Method, apparatus and storage medium for using permission management

CN116226931BActive Publication Date: 2026-09-18WOSIGN CA LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211563418.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-07
Publication Date
2026-09-18
Estimated Expiration
2042-12-07

AI Technical Summary

Technical Problem

[0005]本发明的主要目的在于提供一种使用权限管理方法,旨在解决现有技术如何对软件使用权限进行有效管理的技术问题

Benefits of technology

[0039] This invention generates digital certificates from the license certificates of the managed software, and then binds the license certificates to the managed software one by one through the digital certificates. During the use of the managed software, the digital certificates of the license certificates are verified by the verification server. The usage status of the managed software is obtained from the verification results of the digital certificates. The managed software is controlled only through digital certificates, without the need to bind the software to the running devices and the number of devices, thereby realizing effective management of the usage rights of the managed software through digital certificates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116226931B_ABST
    Figure CN116226931B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of software management, and discloses a use permission management method, device, equipment and storage medium; the method comprises the following steps: when the software to be managed is used for the first time, sending registration information of a license of the software to be managed to a verification server, so that the verification server generates a digital certificate of the software to be managed according to the registration information and issues the digital certificate; binding the license and the software to be managed through the digital certificate; determining the use state of the digital certificate according to the verification result after the digital certificate is verified; and determining the use state of the software to be managed according to the use state of the digital certificate. The application binds the digital certificate, the software to be managed and the license one by one, controls the license of the software to be managed according to the use state of the digital certificate, and only controls the software to be managed through the digital certificate, so that the software running equipment and quantity do not need to be bound, and the effective management of the use permission of the software to be managed through the digital certificate is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of software management technology, and in particular to a method, apparatus, device, and storage medium for managing access permissions. Background Technology

[0002] With the development of computer technology, software applications are becoming increasingly convenient. Good software can bring great convenience to people's lives, work, and study. How to manage users' software access permissions while utilizing software is an important issue faced by software developers.

[0003] Currently, using licenses is a common business model for software developers. Licenses are used to authenticate users, determine their legitimacy, and prevent hackers or competitors from using the software. Licenses can also be used to control user access permissions by managing their validity period. However, in real life, it is not possible to maintain a continuous internet connection. Once the internet is disconnected, it is impossible to perform a series of authentications on users.

[0004] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main objective of this invention is to provide a method for managing software usage permissions, aiming to solve the technical problem of how to effectively manage software usage permissions in the prior art.

[0006] To achieve the above objectives, the present invention provides a method for managing access permissions, the method comprising the following steps:

[0007] When the software to be managed is used for the first time, the registration information of the license certificate of the software to be managed is sent to the verification server, so that the verification server can generate and issue a digital certificate for the use of the software to be managed based on the registration information.

[0008] The digital certificate issued by the verification server will be bound one-to-one with the license certificate of the software to be managed and the software to be managed.

[0009] After binding is completed, the digital certificate is verified by the verification server, and the usage status of the digital certificate is determined based on the verification result.

[0010] The usage status of the software to be managed is determined based on the usage status of the digital certificate.

[0011] Optionally, sending the registration information of the software license certificate to the verification server, so that the verification server generates and issues a digital certificate for using the software to be managed based on the registration information, includes:

[0012] Obtain the random factor;

[0013] The registration information of the software license certificate to be managed and the random factor are sent to the verification server, so that the verification server generates unique identification information based on the registration information and the random factor, obtains a digital certificate for using the software to be managed based on the unique identification information, and issues it.

[0014] Optionally, the step of verifying the digital certificate through the verification server and determining the usage status of the digital certificate based on the verification result includes:

[0015] Get the current network connection status;

[0016] The usage status of the digital certificate is obtained by adopting the corresponding certificate status acquisition strategy based on the current network status.

[0017] Optionally, obtaining the usage status of the digital certificate by adopting a corresponding certificate status acquisition strategy based on the current network connection status includes:

[0018] When the current network connection status is semi-offline, a preset response period for obtaining the online certificate status protocol is set.

[0019] If the current date is within the preset response period, the usage status of the digital certificate at the previous moment is obtained, and the usage status of the digital certificate at the previous moment is used as the usage status of the current digital certificate.

[0020] If the current date is not within the preset response period, the validity period of the current digital certificate is obtained after connecting to the network, and a new preset response period for the digital certificate is obtained based on the validity period.

