Authorization method, device, non-volatile storage medium and electronic device
By using UUIDs to generate and encrypt authorization files in a virtualized environment, the problem of traditional authorization methods being unable to verify authorization in a virtualized environment is solved, thus enabling effective deployment and verification of authorization services.
Patent Information
- Application Number
- CN202411978577.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-12-30
AI Technical Summary
Traditional authorization methods rely on hardware information such as media access control addresses for verification, which cannot be effectively verified in a virtualized environment, leading to authorization failure.
By obtaining the unique identifier of the authorized service container in the private network, generating an authorization file and encrypting it, and using the UUID in the virtual machine to check the validity of the license authorization file, local deployment in a virtualized environment is achieved.
It enables effective verification of authorized services in a virtualized environment, prevents authorization from becoming invalid, and improves the flexibility and security of authorization.
Smart Images

Figure CN119814448B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of atomic capability deployment, and more specifically, to a licensing method, apparatus, non-volatile storage medium, and electronic device. Background Technology
[0002] With the continuous development of the internet, cybersecurity issues have become increasingly prominent, with various cybersecurity problems emerging one after another. Therefore, many companies choose to build their own ecosystems within their internal network environments, leading to a growing demand for locally deployed atomic capability services. Local deployment of atomic capability services requires robust authorization mechanisms to restrict user usage, including limits on concurrency, duration, and validity period. As virtualization technology has matured significantly, many project environments rely on virtualization platforms. Traditional license authorization methods, which involve deploying to physical machines and verifying hardware information such as the machine's MAC address (Media Access Control address), are no longer sufficient to meet the needs of virtualization.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This application provides an authorization method, apparatus, non-volatile storage medium, and electronic device to at least solve the technical problem that authorization verification cannot be performed in a virtualized environment due to the fact that traditional authorization methods verify hardware information such as media access control addresses.
[0005] According to one aspect of the embodiments of this application, an authorization method is provided, comprising: obtaining a unique identifier of an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; generating an authorization file based on the unique identifier and configuration information of a target object; encrypting the authorization file; and sending the encrypted authorization file to the authorization service container, wherein the authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if it is determined that the authorization file has been verified successfully.
[0006] Optionally, after activating the authorization service instance, the authorization method further includes: the authorization service container starts a first transport protocol service and uses the first transport protocol service to receive data uploaded by the target atomic capability service, wherein the target atomic capability service is an atomic capability service bound to the authorization service instance.
[0007] Optionally, obtaining the unique identifier of the authorized service container in the private network includes: starting the authorized service container based on the authorized service image, wherein the authorized service container is used to generate a unique identifier after startup, and starting a second transport protocol service, the second transport protocol service is used to provide a transport protocol interface for obtaining the unique identifier; and obtaining the unique identifier through the transport protocol interface.
[0008] Optionally, obtaining a unique identifier through the transmission protocol interface includes: obtaining a network status statistics instruction input by the target object, wherein the network status statistics instruction is used to instruct the retrieval of the transmission protocol interface; and after retrieving the transmission protocol interface based on the network status statistics instruction, obtaining a unique identifier through the transmission protocol interface.
[0009] Optionally, the authorization method further includes: the authorization service instance uses a polling method to determine whether an authorization file exists at a preset location in the container, until it is confirmed that an authorization file exists at the preset location.
[0010] Optionally, the authorization service container is also used to store a unique identifier; the authorization method further includes: decrypting the authorization file and extracting the unique identifier from the authorization file; comparing whether the extracted unique identifier and the stored unique identifier are consistent, and determining that the authorization file verification is successful if they are consistent.
[0011] Optionally, the configuration information includes at least one of the following: user identifier, user key, user service name, user service identifier, concurrent number limit agreed with the user, duration limit agreed with the user, and validity period limit agreed with the user.
[0012] According to another aspect of the embodiments of this application, an authorization device is also provided, comprising: a first processing module, configured to obtain a unique identifier of an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; a second processing module, configured to generate an authorization file based on the unique identifier and configuration information of a target object; a third processing module, configured to encrypt the authorization file; and a fourth processing module, configured to send the encrypted authorization file to the authorization service container, wherein the authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if it is determined that the authorization file has been verified successfully.
[0013] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, wherein a program is stored in the non-volatile storage medium, and the program controls the device where the non-volatile storage medium is located to execute an authorization method when it runs.
[0014] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory and a processor, the processor being configured to run a program stored in the memory, wherein the program executes an authorization method during runtime.
[0015] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that implements an authorization method when executed by a processor.
