Object control method and apparatus
Patent Information
- Application Number
- CN202110649813.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-06-10
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2041-06-10
AI Technical Summary
[0002]随着计算机技术的发展,计算机软件的种类越来越多,功能也越来越强大,当软件产品安装完成后,软件会在初始登录或者升级时,需要得到软件管理方的授权,基于此,对于绑定硬件信息的序列号的软件,在更换硬件时,需要重新拿到软件管理方的授权,才能继续使用,或者是在用户升级软件版本、续签有效期时,也需要软件管理方重新办法和部署授权信息,这种操作不仅存在时效性差,操作成本较高的问题,也会降低应用软件的服务质量
[0018] This specification provides an object control method according to one embodiment. Based on object information carried in a control request for a target object sent by a client, authorization information for the target object is generated. The target object is obtained based on the object information, and the target object and a first key from the authorization information are sent to the client. Upon successful verification of the first key by the client, the target object is run. A second key is generated based on the first key, and data control instructions are encrypted based on the second key. The encrypted data control instructions are used to control the target object. By binding the first key, the second key, and the authorization information, asymmetric key technology is used to run and control the target object. This allows for direct data control of the target object on the client based on the second key, without considering hardware information or redeployment of authorization, during software version upgrades or license renewals. This achieves the effect of authorizing software operations, improving the efficiency of authorization operations and reducing operating costs while ensuring the quality of software services.
Smart Images

Figure CN115470472B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to an object control method. One or more embodiments of this specification also relate to an object control device, a computing device, and a computer-readable storage medium. Background Technology
[0002] With the development of computer technology, computer software is becoming increasingly diverse and powerful. After a software product is installed, it requires authorization from the software administrator during initial login or upgrade. Consequently, for software with serial numbers bound to hardware information, authorization from the software administrator must be obtained again when the hardware is replaced in order to continue using it. Similarly, when users upgrade software versions or renew their licenses, the software administrator needs to re-issue and redeploy authorization information. This process not only suffers from poor timeliness and high operational costs but also reduces the service quality of application software. Summary of the Invention
[0003] In view of this, embodiments of this specification provide an object control method. One or more embodiments of this specification also relate to an object control device, a computing device, and a computer-readable storage medium to address technical deficiencies in the prior art.
[0004] According to a first aspect of the embodiments of this specification, an object control method is provided, comprising:
[0005] Based on the object information carried in the control request for the target object sent by the client, the authorization information of the target object is generated;
[0006] The target object is obtained based on the object information, and the target object and the first key in the authorization information are sent to the client.
[0007] Upon receiving a successful verification of the first key from the client, the target object is executed;
[0008] A second key is generated based on the first key, and the data control instructions are encrypted based on the second key. The target object is then controlled according to the encrypted data control instructions.
[0009] According to a second aspect of the embodiments of this specification, an object control device is provided, comprising:
[0010] The generation module is configured to generate authorization information for the target object based on the object information carried in the control request for the target object sent by the client.
[0011] The sending module is configured to obtain the target object based on the object information, and send the target object and the first key in the authorization information to the client;
[0012] The execution module is configured to run the target object upon receiving a successful verification of the first key from the client;
[0013] The control module is configured to generate a second key based on the first key, encrypt data control instructions based on the second key, and control the target object according to the encrypted data control instructions.
[0014] According to a third aspect of the embodiments of this specification, a computing device is provided, comprising:
[0015] Memory and processor;
[0016] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, wherein the processor executes the computer-executable instructions to implement the steps of the object control method.
[0017] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of any one of the object control methods described herein.
[0018] This specification provides an object control method according to one embodiment. Based on object information carried in a control request for a target object sent by a client, authorization information for the target object is generated. The target object is obtained based on the object information, and the target object and a first key from the authorization information are sent to the client. Upon successful verification of the first key by the client, the target object is run. A second key is generated based on the first key, and data control instructions are encrypted based on the second key. The encrypted data control instructions are used to control the target object. By binding the first key, the second key, and the authorization information, asymmetric key technology is used to run and control the target object. This allows for direct data control of the target object on the client based on the second key, without considering hardware information or redeployment of authorization, during software version upgrades or license renewals. This achieves the effect of authorizing software operations, improving the efficiency of authorization operations and reducing operating costs while ensuring the quality of software services. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the structure of an object control method provided in one embodiment of this specification;
[0020] Figure 2 This is a flowchart of an object control method provided in one embodiment of this specification;
[0021] Figure 3 This is a schematic diagram of the processing procedure of an object control method provided in one embodiment of this specification;
[0022] Figure 4 This is a flowchart illustrating the automatic construction of an application image of an object control method provided in one embodiment of this specification;
[0023] Figure 5 This is a flowchart illustrating the remote management of the client application software status of an object control method provided in one embodiment of this specification;
[0024] Figure 6 This is a flowchart illustrating the real-time verification of a software license file for an object control method provided in one embodiment of this specification.
[0025] Figure 7 This is a schematic diagram of the structure of an object control device provided in one embodiment of this specification;
[0026] Figure 8 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation
[0027] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0028] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0029] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."
[0030] First, the terms and concepts used in one or more embodiments of this specification will be explained.
[0031] Decision Engine: Features include personalized project scenario event management, visual orchestration of complex decisions, and rich feature variables and scenario recognition services.
[0032] Execution Engine: Real-time computing engine, a one-stop real-time rule and strategy computing platform.
[0033] Software protection: This involves using encryption-based techniques to prevent software from being cracked. Theoretically, given enough resources and time, all software protection technologies can be cracked. However, if a protection technology's security level is high enough that crackers have to pay a higher cost than purchasing the software itself, then that technology is successful and worth using.
[0034] Software licensing is an extension and development of the concept of software protection. The goal of software licensing is to ensure that software users use the software according to a purchased license, which includes details such as the number of copies installed, usage time, application scope, and functional modules.
