Network Fingerprint License Control for Virtual Machine Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for controlling software application execution on an execution platform are ineffective when the application is run in a virtual machine, as they rely on locking licenses to the hardware platform, which becomes unusable in such environments.
Innovation Solution
The method involves locking the license to the local network environment rather than the execution platform, using a network fingerprint that matches the initial network fingerprint to ensure secure execution, even in virtual machine scenarios, by characterizing the network with unique features like printers, storage, and users, and adapting to changes within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the license is locked to the hardware of the execution platform, then the protection against unauthorized use is effective for physical machines, but the license control becomes ineffective when the application is executed in a virtual machine
Solution Approach 1:
The patent introduces a network environment fingerprint as an intermediary between the license and the execution platform. Instead of directly binding the license to hardware identifiers (which fail in virtual machines), the system creates a network-based fingerprint that encompasses multiple network characteristics. This intermediary layer maintains license control effectiveness while adapting to virtual machine execution, as the network environment remains relatively stable even when the virtualized platform changes.
Solution Approach 2:
The patent transitions from a single-dimension hardware-based licensing approach to a multi-dimensional network environment fingerprinting approach. By collecting and analyzing multiple network parameters (DNS settings, network interface configurations, routing tables, etc.), the system creates a comprehensive fingerprint that operates in a higher-dimensional space. This dimensional expansion allows the license control to remain effective across different execution environments including virtual machines.
2Reliability
If the license is locked to the execution platform hardware, then the security against unauthorized copying is improved, but the ease of legitimate deployment and migration is reduced
Solution Approach 1:
The patent implements a dynamic licensing approach where the network environment fingerprint is continuously monitored and compared. The system allows for legitimate migrations by detecting changes in the network environment and determining whether they represent authorized moves (such as relocating servers within the same network infrastructure) versus unauthorized copying. This dynamic evaluation maintains security while enabling operational flexibility.
Solution Approach 2:
The system changes the parameters used for license validation from static hardware identifiers to dynamic network environment parameters. By monitoring changes in network configuration parameters and comparing them against the original fingerprint, the system can distinguish between legitimate parameter changes (such as network reconfiguration during migration) and unauthorized attempts to bypass license restrictions.
3Adaptability or versatility
If network fingerprinting is implemented to control license execution, then the adaptability to virtual machine execution is improved, but the system complexity increases
Solution Approach 1:
The patent segments the license control system into distinct functional modules: network parameter collection, fingerprint generation, fingerprint storage, and fingerprint verification. Each module performs a specific task, making the overall complex system manageable and maintainable. The segmentation also allows for independent testing and validation of each component, reducing the operational complexity despite the increased functional capabilities.
Data Source
Figure 1
Figure 2
AI summary
There is provided a method for controlling an execution of a software application on an execution platform in a first local network, comprising the steps a) determining a first environment fingerprint including a first network fingerprint of the first local network by using predetermined rules, said first network fingerprint is characteristic for the first local network and can be used to distinguish the first local network from other local networks, b) generating a license including said first environment fingerprint, said license defines terms of allowed execution of the software application on an execution platform in the first local network, and c) controlling the execution by - determining a second environment fingerprint including a second network fingerprint of the local network in which the execution platform for said software application is included by using said predetermined rules, - comparing the second environment fingerprint with the first environment fingerprint of the license, and - allowing the execution of the software application according to the terms of the license in case of the second environment fingerprint complies with the first environment fingerprint, and preventing the execution of the software application in case of the second environment fingerprint does not comply with the first environment fingerprint.