OpenHarmony-based equipment offline authorization method and device, equipment and medium
By generating and verifying the License request file in the offline authorization system of the device and obtaining and sending the License permission file, the problem of poor authorization validity and reliability in the prior art is solved, and more effective and reliable device authorization management is achieved.
Patent Information
- Application Number
- CN202510112055.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-16
AI Technical Summary
The existing offline device authorization technology has poor effectiveness and reliability, resulting in poor authorization protection effect.
By configuring the offline authorization system of the target device and the production and testing tool, generate the license request file and verify the activation authorization operation, obtain the pre-stored license permission files, generate the license authorization file based on these files, and send it to the target device for offline authorization.
Improve the effectiveness and reliability of device authorization management, improve the authorization protection of the device, and prevent flash transcription and license reuse.
Smart Images

Figure CN120012048A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to an offline authorization method, device, equipment and medium for a device. Background Art
[0002] In today's highly information-based era, the application of software and hardware products in various fields is becoming more and more extensive and in-depth. In order to protect the intellectual achievements and legitimate rights and interests of developers and ensure the orderliness and sustainability of business operations, it is crucial to implement effective authorization management of software and hardware products. In many application scenarios, there are some special situations, such as some devices deployed in remote areas with weak network infrastructure and inability to frequently connect to the Internet, or in an environment that is completely disconnected from the Internet for security and confidentiality requirements. In these special environments, offline authorization has become a key means to ensure the legal use of software and hardware products.
[0003] As for the existing offline authorization technology, the commonly used method is to generate a unique authorization file through the authorization service based on the unique characteristics of the software and hardware (such as hardware serial number, MAC address, etc.) and purchase information (such as buyer identity, purchase time, usage period, etc.). In order to enhance security, the authorization file will also be encrypted and signed. However, this common method has exposed many problems in actual applications. On the one hand, it is difficult to effectively prevent flash copying. Due to technical limitations, the authorization file may be completely copied from the original storage medium by criminals through technical means, and then used on unauthorized devices, thereby bypassing the normal authorization process. On the other hand, it is also difficult to prevent license reuse. That is, a legal authorization file may be illegally copied and used multiple times, resulting in loss of control of authorization. In addition, a serious vulnerability is that when the local time is maliciously modified, the judgment of license authorization will be abnormal. Because the validity of authorization is often related to time factors, once the local time is tampered with, the system may mistakenly believe that the authorization is still valid or has expired, which greatly undermines the accuracy and reliability of authorization management and brings huge challenges and risks to the legal use and authorization management of software and hardware products.
[0004] In summary, the existing device offline authorization technology has poor effectiveness and reliability, which in turn leads to the problem of poor device authorization protection effect. Summary of the invention
[0005] The present invention provides a method, apparatus, device and medium for offline authorization of a device, which can solve the problem that the existing offline authorization technology of the device has poor effectiveness and reliability, thereby resulting in poor authorization protection effect of the device.
[0006] In a first aspect, an embodiment of the present invention provides an offline authorization method for a device, which is performed by an offline authorization system configured with a target device and a production test tool, and the method includes:
[0007] Based on the user's activation authorization operation for the target device, a license request file is generated through the target device, and the license request file is sent to the production test tool;
[0008] After receiving the license request file, the production test tool verifies the activation authorization operation of the target device according to the license request file and the preset production test quantity;
[0009] After the verification of the activation authorization operation is passed, the pre-stored license authority file is obtained through the production test tool, a license authorization file is generated based on the license authority file and the license request file, and the current production test quantity is updated;
[0010] The license permission file, license authorization file and pre-configured U-shield public key are sent to the target device through the production test tool to perform offline authorization operations on the target device.
[0011] In a second aspect, an embodiment of the present invention provides an offline authorization device for a device, which is executed by an offline authorization system configured with a target device and a production test tool, and the device includes:
[0012] A request file generation module, used to generate a license request file through the target device based on the user's activation authorization operation on the target device, and send the license request file to the production test tool;
[0013] An authorization verification module, configured to verify the activation authorization operation of the target device according to the License request file and a preset production test quantity after the production test tool receives the License request file;
[0014] An authorization file generation module, used to obtain a pre-stored license authority file matching the target device after the verification of the activation authorization operation is passed through the production test tool, generate a license authorization file based on the license authority file and the license request file, and update the current production test quantity;
[0015] The offline authorization module is used to send the license permission file, license authorization file and the pre-configured U shield public key to the target device through the production test tool to perform offline authorization operations on the target device.
[0016] In a third aspect, an embodiment of the present invention provides an electronic device, the electronic device comprising:
[0017] at least one processor; and
[0018] a memory communicatively connected to the at least one processor; wherein,
[0019] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute an offline authorization method for a device described in any embodiment of the present invention.
