Software license management and authentication
By generating a unique identifier and embedding licensing information on the client device, and performing authentication and unlock code verification, the management difficulties and security vulnerabilities of software license management in the prior art are solved, and flexible and secure software license management is achieved under different connection states.
Patent Information
- Application Number
- CN202080036506.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-05-21
- Filing Date
- 2020-05-21
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2040-05-21
AI Technical Summary
Existing software license management and authentication technologies are difficult to manage, especially when client devices are not connected to the Internet. They are easily bypassed by malicious users or cannot be effectively managed. Furthermore, existing solutions have security vulnerabilities and lack flexibility.
By generating a unique identifier on the client device, embedding license information, performing authentication protocols, generating an unlock code, and verifying user permissions, it supports multiple unlocking methods, including verbal, visual codes, and network communication, enabling secure software license management and authentication regardless of the connection status.
It provides flexible and secure software license management in connectionless, limited-connection, and fully connected scenarios, ensuring the traceability and security of user rights, covering a variety of use cases, including laboratory environments without internet connectivity.
Smart Images

Figure CN113826094B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to U.S. Patent Application Serial No. 62 / 850,974 (“974 Application”) (Attorney No. 20180164-01), filed May 21, 2019, entitled “Method and System for Implementing Software Licensing Management and Authentication”, the disclosure of which is incorporated herein by reference in its entirety for all purposes.
[0003] The publications of these applications / patents (collectively referred to in this document as “Related Applications”) are incorporated herein by reference in their entirety for all purposes.
[0004] Copyright Notice
[0005] This patent document contains copyrighted material. The copyright holder does not object to the reproduction of this patent document or patent disclosure by any person in the form it appears in in the U.S. Patent and Trademark Office's patent files or records, but otherwise reserves all copyright rights. Technical Field
[0006] This disclosure generally relates to methods, systems, and apparatus for implementing software license management and authentication, and more specifically to methods, systems, and apparatus for implementing software license management and authentication regardless of whether the client device associated with a potential licensee is connected via a communication network (such as the Internet). Background Technology
[0007] Conventional license management and authentication technologies and systems, such as those utilizing pay-as-you-go models for software licensing, allow for flexible consumption of services by users or customers. However, such conventional technologies and systems also present management challenges for license providers. In particular, conventional methods either expose vulnerabilities that allow bypassing license enforcement mechanisms, use external hardware (e.g., dongles), or force users to maintain an internet connection. In some cases, customers may require that the software or the lab itself be disconnected from the internet, forcing these customers or service providers to choose from licensing solutions known to allow for license tampering.
[0008] Previous solutions fell into four main categories: (i) local license servers; (ii) file-based licensing; (iii) hardware-based licensing; and (iv) internet-based licensing (or telex licensing). In the (i) local license server model, the end user installs a local license server to manage licenses. Because the server is installed locally, it is vulnerable to exploitation by malicious users. A similar model, (ii) file-based licensing, requires separate software to manage usage, where usage records are stored in local files, exposing the same attack surface as local license servers. (iii) Hardware-based licensing uses external hardware (e.g., dongles) connected to the machine running the software. While more robust than the two methods mentioned above, many customers are not keen on attaching externally sourced hardware to their devices to run software. Furthermore, it is known that malicious users can "ghost" or "steal" data from dongles (exposing another attack surface). In the (iv) internet-based licensing model, all management is performed by the licensor. While a separate software installation that communicates with the licensor's license server to perform license management tasks avoids the potential risks highlighted in (i) and (ii) above, this may be unacceptable due to the customer's internet policies. This model is also problematic, especially for highly sensitive labs developing business-critical products where the customer may not allow any software access to the external internet.
[0009] Therefore, there is a need for more robust and scalable solutions for implementing software license management and authentication, and more specifically, for methods, systems, and devices for implementing software license management and authentication regardless of whether the client device associated with the potential licensee is connected to a communication network (such as the Internet or other networks). Attached Figure Description
[0010] A further understanding of the nature and advantages of a particular example can be achieved by referring to the remainder of the specification and accompanying drawings, where similar reference numerals are used to refer to similar parts. In some cases, sublabels are associated with reference numerals to indicate one of several similar parts. When reference is made to reference numerals without specifying existing sublabels, it is intended to refer to all such several similar parts.
[0011] Figure 1 This is a schematic diagram illustrating various examples of systems for implementing software license management and authentication.
[0012] Figure 2 This is a schematic flowchart illustrating methods for implementing software license management and authentication based on various examples.
[0013] Figures 3A to 3FThese are schematic diagrams illustrating various non-limiting examples of software interfaces, web interfaces, pop-ups, or other user interfaces that can be used to implement software license management and authentication, based on various examples.
[0014] Figures 4A to 4D This is a flowchart illustrating methods for implementing software license management and authentication based on various examples.
[0015] Figures 5A to 5C This is a flowchart illustrating various examples of methods for implementing software license management and authentication from the perspective of a computing system or license server.
[0016] Figures 6A to 6C This is a flowchart illustrating methods for implementing software license management and authentication from the perspective of a client device, based on various examples.
[0017] Figure 7 It is a block diagram illustrating exemplary computer or system hardware architectures according to various examples.
[0018] Figure 8 It is a block diagram illustrating a networked system of computer, computing system, or system hardware architecture that can be used according to various examples. Detailed Implementation
[0019] Overview
[0020] Various examples provide tools and techniques for implementing software license management and authentication, and more specifically, methods, systems, and devices for implementing software license management and authentication regardless of whether the client device associated with the potential licensee is connected to a communication network (such as the Internet or other networks).
[0021] In various examples, a client device executing or running the first software (or licensed software) may receive a user's request for the use of a service requested by the first software. In some examples, the first software may be software that performs operations on the client device without operating or controlling any external hardware or equipment. Alternatively, the first software can be software for operating or controlling equipment, which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, optical emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments. In this example, the equipment can be any non-laboratory equipment operated by the first software that requires licensing and certification to function.
[0022] In response to receiving a request, the client device may initiate an authentication protocol of the first software, which causes the generation of a unique identifier associated with at least one of the requested service or the first software, and presents a prompt to the user to request an unlock code using the generated unique identifier.
[0023] The computing system can receive a request for an unlock code. In an example, the request for an unlock code may include a generated unique identifier, and the generated unique identifier may include license information. In response to receiving the generated unique identifier, the computing system may determine, at least in part, whether a user should have access to the requested service using the first software based on the license information embedded in the generated unique identifier. In an example, this determination may include retrieving the license information embedded in the unique identifier. The computing system may then determine, at least in part, whether a user should have access to the requested service using the first software based on at least the license information and at least one of the stored information about the user, an entity associated with the user, the requested service, or the first software.
[0024] Based on the determination that a user should have the right to access the requested service using the first software, the computing system can generate an unlock code associated with the requested service using the first software and can deduct fees associated with licensing information. In an example, the unlock code may be a session code used for unlocking a single session of the requested service using the first software. In an example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc.
[0025] The computing system can send an unlock code to the user. The client device can receive the unlock code. In response to receiving the unlock code, the client device can verify the unlock code. In response to the unlock code being verified, the client device can unlock the single-session use of the requested service using the first software, thereby allowing the user to access the single-session use of the requested service using the first software.
[0026] In some examples, the license information may include, but is not limited to, one or more of the following: data regarding the requested service using the first software; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the first software; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to the license associated with at least one of the requested service or the first software; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the first software; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on.
[0027] In the example, the license type may include, but is not limited to, one of the following: pay-per-use license, recurring subscription license, right-to-use license, or free-use license. In the example, a pay-per-use license may include, but is not limited to, a single license valid for one-time use, a single license valid for a limited number of uses, or a series of licenses valid for a limited number of uses. In the example, a recurring subscription license may include, but is not limited to, a license valid for unlimited use within a limited subscription period (e.g., a one-day license, a multi-day license, a one-week license, a multi-week license, a one-month license, a multi-month license, a quarterly license, a semi-annual license, an annual license, etc.) or a license valid for conditional or limited use within a limited subscription period (e.g., a license limited to a specific user, a license allowing multiple users to use one at a time (i.e., a seat license), etc.). For example, a right-to-use license may include, but is not limited to, an unlimited-use license with no limit on the number of uses or the duration of use. In the example, a free-use license may include, but is not limited to, a license with no charge.
[0028] As an example only, presenting a prompt to a user to request an unlock code using a generated unique identifier may include presenting two or more options, including but not limited to: displaying the generated unique identifier and communication device (or contact information) for the user to use or contact and provide (e.g., by speaking, typing, copying and pasting, etc.) the generated unique identifier; displaying a connection mechanism (e.g., a link or hyperlink, etc.) to an information collection (e.g., a webpage, database, server, data repository, etc.) that includes the generated unique identifier; or displaying a visual code and prompting the user to scan the visual code, which contains data associated with the generated unique identifier; and so on. In the example, the visual code may include, but is not limited to, a barcode or a quick response (“QR”) code.
[0029] In some examples, receiving the generated unique identifier included in the received request for an unlock code may include, but is not limited to, receiving a generated unique identifier dictated by the user over a telephone and converted via speech-to-text conversion; receiving a generated unique identifier manually entered by the user or another user via a user interface via a text input field; receiving a generated unique identifier copied and pasted by the user via a user interface via a text input field; receiving the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera; or receiving the generated unique identifier from the client device via network communication when the client device is connected to a communication network (e.g., the Internet or other networks); and so on. In the examples, the capture of the visual code image may trigger one of the following: sending the generated unique identifier to a computing system via a network; or accessing an information collection (e.g., a webpage, website, or web portal, etc.) that allows the user to manually enter the generated unique identifier.
[0030] Based on the various examples described herein, software license management and authentication systems and functions provide traceability and security for a communication network connectivity model while allowing for the flexibility of a pay-as-you-go model. Software license management and authentication systems and functions also provide a simple path for users not connected to a communication network to communicate with a license server for licensing purposes. In fact, software license management and authentication systems and functions cover a wide range of use cases, allowing for secure licensing with the flexibility of a pay-as-you-go model: (a) connectionless; (b) limited connectivity via a telephone data plan; or (c) full communication network (e.g., full internet connectivity, etc.). In the connectionless model, the licensee can use a telephone to transmit a short, easily spoken set of characters to the license server. In the limited connectivity model, the licensee can use his / her or their telephone to capture the license code and transmit it to the license server (either verbally or via DTMF signaling, etc.). In the full communication network connectivity use case, the software silently handles all communications for the licensee (i.e., handles all communications between the client device and the license server, etc., in the background). Based on some examples, some key features or benefits of software license management and authentication systems and functions may include, but are not limited to: creating a unique identifier in which license information is embedded or “buried”; providing multiple ways to unlock the license (including, but not limited to: (a) verbally speaking the identifier, unlock code numbers and / or letters over the phone; (b) via a smartphone; or (c) silently or in the background process via a communication network; etc.); uniquely binding the identifier and unlock code together; etc.
[0031] These and other aspects of the software license management and certification system and functionality are described in more detail with reference to the accompanying drawings. In some aspects, the software license management and certification system and functionality can also be integrated with smart labs, content management, or lab workflow management systems (such as, but not limited to, Agilent Technologies). It can be integrated with other similar software suites, etc.
[0032] The following detailed description illustrates several exemplary examples in more detail to enable those skilled in the art to practice such examples. The described examples are provided for illustrative purposes and are not intended to limit the scope of the invention.
[0033] In the following description, numerous specific details are set forth for purposes of explanation in order to provide a thorough understanding of the described examples. However, it will be apparent to those skilled in the art that other examples of the invention can be practiced without some of these specific details. In other instances, certain structures and devices are shown in block diagram form. Several examples are described herein, and although various features are attributed to different examples, it should be understood that features described with respect to one example may also be combined with other examples. However, for the same reason, no single feature or multiple features of any described example should be considered essential to every example of the invention, as such features may be omitted in other examples of the invention.
[0034] Unless otherwise stated, all figures used herein to indicate quantity, size, etc., should be understood to be modified by the term "about" in all cases. In this application, unless otherwise specified, the use of the singular includes the plural, and unless otherwise indicated, the use of the terms "and" and "or" means "and / or". Furthermore, the use of the term "including" and other forms such as "includes" and "included" should be considered non-exclusive. Additionally, unless otherwise specified, terms such as "element" or "component" cover both elements and components comprising one unit and elements and components comprising more than one unit.
[0035] While the various examples described herein embody (in some cases) software products, computer-executed methods, and / or computer systems, they represent tangible, concrete improvements to existing technologies, including but not limited to license management technologies, license authentication technologies, license management and authentication technologies, etc. In other aspects, certain examples may improve the functionality of the user equipment or system itself (e.g., a license management server or system, a license authentication server or system, a license management and authentication server or system, etc.) by: receiving a user's request for a requested service using the first software; in response to receiving the request, initiating an authentication protocol in the first software that causes the generation of a unique identifier associated with at least one of the requested service or the first software, and presenting the user with a prompt to request an unlock code using the generated unique identifier; receiving a request for an unlock code for the requested service using the first software, wherein the request for the unlock code includes the generated unique identifier, wherein the generated unique identifier... The generated unique identifier includes license information; in response to receiving the generated unique identifier, determining whether a user should have access to the requested service of the first software based at least in part on the license information embedded in the generated unique identifier; based on determining that the user should have access to the requested service of the first software, generating an unlock code associated with the requested service of the first software, and sending the unlock code to the user; receiving the unlock code; in response to receiving the unlock code, verifying the unlock code; and in response to the unlock code being verified, unlocking a single session of use of the requested service of the first software to allow the user access to the single session of use of the requested service of the first software; and so on.
