Software authorization control method and device, electronic equipment and storage medium

By employing multiple encryption processes to generate access and activation keys, software licensing control in offline mode is achieved, solving the challenges of software licensing control in private clouds, ensuring that software runs on the licensing server, preventing unauthorized expansion, and enhancing security and legitimacy.

CN115495713BActive Publication Date: 2026-08-04BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING BAIDU NETCOM SCI & TECH CO LTD
Filing Date
2022-08-01
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In private cloud scenarios, existing technologies struggle to effectively control software licensing, prevent users from arbitrarily expanding software capacity, and pose security risks.

Method used

By employing multiple encryption processes to generate access and activation keys, software licensing control is achieved in offline mode, ensuring that the software runs only on the licensing server and that activation verification and licensing control are performed based on the licensing information.

Benefits of technology

It effectively regulates user behavior, prevents arbitrary software installation and expansion, ensures the legality and security of the software, and is suitable for various scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115495713B_ABST
    Figure CN115495713B_ABST
Patent Text Reader

Abstract

This disclosure provides a software authorization control method, apparatus, electronic device, and storage medium, relating to artificial intelligence fields such as cloud computing, cloud storage, cloud networking, and cloud security, and applicable to intelligent cloud scenarios. The method may include: in response to determining that the software to be controlled is installed on a user's server, generating a first access key based on an authorization verification file corresponding to the software to be controlled; obtaining a first activation key generated by the software provider, the first activation key being generated based on the first access key and the authorization verification file; performing activation verification on the software to be controlled based on the first activation key; in response to determining that the verification is successful, activating the software to be controlled, and performing authorization control on the software to be controlled based on the first activation key. Applying the scheme described in this disclosure can effectively achieve authorization control of the software to be controlled and effectively constrain user behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of artificial intelligence technology, and in particular to software licensing control methods, devices, electronic devices and storage media in the fields of cloud computing, cloud storage, cloud networks and cloud security. Background Technology

[0002] In a private cloud scenario, after the software provider delivers the software to the user, it needs to use certain methods to control the authorization, such as preventing the user from arbitrarily expanding the software. The user can refer to a channel (such as a distributor) or a specific customer. Summary of the Invention

[0003] This disclosure provides software licensing control methods, apparatus, electronic devices, and storage media.

[0004] A software licensing control method, comprising:

[0005] In response to determining that the software to be controlled is installed on the user's server, a first access key is generated based on the authorization verification file corresponding to the software to be controlled.

[0006] Obtain the first activation key generated by the software provider, wherein the first activation key is generated based on the first access key and the authorization verification file;

[0007] The software to be controlled is activated and verified according to the first activation key. In response to the verification being successful, the software to be controlled is activated and authorized control is performed on the software to be controlled according to the first activation key.

[0008] A software licensing control method, comprising:

[0009] Obtain the first access key corresponding to the software to be controlled. The first access key is generated by the authorization management software based on the authorization verification file corresponding to the software to be controlled after determining that the software to be controlled is installed on the user's server.

[0010] A first activation key is generated based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation.

[0011] A software licensing control device includes: a first generation module, a first acquisition module, and a control module;

[0012] The first generation module is configured to generate a first access key based on the authorization verification file corresponding to the software to be controlled in response to determining that the software to be controlled is installed on the user's server;

[0013] The first acquisition module is used to acquire a first activation key generated by the software provider, wherein the first activation key is generated based on the first access key and the authorization verification file;

[0014] The control module is configured to perform activation verification on the software to be controlled according to the first activation key, and in response to determining that the verification is successful, activate the software to be controlled and perform authorization control on the software to be controlled according to the first activation key.

[0015] A software licensing control device includes: a second acquisition module and a second generation module;

[0016] The second acquisition module is used to acquire the first access key corresponding to the software to be controlled. The first access key is generated by the authorization management software based on the authorization verification file corresponding to the software to be controlled after determining that the software to be controlled is installed on the user's server.

[0017] The second generation module is used to generate a first activation key based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation.

[0018] An electronic device, comprising:

[0019] At least one processor; and

[0020] A memory communicatively connected to the at least one processor; wherein,

[0021] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described above.

[0022] A non-transitory computer-readable storage medium storing computer instructions for causing a computer to perform the methods described above.

[0023] A computer program product includes a computer program / instructions that, when executed by a processor, implement the method described above.

