Software license authorization method and device, equipment and medium
By generating a blank license file on the license server and calculating the random timestamp difference and file activation time, a globally unique license fingerprint value is established, which solves the problem of illegal distribution of software license files in the cloud environment and realizes software control and prevention of illegal use in a legal environment.
Patent Information
- Application Number
- CN202510775596.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-10-28
AI Technical Summary
Existing software license authorization technology cannot effectively prevent license authorization files from being privately distributed to illegal operating environments in cloud computing and cloud-native environments, resulting in the software still being able to run in illegal environments.
Generate a blank authorization file through the authorization server, use the random timestamp difference and the file activation time to calculate the globally unique authorization fingerprint value, establish a corresponding relationship with the unique authorization code, perform legitimacy verification and save the legal authorization file, and restart the software for authorization authentication.
Effectively control commercial software to run only in legal operating environments, prevent illegal abuse, apply to various operating environments, and break through the limitations of traditional serial number authorization methods.
Smart Images

Figure CN120850256A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of software management technology, and in particular to a software licensing method, apparatus, device, and medium. Background Technology
[0002] Commercial software possesses specific business value and can generate continuous economic returns for its rights holders. To ensure this continued profitability, rights holders typically control the specific users, operating environments, lifespan, number of users, and business scope of the software through various licensing methods. Through licensing, users acquire the right to use the commercial software, while rights holders receive corresponding economic benefits.
[0003] Commercial software licensing hinges on controlling two key elements: the legitimate users of the software and the legitimate operating environment. By designating specific users, it ensures that only those within the authorized scope can use the software; by specifying the legitimate operating environment, it ensures that the software runs only in a specific computer environment. To control these two key elements, commonly used commercial software licensing methods include: dongle licensing, software license licensing, and online licensing.
[0004] Common software license licensing technologies mainly include the following two methods: (a) Serial Number Method, also known as Activation Code Method. The software rights holder generates a license serial number in a specific format according to specific rules. The software user inputs this serial number into the software, and the software verifies the legality of the serial number. If legal, it obtains the built-in, unchanging, globally unique values of the computer running the software, such as the CPU, memory, and network card, for example, the network card's MAC address. Using a specific algorithm, these unique values are used to calculate the fingerprint value of this computer, and the fingerprint value is bound one-to-one with the serial number, thereby ensuring that a legal serial number is used only for one legal operating environment (computer).
[0005] (ii) License file distribution and verification method. Generally, the license file contains an authorization code specific to the software user, the software's validity period, etc. The license file is generated on a license server. After the license file is imported into the software, the software requests verification of its validity from the license server. If valid, the user can continue to use the software.
[0006] While the commonly used software license authorization technologies mentioned above can control software licensing to some extent, they also have many vulnerabilities. For example, the serial number method is no longer viable due to the development of cloud computing and cloud-native technologies. With more and more software deployed in the cloud or containers, it's impossible to obtain immutable, globally unique values such as those for the computer's CPU and network card. Another example is the license file distribution verification method, which cannot prevent users from privately distributing license files to multiple computer operating environments, thus failing to ensure the software runs in a legitimate environment. Summary of the Invention
[0007] This invention provides a software licensing method, apparatus, device, and medium to solve the problem that existing software license licensing technologies, when licensing commercial software without limiting the type of operating environment, cannot prevent the license file from being privately distributed to other illegal operating environments for licensing, thus causing the software to run in illegal environments.
[0008] To solve the above-mentioned technical problems, the present invention provides a software licensing method, comprising the following steps: an authorization server generates a blank license file and copies the blank license file to the software to be licensed in a first operating environment; in the software to be licensed in the first operating environment, the file creation time of the blank license file is obtained, and a random timestamp difference is randomly generated; based on the file creation time and the random timestamp difference, the file activation time of the blank license file is calculated; the random timestamp difference and the file activation time are sent to the authorization server, the authorization server verifies the legality of the first operating environment, and returns the verification result to the software to be licensed in the first operating environment; if the verification result is legal, the random timestamp difference and the file activation time are saved to the blank license file to obtain a legal license file; the software to be licensed is restarted, and the legal license file is used to perform authorization authentication.
[0009] In some embodiments, in the step of calculating the file activation time of the blank license file based on the file creation time and the random timestamp difference, the formula for calculating the file activation time is: random timestamp difference = file activation time - file creation time.
[0010] In some embodiments, after the step of copying the blank license file to the software to be licensed in the first operating environment, the method further includes the following steps: the software to be licensed reads the latest activation time of the file in the blank license file and accesses the license server to obtain the current standard time; compares the latest activation time of the file with the current standard time; if the latest activation time of the file is later than the current standard time, then continues to execute the subsequent steps; if the latest activation time of the file is earlier than the current standard time, then stops executing the subsequent steps.
