Computer system for protecting software and a method for protecting software
76 claims: 42 independent, 34 dependent
- 1A computer system comprising an asymmetric cryptographic Protection mechanism for protecting software, the protection mechanism at least one challenge means (24) That a protected item of software (103) Is associated, and at least one response means with private keying material, to which it has access, including, in which a) the challenge means no access to the private key material has and stored in his public key material used b) the challenge means and the response means each a means for generating shared secret information according to a asymmetric confidentiality scheme include, c) the response means comprises means, which proves the challenge means that the response means access to the private key material has, by using an asymmetric confidentiality proof scheme a dialogue with the inquiry means performs, d) the challenge means comprises means, which prevents a Customer specific or use all of the software items without proof succeeds. Computersystem mit einem asymmetrischen kryptographischen Schutzmechanismus zum Schutz von Software, wobei der Schutzmechanismus mindestens ein Abfragemittel (24), das einem geschützten Softwareposten (103) zugeordnet ist, und mindestens ein Antwortmittel mit privatem Schlüsselmaterial, auf das es zugreifen kann, umfaßt, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet, b) das Abfragemittel und das Antwortmittel jeweils ein Mittel zum Erzeugen von Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema umfassen, c) das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, indem es unter Verwendung eines asymmetrischen Vertraulichkeitsbeweisschemas einen Dialog mit dem Abfragemittel führt, d) das Abfragemittel ein Mittel umfaßt, das verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
- 2Computer system according to claim 1 and with a means for inputting to be protected a Program and for embedding at least one polling agent in this Program, wherein said challenge means comprises means - The shared secret information according to a generates asymmetric confidentiality scheme, - the proof the response means that the Response means the shared secret information known, validated and prevented the existence Customer specific or use all of the software items without proof succeeds. Computersystem nach Anspruch 1 und mit einem Mittel zum Eingeben eines zu schützenden Programms und zum Einbetten mindestens eines Abfragemittels in dieses Programm, wobei das Abfragemittel ein Mittel umfaßt, das – die Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema erzeugt, – den Beweis des Antwortmittels, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt, validiert und verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
- 3A computer system according to claim 1 or 2, wherein the response means comprises means, which proves the query means, the response means the common discovered secret. Computersystem nach Anspruch 1 oder 2, bei dem das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
- 4Computer system according to one of claims 1 to 3, in which the challenge means comprises means which the proof of the response means that the response means the common discovered secret validated. Computersystem nach einem der Ansprüche 1 bis 3, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
- 5A computer system according to claim 4, wherein said query means includes a Means includes, the proof of the response means that the response means the common discovered secret validated by a demonstration, that this discovered response means the value of the shared secret, validated. Computersystem nach Anspruch 4, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
- 6Computer system according to one of claims 1 to 5, - in which the challenge means comprises means encrypts the information and then the encrypted Information about the response means transmits, - Wherein said response means comprises Means includes, the encrypted decrypted information and thus generates the shared secret information and then proves that the Response means knows the shared secret information. Computersystem nach einem der Ansprüche 1 bis 5, – wobei das Abfragemittel ein Mittel umfaßt, das Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet, – wobei das Antwortmittel ein Mittel umfaßt, das die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
- 8Computer system according to one of claims 1 to 5, - in which the challenge means comprises means, a random challenge outputs, and - in which the information includes the random challenge. Computersystem nach einem der Ansprüche 1 bis 5, – wobei das Abfragemittel ein Mittel umfaßt, das eine Zufallsabfrage ausgibt, und – wobei die Informationen die Zufallsabfrage umfassen.
- 9Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Erzeugen einer Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte enthält. The computer system of claim 8, wherein the means for outputting a random challenge includes means for generating a random challenge on hits including on devices by repeatedly Timea responses.
- 10Computersystem nach Anspruch 8, wobei das Mittel zum Erzeugen einer Zufallsabfrage ein Mittel zum Forken neuer Threads dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird, enthält. The computer system of claim 8, wherein the means for generating a random challenge includes means for forking new threads in such a way, that by exploiting of Unverhersehbarkeiten in the scheduler of the operating system additional degree of randomness inserted into the random challenge is containing.
- 11Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Durchführen einer statistischen Prüfung zur Bestimmung der durch jeden der Plattenzugriffe erhaltenen Anzahl von Zufallsbit und ein Mittel zum Bewirken einer Wiederholung von Plattenzugriffen, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde, enthält. The computer system of claim 8, wherein the means for outputting a random challenge includes means for performing a statistical test to determine the obtained through each of the disk accesses number of random bits and a means for effecting a repetition of disk accesses, up a predetermined number of random bits has been obtained, contains.
