Security Device for Software Authorization via Signed Response
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authorization methods, such as dongles, are vulnerable to unauthorized access and manipulation when proprietary software is used on untrusted computing devices, as they can be compromised or fooled into recognizing a false dongle presence.
Innovation Solution
A security device, such as a mobile device, is used to authorize software tool usage by generating a signed response with a key, which includes authorization information and restrictions, ensuring the software tool's validity and geographical compliance, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If proprietary software is encrypted and requires a dongle for decryption, then software security is improved, but the system becomes vulnerable to compromise and false dongle recognition
Solution Approach 1:
The patent introduces a security device as an intermediary between the proprietary software and the computing device. This security device holds the decryption key and must be present for the software to execute. The security device verifies the computing device's authorization credentials before allowing decryption, creating a trusted mediation layer that prevents unauthorized access even if the computing device is compromised.
Solution Approach 2:
The patent implements preliminary authorization verification before software execution. The security device checks authorization credentials and establishes a trusted relationship between the computing device and proprietary software before decryption occurs. This preliminary action ensures that even if the computing device is later compromised, the unauthorized entities cannot access the software without valid credentials.
2Reliability
If dongle presence is checked by modifying executable binary code, then authorization verification is achieved, but the system becomes vulnerable to fooling the software into false recognition
Solution Approach 1:
The security device acts as an intermediary that performs the authorization verification externally, rather than embedding verification logic within the executable binary code. The security device checks credentials and provides authorization information to the software without requiring the software to contain vulnerable checking instructions, thus maintaining software integrity.
Solution Approach 2:
The patent replaces the mechanical approach of modifying executable binary code with a cryptographic system. Instead of altering software instructions to check for dongle presence, the system uses encryption/decryption mechanisms and digital credentials verified by the security device, eliminating the need to compromise the executable binary code.
3Speed
If the computing device stores unencrypted proprietary software, then execution speed is improved, but unauthorized entities can retrieve and copy the software
Solution Approach 1:
The patent performs decryption as a preliminary action at runtime rather than storing pre-decrypted software. The proprietary software remains encrypted during storage and is decrypted only when the security device verifies authorization and initiates decryption during execution. This approach maintains security while enabling fast execution since the decryption occurs once at startup rather than requiring continuous security checks during runtime.
Data Source
AI summary
The described embodiments relate generally to methods, systems and security devices for authorizing use of a software tool. Certain embodiments of the invention relate to a security device. The security device comprises at least one communication subsystem for enabling communication between the security device and a first external device, wherein the first external device has a software tool executable on the first external device. The security device further comprises a memory and processor coupled to the at least one communication subsystem and configured to control the at least one communication subsystem. The memory is accessible to the processor and stores a key for authorizing use of the software tool. The memory further stores program instructions which, when executed by the processor, cause the processor to execute a security application.


