Application License Method, Device, Equipment and Medium Based on Docker Containers

By obtaining the license file in the image file of the Docker container and identifying and terminating the unauthorized container, the abuse caused by the uncontrollable life cycle of the Docker container is solved, and controllable protection for software vendors is achieved.

CN113051036BActive Publication Date: 2025-07-18BOE TECHNOLOGY GROUP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110349882.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-31
Publication Date
2025-07-18
Estimated Expiration
2041-03-31

AI Technical Summary

Technical Problem

Because the life cycle of Docker containers is uncontrollable, users can abuse it within the scope of unauthorized licenses, and cannot provide controllable protection to software manufacturers.

Method used

By identifying the startup Docker container, obtain the license file in its image file, decrypt and determine whether the container is authorized, including detecting the number and duration of the container, and forcibly terminate the unauthorized container.

Benefits of technology

It effectively ensures the controllability of Docker containers under license compliance operation, prevents authorization from being copied and abused, and ensures the protection of software providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113051036B_ABST
    Figure CN113051036B_ABST
Patent Text Reader

Abstract

The present application discloses a method, device, equipment and medium for application program licensing based on Docker containers. The method includes: identifying Docker containers in a startup state; obtaining the image files of the Docker containers and obtaining the license files of the Docker containers from the image files; and determining whether the Docker containers are authorized for licensing according to the license files. Thus, the problem that the software vendor cannot be protected controllably due to the replication and abuse of authorization is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to the field of computer technology, and in particular, to an application program licensing method, apparatus, device, and medium based on Docker containers. Background Art

[0002] Docker containers can run application programs (such as websites, games, etc.) based on virtualization technology. Due to the virtual characteristics of the containers, their life cycles are uncontrollable, and they often exit, rebuild, etc.

[0003] However, since multiple containers can run on one machine and a customer obtains one authorization to run multiple containers, it leads to the abuse of Docker containers by users within the unauthorized license scope, and the software vendor cannot be protected controllably, which needs to be solved. Summary of the Invention

[0004] In view of the above defects or deficiencies in the prior art, it is desirable to provide an application program licensing method, apparatus, device, and medium based on Docker containers to solve the problem that the software vendor cannot be protected controllably due to the replication and abuse of authorizations.

[0005] In a first aspect, an embodiment of the present application provides an application program licensing method based on Docker containers, including:

[0006] Identifying Docker containers in a starting state;

[0007] Obtaining the image file of the Docker container, and obtaining the license file of the Docker container from the image file;

[0008] Determining whether the Docker container is authorized according to the license file.

[0009] Optionally, the Docker container is started by a service node based on the image file, and the image file is obtained by the service node pulling from a private cloud.

[0010] Optionally, the secure path of the license file is burned in the image file. The obtaining the image file of the Docker container and obtaining the license file of the Docker container from the image file includes:

[0011] Reading the digest of the image file and decrypting the digest to obtain the secure path;

[0012] Reading the license file according to the secure path.

[0013] Optionally, determining whether the Docker container is licensed according to the license file includes:

[0014] Decrypting the license file to obtain at least one license label for the Docker container;

[0015] Determining whether the Docker container is licensed based on the at least one license label.

[0016] Optionally, the license label includes the preset number of containers running simultaneously. Determining whether the Docker container is licensed based on the at least one license label includes:

[0017] Detecting the actual number of the Docker containers currently running on the physical machine;

[0018] Determining that the Docker container is licensed when the actual number is less than or equal to the preset number of containers.

[0019] Optionally, the license label includes the authorization period of the Docker container. Determining whether the Docker container is licensed based on the at least one license label includes:

[0020] Determining the expiration time of the Docker container according to the authorization period;

[0021] Obtaining the current time when the physical machine is running;

[0022] Determining that the Docker container is licensed when the current time has not reached the expiration time.

[0023] Optionally, the method further includes:

[0024] Obtaining at least one Docker container that is not licensed;

[0025] Obtaining the forced termination rule from the image file;

[0026] Forcibly terminating the at least one Docker container that is not licensed according to the forced termination rule.

[0027] In a second aspect, an embodiment of the present application provides an application program licensing device based on Docker containers, including:

[0028] An identification module, configured to identify that there is a Docker container in a startup state;

[0029] A first acquisition module, configured to acquire the image file of the Docker container and obtain the license file of the Docker container from the image file;

[0030] A determination module, configured to determine whether the Docker container is authorized according to the license file.

