Device for protecting an electronic apparatus
Abstract
(57) Summary book invention relates to the device for protecting an electronic device, apparatus (4), a system, or the same device so that use of the function which can be accessed using the program or program part in which Locke is possible may be prevented. This protection device is connectable with the electronic device which should be protected, apparatus (4), a system, or the same device through an interface (3). In order to perform this, the predetermined identification number is assigned to this protection device (5), and in order that this protection device (5) may memorize at least one activation code which can be compared with an identification number, an eternal memory (2), for example, EEPROM, is included preferably. Furthermore, this protection device (5) has the program memory (7) protected so that it might not be read for memorizing at least one release program carried out when an activation code and the identification number of a protection device are in agreement. In the protection device (5), the program memory (7) by which the read-out protection of for memorizing at least one release program was carried out is being interlocked with the memory (2) for memorizing at least one activation code. (57) Summary book invention relates to the device for protecting an electronic device, apparatus (4), a system, or the same device so that use of the function which can be accessed using the program or program part in which Locke is possible may be prevented. This protection device is connectable with the electronic device which should be protected, apparatus (4), a system, or the same device through an interface (3). In order to perform this, the predetermined identification number is assigned to this protection device (5), and in order that this protection device (5) may memorize at least one activation code which can be compared with an identification number, an eternal memory (2), for example, EEPROM, is included preferably. Furthermore, this protection device (5) has the program memory (7) protected so that it might not be read for memorizing at least one release program carried out when an activation code and the identification number of a protection device are in agreement. In the protection device (5), the program memory (7) by which the read-out protection of for memorizing at least one release program was carried out is being interlocked with the memory (2) for memorizing at least one activation code.

Term
Term ended
Expired 24 September 2016, 10 years ago.
- Priority and filed
- Granted
- Expired
- Today
10 claims: 1 independent, 9 dependent
- 1claims 1. Device for protecting an electronic device, a system, a system or the like against the Use of lockable programs or program parts executable functions, which Device with the device to be protected system, system od. like. can be connected via an interface, wherein the protective device is associated with a predeterminable identification number and the protection device preferably a non-erasable memory, eg an EEPROM, for storing at least one activation code, which activation code is comparable to the identification number, and a read-only program memory is provided for storing at least one release program, which release program is carried out in accordance with the activation code and the identification number of the protection device, characterized, in that the read-only program memory (7) for storing at least one release program is arranged together with the memory for storing (2) at least one activation code in the protection device (5). AT 405 466 Β
90 paragraphs in 1 section, as filed
(42) Date of commencement of the patent: 15.12.1998 (45) Date of issue: 25. 8.1999
<td>(56) Documents:</td><td>(73) Patent owner:</td>
<td>WO 94 / 06071A1 EP 0457655A1 EP 0478969A2 EP 0537738A2</td><td>ERICSSON AUSTRIA AKTIENGESELLSCHAFT</td>
<td>EP 0594493A1</td><td>A-1120 VIENNA (AT). (72) Inventor: ZIWFERMANN GERHARD HOW »(AT). YEAR'S LEIF INGEMAR WIEK (AT).</td>
(54) DEVICE FOR PROTECTING AN ELECTRONIC EQUIPMENT (57) Device for protecting an electronic device, a system (4), a system or the like like. against the use of lockable programs or program parts executable functions, soft device with the protected device, system, system od. like. via an interface (3) is connectable, wherein the protective device (5) is associated with a predeterminable identification number and the protective device is a preferably non-erasable memory (2), eg an EEPROM, for storing at least one activation code, which activation code is comparable to the identification number, and a read-only program memory (7) is provided for storing at least one release program, which release program is carried out in accordance with the activation code and the identification number of the protection device, wherein the read-only program memory (7) for storing at least one release program is arranged together with the memory for storing (2) at least one activation code in the protection device (5)
<img file="AT405466B_D0001.tif" />
DVR 0078018
AT 405 466 Β
The invention relates to a device for protecting an electronic device, a system, a system od. like. against the use of lockable programs or program parts executable functions, which device with the protected device, system, system od. like. can be connected via an interface, wherein the protective device is associated with a predeterminable identification number and the protection device preferably a non-erasable memory, eg an EEPROM for storing at least one activation code, which activation code is comparable to the identification number, and a read-only program memory for storing at least one release program is provided, which release program is carried out in accordance with the activation code and the identification number of the protection device.
Devices of this type, which are also called dongle, security device, hardlock, etc., serve to protect individual functions of a computer software that are executed by programs or program parts. The hitherto known software protection is based on software or hardware solutions or a combination of these.