[0021] Optionally, the step of obtaining the usage status of the digital certificate by adopting a corresponding certificate status acquisition strategy based on the current network status further includes:

[0022] If the current network status is active, the validity period of the digital certificate is obtained according to the online certificate status protocol;

[0023] Determine whether the current time is within the validity period of the digital certificate, and obtain the usage status of the digital certificate based on the determination result;

[0024] If the current user is offline, the digital certificate is matched with the revoked certificates in the certificate revocation list, and the usage status of the digital certificate is determined based on the matching result.

[0025] Optionally, after matching the digital certificate with revoked certificates in the certificate revocation list if the current user is offline, and determining the usage status of the digital certificate based on the matching result, the method further includes:

[0026] Compare the current time with the preset update time to determine whether the current time belongs to the preset update time;

[0027] If the current time does not belong to the preset update time, obtain the reference certificate revocation list in the verification server;

[0028] The certificate revocation list is updated based on the reference certificate revocation list to obtain a new certificate revocation list.

[0029] Optionally, a preset instruction is obtained, which includes an account banning instruction, a freeze instruction, and a service termination instruction;

[0030] The target usage period is obtained by adjusting the usage period of the digital certificate according to the preset instructions;

[0031] The usage status of the digital certificate is obtained based on the target usage period.

[0032] Furthermore, to achieve the above objectives, the present invention also proposes a usage permission management device, the usage permission management device comprising:

[0033] The certificate generation module is used to send the registration information of the software license certificate to the verification server when the software is used for the first time, so that the verification server can generate and issue a digital certificate for the use of the software based on the registration information.

[0034] The certificate generation module is also used to bind the license certificate of the software to be managed and the software to be managed one by one through the digital certificate issued by the verification server;

[0035] The permission management module is used to verify the digital certificate through the verification server after binding is completed, and to determine the usage status of the digital certificate based on the verification result.

[0036] The permission management module is also used to determine the usage status of the software to be managed based on the usage status of the digital certificate.

[0037] Furthermore, to achieve the above objectives, the present invention also proposes a usage permission management device, which includes: a memory, a processor, and a usage permission management program stored in the memory and executable on the processor, wherein the usage permission management program is configured to implement the steps of the usage permission management method described above.

[0038] In addition, to achieve the above objectives, the present invention also proposes a storage medium storing a usage permission management program, which, when executed by a processor, implements the steps of the usage permission management method described above.

[0039] This invention generates digital certificates from the license certificates of the managed software, and then binds the license certificates to the managed software one by one through the digital certificates. During the use of the managed software, the digital certificates of the license certificates are verified by the verification server. The usage status of the managed software is obtained from the verification results of the digital certificates. The managed software is controlled only through digital certificates, without the need to bind the software to the running devices and the number of devices, thereby realizing effective management of the usage rights of the managed software through digital certificates. Attached Figure Description

[0040] Figure 1 This is a schematic diagram of the hardware operating environment access control device involved in the embodiments of the present invention;

[0041] Figure 2 This is a flowchart illustrating the first embodiment of the access control method of the present invention;

[0042] Figure 3 This is the actual permission management process in one embodiment of the permission management method of the present invention;

[0043] Figure 4 This is a flowchart illustrating the second embodiment of the access control method of the present invention;

[0044] Figure 5 This is a diagram illustrating the update of the certificate revocation list in one embodiment of the permission management method of the present invention;

[0045] Figure 6 This is the actual permission management process in one embodiment of the permission management method of the present invention;

[0046] Figure 7 This is a structural block diagram of the first embodiment of the access control device of the present invention.

[0047] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0048] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.

[0049] Reference Figure 1 , Figure 1 This is a schematic diagram of the hardware operating environment access control device structure involved in the embodiments of the present invention.

[0050] like Figure 1 As shown, the access control device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen or an input unit such as a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed random access memory (RAM) or a stable non-volatile memory (NVM), such as a disk drive. The memory 1005 may also optionally be a storage device independent of the aforementioned processor 1001.

[0051] Those skilled in the art will understand that Figure 1 The structure shown does not constitute a limitation on the use of the access control device and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0052] like Figure 1 As shown, the memory 1005, which serves as a storage medium, may include an operating system, a network communication module, a user interface module, and a usage permission management program.

