Computer system for protecting software and a method for protecting software
114 claims: 78 independent, 36 dependent
- 1A computer system comprising an asymmetric cryptographic protection mechanism for protecting software, the protection mechanism comprising at least one challenge means (24) associated with a protected item of software (103), and at least one response means with private keying material that it can access, wherein:a) the challenge means has no access to the private keying material and uses public kaying material stored in it,b) the challenge means and the response means comprise means for generating shared secret information, respectively, in accordance with an asymmetric confidentiality scheme,c) the response means comprises means for proving to the challenge means that the response means has access to the private keying material by interacting with the challenge means using an asymmetric confidentiality proof scheme,d) the challenge means comprises means for prohibiting a customer from using some or all of said items of software unless the proof is successful. Computersystem mit einem asymmetrischen kryptographischen Schutzmechanismus zum Schutz von Software, wobei der Schutzmechanismus mindestens ein Abfragemittel (24), das einem geschützten Softwareposten (103) zugeordnet ist, und mindestens ein Antwortmittel mit privatem Schlüsselmaterial, auf das es zugreifen kann, umfaßt, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet,b) das Abfragemittel und das Antwortmittel jeweils ein Mittel zum Erzeugen von Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema umfassen,c) das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat, indem es unter Verwendung eines asymmetrischen Vertraulichkeitsbeweisschemas einen Dialog mit dem Abfragemittel führt,d) das Abfragemittel ein Mittel umfaßt, das verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist. Système d'ordinateur, comprenant un mécanisme de protection cryptographique asymétrique pour un logiciel de protection, le mécanisme de protection comprenant au moins un moyen de questionnement (24) associé à un élément de logiciel protégé (103), et au moins un moyen de réponse avec un matériel de codage privé auquel il peut accéder, dans lequel : a) le moyen de questionnement n'a pas accès au matériel de codage privé et utilise un matériel de codage public stocké dans celui-ci ;b) le moyen de questionnement et le moyen de réponse comprennent des moyens respectifs pour générer une information de secret partagé, selon un système de confidentialité asymétrique ;c) le moyen de réponse comprend un moyen pour prouver au moyen de questionnement que le moyen de réponse a accès au matériel de codage privé par interaction avec le moyen de questionnement à l'aide d'un système de preuve de confidentialité asymétrique ;d) le moyen de questionnement comprend un moyen pour interdire à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie.
- 2A computer system according to claim 1 and comprising means for inputting a program to be protected, and for embedding at least one challenge means in that program, wherein said challenge means comprises means for - generating shared secret information in accordance with an asymmetric confidentiality scheme,- validating the response means' proof that the response means knows the shared secret information and for prohibiting a customer from using some or all of said items of software unless the proof is successful. Computersystem nach Anspruch 1 und mit einem Mittel zum Eingeben eines zu schützenden Programms und zum Einbetten mindestens eines Abfragemittels in dieses Programm, wobei das Abfragemittel ein Mittel umfaßt, das - die Gemeinsames-Geheimnis-Informationen gemäß einem asymmetrischen Vertraulichkeitsschema erzeugt,- den Beweis des Antwortmittels, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt, validiert und verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist. Système d'ordinateur selon la revendication 1, comprenant un moyen pour entrer un programme à protéger, et pour insérer au moins un moyen de questionnement dans ce programme, dans lequel ledit moyen de questionnement comprend des moyens pour - générer une information de secret partagé selon un système de confidentialité asymétrique ;- valider la preuve du moyen de réponse que le moyen de réponse connaît l'information de secret partagé et pour interdire à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie.
- 3A computer system according to claim 1 or 2 in which the response means comprises means for proving to the challenge means that the response means discovered the shared secret. Computersystem nach Anspruch 1 oder 2, bei dem das Antwortmittel ein Mittel umfaßt, das dem Abfragemittel beweist, das Antwortmittel das gemeinsame Geheimnis entdeckt hat. Système d'ordinateur selon la revendication 1 ou 2, dans lequel le moyen de réponse comprend un moyen pour prouver au moyen de questionnement que le moyen de réponse a découvert le secret partagé.
- 4A computer system according to one of the claims 1 to 3 in which the challenge means comprises means for validating the response means' proof that the response means discovered the shared secret. Computersystem nach einem der Ansprüche 1 bis 3, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert. Système d'ordinateur selon l'une quelconque des revendications 1 à 3, dans lequel le moyen de questionnement comprend un moyen pour valider la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé.
- 5A computer system according to claim 4 in which the challenge means comprises means for validating the response means' proof that the response means discovered the shared secret by validating a demonstration that the response means discovered the value of the shared secret. Computersystem nach Anspruch 4, bei dem das Abfragemittel ein Mittel umfaßt, das den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert. Système d'ordinateur selon la revendication 4, dans lequel le moyen de questionnement comprend un moyen pour valider la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé en validant une démonstration que le moyen de réponse a découvert la valeur du secret partagé.
- 6A computer system according to one of the claims 1 to 5 - wherein said challenge means comprises means for encrypting information and then sending said encrypted information to said response means,- wherein said response means comprises means for decrypting said encrypted information and thus generating the shared secret information, and then proving that the response means knows the shared secret information. Computersystem nach einem der Ansprüche 1 bis 5, - wobei das Abfragemittel ein Mittel umfaßt, das Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet,- wobei das Antwortmittel ein Mittel umfaßt, das die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt. Système d'ordinateur selon l'une quelconque des revendications 1 à 5, - dans lequel ledit moyen de questionnement comprend un moyen pour crypter l'information et puis pour transmettre ladite information cryptée audit moyen de réponse,- dans lequel ledit moyen de réponse comprend un moyen pour décrypter ladite information cryptée et générer ainsi l'information de secret partagé, et puis donner la preuve que le moyen de réponse connaît l'information de secret partagé.
- 7A computer system according to one of the claims 1 to 5 wherein said asymmetric confidentiality scheme is the Blum-Goldwasser scheme. Computersystem nach einem der Ansprüche 1 bis 5, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist. Système d'ordinateur selon l'une quelconque des revendications 1 à 5, dans lequel ledit système de confidentialité asymétrique est le système Blum-Goldwasser.
