A computer-implemented method and system for controlling use of digitally encoded products
Abstract
This record has no abstract on file.
Term
Term ended
Expired 10 October 2022, 4 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
11 claims: 11 independent, 0 dependent
- 1コンピュータと該コンピュータに接続されたメータリング・サーバとを備えるシステムで用いられ、前記コンピュータ上で実行されるディジタル・エンコードされた製品の使用を制御するための方法(300)であって、 前記コンピュータには、前記製品のリストを保管する 制御カタログ が備えられ、 前記コンピュータ 上で動作する実行エージェントが、 前記コンピュータ上で前記製品の実行要求があったとき、前記製品 のリスト が前記 制御カタログ に含まれない 場合に、 当該製品の開始をイネーブルするステップ(328,330)と、 前記製品 のリスト が前記 制御カタログに含まれる場合に 、前記メータリング・サーバに対して実行要求を送るステップ(328,334)と、 前記メータリング・サーバからの応答に応じて前記実行要求を許可するか否かを決定するステップ(310~315)と、 前記 制御カタログ に含まれない製品の表示を前記コンピュータで保管されるログに追加するステップ(332)と、 前記ログを前記メータリング・サーバに定期的に送るステップ(366)とを実行し、 前記メータリング・サーバ 上で動作するライセンシング・エージェントが、 前記メータリング・サーバに備えられた許可カタログに保管された使用条件に前記実行要求に係る前記製品の実行が従うか否かを 判定するステップ(380,384~385)と、 前記ステップ(380,384~385)における 判定に応じて前記応答を前記コンピュータに返送するステップ(382)と、 前記ログ にリストされた前記製品が少なくとも前記メータリング・サーバに備えられたグローバル・カタログに含まれるか否かを判定して、含まれる場合に前記制御カタログ及び前記許可カタログ を更新する ステップ(389,390) とを実行する方法。
- 2前記コンピュータ 上で動作するオペレーティング・システムのカーネル拡張モジュールが、 前記実行要求に関連するプロセスの開始を検出して 前記実行エージェントに前記実行要求を報告する ステップ(306)と、 前記プロセスの開始が検出されると 前記プロセスを中断するステップ(308) とを 実行し、 前記ステップ(310~315)では、 前記実行エージェントが前記メータリング・サーバからの応答に応じて前記実行要求を許可した場合に前記カーネル拡張モジュールに前記プロセスを再開させ、前記メータリング・サーバからの応答に応じて前記実行要求を不許可とした場合に前記プロセスを打ち切らせる請求項1 に記載の方法(300)。
- 3前記メータリング・サーバには、予め定められた複数のコンピュータが関連しており、 前記ステップ(328,334)では、前記実行要求を示す要求メッセージを、前記コンピュータから複数のコンピュータに関連するメータリング・サーバに送っており、 前記ステップ(380,384~385)は、前記複数のコンピュータのすべてについて前記 使用条件を表すライセンシング情報に前記実行要求に係る前記製品の実行が従うか否かを判定するステップ(380)と、前記実行要求に対して許可を与えた場合に 前記メータリング・サーバによって現在許可されている実行許可を表す メータリング・テーブルに当該許可に係る製品をリストとして追加する ステップ(384~385)とを有する請求項 1又は2 に記載の方法(300)。
- 4前記 実行エージェント では、前記応答が実行許可の拒否を示しているとき、少なくとも1つの代替メータリング・サーバに前記実行要求を送るステップ(336,340,342)をさらに実行する請求項 3 に記載の方法(300)。
- 5前記製品の実行が終了すると、 前記実行エージェント では実行の終了を示す終了メッセージを、前記許可を与えたメータリング・サーバに送るステップ(398,318,349)を実行し、 前記 ライセンシング・エージェント では、前記終了メッセージに応答して、 前記メータリング・テーブルから前記製品のリスト を除去するステップ(387)を実行する 請求項3又は4 に記載の方法(300)。
- 6前記 実行エージェント では、前記メータリング・サーバに、 実行許可中の製品に係る検査を行うための 検査メッセージを定期的に送るステップ(364)を実行し、 前記 ライセンシング・エージェント では、前記検査メッセージを事前に設定された期間中に受け取らないとき、前記メータリング・ テーブル から前記コンピュータで動作する 製品に係るリスト を除去するステップ(392)を実行する 請求項5 に記載の方法(300)。
