EP0881558B1

Computer system for protecting software and a method for protecting software

Abstract

This record has no abstract on file.

EP0881558B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 28 May 2017, 9.3 years ago.

  1. Priority and filed
  2. Granted
  3. Expired
  4. Today

114 claims: 78 independent, 36 dependent

  1. 1
    A computer system comprising an asymmetric cryptographic protection mechanism for protecting software, the protection mechanism comprising at least one challenge means (24) associated with a protected item of software (103), and at least one response means with private keying material that it can access, wherein:a) the challenge means has no access to the private keying material and uses public kaying material stored in it,b) the challenge means and the response means comprise means for generating shared secret information, respectively, in accordance with an asymmetric confidentiality scheme,c) the response means comprises means for proving to the challenge means that the response means has access to the private keying material by interacting with the challenge means using an asymmetric confidentiality proof scheme,d) the challenge means comprises means for prohibiting a customer from using some or all of said items of software unless the proof is successful. Computersystem mit einem asymmetrischen kryptographischen Schutzmechanismus zum Schutz von Software, wobei der Schutzmechanismus mindestens ein Abfragemittel (24), das einem geschützten Softwareposten (103) zugeordnet ist, und mindestens ein Antwortmittel mit privatem Schlüsselmaterial, auf das es zugreifen kann, umfaßt, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet,b) das Abfragemittel und das Antwortmittel jeweils ein Mittel zum Erzeugen von Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema umfassen,c) das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, indem es unter Verwendung eines asymmetrischen Vertraulichkeitsbeweisschemas einen Dialog mit dem Abfragemittel führt,d) das Abfragemittel ein Mittel umfaßt, das verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist. Système d'ordinateur, comprenant un mécanisme de protection cryptographique asymétrique pour un logiciel de protection, le mécanisme de protection comprenant au moins un moyen de questionnement (24) associé à un élément de logiciel protégé (103), et au moins un moyen de réponse avec un matériel de codage privé auquel il peut accéder, dans lequel : a) le moyen de questionnement n'a pas accès au matériel de codage privé et utilise un matériel de codage public stocké dans celui-ci ;b) le moyen de questionnement et le moyen de réponse comprennent des moyens respectifs pour générer une information de secret partagé, selon un système de confidentialité asymétrique ;c) le moyen de réponse comprend un moyen pour prouver au moyen de questionnement que le moyen de réponse a accès au matériel de codage privé par interaction avec le moyen de questionnement à l'aide d'un système de preuve de confidentialité asymétrique ;d) le moyen de questionnement comprend un moyen pour interdire à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie.
  2. 2
    A computer system according to claim 1 and comprising means for inputting a program to be protected, and for embedding at least one challenge means in that program, wherein said challenge means comprises means for - generating shared secret information in accordance with an asymmetric confidentiality scheme,- validating the response means' proof that the response means knows the shared secret information and for prohibiting a customer from using some or all of said items of software unless the proof is successful. Computersystem nach Anspruch 1 und mit einem Mittel zum Eingeben eines zu schützenden Programms und zum Einbetten mindestens eines Abfragemittels in dieses Programm, wobei das Abfragemittel ein Mittel umfaßt, das - die Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema erzeugt,- den Beweis des Antwortmittels, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt, validiert und verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist. Système d'ordinateur selon la revendication 1, comprenant un moyen pour entrer un programme à protéger, et pour insérer au moins un moyen de questionnement dans ce programme, dans lequel ledit moyen de questionnement comprend des moyens pour - générer une information de secret partagé selon un système de confidentialité asymétrique ;- valider la preuve du moyen de réponse que le moyen de réponse connaît l'information de secret partagé et pour interdire à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie.
  3. 3
    A computer system according to claim 1 or 2 in which the response means comprises means for proving to the challenge means that the response means discovered the shared secret. Computersystem nach Anspruch 1 oder 2, bei dem das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, das Antwortmittel das gemeinsame Geheimnis entdeckt hat. Système d'ordinateur selon la revendication 1 ou 2, dans lequel le moyen de réponse comprend un moyen pour prouver au moyen de questionnement que le moyen de réponse a découvert le secret partagé.
  4. 4
    A computer system according to one of the claims 1 to 3 in which the challenge means comprises means for validating the response means' proof that the response means discovered the shared secret. Computersystem nach einem der Ansprüche 1 bis 3, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert. Système d'ordinateur selon l'une quelconque des revendications 1 à 3, dans lequel le moyen de questionnement comprend un moyen pour valider la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé.
