Data processing method, apparatus and device

By generating one-time license credentials using symmetric and asymmetric encryption algorithms and reducing the remaining usable time within a preset period, combined with hash algorithms and code obfuscation technology, the problems of low accuracy in license credential management and high risk of unauthorized authorization are solved, achieving highly secure and efficient license credential management.

CN118797578BActive Publication Date: 2026-05-15CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD
Filing Date
2023-10-26
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing technologies suffer from low accuracy in license credential management and high risk of unauthorized authorization. Users can extend or reuse license credentials by modifying system time or reinstalling the operating system, which affects the accuracy and security of license credential management.

Method used

Multiple encryption processes are used to generate one-time license certificates. The first license certificate is generated through symmetric and asymmetric encryption algorithms. The remaining available time is reduced within a preset time interval, and the encrypted certificate information is updated. Hash algorithms are used to prevent reuse and tampering. Code obfuscation and encryption algorithms are used to improve security.

Benefits of technology

It improves the security and accuracy of license credential management, prevents unauthorized authorization, optimizes the caching information of license credentials, enhances the speed and security of license credential management, reduces the risk of unauthorized authorization, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118797578B_ABST
    Figure CN118797578B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method, device and equipment. The method comprises the following steps: obtaining a first license ticket generated by a service platform through first encryption processing based on first encryption information and a symmetric key, wherein the first encryption information is generated by second encryption processing of device information and service information; performing encryption processing on the first license ticket and a first remaining available time length of the first license ticket to obtain first encrypted ticket information; performing encryption processing on the first encrypted ticket information and the first license ticket to obtain second encrypted ticket information; every interval of a first preset time length, the first remaining available time length is reduced to a second remaining available time length according to a preset unit quantity; and updating the first encrypted ticket information and the second encrypted ticket information based on the second remaining available time length. In this way, the first license ticket is prevented from being repeatedly used, the accuracy of license ticket control is improved, and the risk of illegal authorization is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data processing technology, and in particular relates to a data processing method, apparatus and equipment. Background Technology

[0002] With the development of network technology, a large number of software applications have emerged. To ensure the right to use software and hardware products, software service platforms need to authorize corresponding user devices. In related technologies, software copyright licenses are typically used to authorize users to use the corresponding software and hardware products, achieving effective license control. License control includes authentication, authorization, and validity period verification.

[0003] Since the validity period is determined by the date in the license file, the license can be extended or reused by modifying the user's device operating system runtime or reinstalling the operating system, which poses a high risk of unauthorized authorization and affects the accuracy of license certificate management. Summary of the Invention

[0004] This application provides a data processing method, apparatus, and device that can solve the problems of low accuracy in license credential management and high risk of unauthorized authorization in the prior art.

[0005] In a first aspect, embodiments of this application provide a data processing method, which may include:

[0006] Obtain the first license credential, which is generated by the service platform through the first encryption process based on the first encrypted information and the symmetric key. The first encrypted information is the device information of the user device and the service information that the service platform authorizes the user device to access, which is generated through the second encryption process. The first license credential is a one-time license credential.

[0007] The first license credential and the first remaining available time of the first license credential are subjected to a third encryption process to obtain the first encrypted credential information; and the first encrypted credential information and the first license credential are subjected to a fourth encryption process to obtain the second encrypted credential information.

[0008] At each first preset time interval, the first remaining available time is reduced to the second remaining available time according to a preset unit amount;

[0009] Update the first and second encrypted credential information based on the second remaining available time.

[0010] Secondly, embodiments of this application provide a data processing apparatus, which may include:

[0011] The acquisition module is used to acquire the first license credential. The first license credential is generated by the service platform through the first encryption process based on the first encrypted information and the symmetric key. The first encrypted information is the device information of the user device and the service information that the service platform authorizes the user device to access, which is generated through the second encryption process. The first license credential is a one-time license credential.

[0012] The encryption module is used to perform a third encryption process on the first license credential and the first remaining available time of the first license credential to obtain the first encrypted credential information; and to perform a fourth encryption process on the first encrypted credential information and the first license credential to obtain the second encrypted credential information.

[0013] The adjustment module is used to reduce the first remaining available time to the second remaining available time at each first preset time interval by a preset unit amount;

[0014] The update module is used to update the first encrypted credential information and the second encrypted credential information based on the second remaining available time.

[0015] Thirdly, embodiments of this application provide a computer device, which includes: a processor and a memory storing computer program instructions;

[0016] When the processor executes computer program instructions, it implements the data processing method as described in the first aspect.

[0017] Fourthly, embodiments of this application provide a computer storage medium storing computer program instructions, which, when executed by a processor, implement the data processing method as described in the first aspect.

[0018] Fifthly, embodiments of this application provide a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the data processing method as shown in the first aspect.

[0019] In a sixth aspect, embodiments of this application provide a computer program product stored in a storage medium, which is executed by at least one processor to implement the data processing method as described in the first aspect.

[0020] The data processing method, apparatus, and device of this application embodiment can employ various encryption processes on the device information of the user device and the service information that the service platform authorizes the user device to access, to obtain a first license credential. This improves the security of the first license credential itself. Furthermore, by using a one-time first license credential, it can prevent the first license credential from being reused and extend its usage. In addition, by adjusting the remaining available time at preset intervals and updating the first and second encrypted credential information, the remaining available days of the first license credential can be verified, further preventing certificate reuse due to user tampering with the system time. This optimizes the caching information of the first license credential, improves the accuracy of license credential management, reduces the risk of unauthorized authorization, and enhances the security of license credential management. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 A flowchart illustrating a data processing method provided in an embodiment of this application;

[0023] Figure 2 This application provides a flowchart illustrating a data processing method.

[0024] Figure 3 This application provides a schematic diagram of an entity class in a data processing method.

