Disclosure-Free Software Notarization via Proof Algorithms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software vendors face challenges in authenticating software artifacts securely without exposing proprietary information or trade secrets, as existing methods require sharing the software artifact with a software notarizer.

Innovation Solution

The implementation of a disclosure-free notarization certificate system, where a software notarizer communicates with a software vendor to generate a certificate without requiring access to the software artifact, using a proof algorithm to validate the artifact's authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software artifact is shared with software notarizer for authentication, then authentication capability is improved, but information security deteriorates

Engineering Contradiction:
Improveauthentication capabilityVSAvoidproprietary information exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential authentication characteristics from the software artifact and sends them to the notarizer, rather than sharing the complete artifact. This allows authentication to proceed while keeping the proprietary software code and structure confidential, directly resolving the contradiction between authentication capability and information security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that enables verification without direct exposure of the software artifact to the notarizer. The notarizer verifies authentication properties through this intermediary process rather than by examining the actual software code, thus maintaining security while enabling authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If software artifact is not shared with software notarizer, then information security is improved, but authentication capability deteriorates

Engineering Contradiction:
Improveproprietary information protectionVSAvoidauthentication capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent extracts authentication-relevant properties from the software artifact and transmits only these extracted properties to the notarizer. This extraction mechanism enables the notarizer to perform authentication on the software without needing access to the complete artifact, thus maintaining both information security and authentication capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the traditional mechanical approach of sharing the entire software artifact with a cryptographic/mathematical substitution. Instead of physical or digital sharing of code, the system uses mathematical proofs and cryptographic verification to enable authentication without exposure of proprietary information

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250181697A1Systems and methods for software authentication without providing full software disclosure to a software notarizer
Publication Date: 2025.06.05 SAP SE
  • US20250181697A1 patent drawing
  • US20250181697A1 patent drawing
  • US20250181697A1 patent drawing

AI summary

Embodiments describe techniques for authenticating software artifacts in a secure manner that does not require the software notarizer accessing or storing any software artifact data. A proof algorithm may be utilized by the software vendor and the software notarizer in generating the disclosure-free notarization certificate. The same proof algorithm may then be utilized by the software consumer during validation of the software artifact. These techniques may improve the software security since access to data from the software artifact is limited to the software vendor and the software consumer.