[0036] In particular, with regard to any abstract concepts present in the various examples, these concepts can be implemented, as described herein, by means of apparatus, software, systems, and methods involving specific new functions (e.g., steps or operations) that go beyond mere conventional computer processing operations. These specific new functions (e.g., steps or operations) include, for example, generating a unique identifier in which license information is embedded, such as, to name a few, data about the requested service using the first software, session data used for a session of the requested service, data about the type of system used to provide the requested service, or information about the type of license associated with at least one of the requested service or the first software; using the unique identifier as half of a handshake between the client computer and the license server; generating an unlock code in which data including at least one of the following is embedded: security-related data; data associated with the generated unique identifier; data about the type of user; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service, wherein the unlock code is a session code used to unlock a single session of the requested service using the first software and is the second half of a handshake between the client computer and the license server; and so on. These features can produce tangible results beyond the implementation of computer systems, including (by way of example) optimized license management and authentication features to address the limitations, security vulnerabilities, and fraud inherent in conventional license management and authentication systems (at least some of which customers and / or service providers may observe or measure). Invention Summary
[0037] In one aspect, a method may include receiving from a user of a client device running first software thereon a request for an unlock code for a requested service using the first software. The request for the unlock code may include: a generated unique identifier associated with at least one of the requested service or the first software. The generated unique identifier may include license information. The license information may be embedded in the generated unique identifier. The license information may include at least one of: data regarding the use of the requested service with the first software; session data used for a session of the requested service; data regarding the type of system used to provide the requested service; or information regarding the type of license associated with at least one of the requested service or the first software; and so on.
[0038] In response to receiving the generated unique identifier, the method may further include: extracting the license information embedded in the unique identifier. The method may further include: determining, at least in part, whether the user should have permission to access the requested service using the first software based on the license information and at least one of stored information about the user, an entity associated with the user, the requested service, or the first software.
[0039] The method may further include: generating an unlock code associated with the requested service of the first software based on determining that the user should have the right to access the requested service using the first software, and deducting a fee associated with the license information. The method may further include sending the unlock code to the user. The unlock code may be a session-per-session code used for unlocking a single session of the requested service using the first software.
[0040] In the example, the license information may also include one or more of the following: information about the generation time of the generated unique identifier; information about session information verification; information about the fee corresponding to the license associated with at least one of the requested service or the first software; information about the conditions associated with the license; information about the restrictions associated with the license; information about the type of hardware associated with the first software; information about the type of hardware associated with the requested service; or information about session usage of the requested service; etc. The license type may include one of the following: pay-per-use license, recurring subscription license, right-to-use license, or free-to-use license, etc.
[0041] In the example, the pay-as-you-go license may include a license based on the amount of credits purchased or pre-ordered. The requested service, one of several available services, may use a predetermined amount of credits per session. In such an example, the method may further include, after generating the unlock code, maintaining a counter that indicates the remaining amount of credits from the purchased or pre-ordered amount, decreasing by the predetermined amount of credits used per session. The counter may be associated with the user or an entity associated with the user.
[0042] In the example, the method may further include: receiving, decrypting, and authenticating a refund code from the user. The method may also include: in response to receiving, decrypting, and authenticating the refund code, invalidating the current single-session use of the requested service using the first software, and incrementing a counter indicating the remaining amount of credits by a predetermined amount of credits used per session of the requested service. In the example, the option to access the refund code may be available before the delivery of the single-session use of the requested service using the first software ends. Once the delivery of the single-session use ends, the option to access the refund code may be deactivated.
[0043] In the example, the method may further include: receiving, decrypting, and authenticating a purchase code from the user. The purchase code may correspond to the purchase of one or more additional credits. In the example, the method may further include: in response to receiving, decrypting, and authenticating the purchase code, incrementing a counter indicating the remaining amount of credits by the amount of one or more additional credits purchased. In the example, at least one of the purchased or pre-ordered amount of credits, the remaining amount of credits, or the one or more additional credits may be allocated to at least one of: an entity associated with the pay-per-use license; an account associated with the entity; or one or more individuals associated with the entity; etc.
[0044] In the example, receiving the generated unique identifier included in the received request for the unlock code may include one of the following: receiving the generated unique identifier dictated by the user over a telephone and converted via speech-to-text conversion; receiving the generated unique identifier manually entered by the user or another user via a user interface via a text input field; receiving the generated unique identifier copied and pasted by the user via the user interface via a text input field; receiving the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera; or receiving the generated unique identifier from the client device via network communication when the client device is connected to a communication network; and so on. In the example, the image of the visual code, when captured, may trigger one of the following: sending the generated unique identifier to the computing system via a network; or accessing an information set that allows the user to manually enter the generated unique identifier.
[0045] In the example, the unlock code may include embedded data, which includes at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of service requested; or data about the type of hardware associated with the requested service; and so on.
[0046] In the example, generating the unlock code associated with the requested service using the first software may include: arranging the generated unique identifiers in a predetermined manner, and creating a hash-based message authentication code (“HMAC”) using a cryptographic hash function including a secure hash algorithm (“SHA”). The secure hash algorithm may include one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256, etc.
[0047] In another aspect, an apparatus may include: at least one processor; and a non-transitory computer-readable medium communicatively coupled to said at least one processor. The non-transitory computer-readable medium may store computer software thereon comprising a set of instructions, which, when executed by said at least one processor, cause the apparatus to: receive from a user using a client device executing first software thereon a request for an unlock code for a requested service using the first software, wherein the request for the unlock code includes a generated unique identifier associated with at least one of the requested service or the first software, wherein said generated unique identifier includes license information, the license information including at least one of: data regarding the use of the requested service with the first software; session data for a session using the requested service; data regarding the type of system used to provide the requested service; or license information associated with at least one of the requested service or the first software. Information on the type of license; in response to receiving the generated unique identifier, extracting the license information embedded in the decrypted generated unique identifier, and determining, at least in part, whether the user should have access to the requested service of the first software based on at least one of the license information and stored information about the user, an entity associated with the user, the requested service, or the first software; and based on the determination that the user should have access to the requested service of the first software, generating an unlock code associated with the requested service of the first software; deducting the fee associated with the license information; and sending the unlock code to the user, wherein the unlock code is a session code used for unlocking a single session of the requested service of the first software.
[0048] In another aspect, a method may include: receiving a user's request for use of a requested service using first software. The method may further include: in response to receiving the request, initiating an authentication protocol in the first software to generate a unique identifier associated with at least one of the requested service or the first software, and presenting the user with a prompt to request an unlock code using the generated unique identifier. The generated unique identifier may include license information, which includes at least one of the following: data regarding the use of the requested service using the first software; session data for a session using the requested service; data regarding the type of system used to provide the requested service; or information regarding the type of license associated with at least one of the requested service or the first software; etc. The generated unique identifier may be sent to and verified by a license server.
[0049] The method may further include: receiving an unlock code from the license server in response to sending the generated unique identifier to the license server. The unlock code may be a session code for unlocking a single session of the requested service using the first software. The method may further include: verifying the unlock code in response to receiving it. The method may further include: unlocking the single session of the requested service using the first software in response to the unlock code being verified, thereby allowing the user to access the single session of the requested service using the first software.
[0050] In the example, the license information may also include one or more of the following: information about the generation time of the generated unique identifier; information about session information verification; information about the fee corresponding to the license associated with at least one of the requested service or the first software; information about the conditions associated with the license; information about the restrictions associated with the license; information about the type of hardware associated with the first software; information about the type of hardware associated with the requested service; or information about session usage of the requested service; etc. The license type may include one of the following: pay-per-use license, recurring subscription license, right-to-use license, or free-to-use license, etc.
[0051] In the example, the method may further include encoding the generated unique identifier. Encoding the generated unique identifier may include using one of the following: Base16 encoding scheme, Base32 encoding scheme, Base36 encoding scheme, Base58 encoding scheme, or Base64 encoding scheme, etc.
[0052] In the example, presenting the user with a prompt to request an unlock code using the generated unique identifier may include presenting two or more options, including: displaying the generated unique identifier and a communication device for the user to use or contact and provide the generated unique identifier; displaying a connection mechanism to an information collection, the connection mechanism including the generated unique identifier; or, displaying a visual code and prompting the user to scan the visual code, the visual code containing data associated with the generated unique identifier; and so on. In the example, the visual code may include one of a barcode or a quick response (“QR”) code, etc.
[0053] In the example, the method may further include: determining whether the client device is connected to a communication network before presenting the user with a prompt to request an unlock code using the generated unique identifier. The method may further include: graying out an option to display the connection mechanism with the information collection based on the determination that the client device is not connected to the communication network or has restricted access to the communication network.
[0054] In the example, sending the generated unique identifier to the license server for verification may include one of the following: sending the generated unique identifier dictated by the user over a telephone; sending the generated unique identifier manually entered by the user or another user via a user interface; sending the generated unique identifier copied and pasted by the user via the user interface; sending the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera; or, when the client device is connected to a communication network, sending the generated unique identifier from the client device via network communication; and so on. The capture of the image of the visual code may trigger one of the following: sending the generated unique identifier to the computing system via the network; or accessing an information set that allows the user to manually enter the generated unique identifier; and so on.
[0055] In another aspect, an apparatus may include: at least one processor; and a non-transitory computer-readable medium communicatively coupled to said at least one processor. The non-transitory computer-readable medium may store thereon computer software comprising a set of instructions, which, when executed by said at least one processor, cause the apparatus to: receive a user's request for a requested service using first software executed on said apparatus; in response to receiving the request for use of the first software, initiate an authentication protocol of the first software that causes the generation of a unique identifier, and present the user with a prompt to request an unlock code using the generated unique identifier, wherein the generated unique identifier includes license information, the license information including at least one of: data relating to the use of the requested service of the first software; session data for a session using the requested service; and information relating to a system for providing the requested service. The data pertains to the type of the license; or information regarding the type of license associated with at least one of the requested service or the first software, wherein the generated unique identifier is sent to and verified by a license server; in response to sending the generated unique identifier to the license server, the unlock code is received from the license server, wherein the unlock code is a session code for unlocking a single session of the requested service using the first software; in response to receiving the unlock code, the unlock code is verified; and in response to the unlock code being verified, the single session of the requested service using the first software is unlocked to allow the user to access the single session of the requested service using the first software.
[0056] Various modifications and additions can be made to the examples discussed without departing from the scope of the invention. For example, although the examples above refer to specific features, the scope of the invention also includes examples with different combinations of features and examples that do not include all of the features described above.
[0057] Specific examples
[0058] We now turn to the example shown in the figure. Figures 1 to 8 Some features of methods, systems, and apparatuses for implementing software license management and authentication are shown, and more specifically, methods, systems, and apparatuses for implementing software license management and authentication regardless of whether the client device associated with the potential licensee is connected to a communication network (e.g., the Internet or other networks), as described above. Figures 1 to 8 The methods, systems, and apparatuses illustrated refer to examples of different embodiments including various components and steps, which may be considered alternatives or may be used in combination with each other in various embodiments. Figures 1 to 8The descriptions of the methods, systems, and devices shown are for illustrative purposes and should not be construed as limiting the scope of the different examples.
[0059] Refer to the attached diagram. Figure 1 This is a schematic diagram illustrating a system 100 for implementing software license management and authentication, based on various examples.
[0060] exist Figure 1 In a non-limiting example, system 100 may include client device 105, equipment 110 (optional), and first software or licensed software 115 running on client device 105. In some examples, licensed software 115 may be software that performs operations on client device 105 without operating or controlling any external hardware or equipment. Alternatively, the licensed software 115 may be software for operating or controlling equipment 110 (if present), which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments. In this example, equipment 110 may be any non-laboratory equipment operated by licensed software that requires licensing and certification to function. In the example, the client device 105 may be one of the following: a laboratory computer that communicates with and controls the equipment 110; a desktop computer that communicates with and controls the equipment 110; a laptop computer that communicates with and controls the equipment 110; a portable computing system that communicates with and controls the equipment 110; a mobile user device that communicates with and controls the equipment 110; an external dedicated control device that communicates with and controls the equipment 110; or an integrated dedicated control device that controls the equipment 110, etc.
[0061] System 100 may also include a computing system 120a and a corresponding database 125a. In one example, database 125a may be local to computing system 120a (or located near the computing system) (e.g., integrated within computing system 120a). In other examples, database 125a may be external to computing system 120a but communicatively coupled to it. Computing system 120a may be located near client device 105. System 100 may also include a user 130 and user device 135, also located near client device 105. In some examples, each user device 135 may include, but is not limited to, a processor 135a, a data storage area 135b, one or more cameras 135c, a display device 135d, a transceiver 135e, and a user interface device 135f. In one example, user device 135 may include, but is not limited to, a smartphone, mobile phone, tablet computer, laptop computer, desktop computer, or augmented reality (“AR”) headset. For example, an AR headset is described in detail in U.S. Patent Application Serial No. 16 / 418,818 (Attorney's Case No. 20160073-02), filed May 21, 2019, entitled "Method and System for Implementing Augmented Reality (AR)-Based Assistance Within Work Environment," which claims priority to U.S. Patent Application Serial No. 62 / 675,122 ("122 Application") (Attorney's Case No. 20160073-01), filed May 22, 2018, entitled "Method and Apparatus for Facilitating Manual Sorting of Objects," each of which disclosures is incorporated herein by reference in its entirety for all purposes.