- 15Computersystem nach Anspruch 14, wobei das in der Schlüsseldatei gehaltene öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden. The computer system of claim 14, wherein the in the key file held public key material is cryptographically secured, making it computationally impractical is any part of the key file including the public key material, to change, without the challenge means to veränden.
- 16Computersystem nach, Anspruch 15, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Sof-twareposten geliefert wurde. The computer system of, claim 15 wherein said keyfile contains information the customer identify the supplied the proof Sof-twareposten has been.
- 17Computersystem nach Anspruch 16, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält. The computer system of claim 16, wherein said keyfile false bit to cloak the held therein first public Key material contains.
- 18Computersystem nach Anspruch 16, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält. The computer system of claim 16, wherein said keyfile information regarding the selective activation of services of the protected software item contains.
- 19Computer system according to one of claims 1 to 18 with a plurality of protected items of software, the each having its own challenge means, and a single, shared by all the protected items used response means. Computersystem nach einem der Ansprüche 1 bis 18 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
- 20Gebrauch eines Computersystems nach Anspruch 1 bei der Verteilung von Software an mehrere Kunden, wobei jeder Kunde über ein Computersystems nach Anspruch 1 verfügt und eine identische Kopie des geschützten Programms und des Abfragemittels erhält. Use of a computer system according to claim 1 in the distribution software to multiple customers, each customer has a Computer system according to claim 1 has an identical and Copy the protected Program and the query agent receives.
- 21A method for protecting a software item by an asymmetric cryptographic protection mechanism, wherein the protected item of software (103) At least one challenge means (24assigned) and at least one response means on private key material accesses, wherein a) the challenge means no access to the private key material has and stored in his public key material used b) the challenge means and the response means in each case according to a asymmetric confidentiality scheme shared secret information produce, c) the response means proves to the challenge means that the response means Access to the private key material Has, d) prevents the interrogation means that a customer specific or used all the items of software without the proof is successful. Verfahren zum Schutz eines Softwarepostens durch einen asymmetrischen kryptographischen Schutzmechanismus, wobei dem geschützten Softwareposten (103) mindestens ein Abfragemittel (24) zugeordnet ist und mindestens ein Antwortmittel auf privates Schlüsselmaterial zugreift, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet, b) das Abfragemittel und das Antwortmittel jeweils gemäß einem asymmetrischen Vertraulichkeitsschema Gemeinsames-Geheimnis-Informationen erzeugen, c) das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, d) das Abfragemittel verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
- 22The method of claim 21, wherein the response means the interrogation means proves that the response means has discovered the shared secret. Verfahren nach Anspruch 21, bei dem das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
- 23The method of claim 21 or 22, wherein the interrogation means the proof of the response means that the response means the common discovered secret validated. Verfahren nach Anspruch 21 oder 22, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
- 24The method of claim 23, wherein said challenge means proof the response means that the discovered response means the shared secret, validated, by a demonstration that the discovered response means the value of the shared secret, validated. Verfahren nach Anspruch 23, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
- 25A method according to any one of claims 21 to 24, - in which said challenge means encrypts information and then the encrypted Information about the response means transmits, wherein the response means encrypted decrypted information and thus generates the shared secret information and then proves that the Response means knows the shared secret information. Verfahren nach einem der Ansprüche 21 bis 24, – wobei das Abfragemittel Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet, wobei das Antwortmittel die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
- 27A method according to any one of claims 21 to 26, - in which the challenge means issues a random challenge and - in which the information includes the random challenge. Verfahren nach einem der Ansprüche 21 bis 26, – wobei das Abfragemittel eine Zufallsabfrage ausgibt und – wobei die Informationen die Zufallsabfrage umfassen.
- 28The method of claim 27 wherein the random challenge by repeatedly Timea generated by responses to access to devices. Verfahren nach Anspruch 27, wobei die Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte erzeugt wird.
- 29The method of claim 28 wherein the random challenge forks under new thread is created, such that by utilizing Unverhersehbarkeiten in the scheduler of the operating system, an additional degree of randomness inserted into the random challenge becomes. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Forken neuer Threads erzeugt wird, dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird.
- 30The method of claim 28 wherein the random challenge by performing statistical examination is generated to the number obtained by each of the disk accesses of random bits to determine, and a repetition of disk accesses is caused to receive a predetermined number of random bits has been. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Durchführung einer statistischen Prüfung erzeugt wird, um die durch jeden der Plattenzugriffe erhaltene Anzahl von Zufallsbit zu bestimmen, und eine Wiederholung von Plattenzugriffen bewirkt wird, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde.