[0016] In this embodiment, a unique identifier for the authorization service container in the private network is obtained. The authorization service container includes an authorization service instance to be authorized and verified. An authorization file is generated based on the unique identifier and the configuration information of the target object. The authorization file is encrypted. The encrypted authorization file is sent to the authorization service container. The authorization service instance is used to read and verify the authorization file. If the authorization file is verified successfully, the authorization service instance is activated. By using the UUID generated by the authorization service container in the virtual machine to check the validity of the license authorization file, the purpose of uniquely identifying each virtual container is achieved. This realizes the technical effect of local deployment of authorization services in a virtualized environment, and solves the technical problem that traditional authorization methods cannot perform authorization verification in a virtualized environment due to the verification of hardware information such as media access control addresses. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments of this application and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0018] Figure 1 This is a schematic diagram of the structure of a computer terminal according to an embodiment of this application;
[0019] Figure 2 This is a flowchart illustrating an authorization method provided according to an embodiment of this application;
[0020] Figure 3 This is a schematic diagram of an authorization process provided according to an embodiment of this application;
[0021] Figure 4 This is a schematic diagram of the structure of an authorized device provided according to an embodiment of the present invention. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application are explained below:
[0025] License authorization: A contractual agreement between a supplier and a customer authorizing the scope and duration of use of a product sold / purchased. Through a license, the customer obtains the corresponding services promised by the supplier. The main purpose of a license is to control the usage rights of the software.
[0026] The Boost library is a collective term for a group of C++ libraries that provide extensions to the C++ standard library. It is developed and maintained by the Boost community. The Boost library works seamlessly with the C++ standard library and provides it with extended functionality.
[0027] A UUID (Universally Unique Identifier) is a 128-bit identifier used in computer systems to identify information. When generated using standard methods, a UUID is unique in practical applications and does not rely on registration and allocation by a central authority. The probability of a UUID being duplicated is close to zero and can be ignored. Therefore, anyone can create and use a UUID, and it is almost certain that it will not duplicate existing identifiers. Because of this, UUIDs generated in different places can be used in the same database or the same channel, and duplication is virtually impossible.
[0028] With the continuous development of the internet, cybersecurity issues have become increasingly prominent, with various cybersecurity problems emerging one after another. Therefore, many companies choose to build their own ecosystems within their internal network environments, leading to a growing demand for locally deployed atomic capability services. Local deployment of atomic capability services requires robust authorization mechanisms to restrict user usage, including limits on concurrency, duration, and validity period. As virtualization technology has matured significantly, many project environments rely on virtualization platforms. Traditional license authorization methods, which involve deploying to physical machines and verifying hardware information such as MAC addresses, are no longer sufficient to meet the demands of virtualization.
[0029] To address this issue, relevant solutions are provided in the embodiments of this application, which are described in detail below.
[0030] According to an embodiment of this application, a method embodiment of an authorization method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0031] The method embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing an authorization method is shown. Figure 1 As shown, the computer terminal 10 (or mobile device 10) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0032] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).
[0033] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the authorization method in the embodiments of this application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the above-mentioned authorization method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0034] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0035] The display can be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0036] Under the above operating environment, this application embodiment provides an authorization method, such as... Figure 2 As shown, the method includes the following steps:
[0037] Step S202: Obtain the unique identifier of the authorization service container in the private network, wherein the authorization service container includes an authorization service instance to be authorized and verified.
[0038] Optionally, obtaining the unique identifier of the authorized service container in the private network includes: starting the authorized service container based on the authorized service image, wherein the authorized service container is used to generate a unique identifier after startup, and starting a second transport protocol service, the second transport protocol service is used to provide a transport protocol interface for obtaining the unique identifier; and obtaining the unique identifier through the transport protocol interface.
[0039] Optionally, obtaining a unique identifier through the transmission protocol interface includes: obtaining a network status statistics instruction input by the target object, wherein the network status statistics instruction is used to instruct the retrieval of the transmission protocol interface; and after retrieving the transmission protocol interface based on the network status statistics instruction, obtaining a unique identifier through the transmission protocol interface.
[0040] Optionally, the target audience can be users or operations and maintenance personnel.
[0041] Optionally, starting the authorization service container based on the authorization service image includes:
[0042] 1) Start an authorization service container based on the authorization service image. The authorization service image does not contain authorization files. After the container starts, the authorization service still cannot be called normally for effective monitoring and verification and is in the pending authorization verification stage.
[0043] 2) After the authorization service container starts, it will call the method provided by the boost library to generate a UUID (Universally Unique Identifier).
[0044] 3) Cache the UUID in memory for later use by users or operations and maintenance personnel, and for subsequent verification of the license authorization file.
[0045] 4) The service is suspended, waiting to read the generated license file.