- 7前記 実行エージェント では、 当該コンピュータにインストールされた製品を示すインストール情報を定期的に収集するステップ(368,370)と、 前記 メータリング・サーバに前記インストール情報を送るステップ(372)とを実行する請求項 3ないし6 のいずれかに記載の方法(300)。
- 8単一の中央管理サーバから 前記メータリング・サーバの管理を行うための 管理メッセージをメータリング・サーバに送る ステップと、 前記管理メッセージを受けた際前記ライセンシング・エージェントは前記中央管理サーバに保管されたマスタ・カタログから当該メータリング・サーバに係る許可カタログを抽出して展開する ステップ(394) とを 有する請求項 3ないし7 のいずれかに記載の方法(300)。
- 9コンピュータ・アプリケーション ・プログラム (220,225,260)であって、データ処理システム(100)で実行する際、請求項1ないし 8 のいずれかに記載の方法を実行するために前記データ処理システムの作業メモリに直接にロード可能なコンピュータ・アプリケーション ・プログラム 。
- 10請求項 9 に記載の コンピュータ・アプリケーション・プログラム が記録されたコンピュータ読み取り可能な記録媒体(160w,160s)。
- 11コンピュータ(105w)と該コンピュータに接続されたメータリング・サーバ(105s)とを備え、前記コンピュータ上で実行されるディジタル・エンコードされた製品の使用を制御するためのデータ処理システム(100)であって、 前記コンピュータには、前記製品のリストを保管する 制御カタログ (240)と、 前記コンピュータ上で前記製品の実行要求があったとき、前記製品 のリスト が前記制御 カタログ に含まれない 場合に、 当該製品の開始をイネーブルする手段(220,225)と、 前記製品 のリスト が前記 制御カタログに含まれる場合に 、前記メータリング・サーバに対して実行要求を送る手段(210w,225)と、 前記メータリング・サーバからの応答に応じて前記実行要求を許可するか否かを決定する手段(225)と、 前記 制御カタログ に含まれない製品の表示を前記コンピュータで保管されるログに追加する手段(225)と、 前記ログを前記メータリング・サーバに定期的に送る手段(225,210w)とが備えられ、 前記メータリング・サーバには、 前記メータリング・サーバに備えられた許可カタログに保管された使用条件に前記実行要求に係る前記製品の実行が従うか否かを 判定する手段(260,265)と、 前記手段(260,265)による 判定に応じて前記応答を前記コンピュータに返送する手段(260,210s)と、 前記ログ にリストされた前記製品が少なくとも前記メータリング・サーバに備えられたグローバル・カタログに含まれるか否かを判定して、含まれる場合に前記制御カタログ及 び前記許可カタログ を更新する手段(260)とが備えられているデータ処理システム。
Independent claims11
75 paragraphs, as filed
The present invention relates to methods and systems for controlling the use of digitally encoded (digitally encoded) products.
Digitally encoded products, such as software programs, can play a complete copy an unlimited number of times. However, unauthorized copying of a program usually involves infringement of the intellectual property rights of its right holder. For this reason, it is very important to verify that the program used complies with the corresponding permitted terms of use. This problem is particularly acute in large organizations with a large number of computers, and has been exacerbated in recent years by the widespread spread of the Internet, which further facilitates uncontrolled distribution of this type of product.
The verification described above is usually performed by manually auditing all computers. However, this procedure is time consuming (especially in large locations) and error prone.