[0024] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0025] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0026] Figure 1 This is a flowchart of the first embodiment of the software licensing control method described in this disclosure;

[0027] Figure 2 This is a flowchart of the second embodiment of the software licensing control method described in this disclosure;

[0028] Figure 3 This diagram illustrates the relationship between the software provider, deployment personnel, authorization management software, and the software to be controlled as described in this disclosure.

[0029] Figure 4 This is a schematic diagram of the composition structure of the first embodiment 400 of the software licensing control device described in this disclosure;

[0030] Figure 5 This is a schematic diagram of the composition structure of the second embodiment 500 of the software licensing control device described in this disclosure;

[0031] Figure 6 A schematic block diagram of an electronic device 600 that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation

[0032] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0033] Furthermore, it should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0034] Figure 1 This is a flowchart of the first embodiment of the software licensing control method described in this disclosure. Figure 1 As shown, the specific implementation methods are as follows.

[0035] In step 101, in response to determining that the software to be controlled is installed on the user's server, a first access key is generated based on the authorization verification file corresponding to the software to be controlled.

[0036] In step 102, the first activation key (SecretKey) generated by the software provider is obtained. The first activation key is generated based on the first access key and the authorization verification file.

[0037] In step 103, the software to be controlled is activated and verified according to the first activation key. In response to the verification being successful, the software to be controlled is activated and authorized control is performed on the software to be controlled according to the first activation key.

[0038] The above-described method embodiment proposes a software authorization control method in offline mode. It can activate and authorize the software to be controlled by means of the generated access key and activation key, thereby effectively constraining user behavior. Moreover, the implementation method is simple and has good applicability to various scenarios.

[0039] In practical applications, the software provider can send the software installation package of the software to be controlled, the corresponding license verification file, and the license management software to the user together. There are no restrictions on how this is sent. Accordingly, Figure 1 The execution entity in the illustrated embodiment can be license management software.

[0040] Based on the software installation package of the software to be controlled, the software to be controlled can be installed on the user's server. After that, the authorization management software can generate the first access key according to the authorization verification file corresponding to the software to be controlled.

[0041] In one embodiment of this disclosure, the machine fingerprint of the server can be obtained, and a second access key in plaintext can be generated based on the obtained machine fingerprint and the authorization verification file. The second access key can then be encrypted to obtain the required first access key.

[0042] There are no restrictions on how the machine fingerprint is obtained; for example, existing implementation methods can be used. Additionally, if multiple servers exist, the machine fingerprints of all servers can be obtained. Preferably, the obtained machine fingerprint can be converted into a hash value, thus obtaining the hash value of the machine fingerprint, and can be compressed to a predetermined size, such as 64 bits.

[0043] In one embodiment of this disclosure, authorization identifier (id) information can be obtained from an authorization verification file, and a second access key can be generated based on the obtained machine fingerprint and authorization identifier information. The second access key is in plaintext form. The authorization identifier information can be used by the software provider to authenticate the user before generating the first activation key. The machine fingerprint can be included in the generated first activation key for the activation verification.

[0044] In addition to the aforementioned authorization identifier information and machine fingerprint, in practical applications, the second access key may further include other information, such as the version information of the software to be controlled. The specific information included can be determined according to actual needs.

[0045] By using machine fingerprints and other methods, the software to be controlled can only run on authorized servers, preventing the software from being installed / deployed arbitrarily.

[0046] The first access key can be obtained by encrypting the second access key. In one embodiment of this disclosure, the second access key can be encrypted sequentially using the Advanced Encryption Standard (AES) key in the license management software corresponding to the software to be controlled and the AES key in the license verification file.

[0047] Multiple encryption keys can be pre-programmed into the license management software. For example, multiple AES-256 key fragments, each fragment consisting of 4 characters, can be pre-programmed. Eight fragments can be randomly selected to form an AES-256 key. Additionally, multiple public keys can be included, such as RSA-2048 public keys. RSA is an abbreviation for the names Rivest, Shamir, and Adleman.

[0048] In addition, the authorization verification file can be generated by the software provider and sent to the user along with the software installation package and the authorization management software. It may include the authorization identification information mentioned above, as well as the generation date of the authorization verification file, the RSA public key, and the AES key. The RSA public key and AES key may be for the user's exclusive use.

[0049] By performing multiple encryption processes, the security of the obtained first access key can be improved, such as preventing the leakage of sensitive information.

[0050] After obtaining the first access key, the deployment personnel can send it to the software provider. In a private cloud scenario, most servers are deployed on an internal network, meaning they cannot connect to the public network. Therefore, it is preferable for the deployment personnel to transmit various keys, such as the first access key, via instant messaging tools.