[0062] In some examples, processor 135a may be communicatively coupled (e.g., via a bus, via a wired connector, or via electrical pathways (e.g., traces and / or pads, etc.) of a printed circuit board (“PCB”) or integrated circuit (“IC”) to one or more of the following: data storage area 135b; one or more cameras 135c; display device 135d; transceiver 135e; and user interface device 135f, etc.) processor 135a may perform the functions of user device 135, including but not limited to cellular communication functions, network connectivity functions, internet connectivity functions, computing functions, image capture functions, etc. Data storage area 135b may store data acquired during the performance of the functions of user device 135. Camera 135c may be used to capture images of unique identifiers associated with at least one of the requested service or licensed software 115, which may be displayed on the display screen (not shown) of client device 105. In the example, user device 135 may use camera 135c to decode or otherwise read a unique identifier to perform functions (e.g., decode, read, or scan a barcode or QR code, which in the example may direct the user to an information collection (e.g., a webpage, website, or web portal, etc.)) and other user device or camera functions.
[0063] The display screen or display device 135d can be used to display a telephone user interface, an information collection (e.g., a webpage, website, or web portal), a computing-based user interface, an image captured by camera 135c, etc. The transceiver 135e can be used for wireless communication with computing system 120a or with a communication relay device (not shown). The transceiver 135e can also be used to transmit data, including but not limited to data about a unique identifier. The transceiver 135e can also be used to communicate with license server 140 via wireless communication, wired communication, or cellular communication, etc. The transceiver 135e can also be used to communicate with remote computing system 120b or with a communication relay device (not shown), etc. The user interface device 135f can include, but is not limited to: keys; numeric keys; a keyboard; one or more buttons; one or more switches; one or more lights; and / or a touchscreen display (in which case, display device 135d and user interface device 135f can be embodied as a single device), etc. In some examples, wireless communication can be used between or within multiple devices (e.g., ...). Figure 1 The lightning bolt symbol depicts wireless communication between client device 105 and computing system 120a, between client device 105 and network 150, between user device 135 and computing system 120a, and between user device 135 and network 150. Alternatively or additionally, wired communication (such as...) can be used. Figure 1The diagram depicts wired communication between client device 105 and computing system 120a via network 150, between client device 105 and network 150, between user device 135 and computing system 120a via network 150, and between user device 135 and network 150.
[0064] In some examples, system 100 may further include a license server 140 and a corresponding database 145 accessible by client device 105, computing system 120a, and / or user device 135 via one or more networks 150. According to some examples, instead of computing system 120a and the corresponding database 125a being located locally (or near) client device 105, system 100 may also include a remote computing system 120b (optional) and a corresponding database 125b (optional), located remotely from client device 105 and communicatively coupled to client device 105, user device 135, and / or license server 140 via one or more networks 150. In this document, while some components of system 100 are indicated as optional and others are not, this is only for the specific examples shown, and in other examples, one or more components in the former group (or those indicated as “optional”) may be required, while one or more components in the latter group (or those not indicated as “optional”) may actually be optional.
[0065] By way of example only, network 150 may each include: local area network (“LAN”), including but not limited to fiber optic network, Ethernet, Token-Ring TM Wide area network (“WAN”); wireless wide area network (“WWAN”); virtual network, such as virtual private network (“VPN”); Internet; intranet; extranet; public switched telephone network (“PSTN”); infrared network; wireless network, including but not limited to any IEEE 802.11 protocol suite, Bluetooth as known in the art. TM Networks operating under this protocol and / or any other wireless protocol; and / or any combination of these and / or other networks. In a particular example, network 150 may each include the access network of an Internet Service Provider (“ISP”). In another example, network 150 may each include the ISP’s core network and / or the Internet.
[0066] In operation, the client device 105, on which the first software or licensed software 115 is executed or running, can receive a request from the user 130 for the use of a requested service of the licensed software 115. In the example, the requested service may include, but is not limited to, one of the following: Installation Qualification (“IQ”) service, Preventive Maintenance (“PM”) service, Repair Qualification (“RQ”) service, Functional Verification (“FV”) service, Operational Qualification (“OQ”) service, Mechanical Qualification (“MQ”) service, Performance Qualification (“PQ”) service, or other services that can be executed on or using the equipment 110. Alternatively, the requested service may include the operational use of the licensed software 115. In response to receiving a request, the client device 105 may initiate an authentication protocol for the licensed software 115, which causes the generation of a unique identifier associated with at least one of the requested service or the licensed software 115, and presents the user 130 with a prompt to request an unlock code using the generated unique identifier.
[0067] Based on some examples, unique identifiers can be encoded using one of the following schemes: Base16, Base32, Base36, Base58, or Base64. Base32 and Base58 encodings use selected character sets to avoid seemingly similar pairs of different symbols. For example, Base32 encoding includes the 26 uppercase letters A, Z, and the digits 2-7, where the digits 0, 1, 8, and 9 are removed to avoid confusion with the letters O, I, B, and q, respectively. Variations of Base32 encoding similarly avoid seemingly similar pairs of different symbols but use different character sets. Similarly, Base58 encoding includes uppercase letters, lowercase letters, and digits, excluding uppercase letters O and I, lowercase letter l, and the digit 0. While BaseXX encoding is described as a way to encode unique identifiers, various examples are not limited to this; rather, any suitable encoding scheme or technique can be used to encode unique identifiers.
[0068] Computing system 120a, remote computing system 120b, and / or license server 140 (collectively, "computing system, etc.") can receive requests for unlock codes. In an example, the request for an unlock code may include a generated unique identifier, and the generated unique identifier may include license information. In response to receiving the generated unique identifier, the computing system may determine, at least in part, whether a user should have access to the requested service using licensed software 115 (which may be stored in corresponding databases 125a, 125b, and / or 145, etc.) based on the license information embedded in the generated unique identifier. In an example, this determination may include retrieving the license information embedded in the unique identifier. The computing system may then determine, at least in part, whether a user should have access to the requested service using licensed software 115 based on at least one of the license information and at least one of the stored information about user 130, entities associated with that user, the requested service, or licensed software 115, etc.
[0069] Based on the determination that a user should have the right to access the requested service using licensed software 115, the computing system can generate an unlock code associated with the requested service using licensed software 115 and can deduct fees associated with the license information. In an example, the unlock code may be a session code used for unlocking a single session of the requested service using licensed software 115. In an example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc. In an example, generating an unlock code associated with the requested service using licensed software 115 may include: arranging the unique identifier in a predetermined manner and creating a hash-based message authentication code ("HMAC") using a cryptographic hash function including a secure hash algorithm ("SHA"). In the examples, secure hash algorithms may include, but are not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256. Although SHA is described as a way to create hashes, the various examples are not limited to this, and any suitable hashing mechanism or technique can be used.
[0070] The computing system can send an unlock code to the user. The client device 105 can receive the unlock code. Upon receiving the unlock code, the client device 105 can verify it. In response to the verified unlock code, the client device 105 can unlock the single-session use of the requested service by the licensed software 115, thereby allowing the user to access the single-session use of the requested service by the licensed software 115.
[0071] Alternatively, based on the determination that the user should not have the right to access the requested services using licensed software 115, the computing system may send or display a message to the user indicating that the unique identifier is invalid or incorrect. In other examples, based on the determination that the unique identifier matches a known but already used unique identifier corresponding to licensed software 115, the computing system may send or display a message to the user indicating that the unique identifier is no longer valid or has expired. In the example, during the verification process, the unlock code may be deemed invalid or expired; in this case, the client device may display a message to the user indicating that the unlock code is invalid or has expired.
[0072] In some examples, the license information may include, but is not limited to, at least one of the following: data regarding the use of the requested service by the licensed software 115; session data for the session use of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the licensed software 115; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to (or associated with) the license associated with at least one of the requested service or the licensed software 115; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the licensed software 115; information regarding the type of hardware associated with the requested service; or information regarding the session use of the requested service; and so on.
[0073] In the example, the license type may include, but is not limited to, one of the following: pay-per-use license, recurring subscription license, right-to-use license, or free-use license. In the example, a pay-per-use license may include, but is not limited to, a single license valid for one-time use, a single license valid for a limited number of uses, or a series of licenses valid for a limited number of uses. In the example, a recurring subscription license may include, but is not limited to, a license valid for unlimited use within a limited subscription period (e.g., a one-day license, a multi-day license, a one-week license, a multi-week license, a one-month license, a multi-month license, a quarterly license, a semi-annual license, an annual license, etc.) or a license valid for conditional or limited use within a limited subscription period (e.g., a license limited to a specific user, a license allowing multiple users to use one at a time (i.e., a seat license), etc.). For example, a right-to-use license may include, but is not limited to, an unlimited-use license with no limit on the number of uses or the duration of use. In the example, a free-use license may include, but is not limited to, a license with no charge.
[0074] In some respects, a pay-per-use license may provide a user with one of the following: a single-use pay-per-use license may provide a single use; a single-use pay-per-use license may provide a predetermined or selected number of uses (e.g., 5 uses, 10 uses, etc.); or a single-use pay-per-use license may provide a predetermined or selected number of credits (e.g., 10 credits, 15 credits, 20 credits, etc.), where using the licensed software 115 to operate a specific instrument or equipment 110 or to perform a specific process may require 5 credits, while using the licensed software 115 to operate or perform another may require 10 credits, and so on; and so on. In the event of a refund, the use may be credited as another single use, yet another use, or one or more credits corresponding to the amount of credits for which the refunded use is valued, respectively corresponding to the types of pay-per-use licenses described above. In the example, the user may purchase additional uses and / or credits. In the example, the fee corresponding to the license may refer to one of the following: the remaining number of uses for the licensed software 115; the remaining amount of credits for using the licensed software 115; or the amount of credits required to operate a specific instrument or perform a specific process using the licensed software 115; etc. For simplicity but without limitation, the described... Figure 2 The example up to Figure 6 utilizes a credit-based system, but it can alternatively (or additionally) utilize a usage-based system, etc.
[0075] As an example only, presenting a prompt to a user to request an unlock code using a generated unique identifier may include presenting two or more options (on a display screen (not shown) of a client device). In the example, the two or more options may include, but are not limited to: displaying the generated unique identifier and a communication device for the user to use or contact and provide (e.g., by speaking, typing, copying and pasting, etc.) the generated unique identifier (or manually entering it via a telephone number pad, etc., using DTMF signaling input). In the example, the two or more options may also include, but are not limited to, displaying a connection mechanism to an information collection, which (e.g., a link including a Uniform Resource Locator ("URL") includes the generated unique identifier. In the example, the two or more options may also include, but are not limited to, displaying a visual code and prompting the user to scan it, the visual code containing data associated with the generated unique identifier (and in the example, including an embedded connection mechanism (e.g., an embedded URL, etc.) or instructions to connect to an information collection (e.g., a webpage, website, or web portal, etc.); and so on. In the example, the visual code may include, but is not limited to, a barcode or a quick response ("QR") code.
[0076] In some examples, receiving the generated unique identifier included in the received request for the unlock code may include, but is not limited to, receiving a generated unique identifier dictated by user 130 via telephone (e.g., user device 135) and converted via speech-to-text conversion; receiving the generated unique identifier manually entered by the user or another user via a user interface via a text input field; receiving the generated unique identifier copied and pasted by the user via a user interface via a text input field; receiving the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera (e.g., camera 135c of user device 135, etc.); or receiving the generated unique identifier from client device 105 via network communication when client device 105 is connected to a communication network (e.g., network 150, etc.); and so on. In the examples, the capture of the image of the visual code may trigger one of the following: (in some cases, via a network (e.g., network 150)) sending the generated unique identifier to a computing system; or accessing an information collection (e.g., a webpage, website, or web portal, etc.) that allows the user to manually enter the generated unique identifier.
[0077] The following is for reference. Figure 2 These and other functions of system 100 (and its components) are described in more detail in Figure 4.
[0078] Figure 2This is a schematic flowchart illustrating a method 200 for implementing software license management and authentication, based on various examples.
[0079] refer to Figure 2 In a non-limiting example, method 200 may include starting at client device 205, on which licensed software 215 runs or executes. At step 1, in the example, in response to a user's request to use a requested service employing licensed software 215, the client device may generate a unique identifier associated with at least one of the requested service or licensed software 215. In the example, the unique identifier (which may be embodied in a session code, etc.) may include embedded licensing information. The license information may include, but is not limited to, at least one of the following: data regarding the use of the requested service by the licensed software 215; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the licensed software 215; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to the license associated with at least one of the requested service or the licensed software 215; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the licensed software 215; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on. In the example, the type of license may include, but is not limited to, one of the following: a pay-per-use license, a periodic subscription license, a right-to-use license, or a free-to-use license, etc.