Several automated tools have also been proposed to assess whether the program complies with the permitted terms of use. These tools typically utilize agents installed on each computer. The agent periodically inspects the programs running on your computer. The results of the validation are logged to generate a program usage report. In addition, if a program that violates its permitted terms of use is running, this tool can kill each process (to stop the program from running) and start the program again. You can make it impossible.
However, the solution described above does not monitor program usage in real time, and as a result, it is not possible to perform actual licensing verification. In addition, when you force termination of program execution to force compliance with permitted terms of use, the corresponding data may be damaged, which causes the end user to: It is also forced to reinstall the program on the computer for use.
A different solution, called technical licensing, proposed in the art involves modifying each program to include a call to a licensing management system. Each time the end user starts the program, the corresponding request is forwarded to the licensing management system. The licensing management system verifies that the execution of the program is within the limits indicated by the permitted terms of use incorporated in each digital certificate and provides the program with a corresponding return code. If the result of the validation is affirmative, the program can continue its execution, otherwise the program will be forced to stop.
However, the solution described above requires each program to be modified by the right holder. Moreover, this solution is very strict and cannot easily meet different requirements. Technical licensing technology applies only to programs that support licensing management systems and is completely inefficient in controlling the use of different products.
<p> An object of the present invention is to overcome the above-mentioned disadvantages. To achieve this goal, the method of claim 1 is proposed.</p>
<p> In short, the present invention is a method performed by a computer that controls the use of a digitally encoded product, which requires the execution of the digitally encoded product on the computer and the initiation of the product. Before, the step of intercepting the execution request, the step of verifying that the execution request complies with the permitted conditions of use of the product, and enabling or preventing the start of the product according to the result of the verification. Provides a method including steps and.</p><p> In addition, the invention also provides a computer program application that performs the method, a program product that stores this application, and a data processing system that controls the use of digitally encoded products.</p><p> Further features and advantages of the solution according to the invention will become apparent from the following description of preferred embodiments of the invention, given as purely non-limiting indications with respect to the accompanying drawings.</p>
In particular, with respect to FIG. 1, a data processing system 100 capable of using the present invention is shown. System 100 includes multiple workstations 105w. Workstations 105w are grouped into a set of subsets, with metering servers 105s associated with each subset of workstations 105w. The metering server 105s and the corresponding workstation 105w are connected to each other via a network 110 (eg, an intranet). The different metering servers 105s communicate with the management server 115 (installed at a remote location) over a different network 120 (eg, the Internet). In addition, the management server 115 is connected to the asset management system 125 (via another network 127), which stores information about the workstation and its users.
For example, each workstation 105w consisting of a personal computer (PC) is formed by a plurality of units connected in parallel to a communication bus 130w. Specifically, the microprocessor (μP) 135w controls the operation of workstation 105w, RAM140w is used directly by the microprocessor 135w as working memory, and ROM145w is the basic program for bootstrap of workstation 105w. Is stored. In addition, multiple peripheral units are connected to bus 130w (via each interface). Specifically, the large-capacity storage device consists of a magnetic hard disk 150w and a driver 155w that reads a CD-ROM 160w. In addition, workstation 105w includes an input device 165w (for example, consisting of a keyboard and mouse) and an output device 170w (for example, consisting of a monitor and a printer). A network interface card (NIC) 175w is used to connect workstation 105w to network 110.
The metering server 105s (for example, consisting of a midrange computer) is similarly formed by a bus 130s, multiple microprocessors 135s, RAM140s, and ROM145s, and the metering server 105s further includes a hard disk 150s, Includes drivers 155s for CD-ROM160s, input devices 165s, output devices 170s, and NIC 175s (for accessing networks 110 and 120).
Similar considerations apply to each workstation or metering if the systems have different architectures, if the workstations, metering servers, and management servers are connected to each other on different networks, or if other networks are used. -This applies when the server has a different structure or contains different components, or when an asset management system is not provided.
