Method for monitoring the validity of a licence, computer program product and computer-readable medium
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- SIEMENS AG
- Filing Date
- 2024-08-02
- Publication Date
- 2026-05-06
Smart Images

Figure EP2024072007_06032025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Method for monitoring the validity of a license, computer program product and computer-readable medium
[0003] The present invention relates to a method, in particular a computer-aided method, for monitoring the validity of a time-limited license for a device, in particular for a functionality of a device, preferably for a software product on a device, of a user.
[0004] Furthermore, the invention relates to a computer program product and a computer-readable medium.
[0005] Particularly with software products, the business model whereby users acquire a right of use or a license for a specific period of time is becoming increasingly established. This means that after purchase and payment, the software product provided by a provider can be used for a defined period of time. The provider of the software product wants to ensure that after this period of use, further use is no longer possible, or that an extension or a new purchase of the software product is required.
[0006] The publication US 2023 / 0104585 Al - Zhang "METHOD AND APPARATUS FOR MONITORING SOFTWARE LICENSE INFORMATION, AND SERVER AND STORAGE MEDIUM" discloses the use of blockchain technology for the purposes of license management of digital products. The publication US 2023 / 0245102 Al - Mistele "NON FUNGIBLE TOKEN (NET) BASED LICENSING AND DIGITAL RIGHTS MANAGEMENT (DRM) FOR SOFTWARE AND OTHER DIGITAL ASSETS" also uses blockchain technology to represent the license information in a non-fungible token (NET).
[0007] The publication US 2018 / 0314809 Al - Mintz et al. "ENTITLEMENT MANAGEMENT SYSTEM" combines blockchain technology with a smart contract concept for the license management of digital products, whereby a license token can contain executable code for validating access to the digital product.
[0008] Such devices usually have an internal clock. Based on such internal time information, it's easy to monitor whether a license for a device, for example, for a software product, is still valid or has expired.
[0009] While such monitoring is relatively simple, it is not tamper-proof. Typically, every device allows users to change the date and time on the internal clock. In practice, it would be possible to regularly reset the date so that—despite the expiration of the time-limited license—the license is still recognized as valid. This would allow the device to continue to be used virtually indefinitely without any problems.
[0010] To counter this problem, it is possible to connect the device in question to a Network Time Protocol (NTP) server. In particular, this can be a trusted, i.e. a particularly reliable NTP server. In this way, the correct time can be made available at all times. Manipulation of the time is no longer possible. However, this solution is not suitable for all devices. In particular, devices located in industrial plants, for example, are often not connected to the Internet and therefore a permanent connection to an NTP server is not possible. In addition, additional communication channels are required, which entails increased complexity.
[0011] In order to prevent unauthorized duplication of licenses by users, blockchain technology is increasingly being used to manage licenses. In this case, non-fungible tokens, i.e. unique, non-replicable tokens, can be used as digital twins of licenses. These are usually generated and provided by a provider and transferred to a wallet assigned to the respective device in order to release the device or a functionality of the device, preferably a software product on this device, for use by the user. Transaction data relating to the transfer to the device-specific wallet is stored in a blockchain data structure. Due to the high level of security against manipulation of the blockchain data structure, it is determined which device and which user has the license.On the other hand, unauthorized duplication of the nonfungible token representing the license or manipulation of the blockchain data structure is largely excluded due to synchronization across a large number of nodes in a blockchain network.
[0012] However, blockchain technology does not typically have a system clock; instead, the block in question is assigned a timestamp that reflects the time of the transaction. As long as no new blocks are created, no new timestamp is generated, which makes monitoring the remaining term of a license very difficult. In other words, the timestamp does not indicate the current time, but merely the time of the last transaction. Furthermore, there is the problem that devices are not always permanently connected to the network, i.e., to other nodes in the blockchain network. Furthermore, the timestamps are based on probabilistic processes, so that a deviation from the real system time can occur.
[0013] Against this background, the object of the present invention is to provide a method for monitoring the validity of a time-limited license, which is characterized by a high level of reliability and a high level of security against manipulation.
[0014] This object is achieved in a method of the type mentioned at the outset in that the device is assigned a block chain structure on which data on private transactions are stored at different times, whereby the data each comprise a timestamp block with information on the time of the transaction and whether the license is valid is monitored on the basis of at least one timestamp block, in particular the last timestamp block present in the blockchain structure.