[0053] exist Figure 1 In the usage permission management device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the usage permission management device of the present invention can be set in the usage permission management device, and the usage permission management device calls the usage permission management program stored in the memory 1005 through the processor 1001 and executes the usage permission management method provided in the embodiment of the present invention.

[0054] This invention provides a method for managing usage permissions, referring to... Figure 2 , Figure 2 This is a flowchart illustrating a first embodiment of a permission management method according to the present invention.

[0055] In this embodiment, the access control method includes the following steps:

[0056] Step S10: When using the software to be managed for the first time, send the registration information of the license certificate of the software to be managed to the verification server, so that the verification server can generate and issue a digital certificate for the use of the software to be managed based on the registration information.

[0057] Understandably, the software to be managed can be software installed on mobile devices, such as games or apps, or it can be software that manages the duration of a user's use of a tool, such as vehicle access control or membership management software. Specifically, the software to be managed can be any software that requires permission management for user access to the product.

[0058] It should be understood that the software license certificate to be managed may be issued when a user first uses the software, based on the account the user obtains for using the software. This account may contain license information (verification information). It is further understood that the software license certificate to be managed may consist of license information and a random factor.

[0059] It should be noted that after obtaining the random factor, the registration information of the license certificate of the software to be managed (the registration information can be understood as the license information) and the random factor are sent to the verification server, so that the verification server generates unique identification information based on the registration information and the random factor, and issues the unique identification information as a digital certificate for using the software to be managed.

[0060] It should be further explained that the verification server can be understood as a background processor that verifies the user's registration information when the user logs into the software to be managed, and generates a unique digital certificate based on the registration information.

[0061] It should be understood that a digital certificate is a digital authentication that identifies the parties involved in internet communication. People can use it to verify the identity of others online. Furthermore, digital certificates are also known as digital identifiers. Digital certificates ensure the integrity and security of information and data exchanged between internet users in computer network communications through encryption or decryption.

[0062] Understandably, the verification server generates and issues a digital certificate for the software to be managed based on the registration information, and then sends the digital certificate generated based on the registration information back to the user. After receiving the digital certificate, the user can bind the digital certificate, the registration information, and the software to be managed.

[0063] Step S20: The digital certificate issued by the verification server binds the license certificate of the software to be managed and the software to be managed one by one.

[0064] Understandably, the license certificate for the managed software can be the validity period of the user's use of the managed software corresponding to the user's registration information when using the managed software, while the digital certificate can be generated by the verification server based on the user's registration information.

[0065] It should be understood that when using the software to be managed, users need to use the registration information to obtain a digital certificate, verify the digital certificate to obtain a license certificate for the software to be managed, and control whether users can use the software to be managed based on the license certificate.

[0066] It should be noted that after binding the digital certificate with the license certificate of the software to be managed, the validity period of the digital certificate can be mapped to the validity period of the software to be managed.

[0067] Step S30: After binding is completed, the digital certificate is verified by the verification server, and the usage status of the digital certificate is determined based on the verification result.

[0068] It should be noted that verifying the digital certificate through the verification server may include verifying the digital certificate through the Online Certificate Status Protocol (OCSP) or the Certificate Revocation List (CRL).

[0069] It is understood that the digital certificate may be in one of three states: valid, revoked, or unknown.

[0070] It should be further explained that after successful binding, the validity period of the digital certificate maps to the usage period of the software. During the use of the software to be managed, the verification server controls the software's verification cycle and real-time availability by responding to the digital certificate with OCSP / CRL. Based on the uniqueness of the digital certificate, the software does not need to obtain hardware information of the software's operating environment for binding, thus achieving protection of the license's uniqueness. After successful registration, the verification server begins providing real-time status responses for the digital certificate. During software operation, the real-time status of the certificate is used to determine whether the software is running normally.

[0071] Step S40: Determine the usage status of the software to be managed based on the usage status of the digital certificate.

[0072] Understandably, when a digital certificate is bound to the software to be managed, the usage status of the digital certificate can be used as the usage status of the software to be managed based on the binding information.

[0073] In practice, users obtain a digital certificate corresponding to their account by logging in. The digital certificate is then verified on the verification server to confirm its validity. This indicates that the user's access rights to the software being managed are also valid.

[0074] It should be noted that the actual process for managing permissions in management software can be referenced from [reference needed]. Figure 3 In the diagram, "License" can be understood as a software usage license or the license certificate described above. The verification of the certificate's status determines whether the digital certificate is valid.