[0080] At step 2, user device 235 (e.g., smartphone, mobile phone, tablet computer, laptop computer, AR headset, etc.) can capture a unique identifier (which can be displayed on the screen (not shown) of client device 205). At step 3, user device 235 can send the unique identifier to license server 240 via network 250. Alternatively, sending the unique identifier may include: sending a unique identifier dictated by the user via telephone (e.g., user device 235, etc.); sending a unique identifier manually entered by the user or another user via a user interface; sending a unique identifier copied and pasted by the user via a user interface; sending the unique identifier as a visual code, the image of which is captured by the user using the user device's camera; or sending the unique identifier via network communication when the client device is connected to a communication network (e.g., network 250, etc.).
[0081] At step 4, in response to receiving the unique identifier, the license server 240 can extract the license information embedded in the unique identifier. The license server 240 can then determine, at least in part, whether the user should have access to the requested service using the licensed software 215 based on at least one of the license information and at least one of stored information about the user, entities associated with the user, the requested service, or the licensed software. Based on the determination that the user should have access to the requested service using the licensed software 215, the license server 240 can generate an unlock code associated with the requested service using the licensed software 215 and can deduct the fees associated with the license information. In the example, the unlock code may be a session code used for unlocking a single session of the requested service using the licensed software 215. In the example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with the generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc.
[0082] At step 5, license server 240 may send an unlock code to user device 235 via network 250. At step 6, user device 235 may input the unlock code on client device 205, which may include: prompting the user to manually enter the unlock code displayed on the display screen (not shown) of user device 235; or sending a signal from user device 235 to client device 205, the signal carrying an instruction to fill in the unlock code (also included in the signal) in the appropriate field displayed on the display screen (not shown) of client device 205. At step 7, client device 205 (or licensed software 215) may verify the unlock code. Once verified, client device 205 may use licensed software 215 to unlock a single session of the requested service, allowing the user to access the single session of the requested service using licensed software 215. During the verification process, if the unlock code is deemed invalid or expired, client device 205 may display a message to the user indicating that the unlock code is invalid or expired.
[0083] Figure 2 The license management and certification process can be referenced in other ways as described above. Figure 1 The operation process described in System 100 is similar, even if not exactly the same.
[0084] Figures 3A to 3F(Collectively, “Figure 3”) is a schematic diagram illustrating various non-limiting examples 300 of software interfaces, web interfaces, pop-ups, or other user interfaces that can be used to implement software license management and authentication, according to various examples. Although Figure 3 depicts a specific set of examples for implementing software license management and authentication (particularly for unlocking software sessions to use specific laboratory equipment under a pay-per-use license), the various examples are provided for illustrative purposes only and are not limited thereto. Therefore, the license management and authentication depicted in Figure 3 can be applied to the license management and authentication of any suitable type of software that requires authentication to function and can be used to operate or control equipment (or alternatively, can be used for software that runs only on a client device without operating or controlling any external hardware or equipment). The license management and authentication depicted in Figure 3 can be used in any suitable license scenario (whether pay-per-use, periodic subscription, or usage rights, etc.).
[0085] refer to Figure 3A This shows a software pre-configuration screen 305, in which the user can select (use) Figure 3A (Radial buttons or other selection mechanisms depicted) for new or existing sessions. The software pre-configuration screen 305 also allows the user to select one or more services to be performed in the selected session (using methods such as...). Figure 3A The drop-down list shown; for example, "Operation Qualifications," etc.). Using the software pre-configuration screen 305, users can also select the system type (also using, for example, drop-down lists). Figure 3A The drop-down lists shown are examples of this; for instance, "Gas Chromatography" and so on. The software pre-configuration screen 305 also allows users to select supported system types (also using drop-down lists such as...). Figure 3A The drop-down list shown; for example, "NA" (or not applicable), etc. Furthermore, using the software pre-configuration screen 305, users can name the selected session (also using, for example,...). Figure 3A The dropdown lists shown in the example can also be manually entered dropdown lists to allow users to manually enter characters when providing dropdown list functionality; for example, "New Session 1", etc.
[0086] Turn Figure 3B The unlock session pop-up window or screen 310 may display the session code in the session code field 315 (in this case, "0800-0002-0000-0PAE-M81G"). The session code is a unique identifier associated with the software for operation or control purposes. Figure 3A The system and / or running software selected in the pre-configuration screen 305 shown Figure 3AThe selected session shown must be authenticated using a unique identifier. In the example, the unique identifier comprises a unique sequence of numbers, alphanumeric characters, alphanumeric characters, special characters, or combinations thereof (collectively referred to as "characters of a unique sequence") used to identify the part of the software being used. Embedded within this unique sequence of characters are at least two key pieces of information: the licensed technology or service (e.g., gas chromatography, liquid chromatography, mass spectrometry, other lab-based analyses, non-lab-based services (e.g., applications or computer programs, etc.)) and the services provided by the system (e.g., operating qualifications, installation qualifications, etc.). Given these two pieces of information, the system can determine how many license credits to charge the user. According to some examples, this identifier may be permanently bound to a specific run of a session initiated by the user (e.g., a field engineer, etc.). Here, there is a one-to-one correspondence between the session (or run) and the identifier.
[0087] In the example, the unique identifier may also contain other licensing information embedded therein, including but not limited to at least one of the following: session data used for session use of the requested service; information about the type of license associated with at least one of the requested service or software; information about the generation time of the unique identifier; information about session information verification; information about the fees corresponding to the license associated with at least one of the requested service or software; information about the conditions associated with the license; information about the restrictions associated with the license; information about the type of hardware associated with the software; information about the type of hardware associated with the requested service; or information about session use of the requested service; and so on. In the example, the type of license may include, but is not limited to, one of the following: a pay-per-use license, a recurring subscription license, a right-to-use license, or a free-to-use license.
[0088] The unlock session pop-up window or screen 310 may also display a message to contact the communication device shown in the contact information field 320 (in this case, dialing the phone number "1-800-123-4567") to unlock the selected session. The unlock session pop-up window or screen 310 may alternatively or additionally display alternative options for navigating to an information collection (e.g., a webpage, website, or web portal), the navigation following a connection mechanism (e.g., a Uniform Resource Locator (“URL”) shown in the connection mechanism field 325). The unlock session pop-up window or screen 310 may alternatively or additionally display a visual code 330 (including, but not limited to, a barcode (not shown) or a quick response (“QR”) code (such as...). Figure 3B(as shown in the image). When the visual code 330 is scanned by a suitable code reader or scanner (e.g., a smartphone or tablet running a barcode or QR code scanner software application (“app”), or a dedicated scanning device), it can direct the user to an information collection (e.g., a webpage, website, or web portal) that provides the user with access to the unlock code. Alternatively, the unlock session pop-up or screen 310 may display the connection mechanism (e.g., a URL) shown in the connection mechanism field 325. In the example, when the user clicks or selects the connection mechanism, the user is navigated to an information collection (such as... Figure 3C The unlock session window 345 shown above, and the appropriate input fields can be automatically filled with the session code (as shown in the session code field 315).
[0089] The unlock session pop-up window or screen 310 may also display the unlock code field 335 and the corresponding unlock session button 340. In this way, after generating the unique identifier (i.e., the session code), the software application stops running and waits for the unlock code to be entered, displaying the unique identifier for the user (e.g., a field engineer, etc.) to capture. Here, as... Figure 3B As shown, multiple paths are presented in the dialog box or screen 310: the user can follow the provided connection mechanism (such as in the case of a communication network connection); the user can scan and activate the visual code (in this case, a QR code; such as in the case of a user device data plan) using a smartphone or other user device; or the user can verbally recite the identifier over the phone (such as in the case of telephone input); and so on.
[0090] refer to Figure 3C Following the connection mechanism or visual code, the user can be taken to the license server via an unlock session window, pop-up window, or screen 345 (omitted for clarity after user login). The unlock session window, pop-up window, or screen 345 may display a session code input field or input field set 350, which may allow manual input of the session code or allow automatic filling of the session code. For manual input, the user can enter the session code (in...) Figure 3B The unlock session pop-up window or the session code field 315 on screen 310 can be manually typed or copied and pasted into the input field or input field set 350. For autofill, when the user clicks... Figure 3B When the unlock session pop-up window or the connection mechanism field 325 of screen 310 contains the connection mechanism (e.g., URL, etc.), or when the user scans... Figure 3BWhen the unlock session pop-up window or visual code 330 on screen 310 appears, the input field or input field set 350 can be automatically filled with a session code. After the session code input field or input field set 350 has been filled with a session code or identifier (in this case, "0800-0002-0000-0PAE-M81G"), the user can press, squeeze, or select (collectively referred to as "clicking") the unlock button 355. Once the unlock button 355 is clicked, the available credit pool associated with the user or an entity associated with the user (e.g., a company, organization, etc.) is activated, and the user is charged for using this combination of services and technologies by deducting or subtracting the predetermined amount of credits used per session for the requested service from the available credit pool using a counter.
[0091] Turn Figure 3D Assuming in Figure 3C If the session code entered in the session code input field or input field set 350 of the unlock session window, pop-up window, or screen 345 is valid and corresponds to the requested service and / or the software used to run the session, another unlock session window, pop-up window, or screen 360 may be displayed. This other unlock session window, pop-up window, or screen 360 may display an unlock code field 365 containing the unlock code (in this case, “JCMX-NR8Y-1W1G-WYN8-2T20”), and in the example, a copy button 370 may also be displayed. When pressed, pressed, or selected, the copy button 370 can copy the unlock code displayed in the unlock code field 365 so that it can be subsequently pasted into the unlock code field 335 in the unlock session window 310 (e.g., ...). Figure 3B (As shown in the examples). In some examples, the session code is modified in a known and / or reproducible manner and then hashed using a cryptographic hash function to create a hash-based message authentication code (“HMAC”). In the examples, the cryptographic hash function may include a secure hash algorithm (“SHA”), which may include, but is not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256. The resulting code (i.e., the unlock code) is created and is highly likely to be unique to that identifier or session code.
[0092] In the example, the unlock code could be a session code used to unlock a single session of access to the requested service using the software. In the example, the unlock code could include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; and so on.
[0093] Subsequently, users can Figure 3B In the unlock session pop-up window or on screen 310, fill in the unlock code in the blank unlock code field 335 (in this case, "JCMX-NR8Y-1W1G-WYN8-2T20"). The user can either manually type the unlock code or paste a copied unlock code (when using...). Figure 3D (After unlocking the session window, pop-up window, or the copy button on the 360-degree screen, click to fill in the information.) Reference Figure 3E In this diagram, the unlock code field 335 has already been filled with the unlock code. The user can then press, squeeze, or select the unlock session button 340 to initiate the unlock code verification process. Once verified, the unlock code will unlock the session and allow the user to access the requested service of the software for a single session.
[0094] Figure 3F This describes a scenario where a user requests a refund (e.g., because the requested service and / or software was not used after the certification agreement began, because the requested service and / or software was not properly completed due to technical problems, or because the user failed to complete or was unable to complete the licensed task, etc.) and the user successfully proves that the refund is appropriate. In this case, such as Figure 3F As shown, Figure 3B The unlock session pop-up or screen 310 can be replaced with a refund session pop-up or screen 310'. The refund session pop-up or screen 310' is... Figure 3B The difference between the unlock session pop-up window or screen 310 and the previous one is that it grays out the session code displayed in the session code field 315' (in this case, "0800-BH02-0000-02WEE820") (indicating that the "old" session code is no longer valid or the "old" session has been canceled, terminated, or deleted). The refund session pop-up window or screen 310' also displays the refund code in the refund code field 375 (in this case, "WNEV-535E-TYX0-E9Q7-3580"). Similar to the unlock session pop-up window or screen 310, the refund session pop-up window or screen 310' displays a message to contact the communication device displayed in the contact information field 320' (in this case, the calling phone number "1-800-123-4567") to request a refund for the session. The refund session pop-up or screen 310' also displays alternative options for navigating to an information collection (e.g., a webpage, website, or web portal), the navigation following the connection mechanism (e.g., a URL) corresponding to the refund code in the connection mechanism field 380. Alternatively or additionally, the refund session pop-up or screen 310' displays a visual code 385 (in this case, a QR code corresponding to the connection mechanism (e.g., a URL) displayed in the connection mechanism field 380).
[0095] Once a refund code is successfully entered and verified via one of the methods described above, the user will be credited to the incomplete session (e.g., by a counter for the predetermined amount of credits used per session for services associated with the incomplete session). In the example, the option to access the refund code may be available before the delivery of a single session using the requested service of the software ends (e.g., generating a qualification report in the case of a qualification service request). Once the delivery of a single session ends, the option to access the refund code can be deactivated.
[0096] Otherwise, the license management and certification process in Figure 3 can be referenced in other aspects as described above. Figure 1 System 100 and / or Figure 2 The operation process described in Method 200 is similar, even if not exactly the same.
[0097] Figures 4A to 4D (Collectively referred to as “Figure 4”) is a flowchart illustrating a method 400 for implementing software license management and authentication according to various examples. Figure 4A Method 400 continues after the circular marker represented by "A" to... Figure 4B .
