Jump to content

Arxan Technologies

From Wikipedia, the free encyclopedia
Arxan Technologies
Company typePrivate
IndustryIT, Cybersecurity, Application Security
Founded2001
Headquarters,
USA
Number of locations
USA (6), United Kingdom (1), France (1), Germany (1), Sweden (1), Japan (1), Korea (1)
Key people
  • Joe Sander (CEO)
  • James Love (CRO)
  • Charlie Velasquez (CFO)
ProductsArxan Code Protection, Cryptographic Key & Data Protection, Threat Analytics, and App Management
Websitewww.arxan.com

Digital Ai (Formerly known as Arxan Technologies) is an American technology company specializing in anti-tamper and digital rights management (DRM) for Internet of Things (IoT), mobile, and other applications. Arxan's security products are used to prevent tampering or reverse engineering of software, thus preventing access or modifications to said software that are deemed undesirable by its developer. The company reports that applications secured by it are running on over 500 million devices. Its products are used across a range of industries, including mobile payments & banking, automotive, healthcare and gaming.[1][2][3]

History

[edit]

Arxan is privately held and private equity-backed. In the fall of 2013, TA Associates, a private equity firm, completed a majority investment in Arxan Technologies. Previously, the company received Series B funding in 2003,[4] followed by $13 million in Series C funding in 2007 and a Series D funding of $4 million in 2009.[citation needed] Early investors included Trident Capital, EDF Ventures, Legend Ventures, Paladin Capital, Dunrath Capital, TDF Fund and Solstice Capital.

Arxan was founded in 2001 by Eric Davis and Purdue University researchers, Mikhail Atallah, Tim Korb, John Rice and Hoi Chang. The first funding came from Richard Early and Dunrath Capital. Rich Early subsequently became Arxan's first CEO. The company's early intellectual property was licensed from Purdue University. The company's initial focus was on defense anti-tamper applications. Following the sale of its defense technology unit, Arxan Defense Systems, to Microsemi in 2010,[5] Arxan focused on commercial applications.

In April 2020, Arxan Technologies joined CollabNet VersionOne and XebiaLabs to form Digital.ai, a software company with the stated aim of 'pulling software development, business agility and application security into a single platform'.[6][7]

Products

[edit]

Arxan offers a number of Anti-Tamper Software products for application and cryptographic key protection. These include:

  • Arxan Code Protection to secure Mobile, IoT & Embedded, Desktop and Server applications
  • Arxan Cryptographic Key & Data Protection to secure secret keys and data with white-box cryptography, which provide all the major crypto algorithms and features required to protect sensitive keys and data in hostile or untrusted operational environments.

In May 2012, the company announced comprehensive support for Android application protection and hardening against tampering and piracy.[8] In June 2014, Arxan announced that its mobile application protection offerings will be sold by IBM as part of IBM's portfolio of security products.

The core technology consists of a multi-layered, interconnected network of Guards that each perform a specific security function and are embedded into application binaries to make programs tamper-aware, tamper-resistant, and self-healing. The company claims a three-layer protection paradigm of defend, detect and react as a differentiating approach. By detecting when an attack is being attempted and responding to detected attacks with alerts and repairs, this protection helps secure software against hacking attacks and threats such as:[9]

  • static reverse engineering or code analysis
  • dynamic reverse engineering or debugging
  • tampering to disable or circumvent security mechanisms (authentication, encryption, anti-virus, security policies, etc.)
  • tampering to modify program functionality
  • tampering for piracy or unauthorized use
  • insertion of malware into an application
  • counterfeiting and IP theft
  • stealing of cryptographic keys

IoT anti-tamper

[edit]

Arxan's IoT products insert the anti-tamper protection into the firmware of the device itself, causing parts of the code to continually check each other for integrity. If any tamper attempt is detected, Arxan's product can either attempt to restore the code to its original form, stop the firmware from running entirely, send a notification to the developer or any combination of the three.[10]

DRM

[edit]

Its DRM solutions have been compared to their competitor Denuvo, with both working to provide a layer of anti-tamper security on top of already existing copy protection mechanisms added by the developer. This results in a multi-layered approach in which the original DRM software protects the software from unauthorized copying, modification or use, while Arxan prevents any attempt to remove or alter said protection. However, much like with Denuvo's application of it, this approach has also been criticised for increasing the use of system resources. Arxan has previously expressed strong confidence that its DRM solutions would not be cracked, but in fact cracks or bypasses for Arxan products have been shown to exist; in one example Zoo Tycoon Ultimate Animal Collection was successfully cracked in 2018 while using a five-layer approach featuring UWP, XbLA, MSStore, EAppX and Arxan protection simultaneously.[11][12][13] Several more bypasses of Arxan's protection have since emerged in 2018[14] and 2019, with Arxan-protected Gears 5 being cracked by a scene group less than two weeks following its original release.[15]

See also

[edit]

References

[edit]
  1. ^ Rosen, Sam. "Arxan Hardens Multiplatform DRM Solutions". ABI Research. Archived from the original on 16 March 2012. Retrieved 25 April 2012.
  2. ^ "Protecting TV Video Content that is Viewed on Multiple Types of Consumer Electronic – CE Devices". IPTV Magazine. Archived from the original on February 21, 2013. Retrieved 25 April 2012.
  3. ^ "So many DRMs, so many headaches" (PDF). CSI Magazine: 36. Jan–Feb 2012.
  4. ^ "Clearing Economic Hurdles, Arxan, Griffin secure additional financing" (PDF). Biz Voice Magazine. Archived from the original (PDF) on 2010-02-15.
  5. ^ "Microsemi acquires Arxan Defense Systems, Inc". Microsemi. Archived from the original on 2012-03-29. Retrieved 2012-05-21.
  6. ^ www.ITSecurityNews.info (2020-04-16). "Arxan Technologies Joins New Software Company Digital.ai | | IT Security News". Retrieved 2020-04-17.
  7. ^ "Arxan Technologies Becomes Part of Digital.ai". Bloomberg.com. 2020-04-16. Retrieved 2020-04-17.
  8. ^ "Android Security: Protection of Java and Native Apps". Android Security. 17 May 2012.
  9. ^ Dager, Mike (16 July 2009). "Cyberattack Defense: Staying One Step Ahead of Hackers". TechNewsWorld. Retrieved 25 April 2012.
  10. ^ "Securing the Internet of Things". PCMAG. Retrieved 2020-06-25.
  11. ^ "Pirates Crack Microsoft's UWP Protection, Five Layers of DRM Defeated * TorrentFreak". TorrentFreak. 2018-02-15. Retrieved 2020-06-25.
  12. ^ Hagedoorn, Hilbert. "Windows 10 UWP protection may have been cracked, Zoo Tycoon Ultimate AC had five layers of DRM". Guru3D.com. Retrieved 2020-06-25.
  13. ^ Popa, Bogdan (16 February 2018). "Pirates Crack the First Windows 10 UWP Game". softpedia. Retrieved 2020-06-25.
  14. ^ Popa, Bogdan (13 March 2018). "Gears of War 4 for Windows 10 (UWP) Cracked by CODEX". softpedia. Retrieved 2020-06-25.
  15. ^ "Gears of War 5 Cracked by CODEX after 13 Days of Release". TheNerdMag. 2019-09-22. Retrieved 2020-06-25.