IP Library Granted Patent US 8,984,293
Granted Patent B2
US 8,984,293 · App. 12/950,777 · Granted Mar 17, 2015

Secure software product identifier for product validation and activation

Inventors: Thomas J. Layson (Monroe, WA); Caglar Gunyakti (Redmond, WA); Tarik Soulami (Redmond, WA); Kalin Georgiev Toshev (Redmond, WA); Jeffrey Paul Harker (Snoqualmie, WA); Josh D. Benaloh (Redmond, WA)
Assignee: Microsoft Corporation
G06F21/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,984,293
App. No.
12/950,777
Granted
Mar 17, 2015
Kind
B2
Abstract

Systems, methods, and apparatus for generating and validating product keys. In some embodiments, a product key includes security information and identification information identifying at least one copy of a software product. The identifying information may be used to access validation information from at least one source other than the product key, and the validation information may be used to process the identification information and the security information to determine whether the product key is valid. In some further embodiments, the security information includes a first portion to be processed by a first validation authority using first validation information and a second portion to be processed by a second validation authority using second validation information, wherein the second validation information is stored separately from the first validation information.

Claims (71)

1. A system for validating product keys, comprising:

at least one memory and at least one processor that are respectively configured to store and execute instructions that:

receive a product key from an activation process of a remote computing device for a software product, wherein the product key includes:

an identifier within the product key, wherein the identifier serves as an indication of a cryptographic algorithm and/or a parameter for the cryptographic algorithm that is to be used in validating the received product key; and

security information associated with the identifier within the product key, wherein the security information includes at least a first security value and a second security value;

determine, based at least in part on the identifier within the product key, validation information from at least one source other than the product key, wherein the validation information defines at least part of a process for validating the product key;

execute the process for validating the product key according to the determined validation information, wherein the process for validating the product key includes:

a determination of whether the first security value is valid;

in response to a determination that the first security value is valid, a determination of whether the second security value is to be validated; and

in response to a determination that the second security value is to be validated, at least a partially facilitation of validation of the second security value; and

transmit an indication of an outcome of the process to the remote computing device.

2. The system of claim 1 , wherein the validation of the second security value is performed by at least one other processor.

3. The system of claim 2 , wherein the validation of the second security value is at least partially based on the identifier within the product key.

4. The system of claim 1 , wherein the identifier comprises a serial number associated with the software product and additional identification information that is different from the serial number, and wherein the at least one memory and at least one processor are further configured to store and execute instructions that:

determine the validation information based at least in part on the additional identification information from the at least one source other than the product key.

5. The system of claim 4 , wherein the additional identification information identifies at least one item selected from a group consisting of:

a type of the software product;

an edition or version of the software product;

a family of software products to which the software product is associated; and

a channel via which the software product is distributed.

6. A method for generating product keys with at least one processor, the method comprising:

determining identification information for a product key, the identification information including an identification of an associated software product and an indication of a cryptographic algorithm and/or a parameter for the cryptographic algorithm that is to be used in validating the product key;

generating security information associated with the identification information, the security information including at least:

a first security value that is to be validated by a first validation process; and

a second security value for selective validation according to a second validation process;

combining at least the first security value, the second security value, and the identification information into the product key; and

storing, in at least one storage device, validation information in association with at least some of the identification information, the validation information for use in processing the security information to validate the product key.

7. The method of claim 6 , wherein

the first security value and the second security value are separately accessible from the at least one storage device.

8. The method of claim 6 , wherein generating the security information comprises:

generating at least one hash value based on at least a portion of the identification information, and wherein the validation information comprises the at least one hash value.

9. The method of claim 6 , wherein the generating the security information comprises:

encrypting at least a portion of the identification information using at least one encryption algorithm and at least one secret key, and wherein the validation information comprises an identification of the at least one encryption algorithm and the at least one secret key.

10. The method of claim 6 , wherein the identification information comprises a serial number associated with the software product and additional identification information that is different from the serial number, and wherein the validation information is stored in association with the additional identification information.

11. The method of claim 6 , wherein the additional identification information identifies at least one item selected from a group consisting of:

a type of the software product;

an edition or version of the software product;

a family of software products that includes the software product; and

a channel via which the software product is distributed.

12. The system of claim 1 , wherein the validation information comprises at least one hash value generated based at least in part on the identifier, and wherein the process for validating the product key includes:

a comparison of the at least one hash value with the security information; and

a determination of the validity of the product key based at least in part on an output of the comparison.

13. The system of claim 1 , wherein the validation information comprises an identification of at least one encryption algorithm and at least one secret key, and wherein the process for validating the product key includes:

encrypting at least a portion of the identification information using the at least one encryption algorithm and the at least one secret key to obtain at least one ciphertext; and

determining whether the security information matches the at least one ciphertext.

14. A method executed at least in part by at least one processor to validate product keys, comprising:

receiving a product key from an activation process of a remote computing device for a software product, wherein the product key includes:

an identifier of the software product, wherein the identifier identifies the software product and also defines at least one cryptographic algorithm and/or parameter for the cryptographic algorithm, wherein the at least one cryptographic algorithm and/or parameter for the cryptographic algorithm is for use in validating the product key; and

security information that includes an encrypted version of at least a portion of the identifier, wherein the security information includes at least a first security value and a second security value;

accessing based at least in part on the identifier of the software product validation information from at least one source other than the product key, wherein the validation information defines at least part of a process for validating the product key;

validating the product key using at least the validation information to process the security information, including:

determining whether the first security value is valid;

in response to determining that the first security value is valid, determining whether the second security value is to be validated; and

in response to determining that the second security value is to be validated, at least partially facilitating validation of the second security value; and

transmitting an indication of an outcome of the validation of the product key to the remote computing device, wherein the indication includes either an authorization to activate the software product or a denial of authorization to activate the software product.

15. The method of claim 14 , wherein the product key also includes additional security information, and wherein the method further comprises:

determining whether the validation of the product key is to be subjected to further validation; and

if it is determined that the product key is to be subjected to further validation, transmitting the additional security information to at least one other processor for further validation.

16. The method of claim 15 , wherein the further validation include validating the additional security information based at least in part on the identifier.

17. The method of claim 14 , wherein the identifier comprises a serial number associated with the software product and additional identification information that is different from the serial number, and wherein accessing the validation information includes:

determining the validation information based at least in part on the additional identification information.

18. The method of claim 17 , wherein the additional identification information identifies at least one item selected from a group consisting of:

a type of the software product;

an edition or version of the software product;

a family of software products including the software product; and

a channel via which the software product is distributed.

19. The method of claim 14 , wherein the validation information comprises at least one hash value generated based at least in part on the identifier and a secret key, and wherein validating the product key includes:

comparing the at least one hash value and the security information.

20. The method of claim 14 , wherein the validation information comprises an identification of at least one decryption algorithm and at least one secret key, and wherein validating the product key includes:

decrypting at least a portion of the security information using the at least one decryption algorithm and the at least one secret key to obtain decrypted information; and

determining whether the decrypted information matches the identifier.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2010
From: LAYSON, THOMAS J.; GUNYAKTI, CAGLAR; SOULAMI, TARIK; TOSHEV, KALIN GEORGIEV; HARKER, JEFFREY PAUL; BENALOH, JOSH D.
To: MICROSOFT CORPORATION
Reel/Frame 025382/0725 →
Continuity (1)
Related Publication 20120131349A1 · May 24, 2012