Pooled FoD Activation Key Management via Policy-Based Reassignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing features on demand (FoD) key authorization process is cumbersome, leading to delays and inefficiencies due to manual code entry, lack of key reassignment, and duplication prevention, especially for hardware feature activation, which is not applicable for hardware-based features and requires costly system reconfiguration.

Innovation Solution

A method and system for user permissions-based control of pooled FoD activation keys, where authorization codes are pooled and managed by pre-defined policies, allowing flexible access and reassignment based on user identity, type of activation key, cost, and usage limits, enabling efficient activation key generation and feature activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual code entry and individual authorization code distribution is used, then each user can access their own activation keys, but the process becomes cumbersome and inefficient with delays

Engineering Contradiction:
Improveactivation key access processVSAvoidactivation key acquisition time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent introduces an automated intermediary system that mediates between authorization codes and activation keys. This system automatically matches users with available activation keys based on predefined policies, eliminating the need for manual code entry and administrative intervention. The intermediary automates the entire key distribution process, resolving the contradiction between ease of operation and time loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by allowing users to automatically obtain activation keys without manual intervention. Users with authorization codes can independently access the automated system, which then provisions the appropriate activation keys based on their credentials and the system's policy rules. This self-service mechanism eliminates the cumbersome manual process while preventing time delays.

Inventive Principle:
Principle #25Self-service

2Reliability

If activation keys are bound to specific hardware instances, then key security is maintained, but key reassignment to different devices becomes impossible

Engineering Contradiction:
Improveactivation key securityVSAvoidactivation key reassignment capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key binding where activation keys are initially associated with hardware instances but can be reassigned through the automated system. The system maintains security through policy-based controls while enabling flexible reassignment when needed. This dynamic approach resolves the contradiction by making the key-hardware binding flexible rather than static, allowing both security maintenance and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the binding parameter from permanent to conditional. Activation keys maintain their hardware association under normal circumstances for security, but the binding parameter can be modified through the automated system when reassignment is authorized. This parameter change capability allows the system to adapt between security-oriented permanent binding and flexibility-oriented temporary binding based on policy rules.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If a key library is used to manage activation keys, then key distribution can be facilitated, but key duplication through copying cannot be prevented

Engineering Contradiction:
Improveactivation key distribution efficiencyVSAvoidactivation key duplication prevention
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces the mechanical key library approach with an automated digital provisioning system. Instead of storing and distributing keys through a static library that is vulnerable to copying, the system uses automated generation and binding mechanisms. The automated system generates activation keys programmatically and binds them to specific users and hardware instances through policy-based rules, preventing duplication while maintaining distribution efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The automated intermediary system acts as a controlled mediator between the key management infrastructure and users. Rather than allowing direct access to a key library that could be copied, the intermediary controls key generation, distribution, and binding through policy enforcement. This intermediary layer maintains productivity by automating distribution while preventing duplication through controlled access and binding mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If hardware features are activated during system restart, then proper low-level reconfiguration is achieved, but license server approach cannot be applied due to firmware network disconnection

Engineering Contradiction:
Improvehardware feature activation reliabilityVSAvoidlicense server infrastructure requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-provisioning activation keys before the system restart when network connectivity is unavailable. The automated system generates and distributes activation keys in advance, allowing them to be stored locally in the firmware environment. When the system restarts and hardware features need activation, the pre-provisioned keys are already available, eliminating the need for real-time network connectivity to a license server during the critical activation phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the key provisioning process from the activation process. Key generation and distribution occur as a separate preliminary phase that can happen with network connectivity. The activation phase then occurs independently during system restart without requiring network connectivity. This segmentation resolves the contradiction by separating the network-dependent provisioning function from the network-independent activation function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9600641B2User permissions based control of pooled features on demand activation keys
Publication Date: 2017.03.21 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US9600641B2 patent drawing
  • US9600641B2 patent drawing
  • US9600641B2 patent drawing

AI summary

Embodiments of the invention provide for user permissions based control of pooled FoD activation keys. In an embodiment of the invention, a method for user permissions based control of pooled FoD activation keys is provided. The method includes pooling one or more authorization codes for access by different end users in activating different features of a set of hardware components using FoD. The method also includes responding to an FoD request to activate one of the features by a particular one of the end users by determining whether or not a pre-defined code usage policy permits the particular one of the end users to use a pooled one of the authorization codes and if permitted according to the pre-defined code usage policy, generating an FoD activation key with the pooled one of the authorization codes and activating the one of the features with the FoD activation key.