A mirror file theft prevention method, device, equipment and storage medium

By verifying and decrypting between the cloud host and the server, the problem of complex offline communication and manual operation in the process of preventing theft of image files is solved, and efficient image file permission verification and startup are achieved.

CN114254376BActive Publication Date: 2025-12-23BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202011001025.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-22
Publication Date
2025-12-23
Estimated Expiration
2040-09-22

AI Technical Summary

Technical Problem

Existing technologies require offline communication and manual operation in the process of preventing theft of mirror files, which makes the implementation process complex and inefficient, and affects the interests of service providers.

Method used

The cloud host sends a verification request to the server. The server determines the permission information based on the cloud host's identification information and generates encrypted information. The cloud host decrypts the encrypted information to obtain the permission information and start the image file.

Benefits of technology

It effectively prevents the mirror file from being pirated, simplifies the anti-piracy process, improves operating efficiency, and avoids offline communication and manual operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254376B_ABST
    Figure CN114254376B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a mirror file anti-theft method, device, equipment and storage medium. The present disclosure sends a verification request to the server through the cloud host installed with the mirror file, so that the server can verify whether the cloud host has the permission to use the mirror file, and generate the permission information of the cloud host to the mirror file. The server sends the encrypted information to the cloud host, the plaintext of the encrypted information includes the permission information, if the cloud host can successfully decrypt the encrypted information, and the permission information indicates that the cloud host has the permission to use the mirror file, then the mirror file can be normally started, thereby effectively preventing the mirror file from being pirated, and the anti-theft process does not need offline communication and manual operation, simplifying the mirror file anti-theft process and improving the running efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the field of information technology, and particularly relates to a mirror file anti-theft method and device, equipment and storage medium. BACKGROUND

[0002] In the cloud product of the mirror type, some mirror files need to be authorized by the service provider before use. However, some customers will make new mirror files according to the mirror files already installed and authorized in the cloud host, and use the new mirror files on the new cloud host. Thus, the customers can use the mirror files for free in the future, which causes the interests of the service provider to be damaged.

[0003] In order to prevent the interests of the service provider from being damaged, the prior art contacts the customer offline after the customer purchases the mirror file, asks the customer for the cloud host identifier of the cloud host that needs to install the mirror file, and makes a license file according to the cloud host identifier. Then the service provider sends the made license file to the customer, and the customer imports the license file into the cloud host to complete the activation authorization of the mirror file.

[0004] However, the prior art needs offline communication and manual operation, which causes the implementation process to be relatively complex and the running efficiency to be relatively low. SUMMARY

[0005] In order to solve the above technical problems or at least partially solve the above technical problems, the present disclosure provides a mirror file anti-theft method, device, equipment and storage medium to simplify the mirror file anti-theft process and improve the running efficiency.

[0006] In a first aspect, the embodiments of the present disclosure provide a mirror file anti-theft method, which is applied to a cloud host installed with a mirror file, and the method comprises the following steps.

[0007] sending a verification request to a server, wherein the verification request comprises identifier information of the cloud host, and the server is configured to determine permission information of the mirror file of the cloud host according to the identifier information of the cloud host;

[0008] receiving encrypted information from the server, wherein the plaintext corresponding to the encrypted information comprises the permission information;

[0009] decrypting the encrypted information according to a decryption key corresponding to the mirror file;

[0010] if the decryption is successful, obtaining the permission information from the decrypted information corresponding to the encrypted information;

[0011] if the permission information indicates that the cloud host has the permission to use the mirror file, starting the mirror file.

[0012] In a second aspect, the embodiments of the present disclosure provide a mirror file theft prevention method, which is applied to a server, and the method comprises the following steps:

[0013] receiving a verification request from a cloud host installed with a mirror file, wherein the verification request comprises identification information of the cloud host;

[0014] determining, according to the identification information of the cloud host, permission information of the mirror file of the cloud host;

[0015] encrypting the permission information according to an encryption key corresponding to the mirror file to obtain encrypted information;

[0016] sending the encrypted information to the cloud host.

[0017] In a third aspect, the embodiments of the present disclosure provide a mirror file theft prevention device, which comprises:

[0018] a sending module configured to send a verification request to a server, wherein the verification request comprises identification information of a cloud host, and the server is configured to determine permission information of a mirror file of the cloud host according to the identification information of the cloud host;

[0019] a receiving module configured to receive encrypted information from the server, wherein the plaintext corresponding to the encrypted information comprises the permission information;

[0020] a decryption module configured to decrypt the encrypted information according to a decryption key corresponding to the mirror file;

[0021] a obtaining module configured to, if the decryption is successful, obtain the permission information from the decrypted information corresponding to the encrypted information;

[0022] a starting module configured to, if the permission information indicates that the cloud host has the permission to use the mirror file, start the mirror file.

