Disclosure-Free Software Notarization via Proof Algorithms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software vendors face challenges in authenticating software artifacts securely without exposing proprietary information or trade secrets, as existing methods require sharing the software artifact with a software notarizer.
Innovation Solution
The implementation of a disclosure-free notarization certificate system, where a software notarizer communicates with a software vendor to generate a certificate without requiring access to the software artifact, using a proof algorithm to validate the artifact's authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software artifact is shared with software notarizer for authentication, then authentication capability is improved, but information security deteriorates
Solution Approach 1:
The patent extracts only the essential authentication characteristics from the software artifact and sends them to the notarizer, rather than sharing the complete artifact. This allows authentication to proceed while keeping the proprietary software code and structure confidential, directly resolving the contradiction between authentication capability and information security
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that enables verification without direct exposure of the software artifact to the notarizer. The notarizer verifies authentication properties through this intermediary process rather than by examining the actual software code, thus maintaining security while enabling authentication
2Loss of information
If software artifact is not shared with software notarizer, then information security is improved, but authentication capability deteriorates
Solution Approach 1:
The patent extracts authentication-relevant properties from the software artifact and transmits only these extracted properties to the notarizer. This extraction mechanism enables the notarizer to perform authentication on the software without needing access to the complete artifact, thus maintaining both information security and authentication capability
Solution Approach 2:
The patent replaces the traditional mechanical approach of sharing the entire software artifact with a cryptographic/mathematical substitution. Instead of physical or digital sharing of code, the system uses mathematical proofs and cryptographic verification to enable authentication without exposure of proprietary information
Data Source
AI summary
Embodiments describe techniques for authenticating software artifacts in a secure manner that does not require the software notarizer accessing or storing any software artifact data. A proof algorithm may be utilized by the software vendor and the software notarizer in generating the disclosure-free notarization certificate. The same proof algorithm may then be utilized by the software consumer during validation of the software artifact. These techniques may improve the software security since access to data from the software artifact is limited to the software vendor and the software consumer.