[0011] In some embodiments, the authorization server verifies the legitimacy of the first runtime environment, specifically including: determining whether an authorization relationship is recorded in a blank authorization file stored in the authorization server; if not, determining that the first runtime environment is legitimate and generating a verification result; calculating an authorization fingerprint value based on the random timestamp difference and the file activation time; establishing an authorization relationship between the authorization fingerprint value and the authorization code in the blank authorization file, and saving the authorization relationship to the blank authorization file in the authorization server; if yes, determining that the first runtime environment is illegitimate and generating a verification result.
[0012] In some embodiments, in the step of restarting the software to be authorized and using a valid license file to perform authorization authentication, the authorization authentication method includes the following steps: re-acquiring the file creation time and obtaining a random timestamp difference and a file activation time from the valid license file; determining whether the calculation formula is valid based on the obtained file creation time, random timestamp difference, and file activation time; if not valid, ending the authorization authentication; if valid, reading the software availability period from the valid license file and accessing the authorization server to obtain the current standard time; determining whether the current standard time is within the software availability period; if yes, passing the authorization authentication; if not, ending the authorization authentication.
[0013] In some embodiments, a first encryption algorithm is used to encrypt the data stored in the blank license file and the legal license file, and the software to be licensed decrypts the stored data using a first key; a second encryption algorithm is used to encrypt the data communicated between the license server and the software to be licensed, and the license server and the software to be licensed decrypt the communicated data using a second key respectively.
[0014] In some embodiments, after the step of returning the verification result to the software to be authorized in the first runtime environment, the method further includes the step of: if the verification result is invalid, then stopping the execution of subsequent steps.
[0015] The present invention also provides a software licensing device, including a licensing server, a first operating environment, and software to be licensed; the licensing server is used to generate a blank license file and copy the blank license file to the software to be licensed in the first operating environment; the first operating environment is used to run the software to be licensed; the software to be licensed is used to obtain the file creation time of the blank license file and randomly generate a random timestamp difference; calculate the file activation time of the blank license file based on the file creation time and the random timestamp difference; and send the random timestamp difference and the file activation time to the licensing server; the licensing server is also used to verify the legitimacy of the first operating environment and return the verification result to the software to be licensed in the first operating environment; the software to be licensed is also used to save the random timestamp difference and the file activation time to the blank license file if the verification result is legitimate, thereby obtaining a legitimate license file; the first operating environment is also used to restart the software to be licensed and use the legitimate license file to perform licensing authentication on the software to be licensed.
[0016] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described above.
[0017] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method described above.
[0018] The beneficial effects of this invention are as follows: This invention discloses a software licensing method, apparatus, device, and medium. The method includes the following steps: an authorization server generates a blank license file and copies the blank license file to the software to be licensed in a first operating environment; in the software to be licensed in the first operating environment, the file creation time of the blank license file is obtained, and a random timestamp difference is randomly generated; the file activation time of the blank license file is calculated based on the file creation time and the random timestamp difference; the random timestamp difference and the file activation time are sent to the authorization server, the authorization server verifies the legality of the first operating environment, and returns the verification result to the software to be licensed in the first operating environment; if the verification result is legal, the random timestamp difference and the file activation time are saved to the blank license file to obtain a legal license file; the software to be licensed is restarted, and the legal license file is used to perform authorization authentication. This application generates a blank license file through an authorization server. The blank license file is then verified in the first operating environment. A globally unique authorization fingerprint value is calculated using two random data points: a random timestamp difference and the file's activation time. This fingerprint value is then linked one-to-one with a unique authorization code, ensuring that commercial software can only run in a legitimate environment. This prevents the illegal misuse of blank license files and avoids unauthorized commercial applications. Furthermore, this application is widely applicable to various types of operating environments, overcoming the limitations imposed by traditional serial number authorization methods. Attached Figure Description
[0019] Figure 1 This is a flowchart illustrating an embodiment of a software licensing method according to this application; Figure 2 This is a schematic diagram of the authorization interaction of a software licensing method according to this application; Figure 3 This is a plaintext illustration of a legal license file in a software licensing method of this application; Figure 4 This is a schematic diagram illustrating the composition of an embodiment of a software licensing device according to this application; Figure 5 This is a schematic diagram of the architecture of an embodiment of an electronic device according to this application; Figure 6 This is a schematic block diagram of an embodiment of a computer-readable storage medium according to this application. Detailed Implementation
[0020] To facilitate understanding of the present invention, a more detailed description is provided below with reference to the accompanying drawings and specific embodiments. Preferred embodiments of the invention are shown in the drawings. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to provide a thorough and complete understanding of the disclosure of the invention.