[0015] The invention is based on the fundamental idea of regularly generating private transactions in a blockchain structure, regularly storing transaction data with a corresponding time stamp, so that the tamper-proof blockchain structure can be used to regularly provide information about the current time. In other words, a separate blockchain structure is created on which transaction data with corresponding time stamps is regularly stored. A blockchain structure can be assigned to multiple devices, which are connected to one another, in particular in a network. It is also possible for each device to be assigned its own blockchain structure.
[0016] A blockchain is a distributed, decentralized database in which transaction data can be stored in a tamper-proof manner. A blockchain structure contains a large number of blocks, with individual blocks being added to the existing structure one after the other. In addition to one or more transactions, each block contains a so-called hash value of a previous block. The high security standard of a blockchain structure is created by a majority of trusted nodes in a blockchain network, which performs what is known as block validation.
[0017] The chain of blocks is thus stored at numerous blockchain nodes, and the participating nodes are regularly synchronized. Information about private transactions is thus stored redundantly in the blockchain network.
[0018] Since all blocks are created based on existing blocks, with the hash value of the previous block being inserted into a new block, a chain is formed. The transactions are thus protected from manipulation, as a chain can be traced back to an initial block by chaining the blocks. Since the transactions are available via the blockchain network, it is possible to trace from which block in the chain, for example, the content of a transaction no longer matches the previous version. Changing a transaction in a block that was already created at an earlier point in time in the network would be traceable if the hash value does not match the previous block.
[0019] The invention takes advantage of the fact that private transactions regularly take place in the blockchain structure, the transaction data of which is stored with a timestamp. These private transactions, which can take place, for example, in a user's network, thus lead to regular information about the current time. The private transactions preferably take place within a user-side network. The main purpose of the private transactions is to regularly create new blocks in the blockchain structure and to store time information in the process. This information can then be used to determine whether the license is still valid or has already expired. Specifically, the remaining term of the license can be calculated for this purpose.If this value is zero or less, the license has expired and will be deleted. This means that the corresponding device, and in particular any software product on that device, can no longer be used. In this case, the user must purchase a new license.
[0020] In a specific embodiment, the blockchain structure is filed or stored on a blockchain network. This can be a network that is at least partially located locally at the user's site. The network preferably comprises a plurality of nodes at the user's site. The plurality of nodes creates a high level of security against manipulation, since the data relating to private transactions is stored on several different devices in the network. The blockchain network can also be located entirely at the user's site. In particular, the blockchain network may not be permanently connected to the internet, preferably only occasionally. In a further embodiment, regular synchronization can take place within the blockchain network so that the blockchain structure is always up to date on every node in the network.
[0021] According to the invention, a non-fungible token is assigned to the license, which represents the respective license and which is stored in a device-related wallet or transferred to such a wallet in order to release the respective device, wherein transaction data for transferring the non-fungible token to a wallet are stored in a blockchain data structure, in particular in a user-related sidechain.
[0022] This design is based on the idea of using a blockchain data structure for licenses and generating or providing a non-fungible token as a digital twin of a license. Such a non-fungible token cannot be easily copied, thus precluding unauthorized duplication of licenses by malicious users. Specifically, such a non-fungible token can be provided or generated by a provider's private licensing network.
[0023] The blockchain data structure for storing transaction data relating to the non-fungible tokens has a sidechain assigned to each user, in which the transaction data relating to the transfer of the non-fungible tokens is stored. In practice, in this case, the blockchain data structure is divided, and a separate sidechain is created for each user, which is essentially structured like a blockchain. Each sidechain contains only the transaction data relating to one user. Preferably, it is not publicly visible which user currently holds which license.In other words, on the one hand, the high data security of non-fungible tokens can be used as digital twins of the license, while at the same time, the confidentiality of individual user data is guaranteed, since this transaction data is not publicly visible due to its storage in a sidechain. Preferably, each user only has access to the sidechains relevant to their devices. A private licensing network can have access to all sidechains.
[0024] The blockchain data structure can be designed for a specific software product. This means that different software products can use different blockchain data structures, particularly for license management. This also allows each user-specific sidechain to be designed for a specific software product. In other words, in this case, the sidechain relates not only to a specific user, but also to a specific software product. A separation into different, software-product-specific blockchain data structures can be achieved based on smart contracts.