- 34The method of claim 33, wherein the in the key file Held first public keying material is cryptographically secured, making it computationally impractical is any part of the key file including the first public keying material, to change, without the challenge means to veränden. Verfahren nach Anspruch 33, wobei das in der Schlüsseldatei gehaltene erste öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das erste öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden.
- 35A method according, to claim 34, wherein said keyfile includes information customers identify, to come to the protected item of software has been. Verfahren nach, Anspruch 34, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde.
- 36The method of claim 34, wherein said keyfile incorrect bit for camouflaging the first public held therein key material contains. Verfahren nach Anspruch 34, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält.
- 37The method of claim 34, wherein the information concerning the key file includes selective activation of services of the protected software item. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält.
- 38A method according to any one of claims 21 to 37 having a plurality of protected Software posts, each having its own challenge means, and a single, shared by all the protected items used response means. Verfahren nach einem der Ansprüche 21 bis 37 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
Independent claims38
103 paragraphs, as filed
General State of the art
The present invention relates to Mechanisms to protect software against unauthorized use and in particular unauthorized copying.
The Business Software Alliance estimates that the financial Losses which are due to the unauthorized copying of software, 1995 8.1 Billion US dollars for Business application software and 15.2 billion US dollars for be all software.
solutions have been proposed in two areas:
<ul><li>- improved legislature for the protection of intellectual property rights (IPR) and</li><li>- improved electronic copy protection (ECP mechanisms).</li></ul>
The IPR legislation and enforcement improved in many countries, but there are still significant difficulties in other Parts of the world. As a result of gradual certain distributors currently ECP new one.
Certain exemplary requirements, an ECP mechanism meet potential must be in the following list:
<ul><li>- It should be prevented from unauthorized clients protected run software.</li><li>- Of the Client should continue to be allowed to create backups.</li><li>- Of the ECP mechanism should have minimal impact on the user interface. The visual effect was on the first initial login to the operating system and / or limits the chip card.</li><li>- It should only standard hardware and software-assumptions will. Although hardware dongles provide copy protection services, many distributors want to For the sale of the software not in the group of customers restrict, possess a dongle or such ready to install are.</li><li>- Of the ECP mechanism should execution protected Software not on a limited group limit of machines. When a customer legitimately Software acquires, the customer should be able to, regardless Software ownership execute on any machine. Optionally, should the Customer to be able, at the same time run the software in multiple machines to authorize.</li><li>- Of the ECP mechanism should not required network dependencies have to execute an already purchased protected program.</li><li>- The Distributors should be allowed, to all customers an identical Version of protected to distribute software. This requirement may be the protected software through normal channels be distributed, such as by CD-ROMs, floppy disks or Network bulletin boards.</li><li>- It should for a potential illegal software copying be extremely difficult and / or computationally impractical, the ECP mechanism To work without the protected to modify program. This requirement serves as a virus protection measure, not validated as a supplied by the distributor digital signature would be if an illegitimate copier distributed a modified version of the original program.</li><li>- Of the ECP mechanism should the distributor, each of the distributor created program or any potential Trojan horse program not the private key material reveal. Although the major functionality therein is to protect the software distributor, it must not at the expense of the customer happened.</li><li>- Of the ECP mechanism should both in a software-only version as well as a hardware-assisted version, for example, a smart card to ensure a wide Market acceptance of used available be.</li></ul>
In [1], a mechanism is proposed, in which a protected Document only a specially configured viewer program can be considered, the a customer only allowed to look at the document when The customer provides the viewer the private key material of the customer. Thereby the customer is prevented from unauthorized copies the Viewer distribute, because this would have the Customer reveal other his own private key material. There This mechanism requires that the viewer program to the private key material accesses, but one of the above-described requirements is violated. In addition, this mechanism is not used in conjunction with a smart card are configured so that a release of private key material is avoided.
International Patent Application WO 88 05941 teaches a software control system to regulate the use of a software program in a digital host data processing system. The software regulation system comprises one or more of the Software program processed checkpoint routines and software-regulating device, the part of the computer system or may be connected to this externally. The checkpoint routines to generate a random checkpoint messages enciphered and are transmitted to the software-regulating device. The software adjustor deciphers the checkpoint message, performs a processing operation by in order to generate a response message, encrypts the response and sends the encrypted response to the checkpoint routine. The Checkpoint routine then determines whether the encrypted answer correctly is allowed and the software program <?page 3?>either to continue running or finished it.
An overview of the asymmetric cryptography For example, with respect to of the RSA algorithm, and probabilistic encryption, such For example, the probabilistic Blum-Goldwasser encryption scheme public key found in [2].
The chi-squared test, Kolmogorov-Smirnov test and the Serial Correlation Test are described in [3].
An overview of digital signature methods (Z. B. Rivest-Shamir-Adleman (RSA), etc.) can be found in [2].