[0020] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement an offline authorization method for a device described in any embodiment of the present invention when executed.
[0021] The technical solution of the embodiment of the present invention first generates a License request file through the target device based on the user's activation authorization operation on the target device, and sends the License request file to the production test tool. After receiving the License request file, the production test tool verifies the activation authorization operation of the target device according to the License request file and the preset production test quantity. After the verification of the activation authorization operation is passed, the production test tool obtains a pre-stored License permission file, generates a License authorization file based on the License permission file and the License request file, and updates the current production test quantity. Finally, the production test tool sends the License permission file, the License authorization file and the pre-configured U-shield public key to the target device to perform an offline authorization operation on the target device, thereby solving the problem that the existing offline authorization technology of the device has poor effectiveness and reliability, which leads to poor authorization protection effect of the device, realizes offline authorization of the device, improves the effectiveness and reliability of device authorization management, and improves the authorization protection of the device.
[0022] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 This is a flowchart of an offline authorization method for a device provided according to Embodiment 1 of the present invention;
[0025] Figure 2 is a flowchart of an offline authorization method for a device provided according to Embodiment 2 of the present invention;
[0026] Figure 3 is a schematic diagram of the structure of an offline authorization device of a device provided in Embodiment 3 of the present invention;
[0027] Figure 4 It is a structural schematic diagram of an electronic device for implementing an offline authorization method for a device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, any variation of the terms "including" and "having" is intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] Embodiment 1
[0031] Figure 1This is a flowchart of an offline authorization method for a device provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of offline authorization of hardware and / or software devices. The method can be executed by an offline authorization device of a device. The offline authorization device of the device can be implemented in the form of hardware and / or software. The offline authorization device of the device can be configured in an offline authorization system configured with a target device and a production test tool.
[0032] like Figure 1 As shown, the method includes:
[0033] S110: Based on the activation authorization operation of the user on the target device, a license request file is generated through the target device, and the license request file is sent to the production test tool.
[0034] S120: After receiving the license request file, the production test tool verifies the activation authorization operation of the target device according to the license request file and a preset production test quantity.
[0035] The production test tool in this embodiment refers to a special software or hardware device used to perform authorization verification on a product.
[0036] Among them, the activation authorization operation of the target device is verified according to the License request file and the preset production test quantity, including: parsing the License request file through the production test tool to obtain device attribute information as the first attribute information, and using the preset ECDH key exchange algorithm to decrypt the License request file, and obtaining the device attribute information from the decrypted file content as the second attribute information; judging whether the first attribute information is consistent with the second attribute information through the production test tool, and using the pre-stored U-shield public key to verify the device signature information of the License request file after judging the consistency; when the verification operation passes, obtaining the current preset production test quantity through the production test tool, and when it is detected that the production test quantity is greater than zero, judging that the verification of the activation authorization operation of the target device passes.
[0037] Among them, the ECDH key exchange algorithm is an algorithm for establishing a shared key, which is used to securely exchange keys in an insecure network environment to encrypt and decrypt data and ensure the confidentiality and integrity of the data; further, the U-Shield public key is a public key stored in a hardware device based on the USB interface for verifying digital signatures; further, the signature verification operation is an operation to verify the validity of a digital signature. In digital signature technology, the sender uses its own private key to process the message to generate a digital signature. After the receiver receives the message and the digital signature, it uses the sender's public key to verify the digital signature. If the verification is successful, it means that the message has not been tampered with during transmission and is indeed from the claimed sender; if the verification fails, it means that there may be problems with the message, such as tampering or the sender's identity is unreliable.
[0038] S130: After the verification of the activation authorization operation is passed, a pre-stored license authority file is obtained through the production test tool, a license authorization file is generated based on the license authority file and the license request file, and the current production test quantity is updated.
[0039] Wherein, generating a license authorization file based on the license permission file and the license request file, and updating the current production test quantity, includes: parsing the license request file through the production test tool to obtain device attribute information matching the target device; extracting the device identification code of the target device from the device attribute information through the production test tool, and judging whether there is at least one target identification code matching the device identification code in the identification code list based on a preset identification code list; after judging whether there is a target identification code matching the device identification code in the identification code list, generating a target data source based on the license permission file, the license request file, the device attribute information, the generation time of the device format file, and the writing time of the device attribute information through the production test tool, and deleting the target identification code from the identification code list; signing the target data source using a preset U-shield private key through the production test tool to obtain an encrypted file, and performing byte conversion processing on the encrypted file using a preset byte conversion algorithm to obtain a license authorization file; after detecting that the license authorization file is successfully generated, subtracting one from the current production test quantity through the production test tool to update the production test quantity.