[0023] In a fourth aspect, the embodiments of the present disclosure provide a mirror file theft prevention device, which comprises:

[0024] a receiving module configured to receive a verification request from a cloud host installed with a mirror file, wherein the verification request comprises identification information of the cloud host;

[0025] a determining module configured to determine, according to the identification information of the cloud host, permission information of the mirror file of the cloud host;

[0026] an encryption module configured to encrypt the permission information according to an encryption key corresponding to the mirror file to obtain encrypted information;

[0027] a sending module configured to send the encrypted information to the cloud host.

[0028] In a fifth aspect, the embodiments of the present disclosure provide a cloud host, comprising:

[0029] a memory;

[0030] a processor; and

[0031] a computer program;

[0032] The computer program is stored in the memory and configured to be executed by the processor to implement the method of the first aspect.

[0033] In a sixth aspect, the embodiments of the present disclosure provide a server, comprising:

[0034] a memory;

[0035] a processor; and

[0036] a computer program;

[0037] The computer program is stored in the memory and configured to be executed by the processor to implement the method of the second aspect.

[0038] In a seventh aspect, the embodiments of the present disclosure provide a storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the method of the first aspect or the second aspect.

[0039] The mirror file anti-piracy method, device, equipment and storage medium provided by the embodiments of the present disclosure, the cloud host installed with the mirror file sends a verification request to the server, so that the server can verify whether the cloud host has the right to use the mirror file, and generate the right information of the cloud host to the mirror file, the server sends the encrypted information to the cloud host, the plaintext of the encrypted information includes the right information, if the cloud host can successfully decrypt the encrypted information, and the right information indicates that the cloud host has the right to use the mirror file, then the mirror file can be normally started, so as to effectively prevent the mirror file from being pirated, and the anti-piracy process does not need offline communication, nor manual operation, simplifying the mirror file anti-piracy process, improving the running efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0040] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure.

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without any creative effort.

[0042] Figure 1 The mirror file theft prevention method flowchart provided by the embodiment of the present disclosure;

[0043] Figure 2 The application scenario schematic diagram provided by the embodiment of the present disclosure;

[0044] Figure 3 Another mirror file theft prevention method flowchart provided by the embodiment of the present disclosure;

[0045] Figure 4 Another mirror file theft prevention method flowchart provided by the embodiment of the present disclosure;

[0046] Figure 5 Another mirror file theft prevention method flowchart provided by the embodiment of the present disclosure;

[0047] Figure 6 The structural schematic diagram of the mirror file theft prevention device provided by the embodiment of the present disclosure;

[0048] Figure 7 The structural schematic diagram of the mirror file theft prevention device provided by the embodiment of the present disclosure;

[0049] Figure 8 The structural schematic diagram of the cloud host provided by the embodiment of the present disclosure;

[0050] Figure 9 The structural schematic diagram of the server provided by the embodiment of the present disclosure. DETAILED DESCRIPTION

[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without any creative effort.

[0052] In the following description, many specific details are set forth in order to fully understand the present disclosure, but the present disclosure can also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some of the embodiments of the present disclosure, not all the embodiments.

[0053] Generally, in the cloud product of the mirror type, some image files need to be authorized by the service provider before use. However, some customers may make new image files according to the image files already installed and authorized in the cloud host, and use the new image files on the new cloud host. Thus, the customer can use the image files for free subsequently, which causes the interests of the service provider to be damaged. In order to prevent the interests of the service provider from being damaged, the prior art contacts the customer offline after the customer purchases the image file, asks the customer for the cloud host identifier of the cloud host that needs to install the image file, and makes a license file according to the cloud host identifier. The cloud host identifier is the identifier information of the cloud host, and the identifier information of the cloud host can specifically include the Media Access Control (MAC) address, Internet Protocol (IP) address, and the like of the cloud host. Then the service provider sends the made license file to the customer, and the customer imports the license file into the cloud host to complete the activation authorization of the image file. However, the prior art needs offline communication and manual operation, which causes the implementation process to be relatively complex and the running efficiency to be relatively low. In view of this problem, the embodiment of the present disclosure provides an image file theft prevention method, which will be introduced below in combination with specific embodiments.

