Bidirectional authentication software license dynamic generation and verification method based on national cryptographic algorithm

Through the two-way authentication and dynamic license generation process of the Guoxin algorithm, the problem of easy key cracking and insufficient hardware binding in traditional software authorization is solved, and high security and flexible software authorization management is achieved.

CN120342612APending Publication Date: 2025-07-18JIANGSU YOULIKA NEW ENERGY TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510749432.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-06
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In traditional software offline authorization methods, the key is easily reverse cracked, one-way verification cannot prevent the client from being faked, and the license lacks hardware binding capabilities, resulting in insufficient software copyright protection.

Method used

The State Secret algorithm is used for two-way authentication, and through hashing operations, encryption, random number obfuscation and verification processes, software licenses are dynamically generated and verified, and key exchange and encryption and decryption are used for key exchange and encryption to realize hardware binding and identity authentication.

Benefits of technology

Improves the security and flexibility of software licensing, enhances the ability to resist attacks, prevents licenses from being forged and copied, and is suitable for a variety of devices and scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342612A_ABST
    Figure CN120342612A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic generation and verification system for a bidirectional authentication software license based on a national cryptographic algorithm, and the system comprises a hash unit which is used for carrying out the hash operation of a machine code to obtain a machine code hash value, and carrying out the verification of the hash code and the original data of the machine code; the encryption unit is used for encrypting the client information at the client to obtain client encrypted information; according to the random number generation and confusion unit, client software obtains a random number through a random number seed and a random number generator, and a software service provider side carries out confusion operation on the random number through a confusion algorithm to obtain a random number confusion value; and the verification unit is used for carrying out reverse obfuscation algorithm on the random number obfuscation value by the client, carrying out comparison verification on the random number obfuscation value and a random numerical value transmitted to a software service provider, reading the machine code, calculating hash, and carrying out hash verification on the machine code abstract in the license. The method has the advantages that the safety performance is high, the anti-attack capability is improved, and the flexibility of software offline authorization is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software authorization, and in particular to a method for dynamically generating and verifying a two-way authentication software license based on a national secret algorithm. Background Art

[0002] A software license is a contract between the developer or team that creates the source code and the end user of the software. In the traditional offline software authorization method, the software service provider encrypts the software information to generate a license file when releasing the software, and decrypts and verifies the license file to confirm the authorization information after the client software is started. The encryption of traditional offline authorization uses AES or RSA encryption algorithms, and the license is decrypted and verified through the decryption key fixed in the software, realizing offline authorization of the software and protecting the software copyright of the software service provider.

[0003] Although the existing technology meets the needs of offline software authorization to a certain extent, the following problems still exist:

[0004] The license is decrypted using the RSA / AES key fixed in the software. Once the key is reverse cracked, all licenses can be forged and replaced;

[0005] Traditional solutions use a one-way authentication and authorization solution, which means that usually only the authorization software verifies the customer license. Once the authorization software successfully verifies the distribution license in the customer device, it can be used. When encountering a third party pretending to be a client, effective authentication cannot be performed.

[0006] The license files in traditional offline authorization lack the ability to bind to hardware. Once the software is reverse cracked, the license becomes invalid and the control of authorization is lost. Summary of the invention

[0007] The purpose of the present invention is to provide a method for dynamically generating and verifying a two-way authentication software license based on a national secret algorithm, which has the advantages of high security performance, improved anti-attack capability, and improved flexibility of software offline authorization.

