysis: Hiding your white-box designs is not enough. In B. Gierlichs & A. Y. Poschmann (Eds.), Cryptographic hardware and embedded systems – CHES 2016 (Lecture Notes in Computer Science, Vol. 9813, pp. 215–236). Springer. https://doi.org/10.1007/978-3-662-53140-2_11
Lu, J., Wang, M., Wang, C., & Yang, C. (2024). Collision-based attacks on white-box implementations of the AES block cipher. In B. Smith & H. Wu (Eds.), Selected areas in cryptography (SAC 2022) (Lecture Notes in Computer Science, Vol. 13742, pp. 328–352). Springer. https://doi.org/10.1007/978-3-031-58411-4_15
Microsoft. (2026, August 18). Trusted Platform Module technology overview. Microsoft Learn. https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview
Galloro, N., Polino, M., Carminati, M., Continella, A., & Zanero, S. (2022). A systematical and longitudinal study of evasive behaviors in Windows malware. Computers & Security, 113, 102550. https://doi.org/10.1016/j.cose.2021.102550
x64dbg. (n.d.). ScyllaHide: Advanced usermode anti-anti-debugger [Computer software]. GitHub. https://github.com/x64dbg/ScyllaHide
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Articles are open access under the Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who publish a manuscript in this journal agree to the following terms:
- The authors reserve the right to authorship of their work and transfer to the journal the right of first publication under the terms of the Creative Commons Attribution License, which allows others to freely distribute the published work with a mandatory link to the the original work and the first publication of the work in this journal.
- Authors have the right to conclude independent additional agreements that relate to the non-exclusive distribution of the work in the form in which it was published by this journal (for example, to post the work in the electronic repository of the institution or publish as part of a monograph), providing the link to the first publication of the work in this journal.
- Other terms stated in the Copyright Agreement.