In [4], the cryptographic randomness of Air turbulence described in disk drives.
An example of a message digest function (Which is also known as one-sided hash function) can be found in MD5 [5]. It is computationally impractical or very difficult, to calculate the inverse of a message digest.
The object of the present invention is to provide an improved ECP mechanism that Most of the example described above, requirements or even all fulfill can.
Summary the invention
The present invention uses an asymmetric confidentiality protocol. In an asymmetric Confidentiality protocol pits two participants A and B on. A owns private key material and B has no access to the private key material from A, without even the private key material to reveal. Initially, A and B, no shared secret. During the proceeding, A and B is a shared secret known. A B proves that A access to the private key material Has.
An asymmetric confidentiality proof is for example, the encryption public key. As shown in the following asymmetric confidentiality protocol, proves AB that A has access to the private key material. A ← B: h (r), B, P<sub>A</sub>(R, B) A → B: r
used the above described protocol scheme the following notation: - A → B means that A sends a message to B; and B → A means that a B sends message to A. - r means a random number that is used as a nonce - h (r) is a message digest of the nonce - P<sub>A</sub>(R, B) is encryption of the nonce and the identity of B using the public key material by A.
Here, B generates a nonce and encrypts the Nonce (together with the identity of B), using the public key material of A, ie, P<sub>A</sub>(R, B).
Additionally B computes the message digest of the nonce, h (r).
B sends the top described information together with a value that represents the identity of B to A.
Next, use A to be private key material to decrypt of P<sub>A</sub>(R, B) and is replaced by r, B. A computes the message digest of decrypted Random value r and compares the result with that obtained by B Mr).
At this point, the random number a both A and B known shared secret.
To terminate the protocol, are A random number of B back, to prove that A the secret knows. Once A delivers the revelation is confidentiality the random number, of course, lost. B validates the proof of A by the value returned by A Mystery is checked for equality with the generated originally from B.
A second example of an asymmetric confidentiality protocol is a probabilistic encryption scheme, such as the. probabilistic Blum-Goldwasser encryption methods with public Keys. This uses the encryption or decryption mechanism Random numbers or other probabilistic means.
For all asymmetric confidentiality protocols each customer can be public key material in a directory with public access ad without compromising the corresponding private keying material. The customer should usually his private key material Protect as a close secret; otherwise, the cryptographic system, the correctness (confidentiality) not guarantee. The best known mechanism for protecting a personal private key material is by the use of a chip card. In this case, the Smart card means no interface for releasing private key material (In a non-cryptographically protected form).
Although smart cards the best protection supply can social factors of electronic commerce a role in ensuring the protection of private key material play. One of the significant difficulties in asymmetric encryption services is authentication. For example, if A be public key material in a public Directory gives up, the question of how B will determine the validity rated? That is, a unlawful copying may try to impersonate A, but its own key material give up. Certain commercial organizations solve this Problem by acting as Zerfifizierungsbehörden (CA). For a (possible) fee mediated the CA identifying material from potential customers, such For a guide<?page 4?>bill or pass a Motorist. After validation. the identification material gives the CA the public key material in a public Directory and the CA signed a certificate (using a digital signature with the private key of the CA); which the public key material the customer holds. Standardized services, for example X.500, may be adapted, to the use of directories, the public key material included to facilitate.
After a customer his public key material applied to the CA, the customer is likely to be very effort, his private key material to protect. If the private key material the customer would be unknowingly compromised, then could in certain asymmetric keys The customer base for Strength . Concern. For example, might in the case of RSA keys that also for digital signatures can be used crosslinked distributor authorize potentially electronic trading transactions.
The invention is by the features the accompanying independent claims 1.20 and 21 defined. Further aspects of the invention are prepared by the features of the dependent claims 2 to 19 and 22 to 38 defined.
Short description tHE dRAWINGS
<figref>1</figref> is a flow chart a purchasing protocol used when a customer buying software would like, by a protective mechanism according to the invention protected is.
<figref idrefs="S32">2</figref> is a block diagram of the software components in the machine the client must be installed, so that the customer protected run software can.
<figref idrefs="S33">3</figref> is a flow chart the operation of the protection mechanism in the protected software.
<figref idrefs="S34">4</figref> is a flow chart the operation of a random number generator used to generate nonces.
description one embodiment the invention
It is now an inventive protection mechanism of an example with reference to the accompanying drawings described.
The purchase log
<figref>1</figref> shows a purchasing protocol used when a customer <figref>102</figref> software wants to buy, the by an ECP mechanism invention protected is. The distributor<figref>101</figref> has public and private keying material, that for digital signatures is used; and each potential customer<figref>102</figref> has public and private key material, that for asymmetric confidentiality proof protocols used. Each Participants will be public key material another participant, but keeps his private key material secret.