[0054] Figure 1 The image file theft prevention method provided by the embodiment of the present disclosure is shown in the flowchart. The image file theft prevention method provided by the embodiment can be applied to a cloud host installed with an image file, and the specific steps of the method are as follows:

[0055] S101, a verification request is sent to a server, the verification request including identifier information of the cloud host, the server being configured to determine permission information of the cloud host to the image file according to the identifier information of the cloud host.

[0056] As shown in Figure 2 The terminal device 21 can be in communication connection with the server 22, and the server 22 can be a platform server of a seller. It can be understood that the platform server can not be limited to one server, and can also be a server cluster. The seller can sell a cloud host installed with an image file. The image file can also be referred to as a mirror, and the image file and the cloud host can be provided by different manufacturers or by the same manufacturer. It can be understood that the seller can be a manufacturer of the image file or a manufacturer of the cloud host, or the seller can also be a third party other than the manufacturer of the image file and the manufacturer of the cloud host.

[0057] When a user of the terminal device 21 needs to purchase a cloud host installed with an image file, the user can send an electronic order to the server 22 through the terminal device 21. As shown in Figure 2As shown, 23 can specifically represent the cloud host purchased by the user and installed with the image file.

[0058] After the user purchases successfully, the server 22 can record the association information of the cloud host purchased by the user and installed with the image file and the image file. Specifically, the association information includes the identification information of the image file and the identification information of the cloud host, and the identification information of the cloud host can be, for example, the MAC address, IP address, etc. of the cloud host. It can be understood that the identification information of the image file can uniquely identify the image file, and the identification information of the cloud host can uniquely identify the cloud host.

[0059] Further, the server 22 can store the association information in a local or a database corresponding to the server 22, wherein the database corresponding to the server 22 can be a database local to the server 22, or a database independent of the server 22 and capable of being communicatively connected to the server 22.

[0060] When the user receives the cloud host 23 installed with the image file, the cloud host 23 needs to verify the use permission of the cloud host 23 to the image file. For example, before the cloud host 23 starts the image file, the cloud host 23 needs to verify the use permission of the cloud host 23 to the image file. Specifically, the cloud host 23 sends a verification request to the server 22, and the verification request includes the identification information of the cloud host 23. When the server 22 receives the verification request, the server 22 queries the image file corresponding to the cloud host 23 according to the identification information of the cloud host 23, and determines whether the cloud host 23 has the permission to use the image file, thereby obtaining the permission information of the cloud host 23 to the image file. Specifically, the permission information can indicate whether the cloud host 23 has the permission to use the image file. Alternatively, in some other embodiments, the permission information can also indicate the permission size or the permission range of the cloud host 23 when using the image file.

[0061] Specifically, as described above, the association relationship can also include the time when the user purchases the cloud host 23. The server 22 can determine whether the cloud host 23 has the permission to use the image file according to the time when the user purchases the cloud host 23. For example, within a preset time after the user purchases the cloud host 23, the cloud host 23 can use the image file. When the server 22 receives the verification request, the server 22 determines whether the sending time of the verification request is within the preset time after the user purchases the cloud host 23 according to the sending time of the verification request and the time when the user purchases the cloud host 23. If yes, the server 22 determines that the cloud host 23 has the permission to use the image file; otherwise, the server 22 determines that the cloud host 23 does not have the permission to use the image file.

[0062] Or, the association relationship as described above can also include the user's payment situation, the validity period of the mirror file, etc. For example, the server 22 can determine whether the cloud host 23 has the right to use the mirror file according to the user's payment situation of the cloud host 23 for the use right of the mirror file. For example, the user can pay the permanent use fee of the mirror file, or pay the use fee of the mirror file within a certain period of time, and the certain period of time corresponds to the validity period of the mirror file. When the server 22 receives the verification request, the user's payment situation, the validity period of the mirror file, etc. are queried according to the identification information of the cloud host. Further, according to the user's payment situation, the validity period of the mirror file, etc., it is determined whether the cloud host 23 has the right to use the mirror file.

[0063] Further, the server 22 can encrypt the permission information of the cloud host 23 for the mirror file to obtain encrypted information, and send the encrypted information to the cloud host 23.

[0064] S102, receiving encrypted information from the server, the plaintext corresponding to the encrypted information including the permission information.

[0065] For example, the cloud host 23 receives the encrypted information from the server 22, and the plaintext corresponding to the encrypted information includes the permission information as described above.

