Software authorization method, device, equipment and medium based on multi-node computer

By using a combination of symmetric and asymmetric encryption algorithms in a multi-node computer cluster, the flexibility and security of software authorization management are achieved, solving the problems of inefficient deployment and waste of resources in traditional methods, ensuring the consistency of software versions and rationality of resource utilization.

CN119808030BActive Publication Date: 2025-05-16CALCULATION AERODYNAMICS INST CHINA AERODYNAMICS RES & DEV CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510286855.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-05-16
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

Traditional software deployment methods are time-consuming and resource-consuming in multi-node computer clusters, making it difficult to ensure the consistency of software versions and configuration correctness. The traditional authorization mechanism cannot consider the utilization of multi-node resources and cannot limit the execution of software tasks.

Method used

Using a combination of symmetric encryption algorithms and asymmetric encryption algorithms, hardware information is obtained through the authorization management server, customized license data is constructed, encrypted transmission and decryption verification is performed, and resources are allocated in combination with the cluster scheduling system to realize authorization verification and resource management.

Benefits of technology

It improves the software deployment efficiency and authorization management flexibility of multi-node computer clusters, ensures the consistency of software versions and the security of resource utilization, and prevents unauthorized software usage behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119808030B_ABST
    Figure CN119808030B_ABST
Patent Text Reader

Abstract

The present application discloses a software authorization method, device, equipment and medium based on a multi-node computer, and relates to the field of software authorization verification, including: an authorization management server sends target information of a management node to a software operator, so that the software operator constructs license data based on the target information, and returns the encrypted license data to the authorization management server; decrypts the encrypted license data, obtains and saves the license data, receives authorization application information sent by client software, and performs authorization verification based on the authorization application information and the license data; if the verification is passed, obtains a node resource file, integrates the node resource file and the authorization license information, and obtains computing resource license data; encrypts the computing resource license data, and sends the encrypted data to the client software, so that the client software decrypts it, obtains the computing resource license data, and runs the target job based on the computing resource license data. The authorization management of the software is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of software authorization verification, and in particular to a software authorization method, device, equipment and medium based on a multi-node computer. Background Art

[0002] With the rapid growth of big data and high-performance computing needs, it is difficult for a single computer to meet the needs of complex computing tasks. Therefore, computer clusters that connect multiple computing nodes have become the standard architecture for processing complex computing tasks. In a computer cluster environment with multiple nodes, software deployment and authorization management face many challenges. First, traditional software deployment methods usually rely on manual configuration and installation, which may lead to huge time and resource consumption in clusters involving a large number of computing nodes. In addition, as the complexity of software components and services increases, it becomes increasingly difficult to ensure the consistency of software versions and correct configuration on all nodes. Traditional software authorization mechanisms are usually designed for single-machine environments, and cannot consider the resource utilization of multiple computing nodes by software, and cannot restrict the execution of software tasks through authorization. Summary of the invention

[0003] In view of this, the purpose of the present invention is to provide a software authorization method, device, equipment and medium based on a multi-node computer, which can realize the authorization management of software, improve the flexibility of authorization management, and take security into consideration. The specific scheme is as follows:

[0004] In a first aspect, the present application discloses a software authorization method based on a multi-node computer, which is applied to an authorization management server, comprising:

[0005] Acquire target information of the management node, send the target information to the software operator, so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server;

[0006] Decrypting the received encrypted license data, acquiring and saving the license data, receiving authorization application information sent by the client software when the client software is running, and performing authorization verification on the client software based on the authorization application information and the license data;

[0007] If the verification is successful, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain computing resource license data;

[0008] The computing resource license data is encrypted based on the symmetric encryption algorithm, and the corresponding encrypted data is sent to the client software so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data.

[0009] Optionally, the target information includes any one or a combination of a media access control address, a CPU serial number, a hard disk serial number, and basic input / output system information; the license data includes software version, maximum upgradeable version, authorized software function modules, authorization initial time, authorization end time, software executable nodes, the number of CPU cores that the software can use, the number of hosts that can be installed, and the target information.

[0010] Optionally, the process in which the software operator encrypts the license data based on a symmetric encryption algorithm and returns the corresponding encrypted license data to the authorization management server includes:

[0011] generating a first symmetric encryption key based on a symmetric encryption algorithm, and encrypting the license data using the first symmetric encryption key to obtain encrypted license data;

[0012] Encrypting the first symmetric encryption key using a public key of a first asymmetric key generated based on an asymmetric encryption algorithm to obtain a first encrypted key;

[0013] Performing a hash operation on the license data using a target hash function to obtain a first hash value, and encrypting the first hash value using a private key of a second asymmetric key generated based on an asymmetric encryption algorithm to generate a corresponding digital signature;

[0014] A license file is constructed by using the encrypted license data, the first encrypted key and the digital signature, and the license file is returned to the authorization management server.