[0025] Figure 4 This is a schematic diagram of the structure of a data processing apparatus provided in one embodiment of this application;

[0026] Figure 5 This is a schematic diagram of the structure of a data processing device provided in one embodiment of this application. Detailed Implementation

[0027] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0028] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0029] The acquisition, storage, use, and processing of data (including but not limited to features and information mentioned in this document) in the technical solution of this application all comply with the relevant provisions of national laws and regulations.

[0030] License credential management includes authentication, authorization, and validity verification. Authentication verifies the user's identity; only those with a license credential issued by the service platform can use the platform's devices. Authorization verifies whether the user has certain functional permissions for the platform's devices. Validity verification limits the license credential's usage period; after the expiration date, the platform's devices will no longer provide services, requiring the user to reapply for a license credential. A challenge in license credential management is that some users may tamper with the license credential's file content or alter the user's device's system time to extend its use and reuse. Furthermore, license credential verification involves validation for every user request; inefficient verification increases user input and negatively impacts the user experience.

[0031] In related technologies, the above problems can be improved in the following three ways, as detailed below. Method one involves requesting a remote service platform to verify the validity of the license credential and using a data caching module to address the verification efficiency issue. While this method effectively prevents users from extending the use of license credentials by modifying the device's system time, it will fail to verify the license credential if the user's device is offline or requires no external network access. Method two involves caching the license credential to improve verification efficiency. However, caching only improves the reading speed of the license credential; the program still needs to read the license credential file cache and then parse the license credential information to perform time and function authorization verification, making the verification process cumbersome and ultimately failing to improve the efficiency of license credential management. Method two determines license expiration by checking the date in the license certificate file. However, this method cannot prevent users from extending the license's validity period by modifying the system time. Method three assigns an identification code to the license certificate during its generation. This allows for verification of the license certificate's file date during registration. Next, the hardware identification code of the user's device is obtained, and the hardware identification code, the license certificate's identification code, and the system time are stored together in the license certificate verification file. Then, the hardware identification code is used as a sector logical number to locate the corresponding sector, and the contents of the license certificate's verification file are written to that sector, resulting in the license certificate verification sector. Finally, the validity of the license certificate is verified using periodic checks or application startup checks, while simultaneously checking the validity of the dates in the license certificate's verification file and the license certificate verification sector. Therefore, in this method, if a user modifies their device's system time to a time greater than the recorded time in the license credential verification sector before re-importing the license credential for registration after its expiration, the license credential can be repeatedly imported. Since the time recorded in the license credential verification sector is the system time at the time of the last registration (i.e., less than the actual system time), the license credential's expiration date will be deemed compliant, making the repeated import legal and registration successful. This also satisfies the time validity check, and subsequent modifications and registrations will also be possible. However, this approach allows for the extension or reuse of license credentials by modifying the user's operating system runtime or reinstalling the operating system, posing a high risk of unauthorized authorization and affecting the accuracy of license credential management.

[0032] To address the aforementioned problems, this application provides a data processing method, apparatus, computer device, and storage medium. The data processing method provided in this application employs various encryption techniques on user device information and service platform access permissions to obtain a first license credential. This improves the security of the first license credential itself. Furthermore, by using a one-time first license credential, it prevents the reuse and extension of the license credential's lifespan. Additionally, by adjusting the remaining available time at preset intervals and updating the first and second encrypted credential information, it verifies the remaining available days of the first license credential, further preventing certificate reuse due to user time tampering. It also optimizes the caching information of the first license credential, improving the accuracy of license credential management. Moreover, by caching and updating the verification results of the license credential, it increases the speed of verifying user-requested license credentials, enhancing authorization control over functions and authentication. Furthermore, through code obfuscation and encryption algorithms, it improves the security of license credential management at the source code level. Thus, it not only improves the accuracy and speed of license credential management and verification but also enhances the user experience.

[0033] First, combined Figure 1 The data processing method provided in the embodiments of this application will be described in detail.

[0034] Figure 1 This is a flowchart of a data processing method provided in an embodiment of this application.

[0035] like Figure 1 As shown, this data processing method can be applied to computer devices, which may include the user's electronic device, i.e., the user device in this embodiment of the application. The data processing method may specifically include the following steps:

[0036] Step 110: Obtain the first license credential. The first license credential is generated by the service platform through a first encryption process based on the first encrypted information and the symmetric key. The first encrypted information is generated through a second encryption process based on the user device's device information and the service information that the service platform authorizes the user device to access. The first license credential is a one-time license credential. Step 120: Perform a third encryption process on the first license credential and the first remaining available time of the first license credential to obtain the first encrypted credential information. And perform a fourth encryption process on the first encrypted credential information and the first license credential to obtain the second encrypted credential information. Step 130: At each first preset time interval, reduce the first remaining available time to the second remaining available time by a preset unit. Step 140: Update the first encrypted credential information and the second encrypted credential information based on the second remaining available time.

[0037] Therefore, multiple encryption processes can be applied to the device information of the user device and the service information that the service platform authorizes the user device to access, resulting in a first license credential. This improves the security of the first license credential itself. Furthermore, by using a one-time first license credential, the reuse and extension of the license credential's use can be prevented. Additionally, by setting a preset time interval, the remaining available time is reduced, and the first and second encrypted credential information is updated to verify the remaining available days of the first license credential. This further prevents certificate reuse due to user tampering with the system time, optimizes the caching information of the first license credential, improves the accuracy of license credential management, reduces the risk of unauthorized authorization, and enhances the security of license credential management.