  5. 5
    A computer system according to claim 4 in which the challenge means comprises means for validating the response means' proof that the response means discovered the shared secret by validating a demonstration that the response means discovered the value of the shared secret. Computersystem nach Anspruch 4, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert. Système d'ordinateur selon la revendication 4, dans lequel le moyen de questionnement comprend un moyen pour valider la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé en validant une démonstration que le moyen de réponse a découvert la valeur du secret partagé.
  6. 6
    A computer system according to one of the claims 1 to 5 - wherein said challenge means comprises means for encrypting information and then sending said encrypted information to said response means,- wherein said response means comprises means for decrypting said encrypted information and thus generating the shared secret information, and then proving that the response means knows the shared secret information. Computersystem nach einem der Ansprüche 1 bis 5, - wobei das Abfragemittel ein Mittel umfaßt, das Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet,- wobei das Antwortmittel ein Mittel umfaßt, das die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt. Système d'ordinateur selon l'une quelconque des revendications 1 à 5, - dans lequel ledit moyen de questionnement comprend un moyen pour crypter l'information et puis pour transmettre ladite information cryptée audit moyen de réponse,- dans lequel ledit moyen de réponse comprend un moyen pour décrypter ladite information cryptée et générer ainsi l'information de secret partagé, et puis donner la preuve que le moyen de réponse connaît l'information de secret partagé.
  7. 7
    A computer system according to one of the claims 1 to 5 wherein said asymmetric confidentiality scheme is the Blum-Goldwasser scheme. Computersystem nach einem der Ansprüche 1 bis 5, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist. Système d'ordinateur selon l'une quelconque des revendications 1 à 5, dans lequel ledit système de confidentialité asymétrique est le système Blum-Goldwasser.
  8. 8
    A computer system according to one of the claims 1 to 5 - wherein said challenge means comprises means for issuing a random challenge, and- wherein said information comprises said random challenge. Computersystem nach einem der Ansprüche 1 bis 5, - wobei das Abfragemittel ein Mittel umfaßt, das eine Zufallsabfrage ausgibt, und- wobei die Informationen die Zufallsabfrage umfassen. Système d'ordinateur selon l'une quelconque des revendications 1 à 5 - dans lequel ledit moyen de questionnement comprend un moyen pour délivrer une question aléatoire, et- dans lequel ladite information comprend ladite question aléatoire.
  9. 9
    A computer system according to claim 8 wherein said means for issuing a random challenge includes means for generating a random challenge by repeatedly timing responses to device accesses. Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Erzeugen einer Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour délivrer une question aléatoire comprend un moyen pour générer une question aléatoire en synchronisant de manière répétée des réponses aux accès de périphérique.
  10. 10
    A computer system according to claim 8 wherein said means for generating a random challenge includes means for forking new threads in such a manner as to introduce an additional degree of randomness into said random challenge by exploiting unpredictabilities in the operating system's scheduler. Computersystem nach Anspruch 8, wobei das Mittel zum Erzeugen einer Zufallsabfrage ein Mittel zum Forken neuer Threads dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird, enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour générer une question aléatoire comprend un moyen pour aiguiller de nouvelles unités d'exécution de manière à introduire un niveau supplémentaire de caractère aléatoire dans ladite question aléatoire en exploitant des imprévisibilités dans le programmateur du système d'exploitation.
  11. 11
    A computer system according to claim 8 wherein said means for generating a random challenge includes means for performing a statistical test to determine the number of random bits obtained by each of said disk accesses, and means for causing disk accesses to be repeated until a predetermined number of random bits has been obtained. Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Durchführen einer statistischen Prüfung zur Bestimmung der durch jeden der Plattenzugriffe erhaltenen Anzahl von Zufallsbit und ein Mittel zum Bewirken einer Wiederholung von Plattenzugriffen, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde, enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour générer une question aléatoire comprend un moyen pour exécuter un test statistique afin de déterminer le nombre de bits aléatoires obtenus par chacun desdits accès au disque, et un moyen pour faire répéter les accès au disque jusqu'à ce qu'un nombre prédéterminé de bits aléatoires soit obtenu.
