Local Dongle Verification for Protected Software Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems using dongles are vulnerable to unauthorized use via remote connections, allowing multiple users to access protected software simultaneously or subsequently, which is not the intended business case.

Innovation Solution

A method that analyzes device setting parameters, drivers, and software programs on a hardware component to ensure a local connection with a predefined type of hardware component is established, identifying and retrieving startup information only from a locally connected second hardware component to start the protected software program.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the security system only checks if the dongle is possessed (provided) but not if it is locally provided/available, then the system is easier to operate and more flexible, but it becomes vulnerable to cheating where the dongle can be made remotely available allowing multiple users to access simultaneously

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary analysis of device setting parameters, device drivers, and software programs before authorizing software execution. This advance verification ensures that the hardware component is properly configured for local connections only, preventing remote access cheating while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and analyzes device configuration information to provide feedback on whether the hardware is properly configured for local connections. This feedback mechanism detects attempts at remote access and prevents unauthorized simultaneous usage, thereby improving security reliability without significantly impacting ease of operation.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If the system allows remote availability of the dongle via network connection, then more users can access the protected software simultaneously or subsequently, but this violates the intended business case where a single user should have exclusive access

Engineering Contradiction:
Improveaccess flexibilityVSAvoidbusiness model integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary analysis of device setting parameters, device drivers, and software programs to detect whether the hardware is configured for remote or local connections before authorizing software execution. This advance verification prevents remote access attempts that would violate the single-user business model while allowing legitimate local access.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the potential harm of remote access attempts into a beneficial security feature by analyzing device configuration information to detect and block unauthorized remote connections. The same analysis capability that could have been used to enable remote access is instead used to prevent it, thereby protecting the business model integrity.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If the system analyzes device setting parameters, device drivers and software programs to ensure local connection, then security is improved, but the system becomes more complex

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs the complex analysis of device setting parameters, device drivers, and software programs as a preliminary one-time action during hardware configuration verification. This initial analysis establishes security credentials that can be used for subsequent authentication without requiring repeated complex analysis, thereby improving security reliability while limiting the complexity impact to the initial setup phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4592873A1A method and a device for protecting a software program running on a hardware component
Publication Date: 2025.07.30 DIEBOLD NIXDORF SYST GMBH
  • EP4592873A1 patent drawingFigure 1
  • EP4592873A1 patent drawingFigure 2
  • EP4592873A1 patent drawing

AI summary

A method of protecting a software program installed on a first hardware component from unauthorized use is provided. The method includes collecting information on device setting parameters, device drivers and/or software programs installed on and/or presently run by the first hardware component, determining whether the collected information indicates that the first hardware component is configured to establish a data connection only to a local hardware interface that is connectable with a predefined type of hardware component, and only if the establishable data connection only to a local hardware interface is determined: identifying a second hardware component of the predefined type that is locally connected to the first hardware component, retrieving startup information and/or functions from the second hardware component, and starting the protected software program using the retrieved startup information and/or functions.