[0035] Docker containers are open-source application container engines that allow developers to package their applications and dependencies into a portable container in a unified way, and then deploy it to any server with the Docker engine installed (including popular Linux machines and Windows machines), which can also achieve virtualization.
[0036] Management Agent: The core program for implementing application software copyright control in this application, referred to as Agent.
[0037] Customer identification code: A globally unique identifier field that distinguishes customers. Each customer ID is randomly assigned an identification code, which can be generated using algorithms such as UUID.
[0038] Product version definition: Configuration information designed to control the scope of application software used by customers (e.g., the maximum number of clients supported for a given application, the list of supported application functions). Users can purchase specific versions of the software as needed.
[0039] Application software license file: includes product version number and its version information (maximum number of clients, feature set) and product validity period (start time, end time).
[0040] Customer authorization definition: A valid purchase by a customer can identify a unique "authorization definition" for that customer.
[0041] Application image: Specifically refers to a Docker image built using a Dockerfile and the Docker build command. The image contains the management agent and the application runtime environment (such as JDK, Tomcat software, etc., which Java web applications depend on).
[0042] Customer-specific application image: This refers to an image built by downloading and writing "customer authorization definition" information (such as RSA public key information in the customer authorization definition) through instructions in the application image build script. This image has a unique binding relationship with the "customer authorization definition" generated by the user's purchase behavior.
[0043] Current application software licensing methods can protect licensed software in two ways: one is to generate a unique identifier based on server hardware information and bind the generated software license code (serial number) uniquely; the other is to encrypt and protect the licensed file based on a fixed RAS public and private key.
[0044] Based on this, the above solutions have several drawbacks. Firstly, if a user replaces the machine hardware, the application software will fail, requiring a new authorization code. Furthermore, because containers are isolated from the host machine, commonly used hardware information, such as MAC addresses and static IPs, cannot be obtained. Moreover, containers are often deployed in cloud environments, which can lead to container migration. Even if the CPU number is specified, it may change during the next verification, causing the authorization to expire and requiring a new authorization code. In other words, re-authorization is required when hardware is replaced, especially in containerized environments where hardware information is easily forged or altered after container migration, making software authorization more susceptible to expiration or cracking. Secondly, while fixed RAS public / private keys are easy to crack, they do not support dynamic updates for license renewal. When customers upgrade versions or renew software validity, they need to reapply for and configure authorization files, resulting in poor timeliness, high operational costs, and potential damage to customer application services.
[0045] The risk identification product allows for customized risk strategies through the "Decision Engine" module in the console, supported by two core backend application services: the Decision Engine application and the Execution Engine application. The object control method provided in this specification, based on data security compliance requirements, installs the "Execution Engine application" software in a user-trusted network domain (private cloud, hybrid cloud, self-built data center, etc.), supporting deployment and use in the customer's environment. Thus, the object control method provided in this specification effectively protects the Execution Engine application software through authorization.
[0046] It should be noted that the object control method provided in the embodiments of this specification can also be applied to cloud servers, and the client corresponding to the cloud server can be a cloud display. The cloud display does not have a CPU to perform complex data calculations; all data is stored in the cloud server. Correspondingly, in the object control method provided in this specification, the cloud server can also generate software authorization information and perform security verification of the software between the cloud server and the cloud display using a key, thereby enabling control of the software's operation in the cloud display according to data control instructions. For example, when a user is using a service at a resource service organization, the service personnel can use the software through a handheld cloud display. In this case, the cloud server corresponding to the handheld cloud display can verify the secure authorization of the software, thereby enabling the cloud server to effectively authorize and protect the application software in the handheld cloud display. The interaction process between the cloud server and the cloud display implementing the object control method is essentially the same as the interaction process between a regular server and a client implementing the object control method, differing only in the server and client devices themselves. The embodiments in this specification below use a regular server and client as an example to specifically describe the object control method process. The interaction process between the cloud server and the cloud display can be found in the specific interaction process of the following embodiments.
[0047] This specification provides an object control method, and also relates to an object control device, a computing device, and a computer-readable storage medium, which will be described in detail in the following embodiments.
[0048] Figure 1 A schematic diagram of an object control method provided according to an embodiment of this specification is shown.
[0049] Figure 1Part A is the server, and Part B is the client. When server A receives the object information carried in the control request for the target object (software) sent by client B, it generates the software's authorization information. Based on the object information, server A acquires the software and sends the software and the first key from the authorization information to client B. If client B successfully verifies the first key, the software can be run. At the same time, server A can generate a second key based on the first key, encrypt the data control commands based on the second key, and control the software according to the encrypted data control commands.
[0050] The object control method provided in the embodiments of this specification, based on the binding relationship between the first key, the second key and the authorization information, utilizes asymmetric key technology to securely verify client authentication and software authorization information. It can quickly achieve control of authorized software without relying on hardware in the operating environment.
[0051] See Figure 2 , Figure 2 A flowchart of an object control method provided in one embodiment of this specification is shown, which specifically includes the following steps.
[0052] It should be noted that the object control method provided in one embodiment of this specification is based on the asymmetric key technology of the first key and the second key, which enables the server to control or deploy application software authorization in real time. This can effectively avoid the cost and time-consuming issues of users having to change the authorization when upgrading software versions or extending the validity period of authorization. At the same time, the whole process does not require restarting the application, thus avoiding the impact on customer service. For specific steps, please refer to the detailed description of the following embodiment.
[0053] Step 202: Generate the authorization information for the target object based on the object information carried in the control request for the target object sent by the client.
[0054] The object information can be understood as the attribute information of the application software, such as the application software identifier, application software version, application software release date and other basic software attribute information. It should be noted that the application software identifier can be understood as the authorization serial number corresponding to the software. The server can determine the order and other information generated by a user's valid purchase behavior based on the software identifier information.