  12. 12
    A computer system according to one of the claims 1 to 11 wherein said challenge means is embedded in said protected item of software. Computersystem nach einem der Ansprüche 1 bis 11, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist. Système d'ordinateur selon l'une quelconque des revendications 1 à 11, dans lequel ledit moyen de questionnement est intégré dans ledit élément de logiciel protégé.
  13. 13
    A computer system according to one of the claims 1 to 12 wherein said challenge means uses the public keying material for encrypting the information. Computersystem nach einem der Ansprüche 1 bis 12, wobei das Abfragemittel das öffentliche Schlüsselmaterial zum Verschlüsseln der Informationen verwendet. Système d'ordinateur selon l'une quelconque des revendications 1 à 12, dans lequel ledit moyen de questionnement utilise le matériel de codage public pour crypter les informations.
  14. 14
    A computer system according to one of the claims 1 to 13 wherein the system includes a keyfile (105) for holding the public keying material. Computersystem nach einem der Ansprüche 1 bis 13, wobei das System eine Schlüsseldatei (105) zum Halten des öffentlichen Schlüsselmaterials enthält. Système d'ordinateur selon l'une quelconque des revendications 1 à 13, dans lequel le système comprend un fichier de clés (105) pour contenir le matériel de codage public.
  15. 15
    A computer system according to claim 14 wherein the public keying material held in said keyfile is cryptographically secured, whereby it is computationally infeasible to alter any portion of the keyfile, including the public keying material, without altering the challenge means. Computersystem nach Anspruch 14, wobei das in der Schlüsseldatei gehaltene öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden. Système d'ordinateur selon la revendication 14, dans lequel le matériel de codage public contenu dans ledit fichier de clés est sécurisé de manière cryptographique, en conséquence de quoi il est impossible de modifier par calcul une partie quelconque du fichier de clés, comprenant le matériel de codage public, sans modifier le moyen de questionnement.
  16. 16
    A computer system according to claim 15 wherein said keyfile includes information identifying the customer to which the protected item of software has been supplied. Computersystem nach Anspruch 15, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde. Système d'ordinateur selon la revendication 15, dans lequel ledit fichier de clés comprend des informations identifiant le client auquel l'élément de logiciel protégé a été fourni.
  17. 17
    A computer system according to claim 16 wherein said keyfile includes decoy bits for disguising the first public keying material held therein. Computersystem nach Anspruch 16, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält. Système d'ordinateur selon la revendication 16, dans lequel ledit fichier de clés comprend des bits leurres pour cacher le premier matériel de codage public qu'il contient.
  18. 18
    A computer system according to claim 16 wherein said keyfile includes information concerning selective activation of services of the protected item of software. Computersystem nach Anspruch 16, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält. Système d'ordinateur selon la revendication 16, dans lequel ledit fichier de clés comprend des informations concernant une activation sélective de services de l'élément de logiciel protégé.
  19. 19
    A computer system according to one of the claims 1 to 18, including a plurality of protected items of software, each having its own challenge means, and a single response means, shared between all of said protected items. Computersystem nach einem der Ansprüche 1 bis 18 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel. Système d'ordinateur selon l'une quelconque des revendications 1 à 18, comprenant une pluralité d'éléments de logiciel protégés, chacun ayant son propre moyen de questionnement, et un moyen de réponse unique partagé entre l'ensemble desdits éléments protégés.
  20. 20
    Gebrauch eines Computersystems nach Anspruch 1 bei der Verteilung von Software an mehrere Kunden, wobei jeder Kunde über ein Computersystems nach Anspruch 1 verfügt und eine identische Kopie des geschützten Programms und des Abfragemittels erhält. Use of a computer system according to claim 1 in the distribution of software to a plurality of customers wherein each customer has a computer system according to claim 1, and wherein every customer receives an identical copy of said protected program and of said challenge means. Utilisation d'un système d'ordinateur selon la revendication 1 dans la distribution de logiciels à une pluralité de clients, dans lequel chaque client a un système d'ordinateur selon la revendication 1, et dans lequel chaque client reçoit une copie identique dudit élément de logiciel protégé et dudit moyen de questionnement.