[0015] Optionally, decrypting the received encrypted license data, acquiring and saving the license data, includes:

[0016] Decrypting the first encrypted key in the license file using the private key of the first asymmetric key to obtain the first symmetric encryption key;

[0017] decrypting the encrypted license data using the first symmetric encryption key to obtain the license data;

[0018] Performing a hash operation on the license data by using the target hash function to generate a second hash value, and decrypting the digital signature in the license file by using the public key of the second asymmetric key to obtain the first hash value;

[0019] The first hash value is compared with the second hash value. If they are the same, it indicates that the signature verification is passed and the license data is saved.

[0020] Optionally, the receiving the authorization application information sent by the client software, and performing authorization verification on the client software based on the authorization application information and the license data, includes:

[0021] Receive the authorization application information sent by the client software, and extract the software information in the authorization application information; the software information includes version information, software function module information and applied node quantity information;

[0022] The authorization verification of the client software is completed by comparing the software information with the license data.

[0023] Optionally, the acquiring the node resource file allocated by the cluster scheduling system based on the authorization application information includes:

[0024] Based on the node quantity information of the software application in the authorization application information and the current resource status of the cluster, a computing node application request is sent to the cluster scheduling system so that after the cluster scheduling system receives the computing node application request, it allocates the node resource file and returns the node resource file to the authorization management server.

[0025] Optionally, encrypting the computing resource license data based on the symmetric encryption algorithm and sending the corresponding encrypted data to the client software so that the client software decrypts the encrypted data to obtain the computing resource license data includes:

[0026] Generate a second symmetric encryption key based on the symmetric encryption algorithm, and use the second symmetric encryption key to encrypt the computing resource permission data to obtain encrypted data;

[0027] Encrypting the second symmetric encryption key using a public key of a third asymmetric key generated based on an asymmetric encryption algorithm to obtain a second encrypted key;

[0028] The encrypted data and the second encrypted key are sent to the client software so that the client software can use the private key of the third asymmetric key to decrypt the second encrypted key to obtain the second symmetric encryption key, and decrypt the encrypted data by the second symmetric encryption key to obtain the computing resource license data.

[0029] In a second aspect, the present application discloses a software authorization device based on a multi-node computer, which is applied to an authorization management server, comprising:

[0030] An information sending module, used for acquiring target information of the management node, sending the target information to the software operator, so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server;

[0031] An authorization verification module, used to decrypt the received encrypted license data, obtain and save the license data, receive the authorization application information sent by the client software when the client software is running, and perform authorization verification on the client software based on the authorization application information and the license data;

[0032] A data acquisition module, for acquiring the node resource file allocated by the cluster scheduling system based on the authorization application information if the verification is passed, and integrating the node resource file with the verified authorization license information to obtain computing resource license data;

[0033] The encrypted data sending module is used to encrypt the computing resource license data based on the symmetric encryption algorithm, and send the corresponding encrypted data to the client software so that the client software can decrypt the encrypted data, obtain the computing resource license data, and run the target job based on the authorization information and node information in the computing resource license data.

[0034] In a third aspect, the present application discloses an electronic device, comprising:

[0035] Memory, used to store computer programs;

[0036] The processor is used to execute the computer program to implement the aforementioned software authorization method based on a multi-node computer.

[0037] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the software authorization method based on a multi-node computer as described above is implemented.

[0038] In this application, the authorization management server obtains the target information of the management node, sends the target information to the software operator, so that the software operator constructs the license data based on the target information, encrypts the license data based on the symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server; then decrypts the received encrypted license data, obtains and saves the license data, receives the authorization application information sent by the client software when the client software is running, and performs authorization verification on the client software based on the authorization application information and the license data; if the verification is passed, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain the computing resource license data; finally, the computing resource license data is encrypted based on the symmetric encryption algorithm, and the corresponding encrypted data is sent to the client software, so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data. It can be seen that this application collects information, verifies authorization licenses, and applies for cluster resources through the authorization management server. One authorization can be effective for multiple software versions and multiple software running instances. This improves deployment efficiency and the flexibility of authorization management. At the same time, data encryption is used to ensure the security of license data during data transmission. This enables the provision of operating licenses and resource usage licenses to client software before the software is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0040] Figure 1 A software authorization method process based on a multi-node computer disclosed in this application;

[0041] Figure 2 A schematic diagram of the structure of an authorization management server disclosed in this application;

[0042] Figure 3 A schematic diagram of an authorization process disclosed in this application;

[0043] Figure 4 A schematic diagram of a license file generation process disclosed in this application;

[0044] Figure 5 A schematic diagram of a decryption process disclosed in this application;

[0045] Figure 6 A schematic diagram of a data structure disclosed in this application;

