A control authority acquisition method and device based on a time type encryption lock

By introducing a time-based dongle control access method into the application, and leveraging the collaborative work of the loader software and the dongle, secure access control of the application is achieved, preventing unauthorized control operations and piracy, thereby enhancing application security and copyright protection.

CN114297613BActive Publication Date: 2025-11-11FEITIAN TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111657564.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-30
Publication Date
2025-11-11
Estimated Expiration
2041-12-30

AI Technical Summary

Technical Problem

In existing technologies, application permission control methods are easy to crack, lack security, and are difficult to effectively prevent unauthorized control operations.

Method used

A time-based dongle-based access control method is adopted. Through the collaborative work of the loader software and the dongle, encryption and decryption operations are performed using SM2 key pairs and SM4 symmetric keys to ensure that the application verifies the dongle before acquiring access control.

Benefits of technology

It improves application security, prevents piracy, enhances the effectiveness of copyright control, and ensures that different applications use different dongles to avoid cross-platform compatibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114297613B_ABST
    Figure CN114297613B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, in particular to a control permission acquisition method and device based on a time type encryption lock. The method comprises the following steps: determining whether an encryption lock in an application program is successfully started; when the encryption lock is successfully started, instructing the encryption lock to call a built-in first processing program to acquire a second random number; encrypting the acquired second random number according to a preset public key to obtain a corresponding public key encryption result; instructing the encryption lock to call a built-in second processing program to perform permission verification processing according to the public key encryption result to obtain a corresponding verification result; and when the verification result is permission authentication passing, obtaining a control permission for the application program based on the verification result. Through the introduction of the encryption lock, the verification processing based on the encryption lock needs to be performed before the control permission of the application program is acquired, and the application program can be effectively prevented from being used by pirates after being extracted, so that the effectiveness of the copyright control of the application program is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a method and apparatus for obtaining control permissions based on a time-based encryption lock. Background Technology

[0002] In existing technologies, for certain applications, anyone has the authority to perform corresponding control operations. However, to avoid the problem of anyone being able to arbitrarily control the application, a permission control instruction can be added to the application. This way, control over the application is only possible if the corresponding permission control instruction is verified, thus improving security. However, while adding a permission control instruction can prevent anyone from controlling the application, it is relatively simple and easy to crack. Therefore, how to implement more secure permission control for applications has become a pressing technical problem that needs to be solved. Summary of the Invention

[0003] This application provides a method and apparatus for obtaining control permissions based on a time-based encryption lock, so as to more securely control the permissions of applications.

[0004] In a first aspect, embodiments of the present invention provide a method for obtaining control permissions based on a time-based encryption lock. The application is developed by a software developer commissioned by a software publisher. The software publisher obtains an encryption lock from an encryption lock provider and initializes the encryption lock. The software developer integrates the initialized encryption lock into the application. After the software publisher releases the application and a user downloads the application using loader software, the method includes:

[0005] The loader software determines whether the dongle in the application has been successfully opened;

[0006] When the dongle is successfully opened, the loader software instructs the dongle to call the built-in first processing program to obtain a second random number;

[0007] The loader software encrypts the obtained second random number according to the preset public key to obtain the corresponding public key encryption result;

[0008] The loader software instructs the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result, and obtains the corresponding verification result.

[0009] When the verification result is that the permission authentication is successful, the loader software obtains control permissions for the application based on the verification result;

[0010] The first and second processing programs are written into the encryption lock by the software publisher during the initialization of the encryption lock.

[0011] Secondly, embodiments of the present invention provide a control permission acquisition device based on a time-based encryption lock, applied to an application containing an encryption lock, the device comprising:

[0012] The first determining module is used to determine whether the dongle in the application has been successfully opened;

[0013] The instruction acquisition module is used to instruct the encryption lock to call the built-in first processing program to obtain a second random number when the encryption lock is successfully opened;

[0014] The encryption module is used to encrypt the obtained second random number according to the preset public key to obtain the corresponding public key encryption result;

[0015] The verification module is used to instruct the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result, and obtain the corresponding verification result.