[0031] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method for licensing an application based on a Docker container as described in the embodiments of the present application is implemented.

[0032] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the method for licensing an application based on a Docker container as described in the embodiments of the present application is implemented.

[0033] Therefore, by acquiring the image file of the Docker container in the startup state and determining whether the Docker container is authorized according to the license file in the image file, the controllability of the Docker container under license compliance operation is effectively ensured, and the problem that the software vendor cannot be controllably protected due to the replication and abuse of authorization is solved.

[0034] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objects, and advantages of the present application will become more apparent:

[0036] Figure 1 Shows a flowchart suitable for implementing the method for licensing an application based on a Docker container according to an embodiment of the present application;

[0037] Figure 2 Shows a schematic diagram suitable for forming an image digest according to an embodiment of the present application;

[0038] Figure 3 Shows a process for starting a component image file suitable for an embodiment of the present application;

[0039] Figure 4 Shows a schematic diagram of a license tag suitable for an embodiment of the present application;

[0040] Figure 5Shows a schematic diagram suitable for implementing an application license system based on Docker containers according to an embodiment of the present application;

[0041] Figure 6 Shows a flowchart suitable for implementing the generation of an image file according to an embodiment of the present application;

[0042] Figure 7 Shows a flowchart suitable for implementing license auditing according to an embodiment of the present application;

[0043] Figure 8 Shows a block diagram of an application license device based on Docker containers according to an embodiment of the present application;

[0044] Figure 9 Shows a schematic diagram of the structure of a computer system of an electronic device or a server suitable for implementing an embodiment of the present application. Detailed implementation manners

[0045] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the sake of description, only the parts related to the invention are shown in the drawings.

[0046] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0047] Figure 1 Is a flowchart of an application license method based on Docker containers according to an embodiment of the present application.

[0048] Before introducing the application license method based on Docker containers according to an embodiment of the present application, Docker containers and SaaS (Software-as-a-Service) applicable to the present application will be briefly introduced.

[0049] Specifically, Docker containers are an open-source application container engine that allows developers to package their applications and the environmental data on which the applications depend into a portable container in a unified manner, and then publish it to any server installed with a docker engine, such as a Linux or Windows machine.

[0050] Docker belongs to a kind of encapsulation of Linux containers and can provide a simple and easy-to-use container interface. Since software developers have packaged the application program and the environmental data on which the program depends in a file (Docker image), software purchasers can directly generate a corresponding virtual container, that is, a Docker container, on a physical machine by running this file, and the program encapsulated in the Docker image can run in this virtual container. The unique identifier of a Docker image is guaranteed by the digest of the image, and the digest of a Docker image is tamper-proof, thus ensuring the stability of the authorization from the developer to the software purchaser.

[0051] That is to say, the interface of Docker is quite simple. Software developers can easily create and use containers and put their own applications into the containers. Docker containers can also perform operations such as version management, replication, sharing, and modification.

[0052] SaaS refers to a new model of providing software services through the Internet. In the traditional model, manufacturers deploy software products to multiple customer terminals within an enterprise through a license agreement for delivery. In the SaaS model, manufacturers uniformly deploy application software on their own servers. Customers can order the required application software services from the manufacturers according to their actual needs through the Internet, pay the manufacturers according to the amount and duration of the ordered services, and obtain the services provided by the manufacturers through the Internet. SaaS defines a new delivery method and also makes software further return to its service nature.

[0053] SaaS application software has three modes: free, paid, and value-added. The payment is usually an "all-inclusive" fee, which includes the usual application software license fee, software maintenance fee, and technical support fee. As Figure 1 shown, the application program licensing method based on Docker containers in the embodiments of this application includes the following steps:

[0054] Step 101, identify that there is a Docker container in the startup state.

[0055] Among them, a Docker container is a carrier for running one or a group of applications independently. It is a concept similar to an object. A Docker image is a system hard disk file. Many containers can be generated from a Docker image. Relevant programs are set in each Docker image. A Docker image is composed of layers. The corresponding Docker container is determined according to the program set in the top layer of the Docker image. That is to say, a Docker container is the entity when a Docker image runs. In other words, a Docker container is obtained through the operation of a physical machine based on the content of a Docker image.

