Trusted Platform Module Software Licensing Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for protecting software licensing information are inadequate, as they rely on access controls or encoding hardware characteristics, which can be bypassed, and require online connectivity, making them ineffective in offline scenarios.
Innovation Solution
The use of a trusted platform module (TPM) to generate and protect software licensing information by creating a secure register with an asymmetric key specific to the software application, allowing for offline validation of licenses through a secure signature verification process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access controls or encoding hardware characteristics are used to protect licensing files, then licensing protection is provided, but the protection can be bypassed or overcome by bad actors
Solution Approach 1:
The patent introduces a Trusted Platform Module (TPM) as an intermediary security device that generates and stores cryptographic keys securely. The TPM acts as a mediator between the licensing system and the hardware platform, providing enhanced protection that cannot be easily bypassed. The TPM's secure key generation and storage capabilities create a higher-level security barrier that addresses the vulnerability of traditional access control methods.
Solution Approach 2:
The patent replaces traditional mechanical access control methods with cryptographic authentication based on TPM-generated keys and digital signatures. Instead of relying on hardware encoding or access control lists that can be bypassed, the system uses mathematical cryptography rooted in the TPM's secure hardware environment, making bypass significantly more difficult.
2Adaptability or versatility
If online connectivity is required for license validation, then centralized control is maintained, but offline scenarios cannot be supported
Solution Approach 1:
The patent implements preliminary action by generating and storing cryptographic keys and license information in the TPM before offline operation is needed. The system prepares security credentials in advance during online phases, enabling autonomous offline validation without requiring real-time connectivity. This allows the system to adapt to offline scenarios while maintaining security through pre-configured TPM-based authentication.
3Reliability
If traditional license protection methods are used, then implementation is simple, but security against tampering is insufficient
Solution Approach 1:
The patent segments the security architecture by separating key generation, key storage, and license validation into distinct TPM functions. The TPM is divided into secure registers for key storage and cryptographic operations, creating modular security components that work together to provide tamper resistance. This segmentation allows complex security to be achieved through coordinated simple operations within the TPM.
Solution Approach 2:
The patent uses cryptographic copying through digital signatures, where the TPM creates a cryptographic copy of the license information signed with its private key. This signed copy can be verified without exposing the original private key, providing tamper resistance while maintaining implementation feasibility through standard cryptographic operations.
Data Source
AI summary
Methods for protecting software licensing information via a trusted platform module (TPM) are performed by systems and devices. When a licensing server is unreachable, a license is generated for a software application by a licensing manager. The license is generated via a secure register of the TPM using an asymmetric key, specific to the software application and policy-tied to the secure register, to generate a signature of a hashed license file for the software application. The asymmetric key is stored, mapped to the license file, and used for subsequent license validation. A licensing manager validation command is provided to validate the license using the key, as applied to the hash, to verify the signature and checking validity of the time stamp. Time stamp expiration or alteration of the license are determined to provoke invalidation indications for the validating application.


