State Hash Verification for Disconnected System Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems managing digital product entitlements in disconnected environments are vulnerable to tampering, as customers can manipulate database tables within their internal networks, making it difficult for providers to verify compliance and usage accurately without direct access.
Innovation Solution
A method involving the generation and verification of system management server state hashes, which are collected from computer systems by a provider server, allowing compliance verification without direct communication with the internal network, using a cryptographically strong algorithm and a random seed for security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the system management server is installed in the customer's internal network in disconnected mode, then the server can operate independently without direct network access, but the provider cannot directly verify the server state or database table correctness
Solution Approach 1:
The patent creates a virtual copy of the system management server state by capturing database table contents and generating hash values. This copy is transmitted to the provider's system for verification, allowing the provider to audit compliance without direct access to the customer's internal network. The hash values serve as cryptographic fingerprints that enable verification of server state integrity.
Solution Approach 2:
The patent introduces an intermediary mechanism using hash values and virtual server instances. Instead of direct verification, the customer's server state is hashed and transmitted as an intermediary data structure to the provider. This intermediary representation enables verification while maintaining the disconnected architecture and customer network security.
2Ease of operation
If customers can access and modify database tables in their internal network, then they have full control over their systems, but they can tamper with entitlement numbers to cheat the system
Solution Approach 1:
The patent replaces direct mechanical access to database tables with a cryptographic hash-based verification system. Instead of physically accessing and modifying tables, customers can still operate their systems freely, but any changes to entitlement data are detected through hash value comparison. The provider compares current hash values against recorded baseline hashes to detect tampering.
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors database table changes through hash value generation and comparison. When modifications are detected, the system provides feedback to the provider, enabling real-time or periodic detection of entitlement tampering without restricting customer system operations.
3Extent of automation
If the system management server does not call home to the provider's network, then it operates completely independently, but no verification of server state correctness is possible
Solution Approach 1:
The patent creates a virtual copy of the server state by capturing database table contents and generating hash values. This copy is transmitted to the provider's system for verification, allowing the provider to audit compliance without direct access to the customer's internal network. The hash values serve as cryptographic fingerprints that enable verification of server state integrity.
Solution Approach 2:
The patent performs preliminary actions by capturing and hashing database table contents at specific intervals or events. These pre-computed hash values are stored and later transmitted to the provider for verification. This preliminary preparation enables verification without requiring continuous or real-time communication with the provider's network.
Data Source
AI summary
Some embodiments of a system and a method to verify compliance in a disconnected system have been presented. For instance, a provider server can collect system management server state hashes from a set of computer systems in transactions not directly related to billing between the provider server and the computer systems. The computer systems may be coupled to a system management server that is within an internal network of a customer. The provider server can verify compliance information submitted by the customer using the system management server state hashes collected without communicating with the system management server in the internal network.