[0021] It should be noted that, unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. The term "and / or" as used in this specification includes any and all combinations of one or more of the associated listed items.
[0022] Figure 1 The flowchart illustrating the implementation of the software licensing method provided in this application is shown, including the following steps: S1: The license server generates a blank license file and copies the blank license file to the software to be licensed in the first runtime environment.
[0023] S2: In the software to be licensed in the first running environment, obtain the file creation time of the blank license file and randomly generate a random timestamp difference; calculate the file activation time of the blank license file based on the file creation time and the random timestamp difference.
[0024] S3: Send the random timestamp difference and file activation time to the authorization server. The authorization server verifies the legitimacy of the first operating environment and returns the verification result to the software to be authorized in the first operating environment.
[0025] S4: If the verification result is valid, save the random timestamp difference and the file activation time to a blank license file to obtain a valid license file.
[0026] S5: Restart the software to be authorized and use a valid license file to perform authorization authentication on the software.
[0027] This application generates a blank license file through an authorization server. The blank license file is then verified in the first operating environment. A globally unique authorization fingerprint value is calculated using two random data points: a random timestamp difference and the file's activation time. This fingerprint value is then linked one-to-one with a unique authorization code, ensuring that commercial software can only run in a legitimate environment. This prevents the illegal misuse of blank license files and avoids unauthorized commercial applications. Furthermore, this application is widely applicable to various types of operating environments, overcoming the limitations imposed by traditional serial number authorization methods.
[0028] The following is combined Figures 1 to 6 The present application will be further described in detail with reference to specific embodiments.
[0029] like Figure 1 As shown, the software licensing method provided in this application embodiment is described in detail below: S1: The license server generates a blank license file and copies the blank license file to the software to be licensed in the first runtime environment.
[0030] Combination Figure 2 As shown, firstly, some technical terms involved in this application will be explained in detail: Authorization server 1 refers to a server that manages and controls software licenses (i.e., software license authorization files) and operates in the cloud; it is primarily responsible for distributing, activating, and tracking software licenses to ensure that only authorized users can legally use the software. In this application, authorization server 1 is a license authorization server.
[0031] The first runtime environment 2 refers to the environment required for the licensed software 3 to run. In this embodiment, the types of the first runtime environment 2 include physical computers, virtual machines, containers (cloud-native), etc.
[0032] The blank license file 4 is generated by the aforementioned license server 1 and is used for licensing and authenticating the software 3 to be licensed. In this embodiment, the blank license file 4 includes a static data area 41 and a runtime data area 42. The static data area 41 stores multiple data items pre-set by the software rights holder, including the license code, the software's validity period, and the latest file activation time. The runtime data area 42 does not currently store any data; it will be stored based on the corresponding data generated during the subsequent runtime of the software 3 to be licensed.
[0033] The authorization code is a globally unique value distributed to the software user to ensure that the licensed software 3 can only be used by one legitimate user and cannot be used by two or more users. In this embodiment, using... Figure 3 For example, the authorization code is a string with a length of at least 64 characters (e.g., ...). Figure 3 Chinese: X#dfEE0R.Kk@k6JVWgi(96g6#wPIK+ D~V.ll@c@kI4SD9LID06h%Tgu^1DsJk8VH). The software availability period refers to the expiration date of the licensed software 3 after the user purchases it. Before this date, the licensed software 3 can be used normally. After the software availability period expires, the licensed software 3 becomes unusable and requires re-purchase and re-licensing. In this embodiment, using... Figure 3For example, the software availability period is set in the format YYYY-MM-DD. Specifically, setting it to 2030-12-01 means that the software to be authorized 3 can be used normally after being authorized before December 1, 2030. The latest file activation time refers to the latest time when the blank license file 4 is first activated; if the blank license file 4 is copied to the first runtime environment 2 within the latest file activation time, it can continue to be used; if the blank license file 4 is copied to the first runtime environment 2 after the latest file activation time, it cannot be authorized for use. In this embodiment, taking... Figure 3 For example, the format for setting the latest activation time of a file is YYYY-MM-DD. Specifically, if it is set to 2025-12-31, it means that if the blank license file 4 is copied to the first runtime environment 2 before December 31, 2025, the blank license file 4 can be used to perform authorization normally.
[0034] In other embodiments, the static data area 41 may also store a pre-defined scope of available software services. The software rights holder sets the scope of services that the software user can use in the licensed software 3, stipulating that the software user can only use specific services, thereby better maintaining the economic benefits generated by the software. Specifically, in this embodiment, using... Figure 3 For example, the available business scope of the software can be set to: [fun1, fun2], which means that the software user can only use the two business functions "fun1" and "fun2"; if the business scope is not limited, it can be set to: [ ].
