Software License Validation via Ephemeral Data and Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mechanisms for secure authorization of technology access become complex when components are developed by independent parties, particularly when a third party needs to grant proper authorization, and shared secret solutions are inadequate due to password interception risks and limitations in issuing additional passwords.
Innovation Solution
The licensor provides licensure information for creating identifying marks associated with applications and implementations, including application private keys and licensor digital signatures, which are validated at runtime by adding ephemeral data to create a marked extended license that can be validated by the implementation, ensuring only authorized access to the technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a shared secret password mechanism is used for authorization validation, then the authorization process is simple to implement, but the system becomes vulnerable to password interception and cannot issue additional passwords dynamically
Solution Approach 1:
The patent replaces the mechanical password-based authentication system with a public key infrastructure (PKI) system. Instead of exchanging and validating passwords through direct communication, the system uses cryptographic key pairs where the application holds a private key and the implementation holds a public key for validation. This substitution eliminates password interception vulnerabilities while maintaining authentication functionality.
Solution Approach 2:
The patent introduces a licensor as an intermediary authority that issues licensing information containing cryptographic key pairs to both applications and implementations. This intermediary enables trusted authorization validation without requiring direct secret sharing between the application and implementation, resolving the security issue while preserving implementation simplicity.
2Adaptability or versatility
If a large list of passwords is stored in the implementation for validation, then all possible applications can be authorized, but the device complexity and storage requirements increase significantly
Solution Approach 1:
Instead of storing multiple password copies in the implementation, the patent uses a single public key that can validate any application license issued by the licensor. The licensing information acts as a portable credential that applications present for validation, eliminating the need for the implementation to maintain large password lists while supporting unlimited applications.
Solution Approach 2:
The public key in the implementation serves as a universal validator for all licensed applications. Rather than requiring specific password entries for each application, the single public key can validate any license issued by the licensor, providing unlimited authorization coverage without increasing storage requirements.
3Reliability
If passwords are written into licensed implementations and applications, then authorization is established, but additional passwords cannot be issued dynamically and intercepted passwords can be misused
Solution Approach 1:
The patent transforms the static password system into a dynamic licensing system. Licensing information including cryptographic key pairs can be issued dynamically by the licensor to new applications without modifying the implementation. The ephemeral nature of license validation tokens allows for dynamic authorization while maintaining security, as each license is time-limited and single-use.
Data Source
AI summary
Methods and systems are provided for facilitating control of access to technology to authorized parties. A licensor provides licensure information to an application developer that includes a private key and a license, the license including an application public key and an identifying mark associated with the licensor, e.g., a digital signature. The licensor additionally provides a licensor public key to an implementation developer. The application developer and the implementation developer subsequently write the received information into the respective application and implementation. At runtime, the application adds ephemeral data and an identifying mark associated with the application to the application license and forwards the marked extended application license to the implementation. The implementation then validates the ephemeral data, the licensor's identifying mark and the licensee's identifying mark. Once all information is validated, the marked extended application license is validated and the licensed application may expose the licensed technology to a user.