[0066] S103, decrypting the encrypted information according to the decryption key corresponding to the mirror file.

[0067] It can be understood that before the user receives the cloud host 23 installed with the mirror file, the manufacturer of the mirror file needs to make the mirror file. If the mirror file is a mirror file that needs to be authorized by the manufacturer or the server 22, the corresponding decryption key can be pre-stored in the mirror file, or the startup program of the mirror file can be generated to generate the decryption key. In addition, in the embodiment, the encryption key and the decryption key can be symmetric keys or asymmetric keys. Alternatively, one mirror file can correspond to one encryption key, so that different mirror files can correspond to different decryption keys. Or a type of mirror file can correspond to an encryption key, so that different types of mirror files can correspond to different decryption keys.

[0068] When the cloud host 23 receives the encrypted information from the server 22, the encrypted information is decrypted according to the decryption information corresponding to the mirror file. For example, the startup program in the mirror file can obtain the encrypted information issued by the server 22, and decrypt the encrypted information according to the decryption key stored in the mirror file. Alternatively, the startup program can generate a corresponding decryption key, and decrypt the encrypted information according to the decryption key.

[0069] S104, if the decryption is successful, obtaining the permission information from the decryption information corresponding to the encrypted information.

[0070] If the cloud host 23 decrypts successfully, further obtaining the permission information from the decryption information corresponding to the encrypted information. If the cloud host 23 fails to decrypt, the image file fails to start.

[0071] S105, if the permission information indicates that the cloud host has the permission to use the image file, starting the image file.

[0072] After the cloud host 23 obtains the permission information by decryption, further, according to the permission information, determining whether the cloud host 23 has the permission to use the image file. If the permission information indicates that the cloud host 23 has the permission to use the image file, the cloud host 23 can normally start the image file. If the permission information indicates that the cloud host 23 does not have the permission to use the image file, the image file fails to start.

[0073] The embodiment of the disclosure sends a verification request to the server through the cloud host installed with the image file, so that the server can verify whether the cloud host has the permission to use the image file, and generate the permission information of the cloud host to the image file. The server sends encrypted information to the cloud host, the plaintext of the encrypted information includes the permission information. If the cloud host can successfully decrypt the encrypted information, and the permission information indicates that the cloud host has the permission to use the image file, the image file can be normally started, thereby effectively preventing the image file from being pirated, and the anti-piracy process does not need offline communication and manual operation, simplifying the image file anti-piracy process and improving the running efficiency.

[0074] Figure 3 Another flowchart of the image file anti-piracy method provided by the embodiment of the disclosure. The image file anti-piracy method provided by the embodiment can be applied to a cloud host installed with an image file, and the specific steps of the method are as follows:

[0075] S301, sending a verification request to a server, the verification request including identification information of the cloud host, the server being configured to determine permission information of the cloud host to the image file according to the identification information of the cloud host.

[0076] The implementation process and specific principles of S301 and S101 are similar, and are not described herein.

[0077] S302, receiving encrypted information from the server, the plaintext corresponding to the encrypted information including the permission information.

[0078] The implementation process and specific principles of S302 and S102 are similar, and are not described herein.

[0079] S303, detecting whether the cloud host locally exists information same as the encryption information, if the cloud host locally does not exist information same as the encryption information, executing S304; if the cloud host locally exists information same as the encryption information, executing S307.

[0080] On the basis of the above embodiment, optionally, the plaintext corresponding to the encryption information includes the permission information and the timestamp of the server.

[0081] For example, after the server 22 determines the permission information of the cloud host 23 to the image file according to the identification information of the cloud host 23, the server 22 can encrypt the permission information and the timestamp of the server 22 together to obtain the encryption information. The timestamp of the server 22 changes over time. The timestamp can be the timestamp of the server 22 receiving the verification request, or the timestamp of the server 22 sending the encryption information. Taking the timestamp of the server 22 receiving the verification request as an example, when the server 22 receives the verification request sent by the cloud host 23 at different times, the timestamp of the server 22 is different, and therefore the encryption information generated by the server 22 is different. That is, the encryption information can change with the change of the timestamp of the server 22. In addition, it can be understood that using the timestamp is only one implementation manner that can make the encryption information generated by the server each time different. In addition, the implementation manner that can make the encryption information generated by the server each time different is not limited to this, for example, a random number, a random string or other random changing information can be used instead of the timestamp, or the random changing information can be used together with the timestamp. That is, as long as the information included in the plaintext encrypted by the server 22 each time can make the encryption information after each encryption different.