[0046] Figure 7 A schematic diagram of the structure of a software authorization device based on a multi-node computer disclosed in this application;

[0047] Figure 8 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION

[0048] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0049] Traditional software deployment methods usually rely on manual configuration and installation, which may lead to huge time and resource consumption in clusters involving a large number of computing nodes. In addition, as the complexity of software components and services increases, it becomes increasingly difficult to ensure the consistency of software versions and configuration correctness on all nodes. Traditional software authorization mechanisms are usually designed for stand-alone environments, and cannot take into account the resource utilization of multiple computing nodes by the software, and cannot restrict the task execution of the software through authorization. In order to solve the above technical problems, the present application discloses a software authorization method, device, equipment and medium based on a multi-node computer, which can realize the authorization management of software, improve the flexibility of authorization management, and take into account security.

[0050] See also Figure 1 As shown, the embodiment of the present invention discloses a software authorization method based on a multi-node computer, which is applied to an authorization management server and includes:

[0051] Step S11, obtaining target information of the management node, and sending the target information to the software operator, so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server.

[0052] In this embodiment, the management node is the node where the main service programs and software run in the cluster; the client software uses other nodes in the cluster to perform computing tasks, such nodes are called computing nodes. The authorization server is deployed on the management node to authorize the software and manage the computing nodes where the software runs, and communicate with the software operator to obtain the license. The relevant structure of the authorization management server is as follows: Figure 2As shown. First, the authorization server collects hardware information, obtains the MAC (Media Access Control) address, CPU (Central Processing Unit) serial number (optional), hard disk serial number (optional), and BIOS (Basic Input Output System) information (optional) of the management node, and sends it to the operator. It provides key hardware binding basis for the subsequent generation of customized licenses, ensures that the license is associated with a specific hardware environment, and improves the security and pertinence of the authorization. After the operator receives the management node hardware information sent by the authorization server, it begins to organize it into a structured license data structure according to the established authorization rules and business logic. The license data structure is as follows:

[0053] Software version: specifies the specific software version corresponding to the authorization, so as to distinguish software products with different iterations;

[0054] Maximum upgradeable version: the maximum version that can be upgraded free of charge within the authorization period;

[0055] Software module information: details the authorized software function modules;

[0056] Authorization start-end time: The validity period of the license is limited by a timestamp (usually in the form of milliseconds or seconds calculated from a certain standard time point, based on the time management mechanism built into the operating system or database). After the end time, the software cannot be used legally.

[0057] Available nodes: specifies the number of nodes in the entire cluster on which the software is allowed to run;

[0058] Number of available cores: Taking into account the utilization of hardware resources, the number of CPU cores that the software can use is limited;

[0059] Number of hosts allowed to install: the number of hosts the software is allowed to be installed on;

[0060] Hardware information: Receives hardware information from the licensing server to ensure that the license is only valid for a single user.

[0061] The process in which the software operator encrypts the license data based on a symmetric encryption algorithm and returns the corresponding encrypted license data to the authorization management server includes: generating a first symmetric encryption key based on a symmetric encryption algorithm, encrypting the license data using the first symmetric encryption key to obtain the encrypted license data; encrypting the first symmetric encryption key using the public key of the first asymmetric key generated based on the asymmetric encryption algorithm to obtain the first encrypted key; performing a hash operation on the license data using a target hash function to obtain a first hash value, and encrypting the first hash value using the private key of the second asymmetric key generated based on the asymmetric encryption algorithm to generate a corresponding digital signature; constructing a license file through the encrypted license data, the first encrypted key and the digital signature, and returning the license file to the authorization management server. It should also be pointed out that the operator generates three sets of asymmetric keys based on the RSA asymmetric encryption algorithm, which are hereinafter referred to as RSA Key1, RSA Key2 and RSA Key3. Among them, RSA Key1 is used to encrypt the license information, its public key is stored in the operator's issuance program, and the private key is embedded in the authorization server when it is released. RSA Key2 is used for digital signature. Its private key is stored in the operator's issuance program, and the public key is released to the public. RSA Key3 is used when the authorization server sends resource license files to the client software. The public key is stored in the authorization server, and the private key is stored in the client software.

[0062] Step S12: decrypt the received encrypted license data, obtain and save the license data, receive the authorization application information sent by the client software when the client software is running, and perform authorization verification on the client software based on the authorization application information and the license data.

[0063] In this embodiment, after receiving the license file, the authorization server starts to extract the license data and verify the digital signature. The first encrypted key in the license file is decrypted using the private key of the first asymmetric key to obtain the first symmetric encryption key; the encrypted license data is decrypted using the first symmetric encryption key to obtain the license data; the license data is hashed using the target hash function to generate a second hash value, and the digital signature in the license file is decrypted using the public key of the second asymmetric key to obtain the first hash value; the first hash value is compared with the second hash value, and if they are the same, it indicates that the signature verification has passed and the license data is saved.

