Volatile Token Licensing for Device Mirroring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software licensing methods that rely on local device serial numbers or manual login authentication are vulnerable to device mirroring, user errors, and false controls, leading to ineffective concurrent use tracking and unauthorized access.
Innovation Solution
An automatic and transparent device/software licensing system using opportunistic remote communication and volatile token/key pairing, where a license enforcement server provides volatile tokens to each device, replacing them at regular intervals, allowing only one device with the current token to access the software, thus preventing unauthorized use and detecting fraudulent attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If local device serial numbers or internal IDs are used for licensing control, then device identification is simple, but the system is vulnerable to device mirroring and unauthorized access
Solution Approach 1:
The patent implements dynamic licensing by replacing static device serial numbers with time-varying volatile tokens that change periodically. The licensing system transitions from a static identification approach to a dynamic one where tokens are issued with expiration times and can be revoked, making mirrored devices unable to maintain unauthorized access over time.
Solution Approach 2:
The patent introduces a licensing server as an intermediary between the device and the software protection mechanism. Instead of relying solely on local device identifiers, the system uses a centralized server to issue, manage, and revoke volatile tokens, adding a layer of external control that prevents unauthorized access even when devices are mirrored.
2Reliability
If manual login authentication is used to track concurrent use, then licensing control is implemented, but user errors and cumbersome requirements increase
Solution Approach 1:
The patent implements automatic authentication where the licensing client on the device automatically obtains and manages volatile tokens without requiring manual user intervention. The system performs background authentication, token renewal, and validation operations automatically, eliminating the need for users to manually log in or manage credentials while maintaining reliable concurrent use tracking.
Solution Approach 2:
The system performs preliminary authentication and token issuance before software execution. The licensing client automatically obtains valid tokens in advance, and the system validates licensing status proactively before allowing software to run, preventing user errors by eliminating the need for manual login credentials during operation.
3Ease of manufacture
If static licensing tokens are used, then device activation is simple, but fraudulent use cannot be detected after device mirroring
Solution Approach 1:
The patent implements periodic token renewal where licensing tokens are issued with expiration times and must be periodically refreshed by communicating with the licensing server. This periodic validation mechanism detects fraudulent use after device mirroring because mirrored devices cannot maintain continuous communication to renew their tokens, causing their licenses to expire while the legitimate device continues to receive valid tokens.
Data Source
AI summary
Device-specific secure software licensing techniques are disclosed. In various embodiments, a key/token pair associated with a client requesting license validation is received. It is determined whether the key/token pair matches an entry in a store of currently valid key/token pairs. An affirmative response is sent in the event the key/token pair matches a corresponding entry in the store of currently valid key/token pairs.


