DE69720972T2

Computer system for protecting software and a method for protecting software

Abstract

This record has no abstract on file.

DE69720972T2, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 28 May 2017, 9.3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

76 claims: 42 independent, 34 dependent

  1. 1
    A computer system comprising an asymmetric cryptographic Protection mechanism for protecting software, the protection mechanism at least one challenge means (24) That a protected item of software (103) Is associated, and at least one response means with private keying material, to which it has access, including, in which a) the challenge means no access to the private key material has and stored in his public key material used b) the challenge means and the response means each a means for generating shared secret information according to a asymmetric confidentiality scheme include, c) the response means comprises means, which proves the challenge means that the response means access to the private key material has, by using an asymmetric confidentiality proof scheme a dialogue with the inquiry means performs, d) the challenge means comprises means, which prevents a Customer specific or use all of the software items without proof succeeds. Computersystem mit einem asymmetrischen kryptographischen Schutzmechanismus zum Schutz von Software, wobei der Schutzmechanismus mindestens ein Abfragemittel (24), das einem geschützten Softwareposten (103) zugeordnet ist, und mindestens ein Antwortmittel mit privatem Schlüsselmaterial, auf das es zugreifen kann, umfaßt, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet, b) das Abfragemittel und das Antwortmittel jeweils ein Mittel zum Erzeugen von Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema umfassen, c) das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, indem es unter Verwendung eines asymmetrischen Vertraulichkeitsbeweisschemas einen Dialog mit dem Abfragemittel führt, d) das Abfragemittel ein Mittel umfaßt, das verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
  2. 2
    Computer system according to claim 1 and with a means for inputting to be protected a Program and for embedding at least one polling agent in this Program, wherein said challenge means comprises means - The shared secret information according to a generates asymmetric confidentiality scheme, - the proof the response means that the Response means the shared secret information known, validated and prevented the existence Customer specific or use all of the software items without proof succeeds. Computersystem nach Anspruch 1 und mit einem Mittel zum Eingeben eines zu schützenden Programms und zum Einbetten mindestens eines Abfragemittels in dieses Programm, wobei das Abfragemittel ein Mittel umfaßt, das – die Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema erzeugt, – den Beweis des Antwortmittels, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt, validiert und verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
  3. 3
    A computer system according to claim 1 or 2, wherein the response means comprises means, which proves the query means, the response means the common discovered secret. Computersystem nach Anspruch 1 oder 2, bei dem das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
  4. 4
    Computer system according to one of claims 1 to 3, in which the challenge means comprises means which the proof of the response means that the response means the common discovered secret validated. Computersystem nach einem der Ansprüche 1 bis 3, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
  5. 5
    A computer system according to claim 4, wherein said query means includes a Means includes, the proof of the response means that the response means the common discovered secret validated by a demonstration, that this discovered response means the value of the shared secret, validated. Computersystem nach Anspruch 4, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
  6. 6
    Computer system according to one of claims 1 to 5, - in which the challenge means comprises means encrypts the information and then the encrypted Information about the response means transmits, - Wherein said response means comprises Means includes, the encrypted decrypted information and thus generates the shared secret information and then proves that the Response means knows the shared secret information. Computersystem nach einem der Ansprüche 1 bis 5, – wobei das Abfragemittel ein Mittel umfaßt, das Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet, – wobei das Antwortmittel ein Mittel umfaßt, das die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
  7. 7
    Computer system according to one of claims 1 to 5, wherein the asymmetric Confidentiality scheme is the Blum-Goldwasser scheme. Computersystem nach einem der Ansprüche 1 bis 5, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist.
  8. 8
    Computer system according to one of claims 1 to 5, - in which the challenge means comprises means, a random challenge outputs, and - in which the information includes the random challenge. Computersystem nach einem der Ansprüche 1 bis 5, – wobei das Abfragemittel ein Mittel umfaßt, das eine Zufallsabfrage ausgibt, und – wobei die Informationen die Zufallsabfrage umfassen.
  9. 9
    Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Erzeugen einer Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte enthält. The computer system of claim 8, wherein the means for outputting a random challenge includes means for generating a random challenge on hits including on devices by repeatedly Timea responses.
