Virtual TPM UUID Encryption for VM License Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software piracy remains a significant concern in virtual environments, with existing solutions like software-based encryption being complex, impacting hardware performance, and vulnerable to hacking, and posing challenges in managing application licenses.

Innovation Solution

The implementation of a system that uses a virtual Trusted Platform Module (vTPM) to validate and encrypt UUIDs within virtual machines, ensuring that only legitimate software installations can generate and decrypt license keys, thereby preventing unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based encryption is used to prevent piracy, then security is improved, but device complexity increases and hardware performance is impacted

Engineering Contradiction:
Improvepiracy prevention securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based encryption with hardware-based encryption using a Trusted Platform Module (TPM). This substitution moves the encryption functionality from the software layer to a dedicated hardware component, thereby reducing software complexity and eliminating the performance overhead on the host system while maintaining strong security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a virtualization layer that mediates between the TPM hardware and the virtual machines. The virtual TPM (vTPM) acts as an intermediary that allows multiple VMs to access encryption services without direct hardware access, simplifying the overall system architecture while maintaining security through controlled access mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software-based encryption is used to prevent piracy, then security is improved, but the system becomes vulnerable to hacking

Engineering Contradiction:
Improvepiracy prevention securityVSAvoidhacking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based encryption with hardware-based encryption using a Trusted Platform Module (TPM). This substitution moves the encryption functionality from the software layer to a dedicated hardware component, thereby reducing software complexity and eliminating the performance overhead on the host system while maintaining strong security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates a secure, isolated environment within the TPM hardware where cryptographic operations occur. This 'inert environment' protects sensitive cryptographic keys and operations from external attacks, as the TPM hardware is designed to resist physical and logical tampering attempts.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Adaptability or versatility

If virtual machines are used to provide flexibility, then adaptability is improved, but managing application licenses becomes more difficult

Engineering Contradiction:
Improvevirtual environment flexibilityVSAvoidlicense management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service license management where each virtual machine automatically generates and manages its own cryptographic keys through the vTPM. The license validation process is automated, with the system itself performing verification without requiring complex external license management infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a virtualization layer that mediates between the TPM hardware and the virtual machines. The virtual TPM (vTPM) acts as an intermediary that allows multiple VMs to access encryption services without direct hardware access, simplifying the overall system architecture while maintaining security through controlled access mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12259953B2Framework for preventing software piracy in virtual machines (VMs) by using virtual hardware encryption verification
Publication Date: 2025.03.25 EMC IP HLDG CO LLC
  • US12259953B2 patent drawing
  • US12259953B2 patent drawing
  • US12259953B2 patent drawing

AI summary

One example method includes receiving, from a VM, a request for a software license, in response to the request, transmitting a UUID to the VM, receiving, from the VM, a response that comprises a first encrypted UUID corresponding to the request, and transmitting a client object that includes the first encrypted UUID, and the client object serves as a request for entry of the client object in a database of a cloud computing site.