[0098] Although the techniques and procedures are depicted and / or described in a particular order for illustrative purposes, it should be understood that specific procedures may be reordered and / or omitted within the scope of various examples. Furthermore, although the method 400 shown in Figure 4 can be performed by or utilize... Figure 1 , Figure 2 The system, examples, or examples 100, 200, and 300 (or their components) of Figure 3 can be used (and are described with reference to them in the examples), but such a method can also be implemented using any suitable hardware (or software) implementation. Similarly, although Figure 1 , Figure 2 Each of the systems, examples, or examples 100, 200, and 300 (or components thereof) of Figure 3 can be operated according to the method 400 shown in Figure 4 (e.g., by executing instructions embodied on a computer-readable medium), but Figure 1 , Figure 2 The system, example, or examples 100, 200, and 300 in Figure 3 may also operate and / or execute other suitable procedures according to other operating modes.
[0099] exist Figure 4AIn a non-limiting example, method 400 at block 405 may include receiving a user's request for use of a service using the first software by a client device executing the first software thereon. In some examples, the first software may be software that performs operations on the client device without operating or controlling any external hardware or equipment. Alternatively, the first software may be software for operating or controlling equipment, which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments. In the example, the client device may be one of the following: a laboratory computer that communicates with and controls the equipment; a desktop computer that communicates with and controls the equipment; a laptop computer that communicates with and controls the equipment; a portable computing system that communicates with and controls the equipment; a mobile user device that communicates with and controls the equipment; an external dedicated control device that communicates with and controls the equipment; or an integrated dedicated control device that controls the equipment, etc.
[0100] At box 410, method 400 may include: in response to receiving a request, the client device initiates an authentication protocol for the first software. The initiated authentication protocol may cause the client device to generate a unique identifier associated with at least one of the requested service or the first software, and present a prompt to the user to request an unlock code using the generated unique identifier. According to some examples, at optional box 415, method 400 may include encoding the unique identifier. In examples, encoding the unique identifier may include encoding the unique identifier using one of the following: Base16 encoding scheme, Base32 encoding scheme, Base36 encoding scheme, Base58 encoding scheme, or Base64 encoding scheme, etc.
[0101] Method 400 at box 420 may further include: receiving a request for an unlock code by the computing system. In the example, the request for the unlock code may include a generated unique identifier, and the generated unique identifier may include licensing information (which may be embedded in the generated first unique identifier). In the example, the computing system may include, but is not limited to: a local computing system located on the client device; a remote computing system located in a geographically separate location from the client device and accessible via a network; a licensing server accessible via a network; and so on.
[0102] Method 400 may further include, at block 425, determining, in response to receiving a generated unique identifier, whether a user should be entitled to access the requested service using the first software, based at least in part on license information embedded in the generated unique identifier. In an example, this determination may include extracting the license information embedded in the unique identifier. The computing system may then determine whether a user should be entitled to access the requested service using the first software, based at least in part on the license information and at least one of stored information about at least one of the user, an entity associated with the user, the requested service, or the first software. Alternatively, this determination may include first decrypting the unique identifier and extracting the license information embedded in the decrypted unique identifier. The computing system may then authenticate at least one of the unique identifier or the extracted license information embedded in the unique identifier. Once at least one of the unique identifier or the extracted license information is authenticated, the computing system can determine whether a user should have the right to access the requested service of the first software based at least in part on the license information embedded in the unique identifier and at least in part on stored information about at least one of the user, the entity associated with the user, the requested service, the first software, the user's or entity's license to access the requested service, or the user's or entity's license to access the first software.
[0103] Method 400 may include: generating an unlock code associated with the requested service using the first software by a computing system based on determining that the user should have the right to access the requested service using the first software, and deducting a fee associated with the license information (box 430). In an example, the unlock code may be a session code used for unlocking a single session of the requested service using the first software. In an example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc. In an example, generating the unlock code associated with the requested service using the first software may include: arranging the unique identifier in a predetermined manner and creating a hash-based message authentication code ("HMAC") using a cryptographic hash function including a secure hash algorithm ("SHA"). In the example, the secure hash algorithm may include, but is not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256. Method 400 may also include: the computing system sending an unlock code to the user (box 435).
[0104] At box 440, method 400 may include: receiving an unlock code by the client device. At box 445, method 400 may further include: verifying the unlock code by the client device in response to receiving the unlock code. Method 400 may further include: unlocking the single-session use of the requested service using the first software by the client device in response to the unlock code being verified, to allow the user to access the single-session use of the requested service using the first software (box 450). Method 400 may continue after the circled marker indicated by "A" to... Figure 4B The process at checkbox 455 in the text.
[0105] In some examples, the license information may include, but is not limited to, at least one of the following: data regarding the requested service used with the first software; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the first software; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to the license associated with at least one of the requested service or the first software; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the first software; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on. The type of license may include, but is not limited to, one of the following: a pay-per-use license, a periodic subscription license, a right-to-use license, or a free-to-use license, etc. Figure 4B The example describes a scenario where the first software is licensed as a pay-per-use license, where the pay-per-use license includes a quantity of credits purchased or pre-ordered. In the example, a requested service among multiple available services uses a predetermined amount of credits per session.
[0106] In particular, Figure 4B At checkbox 455 (after the circular marker indicated by "A"), method 400 may include: after generating the unlock code, a counter, decremented by the computing system by a predetermined amount of credits used per session, indicating the remaining amount of credits in the purchased or pre-ordered pay-per-use license. The counter may be associated with the user or an entity associated with the user (e.g., a company, organization, etc.), or it may be associated with the user's or entity's account.
[0107] If a user requests a refund (e.g., because the requested service and / or the first software was not used after the certification agreement began, because the requested service and / or the first software was not properly completed due to technical problems, or because the user failed to complete or was unable to complete the licensed task, etc.) and the user successfully proves that the refund is appropriate, a refund code will be provided to the user from the service provider associated with at least one of the requested service or the first software and / or the equipment. In such an example, method 400 may further include: receiving, decrypting, and authenticating the refund code from the user by a computing system (optional box 460). Method 400 may further include: in response to receiving, decrypting, and authenticating the refund code, invalidating the current single session use of the requested service using the first software by a computing system, and incrementing a counter indicating the remaining amount of credits by a predetermined amount of credits used per session for the requested service by a computing system (optional box 465). In the example, the option to access the refund code may be available before the delivery of the single session use of the requested service using the first software ends (e.g., generating a qualification report in the case of requesting qualification services, etc.). Once the delivery for a single session has ended, the option to access the refund code can be deactivated.
[0108] refer to Figure 4C Presenting a prompt to the user to request an unlock code using the generated unique identifier (at box 410) at box 470 may include presenting two or more options, including displaying the generated unique identifier and a communication device for the user to use or contact and provide (e.g., by speaking, typing, copying and pasting, etc.) the generated unique identifier. The two or more options may also include displaying a connection mechanism to an information collection, such as a link including a Uniform Resource Locator (“URL”) containing the generated unique identifier. The two or more options may also include displaying a visual code and prompting the user to scan the visual code, which contains data associated with the generated unique identifier, etc. In some examples, the visual code may include, but is not limited to, a barcode or a Quick Response (“QR”) code, etc.
[0109] At box 475, method 400 may further include: before presenting a prompt to the user to request an unlock code using a generated unique identifier, the client device determines whether the client device is connected to a communication network (e.g., the Internet or other network). Method 400 may further include: based on the determination that the client device is not connected to a communication network or has restricted access to the communication network, the client device grays out the option to display the connection mechanism with the information collection (box 480).
[0110] Turn Figure 4DReceiving the generated unique identifier included in the received request for the unlock code (at box 420) may include one of the following: receiving a generated unique identifier dictated by the user over a telephone and converted via speech-to-text conversion (box 485a); receiving a generated unique identifier manually entered by the user or another user via a user interface via a text input field (box 485b); receiving a generated unique identifier copied and pasted by the user via a user interface via a text input field (box 485c); receiving the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera (box 485d); or, when the client device is connected to a communication network, receiving the generated unique identifier from the client device via network communication (box 485e); and so on. According to some examples, the capture of the image of the visual code may trigger one of the following: sending the generated unique identifier to a computing system via a network; or accessing an information collection (e.g., a webpage, website, or web portal, etc.) that allows the user to manually enter the generated unique identifier; and so on.
[0111] Figures 5A to 5C (Collectively referred to as “Figure 5”) is a flowchart illustrating methods for implementing software license management and authentication from the perspective of a computing system or license server, based on various examples. Figure 5A Method 500 continues after the circular marker represented by "A" to... Figure 5B .
[0112] Although the techniques and procedures are depicted and / or described in a particular order for illustrative purposes, it should be understood that specific procedures may be reordered and / or omitted within the scope of various examples. Furthermore, although the method 500 shown in Figure 5 can be performed by or utilize... Figure 1 , Figure 2 The system, examples, or examples 100, 200, and 300 (or their components) of Figure 3 can be used (and are described with reference to them in the examples), but such a method can also be implemented using any suitable hardware (or software) implementation. Similarly, although Figure 1 , Figure 2 Each of the systems, examples, or examples 100, 200, and 300 (or components thereof) of Figure 3 can be operated according to the method 500 shown in Figure 5 (e.g., by executing instructions embodied on a computer-readable medium), but Figure 1 , Figure 2 The system, example, or examples 100, 200, and 300 in Figure 3 may also operate and / or execute other suitable procedures according to other operating modes.
[0113] exist Figure 5AIn a non-limiting example, method 500 at block 505 may include a request from a computing system to receive an unlock code for a requested service using the first software from a user on a client device executing the first software. In this example, the request for the unlock code may include a generated unique identifier, and the generated unique identifier may include licensing information (which may be embedded in the generated first unique identifier). In this example, the computing system may include, but is not limited to: a local computing system local to the client device; a remote computing system located geographically separate from the client device and accessible via a network; a license server accessible via a network; and so on.
[0114] In some examples, the first software may be software that performs operations on a client device without operating or controlling any external hardware or equipment. Alternatively, the first software may be software for operating or controlling equipment, which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments. In the example, the client device may be one of the following: a laboratory computer that communicates with and controls the equipment; a desktop computer that communicates with and controls the equipment; a laptop computer that communicates with and controls the equipment; a portable computing system that communicates with and controls the equipment; a mobile user device that communicates with and controls the equipment; an external dedicated control device that communicates with and controls the equipment; or an integrated dedicated control device that controls the equipment, etc.
[0115] At block 510, method 500 may include: in response to receiving a generated unique identifier, a computing system determining, at least in part, whether a user should have access to the requested service using the first software based on license information embedded in the generated unique identifier. In an example, this determination may include extracting the license information embedded in the unique identifier. The computing system may then determine, at least in part, whether the user should have access to the requested service using the first software based on at least one of the license information and at least one of stored information about at least one of the user, an entity associated with the user, the requested service, or the first software. Alternatively, this determination may include first decrypting the unique identifier and extracting the license information embedded in the decrypted unique identifier. The computing system may then authenticate at least one of the unique identifier or the extracted license information embedded in the unique identifier. Once at least one of the unique identifier or the extracted license information is authenticated, the computing system can determine whether a user should have the right to access the requested service of the first software based at least in part on the license information embedded in the unique identifier and at least in part on stored information about at least one of the user, the entity associated with the user, the requested service, the first software, the user's or entity's license to access the requested service, or the user's or entity's license to access the first software.
[0116] According to some examples, method 500 may include at optional box 515: generating an unlock code associated with the requested service using the first software by a computing system based on determining that the user should have the right to access the requested service using the first software, and deducting a fee associated with the license information. In the examples, the unlock code may be a session code used for unlocking a single session of the requested service using the first software. In the examples, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the type of user; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc. In the examples, generating the unlock code associated with the requested service using the first software may include: arranging the unique identifier in a predetermined manner and creating a hash-based message authentication code (“HMAC”) using a cryptographic hash function including a secure hash algorithm (“SHA”). In the example, the secure hash algorithm may include, but is not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256. Method 500 may also include: the computing system sending an unlock code to the user (box 520). Method 500 may continue after the circular marker represented by "A". Figure 5BThe process at checkbox 525 in the text.
[0117] In some examples, the license information may include, but is not limited to, at least one of the following: data regarding the requested service used with the first software; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the first software; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to the license associated with at least one of the requested service or the first software; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the first software; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on. The type of license may include, but is not limited to, one of the following: a pay-per-use license, a periodic subscription license, a right-to-use license, or a free-to-use license, etc. Figure 5B The example describes a scenario where the first software is licensed as a pay-per-use license, where the pay-per-use license includes a quantity of credits purchased or pre-ordered. In the example, a requested service among multiple available services uses a predetermined amount of credits per session.
[0118] In particular, Figure 5B At checkbox 525 (after the circular marker labeled "A"), method 500 may include: after generating the unlock code, a counter, decremented by a computing system, indicating the remaining amount of credits in the purchased or pre-ordered pay-per-use license, based on a predetermined amount of credits used per session. The counter may be associated with the user or an entity associated with the user (e.g., a company, organization, etc.), or it may be associated with the user's or entity's account.
