Software and host authorization method and system based on intelligent password key
By generating and encrypting host fingerprint information and combining it with a smart password key (Ukey) for hardware binding and authentication, the low security and complexity of existing software authorization methods are resolved, achieving highly secure, simplified processes, and offline-available software authorization.
Patent Information
- Application Number
- CN202510819059.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-23
AI Technical Summary
Existing software authorization methods have the problems of low security, easy piracy and duplication, and cumbersome authorization process, especially inconvenient to use in an offline environment.
Fingerprint information is generated by collecting host hardware information and encrypted, combined with the smart password key (Ukey) for hardware binding and authentication, using hash and encryption algorithms to ensure uniqueness and security, and a security chip integrated in Ukey for encryption operations.
It achieves high security and anti-copying in a network-free environment, simplifies the authorization process, supports the binding of multiple hardware information combinations, adapts to different security level requirements, and provides offline availability and flexible authorization modes.
Smart Images

Figure CN120688040A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software security technology, and in particular to a software and host authorization method and system based on an intelligent password key. Background Art
[0002] In computer terminal systems, there is a class of application software that requires authorization before it can be used. The main purpose of software developers doing this is to protect software copyright, improve security, prevent piracy, and ensure the legal authorization of specific functions. At present, traditional software authorization methods include serial number, registration authorization code, online activation authorization, etc. Although software authorization management has been achieved to a certain extent, due to the limitations of pure soft authorization, the software is easily affected by problems such as illegal copying, piracy, and cracking, and the security is low. The authorization process and management are relatively cumbersome, and although online activation can provide certain security, it still depends on network connection, which may cause inconvenience in use. There are also smart password keys (hereinafter referred to as Ukey) on the market to authorize software, but how to prevent illegal copying has not been substantially solved. If the software is copied and installed on other illegal devices, inserting Ukey into the illegal device can still run. How to provide a simpler and more convenient way to authorize software and bind the terminal to run is the problem to be solved by the present invention. Summary of the Invention
[0003] The purpose of the present invention is to overcome the deficiencies of the prior art and to provide a software and host authorization method and system based on an intelligent password key.
[0004] The object of the present invention is achieved through the following technical solutions: The first aspect of the present invention provides: a software and host authorization method based on a smart password key, comprising the following steps: In the fingerprint information generation phase, the system interface is called to collect the host hardware information, the host hardware information is combined and then the hash algorithm is used to generate the first fingerprint information, and the SM4 algorithm is used to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it in the memory; During the smart password key verification phase, determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If not, execute the Ukey binding process; if it is bound, execute the Ukey authentication process.
[0005] Preferably, the host hardware information includes BIOS serial number, motherboard UUID, CPU ID and system disk serial number.
[0006] Preferably, the hash algorithm is SM3.
[0007] Preferably, the Ukey binding process includes the following steps: Write the fingerprint ciphertext of the first fingerprint information into the secure storage area of Ukey; Write the bound status to Ukey and then provide business functions.
[0008] Preferably, the Ukey authentication process includes the following steps: Read the fingerprint ciphertext in the Ukey secure storage area; The fingerprint ciphertext is decrypted using the SM4 algorithm to obtain the second fingerprint information, and the second fingerprint information is compared with the fingerprint information collected by the current host in real time. If the comparison is inconsistent, an alarm is triggered and the software authorization fails. If the comparison is consistent, the service function is provided.
[0009] Preferably, the Ukey has an integrated security chip, and the read and write operations are completed through the encryption interface of the security chip.
[0010] The second aspect of the present invention provides: a software and host authorization system based on a smart password key, used to implement any of the above-mentioned software and host authorization methods based on a smart password key, comprising: The fingerprint information generation module is used to call the system interface to collect host hardware information, combine the host hardware information and use the hash algorithm to generate the first fingerprint information, and use the SM4 algorithm to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it to the memory; The intelligent password key verification module is used to determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If not, execute the Ukey binding process; if it is bound, execute the Ukey authentication process.
[0011] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned software and host authorization methods based on smart password keys is implemented.
