System for providing access to one or more services relating to a software product and method thereof

The system addresses licensing challenges in cloud environments by using a license enforcement agent and ingress controller to map licenses to services, ensuring flexible and efficient access control across diverse products and services.

WO2025264158A1PCT designated stage Publication Date: 2025-12-26TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/SE2024/050615
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-20
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing software licensing systems face challenges in managing licenses across cloud environments, requiring invasive changes and complex re-designs when adapting to new saleable entities, especially in second/third-party services with distinct pricing models, and lack effective enforcement mechanisms.

Method used

A system and method utilizing a license enforcement agent that maps licenses to services, generates authorization policies, and controls access through an ingress controller, enabling flexible and efficient license management without modifying individual cloud native services.

Benefits of technology

Facilitates seamless license enforcement across different products with varying pricing models, supports second/third-party services, and ensures valid access control, reducing complexity and enabling periodic checks for availability and validity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SE2024050615_26122025_PF_FP_ABST
    Figure SE2024050615_26122025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of present disclosure provide system (200) and method (300) providing access to services relating to software product of the network provider (206). License enforcement agent (212) implemented in the software product. The license enforcement agent (212) being arranged to obtain the license information indicative of at least one license for at least one service of the one or more services. The license enforcement agent (212) being arranged to map the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information. Thereafter, the license enforcement agent (212) being arranged to generate a respective authorization policy for the at least one service in the list of services. The respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM FOR PROVIDING ACCESS TO ONE OR MORE SERVICES RELATING TO A SOFTWARE PRODUCT AND METHOD THEREOF

[0002] TECHNICAL FIELD

[0003] The present disclosure relates to a system and method for providing access to one or more services relating to the software product.

[0004] BACKGROUND

[0005] Research and Development, R&D, sectors, and other industries invest huge amount of money in innovations. Such R&D sectors and industries may generate revenue through licensed software products or other licensed products by making the licensed software product available to consumers. Cloud based software licensing helps many industries to transition their R&D investments obtained in terms of licensed products from dedicated hardware for example conventional storage devices, to software products. With such transition to cloud services, management of licenses can now be enabled on commoditized virtual environments such as public and / or private networks.

[0006] Management and enforcement of licensed software products is now moving to a software space. Due to transition to software space, conventional "honor-based licensing" which were used as pricing models are no longer sustainable. In honor-based licensing, even when a license is expired, functionality of using the licensed services remains unaffected. Also, the device does not report the consumption of licensed services so there is no proper way of monitoring the licensed services. Thus, in case of honor-based licensing, the producer of the software product may not act in case of any wrong or inappropriate usage of the software product by the customer.

[0007] As it is of paramount importance to secure revenue streams from software sales through proper software licensing, it is therefore important to address licensing as a "cross-cutting- concern" which is making availability of the licensed product difficult. Handling licensing as a cross-cutting concern may bring-in an ability to enforce licensing without having to carry out invasive changes in the licensed product. A service agnostic approach to enforce licensing may provide a simpler management of licenses and licensed products.

[0008] SUMMARY Licensed service for a software product adds value to the software product and owner of the software product gets an additional fee from a customer by providing them the licensed services. The existing approaches for providing the licensed service require the licensed services to implement their license checking to detect if the license is present and therefore the service can be activated. Based on checking of the license, the licensed services are made available as the corresponding software entitlement was purchased by a user. While the existing approaches address the requirement of license enforcement, such existing approaches pose some undesirable problems: a) all licensed services need to individually implement a logic to decide on when and / or how to activate or deactivate licensed features associated with the licensed services; b) in few cases the licensed service may not be modifiable to perform the license check, for example, a service containing second / third party services; c) each cloud native service which is used in the process of license enforcement, needs to have knowledge of the structure of saleable entities i.e., the licensed services and features that are open for sale. Furthermore, in case of a change in the services, adapt to new saleable entities in the licensed software product, the process of license enforcement may require extensive re-design of the service itself. Such requirement of structure knowledge is particularly complex if the same licensed service is reused across different products with distinct pricing models and different structure of the saleable entities.

[0009] Therefore, there is a need for an improved system to provide access to the licensed product which may further provide an easy enforcement.

[0010] It is therefore an object of the present disclosure to provide a system and a method for providing access to one or more services relating to a software product wherein all or at least some of the above-discussed drawbacks of presently known solutions are mitigated, alleviated, or eliminated.

[0011] This and other objects are achieved by means of a system and a method defined in the appended claims.

[0012] According to a first aspect of the present disclosure, a system for providing access to one or more services relating to a software product of a network provider is disclosed. The system comprises a license enforcement agent implemented in the software product. The license enforcement agent being arranged to: obtain license information indicative of at least one license for at least one service of the one or more services; map the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information, and generate a respective authorization policy for the at least one service in the list of services, wherein the respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.

[0013] Optionally, the license enforcement agent is arranged to provide the list of services over a network, said license enforcement agent being provided by the network provider.

[0014] Optionally, at least one authorization policy of the one or more authorization policies comprises at least one rule arranged to provide an allowance or a denial of the access to the one or more services.

[0015] Optionally, the at least one rule in the at least one authorization policy is set according to a presence, or an absence of a license key required for access to the at least one service of the one or more services.

[0016] Optionally, the license enforcement agent is arranged to: obtain an indication of a successful mapping as a mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; or obtain an indication of a non-successful mapping as the mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; wherein the at least one rule in the at least one authorization policy corresponding to the successful mapping comprises: allowing the access to the one or more services to an operator, and wherein the at least one rule in the at least one authorization policy corresponding to the non-successful mapping comprises denying the access to the one or more services to an operator.