[0119] If a user requests a refund (e.g., because the requested service and / or the first software was not used after the certification agreement began, because the requested service and / or the first software was not properly completed due to technical problems, or because the user failed to complete or was unable to complete the licensed task, etc.) and the user successfully proves that the refund is appropriate, a refund code will be provided to the user from the service provider associated with at least one of the requested service or the first software and / or the equipment. In such an example, method 500 may further include: receiving, decrypting, and authenticating the refund code from the user by a computing system (optional box 530). Method 500 may further include: in response to receiving, decrypting, and authenticating the refund code, invalidating the current single session use of the requested service using the first software by a computing system, and incrementing a counter indicating the remaining amount of credits by a predetermined amount of credits used per session for the requested service by the computing system (optional box 535). In the example, the option to access the refund code may be available before the delivery of the single session use of the requested service using the first software ends (e.g., generating a qualification report in the case of requesting qualification services, etc.). Once the delivery for a single session has ended, the option to access the refund code can be deactivated.
[0120] Method 500 at box 540 may further include: receiving, decrypting, and authenticating a purchase code from a user by the computing system, wherein the purchase code corresponds to the purchase of one or more additional credits. Method 500 at box 545 may further include: in response to receiving, decrypting, and authenticating the purchase code, incrementing a counter indicating the remaining amount of credits indicating the purchase of one or more additional credits by the computing system. In the example, a user can use a requested service by placing an order and paying a certain amount of credits, wherein the total amount of credits purchased may be based on the number of times the user intends to consume the service multiplied by the cost of using the service (in terms of the amount of credits per use). In this way, the user will have a credit treasury on the computing system (e.g., on a license server, etc.). In the example, at least one of the purchased or pre-ordered amount of credits, the remaining amount of credits, or the one or more additional credits may be allocated to at least one of: an entity associated with a pay-per-use license; an account associated with the entity; or one or more individuals associated with the entity; etc. While various examples are described regarding the purchase of credits representing fees for using the requested service, these examples are not limited to these and can be considered in the following ways: a user makes a payment; a system allows a user to consume services or goods (as described in detail herein, etc.); and a user receives some value based on the consumption of services or goods. In other words, whether a user purchases credits or some other value-based construct, the user may only be able to consume services or goods through the asynchronous two-way authentication (or handshake) method described herein involving the use of a unique identifier that includes (or embeds therein) licensing information (e.g., data about the requested service, session data used for the session of the requested service, data about the type of system used to provide the requested service, information about the type of license associated with at least one of the requested service or first software, etc.) and a corresponding unlock code, which is unique to the unique identifier and unique to the requested service or goods.
[0121] refer to Figure 5CReceiving the generated unique identifier included in the received request for the unlock code (at box 505) may include one of the following: receiving a generated unique identifier dictated by the user over a telephone and converted via speech-to-text conversion (box 550a); receiving a generated unique identifier manually entered by the user or another user via a user interface via a text input field (box 550b); receiving a generated unique identifier copied and pasted by the user via a user interface via a text input field (box 550c); receiving the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera (box 550d); or, when the client device is connected to a communication network, receiving the generated unique identifier from the client device via network communication (box 550e); and so on. According to some examples, the capture of the visual code image may trigger one of the following: sending the generated unique identifier to a computing system via a network; or accessing an information collection that allows the user to manually enter the generated unique identifier (e.g., a webpage, website, or web portal); and so on.
[0122] Figures 6A to 6C (Collectively referred to as “Figure 6”) is a flowchart illustrating methods for implementing software license management and authentication from the perspective of a client device, based on various examples.
[0123] Although the techniques and procedures are depicted and / or described in a particular order for illustrative purposes, it should be understood that specific procedures may be reordered and / or omitted within the scope of various examples. Furthermore, although the method 600 shown in Figure 6 can be performed by or utilize... Figure 1 , Figure 2 The system, examples, or examples 100, 200, and 300 (or their components) of Figure 3 can be used (and are described with reference to them in the examples), but such a method can also be implemented using any suitable hardware (or software) implementation. Similarly, although Figure 1 , Figure 2 Each of the systems, examples, or examples 100, 200, and 300 (or components thereof) of Figure 3 can be operated according to the method 600 shown in Figure 6 (e.g., by executing instructions embodied on a computer-readable medium), but Figure 1 , Figure 2 The system, example, or examples 100, 200, and 300 in Figure 3 may also operate and / or execute other suitable procedures according to other operating modes.
[0124] exist Figure 6AIn a non-limiting example, method 600 at block 605 may include receiving a user's request for use of a service using the first software by a client device executing the first software thereon. In some examples, the first software may be software that performs operations on the client device without operating or controlling any external hardware or equipment. Alternatively, the first software may be software for operating or controlling equipment, which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments. In the example, the client device may be one of the following: a laboratory computer that communicates with and controls the equipment; a desktop computer that communicates with and controls the equipment; a laptop computer that communicates with and controls the equipment; a portable computing system that communicates with and controls the equipment; a mobile user device that communicates with and controls the equipment; an external dedicated control device that communicates with and controls the equipment; or an integrated dedicated control device that controls the equipment, etc.
[0125] At box 610, method 600 may include: in response to receiving a request, the client device initiates an authentication protocol for the first software. The initiated authentication protocol may cause the client device to generate a unique identifier associated with at least one of the requested service or the first software, and present a prompt to the user to request an unlock code using the generated unique identifier. In this example, the generated unique identifier may include license information.
[0126] In some examples, the license information may include, but is not limited to, at least one of the following: data regarding the requested service using the first software; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the first software; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fee corresponding to the license associated with at least one of the requested service or the first software; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the first software; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on. The type of license may include, but is not limited to, one of the following: a pay-per-use license, a recurring subscription license, a right-to-use license, or a free-to-use license. In the example, a pay-per-use license may include purchased or pre-purchased usage times. In the example, the requested service among multiple available services may cost a predetermined amount of credits per session.
[0127] According to some examples, method 600 may include encoding the unique identifier at optional box 615. In the examples, encoding the unique identifier may include encoding the unique identifier using one of the following: Base16 encoding scheme, Base32 encoding scheme, Base36 encoding scheme, Base58 encoding scheme, or Base64 encoding scheme, etc. Method 600 may also include sending the generated unique identifier to a license server for verification (box 620).
[0128] Method 600 may further include, at block 625, receiving an unlock code from a license server by a client device. In an example, the unlock code may be a session code used for unlocking a single session of the requested service using the first software. In an example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the type of user; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc. In an example, the unlock code associated with the requested service using the first software may be generated by arranging the unique identifier in a predetermined manner and creating a hash-based message authentication code (“HMAC”) using a cryptographic hash function including a secure hash algorithm (“SHA”). In an example, the secure hash algorithm may include, but is not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256, etc.
[0129] At box 630, method 600 may include: in response to receiving an unlock code, verifying the unlock code by the client device. Method 600 may also include: in response to the unlock code being verified, unlocking the single-session use of the requested service using the first software by the client device to allow the user to access the single-session use of the requested service using the first software (box 635).
[0130] refer to Figure 6B Presenting a prompt to the user to request an unlock code using the generated unique identifier (at box 610) at box 640 may include presenting two or more options, including displaying the generated unique identifier and a communication device for the user to use or contact and provide (e.g., by speaking, typing, copying and pasting, etc.) the generated unique identifier. The two or more options may also include displaying a connection mechanism to an information collection, such as a link including a Uniform Resource Locator (“URL”) containing the generated unique identifier. The two or more options may also include displaying a visual code and prompting the user to scan the visual code, which contains data associated with the generated unique identifier, etc. In some examples, the visual code may include, but is not limited to, a barcode or a Quick Response (“QR”) code, etc.
[0131] At box 645, method 600 may further include: before presenting a prompt to the user to request an unlock code using a generated unique identifier, the client device determines whether the client device is connected to a communication network (e.g., the Internet or other network). Method 600 may further include: based on the determination that the client device is not connected to a communication network or has restricted access to the communication network, the client device grays out the option to display the connection mechanism with the information collection (box 650).
[0132] Turn Figure 6C Sending the generated unique identifier to a license server for verification (at box 620) may include one of the following: sending the generated unique identifier dictated by the user over a telephone (box 655a); sending the generated unique identifier manually entered by the user or another user via a user interface (box 655b); sending the generated unique identifier copied and pasted by the user via a user interface (box 655c); sending the generated unique identifier as a visual code, the image of which is captured by the user using the user device's camera (box 655d); or, when the client device is connected to a communication network, sending the generated unique identifier from the client device via network communication (box 655e); and so on. According to some examples, the capture of the visual code image may trigger one of the following: sending the generated unique identifier to a computing system over a network; or accessing an information collection that allows the user to manually enter the generated unique identifier (e.g., a webpage, website, or web portal); and so on.
[0133] Exemplary System and Hardware Implementation
[0134] Figure 7 It is a block diagram illustrating exemplary computer or system hardware architectures according to various examples. Figure 7 A schematic diagram of an example of a computer system 700 providing service provider system hardware is provided, which can perform the methods provided by various other examples as described herein, and / or can perform the functions of a computer or hardware system (i.e., client devices 105 and 205, equipment 110, computing systems 120a and 120b, user devices 135 and 235, license servers 140 and 240, etc.) as described above. It should be noted that... Figure 7 This is intended only to provide a general overview of the various components; one or more of each component may be used (or not used) at the discretion of the user. Therefore, Figure 7 It extensively demonstrates how individual system components can be implemented in a relatively separate or relatively more integrated manner.
[0135] Computer or hardware system 700 – which may represent the above reference Figure 1Examples of computer or hardware systems depicted in Figure 6 (i.e., client devices 105 and 205, device 110, computing systems 120a and 120b, user devices 135 and 235, license servers 140 and 240, etc.) are shown as including hardware elements that can be electrically coupled (or otherwise communicated, as appropriate) via bus 705. These hardware elements may include: one or more processors 710, including but not limited to one or more general-purpose processors and / or one or more special-purpose processors (such as microprocessors, digital signal processing chips, graphics accelerators, etc.); one or more input devices 715, which may include but are not limited to mice, keyboards, etc.; and one or more output devices 720, which may include but are not limited to display devices, printers, etc.
[0136] The computer or hardware system 700 may also include (and / or communicate with) one or more storage devices 725, which may include, but are not limited to, local and / or network-accessible storage devices, and / or may include, but are not limited to, disk drives, drive arrays, optical storage devices, solid-state storage devices (such as random access memory (“RAM”) and / or read-only memory (“ROM”)), which may be programmable, flash-updatable, etc. Such storage devices can be configured to implement any suitable data storage, including but not limited to various file systems, database structures, etc.
[0137] Computer or hardware system 700 may further include: a communication subsystem 730, which may include, but is not limited to, a modem, a network card (wireless or wired), an infrared communication device, a wireless communication device, and / or a chipset (such as Bluetooth). TM Devices, 802.11 devices, WiFi devices, WiMax devices, WWAN devices, cellular communication facilities, etc. The communication subsystem 730 may allow the exchange of data with networks (to name only, such as those described below), other computer or hardware systems, and / or any other devices described herein. In many examples, the computer or hardware system 700 will also include working memory 735, which may include RAM or ROM devices as described above.
[0138] As described herein, the computer or hardware system 700 may also include software elements shown as currently residing in working memory 735, including an operating system 740, device drivers, executable libraries, and / or other code, such as one or more application programs 745, which may include computer programs (including, but not limited to, hypervisors, VMs, etc.) provided by various examples, and / or may be designed to implement methods provided by other examples and / or configure systems provided by other examples. By way of example only, one or more programs described with respect to the methods discussed above may be implemented as code and / or instructions executable by a computer (and / or a processor within a computer). In one aspect, such code and / or instructions may then be used to configure and / or adapt a general-purpose computer (or other device) to perform one or more operations according to the described methods.
[0139] A set of these instructions and / or code may be encoded and / or stored on a non-transitory computer-readable storage medium (such as storage device 725 described above). In one example, the storage medium may be incorporated into a computer system (such as system 700). In other examples, the storage medium may be separate from the computer system (i.e., a removable medium, such as an optical disc, etc.) and / or provided in an installation package, such that the storage medium can be used to program, configure, and / or adapt to a general-purpose computer on which instructions / code are stored. These instructions may take the form of executable code that can be executed by the computer or hardware system 700, and / or may take the form of source code and / or installable code that, after being compiled and / or installed on the computer or hardware system 700 (e.g., using any of a variety of generally available compilers, installers, compression / decompression utilities, etc.), takes the form of executable code.
[0140] It will be apparent to those skilled in the art that substantial variations can be made to suit specific requirements. For example, custom hardware (such as programmable logic controllers, field-programmable gate arrays, application-specific integrated circuits, etc.) may be used, and / or specific elements may be implemented in hardware, software (including portable software such as applets), or both. Furthermore, connectivity with other computing devices (such as network input / output devices) may be employed.
[0141] As described above, in one aspect, some examples may employ a computer or hardware system (such as computer or hardware system 700) to perform methods according to various examples of the invention. According to one set of examples, in response to processor 710 executing one or more instructions (which may be incorporated into operating system 740 and / or other code such as application program 745) contained in working memory 735, part or all of such a program of the method is executed by computer or hardware system 700. Such instructions may be read from another computer-readable medium into working memory 735 (such as one or more storage devices 725). By way of example only, execution of the instruction sequence contained in working memory 735 may cause processor 710 to execute one or more programs of the methods described herein.