[0082] Since some users may counterfeit the encryption information of the server 22 through the cloud host 23, an encryption information is generated in the cloud host 23. Since the cloud host 23 cannot obtain the encryption key used by the server 22, the encryption information generated by the cloud host 23 will not be the same as the encryption information generated by the server 22 with a high probability. However, it may also be the same. Therefore, after the startup program in the image file installed in the cloud host 23 obtains the encryption information issued by the server 22, the startup program can first detect whether the cloud host 23 locally exists information same as the encryption information. If the cloud host 23 locally exists information same as the encryption information, it indicates that the cloud host 23 counterfeits the encryption information of the server 22, at this time, the startup program can refuse to start the image file, that is, S307 is executed. If the startup program in the image file determines that the cloud host 23 locally does not exist information same as the encryption information, it indicates that the cloud host 23 does not counterfeit the encryption information of the server 22, at this time, the startup program in the image file can use the decryption key corresponding to the image file to decrypt the encryption information, that is, S304 is executed.

[0083] S304, decrypt the encrypted information according to the decryption key corresponding to the mirror image file.

[0084] The implementation process and specific principles of S304 and S103 are similar, and details are not described herein.

[0085] S305, if the decryption is successful, obtaining the permission information from the decryption information corresponding to the encrypted information.

[0086] The implementation process and specific principles of S305 and S104 are similar, and details are not described herein.

[0087] S306, if the permission information indicates that the cloud host has the permission to use the mirror image file, starting the mirror image file.

[0088] The implementation process and specific principles of S306 and S105 are similar, and details are not described herein.

[0089] S307, refusing to start the mirror image file.

[0090] In the embodiment, after the cloud host receives the encrypted information sent by the server, it is detected whether the cloud host locally exists the same information as the encrypted information. If the cloud host locally does not exist the same information as the encrypted information, the encrypted information is decrypted. If the cloud host locally exists the same information as the encrypted information, the mirror image file is refused to start, thereby preventing the cloud host from copying the encrypted information of the server, so that the cloud host always has the permission to use the mirror image file, and further reducing the risk of the use permission of the mirror image file being stolen. In addition, in the embodiment, the authorization information and the timestamp of the server are encrypted by the server, so that the encrypted information generated by the server can change with the change of the timestamp of the server. Further, the possibility of the cloud host copying the encrypted information is prevented, and the cloud host can also avoid using the mirror image file without verifying the use permission of the mirror image file, thereby improving the protection strength of the use permission of the mirror image file.

[0091] On the basis of the above embodiment, optionally, the plaintext corresponding to the encrypted information further includes: the next time of the cloud host to perform the verification.

[0092] For example, when the server 22 feeds back the local verification request of the cloud host, the server 22 can also determine the next time of the cloud host to perform the verification. In one possible case, the server 22 can encrypt the permission information and the next time of the cloud host to perform the verification to obtain the encrypted information.

[0093] In another possible case, the server 22 can encrypt the permission information, the timestamp of the server 22 and the next time of the cloud host to perform the verification to obtain the encrypted information.

[0094] The embodiment determines the next time for the cloud host to perform the verification by the server, so that the cloud host can perform the re-verification at the time, and the control of the server or the service provider on the usage permission of the image file is further improved.

[0095] Optionally, after starting the image file, the method further includes: periodically sending the verification request to the server.

[0096] For example, the server 22 can not require the next time for the cloud host to perform the verification, and the cloud host 23 can actively and periodically send the verification request to the server 22 to verify whether the cloud host 23 has the permission to use the installed image file. Specifically, the cloud host 23 can send the verification request to the server 22 at a regular time after starting the image file, i.e., in the process of normally using the image file.

[0097] The embodiment enables the server to periodically verify the usage permission of the image file by periodically sending the verification request to the server, and in particular, the usage permission of the image file is verified by the server at a regular time during the use of the image file, and the control of the server or the service provider on the usage permission of the image file is further improved.

[0098] Figure 4 Another flowchart of the image file theft prevention method provided by the embodiment of the present disclosure is provided. The image file theft prevention method provided by the embodiment can be applied to a cloud host installed with an image file, and the specific steps of the method are as follows:

[0099] S401, preparing to start the image file or verifying the usage permission of the cloud host to the image file at a regular time.

[0100] S402, obtaining the encryption information issued by the server.

[0101] S403, whether the encryption information is successfully obtained. If yes, S404 is performed, otherwise, S406 is performed.