[0064] When the client software is running, it provides its own version information and module information to the authorization server through the network communication mechanism, and clearly applies for operation authorization (indicating that the software currently needs to be verified for legality to start running) and node authorization (requesting the allocation of a certain number of cluster computing nodes to perform tasks, and the request will contain the expected number of nodes to be used). After receiving the software authorization application, the authorization server first extracts the key content such as version information, module information and the number of nodes applied for. Then, the corresponding software version, modules allowed to be used and the number of authorized nodes in the license scope are obtained from the license information stored in itself for comparison and verification. That is, the authorization application information sent by the client software is received, and the software information in the authorization application information is extracted; the software information includes version information, software function module information and the number of nodes applied for; the authorization verification of the client software is completed by comparing the software information with the license data. Specifically, through logical judgment operations such as string comparison (for version information), set comparison (for module information, determine whether the applied modules are all in the module set allowed by the license) and value comparison (for the number of nodes applied and the number of nodes authorized by the license), it is determined whether the software application is within the scope of the license.

[0065] At the same time, if the authorization server receives an application from this host for the first time, it will obtain the IP (Internet Protocol) address of this host through the network communication related interface, record the IP address in the authorized host list, and set the corresponding lock mark (represented by a Boolean value). At the same time, the number of hosts allowed to be installed in the license will be reduced by one (by reading the corresponding numerical field in the license and performing a subtraction operation to update the stored value), so as to limit the deployment of the software within the licensed number of hosts to prevent over-range use.

[0066] Step S13: If the verification is successful, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain computing resource license data.

[0067] In this embodiment, if the authorization verification is successful, the authorization server applies for computing nodes from the cluster scheduling system based on the number of nodes applied for by the software and the current resource status of the cluster. After receiving the application, the cluster scheduling system allocates appropriate computing nodes to the software according to its own resource allocation algorithm, and returns the allocated node resource files to the authorization server. The authorization server integrates the previously verified authorization license information (including the various authorization details that the software can use in the license) and the applied node resource files, organizes them according to the data structure, and forms computing resource license data (plain text).

[0068] Step S14: encrypt the computing resource license data based on the symmetric encryption algorithm, and send the corresponding encrypted data to the client software so that the client software can decrypt the encrypted data, obtain the computing resource license data, and run the target job based on the authorization information and node information in the computing resource license data.

[0069] In this embodiment, the present application uses asymmetric encryption to prevent users from using packet interception tools to generate illegal computing resource license packages, thereby bypassing the authorization server. Figure 3 , the authorization server uses the AES (Advanced Encryption Standard) symmetric encryption algorithm to generate a 128-bit random binary symmetric key sequence AES-Key2, and uses the symmetric encryption key to encrypt the integrated computing resource license data through the symmetric encryption algorithm to generate computing resource license data (ciphertext). Use RSA-Key3-public to encrypt AES-Key2 and convert AES-Key2 into ciphertext. Finally, integrate the computing resource license data packet. The data packet content includes the header identifier, the symmetric key area (ciphertext), and the license information body area (ciphertext). Through the network communication mechanism, the computing resource license data packet is returned to the client software. After the client software receives the computing resource license file returned by the authorization server, it uses RSA-Key3-private to decrypt the data packet and obtain the authorization details that it can use and the information related to the assigned node. The software sends the job to the assigned node and runs the job according to the number of cores applied for at the beginning.

[0070] In addition, if the software is deployed on multiple hosts or multiple versions of the software are deployed, the client software will regularly confirm the authorization status to the authorization server before startup and during operation (using a secure network communication method to regularly send authorization query messages containing its own software identification, version, host IP, etc.). After receiving these query messages, the authorization server will compare the license information and the authorized host list and other related data again to determine whether the host where the software is located and the software version are within the license scope. If it is not allowed by the license (for example, the host is not in the authorized host list or the software version does not comply with the license regulations), the authorization management server will send a stop operation instruction to the software (the message contains the reason for stopping, operation code, etc.). After receiving the instruction, the software will immediately stop the job execution and release the occupied resources (close the connection with the node, clean up temporary files, etc.), so as to strictly enforce the authorization restrictions, ensure that the use of the software fully complies with the authorization requirements of the license, and prevent unauthorized software use.

[0071] In summary, in this application, the authorization management server obtains the target information of the management node, sends the target information to the software operator, so that the software operator constructs the license data based on the target information, encrypts the license data based on the symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server; then decrypts the received encrypted license data, obtains and saves the license data, receives the authorization application information sent by the client software when the client software is running, and performs authorization verification on the client software based on the authorization application information and the license data; if the verification is passed, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain the computing resource license data; finally, the computing resource license data is encrypted based on the symmetric encryption algorithm, and the corresponding encrypted data is sent to the client software, so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data. It can be seen that this application collects information, verifies authorization licenses, and applies for cluster resources through the authorization management server. One authorization can be effective for multiple software versions and multiple software running instances. This improves deployment efficiency and the flexibility of authorization management. At the same time, data encryption is used to ensure the security of license data during data transmission. This enables the provision of operating licenses and resource usage licenses to client software before the software is executed.