[0055] The authorization information of the target object can be understood as user identification code (bound to the user's purchase order and globally unique), authorized version of the application software, first key pair, start time of software use, and other user authorization definitions.
[0056] For example, the user authorization definition is as follows: User ID: 1-1-1-1; Product version ID: 1; Version name: Standard Edition; Maximum number of clients: 10; Function set: A, B; Customer identification code: *** (randomly generated by the system); RSA key pair (first key): *** (randomly generated by the system); Validity period: 1 year; Start time: 2021-03-08.
[0057] In practical applications, after receiving a control request for software from a client, the server can generate authorization information for the software based on the object information carried in the control request. The authorization information includes not only the user identification code, the authorized version of the application software, and the start time, but also the first key pair corresponding to the software. It should be noted that the first key pair is set by default by the server.
[0058] Step 204: Obtain the target object based on the object information, and send the target object and the first key in the authorization information to the client.
[0059] In practice, the server can obtain the target object based on the object information carried in the control request for the target object sent by the client. The target object can be understood as a software data packet. The server then sends the software data packet and the first key in the authorization information to the client.
[0060] In practical applications, the server can download software data packages from the software package management module or from the image repository in the image management module. The embodiments in this specification will not be described in detail here, but please refer to the detailed description of the next embodiment.
[0061] Step 206: Upon receiving a successful verification of the first key from the client, run the target object.
[0062] Specifically, after the server sends the target object and the first key from the authorization information to the client, the client can verify the received first key. Only if the verification is successful can the server run the target object to ensure the security of the software operation.
[0063] Furthermore, the client's verification process for the first key is completed through cooperation between the server and the client; specifically, successful client verification of the first key includes:
[0064] Send the public key of the first key to the client, and receive the identification code that the client encrypts based on the public key in the authorization information;
[0065] The identification code is decrypted using the private key of the first key. If the decrypted user identification code matches the pre-stored user identification code, the client is confirmed to have successfully verified the first key.
[0066] The user identification code can be understood as an identification code that distinguishes the user's identity. Each user will be randomly assigned an identification code, which can be generated using algorithms such as UUID (Universally Unique Identifier).
[0067] Specifically, to ensure the client verifies the validity of the first key, the server sends the public key of the first key to the client and receives the identification code that the client encrypts in the authorization information based on the public key. After receiving the encrypted identification code, the server decrypts the encrypted identification code using the private key of the first key, and then matches the decrypted user identification code with the pre-stored user identification code. If they match, the match is successful, and it can be determined that the client has successfully verified the first key.
[0068] In practical applications, it should first be noted that the first key pair can be divided into a public key and a private key. The client uses the public key to encrypt the user identification code sent by the server, generates a random factor, and uploads this random factor to the server. The server can decrypt the data using the private key in the first key pair and compare the decrypted user identification code with the pre-stored user identification code. The pre-stored user identification code can be in plaintext form. After the comparison and matching, the server can determine that the client has successfully verified the first key pair.
[0069] The object control method provided in the embodiments of this specification verifies the first key using the public and private keys of the first key, ensuring secure and smooth communication between the server and the client. It also facilitates the server to ensure that the software runs in a secure environment after confirming that the first key has been successfully verified.
[0070] During the execution of the target object, additional identification information needs to be added to enable server control over the software and enhance its security. Specifically, upon receiving successful verification of the first key from the client, the execution of the target object includes:
[0071] Upon receiving a successful verification of the first key from the client, the runtime code of the target object is sent to the client.
[0072] Receive the input code sent by the client, and if the input code is the same as the runtime code of the target object, run the target object.
[0073] The runtime code can be understood as the identification information of the software operation. This identification information can be entered into the configuration information by user input, or it can be packaged and transmitted to the client directly when transmitting software data packets to the client.
[0074] Specifically, when the server receives a successful verification of the first key from the client, it sends the execution code of the target object to the client. When the server receives the input code from the client, it compares the input code with the execution code sent to the client to determine whether the execution code and the input code are consistent. If they are consistent, the server can run the target object.
[0075] In practical applications, to further ensure the security of running the target object, the server needs to determine whether the client has received the execution code. If an unforeseen situation occurs before running the target object, the client may not receive the real execution code. If a malicious person randomly enters an execution code and sends it to the server, the server can compare the execution code sent by the malicious person with the real execution code and find that the input code is inconsistent with the execution code. As a result, the server will not run the target object.
[0076] The object control method provided in the embodiments of this specification enhances the security of software operation by adding identification information of the client running the software and enabling the server to control the operation of the software.
[0077] Step 208: Generate a second key based on the first key, encrypt the data control command based on the second key, and control the target object according to the encrypted data control command.
[0078] Data control commands can be understood as specific control commands issued by the server to the software running on the client, such as commands to start the software, stop the software, or pause the software.
[0079] Specifically, the server can randomly generate a second key based on the first key, encrypt the data control command based on the second key, and send the encrypted data control command to the client to achieve control over the target object on the client.
[0080] Furthermore, the server can establish an interface binding relationship with the client to achieve a communication connection with the client, thereby generating a second key; specifically, generating a second key based on the first key includes:
[0081] Receive an interface binding request sent by the client, wherein the interface binding request carries the client's first key;
[0082] If the first key of the client matches the first key of the authorization information, a communication connection is established with the client based on the binding interface, and a second key is generated for the client based on the first key.
[0083] The second key can be understood as a key pair of the same type as the first key, and may include a public key and a private key.
[0084] Specifically, in order to establish a connection between the client and the server, the client can send an interface binding request to the server. The interface binding request carries the client's first key. If the server successfully matches the received first key with the first key in the authorization information, the server can call the binding interface to establish a communication connection with the client. At the same time, the server can randomly generate a second key for the client based on the first key.