[0051] Accordingly, in one embodiment of this disclosure, after obtaining the first access key, the first access key can be encoded according to a predetermined base-76 encoding method based on the principle of easy readability.

[0052] Encoding makes it easier for deployment personnel to view and input keys, and can further enhance key security. In addition, it allows for the transmission of more information using keys of limited length.

[0053] For example, 76 human-readable characters can be extracted from the 255-bit American Standard Code for Information Interchange (ASCII). These 76 characters can be randomly shuffled and used to represent each digit in base 76. Correspondingly, the first access key can be converted to base 76, and then each digit in the conversion result can be represented by the corresponding character.

[0054] After providing the first access key to the software provider, the software provider can generate a first activation key based on the first access key and the authorization verification file, and can return the first activation key to the deployment personnel. The first activation key may include machine fingerprints and authorization information, such as authorized capacity, number of authorized nodes, authorization expiration time, and authorized functions.

[0055] For example, the deployment personnel can enter the first activation key on the corresponding interface. Accordingly, the software to be controlled can be activated and verified based on the first activation key. In response to the verification being successful, the software to be controlled can be activated and authorized for control based on the first activation key.

[0056] In one embodiment of this disclosure, a third activation key can be generated in the same manner as the software provider generates the first activation key. Then, the unauthorized information in the third activation key can be compared with the unauthorized information in the first activation key. If they match, the verification is considered successful. The third activation key can be in plaintext form.

[0057] Additionally, the authorization information in the generated third activation key can be empty. Non-authorized information refers to information other than the authorized information, such as machine fingerprints, and the specific information included can be determined according to actual needs.

[0058] The above process enables activation verification of the software to be controlled, thereby achieving software operation license control and ensuring the legality of the software.

[0059] In one embodiment of this disclosure, authorization control can be performed on the software to be controlled based on the authorization information in the first activation key. Specifically, in one embodiment of this disclosure, in response to determining that a user is performing any operation related to authorization, it can be determined whether the operation is allowed based on the authorization information. If the determination result is allowed, the user is allowed to perform the operation; otherwise, the user is denied the right to perform the operation.

[0060] For example, if a user wants to perform a cluster expansion operation, the system can determine whether the number of nodes after expansion exceeds the authorized number of nodes based on the authorization information. If it does not exceed the authorized number of nodes, the user can be allowed to perform the operation; otherwise, the user can be refused to perform the operation.

[0061] Through the above processing, effective management of the software to be controlled can be achieved based on the authorization information, and user behavior can be effectively constrained, such as preventing various unreasonable behaviors such as arbitrary expansion of the software to be controlled.

[0062] In one embodiment of this disclosure, registration information sent each time the software to be controlled is started can also be obtained. In response to determining that the registration is successful based on the registration information, the software to be controlled can be allowed to start; otherwise, the software to be controlled can be refused to start.

[0063] To prevent the software to be controlled from escaping the authorization management software, it can be required that the software register with the authorization management software every time it starts up, and it can only be allowed to start after successful registration.

[0064] In one embodiment of this disclosure, during the operation of the software to be controlled, it can be determined whether the authorization information has expired after a predetermined period of time. If the determination result is that it has not expired, the software to be controlled can be allowed to continue running; otherwise, the software to be controlled can be refused to continue running.

[0065] For example, the expiration time of the authorization can be used to determine whether the authorization has expired. In addition, the specific value of the predetermined duration can be determined according to actual needs, such as 10 minutes.

[0066] The above process prevents the software under control from continuing to run after its license expires, thus achieving more accurate license control.

[0067] In addition, in practical applications, to prevent the controlled software from failing to run due to some reason after the authorization management software malfunctions, if the controlled software cannot register when it starts, it can be allowed to run for a period of time, such as 10 days.

[0068] Figure 2 This is a flowchart of a second embodiment of the software licensing control method described in this disclosure. Figure 2 As shown, the specific implementation methods are as follows.

[0069] In step 201, the first access key corresponding to the software to be controlled is obtained. The first access key is generated by the authorization management software after determining that the software to be controlled is installed on the user's server, based on the authorization verification file corresponding to the software to be controlled.

[0070] In step 202, a first activation key is generated based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation.

[0071] The above-described method embodiment proposes a software authorization control method in offline mode. It can activate and authorize the software to be controlled by means of the generated access key and activation key, thereby effectively constraining user behavior. Moreover, the implementation method is simple and has good applicability to various scenarios.

[0072] In practical applications, Figure 2 The entity executing the embodiment shown may be a software provider.

