License Authorization Management Method, System, Device, and Storage Medium

By generating and encrypting license information on the first server side, updating the interval time and storing it into the data storage side, combining the second server side to manage the number of authorizations and decryption processing, the vulnerability of license authorization management in the cluster is solved, the risk of illegal authorization is reduced, and effective software authorization management and network security are achieved.

CN115795409BActive Publication Date: 2025-07-22PING AN TECH (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210709820.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-22
Publication Date
2025-07-22
Estimated Expiration
2042-06-22

AI Technical Summary

Technical Problem

In the prior art, there are vulnerabilities and limitations in the management of license authorization in clusters, resulting in increased risks of illegal authorization. Especially in docker virtualization deployment and cluster deployment, software developers face economic losses.

Method used

The first server side is used to generate and encrypt license information, update the interval preset time and store it in the data storage side, set the validity period, and manage the number of authorizations and decrypt license information through the second server side, and use RSA encryption technology to increase the difficulty of cracking.

Benefits of technology

Effectively manage software authorization, reduce the risk of illegal authorization, ensure the synchronous management of the number of authorizations, reduce the losses of abuse of authorization to product developers, and improve network security and business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115795409B_ABST
    Figure CN115795409B_ABST
Patent Text Reader

Abstract

The present application provides a license authorization management method, system, device, and storage medium. The method includes: obtaining first license information, where the first license information is generated by the product development end through first encryption processing based on the authorization code generated by the first server end and the corresponding product authorization information, performing second encryption processing on the first license information at intervals of a first preset duration to obtain second license information carrying a corresponding first timestamp, storing the second license information in the data storage end, and setting the validity period of the corresponding second license information to a first effective duration, so that the data storage end removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset duration. The present application can effectively manage software authorization and reduce the risk of illegal authorization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a license authorization management method, system, device, and storage medium. Background Art

[0002] With the development of network technology, a large number of software applications have emerged. In order to ensure the right to use software, software developers need to authorize the corresponding purchasers. The prior art usually uses a license (i.e., software copyright license) to authorize the right to use corresponding software and hardware products for purchasers, so as to achieve effective license management.

[0003] Under the current high requirements for office security, each office machine as a client calling the backend server should also have license restrictions. However, the use of license authorization in the prior art has certain limitations for applications in docker virtualization deployment and cluster deployment. In a cluster scenario, each backend server records how many clients can call. If a customer builds multiple instances through split-brain after purchasing a service to illegally increase authorized clients, there will be a risk of increased authorization, enabling unauthorized clients exceeding the maximum authorized number to also obtain the software usage rights, which will cause certain economic losses to software developers. Summary of the Invention

[0004] In order to solve the technical problem that there are certain loopholes and limitations in software authorization management through license authorization in a cluster in the prior art, resulting in a relatively high risk of increased unauthorized authorization. This application provides a license authorization management method, system, device, and storage medium, whose main purpose is to effectively manage software authorization and reduce the risk of unauthorized authorization.

[0005] To achieve the above object, this application provides a license authorization management method, which is applied to a first server side. The method includes:

[0006] Obtain first license information, where the first license information is generated by the product development side through first encryption processing based on the authorization code generated by the first server side and the corresponding product authorization information;

[0007] Perform second encryption processing on the first license information every first preset time interval to obtain second license information carrying the corresponding first timestamp;

[0008] Store the second license information in the data storage end, and set the validity period of the corresponding second license information to the first effective duration, so that the data storage end removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset duration.

[0009] To achieve the above object, the present application also provides a license authorization management method, which is applied to the second server end. The method includes:

[0010] If a first license information acquisition request from the client is received, obtain the current remaining available authorization quantity according to the authorized data in the data storage end;

[0011] If the current remaining available authorization quantity is not less than the quantity threshold, obtain the current latest second license information;

[0012] Perform a first decryption on the current latest second license information to obtain the corresponding first timestamp;

[0013] If it is determined according to the first timestamp and the first current moment that the current latest second license information has not expired and become invalid, return the current latest second license information to the client, so that the client performs a second decryption on the current latest second license information to obtain the third license information, where the third license information includes the authorization code and the corresponding product authorization information, and the first license information is obtained by the product development end through a first encryption process on the third license information;

[0014] Update the authorized data in the data storage end.

[0015] To achieve the above object, the present application also provides a license authorization management system, which includes:

[0016] A first server end, which is used to obtain the first license information. The first license is generated by the product development end through a first encryption process according to the authorization code generated by the first server end and the corresponding product authorization information. Every first preset duration, perform a second encryption process on the first license information to obtain the second license information carrying the corresponding first timestamp, store the second license information in the data storage end, and set the validity period of the corresponding second license information to the first effective duration, so that the data storage end removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset duration;

[0017] A second server side, which is configured to, if receiving a first license information acquisition request from a client, acquire the current remaining available authorization quantity according to the authorized data in a data storage side; if the current remaining available authorization quantity is not less than a quantity threshold, acquire the current latest second license information, perform a first decryption on the current latest second license information to obtain a corresponding first timestamp; if it is determined according to the first timestamp and the first current moment that the current latest second license information has not expired and become invalid, return the current latest second license information to the client, so that the client performs a second decryption on the current latest second license information to obtain a third license information, where the third license information includes the authorization code and the corresponding product authorization information, the first license information is obtained by the product development side performing a first encryption process on the third license information, and update the authorized data in the data storage side.