- 8A computer system according to one of the claims 1 to 5 - wherein said challenge means comprises means for issuing a random challenge, and- wherein said information comprises said random challenge. Computersystem nach einem der Ansprüche 1 bis 5, - wobei das Abfragemittel ein Mittel umfaßt, das eine Zufallsabfrage ausgibt, und- wobei die Informationen die Zufallsabfrage umfassen. Système d'ordinateur selon l'une quelconque des revendications 1 à 5 - dans lequel ledit moyen de questionnement comprend un moyen pour délivrer une question aléatoire, et- dans lequel ladite information comprend ladite question aléatoire.
- 9A computer system according to claim 8 wherein said means for issuing a random challenge includes means for generating a random challenge by repeatedly timing responses to device accesses. Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Erzeugen einer Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour délivrer une question aléatoire comprend un moyen pour générer une question aléatoire en synchronisant de manière répétée des réponses aux accès de périphérique.
- 10A computer system according to claim 8 wherein said means for generating a random challenge includes means for forking new threads in such a manner as to introduce an additional degree of randomness into said random challenge by exploiting unpredictabilities in the operating system's scheduler. Computersystem nach Anspruch 8, wobei das Mittel zum Erzeugen einer Zufallsabfrage ein Mittel zum Forken neuer Threads dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird, enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour générer une question aléatoire comprend un moyen pour aiguiller de nouvelles unités d'exécution de manière à introduire un niveau supplémentaire de caractère aléatoire dans ladite question aléatoire en exploitant des imprévisibilités dans le programmateur du système d'exploitation.
- 11A computer system according to claim 8 wherein said means for generating a random challenge includes means for performing a statistical test to determine the number of random bits obtained by each of said disk accesses, and means for causing disk accesses to be repeated until a predetermined number of random bits has been obtained. Computersystem nach Anspruch 8, wobei das Mittel zum Ausgeben einer Zufallsabfrage ein Mittel zum Durchführen einer statistischen Prüfung zur Bestimmung der durch jeden der Plattenzugriffe erhaltenen Anzahl von Zufallsbit und ein Mittel zum Bewirken einer Wiederholung von Plattenzugriffen, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde, enthält. Système d'ordinateur selon la revendication 8, dans lequel ledit moyen pour générer une question aléatoire comprend un moyen pour exécuter un test statistique afin de déterminer le nombre de bits aléatoires obtenus par chacun desdits accès au disque, et un moyen pour faire répéter les accès au disque jusqu'à ce qu'un nombre prédéterminé de bits aléatoires soit obtenu.
- 12A computer system according to one of the claims 1 to 11 wherein said challenge means is embedded in said protected item of software. Computersystem nach einem der Ansprüche 1 bis 11, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist. Système d'ordinateur selon l'une quelconque des revendications 1 à 11, dans lequel ledit moyen de questionnement est intégré dans ledit élément de logiciel protégé.
- 13A computer system according to one of the claims 1 to 12 wherein said challenge means uses the public keying material for encrypting the information. Computersystem nach einem der Ansprüche 1 bis 12, wobei das Abfragemittel das öffentliche Schlüsselmaterial zum Verschlüsseln der Informationen verwendet. Système d'ordinateur selon l'une quelconque des revendications 1 à 12, dans lequel ledit moyen de questionnement utilise le matériel de codage public pour crypter les informations.
- 14A computer system according to one of the claims 1 to 13 wherein the system includes a keyfile (105) for holding the public keying material. Computersystem nach einem der Ansprüche 1 bis 13, wobei das System eine Schlüsseldatei (105) zum Halten des öffentlichen Schlüsselmaterials enthält. Système d'ordinateur selon l'une quelconque des revendications 1 à 13, dans lequel le système comprend un fichier de clés (105) pour contenir le matériel de codage public.
- 15A computer system according to claim 14 wherein the public keying material held in said keyfile is cryptographically secured, whereby it is computationally infeasible to alter any portion of the keyfile, including the public keying material, without altering the challenge means. Computersystem nach Anspruch 14, wobei das in der Schlüsseldatei gehaltene öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden. Système d'ordinateur selon la revendication 14, dans lequel le matériel de codage public contenu dans ledit fichier de clés est sécurisé de manière cryptographique, en conséquence de quoi il est impossible de modifier par calcul une partie quelconque du fichier de clés, comprenant le matériel de codage public, sans modifier le moyen de questionnement.
- 16A computer system according to claim 15 wherein said keyfile includes information identifying the customer to which the protected item of software has been supplied. Computersystem nach Anspruch 15, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde. Système d'ordinateur selon la revendication 15, dans lequel ledit fichier de clés comprend des informations identifiant le client auquel l'élément de logiciel protégé a été fourni.
- 17A computer system according to claim 16 wherein said keyfile includes decoy bits for disguising the first public keying material held therein. Computersystem nach Anspruch 16, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält. Système d'ordinateur selon la revendication 16, dans lequel ledit fichier de clés comprend des bits leurres pour cacher le premier matériel de codage public qu'il contient.
- 18A computer system according to claim 16 wherein said keyfile includes information concerning selective activation of services of the protected item of software. Computersystem nach Anspruch 16, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält. Système d'ordinateur selon la revendication 16, dans lequel ledit fichier de clés comprend des informations concernant une activation sélective de services de l'élément de logiciel protégé.
- 19A computer system according to one of the claims 1 to 18, including a plurality of protected items of software, each having its own challenge means, and a single response means, shared between all of said protected items. Computersystem nach einem der Ansprüche 1 bis 18 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel. Système d'ordinateur selon l'une quelconque des revendications 1 à 18, comprenant une pluralité d'éléments de logiciel protégés, chacun ayant son propre moyen de questionnement, et un moyen de réponse unique partagé entre l'ensemble desdits éléments protégés.
- 20Gebrauch eines Computersystems nach Anspruch 1 bei der Verteilung von Software an mehrere Kunden, wobei jeder Kunde über ein Computersystems nach Anspruch 1 verfügt und eine identische Kopie des geschützten Programms und des Abfragemittels erhält. Use of a computer system according to claim 1 in the distribution of software to a plurality of customers wherein each customer has a computer system according to claim 1, and wherein every customer receives an identical copy of said protected program and of said challenge means. Utilisation d'un système d'ordinateur selon la revendication 1 dans la distribution de logiciels à une pluralité de clients, dans lequel chaque client a un système d'ordinateur selon la revendication 1, et dans lequel chaque client reçoit une copie identique dudit élément de logiciel protégé et dudit moyen de questionnement.