[0040] Specifically, in a specific implementation scenario of this embodiment, first, for the process of generating a license authorization file from a license permission file and a license request file, the production test tool will parse the license request file. The license request file here is generated by the target device in the early stage based on the user's activation authorization operation on the target device, and its format is a Json message, for example, the body area contains the device serial number (such as 123456781234, used to uniquely identify the target device), the device media access control address (such as 78:9A:BC:DE:F0:6A, used for device identification), the instruction identifier (such as licenseReq, indicating that this is an authorization request instruction), the signature (signed with the SM2 private key of the authorized USBKEY to ensure the integrity and source reliability of the file) and the timestamp (such as 1696692015, used to prevent replay attacks) and other information. By parsing this file, the production test tool can obtain the device attribute information that matches the target device, which will serve as an important basis for subsequent operations. Then, the production test tool extracts the device identification code of the target device from the acquired device attribute information. The device identification code here is the key information that can uniquely determine the identity of the target device. It may be the device SN or a combination of device identifications processed by a specific algorithm. Then, the production test tool will make a judgment based on the pre-set identification code list. This identification code list is generated and configured to the production test tool by the authorization cloud platform according to the production plan and equipment management rules during the initialization phase of the entire authorization system. Its purpose is to further ensure the legitimacy of the equipment and the accuracy of the authorization. For example, the identification code list may contain the identification code information of all legal devices in this production batch. When it is determined that there is a target identification code in the identification code list that matches the device identification code extracted from the device attribute information, it indicates that the device is within the authorization scope and the authorization file generation operation can continue. After that, the production test tool generates the target data source based on the license permission file, license request file, device attribute information, device format file generation time, and device attribute information writing time. The license permission file is pre-generated in batches by the cloud platform. Its format is also a Json message, which includes important information such as device SN, whether it is offline authorization (such as 0 for offline authorization), whether it supports cloud services (such as 0 for not supporting cloud services), whether it supports configuration modification (such as 0 for not supporting configuration modification), authorization time (such as 0 for permanent authorization, other numbers for authorization days, and the authorization time interval is calculated by issuing timestamp and authorization time), timestamp, instruction identifier (such as licensePms, indicating that this is an authority-related instruction) and signature (signed with the server SM2 private key)When generating the target data source, this information is combined with the relevant information in the license request file and the time information of the device to form a complex and unique data source, making it difficult for the authorization file to be forged. At the same time, after completing the matching judgment, the production test tool will delete the target identification code from the identification code list to prevent repeated authorization. Subsequently, the production test tool uses the pre-set U shield private key to sign the target data source to obtain an encrypted file. The U shield here is a secure USBKEY that has passed the national secret level 2 certification. It plays a key security role in the entire authorization process. It is used to store important key information and perform encryption and signing operations on files. For example, in this scenario, the U shield private key is used to sign the target data source to ensure the integrity and non-tamperability of the data. Then, the encrypted file is byte-converted using the preset byte conversion algorithm to obtain a license authorization file. The byte conversion algorithm here can be an algorithm such as SM3_HMAC or SM2_SM3 to achieve specific calculation and conversion of the authorization source data and obtain a license authorization file format that meets the requirements. For example, when a symmetric algorithm is used to generate a license authorization file, SM3_HMAC (authorization source data) is used for hexadecimal bytecode conversion, a total of 64 bytes; when an asymmetric algorithm is used to generate a license authorization file, SM2_SM3 (authorization source data) is used for hexadecimal bytecode conversion, a total of 128 bytes. Finally, after detecting that the license authorization file is successfully generated, the production test tool will subtract one from the current production test quantity to update the production test quantity. This is to count the number of offline authorizations, prevent authorization from getting out of control, and ensure that the entire authorization process is carried out within the specified quantity range. For example, in the initial stage, the production test quantity may be a fixed value determined based on the production order. Each successful generation of a license authorization file means that a device is successfully authorized, and the production test quantity is reduced accordingly. When the production test quantity is reduced to 0, no new authorization operation will be performed, thereby effectively controlling the scale and security of authorization.
[0041] S140: Send the license permission file, license authorization file, and pre-configured U-shield public key to the target device through the production test tool to perform offline authorization operations on the target device.
[0042] Optionally, after the License authority file, License authorization file and pre-configured U-shield public key are sent to the target device by the production test tool, the method further includes: the target device performs integrity check on the License authority file, License authorization file and U-shield public key in response to receiving the License authority file, License authorization file and U-shield public key; after the integrity check passes, the License authority file is parsed by the target device to obtain the target authorization duration; whether the target authorization duration is legal is detected, and after judging that the target authorization duration is legal, the authorization verification of the target device is determined to be successful; when it is detected that the target device is running continuously, the running time of the target device is accumulated by a preset chip clock, and when it is detected that the accumulated time reaches a preset threshold, the target authorization duration is updated; whether the updated target authorization time is legal is detected by the target device; if it is legal, the current accumulated time is cleared, and the operation of performing integrity check on the License authority file, License authorization file and U-shield public key is returned; if it is illegal, the authorization invalidation mechanism is triggered to restrict the use of the target device.