[0017] Optionally, the system comprises an ingress controller acting as an interface for the system to the operator. The ingress controller being arranged to: receive a request from the operator to provide the access to the at least one service of the one or more services; obtain the respective authorization policy for the at least one service in the list of services; and control the access to the requested at least one service based on the respective authorization policy, wherein the control comprises allowing the access to the one or more services or denying the access to the one or more services.

[0018] Optionally, the ingress controller is arranged to: apply the at least one rule of allowing the access to the at least one service to the operator when the mapping output indicates the successful mapping; or apply the at least one rule of denying the access to the at least one service to the operator when the mapping output indicates the non- successful mapping.

[0019] Optionally, the system comprises a license server implemented in the network of the network provider. The license server is arranged to: provide, for use by the license enforcement agent, the license information indicative of the at least one license for the at least one service of the one or more services.

[0020] Optionally, the license server is arranged to: obtain, from a vendor external to the network, a license file arranged to indicate that network provider which has the at least one license for the at least one of the one or more services; and provide the license information to the license enforcement agent after receipt of a license query originating from the license enforcement agent.

[0021] Optionally, the license server is arranged to: host a latest license key for at least one of the one or more services relating the software product, one or more new services relating to the software product and one or more new services for a new software product, wherein the latest license key is of use for updating the one or more authorization policies by the license enforcement agent, wherein the updated authorization policies are mapped with the at least one license for the at least one service to corresponding at least one service in the list of services to provide the allowance or denial to the access requested by the operator.

[0022] Optionally, the license enforcement agent is arranged to: connect with the license server to check whether the at least one license in the license server is available or not available; and to check whether the at least one license in the license server is valid or invalid, wherein the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services is performed based on the availability and the validity of the at least one license. Optionally, the ingress controller is arranged to deny access in case of the non-availability and / or the invalidity of the software product license in the license server.

[0023] Optionally, the ingress controller is arranged to: control access to the one or more services based on user information, wherein the user information comprises at least one of: user credentials comprising user account and / or password details, and permission provided to the user to use one or more services to access one or more features of the licensed product, wherein the control comprises allowing the access to the one or more services or denying the access to the one or more services.

[0024] Optionally, the one or more services are related to different software products hosted in the network of the network provider.

[0025] Optionally, the network provider has access to the one or more services relating to the software product according to the software product license.

[0026] Optionally, the license server is arranged to: monitor a usage of the software product license by the network provider; and share data on the usage of the software product license with an authorizing entity, wherein the data is used to identify any invalid use of the software product and / or the software product license by the authorizing entity.

[0027] Optionally, the system comprises a consumer module arranged to receive information about the hosted licensed software product and license keys for the one or more services related to the hosted licensed software product from the license server; wherein the license enforcement agent is arranged to obtain the information from the license server via the consumer module.

[0028] Optionally, the consumer module is arranged to: translate one or more commercial entities represented by key codes of the software product license into one or more product services.

[0029] According to a second aspect of the present disclosure, a computer implemented method for providing access to one or more services relating to a software product of a network provider is disclosed. The method comprises obtaining license information indicative of at least one license for at least one service of the one or more services. The method comprises mapping, the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information. Further, the method comprises generating a respective authorization policy for the at least one service in the list of services, wherein the respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.

[0030] According to a third aspect of the present disclosure, there is provided a computer program product comprising a non-transitory computer readable medium, having thereon a computer program comprising program instructions. The computer program is loadable into a data processing unit and configured to cause execution of the method according to the first and second aspects when the computer program is run by the data processing unit.

[0031] Some embodiments disclosed herein have one or more of the following advantages:

[0032] - With the proposed solution the system provides for example, license enforcement agent, license consume tool / module and ingress controller that are specialized services to provide management of the licensed software product and license keys to activate services of the licensed software product;

[0033] - With the proposed license enforcement agent, the system provides periodic checking of availability and validity of licenses;

[0034] - With the proposed solution, the system checks whether the user is having valid credentials and is authorized to access the licensed services before locking or unlocking the access to the licensed services over an interface of the system

[0035] - With the proposed solution, enforcement or access is possible also on second / third party services;

[0036] - With the proposed solution, the system provides a flexibility of adding licenses to a software product without any complexity in terms of number of services associated with any software product;

[0037] - With the proposed solution, the mapping between license keys and product services is encapsulated in a single dedicated service i.e., through the license enforcement agent and can be made fully configurable as per the availability of license keys and service requests at runtime of the license enforcement agent;

[0038] - The proposed solution provides a mapping of services with the license keys to enable / disable the access of the services. The mapping can be configured for a same set of services reused across distinct software products with different sale propositions.

[0039] Other advantages may be readily apparent to one having skill in the art. Certain embodiments may have none, some, or all of the recited advantages.

[0040] BRIEF DESCRIPTION OF THE DRAWINGS

[0041] The foregoing will be apparent from the following more particular description of the example embodiments, as illustrated in the accompanying drawings in which like reference characters refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating the example embodiments.

[0042] FIG. 1 discloses a wireless communication system according to some examples;

[0043] FIG. 2 is a schematic block diagram illustrating a system providing access to one or more services relating to a software product according to some embodiments;

[0044] FIG. 3A-3G is a flowchart illustrating example steps for a method executed by the system providing access to one or more services relating to a software product according to some embodiments;

[0045] FIG. 4a-4b shows additional details of the system providing access to one or more services relating to a software product according to some embodiments;

[0046] FIG. 4c shows an example implementation of the system providing access to one or more services relating to a software product according to some embodiments; and

[0047] FIG. 5 discloses an example computing environment according to some embodiments.

[0048] DETAILED DESCRIPTION

[0049] Aspects of the present disclosure will be described more fully hereinafter with reference to the accompanying drawings. The systems and methods disclosed herein can, however, be realized in many different forms and should not be construed as being limited to the aspects set forth herein. Like numbers in the drawings refer to like elements throughout.