[0073] In one embodiment of this disclosure, before obtaining the first access key corresponding to the software to be controlled, the software installation package, license management software, and license verification file of the software to be controlled can be sent to the user together.

[0074] Accordingly, users can install the software to be controlled based on the software installation package, and the license management software can be configured according to... Figure 1 The processing is performed in the manner described in the illustrated embodiment.

[0075] In one embodiment of this disclosure, when generating a first activation key based on a first access key and an authorization verification file, authorization identification information and a machine fingerprint from the first access key can be obtained. The machine fingerprint is the machine fingerprint of the server. In response to successful authentication of the user based on the authorization identification information, authorization information is generated. Based on the authorization information and the machine fingerprint, a second activation key in plaintext form is generated. The authorization information is used for the authorization control, and the machine fingerprint is used for the activation verification. Afterward, the second activation key can be encrypted to obtain the required first activation key.

[0076] As mentioned earlier, the first access key can be an encrypted key. After obtaining the first access key, it can be decrypted first, that is, decrypted according to the decryption method corresponding to the encryption method, so as to obtain the information carried in the first access key, such as authorization identification information and machine fingerprint.

[0077] Afterwards, user authentication can be performed based on the authorization identifier information. If the authorization identifier information is incorrect, an error message can be displayed. If it is correct, authorization information can be generated, which may include information such as authorization capacity, number of authorized nodes, authorization expiration time, and authorized functions.

[0078] Subsequently, based on the generated authorization information and the obtained machine fingerprint, a second activation key in plaintext can be generated. This second activation key can then be encrypted to obtain the required first activation key. The specific content included in the second activation key can be determined according to actual needs and is not limited to the aforementioned authorization information and machine fingerprint.

[0079] In one embodiment of this disclosure, the second activation key can be encrypted sequentially using the AES key in the authorization management software, the AES key in the authorization verification file, and the private key corresponding to the public key (such as the RSA public key) in the authorization verification file.

[0080] By performing multiple encryption processes, the security of the obtained first activation key can be improved, such as preventing the leakage of sensitive information.

[0081] In one embodiment of this disclosure, after obtaining the first activation key, the first activation key can be encoded according to a predetermined base-76 encoding method based on the principle of easy readability.

[0082] Encoding makes it easier for deployment personnel to view and input keys, and can further enhance key security. In addition, it allows for the transmission of more information using keys of limited length.

[0083] In practical applications, the first access key from the deployment personnel can be obtained. Correspondingly, the first activation key can be returned to the deployment personnel so that the subsequent authorization management software can perform activation verification of the software to be controlled and perform authorization control after activation based on the first activation key.

[0084] Figure 3 This diagram illustrates the relationship between the software provider, deployment personnel, authorization management software, and the software to be controlled as described in this disclosure.

[0085] After the control software is installed on the user's server, the authorization management software can obtain the server's machine fingerprint and generate a second access key in plaintext based on the obtained machine fingerprint and authorization verification file. The second access key can then be encrypted to obtain a first access key, which can be encoded in base-76 encoding. Furthermore, the encoded first access key can be sent to the software provider by the deployment personnel.

[0086] After obtaining the first access key, the software provider can decrypt it and generate a second activation key in plaintext based on the decrypted information and the authorization verification file. The second activation key can then be encrypted to obtain the first activation key, which can be encoded in base-76. Furthermore, the encoded first activation key can be returned by the deployment personnel. Correspondingly, after decryption, the deployment personnel can enter the first activation key on the corresponding interface.

[0087] The authorization management software can activate and verify the software to be controlled based on the first activation key obtained, and can activate the software to be controlled after the verification is successful, and then authorize and control the software to be controlled based on the first activation key.

[0088] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this disclosure. Secondly, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure. Furthermore, for parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0089] In summary, the solution described in the embodiments of this disclosure can effectively control user behavior, prevent the software to be controlled from being installed or expanded at will, and ensure the security of incoming and outgoing data. In addition, the implementation method is simple and has good applicability to various scenarios.

[0090] The above is an introduction to the method embodiments. The following describes the solution described in this disclosure further through device embodiments.

[0091] Figure 4 This is a schematic diagram of the structural composition of the first embodiment 400 of the software licensing control device described in this disclosure. Figure 4 As shown, it includes: a first generation module 401, a first acquisition module 402, and a control module 403.

[0092] The first generation module 401 is used to generate a first access key based on the authorization verification file corresponding to the software to be controlled in response to determining that the software to be controlled is installed on the user's server.

[0093] The first acquisition module 402 is used to acquire the first activation key generated by the software provider. The first activation key is generated based on the first access key and the authorization verification file.