[0043] Specifically, in a specific implementation scenario of this embodiment, after completing the generation of the license authorization file and related operations, the production test tool will send the license permission file, the license authorization file and the pre-configured U shield public key to the target device, thereby officially starting the offline authorization operation on the target device. The production test tool will first establish a secure communication channel with the target device, which can ensure the security and reliability of data transmission based on a specific communication protocol and encryption mechanism. For example, encryption protocols such as SSL / TLS can be used to encrypt and protect the transmitted data to prevent the data from being stolen or tampered with during transmission. Then, the license permission file, the license authorization file and the U shield public key are sent to the target device in the established transmission format and sequence. When the target device receives the license permission file, the license authorization file and the U shield public key, the integrity verification program will be started immediately. The target device will use the pre-built-in verification algorithm and related key information to perform integrity verification on the received files and public keys. For example, for the license permission file and the license authorization file, it may verify whether the signature of the file is correct, whether the hash value of the file is consistent with the expectation, etc.
[0044] After the integrity check passes, the target device will parse the license permission file to obtain the target authorization duration. By parsing the authorization time field in the file, the authorization duration is determined according to the established time calculation rules. For example, if the authorization time field is 30, it means that the authorization duration is 30 days, and the system will convert it into hours (30*24=720 hours) for storage and management. Then, the target device will detect whether the target authorization duration is legal. This may involve comparing with the device's hardware information, system configuration, or pre-set authorization policy. For example, some devices may have an upper limit on the authorization duration, or only the authorization duration within a specific range is considered legal depending on the type and purpose of the device. If the target authorization duration is determined to be legal, the authorization verification of the target device is successful, and the device can run related functions normally within the authorization range. During the continuous operation of the target device, the running time will be accumulated through the preset chip clock. The chip clock here is a high-precision clock chip built into the target device, which is not affected by the local time of the device and can independently and accurately time. For example, every hour after the chip clock passes, an accumulation operation will be triggered to record the running time of the device. When it is detected that the accumulated time reaches the preset threshold, it means that the authorization duration may need to be updated. At this time, the target device will update the target authorization duration according to the pre-set rules. For example, according to the authorization policy, the authorization duration may be reduced after a certain period of time, or dynamically adjusted according to the usage and payment of the device. After updating the target authorization duration, the target device will again detect whether the updated target authorization time is legal. If legal, the current accumulated time will be cleared, and the integrity check of the license permission file, license authorization file, and U-Shield public key will be performed again to ensure that the device is always in a legally authorized state during the entire operation process. If it is illegal, the authorization invalidation mechanism will be triggered to immediately restrict the use of the target device. For example, the device may be prohibited from accessing certain key functions or resources, and an authorization invalidation notification may be sent to the relevant management system for subsequent processing and maintenance.
[0045] Wherein, the offline authorization system also includes: an authorization cloud platform.
[0046] On the basis of the above steps, based on the user's activation authorization operation for the target device, before the target device generates a License request file, it also includes: generating production unit information, production test quantity and identification code list matching the confirmation operation in response to the user's confirmation operation through the authorization cloud platform; generating a U-shield public key, a U-shield private key and permission data to be encrypted based on the unit production information through the authorization cloud platform; encrypting the permission data to be encrypted using the U-shield public key through the authorization cloud platform to obtain License permission data, and signing the License permission data using the U-shield private key to obtain a License permission file; sending the License permission file, production test quantity, U-shield public key and identification code list to the production test tool through the authorization cloud platform.
