IP Library Granted Patent US 7,747,873
Granted Patent B2
US 7,747,873 · App. 11/072,696 · Granted Jun 29, 2010

Method and apparatus for protecting information and privacy

Assignee: ShieldIP, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,747,873
App. No.
11/072,696
Granted
Jun 29, 2010
Kind
B2
Abstract

A mechanism for the purchase of tags for copies of software ensures that identity of the purchaser of a tag table identifier value included in a purchased tag is not revealed. A mechanism of Call-Ups from the user device to a guardian center ensures that each tag table identifier value appears in only one user device and that the data included in a tag table and other data stored in the user device for the purpose of protecting vendor's and owner's rights in software, cannot be modified.

Claims (54)

1. A computer implemented system for purchasing software comprising:

a supervising program executing on a user device, which is associated with a purchaser, where the integrity of the supervising program on the user device is ensured; and

the supervising program having computer readable instructions that enable a purchaser to purchase software from a vendor while protecting the privacy of the purchaser from the vendor during the purchase by:

creating, on the user device, a data structure including:

an identification of said software; and

a tag table identifier value associated with a tag table in the user's device, the tag table providing information about one or more tags that convey permission to use the software, the tag table identifier value identifying the tag table;

where the tag table identifier value is independent of any identifying information associated with hardware of said user device and where use of the same tag table identifier value on multiple user devices is detectable by a communication protocol using a call-up mechanism;

computing, by said user device, a function value of said data structure using a one-way function, where the tag table identifier value cannot be determined by the vendor;

sending, by said user device, a message to the vendor comprising said function value and said identification of said software, where the tag table identifier is masked by the one-way function to avoid revealing the tag table identifier to the vendor; and

wherein the call-up mechanism includes sending, at some time, by the supervising program from the user device, a call-up message to a guardian center, where the call-up message assists the guardian center in detecting whether another user device is using the same tag table identifier value.

2. The computer implemented system of claim 1 wherein the instructions further enable:

said vendor receiving said message, upon receiving said message, said vendor digitally signing said message and returning said signed message to said user device;

said supervising program on said user device verifying said digital signature on said signed message by use of said vendor's public key; and

said supervising program verifying that said signed message includes said message sent by said user device.

3. The computer implemented system of claim 2 wherein the instructions further enable said supervising program storing a tag for said software in said tag table wherein said tag includes said tag table identifier value, said user device created data structure, and said signed message.

4. The computer implemented system of claim 2 further comprising:

a hash function value of a portion of said software in said identification of software; and

wherein the instructions further enable verifying, by said supervising program, that said hash function value in said identification of said software equals a computed hash function value on said portion of said software.

5. The computer implemented system of claim 1 further comprising a secure communication channel established between said user device and said vendor, the secure communication channel being established before sending said message.

6. The computer implemented system of claim 5 wherein establishing a secure communication channel between said user device and said vendor before sending said message further includes providing an anonymous communication channel for the user device to purchase the software, where the anonymous communication channel prevents the vendor from determining the network identifier of the purchaser's user device.

7. The computer implemented system of claim 1 , wherein said data structure further includes a usage policy and said message further comprises said usage policy.

8. The computer implemented system of claim 1 , wherein said data structure further includes a new randomly chosen value occurring only once, the randomly chosen value known only to the user device.

9. The computer implemented system of claim 1 , wherein said message further includes a proof of payment for said software.

10. The computer implemented system of claim 1 wherein the function value is a hash function value, which is a hash key that is unknown to the vendor.

11. The computer implemented system of claim 1 wherein the integrity of the supervising program is ensured by a watchdog program; and

the watchdog program preventing a user of the user device from changing the supervising program.

12. The computer implemented system of claim 1 wherein the supervising program is part of the user device's operating system.

13. The computer implemented system of claim 1 wherein the call-up mechanism is used in connection with supervising usage of the software.