  10. 10
    Computersystem nach Anspruch 8, wobei das Mittel zum Erzeugen einer Zufallsabfrage ein Mittel zum Forken neuer Threads dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird, enthält. The computer system of claim 8, wherein the means for generating a random challenge includes means for forking new threads in such a way, that by exploiting of Unverhersehbarkeiten in the scheduler of the operating system additional degree of randomness inserted into the random challenge is containing.
  11. 11
    Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Durchführen einer statistischen Prüfung zur Bestimmung der durch jeden der Plattenzugriffe erhaltenen Anzahl von Zufallsbit und ein Mittel zum Bewirken einer Wiederholung von Plattenzugriffen, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde, enthält. The computer system of claim 8, wherein the means for outputting a random challenge includes means for performing a statistical test to determine the obtained through each of the disk accesses number of random bits and a means for effecting a repetition of disk accesses, up a predetermined number of random bits has been obtained, contains.
  12. 12
    Computer system according to one of claims 1 to 11 wherein said challenge means in the protected item of software is embedded. Computersystem nach einem der Ansprüche 1 bis 11, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist.
  13. 13
    Computer system according to one of claims 1 to 12 wherein said challenge means the public key material to encrypt the information used. Computersystem nach einem der Ansprüche 1 bis 12, wobei das Abfragemittel das öffentliche Schlüsselmaterial zum Verschlüsseln der Informationen verwendet.
  14. 14
    Computer system according to one of claims 1 to 13, wherein the system a key file (105) For holding the public key material contains. Computersystem nach einem der Ansprüche 1 bis 13, wobei das System eine Schlüsseldatei (105) zum Halten des öffentlichen Schlüsselmaterials enthält.
  15. 15
    Computersystem nach Anspruch 14, wobei das in der Schlüsseldatei gehaltene öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden. The computer system of claim 14, wherein the in the key file held public key material is cryptographically secured, making it computationally impractical is any part of the key file including the public key material, to change, without the challenge means to veränden.
  16. 16
    Computersystem nach, Anspruch 15, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Sof-twareposten geliefert wurde. The computer system of, claim 15 wherein said keyfile contains information the customer identify the supplied the proof Sof-twareposten has been.
  17. 17
    Computersystem nach Anspruch 16, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält. The computer system of claim 16, wherein said keyfile false bit to cloak the held therein first public Key material contains.
  18. 18
    Computersystem nach Anspruch 16, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält. The computer system of claim 16, wherein said keyfile information regarding the selective activation of services of the protected software item contains.
  19. 19
    Computer system according to one of claims 1 to 18 with a plurality of protected items of software, the each having its own challenge means, and a single, shared by all the protected items used response means. Computersystem nach einem der Ansprüche 1 bis 18 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
  20. 20
    Gebrauch eines Computersystems nach Anspruch 1 bei der Verteilung von Software an mehrere Kunden, wobei jeder Kunde über ein Computersystems nach Anspruch 1 verfügt und eine identische Kopie des geschützten Programms und des Abfragemittels erhält. Use of a computer system according to claim 1 in the distribution software to multiple customers, each customer has a Computer system according to claim 1 has an identical and Copy the protected Program and the query agent receives.
  21. 21
    A method for protecting a software item by an asymmetric cryptographic protection mechanism, wherein the protected item of software (103) At least one challenge means (24assigned) and at least one response means on private key material accesses, wherein a) the challenge means no access to the private key material has and stored in his public key material used b) the challenge means and the response means in each case according to a asymmetric confidentiality scheme shared secret information produce, c) the response means proves to the challenge means that the response means Access to the private key material Has, d) prevents the interrogation means that a customer specific or used all the items of software without the proof is successful. Verfahren zum Schutz eines Softwarepostens durch einen asymmetrischen kryptographischen Schutzmechanismus, wobei dem geschützten Softwareposten (103) mindestens ein Abfragemittel (24) zugeordnet ist und mindestens ein Antwortmittel auf privates Schlüsselmaterial zugreift, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet, b) das Abfragemittel und das Antwortmittel jeweils gemäß einem asymmetrischen Vertraulichkeitsschema Gemeinsames-Geheimnis-Informationen erzeugen, c) das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, d) das Abfragemittel verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
  22. 22