- 21A method for protecting an item of software by an asymmetic cryptographic mechanism wherein at least one challenge means (24) is associated with said protected item of software (103), and at least one response means accesses private keying material, a) the challenge means has no access to the private keying material and uses public keying material stored in it,b) the challenge means and the response means generate shared secret information, respectively, in accordance with an asymmetric confidentiality scheme,c) the response means proves to the challenge means that the response means has access to the private keying material,d) the challenge means prohibits a customer from using some or all of said items of software unless the proof is successful. Méthode pour protéger un élément de logiciel par un mécanisme cryptographique asymétrique, dans lequel au moins un moyen de questionnement (24) est associé audit élément de logiciel protégé (103), et au moins un moyen de réponse accède au matériel de codage privé, a) le moyen de questionnement n'a pas accès au matériel de codage privé et utilise le matériel de codage public qu'il contient,b) le moyen de questionnement et le moyen de réponse génèrent respectivement des informations de secret partagé, selon un système de confidentialité asymétrique,c) le moyen de réponse prouve au moyen de questionnement que le moyen de réponse a accès au matériel de codage privé,d) le moyen de questionnement interdit à un client d'utiliser une partie ou la totalité desdits éléments de logiciel à moins que la preuve ne soit réussie. Verfahren zum Schutz eines Softwarepostens durch einen asymmetrischen kryptographischen Schutzmechanismus, wobei dem geschützten Softwareposten (103) mindestens ein Abfragemittel (24) zugeordnet ist und mindestens ein Antwortmittel auf privates Schlüsselmaterial zugreift, wobei a) das Abfragemittel keinen Zugang zu dem privaten Schlüsselmaterial hat und in ihm gespeichertes öffentliches Schlüsselmaterial verwendet,b) das Abfragemittel und das Antwortmittel jeweils gemäß einem asymmetrischen Vertraulichkeitsschema Gemeinsames-Geheimnis-Informationen erzeugen,c) das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel Zugang zu dem privaten Schlüsselmaterial hat,d) das Abfragemittel verhindert, daß ein Kunde bestimmte oder alle der Softwareposten benutzt, ohne daß der Beweis erfolgreich ist.
- 22A method according to claim 21 in which the response means proves to the challenge means that the response means discovered the shared secret. Méthode selon la revendication 21, dans laquelle le moyen de réponse prouve au moyen de questionnement que le moyen de réponse a découvert le secret partagé. Verfahren nach Anspruch 21, bei dem das Antwortmittel dem Abfragemittel beweist, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat.
- 23A method according to claim 21 or 22 in which the challenge means validates the response means' proof that the response means discovered the shared secret. Méthode selon la revendication 21 ou 22, dans laquelle le moyen de questionnement valide la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé. Verfahren nach Anspruch 21 oder 22, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert.
- 24A method according to claim 23 in which the challenge means validates the response means' proof that the response means discovered the shared secret by validating a demonstration that the response means discovered the value of the shared secret. Méthode selon la revendication 23, dans laquelle le moyen de questionnement valide la preuve du moyen de réponse que le moyen de réponse a découvert le secret partagé en validant une démonstration que le moyen de réponse a découvert la valeur du secret partagé. Verfahren nach Anspruch 23, bei dem das Abfragemittel den Beweis des Antwortmittels, daß das Antwortmittel das gemeinsame Geheimnis entdeckt hat, validiert, indem es eine Demonstration, daß das Antwortmittel den Wert des gemeinsamen Geheimnisses entdeckt hat, validiert.
- 25A method according to one of the claims 21 to 24 - wherein said challenge means encrypts information and then sends said encrypted information to said response means,- wherein said response means decrypts said encrypted information and thus generates the shared secret information, and then proving that the response means knows the shared secret information. Méthode selon l'une des revendications 21 à 24 - dans laquelle ledit moyen de questionnement crypte l'information et puis transmet ladite information cryptée audit moyen de réponse,- dans laquelle ledit moyen de réponse décrypte ladite information cryptée et génère ainsi l'information de secret partagé, et puis donne la preuve que le moyen de réponse connaît l'information de secret partagé. Verfahren nach einem der Ansprüche 21 bis 24, - wobei das Abfragemittel Informationen verschlüsselt und dann die verschlüsselten Informationen zu dem Antwortmittel sendet,- wobei das Antwortmittel die verschlüsselten Informationen entschlüsselt und somit die Gemeinsames-Geheimnis-Informationen erzeugt und dann beweist, daß das Antwortmittel die Gemeinsames-Geheimnis-Informationen kennt.
- 26A method according to one of the claims 21 to 25 wherein said asymmetric confidentiality scheme is the Blum-Goldwasser scheme. Méthode selon l'une quelconque des revendications 21 à 25, dans laquelle ledit système de confidentialité asymétrique est le système Blum-Goldwasser. Verfahren nach einem der Ansprüche 21 bis 25, wobei das asymmetrische Vertraulichkeitsschema das Blum-Goldwasser-Schema ist.
- 27A method according to one of the claims 21 to 26 - wherein said challenge means issues a random challenge, and- wherein said information comprises said random challenge. Méthode selon l'une quelconque des revendications 21 à 26, - dans laquelle ledit moyen de questionnement délivre une question aléatoire, et- dans laquelle ladite information comprend ladite question aléatoire. Verfahren nach einem der Ansprüche 21 bis 26, - wobei das Abfragemittel eine Zufallsabfrage ausgibt und- wobei die Informationen die Zufallsabfrage umfassen.
- 28A method according to claim 27 wherein the random challenge is generated by repeatedly timing responses to disk accesses. Méthode selon la revendication 27, dans laquelle la question aléatoire est générée en synchronisant des réponses aux accès au disque de manière répétée. Verfahren nach Anspruch 27, wobei die Zufallsabfrage durch wiederholtes Timen von Antworten auf Zugriffe auf Geräte erzeugt wird.
- 29A method according to claim 28 wherein the random challenge is generated in a way that new threads are forked in such a manner as to introduce an additional degree of randomness into said random challenge by exploiting unpredictabilities in the operating system's scheduler. Méthode selon la revendication 28, dans laquelle la question aléatoire est générée de telle sorte que les nouvelles unités d'exécution soient aiguillées de manière à introduire un niveau supplémentaire de caractère aléatoire dans ladite question aléatoire en exploitant des imprévisibilités dans le programmateur du système d'exploitation. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Forken neuer Threads erzeugt wird, dergestalt, daß durch Ausnutzen von Unverhersehbarkeiten in dem Scheduler des Betriebssystems ein zusätzlicher Zufälligkeitsgrad in die Zufallsabfrage eingeführt wird.