[0047] For example, in the initial stage, when the user is about to carry out the activation authorization operation for the target device, before the target device generates the license request file, the authorization cloud platform will perform a series of key preparations based on the user's confirmation operation. The user confirmation operation here can be a detailed form information containing equipment production and authorization requirements submitted by the user on a specific management system interface. For example, the user may need to fill in the expected usage scenario of the device, the required functional authority range, the expected production scale, and other related customized requirements. Based on the confirmation operation information entered by these users, the authorization cloud platform will generate matching production unit information. The production unit information may include detailed information such as the factory name, workshop number, and production line identification responsible for producing the target device, so as to accurately track and manage the production process. For example, if it is a large electronic equipment manufacturing company, the production unit information may be the No. 2 production line of the No. 3 workshop of a specific factory located in a certain area. At the same time, the production test quantity will also be generated. This quantity clarifies the total number of devices that need to be authorized and tested in this production batch. For example, if 500 devices are planned to be produced this time, the production test quantity is 500. In addition, an identification code list will be generated. The identification code list consists of a series of codes that can uniquely identify the target device. These codes can be based on the device's serial number, hardware feature code, or other unique identification information generated by a specific algorithm; for example, for a batch of network camera devices, the identification code list may contain the unique device serial number of each camera, such as 123456789001, 123456789002, etc. Then, the authorization cloud platform will further generate the U-shield public key, U-shield private key, and permission data to be encrypted based on the generated unit production information. U-shield is a secure USBKEY that has passed the national secret level 2 certification. It plays a key security role in the offline authorization process. The U-shield public key and private key are a pair of key pairs generated based on a specific encryption algorithm (such as the SM2 algorithm). The public key can be publicly used to encrypt and verify data, and the private key is strictly kept confidential by the authorization cloud platform for decryption and signing operations. Then, the authorization cloud platform uses the U-shield public key to encrypt the permission data to be encrypted to obtain the license permission data. This step uses the principle of public key encryption to ensure that only the authorized recipient (such as the production test tool) with the corresponding U-Shield private key can decrypt and obtain the permission data, ensuring the confidentiality of the data during transmission and storage. After the encryption is completed, the U-Shield private key is used to sign the license permission data to obtain the license permission file. The signing operation is to ensure the integrity and source reliability of the data. The recipient can verify the signature to confirm whether the data has been tampered with and whether it comes from a legitimate authorized cloud platform. Finally, the authorized cloud platform will send the license permission file, production test quantity, U-Shield public key, and identification code list to the production test tool.After receiving this information, the production test tool will store it in the local security area, and in the subsequent device offline authorization process, it will interact and verify with the target device and the authorized USBKEY based on this information to ensure the smooth progress and security of the entire offline authorization process. For example, when the production test tool performs authorization verification on the target device, it will use the U-Shield public key to verify and decrypt the license permission file, obtain the device's permission information, and verify the identity of the target device through the identification code list, so as to decide whether to generate a valid license authorization file for the device and complete the offline authorization process.
[0048] The technical solution of the embodiment of the present invention first generates a License request file through the target device based on the user's activation authorization operation on the target device, and sends the License request file to the production test tool. After receiving the License request file, the production test tool verifies the activation authorization operation of the target device according to the License request file and a preset production test quantity. After the verification of the activation authorization operation is passed, the production test tool obtains a pre-stored License permission file, generates a License authorization file based on the License permission file and the License request file, and updates the current production test quantity. Finally, the production test tool sends the License permission file, the License authorization file and the pre-configured U-shield public key to the target device to perform an offline authorization operation on the target device, thereby realizing offline authorization of the device, improving the effectiveness and reliability of device authorization management, and improving the authorization protection of the device.
[0049] Embodiment 2
[0050] Figure 2 This is a flowchart of an offline authorization method for a device provided in Embodiment 2 of the present invention. This embodiment is refined based on the above embodiment. In this embodiment, a method for generating a license request file through a target device based on a user's activation authorization operation on the target device is specifically refined.
[0051] like Figure 2 As shown, the method includes:
[0052] S210: Acquire device attribute information matching the target device through the target device, generate a device format file in response to an activation authorization operation of the user, and acquire the generation time of the device format file.
[0053] The device attribute information includes a device serial number and a device media access address of the target device.
[0054] S220: Write the device attribute information into the device format file through the target device, and obtain the writing time of the device attribute information.
[0055] Specifically, the target device writes the previously acquired device attribute information into the generated device format file, and records the writing time of the device attribute information after writing is completed. This writing time is also an important element in the authorization verification mechanism, and together with the generation time of the device format file, it constitutes a timestamp sequence to ensure the integrity and authenticity of the file. For example, if the file is illegally modified during subsequent transmission or storage, the generation time of the file and the writing time of the attribute information are likely to change, which can be detected during the verification process.
[0056] S230: Generate a file to be encrypted by the target device based on the device attribute information, the device format file, the generation time of the device format file, and the writing time of the device attribute information.
[0057] S240, encrypt the file to be encrypted by the target device based on the preset ECDH key exchange algorithm, and use the pre-configured U-shield private key to sign the encrypted file to obtain a License request file with device signature information.
[0058] Based on the above steps, the target device uses the preset ECDH key exchange algorithm to encrypt the file to be encrypted. In this scenario, the target device uses the server SM2 public key and its own private key through the ECDH algorithm to generate a symmetric key source, and then generates an SM4 symmetric key to encrypt the body area of the target device in SM4_CBC mode. This encryption method can effectively protect the confidentiality and integrity of the file content. After the encryption is completed, the target device uses the pre-configured U-Shield private key to sign the encrypted file to be encrypted. By signing with the U-Shield private key, the source reliability and non-tamperability of the file can be ensured, and a license request file with device signature information can be obtained.
