IP Library › Granted Patent US 12,730,875
Granted Patent B2
US 12,730,875 · App. 18/526,873 · Granted Sep 8, 2026

Systems and methods for software authentication without providing full software disclosure to a software notarizer

Inventor: Christian Martick (Wendisch Rietz, DE)
Assignee: SAP SE
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,875
App. No.
18/526,873
Granted
Sep 8, 2026
Kind
B2
Abstract

Embodiments describe techniques for authenticating software artifacts in a secure manner that does not require the software notarizer accessing or storing any software artifact data. A proof algorithm may be utilized by the software vendor and the software notarizer in generating the disclosure-free notarization certificate. The same proof algorithm may then be utilized by the software consumer during validation of the software artifact. These techniques may improve the software security since access to data from the software artifact is limited to the software vendor and the software consumer.

Claims (44)

1 . A computer-implemented method to generate a notarization certificate for a software artifact performed on a circuit including one or more processors, a bus, and a memory, the computer-implemented method comprising:

defining a plurality of protocol parameters to utilize during notarization, the plurality of protocol parameters including a zero-knowledge proof algorithm configured to verify correctness of the software artifact without revealing internal details thereof, wherein the software artifact comprises software code is partitioned into a plurality of blocks for cryptographic proof operations and a plurality of proof results are received from a software vendor, wherein each proof result is associated with a block from the plurality of blocks;

negotiating, with a software vendor, the plurality of protocol parameters to obtain negotiated protocol parameters, the negotiating comprising performing a multi-round exchange including:

proposing a first zero-knowledge proof algorithm;

receiving vendor feedback as to whether the software vendor accepts the first zero-knowledge proof algorithm, and

selecting a second zero-knowledge proof algorithm and related security constraints based on the vendor feedback;

receiving at least one proof result from the software vendor, the at least one proof result generated using the zero-knowledge proof algorithm, the proof result providing compliance of the software artifact with the security constraints and the negotiated protocol parameters;

validating, by applying the zero-knowledge proof algorithm, the at least one proof result according to a verifier-side execution of the negotiated protocol parameters, and requesting an updated proof result from the software vendor in response to a verification failure; and

bundling, by a certificate-generation module, the at least one proof result after validation to generate the notarization certificate, wherein the notarization certificate that includes the protocol parameters and confirms security or compliance properties of the software artifact without exposing proprietary or sensitive implementation details.

2 . The method as in claim 1 , wherein a proof result is associated with a portion of the software artifact.

3 . The method as in claim 1 , wherein validating the at least one proof result includes:

applying the zero-knowledge proof algorithm to analyze the at least one proof result; and

requesting the software vendor provide another zero-knowledge proof result in response to the analysis.

4 . A system for generating a notarization certificate for a software artifact comprising:

a circuit comprising:

one or more processors;

a memory;

a bus; and

a non-transitory computer-readable medium storing a program executable by the one or more processors, the program comprising sets of instructions for:

defining a plurality of protocol parameters to utilize during notarization, the plurality of protocol parameters including a zero-knowledge proof algorithm configured to verify correctness of the software artifact without revealing internal details thereof, wherein the software artifact comprises software code is partitioned into a plurality of blocks for cryptographic proof operations and a plurality of proof results are received from a software vendor, wherein each proof result is associated with a block from the plurality of blocks;

negotiating, with a software vendor, the plurality of protocol parameters to obtain negotiated protocol parameters, the negotiating comprising performing a multi-round exchange including:

proposing a first zero-knowledge proof algorithm;

receiving vendor feedback as to whether the software vendor accepts the first zero-knowledge proof algorithm, and

selecting a second zero-knowledge proof algorithm and related security constraints based on the vendor feedback;

receiving at least one proof result from the software vendor, the at least one proof result generated using the zero-knowledge proof algorithm, the at least one proof result providing compliance of the software artifact with the security constraints and the negotiated protocol parameters;

validating, by applying the zero-knowledge proof algorithm, the at least one proof result according to a verifier-side execution of the negotiated protocol parameters, and requesting an updated proof result from the software vendor in response to a verification failure; and

bundling, by a certificate-generation module, the at least one proof result after validation to generate the notarization certificate, wherein the notarization certificate that includes the protocol parameters and confirms security or compliance properties of the software artifact without exposing proprietary or sensitive implementation details.