[0038] The above steps are explained in detail below:

[0039] First, regarding step 110, in one or more possible embodiments, the process of generating the first license credential can be performed on a service platform, such as... Figure 2 As shown, the service platform can generate an interface for data transmission with the user equipment. Through this interface, it collects user information such as the user equipment's medium access control (MAC) address, processor serial number, and system serial number to uniquely identify the device and use this information as the basis for subsequent license credential verification. Specifically, a digital envelope encryption method can be used. This involves using a symmetric encryption algorithm and a symmetric key to symmetrically encrypt the user equipment information and the service information authorized by the service platform, obtaining first encrypted information. Then, using the private key in an asymmetric encryption algorithm (RSA), the first encrypted information and the first key are subjected to a first encryption process to obtain a first license credential. The license credential in this embodiment includes authorized functions, a license time window, and other authorized functions. The license time window can include the license credential start time and license credential expiration time.

[0040] Thus, by using the symmetric key of the symmetric encryption algorithm, the device information of the user device and the service information that the service platform authorizes the user device to access are symmetrically encrypted to obtain the first encrypted information. Then, using the private key of the asymmetric encryption algorithm, the symmetric key and the first encrypted information are asymmetrically encrypted to obtain the first license credential. The security of the first license credential is further improved by using double encryption, which solves the problem of the license credential being extended due to the user parsing and cracking the first license credential, and improves the security of the license credential.

[0041] Based on this, the first license credential can be obtained. The first license credential can be obtained in two scenarios: first, when using the user device for the first time, the first license credential must be uploaded before logging into the user device; second, when the license credential expires or is tampered with and cannot be used, the user will be prompted to re-upload the correct license credential. Next, regarding step 120, in one or more possible embodiments, the first license credential in this application embodiment is a one-time, non-repeating license credential that can only be used once. Each upload records the first hash value (MD5) of the first license credential uploaded each time. The purpose is to prevent the first license credential from being uploaded repeatedly. This is because if the first license credential expires or fails verification, and the user modifies the operating system time of the user's device to allow the license credential to be successfully installed before re-uploading the license credential, the user's device usage will be extended. In this case, the one-time first license credential in this application implementation can prevent this situation from occurring. That is, by encrypting and storing the uploaded first license credential with MD5 and comparing it with the MD5 of historical certificates, the situation of the user tampering with the operating system time before re-uploading the license credential, causing the license credential to be extended and reused, is solved. Based on this, the first license credential corresponds to the first hash value, and the first hash value is used to uniquely identify the first license credential. Based on this, before step 120, the data processing method may also include:

[0042] Step 1501: Determine whether the user equipment contains a second license certificate;

[0043] Step 1502: If the user equipment includes a second license credential, match the first hash value with the second hash value corresponding to the second license credential to obtain a first matching result;

[0044] Based on this, step 120 may specifically include:

[0045] Step 1201: If the first matching result indicates that the first hash value does not match the second hash value, or if the electronic device does not contain historical license credentials, install the first license credential in the user device.

[0046] Step 1202: Perform third encryption processing on the first license credential and the first remaining available time of the first license credential to obtain the first encrypted credential information.

[0047] Furthermore, step 1202 mentioned above may specifically include:

[0048] Step 12021: Decrypt the first license credential using the symmetric key to obtain the first encrypted information;

[0049] Step 12022: Decrypt the first encrypted information using the first decryption algorithm corresponding to the second encryption process to obtain device information and service information. The device information includes the media access control address, processor serial number, and system serial number of the user device. The service information includes the license time window.

[0050] Step 12023: If the user device's operating system is within the permitted time window, match the user device information with the device information to obtain a second matching result.

[0051] Step 12024: If the second matching result indicates that the user device information matches the device information, install the first license credential on the user device.

[0052] In addition, after step 1501, the data processing method may further include:

[0053] If the first matching result indicates that the first hash value matches the second hash value, a first prompt message is displayed to inform the user that the license credential is a duplicate credential.

[0054] At this point, the user can be prompted that the first license credential is a duplicate credential and cannot be installed on the user's device.

[0055] For example, if a first license credential is obtained, it is determined whether a second license credential is present in the user device. If the second license credential is present in the user device, to avoid the license credential being extended or reused, the first hash value of the first license credential can be further matched with the second hash value of the second license credential to obtain a first matching result; conversely, if the second license credential is not present in the user device, the first license credential can be directly installed in the user device. Further, if the first matching result indicates that the first hash value and the second hash value do not match, the first license credential can be installed in the user device; conversely, if the first matching result indicates that the first hash value and the second hash value match, the user can be prompted that the first license credential is a duplicate credential and cannot be installed in the user device, thereby ending the data processing flow.

[0056] It should be noted that the process of installing the first license credential in the user equipment in this embodiment of the application can be as follows: First, the first license credential is decrypted using the public key to obtain the decryption result. Next, it is determined whether the decryption result meets the conditions of the preset license credential, i.e., whether the license credential can be parsed normally. If the decryption result meets the conditions of the preset license credential, the first encrypted information is obtained; otherwise, if the decryption result does not meet the conditions of the preset license credential, it indicates that the license credential cannot be parsed normally, thus ending the data processing flow. Furthermore, if the first encrypted information is obtained, it is decrypted to obtain device information and service information, and the device information and service information are verified. If the verification is successful, it indicates that the first license credential has been successfully installed in the user equipment; if the verification fails, it indicates that the installation of the first license credential in the user equipment has failed. The process of verifying device and service information involves checking whether the device's MAC address, CPU serial number, system serial number, and the current time of the operating system are within the license time window specified in the license credential. The license time window includes a start time and an end time. If these parameters are within the license time window, the verification is successful. Conversely, if they are not, the verification fails.

