Secure License Manager Bound to Trusted Host State
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional license managers are vulnerable to tampering and unable to determine the trustworthiness of the computing environment in which they are running, making them ineffective in preventing unauthorized software use.
Innovation Solution
A system where a license manager is bound to a trusted state of a host computer, established through a secure boot process using TCPA-enabled hardware and software components, with cryptographic keys protecting dynamic and static sections of the license manager, ensuring it can only operate within a verified trusted environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional license managers are used, then software access control is provided, but the license manager is vulnerable to tampering and cannot determine trustworthiness of the computing environment
Solution Approach 1:
The system performs preliminary actions by establishing a trusted state before the license manager executes. A secure boot process verifies hardware and software components in advance, and cryptographic keys are prepared and bound to the trusted state. This preliminary setup ensures that when the license manager runs, it operates in a verified secure environment, preventing tampering before it can occur.
Solution Approach 2:
The patent introduces an intermediary trusted state that mediates between the license manager and the computing environment. This trusted state, established through secure boot processes and verified by cryptographic keys, acts as a mediator that guarantees the integrity and security of the execution environment, allowing the license manager to operate without direct exposure to potential tampering in the broader system.
2Reliability
If the license manager is bound to a trusted state, then tampering is prevented, but the system complexity increases due to secure boot processes and cryptographic key management
Solution Approach 1:
The patent segments the license manager into distinct components: a dynamic data section and a static code section. The static code section is further divided into subsections for software program code and configuration data. This segmentation allows different parts to be protected by different cryptographic keys, simplifying the overall security architecture while maintaining high reliability. Each segment can be independently verified and protected.
Solution Approach 2:
Different parts of the license manager have different security properties. The dynamic data section uses a data key for encryption, while the static code section uses a code key. These keys are themselves protected by an external key bound to the trusted state. This local differentiation of security measures allows the system to achieve high trustworthiness without uniformly applying maximum security complexity throughout the entire system.
3Reliability
If cryptographic keys are used to protect license manager sections, then data security is improved, but the difficulty of key management and distribution increases
Solution Approach 1:
The patent merges multiple cryptographic key functions into a unified key management structure. The external key serves as a master key that protects both the data key and code key. By combining these key functions into a hierarchical structure where keys are bound to the trusted state, the system simplifies key management and distribution while maintaining strong data protection. The trusted state acts as a centralized authority for key management.
Data Source
AI summary
Systems, methods, and computer program products for secure license management. A host computer runs in a trusted state. A license manager is installed on the host computer. The license manager is configured to provide access to one or more software programs. The one or more software programs are accessible only through the license manager. The license manager is bound to the trusted state of the host computer, such that if the trusted state ceases to exist, then the license manager is not executable and the one or more software programs are not accessible. The host computer can be a TCPA (Trusted Computing Platform Alliance) enabled computer.