[0046] Optionally, obtaining the unique identifier of the authorized service container in the private network includes:
[0047] 1) The authorization service container provides an HTTP interface to the user:
[0048] 2) When the container starts, an HTTP service (second transport protocol service) is started in the background to provide users with an HTTP interface to obtain their UUID;
[0049] 3) The user checks that the background HTTP service has started successfully and checks the specific port (transmission protocol interface) using the netstat -nltp command (network status statistics command);
[0050] 4) Call the specified HTTP interface to return the generated UUID.
[0051] Step S204: Generate an authorization file based on the unique identifier and the configuration information of the target object.
[0052] Optionally, the configuration information includes at least one of the following: user identifier, user key, user service name, user service identifier, concurrent number limit agreed with the user, duration limit agreed with the user, and validity period limit agreed with the user.
[0053] Optionally, generating an authorization file based on a unique identifier and the target object's configuration information includes:
[0054] After a user obtains a unique identifier through the second transport protocol service, an authorization file is generated in the authorization service container. The license file information is stored in TOML format, and the specific information includes: user_id: user ID (i.e., user identifier), secret_key: the key assigned to the current user (i.e., user key), server_name: the service name under the current user (i.e., user service name), server_id: the service ID under the current user (i.e., user service identifier), instance_uuid: the UUID generated internally by the license service obtained by calling the specified HTTP interface (i.e., unique identifier), concurrent_num_threshold: the concurrent number limit agreed with the user (i.e., the concurrent number limit agreed with the user), audio_duration_threshold: the duration limit agreed with the user (i.e., the duration limit agreed with the user), and live_time: the validity period limit agreed with the user (i.e., the validity period limit agreed with the user). In addition to the above configuration, other parameters can be added according to your own business needs.
[0055] Step S206: Encrypt the authorization file.
[0056] Optionally, after configuring the plaintext license file, to prevent the configuration information from being tampered with in a user's private environment, the license file needs to be encrypted using the openssl aes-256-cbc encryption method.
[0057] Step S208: The encrypted authorization file is sent to the authorization service container, where the authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if the authorization file is verified successfully.
[0058] Optionally, the generated license file (authorization file) can be uploaded to the container (authorization service container) corresponding to the already started license service (authorization service instance).
[0059] Optionally, the authorization method further includes: the authorization service instance uses a polling method to determine whether an authorization file exists at a preset location in the container, until it is confirmed that an authorization file exists at the preset location.
[0060] Optionally, the already started license service can poll to read the license file, but will stop polling once the license file is read.
[0061] Optionally, the authorization service container is also used to store a unique identifier; the authorization method further includes: decrypting the authorization file and extracting the unique identifier from the authorization file; comparing whether the extracted unique identifier and the stored unique identifier are consistent, and determining that the authorization file verification is successful if they are consistent.
[0062] Optionally, the authorization service instance decrypts the authorization file according to openssl aes-256-cbc, obtains the authorization file information, and stores it in memory. It then compares the configuration instance_uuid field in the license file information with the field containing the UUID generated by calling the Boost library's UUID generation method and stored in memory. If the two field values are completely identical, the license file is considered a valid license authorization file, and the authorization file verification is confirmed.
[0063] Optionally, after activating the authorization service instance, the authorization method further includes: the authorization service container starts a first transport protocol service and uses the first transport protocol service to receive data uploaded by the target atomic capability service, wherein the target atomic capability service is an atomic capability service bound to the authorization service instance.
[0064] Optionally, if the license authorization file is detected to be valid, the license service instance is activated, and the activated license service instance then starts an HTTP service (first transport protocol service) to receive the data to be collected reported by the atomic capability service bound to the license service.
[0065] Optionally, the data reported by the atomic capability service includes: service concurrency, service duration, etc.
[0066] This application provides an authorization process, such as... Figure 3 As shown, the process includes the following steps:
[0067] 1. The License authorization service generates a UUID and starts an HTTP service in the background.
[0068] 2. The operations and maintenance personnel obtain the UUID by using the curl command to make an HTTP request.
[0069] 3. The HTTP response body sent by the License authorization service includes the generated UUID.
[0070] 4. The operations and maintenance personnel create a plaintext license authorization file based on the UUID.
[0071] 5. The maintenance personnel invoke the authorization file encryption program.
[0072] 6. The license file encryption program generates an encrypted license file.
[0073] 7. The operations and maintenance personnel upload the generated encrypted license authorization file.
[0074] 8. The License authorization service checks the validity of the authorization document.
[0075] 9. If the license file is found to be valid, the license service will be officially started.
[0076] 10. If the license file is found to be invalid, continue waiting for a valid license file.