[0056] Furthermore, a Docker image file is a template for creating a Docker container. It packages all the applications that implement business functions and the environmental data on which the applications depend into a "software package", similar to a software installation package. The software purchaser downloads the Docker image file to a physical machine through a cloud storage device and then starts it through special commands.

[0057] Optionally, the cloud storage device may include a public cloud and a private cloud. Among them, a public cloud usually refers to a cloud that can be used provided by a third-party provider for users. A public cloud can generally be used through the Internet and may be free or inexpensive. The core attribute of a public cloud is shared resource services. A private cloud is to create cloud infrastructure and software and hardware resources within a firewall for sharing resources in the data center among various departments within an institution or enterprise. To create a private cloud, in addition to hardware resources, there is generally cloud device (Iaas, Infrastructure as a Service) software. Private cloud computing also includes three layers: cloud hardware, cloud platform, and cloud service. The difference is that the cloud hardware is the user's own personal computer or server, rather than the data center of a cloud computing manufacturer. The purpose of a cloud computing manufacturer to build a data center is to provide public cloud services for millions of users, so it needs to have hundreds of thousands of servers. Private cloud computing only serves the employees of the enterprise, as well as the enterprise's customers and suppliers. Therefore, preferably, the software purchaser of this application can download the Docker image file from the private cloud, effectively improving the security during the download process of the Docker image file and reducing the risk of being cracked by software developers or hackers when using the public cloud.

[0058] Among them, the private cloud can be deployed within the firewall of the enterprise data center or can also be deployed in a secure physical machine hosting site. The core attribute of the private cloud is proprietary resources.

[0059] Optionally, to further increase the security of the Docker image file, the software purchaser can set up an image repository in the private cloud. The image repository can be accessed through an independent password, and the Docker image can be stored in the image repository. Thus, the possibility of non-software purchasers obtaining the Docker image can be further reduced, thereby reducing the risk of the Docker image being maliciously cracked and improving the controllable protection for software developers.

[0060] In one or more embodiments, a private cloud may be provided by a software developer. That is, the software developer stores the packaged Docker image files in the private cloud of the software developer. The software purchaser pulls the Docker image files from the private cloud of the software developer or the image repository in the private cloud using information such as the private cloud address provided by the software developer and the purchased product identifier.

[0061] Furthermore, the embodiment of the present application can be implemented by using the "Docker pull command". Docker pull means pulling or updating a specified image from the private cloud. For example, if the pulled image file is the product image of the java file stored by the software purchaser in the private cloud, it is docker pull java.

[0062] That is to say, in the embodiment of the present application, the image file (such as a software package) corresponding to the Docker container to be started can be downloaded to the local first. The image file contains a license file. By pulling the image file containing the license file to the local, and then using the image file to start the Docker container. Therefore, in the embodiment of the present application, when it is recognized that there is a Docker container in the starting state, it can be recognized according to the reading situation of the image file.

[0063] Step 102, obtain the image file of the Docker container, and obtain the license file of the Docker container from the image file.

[0064] Among them, the security path for storing the license file of the Docker container is burned in the image file. After obtaining the image file of the Docker container by pulling, the license file of the Docker container can be obtained from the image file, including: reading the digest of the image file and decrypting the digest to obtain the security path; reading the license file according to the security path. Here, burning means burning the required data into a storage medium through a corresponding burning tool, such as an optical disc, a burning card, a computer-readable storage medium, etc. In the present application, the storage medium can be a computer-readable storage medium for storing the image file.

[0065] It should be understood that, as Figure 2 shown in Table 1, before pushing the customized image containing the license file to the private cloud, the present application embodiment maps the license file in the Dockerfile to the security path in the image system. Among them, the Dockerfile is a text file used to build an image, and the text content contains the instructions and descriptions required for building the image; that is to say, the dockerfile is the source code file for making an image and is the instruction in the process of building a container. Docker can automatically build a container by reading the specified content of the dockerfile and make an image based on the dockerfile.

[0066] The naming method of the license file can consist of numbers and letters. For example, in the embodiments of this application, the license file can be named as follows:

[0067] a5e4c87aa1b1ad044d4566421e02f784.lic,

[0068] In the embodiments of this application, the mirror file can be mapped to a secure path in the system. Among them, the secure path can be a hidden folder. For example, the hidden folder can be / opt / boe / clf / .hidden, so as to effectively protect the license file and effectively avoid the malicious copying of the license file.