[0050] The terminology used herein is for the purpose of describing particular aspects of the disclosure only and is not intended to limit the invention. It should be emphasized that the term "comprises / comprising" when used in this specification is taken to specify the presence of stated features, integers, steps, or components, but does not preclude the presence or addition of one or more other features, integers, steps, components, or groups thereof. As used herein, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.

[0051] Embodiments of the present disclosure will be described and exemplified more fully hereinafter with reference to the accompanying drawings. The solutions disclosed herein can, however, be realized in many different forms and should not be construed as being limited to the embodiments set forth herein.

[0052] It will be appreciated that when the present disclosure is described in terms of a system and a method, it may also be embodied in one or more processors and one or more memories coupled to the one or more processors, wherein the one or more memories store one or more programs that perform the steps, services and functions disclosed herein when executed by the one or more processors.

[0053] FIG. 1 discloses an example wireless communication system 100. Although the subject matter described herein may be implemented in any appropriate type of system using any suitable components, the examples disclosed herein are described in relation to a wireless communication system / wireless network, such as the example wireless communication system 100 described in FIG. 1.

[0054] The wireless communication system 100 may comprise and / or interface with any type of communication, telecommunication, data, cellular, and / or radio network or other similar type of system. The wireless communication system 100 may be configured to operate according to specific standards or other types of predefined rules of procedures. Thus, the wireless communication system 100 may implement communication standards, such as, but are not limited to, global system for mobile communications, GSM, universal mobile telecommunications system, UMTS, long term evolution, LTE, new radio, NR, and / or other suitable 2G, 3G, 4G, 5G, or 6G standards, wireless local area network, WLAN, standards such as, IEEE 802.11 standards, and / or any other appropriate wireless communication standards, such as, worldwide interoperability for microwave access, WiMax, Bluetooth, Z-Wave and / or ZigBee standards. For simplicity, as depicted in FIG. 1, the wireless communication system 100 comprises a system 200, a network node 104, and a network 106 (customer network or vendor network or may also be referred as wireless communication network). The system 200 and the network node 104 operate together in order to provide wireless connections in the wireless communication system. The wireless communication network 106 may comprise one or more backhaul networks, core networks, IP networks, public switched telephone networks, PSTNs, packet data networks, optical networks, wide-area networks, WANs, local area networks, LANs, wireless local area networks, WLANs, wired networks, wireless networks, metropolitan area networks, and other networks to enable communication between devices (for example, wireless devices and network node).

[0055] In an example, the network node 104 refers to equipment capable, configured, arranged, and / or operable to communicate directly or indirectly with the system 200 and / or with other network nodes or equipment in the wireless communication system 100 to enable and / or provide wireless access to the system 200 and / or to perform other functions (for example, administration) in the wireless communication system 100. Examples of the network node 104 may include, but are not limited to, access points, APs (for example, radio access points), base stations, BSs (for example, radio base stations, nodeBs, evolved NodeBs, eNBs, new radio, NR, nodes (gNBs), or the like). The BSs may be categorized based on an amount of coverage the BSs provide (or, stated different, their transmit power level) and may then also be referred to as femto BSs, pico BSs, micro BSs, macro BSs. The BS may be a relay node or a relay donor node controlling a relay.

[0056] The system 200 refers to a device capable, configured, arranged and / or operable to communicate wirelessly with the network node 104 and / or other wireless devices.

[0057] In some examples, the system 200 may include one or more of: computing devices, wireless devices, ultra-low power wireless devices, Internet of Things, loT, devices, and so on which are used by the user for remote access of the licensed software product.

[0058] It should be understood that the system 200 may not be limited to the above-described wireless devices. The system 200 may be extended to other wireless devices of different classes or categories providing different services while supporting, for example, Enhanced Mobile Broadband, eMBB, massive Machine-Type Communication, MTC, Ultra-Reliable Low Latency Communication, URLLC, Time Sensitive Networking, TSN, or the like.

[0059] In the wireless communication system 100, the network node 104 and the system 200 are connected through 3GPP core network where specific network services and operations are provided through software components called network functions (NFs). The wireless communication system 100 hosts large scale applications.

[0060] In an example, one or more network nodes, such as the network node 104 or the network 106 as shown in FIG. 1 may be arranged to communicate directly or indirectly with one or more components of the system 200 to enable and / or provide wireless access within the system 2OO.The existing approaches for providing licensed service require cloud native services to implement their license checking to detect whether a given licensed service related to a licensed product may be activated. Based on checking through the cloud native services, the licensed services are made available as the corresponding software entitlement was purchased by a user.

[0061] While the existing approaches address the requirement of license enforcement, such existing approaches pose some undesirable problems: a) all licensed services need to individually implement a logic through the cloud native services to decide on when and / or how to activate or deactivate licensed features associated with the licensed services b) the cloud native services may not modify licensed services such as, for example, second / third party services c) each cloud native service which is used in the process of license enforcement, need to have knowledge of the structure of saleable entities i.e., the licensed services and features that are open for sale. Furthermore, in case of change, adapt to new saleable entities for example, update in licensed services or associated features, the process of license enforcement may not be successful. Such requirement of structure knowledge is particularly complex if the same licensed service is reused across different products with distinct pricing models and different structure of the saleable entities. Thus, the present disclosure enables the wireless communication network 100, the network node 104, and the system 200 for providing access to one or more services relating to a software product.

[0062] FIG. 2 is a schematic block diagram illustrating an example system 200 for providing access to one or more services relating to a software product.

[0063] The system 200 comprises a license server 202, also referred as server 202, implemented in a network 204 of a network provider 206. Details of the network 204 are similar to the network 106 as discussed above in relation to FIG. 1.