Examining Figure 2 shows the partial contents of the workstation and metering server working memories 140w and 140s. Information (programs and data) is usually stored on each hard disk, loaded into working memory (at least partially) when the program is running, and the program is initially installed from the CD-ROM to the hard disk. Will be done.
Operating system 205w and operating system 205s provide software platforms for workstations and metering servers, respectively. Stack 210w (workstation side) and Stack 210s (metering server side) process a set of protocol layers that work together to define network communication. To ensure the effective transmission of information over the Internet, the information is transmitted using a protocol that is encrypted (to ensure security) and can pass through firewalls (such as HTTP).
Especially considering workstations, the operating system 205w contains a main module 215 (referred to as the kernel), which provides all the essential services required by other parts of the operating system. .. Kernel extension module 220 adds functionality to the operating system using commonly available standard interfaces.
The run-time agent 225 runs in the background to control the execution of application program 230 on the workstation. The run-time agent 225 interfaces with the stack 210w to exchange information with the metering server. The run-time agent is quietly installed on the workstation during the registration process. In this registration process, the workstation end user registers himself by connecting to a web page hosted on the associated metering server.
The run-time agent 225 controls multiple memory structures. Specifically, server table 235 contains the IP address of a possible alternate metering server associated with that workstation (in addition to the main metering server that is directly connected to the workstation). When identified in the agent's configuration table). The control catalog 240 lists the programs that must be controlled to run on the workstation, while the internal log 245 lists the programs that are not included in the control catalog 240 but run on the workstation. .. In addition, the run-time agent 225 controls the entry of information into the running table 250, which is the program currently running on the workstation with the corresponding execution permission (granting permission). Listed (along with the metering server identifier). The run-time agent 225 also generates a program inventory 255 (for sending to the metering server), which contains information about the programs installed on the workstation.
Moving to the metering server, the licensing agent 260 running in the background controls the associated workstation. The licensing agent 260 interfaces with the stack 210s to exchange information with workstations and management servers.
The licensing agent 260 manages the authorization catalog 265, which contains information about the authorization terms of use for each program, for example, the authorization catalog 265 allows the maximum processing power of the workstation that can run the program. Alternatively, the maximum amount of working memory, the number of program licenses (which defines the maximum number of instances of the program allowed to run at the same time), and other information are specified. In addition, the licensing agent controls the entry of information into the metering table 270, which is the program currently running on the workstation that the metering server has authorized to run. Is listed. Licensing Agent 260 also manages a global catalog 273 containing known programs that can be generally allowed to run on associated workstations.
In addition, Licensing Agent 260 manages Repository 275, which contains different information distributed to associated workstations (latest version of runtime agent code, or a list and control of alternative metering servers. Contains different information collected from the workstation (such as a list of programs) or different information (such as real-time reports of software usage and inventory information of programs installed on the workstation).
Similar considerations apply when programs and data are configured differently, when other modules or functions are provided, when data is stored in equivalent memory structures, when different conditions of use are expected. This is the case, for example, when information is transmitted using different protocols, when a licensing agent is embedded in a web server, and so on. In the alternative, the run-time agent is installed by a logon script stored on the workstation or deployed by software distribution.
As can be seen in Figures 3-5, a set of routines that together make up Method 300 are executed on the workstation and metering server to control the use of programs installed on the workstation.
Specifically, the kernel extension module is loaded during the workstation bootstrap. Referring to FIG. 3, the routine executed by the kernel extension module starts at block 302 and cycles in the idle loop of block 304 waiting for an event to occur. When a program execution request is detected, blocks 306 to 308 are executed, and when the corresponding response message is returned by the run-time agent, blocks 310 to 315 are executed and the end of the program is detected. , Block 318 is executed, and in any case, this routine then returns to block 304 and waits for a new event to occur. Conversely, if the workstation is shut down, the routine ends at final block 322.