[0077] Through the above steps, a completely new localized authorization service process is provided to address the problem that traditional authorization methods are not applicable to license authorization in virtualized environments. This process enables localized deployment of license authorization within a virtualized environment, relying on online-generated UUIDs for license file validity checks. This solves the technical problem of traditional authorization methods, which rely on hardware information such as media access control addresses for verification, being unable to perform authorization verification in virtualized environments. Specifically, the method embodiments of this application have the following advantages:
[0078] (1) As a localized deployment licensing solution. It perfectly solves the problem of not being able to obtain the true and unique device information used to generate the license file during private deployment. This makes the license service deployment scenario more flexible and prevents various risks that may lead to license invalidation when users deploy licensing services using virtual containers.
[0079] (2) Local deployment requires copying the license service image to the user's server. The user can then start multiple containers based on the license service image. Since the license service image does not include the license file, the multiple instances of the started license service will still be in an invalid license state. This avoids the license restrictions from becoming invalid due to starting multiple containers.
[0080] (3) Local deployment and maintenance personnel cannot connect to the customer's deployment environment and need to send the generated license file to the customer. However, the UUID for license authorization verification is the UUID generated when the service starts. When a user uses the generated license file to start another container, the verification fails because the UUID generated by the newly started container is inconsistent with the UUID in the license file, and the license service remains invalid. This avoids the situation where users use the generated license file to start multiple containers, causing the license restrictions to become invalid.
[0081] (4) When a locally deployed containerized license service starts normally, the user may copy the container image or directly copy the disk data storing Docker to ensure that the copied container information is completely consistent with the already started license service container. When the copied container starts, it will regenerate a UUID, which will be inconsistent with the UUID generated by the copied container. If the license authorization file of the copied container is used, the inconsistent UUID will cause the UUID consistency check, which is crucial for the license service to change from an invalid to a valid state, to fail. This prevents users from starting multiple license service containers by copying containers, thus avoiding the invalidation of authorization restrictions.
[0082] (5) The method implementation of this application has been used in multiple projects such as speech recognition. Since our operation and maintenance personnel cannot remotely log in to the customer's environment, all image packages, authorization files and other materials need to be sent to the other party's operation and maintenance personnel. Users can operate flexibly, which greatly increases the risk of authorization restrictions failing. It perfectly realizes the license authorization scheme for local deployment in a virtualized environment.
[0083] This application provides an authorization device. Figure 4 This is a schematic diagram of the device, as shown below. Figure 4 As shown, the device includes: a first processing module 40, used to obtain a unique identifier for the authorized service container in a private network, wherein the authorized service container includes an authorized service instance to be authorized and verified; a second processing module 42, used to generate an authorization file based on the unique identifier and the configuration information of the target object; a third processing module 44, used to encrypt the authorization file; and a fourth processing module 46, used to send the encrypted authorization file to the authorized service container, wherein the authorized service instance is used to read and verify the authorization file, and activates the authorized service instance if the authorization file is verified successfully.
[0084] In some embodiments of this application, after activating the authorization service instance, the authorization method further includes: the authorization service container starts a first transmission protocol service and uses the first transmission protocol service to receive data uploaded by the target atomic capability service, wherein the target atomic capability service is an atomic capability service bound to the authorization service instance.
[0085] In some embodiments of this application, the first processing module 40 obtains the unique identifier of the authorized service container in the private network by: starting the authorized service container according to the authorized service image, wherein the authorized service container is used to generate a unique identifier after starting, and starting a second transmission protocol service, the second transmission protocol service is used to provide a transmission protocol interface for obtaining the unique identifier; and obtaining the unique identifier through the transmission protocol interface.
[0086] In some embodiments of this application, the first processing module 40 obtains a unique identifier through a transmission protocol interface by: obtaining a network status statistics instruction input by the target object, wherein the network status statistics instruction is used to instruct the retrieval of the transmission protocol interface; and after retrieving the transmission protocol interface based on the network status statistics instruction, obtaining a unique identifier through the transmission protocol interface.
[0087] In some embodiments of this application, the authorization method further includes: an authorization service instance using a polling method to determine whether an authorization file exists at a preset location of the container, until it is confirmed that an authorization file exists at the preset location.
[0088] In some embodiments of this application, the authorization service container is also used to store a unique identifier; the authorization method further includes: decrypting the authorization file and extracting the unique identifier from the authorization file; comparing whether the extracted unique identifier and the stored unique identifier are consistent, and determining that the authorization file verification is successful if they are consistent.
[0089] In some embodiments of this application, the configuration information includes at least one of the following: user identifier, user key, user service name, user service identifier, concurrent number limit agreed with the user, duration limit agreed with the user, and validity period limit agreed with the user.