[0064] The system 200 comprises a license enforcement agent 212 implemented in the software product. The license enforcement agent 212 is arranged to obtain license information indicative of at least one license for at least one service of the one or more services. The license enforcement agent 212 is arranged to map the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information. Further, the license enforcement agent 212 is arranged to generate a respective authorization policy for the at least one service in the list of services, wherein the respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.

[0065] In an example, the license information comprises information whetherthe at least one license is a valid license purchased by a customer and information about the one or more services that may be accessed through the at least one license.

[0066] Optionally, the license enforcement agent 212 is arranged to provide the list of services over a network 204. The license enforcement agent 212 is provided by the network provider 206.

[0067] Optionally, at least one authorization policy of the one or more authorization policies comprises at least one rule arranged to provide an allowance or a denial of the access to the one or more services.

[0068] Optionally, the at least one rule in the at least one authorization policy is set according to a presence, or an absence of a license key required for access to the at least one service of the one or more services. Optionally, the license enforcement agent 212 is arranged to obtain an indication of a successful mapping as a mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services. The license enforcement agent 212 is arranged to obtain an indication of a non-successful mapping as the mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services. The at least one rule in the at least one authorization policy corresponding to the successful mapping comprises: allowing the access to the one or more services to an operator 208. The at least one rule in the at least one authorization policy corresponding to the non-successful mapping comprises denying the access to the one or more services to an operator 208.

[0069] Optionally, the system 200 comprises an ingress controller 210 acting as an interface for the system 200 to the operator 208. The ingress controller 210 being arranged to receive a request from the operator 208 to provide the access to the at least one service of the one or more services. The ingress controller 210 is arranged to obtain the respective authorization policy for the at least one service in the list of services and control the access to the requested at least one service based on the respective authorization policy. The control comprises allowing the access to the one or more services or denying the access to the one or more services.

[0070] Optionally, the ingress controller 210 is arranged to apply the at least one rule of allowing the access to the at least one service to the operator 208 when the mapping output indicates the successful mapping or apply the at least one rule of denying the access to the at least one service to the operator 208 when the mapping output indicates the non- successful mapping.

[0071] Optionally, the system 200 comprises a license server 202 implemented in the network of the network provider 206. The license server 202 is arranged to provide, for use by the license enforcement agent 212, the license information indicative of the at least one license for the at least one service of the one or more services.

[0072] Optionally, the license server 202 is arranged to obtain, from a vendor external to the network 204, a license file arranged to indicate that network provider 206 which has the at least one license for the at least one of the one or more services. The license server 202 is arranged to provide the license information to the license enforcement agent 212 after receipt of a license query originating from the license enforcement agent 212.

[0073] Optionally, the license server 202 is arranged to host a latest license key for at least one of the one or more services relating the software product, one or more new services relating to the software product and one or more new services for a new software product, wherein the latest license key is of use for updating the one or more authorization policies by the license enforcement agent 212. The one or more updated authorization policies are mapped to the at least one license for the at least one service to corresponding at least one service in the list of services to provide the allowance or denial to the access requested by the operator 208.

[0074] Optionally, the license enforcement agent 218 is arranged to connect with the license server 202 to check whether the at least one license in the license server 202 is available or not available and to check whether the at least one license in the license server 202 is valid or invalid. The mapping of the at least one license for the at least one service to corresponding at least one service in the list of services is performed based on the availability and the validity of the at least one license.

[0075] Optionally, the ingress controller 210 is arranged to deny access in case of the non-availability and / or the invalidity of the software product license in the license server 202.

[0076] Optionally, the ingress controller 210 is arranged to control access to the one or more services based on user information. The user information may comprise at least one of user credentials comprising user account and / or password details, and permission provided to the user to use one or more services to access one or more features of the licensed product. The control access comprises allowing the access to the one or more services or denying the access to the one or more services.

[0077] Optionally, the one or more services are related to different software products hosted in the network 204 of the network provider 206.

[0078] Optionally, the network provider 206 has access to the one or more services relating to the software product according to the software product license. Optionally, the license server 202 is arranged to monitor a usage of the software product license by the network provider 206 and share data on the usage of the software product license with an authorizing entity. The data is used to identify any invalid use of the software product and / or the software product license by the authorizing entity.

[0079] Optionally, the system 200 comprises a consumer module 214 arranged to receive information about the hosted licensed software product and license keys for the one or more services related to the hosted licensed software product from the license server 202. The license enforcement agent 212 is arranged to obtain the information from the license server 202 via the consumer module 214.

[0080] Optionally, the consumer module 214 is arranged to translate one or more commercial entities represented by key codes of the software product license into one or more product services. In an example, a commercial entity may refer to an independent organization that engages in commercial activities for a product. For example, the commercial entities may include, but are not limited to, business organizations, retail organizations, industrial organizations etc.

[0081] FIG. 3 is an exemplary flowchart illustrating example steps for a method 300 implemented in the system 200 for providing access to the one or more services relating to the software product of the network provider 206.

[0082] The order in which the steps of the method 300 are described is not intended to be construed as a limitation, and any number of the described method blocks may be combined in any order to implement the method 300 or alternative methods. Additionally, individual blocks may be deleted from the method 300 without departing from the spirit and scope of the embodiments described herein.

[0083] At step 302, the method 300 obtains the license information indicative of the at least one license for the at least one service of the one or more services.

[0084] At step 304, the method 300 maps the at least one license for the at least one service to the corresponding at least one service in the list of services by using the license information. At step 306, the method 300 generates the respective authorization policy for the at least one service in the list of services. The respective authorization policy is arranged to be of use to provide the access to one or more services relating to the software product.

[0085] Optionally, the list of services is provided by the network provider 206 over the network 204.

[0086] Optionally, the at least one authorization policy of the one or more authorization policies comprises at least one rule arranged to provide the allowance or the denial of the access to the one or more services.