[0035] The method of this application first generates the aforementioned blank license file 4 by the authorization server 1, and then encrypts the data stored in the blank license file 4 (i.e., the authorization code, software availability period, and the latest file activation time, etc.) using a first encryption algorithm. The first encryption algorithm is a symmetric encryption algorithm, meaning the encryption key and decryption key are the same. Furthermore, the decryption keys in this application are all hardcoded into the software to be licensed 3 and cannot be changed. In this embodiment, the first encryption algorithm includes, but is not limited to, any one of the following encryption algorithms: AES symmetric encryption algorithm, DES symmetric encryption algorithm, and SM2 symmetric encryption algorithm.
[0036] By encrypting the data stored in the blank license file 4 using the first encryption algorithm, it is possible to prevent unauthorized software users from obtaining the blank license file 4 and tampering with the data to make it a legitimate license file 5, thereby completing the authorization verification of the unauthorized software 3; effectively protecting the rights and interests of software rights holders and legitimate software users.
[0037] Furthermore, the encrypted blank license file 4 is copied to the software 3 to be licensed in the first runtime environment 2. The copying method includes import / export and downloading from the first runtime environment 2.
[0038] Furthermore, the software to be authorized 3 decrypts the data stored in the blank authorization file 4 using the first key. This first key is written into the software to be authorized 3 in code.
[0039] Furthermore, the decrypted blank authorization file 4 is read.
[0040] Specifically, the software to be authorized 3 first reads the latest activation time of the file in the blank authorization file 4; and then accesses the time server 11 in the authorization server 1 to obtain the current standard time. The current standard time is a unified time, such as Beijing time, which is obtained through the time server 11 and cannot be changed locally.
[0041] Next, the latest activation time of the file is compared with the current standard time. If the latest activation time is later than the current standard time, the subsequent steps continue. For example, if the latest activation time is 2025-12-31 and the current standard time is 2025-08-31, the later activation time indicates that the initial verification has passed, and the blank license file 4 is within its validity period, so the licensing process can continue. If the latest activation time is earlier than the current standard time, the subsequent steps are stopped. For example, if the latest activation time is 2025-12-31 and the current standard time is 2026-08-31, the earlier activation time indicates that the initial verification has failed, and the blank license file 4 is no longer valid, so the licensing of the software to be licensed 3 is stopped.
[0042] S2: In the software to be licensed in the first running environment, obtain the file creation time of the blank license file and randomly generate a random timestamp difference; calculate the file activation time of the blank license file based on the file creation time and the random timestamp difference.
[0043] Combination Figure 2 , Figure 3 As shown, after the initial verification is passed, the software to be licensed 3 calls the API (Application Programming Interface) of the operating system of the first runtime environment 2 to obtain the file creation time of the blank license file 4. The file creation time refers to the time when the blank license file 4 is first copied to the software to be licensed 3 in the first runtime environment 2. After obtaining the file creation time, the software to be licensed 3 randomly generates a random timestamp difference, such as... Figure 3As shown, the random timestamp difference is a random 32-bit positive integer, such as 6552226793. Since the random timestamp difference is randomly generated by the unlicensed software 3 in the first operating environment 2, the random timestamp difference generated in different operating environments is different, thus having uncertainty, which can prevent unauthorized software users from using it in other operating environments.
[0044] Furthermore, based on the file creation time and the difference between the random timestamps, the file activation time of the blank authorized file 4 is calculated. The formula for calculating the file activation time is: Random timestamp difference = File activation time - File creation time. In this embodiment, using... Figure 3 For example, the format for setting the file activation time is YYYY-MM-DDHH:mm:ss.SSSS (year-month-day hour:minute:second.millisecond); specifically, for example, the result of calculating the file activation time based on the difference between the file creation time and the random timestamp is 2025-04-02 14:20:33.0450.
[0045] S3: Send the random timestamp difference and file activation time to the authorization server. The authorization server verifies the legitimacy of the first operating environment and returns the verification result to the software to be authorized in the first operating environment.
[0046] Combination Figure 2 , Figure 3 As shown, after obtaining the random timestamp difference and file activation time in the software to be authorized (3), the second encryption algorithm is used to encrypt these two data. The second encryption algorithm is also a symmetric encryption algorithm, meaning the encryption key and decryption key are the same. In this embodiment, the second encryption algorithm includes, but is not limited to, any one of the following encryption algorithms: AES symmetric encryption algorithm, DES symmetric encryption algorithm, and SM2 symmetric encryption algorithm. Encrypting the random timestamp difference and file activation time using the second encryption algorithm prevents these two data from being leaked during transmission and used by unauthorized parties.