Pure software solutions are typical for professional computer systems, which are equipped with an individual, worldwide unique identification number, the Node-ID. The protected program only runs if a suitable response code has been stored in the system for a query code. Before the protected program or program part is executed, the system software calculates a key value from the machine identification number, which is compared with a second key value calculated from the response code. If these match, the program will continue. But even a part of the program code can be encrypted, which must first be decoded with a key made up of the answer code and the serial number.
The advantages of such a software solution are its ease of maintenance, since the response code storage in the system can be done very quickly automatically, for example via modem, or manually by keyboard, for example, by the code by phone, by fax or verbally passed on to an operator who then enter it. Furthermore, it is advantageous that different codes are possible for different program functions. There are no additional costs for each protected program and the security is relatively high.
The disadvantages of such a software solution is that a change to another system with a different identification number from the licensee is not feasible. Furthermore, the system to be protected requires a unique identification number, which is not always available, which makes the protection unsafe.
The second major area of known software security implementations is hardware solutions that are typically used in the PC sector. A device to be connected to a computer interface (dongle) responds to question codes of the software with appropriate response codes. Instead of simple response codes, a coded part of the program can be decrypted by this dongle or calculations from program algorithms can be transferred to the dongle. The advantages of the hardware solutions are that dongle protection can be transferred from system to system, which is very important in system replacement in the event of a defect or generation fit. No identification number is required within the system.
A disadvantage of the hardware solutions, however, is that normally only protection for a program or a program part is to be obtained for a dongle. Individual program parts can not be re-licensed or only with great effort. Furthermore, this requires its own interface and also draws the power supply from this.
US Pat. No. 5,222,133 discloses a protection device in which, for each program part to be unlocked, a response code is stored in a read-only memory of a system to be protected, from where it can be called up with the correct activation code.
Furthermore, in WO-A1-94 / 06071 a circuit (dongle) for protection against unauthorized copying of software is described which changes information at a specific, virtual or real memory location of a computer system in the form of a code. A computer checked for correctness, which is generated due to the implementation of an algorithm in the circuit, causes the beginning or continuation of the locked program.
By loading the software to be protected, the dongle is activated, which uses the algorithm to change the code at the relevant memory location in a predeterminable manner and to return it to the software. If this returned data is correct, the program will continue to run properly.
The dongle is formed, for example, by a magnetic disk having an integrated memory circuit thereon, a battery, and a read / write head. This allows a very specific sector of the program stored on the disk to be located on the diskette
AT 405 466 Β
Circuit in its information content to be changed. The predetermined course of this information change is set in the software to be protected, so that it can only be executed when the specified sequence is determined by this. The floppy disk can contain only one release routine or a complete program to be installed. The copying of the floppy disk is prevented by transferring only one value at that location of the floppy disk where the information change is performed, but not the predetermined sequence generated within the integrated circuit on the floppy disk. However, the dongle device disclosed in this document does not make it possible subsequently to change the activation codes, for example when the manufacturer releases another function.
EP-A2-478 969 describes a device for protecting against unauthorized use of software that includes a first permanent code and a second code that can be plugged into a connector of a computer, whereby a connection between the device and the computer can be established. The dongle device is queried by the computer software to be protected. A control code is generated via an algorithm decoder from the first and second code. The first code is provided to the user together with the device under the control of the manufacturer, while the second variable code can be entered from the outside through a separate input of the computer. The algorithm decoder can be realized either in the software or in the hardware of the computer. In one embodiment of the device, a plurality of second codes are stored, via which different program modules can be unlocked. For each additional program element, however, the first code must always be known or be requested by the manufacturer via telephone. The dongle device shown in Fig. 2 of the preamble includes a permanent code K in addition to the one<sub>x</sub> a variety of modifiable codes K<sub>a</sub>, each of which in combination with the code K<sub>x</sub> to activate each one program or program part is capable of. Thus, the identification number and various activation codes are stored on the dongle device, the evaluation and assignment is made outside the dongle in the device, so that they take up space and computing power there.
Similar to the device according to EP-A2-478 969, a first and a second code for protecting computer software are also used in the device described in EP-A2-537 738. The computer-mountable dongle stores the first code, while the algorithm for generating a control code that releases the protected program (s) is implemented by the computer software of the device to be protected. The second code, which generates the control code by using this algorithm in combination with the first code, is secret and is either entered directly from the user's keyboard via the computer keyboard or stored on the hard disk of the device to be protected. The significant disadvantage of this solution is that the device to be protected a permanent storage must be provided, which must be installed again in case of failure of the device on a replacement system only the appropriate key.