[0102] S404, whether the encryption information is successfully decrypted. If yes, S405 is performed, otherwise, S406 is performed.

[0103] S405, verifying whether the cloud host has the permission to use the image file. If yes, S407 is performed, otherwise, S406 is performed.

[0104] S406, the image file fails to start.

[0105] S407, the image file starts successfully.

[0106] It can be understood that, as Figure 4The implementation method and specific principle of S401-S407 shown are consistent with the above-mentioned embodiments, and will not be described here.

[0107] Figure 5 Another mirror file theft prevention method flowchart is provided for the embodiments of the present disclosure. The mirror file theft prevention method provided by the present embodiment can be applied to a server, and the specific steps of the method are as follows:

[0108] S501, receiving a verification request from a cloud host installed with a mirror file, the verification request comprising identification information of the cloud host.

[0109] When the user receives the cloud host 23 installed with the mirror file, the cloud host 23 needs to verify the use permission of the cloud host 23 to the mirror file. For example, before the cloud host 23 starts the mirror file, the cloud host 23 needs to verify the use permission of the cloud host 23 to the mirror file. Specifically, the cloud host 23 sends a verification request to the server 22, and the verification request comprises the identification information of the cloud host 23.

[0110] S502, determining the permission information of the cloud host to the mirror file according to the identification information of the cloud host.

[0111] Optionally, the server or the database corresponding to the server pre-stores the association information of the mirror file and the cloud host.

[0112] When the server 22 receives the verification request, the server 22 queries the mirror file corresponding to the cloud host 23 according to the identification information of the cloud host 23, and determines whether the cloud host 23 has the permission to use the mirror file, thereby obtaining the permission information of the cloud host 23 to the mirror file. Specifically, the permission information can indicate whether the cloud host 23 has the permission to use the mirror file. Alternatively, in some other embodiments, the permission information can also indicate the permission size or the permission range of the cloud host 23 when using the mirror file.

[0113] S503, encrypting the permission information according to the encryption key corresponding to the mirror file to obtain encrypted information.

[0114] Further, the server 22 can encrypt the permission information of the cloud host 23 to the mirror file to obtain encrypted information.

[0115] Optionally, the encryption keys corresponding to different types of mirror files are different.

[0116] For example, one mirror file can correspond to one encryption key, so that different mirror files can correspond to different decryption keys. Alternatively, one type of mirror file can correspond to one encryption key, so that different types of mirror files can correspond to different decryption keys.

[0117] S504, send the encrypted information to the cloud host.

[0118] The server 22 sends the encrypted information to the cloud host 23. When the cloud host 23 receives the encrypted information from the server 22, the encrypted information is decrypted according to the decryption information corresponding to the image file. For example, the startup program in the image file can obtain the encrypted information issued by the server 22, and decrypt the encrypted information according to the decryption key stored in the image file. Alternatively, the startup program can generate a corresponding decryption key and decrypt the encrypted information according to the decryption key. If the cloud host 23 decrypts successfully, the permission information is further obtained from the decryption information corresponding to the encrypted information. If the cloud host 23 fails to decrypt, the image file fails to start.

[0119] After the cloud host 23 decrypts the permission information, further, according to the permission information, it is determined whether the cloud host 23 has the permission to use the image file. If the permission information indicates that the cloud host 23 has the permission to use the image file, the cloud host 23 can normally start the image file. If the permission information indicates that the cloud host 23 does not have the permission to use the image file, the image file fails to start.

[0120] The embodiment of the disclosure sends a verification request to the server through the cloud host installed with the image file, so that the server can verify whether the cloud host has the permission to use the image file, and generate the permission information of the cloud host to the image file. The server sends encrypted information to the cloud host, the plaintext of the encrypted information includes the permission information, if the cloud host can successfully decrypt the encrypted information, and the permission information indicates that the cloud host has the permission to use the image file, the image file can be normally started, thereby effectively preventing the image file from being pirated, and the anti-piracy process does not need offline communication and manual operation, simplifying the image file anti-piracy process and improving the running efficiency.

[0121] Figure 6 The structure diagram of the image file anti-piracy device provided by the embodiment of the disclosure. The image file anti-piracy device can be the cloud host or a component in the cloud host as described above. The image file anti-piracy device provided by the embodiment of the disclosure can execute the processing flow provided by the image file anti-piracy method embodiment, as shown in Figure 6 The image file anti-piracy device 60 includes:

[0122] The sending module 61 is configured to send a verification request to a server, the verification request including identification information of a cloud host, and the server being configured to determine permission information of the cloud host to an image file according to the identification information of the cloud host.