14. The computer implemented system of claim 1 wherein sending, by said purchaser's user device, a message to the vendor further includes sending the message to the vendor without revealing the purchaser's user device.

15. The computer implemented system of claim 1 wherein a call-up message is sent, periodically, to the guardian center from the user device.

16. The computer implemented system of claim 1 wherein the call-up message is used to prevent a tag table identifier value from being used simultaneously on multiple user devices.

17. An apparatus for purchasing software comprising:

means for enabling a purchaser to purchase software from a vendor while protecting the privacy of the purchaser from the vendor during the purchase by:

means for creating, on a user device associated with the purchaser, a data structure including:

identification of said software; and

a tag table identifier value associated with a tag table in the user's device, the tag table providing information about one or more tags that convey permission to use the software, the tag table identifier value identifying the tag table;

where the tag table identifier value is independent of any identifying information associated with hardware of said user device and where use of the same tag table identifier value on multiple user devices is detectable by a communication protocol using a call-up mechanism;

means for computing, by said user device, a function value of said data structure using a one-way function, where the tag table identifier value cannot be determined by the vendor; and

means for sending, by said user device, a message to the vendor comprising said function value and said identification of said software, where the tag table identifier is masked by the one-way function to avoid revealing the tag table identifier to the vendor; and

the call-up mechanism including:

means for sending, at some time, by the supervising program from the user device, a call-up message to a guardian center; and

means for assisting the guardian center in detecting whether another user device is using the same tag table identifier value.

18. A computer implemented system for purchasing software comprising:

a supervising program executing on a purchaser's user device, where the integrity of the supervising program on the user device is ensured;

the supervising program enabling the user device to purchase software from a vendor while protecting the privacy of the purchaser from the vendor during the purchase by:

creating, on the user device, a data structure including:

a tag table identifier value associated with a tag table in the user's device, the tag table providing information about one or more tags that convey permission to use software,

an identification of said software, where the tag table identifier cannot be determined by the vendor, the tag table identifier value being independent of any identifying information associated with hardware of said user device and where use of the same tag table identifier on value multiple user devices is detectable by a communication protocol using a call-up mechanism;

computing, by said user device, a function value of said data structure using a one-way function, where the tag table identifier value cannot be determined by the vendor; and

sending, by said user device, a message to the vendor said message comprising said function value and said identification of said software, where the tag table identifier is masked by the one-way function to avoid revealing the tag table identifier to the vendor;

an anonymous communication channel for enabling the purchaser to purchase the software, where the anonymous communication channel prevents the vendor from determining the network identifier of the user device;

a one way function value storing a portion of said software in said identification of software;

said supervising program verifying that said one way function value in said identification of said software equals a computed one way function value on said portion of said software; and

wherein the call-up mechanism includes sending, at some time, by the supervising program from the user device, a call-up message to a guardian center, where the call-up message assists the guardian center in detecting whether another user device is using the same tag table identifier value.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Oct 26, 2020
From: JEFFERIES FINANCE LLC
To: RPX CORPORATION
Reel/Frame 054486/0422 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054198/0029 →
PATENT SECURITY AGREEMENT Recorded Oct 23, 2020
From: RPX CLEARINGHOUSE LLC; RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 054244/0566 →
SECURITY INTEREST Recorded Jun 29, 2018
From: RPX CORPORATION
To: JEFFERIES FINANCE LLC
Reel/Frame 046486/0433 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2016
From: IP SOFTWARE AUTHENTICATION SERVICES, LLC
To: RPX CORPORATION
Reel/Frame 038337/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2015
From: SHIELDIP, INC.
To: IP SOFTWARE AUTHENTICATION SERVICES LLC
Reel/Frame 035931/0448 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2014
From: RABIN, MICHAEL O.; SHASHA, DENNIS E.
To: SHIELDIP, INC.
Reel/Frame 033294/0549 →
Continuity (2)
Division 0970607400 · Nov 3, 2000
Related Publication 20050216760A1 · Sep 29, 2005