- 30A method according to claim 28 wherein the random challenge is generated in a way that a statistical test is performed to determine the number of random bits obtained by each of said disk accesses, and disk accesses are caused to be repeated until a predetermined number of random bits has been obtained. Méthode selon la revendication 28, dans laquelle la question aléatoire est générée de telle sorte qu'un test statistique soit exécuté afin de déterminer le nombre de bits aléatoires obtenus par chacun desdits accès au disque, et de faire répéter les accès au disque jusqu'à ce qu'un nombre prédéterminé de bits aléatoires soit obtenu. Verfahren nach Anspruch 28, wobei die Zufallsabfrage unter Durchführung einer statistischen Prüfung erzeugt wird, um die durch jeden der Plattenzugriffe erhaltene Anzahl von Zufallsbit zu bestimmen, und eine Wiederholung von Plattenzugriffen bewirkt wird, bis eine vorbestimmte Anzahl von Zufallsbit erhalten wurde.
- 31A method according to one of the claims 21 to 30 wherein said challenge means is embedded in said protected item of software. Méthode selon l'une quelconque des revendications 21 à 30, dans laquelle ledit moyen de questionnement est intégré dans ledit élément de logiciel protégé. Verfahren nach einem der Ansprüche 21 bis 30, wobei das Abfragemittel in den geschützten Softwareposten eingebettet ist.
- 32A method according to one of the claims 21 to 31 wherein said challenge means uses the first public keying material for encrypting the information. Méthode selon l'une quelconque des revendications 21 à 31, dans laquelle ledit moyen de questionnement utilise le premier matériel de codage public pour crypter les informations. Verfahren nach einem der Ansprüche 21 bis 31, wobei das Abfragemittel das erste öffentliche Schlüsselmaterial zur Verschlüsselung der Informationen verwendet.
- 33A method according to one of the claims 21 to 32 wherein the first public keying material is held in a keyfile. Méthode selon l'une quelconque des revendications 21 à 32, dans laquelle le premier matériel de codage public est contenu dans un fichier de clés. Verfahren nach einem der Ansprüche 21 bis 32, wobei das erste öffentliche Schlüsselmaterial in einer Schlüsseldatei gehalten wird.
- 34A method according to claim 33 wherein the first public keying material held in said keyfile is cryptographically secured, whereby it is computationally infeasible to alter any portion of the keyfile, including the first public keying material, without altering the challenge means. Méthode selon la revendication 33, dans laquelle le premier matériel de codage public contenu dans ledit fichier de clés est sécurisé de manière cryptographique, en conséquence de quoi il est impossible de modifier par calcul une partie quelconque du fichier de clés, comprenant le matériel de codage public, sans modifier le moyen de questionnement. Verfahren nach Anspruch 33, wobei das in der Schlüsseldatei gehaltene erste öffentliche Schlüsselmaterial kryptographisch gesichert ist, wodurch es rechnerisch impraktikabel wird, irgendeinen Teil der Schlüsseldatei, darunter das erste öffentliche Schlüsselmaterial, zu verändern, ohne das Abfragemittel zu veränden.
- 35A method according to claim 34 wherein said keyfile includes information identifying the customer to which the protected item of software has been supplied. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des informations identifiant le client auquel l'élément de logiciel protégé a été fourni. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen enthält, die den Kunden identifizieren, an den der geschützte Softwareposten geliefert wurde.
- 36A method according to claim 34 wherein said keyfile includes decoy bits for disguising the first public keying material held therein. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des bits leurres pour cacher le premier matériel de codage public qu'il contient. Verfahren nach Anspruch 34, wobei die Schlüsseldatei falsche Bit zum Tarnen des darin gehaltenen ersten öffentlichen Schlüsselmaterials enthält.
- 37A method according to claim 34 wherein said keyfile includes information concerning selective activation of services of the protected item of software. Méthode selon la revendication 34, dans laquelle ledit fichier de clés comprend des informations concernant une activation sélective de services de l'élément de logiciel protégé. Verfahren nach Anspruch 34, wobei die Schlüsseldatei Informationen bezüglich der selektiven Aktivierung von Diensten des geschützten Softwarepostens enthält.
- 38A method according to one of the claims 21 to 37, including a plurality of protected items of software, each having its own challenge means, and a single response means, shared between all of said protected items. Méthode selon l'une quelconque des revendications 21 à 37, comprenant une pluralité d'éléments de logiciel protégés, chacun ayant son propre moyen de questionnement, et un moyen de réponse unique, partagé entre l'ensemble desdits éléments protégés. Verfahren nach einem der Ansprüche 21 bis 37 mit mehreren geschützten Softwareposten, die jeweils ihr eigenes Abfragemittel aufweisen, und einem einzigen, gemeinsam von allen geschützten Posten benutzten Antwortmittel.
Independent claims38
97 paragraphs, as filed
Background to the Invention
This invention relates to mechanisms for protecting software against unauthorized use, in particular against unauthorized copying.
The Business Software Alliance estimates the 1995 financial losses attributed to software piracy as US$ 8.1 Billion for business application software and US$ 15.2 Billion for all software.
Solutions have been proposed in two areas: <ul id="ul0001" list-style="dash" compact="compact"><li>improved Intellectual Property Rights (IPR) legislation, and</li><li>enhanced electronic copy protection (ECP) mechanisms.</li></ul>
IPR legislation and enforcement are improving in many countries, but there are still significant difficulties in other parts of the world. As a result, some vendors are currently reassessing ECP.