[0047] Furthermore, the encrypted random timestamp difference and file activation time are sent to Authorization Server 1 via a TCP secure channel (i.e., Transmission Control Protocol Secure Channel). Authorization Server 1 decrypts the data using the second key.
[0048] Furthermore, the authorization server 1 verifies the legitimacy of the first runtime environment 2 by using a random timestamp difference and file activation time, specifically including: Determine whether the blank license file 4 stored in license server 1 contains a record of a license relationship. If it does, it means that the blank license file 4 has been used by a legitimate runtime environment, i.e., it has been used to license the legitimate software to be licensed 3. Since there is a one-to-one correspondence between the blank license file 4 and the software to be licensed 3 in the runtime environment, the first runtime environment 2 is now an invalid runtime environment. If no license relationship is recorded, it means that the blank license file 4 has not been used, i.e., it has not been used to license the legitimate software to be licensed 3. In this case, the first runtime environment 2 is a legitimate runtime environment.
[0049] Furthermore, if there is an authorization relationship recorded, the legitimacy of the first runtime environment 2 is determined to be illegal, and a corresponding verification result is generated.
[0050] If no authorization relationship is recorded, the legitimacy of the first operating environment 2 is determined to be valid, and a corresponding verification result is generated. Further, based on the random timestamp difference and the file activation time, a hash algorithm is used to calculate the authorization fingerprint value. The generated authorization fingerprint value is a sufficiently long and globally unique string. In this application, the hash algorithm includes, but is not limited to, any one of the following algorithms: SHA1, SHA2, and SM3. Further, a one-to-one authorization relationship is established between the authorization fingerprint value and the authorization code in the blank authorization file 4, and this authorization relationship is saved in the blank authorization file 4 within the authorization server 1, indicating that the blank authorization file 4 has been used.
[0051] The above method can effectively prevent the blank license file 4 from being copied to multiple illegal operating environments, which would allow unauthorized software users to also authorize the software to be authorized 3 using the blank license file 4.
[0052] This application calculates a globally unique value (i.e., an authorization fingerprint value) using two random data points: a random timestamp difference and a file activation time. It then establishes a one-to-one correspondence between this authorization fingerprint value and the authorization code, effectively preventing the illegal abuse of blank authorization files. Furthermore, this application is widely applicable to various operating environments, overcoming the limitations of traditional serial number authorization methods (which only apply to physical computers).
[0053] Furthermore, the verification result is encrypted using a second encryption algorithm and returned to the unauthorized software 3 in the first operating environment 2.
[0054] S4: If the verification result is valid, save the random timestamp difference and the file activation time to a blank license file to obtain a valid license file.
[0055] Combination Figure 2 , Figure 3As shown, after the authorized software 3 receives the verification result, it decrypts it using the second key and makes a judgment.
[0056] Specifically, if the verification result is valid, the random timestamp difference and file activation time are saved to the runtime data area 42 in the blank license file 4 of the software to be licensed 3, thus obtaining the following: Figure 2 , Figure 3 The legally authorized document 5 is shown. The data in legally authorized document 5 is further encrypted using the first encryption algorithm to prevent leakage.
[0057] If the verification result is invalid, the subsequent steps will be stopped, indicating that the authorization of software 3 failed and cannot be used.
[0058] S5: Restart the software to be authorized and use a valid license file to perform authorization authentication on the software.
[0059] Combination Figure 2 , Figure 3 As shown, after generating the valid license file 5, the software to be licensed 3 also needs to undergo local license authentication. The license authentication method includes the following steps: First, restart the software to be authorized 3. After restarting, the software to be authorized 3 calls the API of the operating system of the first running environment 2 to obtain the file creation time; and obtains the random timestamp difference and file activation time from the legally authorized file 5 (the data is obtained after decryption using the first key).
[0060] Furthermore, based on the obtained file creation time, random timestamp difference, and file activation time, it is determined whether the calculation formula (random timestamp difference = file activation time - file creation time) is valid.
[0061] If the condition is not met, the authorization process ends. This situation indicates that the file creation time has changed, causing the calculation formula to fail. Specifically, the legitimate licensed file 5 was illegally copied from another legitimate runtime environment to the first runtime environment 2. During the copying process, the file creation time changed in the illegal first runtime environment 2, thus rendering the formula invalid. Therefore, authorization must be stopped to prevent the legitimate licensed file 5 from being illegally authenticated.