[0018] To achieve the above object, the present application further provides a computer device, including a memory, a processor, and computer-readable instructions stored on the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the license authorization management method as described in any one of the foregoing are executed.

[0019] To achieve the above object, the present application further provides a computer-readable storage medium, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the processor is caused to execute the steps of the license authorization management method as described in any one of the foregoing.

[0020] For the license authorization management method, system, device, and storage medium proposed by the present application, the present application updates the second license information at an interval by adding a first server side and a data storage side, so that the second server of the second server side can share the second license information stored in the data storage side, realizing the synchronous management of the authorized client quantity. Setting an expiration date for the license information ensures to a certain extent the restricted use of the license information. The present application is also applicable to license authorization management in a cluster. By restricting the first server side to update the second license information every first preset time interval and performing a different encryption on the license information every time it is updated, the cracking difficulty of the encrypted content is increased, thereby breaking the loopholes and limitations existing in software authorization management through license authorization in the cluster, reducing the risk of illegal authorization increase, effectively managing software authorization, effectively restricting the product authorization behavior of the purchaser, and reducing the losses brought to the product developer by the abuse of authorization. Description of the Drawings

[0021] Figure 1 It is an application scenario diagram of the license authorization management method in an embodiment of the present application;

[0022] Figure 2 It is a schematic flowchart of the license authorization management method in an embodiment of the present application;

[0023] Figure 3 It is a schematic flowchart of the license authorization management method in another embodiment of the present application;

[0024] Figure 4 It is an internal structure block diagram of a computer device in an embodiment of the present application.

[0025] The realization of the purpose of the present application, functional features and advantages will be further described in conjunction with the embodiments with reference to the accompanying drawings. Detailed implementation manners

[0026] To make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0027] The license authorization management method provided by the present application can be applied to a license authorization management system such as Figure 1 The license authorization management system includes a first server 10, a second server 20 and a data storage 30;

[0028] The first server 10 is used to obtain the first license information. Among them, the first license information is generated by the product development side through the first encryption process based on the authorization code generated by the first server and the corresponding product authorization information. The first license information is secondarily encrypted every first preset time interval to obtain the second license information carrying the corresponding first timestamp, and the second license information is stored in the data storage 30, and the validity period of the corresponding second license information is set to the first effective duration, so that the data storage 30 removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset duration;

[0029] The second server side 20 is configured to, if receiving a first license information acquisition request from the client side 40, obtain the current remaining available authorization quantity according to the authorized data in the data storage side. If the current remaining available authorization quantity is not less than the quantity threshold, obtain the current latest second license information, perform a first decryption on the current latest second license information to obtain a corresponding first timestamp. If it is determined that the current latest second license information has not expired and become invalid according to the first timestamp and the first current moment, return the current latest second license information to the client side 40, so that the client side 40 performs a second decryption on the current latest second license information to obtain a third license information. Wherein, the third license information includes the authorization code and the corresponding product authorization information. The first license information is obtained by the product development side performing a first encryption process on the third license information, and update the authorized data in the data storage side.

[0030] Among them, the client side 40 can be but is not limited to various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices.

[0031] The first server side 10 and the second server side 20 form a cluster. The second server side 20 includes at least one second server, and the second server is the application server corresponding to the client side 40. Through the scheduling of load balancing, any client side 40 can communicate with one of the second servers in the second server side 20, and the second server provides corresponding services for the client side 40. The specific number of clients that can be authorized by the license is determined according to the actual purchased permissions.

[0032] Figure 2 It is a schematic flowchart of the license authorization management method in an embodiment of this application. Refer to Figure 2 , taking the application of this method in Figure 1 the first server side as an example for illustration. The license authorization management method includes the following steps S110 - S130.

[0033] S110: Obtain the first license information, where the first license information is generated by the product development side through a first encryption process based on the authorization code generated by the first server side and the corresponding product authorization information.

[0034] Specifically, the first license information is generated by the product development side. The product development side generates an encrypted string containing the product authorization information as the first license information through a first encryption based on the authorization code and the product authorization information of the product to be authorized.

[0035] The product authorization information includes, but is not limited to, the validity period of product use, the total number of licenses available for the client, the product authorization version (such as the professional version, trial version, or standard version).

[0036] The authorization code, i.e., the machine code, is a unique string generated by the first server based on the machine's hardware information.

[0037] S120: Perform a second encryption process on the first license information every first preset time interval to obtain the second license information carrying the corresponding first timestamp.

[0038] Specifically, the first server will perform a second encryption process on the first license information every first preset time interval to obtain the second license information carrying the corresponding first timestamp. Since the encryption moment, i.e., the first timestamp, is different for each second encryption process, the second license information is different each time.

[0039] The first timestamp is specifically the current timestamp at the encryption moment.

[0040] The second encryption process can specifically be to encrypt the first license information after adding the first timestamp and a random number (salt value). The first license information is fixed. By adding a timestamp random number (salting) to the first license information, since the content encrypted each time has no pattern, it can effectively prevent cracking.

[0041] Specifically, perform a second encryption process on licensestr + 2022040322.08 + random number to obtain the second license information. Here, licensestr is the first license information, 2022040322.08 is the first timestamp. The random number, i.e., the salt value, is randomly generated. Adding a random number can prevent crackers from grasping the pattern, ensuring the security of the license information and preventing the license information from being stolen or tampered with.