[0072] Based on the previous embodiment, it can be known that the operator of this application will first encrypt the license file when generating the license file, and send the encrypted license file to the authorization management server, which will decrypt the encrypted license file after receiving it. The specific encryption and decryption process will be described in detail below.

[0073] The process of generating a license file is as follows Figure 4 The detailed description is as follows:

[0074] The software operator uses the AES symmetric encryption algorithm to generate a 128-bit random binary key sequence based on a pseudo-random number generator, hereinafter referred to as AES Key1; the symmetric encryption key is used to encrypt the integrated license original information (plaintext) through the symmetric encryption algorithm to generate the license information body (ciphertext).

[0075] Use RSA Key1 public to encrypt AES Key1, and convert AES Key1 into ciphertext through encryption mathematical operations corresponding to the public key. The symmetric key encrypted with the public key can only be decrypted by the corresponding private key, thus ensuring the security of the symmetric key during transmission.

[0076] Use the SHA 256 hash function to hash the original data (plain text) of the license to generate the hash value HASH-1 of the data. Use RSA Key2 private to encrypt the hash value HASH-1 to generate a digital signature (ciphertext). Finally, integrate the authorization license data file. The file contains the header identifier, symmetric key area (ciphertext), license information main area (ciphertext), and digital signature (ciphertext). Package and generate a binary license file and return the license to the authorization management server.

[0077] After receiving the license file, the authorization server begins to extract the license data and verify the digital signature. Figure 5 The detailed description is as follows:

[0078] Use the RSA Key1 private pre-embedded in the program to decrypt the symmetric key area of ​​the license file and obtain the symmetric key AES Key1;

[0079] Use AES Key1 to decrypt the license information main area to obtain the license data (plain text);

[0080] Use the SHA 256 hash function to perform a hash operation on the license data (plain text) to generate a hash value HASH-2 of the data;

[0081] Use the public RSA Key2 public to decrypt the digital signature and obtain the original hash value HASH-1 of the data. Compare HASH-1 with HASH-2. If the two are the same, the signature verification is successful, indicating that the data has not been tampered with and is indeed signed by the private key holder.

[0082] After the signature verification is passed, the authorization server saves the license information.

[0083] The technical solution of the present application will be described clearly and completely below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments.

[0084] The user purchased a one-year use period of Software A version 1.0.0 from the operator of Software A, and can upgrade to any version before 2.0.0 (excluding 2.0.0) for free during the use period of the software, and the maximum number of running instances of Software A does not exceed 10, the maximum number of nodes used for calculation is 208, and the maximum number of CPU cores used is 9984. The following example is used to illustrate the specific implementation process, and the following embodiments are only descriptive and non-restrictive, and cannot be used to limit the scope of protection of this application.

[0085] First, in a cluster environment, install and deploy the authorization management server on the management node. The authorization server collects hardware information and obtains the management node MAC address: "00-50-56-C0-00-01", CPU serial number: "BFEBFBFF00040651". The authorization server sends the hardware information to the operator of software A. After receiving the hardware information sent by the authorization server, the operator of software A begins to build the license information content. The various fields of the license data are organized in a custom JSON (JavaScript Object Notation) format, and the data structure is as follows: Figure 6 .

[0086] The operator of software A first uses the symmetric encryption algorithm AES to generate a 128-bit symmetric encryption key: AES-Key1. The symmetric encryption key is used to encrypt the above-integrated JSON format license original information.

[0087] Next, the symmetric encryption key just generated is encrypted using the RSA-Key1-public in custody. The operator uses the SHA-256 hash function to hash the original license data (plain text) to generate the hash value HASH-1 of the data. The hash value HASH-1 is encrypted using RSA-Key2-private to generate a digital signature. Finally, the encrypted symmetric encryption key, the symmetric encrypted license information, and the digital signature are used to generate the final software A license file and return the license to the authorization management server.

[0088] After receiving the license file, the authorization server uses the RSA-Key1-private in its custody to decrypt the symmetric key area of ​​the license file and obtain the symmetric key AES-Key1. It then uses the symmetric key AES-Key1 to decrypt the main area of ​​the license information and obtain the license data (plain text). It uses the SHA-256 hash function to perform a hash operation on the license data (plain text) to generate the hash value HASH-1 of the data. It obtains the public RSA-Key2-public from the operator's official website or other places to decrypt the digital signature and obtain the original hash value HASH-2 of the data. It compares HASH-1 with HASH-2. If the two are the same, the signature verification passes and the license file is valid.