[0085] In practical applications, the server and the client need to call the API binding interface to complete the interface binding and obtain a random key pair, i.e., the second key pair. This allows the server to send control commands to the client based on the bound interface and process the control commands based on the generated second key pair.
[0086] The object control method provided in the embodiments of this specification implements interface binding between the server and the client to facilitate the establishment of a communication connection through the bound interface.
[0087] Furthermore, the server can encrypt data control commands based on a second key to control the client; specifically, encrypting data control commands based on the second key and controlling the target object according to the encrypted data control commands includes:
[0088] Send the private key of the second key to the client, encrypt the data control command based on the public key of the second key, and send the encrypted data control command to the client;
[0089] The client decrypts the encrypted data control command based on the private key of the second key, and executes the result of the data control command.
[0090] In practical applications, to ensure that the client can decrypt the encrypted data control commands, the server can send the private key of the second key to the client for subsequent decryption of the data control commands. The server can encrypt the data control commands based on the public key of the second key and send the encrypted data control commands to the client. The client can decrypt the encrypted data control commands based on the private key of the second key, execute the decrypted data control commands, and return the execution result to the server.
[0091] The object control method provided in the embodiments of this specification further ensures the security of server control over the client by encrypting data control commands.
[0092] After a communication connection is established between the server and the client, if an error occurs in the software running on the client, the reported information can be verified. Specifically, after encrypting the data control command based on the second key and controlling the target object according to the encrypted data control command, the process further includes:
[0093] Receive reporting information sent by the client, wherein the reporting information is information signed by the client based on the private key of the second key;
[0094] The reported information is verified using the public key of the second key. If the verification of the reported information is successful, the reported information is stored.
[0095] The reported information can be understood as error messages from the software, such as execution errors or network errors.
[0096] Specifically, after the client determines that a software error has occurred, it sends the error information, i.e., the reporting information, to the server. This reporting information can be information signed by the client using its private key (a second key). The server verifies the reporting information using the public key of the second key. If the verification is successful, the reporting information is stored. In practical applications, the server stores the reporting information so that it can be used to update or upgrade the software content, authorization information, etc. Verifying the reporting information ensures that the server receives the client's report, preventing malicious individuals from damaging it and affecting the security of the software.
[0097] The object control method provided in the embodiments of this specification verifies the reported information returned by the client and stores the verified reported information so that the software can be adjusted according to the reported information in the future, thereby ensuring the security of the software operating environment.
[0098] In another embodiment provided in this specification, the operation of the software can be controlled by the number of second keys corresponding to the software generated by the server; specifically, after encrypting the data control instructions based on the second key and controlling the target object according to the encrypted data control instructions, the method further includes:
[0099] Based on the number of the second key, the number of clients is determined. When the number of clients reaches the preset number of clients in the authorization information, the operation of the target object is controlled based on the binding interface.
[0100] Specifically, in order to control the number of clients of the software application, the server can first determine the number of clients based on the number of second keys. If it is determined that the number of clients running the software has reached the preset number of clients, the server can control the further operation of the software based on the binding interface.
[0101] In practical applications, the software's licensing information has a maximum number of clients. For example, if the version name is Standard Edition and the version ID is 1, the maximum number of clients is 10; if the version name is Professional Edition and the version ID is 2, the maximum number of clients is 100. For example, if the software version is Standard Edition, and the server has not yet reached the maximum number of clients (10) when it determines that the number of second keys is 9, the server can control the software to run normally on 9 clients based on the binding interface. If the server has reached the maximum number of clients (10) when it determines that the number of second keys is 11, the server can control the software on the first ten clients to run normally based on the binding interface, while controlling the software on the 11th client to stop running.
[0102] The object control method provided in this specification determines the number of clients running the software on the client by the number of second keys generated by the server. When the number of clients reaches the preset maximum number of clients, the software on the client can be further controlled based on the binding interface, so that the server can control the client.
[0103] Another embodiment of this specification provides an object control method that, in response to a software licensing request sent by a client, can issue corresponding control commands to the client to achieve control over the client; specifically, after encrypting the data control commands based on the second key and controlling the target object according to the encrypted data control commands, it further includes:
[0104] Receive the authorization request for the target object sent by the client, and determine the attribute information of the target object based on the user identification code carried in the authorization request;
[0105] Based on the attribute information of the target object and the target attribute information carried in the authorization request, a control command for the target object is generated. The control command is encrypted based on the second key, and the encrypted control command is returned to the client through the binding interface.
[0106] Among them, attribute information can be understood as the software version of the software running on the client, the number of users of the client, the usage period, and other information.
[0107] Among them, target attribute information can be understood as the attribute information of the user's target needs for the software. For example, the original software version is the standard version, but based on the user's needs, the target attribute information for the software is the professional version.
[0108] In practical applications, when a server receives a software license request from a client, it can determine the current attribute information of the software based on the user identification code carried in the software license request. This attribute information includes basic attributes such as the software version, maximum number of clients using the software, and license duration. The server can then match the current attribute information of the software with the target attribute information in the software license request to determine the operation content for further license of the software. This allows the server to generate control instructions for the software. The server then encrypts the control instructions based on a second key and returns the encrypted control instructions to the client through the binding interface.
[0109] For example, if the server determines that the current client's software has a maximum client count of 5, and upon receiving the user's target client count (i.e., a target maximum client count of 20), it can generate a control command to increase the number of clients, encrypt the control command, and send it to the client through the binding interface.
[0110] It should be noted that the server can periodically poll to obtain real-time authorization information for the software. By encrypting the authorization information or control commands, the server can verify the software authorization information in real time, such as verifying whether the software has reached the expiration date or whether it has implemented the target authorized functions.