[0094] The control module 403 is used to perform activation verification on the software to be controlled according to the first activation key, and in response to the verification being successful, activate the software to be controlled and perform authorization control on the software to be controlled according to the first activation key.

[0095] The above-described device embodiment proposes a software authorization control method in offline mode. It can activate and authorize the software to be controlled by means of the generated access key and activation key, thereby effectively constraining user behavior. Moreover, the implementation method is simple and has good applicability to various scenarios.

[0096] In one embodiment of this disclosure, the first generation module 401 can obtain the machine fingerprint of the server and generate a second access key in plaintext form based on the obtained machine fingerprint and the authorization verification file. The second access key can then be encrypted to obtain the required first access key.

[0097] In one embodiment of this disclosure, the first generation module 401 can obtain authorization identification information from the authorization verification file and generate a second access key based on the obtained machine fingerprint and authorization identification information. The second access key is in plaintext form. The authorization identification information can be used by the software provider to authenticate the user before generating the first activation key. The machine fingerprint can be included in the generated first activation key for the activation verification.

[0098] In addition to the aforementioned authorization identifier information and machine fingerprint, in practical applications, the second access key may further include other information, such as the version information of the software to be controlled. The specific information included can be determined according to actual needs.

[0099] The first access key can be obtained by encrypting the second access key. In one embodiment of this disclosure, the first generation module 401 can sequentially encrypt the second access key using the AES key in the authorization management software corresponding to the software to be controlled and the AES key in the authorization verification file.

[0100] After obtaining the first access key, the deployment personnel can send it to the software provider. In a private cloud scenario, most servers are deployed on an internal network, meaning they cannot connect to the public network. Therefore, it is preferable for the deployment personnel to transmit various keys, such as the first access key, via instant messaging tools.

[0101] Accordingly, in one embodiment of this disclosure, after obtaining the first access key, the first generation module 401 may also encode the first access key according to a predetermined base-76 encoding method based on the principle of easy readability.

[0102] After providing the first access key to the software provider, the software provider can generate a first activation key based on the first access key and the authorization verification file, and can return the first activation key to the deployment personnel. The first activation key may include machine fingerprints and authorization information, such as authorized capacity, number of authorized nodes, authorization expiration time, and authorized functions.

[0103] For example, the deployment personnel can enter the first activation key on the corresponding interface. Accordingly, the control module 403 can perform activation verification on the software to be controlled based on the first activation key. In response to the verification being successful, the software to be controlled can be activated, and the software to be controlled can be authorized and controlled based on the first activation key.

[0104] In one embodiment of this disclosure, the control module 403 can generate a third activation key in the same manner as the software provider generates the first activation key. Then, the unauthorized information in the third activation key can be compared with the unauthorized information in the first activation key. Upon determining that the two are consistent, the verification is deemed successful. The third activation key can be in plaintext form.

[0105] Additionally, the authorization information in the generated third activation key can be empty. Non-authorized information refers to information other than the authorized information, such as machine fingerprints, and the specific information included can be determined according to actual needs.

[0106] In one embodiment of this disclosure, the control module 403 can perform authorization control on the software to be controlled based on the authorization information in the first activation key. Specifically, in one embodiment of this disclosure, in response to determining that a user is performing any operation related to authorization, the control module can determine whether the operation is allowed based on the authorization information. If the determination result is allowed, the user can be allowed to perform the operation; otherwise, the user can be refused to perform the operation.

[0107] In one embodiment of this disclosure, the control module 403 may also obtain registration information sent each time the software to be controlled starts. In response to determining that the registration is successful based on the registration information, the control module 403 may allow the software to be controlled to start; otherwise, the control module 403 may refuse to allow the software to be controlled to start.

[0108] In one embodiment of this disclosure, during the operation of the software to be controlled, the control module 403 may determine whether the authorization information has expired after a predetermined period of time. If the determination result is that the authorization information has not expired, the software to be controlled may be allowed to continue running; otherwise, the software to be controlled may be refused to continue running.

[0109] Figure 5 This is a schematic diagram of the structural composition of the second embodiment 500 of the software licensing control device described in this disclosure. Figure 5 As shown, it includes: a second acquisition module 501 and a second generation module 502.

[0110] The second acquisition module 501 is used to acquire the first access key corresponding to the software to be controlled. The first access key is generated by the authorization management software after determining that the software to be controlled is installed on the user's server, based on the authorization verification file corresponding to the software to be controlled.

[0111] The second generation module 502 is used to generate a first activation key based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation.