[0090] It should be noted that each module in the above-mentioned authorized device can be a program module (e.g., a set of program instructions to implement a certain function) or a hardware module. For the latter, it can be manifested in the following forms, but is not limited to them: each of the above modules is manifested as a processor, or the functions of each of the above modules are implemented by a processor.
[0091] This application provides a non-volatile storage medium storing a program. During program execution, the program controls the device containing the non-volatile storage medium to perform the following authorization method: obtaining a unique identifier for an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; generating an authorization file based on the unique identifier and the configuration information of the target object; encrypting the authorization file; and sending the encrypted authorization file to the authorization service container. The authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if the authorization file verification is successful.
[0092] This application provides an electronic device, including a memory and a processor. The processor is used to run a program stored in the memory. When the program runs, it executes the following authorization method: obtaining a unique identifier of an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; generating an authorization file based on the unique identifier and the configuration information of the target object; encrypting the authorization file; and sending the encrypted authorization file to the authorization service container. The authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if the authorization file is verified successfully.
[0093] This application provides a computer program product, including a computer program that, when executed by a processor, implements the following authorization method: obtaining a unique identifier for an authorization service container in a private network, wherein the authorization service container includes an authorization service instance to be authorized and verified; generating an authorization file based on the unique identifier and the configuration information of the target object; encrypting the authorization file; and sending the encrypted authorization file to the authorization service container, wherein the authorization service instance is used to read and verify the authorization file, and activates the authorization service instance if the authorization file verification is successful.
[0094] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0095] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0096] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0097] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0098] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0099] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. An authorization method, characterized in that, include: Obtain the unique identifier of the authorized service container in the private network, wherein the authorized service container includes an authorized service instance to be authorized and verified; An authorization file is generated based on the unique identifier and the configuration information of the target object; The authorization file is encrypted; The encrypted authorization file is sent to the authorization service container, wherein the authorization service instance is used to read and verify the authorization file, and activate the authorization service instance if the authorization file is verified successfully.
2. The authorization method according to claim 1, characterized in that, After activating the authorized service instance, the authorization method further includes: The authorized service container starts a first transport protocol service and uses the first transport protocol service to receive data uploaded by a target atomic capability service, wherein the target atomic capability service is an atomic capability service bound to the authorized service instance.
3. The authorization method according to claim 1, characterized in that, The unique identifier for the authorized service container in the private network includes: The authorization service container is started based on the authorization service image, wherein the authorization service container is used to generate the unique identification code after startup and start the second transmission protocol service, the second transmission protocol service is used to provide a transmission protocol interface for obtaining the unique identification code; The unique identification code is obtained through the transmission protocol interface.
4. The authorization method according to claim 3, characterized in that, Obtaining the unique identifier through the transmission protocol interface includes: Obtain the network status statistics instruction input by the target object, wherein the network status statistics instruction is used to instruct the retrieval of the transmission protocol interface; Based on the network status statistics command, after retrieving the transmission protocol interface, the unique identification code is obtained through the transmission protocol interface.
5. The authorization method according to claim 1, characterized in that, The authorization method further includes: The authorization service instance uses a polling method to determine whether the authorization file exists at a preset location in the container, until it is confirmed that the authorization file exists at the preset location.
6. The authorization method according to claim 1, characterized in that, The authorization service container is also used to store the unique identification code; the authorization method further includes: The authorization file is decrypted, and the unique identifier in the authorization file is extracted. Compare the extracted unique identifier with the stored unique identifier to see if they match, and if they match, determine that the authorization file has passed verification.
7. The authorization method according to claim 1, characterized in that, The configuration information includes at least one of the following: user identifier, user key, user service name, user service identifier, concurrent number limit agreed with the user, duration limit agreed with the user, and validity period limit agreed with the user.
8. An authorization device, characterized in that, include: The first processing module is used to obtain the unique identifier of the authorized service container in the private network, wherein the authorized service container includes an authorized service instance to be authorized and verified; The second processing module is used to generate an authorization file based on the unique identification code and the configuration information of the target object; The third processing module is used to encrypt the authorization file; The fourth processing module is used to send the encrypted authorization file to the authorization service container, wherein the authorization service instance is used to read and verify the authorization file, and activate the authorization service instance if the authorization file is verified successfully.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, wherein when the program is executed, it controls the device containing the non-volatile storage medium to perform the authorized method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when executed, performs the authorized method according to any one of claims 1 to 7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the authorized method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Authorization verification method, module and system
CN113536334A
Systems and methods to transfer software entitlements between information handling systems
US20230044720A1