Software offline authorization method and system
By using encryption algorithms and MD5 operations in offline authorization, short and refined activation codes are generated, which solves the problems of excessive length and high generation cost of traditional activation codes, and an efficient and secure authorization process is achieved.
Patent Information
- Application Number
- CN202411887127.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-16
AI Technical Summary
The length of traditional offline activation codes is long, resulting in low efficiency of manual input, which can easily lead to authorization failure due to input errors, and the time cost of activation code generation and verification is high, the design is too complex or redundant, making it difficult to take into account the requirements of short and diverse functions.
The first symmetric encryption algorithm and the second symmetric encryption algorithm are used to generate a unique authorization code through the characteristic values of the target host, shorten the length of the plaintext activation code and the fixed-length ciphertext activation code, combine MD5 operations and encoding of the software's authorization date, time, function and restriction information to generate a short and refined plaintext activation code, and generate a fixed-length ciphertext activation code through the second symmetric encryption algorithm.
It significantly shortens the length of the activation code, improves authorization efficiency and user experience, reduces the time cost of activation code generation and verification, and ensures the security and functional integrity of the authorization.
Smart Images

Figure CN120012051A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of offline software information technology, and in particular to a software offline authorization method and system. Background Art
[0002] Software authorization is mainly divided into two modes: online authorization and offline authorization. Among them, online authorization relies on network connection, and the authorization information is verified by the server to activate and manage software functions. Although this method is easy to manage, it is difficult to meet user needs in an environment without network or intranet isolation. Offline authorization usually generates an activation code, and the user enters the activation code into the target device to complete the authorization. The offline authorization mode is suitable for environments without network or intranet isolation, but the existing offline authorization mechanism still has the following shortcomings (such as CN 115659289A, a method, device, electronic device and storage medium for offline activation of software): First, the length of the traditional offline activation code is relatively long (generally, the length of the activation code is usually in the range of 200 to 400 bits), and the activation code usually contains device identification, function permissions and security verification information, which leads to low efficiency when manually input, and it is easy to cause authorization failure due to input errors, affecting user experience. Secondly, some activation code generation methods rely on asymmetric encryption or complex calculation processes, which increases the time cost of activation code generation and verification; in addition, the design of the activation code is too complex or redundant, and it is difficult to take into account the needs of short and diversified functional restrictions, which increases storage and transmission costs. Especially in special scenarios without network or intranet isolation, such as industrial control and military equipment, users prefer to manually enter the activation code through the keyboard to complete the activation, which places higher requirements on the length and inputtability of the activation code. Therefore, a software offline authorization method and system are urgently needed to solve the above problems. Summary of the invention
[0003] In order to solve the technical problems that the length of traditional offline activation codes is long, resulting in low manual input efficiency, authorization failure is easily caused by input errors, the time cost of activation code generation is high, and the design of activation codes is too complicated or redundant, the present invention provides a software offline authorization method and system, which greatly shortens the code length of plaintext activation codes and fixed-length ciphertext activation codes, meets the security and function restriction requirements required for authorization, ensures that the fixed-length ciphertext activation codes are short and concise, and the fixed-length ciphertext activation codes are highly inputtable and convenient, and also improves the authorization efficiency of the software; the first symmetric encryption algorithm and the second symmetric encryption algorithm are adopted, and finally the time cost of the fixed-length ciphertext activation code generation method is reduced compared with the previous one.