[0057] Furthermore, regarding step 130, in one or more possible embodiments, after installing the first license credential in the user equipment, the difference between the expiration time of the first license credential and the current time of the operating system in the user equipment is used as the first remaining available time T of the first license credential. Next, the authorized functions are extracted, and the device information and service information A, along with the first remaining available time T, are subjected to a third encryption process using a symmetric encryption algorithm and a symmetric key S to obtain the first encrypted credential information B, which is then stored in the database. Furthermore, the device information and service information A, along with the first encrypted credential information B, are subjected to a fourth encryption process using a hash algorithm to obtain the second encrypted credential information C, which is also stored in the database. Then, a timer is started, and every first preset duration, such as 24 hours, the first remaining available time T is reduced to the second remaining available time, i.e., T-1, according to a preset unit, i.e., 1. Then, step 120 is re-executed using the second remaining available time, i.e., T-1, as the first remaining available time, i.e., updating the first encrypted credential information B and the second encrypted credential information C. For example, if the first remaining available time is 14 days, from 10:00 AM on April 1st to 10:00 AM on April 15th, then in the first 24 hours, at 10:00 AM on April 2nd, the first remaining available time is reduced by 1, resulting in a second remaining available time of 13 days. At this point, the second remaining available time can be used as the first remaining available time. Then, in the next 24 hours, at 10:00 AM on April 3rd, the first remaining available time is reduced by 1 again, resulting in a second remaining available time of 12 days. This process continues until the second remaining available time reaches 0, at which point the first license certificate expires, prompting the user to reapply for a license certificate.

[0058] It should be noted that for unauthorized functions, the corresponding function switch will be forcibly turned off, and subsequent control will be carried out through an interceptor to prevent the switch from being turned on.

[0059] Therefore, by adding the recording, correction, and verification of the remaining available days T factor to the verification certificate time, it is further possible to prevent users from extending the use of the license certificate by modifying the system time during the use of the equipment.

[0060] Then, relating to step 140, in one or more possible embodiments, step 140 may specifically include:

[0061] The first license credential and the second remaining usable time are subjected to a fifth encryption process to obtain the updated first encrypted credential information;

[0062] The updated first encrypted credential information and the first license credential are subjected to a sixth encryption process to obtain the updated second encrypted credential information.

[0063] For example, following the above example, when the second remaining available time is 13 days, a fifth encryption process can be performed on the second remaining available time and the first license certificate using a symmetric encryption algorithm to obtain the updated first encrypted certificate information. Then, a sixth encryption process can be performed on the updated first encrypted certificate information and the first license certificate using a hash algorithm to obtain the updated second encrypted certificate information.

[0064] Furthermore, based on the certificate verification cache update process, in one or more possible embodiments, after step 140, the data processing method may further include:

[0065] Step 1601: If an application request is detected sent by an application on the user device, the application request is intercepted. The application request includes a service verification result viewing request, a user login application request, a request to verify whether a license certificate is installed, a request to query the status of the installed license certificate, or a request to query the authorized functions of the installed license certificate.

[0066] Step 1602: Based on the application request, feed back the license credential verification cache result to the application. The license credential verification cache result includes the LicenseVerifyResultBo entity class, which is the verification result of the encapsulated first license credential at a second preset time interval.

[0067] For example, in this embodiment, license credential verification needs to be triggered periodically. Specifically, license credential verification is required before or after a user logs into their device. Before logging in, it checks whether a license credential is installed and whether it is valid or expired. After logging in, it queries the authorized services or functions in the license credential. Unauthorized services or functions are prohibited from access and the user is notified. Simultaneously, the validity and expiration of the license credential are also verified. This allows for interception and verification of each interface on the user device. Specifically, in this embodiment, this is implemented by inheriting the OncePerRequestFilter interceptor from the Spring framework. Thus, the license credential verification process after intercepting a request directly reads the LicenseVerifyResultBo entity class returned by the cached verification result of the license credential. The verification logic also includes a status check of whether the requested function is authorized. Only after successful verification can the user access the corresponding function interface; otherwise, the user is prompted that the accessed function is unauthorized, or the user is directly redirected to the login page due to license credential verification failure, and prompted to reinstall a new license credential.

[0068] Therefore, by using request interception verification and by adding caching and updating of license credential verification results, the speed of license credential verification was improved, and the user experience was enhanced.

[0069] Therefore, before step 1602, it is also necessary to obtain the verification result. Based on this, the data processing may also include:

[0070] Step 1603: At every second preset time interval, obtain the second encrypted information stored in the electronic device. The second encrypted information is generated by the seventh encryption process through the device information of the user device and the service information that the service platform authorizes the user device to access. The seventh encryption process can be the same as the second encryption process, that is, the processing process corresponding to the symmetric encryption algorithm.

[0071] Step 1604: Perform the eighth encryption process on the second encrypted information and the symmetric key to obtain the third license credential;

[0072] Step 1605: Decrypt the first encrypted credential information B using the second decryption algorithm corresponding to the third encryption process to obtain the first license credential and the first remaining usable time T;

[0073] Step 1606: Perform a ninth encryption process on the third license credential and the first remaining available time T to obtain the third encrypted credential information; wherein, the ninth encryption process can be the processing procedure corresponding to the hash algorithm;

[0074] Step 1607: Match the third encrypted credential information with the second encrypted credential information to obtain the third matching result;

[0075] Step 1608: If the third matching result indicates that the third encrypted credential information and the second encrypted credential information match, determine whether the second time of the user device's operating system is within the licensed time window in the service information.

[0076] Step 1609: If it is determined that the second time is within the permitted time window, determine whether the second remaining available time is greater than the preset remaining available time;

[0077] Step 1610: If it is determined that the second remaining available time is greater than the preset remaining available time, a verification result is generated based on the second time and the second remaining available time.

[0078] Step 1611: Encapsulate the verification results at each second preset time interval to obtain the LicenseVerifyResultBo entity class.