[0111] The object control method provided in this specification compares the attribute information of the current software with the attribute information of the target software to generate control instructions for the software. At the same time, the control instructions are encrypted based on a second key and returned to the client. In this way, the current operation status of the software can be verified in real time, and the operation of the software can be controlled in a timely manner according to the needs.
[0112] Based on this, the embodiments of this specification provide a detailed description of the software licensing and protection process. It should be noted that the object control method provided in the embodiments of this specification is applied to a virtual application platform. The virtual application platform generates a mirror object control method based on the object control method and sends the mirror object control method to at least one server associated with the virtual application platform.
[0113] In practical applications, by creating application images in a virtual application platform, including managing agent instances and application runtime environments, the above-mentioned authorization and protection of application software can be deployed on the server. The object control method provided in this application is characterized by easy deployment, no dependence on runtime environment hardware, and high security, and is a general method for real-time control of application software authorization.
[0114] In summary, the object control method provided in this specification, through the binding relationship between the first key, the second key, and authorization information, utilizes asymmetric key technology to operate and control the target object. This enables data control of the target object on the client side directly based on the second key when performing authorization operations such as upgrading the software version or renewing the license, without considering hardware information or redeploying the authorization. This achieves the effect of authorizing software operations, not only improving the efficiency of authorization operations but also reducing operating costs while ensuring the quality of software services.
[0115] The following is in conjunction with the appendix Figure 3 Taking the object control method provided in this specification applied to a virtual application platform as an example, the object control method will be further explained. Figure 3 This specification shows a schematic diagram illustrating the processing flow of an object control method according to an embodiment of this specification.
[0116] It should be noted that the object control method provided in this embodiment is deployed in a virtual application platform. By utilizing Docker containers (an open-source application container engine), developers can deploy application software in the form of data packages in a unified manner in portable containers. Subsequently, it can be deployed to any server with the Docker engine installed (including Linux machines and Windows machines), and virtualization can also be achieved. The Agent software involved in the object control method provided in this application embodiment is developed using the Go language and needs to be deployed in the environment required by the customer. However, this application does not limit any development language for implementing this solution.
[0117] Appendix Figure 3 This is a schematic diagram of the software deployment in a server virtual container scenario. This embodiment provides a detailed description of the deployment module, in which... Figure 3It can be divided into two parts: the upper part is the service provider environment A, and the lower part is the customer environment B. In the service provider environment A, there are mainly authorization management modules, package management modules, image management modules, project center service modules, package download service modules, and image repository service modules, as well as project personnel and R&D personnel. In the customer environment B, there is mainly at least one server, which includes Docker instances and other application instances. The Docker instance includes an API caller, a main controller, a cache (memory), and an application controller-polling service.
[0118] In practical implementation, under service provider environment A, the authorization management module can include three functions: "customer authorization definition", "product version definition", and "customer dynamic authorization record". It provides an internal interface to the "project center service". The customer authorization definition can include customer ID, customer identification code, authorized version ID, RSA key pair (first key) and start time; the authorized version can include version ID, number of clients, validity period and function list; the customer dynamic authorization record includes customer identification code, public key ID (hash value), RSA key pair (second key) and online status. It should be noted that the dynamic authorization record can also store the software's most recent heartbeat record.
[0119] The package management module can read the corresponding source code from the application source code and Agent source code and send it to the compiler for compilation. The compiled application package or Agent is then uploaded to the package download service, thereby enabling the compilation, packaging and pushing of the application software program and Agent software program to the package download service (for use when deploying application instances of the management Agent). It also provides an internal interface to the "Project Center Service Module".
[0120] The image management module retrieves the public key information (first key) based on the customer ID, downloads the Agent application and application dependency packages to generate an image configuration (Dockerfile), and sends the built image to the image repository service. This enables the creation of a customer-specific Docker image based on the customer's purchased product version information and its push to the image repository service (for operations and maintenance personnel to deploy container instances). It also provides an internal interface to the "Project Center Service Module".
[0121] The Project Center Service Module may include an Application Management Module and a Control API Service Module. The Application Management Module manages the application status (startup, shutdown, restart) and monitors the application software (CPU, memory, IO). The Control API Service Module may include an Agent Registration Interface, a Dynamic Authorization File Acquisition Interface, a Heartbeat Reporting Interface, an Application Control Command Acquisition Interface, and a Command Execution Result Reporting Interface. It should be noted that the Application Management Module enables project personnel to remotely manage and monitor the status of customer instances, providing internal interfaces to the Project Center Service Module. The Control API Service Module exposes various interface services to the Control Agent via APIs, such as Agent Binding Interface, Dynamic Authorization Acquisition Interface, Heartbeat Upload Interface, Application Control Command Acquisition Interface, and Command Execution Result Reporting Interface.
[0122] Furthermore, the project center service module can control the construction of user-specific application images, enabling the generation of corresponding customer authorization definition information and the construction and delivery of user-specific application images based on customer purchase behavior. See [link to relevant documentation]. Figure 4 , Figure 4 The flowchart illustrating the automatic construction of an application image of an object control method provided in an embodiment of this specification is shown, specifically including the following steps.
[0123] Step 402: The customer selects the software version, generates order information, and sends it to the project center service on the server.
[0124] Step 404: The server's project center service calls "Authorization Management" to generate the corresponding "Customer Authorization Definition" information based on the order information.
[0125] Specifically, the customer authorization definition includes customer ID, customer identification code (randomly generated), software version number, start time, purchase duration, RSA public key pair (randomly generated), and dedicated application image storage path (default is empty).
[0126] Step 406: The server's project center service calls "image management" to build a customer-specific application image based on the "customer authorization definition" information.
[0127] Specifically, the dedicated image includes the customer's RSA public key (first key), management agent program, application runtime environment, and customer identification code. It is uploaded to the image repository according to the specified path, and the path of the customer's dedicated image is stored in the customer's authorization definition information.