[0008] The above technical objectives of the present invention are achieved through the following technical solutions:

[0009] A method for dynamically generating and verifying a two-way authentication software license based on a national secret algorithm, including a dynamic generation and verification system for a two-way authentication software license based on a national secret algorithm;

[0010] The two-way authentication software license dynamic generation and verification system based on the national secret algorithm includes:

[0011] A hash unit is used to perform a hash operation on the machine code to obtain a machine code hash value, and to verify the hash code and the original data of the machine code to obtain a verification result;

[0012] An encryption unit encrypts customer information at the client side to obtain encrypted customer information and decrypts customer information at the software service provider side to obtain customer information;

[0013] A random number generation and obfuscation unit. The client software obtains a random number through a random number seed and a random number generator, and the software service provider side performs an obfuscation operation on the random number through an obfuscation algorithm to obtain a random number obfuscation value;

[0014] A verification unit performs an inverse obfuscation algorithm on the random number obfuscation value at the client side, compares and verifies it with the random number value transmitted to the software service provider, and reads and calculates the hash of the machine code and performs a hash verification with the machine code digest in the license;

[0015] A dynamic generation and verification method for a two-way authentication software license based on the national cryptographic algorithm includes the following operation steps:

[0016] Step 1: When the software service provider distributes software to a customer, it obtains the customer's public key A, private key A, and customer identifier through the national cryptographic algorithm. The private key A and the customer identifier use the customer ID as the primary key and are stored in the service provider's database. The public key A is distributed to the customer together with the software;

[0017] Step 2: After the software client of the customer determines that the license verification fails, the client generates a pair of temporary public key B, private key B, random number, and timestamp through the national cryptographic algorithm SM2. The temporary private key B and the customer's public key A are calculated through the national cryptographic algorithm SM2 to obtain a shared key C. A part of the shared key C is intercepted according to the rule as the key X of the national cryptographic algorithm SM4;

[0018] The customer reads the machine unique code of the device on which the software runs at the client side and calculates the hash through the national cryptographic algorithm SM3 to obtain the machine code hash value;

[0019] Step 3: The machine code hash value, customer identifier, random number, and timestamp are encrypted through the national cryptographic algorithm SM4 with the key X to generate encrypted information, and the encrypted information, public key B, and customer ID are sent to the software service provider together;

[0020] Step 4: The software service provider finds the customer's private key A through the customer ID, generates a shared key D through the national cryptographic algorithm SM2 with the received public key B, a part of the shared key D is used as the key Y, and the key Y is decrypted through the national cryptographic algorithm SM4 to obtain the customer's machine code hash value, random number, timestamp information, and customer identifier and perform verification;

[0021] The software service provider compares and verifies the decrypted customer identifier with the service provider's database and verifies the validity of the timestamp information;

[0022] Step 5: The software service provider performs XOR confusion on the random number, adds the decrypted information to the authorization period and the service provider's ID, obtains the license file through the national secret algorithm SM4 key, and sends it to the customer;

[0023] Step 8: The client uses the national secret algorithm SM4 to decrypt the received license file with key X to obtain the machine code hash value, authorization period, timestamp information, service provider identification, and random number;

[0024] The client verifies and compares the random number, timestamp information, and service provider ID;

[0025] The client calculates the current machine code hash value using the national encryption algorithm SM3 and compares it with the decrypted machine code hash value;

[0026] The client compares the authorization period with the current date;

[0027] The client obtains the authorization result.

[0028] The preferred solutions are as follows:

[0029] Preferably: when the license is reversely authenticated by this method, the license file and public key B are sent back to the software service provider, and the software service provider re-decrypts and verifies the validity of the service provider identification and the authorization period.

[0030] Preferably: the software service provider uses a fixed value when performing XOR confusion on the random number, and the fixed value is solidified in the software code distribution storage on the client to ensure its security.

[0031] Preferably: the machine code of the device on which the software runs includes but is not limited to CPUID, network card number, and hardware SN code.

[0032] Preferably: each time the client applies for a license, the public key B, private key B, random number, and timestamp information generated are all inconsistent and are valid only once.