[0079] For example, all user requests to access the operating system of a user's device require verification of license credentials and whether the requested function is authorized. Due to the large number of requests, this patent adopts a timed caching method to improve the efficiency of verification. The license credential verification logic is encapsulated and the license credential is verified every 5 minutes. The verification result is encapsulated into a verification result entity class LicenseVerifyResultBo. The license credential verification of interface requests can be directly judged by reading the verification result LicenseVerifyResultBo cache, which greatly improves the verification speed and the efficiency of license credential management.

[0080] Furthermore, the verification process for the license credential is as follows. First, at second preset time intervals, such as 5 minutes, the basic license information is verified (including the device's MAC address, CPU serial number, system serial number, and whether the current system time is within the time period of the certificate's start and end times). This is achieved by obtaining the second encrypted information A1 stored in the electronic device, which may include device information encrypted using a symmetric encryption algorithm and service information authorized for access by the service platform. Next, the second encrypted information A1 is encrypted using a symmetric encryption algorithm and a symmetric key S to obtain the third license credential. Then, the first encrypted credential information B is decrypted using a second decryption algorithm corresponding to the third encryption to obtain the first license credential and the updated first remaining available time T. Finally, the third license credential and the updated first remaining available time T are encrypted using a hash algorithm to obtain the third encrypted credential information. Finally, the third encrypted credential information is matched with the second encrypted credential information to obtain the third matching result.

[0081] Then, if the third matching result indicates that the third encrypted credential information and the second encrypted credential information match, then it is determined whether the current time is within the license time window, and whether the updated remaining available time T is greater than 0. If both are true, the first license credential is considered to be within the validity period. That is, it is determined whether the second time of the user device's operating system is within the license time window in the service information. If the second time is determined to be within the license time window, it is determined whether the second remaining available time is greater than the preset remaining available time. If the second remaining available time is determined to be greater than the preset remaining available time, a verification result is generated based on the second time and the second remaining available time, so as to encapsulate the verification result at each second preset time interval to obtain the LicenseVerifyResultBo entity class.

[0082] Conversely, if one of the conditions is not met, the certificate is considered to have expired, and the user is prompted to reapply for a license certificate. That is, the data processing method provided in this application embodiment may further include: displaying a second prompt message when the third matching result indicates that the third encrypted certificate information and the second encrypted certificate information do not match, the second time is not within the license time window, or the second remaining available time is less than or equal to the preset remaining available time. The second prompt message is used to prompt the user that the license certificate is an invalid certificate.

[0083] For example, if all conditions are met, the certificate is considered to be within its validity period; if one condition is not met, the certificate is considered to have expired, and the user is prompted to reapply for a license certificate.

[0084] Here, the properties contained in the LicenseVerifyResultBo entity class returned by the validation cache result are as follows: Figure 3 As shown, the authorization function may include at least one.

[0085] Therefore, it is possible to determine in both directions whether the license certificate and the encrypted information in the database, namely the first encrypted certificate information and the second encrypted certificate information, have been tampered with, thereby further improving the security of license certificate management.

[0086] Furthermore, the data processing method provided in this application embodiment may also include initiating a license credential loading process. Based on this, in some other examples, after step 140, the first license credential is a license credential for an application in the user device, and the service information includes a license time window, which includes the license end time of the first license credential. Therefore, the data processing may further include:

[0087] Step 1701: If the application is restarted and the user device includes the first license credential, calculate the third remaining available time of the first license credential based on the third time in the electronic device and the license end time;

[0088] Step 1702: If the third remaining available time is greater than the first remaining available time, adjust the first remaining available time to the third remaining available time.

[0089] Alternatively, in step 1703, if the third remaining available time is less than or equal to the first remaining available time, a third prompt message is displayed. The third prompt message is used to notify the user that the first license certificate has been tampered with.

[0090] Exemplarily, when the program restarts, the license credential needs to be initialized and loaded. Then, if there is a license credential in the user device, the license credential is installed in the user device, and the installation process is as shown above. After the installation is completed, the remaining available duration A of the license credential is calculated based on the system time and the end date of the license credential, and compared with the remaining available duration B parsed from the database. If B > A holds, it may indicate that the user device has stopped running for B - A days, and the value of the remaining available duration is corrected to A. Then, it is judged whether B < A holds. If it holds, it means that the license credential or the database has been tampered with. Updates to the license credential verification cache are triggered for whether the license credential exists, whether the license credential is successfully installed, and whether the license credential is tampered with. When the user requests access, the verification result cache is read and returned to the user according to the prompt information.

[0091] It should be noted that the code for executing the data processing method in the embodiments of the present application can be securely protected through code obfuscation and encryption. Among them, to enhance the protection of the source code and prevent the source code from being decompiled, the data processing method in the embodiments of the present application adopts the method of obfuscation encryption to improve security, that is, proGuard is used to obfuscate the source code, and then the encryption algorithm (DES algorithm) is used to modify the classloader to encrypt the compiled.class file for the core code of license credential management, further strengthening the security of the code.

[0092] In this way, through the technologies of code obfuscation and encryption, the security of the license credential management code is further guaranteed.

[0093] Therefore, the data processing method in this application addresses the shortcomings of existing technologies in managing license credentials on offline user devices by proposing a database-based and cache-and-interceptor-based approach to improve the efficiency of license credential anti-tampering and verification. Specifically, the use of digital envelope encryption and double encryption under asymmetric encryption technology enhances the security of the license credential and the information within it. By verifying the hash algorithm of the uploaded license credential, the system time is prevented from being tampered with before the user repeatedly uploads the license credential, thus avoiding the extension and reuse of the license credential. In addition to verifying the remaining usable time of the license credential, a verification factor for the remaining usable time T is added, further strengthening the prevention of license credential extension and reuse caused by user tampering with the system time. The speed of license credential verification is improved by caching and updating the verification results. The method supports the authorization and control of system functions using license credentials, enabling dynamic management of system function authorization. Through code obfuscation and encryption techniques, the security of license credential management is protected at the source code level. By significantly improving the security of license credential management across multiple dimensions, including license credential information, the license credential itself, database entry information, and source code, the system avoids the reuse and extension of license credentials due to user tampering with system time by adding a remaining available days factor while ensuring security. In addition, the system directly calls the cache of verification results, which greatly improves the verification speed.