[0062] If the conditions are met, the software availability period is read from the valid license document 5, and the time server 11 in the license server 1 is accessed to obtain the current standard time. It is then determined whether the current standard time is within the software availability period. If it is, the license is granted; for example, if the software availability period is set to 2030-12-01, it means that the software to be licensed 3 can be used normally after being licensed before December 1, 2030; and if the current standard time is 2025-12-01, which is within the software availability period of 2030-12-01, it means that the software to be licensed 3 is within its validity period and can be used normally, thus the license is granted and can be used. If not, the license is terminated; for example, if the software availability period is set to 2030-12-01, and the current standard time is 2031-12-01, which is not within the software availability period of 2030-12-01, it means that the software to be licensed 3 is not within its validity period, thus the license is terminated and cannot be used.
[0063] After the software to be authorized 3 is authorized and certified for the first time, it needs to be authorized and certified locally every time it is restarted in the first running environment 2 to ensure that the software to be authorized 3 always works within the software availability period.
[0064] The local authorization authentication in this application does not require the establishment of a network channel for verification with the authorization server 1. For operating environments with high network egress security requirements, this method can avoid the problem of the software to be authorized 3 having to connect to the network every time it restarts.
[0065] Corresponding to the software licensing method in the above embodiments, this application also provides a software licensing device. For ease of explanation, only the parts related to this application are shown.
[0066] like Figure 4 As shown, the software licensing device includes a licensing server 1, a first operating environment 2, and software to be licensed 3.
[0067] The authorization server 1 is used to generate a blank authorization file and copy the blank authorization file to the software 3 to be authorized in the first operating environment 2.
[0068] The first runtime environment 2 is used to run the software 3 to be licensed.
[0069] The software to be licensed (3) is used to obtain the file creation time of the blank license file and randomly generate a timestamp difference; based on the file creation time and the random timestamp difference, it calculates the file activation time of the blank license file. It is also used to send the random timestamp difference and the file activation time to the license server (1).
[0070] The authorization server 1 is also used to verify the legitimacy of the first operating environment 2 and return the verification result to the software 3 to be authorized in the first operating environment 2.
[0071] The software to be authorized 3 is also used to save the random timestamp difference and the file activation time to a blank authorization file if the verification result is valid, thereby obtaining a valid authorization file.
[0072] The first operating environment 2 is also used to restart the software to be authorized 3 and to perform authorization authentication on the software to be authorized 3 using a valid authorization file.
[0073] It should be noted that other technical features in the above-mentioned software licensing device are the same as those disclosed in the above-mentioned embodiments. They can be referred to the descriptions in the corresponding method embodiments above, and will not be repeated here.
[0074] Based on the same inventive concept, this application also provides an electronic device, which includes a processor, a memory, and a communication circuit, wherein the processor is connected to the memory and the communication circuit respectively; wherein the communication circuit is used for communication connection, the memory is used to store computer programs, and the processor is used to execute the computer programs to implement the above-mentioned software licensing method.
[0075] See Figure 5 The electronic device 200 described in this application embodiment may specifically include a processor 210 and a memory 220. The memory 220 is coupled to the processor 210.
[0076] Processor 210 is used to control the operation of electronic device 200. Processor 210 can also be referred to as CPU (Central Processing Unit). Processor 210 may be an integrated circuit chip with signal processing capabilities. Processor 210 can also be a general-purpose processor, digital signal processor (DSP), application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component. The general-purpose processor can be a microprocessor, or processor 210 can be any conventional processor.
[0077] Memory 220 is used to store computer programs and may be RAM, ROM, or other types of storage terminals. Specifically, memory 220 may include one or more computer-readable storage media, which may be non-transitory or transient. Memory 220 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage terminals or flash memory terminals. In some embodiments, the non-transitory computer-readable storage media in memory 220 is used to store at least one line of program code.
[0078] The processor 210 is used to execute computer programs stored in the memory 220 to implement the methods described in the various method embodiments of this application.
[0079] In some embodiments, the electronic device 200 may further include a peripheral terminal interface 230 and at least one peripheral terminal. The processor 210, memory 220, and peripheral terminal interface 230 may be connected via a bus or signal line. Each peripheral terminal may be connected to the peripheral terminal interface 230 via a bus, signal line, or circuit board. Specifically, the peripheral terminal includes at least one of a radio frequency circuit 240, a display screen 250, an audio circuit 260, and a power supply 270.
[0080] The peripheral terminal interface 230 can be used to connect at least one I / O (Input / output) related peripheral terminal to the processor 210 and the memory 220. In some embodiments, the processor 210, memory 220 and peripheral terminal interface 230 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 210, memory 220 and peripheral terminal interface 230 can be implemented on separate chips or circuit boards, which is not limited in this embodiment.