[0075] It should be emphasized that before determining the usage status of the software to be managed based on the usage status of the digital certificate, a preset instruction is obtained. The preset instruction includes an account ban instruction, a freeze instruction, and a service termination instruction. It should be understood that during the user's use of the software to be managed, there may be user violations or software updates. In this case, the user's usage period for the software to be managed has not expired. In this case, the user's usage period can be managed by adjusting the trial period of the digital certificate.

[0076] In practice, User A disrupted the game's internal balance by using cheats while using game software A. Prior to this, User A had purchased a one-year usage period for game software A. However, due to User A's violation, a ban order was issued for User A's digital certificate. Based on the ban order, the validity period of User A's digital certificate was adjusted. Different orders correspond to different adjustment strategies. For example, a ban order could change the validity period of the digital certificate to the current time, while a freeze order could change the validity period of the digital certificate to the current time and then adjust the validity period again after 7 days.

[0077] It should be further explained that the target usage period is obtained by adjusting the usage period of the digital certificate according to the preset instruction. The target usage period is the usage period line of the digital certificate after modification according to the instruction. The usage status of the digital certificate is obtained according to the target usage period. The current time is compared with the target usage period. If the current time is within the usage period of the digital certificate, the usage status of the digital certificate is valid. If the current time is not within the usage period of the digital certificate, the usage status of the digital certificate is revoked. If the usage period of the digital certificate cannot be known, the usage status of the digital certificate is unknown.

[0078] This embodiment generates a digital certificate through the license certificate of the managed software, and then binds the license certificate to the managed software one by one through the digital certificate. During the use of the managed software, the digital certificate of the license certificate is verified by the verification server. The usage status of the managed software is obtained from the verification result of the digital certificate. The managed software is controlled only through the digital certificate, without the need to bind the software running on the device or the number of devices, thereby realizing effective management of the usage rights of the managed software through the digital certificate.

[0079] This invention provides a method for managing usage permissions, referring to... Figure 4 , Figure 4 This is a flowchart illustrating a second embodiment of a permission management method according to the present invention.

[0080] In this embodiment, step S30 of the access control method verifies the digital certificate through the verification server and determines the usage status of the digital certificate based on the verification result, including the following steps:

[0081] Step S31: Obtain the current network connection status.

[0082] It should be noted that the current network status can be divided into offline status and network status. However, in specific implementation, there may be three situations. The first situation is an offline status where the network cannot be connected at all. For example, some enterprises may have an intranet. In the case of an intranet, it is impossible to connect to the external network. The external network is the network under normal circumstances.

[0083] Scenario two could be that the software being managed is constantly connected to the internet, indicating a relatively stable network connection.

[0084] Scenario 3 could be that the current network connection is unstable, and there may be periods where the network can be connected but then becomes unavailable after a period of time.

[0085] Step S32: Based on the current network connection status, adopt the corresponding certificate status acquisition strategy to obtain the usage status of the digital certificate.

[0086] Understandably, the current network status can be semi-offline, connected, or offline.

[0087] It should be understood that the certificate status acquisition strategy uses different methods to obtain the usage status of digital certificates based on different network connection statuses. For example, in the online state, the usage status of digital certificates is obtained according to the online certificate status protocol; in the offline state, the usage status of digital certificates is obtained according to the certificate revocation list; and in the semi-offline state, the usage status of digital certificates is obtained according to the preset response period.

[0088] It should be noted that if the current network connection status is active, the validity period of the digital certificate is obtained according to the online certificate status protocol; it is then determined whether the current time is within the validity period of the digital certificate. If the current time is within the validity period of the digital certificate, the current usage status of the digital certificate is valid; if the current time is not within the validity period of the digital certificate, the current usage status of the digital certificate is revoked; if the validity period of the digital certificate cannot be obtained according to the online certificate status protocol, the current usage status of the digital certificate is unknown.

[0089] It should be further explained that if the current user is offline, the digital certificate is matched with the revoked certificates in the certificate revocation list. If the digital certificate matches successfully with the revoked certificates in the certificate revocation list, the current digital certificate is in a revoked state. If the digital certificate fails to match successfully with the revoked certificates in the certificate revocation list, the current digital certificate is in a valid state. If the certificate revocation list cannot be obtained, the current digital certificate is in an unknown state.