[0087] Optionally, as shown in FIG. 3B, at step 308, the mapping 304 comprises: obtaining the indication of the successful mapping as mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; or at step 310, obtaining an indication of a non-successful mapping as the mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services. The at least one rule in the at least one authorization policy corresponding to the successful mapping comprises: allowing the access to the one or more services to the operator 208. The at least one rule in the at least one authorization policy corresponding to the non-successful mapping comprises denying the access to the one or more services to the operator 208.

[0088] Optionally, as shown in FIG. 3C, at step 312, the method 300 provides applying the at least one rule of allowing the access to the one or more services to the operator 208 when the mapping output indicates the successful mapping; or at step 314, the method 300 provides applying the at least one rule of denying the access to the one or more services to the operator 208 when the mapping output indicates the non-successful mapping.

[0089] Optionally, as shown in FIG. 3D, at step 316, the method 300 comprises receiving the request from the operator 208 to provide the access to the at least one service of the one or more services. At step 318, the method 300 provides obtaining the respective authorization policy for the at least one service in the list of services. At step 320, the method 300 provides controlling the access to the requested at least one service based on the respective authorization policy. The controlling access comprises allowing the access to the one or more services or denying the access to the one or more services. Optionally, as shown in FIG. 3E, at step 322, the method 300 comprises controlling access to the one or more services also based on user information. The user information comprises at least one of: user credentials comprising user account and / or password details, and permission provided to the user to use one or more services to access one or more features of the licensed product. The controlling access comprises allowing the access to the one or more services or denying the access to the one or more services.

[0090] Optionally, the one or more services are related to different software products hosted in the network 204 of the network provider 206.

[0091] Optionally, the network provider 206 has access to the one or more services relating to the software product according to the software product license.

[0092] Optionally, as shown in FIG. 3F, at step 324, the method 300 comprises monitoring a usage of the software product license by the network provider 206. At step 326, the method 300 comprise sharing data on the usage of the software product license with an authorizing entity. The data is used to identify any invalid use of the software product and / or the software product license by the authorizing entity.

[0093] Optionally, as shown in FIG. 3G, at step 328, the method 300 comprises translating one or more commercial entities represented by key codes of the software product license into one or more product services. In an example, the commercial entity may refer to an independent organization that engages in commercial activities for a product. For example, the commercial entities may include, but are not limited to, business organizations, retail organizations, industrial organizations etc.

[0094] In an example, FIG. 4a illustrates the system 200 as a cloud native product equipped with licensing services. The system 200 is installed in the customer network 204 (referred above as the network 204 of the network provider 206) and is accessed remotely by one or more users 208. In an example, the one or more users 208 may be human operators, or machine- to-machine connections, i.e., user devices connected through the operator 208.

[0095] Regardless of the nature of the user (human or machine), the licensed software product is exposed for external access via the ingress controller 210. The ingress controller 210 is a single admittance point to accept (or reject) user requests or requests from the operator 208. Requests for example may be rejected for the user not having the necessary privilege for a given operation (e.g., the user with a read-only role in the system 200 trying to perform a write operation), or not having valid credentials to access the system 200 (e.g., wrong password, or expired account). The user privilege for the given operation is assigned to the user by an administrator of the software product, wherein the software product is assigned by the producer to the administrator. The customer may purchase the software product from the producer and the producer of the software product may decide on giving the rights to access the software product by giving the credentials and the privileges to the customers or users. Action of giving the privileges and rights is done by the product administrator.

[0096] The licensed software product contains a plurality of licensed services or product services or services that make available the features of the licensed product to the user. For example, "product service #1" may comprise a machine learning feature realized by some Kubernetes pods, and the machine learning feature is made available to the users via the exposure of an entry point of the service#! over the ingress controller 210.

[0097] This arrangement of the ingress controller 210 in the system 200 makes the ingress controller 210 a preferred enforcement point for licensing. The ingress controller 210 may also restrict or bar the exposure of the service if the product license enabling that service is not present.

[0098] The system 200 implements the license enforcement through at least one of the license server 202, the license consumer module 214 and the license enforcement agent 212 also referred as license poller 212.

[0099] The license server 202 hosts the licenses purchased by the customer and are made available by a vendor over the network 204 of the customer 208. The license server 202 is also responsible for reporting back to the vendor, data on the actual usage of the licenses.

[0100] The license consumer 214 is arranged to translate the commercial entities in the license key codes into tangible product services. In an example, the tangible product services may comprise any promotional products used for marketing in case of any business events. The tangible product services may also comprise physical features of the licensed service for which access may be given to the user, such as quality assurance services. The license poller 212 is arranged to check periodically the availability and validity of licenses that may be hosted over the server 202. The license poller 212 may then act accordingly on the ingress controller 210 by enabling / disabling authorization policies forthe exposure points i.e., providing the access to the licensed service(s).

[0101] In an example, business logic implemented by the license poller 212 is discussed below. The logic may be implemented in any desired language for e.g., Java, Python etc., and with one or more ingress controllers 210.

[0102] The invention described is inherently conceived for cloud native applications, and the implementation of the system 200 is based on a cloud architecture.

[0103] In an example implementation of the system 200 may be based on Kubernetes Application Programming Interface, API objects.

[0104] The one or more authorization policies may be implemented following the technology of the ingress controller 210. In the following example, the one or more authorization policies are based on an Istio open-source ingress controller 210. apiVersion: security. istio. io / vlbetal kind: Authorizationpolicy metadata: name: ap-servicel spec: action: ALLOW ## this field changes to DENY if the license key for service 1 is missing selector: matchLabels: app: istio-ingress-gateway rules:

[0105] - to:

[0106] - operation: ## needed to perform authentication methods: [ "POST", "GET", "DELETE"] paths: [ " / servicel / api / *" ]

[0107] In an example implementation, a business logic that the license poller 212 may implement to fulfil its functionality is discussed below.