[0025] A wallet is specifically a software that allows you to store digital objects such as non-fungible tokens.
[0026] When the non-fungible token is transferred to the device-specific wallet, the device's internal time is compared with the private licensing network, in particular with an NTP server contained in the private licensing network. This design is based on the idea that when the non-fungible token, which represents a license, is transferred, the device is connected to the private licensing network and thus has access to external information about the current time. In a further design, the non-fungible token can be created, provided, or generated on the basis of a smart contract. Such a smart contract agrees on certain conditions that are stored in the blockchain data structure. In particular, a smart contract can be defined as an if-then condition. This means that if a certain condition is met, the contract is automatically processed via the network.External verification of the contract conditions is not required because a smart contract is automatically executed when the conditions are met.
[0027] The non-fungible token can be provided or generated according to the ERC721 standard. Transferring the non-fungible token to a device-specific wallet can be done according to the ERC721 standard. The ERC721 standard is a blockchain data structure based on Ethereum. In particular, an Ethereum Virtual Machine can be used to evaluate the agreements in a smart contract.
[0028] The non-fungible token can be generated in a user's private licensing network and, in particular, transferred over the internet to the respective device-specific wallet. A private licensing network operated by a provider ensures that only the provider can create defined non-fungible tokens when a license is needed, requested, and / or acquired by a user. This gives the provider complete control over the creation of licenses.
[0029] The method according to the invention can be characterized in that the initial transfer of the non-fungible token into a user's device-specific wallet generates the blockchain structure. In other words, after generating a non-fungible token, preferably in a private licensing network, and the subsequent initial transfer of the non-fungible token into a user's device-specific wallet, the blockchain structure is generated or created, in which data relating to private transactions is stored with a time delay. Thus, when a user transfers a non-fungible token into a wallet for the first time, the blockchain structure is generated.
[0030] The initial transfer of the non-fungible token to a device-specific wallet can generate a block with an activation timestamp in the blockchain structure. This means that at the time of transfer to a device-specific wallet and thus the release of the corresponding device to the user, a defined timestamp is generated, which specifically indicates the initial activation of the device, functionality, or software product.
[0031] To increase data security and protection against tampering, the activation timestamp can be signed by a provider's private licensing network. This type of signing prevents, for example, malicious users from setting such initial activation timestamps themselves, thus enabling unauthorized use of the license. Further transactions are preferably signed by the respective wallet from which the transaction originates.
[0032] In a further embodiment, the non-fungible token representing a license can contain information on the maximum term of use of the license. Such information is also tamper-proof because it is part of the non-fungible token. This prevents users from intentionally or inadvertently changing the term of use. Particularly in conjunction with an activation timestamp, which must preferably be signed by the private licensing network, a high level of security against tampering can be achieved because, on the one hand, the activation time and the term of use of the license are stored in the blockchain structure or in the blockchain data structure in a tamper-proof manner.
[0033] To check whether the license is still valid, the smart contract can instruct the non-fungible token to query the last available timestamp block of the blockchain structure and, based on this, calculate the remaining useful life of the non-fungible token or the license it represents.
[0034] Preferably, private transactions are triggered by a time-tracking smart contract. This means that a separate smart contract exists that leads to private transactions, particularly in the user-side network. Preferably, private transactions are stored exclusively locally on the user's network.
[0035] The time recording smart contract can initiate a call to a user-side Network Time Protocol (NTP) server at regular intervals. The time recording smart contract can access an oracle, which can be used to check certain conditions in smart contracts. Such oracles, which are also referred to here as remote clock oracles, can thus access data outside the blockchain network. In other words, an oracle can be software that is designed to access information outside the blockchain network. Accordingly, in addition to the device's internal clock, which is not tamper-proof, the smart contract is designed to call a user-side, i.e., local, NTP server on an oracle at regular intervals in order to obtain information about the current time.Such a call to a user-side NTP server can be made at regular intervals. For example, such a call can be made once a day. If contact is made, further attempts to establish a connection can be ruled out for a further period of 24 hours. Attempts can also be made three times per hour, with a further attempt being made after a certain number of failed attempts for a further period. This means that even if a device is only irregularly connected to a user-side network, current time information can be obtained at least occasionally.