[0042] S130: Store the second license information in the data storage end and set the validity period of the corresponding second license information to the first effective duration, so that the data storage end removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset time interval.

[0043] Specifically, the first server will store the newly generated second license information in the data storage end each time. The data storage end can be a redis (Remote Dictionary Server) end, which is a key-value storage system. Specifically, the first server can overwrite the historically generated second license information in the data storage end with the newly generated second license information in a covering manner, and set the corresponding expiration period, i.e., the lifecycle, for the newly generated second license information. In this way, normally, only one version-unique second license information is stored in the data storage end at the same moment, which is convenient for reading.

[0044] The first server can also store the newly generated second license information in the data storage end in a non-covering manner, and the historically generated second license information originally existing in the data storage end will not be overwritten or cleared. To distinguish the second license information generated and stored at different times, a corresponding first timestamp or storage timestamp can be marked for each version of the second license information in the data storage end. This is convenient for external parties to read the newly generated second license information according to the first timestamp or storage timestamp.

[0045] Because after the second license information is stored in the data storage end, the data storage end will automatically clear the expired and invalid second license information after the cumulative storage duration exceeds the first effective duration. Therefore, to ensure that the data storage end always stores the second license information, it is necessary to ensure that the first effective duration is not less than the first preset duration to prevent the lack of the second license information in the data storage end due to an overly long first preset duration.

[0046] Generating new second license information and storing it in the data storage end every first preset duration is similar to signing in, which can enable the first server to serve a cluster as much as possible.

[0047] The first preset duration can be set to 6 hours, 8 hours, 10 hours, etc., without being limited to this.

[0048] The first effective duration can be 24 hours, 12 hours, etc., without being limited to this.

[0049] In addition, the second license information is stored in the data storage end. Therefore, the outside will directly read the second license information from the data storage end, which reduces the direct access and interaction with the first server end, and further reduces the access pressure on the first server end. At the same time, since the second license information stored in the data storage end is set with an expiration date, when the first server end experiences a downtime or an unexpected event, there is time reserved to recover the first server end, reducing the possibility of service interruption and ensuring the normal operation of the service.

[0050] In this embodiment, by adding a first server end and a data storage end to update the second license information at intervals, the second server of the second server end can share the second license information stored in the data storage end, realizing the synchronous management of the number of authorized clients. Setting an expiration date for the license information ensures to a certain extent the restricted use of the license information. This application is also applicable to license authorization management in a cluster. By restricting the first server end to update the second license information every first preset time interval and encrypting the license information differently each time it is updated, the difficulty of cracking the encrypted content is increased, thus breaking the loopholes and limitations existing in software authorization management through license authorization in a cluster, reducing the risk of illegal authorization increase, and effectively managing software authorization.

[0051] In one embodiment, before step S110, the method further includes:

[0052] If an authorization code acquisition request from the second server end is received, an authorization code is generated according to the obtained local hardware information;

[0053] The authorization code is returned to the second server end.

[0054] Specifically, after the first server end receives the authorization code acquisition request from the second server end, the first server end can generate an authorization code or a machine code according to the mac address and motherboard information of the first server end, or the first server end generates an authorization code or a machine code through calculation according to the motherboard number and the serial number of the CPU of the first server end. This application is not limited to this.

[0055] The first server end returns the authorization code to the second server end. The second server end is used to communicate with the outside and provide the authorization code to the product development end. This can ensure that the first server end does not directly communicate with the outside and ensure the network security of the first server end.

[0056] Among them, the second server end includes at least one second server, and a second server is determined through load balancing to send an authorization code acquisition request to the first server end and receive the authorization code returned by the first server end.

[0057] In one embodiment, the method further includes:

[0058] If a third license information acquisition request from the second server is received, perform a second encryption process on the first license information,

[0059] and return the obtained second license information carrying the corresponding first timestamp as the fourth license information to the second server;

[0060] Or,

[0061] If a third license information acquisition request from the second server is received, return the first license information as the fourth license information to the second server.

[0062] Specifically, if the second server fails to obtain the unexpired (within the validity period) second license information from the data storage end or the second license information obtained by the client from the second server has expired, the second server will directly send a third license information acquisition request to the first server.

[0063] In a specific embodiment, after receiving the third license information acquisition request, the first server re - encrypts the first license information to obtain the fourth license information and directly returns the fourth license information to the second server. The fourth license information is a type of second license information.

[0064] In another specific embodiment, there is no need to perform a second encryption process on the first license information, and the first license information is directly returned to the second server as the fourth license information, thus saving time cost. Therefore, after receiving the first license information returned by the second server, the client only needs to perform the third decryption corresponding to the first encryption process to obtain the third license information.

[0065] In the event of an emergency or server downtime, the first server may not be able to update the second license information in the data storage end in a timely manner, resulting in the expiration and invalidation of the second license information in the data storage end and being cleared. Or, the first valid duration of the data storage end is tampered with, resulting in the second license information that has expired and should have been cleared not being cleared. In this case, the second server cannot obtain the unexpired and valid second license information from the data storage end. Or, due to latency, the second license information received by the client has expired. In all these cases, the second server can directly access the first server to obtain the latest second license information in a timely manner.