[0094] It should be noted that the data processing method provided in this application embodiment can be applied to the offline state of user equipment to prevent users from reusing and extending the use of license certificates by modifying the operating system time of the user equipment.

[0095] Based on the same inventive concept, this application also provides a data processing device. (Specifically combined with...) Figure 4 Please provide a detailed explanation.

[0096] Figure 4 This is a schematic diagram of the structure of a data processing apparatus provided in one embodiment of this application.

[0097] like Figure 4 As shown, this data processing device can be applied to computer equipment, and the data processing device 40 specifically may include:

[0098] The acquisition module 401 is used to acquire a first license credential. The first license credential is generated by the service platform through a first encryption process based on a first encrypted information and a symmetric key. The first encrypted information is generated through a second encryption process, which is generated by the user device's device information and the service information that the service platform authorizes the user device to access. The first license credential is a one-time license credential.

[0099] The encryption module 402 is used to perform a third encryption process on the first license credential and the first remaining available time of the first license credential to obtain the first encrypted credential information; and to perform a fourth encryption process on the first encrypted credential information and the first license credential to obtain the second encrypted credential information.

[0100] The adjustment module 403 is used to reduce the first remaining available time to the second remaining available time at each first preset time interval by a preset unit amount.

[0101] Update module 404 is used to update the first encrypted credential information and the second encrypted credential information based on the second remaining available time.

[0102] The data processing device 40 in the embodiments of this application will be described in detail below.

[0103] In one or more optional embodiments, the data processing device 40 in this application embodiment may further include a first determining module, a first matching module, and a first installing module; wherein,

[0104] The first determining module is used to determine whether the user equipment includes a second license credential, provided that the first license credential corresponds to a first hash value and the first hash value is used to uniquely identify the first license credential.

[0105] The first matching module is used to match the first hash value with the second hash value corresponding to the second license credential when the user device includes the second license credential, so as to obtain the first matching result;

[0106] The first installation module is used to install the first license credential in the user device when the first matching result indicates that the first hash value does not match the second hash value, or the electronic device does not contain historical license credentials.

[0107] The encryption module is also used to perform a third encryption process on the first license credential and the first remaining available time of the first license credential to obtain the first encrypted credential information.

[0108] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a first decryption module, a second matching module, and a second installation module; wherein,

[0109] The first decryption module is used to decrypt the first license credential using a symmetric key to obtain the first encrypted information;

[0110] The first decryption module is also used to decrypt the first encrypted information using a first decryption algorithm corresponding to the second encryption process to obtain device information and service information. The device information includes the media access control address, processor serial number, and system serial number of the user device, and the service information includes a license time window.

[0111] The second matching module is used to match the user device information with the device information when the user device's operating system is within the permitted time window, and obtain the second matching result.

[0112] The second installation module is used to install the first license credential on the user device when the second matching result indicates that the user device information matches the device information.

[0113] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a first display module; wherein,

[0114] The first display module is used to display a first prompt message when the first matching result indicates that the first hash value matches the second hash value. The first prompt message is used to prompt the user that the license credential is a duplicate credential.

[0115] In another or more alternative embodiments, the update module in this application embodiment may be specifically used to perform a fifth encryption process on the first license certificate and the second remaining available time to obtain the updated first encrypted certificate information;

[0116] The updated first encrypted credential information and the first license credential are subjected to a sixth encryption process to obtain the updated second encrypted credential information.

[0117] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include an interception module and a feedback module; wherein,

[0118] The interception module is used to intercept application requests when an application request sent by an application on a user device is detected. Application requests include requests to view service verification results, requests for user login to the application, requests to verify whether license credentials are installed, requests to query the status of installed license credentials, or requests to query the authorized functions of installed license credentials.

[0119] The feedback module is used to provide the application with the license credential verification cache result based on the application request. The license credential verification cache result includes the LicenseVerifyResultBo entity class, which is the verification result of the encapsulated first license credential at a second preset time interval.

[0120] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a second decryption module, a third matching module, a second determining module, a generating module, and an encapsulation module; wherein,

[0121] The acquisition module 401 can also be used to acquire second encrypted information stored in the electronic device at intervals of a second preset time period. The second encrypted information is generated by a seventh encryption process, which is the device information of the user device and the service information that the service platform authorizes the user device to access.

[0122] The encryption module 402 can also be used to perform an eighth encryption process on the second encrypted information and the symmetric key to obtain a third license credential;

[0123] The second decryption module is used to decrypt the first encrypted credential information B using the second decryption algorithm corresponding to the third encryption process, to obtain the first license credential and the first remaining usable time T.

[0124] The encryption module 402 can also be used to perform a ninth encryption process on the third license credential and the first remaining available time T to obtain the third encrypted credential information;

[0125] The third matching module is used to match the third encrypted credential information with the second encrypted credential information to obtain the third matching result;

[0126] The second determining module is used to determine whether the second time of the user device's operating system is within the licensed time window in the service information, when the third matching result indicates that the third encrypted credential information and the second encrypted credential information match.

[0127] The second determining module can also be used to determine whether the second remaining available time is greater than the preset remaining available time when the second time is determined to be within the permitted time window.