[0036] In a further development, the time tracking smart contract can trigger a new private transaction upon contact with the user-side NTP server, for which data is stored in the blockchain structure. This data includes a timestamp block with information about the current time. Thus, if contact is established with a user-side NTP server, a new private transaction is automatically triggered based on the time tracking smart contract, and the corresponding data is stored in the blockchain structure. This creates a timestamp block with the current time.
[0037] Furthermore, the time recording smart contract can initiate a call to an external NTP server at regular intervals, in particular an NTP server of the private licensing network. For this purpose, a remote clock oracle can be used in particular, or the time recording smart contract can access it. As a further option, in particular to obtain a verified, current time, an NTP server can be contacted at regular intervals, for example once a week or at most three times a day, for example via the Internet, which is provided by the provider or the private licensing network. This creates an additional option, in addition to the internal clock of the device and, if applicable, a user-side NTP server, of obtaining information about the current time.Such a connection can, of course, only be established if the device is at least indirectly connected to the external NTP server via the Internet. During periods in which such a connection is not established, the time can only be determined based on the user-side NTP server or the device's internal time.
[0038] The time recording smart contract or an oracle can also contact both a user-side, i.e. local NTP server, and an external NTP server at regular intervals.
[0039] Preferably, the time recording smart contract triggers private transactions at regular intervals, the data for which is stored in the blockchain structure, which includes a timestamp block with information on the current time based on the device's internal clock. In other words, transactions are regularly initiated automatically by the time recording smart contract which are based on the device's internal clock - particularly if there is no connection to a user-side, i.e. local NTP server or an external NTP server. For this purpose, the time recording smart contract can access an oracle, in particular a local clock oracle. For example, such automated transactions can be executed every hour, every half hour or every quarter hour to generate a new timestamp.Storing data related to regular private transactions can make it difficult to manipulate the device's internal clock, as timestamps are regularly stored in the blockchain structure, even if the device is not connected to an NTP server or is at least occasionally connected to one. A user resetting the device's internal clock would then be detected by the timestamps in the blockchain structure.
[0040] The method can be characterized in that, after a new private transaction, whose transaction data is stored on the blockchain structure, previous blocks of the blockchain structure are deleted or combined. In particular, such a deletion can occur if a new private transaction is based on contact with the external NTP server, since this is particularly trustworthy time information. By removing previous blocks from the blockchain structure, the data volume can be reduced.
[0041] It is also possible for a device to be connected to other devices in a device network, even if it is not connected to the internet or to another node. In this case, in particular, synchronization of the blocks relating to the transaction data can take place within this device network. Preferably, a private sidechain of the blockchain structure can be created in which the private transactions of the various devices are stored. In this case, too, a high level of time security can be achieved, even if devices are never connected to the internet.
[0042] A device can be practically any technical device. The device can comprise hardware and at least one piece of software or a software product. In particular, the license can serve to release the software or the software product for use on the device. The device can in particular be a device which has sensors for recording operating parameters in a production process or is connected to such sensors. The device can have a computer unit and / or storage means on which a software product is stored and can run. The license can in particular relate to the release of a software product on this device. The software or the software product can, for example, be operating software and / or control software and / or configuration software for setting up technical devices or systems.The device can also be configured to communicate with other devices in a device network. For this purpose, it can have wireless or wired interfaces in a conventional manner.
[0043] For the further development of the invention, reference is made to the dependent claims and to the following description of an embodiment with reference to the drawing.
[0044] The drawing shows:
[0045] Figure 1 shows a method according to the present invention in a schematic representation;
[0046] Figure 2 shows a system for carrying out the method according to the invention in a schematic representation.
[0047] Figure 1 schematically shows an embodiment of a method according to the invention for monitoring the validity of a time-limited license for a device, preferably for a software product on this device, of a user. The license is assigned a non-fungible token 2, which represents the respective license. The non-fungible token 2 is generated on a private licensing network 3. The generated non-fungible token 2 is transferred via the Internet from the private licensing network 3 to a wallet 4, which is assigned to the device 1. The transaction data for transferring the non-fungible token 2 to the device-related wallet is stored in a blockchain data structure 5, which is shown only schematically in Figure 1.Preferably, the blockchain data structure 5 comprises a plurality of software product and user-related sidechains in which the respective transaction data relating to the respective device and the respective user are stored.