[0090] The acquisition and updating of the certificate revocation list involves comparing the current time with a preset update time (which can be obtained by adding a preset interval to the last update time, such as a week or a month), determining whether the current time falls within the preset update time; if the current time does not fall within the preset update time, a reference certificate revocation list is retrieved from the verification server. This reference certificate list is a list of revoked digital certificates that is updated in real-time on the verification server (understandably, because it is offline, this reference certificate revocation list can be downloaded from the external network via an external storage medium and then transferred to the internal network); the certificate revocation list is then updated based on the reference certificate revocation list to obtain a new certificate revocation list. The update of the certificate revocation list can refer to... Figure 5 , Figure 5 To demonstrate the update of the certificate revocation list during actual use, the effective date is the last update time, and the next update time is the preset update time. Based on the last update time and the next update time, it can be known that the preset interval is one week.

[0091] It should be emphasized that when the current network connection status is semi-offline, the preset response period for obtaining the online certificate status protocol is as follows: the data packet of the online certificate status protocol response includes the real-time status of the digital certificate and the validity period of the online certificate status protocol data response.

[0092] For ease of understanding, the validity period of the data response can be obtained by adding the time when the digital certificate status was obtained during the last network connection to the preset response period. For example, if the current digital certificate status was found to be valid through the online certificate status protocol during the last network connection on November 30, 2022, the preset response period can be one week or one month. If the preset response period is one week, then the validity period of the data response is from November 30, 2022 to December 7, 2022.

[0093] If the current date is within the preset response period, the usage status of the digital certificate at the previous moment is obtained (which can be understood as the usage status of the digital certificate at the last time the network was connected), and the usage status of the digital certificate at the previous moment is used as the usage status of the current digital certificate; if the current date is not within the preset response period, the validity period of the current digital certificate is obtained after connecting to the network, and a new preset response period for the digital certificate is obtained based on the validity period.

[0094] For a complete verification process, please refer to [link / reference]. Figure 6 This system dynamically authorizes and revokes software based on the real-time status of digital certificates; it manages the authentication cycle of software through the validity period of the digital certificate's OCSP / CRL. Software can be used offline within the validity period of the digital certificate's OCSP / CRL status response, without requiring online verification and authorization. For completely offline intranet environments, authentication can be performed by periodically updating the CRL file. For expired software, the server will no longer provide OCSP / CRL responses, thus rendering the software unusable.

[0095] This effectively balances the conflict between offline use and online monitoring of software products, thereby achieving effective protection of the intellectual property rights and commercial value of the software products. Authentication can be performed through a unified interface (Online Certificate Status Protocol (OCSP) and Certificate Revocation List (CRL)). When the software's usage period expires, the normal use rights of the managed software can be revoked directly by revoking the corresponding digital certificate.

[0096] This embodiment manages permissions for the software to be managed in offline, semi-offline, and online states through an online certificate status protocol and a certificate revocation list. It allows the software to be managed to be used normally in an intranet environment, while also enabling dynamic management and periodic verification of the permissions of the software to be managed. This solves the problem of not being able to manage the permissions of the software to be managed in offline or semi-offline environments, and effectively resolves the contradiction between offline use and online supervision of software products.

[0097] Furthermore, this embodiment of the invention also proposes a storage medium storing a usage permission management program, which, when executed by a processor, implements the steps of the usage permission management method described above.

[0098] Reference Figure 7 , Figure 7 This is a structural block diagram of the first embodiment of the access control device of the present invention.

[0099] like Figure 7 As shown, the usage permission management device proposed in this embodiment of the invention includes:

[0100] The certificate generation module 10 is used to send the registration information of the license certificate of the software to be managed to the verification server when the software is used for the first time, so that the verification server generates and issues a digital certificate for the use of the software to be managed based on the registration information.

[0101] The certificate generation module 10 is also used to bind the license certificate of the software to be managed and the software to be managed one by one through the digital certificate issued by the verification server;

[0102] The permission management module 20 is used to verify the digital certificate through the verification server after the binding is completed, and to determine the usage status of the digital certificate based on the verification result.

[0103] The permission management module 20 is also used to determine the usage status of the software to be managed based on the usage status of the digital certificate.

[0104] This embodiment generates a digital certificate through the license certificate of the managed software, and then binds the license certificate to the managed software one by one through the digital certificate. During the use of the managed software, the digital certificate of the license certificate is verified by the verification server. The usage status of the managed software is obtained from the verification result of the digital certificate. The managed software is controlled only through the digital certificate, without the need to bind the software running on the device or the number of devices, thereby realizing effective management of the usage rights of the managed software through the digital certificate.