[0123] The receiving module 62 is configured to receive encrypted information from the server, and the plaintext corresponding to the encrypted information includes the permission information.

[0124] The decryption module 63 is configured to decrypt the encrypted information according to a decryption key corresponding to the mirror image file.

[0125] The obtaining module 64 is configured to obtain the permission information from the decrypted information corresponding to the encrypted information if the decryption is successful.

[0126] The starting module 65 is configured to start the mirror image file if the permission information indicates that the cloud host has the permission to use the mirror image file.

[0127] Optionally, the plaintext corresponding to the encrypted information includes the permission information and a timestamp of the server.

[0128] Optionally, the plaintext corresponding to the encrypted information further includes a next time for the cloud host to perform the verification.

[0129] Optionally, the mirror image file theft prevention apparatus 60 further includes a detection module 66, configured to detect whether the cloud host locally has information identical to the encrypted information after the receiving module receives the encrypted information from the server; and the decryption module is specifically configured to decrypt the encrypted information according to the decryption key corresponding to the mirror image file if the cloud host locally does not have information identical to the encrypted information.

[0130] Optionally, the starting module is further configured to refuse to start the mirror image file if the cloud host locally has information identical to the encrypted information.

[0131] Optionally, the sending module is further configured to periodically send the verification request to the server after the starting module starts the mirror image file.

[0132] Figure 6 The mirror image file theft prevention apparatus of the embodiment can be used to execute the technical solutions of the above-mentioned method embodiments, and has similar principles and technical effects, which will not be repeated here.

[0133] Figure 7 A structural diagram of the mirror image file theft prevention apparatus provided by the embodiment of the present disclosure is shown. The mirror image file theft prevention apparatus can be a server or a component in the server as described above. The mirror image file theft prevention apparatus provided by the embodiment of the present disclosure can execute the processing flow provided by the mirror image file theft prevention method embodiment, such as Figure 7 As shown, the mirror image file theft prevention apparatus 70 includes:

[0134] The receiving module 71 is configured to receive a verification request from a cloud host installed with a mirror image file, and the verification request includes identification information of the cloud host.

[0135] The determining module 72 is configured to determine the permission information of the cloud host to the image file according to the identification information of the cloud host.

[0136] The encryption module 73 is configured to encrypt the permission information according to the encryption key corresponding to the image file to obtain encrypted information.

[0137] The sending module 74 is configured to send the encrypted information to the cloud host.

[0138] Optionally, the device or the database corresponding to the device pre-stores the association information of the image file and the cloud host.

[0139] Optionally, the encryption keys corresponding to different types of image files are different.

[0140] Figure 7 The image file theft prevention device of the embodiment can be used to execute the technical solutions of the above-mentioned method embodiments, and the implementation principles and technical effects are similar, which will not be described here.

[0141] Figure 8 A structural diagram of a cloud host provided by the embodiment of the present disclosure. The cloud host provided by the embodiment of the present disclosure can execute the processing flow provided by the image file theft prevention method embodiment, as shown in Figure 8 The cloud host 80 includes a storage 81, a processor 82, a computer program, and a communication interface 83; wherein the computer program is stored in the storage 81 and is configured to be executed by the processor 82 to execute the image file theft prevention method as described above.

[0142] Figure 9 A structural diagram of a server provided by the embodiment of the present disclosure. The server provided by the embodiment of the present disclosure can execute the processing flow provided by the image file theft prevention method embodiment, as shown in Figure 9 The server 90 includes a storage 91, a processor 92, a computer program, and a communication interface 93; wherein the computer program is stored in the storage 91 and is configured to be executed by the processor 92 to execute the image file theft prevention method as described above.

[0143] In addition, the embodiment of the present disclosure also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the image file theft prevention method described in the above-mentioned embodiments.

[0144] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0145] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A mirror file theft prevention method, characterized by, The method is applied to a cloud host installed with an image file, and the method comprises: sending a check request to a server, the check request comprising identification information of the cloud host, the server being configured to determine, according to the identification information of the cloud host, permission information of the cloud host to the image file; receiving, from the server, encrypted information, the plaintext corresponding to the encrypted information comprising the permission information; detecting whether the cloud host locally has information identical to the encrypted information; if the cloud host does not locally have information identical to the encrypted information, decrypting the encrypted information according to a decryption key corresponding to the image file; if the decryption is successful, obtaining the permission information from decrypted information corresponding to the encrypted information; if the permission information indicates that the cloud host has permission to use the image file, starting the image file, the permission information comprising a permission size or a permission range of the cloud host in using the image file.