[0012] A fourth aspect of the present invention provides: a computer program product comprising instructions, which, when run on a terminal, enables the terminal to execute any of the above-mentioned software and host authorization methods based on a smart password key.
[0013] The beneficial effects of the present invention are: 1) Strong security and anti-copying: Through hardware-level binding, even if the software is copied to other devices, the hardware information stored in the UKey will not match and the software will not run, completely blocking piracy. The hardware information encrypted and stored in the UKey cannot be extracted or forged, preventing the UKey from being illegally copied.
[0014] 2) Offline availability: The verification process is completely localized and does not require online activation or verification. It is suitable for environments without a network (such as military and industrial control scenarios).
[0015] 3) Simplified authorization management: Users only need to insert the UKey to complete binding and verification, without having to remember complex serial numbers or perform multiple online operations.
[0016] 4) Compatibility and scalability: Supports binding of multiple hardware information combinations (such as BIOS + motherboard + hard disk) to meet different security level requirements; can be expanded to flexible authorization modes such as "one key for multiple devices" or "one device for multiple keys". BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 The flowchart of the software and host authorization method based on the smart password key is shown. DETAILED DESCRIPTION
[0018] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.
[0019] See Figure 1 The first aspect of the present invention provides: a software and host authorization method based on a smart password key, comprising the following steps: In the fingerprint information generation phase, the system interface is called to collect the host hardware information, the host hardware information is combined and then the hash algorithm is used to generate the first fingerprint information, and the SM4 algorithm is used to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it in the memory; During the smart password key verification phase, determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If not, execute the Ukey binding process; if it is bound, execute the Ukey authentication process.
[0020] In this embodiment, hardware information collection and binding are adopted: the Ukey status is detected when the software is running. If the Ukey is not bound, the hardware information of the current host (such as BIOS serial number, motherboard UUID, CPU ID, system disk serial number, etc.) is collected, the host fingerprint is generated and encrypted and written to the UKey. After binding, Ukey is only allowed to authorize the software to run on the bound host. A dynamic verification mechanism is introduced: each time the software is started, it checks whether the Ukey is inserted, and verifies whether the hardware fingerprint information stored in the Ukey is consistent with the hardware fingerprint information calculated by the current host. If they are consistent, the authorized software is run. An anti-tampering design is adopted: a security chip is used in the Ukey to store encrypted hardware information to prevent the information from being extracted or tampered with. After binding, new hardware information cannot be written to the Ukey again unless it is untied by the authorized party.
[0021] When the software starts, it calls system interfaces to extract information such as the host's BIOS serial number, motherboard UUID, CPU ID, and system disk serial number. It then uses a hash algorithm (such as SM3) to generate a unique fingerprint for the host. This fingerprint is then encrypted to produce a ciphertext. The software then checks whether a Ukey is inserted. If so, to prevent unauthorized insertion, the software verifies the Ukey's legitimacy and determines whether it is bound to the host. The Ukey integrates a security chip, and read and write operations require access to the chip's encryption interface. If not, the software writes the ciphertext to the Ukey's secure storage area, marking the Ukey as bound. The software then continues to run and provide service functionality. If bound, the software reads the Ukey's ciphertext, decrypts it, and compares it with the fingerprint collected in real time by the host. If the match is consistent, the software allows the software to run and provide service functionality. Otherwise, an alarm is triggered.
[0022] In some embodiments, the host hardware information includes a BIOS serial number, a motherboard UUID, a CPU ID, and a system disk serial number.
[0023] In some embodiments, the hash algorithm is SM3.
[0024] In some embodiments, the Ukey binding process includes the following steps: Write the fingerprint ciphertext of the first fingerprint information into the secure storage area of Ukey; Write the bound status to Ukey and then provide business functions.
[0025] In some embodiments, the Ukey authentication process includes the following steps: Read the fingerprint ciphertext in the Ukey secure storage area; The fingerprint ciphertext is decrypted using the SM4 algorithm to obtain the second fingerprint information, and the second fingerprint information is compared with the fingerprint information collected by the current host in real time. If the comparison is inconsistent, an alarm is triggered and the software authorization fails. If the comparison is consistent, the service function is provided.