Some example requirements that an ECP mechanism may potentially satisfy are listed below: <ul id="ul0002" list-style="dash"><li>Unauthorized customers should be prohibited from executing protected software.</li><li>The customer should not be prohibited from making backups.</li><li>The ECP mechanism should have minimal impact upon the user interface. The visible impact should be limited to the first initial login to the operating system and/or smart card.</li><li>Only standard hardware and software assumptions should be made. For example, although hardware dongles provide copy protection services, many vendors do not wish to limit the sale of the software to the collection of customers who own or are willing to install a dongle.</li><li>The ECP mechanism should not limit execution of the protected software to a limited collection of machines. When a customer legitimately purchases software, the customer should be able to execute the software on any machine regardless of ownership. The customer should optionally be able to authorize simultaneous execution of the software in multiple machines.</li><li>The ECP mechanism should have no required network dependencies in order to execute an already purchased protected program.</li><li>The vendor should be permitted to distribute an identical version of the protected software to all customers. This requirement permits the protected software to be distributed through normal channels such as, for example, CD-ROMs, floppy disks, or network bulletin boards.</li><li>It should be excessively difficult and/or computationally infeasible for a potential software pirate to circumvent the ECP mechanism without modifying the protected program. This requirement serves as a virus-protection measure because a digital signature supplied by the vendor would not validate if a pirate distributes a modified version of the original program.</li><li>The ECP mechanism should not disclose the private keying material to the vendor, any program produced by the vendor, or any potential Trojan horse program. Though the primary functionality is to protect the software vendor, one must not do so at the expense of the customer.</li><li>The ECP mechanism should be available in a software-only version as well as in a hardware-assisted version, using smart card, for example, to assure widespread market acceptance.</li></ul>
In [1], a mechanism is proposed in which a protected document can be viewed only via a specially configured viewer program, which allows a customer to view the document only if the customer supplies to the viewer the customer's private keying material. This deters the customer from distributing unauthorized copies of the viewer program, since that would require the customer to divulge his or her private keying material to others. However, because this mechanism requires that the viewer program obtain access to the private keying material, it breaks one of the requirements described above. Furthermore, this mechanism may not be used in conjunction with a smart card that is configured to avoid releasing private keying material.
International Patent Application WO 88 05941 teaches a software regulation system for regulating the use of a software program in a host digital data processing system. The software regulation system includes one or more checkpoint routines processed by the software program and a software regulation device, which may be part of the computer system or connected externally thereto. The checkpoint routines generate random checkpoint messages, which are enciphered and transmitted to the software regulation device. The software regulation device deciphers the checkpoint message, performs a processing operation to generate a response message, enciphers the response and sends the enciphered response to the checkpoint routine. The checkpoint routine then determines whether the enciphered response is correct and either allows the software program to proceed or terminates it.
An overview on asymmetric cryptography, for example on the RSA scheme, and probabilistic encryption, for example the Blum-Goldwasser probabilistic public-key encryption scheme can be found in [2].
The Chi-Square Test, the Kolmogorov-Smirnov Test, and the Serial Correlation Test are described in [3].
An overview of digital signature schemes (e.g. Rivest-Shamir-Adleman (RSA), etc.,) can be found in [2].
In [4], cryptographic randomness from air turbulence in disk drives is described.
An example of a message digest function (otherwise known as a one-way hash function) is MD5 [5]. It is computationally infeasible or very difficult to compute the inverse of a message digest.
The object of the present invention is to provide an improved ECP mechanism that is able to satisfy most, if not all of the example requirements described above.
Summary of the Invention
The present invention makes use of an asymmetric confidentiality protocol. An asymmetric confidentiality protocol involves two parties, A and B. A possesses private keying material and B has no access to A's private keying material without disclosing the private keying material itself. At the beginning, A and B have no shared secret. During the method, a shared secret becomes known to A and B. A proves to B that A has access to the private keying material.
An example of an asymmetric confidentiality proof is public key encryption. As illustrated in the asymmetric confidentiality protocol below. A proves to B that A has access to the private keying material. <ul id="ul0003" list-style="none" compact="compact"><li>A ← B: h(r), B, P<sub>A</sub>(r, B)</li><li>A → B: r</li></ul>
The protocol scheme described above uses the following notation: <ul id="ul0004" list-style="bullet" compact="compact"><li>A → B denotes that A sends a message to B; and B <b>→</b> A denotes that B sends a message to A.</li><li>r denotes a random number used as a nonce</li><li>h(r) is a message digest of the nonce</li><li>P<sub>A</sub>(r,B) is encryption of the nonce and B's identity using A's public keying material</li></ul>
Here, B generates a nonce and encrypts the nonce (together with B's identity) using A's public keying material, i.e., P<sub>A</sub>(r,B).
Additionally B computes the message digest of the nonce, h(r).
B sends the information described above, along with a value representing B's identity, to A.
Next, A uses its private keying material to decrypt P<sub>A</sub>(r,B) obtaining r,B. A computes the message digest of the decrypted random value, r, and compares the result against h(r)obtained from B.
At this point, the random number is a shared secret known by both A and B.
In order to complete the protocol, A returns the random number to B in order to demonstrate that A knows the secret. Of course, once A provides the disclosure, the secrecy of the random number is lost. B validates A's proof by checking for equality A's returned secret against the one that B originally generated.
A second example of an asymmetric confidentiality protocol is a probabilistic encryption scheme, e.g. the Blum-Goldwasser probabilistic public key encryption scheme. Here, the encryption or decryption mechanism uses random numbers or other probabilistic means.
In all asymmetric confidentiality protocols, each customer may post his or her public keying material to a publicly accessed directory without compromising the corresponding private keying material. The customer usually should guard his or her private keying material as a close secret; otherwise, the cryptographic system may not guarantee correctness (secrecy). The best known mechanism for protecting one's private keying material is through the use of a smart card. In this case, the smart card is a device with no interface for releasing private keying material (in a non-cryptographically protected form).
Although smart cards provide the best protection, social factors of electronic commerce may provide a role in ensuring private keying material protection. One of the significant difficulties associated with asymmetric encryption services is authentication. For example, if A posts his or her public keying material to a public directory, then how does B assess validity? That is, a pirate may attempt to masquerade as A but post the pirate's keying material. Some commercial organizations provide solutions to this problem by acting as Certification Authorities (CA). For (possibly) a fee, the CA solicits identifying material from potential customers such as a driver's license or passport. After validating the identifying material, the CA posts the customer's public keying material to a public directory, and the CA signs a certificate (using a digital signature with the CA's private key) that holds the customer's public keying material. Standardized services, for example X.500, may be adopted to help facilitate the use of directories that contain public keying material.