In step 1, the customer receives <figref>102</figref> the protected software <figref>103</figref> of the distributor <figref>101</figref>, by the software from a network bulletin board downloads.
A later detail to descriptive query mechanism <figref>24</figref> (please refer <figref idrefs="S32">2</figref>) Is dergestallt in the protected software <figref>103</figref> embedded such that a potential attacker not easy to query mechanism <figref>24</figref> of the protected program can separate. The attacker would have to disassemble code and remove the scanner mechanism manually. In the query mechanism <figref>24</figref> is the public key material the distributor embedded. As will be described, prevents the Abfragemechänismus <figref>24</figref>. that the Customer executes the software at this stage. The entire protected program, including the query mechanism is using the private key material the distributor signed.
In step 2, the customer sends <figref>102</figref> on Registration package <figref>104</figref> by e-mail to the distributor <figref>101</figref>, The Reg strationspaket <figref>104</figref> contains a reference to a public Directory that the public key material the customer holds.
In step 3 finds the software distributor <figref>101</figref> the public key material the Customer and embeds the public key material the customer in a key file <figref>105</figref> on and sends the key file <figref>105</figref> by E-mail to the customer <figref>102</figref>, After the customer<figref>102</figref> the key file <figref>105</figref> installed has the protection mechanism allows the customer <figref>102</figref>, the protected software <figref>103</figref> execute, as long as the customer can prove an asymmetric confidentiality proof that he access to the private key material the customer has.
The generation of the key file <figref>105</figref> is of a key file generator conducted in which it is a program that is run at the distributor. The distributor <figref>101</figref> must care exercise to protect this program.
In the. Using the key file generator an operator inputs the following information: Distributor Name: Distributor is the name of the company of the distributor. Vertreiberpaßwort: Vertreiberpaßwort is the password, the private key material the distributing company is unlocked. Company employees who do not the password know, can not generate key files. Customer Name: The customer name is the distinguished name of a customer (defined in [6]) for the key file to be generated. The name indi<?page 5?>ed in a database of public Key material. Key Filename: The key file name is the name of a new key file.
After receiving this information, builds the key file generator a key file <figref>105</figref> on, the public key material the customer has. Part of the key file <figref>105</figref> appear the customers <figref>102</figref> as a whole random Sequence of values.
The structure of the key file <figref>105</figref> comprising the Operations.
First produced key file generator adds a file and the public key material of customers with thousands of Tarnungsbit in the file. In the present example, each keyfile <figref>105</figref> approximately 480 000 Tarnungsbit. This number of bits provides a significant amount to Tarnungsmaterial represents, fits However, in a standard e-mail message.
Each key file <figref>105</figref> stores the public key material of the customer in a different memory location. In addition, in every key file<figref>105</figref> embedded encrypted customer information, without the required encryption key is revealed. This encrypted Customer information, a software distributor easily the owner of a key file <figref>105</figref> identify, If the key file <figref>105</figref> at a public Place, such as a bulletin board, appears. The key file (Or parts of the key file) <figref>105</figref> becomes then from the key file generator encrypted multiple times with different algorithms and re-encrypted. As last signed the key file generator the key file <figref>105</figref> among Using the private key material the distributor by applying a digital Signaturalgorhythmus.
A key file is to be valid called if the challenge means the signature of the distributor using the binary file Query agent stored public key material validate and public Deciphering stored in the key file key material can access.
The client software
<figref idrefs="S32">2</figref> shows the software components that, in the machine of the client, a computer must be installed so that the customer <figref>102</figref> the protected software <figref>103</figref> can perform. These consist of a protection server <figref>20</figref>, In addition, the key file <figref>105</figref> and protected software <figref>103</figref> shown. The copy-protected software<figref>103</figref> contains a query mechanism <figref>24</figref>,
Protecting Server <figref>20</figref> is a program that the customer <figref>102</figref> executes when the system initially booted becomes. The customer<figref>102</figref> the system is activated by inserting a floppy disk, the encrypted Copy of the private key material the customer has. Protecting Server <figref>20</figref> Calls to customers <figref>102</figref> then to enter a passphrase on which to decrypt the floppy disk is used. The protection software is not executed if the customer does not. the correct passphrase is entered. Of the protection Server <figref>20</figref> is then run in the background awaiting requests to perform the asymmetric confidentiality protocol.