[0081] The radio frequency (RF) circuit 240 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The RF circuit 240 communicates with communication networks and other IoT devices via electromagnetic signals; it is the communication circuit of the electronic device 200. The RF circuit 240 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals back into electrical signals. Optionally, the RF circuit 240 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, an operator identification module card, etc. The RF circuit 240 can communicate with other terminals via at least one wireless communication protocol. This wireless communication protocol includes, but is not limited to: the World Wide Web, metropolitan area networks, intranets, various generations of mobile communication networks (2G, 3G, 4G, and 5G), wireless local area networks, and / or WiFi (Wireless Fidelity) networks. In some embodiments, the RF circuit 240 may also include circuitry related to NFC (Near Field Communication), which is not limited in this application.
[0082] Display screen 250 is used to display a UI (User Interface). This UI may include graphics, text, icons, videos, and any combination thereof. When display screen 250 is a touch display screen, it also has the ability to collect touch signals on or above its surface. These touch signals can be input as control signals to processor 210 for processing. In this case, display screen 250 can also be used to provide virtual buttons and / or a virtual keyboard, also known as soft buttons and / or a soft keyboard. In some embodiments, there may be one display screen 250, located on the front panel of electronic device 200; in other embodiments, there may be at least two display screens, respectively located on different surfaces of electronic device 200 or in a folded design; in still other embodiments, display screen 250 may be a flexible display screen, located on a curved or folded surface of electronic device 200. Furthermore, display screen 250 may be configured as a non-rectangular, irregular shape, i.e., a non-rectangular screen. Display screen 250 may be made of materials such as LCD (Liquid Crystal Display) or OLED (Organic Light-Emitting Diode).
[0083] The audio circuit 260 may include a microphone and a speaker. The microphone is used to collect sound waves from the operator and the environment, converting the sound waves into electrical signals that are input to the processor 210 for processing, or input to the radio frequency circuit 240 for voice communication. For stereo sound acquisition or noise reduction purposes, multiple microphones may be used, each located at a different part of the electronic device 200. The microphone may also be an array microphone or an omnidirectional microphone. The speaker is used to convert electrical signals from the processor 210 or the radio frequency circuit 240 into sound waves. The speaker may be a conventional diaphragm speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can convert electrical signals not only into audible sound waves but also into inaudible sound waves for purposes such as distance measurement. In some embodiments, the audio circuit 260 may also include a headphone jack.
[0084] Power supply 270 is used to supply power to various components in electronic device 200. Power supply 270 can be alternating current, direct current, a disposable battery, or a rechargeable battery. When power supply 270 includes a rechargeable battery, the rechargeable battery can be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery that is charged via a wired line, while a wireless rechargeable battery is a battery that is charged via a wireless coil. The rechargeable battery can also be used to support fast charging technology.
[0085] For a detailed description of the functions and execution processes of each functional module or component in the embodiments of the electronic device 200 of this application, please refer to the descriptions in the above-mentioned method embodiments of this application, which will not be repeated here.
[0086] In the several embodiments provided in this application, it should be understood that the disclosed electronic device 200 and method can be implemented in other ways. For example, the embodiments of the electronic device 200 described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0087] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0088] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0089] Based on the same inventive concept, this application also provides a computer-readable storage medium storing a computer program that can be executed by a processor to implement the above-described software licensing method.
[0090] See Figure 6If the integrated units described above are implemented as software functional units and sold or used as independent products, they can be stored in computer-readable storage medium 300. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions / computer programs to cause an Internet of Things device (which may be a personal computer, server, or network terminal, etc.) or processor to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes various media such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, as well as electronic terminals such as computers, mobile phones, laptops, tablets, and cameras that have the aforementioned storage media.
[0091] The description of the execution process of program data in a computer-readable storage medium can be found in the descriptions in the various method embodiments of this application above, and will not be repeated here.
[0092] Therefore, this invention discloses a software licensing method, apparatus, device, and medium. The method includes the following steps: an authorization server generates a blank license file and copies the blank license file to the software to be licensed in a first operating environment; in the software to be licensed in the first operating environment, the file creation time of the blank license file is obtained, and a random timestamp difference is randomly generated; the file activation time of the blank license file is calculated based on the file creation time and the random timestamp difference; the random timestamp difference and the file activation time are sent to the authorization server, the authorization server verifies the legality of the first operating environment, and returns the verification result to the software to be licensed in the first operating environment; if the verification result is legal, the random timestamp difference and the file activation time are saved to the blank license file to obtain a legal license file; the software to be licensed is restarted, and the legal license file is used to perform authorization authentication. This application generates a blank license file through an authorization server. The blank license file is then verified in the first operating environment. A globally unique authorization fingerprint value is calculated using two random data points: a random timestamp difference and the file's activation time. This fingerprint value is then linked one-to-one with a unique authorization code, ensuring that commercial software can only run in a legitimate environment. This prevents the illegal misuse of blank license files and avoids unauthorized commercial applications. Furthermore, this application is widely applicable to various types of operating environments, overcoming the limitations imposed by traditional serial number authorization methods.