Once a customer posts his or her public keying material to the CA, the customer will probably make an extensive effort to protect his or her private keying material. For some asymmetric keys, if the customer's private keying material were to become unknowingly compromised, then the customer would have cause for significant concern. For example, in the case of RSA keys that can also be used for digital signatures, networked vendors could potentially authorize electronic commerce transactions.
The invention is defined by the features of the accompanying independent claims 1, 20 and 21. Further aspects of the invention are defined by the features of the dependent claims 2 to 19 and 22 to 38.
Brief Description of the Drawings
<ul id="ul0005" list-style="none"><li>Figure 1 is a flow diagram of a purchasing protocol used when a customer wishes to purchase software that is protected by a protection mechanism in accordance with the invention.</li><li>Figure 2 is a block diagram showing the software components that are required to be installed in the customer's machine to enable the customer to run the protected software.</li><li>Figure 3 is a flow diagram showing the operation of the protection mechanism in the protected software.</li><li>Figure 4 is a flowchart showing the operation of a random number generator used to generate nonces.</li></ul>
Description of an Embodiment of the Invention
One protection mechanism in accordance with the invention will now be described by way of example with reference to the accompanying drawings.
Purchasing protocol
Figure 1 shows a purchasing protocol used when a customer 102 wishes to purchase software that is protected by an ECP mechanism in accordance with the invention. The vendor 101 has public and private keying material used for digital signatures; and each potential customer 102 has public and private keying material used for asymmetric confidentiality proof protocols. Each party makes its public keying material available to other parties, but keeps its private keying material secret.
In step 1, the customer 102 obtains protected software 103 from the vendor 101 by downloading the software from a network bulletin board.
A challenge mechanism 24 (cp. Fig. 2), to be described later in detail, is embedded in the protected software 103 in such a way that a potential attacker cannot easily separate the challenge mechanism 24 from the protected program 103. The attacker would need to disassemble the code and to manually remove the challenge mechanism. The challenge mechanism 24 has the vendor's public keying material embedded in it. As will be described, the challenge mechanism 24 prevents the customer from running the software at this stage. The entire protected program, including the challenge mechanism is signed using the vendor's private keying material.
In step 2, the customer 102 sends a registration package 104 to the vendor 101 by electronic mail. The registration package 104 contains a reference to a public directory that holds the customer's public keying material.
In step 3, the software vendor 101 locates the customer's public keying material and embeds the customer's public keying material into a keyfile 105 and sends the keyfile 105 to the customer 102 by electronic mail. Once the customer 102 installs the keyfile 105, the protection mechanism permits the customer 102 to execute the protected software 103 provided that the customer can prove that he or she has access to the customer's private keying material via an asymmetric confidentiality proof.
The creation of the keyfile 105 is performed by a keyfile generator, which is a program that executes at the vendor's facility. The vendor 101 must take care to guard this program.
In use of the keyfile generator, an operator enters the following information: <dl id="dl0001"><dt>Vendor name:</dt><dd>Vendor name is the name of the vendor's company.</dd><dt>Vendor password:</dt><dd>Vendor password is the password that unlocks the vendor company's private keying material. Company employees who do not know the password cannot generate keyfiles.</dd><dt>Customer name:</dt><dd>The customer name is the distinguished name of a customer (defined in [6]) for whom to generate a keyfile. The name indexes into a database of public keying material.</dd><dt>Keyfile name:</dt><dd>The keyfile name is the name of a new keyfile.</dd></dl>
After obtaining this information, the keyfile generator builds a keyfile 105, containing the customer's public keying material. Portions of the keyfile 105 appears to the customer 102 as a completely random sequence of values.
Building of the keyfile 105 involves the following operations.
First, the keyfile generator creates a file and inserts the customer's public keying material into the file, along with thousands of decoy bits. In the present example, each keyfile 105 contains approximately 480,000 decoy bits. This number of bits represents a significant amount of decoy material, yet can fit into a standard e-mail message.
Each keyfile 105 stores the customer's public keying material in a different location. Additionally, each keyfile 105 has encrypted customer information embedded in it without disclosing the required encryption key. This encrypted customer information permits a software vendor to easily identify the owner of a keyfile 105 in the event that the keyfile 105 appears in a public location such as a bulletin board. The keyfile generator then encrypts and re-encrypts the keyfile (or portions of the keyfile) 105 multiple times, using different algorithms. Finally, the keyfile generator signs the keyfile 105 using the vendor's private keying material by applying a digital signature algorithm.
A keyfile is said to be validated if the challenge means can validate the vendor's signature using the public keying material stored in the challenge means' binary and access the decrypted public keying material stored in the keyfile.
Customer software
Figure 2 shows the software components that are required to be installed in the customer's machine, a computer, to enable the customer 102 to run the protected software 103. These consist of a protection server 20. Also shown are the keyfile 105 and the protected software 103. The copy protected software 103 includes a challenge mechanism 24.
The protection server 20 is a program that the customer 102 executes when the system initially boots. The customer 102 enables the system by inserting a floppy disk that contains an encrypted copy of the customer's private keying material. The protection server 20 then prompts the customer 102 for a pass phrase used to decrypt the floppy. The protection software does not continue executing if the customer cannot supply the correct pass phrase. The protection server 20 then executes in the background waiting for requests for executing the asymmetric confidentiality protocol
It should be noted that the protection server 20 never releases the customer's private keying material out of its process boundary. The protection server 20 relies on operating system protections to ensure its own integrity. The protection server 20 executes in its own address space and communicates with external processes.
Operation of the protection mechanism
Figure 3 shows the operation of the protection mechanism. This is performed when the customer initially attempts to execute the protected software 103, and is also repeated periodically during execution of the protected software 103. By sending a new challenge and waiting for a response that can be validated.
(Box 31) When the challenge mechanism 24 starts the process, the challenge mechanism 24 accesses the keyfile 105 associated with the protected software 103 and calls a signature validation function in the challenge mechanism 24 to validate the vendor's signature of the keyfile 105, using the vendor's public keying material that is embedded in the challenge mechanism 24. This validation of the keyfile signature ensures that an attacker cannot modify the keyfile 105 or its digital signature without additionally modifying the challenge mechanism 24. Vendors may optionally augment this protection using additional proprietary lines of defense. If the keyfile 105 has been modified, the challenge mechanism 24 hangs the program, or otherwise disturbs normal program execution.
Assuming the signature of the keyfile 105 is validated, the challenge mechanism 24 then parses the keyfile 105, using a proprietary, vendor-specific algorithm, to locate the customer's public keying material in the keyfile 105, and extracts the customer's public keying material.
