Just-in-time Software Activation via Short-Range Device Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing deployed software lack reliable, secure, and flexible techniques for monitoring and controlling software provisioning, usage, and updates, often requiring cumbersome and insecure manual processes for license management and customization of setup files.

Innovation Solution

A system that enables secure and efficient activation of access-limited software by using short-range communications between personal computing devices and endpoint resources, where software identifiers and tenant identifiers are used to determine permission, allowing just-in-time activation without requiring customized setup files, and ensuring only authorized software communicates with backend systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual license key entry is used for software activation, then software can be activated on authorized devices, but the process becomes cumbersome and insecure requiring administrator intervention and key concealment

Engineering Contradiction:
Improvesoftware activation securityVSAvoidactivation process complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables devices to automatically activate software without administrator intervention. The activation server autonomously validates device credentials and provisions software, eliminating the need for manual license key entry and administrator involvement while maintaining security through automated credential verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

An activation server acts as an intermediary between devices and software. Instead of direct manual key entry or complex certificate management, the activation server mediates the activation process by receiving device credentials, validating them against authorized device lists, and automatically provisioning software to authorized devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If client certificates are provided as setup file parameters to enable authorized software installation, then only authorized software can be installed on trusted devices, but the approach becomes complex requiring setup file changes and remains vulnerable if certificates are stolen

Engineering Contradiction:
Improveauthorized software installationVSAvoidsetup file customization
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the complex certificate and setup file customization requirements from the activation process. Instead of embedding credentials in setup files or requiring certificate management, the activation server stores authorized device credentials centrally and performs validation during activation, simplifying the installation process to a single executable file without setup file modifications.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of using complex certificates embedded in setup files, the system uses simplified device credentials (such as device IDs or hashed identifiers) that are copied and stored on authorized devices. These credentials are validated by the activation server against stored authorized device lists, providing security without requiring complex setup file customization.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If custom setup files with unique GUIDs are created on a per-customer basis to link software to particular users, then access to software can be limited based on valid GUIDs, but the approach becomes complex requiring setup file customization and administrator involvement

Engineering Contradiction:
Improveuser-specific software access controlVSAvoidsetup file customization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses a universal activation mechanism that works across all devices and software types. Instead of creating custom setup files with embedded GUIDs for each customer, a single activation server handles all activation requests by validating device credentials against authorized device lists, providing user-specific access control through a standardized process that requires no setup file customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system copies simplified device credentials (such as device identifiers or hashed values) to authorized devices during activation. These credentials are stored locally and used for future validation without requiring custom setup files or administrator involvement, enabling user-specific access control through simple credential verification rather than complex per-customer setup file customization.

Inventive Principle:
Principle #26Copying

4Reliability

If software activation requires administrator manual processes and customized setup files, then security can be maintained through controlled distribution, but deployment efficiency and speed are reduced

Engineering Contradiction:
Improvesoftware distribution securityVSAvoidsoftware deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-configuring the activation server with authorized device credentials and software provisioning information before deployment. Devices can then self-register and activate software automatically without waiting for administrator intervention or manual setup file customization, maintaining security through pre-established authorization while dramatically improving deployment speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Devices autonomously perform the activation process by communicating with the activation server, presenting their credentials, and receiving software provisioning information. This self-service approach eliminates the need for administrator manual processes and customized setup files, maintaining security through automated credential validation while enabling rapid parallel deployment across multiple devices simultaneously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10579830B1Just-in-time and secure activation of software
Publication Date: 2020.03.03 CYBER ARK SOFTWARE LTD
  • US10579830B1 patent drawing
  • US10579830B1 patent drawing
  • US10579830B1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for securely and efficiently enabling activation of access-limited software to permitted identities. Techniques include receiving, from a personal computing device associated with an identity, a software identifier associated with access-limited software available on an endpoint computing resource; identifying a tenant identifier associated with the identity; identifying a prompt to activate the access-limited software available on the endpoint computing resource; determining that the identity is permitted to utilize the access-limited software based on at least the software identifier and tenant identifier; and enabling, based on the determining, activation of the access-limited software for use by the identity at the endpoint computing resource.