[0048] Device 1 is also assigned a blockchain structure 6, on which data on private transactions is stored at a later time. The data on each private transaction includes a timestamp block 7 with information about the time of the transaction.
[0049] When the non-fungible token 2 is transferred to the device-specific wallet 4 for the first time, the blockchain structure 6 is generated and an activation timestamp 8 is created in the blockchain structure. The activation timestamp 8 is signed by the private licensing network 3.
[0050] Furthermore, there is a time-tracking smart contract 9 that triggers private transactions. At regular intervals, the time-tracking smart contract 9 determines the current time and triggers a private, i.e., locally running transaction. Firstly, the local time 11 of the device 1 is determined at regular intervals via a so-called local clock oracle 10. A private transaction is then triggered, with data relating to this transaction being stored in the blockchain structure 6. The data includes a timestamp block 7 that contains the current time.
[0051] In addition to the regular query of the local time 11 in device 1, a so-called remote clock oracle 12 initiates a call to a user-side network time (NTP) server 13 at the instigation of the time recording smart contract 9. If contact is established with this user-side NTP server 13, the time recording smart contract 9 triggers a new private transaction, for which data is stored in the blockchain structure 6. This data also includes a timestamp block 7 with information about the current time.
[0052] In addition, the time recording smart contract 9 initiates a call to an external NTP server 14 at regular intervals. If contact is established with the external NTP server 14, the time recording smart contract 9 triggers a new private transaction, the transaction data of which is also stored in the blockchain structure 6 and includes a timestamp block with information about the current time.
[0053] The method can be designed such that when a new timestamp block 7 is created, previous timestamp blocks 7 are deleted or combined. This combination is also referred to as compaction. In this way, the amount of data in the blockchain structure 6 can be kept small.
[0054] The blockchain structure 6 is stored in a blockchain network located locally at the user's location. In this way, different sources can be used to determine the current time. The determination of the current time is not limited to the local time of the device 1, which can be manipulated relatively easily, but rather information from a user-side (internal) NTP server 13 and from an external NTP server 14 is used as soon as at least temporary contact with these servers 13 is established.
[0055] 14 exists .
[0056] Figure 2 shows a system for carrying out the method according to the invention in a schematic representation. This system comprises a user-side network
[0057] 15 with a plurality of devices 1 and a user-side NTP server 13. At least part of the system, specifically the devices 1 designated by subnet A, is connected via the Internet to a private licensing network 3 of the provider. This licensing network 3 includes an external NTP server 14, which provides reliable information about the current time.
[0058] The method according to the invention now provides that private transactions, which are triggered by a time recording smart contract 9 (not shown), are regularly executed and that time stamp blocks 7 with information on the current time are stored in a blockchain structure 6.
[0059] The device 1, which is contained in subnetwork B, is not permanently connected to any other device. The method according to the invention is therefore limited to regularly carrying out private transactions, wherein time stamp blocks are stored in a local blockchain structure which receives its information from the internal clock of the device 1. The devices contained in subnetwork A are connected via an intermediate PC 16 to a user-side NTP server 13 and an external NTP server 14. The PC 16 acts as a mediator for the devices 1. Due to the permanent connection of the devices 1 via the PC 16 to the external NTP server 14, private transactions can be generated regularly, which are stored on the blockchain structure 6 related to the respective block device and contain a current time stamp block 7 based on information from the external NTP server 14.
[0060] The devices 1 assigned to subnetwork C are connected to the user-side NTP server 13 via PC 16. This means that upon contact with the user-side NTP server 13, time stamp blocks containing information about the current time are regularly stored in the respective blockchain structure 6.
[0061] Each device 1 and each PC 16 initially has an independent blockchain structure 6 .
[0062] Against the background of the architecture shown in Figure 2, it happens that individual devices 1, in particular those in subnetwork C, are never connected to the particularly trustworthy external NTP server 14 via the Internet. However, it is possible for the various blockchain structures 6 to be exchanged between the interconnected devices, so that the devices 1 contained in subnetwork C also synchronize via the user-side NTP server 13, which in turn is connected to the PC 16 in subnetwork A. In this way, the devices 1 in subnetwork C can also indirectly access the particularly trustworthy time information of the external NTP server 14, which is integrated into the private licensing network 3, using this synchronization. This further increases the security against manipulation and the accuracy of the time information.