It should be noted that the protection server <figref>20</figref> no way the private key material the customer from its process limit clears out. Protecting Server<figref>20</figref> used protection devices Operating system, to ensure its own integrity. Protecting Server<figref>20</figref> becomes in its own address space accomplished and communicates with external processes.
operation the protection mechanism
<figref idrefs="S33">3</figref> shows the functioning of Schutzmechanimus. This is carried out when tried the customer at the beginning, the protected software <figref>103</figref> perform, and is also periodically during execution protected software <figref>103</figref> repeated. By sending a new query and waiting for a response that can be validated.
(Box <figref>31</figref>) If the query mechanism <figref>24</figref> the Process starts, accesses the query mechanism <figref>24</figref> to the protected software <figref>103</figref> assigned key file <figref>105</figref> to and calls a signature validation function in the query mechanism <figref>24</figref> on, the distributor signature key file <figref>105</figref> among Using the public key material the distributor, which in the query mechanism <figref>24</figref> embedded is to validate. This validation of the key file signature ensures the existence Attacker the key file <figref>105</figref> or its digital signature can not be modified without the additional query mechanism <figref>24</figref> to modify. distributors may alternatively this protection by using additional proprietary lines of defense complete. If the key file <figref>105</figref> modified has been, lets the scanner mechanism <figref>24</figref> the hang program or interfere normal program execution otherwise.
Assuming that the signature of the key file <figref>105</figref> validated is analyzed the query mechanism <figref>24</figref> then the key file <figref>105</figref> among Using a proprietary distributor-specific algorithm to the public key of the material Customers in the key file <figref>105</figref> to find, and extracts the public key material of the customer.
The query and the response means lead the shown below asymmetric confidentiality protocol out. A • B: h®, B, P<sub>A</sub>(R, $) A • B: r
The expression uses the following Notati<?page 6?>on: - The Interrogation means (the scanner mechanism) <figref>24</figref> with the label B (listed also the identity . Of B, for example, "copy-protected program x") - The response means (Protection server) <figref>20</figref> designated by notation A ( the identity of A, z. B. "Protection Server, version 1<figref>"</figref>, - R means a random number that is used as a nonce - h (r) is a message digest the nonce - P<sub>A</sub>(R, B) is encryption of the nonce and the identity of B using the public key material by A.
(Box <figref>31</figref>) The inquiry means <figref>24</figref> of the protected software <figref>103</figref> produces a non erratbares nonce (a random number). Next calculates the Abfragemechn smus h (r) (the message digest of r).
The query mechanism <figref>24</figref> calls then an encryption function in the query mechanism <figref>24</figref> on to the nonce and the identity of B with the public key material to encrypt the customer. The query mechanism forwards the message digest of the nonce h (r) the identity of B and the result of the encryption with a request to participate in an asymmetric confidentiality proof to the Protection Server <figref>20</figref> continue.
(Box <figref>32</figref>) If the Protection Server <figref>20</figref> the receives request, decrypts he first encrypted Part of the message using the private keying material of the customer.
Next, validate the Protection Server h (r) in comparison to the decrypted Value.
Next, validate the Protection Server <figref>20</figref>That his identity B appears correctly in the message and the decrypted value.
If any validation fails, are the protection server <figref>20</figref> a failure back without the decrypted Nonce return. If the validation is successful, is the protection server <figref>20</figref> however Deciphering Nonce back.
(Box <figref>33</figref>) The query mechanism <figref>24</figref> compares decrypted the received Nonce with the nonce, the query mechanism <figref>24</figref> originally encrypted. If they do not match, lets the scanner mechanism <figref>24</figref> the protected hang program or interfere normal program execution otherwise.
It is thus seen that the protected program only continue to run normally is when the customer the proper private key material and the proper key file <figref>105</figref> features.
The nonce generator
The creation of a nonce is of one in the query mechanism <figref>24</figref> contained nonce generator performed. The operation of the nonce Genetators is as follows.
First ask the nonce generator a big Number of system parameters, eg. As the system time, the remaining Place in the page table, the number of logical drives, the names of the files in the directory of the operating system, etc.
builds Next, the nonce generator using a random number generator, a random number on. The Zufalhszahlengenerator consists of two process threads, referred to herein as Thread <figref>1</figref> and thread <figref>2</figref> designated will. <figref idrefs="S34">4</figref> show the Operation of thread <figref>1</figref>In which it is the main thread the random number generator is.
(Box <figref>51</figref>) thread <figref>1</figref> generated First, a data structure valuelist for holding a list of Counter values. The list is empty at the beginning.
(Box <figref>52</figref>) thread <figref>1</figref> puts a current counter value to zero and sets a done_test-flag to FALSE.