[0016] The permission acquisition module is used to obtain control permissions for the application based on the verification result when the verification result is that the permission authentication is successful.

[0017] Thirdly, embodiments of the present invention provide an electronic device, including: a processor and a memory;

[0018] The memory is used to store operation instructions;

[0019] The processor is used to execute the aforementioned method for obtaining control permissions based on a time-based encryption lock by invoking the operation instructions.

[0020] Fourthly, embodiments of the present invention provide a computer-readable storage medium for storing computer instructions, which, when executed on a computer, enable the computer to execute the aforementioned method for obtaining control permissions based on a time-based encryption lock.

[0021] By employing the above-described technical solution, the technical solution provided in this application has at least the following advantages:

[0022] In this application, by introducing a dongle, access control is performed on both the loader software and the application. This requires a dongle-based verification process before obtaining control permissions for the application, and effectively prevents the application from being extracted and used in a pirated manner, thus further improving the effectiveness of application copyright control. Attached Figure Description

[0023] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0024] Figure 1 A flowchart illustrating a method for obtaining control permissions based on a time-based encryption lock, as provided in this application;

[0025] Figure 2 A schematic diagram illustrating the specific processing flow of a possible implementation of a time-based encryption lock-based method for obtaining control permissions provided in this application;

[0026] Figure 3 A flowchart illustrating a specific example of a time-based encryption lock-based method for obtaining control permissions provided in this application;

[0027] Figure 4 A schematic diagram of a control access acquisition device based on a time-based encryption lock provided in this application;

[0028] Figure 5 A schematic diagram of the structure of an electronic device for obtaining control permissions based on a time-based encryption lock, as provided in this application. Detailed Implementation

[0029] This application proposes a method and apparatus for obtaining control permissions based on a time-based encryption lock. The specific implementation of this application will be described in detail below with reference to the accompanying drawings.

[0030] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings. The same or similar reference numerals are used throughout to denote the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0031] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this application means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.

[0032] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0033] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0034] like Figure 1 The diagram shown is a flowchart illustrating a time-based encryption key acquisition method provided in this application. The application is developed by a software developer commissioned by the software publisher. The software publisher obtains the encryption key from the encryption key provider and initializes it. The software developer integrates the initialized encryption key into the application. After the software publisher releases the application and the user downloads the application using the loader software, the method in this embodiment includes:

[0035] Step S101: The loader software determines whether the dongle in the application has been successfully opened;

[0036] Step S102: When the dongle is successfully opened, the loader software instructs the dongle to call the built-in first processing program to obtain the second random number.

[0037] Step S103: The loader software encrypts the second random number returned by the encryption lock according to the preset public key to obtain the corresponding public key encryption result;

[0038] In step S104, the loader software instructs the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result, and obtains the corresponding verification result.

[0039] In step S105, the loader software receives the verification result returned by the dongle; when the verification result is that the permission verification is successful, it obtains control permissions for the application.

[0040] In this application, the introduction of a dongle adds a layer of protection based on dongle verification for the application's access to control permissions. At the same time, by using SM2 key pairs and SM4 symmetric keys for encryption and decryption, the interoperability between different dongles is avoided, allowing different applications to use different dongles, thereby improving the security of the applications.

[0041] Based on the technical solution provided in this application, the following is a detailed explanation of the technical solution, such as... Figure 2 The diagram shows a specific processing flow of a possible implementation of the time-based encryption lock-based access control method provided in this application.

[0042] In this application, a software publisher intends to release a software (application) and requires a software developer to develop the software according to the publisher's needs. To increase the software's security and meet the requirements for access control, a security barrier—a dongle—is added to the software. The publisher purchases the dongle from the dongle provider, and the software developer integrates the dongle into the software to be released (the software to be released requires the dongle to be used).

[0043] For software developers, the process involves developing software based on the needs of the software publisher, integrating the dongle into the software, and conducting joint testing with the dongle provider to meet the publisher's access control requirements.

[0044] For dongle providers, they offer dongles, initialization tools, and access control solutions (loader software), which can be integrated with software developers, and they also sell dongles, initialization tools, and loader software to software distributors.

[0045] For software users, they are the end users of the software.