[0004] The present invention provides a software offline authorization method, comprising the following steps:
[0005] S1. When the target host is running, the software obtains a characteristic value of the target host, and the software encrypts the characteristic value using a first symmetric encryption algorithm and generates an authorization code;
[0006] S2, the user receives the authorization code and sends it to the software supplier, and the software supplier decrypts the authorization code using the symmetric key of the first symmetric encryption algorithm. If the decryption fails, the authorization ends and the software supplier refuses to provide the next service for the target host; if the decryption succeeds, the process proceeds to step S3;
[0007] S3. The software vendor performs MD5 operation based on the successfully decrypted authorization code and extracts N bits, and at the same time encodes the authorization date, authorization duration, functions and restrictions of the software, and finally generates a plaintext activation code; the software vendor then encrypts the plaintext activation code through a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code;
[0008] S4, the user receives the fixed-length ciphertext activation code and inputs it into the software, the software decrypts the fixed-length ciphertext activation code using the symmetric key of the second symmetric encryption algorithm, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host, if they are consistent, the verification is successful, and the process goes to step S5, otherwise the decryption fails, and the software refuses to activate;
[0009] S5. The software is successfully activated and all or part of its functions are enabled within the specified time.
[0010] Furthermore, the software offline authorization method also includes: step S6, the fixed-length ciphertext activation code for successful software activation is encrypted by the software and cached in the target host, the software periodically decrypts the fixed-length ciphertext activation code, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host. If they are consistent, the verification is successful and returns to step S5, otherwise the decryption fails and the software refuses to activate.
[0011] Furthermore, S1 specifically includes: when the software is running on the target host, it generates a characteristic value by reading the hardware information and operating system information of the target host; wherein the hardware information of the target host includes the motherboard serial number, CPU number and hard disk number of the target host; the operating system information of the target host includes the operating system version number and operating system installation time of the target host; the software finally encrypts the characteristic value through the first symmetric encryption algorithm and generates an authorization code.
[0012] Furthermore, in S2, if the characteristic value is obtained by decryption, the decryption is successful.
[0013] Furthermore, S3 specifically includes:
[0014] S31. The software vendor performs an MD5 operation on the authorization code after successful decryption, extracts N bits, and performs a fixed permutation and combination on the N-bit data;
[0015] S32. The software vendor encodes the authorization date of the software. The current year when the software authorization starts is represented by a fixed English letter, and the current month when the software authorization starts is represented by a fixed English letter;
[0016] S33. The software vendor encodes the authorization duration of the software. The authorization duration of the software uses years and months as the time units. Among them, a fixed number represents years, and a fixed English letter represents months;
[0017] S34. The software vendor encodes the functions and restrictions of the software. 1 represents that a certain function of the software is authorized, 0 represents that a certain function of the software is not authorized, and a fixed English letter represents the restriction level of the software;
[0018] S35. The number of bits of the plaintext activation code is equal to the sum of the number of bits after encoding the software authorization date, the number of bits after encoding the software authorization duration, the number of bits after encoding the functions and restrictions of the software, and the N value;
[0019] S36. The software vendor encrypts the plaintext activation code through a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code.
[0020] Further, in S31, 3 < N < 8; in S33, the number of bits after encoding the software authorization duration is 3; in S34, the number of bits after encoding the functions and restrictions of the software is M, 2 < M < 7.
[0021] Further, in S3, the number of bits of the plaintext activation code does not exceed 15 bits, and the number of bits of the fixed-length ciphertext activation code is 24 bits.
[0022] Compared with the prior art, the present invention has the following beneficial effects: The software offline authorization method of the present invention significantly shortens the lengths of the plaintext activation code and the fixed-length ciphertext activation code on the premise of ensuring authorization security and function integrity, so as to improve the authorization efficiency and optimize the user experience. By taking the eigenvalue of the target host as the core and combining the first symmetric encryption algorithm to generate a unique authorization code, the anti-tampering of the authorization code is realized, ensuring the uniqueness, security and function integrity of the authorization code. In the generation of the plaintext activation code, a permutation and combination method of MD5 operation is proposed, and combined with the software authorization date, authorization duration and function and restriction information, the complex authorization code content is refined into a plaintext activation code with a short and concise length. By restricting the length of the plaintext activation code and combining the second symmetric encryption algorithm, the generated fixed-length ciphertext activation code has a short length, further optimizing the inputability and convenience of the fixed-length ciphertext activation code. By adopting the first symmetric encryption algorithm and the second symmetric encryption algorithm, the time cost of the generation method of the fixed-length ciphertext activation code is finally reduced compared with the previous one.