[0128] The generation module is used to generate a verification result based on the second time and the second remaining available time when it is determined that the second remaining available time is greater than the preset remaining available time.

[0129] The encapsulation module is used to encapsulate the verification results at each second preset time interval to obtain the LicenseVerifyResultBo entity class.

[0130] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a second display module; wherein,

[0131] The second display module is used to display a second prompt message when the third matching result indicates that the third encrypted credential information and the second encrypted credential information do not match, the second time is not within the licensed time window, or the second remaining available time is less than or equal to the preset remaining available time. The second prompt message is used to prompt the user that the license credential is an invalid credential.

[0132] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a computing module; wherein,

[0133] The calculation module is used to calculate the third remaining available time of the first license credential based on the third time in the electronic device and the license end time when the application is restarted and the user device contains the first license credential. The service information includes a license time window, which includes the license end time of the first license credential.

[0134] The adjustment module 403 can also be used to adjust the first remaining available time to the third remaining available time when the third remaining available time is greater than the first remaining available time.

[0135] In another or more alternative embodiments, the data processing device 40 in this application embodiment may further include a third display module; wherein,

[0136] The third display module is used to display a third prompt message when the third remaining available time is less than or equal to the first remaining available time. The third prompt message is used to remind the user that the first license certificate has been tampered with.

[0137] Therefore, multiple encryption processes can be applied to the device information of the user device and the service information that the service platform authorizes the user device to access, resulting in a first license credential. This improves the security of the first license credential itself. Furthermore, by using a one-time first license credential, the reuse and extension of the license credential's use can be prevented. Additionally, by setting a preset time interval, the remaining available time is reduced, and the first and second encrypted credential information is updated to verify the remaining available days of the first license credential. This further prevents certificate reuse due to user tampering with the system time, optimizes the caching information of the first license credential, improves the accuracy of license credential management, reduces the risk of unauthorized authorization, and enhances the security of license credential management.

[0138] Based on the same inventive concept, this application also provides a data processing device. (Specifically combined with...) Figure 5 Please provide a detailed explanation.

[0139] Figure 5 This is a schematic diagram of the structure of a data processing device provided in one embodiment of this application.

[0140] like Figure 5 As shown, the data processing device may include at least one of the following as described in the embodiments of this application: an electronic device, a server. The data processing device may include a processor 501 and a memory 502 storing computer program instructions.

[0141] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0142] Memory 502 may include a large-capacity memory for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory. In a particular embodiment, memory 502 includes solid-state storage (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.

[0143] The processor 501 implements any of the data processing methods described in the above embodiments by reading and executing computer program instructions stored in the memory 502.

[0144] In one example, the data processing device may further include a communication interface 503 and a bus 510. Wherein, as... Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 510 and complete communication with each other.

[0145] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0146] Bus 510 includes hardware, software, or both, that couples components of a flow control device together. For example, and not limitingly, the bus may include Accelerated Graphics Gateway (AGP) or other graphics buses, Enhanced Industry Standard Architecture (EISA) buses, Front Side Bus (FSB), HyperTransport (HT) interconnects, Industry Standard Architecture (ISA) buses, Infinite Bandwidth Interconnects, Low Pin Count (LPC) buses, memory buses, Microchannel Architecture (MCA) buses, Peripheral Component Interconnect (PCI) buses, PCI-Express (PCI-X) buses, Serial Advanced Technology Attachment (SATA) buses, Video Electronics Standards Association Local (VLB) buses, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 510 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.

[0147] The data processing device can execute the data processing method described in the embodiments of this application, thereby achieving the combination Figures 1 to 4 The data processing methods and apparatus described.

[0148] Furthermore, in conjunction with the data processing methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores computer program instructions; when executed by a processor, these computer program instructions implement any of the data processing methods in the above embodiments.

[0149] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0150] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0151] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0152] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A data processing method, characterized in that, include: Obtain a first license credential. The first license credential is generated by the service platform using the private key in an asymmetric encryption algorithm to perform a first encryption process on the symmetric key and the first encrypted information. The first encrypted information is generated by performing a second encryption process on the device information of the user device and the service information that the service platform authorizes the user device to access using a symmetric encryption algorithm and the symmetric key. The first license credential is a one-time license credential. The first license credential and the first remaining available time of the first license credential are subjected to a third encryption process to obtain the first encrypted credential information; and the first encrypted credential information and the first license credential are subjected to a fourth encryption process to obtain the second encrypted credential information. At each first preset time interval, the first remaining available time is reduced to the second remaining available time according to a preset unit amount; Based on the second remaining available time, update the first encrypted credential information and the second encrypted credential information; Every second preset time interval, the first license credential is verified, and a verification result is generated. The verification process is as follows: Obtain the second encrypted information stored in the user equipment, wherein the second encrypted information is generated by the device information of the user equipment and the service information that the service platform authorizes the user equipment to access through a seventh encryption process; The second encrypted information and the symmetric key are subjected to an eighth encryption process to obtain the third license credential. The first encrypted credential information is decrypted using the second decryption algorithm corresponding to the third encryption process to obtain the first license credential and the first remaining usable time T. The third license credential and the first remaining available time T are subjected to a ninth encryption process to obtain the third encrypted credential information; The third encrypted credential information and the second encrypted credential information are matched to obtain a third matching result; If the third matching result indicates that the third encrypted credential information and the second encrypted credential information match, determine whether the second time of the user equipment's operating system is within the licensed time window in the service information; If it is determined that the second time is within the permitted time window, it is determined whether the second remaining available time is greater than the preset remaining available time; If it is determined that the second remaining available time is greater than the preset remaining available time, a verification result is generated based on the second time and the second remaining available time.