[0046] To better implement the technical solution in this application, the dongle provider also provides a loader software and an initialization tool, integrating the storage path of the software to be released into the loader software, and implementing the technical solution of this application through the loader software.

[0047] In the technical solution of this application, before the software to be released is officially used, the encryption dongle is initialized using an initialization tool, and after initialization, the encryption dongle is integrated into the software to be released (i.e., the encryption dongle is used in conjunction with the software to be released). After the software publisher releases the software, users can download the released software using the loader software.

[0048] Specifically, the software publisher uses an initialization tool to initialize the dongle. This involves first launching the dongle initialization tool, which generates a key pair and a first random number. Using the private key from the generated key pair, the tool selects the corresponding file path and writes the private key into the configured file package based on that file path. The first random number is then written into the first data file within the file package. Simultaneously, a key file is created within this file package to store specific bytes of the first random number. This file package also needs to configure the dongle's expiration time and the first and second processing programs used when downloading the application. After the file package configuration is complete, the file package path is selected, and the configured file package is used to initialize the dongle, ensuring that the dongle stores the configuration settings from the file package.

[0049] Before releasing software, the software publisher needs to encrypt the software in advance, that is, to encrypt specific bytes of data of the software to be released using the key file configured in the file package.

[0050] In one possible implementation of this application, after the software distributor initializes the dongle using an initialization tool, the loader software controls the application's permissions based on the initialized dongle. The aforementioned step S101 specifically includes the following step S201.

[0051] Step S201: The loader software starts and determines whether the dongle has been successfully opened. If yes, proceed to step S202; otherwise, the process ends.

[0052] In one possible implementation, the loader software attempts to activate the dongle in the application and determines whether the dongle is successfully opened. If it is successfully opened, step S202 is executed; otherwise, the process ends.

[0053] In one possible implementation of this application, the aforementioned step S102 specifically includes the following steps S202 to S203.

[0054] In step S202, the loader software instructs the dongle to generate a second random number.

[0055] In one possible implementation, the loader software instructs the dongle to call a built-in first processor, which generates a second random number and returns it via the dongle. The loader software then receives the second random number returned by the dongle.

[0056] The first processing procedure is written by the software publisher during the initialization of the encryption key, and it presets a first random number of 128 bytes. The length of this first random number matches (is the same as or an integer multiple of) the key length of the block cipher algorithm used by the first processing procedure; for example, the length of the first random number is 128 bytes. Furthermore, the software publisher uses different first random numbers to distinguish the first processing procedures for different software developers.

[0057] The loader software instructs the dongle to call the built-in first process to generate a second random number. Specifically, the loader software instructs the dongle to call the built-in first process. The first process uses the random number generator in the dongle to generate a random number with the same number of bits as the first random number and caches it. It performs a bitwise XOR operation between the first random number and the generated random number, and returns the XOR result as the second random number to the loader software, which also caches the second random number.

[0058] In step S203, the loader software receives the second random number returned by the encryption lock.

[0059] In one possible implementation of this application, the aforementioned step S103 specifically includes the following step S204.

[0060] In step S204, the loader software uses a preset public key to encrypt the second random number, obtaining the public key encryption result.

[0061] In one possible implementation, after receiving the second random number sent by the dongle, the loader software encrypts the second random number according to the public key in the preset key pair to obtain the corresponding public key encryption result; wherein, the public key is the public key in the key pair generated by the software publisher using the initialization tool when the dongle is initialized, and is written into the loader software source code by the dongle provider when the loader software is developed.

[0062] Furthermore, the key pair written by the software distributor is generated by an initialization tool controlled by the software distributor.

[0063] In one possible implementation of this application, the aforementioned step S104 specifically includes the following step S205.

[0064] In step S205, the loader software instructs the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result. If the permission verification is successful, step S206 is executed.

[0065] In one possible implementation, after the loader software obtains the public key encryption result, it instructs the encryption lock to call its built-in second processing program. The encryption lock uses the public key encryption result as input data to the second processing program for authorization verification. Specifically, the second processing program uses the private key preset in the encryption lock to decrypt the public key encryption result, and performs an XOR operation on the decryption result using a preset first random number to obtain the XOR result. The XOR result is then compared with the currently cached random number. If the two match, the authorization verification passes; otherwise, the authorization verification fails.

