Software Authorization Transfer via Encrypted Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software suppliers face challenges in verifying the uninstallation of software on machines operating in offline environments, as they cannot confirm whether the original machine has been properly uninstalled before authorizing a new machine.

Innovation Solution

An authorization management method and system that involves disabling a portion of the deployed software on the first processing device, generating an encrypted value based on device information, and decrypting this value on a second processing device to verify its authenticity before releasing an authorized quota.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the software supplier's server verifies machine authorization through network connection, then the authorization management is reliable, but machines operating in offline environments cannot be verified

Engineering Contradiction:
Improveauthorization verification reliabilityVSAvoidadaptability to offline environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by having the first processing device disable at least a portion of the deployed software before generating the encrypted value. This preliminary disabling action ensures that the software is not running on the original machine, and the subsequent encryption of device information allows the second processing device to verify both the disabling status and device identity without requiring network connection, thus resolving the contradiction between reliability and offline adaptability

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the software supplier requires network connection to verify machine changes, then the authorization control is effective, but the process becomes complex and time-consuming for offline machines

Engineering Contradiction:
Improveauthorization control effectivenessVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism by using encrypted device information as a mediator between the first processing device and the second processing device. The encrypted value contains both the device information and the disabling status, allowing the second processing device to verify authorization control effectiveness without requiring complex network-based verification processes, thus reducing overall system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the software supplier releases authorization quota without verifying uninstallation, then the authorization transfer is fast, but the security and reliability are compromised

Engineering Contradiction:
Improveauthorization transfer speedVSAvoidauthorization security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements feedback by having the first processing device generate an encrypted value that includes information about the disabling status of the software. The second processing device decrypts this value and uses the feedback information to determine whether to release the authorization quota. This feedback mechanism ensures that authorization is only released when the software is confirmed to be disabled, maintaining both speed and security

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4546176A1Authorization management method and system
Publication Date: 2025.04.30 GETAC TECH CORP
  • EP4546176A1 patent drawingFigure 1~2
  • EP4546176A1 patent drawingFigure 3
  • EP4546176A1 patent drawingFigure 4~5

AI summary

An authorization management method, adapted to a deployed software installed on a first processing device, includes: disabling at least a portion of the deployed software by the first processing device, outputting an encrypted value based on device information of the first processing device after the disabling by the first processing device, receiving and decrypting the encrypted value to obtain decrypted information by a second processing device, and releasing an authorized quota corresponding to the deployed software by the second processing device when the decrypted information matches pre-stored information of the second processing device, wherein the pre-stored information comprises the device information.