[0089] When a user starts software A on a host in the cluster, software A sends authorization request information to the authorization management server:

[0090] Software version: "1.0.0";

[0091] Module: ["A1","A2"];

[0092] Number of nodes: 10

[0093] Number of computing cores: 960

[0094] After receiving the software authorization application, the authorization server compares and verifies the license information stored in itself:

[0095] The version used is "1.0.0" which is consistent with the license version;

[0096] Function modules "A1, A2" are within the license scope "A1, A2, A3";

[0097] The IP address of the host where software A is currently running (for example, "192.168.1.100") is not recorded in the authorized host list;

[0098] The number of nodes applied for, 20, is less than the maximum number of nodes allowed by the license, 100, and the remaining idle nodes are greater than 20;

[0099] The requested number of computing cores, 960, is less than the maximum number of cores allowed by the license, 9984, and the number of remaining idle cores is greater than 960.

[0100] If the authorization verification succeeds, the IP address of the host running software A is recorded in the authorized host list, and the number of executable software is reduced by one. At the same time, the authorization server applies for a computing node from the cluster scheduling system. After receiving the application, the cluster scheduling system allocates a suitable computing node to the software according to its own resource allocation algorithm, and returns the allocated node resources to the authorization server.

[0101] The authorization server integrates the previously verified authorization license information (including the various authorization details that the software in the license can use) and the applied node resource files to form computing resource license data (plain text). The authorization server generates a symmetric key AES-Key2 based on the AES symmetric encryption algorithm, and uses AES-Key2 to encrypt the computing resource license data through the symmetric encryption algorithm to generate computing resource license data (ciphertext). Use RSA-Key3-public to encrypt AES-Key2 and convert the symmetric key into ciphertext form. Finally, integrate the computing resource license data packet. The data packet content includes the header identifier, symmetric key area (ciphertext), and license information body area (ciphertext) and returns the computing resource license data packet to the client software.

[0102] Finally, after receiving the computing resource license file returned by the authorization server, the client software uses SA Key3private to decrypt the data packet and obtain the authorization details that it can use and the information related to the assigned node. The software sends the job to the assigned node and runs the job according to the number of cores requested at the beginning.

[0103] It can be seen that this application uses hardware information plus authorization information as part of the license data, ensuring that the authorization is only effective for a single management node. An authorization management server is provided for hardware information collection, authorization license verification, and cluster resource application. One authorization can be effective for multiple software versions and multiple software running instances. Subsequent version upgrades and expansion installations do not require the deployment of new authorization management servers, which improves deployment efficiency and the flexibility of authorization management. And the security of license data is ensured by combining symmetric encryption and asymmetric encryption. At the same time, two sets of asymmetric keys are used for encryption and digital signature to ensure the integrity of license data and the reliability of the source. Before the client software executes the program, it needs to apply to the authorization server for operation permission and resource use permission at the same time. The combination of the two types of authorization verification can provide the client software with operation permission and resource use permission. The authorization management server dynamically monitors the authorization status during operation. During the execution of computing tasks, the software will regularly confirm the authorization status to the authorization server. If it is not allowed by the license, the authorization management server sends a stop operation instruction to the software. After receiving the instruction, the software will immediately stop the job execution and release the occupied resources.

[0104] See also Figure 7 As shown, the embodiment of the present invention discloses a software authorization device based on a multi-node computer, which is applied to an authorization management server, including:

[0105] An information sending module 11 is used to obtain target information of the management node, and send the target information to the software operator so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server;

[0106] The authorization verification module 12 is used to decrypt the received encrypted license data, obtain and save the license data, receive the authorization application information sent by the client software when the client software is running, and perform authorization verification on the client software based on the authorization application information and the license data;

[0107] The data acquisition module 13 is used to acquire the node resource file allocated by the cluster scheduling system based on the authorization application information if the verification is passed, and integrate the node resource file and the verified authorization license information to obtain computing resource license data;

[0108] The encrypted data sending module 14 is used to encrypt the computing resource license data based on the symmetric encryption algorithm, and send the corresponding encrypted data to the client software so that the client software can decrypt the encrypted data, obtain the computing resource license data, and run the target job based on the authorization information and node information in the computing resource license data.

[0109] In this application, the authorization management server obtains the target information of the management node, sends the target information to the software operator, so that the software operator constructs the license data based on the target information, encrypts the license data based on the symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server; then decrypts the received encrypted license data, obtains and saves the license data, receives the authorization application information sent by the client software when the client software is running, and performs authorization verification on the client software based on the authorization application information and the license data; if the verification is passed, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain the computing resource license data; finally, the computing resource license data is encrypted based on the symmetric encryption algorithm, and the corresponding encrypted data is sent to the client software, so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data. It can be seen that this application collects information, verifies authorization licenses, and applies for cluster resources through the authorization management server. One authorization can be effective for multiple software versions and multiple software running instances. This improves deployment efficiency and the flexibility of authorization management. At the same time, data encryption is used to ensure the security of license data during data transmission. This enables the provision of operating licenses and resource usage licenses to client software before the software is executed.

