Arxan Technologies

{{Short description|US technology security company}}

{{Infobox company|

| type = Private

| logo = Arxan logo.png

| industry = IT, Cybersecurity, Application Security

| founded = 2001

| key_people = {{unbulleted list|Joe Sander (CEO)|James Love (CRO)|Charlie Velasquez (CFO)}}

| location_city = San Francisco, CA

| location_country = USA

| locations = USA (6), United Kingdom (1), France (1), Germany (1), Sweden (1), Japan (1), Korea (1)

| products = Arxan Code Protection, Cryptographic Key & Data Protection, Threat Analytics, and App Management

| website = [http://www.arxan.com www.arxan.com]

}}

Digital Ai (Formerly known as Arxan Technologies) is an American technology company specializing in anti-tamper and digital rights management (DRM) for Internet of Things (IoT), mobile, and other applications. Arxan's security products are used to prevent tampering or reverse engineering of software, thus preventing access or modifications to said software that are deemed undesirable by its developer. The company reports that applications secured by it are running on over 500 million devices. Its products are used across a range of industries, including mobile payments & banking, automotive, healthcare and gaming.{{cite web|last=Rosen|first=Sam|title=Arxan Hardens Multiplatform DRM Solutions|url=http://www.abiresearch.com/research_blog/1675|publisher=ABI Research|accessdate=25 April 2012|archive-url=https://web.archive.org/web/20120316103025/http://www.abiresearch.com/research_blog/1675|archive-date=16 March 2012|url-status=dead}}{{cite web|title=Protecting TV Video Content that is Viewed on Multiple Types of Consumer Electronic – CE Devices|url=http://www.iptv-blog.net/2011/06/protecting-tv-video-content-that-is.html|archive-url=https://archive.today/20130221230324/http://www.iptv-blog.net/2011/06/protecting-tv-video-content-that-is.html|url-status=dead|archive-date=February 21, 2013|publisher=IPTV Magazine|accessdate=25 April 2012}}{{cite journal|title=So many DRMs, so many headaches|journal=CSI Magazine|date=Jan–Feb 2012|pages=36|url=http://www.csimagazine.com/Digital_edition/csi_digital-csi-jan-feb12.pdf?vcabid=geaSelgnlSgrapgc&count=30/11/2011}}

History

Arxan is privately held and private equity-backed. In the fall of 2013, TA Associates, a private equity firm, completed a majority investment in Arxan Technologies. Previously, the company received Series B funding in 2003,{{cite web|url=http://www.bizvoicemagazine.com/archives/03sepoct/Financing.pdf |publisher=Biz Voice Magazine |title=Clearing Economic Hurdles, Arxan, Griffin secure additional financing |url-status=dead |archiveurl=https://web.archive.org/web/20100215144442/http://www.bizvoicemagazine.com/archives/03sepoct/Financing.pdf |archivedate=2010-02-15 }} followed by $13 million in Series C funding in 2007 and a Series D funding of $4 million in 2009.{{Citation needed|date=July 2020}} Early investors included Trident Capital, EDF Ventures, Legend Ventures, Paladin Capital, Dunrath Capital, TDF Fund and Solstice Capital.

Arxan was founded in 2001 by Eric Davis and Purdue University researchers, Mikhail Atallah, Tim Korb, John Rice and Hoi Chang. The first funding came from Richard Early and Dunrath Capital. Rich Early subsequently became Arxan's first CEO. The company's early intellectual property was licensed from Purdue University. The company's initial focus was on defense anti-tamper applications. Following the sale of its defense technology unit, Arxan Defense Systems, to Microsemi in 2010,{{cite web|url=http://investor.microsemi.com/releasedetail.cfm?releaseid=507698|publisher=Microsemi|title=Microsemi acquires Arxan Defense Systems, Inc.|access-date=2012-05-21|archive-url=https://web.archive.org/web/20120329144726/http://investor.microsemi.com/releasedetail.cfm?ReleaseID=507698|archive-date=2012-03-29|url-status=dead}} Arxan focused on commercial applications.

In April 2020, Arxan Technologies joined CollabNet VersionOne and XebiaLabs to form Digital.ai, a software company with the stated aim of 'pulling software development, business agility and application security into a single platform'.{{Cite web|url=https://www.itsecuritynews.info/arxan-technologies-joins-new-software-company-digital-ai/|title=Arxan Technologies Joins New Software Company Digital.ai {{!}} {{!}} IT Security News|last=www.ITSecurityNews.info|date=2020-04-16|language=en-US|access-date=2020-04-17}}{{Cite web|last=|first=|date=2020-04-16|title=Arxan Technologies Becomes Part of Digital.ai|url=https://www.bloomberg.com/press-releases/2020-04-16/arxan-technologies-becomes-part-of-digital-ai|access-date=2020-04-17|website=Bloomberg.com}}

Products

Arxan offers a number of Anti-Tamper Software products for application and cryptographic key protection. These include:

  • Arxan Code Protection to secure Mobile, IoT & Embedded, Desktop and Server applications
  • Arxan Cryptographic Key & Data Protection to secure secret keys and data with white-box cryptography, which provide all the major crypto algorithms and features required to protect sensitive keys and data in hostile or untrusted operational environments.