[0108] The example is purely indicative as the same business logic may be implemented in any desired programming language (e.g., Java, Python, etc.) and with a variety of ingress controllers 210 that may be configured in the system 200. apiVersion : batch / vl kind : Cronlob metadata : name : license-poller labels : app . kubernetes . io / name : license-poller spec : schedule: "* * * * *" ### run every minute jobTemplate : spec : template : metadata : labels : spec : serviceAccount : license-poller ## granting access rights to patch the authorization policies containers :

[0109] - name : license-poller image : alpine command : ### pseudo code following licenses=<Retrieve licenses from License Consumer LC . l over interface LC-LP-IF .1> services=<Retrieve list of services from configmap LP-CM.1> mapping=<Retrieve mapping of licenses-to-services from configmap LP-CM. l

[0110] Foreach service in Jservices {

[0111] If cservice n is enabled by any of the licenses in $licenses> Then <decision=mark authorization policy for service n as “ALLOW”>

[0112] Else <decision=mark authorization policy for service n as “DENY”> Patch the authorization policy AP . n for service n to Jdecision over interface LP-K8S-IF .1

[0113] In an example, FIG. 4b illustrates the mapping of the one or more authorization policies by the license enforcement agent 212. The ingress controller 210 is a programmable ingress controller and acts as the interface to the operator 208 or the user (interface IC.l) as the prime enforcement point for accessing the licensed services. If the service is associated to a valid license (as checked by the license enforcement agent 212) purchased by the customer, then a relevant traffic, i.e., requests from multiple operators 208 will be permitted across the interface IC.l.

[0114] The control of what traffic is permitted (or forbidden) is done through the "authorization policy" also referred as objects (AP.l-AP.n). Each authorization policy controls a set of endpoints (wherein an endpoint is a destination in the network 106 composed by a network protocol and a network address) of the services exposed over interface IC.l. Authorization Policies have an attribute "action" to specify if the rules contained in each authorization policy must be applied by the ingress controller 210 to allow or to deny the traffic matching the rules in each AP.x object. The key business logic in terms of the authorization policies is implemented in the license enforcement agent 212, i.e., the license poller (LP.l). According to the mappings specified in a configmap (LP-CM.l), the mapping may act upon the relevant authorization policy to turn its behavior from allow (or deny) to deny (or allow), depending on the presence (or absence) of the relevant license key. Such change from allow to deny or from deny to allow is done when the license enforcement agent 212 or the license poller receives the update in the license keys from the server 202.

[0115] The license server (LS.l) 202 arranged in the system 200 makes the license key files available to the license consumer (LC.l) 402 over an internal interface (LS-LC-I F.l). The license consumer 402 in turn makes the information available to its client modules, and then to the license poller (LP.l) 212 over an internal interface (LC-LP-IF.l). The license consumer 214 feeds the necessary information about the license keys to the license poller 212 to decide which rule in the authorization policy needs to be set to "allow" and which rule need to be set to "deny".

[0116] The license consumer (LC.l) 214 is also used to provide regular reporting to the license server (LS.l) 202 over the interface LS-LC-IF.l of actual license usage. Data on the usage may be used to provide information about actual license usage patterns, and may be helpful in detecting any tampering that a malicious user may have attempted by disabling the license poller 212 to try and stop the license enforcement.

[0117] In an example, FIG. 4c provides an implementation of the system 200. The Vendor 412 may generate the license key or license key file for the Customer X 206. The license key enables the services covered by the purchase order, i.e., conditions of the software product license, for example, the service A and service B, but not service C.

[0118] The Vendor 412 then pushes the license key file to the license server 202 of Customer X 206. The system 200 now provides an automatic way of providing the access of the services A and B to the user 208.

[0119] The License server (LS.l) 202 uploads the latest license key file for Customer X 206 and makes the latest license key available to all the license consumers 208 that may request that information i.e., request for the access. Each of the products which are licensed and are installed by Customer X 206 has a license consumer (LC.l) 214 which queries the license server 202 periodically and shares the information with the license poller 212.

[0120] As also discussed in preceding paragraphs, the license poller (LP.l) 212 implements the key business logic. The license poller 212 queries the license consumer 214 to have up-to-date information on the licensed services. The license poller 212 maps the at least one license for the at least one service to corresponding at least one service in a list of services, according to a table containing the information about license key availability for the one or more services in a configmap (LP-CM.l), to enable to rules in the relevant authorization policies (AP.l-AP.n). The license poller 212 may also change the setting in the authorization policies to allow or deny via the Kubernetes api server interface (LP-K8S-I F.l).

[0121] In an example, the configmap data for a licensed application (licensed software product) is shown below:

[0122] {

[0123] "application": "service-orchestrator",

[0124] "product number": "FAT 102 xxx",

[0125] "package description": "RTU base package YY",

[0126] "permissions": [

[0127] "catalog-manager",

[0128] "dashboard",

[0129] "ipam",

[0130] "playbook-service",

[0131] "sol005-adapter",

[0132] "workflow"]

[0133] }

[0134] The ingress controller (IC.l) 210 then decides whether to allow or deny the requests based on the programmed rules i.e., the mapping out in the current set of authorization policies.