The challenge and response means execute the asymmetric confidentiality protocol as illustrated below. <ul id="ul0006" list-style="none" compact="compact"><li><i>A ← B</i>:<i>h</i>(<i>r</i>)<i>,B,P</i><sub><i>A</i></sub>(<i>r,B</i>)</li><li><i>A → B</i>:<i>r</i></li></ul>
The expression uses the following notation: <ul id="ul0007" list-style="bullet" compact="compact"><li>Challenge means (challenge mechanism) 24 denoted by B (also denotes B' s identity, .e.g., "copy protected program x")</li><li>Response means (protection server) 20 denoted by A (also denotes A's identity, e.g., "protection server version 1".</li><li>r denotes a random number used as a nonce</li><li>h(r) is a message digest of the nonce</li><li>P<sub>A</sub>(r,B) is encryption of the nonce and B's identity using A's public keying material</li></ul>
(Box 31) The challenge means 24 of the protected software 103 generates an unguessable nonce (random number). Next, the challenge means computes h(r) (the message digest of r).
The challenge mechanism 24 then calls an encryption function in the challenge mechanism 24 to encrypt the nonce and B's identity with the customer's public keying material. The challenge mechanism passes the message digest of the nonce h(r), B's identity, and the result of the encryption to the protection server 20 with a request for participating in an asymmetric confidentiality proof.
(Box 32) When the protection server 20 receives the request, it first decrypts the encrypted portion of the message using the customer's private keying material.
Next, the protection server validates h(r) against the decrypted value.
Next, the protection server 20 validates that its identity, B, appears in the message and the decrypted value correctly.
If any validation fails, the protection server 20 returns failure without returning the decrypted nonce. However, if the validation succeeds, then the protection server 20 returns the decrypted nonce.
(Box 33) The challenge mechanism 24 compares the received decrypted nonce with the nonce that the challenge mechanism 24 originally encrypted. If they are not the same, the challenge mechanism 24 hangs the protected program, or otherwise disturbs normal program execution.
Thus, it can be seen that the protected program continues executing normally only if the customer possesses the proper private keying material and keyfile 105.
Nonce generator
Generation of a nonce is performed by a nonce generator included in the challenge mechanism 24. Operation of the nonce generator is as follows.
First, the nonce generator queries a large number of system parameters, e.g. the system time, the amount of space remaining free in the page table, the number of logical disk drives, the names of the files in the operating system's directory, etc.
Next, the nonce generator builds a random number, using a random number generator. The random number generator consists of two process threads, referred to herein as Thread 1 and Thread 2. Figure 4 shows the operation of Thread 1, which is the main thread of the random number generator.
(Box 51) Thread 1 first creates a data structure value_list, for holding a list of counter values. The list is initially empty.
(Box 52) Thread 1 sets a current counter value to zero, and sets a done_test flag to FALSE.
(Box 53) Thread 1 then forks Thread 2. Thread 2 posts an asynchronous disk access, and then sleeps until the disk access is complete. When the disk access is complete, Thread 2 sets the done_test flag to TRUE. Note that Thread 1 and Thread 2 share the done_test flag.
(Box 54) Thread 1 increments the counter value by one.
(Box 55) Thread 1 then tests whether the done_test flag is now TRUE, indicating that the disk access initiated by Thread 2 is complete. If done_test flag is FALSE, the thread returns to box 54. Thus it can be seen that, while waiting for the disk access to complete, Thread 1 continually increments the counter value.
(Box 56) When done_test flag is TRUE, Thread 1 terminates Thread 2, and saves the counter value in the first free location in value_list.
(Box 57) Thread 1 then calls a Statstest function, which estimates the degree of randomness of the counter values (or portions of counter values, e.g., low-order bits) saved in value_list. This function may use the Chi-Square Test, the Kolmogorov-Smirnov Test, or the Serial Correlation Test, which are described in [3]. The Statstest function may be optimized to ensure that complicated calculations are not repeated for each disk access. The Statstest function returns a value which indicates how many low-order bits of each saved counter value should be considered random.
(Box 58) Thread 1 compares the value returned by the Statstest function when combined with the length of the value_list with a predetermined threshold value, to determine whether enough random bits have now been generated. If not enough random bits have been generated, the process returns to box 52 above, so as to generate and save another counter value.
(Box 59) When the required number of random bits has been generated, Thread 1 extracts the specified number of low-order bits from each counter value in the value_list, and returns this sequence of bits as the output random number.
In summary, it can be seen that the random number generator exploits the unpredictability in the timing of a series of disk accesses as a source of randomness in the generation of nonces (see [4]). By forking new threads on each disk access, the random number generator also exploits unpredictabilities in the operation of the operating system's scheduler as a second source of randomness.
The analysis performed by the Statstest function permits the random number generator to self-tune for any speed processor and disk, by computing the number of low-order bits of each saved counter value to return. For example, a system with a high-variance disk access time will generate more random bits per-disk access than a system with a low-variance disk access time. For example, for a Quantum 1080s disk (6ms average write time), and a 486 66 Mhz processor, the system generates approximately 45 bits per second. Alternatively, one may hard code the number of bits per-disk access and use a de-skewing technique to ensure a good degree of randomness.
The nonce generator also queries the operating system to ensure that it posts each disk access to an actual disk. The final output nonce is formed by combining the output random number from the random number generator with the result of querying the system parameters as described above using a message digest.
The nonce generator described above works best when executing on an operating system that provides direct access to the disk, e.g., Windows 95 or Windows NT 4.0. In such an operating system, special operating system calls available to programs executing in user space permit a program to bypass the operating system's internal buffering mechanism and write directly to the disk. Most programs do not take advantage of these special operating system calls because they may be relatively inefficient and difficult to use. On Windows 95 and Windows NT, a program may only use these special calls if the program accesses data that is a multiple of the disk's sector size by querying the operating system.
If the operating system does not provide direct access to the disk, then the challenge mechanism 24 could still use the disk timing random number generator. However, in this case, the quality of the generated values would have a greater reliance upon unpredictabilities in the operating system's scheduler as opposed to the variance inherent to the disk access time.
