Virtual Execution File Security Controller for Software Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional software security methods fail to provide comprehensive protection against unauthorized duplication and usage of software beyond installation, lacking control over usage authority and allowing unauthorized copying and execution.

Innovation Solution

A method and apparatus that creates a virtual execution and data environment during software installation, with a controller managing security functions such as user authentication, usage frequency, and duration, and integrating security modules like screen saving and clipboard control, allowing for secure software execution and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication procedures are performed during software installation, then software can be secured during installation, but security cannot be provided after installation and unauthorized copying can occur

Engineering Contradiction:
Improvesoftware securityVSAvoidsecurity protection duration
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent applies preliminary action by performing authentication and security setup during the installation phase before the software is executed. The installation file includes authentication information and security settings that are established in advance, enabling continuous security protection throughout the software's entire lifecycle rather than only during installation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent ensures continuity of useful action by maintaining security protection throughout the software's entire lifecycle. The system continuously monitors and controls software execution, usage frequency, and duration, ensuring that security remains active from installation through ongoing use, preventing gaps in protection.

Inventive Principle:
Principle #20Continuity of useful action

2Ease of manufacture

If simple authentication procedures are used during installation, then installation security can be provided, but the authentication fails due to cracking or leakage of serial numbers

Engineering Contradiction:
Improveauthentication procedure simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies parameter changes by evolving the authentication mechanism from simple serial number verification to multi-parameter authentication. The system incorporates usage frequency limits, execution duration controls, and continuous validation parameters that make cracking and leakage ineffective, while maintaining ease of use through automated background validation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary security management system that mediates between the user and the software execution. This intermediary layer continuously validates authentication credentials, monitors usage patterns, and controls access rights, preventing direct attacks on the authentication mechanism while maintaining user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If users can know the installation path through the installation file, then files can be copied without permission, but comprehensive security control over usage authority cannot be implemented

Engineering Contradiction:
Improveuser convenienceVSAvoidusage authority control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary security management system that mediates between the user and the software execution. This intermediary layer continuously validates authentication credentials, monitors usage patterns, and controls access rights, preventing direct attacks on the authentication mechanism while maintaining user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements feedback mechanisms that continuously monitor software execution and usage patterns. The system provides real-time feedback on authentication status, usage frequency, and duration, enabling dynamic control of access rights and preventing unauthorized copying while maintaining user convenience through automated validation.

Inventive Principle:
Principle #23Feedback

4Device complexity

If only expired date control is used for software execution, then implementation is simple, but various selling models and paid policies cannot be controlled

Engineering Contradiction:
Improveusage control mechanismVSAvoidselling model flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the usage control mechanism adjustable and adaptable. The security management system allows distributors to dynamically configure various control parameters such as usage frequency limits, execution duration, authentication requirements, and policy rules, enabling flexible adaptation to different selling models and paid policies without increasing basic implementation complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8549580B2Method and apparatus for providing software security
Publication Date: 2013.10.01 TERUTEN
  • US8549580B2 patent drawing
  • US8549580B2 patent drawing
  • US8549580B2 patent drawing

AI summary

A method and apparatus for providing software security is provided. In the software security method, an installation file of software that includes at least one execution file and at least one data file which are stored in a user terminal is executed. Accordingly, at least one virtual execution file corresponding to the at least one execution file and at least one virtual data file corresponding to the at least one data file are installed in a user area of the user terminal, and the at least one execution file, the at least one data file, and a controller for controlling the at least one virtual execution file and the at least one execution file are installed in a security area of the user terminal.