Secure Software Service Token Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software security mechanisms are inadequate for providing secure and flexible pricing models in service-oriented architectures, particularly in software-as-a-service (SaaS) systems, where traditional license-based pricing models do not align with modern usage patterns and business needs.

Innovation Solution

The implementation of a secure software service system that uses symmetric and asymmetric key encryption for secure transactions between software service consumers and providers, including the issuance and validation of license tokens and capability tokens, to ensure authorized access and usage of software services, with each transaction utilizing shared symmetric keys for encoding information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional license-based pricing models are used in software-as-a-service systems, then software vendors can maintain simple pricing structures, but the systems lack the security and flexibility needed for modern service-oriented architectures

Engineering Contradiction:
Improvepricing model flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the traditional monolithic licensing model into multiple independent token types (license tokens, capability tokens, service tokens) that can be issued and validated separately. This segmentation allows the system to provide fine-grained access control and flexible pricing while maintaining security through modular validation components that verify each token type independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces token-based intermediaries (license tokens, capability tokens) that mediate between the service consumer and the software service provider. These tokens act as secure carriers of authorization information, enabling flexible pricing models while maintaining strong security through cryptographic validation, thus resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If symmetric key encryption is used for all transactions, then security is enhanced through consistent encoding, but the system complexity increases due to key management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies symmetric key encryption selectively to specific transactions and data elements rather than uniformly across the entire system. Each token type and transaction phase uses appropriate encryption with symmetric keys, providing localized security where needed while avoiding unnecessary complexity in other parts of the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the cryptographic parameters dynamically based on the transaction type and sensitivity. Different symmetric keys are used for different token types and validation phases, allowing the system to optimize security for each specific operation while managing overall key complexity through structured key generation and distribution protocols.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8843415B2Secure software service systems and methods
Publication Date: 2014.09.23 SAP SE
  • US8843415B2 patent drawing
  • US8843415B2 patent drawing
  • US8843415B2 patent drawing

AI summary

In one embodiment the present invention includes a method of performing a secure transaction in a software system, such as a software service system, for example. Embodiments of the invention include encoding symmetric keys for securing transactions between a service consumer and service provider. Asymmetric keys are also used for providing additional security during transactions. In one embodiment, license tokens and capability tokens are encoded and passed between a service consumer and service provider for allowing a consumer secure access to authorized services.