The example of the invention described above assumes that the operating system permits a program to fork multiple threads within a single address space. Additionally, the example of the invention assumes that the operating system permits the threads to access synchronization variables such as semaphores. Most modern operating systems provide these services. The example of the invention uses multiple threads to implement a mechanism which quantifies each disk access time. However, if an implementation of the invention were to execute on a system that does not provide multiple threads or synchronization variables, then the nonce generator could substitute other mechanisms, e.g. querying a physical clock.
Some possible modifications
The customer need not get the software by downloading the software from a network bulletin board. The customer may also get the software on a floppy disk, CD-ROM, DVD, a PC store, Internet, or other distribution media.
Alternatively, the protection server 20 could also use a probabilistic encryption scheme, for example the Blum-Goldwasser probabilistic public-key encryption scheme to make sure that only the customer possesses the proper private keying material.
Thus it can be seen, that it is only important in accordance with the present invention, that an asymmetric confidentiality proof is used.
Furthermore, a smart card may be used to store and access the customer's private keying material (or the vendor's private keying material used in keyfile generation). In such a smart card-enabled configuration, a pirate cannot extract the private keying material from the smart card, which provides even greater defense against attack. Some smart cards do not execute until the user supplies a correct password or personal identification number.
We may optionally extend this present example by constructing the challenge means to reference an internal timer, e.g., a counting thread, or an external timer, e.g., a clock. If an a priori defined threshold terminates before completing the probabilistic proof protocol, then the validation automatically fails.
In addition to implementing copy protection, the invention may be used to trace software pirates. The mechanism provides excellent traceability, without requiring that each customer obtains a unique version of the program.
The protection server 20, the challenge mechanism 24, and the protected software 103 described above may be deployed in a number of different configurations.
For example: <ul id="ul0008" list-style="dash" compact="compact"><li>The protection server 20 may reside in one address space and the challenge mechanism 24 and the protected software 103 may reside in a different address space in a single machine.</li><li>The protection server 20 may reside in an address space on one machine and the challenge mechanism 24 and the protected software 103 may reside in a different address space on a different machine.</li></ul>
Furthermore, multiple customers, each with their own copy of the protected item of software, may share a common protection server 20, which responds to challenges from all these copies.
Another alternative is that multiple customers may share common private keying material. A company may use one or more of these deployment options, for example, when constructing multi-user licensing functionality.
In another possible modification, the keyfile 105 may contain hidden information concerning selective activation of services of the protected program 103. For example, the keyfile 105 may specify that the protected program 103 may permit execution of a Print service but disable execution of a Save-On-Disk service. As another example, the keyfile 105 may contain an expiration date that describes the last date that a particular service may execute. The protected program 103 would read the keyfile 105 to determine the services that the protected program 103 should execute. A customer could obtain the ability to execute more services by requesting another keyfile from the vendor.
In another possible modification, the protected program could distribute the result of the asymmetric confidentiality proofs to other programs. These other programs could use this result to help determine if the other programs should cease executing, or executed in a limited manner.
The following publications are cited in this document: <ul id="ul0009" list-style="none"><li>[1] Choudhury et al, Copyright Protection for Electronic Publishing over Computer Networks, IEEE Network, May/June 1995, pp. 12 - 20.</li><li>[2] A. Menezes, P. Van Oorschot and S. Vanstone, Handbook of Applied Cryptography, CRC Press, Boca Raton, ISBN 0-8493-8523-7, pp. 405 - 424, 1997.</li><li>[3] D. Knuth, The Art of Computer Programming, Vol. 2, Seminumerical Algorithms, Addison-Wesley Publishing Co., Reading MA, 2nd Edition, 1981, pp. 38-73, ISBN 0-201-03822-6</li><li>[4] P. Fenstermacher et al, Cryptographic randomness from air turbulence in disk drives, Advances in Cryptology: Crypto '94, pp. 114 - 120, Springer Verlag, 1994</li><li>[5] R. Rivest, The MD5 message-digest algorithm, RFC 1321, April 1992</li><li>[6] ISO/IEC 9594-1, "Information technology - Open Systems Interconnection - The Directory: Overview of concepts, models, and services", International Organization for Standardization, Geneva, Switzerland, 1995 (equivalent to ITU-T Rec. X.509, 1993).</li></ul>
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both waysCites: the store holds 2 of 3
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO8805941A | Cites | World Intellectual Property Organization (WIPO) | – |
| US5351293A | Cites | United States of America | – |
| ROTRAUT LAUN: "ASYMMETRIC USER AUTHENTICATION" COMPUTERS & SECURITY INTERNATIONAL JOURNAL DEVOTED TO THE STUDY OF TECHNICAL AND FINANCIAL ASPECTS OF COMPUTER SECURITY, vol. 11, no. 2, 1 April 1992, pages 173-183, XP000245841 | Non-patent | – | – |
| MENEZES, VAN OORSCHOT, VANSTONE: "Handbook of Applied Cryptography, pp. 308, 397-405", 1996, CRC, BOCA RATON, USA | Non-patent | – | – |
| MENEZES, VAN OORSCHOT, VANSTONE: "Handbook of Applied Cryptography, pp. 308, 397-405", 1996, CRC, BOCA RATON, USA | Non-patent | – | Examiner |
7 members in 4 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 97710012 | European Patent Office (EPO) | A | |
| EP19970710012 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| EP0881558A1 | European Patent Office (EPO) | A1 | |
| CN1206151A | China | A | |
| EP0881558B1This record | European Patent Office (EPO) | B1 | |
| DE69720972D1 | Germany | D1 | |
| US6651169B1 | United States of America | B1 | |
| DE69720972T2 | Germany | T2 | |
| CN1165848C | China | C |
28 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Designation fees paidDE FR GB ITAKX | AKX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0881558
- Publication, DOCDB
- 0881558
- Publication, EPODOC
- EP0881558
- Application
- 97710012
- Application, DOCDB
- 97710012
- Application, EPODOC
- EP19970710012
Titles3
- German
- Computersystem und Verfahren zum Schutz von Software
- English
- Computer system for protecting software and a method for protecting software
- French
- Système d'ordinateur et méthode pour protégér des logiciels
Classification
- CPC, 5
- G06F21/10
- H04L9/3271
- H04L2209/56
- H04L2209/605
- H04L9/3218
- IPC, 3
- G06F1 00
- G06F21 10
- H04L9 32
Designated states4
- Contracting states, 4
- Germany
- France
- United Kingdom
- Italy