[0066] In addition, the first server can also monitor whether there is a target process ID (i.e., process ID, abbreviated as pid) corresponding to the target process or whether there is a corresponding port occupation to determine whether the first server can normally execute the corresponding steps of the license authorization management method. If there is no target process ID (i.e., pid) corresponding to the target process or there is no corresponding port occupation, it indicates that the first server is down or there is other abnormality. The first server can send an exception warning message to the monitoring end in the form of a text message or an email, so that the operation personnel of the monitoring end can repair and restore the service function of the first server as soon as possible, and at the same time ensure that the first server can write the latest second license information to the data storage end as early as possible to prevent the second license information in the data storage end from expiring and becoming invalid before it can be updated.

[0067] In one embodiment, after performing second encryption processing on the first license information and using the obtained second license information carrying the corresponding first timestamp as the fourth license information, the method further includes:

[0068] Storing the fourth license information as the second license information in the data storage end and setting the valid period corresponding to the fourth license information as the second valid duration, so that the data storage end removes the fourth license information whose cumulative storage duration exceeds the second valid duration, where the second valid duration is not less than the first preset duration.

[0069] Specifically, in addition to updating the latest second license information to the data storage end every first preset duration, the first server will also store the fourth license information as the second license information in the data storage end after generating the fourth license information. This can also achieve the purpose of updating the second license information in the data storage end.

[0070] In one embodiment, the method further includes:

[0071] After the first server is started, monitor the number of target processes currently running;

[0072] If the number of target processes currently running exceeds one, retain the most recently started target process and close the other target processes.

[0073] Specifically, to prevent the first server from executing multiple instances on the machine, that is, to prevent the first server from restarting repeatedly, and further to prevent different instances from performing authorization in parallel, which may lead to the risk of increased authorization, this embodiment determines whether there are multiple target processes running simultaneously by monitoring the number of target processes currently running on the first server in real time or at regular intervals. Among them, the target process is the process started by the first server when executing the corresponding steps of the license authorization management method.

[0074] Each time the first server starts a new target process, it assigns a corresponding process ID to this target process. And the first server writes the process ID of the most recently started target process into a target file in a fixed directory to overwrite the previously stored target process ID. The first server determines how many target processes have been started currently and which target process corresponds to the target process ID in the current target file based on the target process ID in the current target file. In this way, when the number of started target processes exceeds one, the most recently started target process can be retained and the other target processes can be closed. By monitoring the number of target processes, it can be determined whether the first server has generated multiple instances or repeated starts. If multiple starts or multiple instances occur, the redundant target processes can be closed, which can prevent the first server from fraudulently authorizing clients exceeding the maximum authorized number to use the product to be authorized, reducing the risk of increased authorization.

[0075] More specifically, for example, Company A purchases a watermark backend service from Company B for use on the display screens of office computers, and a total of 1000 clients can be authorized. According to the existing technology, if Party A uses two backend servers as a cluster for load balancing, then Company A can make each backend server authorize 1000 clients through "split brain", so Company A can authorize a total of 2000 clients to provide services. This illegal authorization behavior of Company A increases the number of authorizations that can be granted, which will undoubtedly cause certain economic losses to Company B.

[0076] This embodiment monitors the number of target processes of the first server to prevent multi-instance operation of the first server, enabling the first server to serve a cluster and share a data storage end, making the actual authorized quantity recorded in the data storage end true. In addition, sharing a data storage end can prevent authorization data from being disordered and out of sync.

[0077] Both the first encryption and the second encryption of this application can adopt the RSA encryption technology. The RSA encryption technology is an encryption algorithm widely used in the field of computer security. Its principle is based on the fact that it is difficult to factorize after multiplying two large prime numbers. Each time a key pair is generated, which is divided into a public key (PK) and a private key (SK). The public key can be written in the Java backend code on the second server side. Since only the public key can be seen and it is impossible to deduce the private key based on the public key, and thus it cannot be cracked, the public key can be made public.

[0078] Both the first encryption and the second encryption have corresponding public keys and private keys.

[0079] The first server side can be developed using the C++ programming language. The private key for the second encryption process is stored in the C++ code on the first server side. Since C++ is relatively difficult to decompile while Java is relatively easy to decompile to obtain the private key, therefore, using the C++ programming language on the first server side can ensure a certain level of data security.

[0080] Figure 3 It is a schematic flowchart of the license authorization management method in an embodiment of this application. Refer to Figure 3 , taking the application of this method in Figure 1 the second server side as an example for illustration. The license authorization management method includes the following steps S210 - S250.

[0081] S210: If a first license information acquisition request from the client is received, then obtain the current remaining available authorization quantity according to the authorized data in the data storage end.

[0082] Specifically, the current remaining available authorization quantity can be obtained according to the difference between the total available authorization quantity and the current authorized quantity included in the authorized data in the data storage end. Each time a client is authorized, the authorized quantity increases and the remaining available authorization quantity decreases.

[0083] In another specific embodiment, a target list is provided in the data storage end. The target list stores the usage data of the authorized clients without repetition as the authorized data. The usage data of each authorized client occupies a part of the allowed writing length of the list. The allowed writing length of the list is determined by the total available authorization quantity of the client. Therefore, the more usage data of the authorized clients that has been written, the smaller the remaining writable length. The current remaining available authorization quantity can be judged through the remaining writable length. Among them, the usage data of the authorized clients includes data such as the machine number (the unique identifier of the client) of the authorized client, not limited to this.