[0105] In one embodiment, the certificate generation module 10 is further configured to obtain a random factor;

[0106] The registration information of the software license certificate to be managed and the random factor are sent to the verification server, so that the verification server generates unique identification information based on the registration information and the random factor, obtains a digital certificate for using the software to be managed based on the unique identification information, and issues it.

[0107] In one embodiment, the permission management module 20 is further configured to obtain the current network connection status;

[0108] The usage status of the digital certificate is obtained by adopting the corresponding certificate status acquisition strategy based on the current network status.

[0109] In one embodiment, the permission management module 20 is further configured to obtain a preset response period of the online certificate status protocol when the current network status is semi-offline.

[0110] If the current date is within the preset response period, the usage status of the digital certificate at the previous moment is obtained, and the usage status of the digital certificate at the previous moment is used as the usage status of the current digital certificate.

[0111] If the current date is not within the preset response period, the validity period of the current digital certificate is obtained after connecting to the network, and a new preset response period for the digital certificate is obtained based on the validity period.

[0112] In one embodiment, the permission management module 20 is further configured to, if the current network status is in a network state, obtain the validity period of the digital certificate according to the online certificate status protocol;

[0113] Determine whether the current time is within the validity period of the digital certificate, and obtain the usage status of the digital certificate based on the determination result;

[0114] If the current user is offline, the digital certificate is matched with the revoked certificates in the certificate revocation list, and the usage status of the digital certificate is determined based on the matching result.

[0115] In one embodiment, the permission management module 20 is further configured to compare the current time with a preset update time to determine whether the current time belongs to the preset update time;

[0116] If the current time does not belong to the preset update time, obtain the reference certificate revocation list in the verification server;

[0117] The certificate revocation list is updated based on the reference certificate revocation list to obtain a new certificate revocation list.

[0118] In one embodiment, the permission management module 20 is further configured to obtain preset instructions, which include account banning instructions, freezing instructions, and service termination instructions;

[0119] The target usage period is obtained by adjusting the usage period of the digital certificate according to the preset instructions;

[0120] The usage status of the digital certificate is obtained based on the target usage period.

[0121] It should be understood that the above are merely illustrative examples and do not constitute any limitation on the technical solutions of the present invention. In specific applications, those skilled in the art can make settings as needed, and the present invention does not impose any restrictions on this.

[0122] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of this invention. In practical applications, those skilled in the art can select some or all of the workflow to achieve the purpose of this embodiment according to actual needs, and no restrictions are imposed here.

[0123] Furthermore, it should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0124] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0125] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as read-only memory (ROM) / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0126] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for managing user access permissions, characterized in that, The access control method includes: When the software to be managed is used for the first time, the registration information of the license certificate of the software to be managed is sent to the verification server, so that the verification server can generate and issue a digital certificate for the use of the software to be managed based on the registration information. The digital certificate issued by the verification server will be bound one-to-one with the license certificate of the software to be managed and the software to be managed. After binding is complete, obtain the current network connection status; The usage status of the digital certificate is obtained by adopting the corresponding certificate status acquisition strategy based on the current network status. The step of obtaining the usage status of the digital certificate by adopting a corresponding certificate status acquisition strategy based on the current network status includes: When the current network connection status is semi-offline, a preset response period for obtaining the online certificate status protocol is set. If the current date is within the preset response period, the usage status of the digital certificate at the previous moment is obtained, and the usage status of the digital certificate at the previous moment is used as the usage status of the current digital certificate. If the current date is not within the preset response period, the validity period of the current digital certificate is obtained after connecting to the network, and a new preset response period for the digital certificate is obtained based on the validity period. If the current network status is active, the validity period of the digital certificate is obtained according to the online certificate status protocol; Determine whether the current time is within the validity period of the digital certificate, and obtain the usage status of the digital certificate based on the determination result; If the current user is offline, the digital certificate is matched with the revoked certificates in the certificate revocation list, and the usage status of the digital certificate is obtained based on the matching result. The current time is compared with the preset update time to determine whether the current time belongs to the preset update time. The preset update time is obtained by adding a preset interval time to the last update time. If the current time belongs to the preset update time, obtain the reference certificate revocation list in the verification server, wherein the reference certificate revocation list is downloaded from the verification server and transferred to the local machine through an external storage medium; The certificate revocation list is updated based on the reference certificate revocation list to obtain a new certificate revocation list; Obtain preset instructions, including account banning instructions, freeze instructions, and service termination instructions; The target usage period is obtained by adjusting the usage period of the digital certificate according to the preset instructions; If the preset instruction is an account banning instruction, the validity period of the digital certificate will be set to the current time; If the preset instruction is a freeze instruction, the validity period of the digital certificate is set to the current time, and the original validity period of the digital certificate is restored after the preset time. If the preset instruction is a stop service instruction, then the issuance of a new preset response period for the digital certificate will be stopped, so that the digital certificate cannot obtain an updated valid status; The usage status of the digital certificate is obtained based on the target usage period; The usage status of the software to be managed is determined based on the usage status of the digital certificate.