[0093] The above are merely embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structural transformations made based on the content of the present invention specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A software licensing method, characterized in that, Including the following steps: The authorization server generates a blank authorization file and copies the blank authorization file to the software to be authorized in the first operating environment; In the software to be authorized in the first operating environment, the file creation time of the blank authorization file is obtained, and a random timestamp difference is randomly generated; based on the file creation time and the random timestamp difference, the file activation time of the blank authorization file is calculated. The random timestamp difference and the file activation time are sent to the authorization server, which verifies the legitimacy of the first operating environment and returns the verification result to the software to be authorized in the first operating environment. If the verification result is valid, the random timestamp difference and the file activation time are saved to the blank authorization file to obtain a valid authorization file; Restart the software to be authorized, and use the legitimate authorization file to perform authorization authentication on the software to be authorized.
2. The software licensing method according to claim 1, characterized in that, In the step of calculating the file activation time of the blank authorized file based on the file creation time and the random timestamp difference, the calculation formula for the file activation time is: random timestamp difference = file activation time - file creation time.
3. The software licensing method according to claim 1, characterized in that, After the step of copying the blank license file to the software to be licensed in the first runtime environment, the method further includes the following step: The software to be authorized reads the latest activation time of the file in the blank authorization file and accesses the authorization server to obtain the current standard time; Compare the latest activation time of the file with the current standard time; If the latest activation time of the file is later than the current standard time, then continue with the subsequent steps; If the latest activation time of the file is earlier than the current standard time, then the subsequent steps will be stopped.
4. The software licensing method according to claim 1, characterized in that, The authorization server verifies the legitimacy of the first operating environment, specifically including: Determine whether the blank authorization file stored in the authorization server contains an authorization relationship; If not, the first operating environment is deemed legal and the verification result is generated; and based on the random timestamp difference and the file activation time, the authorization fingerprint value is calculated; the authorization relationship between the authorization fingerprint value and the authorization code in the blank authorization file is established, and the authorization relationship is saved to the blank authorization file in the authorization server; If so, the legitimacy of the first operating environment is determined to be illegal, and the verification result is generated.
5. The software licensing method according to claim 2, characterized in that, In the step of restarting the software to be authorized and using the valid authorization file to perform authorization authentication on the software to be authorized, the authorization authentication method includes the following steps: Retrieve the file creation time, and obtain the random timestamp difference and file activation time from the legally authorized file; Based on the obtained file creation time, random timestamp difference, and file activation time, determine whether the calculation formula is valid; If the authentication fails, the authorization process ends. If true, the software availability period is read from the legally authorized file, and the authorization server is accessed to obtain the current standard time; Determine whether the current standard time is within the software's available period; If present, then authorization and authentication will be granted; If not, the authorization process will end.
6. The software licensing method according to claim 1, characterized in that, The data stored in the blank authorization file and the legal authorization file are encrypted using a first encryption algorithm, and the software to be authorized decrypts the stored data using a first key; The data communicated between the authorization server and the software to be authorized is encrypted using a second encryption algorithm, and the authorization server and the software to be authorized decrypt the data using a second key.
7. The software licensing method according to claim 1, characterized in that, After the step of returning the verification result to the software to be authorized in the first operating environment, the method further includes the following step: If the verification result is invalid, then stop executing the subsequent steps.
8. A software licensing device, characterized in that, This includes the authorization server, the initial runtime environment, and the software to be authorized; The authorization server is used to generate a blank authorization file and copy the blank authorization file to the software to be authorized in the first operating environment; The first operating environment is used to run the software to be authorized; The software to be authorized is used to obtain the file creation time of the blank authorization file and randomly generate a random timestamp difference; based on the file creation time and the random timestamp difference, the file activation time of the blank authorization file is calculated. It is also used to send the random timestamp difference and the file activation time to the authorization server; The authorization server is also used to verify the legitimacy of the first operating environment and return the verification result to the software to be authorized in the first operating environment; The software to be authorized is also used to save the random timestamp difference and the file activation time to the blank authorization file if the verification result is valid, thereby obtaining a valid authorization file; The first operating environment is also used to restart the software to be authorized and to perform authorization authentication on the software to be authorized using the legal authorization file.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of the method as claimed in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 7.