[0066] After the loader software permission verification is completed, clear the currently cached random numbers.

[0067] Optionally, when the second process is invoked by the dongle, the dongle checks whether the current time exceeds the pre-configured expiration time of the dongle's valid use according to the built-in timer. If it does, it means that the valid use period of the dongle has expired, and a failure notification message is returned directly to the loader software.

[0068] In one possible implementation of this application, the aforementioned step S105 specifically includes the following step S206.

[0069] In step S206, the loader software reads the ciphertext of the application, instructs the encryption key to call the built-in first processor to decrypt the ciphertext of the application, loads the successfully decrypted application into memory, runs the application, and ends.

[0070] The application's ciphertext is obtained by encrypting it using an initialized encryption dongle before the software is released. Specifically, the first processing program in the encryption dongle is invoked to encrypt the application; that is, the first processing program uses a built-in first random number as the key and the encryption function of the encryption dongle to encrypt the application, thus obtaining the application's ciphertext.

[0071] Alternatively, encrypting an application can be done by encrypting the entire application (binary code) or by encrypting a portion of the application's core content (such as data located in a specific area of ​​the binary code).

[0072] When the application runs, it requires the dongle to verify permissions. The dongle uses a built-in timer to check if the current time has exceeded the pre-configured expiration time. If it has, the dongle returns a notification message indicating that the permission verification failed; otherwise, it returns a notification message indicating that the permission verification passed. If the application receives a notification message indicating that the permission verification passed, it runs normally; otherwise, it stops running.

[0073] Based on the technical solution provided in this application, the following is a detailed explanation of the technical solution, such as... Figure 3 The diagram shown is a flowchart of a specific implementation of a time-based encryption lock-based control permission acquisition method provided in this application.

[0074] Step S301: The software distributor starts the initialization tool to generate an SM2 key pair and a first random number of 128 bytes.

[0075] Specifically, the software distributor first needs to perform initialization processing for the dongle, for which an initialization tool is launched, which generates an SM2 key pair and a first random number of 128 bytes.

[0076] In step S302, the software distributor writes the SM2 private key and the first random number of 128 bytes from the SM2 key pair into the configured file package.

[0077] Specifically, the software distributor selects the file path corresponding to the SM2 private key in the SM2 key pair generated by the initialization tool, and writes the SM2 private key into the configured file package according to the file path. Similarly, the aforementioned 128-byte first random number is written into the first data file of the file package. Within this configured file package, an SM4 key file is also created to store the first 16 bytes of the 128-byte first random number, the expiration time of the dongle's valid use, and the first processing program (random number processing program) and the second processing program (access control program) used during application upgrades, thus completing the configuration of the dongle's file package.

[0078] In step S303, the software publisher initializes the encryption key according to the configured file package.

[0079] Specifically, an empty dongle is inserted into the initialization tool, and the empty dongle is initialized according to the configured file package path.

[0080] In step S304, the software publisher sends the dongle to the software developer.

[0081] Specifically, after receiving the initialized encryption key, the software publisher sends it to the software developer.

[0082] In step S305, the software developer integrates the dongle into the application to be released.

[0083] In step S306, the software distributor uses the SM4 key file in the file package to encrypt the first 64 bytes of data of the application.

[0084] Specifically, after integrating the dongle into the application to be released, the software publisher encrypts the first 64 bytes of the application using the first 16 bytes of a first random number in the file package.

[0085] In step S307, the software publisher releases the encrypted application to be published.

[0086] Step S308: The loader software downloads the encrypted application to be released.

[0087] Specifically, after the software publisher releases the encrypted application, the loader software can be used to launch the application.

[0088] In step S309, the loader software confirms the opening of the encryption lock in the application.

[0089] In one possible implementation, when the loader software is preparing to launch the application, it first needs to open the dongle in the application and determine whether the dongle is successfully opened. If so, it executes step S310.