[0135] The system 200 described is inherently conceived for cloud native applications, and the system 200 is implemented in a cloud architecture. An example implementation of the system 200 is based on Kubernetes API objects. The Authorization Policies may be implemented following the technology of the ingress controller 210 for example, on an Istio open-source ingress controller. The business logic in the license poller 212 may be implemented in any desired programming language (e.g., Java, Python, etc.) and with a variety of ingress controllers as shown in the example below: apiVersion: security. istio.io / vlbetal kind: Authorizationpolicy metadata: name: ap-servicel spec: action: ALLOW ## this field changes to DENY if the license key for service 1 is missing selector: matchLabels: app: istio-ingress-gateway rules:

[0136] - to:

[0137] - operation: ## needed to perform authentication methods: [ "POST", "GET", "DELETE"] paths: [ " / servicel / api / *" ]

[0138] FIG. 5 illustrates an example-computing environment 500 implementing the system 200 and method 300 as shown in FIGs. 3A-3G for providing access to one or more services relating to a software product. The example-computing environment 500 further implementing the system 200, and the methods 300 as shown in FIGs. 3A-3G providing access to one or more services relating to a software product. As depicted in FIG. 5, the computing environment 500 comprises at least one data processing unit 506 that is equipped with a control unit 502 and an Arithmetic Logic Unit (ALU) 504, a plurality of networking devices 508 and a plurality Input output, I / O devices 510, a memory 512, a storage 514. The data processing unit 506 may be responsible for implementing the system 200 and methods 300 described in FIGs. 3A-3G. For example, the data processing unit 506 in some embodiments be equivalent to the controlling circuitry of the platform described above in conjunction with FIGs 4a and 4b. For another example, the data processing unit 506 in some embodiments be equivalent to the controlling circuitry of the platform described above in conjunction with FIGs. 4a and 4b. The data processing unit 506 is capable of executing software instructions stored in memory 512. The data processing unit 506 receives commands from the control unit 502 in order to perform its processing. Further, any logical and arithmetic operations involved in the execution of the instructions are computed with the help of the ALU 504.

[0139] The computer program is loadable into the data processing unit 506, which may, for example, be comprised in an electronic apparatus (such as the platform). When loaded into the data processing unit 506, the computer program may be stored in the memory 512 associated with or comprised in the data processing unit 506. According to some embodiments, the computer program may, when loaded into and run by the data processing unit 506, cause execution of method steps according to, for example, any of the methods illustrated in FIGs. 3A-3G described herein.

[0140] The overall computing environment 500 may be composed of multiple homogeneous and / or heterogeneous cores, multiple CPUs of different kinds, special media, and other accelerators. Further, the plurality of data processing unit 506 may be located on a single chip or over multiple chips.

[0141] The algorithm comprising of instructions and codes required for the implementation are stored in either the memory 512 or the storage 514 or both. At the time of execution, the instructions may be fetched from the corresponding memory 512 and / or storage 514 and executed by the data processing unit 506.

[0142] In case of any hardware implementations various networking devices 508 or external I / O devices 510 may be connected to the computing environment to support the implementation through the networking devices 508 and the I / O devices 510.

[0143] The embodiments disclosed herein can be implemented through at least one software program running on at least one hardware device and performing network management functions to control the elements. The elements shown in FIG. 5 include blocks which can be at least one of a hardware device, or a combination of hardware device and software module.

Claims

CLAIMS1. A system (200) for providing access to one or more services relating to a software product of a network provider (206), the system (200) comprising: a license enforcement agent (212) implemented in the software product, the license enforcement agent (212) being arranged to: obtain license information indicative of at least one license for at least one service of the one or more services; map the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information, and generate a respective authorization policy for the at least one service in the list of services, wherein the respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.

2. The system (200) according to claim 1, wherein the license enforcement agent (212) is arranged to provide the list of services over a network (204), said license enforcement agent (212) being provided by the network provider (206).

3. The system (200) according to any of the preceding claims, wherein at least one authorization policy of the one or more authorization policies comprises at least one rule arranged to provide an allowance or a denial of the access to the one or more services.

4. The system (200) according to claim 3, wherein the at least one rule in the at least one authorization policy is set according to a presence, or an absence of a license key required for access to the at least one service of the one or more services.

5. The system (200) according to any of the preceding claims, wherein the license enforcement agent (212) is arranged to:obtain an indication of a successful mapping as a mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; or obtain an indication of a non-successful mapping as the mapping output, based on the mapping of the at least one license forthe at least one service to corresponding at least one service in the list of services; wherein the at least one rule in the at least one authorization policy corresponding to the successful mapping comprises: allowing the access to the one or more services to an operator (208), and wherein the at least one rule in the at least one authorization policy corresponding to the non-successful mapping comprises denying the access to the one or more services to an operator (208).

6. The system (200) according to any of the claims 1 to 5, comprising: an ingress controller (210) acting as an interface for the system (200) to an operator (208), said ingress controller (210) being arranged to: receive a request from the operator (208) to provide the access to the at least one service of the one or more services; obtain the respective authorization policy for the at least one service in the list of services; and control the access to the requested at least one service based on the respective authorization policy, wherein the control the access comprises allowing the access to the one or more services or denying the access to the one or more services.

7. The system (200) according to claims 6, wherein the ingress controller (210) is arranged to: apply the at least one rule of allowing the access to the at least one service to the operator (208) when the mapping output indicates the successful mapping; or apply the at least one rule of denying the access to the at least one service to the operator (208) when the mapping output indicates the non- successful mapping.

8. The system (200) according to any of the preceding claims, comprising: a license server (202) implemented in the network (204) of the network provider (206), wherein the license server (202) is arranged to: provide, for use by the license enforcement agent (212), the license information indicative of the at least one license for the at least one service of the one or more services.

9. The system (200) according to claim 8, wherein the license server (202) is arranged to: obtain, from a vendor external to the network (204), a license file arranged to indicate that network provider (206) which has the at least one license for the at least one of the one or more services; and provide the license information to the license enforcement agent (212) after receipt of a license query originating from the license enforcement agent (212).

