Cloud License Security via Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current licensing solutions for cloud-based applications and services are proprietary and not designed for cloud environments, lacking hardware-rooted security, which poses risks such as tampering and unauthorized use.

Innovation Solution

The implementation of a secure, hardened license mechanism using Intel Software Guard Extensions (SGX) or Trusted Execution Engines (TEE) to establish a secure channel between license agents and servers, verifying licenses through unique hardware-based keys and secure clocks, preventing tampering and unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary licensing solutions are used in cloud environments, then licensing functionality is provided, but security is weakened due to lack of hardware-rooted protection

Engineering Contradiction:
Improvelicensing securityVSAvoidlicense mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Trusted Execution Environment (TEE) as an intermediary component between the licensing software and the hardware. This TEE acts as a secure mediator that hosts the licensing solution, providing hardware-rooted security while maintaining the functionality of proprietary licensing mechanisms. The TEE isolates the licensing operations in a protected environment, preventing tampering and unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The licensing system is segmented into distinct components: the proprietary licensing software layer and the hardware-based Trusted Execution Environment layer. This segmentation allows the licensing functionality to be separated from the underlying hardware details, enabling security hardening through the TEE while preserving the existing licensing logic and operations.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If virtual machines are migrated between hosts, then flexibility and cloud utility are improved, but license validation becomes challenging without hardware-rooted security

Engineering Contradiction:
ImproveVM migration capabilityVSAvoidlicense validation reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The Trusted Execution Environment provides self-service capabilities for license validation during VM migration. The TEE automatically performs identity verification and license validation operations without requiring external intervention or complex coordination. This self-service approach enables seamless VM migration while maintaining secure license validation through hardware-rooted identity verification.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure channels are established using hardware-based keys, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecure channel securityVSAvoidhardware integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Trusted Execution Environment provides universal security services that can be used for multiple purposes: establishing secure channels, validating licenses, verifying VM identities, and protecting cryptographic operations. This multi-functionality reduces the need for separate hardware components for each security function, thereby limiting the increase in device complexity while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11775621B2Licensing in the cloud
Publication Date: 2023.10.03 INTEL CORP
  • US11775621B2 patent drawing
  • US11775621B2 patent drawing
  • US11775621B2 patent drawing

AI summary

At least one machine readable medium comprising a plurality of instructions that in response to being executed by a system cause the system to send a unique identifier to a license server, establish a secure channel based on the unique identifier, request a license for activating an appliance from a license server over the secure channel, receive license data from the license server over the secure channel; determine whether the license is valid, and activate the appliance in response to a determination that the license data is valid.