[0090] In step S310, the loader software instructs the dongle to call the built-in random number processing program.

[0091] In one possible implementation, the loader software instructs the dongle to call the random number processing program within the dongle, causing the random number processing program to generate a second random number of 128 bytes. The dongle writes the second random number of 128 bytes to a second data file, writes the second random number of 128 bytes to an input / output buffer, and then returns the second random number of 128 bytes to the loader software.

[0092] In step S311, the loader software receives a second random number of 128 bytes returned by the encryption lock.

[0093] In step S312, the loader software encrypts the second random number, which is 128 bytes long, to obtain the SM2 public key encryption result.

[0094] In one possible implementation, the loader software encrypts a 128-byte second random number using the SM2 public key from the SM2 key pair generated during initialization, thus obtaining the corresponding SM2 public key encryption result.

[0095] In step S313, the loader software instructs the dongle to call the built-in access control program based on the encryption result of the SM2 public key.

[0096] In one possible implementation, the loader software instructs the dongle to call a built-in access control program based on the SM2 public key encryption result, and the dongle inputs the SM2 public key encryption result as input data into the access control program.

[0097] Step S314: The encryption lock determines whether the current time is less than the pre-configured expiration time of the encryption lock's valid use. If so, proceed to step S315.

[0098] Specifically, the dongle obtains the current time and determines whether the current time is less than the previously configured expiration time of the dongle's valid use; if the current time is determined to be less than the previously configured expiration time, step S315 is executed; otherwise, a failure notification message is directly returned to the loader software.

[0099] Step S315: The encryption lock decrypts the encryption result of the SM2 public key to obtain a third random number of 128 bytes.

[0100] Specifically, the encryption lock decrypts the SM2 public key encryption result based on the pre-stored SM2 private key, and obtains a third random number of 128 bytes.

[0101] Step S316: The encryption lock performs an XOR operation on the third random number (128 bytes long) and the first random number (128 bytes long) stored to obtain the first operation result.

[0102] Specifically, the encryption lock reads a first random number of 128 bytes stored in the first data file, and performs an XOR operation between the first random number of 128 bytes and a third random number of 128 bytes to obtain the first operation result.

[0103] Step S317: The encryption lock performs an XOR operation on the stored first random number of 128 bytes and the second random number of 128 bytes to obtain the second operation result.

[0104] Specifically, the encryption lock reads the second data file again to obtain a second random number of 128 bytes. It then performs an XOR operation between the first random number of 128 bytes and the second random number of 128 bytes to obtain the second operation result.

[0105] Optionally, the order of steps S316 and S317 can be interchanged;

[0106] Step S318: The encryption lock compares the first operation result with the second operation result to obtain the corresponding XOR operation result.

[0107] Furthermore, the encryption lock compares the first operation result with the second operation result to obtain the corresponding XOR operation result.

[0108] Step S319: The encryption lock determines whether the XOR operation result is equal to the two. If so, proceed to step S320.

[0109] Specifically, the encryption lock determines whether the XOR operation result is equal to the two. If they are equal, the verification is successful and step S320 is executed; otherwise, a failure notification message is returned directly to the loader software.

[0110] In step S320, the encryption lock sends a notification message to the loader software indicating that the verification result was successful.

[0111] In step S321, the loader software obtains control of the application based on the successful verification result.

[0112] In step S322, the loader software decrypts the first 64 bytes of data of the application based on the obtained control permissions.

[0113] In one possible implementation, after the loader software gains control of the application, it calls the SM4 algorithm to decrypt the first 64 bytes of the application data using the first 16 bytes of a 128-byte random number in the SM4 key file stored in the dongle, thus obtaining the corresponding decryption result.

[0114] In step S323, the loader software triggers the application launch based on the decryption result.

[0115] In one possible implementation, when the application exits, it also includes:

[0116] In step S324, the loader software encrypts the aforementioned decryption result based on the application's exit.

[0117] In one possible implementation, after the loader software receives a notification message that the application has exited, it can also call the SM4 algorithm to encrypt the aforementioned decryption result using the first 16 bytes of the first random number of 128 bytes in the SM4 key file stored in the dongle, thus obtaining the first 64 bytes of encrypted application data.