[0110] In some specific embodiments, the information sending module 11 may specifically include:

[0111] a license data encryption unit, configured to generate a first symmetric encryption key based on a symmetric encryption algorithm, and encrypt the license data using the first symmetric encryption key to obtain encrypted license data;

[0112] An encryption key encryption unit, configured to encrypt the first symmetric encryption key using a public key of a first asymmetric key generated based on an asymmetric encryption algorithm to obtain a first encrypted key;

[0113] A first hash value encryption unit, configured to perform a hash operation on the license data using a target hash function to obtain a first hash value, and encrypt the first hash value using a private key of a second asymmetric key generated based on an asymmetric encryption algorithm to generate a corresponding digital signature;

[0114] The license file construction unit is used to construct a license file using the encrypted license data, the first encrypted key and the digital signature, and return the license file to the authorization management server.

[0115] In some specific embodiments, the authorization verification module 12 may specifically include:

[0116] a first decryption unit, configured to decrypt the first encrypted key in the license file by using the private key of the first asymmetric key to obtain the first symmetric encryption key;

[0117] a second decryption unit, configured to decrypt the encrypted license data using the first symmetric encryption key to obtain the license data;

[0118] a third decryption unit, configured to perform a hash operation on the license data by using the target hash function to generate a second hash value, and to decrypt the digital signature in the license file by using the public key of the second asymmetric key to obtain the first hash value;

[0119] The comparison unit is used to compare the first hash value with the second hash value. If they are the same, it indicates that the signature verification is passed and the license data is saved.

[0120] In some specific embodiments, the authorization verification module 12 may specifically include:

[0121] An information extraction unit, used to receive the authorization application information sent by the client software, and extract the software information in the authorization application information; the software information includes version information, software function module information and applied node quantity information;

[0122] The authorization verification unit is used to complete the authorization verification of the client software by comparing the software information with the license data.

[0123] In some specific embodiments, the data acquisition module 13 may specifically include:

[0124] A node resource file returning unit is used to send a computing node application request to the cluster scheduling system based on the node quantity information of the software application in the authorization application information and the current resource status of the cluster, so that after the cluster scheduling system receives the computing node application request, it allocates the node resource file and returns the node resource file to the authorization management server.

[0125] In some specific embodiments, the encrypted data sending module 14 may specifically include:

[0126] a first encryption unit, configured to generate a second symmetric encryption key based on the symmetric encryption algorithm, and encrypt the computing resource permission data using the second symmetric encryption key to obtain encrypted data;

[0127] A second encryption unit, configured to encrypt the second symmetric encryption key using a public key of a third asymmetric key generated based on an asymmetric encryption algorithm to obtain a second encrypted key;

[0128] A data acquisition unit is used to send the encrypted data and the second encrypted key to the client software, so that the client software uses the private key of the third asymmetric key to decrypt the second encrypted key to obtain the second symmetric encryption key, and decrypts the encrypted data by the second symmetric encryption key to obtain the computing resource license data.

[0129] Furthermore, the present application also discloses an electronic device. Figure 8 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0130] Figure 8 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the software authorization method based on a multi-node computer disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0131] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0132] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0133] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, and can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the software authorization method based on a multi-node computer executed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.

[0134] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the software authorization method based on a multi-node computer disclosed above is implemented. For the specific steps of the method, reference may be made to the corresponding contents disclosed in the above embodiments, and no further description will be given here.

[0135] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0136] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0137] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0138] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0139] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of ​​the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A software authorization method based on a multi-node computer, characterized in that: Applicable to the authorization management server, including: Acquire target information of the management node, send the target information to the software operator, so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server; Decrypting the received encrypted license data, acquiring and saving the license data, receiving authorization application information sent by the client software when the client software is running, and performing authorization verification on the client software based on the authorization application information and the license data; If the verification is successful, the node resource file allocated by the cluster scheduling system is obtained based on the authorization application information, and the node resource file and the verified authorization license information are integrated to obtain computing resource license data; Encrypting the computing resource license data based on the symmetric encryption algorithm, and sending the corresponding encrypted data to the client software, so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data; The receiving the authorization application information sent by the client software and performing authorization verification on the client software based on the authorization application information and the license data includes: Receive the authorization application information sent by the client software, and extract the software information in the authorization application information; the software information includes version information, software function module information and applied node quantity information; Comparing the software information with the license data to complete the authorization verification of the client software; The step of obtaining the node resource file allocated by the cluster scheduling system based on the authorization application information includes: Based on the node quantity information of the software application in the authorization application information and the current resource status of the cluster, a computing node application request is sent to the cluster scheduling system so that after the cluster scheduling system receives the computing node application request, it allocates the node resource file and returns the node resource file to the authorization management server.