5 . The system of claim 4 , wherein a proof result is associated with a portion of the software artifact.

6 . The system of claim 4 , wherein validating the at least one proof result includes:

applying the zero-knowledge proof algorithm to analyze the at least one proof result; and

requesting the software vendor provide another zero-knowledge proof result in response to the analysis.

7 . A non-transitory computer-readable medium storing a program executable by a circuit including, a bus, and one or more processors, the program for generating a notarization certificate for a software artifact, the program comprising sets of instructions for:

defining a plurality of protocol parameters to utilize during notarization, the plurality of protocol parameters including a zero-knowledge proof algorithm configured to verify correctness of the software artifact without revealing internal details thereof, wherein the software artifact comprises software code is partitioned into a plurality of blocks for cryptographic proof operations and a plurality of proof results are received from a software vendor, wherein each proof result is associated with a block from the plurality of blocks;

negotiating, with a software vendor, the plurality of protocol parameters to obtain negotiated protocol parameters, the negotiating comprising performing a multi-round exchange including:

proposing a first zero-knowledge proof algorithm;

receiving vendor feedback as to whether the software vendor accepts the first zero-knowledge proof algorithm, and

selecting a second zero-knowledge proof algorithm and related security constraints based on the vendor feedback;

receiving at least one proof result from the software vendor, the at least one proof result generated using the zero-knowledge proof algorithm, the at least one proof result providing compliance of the software artifact with the security constraints and the negotiated protocol parameters;

validating, by applying the zero-knowledge proof algorithm, the at least one proof result according to a verifier-side execution of the negotiated protocol parameters, and requesting an updated proof result from the software vendor in response to a verification failure; and

bundling, by a certificate-generation module, the at least one proof result after validation to generate the notarization certificate, wherein the notarization certificate that includes the protocol parameters and confirms security or compliance properties of the software artifact without exposing proprietary or sensitive implementation details.

8 . The non-transitory computer-readable medium of claim 7 , wherein validating the at least one proof result includes:

applying the proof algorithm to analyze the at least one proof result; and

requesting the software vendor provide another proof result in response to the analysis.

9 . The non-transitory computer-readable medium of claim 7 , wherein a proof result is associated with a portion of the software artifact.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2023
From: MARTICK, CHRISTIAN
To: SAP SE
Reel/Frame 065797/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: MARTICK, CHRISTIAN
To: SAP SE
Reel/Frame 065738/0305 →
Continuity (1)
Related Publication 20250181697A1 · Jun 5, 2025
References Cited (23)
US 10505741B1 · Conley · 2019 [cited by examiner]
US 11153074B1 · Nikitas · 2021 [cited by examiner]
US 11423498B2 · Kraemer · 2022 [cited by examiner]
US 20030093678A1 · Bowe · 2003 [cited by examiner]
US 20080010287A1 · Hinton · 2008 [cited by examiner]
US 20120254624A1 · Malkhasyan · 2012 [cited by examiner]
US 20150319671A1 · Nakatsugawa · 2015 [cited by examiner]
US 20170279611A1 · Kraemer · 2017 [cited by examiner]
US 20180285570A1 · Leblanc · 2018 [cited by examiner]
US 20190057115A1 · Liu · 2019 [cited by examiner]
US 20190260574A1 · Shi · 2019 [cited by examiner]
US 20200028945A1 · Allen · 2020 [cited by examiner]
US 20200186506A1 · Shockley · 2020 [cited by examiner]
US 20220029822A1 · Ubbens · 2022 [cited by examiner]
US 20230208654A1 · Chao · 2023 [cited by examiner]
US 20240086503A1 · Chodroff · 2024 [cited by examiner]
EP 2073142A2 · 2009 [cited by examiner]
EP 4290393A1 · 2023 [cited by examiner]
WO WO2019186546A1 · 2019 [cited by examiner]
WO WO2022087239A1 · 2022 [cited by examiner]
WO WO2024102897A1 · 2024 [cited by examiner]
WO WO2024173547A2 · 2024 [cited by examiner]
Michael Backes et al, Achieving Security Despite Compromise using Zero-Knowledge, Saarland University, Germany, pp. 1-69 (Year: 2009). [cited by examiner]