[0118] In this application, the introduction of a dongle adds a layer of protection based on dongle verification for the application's access to control permissions. At the same time, by using SM2 key pairs and SM4 symmetric keys for encryption and decryption, the interoperability between different dongles is avoided, allowing different applications to use different dongles, thereby improving the security of the applications.

[0119] Based on the technical solution of the control permission acquisition method provided in this application, this application correspondingly provides a control permission acquisition device based on a time-based encryption lock. The application is developed by a software developer commissioned by the software publisher. The software publisher obtains the encryption lock from the encryption lock provider and initializes it. The software developer integrates the initialized encryption lock into the application. After the software publisher releases the application and the user downloads the application using the loader software, such as... Figure 4 As shown, the control access acquisition device 40 based on a time-type encryption lock of this application includes:

[0120] The first determining module 401 is used to determine whether the dongle in the application has been successfully opened;

[0121] The instruction acquisition module 402 is used to instruct the encryption lock to call the built-in first processing program to obtain a second random number when the encryption lock is successfully opened;

[0122] The encryption module 403 is used to encrypt the obtained second random number according to the preset public key to obtain the corresponding public key encryption result;

[0123] The verification module 404 is used to instruct the encryption lock to call the built-in second processing program to perform authorization verification based on the public key encryption result, and obtain the corresponding verification result.

[0124] The permission acquisition module 405 is used to obtain control permissions for the application based on the verification result when the verification result is successful.

[0125] In one possible implementation, the instruction acquisition module 402 is specifically used to instruct the encryption lock to call a built-in first processing program when the encryption lock is successfully opened. The first processing program generates a second random number and returns it through the encryption lock; and receives the second random number returned by the encryption lock.

[0126] In one possible implementation, the verification module 404 is specifically used to instruct the encryption lock to call its built-in second processing program. When the second processing program is called by the encryption lock, the encryption lock obtains the current time according to its built-in timer and determines whether the current time is less than the pre-configured expiration time of the encryption lock's valid use. When the current time is less than the pre-configured expiration time, the verification module 404 is further used to perform an XOR operation based on the public key encryption result to obtain the XOR operation result. When the XOR operation result meets the preset conditions, it is determined that the authorization verification of the public key encryption result is successful, and the corresponding verification result is obtained.

[0127] Furthermore, the verification module 404 is instructed to perform an XOR operation based on the public key encryption result to obtain the XOR operation result, including: reading a first data file to obtain a first random number stored in the first data file; decrypting the public key encryption result according to a pre-configured private key corresponding to the public key to obtain a third random number; performing an XOR operation between the first random number and the third random number to obtain a first operation result; reading a second data file to obtain a second random number stored in the second data file; performing an XOR operation between the first random number and the second random number to obtain a second operation result; and comparing the first operation result with the second operation result to obtain the corresponding XOR operation result.

[0128] In one possible implementation, after obtaining control permissions for the application based on the verification result, the apparatus of this embodiment further includes:

[0129] The startup module is used to trigger the launch of the application based on the obtained control permissions;

[0130] The waiting module is used to wait for notification messages that the application has exited.

[0131] In one possible implementation, the startup module is specifically used to call the first algorithm based on the obtained control permissions to decrypt specific byte data of the application and obtain the corresponding decryption result; and trigger the startup of the application based on the decryption result.

[0132] In one possible implementation, the apparatus of this embodiment may further include:

[0133] The decryption module is invoked when the waiting receiving module receives a notification message that the application has exited. The first algorithm is then invoked to encrypt the decryption result, resulting in encrypted specific byte data.

[0134] In this application, the introduction of a dongle adds a layer of protection based on dongle verification for the application's access to control permissions. At the same time, by using SM2 key pairs and SM4 symmetric keys for encryption and decryption, the interoperability between different dongles is avoided, allowing different applications to use different dongles, thereby improving the security of the applications.

[0135] The following is for reference. Figure 5 The diagram illustrates a structural schematic of an electronic device 500 suitable for implementing embodiments of this application. This electronic device may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0136] like Figure 5 As shown, the electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage device 508 into a random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of the electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0137] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0138] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined in the methods of the embodiments of this application.