2. The software authorization method based on a multi-node computer according to claim 1, characterized in that: The target information includes any one or a combination of media access control address, CPU serial number, hard disk serial number and basic input and output system information; the license data includes software version, maximum upgradeable version, authorized software function modules, authorization initial time, authorization end time, software executable nodes, the number of CPU cores that the software can use, the number of hosts that can be installed and the target information.

3. The software authorization method based on a multi-node computer according to claim 1, characterized in that: The process in which the software operator encrypts the license data based on a symmetric encryption algorithm and returns the corresponding encrypted license data to the authorization management server includes: generating a first symmetric encryption key based on a symmetric encryption algorithm, and encrypting the license data using the first symmetric encryption key to obtain encrypted license data; Encrypting the first symmetric encryption key using a public key of a first asymmetric key generated based on an asymmetric encryption algorithm to obtain a first encrypted key; Performing a hash operation on the license data using a target hash function to obtain a first hash value, and encrypting the first hash value using a private key of a second asymmetric key generated based on an asymmetric encryption algorithm to generate a corresponding digital signature; A license file is constructed by using the encrypted license data, the first encrypted key and the digital signature, and the license file is returned to the authorization management server.

4. The software authorization method based on a multi-node computer according to claim 3, characterized in that: The step of decrypting the received encrypted license data, acquiring and saving the license data comprises: Decrypting the first encrypted key in the license file using the private key of the first asymmetric key to obtain the first symmetric encryption key; decrypting the encrypted license data using the first symmetric encryption key to obtain the license data; Performing a hash operation on the license data by using the target hash function to generate a second hash value, and decrypting the digital signature in the license file by using the public key of the second asymmetric key to obtain the first hash value; The first hash value is compared with the second hash value. If they are the same, it indicates that the signature verification is passed and the license data is saved.

5. The software authorization method based on a multi-node computer according to any one of claims 1 to 4, characterized in that: The step of encrypting the computing resource permission data based on the symmetric encryption algorithm and sending the corresponding encrypted data to the client software so that the client software decrypts the encrypted data and obtains the computing resource permission data comprises: Generate a second symmetric encryption key based on the symmetric encryption algorithm, and use the second symmetric encryption key to encrypt the computing resource permission data to obtain encrypted data; Encrypting the second symmetric encryption key using a public key of a third asymmetric key generated based on an asymmetric encryption algorithm to obtain a second encrypted key; The encrypted data and the second encrypted key are sent to the client software so that the client software can use the private key of the third asymmetric key to decrypt the second encrypted key to obtain the second symmetric encryption key, and decrypt the encrypted data by the second symmetric encryption key to obtain the computing resource license data.

6. A software authorization device based on a multi-node computer, characterized in that: Applicable to the authorization management server, including: An information sending module, used for acquiring target information of the management node, sending the target information to the software operator, so that the software operator constructs license data based on the target information, encrypts the license data based on a symmetric encryption algorithm, and returns the corresponding encrypted license data to the authorization management server; An authorization verification module, used to decrypt the received encrypted license data, obtain and save the license data, receive the authorization application information sent by the client software when the client software is running, and perform authorization verification on the client software based on the authorization application information and the license data; A data acquisition module, for acquiring the node resource file allocated by the cluster scheduling system based on the authorization application information if the verification is passed, and integrating the node resource file with the verified authorization license information to obtain computing resource license data; An encrypted data sending module, used to encrypt the computing resource license data based on the symmetric encryption algorithm, and send the corresponding encrypted data to the client software, so that the client software decrypts the encrypted data, obtains the computing resource license data, and runs the target job based on the authorization information and node information in the computing resource license data; The authorization verification module includes: An information extraction unit, used to receive the authorization application information sent by the client software, and extract the software information in the authorization application information; the software information includes version information, software function module information and applied node quantity information; An authorization verification unit, used to complete the authorization verification of the client software by comparing the software information with the license data; The data acquisition module comprises: A node resource file returning unit is used to send a computing node application request to the cluster scheduling system based on the node quantity information of the software application in the authorization application information and the current resource status of the cluster, so that after the cluster scheduling system receives the computing node application request, it allocates the node resource file and returns the node resource file to the authorization management server.

7. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the software authorization method based on a multi-node computer as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the software authorization method based on a multi-node computer as described in any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Information encryption transmission method and system based on block chain and high-speed cipher card

    CN112217635A

  • Software authorization method and system

    CN116167020A