[0112] The above-described device embodiment proposes a software authorization control method in offline mode. It can activate and authorize the software to be controlled by means of the generated access key and activation key, thereby effectively constraining user behavior. Moreover, the implementation method is simple and has good applicability to various scenarios.

[0113] In one embodiment of this disclosure, before obtaining the first access key corresponding to the software to be controlled, the second acquisition module 501 may send the software installation package, authorization management software, and authorization verification file of the software to be controlled to the user together.

[0114] In one embodiment of this disclosure, when the second generation module 502 generates the first activation key based on the first access key and the authorization verification file, it can obtain the authorization identifier information and machine fingerprint in the first access key. The machine fingerprint is the machine fingerprint of the server. In response to the successful authentication of the user based on the authorization identifier information, authorization information is generated. Based on the authorization information and the machine fingerprint, a second activation key in plaintext form is generated. The authorization information is used for the authorization control, and the machine fingerprint is used for the activation verification. Afterward, the second activation key can be encrypted to obtain the required first activation key.

[0115] As mentioned earlier, the first access key can be an encrypted key. After obtaining the first access key, it can be decrypted first, that is, decrypted according to the decryption method corresponding to the encryption method, so as to obtain the information carried in the first access key, such as authorization identification information and machine fingerprint.

[0116] Afterwards, user authentication can be performed based on the authorization identifier information. If the authorization identifier information is incorrect, an error message can be displayed. If it is correct, authorization information can be generated, which may include information such as authorization capacity, number of authorized nodes, authorization expiration time, and authorized functions.

[0117] Subsequently, based on the generated authorization information and the obtained machine fingerprint, a second activation key in plaintext can be generated. This second activation key can then be encrypted to obtain the required first activation key. The specific content included in the second activation key can be determined according to actual needs and is not limited to the aforementioned authorization information and machine fingerprint.

[0118] In one embodiment of this disclosure, the second generation module 502 may sequentially encrypt the second activation key using the AES key in the authorization management software, the AES key in the authorization verification file, and the private key corresponding to the public key (such as the RSA public key) in the authorization verification file.

[0119] In one embodiment of this disclosure, after obtaining the first activation key, the second generation module 502 can further encode the first activation key according to a predetermined base-76 encoding method based on the principle of easy readability.

[0120] Figure 4 and Figure 5 The specific workflow of the illustrated device embodiment can be found in the relevant descriptions in the foregoing method embodiments.

[0121] In summary, the solution described in the embodiments of this disclosure can effectively control user behavior, prevent the software to be controlled from being installed or expanded at will, and ensure the security of incoming and outgoing data. In addition, the implementation method is simple and has good applicability to various scenarios.

[0122] The solutions described in this disclosure can be applied to the field of artificial intelligence, particularly in areas such as cloud computing, cloud storage, cloud networks, and cloud security, and can be applied in intelligent cloud scenarios. Artificial intelligence is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It involves both hardware and software technologies. Artificial intelligence hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. Artificial intelligence software technologies mainly include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.

[0123] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0124] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0125] Figure 6A schematic block diagram of an electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0126] like Figure 6 As shown, device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 602 or a computer program loaded from storage unit 608 into random access memory (RAM) 603. RAM 603 may also store various programs and data required for the operation of device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.

[0127] Multiple components in device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of monitors, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0128] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as those described in this disclosure. For example, in some embodiments, the methods described in this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed on device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the methods described in this disclosure can be performed. Alternatively, in other embodiments, the computing unit 601 can be configured to perform the methods described in this disclosure by any other suitable means (e.g., by means of firmware).

[0129] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0130] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0131] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0132] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0133] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0134] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.

[0135] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0136] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A software licensing control method, comprising: In response to determining that the software to be controlled is installed on the user's server, a first access key is generated based on the authorization verification file corresponding to the software to be controlled. Obtain the first activation key generated by the software provider, wherein the first activation key is generated based on the first access key and the authorization verification file; The software to be controlled is activated and verified according to the first activation key. In response to the verification being successful, the software to be controlled is activated and authorized control is performed on the software to be controlled according to the first activation key, including: authorizing control on the software to be controlled according to the authorization information in the first activation key, wherein the authorization information includes authorized capacity, number of authorized nodes, authorization expiration time and authorized functions. It also includes: after generating the first access key, encoding the first access key according to a predetermined base-76 encoding method based on the principle of easy readability, including: taking 76 human-readable characters from the 255-bit information exchange standard code, randomly shuffling the 76 characters, and using them to represent each digit in base-76; for the first access key, converting it to base-76, and representing each digit in the conversion result with the corresponding character.