The workstation bootstrap also includes loading the run-time agent, which implements the routine starting at block 324. This routine cycles in an idle loop in block 326, waiting for an event to occur. When the execution request is notified, blocks 328 to 334 are executed, and when the corresponding response message is received from the metering server, blocks 336 to 346 are executed and the end of the program is notified. If blocks 348-350 are executed and the timeout expires, blocks 364-374 are executed, and in any case, this routine returns to block 326 and waits for a new event to occur. Conversely, if the workstation is shut down, this routine ends at final block 375.
At the same time, the licensing agent is loaded during the bootstrap of the metering server. Referring to FIG. 5, the licensing agent executes a routine that starts at block 376 and then cycles through an idle loop at block 378 to wait for an event to occur. Blocks 380-386 are executed when the execute request message is received, block 387 is executed when the end message is received, and blocks 388-390 are executed when the information is received from the workstation. Blocks 392 to 393 are executed if the inspection message is not received from each associated workstation during a preset cycle, and block 394 if the management message is received from the management server. Is executed, and in any case, this routine then returns to block 378 and waits for a new event to occur. Conversely, if the metering server is shut down, this routine ends at final block 396.
Returning to Figure 3, when the end user requests the program to run on the workstation, for example by double-clicking the icon with the mouse (block 397), the kernel starts a new process. The start of the process is notified to the kernel extension module (using the so-called kernel hook technique), and at block 306, the kernel extension module reports that information to the runtime agent. The kernel execution module suspends the process at block 308.
In response to the notification, the execution agent verifies in block 328 whether the program is included in the control catalog. If not, this method moves to block 330 and the run-time agent informs the kernel extension module that it can start the program. The program is added to the internal log at block 332. In response, the kernel extension module restarts the processes associated with the program in block 312 to enable the program to start its execution. Conversely, if the program is included in the control catalog, in block 334, the run-time agent provides the corresponding execute request message (configuration information that defines the program's execution environment, such as workstation processing power or work memory capacity. Including) is sent to the metering server.
With reference to Figure 5, when the licensing agent running on the metering server receives a request message, at block 380, does program execution comply with the permitted terms of use stored in the authorization catalog? For example, whether the execution environment matches the allowed environment and the number of running program instances has not reached the maximum allowed) is verified. At block 382, the licensing agent returns the corresponding response message to the workstation. Then run the test on block 384 to determine if it has been granted permission to run. If so, the licensing agent adds the program to the metering table in block 385 and then proceeds to block 386, otherwise it goes directly to block 386. Considering block 386, the metering server sends a notification email to the system administrator when a preset percentage of product availability licenses (such as 80%) is reached, causing the metering server to You will receive another notification email when your product license is exhausted.
Returning to Figure 3, as soon as the run-time agent receives the response message, it tests in block 336 to determine if it has been granted permission to run. If so, this method proceeds to block 338 (discussed below). In the opposite case, the execution agent determines in block 340 whether an alternate metering server is listed in the server table. If one or more alternate metering servers are available, the run-time agent sends a run request message to each alternate metering server in turn, the same validation as described above. Is executed, then this method proceeds to block 338. Conversely, if an alternative metering server is not available, this method goes directly to block 338.
Considering block 338, the run-time agent forwards the response message to the kernel extension module before proceeding to decision block 344. If permission is given to execute, block 346 adds the program to the running table (and vice versa, this method goes back directly to block 326).
As soon as the response message is received, the kernel extension module runs a test in block 310 to determine if execution permission has been granted. If so, the kernel execution module restarts the processes associated with the program in block 312 so that it can start executing the program. Conversely, if execution permission is denied, the kernel extension module terminates the process at block 315 to prevent the program from starting.
When the program finishes executing (block 398), an event is notified to the kernel extension module, which reports that information to the run-time agent in block 318. In response to this notification, at block 348, the run-time agent checks whether the program is included in the running table. If so, the run-time agent sends the corresponding termination message in block 349 to the metering server, moves it to block 350, and removes the program from the running table (and vice versa). This method goes back directly to block 326). Referring to FIG. 5, when the licensing agent (metering server side) receives the termination message, the program is removed from the metering table in block 387 to release each license.