  21. 21
    A method for protecting an item of software by an asymmetic cryptographic mechanism wherein at least one challenge means (24) is associated with said protected item of software (103), and at least one response means accesses private keying material, a) the challenge means has no access to the private keying material and uses public keying material stored in it,b) the challenge means and the response means generate shared secret information, respectively, in accordance with an asymmetric confidentiality scheme,c) the response means proves to the challenge means that the response means has access to the private keying material,d) the challenge means prohibits a customer from using some or all of said items of software unless the proof is successful. Méthode pour protéger un élément de logiciel par un mécanisme cryptographique asymétrique, dans lequel au moins un moyen de questionnement (24) est associé audit élément de logiciel protégé (103), et au moins un moyen de réponse accède au matériel de codage privé, a) le moyen de questionnement n'a pas accès au matériel de codage privé et utilise le matériel de codage public qu'il contient,b) le moyen de questionnement et le moyen de réponse génèrent respectivement des informations de secret partagé, selon un système de confidentialité asymétrique,c) le moyen de réponse prouve au moyen de questionnement que le moyen de réponse a accès au matériel de codage privé,d) le moyen de questionnement interdit à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie. Verfahren zum Schutz eines Softwarepostens durch einen asymmetrischen kryptographischen Schutzmechanismus, wobei dem geschützten Softwareposten (103) mindestens ein Abfragemittel (24) zugeordnet ist und mindestens ein Antwortmittel auf privates Schlüsselmaterial zugreift, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet,b) das Abfragemittel und das Antwortmittel jeweils gemäß einem asymmetrischen Vertraulichkeitsschema Gemeinsames-Geheimnis-Informationen erzeugen,c) das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat,d) das Abfragemittel verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
  22. 22
    A method according to claim 21 in which the response means proves to the challenge means that the response means discovered the shared secret. Méthode selon la revendication 21, dans laquelle le moyen de réponse prouve au moyen de questionnement que le moyen de réponse a découvert le secret partagé. Verfahren nach Anspruch 21, bei dem das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
  23. 23
    A method according to claim 21 or 22 in which the challenge means validates the response means' proof that the response means discovered the shared secret. Méthode selon la revendication 21 ou 22, dans laquelle le moyen de questionnement valide la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé. Verfahren nach Anspruch 21 oder 22, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
  24. 24
    A method according to claim 23 in which the challenge means validates the response means' proof that the response means discovered the shared secret by validating a demonstration that the response means discovered the value of the shared secret. Méthode selon la revendication 23, dans laquelle le moyen de questionnement valide la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé en validant une démonstration que le moyen de réponse a découvert la valeur du secret partagé. Verfahren nach Anspruch 23, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
  25. 25
    A method according to one of the claims 21 to 24 - wherein said challenge means encrypts information and then sends said encrypted information to said response means,- wherein said response means decrypts said encrypted information and thus generates the shared secret information, and then proving that the response means knows the shared secret information. Méthode selon l'une des revendications 21 à 24 - dans laquelle ledit moyen de questionnement crypte l'information et puis transmet ladite information cryptée audit moyen de réponse,- dans laquelle ledit moyen de réponse décrypte ladite information cryptée et génère ainsi l'information de secret partagé, et puis donne la preuve que le moyen de réponse connaît l'information de secret partagé. Verfahren nach einem der Ansprüche 21 bis 24, - wobei das Abfragemittel Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet,- wobei das Antwortmittel die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
  26. 26
    A method according to one of the claims 21 to 25 wherein said asymmetric confidentiality scheme is the Blum-Goldwasser scheme. Méthode selon l'une quelconque des revendications 21 à 25, dans laquelle ledit système de confidentialité asymétrique est le système Blum-Goldwasser. Verfahren nach einem der Ansprüche 21 bis 25, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist.
  27. 27
    A method according to one of the claims 21 to 26 - wherein said challenge means issues a random challenge, and- wherein said information comprises said random challenge. Méthode selon l'une quelconque des revendications 21 à 26, - dans laquelle ledit moyen de questionnement délivre une question aléatoire, et- dans laquelle ladite information comprend ladite question aléatoire. Verfahren nach einem der Ansprüche 21 bis 26, - wobei das Abfragemittel eine Zufallsabfrage ausgibt und- wobei die Informationen die Zufallsabfrage umfassen.
  28. 28
    A method according to claim 27 wherein the random challenge is generated by repeatedly timing responses to disk accesses. Méthode selon la revendication 27, dans laquelle la question aléatoire est générée en synchronisant des réponses aux accès au disque de manière répétée. Verfahren nach Anspruch 27, wobei die Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte erzeugt wird.