In May 2012, the company announced comprehensive support for Android application protection and hardening against tampering and piracy.{{cite web|url=http://www.net-security.org/secworld.php?id=12946|publisher=Android Security|title=Android Security: Protection of Java and Native Apps|date=17 May 2012 }} In June 2014, Arxan announced that its mobile application protection offerings will be sold by IBM as part of IBM's portfolio of security products.

The core technology consists of a multi-layered, interconnected network of Guards that each perform a specific security function and are embedded into application binaries to make programs tamper-aware, tamper-resistant, and self-healing. The company claims a three-layer protection paradigm of defend, detect and react as a differentiating approach.

By detecting when an attack is being attempted and responding to detected attacks with alerts and repairs, this protection helps secure software against hacking attacks and threats such as:{{cite web|last=Dager|first=Mike|title=Cyberattack Defense: Staying One Step Ahead of Hackers|date=16 July 2009 |url=http://www.technewsworld.com/story/67605.html|publisher=TechNewsWorld|accessdate=25 April 2012}}

  • static reverse engineering or code analysis
  • dynamic reverse engineering or debugging
  • tampering to disable or circumvent security mechanisms (authentication, encryption, anti-virus, security policies, etc.)
  • tampering to modify program functionality
  • tampering for piracy or unauthorized use
  • insertion of malware into an application
  • counterfeiting and IP theft
  • stealing of cryptographic keys

= IoT anti-tamper =

Arxan's IoT products insert the anti-tamper protection into the firmware of the device itself, causing parts of the code to continually check each other for integrity. If any tamper attempt is detected, Arxan's product can either attempt to restore the code to its original form, stop the firmware from running entirely, send a notification to the developer or any combination of the three.{{Cite web|title=Securing the Internet of Things|url=https://www.pcmag.com/news/securing-the-internet-of-things|access-date=2020-06-25|website=PCMAG|language=en}}

= DRM =

Its DRM solutions have been compared to their competitor Denuvo, with both working to provide a layer of anti-tamper security on top of already existing copy protection mechanisms added by the developer. This results in a multi-layered approach in which the original DRM software protects the software from unauthorized copying, modification or use, while Arxan prevents any attempt to remove or alter said protection. However, much like with Denuvo's application of it, this approach has also been criticised for increasing the use of system resources. Arxan has previously expressed strong confidence that its DRM solutions would not be cracked, but in fact cracks or bypasses for Arxan products have been shown to exist; in one example Zoo Tycoon Ultimate Animal Collection was successfully cracked in 2018 while using a five-layer approach featuring UWP, XbLA, MSStore, EAppX and Arxan protection simultaneously.{{Cite web|date=2018-02-15|title=Pirates Crack Microsoft's UWP Protection, Five Layers of DRM Defeated * TorrentFreak|url=https://torrentfreak.com/pirates-crack-microsofts-uwp-protection-five-layers-of-drm-defeated-180215/|access-date=2020-06-25|website=TorrentFreak|language=en}}{{Cite web|last=Hagedoorn|first=Hilbert|title=Windows 10 UWP protection may have been cracked, Zoo Tycoon Ultimate AC had five layers of DRM|url=https://www.guru3d.com/news-story/windows-10-uwp-protection-may-have-been-crackedzoo-tycoon-ultimate-ac-had-five-layers-of-drm,3.html|access-date=2020-06-25|website=Guru3D.com|language=en-us}}{{Cite web|last=Popa|first=Bogdan|title=Pirates Crack the First Windows 10 UWP Game|url=https://news.softpedia.com/news/pirates-crack-the-first-windows-10-uwp-game-519843.shtml|access-date=2020-06-25|website=softpedia|date=16 February 2018 |language=english}} Several more bypasses of Arxan's protection have since emerged in 2018{{Cite web|last=Popa|first=Bogdan|title=Gears of War 4 for Windows 10 (UWP) Cracked by CODEX|url=https://news.softpedia.com/news/gears-of-war-4-for-windows-10-uwp-cracked-by-codex-520193.shtml|access-date=2020-06-25|website=softpedia|date=13 March 2018 |language=english}} and 2019, with Arxan-protected Gears 5 being cracked by a scene group less than two weeks following its original release.{{Cite web|date=2019-09-22|title=Gears of War 5 Cracked by CODEX after 13 Days of Release|url=https://www.thenerdmag.com/gears-of-war-5-cracked-by-codex-after-13-days-of-release/|access-date=2020-06-25|website=TheNerdMag|language=en-US}}

See also

References