[0059] S250: Send the license request file to a production test tool.
[0060] S260: After receiving the license request file, the production test tool verifies the activation authorization operation of the target device according to the license request file and a preset production test quantity.
[0061] S270: After the verification of the activation authorization operation is passed, a pre-stored license authority file is obtained through the production test tool, a license authorization file is generated based on the license authority file and the license request file, and the current production test quantity is updated.
[0062] S280: Send the license permission file, license authorization file, and pre-configured U-shield public key to the target device through the production test tool to perform offline authorization operations on the target device.
[0063] The technical solution of the embodiment of the present invention first obtains device attribute information matching the target device through the target device, generates a device format file in response to the user's activation authorization operation, obtains the generation time of the device format file, then writes the device attribute information into the device format file through the target device, and obtains the writing time of the device attribute information, then generates a to-be-encrypted file through the target device based on the device attribute information, the device format file, the generation time of the device format file, and the writing time of the device attribute information, then encrypts the to-be-encrypted file through the target device based on a preset ECDH key exchange algorithm, and signs the encrypted to-be-encrypted file with a pre-configured U-shield private key to obtain a License request file with device signature information, and sends the License request file to the The License request file is sent to the production test tool. After receiving the License request file, the production test tool verifies the activation authorization operation of the target device according to the License request file and the preset production test quantity. After the verification of the activation authorization operation is passed, the production test tool obtains the pre-stored License authority file, generates a License authorization file based on the License authority file and the License request file, and updates the current production test quantity. Finally, the production test tool sends the License authority file, the License authorization file and the pre-configured U-shield public key to the target device to perform offline authorization operation on the target device, thereby realizing offline authorization of the device, improving the effectiveness and reliability of device authorization management, and improving the authorization protection of the device.
[0064] Embodiment 3
[0065] Figure 3 This is a structural diagram of an offline authorization device of a device provided in Embodiment 3 of the present invention.
[0066] like Figure 3 As shown, the device comprises:
[0067] A request file generating module 310 is used to generate a license request file through the target device based on the user's activation authorization operation on the target device, and send the license request file to the production test tool;
[0068] The authorization verification module 320 is used for verifying the activation authorization operation of the target device according to the license request file and the preset production test quantity after the production test tool receives the license request file;
[0069] The authorization file generation module 330 is used to obtain a pre-stored license authority file matching the target device after the verification of the activation authorization operation is passed through the production test tool, generate a license authorization file based on the license authority file and the license request file, and update the current production test quantity;
[0070] The offline authorization module 340 is used to send the license permission file, license authorization file and the pre-configured U-shield public key to the target device through the production test tool to perform offline authorization operations on the target device.
[0071] The technical solution of the embodiment of the present invention first generates a License request file through the target device based on the user's activation authorization operation on the target device, and sends the License request file to the production test tool. After receiving the License request file, the production test tool verifies the activation authorization operation of the target device according to the License request file and a preset production test quantity. After the verification of the activation authorization operation is passed, the production test tool obtains a pre-stored License permission file, generates a License authorization file based on the License permission file and the License request file, and updates the current production test quantity. Finally, the production test tool sends the License permission file, the License authorization file and the pre-configured U-shield public key to the target device to perform an offline authorization operation on the target device, thereby realizing offline authorization of the device, improving the effectiveness and reliability of device authorization management, and improving the authorization protection of the device.
[0072] Based on the above embodiment, the request file generation module 310 includes:
[0073] A device format file generating unit, configured to obtain device attribute information matching the target device through the target device, generate a device format file in response to an activation authorization operation of the user, and obtain a generation time of the device format file;
[0074] an attribute information writing unit, used to write the device attribute information into the device format file through the target device, and obtain the writing time of the device attribute information;
[0075] a to-be-encrypted file generating unit, configured to generate, by the target device, a to-be-encrypted file based on the device attribute information, the device format file, the generation time of the device format file, and the writing time of the device attribute information;
[0076] The device signature file is used to encrypt the file to be encrypted through the target device based on the preset ECDH key exchange algorithm, and use the pre-configured U-Shield private key to sign the encrypted file to obtain a license request file with device signature information.
[0077] Based on the above embodiment, the authorization verification module 320 includes:
[0078] An attribute information extraction unit, configured to parse the license request file through a production test tool to obtain device attribute information as first attribute information, and decrypt the license request file using a preset ECDH key exchange algorithm, and obtain the device attribute information from the decrypted file content as second attribute information;
[0079] An attribute information comparison unit, configured to determine whether the first attribute information is consistent with the second attribute information through a production test tool, and perform a signature verification operation on the device signature information of the license request file using a pre-stored U-shield public key after determining that they are consistent;
[0080] The production test quantity detection unit is used to obtain the current preset production test quantity through the production test tool after the signature verification operation is passed, and when it is detected that the production test quantity is greater than zero, determine that the verification of the activation authorization operation of the target device is passed.