[0069] Table 1

[0070] sha256:e78f42e08aacdc880c05f4e3977d0c36835e56342dac2acb8f5039109173b2dc

[0071] Furthermore, as Figure 3 shown Figure 3 is a schematic diagram of the process of starting the component mirror file in the embodiments of this application and building the license file into the mirror file. Thus, after obtaining the mirror file of the Docker container in the embodiments of this application, the license file of the Docker container can be obtained from the mirror file.

[0072] Among them, there are multiple formats for the license file. As shown in Table 2 to Table 4, Table 2 is a simple string format. The string can be composed of five parts, each part contains five digits, and the five digits can be randomly combined by numbers and letters; Table 3 is a multi-factor character set qualification format. The string can be composed of five parts. The first part is a random number, and the remaining four parts are composed of five random numbers; Table 4 is a self - contained comprehensive certificate format, which can be randomly generated by numbers, uppercase and lowercase letters. Those skilled in the art can select the corresponding license file format according to the actual situation. To avoid redundancy, no detailed description will be given here.

[0073] Table 2

[0074]

[0075] Table 3

[0076]

[0077] Table 4

[0078]

[0079] Step 103: Determine whether the Docker container is authorized according to the license file.

[0080] Optionally, according to the license file, determine whether the Docker container is authorized, including: decrypting the license file to obtain at least one license label for the Docker container; and determining whether the Docker container is authorized based on the at least one license label.

[0081] Specifically, embodiments of the present application can obtain the encrypted license file from a securely hidden path of the Docker container image file, such as:

[0082] a5e4c87aa1b1ad044d4566421e02f784.lic;

[0083] Thus, the relevant file can be decrypted to obtain at least one license label for the Docker container. The schematic diagram of the license label can be as shown in Figure 4 As shown, it can be seen from Figure 4 that the number of authorized containers is 1, and the expiration date is December 31, 2020. Thus, it can be determined whether the Docker container is authorized according to the license label, realizing the controllability of authorization.

[0084] As a possible implementation manner, the license label includes the preset number of containers running simultaneously. Determining whether the Docker container is authorized based on the at least one license label includes: detecting the actual number of Docker containers currently running on the physical machine; and determining that the Docker container is authorized when the actual number is less than or equal to the preset number of containers. Herein, the physical machine can be a local physical machine or a remote physical machine.

[0085] Specifically, embodiments of the present application can determine the authorization of the Docker container according to the number of legal authorization instances. For example, embodiments of the present application can obtain the number of instances running on the machine according to the image signature and verify whether it is within the legal range, so as to determine whether the Docker container is authorized.

[0086] As another possible implementation manner, the license label includes the authorization period of the Docker container. Determining whether the Docker container is authorized based on the at least one license label includes: determining the expiration time of the Docker container according to the authorization period; obtaining the current time when the physical machine is running; and determining that the Docker container is authorized when the current time has not reached the expiration time.

[0087] It should be understood that the authorization period can be 3 months, 6 months, one year, etc. The embodiments of the present application can refer to the label information of Docker containers and start the authorized containers 1... N according to the license requirements. As shown in Table 5, the label authorization information of Docker containers is: the number of authorized containers is 1, and the expiration date is December 31, 2020.

[0088] Table 5

[0089] grant.number="1" license.expire="2021-12-31"

[0090] That is to say, the expiration time of the Docker container is December 31, 2020. If the current time of the current physical machine does not reach December 31, 2020, it is determined that the Docker container is licensed. If the current time of the current physical machine reaches December 31, 2020, it means that the authorization period has expired and the software cannot continue to run.

[0091] It can be seen from this that the embodiments of the present application also set up a license audit module, and through the license audit module, license checks, verifications, and control operations are performed on the containers of the business applications running on the current physical machine. The main purpose is to ensure that the containers running on the physical machine operate under reasonable and compliant conditions. For example, whether the license files included in the containers are officially released, whether there are any tampering, whether the software authorized in the license files is genuine, whether the software authorization has expired, and whether the authorized quantity is within the specified quantity, etc. If it is not compliant, the abnormal containers will be forcibly terminated. The license audit module can be a separate container or process, and can be continuously cycled and started, so as to perform license checks, verifications, and control operations on the containers of the business applications running on the physical machine in real time; and, in order to prevent the mirror from being tampered with, such as changing the name and license authorization file, it compares the original mirror signature with the mirror signatures in all currently running containers. If the comparison is normal, the container is allowed to run, and statistics and counting are performed.

