Offline Copy Protection via Mutual Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing copy protection methods for electronic systems are not offline-capable and are susceptible to man-in-the-middle attacks, which compromises the operational reliability and authenticity of components within these systems.

Innovation Solution

A copy protection method utilizing a public-key infrastructure with premade certificates loaded onto electronic units and components during production or configuration, allowing for offline authenticity verification and preventing man-in-the-middle attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificates are requested and transmitted from a certification authority via an Internet connection, then copy protection can be implemented, but the system cannot be used offline and is susceptible to man-in-the-middle attacks

Engineering Contradiction:
Improveoperational reliabilityVSAvoidoffline capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-distributing certificates from the certification authority to electronic units and components before offline operation is needed. These certificates are stored locally in secure memory, enabling authenticity verification to be performed offline without requiring real-time connection to the certification authority, thus resolving the contradiction between offline capability and copy protection implementation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificates are transmitted via Internet connection, then authenticity can be verified, but the system is susceptible to man-in-the-middle attacks

Engineering Contradiction:
Improveauthenticity verificationVSAvoidman-in-the-middle attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent eliminates man-in-the-middle attacks by performing preliminary distribution of certificates through secure offline channels during manufacturing or initial setup. The certificates are stored in tamper-resistant memory within each electronic unit and component. During operation, authenticity verification is performed by comparing locally stored certificates with digital signatures, completely avoiding real-time Internet transmission and thus eliminating the vulnerability to man-in-the-middle attacks

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the certificate verification process from the online Internet-based system and implements it as a standalone offline capability. By extracting the essential authentication data (certificates) and storing them locally, the system performs verification independently without requiring connection to the certification authority, thus removing the attack vector for man-in-the-middle interference

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12244735B2Copy protection method and copy-protected electronic system
Publication Date: 2025.03.04 ETO MAGNETIC GMBH
  • US12244735B2 patent drawing
  • US12244735B2 patent drawing
  • US12244735B2 patent drawing

AI summary

A copy protection method for an electronic system has one or more electronic units and one or more component which interacts with the electronic unit, in which or more one public-key infrastructure having one or more certification authority is used. The certification authority issues a first certificate for the electronic unit and a second certificate for the component, based on an identification feature of the electronic unit and of the component, respectively. To check authenticity of the component by means of the electronic unit, the respective certificates are mutually checked. The first certificate is premade and loaded onto the electronic unit when producing and/or configuring the electronic unit, and/or the second certificate is premade and loaded onto the component when producing and/or configuring the component.