In EP-A1-594 493 a data acquisition system is described, which allows controlled access to several programs stored on a central computer via a data transmission line. The user can with the existing authorization, which is made possible by a security module, the programs from the central computer to his computer, for example via a telephone line, dubbing. The safety module which can be plugged into the user computer consists of an integrated circuit, a secret activation code non-volatile memory and a program protection circuit, the latter linking the code entered by the user with the activation code in order to achieve the release. On the one hand, the programs to be protected according to this document are stored in a remote location and on the other hand, no possibility is given, with a subsequent change of the activation code is made possible. In addition, a storage device for storing the secret codes must be provided for several accessible functions within the device to be protected.
Furthermore, EP-A1-0 457 655 discloses a device for access authorization for a plurality of programs stored in a computer workstation. Each program to be protected is assigned a respective protection module which must be plugged into a device connected to the computer in order to obtain the release of the associated program. Each module contains a microprocessor with a memory that contains the access authorization. Although it can be accessed on various programs that must be present in the computer itself, for each program but a specific dongle is necessary. This makes the handling of such a device considerably more difficult if several functions are to be freely enabled or disabled. Furthermore, the evaluation of the activation code takes place within the computer, whereby a relatively low level of security against a trial of code combinations is made possible.
AT 405 466 Β
The object of the invention is to provide a device of the type mentioned above, which provides secure protection against unauthorized start-up of several locked functions, without having to provide exclusively required components in the device to be protected.
Another object of the invention is to allow a change of the functions to be released, which must be performed over very long distances without having to return the system to be protected or the protection device to the licensor.
According to the invention, this is achieved in that the read-only program memory for storing at least one release program is arranged together with the memory for storing at least one activation code in the protection device.
Thus, not only the identification number is included in the protection device according to the invention, but it is also included in this memory for the release programs for individual functions of the device to be protected.
This protection against unauthorized release of programs or program parts is possible without the activation code must be recalculated when replacing the protected device or system. Due to the arrangement of the program memory in the protection device, no such is required in the system to be protected. Different protection mechanisms for the individual programs or program parts can be selected as long as the corresponding algorithms fit into the program memory of the protection device according to the invention. These can then be switched on and off individually. Should the device to be protected become defective, a replacement system with the protective device according to the invention can continue to work at any time. The protective device according to the invention can already be preconfigured by the system manufacturer or software supplier for the wishes of the user.
According to another variant of the invention, it can be provided that a plurality of release programs and activation codes assigned to the release programs in the activation code memory are stored in the read-out-assured program memory, which release programs are separately retrievable.
This allows protection mechanisms for several programs or program parts in different forms to be selected independently of each other.
According to a further feature of the invention, the read-only program memory may be arranged together with a microprocessor in the protection device.
As a result, all communication or conversion and comparison processes can be easily processed centrally.
In a further embodiment of the invention it can be provided that at least part of the release programs can be activated via an input device separate from the device to be protected, with which the protective device can be connected.
If no input system for activating further release programs is present on the device to be protected, the activation codes of the protection device according to the invention can be correspondingly changed on this separate input device.
According to another variant of the invention can be provided that the protective device via a plug contact with the device to be protected device, system,. Like. Connected.
As a result, the authorization obtained by the protection device for operating a special program can also be used for other devices, installations, for example for a new generation installation, with such a plug connection.
In a further embodiment of the invention it can be provided that the power supply of the protective device takes place from the parallel interface.
As a result, the protective device can be operated without its own supply device.
Another object of the invention may be to provide a method for releasing a locked program or program part using a protection device according to the invention.
This can be achieved in that od in a first step of the device, the system, the system. like. a query is made for a program or program part for a protected function to the protection device, that in a second step one of the release programs stored in the program memory is determined, with which the query can be answered, that in a third step the associated activation code is read from the memory and decrypted, and the result obtained is compared with the identification number of the protection device, in a fourth step if the identification number and the decrypted activation code match, the determined approval program releases the blocked program or program part in the device, or if the identification number and the decrypted activation code do not match, the program or program part of the query remains blocked.
AT 405 466 Β
In this way, different programs or program parts can be freed independently of each other in the device to be protected from their lock, but there is no storage of data in the device to be protected, but there are all the protective measures concerned parts in the protection device.
In a further embodiment of the invention can be provided that in the fourth step in case of non-compliance of identification number and the decrypted activation code of the query corresponding program or program part with only limited functionality or limited in time and another program is released.
This prevents trying out of activation codes by unauthorized persons, since the other released program can first pretend that an activation code has been correctly decoded. Due to the resulting loss of time in the search for the correct activation code, the unwanted attempting an activation code under normal circumstances is made impossible.