[0142] As used herein, the terms “machine-readable medium” and “computer-readable medium” refer to any medium that participates in providing data that enables a machine to operate in a particular manner. In examples implemented using a computer or hardware system 700, various computer-readable media may involve providing instructions / code to a processor 710 for execution, and / or may be used to store and / or carry such instructions / code (e.g., as signals). In many implementations, a computer-readable medium is a non-transitory, physical, and / or tangible storage medium. In some examples, a computer-readable medium may take many forms, including but not limited to non-volatile media, volatile media, etc. Non-volatile media include, for example, optical discs and / or magnetic disks, such as storage devices 725. Volatile media include, but are not limited to, dynamic memory, such as working memory 735. In some alternative examples, a computer-readable medium may take the form of a transmission medium, including but not limited to coaxial cables, copper wires, and optical fibers (including wires constituting bus 705) and various components of the communication subsystem 730 (and / or the medium through which the communication subsystem 730 provides communication with other devices). In another set of examples, the transmission medium may also take the form of waves (including, but not limited to, radio waves, sound waves, and / or light waves, such as those generated during radio wave and infrared data communication).
[0143] Common forms of physical and / or tangible computer-readable media include, for example, floppy disks, floppy disks, hard disks, magnetic tapes or any other magnetic media, CD-ROMs, any other optical media, punched cards, paper tapes, any other physical media with a pattern of holes, RAM, PROMs and EPROMs, FLASH-EPROMs, any other memory chips or cartridges, carrier waves as described below, or any other media from which a computer can read instructions and / or code.
[0144] When loading one or more instructions of one or more sequences onto processor 710 for execution, various forms of computer-readable media may be involved. By way of example only, the instructions may initially be carried on a disk and / or optical disk of a remote computer. The remote computer may load the instructions into its dynamic memory and transmit the instructions as signals via a transmission medium for reception and / or execution by the computer or hardware system 700. According to various examples of the invention, these signals, which may be in the form of electromagnetic signals, acoustic signals, optical signals, etc., are examples of carrier waves on which instructions can be encoded.
[0145] The communication subsystem 730 (and / or its components) typically receives signals, and then the bus 705 can transport the signals (and / or data, instructions, etc. carried by the signals) to the working memory 735. The processor 705 retrieves instructions from the working memory and executes them. Instructions received by the working memory 735 may optionally be stored on the storage device 725 before or after execution by the processor 710.
[0146] As described above, a set of examples includes methods and systems for implementing software license management and authentication, and more specifically, methods, systems, and apparatus for implementing software license management and authentication regardless of whether the client device associated with a potential licensee is connected to a communication network (e.g., the Internet or other networks). Figure 8 A schematic diagram of a system 800 is shown, which can be used according to a set of examples. System 800 may include one or more user computers, user devices, or client devices 805. User computers, user devices, or client devices 805 may be general-purpose personal computers (including, by way of example only, desktop computers, tablet computers, laptop computers, handheld computers, etc. running any suitable operating system, some of which may be available from vendors such as Apple, Microsoft Corp.), cloud computing devices, servers, and / or running various commercial UNIX systems. TMThis can be a workstation computer or any operating system similar to UNIX. The user computer, user device, or client device 805 may also have any of a variety of applications, including one or more applications configured to perform methods provided by various examples (e.g., as described above), and one or more office applications, database client and / or server applications, and / or web browser applications. Alternatively, the user computer, user device, or client device 805 may be any other electronic device capable of communicating via a network (e.g., network 810 described below) and / or capable of displaying and navigating web pages or other types of electronic documents, such as a thin client computer, an internet-enabled mobile phone, and / or a personal digital assistant. Although the exemplary system 800 is shown as having two user computers, user devices, or client devices 805, any number of user computers, user devices, or client devices can be supported.
[0147] Some examples operate in a networked environment, which may include network 810. Network 810 can be any type of network familiar to those skilled in the art, and can support data communication using any of a variety of commercial (and / or free or proprietary) protocols, including but not limited to TCP / IP, SNA, etc. TM IPX TM AppleTalk TM Etc. For example only, Network 810 (similar to...) Figure 1 and Figure 2 Networks 150 or 250, etc., may each include: Local Area Networks (“LANs”), including but not limited to fiber optic networks, Ethernet, Token-Ring networks, etc. TM Wide area network (“WAN”); wireless wide area network (“WWAN”); virtual network, such as virtual private network (“VPN”); Internet; intranet; extranet; public switched telephone network (“PSTN”); infrared network; wireless network, including but not limited to any IEEE 802.11 protocol suite, Bluetooth as known in the art. TM A network operating under a protocol and / or any other wireless protocol; and / or any combination of these and / or other networks. In a particular example, a network may include the access network of a service provider (e.g., an Internet Service Provider (“ISP”)). In another example, a network may include the service provider’s core network and / or the Internet.
[0148] The implementation scheme may also include one or more server computers 815a or 815b (collectively referred to as "server 815" or "server computer 815," etc.). Each of the server computers 815 may be configured with an operating system, including but not limited to any operating system discussed above, and any commercial (or free) server operating system. Each of the servers 815 may also run one or more applications that can be configured to provide services to one or more clients 805 and / or other servers 815.
[0149] As an example only, as described above, one of the servers 815 can be a data server, a web server, a cloud computing device, etc. The data server may include (or communicate with) a web server, which, as an example only, can be used to process requests for web pages or other electronic documents from user computer 805. The web server can also run various server applications, including HTTP servers, FTP servers, CGI servers, database servers, Java servers, etc. In some examples of the invention, the web server can be configured to provide web pages that can be operated within a web browser on one or more user computers 805 to perform the methods of the invention.
[0150] In some examples, server computer 815 may include one or more application servers configured with one or more applications accessible to clients running on one or more client computers 805 and / or other server 815. By way of example only, server 815 may be one or more general-purpose computers capable of executing programs or scripts (including, but not limited to, network applications, which in this example may be configured to execute methods provided by various examples) in response to user computer 805 and / or other server 815. By way of example only, network applications may be implemented in any suitable programming language (such as Java). TM C, C# TM One or more scripts or programs written in C++ and / or any scripting language (such as Perl, Python, or TCL) and any combination of programming and / or scripting languages. The application server may also include a database server, including but not limited to those available from Oracle. TM Microsoft TM Sybase TM IBM TMThose acquired through commercial purchase can process requests from clients (including, depending on the configuration, dedicated database clients, API clients, web browsers, etc.) running on a user's computer, user device, or client device 805 and / or another server 815. In some examples, the application server can perform one or more processes for implementing software license management and authentication, and more specifically, perform methods, systems, and apparatus for implementing software license management and authentication regardless of whether the client device associated with the potential licensee is connected to a communication network (e.g., the Internet or other networks), as described in detail above. Data provided by the application server can be formatted as one or more web pages (e.g., including HTML, JavaScript, etc.) and / or can be forwarded to the user's computer 805 via a web server (e.g., as described above). Similarly, the web server can receive web page requests and / or input data from the user's computer 805 and / or forward web page requests and / or input data to the application server. In the examples, the web server can be integrated with the application server.
[0151] According to a further example, one or more servers 815 may serve as a file server and / or may include one or more files (e.g., application code, data files, etc.) necessary for implementing various disclosed methods, which are incorporated by an application running on user computer 805 and / or another server 815. Alternatively, as those skilled in the art will understand, the file server may include all necessary files to allow user computer, user device, or client device 805 and / or server 815 to remotely invoke such an application.
[0152] It should be noted that the functions described in this article regarding various servers (e.g., application servers, database servers, network servers, file servers, etc.) can be performed by a single server and / or multiple dedicated servers, depending on the specific requirements and parameters of the implementation.
[0153] In some examples, the system may include one or more databases 820a to 820n (collectively, “database 820”). The location of each database 820 is arbitrary: by way of example only, database 820a may reside on storage media local to server 815a (and / or user computer, user device, or client device 805) (and / or reside within said server). Alternatively, database 820n may reside remotely to any or all computers 805, 815, as long as it can communicate with one or more of these computers (e.g., via network 810). In a particular set of examples, database 820 may reside in a storage area network (“SAN”) familiar to those skilled in the art. (Similarly, any necessary files for performing the functions belonging to computers 805, 815 may be stored locally on the respective computers and / or remotely, as appropriate.) In one set of examples, database 820 may be a relational database, such as an Oracle database, adapted to store, update, and retrieve data in response to commands in SQL format. For example, as described above, the database may be controlled and / or maintained by a database server.
[0154] According to some examples, system 800 may also include client device 825 (similar to...). Figure 1 and Figure 2 Client devices 105 and 205, etc.), equipment 830 (optional; similar to Figure 1 Equipment 110, etc.), the first software or licensed software 835 running on the client device 825 (similar to Figure 1 and Figure 2 Licensed software 115 or 215, etc.), computing system 840 and corresponding database 845 (similar to Figure 1 The computing system 120a and the corresponding database 125a, etc.) and the remote computing system 855 and the corresponding database 860 (optional; similar to Figure 1 The remote computing system 120b and the corresponding database 125b, etc.). Each of the client device 825 and / or user device 805a or 805b can communicate via wired communication (in Figure 8 The connection is made via a line between the client device 825 and the computing system 840 through network 810, or between each user device 805a or 805b and the computing system 840 through network 810 (as depicted in the diagram) or via wireless communication (in... Figure 8 The client device 825 is communicatively coupled to the computing system 840 via lightning bolt symbols between the client device 825 and the network 810, between the client device 825 and the network 810, between each user device 805a or 805b and the computing system 840, and between each user device 805a or 805b and the network 810. The system 800 may also include a license server 865 and a corresponding database 870.
[0155] In operation, the client device 825, on which the first software or licensed software 835 is executed or runs, can receive a request from the user 850 for the use of the requested services of the licensed software 835. In some examples, the licensed software 835 may be software that performs operations on the client device 825 without operating or controlling any external hardware or equipment. Alternatively, the licensed software 835 may be software for operating or controlling equipment 830, which may include, but is not limited to, atomic absorption (“AA”) systems, capillary electrophoresis (“CE”) systems, dissolution systems, emission spectroscopy (“OES”) systems, inductively coupled plasma (“ICP”) OES systems, gas chromatography (“GC”) systems, GC mass spectrometry (“MS”) systems, gel permeation chromatography (“GPC”) systems, mass spectrometers, ICP-MS systems, infrared spectroscopy systems, Fourier transform infrared (“FT-IR”) spectroscopy systems, liquid chromatography (“LC”) systems, LC-MS systems, microfluidic systems, sample preparation (“SP”) systems, supercritical fluid chromatography (“SFC”) systems, ultraviolet-visible (“UV-Vis”) spectrophotometers, or other laboratory instruments.
[0156] In response to a received request, client device 825 may initiate an authentication protocol for licensed software 835, which causes the generation of a unique identifier associated with at least one of the requested service or licensed software 835, and presents a prompt to user 850 to request an unlock code using the generated unique identifier. According to some examples, the unique identifier may be encoded using one of the following encoding schemes: Base16, Base32, Base36, Base58, or Base64. Base32 encoding, Base58 encoding, etc., use a selected character set to avoid seemingly similar pairs of different symbols.
[0157] Computing system 840, server 815a or 815b, remote computing system 855, and / or license server 865 (collectively, "computing system, etc.") can receive requests for unlock codes. In an example, the request for an unlock code may include a generated unique identifier, and the generated unique identifier may include license information. In response to receiving the generated unique identifier, the computing system may determine, at least in part, whether a user should have access to the requested service using licensed software 835 (which may be stored in a corresponding database 845, 820a to 820n, or 860, etc.) based on the license information embedded in the generated unique identifier. In an example, this determination may include retrieving the license information embedded in the unique identifier. The computing system may then determine, at least in part, whether the user should have access to the requested service using licensed software 835 based on at least one of the license information and at least one of the stored information about user 850, entities associated with the user, the requested service, or licensed software 835, etc.
[0158] Based on the determination that a user should have the right to access the requested service using licensed software 835, the computing system can use licensed software 835 to generate an unlock code associated with the requested service and may deduct fees associated with the license information. In an example, the unlock code may be a session code used for unlocking a single session of the requested service using licensed software 835. In an example, the unlock code may include embedded data, including but not limited to at least one of the following: security-related data; data associated with a generated unique identifier; data about the user's type; data about whether the user needs to pay; session identification data; data about the type of the requested service; or data about the type of hardware associated with the requested service; etc. In an example, generating an unlock code associated with the requested service using licensed software 835 may include: arranging the unique identifier in a predetermined manner and creating a hash-based message authentication code ("HMAC") using a cryptographic hash function including a secure hash algorithm ("SHA"). In the examples, secure hash algorithms may include, but are not limited to, one of the following: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512 / 224, or SHA-512 / 256. Although SHA is described as a way to create hashes, the various examples are not limited to this, and any suitable hashing mechanism or technique can be used.