2. The method of claim 1, wherein, The step of generating the first access key based on the authorization verification file corresponding to the software to be controlled includes: Obtain the machine fingerprint of the server; Based on the machine fingerprint and the authorization verification file, a second access key in plaintext is generated; The second access key is encrypted to obtain the first access key.

3. The method of claim 2, wherein, The second access key, which generates plaintext form, includes: Obtain the authorization identifier information from the authorization verification file; The second access key is generated based on the machine fingerprint and the authorization identifier information. The authorization identifier information is used by the software provider to authenticate the user before generating the first activation key, and the machine fingerprint is used for the activation verification.

4. The method of claim 2, wherein, The encryption of the second access key includes: The second access key is encrypted sequentially using the Advanced Encryption Standard Key in the authorization management software corresponding to the software to be controlled and the Advanced Encryption Standard Key in the authorization verification file.

5. The method of claim 1, wherein, The activation verification of the software to be controlled based on the first activation key includes: Generate a third activation key in the same manner as the software provider in generating the first activation key; The unauthorized information in the third activation key is compared with the unauthorized information in the first activation key. In response to determining that the two are consistent, the verification is confirmed to be successful.

6. The method of claim 1, wherein, The step of authorizing and controlling the software to be controlled based on the authorization information in the first activation key includes: In response to determining that the user is performing any authorization-related operation, determine whether the operation is allowed based on the authorization information; If the result is deemed acceptable, the user is allowed to perform the operation; otherwise, the user is denied the right to perform the operation.

7. The method according to claim 1, further comprising: Obtain the registration information sent by the software to be controlled each time it starts; in response to determining that the registration is successful based on the registration information, allow the software to start; otherwise, refuse the software to start. And / or, during the operation of the software to be controlled, after a predetermined period of time, it is determined whether the authorization information has expired. In response to the determination result being that it has not expired, the software to be controlled is allowed to continue running; otherwise, the software to be controlled is refused to continue running.

8. A software licensing control method, comprising: Obtain the first access key corresponding to the software to be controlled. The first access key is generated by the authorization management software after determining that the software to be controlled is installed on the user's server, based on the authorization verification file corresponding to the software to be controlled. The first access key is encoded according to a predetermined base-76 encoding method based on the principle of easy reading. The encoded first access key is obtained by taking 76 human-readable characters from the 255-bit information exchange standard code, randomly shuffling the 76 characters to represent each digit in base-76, converting the first access key into base-76, and representing each digit in the conversion result with the corresponding character. A first activation key is generated based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation. The authorization control is the authorization control performed on the software to be controlled based on the authorization information in the first activation key. The authorization information includes authorization capacity, number of authorization nodes, authorization expiration time, and authorization functions.

9. The method according to claim 8, further comprising: Before obtaining the first access key corresponding to the software to be controlled, the software installation package of the software to be controlled, the authorization management software, and the authorization verification file are sent to the user together.

10. The method of claim 8 or 9, wherein, The step of generating the first activation key based on the first access key and the authorization verification file includes: Obtain the authorization identifier information and machine fingerprint from the first access key, wherein the machine fingerprint is the machine fingerprint of the server; In response to successful authentication of the user based on the authorization identifier information, the authorization information is generated; Based on the authorization information and the machine fingerprint, a second activation key in plaintext is generated, wherein the machine fingerprint is used for the activation verification. The second activation key is encrypted to obtain the first activation key.

11. The method of claim 10, wherein, The encryption of the second activation key includes: The second activation key is encrypted sequentially using the Advanced Encryption Standard (AES) key in the authorization management software, the AES key in the authorization verification file, and the private key corresponding to the public key in the authorization verification file.

12. The method of claim 10, further comprising: After obtaining the first activation key, the first activation key is encoded according to a predetermined base-76 encoding method based on the principle of easy readability.

13. A software authorization control device comprising: The module comprises a first generation module, a first acquisition module, and a control module; The first generation module is configured to generate a first access key based on the authorization verification file corresponding to the software to be controlled in response to determining that the software to be controlled is installed on the user's server; The first acquisition module is used to acquire a first activation key generated by the software provider, wherein the first activation key is generated based on the first access key and the authorization verification file; The control module is configured to perform activation verification on the software to be controlled according to the first activation key, and in response to determining that the verification is successful, activate the software to be controlled and perform authorization control on the software to be controlled according to the first activation key, including: performing authorization control on the software to be controlled according to the authorization information in the first activation key, wherein the authorization information includes authorization capacity, number of authorization nodes, authorization expiration time and authorization functions; The first generation module is further configured to, after generating the first access key, encode the first access key according to a predetermined base-76 encoding method based on the principle of easy readability, including: extracting 76 human-readable characters from the 255-bit information exchange standard code, randomly shuffling the extracted 76 characters, and using them to represent each digit in base-76; for the first access key, converting it to base-76, and representing each digit in the conversion result with the corresponding character.