[0033] In summary, the present invention has the following beneficial effects:

[0034] 1. High security performance. Through two-way identity authentication, customers and service providers can exchange keys with the national secret algorithm SM2 to verify each other's identities, preventing man-in-the-middle attacks such as counterfeiting service providers or malicious clients. Through dynamic key negotiation, a temporary key pair is generated for each license request, and the shared key is limited to a single session to achieve forward secrecy. Through hardware binding and anti-copying, the license is strongly bound to the device machine code hash value to prevent the license from being copied to other devices. Compared with ordinary MAC address binding: the machine code is generated based on multiple hardware parameters and is more difficult to forge.

[0035] 2. The anti - attack ability is improved. The ability to resist man - in - the - middle attacks is enhanced through SM2 two - way authentication and key identity binding; the ability to resist replay attacks is enhanced through the confusion check of timestamps and random numbers; the possibility of static keys being easily leaked and cracked in the traditional method is reduced by saving the temporary key pair and the root key in the database, improving the security of the overall solution;

[0036] 3. The flexibility of software offline authorization is improved. The dynamic variability of software authorization is increased through timestamps and authorization periods; in the current invention, the national cryptography SM2 is used to implement public - key exchange, and SM4 is used for encryption and decryption, which improves the execution efficiency of encryption and decryption, enabling the current solution to adapt to more lightweight devices;

[0037] In summary, the method for dynamically generating and verifying a two - way authentication software license based on national cryptography algorithms proposed by the present invention significantly improves the software authorization efficiency, provides a highly secure, compliant, and efficient license management solution for fields such as software copyright protection and Internet of Things security, and especially provides a convenient and fast solution for government and enterprise customers with strict requirements for autonomy and controllability. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 It is the overall interaction flowchart of the method and system for dynamically generating and verifying a two - way authentication software license based on national cryptography algorithms in the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] The following further elaborates on the present invention with reference to the accompanying drawings.

[0040] The system for dynamically generating and verifying a two - way authentication software license based on national cryptography algorithms includes,

[0041] A hash unit, which is used to perform a hash operation on the machine code to obtain a machine - code hash value, and to verify the hash code and the original machine - code data to obtain a verification result;

[0042] An encryption unit, which encrypts customer information at the client side to obtain encrypted customer information, and decrypts customer information at the software service provider side to obtain customer information;

[0043] A random - number generation and confusion unit. The client software obtains a random number through a random - number seed and a random - number generator, and the software service provider side performs a confusion operation on the random number through a confusion algorithm to obtain a random - number confusion value;

[0044] A verification unit. The client performs an inverse confusion algorithm on the random - number confusion value, compares and verifies it with the random - number value transmitted to the software service provider, and reads and calculates the hash of the machine code and performs a hash verification on the machine - code digest in the license.

[0045] Method for dynamically generating and verifying software license based on national cryptographic algorithm, as Figure 1 shown, including the following operation steps,

[0046] Step 1: When the software service provider distributes software to customers, the public key A, private key A, and customer identifier of the customer are obtained through the national cryptographic algorithm. The private key A and the customer identifier use the customer ID as the primary key and are stored in the service provider's database. The public key A is distributed to the customer together with the software;

[0047] Step 2: After the software client of the customer determines that the license verification fails, the client generates a pair of temporary public key B, private key B, random number, and timestamp through the national cryptographic algorithm SM2. The temporary private key B and the public key A of the customer are calculated through the national cryptographic algorithm SM2 to obtain the shared key C. A part of the shared key C is intercepted according to the rule as the key X of the national cryptographic algorithm SM4;

[0048] The customer reads the machine unique code of the device where the software runs on the client, calculates the hash through the national cryptographic algorithm SM3 to obtain the machine code hash value;

[0049] Step 3: The machine code hash value, customer identifier, random number, and timestamp are encrypted through the national cryptographic algorithm SM4 by the key X to generate the encrypted information. The encrypted information, public key B, and customer ID are sent to the software service provider together;

[0050] Step 4: The software service provider finds the private key A of the customer through the customer ID, generates the shared key D through the national cryptographic algorithm SM2 with the received public key B together. A part of the shared key D is used as the key Y, and the key Y is decrypted through the national cryptographic algorithm SM4 to obtain the customer's machine code hash value, random number, timestamp information, and customer identifier and perform verification;