[0128] The application image building method provided in this embodiment is for operation and maintenance personnel to deploy container instances and provides internal interfaces to the corresponding project center service modules.
[0129] Furthermore, project personnel can issue application management commands through the application management module to remotely control the software, enabling remote control of customer applications based on specific project needs, such as starting and stopping operations; see also Figure 5 , Figure 5 A flowchart illustrating the remote management of the client application software status of an object control method provided in an embodiment of this specification is shown, specifically including the following steps.
[0130] Step 502: The server management agent starts up and completes the dynamic verification of the software, and periodically pulls the latest application management instructions.
[0131] For details on the specific dynamic verification process, please refer to the detailed process of dynamic verification, which will not be elaborated on here.
[0132] Step 504: The server's application management module reads the highest priority application control instruction from the queue of instructions to be executed by listening.
[0133] Step 506: The server's application management module writes the instruction content to a temporary file and executes it, writes the execution result to the executed instruction queue, and deletes the temporary file.
[0134] Step 508: When the server's main controller module listens for a newly inserted control instruction execution result queue, calls the control API's report instruction execution result interface, and loops to obtain the next control instruction to be executed, it can continue to execute step 504 until there are no more control instructions to be executed in the instruction queue, at which point the loop process ends.
[0135] Specifically, the interface parameter verification algorithm works as follows: First, the corresponding private key is retrieved from "Customer Authorization Definition" based on CustomId. Then, the decrypted ParamsEncryped key is compared with the plaintext CustomId in Params. If they match, it is considered legitimate, and the process continues. Next, the customer dynamic authorization record is checked to see if there is a record of a corresponding Agent bound to and online for the current CustomId. If there is no binding record for the current CustomId or it is bound but not online, the process continues. Based on "Customer Authorization Definition," the total number of currently bound clients and the validity period are checked and found to be normal. If both are normal, the binding is returned as successful (and the online authorization binding record is updated). A randomly generated second key pair is returned for the Agent to use when calling other interfaces. Otherwise, the binding is returned as failed.
[0136] Non-binding Agent Interface Verification Algorithm: First, retrieve the corresponding dynamic public key from the "Customer Dynamic Authorization Record" based on the CustomId. Use the public key to sign the Params plaintext. Then, compare and verify the ParamsSigned. If the verification passes, continue execution; otherwise, return an error.
[0137] The specific process for remotely controlling the status of application software provided in this embodiment, as well as the interaction process between the server and the client, can be found in the embodiments provided in the above specification, and will not be elaborated further here.
[0138] Application management command format description, main fields: ActionId: command ID (globally unique), ActionName: command name, ActionScript: specific script content, Timeout: timeout period. ActionScript is a script program consisting of one or more shell commands, which the executor directly calls and checks for timeout. Example: The startTomcatApp command script logic might be, where http: / / xxx.tgz is a temporary URL. #! / bin / sh; wget http: / / xxx.tgz-Oapp.tgz; tar zxvf app.tgz-O / home / webapps; / bin / sh / user / local / tomcat / bin / startup.sh.
[0139] In addition, the Agent heartbeat detection control can periodically poll the time of the most recent heartbeat packet in the dynamic authorization record. The following heartbeat detection algorithm can be used to maintain the online status of the application. The heartbeat detection algorithm is: keepalive 5, which represents the heartbeat frequency, where 5 represents 2 seconds; 200ms represents 200 milliseconds; offlinetime 60, which represents the node offline time. If no heartbeat is received after 60 seconds, the client is considered offline. After the client goes offline, the dynamic key currently used by the Agent automatically becomes invalid, and the Agent needs to call the Agent binding interface again to obtain a new dynamic key (second key).
[0140] The software package download service module is based on the software package management module for open source software and other services. The image repository service module is also based on the images uploaded by the image management module for open source software or services. Project personnel are internal staff of the software service provider, responsible for managing customer authorization and customer application status. R&D personnel are internal staff of the software service provider, responsible for developing application software programs (application programs, agent programs) and creating software packages, as well as creating application Dockerk images, and can also submit code to the code repository service.
[0141] In specific implementation, under customer environment B, the API caller of the Agent instance in the Docker container instance on the server may include encapsulated call management API functions, signature / verification functions (encryption signature / decryption signature), and encryption / decryption functions; the main controller-polling task includes an Agent registration module, a dynamic authorization update module, a control command retrieval module, a command result reporting module, and a heartbeat reporting module; the cache area (memory) includes a built-in public key (first key), a dynamic private key (second key), authorized information ciphertext, a queue of commands to be executed, a queue of executed commands, and heartbeat packets; the application controller-polling task includes a control command execution module and a status acquisition module; the application instance (which can be in multiple forms) includes a JDK+TOMCAT+WAR package, a JDK+FatJar package, and a binary program; among them, the various modules in the Agent instance can cooperate and communicate with each other, and the application controller can control the application status or obtain monitoring data and send it to other application instances.
[0142] In addition, operations and maintenance personnel are the technical staff within the customer responsible for the operation and maintenance of this application. Their main responsibilities include setting up the system environment and installing and deploying applications.
[0143] It should be noted that the main controller is responsible for communication between the API caller and the management API service based on the open API, such as authorization verification and obtaining package addresses, real-time software authorization verification, and maintenance and management of the application instruction queue. The package download service can also pull packages from the Agent instance and enable application instructions to the control instruction execution module of the application controller. The image repository service can pull images and start Docker container instances.
[0144] As for the built-in public key (first key), each client has a unique first key (assigned by the server, recording the mapping relationship between the public key and the client identification code), and it depends on the binding agent interface. After encrypting the client identification code with the public key, the interface can be bound to the client based on the plaintext of the client identification code, and a dynamic private key (second key) is generated at the same time.