    The method of claim 21, wherein the response means the interrogation means proves that the response means has discovered the shared secret. Verfahren nach Anspruch 21, bei dem das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
  23. 23
    The method of claim 21 or 22, wherein the interrogation means the proof of the response means that the response means the common discovered secret validated. Verfahren nach Anspruch 21 oder 22, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
  24. 24
    The method of claim 23, wherein said challenge means proof the response means that the discovered response means the shared secret, validated, by a demonstration that the discovered response means the value of the shared secret, validated. Verfahren nach Anspruch 23, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
  25. 25
    A method according to any one of claims 21 to 24, - in which said challenge means encrypts information and then the encrypted Information about the response means transmits, wherein the response means encrypted decrypted information and thus generates the shared secret information and then proves that the Response means knows the shared secret information. Verfahren nach einem der Ansprüche 21 bis 24, – wobei das Abfragemittel Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet, wobei das Antwortmittel die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
  26. 26
    Method according to one of claims 21 to 25, wherein the asymmetric Confidentiality scheme is the Blum-Goldwasser scheme. Verfahren nach einem der Ansprüche 21 bis 25, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist.
  27. 27
    A method according to any one of claims 21 to 26, - in which the challenge means issues a random challenge and - in which the information includes the random challenge. Verfahren nach einem der Ansprüche 21 bis 26, – wobei das Abfragemittel eine Zufallsabfrage ausgibt und – wobei die Informationen die Zufallsabfrage umfassen.
  28. 28
    The method of claim 27 wherein the random challenge by repeatedly Timea generated by responses to access to devices. Verfahren nach Anspruch 27, wobei die Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte erzeugt wird.
  29. 29
    The method of claim 28 wherein the random challenge forks under new thread is created, such that by utilizing Unverhersehbarkeiten in the scheduler of the operating system, an additional degree of randomness inserted into the random challenge becomes. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Forken neuer Threads erzeugt wird, dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird.
  30. 30
    The method of claim 28 wherein the random challenge by performing statistical examination is generated to the number obtained by each of the disk accesses of random bits to determine, and a repetition of disk accesses is caused to receive a predetermined number of random bits has been. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Durchführung einer statistischen Prüfung erzeugt wird, um die durch jeden der Plattenzugriffe erhaltene Anzahl von Zufallsbit zu bestimmen, und eine Wiederholung von Plattenzugriffen bewirkt wird, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde.
  31. 31
    Method according to one of claims 21 to 30, wherein said challenge means in the protected Software item is embedded. Verfahren nach einem der Ansprüche 21 bis 30, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist.
  32. 32
    Method according to one of claims 21 to 31 wherein said challenge means the first public keying material encryption the information used. Verfahren nach einem der Ansprüche 21 bis 31, wobei das Abfragemittel das erste, öffentliche Schlüsselmaterial zur Verschlüsselung der Informationen verwendet.
  33. 33
    Method according to one of claims 21 to 32 wherein the first public key material in a key file is maintained. Verfahren nach einem der Ansprüche 21 bis 32, wobei das erste öffentliche Schlüsselmaterial in einer Schlüsseldatei gehalten wird.
  34. 34
    The method of claim 33, wherein the in the key file Held first public keying material is cryptographically secured, making it computationally impractical is any part of the key file including the first public keying material, to change, without the challenge means to veränden. Verfahren nach Anspruch 33, wobei das in der Schlüsseldatei gehaltene erste öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das erste öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden.
  35. 35
    A method according, to claim 34, wherein said keyfile includes information customers identify, to come to the protected item of software has been. Verfahren nach, Anspruch 34, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde.
  36. 36
    The method of claim 34, wherein said keyfile incorrect bit for camouflaging the first public held therein key material contains. Verfahren nach Anspruch 34, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält.
  37. 37
    The method of claim 34, wherein the information concerning the key file includes selective activation of services of the protected software item. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält.
  38. 38
    A method according to any one of claims 21 to 37 having a plurality of protected Software posts, each having its own challenge means, and a single, shared by all the protected items used response means. Verfahren nach einem der Ansprüche 21 bis 37 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
Independent claims38