[0092] In addition, if the authorization rule verification fails, warning information is sent to the relevant applications to warn the business users that the current authorization is over-limit and out-of-bounds, and the warning information is recorded in the business log for business viewing for traceability. The audit results are shown in Table 6.

[0093] Table 6

[0094] Audit time Audit object Audit result Audit reason Audit process 2020-12-31 BOEXX system Success Authorization compliance LicenseSidecar 2020-12-30 BOEXX system Failure Authorization expired LicenseSidecar

[0095] Optionally, the method further includes: obtaining at least one Docker container that has not been licensed; obtaining the forced termination rule from the mirror file; and forcibly terminating at least one Docker container that has not been licensed according to the forced termination rule.

[0096] Among them, the forced termination rule can be sorted by time. According to the business scenario, the most recently started container can be forcibly terminated; or the oldest started container can be forcibly terminated; or a container can be randomly selected for forced termination, which is not specifically limited here.

[0097] Specifically, the embodiments of the present application can also obtain one or more Docker containers that have not been authorized, and the same forced termination rule or different forced termination rules can be adopted for different unauthorized Docker containers. Specifically, relevant technical personnel can perform forced termination according to the actual situation. To avoid redundancy, it will not be elaborated in detail here.

[0098] Thus, by forcibly terminating the unauthorized Docker containers according to the obtained forced termination rule, the controllability of the Docker containers under license-compliant operation is effectively ensured, and the problem that the software vendor cannot be controllably protected due to the replication and abuse of authorization is solved.

[0099] To enable those skilled in the art to further understand the application program authorization and licensing method based on Docker containers in the embodiments of the present application, the following will be combined with Figure 5 and Figure 6 be further described.

[0100] As Figure 5 shown, Figure 5 is a schematic diagram of a system involved in the application program licensing method based on Docker containers according to an embodiment of the present application. The system includes Clients, Hosts, and Registries (registries).

[0101] Specifically, the Docker client uses the Docker SDK to communicate with the Docker daemon process through the command line or other tools. The Docker daemon process is the background monitor for running Docker containers. It contains information about the running containers, such as the list of running containers, running status, and number of running containers. Through it, the current situation of the containers running on the machine can be understood in real time, and through it, containers can be restarted or forcibly terminated; the host is a physical or virtual machine used to execute the Docker daemon process and containers. A container is the state when an image is running, such as the interface for game operations. It provides application services. The daemon process is a system background process, similar to a system monitoring program, which monitors and controls the running of containers. Registry can be a code repository in code control. A Docker Registry can contain multiple repositories; each repository can contain multiple tags; each tag corresponds to an image. A tag is used to set a mark for the image file (virtual software package). For example, if the image of this application is an artificial intelligence image processing software, we can set a mark for it, so that users can easily query and download the images they are interested in. Tag example: category=AI, product=image processing, expiration date=2021-12-31.

[0102] Docker Machine is a command-line tool that simplifies the installation of Docker. Specifically, Docker Machine is a tool that can install Docker on virtual hosts and can use the docker-machine command to manage physical machines; Docker Machine can also centrally manage all docker physical machines, such as quickly installing docker on 100 servers. It can install Docker on the corresponding local or remote platforms. It is similar to a standard tool for installing and running containers, helping users easily install Docker on various machines.

[0103] Furthermore, as Figure 6 shown, Figure 6 is the flowchart for generating an image file according to an embodiment of the present application.

[0104] S601, Prepare the license file.

[0105] S602, Map the license file to a secure path in the image file in the Dockerfile.

[0106] S603, Start the process of building the component image file and build the license file into the image process.

[0107] S604, Tag the image file to describe the authorization rules.

[0108] S605, Send the image file to the private cloud.

[0109] Further, as Figure 7 shown, Figure 7 is a flowchart of license auditing according to an embodiment of the present application.

[0110] S701, Pull the image file.

[0111] S702, Start containers 1...N.

[0112] S703, Start auditing.

[0113] S704, Read the signature of the image file.

[0114] S705, Obtain the license file from the container security path.