[0145] The dynamic private key (second key) is unique to each Agent instance and is used to decrypt authorization files. It can also be used to sign parameters outside of the Agent API binding.
[0146] The encrypted authorization information can include version number ***, start time ***, current network time *** (to prevent modification of local time), maximum number of application instances ***, and feature list ***.
[0147] The heartbeat packet includes system time, application instance status (starting, running, stopping, stopped), and application instance resource usage (including CPU, memory, IO, etc.).
[0148] The principle of the control instruction execution module in the application controller is to obtain a priority instruction to be executed from the cache, execute the instruction, write the result to the cache, read and execute the control instructions to be executed from the control application instruction queue, and obtain the application monitoring information (such as CPU, memory, IO, etc.) in real time.
[0149] It should be noted that the Agent's control command execution module verifies the customer's software license file in real time to achieve real-time verification of the customer's software license purchase. For details, please refer to [link / reference needed]. Figure 6 , Figure 6 The flowchart illustrating the real-time verification process of the software license file for the object control method provided in the embodiments of this specification is shown, which may specifically include the following steps.
[0150] Step 602: The server determines the user identification code based on the parameters specified by the operations and maintenance personnel and starts the container instance.
[0151] Specifically, the parameters set by the operations and maintenance personnel are the customer's dedicated application image address and environment variables.
[0152] Step 604: The container instance on the server executes the startup management agent process.
[0153] Specifically, container instances can be specified using the ENTRYPCINT command when building a Dockerfile.
[0154] Step 606: The main controller of the server container instance management agent determines whether the binding agent interface of the management API call was successful. If so, proceed to step 608; otherwise, proceed to step 616.
[0155] Specifically, the server needs to determine whether the interface is bound correctly and whether the software is started correctly. If the binding fails, it may be due to reasons such as an incorrect key or a sufficient number of clients causing the verification to fail.
[0156] Step 608: The server can cache the private key of the random second key returned by the interface.
[0157] Step 610: The server can periodically poll to obtain real-time software authorization encryption information.
[0158] Step 612: The server determines whether the authorization information has been successfully decrypted using the second private key. If yes, the verification is successful and step 614 is executed; otherwise, step 616 is executed.
[0159] Step 614: The server confirms that the software license file verification was successful.
[0160] Specifically, if decryption is successful, the authorization validity is marked as TRUE.
[0161] Step 616: The server determines that the software license file verification failed.
[0162] Specifically, if decryption fails, the authorization validity flag is set to non-TRUE.
[0163] The real-time verification process for software license files provided in this embodiment can determine the currently valid license information of the software. For example, if the software's usage time needs to be extended, the new license information after the extension period can be retrieved in real time, which can automatically extend the validity period.
[0164] Corresponding to the above method embodiments, this specification also provides embodiments of an object control device. Figure 7 A schematic diagram of an object control device according to one embodiment of this specification is shown. Figure 7 As shown, the device includes:
[0165] The generation module 702 is configured to generate authorization information for the target object based on the object information carried in the control request for the target object sent by the client.
[0166] The sending module 704 is configured to obtain the target object based on the object information and send the target object and the first key in the authorization information to the client.
[0167] The execution module 706 is configured to run the target object upon receiving a successful verification of the first key from the client.
[0168] The control module 708 is configured to generate a second key based on the first key, encrypt data control instructions based on the second key, and control the target object according to the encrypted data control instructions.
[0169] Optionally, the operation module 706 is further configured to:
[0170] The receiving module is configured to send the public key of the first key to the client and receive an identification code that is encrypted by the client based on the public key using the user identification code in the authorization information;
[0171] The matching module is configured to decrypt the identification code based on the private key of the first key, and if the decrypted user identification code matches the pre-stored user identification code, confirm that the client has successfully verified the first key.
[0172] Optionally, the control module 708 is further configured to:
[0173] The encryption module is configured to send the private key of the second key to the client, encrypt the data control command based on the public key of the second key, and send the encrypted data control command to the client.
[0174] The decryption module is configured to receive the encrypted data control command from the client based on the private key of the second key, decrypt the data control command, and execute the result of the data control command.
[0175] Optionally, the device further includes:
[0176] The information receiving module is configured to receive reporting information sent by the client, wherein the reporting information is information signed by the client based on the private key of the second key;
[0177] The verification module is configured to verify the reported information based on the public key of the second key, and store the reported information if the verification of the reported information is successful.
[0178] Optionally, the operation module 706 is further configured to:
[0179] The runtime code sending module is configured to send the runtime code of the target object to the client upon receiving successful verification of the first key from the client.
[0180] Receive the input code sent by the client, and if the input code is the same as the runtime code of the target object, run the target object.
[0181] Optionally, the control module 708 is further configured to:
[0182] Receive an interface binding request sent by the client, wherein the interface binding request carries the client's first key;
[0183] If the first key of the client matches the first key of the authorization information, a communication connection is established with the client based on the binding interface, and a second key is generated for the client based on the first key.
[0184] Optionally, the device further includes:
[0185] Based on the number of the second key, the number of clients is determined. When the number of clients reaches the preset number of clients in the authorization information, the operation of the target object is controlled based on the binding interface.
[0186] Optionally, the device further includes:
[0187] Receive the authorization request for the target object sent by the client, and determine the attribute information of the target object based on the user identification code carried in the authorization request;
[0188] Based on the attribute information of the target object and the target attribute information carried in the authorization request, a control command for the target object is generated. The control command is encrypted based on the second key, and the encrypted control command is returned to the client through the binding interface.
[0189] Optionally, the device further includes:
[0190] The object control device is applied to a virtual application platform, which generates a mirror object control device based on the object control device and sends the mirror object control device to at least one server associated with the virtual application platform.
