MY134635A

System for binding secrets to a computer system having tolerance for hardware changes

Abstract

SYSTEMS AND METHODS FOR BINDING A SECRET TO A COMPUTER SYSTEM ARE DISCLOSED. SYSTEMS AND METHODS FOR GENERATING A STRONG HARDWARE IDENTIFICATION (SHWID) FOR A GIVEN COMPUTER SYSTEM ARE ALSO DISCLOSED. THE STRONG HARDWARE IDENTIFICATION (SHWID) IS COUPLED TO A BOUND SECRET. THE STRONG HARDWARE IDENTIFICATION (SHWID) MAY BE USED TO CONTROL THE USE OF SOFTWARE ON THE GIVEN COMPUTER SYSTEM DEPENDING ON THE DEGREE OF HARDWARE CHANGES TO THE COMPUTER SYSTEM.(FIG 1)

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

41 claims: 6 independent, 35 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A method of generating a strong hardware identification (SHWID) for a first computer system having a first hardware configuration, wherein the method comprises: identifying each component class within the first hardware configuration, wherein the number of component classes is equal to n;determining a class product, cp, for each component class;determining a partial secret, Pp, for each component class;and adding the class product, cp, and the partial secret, Pp, for each component class to form η strong class IDs, wherein the n strong class IDs in combination form the strong hardware identification (SHWID) of the first computer system.
  2. 11
    A method of determining whether a software product can be used on a second computer system having a second hardware configuration, wherein the second computer system is identical to or different from the first computer system, wherein the method comprises:identifying the n components classes used to determine the strong hardware identification (SHWID) generated by the method of Claim 1;identifying all instances within each component class of the second hardware configuration;retrieving an identification string that represents each individual component instance;generating instance primes, zpq, for each component instance, wherein each instance prime is a positive prime number, and wherein p represents a given component class number ranging from 1 to n, and q represents the q-th type of component within the first hardware configuration or the second hardware configuration;retrieving possible class partial secrets, P , wherein: Pp., = [Cp (mod zp„)];extracting possible class primes, ppq, and possible class remainders, <7pq, from the possible class partial secrets, Ppq;solving a set of congruences provided by a permutation of the possible class primes and the possible class remainders to produce a possible secret;and testing the possible secret by decoding a given ciphertext and testing a result of the testing against a corresponding known plaintext;wherein: if the resultant plaintext matches the known plaintext, loading the software product onto the second computer system;and if the resultant plaintext does not match the known plaintext, preventing the software product from being loaded onto the second computer system.
  3. 16
    A computer readable medium having stored thereon computer-executable instructions for performing a method of generating a strong hardware identification (SHWID) for a first computer system having a first hardware configuration, wherein the method comprises:identifying each component class within the first hardware configuration, wherein the number of component classes is equal to n;determining a class product, cp, for each component class;determining a partial secret, Pp, for each component class;and adding the class product, cp, and the partial secret, Pp, for each component class to form n strong class IDs, wherein the n strong class IDs in combination form the strong hardware identification (SHWID) of the first computer system.
  4. 26
    A computer readable medium having stored thereon computer-executable instructions for performing a method of determining whether a software product can be used on a second computer system having a second hardware configuration, wherein the second computer system is identical to or different from the first computer system, wherein the method comprises:identifying the n components classes used to determine the strong hardware identification (SHWID) generated by the method of Claim 16;identifying all instances within each component class of the second hardware configuration;retrieving an identification string that represents each individual component instance;generating instance primes, /p q, for each component instance, wherein each instance prime is a positive prime number, and wherein p represents a given component class number ranging from 1 to n, and q represents the q-th type of component within the first hardware configuration or the second hardware configuration;retrieving possible class partial secrets, Ppq, wherein: p„ = [Cp (mod IM )];extracting possible class primes, ppq, and possible class remainders, <7pq, from the possible class partial secrets, Ppq;solving the set of congruences provided by a permutation of possible class primes and possible class remainders to produce a possible secret;and testing the possible secret by decoding a given ciphertext and testing the result against the corresponding known plaintext;wherein: if the resultant plaintext matches the known plaintext, loading the software product onto the second computer system;and if the resultant plaintext does not match the known plaintext, preventing the software product from being loaded onto the second computer system.
  5. 29
    A computing system containing at least one application module usable on the computing system, wherein the at least one application module comprises application code for performing a method of generating a strong hardware identification (SHWID) for a first computer system having a first hardware configuration, wherein the method comprises:identifying each component class within the first hardware configuration, wherein the number of component classes is equal to «;determining a class product, cp, for each component class;determining a partial secret, Pp, for each component class;and adding the class product. cp, and the partial secret, Pp, for each component class to form n strong class IDs, wherein the n strong class IDs in combination form the strong hardware identification (SHWID) of the first computer system.
  6. 39
    A computing system containing at least one application module usable on the computing system, wherein the at least one application module comprises application code for performing a method of determining whether a software product can be used on a second computer system having a second hardware configuration, wherein the second computer system is identical to or different from the first computer system, wherein the method comprises:identifying the n components classes used to determine the strong hardware identification (SHWID) generated by the method of Claim 29;identifying all instances within each component class of the second hardware configuration;retrieving an identification string that represents each individual component instance;generating instance primes, /pq, for each component instance, wherein each instance prime is a positive prime number, and wherein p represents a given component class number ranging from 1 to «, and q represents the q-th type of component within the first hardware configuration or the second hardware configuration;retrieving possible class partial secrets, Pp q, wherein: Pp., = [Cp (mod iM )];extracting possible class primes, ppq, and possible class remainders, t/p q, from the possible class partial secrets, Pp q;solving the set of congruences provided by a permutation of possible class primes and possible class remainders to produce a possible secret;and testing the possible secret by decoding a given ciphertext and 5 testing the result against the corresponding known plaintext;wherein: if the resultant plaintext matches the known plaintext, loading the software product onto the second computer system;and if the resultant plaintext does not match the known plaintext, 10 preventing the software product from being loaded onto the second computer system.