2. The method of claim 1, wherein, The plaintext corresponding to the encrypted information comprises the permission information and a timestamp of the server.

3. The method according to claim 1 or 2, characterized in that, The plaintext corresponding to the encrypted information further comprises a next time of check of the cloud host.

4. The method of claim 1, wherein, The method further comprises: if the cloud host locally has information identical to the encrypted information, refusing to start the image file.

5. The method of claim 1, wherein, After starting the image file, the method further comprises: periodically sending the check request to the server.

6. A mirror file theft prevention method characterized by comprising: The method is applied to a server, and the method comprises: receiving, from a cloud host installed with an image file, a check request, the check request comprising identification information of the cloud host; determining, according to the identification information of the cloud host, permission information of the cloud host to the image file, the permission information comprising a permission size or a permission range of the cloud host in using the image file; encrypting the permission information according to an encryption key corresponding to the image file to obtain encrypted information, the encrypted information being used at least for the cloud host to detect whether the cloud host locally has information identical to the encrypted information; sending the encrypted information to the cloud host.

7. The method of claim 6, wherein, The server or a database corresponding to the server has pre-stored association information of the image file and the cloud host.

8. The method according to claim 6 or 7, characterized in that, Encryption keys corresponding to different types of image files are different.

9. An apparatus for protecting a mirror file, characterized by comprising: The method comprises: a sending module configured to send a check request to a server, the check request comprising identification information of the cloud host, the server being configured to determine, according to the identification information of the cloud host, permission information of the cloud host to the image file; a receiving module configured to receive, from the server, encrypted information, the plaintext corresponding to the encrypted information comprising the permission information; a detecting module configured to, after the receiving module receives the encrypted information from the server, detect whether the cloud host locally has information identical to the encrypted information; a decrypting module configured to, if the cloud host does not locally have information identical to the encrypted information, decrypt the encrypted information according to a decryption key corresponding to the image file; an obtaining module configured to, if the decryption is successful, obtain the permission information from decrypted information corresponding to the encrypted information; The starting module is configured to start the image file if the permission information indicates that the cloud host has the permission to use the image file, and the permission information includes a permission size or a permission range of the cloud host when using the image file.

10. The apparatus of claim 9, wherein, The plaintext corresponding to the encrypted information includes the permission information and a timestamp of the server.

11. The apparatus of claim 9 or 10, wherein, The plaintext corresponding to the encrypted information further includes a next time of the cloud host for performing the verification.

12. The apparatus of claim 9, wherein, The starting module is further configured to: If the cloud host locally exists the same information as the encrypted information, the starting module is configured to refuse to start the image file.

13. The apparatus of claim 9, wherein, The sending module is further configured to periodically send the verification request to the server after the starting module starts the image file.

14. A device for preventing theft of mirrored files, characterized in that, The apparatus includes: a receiving module configured to receive a verification request from a cloud host installed with an image file, and the verification request includes identification information of the cloud host; a determining module configured to determine permission information of the cloud host to the image file according to the identification information of the cloud host, and the permission information includes a permission size or a permission range of the cloud host when using the image file; an encrypting module configured to encrypt the permission information according to an encrypted key corresponding to the image file to obtain encrypted information, and the encrypted information is at least used for the cloud host to detect whether the cloud host locally exists the same information as the encrypted information; a sending module configured to send the encrypted information to the cloud host.

15. The apparatus of claim 14, wherein, The apparatus or a database corresponding to the apparatus pre-stores associated information of the image file and the cloud host.

16. The apparatus of claim 14 or 15, wherein, The encrypted keys corresponding to different types of image files are different.

17. A cloud host, comprising: The apparatus includes: a memory; a processor; and a computer program. The computer program is stored in the memory and is configured to be executed by the processor to implement the method in any one of claims 1-5. The apparatus includes:

18. A server, comprising: a memory; a processor; and a computer program. The computer program is stored in the memory and is configured to be executed by the processor to implement the method in any one of claims 6-8. The computer program is executed by the processor to implement the method in any one of claims 1-8. ​ 19. A computer readable storage medium having stored thereon a computer program, characterized in that, ​

Citation Information

Patent Citations

  • Root permission obtaining method and device, electronic equipment and storage medium

    CN109657448A

  • Software starting method, software authorization verification method, equipment and storage medium

    CN109684790A