[0084] The second server side includes multiple second servers. Through load balancing, the client can communicate with one of the second servers in the second server side. The second server for this communication provides corresponding services to the client, and the second server for this communication reads data from the data storage side or communicates with the first server in the first server side.

[0085] S220: If the current remaining number of licenses available for authorization is not less than the quantity threshold, obtain the current latest second license information.

[0086] Specifically, the quantity threshold can be values such as 0, 1, 2, etc., not limited to this. Only when the current remaining number of licenses available for authorization is not less than the quantity threshold can the second server side obtain the current latest second license information and provide it to the client for authorization; if the current remaining number of licenses available for authorization is less than the quantity threshold, the client cannot be authorized again, and the second server side cannot obtain the current latest second license information.

[0087] S230: Perform a first decryption on the current latest second license information to obtain the corresponding first timestamp.

[0088] Specifically, the second license information is obtained by performing a second encryption process on the first license information, and the first decryption is the inverse operation corresponding to the second encryption. Therefore, the first timestamp used when performing the second encryption process on the first license information can be obtained.

[0089] S240: If it is determined that the current latest second license information has not expired and become invalid according to the first timestamp and the first current moment, return the current latest second license information to the client, so that the client performs a second decryption on the current latest second license information to obtain the third license information. The third license information includes the authorization code and the corresponding product authorization information, and the first license information is obtained by the product development side performing a first encryption process on the third license information.

[0090] Specifically, if the time duration between the first current moment and the first timestamp does not exceed the first effective duration, it means that the current latest second license information has not expired and become invalid, and the second server side will return the current latest second license information to the client.

[0091] The client performs a second decryption on the current latest second license information to obtain the third license information. Among them, the second decryption includes a first decryption corresponding to the second encryption and a third decryption corresponding to the first encryption. Specifically, the client first performs a first decryption on the current latest second license information to obtain the first license information, and then performs a third decryption on the first license information to obtain the third license information. The third license information includes the authorization code generated by the first server and the product authorization information corresponding to the product to be authorized.

[0092] S250: Update the authorized quantity in the data storage end.

[0093] Specifically, after the second server returns the current latest second license information to the client, it is equivalent to authorizing the client. At this time, it is necessary to synchronously update the authorized quantity in the data storage end.

[0094] In this embodiment, the second server reduces the frequent access to the first server and the access pressure by obtaining the latest second license information from the data storage end. The second server in the second server shares the authorized data and the second license information in the data storage end to achieve data synchronization. Since the second license information in the data storage end is updated at intervals, and each second license information is encrypted with a timestamp, the difficulty of cracking the encrypted content is increased, the risk of the license information being tampered with or stolen is reduced, the authorized quantity of the license for the client is updated in a timely manner, ensuring that the actual authorized quantity does not exceed the maximum authorized quantity, and the license information and license authorization are effectively managed.

[0095] In one embodiment, before step S210, the method further includes:

[0096] Send an authorization code acquisition request to the first server;

[0097] After receiving the authorization code returned by the first server, send a second license information acquisition request to the product development end, where the second license information acquisition request carries the authorization code and the product information of the product to be authorized;

[0098] Provide the received first license information returned by the product development end to the first server;

[0099] Perform a third decryption on the first license information, store the total authorized quantity of the product to be authorized obtained into the data storage end, and initialize the authorized data in the data storage end.

[0100] Specifically, if the second server receives an authorization code acquisition instruction sent by the management end, it generates an authorization code acquisition request and sends it to the first server.

[0101] After receiving the authorization code acquisition request, the first server generates an authorization code based on the local hardware information and returns it to the second server. The second server generates a second license information acquisition request based on the authorization code and sends the second license information acquisition request to the product development end.

[0102] The second license information acquisition request carries the authorization code and the product information of the product to be authorized. The product development end obtains the identity information of the second server according to the authorization code acquisition instruction, then obtains the corresponding product authorization information according to the identity information of the second server and the product information, and generates the first license information through the first encryption process for the product authorization information and the authorization code, and returns the first license information to the second server.

[0103] The second server provides the first license information to the first server.

[0104] The second server also performs the third decryption on the first license information to obtain the product authorization information, and stores the total number of licenses that can be authorized in the product authorization information in the data storage end.

[0105] In one embodiment, the method further includes:

[0106] If it is determined that the current latest second license information has expired and become invalid according to the first timestamp and the first current moment, a third license information acquisition request is sent to the first server;

[0107] Perform the first decryption on the fourth license information returned by the first server, and use the obtained corresponding first timestamp as the second timestamp, where the fourth license information is returned by the first server according to the third license information acquisition request;

[0108] If it is determined that the fourth license information has not expired and become invalid according to the second timestamp and the second current moment, the fourth license information is returned to the client, so that the client performs the second decryption on the fourth license information to obtain the third license information,

[0109] Or,

[0110] Return the fourth license information returned by the first server to the client, so that the client performs the third decryption on the fourth license information to obtain the third license information.

[0111] Specifically, if the duration between the first current moment and the first timestamp exceeds the first valid duration, it indicates that the current latest second license information has expired and become invalid. At this time, the second server will generate a third license information acquisition request and send it to the first server.