As shown in Figure 4, whenever a timeout expires, for example a few minutes (block 364), each of the metering servers (running table) that the run-time agent has given permission to run the program on the workstation. Send an inspection message to). This method then proceeds to block 366, where the run-time agent sends the entire internal log to the associated metering server.
Then test in decision block 368 to determine if a longer timeout (for example, tens of minutes) has expired. If so, at block 370, the run-time agent scans the workstation hard disk to collect information about the installed programs. Following block 372, the installation information so collected (stored in the program inventory) is sent to the metering server. At block 374, the run-time agent downloads the server table, control catalog, or upgrade to the run-time agent code or a combination thereof (from the metering server) without the need for user intervention.
See Figure 5. When moving to the licensing agent running on the metering server, all information received from the associated workstations (such as internal logs or program inventory) is stored in block 388. When the metering server receives the internal log, this method checks in block 389 whether each program listed in the internal log is included in the global catalog. If so, this method proceeds to block 390, where the program is added to the control and authorization catalogs distributed to the workstation (without restrictions on the corresponding allowed terms of use) and in this way. , All of the following requests to run the program will always be enabled so that the use of the program can be tracked for analysis by the system administrator. In the opposite case, this method goes back directly to block 378.
Considering block 392, if inspection messages are not received from a generally associated workstation during a preset period of time (eg 10 minutes), all programs running on this workstation will block 392. Is removed from the metering table (to release each license) and the corresponding email of the notification is sent to the system administrator in block 393.
In addition, whenever a management message is received from the management server, the corresponding action is taken in block 394. For example, the authorization catalog for each metering server can be extracted from the master catalog stored on the management server, and each authorization catalog is deployed to the corresponding metering server (thus networked). The amount of information transferred is reduced). In addition, the management server can collect information from the metering server (information about programs installed on and / or running on the corresponding workstation). Different management servers can create different reports. For more information, system administrators report on product usage (filtered by start and end times), detailed usage of a particular product, and a comparison view of installed, used, and licensed products. Can be requested. Security profiles are also defined on the Administration Server, which allows each workstation end user to access only information about the programs they are using. In this way, the Administration Server implements a single repository in which usage data, procurement data, and inventory data are collected and managed.
A similar consideration is that if the equivalent method is performed (for example, if you use multiple parallel processes that perform the operations described above in parallel), or if other features are provided, then the program execution is different. If requested by the program, if the request message contains different information, if the timeout value is different or can be customized by the system administrator, an equivalent check message will be sent to the metering server on a regular basis (for example). This is the case, for example, if the notification email is not sent to the system administrator (including the corresponding record in the running table). In the alternative, the proposed method is also used to control the use of equivalent digitally encoded products, such as audio and video recordings, ebooks, or multimedia works.
More generally, the present invention provides computer-implemented methods of controlling the use of digitally encoded products. The method begins with the step of requesting the execution of the digitally encoded product on the computer, and the execution request is intercepted prior to the start of the product. It is verified that the execution request complies with the permitted conditions of use of the product, and the start of the product is enabled or prevented depending on the result of the verification.
By using the solution of the present invention, it becomes possible to control a program running on a computer in real time. In this way, very effective licensing verification is performed at low cost.
The operation of the proposed method is extremely safe. This is because the program is prevented from starting itself, so it cannot be killed while it is already processing data and performing potentially dangerous actions. In addition, program integrity is not affected by permission denials, so program execution can be easily enabled later (without having to reinstall the code).
The solution of the present invention provides an integrated solution that controls the use of all types of programs, either under technical license or not. Therefore, even programs that do not contain special logic to control the enforcement of permitted conditions of use can be controlled, while at the same time existing solutions that utilize licensing management systems in the proposed way. Supported.