[0191] The object control device provided in the embodiments of this specification, through the binding relationship between the first key, the second key and the authorization information, utilizes asymmetric key technology to operate and control the target object. When the target object upgrades its software version, renews its license, or performs other authorization operations, there is no need to consider hardware information or redeployment of the authorization. The device can directly control the target object on the client based on the second key to achieve the effect of authorizing software operations. This not only improves the efficiency of the authorization operation, but also reduces the operating cost while ensuring the quality of the software service.
[0192] The above is a schematic scheme of an object control device according to this embodiment. It should be noted that the technical solution of this object control device and the technical solution of the object control method described above belong to the same concept. For details not described in detail in the technical solution of the object control device, please refer to the description of the technical solution of the object control method described above.
[0193] Figure 8 A structural block diagram of a computing device 800 according to one embodiment of this specification is shown. The components of the computing device 800 include, but are not limited to, a memory 810 and a processor 820. The processor 820 is connected to the memory 810 via a bus 830, and a database 850 is used to store data.
[0194] The computing device 800 also includes an access device 840, which enables the computing device 800 to communicate via one or more networks 860. Examples of these networks include a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 840 may include one or more of any type of wired or wireless network interface (e.g., a Network Interface Card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) interface, a Wi-MAX interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.
[0195] In one embodiment of this specification, the above-described components of the computing device 800 and Figure 8 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 8 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0196] The computing device 800 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or PCs. The computing device 800 can also be a mobile or stationary server.
[0197] The processor 820 is configured to execute the following computer-executable instructions, wherein the processor executes the computer-executable instructions to implement the steps of the object control method.
[0198] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the object control method described above belong to the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the object control method described above.
[0199] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the object control method.
[0200] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the object control method described above belong to the same concept. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the object control method described above.
[0201] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0202] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.
[0203] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.
[0204] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0205] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. An object control method, comprising: Based on the object information carried in the control request for the target object sent by the client, the authorization information of the target object is generated, wherein the object information is software attribute information; The target object is obtained based on the object information, and the target object and the first key in the authorization information are sent to the client. Upon receiving a successful verification of the first key from the client, the target object is executed; A second key is generated based on the first key, and data control instructions are encrypted based on the second key. The target object is controlled according to the encrypted data control instructions. The online status of the client affects the validity of the second key, that is, the second key automatically expires after the client's offline period expires.
2. The object control method according to claim 1, wherein the client successfully verifies the first key, comprising: Send the public key of the first key to the client, and receive the identification code that the client encrypts based on the public key in the authorization information; The identification code is decrypted using the private key of the first key. If the decrypted user identification code matches the pre-stored user identification code, the client is confirmed to have successfully verified the first key.
3. The object control method according to claim 2, wherein encrypting the data control command based on the second key and controlling the target object according to the encrypted data control command includes: Send the private key of the second key to the client, encrypt the data control command based on the public key of the second key, and send the encrypted data control command to the client; The client decrypts the encrypted data control command based on the private key of the second key, and executes the result of the data control command.
4. The object control method according to claim 3, further comprising, after encrypting the data control command based on the second key and controlling the target object according to the encrypted data control command: Receive reporting information sent by the client, wherein the reporting information is information signed by the client based on the private key of the second key; The reported information is verified using the public key of the second key. If the verification of the reported information is successful, the reported information is stored.
5. The object control method according to claim 3, wherein running the target object upon receiving successful verification of the first key from the client includes: Upon receiving a successful verification of the first key from the client, the runtime code of the target object is sent to the client. Receive the input code sent by the client, and if the input code is the same as the runtime code of the target object, run the target object.
6. The object control method according to claim 5, wherein generating the second key based on the first key comprises: Receive an interface binding request sent by the client, wherein the interface binding request carries the client's first key; If the first key of the client matches the first key of the authorization information, a communication connection is established with the client based on the binding interface, and a second key is generated for the client based on the first key.
7. The object control method according to claim 6, further comprising, after encrypting the data control command based on the second key and controlling the target object according to the encrypted data control command: Based on the number of the second key, the number of clients is determined. When the number of clients reaches the preset number of clients in the authorization information, the operation of the target object is controlled based on the binding interface.
8. The object control method according to claim 6, further comprising, after encrypting the data control command based on the second key and controlling the target object according to the encrypted data control command: Receive the authorization request for the target object sent by the client, and determine the attribute information of the target object based on the user identification code carried in the authorization request; Based on the attribute information of the target object and the target attribute information carried in the authorization request, a control command for the target object is generated. The control command is encrypted based on the second key, and the encrypted control command is returned to the client through the binding interface.
9. The object control method according to claim 1, further comprising: The object control method of any one of claims 1-8 is applied to a virtual application platform, wherein the virtual application platform generates a mirror object control method based on the object control method and sends the mirror object control method to at least one server associated with the virtual application platform.
10. An object control device, comprising: The generation module is configured to generate authorization information for the target object based on the object information carried in the control request for the target object sent by the client, wherein the object information is software attribute information; The sending module is configured to obtain the target object based on the object information, and send the target object and the first key in the authorization information to the client; The execution module is configured to run the target object upon receiving a successful verification from the client using the first key; The control module is configured to generate a second key based on the first key, encrypt data control commands based on the second key, and control the target object according to the encrypted data control commands. The online status of the client affects the validity of the second key, that is, the second key automatically expires after the client's offline period expires.
11. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, wherein when the processor executes the computer-executable instructions, it implements the steps of the object control method according to any one of claims 1-9.
12. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the object control method according to any one of claims 1-9.
Citation Information
Patent Citations
Method for binding hardware information and secret keys in software copyright protection
CN103995991A
Authorization methods, authorization device and authorization systems of software
CN108062461A
Software authorization management method, server and system
CN108376211A