US2010318789A1PendingUtilityA1

Method and system for license management

Individually held — no corporate assignee on recordPriority: Sep 13, 2004Filed: Mar 19, 2010Published: Dec 16, 2010
Est. expirySep 13, 2024(expired)· nominal 20-yr term from priority
H04L 63/0823H04L 2209/56H04L 9/3263H04L 63/0428G06F 21/105H04L 63/104
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

System and method are disclosed for securing and managing individual end-user platforms as part of an enterprise network. The method/system of the invention has three main components: a security module, a manager appliance, and a console appliance. The security module enforces the enterprise licenses and security policies for the end-user platforms while the manager appliance provides secure, centralized communication with, and oversight of, the security module. The console appliance allows an administrator to access the manager appliance for purposes of monitoring and changing the licenses. Security is established and maintained through an innovative use of data encryption and authentication procedures. The use of these procedures allows the appliances to be uniquely identified to one another, which in turn provides a way to dynamically create unique identifiers for the security modules. These various components together form an infrastructure over the enterprise network to securely manage the end-user platforms.

Claims

exact text as granted — not AI-modified
1 - 26 . (canceled) 
     
     
         27 . A method for authenticating a plurality of computing platforms, the method comprising:
 generating platform level authentication information;   using said platform level authentication information to generate appliance level authentication information, said appliance level authentication information unique to each appliance and allowing all appliances to authenticate one another;   using at least a portion of said appliance level authentication information to generate client level authentication information, said client level authentication information unique to each end-user platform and allowing said appliances to authenticate said end-user platforms;   generating administration level authentication information for allowing an administrator to be authenticated by said appliances; and   using said administration level authentication information to generate electronic token level authentication information, said electronic token level authentication information unique to an electronic token used by an administrator for logging in to said appliances, said electronic token level authentication information allowing said appliances to authenticate said administrator.   
     
     
         28 . The method of  claim 27 , wherein the generation of administration level authentication information comprises storing an administrator certificate, said administrator certificate unique to the administrator and digitally signed via a private key unique to an administrator-generation certificate. 
     
     
         29 . The method according to  claim 27 , further comprising generating vendor level authentication information for allowing a vendor to authenticate said vendor's software products. 
     
     
         30 . The method according to  claim 29 , further comprising using said vendor level authentication information to generate product level authentication information, said product level authentication information unique to a software for verifying that said software is not corrupted. 
     
     
         31 . The method according to  claim 28 , further comprising using said vendor level authentication information to generate licensing level authentication information, said licensing level authentication information unique to an appliance for verifying that a software is authorized to be used by said appliance. 
     
     
         32 . The method according to  claim 28 , further comprising using said vendor level authentication information to generate maintenance level authentication information, said maintenance level authentication information unique to a software for verifying that said software is authorized to be maintained. 
     
     
         33 . The method according to  claim 27 , further comprising generating root level authentication, said root level authentication information being self-authenticating and usable to generate said platform level authentication information. 
     
     
         34 . The method according to  claim 27 , wherein all authentication information is in the form of digital certificates. 
     
     
         35 . A method of establishing a secure environment for an end-user platform and a system manager usable to manage the end-user platform, comprising:
 storing manager authentication information on the system manager, the manager authentication information unique to the system manager;   generating client authentication information on the system manager for the end-user platform, the client authentication information unique to the end-user platform and operable to be authenticated via the manager authentication information;   transferring the client authentication information from the system manager to the end-user platform;   storing vendor-generation authentication information on the system manager;   storing vendor authentication information, the vendor authentication information unique to a software vendor and operable to be authenticated via the vendor-generation authentication information;   generating license authentication information on the system manager, the license authentication information unique to an authorization of use of a software of the software vendor on a specifically-identified appliance, the software stored on the system manager, the license authentication information operable to be authenticated via the vendor authentication information;   wherein the specifically-identified appliance is at least one of the system manager and the end-user platform;   verifying that the software is licensed for use on the at least one of the system manager and the end-user platform, the verification comprising comparing the license authentication information to at least one of the manager authentication information and the client authentication information; and   wherein the system manager is resident on one or more computers having at least a processor and memory, the method being performed by the one or more computers.   
     
     
         36 . The method according to  claim 35 , further comprising loading installation authentication information on the end-user platform for allowing the system manager to verify that the end-user platform has been designated to be managed from the system manager. 
     
     
         37 . The method according to  claim 36 , wherein the manager authentication information and the installation authentication information are derived from a common source of authentication information. 
     
     
         38 . The method according to  claim 35 , further comprising storing console authentication information on a console operable to access the system manager, the console authentication information unique to the console for allowing the system manager to authenticate the console. 
     
     
         39 . The method according to  claim 38 , further comprising allowing the console to authenticate the system manager using the manager authentication information. 
     
     
         40 . The method according to  claim 35 , further comprising storing product authentication information on the system manager, the product authentication information operable to be authenticated via the vendor authentication information, the product authentication information unique to the software stored on the system manager, the product authentication information allowing the system manager to verify that the software stored on the system manager is not corrupted. 
     
     
         41 . The method according to  claim 40 , wherein the product authentication information further allows the system manager to verify that the software running in a memory of the system manager is not corrupted. 
     
     
         42 . The method according to  claim 35 , further comprising wherein the license authentication information comprises manager-license authentication information and the at least one of the system manager and the end-user platform comprises the system manager. 
     
     
         43 . The method according to  claim 35 , further comprising:
 wherein the license authentication information includes information specifying one or more software to be managed by the system manager;   transferring the license authentication information to the end-user platform; and   wherein the at least one of the system manager and the end-user platform comprises the end-user platform.   
     
     
         44 . The method according to  claim 42 , wherein the software includes one or more of the following: application files, data files, audio files, image files, video files. 
     
     
         45 . The method according to  claim 35 , further comprising storing manager-maintenance authentication information on the system manager, the manager-maintenance authentication information operable to be authenticated via the vendor authentication information, the manager-maintenance authentication information uniquely identifying the software and allowing the system manager to verify that the software is authorized for maintenance on the system manager. 
     
     
         46 . The method according to  claim 45 , wherein the manager-maintenance authentication information includes information specifying one or more software authorized to be maintained via the system manager, further comprising generating an end-user platform maintenance authentication information for the one or more software authorized to be maintained and transferring the end-user platform maintenance authentication information to the end-user platform.

Join the waitlist — get patent alerts

Track US2010318789A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.