Further benefits are also provided by the preferred embodiments of the invention described above.
Specifically, the execution request is intercepted by detecting the start of each process, and the process is interrupted and restarted or terminated according to the result of verification.
This procedure is very simple and at the same time very effective.
Advantageously, the operating system notifies the kernel extension module of the start of the process, which reports the execution request to the run-time agent running on the workstation. At the same time, the kernel extension module suspends the process (waits for a response to the execution request).
The provision of kernel extension modules and run-time agents makes the solution embodiments of the present invention platform-independent and easily portable to all types of operating systems.
In a preferred embodiment of the invention, the execution request is processed by a metering server, which controls a plurality of workstations associated with it.
The proposed solution allows for very flexible management of licenses. For example, the maximum number of concurrent use of each program instance on a workstation can be controlled from a single point in a very simple way.
Advantageously, the workstation is allowed to contact an alternate metering server if the associated server has already granted all available licenses.
Therefore, the total amount of licenses available for each product can be shared among all workstations in the organization (even if controlled by different metering servers).
However, the solution of the present invention intercepts the execution request in a different way (for example, to monitor end-user actions), uses only the kernel extension module or run-time agent, and issues the execution request directly by the workstation. It processes (without a metering server) and runs without having the workstation contact an alternative metering server.
It is preferable that the control catalog lists the programs to be weighed (the execution of other programs is not affected by the expected method).
This feature allows system administrators to implement customized licensing policies.
Programs not included in the control catalog are always allowed to run, but are added to the internal log and the internal log is sent to the metering server on a regular basis (to update the workstation authorization catalog and control catalog). To).
Internal logs supplied by different workstations make it easy to track the use of new products (along with unlicensed programs that are reported to the metering server as soon as they are used).
The alternative is that there is no control catalog (for all programs that are always controlled), execution of programs not included in the control catalog is immediately notified to the metering server, and the authorization and control catalogs are internal. Only programs that are updated differently according to the log (without using the global catalog) or listed in the control catalog will run on the workstation (if allowed).
In addition, when the program finishes executing, a termination message is sent from the workstation to the metering server that has given each permission to execute, and the program is running on the running table (workstation side) and the metering table. Deleted from (metering server side).
This procedure guarantees the direct release of the corresponding license as soon as the program finishes executing, and the license is immediately available for use by other workstations.
Advantageously, each workstation sends a test message to each metering server to grant permission to run, if the test message from the workstation is not received within a preset period of time. The metering server automatically releases the license used by that workstation.
In this way, if the workstation cannot release the license, for example due to a network problem, the license is automatically released on the metering server side.
However, the solution of the present invention does not even periodically transmit inspection messages by detecting the end of each program in different ways (eg, polling procedures under the control of each metering server) (licenses every night). Etc., will be automatically released after a preset period of time) and will be implemented properly.
Advantageously, each workstation collects installation information on a regular basis and sends that information to the associated metering server.
The envisioned features allow you to remember and monitor the products installed on each workstation (even if they are not used).
In a preferred embodiment of the invention, a single management server controls multiple metering servers from the center.
The proposed three-tier architecture (workstation, metering server, and management server) allows for very flexible license management from a centralized point of view.
For example, the Administration Server collects information from all metering servers to provide historical reports on program usage and inventory information for all workstations. In addition, the management server provides a management interface for maintaining licensing information from a centralized point of view.
Therefore, it is possible to save money by detecting over-acceptance conditions (if too many licenses are available for unused products), or proactively detect potential infringement conditions (licenses). It is possible (to take corrective action before it runs short).
The proposed architecture features high scalability. For example, a small company only needs one metering server and one management server (which can be installed on the same computer). Conversely, large companies may have multiple metering servers (controlled by a single management server) within one or more networks. On the other hand, the management server can be installed remotely and the management server can control metering servers in different facilities (for example, in an organization that provides software management services to other companies). ..