[0063] Based on the timestamp blocks 7, in particular the last timestamp block 7 present in the respective blockchain structure 6, it is monitored whether the license represented by the non-fungible token 2 is still valid. Specifically, the non-fungible token 2 contains information on the maximum usage period of the license. The smart contract causes the non-fungible token 2 to query the last available timestamp block 7 of the respective blockchain structure 6 and, based on this, to calculate the remaining usage period of the non-fungible token 2 or the license it represents.
[0064] Although the invention has been illustrated and described in detail by the preferred embodiment, the invention is not limited to the disclosed examples and other variations may be derived therefrom by those skilled in the art without departing from the scope of the invention.
[0065] Regardless of the grammatical gender of a particular term, persons with male, female or other gender identities are included.
Claims
Patent claims 1. Method, in particular a computer-aided method, for monitoring the validity of a time-limited license for a device (1), in particular for a functionality of a device (1), preferably for a software product on a device (1), of a user, wherein the device (1) is assigned a blockchain structure (6), on which data on private transactions are stored with a time delay, wherein the data each comprise a timestamp block with information on the time of the transaction and whether the license is valid is monitored on the basis of at least one timestamp block, in particular the last timestamp block (7) present in the blockchain structure (6), characterized in that the blockchain structure (6) is stored oris stored, that the license is assigned a non-fungible token (2), which represents the respective license and which is stored in a device-related wallet (4) for releasing the respective device (1), wherein transaction data for transferring the non-fungible token (2) to a wallet (4) are stored in a user-related sidechain of a blockchain data structure (5), that the first transfer of the non-fungible token (2) to a device-related wallet generates a block with an activation timestamp (8) in the blockchain structure (6), and that the activation timestamp (8) is signed by the private licensing network.
2. Method according to claim 1, characterized in that the blockchain network z is arranged locally at the user's site, preferably comprising a plurality of nodes at the user's site.
3. Method according to claim 2, characterized in that the non-fungible token (2) is created on the basis of a smart contract.
4. Method according to claim 2 or 3, characterized in that the non-fungible token (2) is generated in a private licensing network of a user and is transferred in particular via the Internet into the respective device-related wallet (4).
5. Method according to one of claims 1 to 4, characterized in that the first transfer of the non-fungible token (2) into a device-related wallet (4) of a user generates the blockchain structure (6) 6. Method according to one of claims 1 to 5, characterized in that the non-fungible token (2) contains information on the maximum period of use of the license, wherein, in particular, the smart contract causes the non-fungible token (2) to query the last available timestamp block (7) of the blockchain structure (6) and, based thereon, to calculate the remaining period of use of the non-fungible token (2) or of the license represented by it.
7. Method according to one of the preceding claims, characterized in that the private transactions are triggered by a time recording smart contract (9), wherein, in particular, the time recording smart contract (9) causes the call of a user-side Network Time Protocol (NTP) server (13) at regular intervals, wherein, preferably, the time recording smart contract (9) upon contact with the user-side NTP server triggers a new private transaction, for which data is stored in the blockchain structure (6), which contains a time stamp block (7) with information on current time based on the user-side NTP server (13).
8. The method according to claim 7, characterized in that the time recording smart contract (9) causes the call of an external NTP server (14), in particular an NTP server of the private licensing network, at regular intervals.
9. The method according to claim 8, characterized in that the time recording smart contract (9) triggers a new private transaction upon contact with the external NTP server, the transaction data of which are stored in the blockchain structure (6) and comprise a timestamp block (7) with information on the current time based on the external NTP server (14).
10. Method according to one of claims 6 to 9, characterized in that the time recording smart contract (9) triggers private transactions at regular intervals, the data of which are stored in the blockchain structure (6), which comprises a timestamp block (7) with information on the current time based on the internal clock of the device (1).
11. A computer program product which is designed to carry out the method according to any one of the preceding claims when installed on a computer or on a computer network.
12. A computer-readable medium on which the computer program product according to claim 11 is stored.