[0081] Based on the above embodiment, the authorization file generation module 330 includes:
[0082] A file parsing unit, configured to parse the license request file through the production test tool to obtain device attribute information matching the target device;
[0083] an identification code matching unit, configured to extract the device identification code of the target device from the device attribute information by using the production test tool, and determine whether there is at least one target identification code in the identification code list that matches the device identification code based on a preset identification code list;
[0084] a target data source generating unit, configured to generate a target data source through the production test tool based on the license permission file, the license request file, the device attribute information, the generation time of the device format file, and the writing time of the device attribute information after determining that there is a target identification code matching the device identification code in the identification code list, and delete the target identification code from the identification code list;
[0085] The byte conversion unit is used to sign the target data source using a preset U-shield private key through a production test tool to obtain an encrypted file, and perform byte conversion processing on the encrypted file using a preset byte conversion algorithm to obtain a license authorization file;
[0086] The production test quantity updating unit is used to detect that the license authorization file is successfully generated, and then use the production test tool to reduce the current production test quantity by one to update the production test quantity.
[0087] On the basis of the above embodiment, the offline authorization module 340 is further used to: after the License authority file, the License authorization file and the pre-configured U-shield public key are sent to the target device through the production test tool, the target device responds to the reception of the License authority file, the License authorization file and the U-shield public key, and performs integrity verification on the License authority file, the License authorization file and the U-shield public key; after the integrity verification passes, the License authority file is parsed by the target device to obtain the target authorization duration; and detect whether the target authorization duration is legal , and after judging that the target authorization duration is legal, determining that the authorization verification of the target device is successful; when detecting that the target device is continuously running, accumulating the running time of the target device through the preset chip clock, and when detecting that the accumulated time reaches the preset threshold, updating the target authorization duration; detecting whether the updated target authorization time is legal through the target device; if legal, clearing the current accumulated time, returning to perform the integrity check operation on the License permission file, License authorization file and U shield public key; if illegal, triggering the authorization invalidation mechanism to restrict the use of the target device.
[0088] On the basis of the above embodiment, the request file generation module 310 is also used for: based on the user's activation authorization operation for the target device, before the target device generates the License request file, it also includes: generating production unit information, production test quantity and identification code list matching the confirmation operation in response to the user's confirmation operation through the authorization cloud platform; generating a U-shield public key, a U-shield private key and permission data to be encrypted based on the unit production information through the authorization cloud platform; encrypting the permission data to be encrypted using the U-shield public key through the authorization cloud platform to obtain License permission data, and signing the License permission data using the U-shield private key to obtain a License permission file; sending the License permission file, production test quantity, U-shield public key and identification code list to the production test tool through the authorization cloud platform.
[0089] An offline authorization device for a device provided in an embodiment of the present invention can execute an offline authorization method for a device provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0090] Embodiment 4
[0091] Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0092] like Figure 4 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, ROM 12 and RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0093] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0094] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as an offline authorization method for a device.
[0095] Accordingly, the method comprises:
[0096] Based on the user's activation authorization operation for the target device, a license request file is generated through the target device, and the license request file is sent to the production test tool;
[0097] After receiving the license request file, the production test tool verifies the activation authorization operation of the target device according to the license request file and the preset production test quantity;
[0098] After the verification of the activation authorization operation is passed, the pre-stored license authority file is obtained through the production test tool, a license authorization file is generated based on the license authority file and the license request file, and the current production test quantity is updated;
[0099] The license permission file, license authorization file and pre-configured U-shield public key are sent to the target device through the production test tool to perform offline authorization operations on the target device.
[0100] In some embodiments, an offline authorization method for a device may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the offline authorization method for a device described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute an offline authorization method for a device in any other appropriate manner (e.g., by means of firmware).
[0101] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0102] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0103] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0104] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0105] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0106] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0107] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
Claims
1. A method for offline authorization of a device, executed by an offline authorization system equipped with a target device and a production test tool, characterized in that: include: Based on the user's activation authorization operation on the target device, a license request file is generated through the target device, and the license request file is sent to the production test tool; After receiving the license request file, the production test tool verifies the activation authorization operation of the target device according to the license request file and the preset production test quantity; After the verification of the activation authorization operation is passed, the pre-stored license authority file is obtained through the production test tool, a license authorization file is generated based on the license authority file and the license request file, and the current production test quantity is updated; The license permission file, license authorization file and pre-configured U-shield public key are sent to the target device through the production test tool to perform offline authorization operations on the target device.