[0023] The present invention also provides a software offline authorization system, the software offline authorization system comprising:
[0024] Authorization code generation module, used for software to generate registration code;
[0025] The authorization code decryption module is used by software vendors to decrypt the authorization code;
[0026] Activation code generation module, used by software vendors to generate activation codes;
[0027] An activation code decryption module is used for the software to decrypt the activation code;
[0028] and a verification module for periodic verification of the software.
[0029] Compared with the prior art, the present invention has the following beneficial effects: the software offline authorization system of the present invention optimizes the generation method of the plaintext activation code and the fixed-length ciphertext activation code, greatly shortens the code length of the plaintext activation code and the fixed-length ciphertext activation code, satisfies the security and functional restriction requirements required for authorization, ensures that the fixed-length ciphertext activation code is short and concise, and has strong input and convenience, and also improves the authorization efficiency of the software. The first symmetric encryption algorithm and the second symmetric encryption algorithm are adopted, and finally the time cost of the fixed-length ciphertext activation code generation method is reduced compared with the previous one. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a flowchart of the software offline authorization method of the present invention;
[0031] Figure 2 It is a structural block diagram of the software offline authorization system of the present invention. DETAILED DESCRIPTION
[0032] The present invention is further described below in conjunction with the accompanying drawings and specific embodiments.
[0033] like Figure 1 As shown, a software offline authorization method includes the following steps:
[0034] S1. The software obtains the characteristic value of the target host when the target host is running. Specifically, when the target host is running, the software generates the characteristic value by reading the hardware information and operating system information of the target host; wherein the hardware information of the target host includes the motherboard serial number, CPU number and hard disk number of the target host; the operating system information of the target host includes the operating system version number and operating system installation time of the target host; the software encrypts the characteristic value through the first symmetric encryption algorithm and generates an authorization code. The first symmetric encryption algorithm adopts the symmetric encryption algorithm AES-128. The ciphertext encrypted by the first symmetric encryption algorithm is the unique authorization code of the target host. The format of the authorization code is fixed and the length can be controlled within an appropriate range. The generation of the characteristic value must ensure uniqueness, thereby avoiding forgery or reproduction by changing the hardware or software settings of the target host.
[0035] S2. The user receives the authorization code and sends it to the software vendor. The software vendor decrypts the authorization code using the symmetric key of the first symmetric encryption algorithm. If the decryption fails, the authorization ends, and the software vendor refuses to provide the next service to the target host. If the decryption succeeds, the process proceeds to step S3. Specifically, if the decryption obtains a characteristic value, the decryption succeeds, and the process proceeds to step S3. Otherwise, the decryption fails. The decryption failure indicates that the authorization code has been tampered with or the information obtained by decryption is a null value. Therefore, the authorization ends, and the software vendor refuses to provide the next service to the target host. The software vendor does not proceed to the step of generating a plaintext activation code.
[0036] S3. The software vendor performs MD5 operation on the decrypted authorization code and extracts N bits, and encodes the authorization date, authorization duration, functions and restrictions of the software at the same time, and finally generates a plaintext activation code; the software vendor then encrypts the plaintext activation code through a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code, and the second symmetric encryption algorithm adopts the symmetric encryption algorithm AES-128-CBC;
[0037] S4. The user receives the fixed-length ciphertext activation code and inputs it into the software. The software decrypts the fixed-length ciphertext activation code using the symmetric key of the second symmetric encryption algorithm, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host. If they are consistent, the verification is successful and the process proceeds to step S5. Otherwise, the decryption fails, which means that the authorization code has been tampered with or the information obtained by decryption is wrong, and the software refuses to activate.
[0038] S5. The software is successfully activated, and all or part of the software functions are enabled within the specified time. According to the restriction information in the fixed-length ciphertext activation code, the software enables or disables the corresponding functions of the software. The first symmetric encryption algorithm and the second symmetric encryption algorithm are used to ensure the security of data transmission and storage.