[0139] It should be noted that the computer-readable medium described above in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying built-in computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0140] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0141] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: acquire at least two Internet Protocol (IP) addresses; send a node evaluation request including the at least two IP addresses to a node evaluation device, wherein the node evaluation device selects an IP address from the at least two IP addresses and returns it; receive the IP address returned by the node evaluation device; wherein the acquired IP address indicates an edge node in the content delivery network.

[0142] Alternatively, the aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: receive a node evaluation request including at least two Internet Protocol (IP) addresses; select an IP address from the at least two IP addresses; return the selected IP address; and embed the received IP address as indicating an edge node in the content delivery network.

[0143] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0144] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0145] The units described in the embodiments of this application can be implemented in software or hardware. The name of a unit is not necessarily a limitation on the unit itself; for example, the first acquisition unit can also be described as "a unit that acquires at least two Internet Protocol addresses".

[0146] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

[0147] The electronic device provided in this application is applicable to any embodiment of the above-described application launch method, and will not be described in detail here.

[0148] In this application, by introducing a dongle, access control is performed on both the loader software and the application. This requires a dongle-based verification process before obtaining control permissions for the application, and effectively prevents the application from being extracted and used in a pirated manner, thus further improving the effectiveness of application copyright control.

[0149] This application provides a computer-readable storage medium that stores a computer program that causes a computer to execute the application startup method shown in the above embodiments.

[0150] The computer-readable storage medium provided in this application is applicable to any embodiment of the Bluetooth device connection method described above, and will not be described in detail here.

[0151] In this application, the introduction of a dongle adds a layer of protection based on dongle verification for the application's access to control permissions. At the same time, by using SM2 key pairs and SM4 symmetric keys for encryption and decryption, the interoperability between different dongles is avoided, allowing different applications to use different dongles, thereby improving the security of the applications.

[0152] Those skilled in the art will understand that each block in these structural diagrams and / or block diagrams and / or flow diagrams, as well as combinations of blocks in these structural diagrams and / or block diagrams and / or flow diagrams, can be implemented using computer program instructions. Those skilled in the art will also understand that these computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing method for implementation, thereby enabling the processor of the computer or other programmable data processing method to execute the schemes specified in the blocks or multiple blocks of the structural diagrams and / or block diagrams and / or flow diagrams disclosed in this application.

[0153] Built-in, the various modules of the device in this application can be integrated into one unit or deployed separately. The above modules can be combined into one module or further divided into multiple sub-modules.

[0154] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application.

[0155] Those skilled in the art will understand that the modules in the apparatus of the embodiments can be distributed in the apparatus of the embodiments as described in the embodiments, or they can be located in one or more devices different from this embodiment with corresponding changes. The modules of the above embodiments can be combined into one module, or they can be further divided into multiple sub-modules.

[0156] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0157] The above-disclosed embodiments are merely a few specific examples of this application. However, this application is not limited thereto, and any variations that can be conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A method for obtaining control permissions based on a time-based encryption lock, characterized in that, The application is developed by a software developer commissioned by a software publisher. The software publisher obtains a dongle from a dongle provider and initializes the dongle. The software developer integrates the initialized dongle into the application. After the software publisher releases the application and a user downloads the application using loader software, the method includes: The loader software determines whether the dongle in the application has been successfully opened; When the dongle is successfully opened, the loader software instructs the dongle to call the built-in first processing program to obtain a second random number; The loader software encrypts the obtained second random number according to the preset public key to obtain the corresponding public key encryption result; The loader software instructs the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result, and obtains the corresponding verification result. When the verification result is that the permission authentication is successful, the loader software obtains control permissions for the application based on the verification result; The first and second processing programs are written into the encryption lock by the software publisher during the initialization of the encryption lock. The loader software instructs the encryption lock to call its built-in second processing program to perform authorization verification based on the public key encryption result, and obtains the corresponding verification result, including: The loader software instructs the dongle to call a built-in second process. When the dongle calls the second process, the dongle obtains the current time according to a built-in timer. The encryption lock determines whether the current time is less than the pre-configured expiration time for the valid use of the encryption lock; When the current time is less than the expiration time of the pre-configured valid use of the encryption lock, the loader software performs an XOR operation based on the public key encryption result to obtain the XOR operation result; When the XOR operation result meets the preset conditions, the loader software determines that the permission verification of the public key encryption result is successful and obtains the corresponding verification result; The loader software performs an XOR operation based on the public key encryption result to obtain the XOR result, including: The loader software reads the first data file and obtains the first random number stored in the first data file; The loader software decrypts the public key encryption result based on a pre-configured private key corresponding to the public key to obtain a third random number; The loader software performs an XOR operation on the first random number and the third random number to obtain the first operation result; The loader software reads the second data file and obtains a second random number stored in the second data file; The loader software performs an XOR operation between the first random number and the obtained second random number to obtain a second operation result; The loader software compares the first calculation result with the second calculation result to obtain the corresponding XOR operation result.

