State Hash Verification for Disconnected System Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems managing digital product entitlements in disconnected environments are vulnerable to tampering, as customers can manipulate database tables within their internal networks, making it difficult for providers to verify compliance and usage accurately without direct access.

Innovation Solution

A method involving the generation and verification of system management server state hashes, which are collected from computer systems by a provider server, allowing compliance verification without direct communication with the internal network, using a cryptographically strong algorithm and a random seed for security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the system management server is installed in the customer's internal network in disconnected mode, then the server can operate independently without direct network access, but the provider cannot directly verify the server state or database table correctness

Engineering Contradiction:
Improvedisconnected mode operationVSAvoidcompliance verification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent creates a virtual copy of the system management server state by capturing database table contents and generating hash values. This copy is transmitted to the provider's system for verification, allowing the provider to audit compliance without direct access to the customer's internal network. The hash values serve as cryptographic fingerprints that enable verification of server state integrity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary mechanism using hash values and virtual server instances. Instead of direct verification, the customer's server state is hashed and transmitted as an intermediary data structure to the provider. This intermediary representation enables verification while maintaining the disconnected architecture and customer network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If customers can access and modify database tables in their internal network, then they have full control over their systems, but they can tamper with entitlement numbers to cheat the system

Engineering Contradiction:
Improvesystem control flexibilityVSAvoiddatabase table tampering
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces direct mechanical access to database tables with a cryptographic hash-based verification system. Instead of physically accessing and modifying tables, customers can still operate their systems freely, but any changes to entitlement data are detected through hash value comparison. The provider compares current hash values against recorded baseline hashes to detect tampering.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors database table changes through hash value generation and comparison. When modifications are detected, the system provides feedback to the provider, enabling real-time or periodic detection of entitlement tampering without restricting customer system operations.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If the system management server does not call home to the provider's network, then it operates completely independently, but no verification of server state correctness is possible

Engineering Contradiction:
Improveindependent operationVSAvoidserver state verification information
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The patent creates a virtual copy of the server state by capturing database table contents and generating hash values. This copy is transmitted to the provider's system for verification, allowing the provider to audit compliance without direct access to the customer's internal network. The hash values serve as cryptographic fingerprints that enable verification of server state integrity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary actions by capturing and hashing database table contents at specific intervals or events. These pre-computed hash values are stored and later transmitted to the provider for verification. This preliminary preparation enables verification without requiring continuous or real-time communication with the provider's network.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9299094B2State-based compliance verification in a disconnected system
Publication Date: 2016.03.29 RED HAT INC
  • US9299094B2 patent drawing
  • US9299094B2 patent drawing
  • US9299094B2 patent drawing

AI summary

Some embodiments of a system and a method to verify compliance in a disconnected system have been presented. For instance, a provider server can collect system management server state hashes from a set of computer systems in transactions not directly related to billing between the provider server and the computer systems. The computer systems may be coupled to a system management server that is within an internal network of a customer. The provider server can verify compliance information submitted by the customer using the system management server state hashes collected without communicating with the system management server in the internal network.