Signed Genuine Ticket for Secure Client Licensing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software licensing technologies face challenges in securely validating and managing licensing information, particularly when dealing with untrusted clients, as repeated validation requests can be cumbersome and vulnerable to tampering.

Innovation Solution

A system where a validation server provides a client with a private key and signed genuine ticket, allowing the client to authenticate with a service provider server using a client signature and lockbox signature, thereby securing licensing information without overloading the validation server with repeated requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a validation server repeatedly validates licensing information for untrusted clients, then licensing validation can be performed, but the validation server becomes overloaded and vulnerable to tampering

Engineering Contradiction:
Improvelicensing validation securityVSAvoidvalidation server performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The validation server performs preliminary validation of the client and licensing information before allowing repeated requests. A genuine ticket is issued containing a signature and timestamp that proves the client's authorization status in advance, enabling the client to access services without repeated validation requests.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The genuine ticket acts as an intermediary credential between the validation server and service provider servers. This ticket contains the client's authorization information and can be presented to multiple service providers, eliminating the need for repeated validation requests to the validation server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If licensing information is transferred through untrusted clients, then client flexibility is improved, but security and trustworthiness of the licensing information deteriorates

Engineering Contradiction:
Improveclient access flexibilityVSAvoidlicensing information trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The validation server performs preliminary validation of the client and licensing information before allowing repeated requests. A genuine ticket is issued containing a signature and timestamp that proves the client's authorization status in advance, enabling the client to access services without repeated validation requests.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The genuine ticket acts as an intermediary credential between the validation server and service provider servers. This ticket contains the client's authorization information and can be presented to multiple service providers, eliminating the need for repeated validation requests to the validation server.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a signed genuine ticket with client correlation data is issued, then cloning of the ticket is inhibited, but the complexity of the validation process increases

Engineering Contradiction:
Improveticket uniquenessVSAvoidvalidation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The validation server validates the client and licensing information, then issues a genuine ticket as an intermediary credential. This ticket includes a signature from the validation server and correlation data (timestamp, IP address, MAC address, product ID) that ties the ticket to specific client characteristics, preventing cloning while streamlining the validation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8806192B2Protected authorization for untrusted clients
Publication Date: 2014.08.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8806192B2 patent drawing
  • US8806192B2 patent drawing
  • US8806192B2 patent drawing

AI summary

One or more techniques and/or systems are provided for securely authorizing a client to consume data and/or services from a service provider server while mitigating burdensome requests made to a validation server. That is, validation data provided to a client from a validation server may be maintained on the client and at least some of that validation data can be used to subsequently authorize the client when the client attempts to consume data and/or services from the service provider server (e.g., download a song). However, the validation data is maintained on the client and/or provided to the service provider server in a manner that inhibits user tampering. In this manner, numerous requests for validation of the client need not be made from the service provider server to the validation server when a client requests content from the service provider server, while also inhibiting unauthorized consumptions of data by the client.