(Box <figref>53</figref>) thread <figref>1</figref> generated then thread <figref>2</figref>, thread<figref>2</figref> is an asynchronous Disk access and sleeping on then, to the disk access is complete. If the disk access is completed, sets thread <figref>2</figref> the flag on done_test TRUE. Note that Thread<figref>1</figref> and thread <figref>2</figref> be done, the flag<sub>-</sub>test divide.
(Box <figref>54</figref>) thread <figref>1</figref> increments the counter value by one.
(Box <figref>55</figref>) thread <figref>1</figref> then checks whether the done_test flag is now TRUE, indicating that the by thread <figref>2</figref> initiated disk access is complete. If that's done_test flag is FALSE, the thread returns to the Box <figref>54</figref> back. is therefore can be seen that, while on the conclusion of the disk access waits thread <figref>1</figref> the counter value increases continuously.
(Box <figref>56</figref>) When done_test flag is TRUE, terminated thread <figref>1</figref> the thread <figref>2</figref> and ensures the counter value in the first free memory location in value_list.
(Box <figref>57</figref>) thread <figref>1</figref> calls Then, a storage test function. in which the degree of randomness the counter values (Or portions of counter values, z. B. bit lower order) that were backed up in value_list, estimates. This function can the chi-squared test, the Kolmogorov-Smirnov test, or use the serial correlation test, which are described in [3]. The Statstest-function may optimize are to ensure that no complicated calculations for each disk access are repeated. are The Statstest function returns a value, which indicates how many bits of lower order of each secured counter value as accidental should be considered.
(Box <figref>58</figref>) thread <figref>1</figref> compares the value associated with the Statstest function with the combination of length of returned value_list is, with a predetermined threshold to determine whether now enough random bits have been generated. <?page 7?>If not enough Random bits have been generated, the process returns to the above box <figref>52</figref> back to so another counter value to generate and secure.
(Box <figref>59</figref>) If the required Number of random bits has been generated, Thread extracted <figref>1</figref> the specified Number of bits of lower order of each counter value in value_list and is this sequence of bits than the output random number.
Briefly, it can be seen that the random number generator the unpredictability of the timing of a number of disk accesses as the source of randomness exploited in the generation of nonces (see [4]). By generating new threads at each disk access also uses the random number generator unpredictability in the operation of the scheduler of the operating system as a second Source of randomness out.
The study conducted by the Statstest function analysis allows the random number generator, with for processors and disks tune any speed even by the number calculated from the lower order bits of each saved counter value to return becomes. For example, a system with a disk access time generate more random bits per disk access high variance as a system with a disk access time low variance. For example. generates the system in case of a disk of the type Quantum 1080s (average write time 6 ms) and a 486-processor with 66 About 45 Mhz Bits per second. Alternatively, the number of bits per disk access be encoded and used a de-skewing technique to a good degree of randomness ensure.
The nonce generator also queries the operating system from, to make sure that it each disk access issues on an actual disk. The final output nonce is formed by combining the output random number from the random number generator described the result of the query of system parameters as above formed using a message digest.
The above-described nonce generator works best when it is running on an operating system, providing the direct access to the disk, such as Windows 95 or Windows NT 4.0. In such an operating system allow special operating system calls that the user space exported are programs available, a program, the internal buffer mechanism of the operating system To work and to write directly to disk. use Most programs these special operating system calls not made, because they are relatively can be inefficient and difficult to use. Under Windows 95 and Windows NT can only use a program these special views, when the program accesses data that have a multiple of the sector size of the disk, by the operating system is queried.
If the operating system can not directly access provides on the plate, then could the query mechanism <figref>24</figref> always still use the disk timing random number generator. In this case, would the quality the generated values but more on unpredictability in the Scheduler leave the operating system, rather than on the disk access time inherent variance.
The above-described example of Invention assumes that the OS a utility that allows multiple threads in a single address space to create. additionally takes the example of the invention is that the operating system the threads allowed to Synchronisationsvar variables such as semaphores access. Most modern operating systems provide these Services. The example of the invention uses multiple threads to Implementation of a mechanism which quantifies each disk access time. However, if an implementation of the invention on a system accomplished would be, that does not provide multiple threads or synchronization variables, then could Insert the nonce generator other mechanisms, eg. as query a physical clock.
Some possible modifications
The customer does not have the software get download the software from a network bulletin board. The customer can get the software in a floppy disk, a CD-ROM, a DVD, a PC-department store, the Internet or other distribution media receive.
Alternatively, the protection server could <figref>20</figref> also a probabilistic encryption methods use, such as the probabilistic B1um-Goldwasser encryption scheme with public keys, to ensure that only the customer the proper private key material owns.
It can thus be seen that according to the present Invention is important only that a asymmetric confidentiality proof is used.