[0112] Theoretically, since the first server generates new second license information at intervals of the first preset duration and updates it to the data storage, and the data storage clears the expired second license information, the current latest second license information obtained by the second server from the data storage is not expired. However, in the case of sudden state or server downtime, the first server may not be able to update the second license information in the data storage in a timely manner and the first valid duration in the data storage is tampered with, resulting in the situation where the expired and should-have-been-cleared second license information is not cleared, and the second server will not be able to obtain the unexpired second license information from the data storage.

[0113] In this embodiment, when the second server cannot obtain valid second license information, the second server can directly access the first server to quickly obtain the latest unexpired second license information in a timely manner, achieving the purpose of quick response and solving sudden situations.

[0114] In a specific embodiment, after receiving the third license information acquisition request, the first server re-performs second encryption processing on the first license information to obtain the fourth license information, and directly returns the fourth license information to the second server. Among them, the fourth license information is a type of second license information. The first license information is obtained by the product development side performing first encryption processing on the third license information.

[0115] In this case, after the client receives the fourth license information returned by the second server, it will perform second decryption on the fourth license information to obtain the third license information. The second decryption specifically includes first performing first decryption on the fourth license information to obtain the first license information, and then performing third decryption on the first license information to obtain the third license information.

[0116] In another specific embodiment, there is no need to perform a second encryption process on the first license information, and the first license information is directly returned to the second server as the fourth license information, thus saving time costs. Therefore, after receiving the first license information returned by the second server, the client only needs to perform a third decryption to obtain the third license information. The third decryption is the inverse operation corresponding to the first encryption process.

[0117] In addition, when the second server detects that the current latest second license information has expired, it can also send an exception warning message to the monitoring end via email, text message, etc., so that the operation and maintenance personnel at the monitoring end can restore the service of the server in a timely manner.

[0118] In one embodiment, the method further includes:

[0119] If it is determined that the current latest second license information has expired according to the first timestamp and the first current moment, the expiration period setting of the data storage end is reset to the first effective duration.

[0120] Specifically, theoretically, if the second license information reaches its lifecycle, i.e., the first effective duration, the data storage end will automatically clear the expired and invalid second license information. However, if the second server can still obtain the actually invalid second license information from the data storage end, it means that the expiration period of the data storage end has been tampered with. Therefore, in this embodiment, the expiration period of the data storage end is reset to the first effective duration to restore the normal storage and management of the second license information by the data storage end.

[0121] In one embodiment, the client decrypts the current latest second license information to obtain the third license information, including:

[0122] The client decrypts the current latest second license information for the first time to obtain the first license information and the first timestamp;

[0123] If it is determined that the current latest second license information has not expired according to the first timestamp and the third current moment, the first license information is decrypted for the third time to obtain the third license information.

[0124] Specifically, the client in this embodiment also needs to judge the validity of the currently obtained latest second license information. This can further ensure data security and prevent unauthorized use, resulting in an increase in illegal authorizations.

[0125] In one embodiment, the method further includes:

[0126] If a fourth license information acquisition request from the client is received, a third license information acquisition request is sent to the first server. The fourth license information acquisition request is generated and sent by the client after determining that the currently latest second license information has expired based on the first timestamp and the third current moment.

[0127] Perform a first decryption on the fourth license information returned by the first server, and use the obtained corresponding first timestamp as the second timestamp.

[0128] If it is determined based on the second timestamp and the second current moment that the fourth license information has not expired, the fourth license information is returned to the client, enabling the client to perform a second decryption on the fourth license information to obtain the third license information.

[0129] Or,

[0130] Return the fourth license information returned by the first server to the client, enabling the client to perform a third decryption on the fourth license information to obtain the third license information.

[0131] Specifically, after the client receives the currently latest second license information returned by the second server, it performs a first decryption on the currently latest second license information to obtain the first license information and the first timestamp. If the duration between the first timestamp and the current third moment exceeds the first effective duration, it indicates that the currently latest second license information has expired. The client then sends a fourth license information acquisition request to the second server. The reason why the currently latest second license information has expired when the client receives it may be due to network latency or other reasons, resulting in a long waiting time in the process of the second server providing the currently latest second license information to the client.

[0132] After receiving the fourth license information acquisition request, the second server generates a third license information acquisition request and sends the third license information acquisition request to the first server.

[0133] After receiving the third license information acquisition request, the first server end performs a second encryption process on the first license information, and returns the obtained second license information carrying the corresponding first timestamp as the fourth license information to the second server end; or, returns the first license information as the fourth license information to the second server end. The first server end will return the fourth license information to the second server end.

[0134] The second server end will perform a first decryption on the fourth license information, take the obtained first timestamp as the second timestamp, and compare the duration between the second timestamp and the second current moment with the first valid duration. If the duration between the second timestamp and the second current moment does not exceed the first valid duration, it means that the fourth license information has not expired. The second server end will return the fourth license information to the client.

[0135] If the fourth license information has been secondarily encrypted, the client will perform a second decryption on the fourth license information to obtain the third license information, that is, first perform a first decryption on the fourth license information to obtain the first license information, and then perform a third decryption on the first license information to obtain the third license information.

[0136] If the fourth license information has not been secondarily encrypted, the client directly performs a third decryption on the fourth license information to obtain the third license information.

