Interoperability and Reverse Engineering Checklist: Clean Room, Documentation, Terms, and Circumvention

By ·

A reverse engineering project is defensible or indefensible on decisions made in its first week, and none of them is doctrinal. This checklist runs the work in fifteen phases: scope the requirement, choose the acquisition path, analyze access controls, adopt the clean room protocol, run the specification team, run the gatekeeper review, isolate implementation, handle and destroy intermediate copies, run the parallel patent analysis, compare before release, assemble the release file, respond to a claim, run security research and repair variants, advise the incumbent, and make the program repeatable. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before anyone touches the target. A worked program runs throughout.

IP and Technology > Information Technology | Checklist | Published 16 May 2024 - Updated 21 July 2025 | Casey Scott McKay - marksy.us

Summary. A reverse engineering project is defensible or indefensible on decisions made in its first week, and none of them is doctrinal. This checklist runs the work in fifteen phases: scope the requirement, choose the acquisition path, analyze access controls, adopt the clean room protocol, run the specification team, run the gatekeeper review, isolate implementation, handle and destroy intermediate copies, run the parallel patent analysis, compare before release, assemble the release file, respond to a claim, run security research and repair variants, advise the incumbent, and make the program repeatable. Each box gives the reason, the authority, and the trap. Boxes marked as gates should clear before anyone touches the target. A worked program runs throughout.

Keywords: scoping memorandum, acquisition path, license prohibition, preemption, access control analysis, circumvention exception, clean room protocol, specification team, implementation team, gatekeeper review, personnel attestation, transfer log, intermediate copies, destruction certificate, independent comparison, registration, freedom to operate, release file, security research, repair exemptions


How to use this checklist

| Phase | What it covers | |---|---| | 1 | Scope the requirement | | 2 | The acquisition path | | 3 | Access controls | | 4 | The clean room protocol | | 5 | The specification team | | 6 | The gatekeeper review | | 7 | Implementation | | 8 | Intermediate copies | | 9 | The parallel patent analysis | | 10 | Comparison and release | | 11 | The release file | | 12 | If a claim arrives | | 13 | Research and repair variants | | 14 | Advising the incumbent | | 15 | Making it repeatable |

Boxes marked [Gate] should clear before anyone touches the target.

The matter. A file converter for a competitor's proprietary format. Twenty-six weeks, sued two years later, resolved on summary judgment because the release file answered the access element.


Phase 1. Scope the requirement


Phase 2. The acquisition path


Phase 3. Access controls


Phase 4. The clean room protocol


Phase 5. The specification team


Phase 6. The gatekeeper review


Phase 7. Implementation


Phase 8. Intermediate copies


Phase 9. The parallel patent analysis


Phase 10. Comparison and release


Phase 11. The release file

Assemble it at release, not when a complaint arrives.


Phase 12. If a claim arrives


Phase 13. Research and repair variants

Security research

Repair and aftermarket


Phase 14. Advising the incumbent


Phase 15. Making it repeatable

Phase 16. What kind of target you have

The protocol is constant; the analysis shifts with what is being examined. Run the boxes for whichever applies.

A physical product

Embedded firmware

Packaged software

A hosted service

Network traffic

Files a customer holds

Code produced in litigation


Phase 17. Staffing and cost


Phase 18. Failure modes, collected


Phase 19. When not to proceed


Phase 20. Standards implementation

Where a standard governs, the whole shape of the work changes and most of this checklist does not apply.


Phase 21. The one-page decision framework

Before any examination begins, answer these seven questions in writing.


Phase 22. The gatekeeper's working rules

The role decides more outcomes than any other, and it benefits from a written set of rules the gatekeeper applies consistently.

Phase 23. Making it repeatable

Outcome. The company bought the retail box rather than downloading under a prohibition, documented the absence of access controls, worked primarily from customer-held sample files rather than from code, adopted the protocol before any examination, and had counsel remove three artifacts from the specification. The independent comparison found nothing. Sued two years later, the case turned on access; the release file answered it; the matter resolved on summary judgment. The incremental cost of the discipline was the price difference between a download and a box, counsel's gatekeeper time, the independent review, and two weeks of schedule.


Key Authorities at a Glance

| Authority | Proposition | Phase | |---|---|---| | 17 U.S.C. § 102(b) | Ideas, procedures, and methods unprotected | 5, 12 | | 17 U.S.C. § 106 | Reproduction; intermediate copies | 8 | | 17 U.S.C. § 107 | Fair use; copying for analysis | 8 | | 17 U.S.C. § 109 | First sale; lawful acquisition | 2 | | 17 U.S.C. § 117 | Essential step and archival copies | 8 | | 17 U.S.C. § 301 | Preemption; contractual prohibitions | 2 | | 17 U.S.C. § 411 | Registration as a precondition | 10, 12 | | 17 U.S.C. § 504 | Statutory damages | 10 | | 17 U.S.C. § 505 | Fees | 12 | | 17 U.S.C. § 1201 | Circumvention; interoperability exception | 3 | | 17 U.S.C. § 1202 | Copyright management information | 10 | | 18 U.S.C. § 1030 | Computer access; hosted targets | 2 | | 18 U.S.C. § 1836 | Trade secret civil action | 12 | | 18 U.S.C. § 1839(6) | Reverse engineering not improper means | 13, 14 | | 35 U.S.C. § 271 | Patent infringement; no independence defense | 9 | | 35 U.S.C. § 282 | Defenses | 9 | | 35 U.S.C. § 298 | Advice of counsel | 9 | | Fed. R. Evid. 702 | Expert filtration and comparison | 12 |


The five things people get wrong

One: they start examining before anyone writes a protocol. A clean room adopted after the work began is nominal, because the specification team already includes people who will implement and the implementation team already includes people who saw the target. Access is conceded in fact whatever the paper says.

Two: they download the target under a license prohibiting the work. The same product was frequently available for purchase on the open market, and the price difference is trivial against removing the contract question entirely.

Three: they put an engineer in the gatekeeper role. Engineers optimize for a clear specification, which is precisely the pressure that pushes identifiers, error text, and structural detail across the boundary from function into expression.

Four: they never ask whether an access control is present. 17 U.S.C. § 1201 prohibits circumvention independent of infringement, the exceptions are narrow, and a project that skipped the question rather than answering it has an unexamined claim waiting.

Five: they run the patent analysis at release. A clean room does nothing about patents, independent development is no defense under 35 U.S.C. § 271, and a design-around that would have cost little in month one costs a redesign in month twenty-five. See Running a Reverse Engineering or Interoperability Program.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Reverse engineering outcomes turn on specific products, agreements, and records. Marksy is not a law firm.

Read this article on Marksy