14. The apparatus according to claim 13, wherein, The first generation module obtains the machine fingerprint of the server, generates a second access key in plaintext form based on the machine fingerprint and the authorization verification file, and encrypts the second access key to obtain the first access key.

15. The apparatus according to claim 14, wherein, The first generation module obtains authorization identifier information from the authorization verification file, and generates the second access key based on the machine fingerprint and the authorization identifier information. The authorization identifier information is used by the software provider to authenticate the user before generating the first activation key, and the machine fingerprint is used for the activation verification.

16. The apparatus according to claim 14, wherein, The first generation module sequentially uses the Advanced Encryption Standard Key in the authorization management software corresponding to the software to be controlled and the Advanced Encryption Standard Key in the authorization verification file to encrypt the second access key.

17. The apparatus according to claim 13, wherein, The control module generates a third activation key in the same way as the software provider generates the first activation key, compares the unauthorized information in the third activation key with the unauthorized information in the first activation key, and determines that the verification is successful in response to the determination that the two are consistent.

18. The apparatus according to claim 13, wherein, In response to determining that the user is performing any operation related to authorization, the control module determines whether the operation is allowed based on the authorization information. If the determination result is allowed, the control module allows the user to perform the operation; otherwise, it refuses the user from performing the operation.

19. The apparatus according to claim 13, wherein, The control module is further configured to acquire registration information sent by the software to be controlled each time it starts, and in response to determining that the registration is successful based on the registration information, allow the software to be controlled to start; otherwise, refuse the software to be controlled to start. And / or, the control module is further configured to, during the operation of the software to be controlled, determine whether the authorization information has expired after a predetermined period of time; in response to the determination result being that it has not expired, allow the software to be controlled to continue running; otherwise, refuse the software to be controlled to continue running.

20. A software licensing control device, comprising: The second acquisition module and the second generation module; The second acquisition module is used to acquire the first access key corresponding to the software to be controlled. The first access key is generated by the authorization management software after determining that the software to be controlled is installed on the user's server, based on the authorization verification file corresponding to the software to be controlled. The first access key is encoded according to a predetermined base-76 encoding method based on the principle of easy reading. The encoded first access key is obtained by taking 76 human-readable characters from the 255-bit information exchange standard code, randomly shuffling the 76 characters to represent each digit in base-76, converting the first access key into base-76, and representing each digit in the conversion result with the corresponding character. The second generation module is used to generate a first activation key based on the first access key and the authorization verification file. The first activation key is used by the authorization management software to perform activation verification on the software to be controlled and to perform authorization control after activation. The authorization control is the authorization control performed on the software to be controlled based on the authorization information in the first activation key. The authorization information includes authorization capacity, number of authorization nodes, authorization expiration time, and authorization functions.

21. The apparatus according to claim 20, wherein, The second acquisition module is further configured to send the software installation package of the software to be controlled, the authorization management software, and the authorization verification file to the user before acquiring the first access key corresponding to the software to be controlled.

22. The apparatus according to claim 20 or 21, wherein, The second generation module obtains the authorization identifier information and machine fingerprint from the first access key, wherein the machine fingerprint is the machine fingerprint of the server. In response to the successful authentication of the user based on the authorization identifier information, the authorization information is generated. Based on the authorization information and the machine fingerprint, a second activation key in plaintext form is generated. The machine fingerprint is used for the activation verification. The second activation key is encrypted to obtain the first activation key.

23. The apparatus according to claim 22, wherein, The second generation module sequentially uses the Advanced Encryption Standard Key in the authorization management software, the Advanced Encryption Standard Key in the authorization verification file, and the private key corresponding to the public key in the authorization verification file to encrypt the second activation key.

24. The apparatus according to claim 22, wherein, The second generation module is further configured to, after obtaining the first activation key, encode the first activation key according to a predetermined base-76 encoding method based on the principle of easy readability.

25. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-12.

26. A non-transitory computer readable storage medium having stored thereon computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-12.

27. A computer program product comprising a computer program / instructions that, when executed by a processor, implement the method of any one of claims 1-12.