In addition, a smart card for storing the private key material the customer (or the private key material of the distributor, when engine key file generation is used) or be used to access it. At a such a configuration with smart card option, a copier unrechtmäßiger- the private key material not extract from the chip card, which even more defense opposite to is provided attacks. Certain chip cards only executed when the user a correct password or correct personal identification number indicates.
Optionally, this present EXAMPLE be extended by constructing the challenge means to the existence internal timer, z. B. a count<?page 8?>thread, or an external timer, eg. as a clock, is referenced. If a predefined threshold terminates before the probablistische is complete proof protocol, then the validation is automatically unsuccessful.
In addition to the implementation of the copy can be the invention for tracking illegal software copiers use. The mechanism provides excellent traceability, without is necessary that each Customer receives a unique version of the program.
Protecting Server <figref>20</figref>, of the query mechanism <figref>24</figref> and the protected software <figref>103</figref>. which have been described above, be used in a number of different configurations.
For example:
<ul><li>- Of the protection Server <figref>20</figref> can in an address space and the query mechanism <figref>24</figref> and the protected software <figref>103</figref> in another address space be anchored in a single machine.</li><li>- Protection Server <figref>20</figref> can in an address space on a Machine be anchored, and the query mechanism <figref>24</figref> and protected software <figref>103</figref> can in another address space be anchored on another machine.</li></ul>
In addition, several customers who each have their own copy of the protected Software product feature, be a common protection server <figref>20</figref> Share, the on Queries from all these copies replies.
Another alternative is to that multiple customers can share common private key material. A Company can use one or more of these applications, if designed as multi-user licensing functionality becomes.
In another possible Modification, the key file <figref>105</figref> hidden information regarding the selektieven activation of services of the protected program <figref>103</figref> receive. For example, the key file specify 105 that the protected program <figref>103</figref> the execution of a Print service allowed, but the execution of a Backup-to-disk service locks. As another example, the key file<figref>105</figref> on contain expiration date that describes the last date on which a certain service are running can. The protected program <figref>103</figref> would the key file <figref>105</figref> read, to determine the services that the protected program <figref>103</figref> to perform. A customer could the possibility get to run more services, by another key file is requested by the distributor.
In a further possible modification could the protected Program, the result of the asymmetric confidentiality proofs distribute to other programs. These other programs could this use found to help to determine whether the other Programs with execution stop intended or restricted way accomplished to be.
The following publications cited in this document: [1] Choudhury et al, Copyright Protection for Electronic Publishing over Computer Networks, IEEE Network, May / June 1995, pp 12-20 [2] A. Menezes, P. van Oorschot and S. Vanstone, Handbook of Applied Cryptography, CRC Press, Boca Raton, ISBN 0-8493-8523-7, pages 405-424, 1997. [3] D. Knuth, The Art of Computer Programming, Volume 2, Sminumerical Algorithms, Addison-Weslez Publishing Co., Reading MA, 2nd edition, Pages 38 -73, ISBN 0-201-03822-6. [4] P. Fenstermacher et at, Cryptographic randomness from air turbulence in disk drives, Advances in Cryptology: Crypto 94, pp 114-120. Springer Verlag 1994 [<figref>5]</figref> R. Rivest, The MD5 message-digest algorithm, RFC <figref>1321</figref>, April 1992 [6] ISO / IEC 9594-1, "Information technology - Open Systems Interconnection - The Directory: Overview of concepts, models, and services ", International Organiyation for Standardization, Geneva, Switzerland, 1995 (corresponding to ITU-T Rec. X.509, 1993).
3 sheets
Sheet 1 Sheet 2 Sheet 3
7 members in 4 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 97710012 | European Patent Office (EPO) | A | |
| 97710012 | European Patent Office (EPO) | A | |
| 97710012 | European Patent Office (EPO) | – | |
| 97710012 | – | – | – |
| EP19970710012 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| EP0881558A1 | European Patent Office (EPO) | A1 | |
| CN1206151A | China | A | |
| EP0881558B1 | European Patent Office (EPO) | B1 | |
| DE69720972D1 | Germany | D1 | |
| US6651169B1 | United States of America | B1 | |
| DE69720972T2This record | Germany | T2 | |
| CN1165848C | China | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 69720972
- Publication, DOCDB
- 69720972
- Publication, EPODOC
- DE69720972T
- Application
- 69720972
- Application, DOCDB
- 69720972
- Application, EPODOC
- DE1997620972T
Titles2
- German
- Computersystem und Verfahren zum Schutz von Software
- English
- Computer system and method for protection of software
Classification
- CPC, 5
- G06F21/10
- H04L9/3271
- H04L2209/56
- H04L2209/605
- H04L9/3218
- IPC, 3
- G06F1 00
- G06F21 10
- H04L9 32