[0137] This embodiment solves the problem that due to delays, the second license information received by the client has expired, and the second server end can directly access the first server end to timely obtain the latest second license information.

[0138] It should be understood that the magnitudes of the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0139] The meanings of "first" and "second" in the above-mentioned modules / units are only used to distinguish different modules / units, and are not used to limit which module / unit has a higher priority or other limiting meanings. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or modules does not have to be limited to those steps or modules clearly listed, but may include other steps or modules not clearly listed or inherent to these processes, methods, products or devices. The division of modules in this application is only a logical division, and there may be other division methods in actual implementation.

[0140] Each second server in the second server side of this application does not directly interact with the first server side, and will not cause a large traffic pressure on the first server side. After saving the second license information obtained by the second encryption process to the data storage side, the first server side is allowed to be down or have other exceptions within a certain period of time, as long as it is restored within the first effective duration. The first server side is written in C++, which increases the difficulty of cracking. The second server side can continue to be written in Java (or other scripting languages), which reduces the development difficulty. The RSA algorithm is used to encrypt the license content, and a timestamp and a random number are added to increase the difficulty of cracking the encrypted content, and it can also ensure that the license information is not tampered with or forged.

[0141] The first server side includes a first server, and this first server can also be a second server in the second server side. The Java call C++ so (JNI) method is used, without adding an extra server, and only one more jar package and so are added when packaging this server to achieve server reuse.

[0142] Figure 4 It is the internal structure block diagram of a computer device in an embodiment of this application. This computer device can specifically be Figure 1 the first server side or the second server side in Figure 4As shown in the figure, the computer device includes a processor, a memory, a network interface, an input device, and a display screen connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory includes a storage medium and an internal memory. The storage medium can be a non-volatile storage medium or a volatile storage medium. The storage medium stores an operating system and can also store computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor can implement the license authorization management method. The internal memory provides an environment for the operation of the operating system and computer-readable instructions in the storage medium. Computer-readable instructions can also be stored in the internal memory. When the computer-readable instructions are executed by the processor, the processor can execute the license authorization management method. The network interface of the computer device is used to communicate with an external server through a network connection. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad set on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0143] In one embodiment, a computer device is provided, including a memory, a processor, and computer-readable instructions (such as a computer program) stored on the memory and executable on the processor. When the processor executes the computer-readable instructions, the steps of the license authorization management method in the above embodiment are implemented, such as Figure 2 The steps S110 to S120 shown and the extension of other extended and related steps of the method, or, for example Figure 3 The steps S210 to S250 shown and the extension of other extended and related steps of the method. To avoid repetition, it will not be elaborated here.

[0144] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The processor is the control center of the computer device, connecting various parts of the entire computer device through various interfaces and lines.

[0145] The memory can be used to store computer-readable instructions and / or modules. By running or executing the computer-readable instructions and / or modules stored in the memory, and by invoking the data stored in the memory, the processor can implement various functions of the computer device. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, video data, etc.).

[0146] The memory can be integrated in the processor or can be separately provided from the processor.

[0147] Those skilled in the art can understand that Figure 4 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0148] In one embodiment, a computer-readable storage medium is provided, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the steps of the license authorization management method in the above embodiment are implemented, such as Figure 2 the steps S110 to S120 shown and the extension of other extended and related steps of the method, or, for example Figure 3 the steps S210 to S250 shown and the extension of other extended and related steps of the method. To avoid repetition, it will not be elaborated here.

[0149] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium. When the computer-readable instructions are executed, they can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0150] It should be noted that in this document, the terms "including", "comprising", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, apparatus, article, or method including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such a process, apparatus, article, or method. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, apparatus, article, or method including that element.

[0151] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments. Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present application.

[0152] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be similarly included in the patent protection scope of the present application.

Claims

1. A license authorization management method, applied to a first server side, characterized in that The method includes: Obtaining first license information, where the first license information is generated by the product development side through first encryption processing based on the authorization code generated by the first server side and the corresponding product authorization information; Performing second encryption processing on the first license information every first preset time interval to obtain second license information carrying a corresponding first timestamp; Storing the second license information in a data storage side, and setting the validity period of the corresponding second license information to a first effective duration, so that the data storage side removes the second license information whose cumulative storage duration exceeds the first effective duration, where the first effective duration is not less than the first preset time interval; Before performing the second encryption processing on the first license information every first preset time interval, the method further includes: If an authorization code acquisition request from a second server side is received, generating an authorization code according to the obtained local hardware information; Returning the authorization code to the second server side; The method further includes: If a third license information acquisition request from the second server side is received, performing second encryption processing on the first license information, Returning the obtained second license information carrying a corresponding first timestamp as fourth license information to the second server side; Or, If a third license information acquisition request from the second server side is received, returning the first license information as fourth license information to the second server side.

2. The method according to claim 1, characterized in that, After performing the second encryption processing on the first license information and using the obtained second license information carrying a corresponding first timestamp as fourth license information, the method further includes: Storing the fourth license information as second license information in the data storage side, and setting the validity period of the fourth license information to a second effective duration, so that the data storage side removes the fourth license information whose cumulative storage duration exceeds the second effective duration, where the second effective duration is not less than the first preset time interval.