[0051] The software service provider compares and verifies the decrypted customer identifier with the service provider's database, and verifies the validity of the timestamp information;

[0052] Step 5: The software service provider performs exclusive OR confusion on the random number, adds the decrypted information with the authorization period and service provider identifier, and obtains the license file through the national cryptographic algorithm SM4 key and sends it to the customer;

[0053] Step 8: The client decrypts the received license file through the key X through the national cryptographic algorithm SM4 to obtain the machine code hash value, authorization period, timestamp information, service provider identifier, and random number;

[0054] The client verifies and compares the random number, timestamp information, and service provider identifier;

[0055] The client calculates the current machine code hash value using the national encryption algorithm SM3 and compares it with the decrypted machine code hash value;

[0056] The client compares the authorization period with the current date;

[0057] The client obtains the authorization result.

[0058] When the license is reversely verified by this method, the license file and public key B are sent back to the software service provider, and the software service provider re-decrypts and verifies the validity of the service provider identification and authorization period.

[0059] The software service provider uses a fixed value when XORing random numbers. The fixed value is solidified in the software code distribution storage on the client to ensure its security.

[0060] The machine code of the device on which the software runs includes but is not limited to CPUID, network card number, and hardware SN code.

[0061] Each time the client applies for a license, the public key B, private key B, random number, and timestamp information generated are inconsistent and are valid only once.

[0062] Specific application scenarios of the present invention:

[0063] Software copyright protection and license management: Commercial software, such as CAD and EDA tools, can use this patent to implement hardware-bound licenses to prevent illegal copying. When customers install the software, computer information is automatically collected to generate customer authentication information, and the server dynamically issues hardware-bound licenses, such as per-device authorization for high-value industrial design software such as AutoCAD and ANSYS.

[0064] Cloud computing and SaaS services: Cloud service providers generate temporary licenses for virtual machine instances and bind virtual hardware fingerprints, such as vCPU / virtual disk IDs. Through SM2 key exchange, two-way authentication between tenants and cloud platforms is achieved, and Alibaba Cloud / Tencent Cloud’s national secret compliance cloud host authorization access control is implemented.

[0065] IoT device authentication: The device is pre-set with an SM2 key pair when it leaves the factory. When activated, it negotiates a shared key with the server to encrypt the firmware update package to prevent unauthorized devices from accessing, such as smart meters and vehicle terminals. State Grid smart meter firmware signature and encryption upgrade.

[0066] Mobile APP anti-piracy: Verify device fingerprints when the APP is started, such as the SM3 hash of the Android ID + CPU serial number, and dynamically request a license. White box SM4 protects the decryption key in memory, an anti-cracking solution for domestic mobile games.

[0067] Industrial Control System (ICS) Security: Industrial control devices such as PLCs and DCSs ensure the legitimacy of the source of operation instructions through SM2 mutual authentication. The license contains the validity period of the operation permission, such as "Only debugging is allowed in January 2024".

[0068] Digital Medical Device Authorization: Medical imaging devices, such as CT scanners, issue licenses based on the number of scans and are encrypted and stored in the HSM.

[0069] The service provider updates the authorization quota through SM4 encryption.

[0070] This specific embodiment is only an explanation of the present invention and does not limit the present invention. After reading this specification, those skilled in the art can make modifications to this embodiment without creative contributions as needed, but as long as it is within the scope of the claims of the present invention, it is protected by the patent law.