According to another feature of the invention, it may be provided that in the fourth step, if the identification number and the decrypted activation code do not match, a signal release program is started which triggers a signaling.
As a result, an unauthorized or incorrect erroneous entering an activation code can be reported in an appropriate manner, such as by reporting the process via a modem or stored in a memory module with date and time.
Finally, it can be provided that in the third step, the associated activation code is read from the activation code memory and mathematically linked to the identification number, whereby a functional part of the release program, eg a calculation constant or a program code, is formed.
This eliminates the fourth step because the release program automatically returns false results if the activation code is incorrect.
The invention will be explained in detail with reference to the embodiments illustrated in the drawings. It shows:
A schematic representation of the organization of the program memory and the activation code memory of a protective device according to the invention and
2 shows a block diagram with an embodiment of a protective device according to the invention.
FIG. 2 shows a device 5 for protecting a telephone extension 4 against the use of certain functions that can be executed via programs or program sections. These functions have already been provided in the production in the telephone system but initially blocked on delivery to the operator. Thus, such a function may be that about incoming calls are connected to any currently free private branch exchanges. The assets offered for sale now contain all of this feature, but it will only be made available against an upfront payment. If the operator now wants such an additional function, he can obtain it, for example, by paying a license fee, whereupon the manufacturer of the system or an authorized dealer effects the release of the locked program or program part by storing a suitable activation code. It should be achieved that systems can be fully equipped with all additional functions, but it is only possible for a certain group of people to carry out the release of the same. This can be realized within the scope of the invention for all possible electronic devices, systems, systems which work with program parts or programs.
The activation codes can be entered by modern or by keyboard input in the system to be protected 4 and then passed to the protection device 5, which is connectable to the system 4 via an interface 3, preferably by means of a plug contact, not shown. Plug-in protection devices are commonly referred to in the jargon as dongles. About the protection device 5 certain program functions of Appendix 4 are releasable or lockable.
The protection device 5 comprises a non-erasable memory, eg an EEPROM, for storing activation codes, which activation codes are callable and comparable to a predeterminable identification number, which is stored in the protection device 5 in a read-only manner. Furthermore, a read-only program memory 7 is provided for the storage of release programs, a specific release program being executed when the decrypted activation code matches the identification number.
Under release programs all known processes such as program part or data decoding, external calculations, encrypted program parameters, statemachines, etc. individually combined and / or varied to understand.
AT 405 466 Β
According to the invention, it is now provided that the read-only program memory 7 is arranged together with the activation code memory 2 in the protective device 5.
As a result, no own memory must be provided in the system to be protected 4 and this should be defective, at any time a replacement system with the same protection device 5 continue working, which only needs to be plugged into this, without activation codes or release programs must be changed.
The program memory 7 is managed in the embodiment of Figure 1 by a microprocessor 1, which operates the exchange of information between the system to be protected 4 and the protection device 5 and performs further operations for the purpose of releasing or blocking certain ro functions of the system 4.
As can be seen from the schematic structure of the two memories 7 and 2 shown in FIG. 1, a plurality of enabling programs d, 1... N are located in the read-out program memory 7 and the activation codes e, 1 are assigned to the enabling programs memory 2. .n, wherein the individual release programs d, 1 ... n are separately retrievable.
The embodiment of a protection device according to the invention shown in FIG. 2 includes in the protection device 5 a microprocessor with a read-out-assured flash PROM program memory 7, in which the program parts a to d and the identification number f according to FIG. The activation codes e are stored in the EEPROM 2. The communication with the system to be protected via the parallel interface 3, but could be due to the built-in processor 1
Interface also be serial. The power supply of the protection device 5 takes place from the parallel interface.
The telephone system 4 to be protected is provided with a maintenance modem via which all release programs can be activated and deactivated by modem. Likewise, the protection device can be delivered preconfigured from the factory. The protective device 5 according to the invention has several protected programs or Program parts of the telephone system 4 via the corresponding release programs, which are of various types and independently activated or can be changed.
The activation, deactivation and modification takes place via the communication interface 3 of the protection device 5 according to the invention, the associated activation codes dependent on their identification number only being valid for exactly one release program in precisely this protection device. Therefore, an unprotected transmission of the activation code, such as the maintenance modem of the telephone system 4, allowed. The communication can be done to increase security but also encrypted.
The activation codes are best calculated by means of PC programs and can be entered in the existing data path, such as network, modem or the like, or manually via the terminal. The
The identification number and the number of the release program 1... N (FIG. 1) to be activated or modified can be incorporated by the protection device 5 into a code, from which the corresponding activation codes can be calculated. These activation codes can be interrogated by the protection device.