[0026] In some embodiments, the Ukey has an integrated security chip, and the read and write operations are completed through the encryption interface of the security chip.
[0027] The second aspect of the present invention provides: a software and host authorization system based on a smart password key, used to implement any of the above-mentioned software and host authorization methods based on a smart password key, comprising: The fingerprint information generation module is used to call the system interface to collect host hardware information, combine the host hardware information and use the hash algorithm to generate the first fingerprint information, and use the SM4 algorithm to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it to the memory; The intelligent password key verification module is used to determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If not, execute the Ukey binding process; if it is bound, execute the Ukey authentication process.
[0028] The third aspect of the present invention provides: a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, any of the above-mentioned software and host authorization methods based on smart password keys is implemented.
[0029] A fourth aspect of the present invention provides: a computer program product comprising instructions, which, when run on a terminal, enables the terminal to execute any of the above-mentioned software and host authorization methods based on a smart password key.
[0030] The foregoing description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein and should not be construed as excluding other embodiments. Rather, the present invention can be used in various other combinations, modifications, and environments and can be modified within the scope of the concept described herein through the above teachings or techniques or knowledge in the relevant field. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention are intended to be protected by the appended claims.
Claims
1. A software and host authorization method based on an intelligent password key, characterized by: The following steps are involved: In the fingerprint information generation phase, the system interface is called to collect the host hardware information, the host hardware information is combined and then the hash algorithm is used to generate the first fingerprint information, and the SM4 algorithm is used to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it in the memory; During the smart password key verification phase, determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; Then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If it is not bound, execute the Ukey binding process. If it is bound, execute the Ukey authentication process.
2. The software and host authorization method based on the smart password key according to claim 1, characterized in that: The host hardware information includes BIOS serial number, motherboard UUID, CPU ID and system disk serial number.
3. The software and host authorization method based on the smart password key according to claim 1, characterized in that: The hash algorithm is SM3.
4. The software and host authorization method based on the smart password key according to claim 1, characterized in that: The Ukey binding process includes the following steps: Write the fingerprint ciphertext of the first fingerprint information into the secure storage area of Ukey; Write the bound status to Ukey and then provide business functions.
5. The software and host authorization method based on the smart password key according to claim 1, characterized in that: The Ukey authentication process includes the following steps: Read the fingerprint ciphertext in the Ukey secure storage area; The fingerprint ciphertext is decrypted using the SM4 algorithm to obtain the second fingerprint information, and the second fingerprint information is compared with the fingerprint information collected by the current host in real time. If the comparison is inconsistent, an alarm is triggered and the software authorization fails. If the comparison is consistent, the service function is provided.
6. The software and host authorization method based on the smart password key according to any one of claims 1 to 5, characterized in that: The Ukey has an integrated security chip, and the read and write operations are completed through the encryption interface of the security chip.
7. A software and host authorization system based on an intelligent password key, characterized by: The method for implementing software and host authorization based on a smart password key according to any one of claims 1 to 6 comprises: The fingerprint information generation module is used to call the system interface to collect host hardware information, combine the host hardware information and use the hash algorithm to generate the first fingerprint information, and use the SM4 algorithm to encrypt the first fingerprint information to obtain the fingerprint ciphertext and save it to the memory; The intelligent password key verification module is used to determine whether the Ukey is inserted, scan the inserted Ukey, and monitor the Ukey insertion event; then verify the legitimacy of the Ukey. If it is legal, read the Ukey status and check whether the Ukey is bound. If not, execute the Ukey binding process; if it is bound, execute the Ukey authentication process.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by the processor, the software and host authorization method based on the smart password key as described in any one of claims 1 to 6 is implemented.
9. A computer program product comprising instructions, characterized in that: When the computer program product is run on a terminal, the terminal executes the software and host authorization method based on the smart password key according to any one of claims 1 to 6.
Citation Information
Cited By
Vehicle intelligent management and control system and method integrating Beidou positioning and digital keys
CN121425129A