[0159] The computing system can send an unlock code to the user. The client device 825 can receive the unlock code. Upon receiving the unlock code, the client device 825 can verify it. In response to the verified unlock code, the client device 825 can unlock the single-session use of the requested service by the licensed software 835, thereby allowing the user to access the single-session use of the requested service by the licensed software 835.
[0160] In some examples, the license information may include, but is not limited to, at least one of the following: data regarding the requested service used by the licensed software 835; session data used for the session of the requested service; data regarding the type of system used to provide the requested service; information regarding the type of license associated with at least one of the requested service or the licensed software 835; information regarding the generation time of the generated unique identifier; information regarding session information verification; information regarding the fees corresponding to the license associated with at least one of the requested service or the licensed software 835; information regarding the conditions associated with the license; information regarding the restrictions associated with the license; information regarding the type of hardware associated with the licensed software 835; information regarding the type of hardware associated with the requested service; or information regarding the session of the requested service; and so on. In the examples, the license type may include, but is not limited to, one of the following: a pay-per-use license, a periodic subscription license, a right-to-use (or unlimited use) license, or a free-to-use license (e.g., a no-fee license, etc.).
[0161] As an example only, presenting a prompt to a user to request an unlock code using a generated unique identifier may include presenting two or more options, including but not limited to: displaying the generated unique identifier and a communication device for the user to use or contact and provide (e.g., by speaking, typing, copying and pasting, etc.) the generated unique identifier; displaying a connection mechanism to an information collection, such as a link including a Uniform Resource Locator (“URL”) that includes the generated unique identifier; or displaying a visual code and prompting the user to scan the visual code, which contains data associated with the generated unique identifier; and so on. In this example, the visual code may include, but is not limited to, a barcode or a Quick Response (“QR”) code.
[0162] In some examples, receiving the generated unique identifier included in the received request for an unlock code may include, but is not limited to, one of the following: receiving a generated unique identifier dictated by the user over a telephone and converted via speech-to-text conversion; receiving the generated unique identifier manually entered by the user or another user via a user interface via a text input field; receiving the generated unique identifier copied and pasted by the user via the user interface via a text input field; receiving the generated unique identifier as a visual code, the image of which is obtained by the user using a user device (e.g., user device 805a or 805b (similar to...)). Figure 1 and Figure 2 The image of the visual code may be captured by a camera on a user device (e.g., 135 and 235); or, when the client device is connected to a communication network (e.g., the Internet or other networks), the generated unique identifier may be received from the client device via network communication; and so on. In the example, the image of the visual code may trigger one of the following when it is captured: the generated unique identifier is sent to a computing system via a network; or access to a collection of information (e.g., a webpage, website, or web portal, etc.) that allows the user to manually enter the generated unique identifier.
[0163] The above references Figure 1 Figure 6 describes these and other functions of system 800 (and its components) in more detail.
[0164] Although certain features and aspects have been described with respect to exemplary examples, those skilled in the art will recognize that many modifications are possible. For example, the methods and processes described herein can be implemented using hardware components, software components, and / or any combination thereof. Furthermore, although the various methods and processes described herein may be described with respect to specific structural and / or functional components for ease of description, the methods provided by the various examples are not limited to any particular structural and / or functional architecture, but can be implemented on any suitable hardware, firmware, and / or software configuration. Similarly, although certain functions belong to certain system components, unless the context otherwise indicates, such functions may be distributed across a variety of other system components according to several examples.
[0165] Furthermore, although the procedures described herein are presented in a specific order for ease of description, various procedures may be reordered, added, and / or omitted according to various examples unless the context otherwise indicates. Moreover, procedures described with respect to a method or process may be incorporated into other described methods or processes; similarly, system components described according to a particular architectural structure and / or with respect to a system may be organized in alternative architectural structures and / or incorporated into other described systems. Therefore, although various examples have been described with or without certain features for ease of description and illustration of exemplary aspects of those examples, various components and / or features described herein with respect to particular examples may be substituted, added, and / or subtracted from examples described herein unless otherwise indicated. Therefore, although several exemplary examples have been described above, it should be understood that the invention is intended to cover all modifications and equivalents within the scope of the appended claims.
Claims
1. A method comprising: receiving, from a user using a client device on which a first software is executed, a request for an unlock code for a requested service using the first software, wherein the request for the unlock code comprises: a generated unique identifier associated with the requested service, wherein the generated unique identifier comprises license information comprising at least one of: data regarding the requested service using the first software; session data for a session use of the requested service; data regarding a type of a system used to provide the requested service; or information regarding a type of a license associated with at least one of the requested service or the first software; in response to receiving the generated unique identifier, extracting the license information embedded in the unique identifier, and determining, based at least in part on the license information and stored information regarding at least one of the user, an entity associated with the user, the requested service, or the first software, whether the user should have access to the requested service using the first software; and based on determining that the user should have access to the requested service using the first software, generating an unlock code associated with the requested service using the first software; deducting a fee associated with the license information; sending the unlock code to the user, wherein the unlock code is a per-session code for unlocking a single session use of the requested service using the first software; receiving, decrypting, and authenticating a refund code from the user; and in response to receiving, decrypting, and authenticating the refund code, invalidating a current single session use of the requested service using the first software, and incrementing the counter indicating a remaining credit number by a predetermined credit number for each session use of the requested service, wherein an option to access the refund code is available until an end of the single session use of the requested service using the first software, wherein the option to access the refund code is deactivated once the end of the single session use occurs.
2. The method of claim 1, wherein the license information further comprises one or more of: information regarding a time of generation of the generated unique identifier; information regarding a session information check; information regarding a fee corresponding to the license associated with the at least one of the requested service or the first software; information regarding a condition associated with the license; information regarding a restriction associated with the license; information regarding a type of hardware associated with the first software; information regarding a type of hardware associated with the requested service; or information regarding a session use of the requested service, wherein a license type comprises one of a pay-per-use license, a periodic subscription license, a usage rights license, or a free use license.
3. The method of claim 2, wherein the pay-per-use license comprises a number of credit purchased or pre-purchased based usage license, wherein the requested service of the plurality of available services costs a predetermined number of credit per session use, wherein the method further comprises: decrementing, after generating the unlock code, a counter indicating a remaining number of credit of the number of credit purchased or pre-purchased by the predetermined number of credit per session use, the counter being associated with the user or an entity associated with the user.
4. The method of claim 3, further comprising: receiving, decrypting, and authenticating a purchase code from the user, wherein the purchase code corresponds to a purchase of one or more additional credit; and in response to receiving, decrypting, and authenticating the purchase code, incrementing the counter indicating the remaining number of credit by the one or more additional credit purchased.
5. The method of claim 4, wherein at least one of the number of credit purchased or pre-purchased, the remaining number of credit, or the one or more additional credit is assignable to at least one of: an entity associated with the pay-per-use license; an account associated with the entity; or one or more individuals associated with the entity.
6. The method of claim 1, wherein receiving the generated unique identifier contained in the received request for the unlock code comprises one of: receiving the generated unique identifier spoken by the user over the phone and converted via speech-to-text conversion; receiving the generated unique identifier manually entered by the user or another user via a user interface via a text input field; receiving the generated unique identifier copied and pasted by the user via the user interface via a text input field; receiving the generated unique identifier as a visual code, an image of which is captured by the user using a camera of a user device; or, when the client device is connected to a communication network, receiving the generated unique identifier from the client device via network communication.
7. The method of claim 6, wherein the image of the visual code, when captured, triggers one of: sending the generated unique identifier over a network; or accessing a collection of information that allows the user to manually enter the generated unique identifier.
8. The method of claim 1, wherein the unlock code comprises embedded data comprising at least one of: security-related data; data associated with the generated unique identifier; data about a type of user; data about whether the user needs to pay; session identification data; data about a type of requested service; or data about a type of hardware associated with the requested service.
9. The method of claim 1, wherein generating the unlock code associated with the requested service using the first software comprises: arranging the generated unique identifier in a predetermined manner and creating a hash-based message authentication code ("HMAC") using a cryptographic hash function comprising a secure hash algorithm ("SHA"), wherein the secure hash algorithm comprises one of a SHA-224 algorithm, a SHA-256 algorithm, a SHA-384 algorithm, a SHA-512 algorithm, a SHA-512 / 224 algorithm, or a SHA-512 / 256 algorithm.
10. A device comprising: at least one processor; and a non-transitory computer-readable medium communicatively coupled with the at least one processor, the non-transitory computer-readable medium having stored thereon computer software comprising a set of instructions, the set of instructions when executed by the at least one processor cause the device to: receive, from a user of a client device using a first software, a request for an unlock code for a requested service using the first software, wherein the request for the unlock code comprises a generated unique identifier associated with the requested service, wherein the generated unique identifier comprises licensing information comprising at least one of: data regarding the requested service using the first software; session data for a session use of the requested service; data regarding a type of system used to provide the requested service; or information regarding a type of license associated with at least one of the requested service or the first software; in response to receiving the generated unique identifier, extract the licensing information embedded in the unique identifier, and determine whether the user should have access to the requested service using the first software based at least in part on the licensing information and stored information regarding at least one of the user, an entity associated with the user, the requested service, or the first software: based on a determination that the user should have access to the requested service using the first software, generate the unlock code associated with the requested service using the first software; deduct a fee associated with the licensing information; and send the unlock code to the user, wherein the unlock code is a per-session code for unlocking a single session use of the requested service using the first software; receive, decrypt, and authenticate a refund code from the user; and in response to receiving, decrypting, and authenticating the refund code, invalidate a current single session use of the requested service using the first software, and increment the counter indicating a remaining credit number by a predetermined credit number for each session use of the requested service, wherein an option to access the refund code is available prior to an end of the single session use of the requested service using the first software, wherein upon the end of the single session use occurring, the option to access the refund code is deactivated.
11. A method comprising: receiving a request by a user for a requested service using a first software; in response to receiving the request, initiating an authentication protocol of the first software that causes generation of a unique identifier, and presenting a prompt to the user to request an unlock code using the generated unique identifier, wherein the generated unique identifier includes licensing information including at least one of: data regarding the requested service of using the first software; session data for a session use of the requested service; data regarding a type of system for providing the requested service; or information regarding a type of license associated with at least one of the requested service or the first software, wherein the generated unique identifier is sent to a license server and verified by the license server; in response to sending the generated unique identifier to the license server, receiving the unlock code from the license server, wherein the unlock code is a per-session code for unlocking the single session use of the requested service of using the first software; in response to receiving the unlock code, verifying the unlock code; and in response to the unlock code being verified, unlocking the single session use of the requested service of using the first software to allow the user access to the single session use of the requested service of using the first software; receiving, decrypting, and authenticating a refund code from the user; and in response to receiving, decrypting, and authenticating the refund code, invalidating a current single session use of the requested service of using the first software, and incrementing the counter indicating the remaining credit number by a predetermined credit number for each session use of the requested service, wherein an option to access the refund code is available prior to an end of the delivery of the single session use of the requested service of using the first software, wherein the option to access the refund code is deactivated once the end of the delivery of the single session use occurs.
12. The method of claim 11, wherein the license information further comprises one or more of: information regarding a time of generation of the generated unique identifier; information regarding a session information check; information regarding a cost corresponding to the license associated with the at least one of the requested service or the first software; information regarding conditions associated with the license; information regarding limitations associated with the license; information regarding a type of hardware associated with the first software; information regarding a type of hardware associated with the requested service; or information regarding a session use of the requested service, wherein license type includes one of a pay-per-use license, a periodic subscription license, a usage rights license, or a free use license.
13. The method of claim 11, further comprising: encoding the generated unique identifier.
14. The method of claim 11, wherein presenting the prompt to the user to request an unlock code using the generated unique identifier comprises presenting two or more options, the two or more options comprising: displaying the generated unique identifier and a communication means for the user to use or contact and provide the generated unique identifier; displaying a connection mechanism to a collection of information, the connection mechanism including the generated unique identifier; or, displaying a visual code and prompting the user to scan the visual code, the visual code containing data associated with the generated unique identifier.
15. The method of claim 14, wherein the visual code includes one of a barcode or a quick response ("QR”) code.
16. The method of claim 14, further comprising: determining whether a client device is connected to a communication network prior to presenting the user with the prompt to request an unlock code using the generated unique identifier; and causing the option to display the connection mechanism of the information collection to be greyed out based on a determination that the client device is not connected to a communication network or that access to the communication network is restricted.
17. The method of claim 11, wherein sending the generated unique identifier to the license server for verification comprises one of: sending the generated unique identifier spoken by the user over the phone; sending the generated unique identifier manually entered by the user or another user via a user interface; sending the generated unique identifier copied and pasted by the user via the user interface; sending the generated unique identifier as a visual code whose image is captured by the user using a camera of a user device; or sending the generated unique identifier from the client device via network communication when the client device is connected to a communication network.
18. The method of claim 17, wherein the image of the visual code, when captured, triggers one of: sending the generated unique identifier over a network; or accessing an information collection that allows the user to manually enter the generated unique identifier.
Citation Information
Patent Citations
Method and System for Implementing Augmented Reality (AR)-Based Assistance Within Work Environment
US20190362556A1
Distributed execution software license server
US20010011254A1
Licensing the use of software on a particular CPU
US20060059571A1
Benefits administration system and methods of use and doing business
US20060064313A1
Technologies and methods for security access
US20140375422A1