  29. 29
    A method according to claim 28 wherein the random challenge is generated in a way that new threads are forked in such a manner as to introduce an additional degree of randomness into said random challenge by exploiting unpredictabilities in the operating system's scheduler. Méthode selon la revendication 28, dans laquelle la question aléatoire est générée de telle sorte que les nouvelles unités d'exécution soient aiguillées de manière à introduire un niveau supplémentaire de caractère aléatoire dans ladite question aléatoire en exploitant des imprévisibilités dans le programmateur du système d'exploitation. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Forken neuer Threads erzeugt wird, dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird.
  30. 30
    A method according to claim 28 wherein the random challenge is generated in a way that a statistical test is performed to determine the number of random bits obtained by each of said disk accesses, and disk accesses are caused to be repeated until a predetermined number of random bits has been obtained. Méthode selon la revendication 28, dans laquelle la question aléatoire est générée de telle sorte qu'un test statistique soit exécuté afin de déterminer le nombre de bits aléatoires obtenus par chacun desdits accès au disque, et de faire répéter les accès au disque jusqu'à ce qu'un nombre prédéterminé de bits aléatoires soit obtenu. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Durchführung einer statistischen Prüfung erzeugt wird, um die durch jeden der Plattenzugriffe erhaltene Anzahl von Zufallsbit zu bestimmen, und eine Wiederholung von Plattenzugriffen bewirkt wird, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde.
  31. 31
    A method according to one of the claims 21 to 30 wherein said challenge means is embedded in said protected item of software. Méthode selon l'une quelconque des revendications 21 à 30, dans laquelle ledit moyen de questionnement est intégré dans ledit élément de logiciel protégé. Verfahren nach einem der Ansprüche 21 bis 30, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist.
  32. 32
    A method according to one of the claims 21 to 31 wherein said challenge means uses the first public keying material for encrypting the information. Méthode selon l'une quelconque des revendications 21 à 31, dans laquelle ledit moyen de questionnement utilise le premier matériel de codage public pour crypter les informations. Verfahren nach einem der Ansprüche 21 bis 31, wobei das Abfragemittel das erste öffentliche Schlüsselmaterial zur Verschlüsselung der Informationen verwendet.
  33. 33
    A method according to one of the claims 21 to 32 wherein the first public keying material is held in a keyfile. Méthode selon l'une quelconque des revendications 21 à 32, dans laquelle le premier matériel de codage public est contenu dans un fichier de clés. Verfahren nach einem der Ansprüche 21 bis 32, wobei das erste öffentliche Schlüsselmaterial in einer Schlüsseldatei gehalten wird.
  34. 34
    A method according to claim 33 wherein the first public keying material held in said keyfile is cryptographically secured, whereby it is computationally infeasible to alter any portion of the keyfile, including the first public keying material, without altering the challenge means. Méthode selon la revendication 33, dans laquelle le premier matériel de codage public contenu dans ledit fichier de clés est sécurisé de manière cryptographique, en conséquence de quoi il est impossible de modifier par calcul une partie quelconque du fichier de clés, comprenant le matériel de codage public, sans modifier le moyen de questionnement. Verfahren nach Anspruch 33, wobei das in der Schlüsseldatei gehaltene erste öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das erste öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden.
  35. 35
    A method according to claim 34 wherein said keyfile includes information identifying the customer to which the protected item of software has been supplied. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des informations identifiant le client auquel l'élément de logiciel protégé a été fourni. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde.
  36. 36
    A method according to claim 34 wherein said keyfile includes decoy bits for disguising the first public keying material held therein. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des bits leurres pour cacher le premier matériel de codage public qu'il contient. Verfahren nach Anspruch 34, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält.
  37. 37
    A method according to claim 34 wherein said keyfile includes information concerning selective activation of services of the protected item of software. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des informations concernant une activation sélective de services de l'élément de logiciel protégé. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält.
  38. 38
    A method according to one of the claims 21 to 37, including a plurality of protected items of software, each having its own challenge means, and a single response means, shared between all of said protected items. Méthode selon l'une quelconque des revendications 21 à 37, comprenant une pluralité d'éléments de logiciel protégés, chacun ayant son propre moyen de questionnement, et un moyen de réponse unique, partagé entre l'ensemble desdits éléments protégés. Verfahren nach einem der Ansprüche 21 bis 37 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
Independent claims38