SWI-Prolog reaches the dongle through the keynub_licdongle pack, whose foreign module loads the SDK’s flat C API at run time, on the first call that needs it, so nothing is linked against the native library and nothing sits in the path of the check that a customer could substitute for something more agreeable. Loading library(keynub_licdongle) needs no native library. SWI-Prolog 8.4 or later, on Windows, Linux and macOS; the pack install builds the foreign module with CMake and a C compiler.
swipl pack install keynub_licdongleCode language: Prolog (prolog)
Reading a License
:- use_module(library(keynub_licdongle)).
license(License) :-
with_dongle(D, % first dongle, or with_dongle([serial(S)], D, Goal)
( dongle_verify_genuine(D), % throws unless genuine
with_session(D, % closed on every exit path
read_record(D, license, License))
)).Code language: Prolog (prolog)
What You Are Protecting
SWI-Prolog software that is sold ships as a saved state or an executable from qsave_program: an expert system, a configuration or scheduling tool, a rules service on a customer’s server. A check that succeeds or fails is one if-then-else in that program, and patching one of those is a beginner exercise.
So the strong pattern is the one to reach for: the data the program needs only exists when the dongle is present.
% Weak: one patched branch.
( dongle_genuine(D) -> true ; halt(1) )
% Strong: the parameters only exist with the dongle present.
parameters(D, Parameters) :-
sealed_blob_shipped_with_your_program(Sealed),
with_session(D,
( app_decrypt(D, Sealed, Plain),
decode_parameters(Plain, Parameters) )).Code language: Prolog (prolog)
Every failed call throws error(keynub_error(Status, Code, Operation, Detail), _) with the status as an atom (no_device, not_genuine, auth_required, …), and a library that cannot be loaded throws error(keynub_library_error(Message), _); print_message/2 prints both, and dongle_genuine/1 fails closed. with_dongle and with_session call their goal once and close the dongle and the session on every exit path, exceptions included. The pack calls the SDK’s flat companion API, the one designed for foreign function interfaces: integer handles and buffers, no hand-written structure layouts.
Shipping the Native Library with a SWI-Prolog Application
The keynub_licdongle pack’s foreign module loads the SDK’s flat API at run time, on the first call that needs it, so nothing is linked against the native library. swipl pack install builds that module with CMake and a C compiler and runs the unit tests: on Windows it needs gcc (MinGW-w64), cmake and ninja on the PATH, on Linux and macOS cmake and the system C compiler. A program takes keynub_licdongle_flat for its platform in natives/<platform>/ beside it, or names it with set_library_path/1 or KEYNUB_LICDONGLE_FLAT_LIBRARY.
The prebuilt libraries for every platform are in the SDK repository’s natives/<platform>/ folder, with a SHA-256 manifest: Windows x64, x86 and ARM64, Linux x86_64 and aarch64, and universal macOS binaries for Intel and Apple silicon. On Linux, install the udev rule from NATIVES.md once, so that ordinary users may open the device.
Questions SWI-Prolog Developers Ask
Which SWI-Prolog Versions Does the Pack Support?
SWI-Prolog 8.4 and later, on Windows, Linux and macOS.
How Do I Install the SWI-Prolog Pack?
swipl pack install keynub_licdongle installs it from the SWI-Prolog pack list; from a clone of the SDK repository, give the pack folder as a file:// URL instead. The install builds the foreign module with CMake and a C compiler and runs the unit tests, which need neither the native library nor a dongle.
Does a SWI-Prolog Application Need Administrator Rights to Talk to the Dongle?
No, and no driver either: the dongle is a USB HID device that the operating systems handle with their built-in class drivers. On Linux, install the shipped udev rule once so that ordinary users may open it; without the rule the SDK reports access denied and names the cause in its error detail.
Does a SWI-Prolog License Check Need an Internet Connection?
No. Verification is a local exchange between your program and the dongle over USB: the SDK checks the dongle’s certificate chain to KeyNub’s root and runs a live challenge-response. There is no activation server and no account, so the check works on air-gapped machines.
Who Can Read the License Records on a Dongle?
Anyone holding the dongle: a program opens a session and reads records, and can decrypt data sealed for that dongle. Writing records, erasing them and incrementing counters need your write key. What the dongle guarantees is that none of it is available without the dongle present.
Can a License Written from SWI-Prolog Be Read by a Program in Another Language?
Yes. Every binding drives the same core library and the same dongle, and records and sealed data are language-neutral bytes. Your issuing tool can be written in one language and your product in another.
Code
Runnable sample: prolog/verify_and_read.pl. Binding source: bindings/prolog. Both are Apache-2.0, in the public SDK repository; the prebuilt native libraries are in the repository’s natives/ folder, one per platform.
All supported languages · All industries · Buy a KeyNub · Ask us something