2. The method according to claim 1, characterized in that, The first license credential corresponds to a first hash value, which is used to uniquely identify the first license credential; before performing a third encryption process on the first license credential and its first remaining usable time to obtain the first encrypted credential information, the method further includes: Determine whether the user equipment includes a second license credential; If the user equipment includes a second license credential, the first hash value is matched with the second hash value corresponding to the second license credential to obtain a first matching result; The third encryption process, which involves encrypting the first license credential and its first remaining usable duration to obtain first encrypted credential information, includes: If the first matching result indicates that the first hash value and the second hash value do not match, or if the user equipment does not contain historical license credentials, the first license credential is installed in the user equipment, and the first license credential and the first remaining available time of the first license credential are subjected to third encryption processing to obtain first encrypted credential information.

3. The method according to claim 2, characterized in that, Installing the first license credential in the user equipment includes: The first license credential is decrypted using the public key to obtain the first encrypted information; The first encrypted information is decrypted using the first decryption algorithm corresponding to the second encryption process to obtain the device information and the service information. The device information includes the media access control address, processor serial number, and system serial number of the user equipment. The service information includes a license time window. If the operating system of the user equipment is within the licensed time window at the first moment, the user equipment information of the user equipment is matched with the equipment information to obtain a second matching result; If the second matching result indicates that the user equipment information matches the device information, the first license credential is installed on the user equipment.

4. The method according to claim 2, characterized in that, After determining whether the user equipment includes a second license credential, the method further includes: If the first matching result indicates that the first hash value matches the second hash value, a first prompt message is displayed, which is used to prompt the user that the first license credential is a duplicate credential.

5. The method according to claim 1, characterized in that, The step of updating the first encryption credential information and the second encryption credential information based on the second remaining available time includes: The first license credential and the second remaining available time are subjected to a fifth encryption process to obtain the updated first encrypted credential information; The updated first encrypted credential information and the first license credential are subjected to a sixth encryption process to obtain the updated second encrypted credential information.

6. The method according to claim 1 or 2, characterized in that, After updating the first encrypted credential information and the second encrypted credential information based on the second remaining available time, the method further includes: If an application request is detected from an application in the user device, the application request is intercepted. The application request includes a service verification result viewing request, a user login request, a request to verify whether a license certificate is installed, a request to query the status of an installed license certificate, or a request to query the authorized functions of an installed license certificate. Based on the application request, the license credential verification cache result is fed back to the application. The license credential verification cache result includes a LicenseVerifyResultBo entity class, which is the verification result of the encapsulated first license credential at a second preset time interval.

7. The method according to claim 6, characterized in that, Before sending the license credential verification cache result back to the application based on the application request, the method further includes: The verification results at each interval of the second preset time are encapsulated to obtain the LicenseVerifyResultBo entity class.

8. The method according to claim 7, characterized in that, The method further includes: If the third matching result indicates that the third encrypted credential information and the second encrypted credential information do not match, or if the second time is not within the licensed time window, or if the second remaining available time is less than or equal to the preset remaining available time, a second prompt message is displayed. The second prompt message is used to remind the user that the first license credential is an invalid credential.

9. The method according to claim 1, characterized in that, The first license credential is a license credential for an application in the user equipment; the service information includes a license time window, which includes the license expiration time of the first license credential; the method further includes: In the case where the application is restarted and the user device includes the first license credential, the third remaining available time of the first license credential is calculated based on the third time in the user device and the license end time; If the third remaining available time is less than the first remaining available time, the first remaining available time will be adjusted to the third remaining available time.

10. The method according to claim 9, characterized in that, The method further includes: If the third remaining available time is greater than the first remaining available time, a third prompt message will be displayed, which is used to prompt the user that the first license certificate has been tampered with.

11. A data processing apparatus, characterized in that, include: The acquisition module is used to acquire a first license credential. The first license credential is generated by the service platform using the private key in the asymmetric encryption algorithm to perform a first encryption process on the symmetric key and the first encrypted information. The first encrypted information is generated by performing a second encryption process on the device information of the user device and the service information that the service platform authorizes the user device to access through the symmetric encryption algorithm and the symmetric key. The first license credential is a one-time license credential. The encryption module is used to perform a third encryption process on the first license credential and the first remaining available time of the first license credential to obtain first encrypted credential information; and to perform a fourth encryption process on the first encrypted credential information and the first license credential to obtain second encrypted credential information. The adjustment module is used to reduce the first remaining available time to a second remaining available time at each first preset time interval by a preset unit amount; The update module is used to update the first encrypted credential information and the second encrypted credential information based on the second remaining available time. The data processing device further includes a second decryption module, a third matching module, a second determination module, and a generation module; The acquisition module is further configured to acquire second encrypted information stored in the user equipment at intervals of a second preset time period. The second encrypted information is generated by a seventh encryption process through the device information of the user equipment and the service information that the service platform authorizes the user equipment to access. The encryption module is further configured to perform an eighth encryption process on the second encrypted information and the symmetric key to obtain a third license credential; The second decryption module is used to decrypt the first encrypted credential information using a second decryption algorithm corresponding to the third encryption process, to obtain the first license credential and the first remaining available time T; The encryption module is further configured to perform a ninth encryption process on the third license credential and the first remaining available time T to obtain the third encrypted credential information; The third matching module is used to match the third encrypted credential information and the second encrypted credential information to obtain a third matching result; The second determining module is used to determine whether the second time of the user equipment's operating system is within the licensed time window in the service information when the third matching result indicates that the third encrypted credential information and the second encrypted credential information match; The second determining module is further configured to determine whether the second remaining available time is greater than a preset remaining available time when the second time is determined to be within the permitted time window; The generation module is used to generate a verification result based on the second time and the second remaining available time when it is determined that the second remaining available time is greater than the preset remaining available time.

12. A computer device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the data processing method as described in any one of claims 1-10.