Claims

1. A method for dynamically generating and verifying a two-way authentication software license based on national cryptographic algorithms, characterized in that: Include a two-way authentication software license dynamic generation and verification system based on national cryptographic algorithms; The two-way authentication software license dynamic generation and verification system based on national cryptographic algorithms includes: A hash unit, which is used to perform a hash operation on the machine code to obtain a machine code hash value, and verify the hash code and the original machine code data to obtain a verification result; An encryption unit, which encrypts customer information on the client side to obtain encrypted customer information, and decrypts customer information on the software service provider side to obtain customer information; A random number generation and obfuscation unit. The client software obtains a random number through a random number seed and a random number generator, and the software service provider side performs an obfuscation operation on the random number through an obfuscation algorithm to obtain a random number obfuscation value; A verification unit. The client performs an inverse obfuscation algorithm on the random number obfuscation value, compares and verifies it with the random number value transmitted to the software service provider, reads and calculates the hash of the machine code, and performs a hash verification on the machine code digest in the license; A two-way authentication software license dynamic generation and verification method based on national cryptographic algorithms includes the following operation steps: Step 1: When the software service provider distributes software to customers, it obtains the customer's public key A, private key A, and customer identifier through national cryptographic algorithms. The private key A and the customer identifier use the customer ID as the primary key and are stored in the service provider's database. The public key A is distributed to the customer together with the software; Step 2: After the software client of the customer determines that the license verification fails, the client generates a pair of temporary public key B, private key B, random number, and timestamp through the national cryptographic algorithm SM2. The temporary private key B and the customer's public key A are calculated through the national cryptographic algorithm SM2 to obtain a shared key C. A part of the shared key C is intercepted according to the rule as the key X of the national cryptographic algorithm SM4; The customer calculates the hash of the machine unique code read by the device where the software runs on the client side through the national cryptographic algorithm SM3 to obtain the machine code hash value; Step 3: The machine code hash value, customer identifier, random number, and timestamp are encrypted through the national cryptographic algorithm SM4 using the key X to generate encrypted information. The encrypted information, public key B, and customer ID are sent to the software service provider together; Step 4: The software service provider finds the customer's private key A through the customer ID, generates a shared key D by using the customer's private key A and the received public key B through the national cryptographic algorithm SM2. A part of the shared key D is used as the key Y, and the key Y is decrypted through the national cryptographic algorithm SM4 algorithm to obtain the customer's machine code hash value, random number, timestamp information, and customer identifier, and perform verification; The software service provider compares and verifies the decrypted customer identifier with the service provider's database, and verifies the validity of the timestamp information; Step 5: The software service provider performs an exclusive OR obfuscation on the random number, adds the decrypted information, authorization period, and service provider identifier, and obtains a license file through the national cryptographic algorithm SM4 key and sends it to the customer; Step 8: The client decrypts the received license file through the national cryptographic algorithm SM4 using the key X to obtain the machine code hash value, authorization period, timestamp information, service provider identifier, and random number; The client verifies and compares the random number, timestamp information, and service provider identifier; The client calculates the current machine code hash value using the national encryption algorithm SM3 and compares it with the decrypted machine code hash value; The client compares the authorization period with the current date; The client obtains the authorization result.

2. The method for dynamically generating and verifying a two-way authentication software license based on the national cryptographic algorithm according to claim 1, wherein: When the license is reversely verified by this method, the license file and public key B are sent back to the software service provider, and the software service provider re-decrypts and verifies the validity of the service provider identification and authorization period.

3. The method for dynamically generating and verifying a two-way authentication software license based on the national cryptographic algorithm according to claim 1, characterized in that: The software service provider uses a fixed value when XORing random numbers. The fixed value is solidified in the software code distribution storage on the client to ensure its security.

4. The method for dynamically generating and verifying a two-way authentication software license based on the national cryptographic algorithm according to claim 1, characterized in that: The machine code of the device on which the software runs includes but is not limited to CPUID, network card number, and hardware SN code.

5. The method for dynamically generating and verifying a two-way authentication software license based on the national cryptographic algorithm according to claim 1, characterized in that: Each time the client applies for a license, the public key B, private key B, random number, and timestamp information generated are inconsistent and are valid only once.

Citation Information

Cited By

  • Software upgrading method and device and related equipment

    CN120751366A