In the alternative, the installation information is collected on demand and the suggested method controls only the execution of the program (does not control the installation), or the system has a different architecture (even without a management server). ).
Advantageously, the solution according to the invention is implemented using a computer program application provided on a CD-ROM. This application consists of programs installed on each workstation and associated metering server.
Alternatively, the program is provided on a floppy disk, preloaded on a hard disk, stored on another computer-readable medium, or workstations and metering over a network (usually the Internet). It is sent to a server, broadcast, or more generally provided in other form that can be loaded directly into working memory. However, the method according to the invention is carried out using a hardware structure, for example, integrated on a chip of a semiconductor material.
Of course, to meet local and specific requirements, one of ordinary skill in the art can make numerous modifications and changes to the solutions described above, all of which are the protections of the invention as defined by the claims. Is included in the range of.
<figref num="1">It is a basic block diagram which shows the data processing system which can use the method of this invention.</figref><figref num="2">It is a figure which shows the partial contents of the working memory of the workstation and the metering server included in the system of this invention.</figref><figref num="3">It is a flow chart which shows the logic of the method of controlling the use of a software program.</figref><figref num="4">It is a flow chart which shows the logic of the method of controlling the use of a software program.</figref><figref num="5">It is a flow chart which shows the logic of the method of controlling the use of a software program.</figref>
Every citation, both waysCites: the store holds 11 of 12
| Document | Relation | Office |
|---|---|---|
| JP06223040A | Cites | Japan |
| JP2001222424A | Cites | Japan |
| JP10171649A | Cites | Japan |
| JP09237189A | Cites | Japan |
| JP2001142689A | Cites | Japan |
| JP2001236219A | Cites | Japan |
| US05758069A | Cites | United States of America |
| US06021438A | Cites | United States of America |
| JP2000305776A | Cites | Japan |
| JP2000057035A | Cites | Japan |
| US05790664A | Cites | United States of America |
| 鈴木信夫,ネットワーク時代のライセンス管理、ライセンスサーバが切り札に,日経エレクトロニクス,日本,日経BP社,1990年11月26日,no.514,p.157-p.163,JPN402004421 | Non-patent | – |
11 members in 5 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 01480108 | European Patent Office (EPO) | A | |
| 01480108 | European Patent Office (EPO) | A | |
| 014801088 | European Patent Office (EPO) | – | |
| 0212190 | European Patent Office (EPO) | W | |
| 0212190 | European Patent Office (EPO) | W | |
| 200101480108 | – | – | – |
| 2002012190 | – | – | – |
| EP20010480108 | – | – | – |
| WO2002EP12190 | – | – | – |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| WO03038570A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03038570A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2004133801A1 | United States of America | A1 | |
| EP1466228A2 | European Patent Office (EPO) | A2 | |
| CN1582421A | China | A | |
| JP2005507519A | Japan | A | |
| JP3963385B2This record | Japan | B2 | |
| US7376971B2 | United States of America | B2 | |
| US2008189795A1 | United States of America | A1 | |
| CN100487626C | China | C | |
| US7661147B2 | United States of America | B2 |
28 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Notification of resignation of power of sub attorneyJAPANESE INTERMEDIATE CODE: A7434RD14 | RD14 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of acceptance of power of sub attorneyJAPANESE INTERMEDIATE CODE: A7432RD12 | RD12 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 |
Numbers
- Publication
- 3963385
- Publication, DOCDB
- 3963385
- Publication, EPODOC
- JP3963385B
- Application
- 2003540769
- Application, DOCDB
- 2003540769
- Application, EPODOC
- JP20030540769
Titles2
- Japanese
- ディジタル・エンコードされた製品の使用を制御する方法およびシステム
- English
- Methods and systems to control the use of digitally encoded products
Classification
- CPC, 3
- G06F21/121
- G06F21/126
- G06F2221/2135
- IPC, 3
- G06F21 22
- G06F1 00
- G06F21 12