10. The system (200) according to any of the claims 8 or 9, wherein the license server (202) is arranged to: host a latest license key for at least one of the one or more services relating the software product, one or more new services relating to the software product and one or more new services for a new software product, wherein the latest license key is of use for updating the one or more authorization policies by the license enforcement agent (212), wherein the updated authorization policies are mapped with the at least one license for the at least one service to corresponding at least one service in the list of services to provide the allowance or denial to the access requested by the operator (208).

11. The system (200) according to any of the preceding claims, wherein the license enforcement agent (212) is arranged to: connect with the license server (202) to check whether the at least one license in the license server (202) is available or not available; and to check whether the at least one license in the license server (202) is valid or invalid, wherein the mapping of the at least one license for the at least one service to corresponding at least oneservice in the list of services is performed based on the availability and the validity of the at least one license.

12. The system (200) according to claim 11, wherein the ingress controller (210) is arranged to deny access in case of the non-availability and / or the invalidity of the software product license in the license server (202).

13. The system (200) according to any of the preceding claims, wherein the ingress controller (210) is arranged to: control access to the one or more services based on user information, wherein the user information comprises at least one of: user credentials comprising user account and / or password details, and permission provided to the user to use one or more services to access one or more features of the licensed product, wherein the control comprises allowing the access to the one or more services or denying the access to the one or more services.

14. The system (200) according to any of the preceding claims, wherein the one or more services are related to different software products hosted in the network of the network provider (206).

15. The system (200) according to any of the preceding claims, wherein the network provider (206) has access to the one or more services relating to the software product according to the software product license.

16. The system (200) according to any of the preceding claims, wherein the license server (202) is arranged to: monitor a usage of the software product license by the network provider (206); and share data on the usage of the software product license with an authorizing entity, wherein the data is used to identify any invalid use of the software product and / or the software product license by the authorizing entity.

17. The system (200) according to any of the preceding claims, comprising:a consumer module (214) arranged to receive information about the hosted licensed software product and license keys for the one or more services related to the hosted licensed software product from the license server (202); wherein the license enforcement agent (212) is arranged to obtain the information from the license server (202) via the consumer module (214).

18. The system (200) according to any of the preceding claims, wherein the consumer module (214) is arranged to: translate one or more commercial entities represented by key codes of the software product license into one or more product services.

19. A method (300) implemented by a system (100) for providing access to one or more services relating to a software product of a network provider (206), the method (300) comprising: obtaining (302) license information indicative of at least one license for at least one service of the one or more services; mapping (304), the at least one license for the at least one service to corresponding at least one service in a list of services by using the license information; and generating (306) a respective authorization policy for the at least one service in the list of services, wherein the respective authorization policy is arranged to be of use to provide access to one or more services relating to the software product.

20. The method (300) according to claim 19, wherein the list of services is provided by the network provider (206) over the network (204).

21. The method (300) according to any of the claims 19-20, wherein the at least one authorization policy of the one or more authorization policies comprises at least one rule arranged to provide an allowance or a denial of the access to the one or more services.

22. The method (300) according to claim 21, wherein the at least one rule in the at least one authorization policy is set according to a presence, or an absence of a license key required for access to each service of the one or more services.

23. The method (300) according to any of the claims 19-22, wherein the mapping comprises: obtaining (308) an indication of a successful mapping as a mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; or obtaining (310) an indication of a non-successful mapping as the mapping output, based on the mapping of the at least one license for the at least one service to corresponding at least one service in the list of services; wherein the at least one rule in the at least one authorization policy corresponding to the successful mapping comprises: allowing the access to the one or more services to an operator (208), and wherein the at least one rule in the at least one authorization policy corresponding to the non-successful mapping comprises denying the access to the one or more services to the operator (208).

24. The method (300) according to any of the claims 22 or 23, comprising: applying (312) the at least one rule of allowing the access to the one or more services to the operator (208) when the mapping output indicates the successful mapping; or applying (314) the at least one rule of denying the access to the one or more services to the operator (208) when the mapping output indicates the non- successful mapping.

25. The method (300) according to any of the claims 19-23, comprising: receiving (316) a request from the operator (208) to provide the access to the at least one service of the one or more services; obtaining (318) the respective authorization policy for the at least one service in the list of services; andcontrolling (320) the access to the requested at least one service based on the respective authorization policy, wherein the controlling the access comprises allowing the access to the one or more services or denying the access to the one or more services.

26. The method (300) according to any of the claims 19-25, comprising: controlling (322) the access to the one or more services also based on user information, wherein the user information comprises at least one of: user credentials comprising user account and / or password details, and permission provided to the user to use one or more services to access one or more features of the licensed product, wherein the controlling the access comprises allowing the access to the one or more services or denying the access to the one or more services.

27. The method (300) according to any of the claims 19-26, wherein the one or more services are related to different software products hosted in the network (204) of the network provider (206).

28. The method (300) according to any of the claims 19-27, wherein the network provider (206) has access to the one or more services relating to the software product according to the software product license.

29. The method (300) according to any of the claims 19-28, comprising: monitoring (324) a usage of the software product license by the network provider (206); and sharing (326) data on the usage of the software product license with an authorizing entity, wherein the data is used to identify any invalid use of the software product and / or the software product license by the authorizing entity.

30. The method (300) according to any of the claims 19-29, comprising:translating (328) one or more commercial entities represented by key codes of the software product license into one or more product services.

31. A computer program product comprising a non-transitory computer readable medium, having thereon a computer program comprising program instructions, the computer program is loadable into a data processing unit and configured to cause execution of the method according to any of claims 19 through 30 when the computer program is run by the data processing unit.

Citation Information

Patent Citations

  • Method and system for delivery of secure software license information

    US20030149670A1

  • Method for automatic creation and configuration of license models and policies

    US20050071276A1

  • Methods and systems for licensing computer software

    US20060179058A1

  • Automated license reconciliation for deployed applications

    US20100250730A1

  • Software feature authorization through delegated agents

    US20110197077A1