[0115] S706, Decrypt the license file to obtain the authorization rules.

[0116] S707, Determine whether it is within the scope of the authorization rules. If so, execute step S711; otherwise, execute step S708.

[0117] S708, License alarm.

[0118] S709, Record the alarm log.

[0119] S710, Forcefully terminate redundant containers.

[0120] S711, Record the authorization log.

[0121] It should be noted that although the operations of the method of the present invention are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result.

[0122] According to the application program authorization and licensing method based on Docker containers proposed by the embodiments of the present application, by obtaining the image file of the Docker container in the startup state and determining whether the Docker container is authorized and licensed according to the license file in the image file, the controllability of the Docker container under license compliance operation is effectively ensured, and the problem that the software vendor cannot be controllably protected due to the replication and abuse of authorization is solved.

[0123] Further referring to Figure 8 , which shows an exemplary structural block diagram of an application program licensing device 10 based on Docker containers according to an embodiment of the present application.

[0124] As Figure 8As shown, the application program licensing device 10 based on Docker containers includes: an identification module 100, a first acquisition module 200, and a determination module 300.

[0125] The identification module 100 is used to identify the existence of Docker containers in the startup state;

[0126] The first acquisition module 200 is used to acquire the image file of the Docker container and obtain the license file of the Docker container from the image file;

[0127] The determination module 300 is used to determine whether the Docker container is authorized for licensing according to the license file.

[0128] Optionally, in some embodiments, the Docker container is started based on the image file by the service node, and the image file is obtained by the service node pulling from the private cloud.

[0129] Optionally, in some embodiments, the security path of the license file is burned in the image file, and the first acquisition module 200 is specifically used for:

[0130] Read the digest of the image file and decrypt the digest to obtain the security path;

[0131] Read the license file according to the security path.

[0132] Optionally, in some embodiments, the determination module 300 is specifically used for:

[0133] Decrypt the license file to obtain at least one license label for the Docker container;

[0134] Based on at least one license label, determine whether the Docker container is authorized for licensing.

[0135] Optionally, in some embodiments, the license label includes the preset number of containers running simultaneously, and the determination module 300 is further used for:

[0136] Detect the actual number of Docker containers currently running on the physical machine;

[0137] When the actual number is less than or equal to the preset number of containers, determine that the Docker container is authorized for licensing.

[0138] Optionally, in some embodiments, the license label includes the authorization period of the Docker container, and the determination module 300 is further used for:

[0139] Determine the expiration time of the Docker container according to the authorization period;

[0140] Obtain the current time when the physical machine is running;

[0141] When the current time has not reached the expiration time, it is determined that the Docker container is authorized.

[0142] Optionally, in some embodiments, the above-mentioned device 10 further includes:

[0143] A second acquisition module, configured to acquire at least one Docker container that is not authorized;

[0144] A third acquisition module, configured to acquire a forced termination rule from the image file;

[0145] A forced termination module, configured to forcibly terminate at least one Docker container that is not authorized according to the forced termination rule.

[0146] It should be understood that the various units or modules described in the device 10 correspond to the respective steps in the method described with reference to Figure 1 Therefore, the operations and features described above for the method also apply to the device 10 and the units included therein, and will not be repeated here. The device 10 can be pre-implemented in the browser or other security applications of the electronic device, or can be loaded into the browser or its security application of the electronic device by means of downloading, etc. The corresponding units in the device 10 can cooperate with the units in the electronic device to implement the solution of the embodiments of the present application.

[0147] The division of several modules or units mentioned in the above detailed description is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0148] According to the application program authorization and licensing device based on Docker containers proposed in the embodiments of the present application, by acquiring the image file of the Docker container in the startup state and determining whether the Docker container is authorized according to the license file in the image file, the controllability of the Docker container under license compliance operation is effectively ensured, and the problem that the software vendor cannot be controllably protected due to the replication and abuse of authorization is solved.

[0149] Next, with reference to Figure 9 , Figure 9 FIG. shows a schematic structural diagram of a computer system of an electronic device or a server suitable for implementing the embodiments of the present application,

[0150] As Figure 9As shown, computer system 900 includes a central processing unit (CPU) 901, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 902 or programs loaded into a random access memory (RAM) 903 from a storage section 908. In the RAM 903, various programs and data required for the operation instructions of the system are also stored. The CPU 901, ROM 902, and RAM 903 are connected to each other via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.