In Figure 2, the internal processes are to be taken in a query carried out by the system to be protected 4 query, with a locked program part is to be released.
1. In a first step, a query for a program or program part for a protected function to the protection device 5 is carried out from the system 4 by means of a communication routine a.
Second In a second step, a message evaluation routine b determines that of the release programs d (# 1... N) stored in the program memory 7 with which the query can be answered.
Third In a third step, the associated activation code e (# 1... # N) is read from the memory 2 and decrypted using a read / write routine c , and the result obtained is compared with the identification number f of the protection device. The identification number f is stored in the program memory 7.
4). In a fourth step, if the identification number f and the decrypted activation code e match, the locked program or program part is released in the system 4, or the program remains if the identification code f and the decrypted activation code e do not match or program part of the query locked.
The activation codes need not be encrypted, since each activation code only works on the protection device according to the invention for which it was generated, ie the activation code must match the desired protected function and the internal identification number of the protection device. To prevent a successful trial of the activation codes, should
AT 405 466 Β the code has at least 32 bits = 9 decimal places.
In order to further complicate the trial, it is recommended to accept all activation codes, but to easily execute the corresponding release programs with invalid activation codes, so that the program to be protected is not executed correctly.
A suitable variant of the fourth step may be that in case of non-compliance of the identification number and the decrypted activation code, the program or program part corresponding to the query is released with only limited functionality or for a limited time.
If, after entering an activation code, it would immediately be apparent from an answer of the protection device whether the code was correct, all possible activation codes could be tested fully automatically with appropriately programmed computers very quickly. For such a case, very long activation codes each having 64 bits or more would have to be used.
Furthermore, it can be provided that in the fourth step, if the identification number and the decrypted activation code are not matched, a special signal release routine is started, which triggers a signaling. This signaling may be that an attempt made with the wrong activation code is reported via an existing modem so that a central office is informed. Furthermore, it is possible to store such an input with date and time in a memory, from which these information can be read later.
The activation codes can also be supplied by modem or by keyboard input to the system to be protected and from there to the protective device according to the invention.
A further variant of the invention can be that in the third step, the associated activation code is read from the activation code memory and mathematically linked to the identification number, whereby a functional part of the release program, eg a calculation constant or a program code, is formed.
Then the fourth step is completely eliminated, because the release program automatically gives wrong results with the wrong activation code. This variant can therefore even be used to re-program the release programs, assuming longer activation codes.
To enter further activation codes in the protection device 5, the following procedure is selected:
1. ) A query is made about the number (1 ... n) of the release program to be released to the protection device.
Second ) The evaluation routine b generates a code from the identification number f and the number of the release program.
3) The code will be sent by modem, fax, telephone, network connection or similar. sent licensor.
4.) The licensor generates a response code by means of a program.
5) The response code is sent back to the protection device, which stores this as the activation code.
Points 2 and 3 may be omitted if the licensor knows the internal identification number of the protection device.
To delete an activation code, the same procedure is used as for entries. However, the message to the protection device contains a false code for the number of the activation code, with which no release of a function can be achieved.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP0457655A1 | Cites | European Patent Office (EPO) | Search report |
| EP0478969A2 | Cites | European Patent Office (EPO) | Search report |
| EP0537738A2 | Cites | European Patent Office (EPO) | Search report |
| EP0594493A1 | Cites | European Patent Office (EPO) | Search report |
| WO9406071A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
8 members in 7 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 169496 | Austria | A | |
| AT19960001694 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO9813741A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU4370597A | Australia | A | |
| EP0928444A1 | European Patent Office (EPO) | A1 | |
| AT405466BThis record | Austria | B | |
| JP2001501004A | Japan | A | |
| EP0928444B1 | European Patent Office (EPO) | B1 | |
| DE59711035D1 | Germany | D1 | |
| US6721889B1 | United States of America | B1 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| ExpiryMK07 | MK07 | |
| Change in the person of patent ownerEIH | EIH | |
| Publication of translation of european patent specificationUEP | UEP |
Numbers
- Publication, DOCDB
- 405466
- Publication, EPODOC
- AT405466B
- Application
- 169496
- Application, DOCDB
- 169496
- Application, EPODOC
- AT19960001694
Titles2
- German
- VORRICHTUNG ZUM SCHUTZ EINES ELEKTRONISCHEN GERÄTS
- English
- DEVICE FOR PROTECTION OF AN ELECTRONIC DEVICE
Classification
- CPC, 3
- G06F21/123
- G06F21/629
- G06F2221/2153
- IPC, 4
- G06F1 00
- G06F
- G06F12 14
- H04L9 00