3. The method according to claim 1, wherein The method further includes: After the first server side is started, monitoring the number of target processes currently running; If the number of target processes currently running exceeds one, retaining the latest started target process and closing other target processes.

4. A license authorization management method, applied to the second server side, characterized in that The method includes: If a first license information acquisition request from a client is received, obtaining the current remaining available authorization quantity according to the authorized data in the data storage side; If the current remaining available authorization quantity is not less than a quantity threshold, obtaining the current latest second license information; Performing first decryption on the current latest second license information to obtain a corresponding first timestamp; If it is determined, based on the first timestamp and the first current moment, that the currently latest second license information has not expired or become invalid, then the currently latest second license information is returned to the client, enabling the client to perform a second decryption on the currently latest second license information to obtain third license information, where the third license information includes an authorization code and corresponding product authorization information, and the first license information is obtained by the product development end performing a first encryption process on the third license information; Update the authorized data in the data storage end; Before obtaining the currently remaining available authorization quantity based on the authorized data in the data storage end, the method further includes: Send an authorization code acquisition request to the first server end; After receiving the authorization code returned by the first server end, send a second license information acquisition request to the product development end, where the second license information acquisition request carries the authorization code and the product information of the product to be authorized; Provide the first license information received and returned by the product development end to the first server end; Perform a third decryption on the first license information, store the total available authorization quantity of the product to be authorized obtained into the data storage end, and initialize the authorized data in the data storage end; The method further includes: If it is determined, based on the first timestamp and the first current moment, that the currently latest second license information has expired or become invalid, then send a third license information acquisition request to the first server end; Perform a first decryption on the fourth license information returned by the first server end, and use the obtained corresponding first timestamp as the second timestamp, where the fourth license information is returned by the first server end according to the third license information acquisition request; If it is determined, based on the second timestamp and the second current moment, that the fourth license information has not expired or become invalid, then return the fourth license information to the client, enabling the client to perform a second decryption on the fourth license information to obtain third license information, Or, Return the fourth license information returned by the first server end to the client, enabling the client to perform a third decryption on the fourth license information to obtain third license information.

5. The method according to claim 4, wherein The method further includes: If it is determined, based on the first timestamp and the first current moment, that the currently latest second license information has expired or become invalid, then reset the validity period setting of the data storage end to the first effective duration.

6. The method according to claim 4, wherein The client performing a second decryption on the currently latest second license information to obtain third license information includes: The client decrypts the current latest second license information for the first time to obtain the first license information and the first timestamp; If it is determined according to the first timestamp and the third current moment that the current latest second license information has not expired and become invalid, the first license information is decrypted for the third time to obtain the third license information.

7. The method according to claim 6, wherein The method further includes: If a fourth license information acquisition request from the client is received, a third license information acquisition request is sent to the first server, where the fourth license information acquisition request is generated and sent by the client after determining that the current latest second license information has expired and become invalid according to the first timestamp and the third current moment; The fourth license information returned by the first server is decrypted for the first time, and the obtained corresponding first timestamp is used as the second timestamp; If it is determined according to the second timestamp and the second current moment that the fourth license information has not expired and become invalid, the fourth license information is returned to the client, so that the client decrypts the fourth license information for the second time to obtain the third license information, Or, The fourth license information returned by the first server is returned to the client, so that the client decrypts the fourth license information for the third time to obtain the third license information.

8. A license authorization management system, which is applied to the license authorization management method described in any one of claims 1-7, and is characterized in that, The system includes: A first server for obtaining the first license information, where the first license information is generated by the product development end through first encryption processing based on the authorization code generated by the first server and the corresponding product authorization information, the first license information is encrypted for the second time every first preset time interval to obtain the second license information carrying the corresponding first timestamp, the second license information is stored in the data storage end, and the validity period of the corresponding second license information is set to the first validity duration, so that the data storage end removes the second license information whose cumulative storage duration exceeds the first validity duration, where the first validity duration is not less than the first preset time interval; The second server side is configured to, if receiving a first license information acquisition request from the client, acquire the current remaining available authorization quantity according to the authorized data in the data storage end; if the current remaining available authorization quantity is not less than the quantity threshold, acquire the current latest second license information, perform a first decryption on the current latest second license information to obtain a corresponding first timestamp; if it is determined according to the first timestamp and the first current moment that the current latest second license information has not expired and become invalid, return the current latest second license information to the client, so that the client performs a second decryption on the current latest second license information to obtain a third license information, where the third license information includes the authorization code and the corresponding product authorization information, the first license information is obtained by the product development end performing a first encryption process on the third license information, and update the authorized data in the data storage end.

9. A computer device, comprising a memory, a processor, and computer-readable instructions stored on the memory and executable on the processor, characterized in that, When the processor executes the computer-readable instructions, it executes the steps of the license authorization management method according to any one of claims 1-3, or when the processor executes the computer-readable instructions, it executes the steps of the license authorization management method according to any one of claims 4-7.

10. A computer-readable storage medium having computer-readable instructions stored thereon, characterized in that, When the computer-readable instructions are executed by the processor, it causes the processor to execute the steps of the license authorization management method according to any one of claims 1-3, or causes the processor to execute the steps of the license authorization management method according to any one of claims 4-7.

Citation Information

Patent Citations

  • Software service authorization management method and device, equipment and storage medium

    CN113434824A

  • Authorization management method and system, server and client

    CN113656101A