[0151] The following components are connected to the I / O interface 905; an input section 906 including a keyboard, a mouse, etc.; an output section 907 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 908 including a hard disk, etc.; and a communication section 909 including a network interface card such as a LAN card, a modem, etc. The communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed so that a computer program read therefrom can be installed into the storage section 908 as needed.

[0152] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart Figure 1 can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909, and / or installed from the removable medium 911. When the computer program is executed by the central processing unit (CPU) 901, the above functions defined in the system of the present application are executed.

[0153] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0154] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operation instructions of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code, and the foregoing module, program segment, or part of code contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two connected blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that executes the specified functions or operation instructions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0155] The units or modules involved in the embodiments described in this application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. For example, it can be described as: a processor includes the above-mentioned application authorization and licensing method based on Docker containers. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves. For example, the identification module can also be described as "identifying Docker containers in the startup state".

[0156] On the other hand, this application also provides a computer-readable storage medium, which can be included in the electronic device described in the above embodiments, or can exist alone without being assembled into the electronic device. The above computer-readable storage medium stores one or more programs, and when the above programs are executed by one or more processors, they implement the application authorization and licensing method based on Docker containers described in this application.

[0157] The above description is only a preferred embodiment of this application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. An application program licensing method based on Docker containers, characterized in that The method includes: Identifying Docker containers in a starting state; Obtaining the image file of the Docker container from the private cloud, reading the digest of the image file, and decrypting the digest to obtain a security path, where the security path maps to a hidden folder; the image file is stored in the private cloud during the construction process; Reading the license file according to the security path; Determining whether the Docker container is authorized and licensed based on whether the license file is an official release, whether it has been tampered with, whether the software authorized in the license file is genuine, whether the current time of the physical machine operation has reached the expiration time of the Docker container, whether the actual number of Docker containers currently running on the physical machine is less than or equal to the preset container number, and the comparison result between the original image signature and the image signatures of all currently running containers; 2. The application program licensing method based on Docker containers according to claim 1, wherein The Docker container is started by the service node based on the image file, and the image file is pulled by the service node from the private cloud.

3. The method according to claim 1, characterized in that Determining whether the Docker container is authorized and licensed according to the license file includes: Decrypting the license file to obtain at least one license label for the Docker container; Determining whether the Docker container is authorized and licensed based on the at least one license label.

4. The method according to claim 3, wherein The license label includes the preset number of containers running simultaneously. Determining whether the Docker container is authorized and licensed based on the at least one license label includes: Detecting the actual number of the Docker containers currently running on the physical machine; Determining that the Docker container is authorized and licensed when the actual number is less than or equal to the preset container number.

5. The method according to claim 3, characterized in that, The license label includes the authorization period of the Docker container. Determining whether the Docker container is authorized and licensed based on the at least one license label includes: Determining the expiration time of the Docker container according to the authorization period; Obtaining the current time of the physical machine operation; Determining that the Docker container is authorized and licensed when the current time has not reached the expiration time.

6. The method according to claim 4, wherein The method further includes: Obtaining at least one Docker container that is not authorized and licensed; Obtaining the forced termination rule from the image file; Forcibly terminating the at least one Docker container that is not authorized and licensed according to the forced termination rule.

7. An application program licensing device based on Docker containers, characterized in that, The device includes: An identification module, configured to identify Docker containers in a starting state; A first acquisition module, configured to obtain the image file of the Docker container from the private cloud, read the digest of the image file, decrypt the digest to obtain a security path, where the security path maps to a hidden folder; the image file is stored in the private cloud during the construction process; reading the license file according to the security path; A determination module, configured to determine whether the Docker container is authorized and licensed according to whether the license file is an official release, whether there is any tampering, whether the software authorized in the license file is genuine, whether the current time when the physical machine runs reaches the expiration time of the Docker container, whether the actual number of Docker containers currently running on the physical machine is less than or equal to the preset number of containers, and the comparison result between the original image signature and the image signatures in all currently running containers.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the application program licensing method based on Docker containers according to any one of claims 1-6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the application program licensing method based on Docker containers according to any one of claims 1-6.

Citation Information

Patent Citations

  • License managing method and device for containers

    CN108628658A

  • Docker dynamic scheduling algorithm for typical containers

    CN108897627A