2. The method according to claim 1, characterized in that Based on the user's activation authorization operation on the target device, a license request file is generated through the target device, including: Acquire device attribute information matching the target device through the target device, generate a device format file in response to an activation authorization operation of the user, and acquire the generation time of the device format file; Writing the device attribute information into the device format file through the target device, and obtaining the writing time of the device attribute information; Generate a file to be encrypted by the target device based on the device attribute information, the device format file, the generation time of the device format file, and the writing time of the device attribute information; The target device encrypts the file to be encrypted based on the preset ECDH key exchange algorithm, and uses the pre-configured U-shield private key to sign the encrypted file to obtain a license request file with device signature information.
3. The method according to claim 1, characterized in that The activation authorization operation of the target device is verified according to the license request file and the preset production test quantity, including: The license request file is parsed by a production test tool to obtain device attribute information as the first attribute information, and the license request file is decrypted by using a preset ECDH key exchange algorithm, and the device attribute information is obtained from the decrypted file content as the second attribute information; Determine whether the first attribute information is consistent with the second attribute information through a production test tool, and after determining that they are consistent, use a pre-stored U-shield public key to verify the device signature information of the license request file; When the signature verification operation is passed, the currently preset production test quantity is obtained through the production test tool, and when it is detected that the production test quantity is greater than zero, it is determined that the verification of the activation authorization operation of the target device is passed.
4. The method according to any one of claims 1 to 2, characterized in that: Generate a license authorization file based on the license authority file and the license request file, and update the current production test quantity, including: Parsing the license request file through the production test tool to obtain device attribute information matching the target device; Extracting the device identification code of the target device from the device attribute information by the production test tool, and judging whether there is at least one target identification code in the identification code list that matches the device identification code based on a preset identification code list; After determining that there is a target identification code in the identification code list that matches the device identification code, generating a target data source based on the license permission file, the license request file, the device attribute information, the generation time of the device format file, and the writing time of the device attribute information by the production test tool, and deleting the target identification code from the identification code list; The target data source is signed by the production test tool using a preset U-shield private key to obtain an encrypted file, and the encrypted file is byte-converted using a preset byte conversion algorithm to obtain a license authorization file; After detecting that the license authorization file is successfully generated, the current production test quantity is reduced by one through the production test tool to update the production test quantity.
5. The method according to claim 1, characterized in that After the license permission file, license authorization file and pre-configured U-shield public key are sent to the target device through the production test tool, the method further includes: The target device performs integrity verification on the License authority file, the License authorization file, and the U-shield public key in response to receiving the License authority file, the License authorization file, and the U-shield public key; After the integrity check is passed, the license permission file is parsed by the target device to obtain the target authorization duration; Detecting whether the target authorization duration is legal, and after determining that the target authorization duration is legal, determining that the authorization verification of the target device is successful; When it is detected that the target device is continuously running, the running time of the target device is accumulated through a preset chip clock, and when it is detected that the accumulated time reaches a preset threshold, the target authorization duration is updated; Detecting whether the updated target authorization time is legal through the target device; If it is legal, the current accumulated time is cleared, and the operation of performing integrity check on the license permission file, license authorization file, and U-shield public key is returned; If it is illegal, the authorization invalidation mechanism will be triggered to restrict the use of the target device.
6. The method according to claim 1, characterized in that The offline authorization system also includes: an authorization cloud platform.
7. The method according to any one of claims 1 to 6, characterized in that: Based on the user's activation authorization operation on the target device, before the license request file is generated through the target device, the following steps are also included: In response to the user's confirmation operation, the authorized cloud platform generates production unit information, production test quantity and identification code list matching the confirmation operation; Generate a U-shield public key, a U-shield private key and permission data to be encrypted based on the unit production information through the authorization cloud platform; The cloud platform is authorized to use the U-shield public key to encrypt the permission data to be encrypted to obtain the license permission data, and the U-shield private key is used to sign the license permission data to obtain the license permission file; The license permission file, production test quantity, U-shield public key and identification code list are sent to the production test tool through the authorization cloud platform.
8. An offline authorization device for a device, executed by an offline authorization system equipped with a target device and a production test tool, characterized in that: include: A request file generation module, used to generate a license request file through the target device based on the user's activation authorization operation on the target device, and send the license request file to the production test tool; An authorization verification module, configured to verify the activation authorization operation of the target device according to the License request file and a preset production test quantity after the production test tool receives the License request file; An authorization file generation module, used to obtain a pre-stored license authority file matching the target device after the verification of the activation authorization operation is passed through the production test tool, generate a license authorization file based on the license authority file and the license request file, and update the current production test quantity; The offline authorization module is used to send the license permission file, license authorization file and the pre-configured U shield public key to the target device through the production test tool to perform offline authorization operations on the target device.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the offline authorization method for a device according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement an offline authorization method for a device according to any one of claims 1 to 7 when executed.