2. The method as described in claim 1, characterized in that, The loader software instructs the dongle to call a built-in first processor to obtain a second random number, including: The loader software instructs the dongle to call a built-in first processing program, which generates a second random number and returns it through the dongle. The loader software receives the second random number returned by the dongle.

3. The method as described in claim 1, characterized in that, After obtaining control permissions for the application based on the verification result, the process further includes: The loader software triggers the launch of the application based on the obtained control permissions; The loader software waits to receive a notification message that the application has exited.

4. The method as described in claim 3, characterized in that, The loader software triggers the launch of the application based on the obtained control permissions, including: The loader software, based on the obtained control permissions, calls the first algorithm to decrypt specific byte data of the application and obtain the corresponding decryption result; The loader software triggers the launch of the application based on the decryption result.

5. The method as described in claim 4, characterized in that, Also includes: When the loader software receives a notification message that the application has exited, the loader software calls the first algorithm to encrypt the decryption result, thereby obtaining encrypted specific byte data.

6. A control permission acquisition device based on a time-based encryption lock, applied to an application containing an encryption lock, characterized in that, The device includes: The first determining module is used to determine whether the dongle in the application has been successfully opened; The instruction acquisition module is used to instruct the encryption lock to call the built-in first processing program to obtain a second random number when the encryption lock is successfully opened; The encryption module is used to encrypt the obtained second random number according to the preset public key to obtain the corresponding public key encryption result; The verification module is used to instruct the encryption lock to call the built-in second processing program to perform permission verification based on the public key encryption result, and obtain the corresponding verification result. The permission acquisition module is used to obtain control permissions for the application based on the verification result when the verification result is that the permission authentication is successful. The instruction verification module is specifically used to instruct the encryption lock to call its built-in second processing program. When the second processing program is called by the encryption lock, the encryption lock obtains the current time according to its built-in timer and determines whether the current time is less than the pre-configured expiration time of the encryption lock's valid use. When the current time is less than the pre-configured expiration time, an XOR operation is performed based on the public key encryption result to obtain the XOR operation result. When the XOR operation result meets the preset conditions, the authorization verification of the public key encryption result is determined to be successful, and the corresponding verification result is obtained. The XOR operation performed on the public key encryption result in the instruction verification module to obtain the XOR operation result includes: reading a first data file to obtain a first random number stored in the first data file; decrypting the public key encryption result according to a pre-configured private key corresponding to the public key to obtain a third random number; performing an XOR operation on the first random number and the third random number to obtain a first operation result; reading a second data file to obtain a second random number stored in the second data file; performing an XOR operation on the first random number and the second random number to obtain a second operation result; and comparing the first operation result with the second operation result to obtain the corresponding XOR operation result.

7. An electronic device, characterized in that, include: Processor and memory; The memory is used to store operation instructions; The processor is configured to execute, by invoking the operation instructions, a control permission acquisition method based on any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store computer instructions, which, when executed on a computer, cause the computer to perform any one of the control permission acquisition methods based on a time-based encryption lock as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Identity authentication method and device

    CN106302354A

  • A user authority management method and system based on an encryption lock

    CN109885989A