2. The access control method as described in claim 1, characterized in that, The step of sending the registration information of the software license certificate to be managed to the verification server, so that the verification server generates and issues a digital certificate for the use of the software to be managed based on the registration information, includes: Obtain the random factor; The registration information of the software license certificate to be managed and the random factor are sent to the verification server, so that the verification server generates unique identification information based on the registration information and the random factor, obtains a digital certificate for using the software to be managed based on the unique identification information, and issues it.

3. A user access control device, characterized in that, The access control device includes: The certificate generation module is used to send the registration information of the software license certificate to the verification server when the software is used for the first time, so that the verification server can generate and issue a digital certificate for the use of the software based on the registration information. The certificate generation module is also used to bind the license certificate of the software to be managed and the software to be managed one by one through the digital certificate issued by the verification server; The permission management module is used to obtain the current network status after the binding is completed; The usage status of the digital certificate is obtained by adopting the corresponding certificate status acquisition strategy based on the current network status. The access control module is further configured to obtain the usage status of the digital certificate based on the current network connection status and a corresponding certificate status acquisition strategy, including: When the current network connection status is semi-offline, a preset response period for obtaining the online certificate status protocol is set. If the current date is within the preset response period, the usage status of the digital certificate at the previous moment is obtained, and the usage status of the digital certificate at the previous moment is used as the usage status of the current digital certificate. If the current date is not within the preset response period, the validity period of the current digital certificate is obtained after connecting to the network, and a new preset response period for the digital certificate is obtained based on the validity period. If the current network status is active, the validity period of the digital certificate is obtained according to the online certificate status protocol; Determine whether the current time is within the validity period of the digital certificate, and obtain the usage status of the digital certificate based on the determination result; If the current user is offline, the digital certificate is matched with the revoked certificates in the certificate revocation list, and the usage status of the digital certificate is obtained based on the matching result. The current time is compared with the preset update time to determine whether the current time belongs to the preset update time. The preset update time is obtained by adding a preset interval time to the last update time. If the current time belongs to the preset update time, obtain the reference certificate revocation list in the verification server, wherein the reference certificate revocation list is downloaded from the verification server and transferred to the local machine through an external storage medium; The certificate revocation list is updated based on the reference certificate revocation list to obtain a new certificate revocation list; Obtain preset instructions, including account banning instructions, freeze instructions, and service termination instructions; The target usage period is obtained by adjusting the usage period of the digital certificate according to the preset instructions; If the preset instruction is an account banning instruction, the validity period of the digital certificate will be set to the current time; If the preset instruction is a freeze instruction, the validity period of the digital certificate is set to the current time, and the original validity period of the digital certificate is restored after the preset time. If the preset instruction is a stop service instruction, then the issuance of a new preset response period for the digital certificate will be stopped, so that the digital certificate cannot obtain an updated valid status; The usage status of the digital certificate is obtained based on the target usage period; The permission management module is also used to determine the usage status of the software to be managed based on the usage status of the digital certificate.

4. A device for managing user access rights, characterized in that, The device includes: a memory, a processor, and a usage permission management program stored in the memory and executable on the processor, the usage permission management program being configured to implement the usage permission management method as described in any one of claims 1 to 2.

5. A storage medium, characterized in that, The storage medium stores a usage permission management program, which, when executed by a processor, implements the usage permission management method as described in any one of claims 1 to 2.

Citation Information

Patent Citations

  • Web service and signature certificate-based software trial authorization method

    CN103078858A

  • Management method and system for software digital permission

    CN106971095A