[0039] The software offline authorization method of this embodiment significantly shortens the length of the plaintext activation code and the fixed-length ciphertext activation code under the premise of ensuring the authorization security and functional integrity, so as to improve the authorization efficiency and optimize the user experience. By taking the characteristic value of the target host as the core and combining the first symmetric encryption algorithm to generate a unique authorization code, the tamper-proof of the authorization code is realized, and the uniqueness, security and functional integrity of the authorization code are ensured. In the generation of the plaintext activation code, the permutation and combination method of the MD5 operation is proposed, and the complex authorization code content is refined into a short and concise plaintext activation code in combination with the authorization date, authorization duration and function and restriction information of the software. In addition, by limiting the length of the plaintext activation code and combining the second symmetric encryption algorithm, the length of the generated fixed-length ciphertext activation code is short, which further optimizes the input and convenience of the fixed-length ciphertext activation code. The plaintext activation code and the fixed-length ciphertext activation code are streamlined, which not only meets the security and functional restriction requirements required for authorization, but also ensures that the fixed-length ciphertext activation code is short and concise, which is convenient for manual input.
[0040] In response to the manual input requirements in offline authorization scenarios, the generation methods of plaintext activation codes and fixed-length ciphertext activation codes have been optimized, which greatly shortens the length of plaintext activation codes and fixed-length ciphertext activation codes. Fixed-length ciphertext activation codes are easy to input manually to improve authorization efficiency. The first symmetric encryption algorithm and the second symmetric encryption algorithm are used, which ultimately reduces the time cost of the fixed-length ciphertext activation code generation method compared to before.
[0041] The software offline authorization method of this embodiment is suitable for software authorization needs in offline authorization scenarios. It can realize authorization activation without network connection, realize convenient and efficient software authorization management, fully meet the requirements of short, secure and easy-to-use fixed-length ciphertext activation codes in offline authorization scenarios, and also adapt to the usage requirements in intranet isolation scenarios, greatly optimize the convenience of operation, improve the authorization efficiency of software products, and have high security and anti-counterfeiting.
[0042] On the basis of the above embodiment, the software offline authorization method also includes: step S6, the fixed-length ciphertext activation code that successfully activates the software is encrypted by the software and cached in the target host, the software periodically decrypts the fixed-length ciphertext activation code, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host. If they are consistent, the verification is successful and returns to step S5, otherwise the decryption fails and the software refuses to activate. The software does not limit the encryption method of the fixed-length ciphertext activation code, as long as it is encrypted and then cached in the target host. And the validity of the fixed-length ciphertext activation code is verified daily. Specifically, the fixed-length ciphertext activation code is decrypted every day to prevent the fixed-length ciphertext activation from being tampered with or exceeding the authorized time of the software.
[0043] Based on the above embodiments, S3 specifically includes:
[0044] S31. The software supplier performs MD5 operation based on the authorization code after successful decryption and extracts N bits, and performs fixed permutations and combinations on the N bits of data to increase security and complexity. In this implementation, the authorization code after successful decryption is 32 bits, of which 3 <N<8;
[0045] S32. Encode the software authorization date. The current year when the software authorization starts is represented by a fixed English letter, and the current month when the software authorization starts is represented by a fixed English letter. Generally, the software has a limited period. The last digit of the software authorization date code is 2. The first digit represents the current year when the software authorization starts, and the second digit represents the current month when the software authorization starts. For example, 2024 is represented by a fixed English letter F, and 2025 is represented by a fixed English letter G. Alternatively, 2024 is represented by a fixed English letter AA, and 2025 is represented by a fixed English letter AB. January is represented by a fixed English letter A, February is represented by a fixed English letter B, and so on. December is represented by a fixed English letter L.
[0046] S33. Encode the software authorization duration. The software authorization duration uses year and month as the time unit, where fixed numbers are used to represent years and fixed English letters are used to represent months. The last digit of the software authorization duration encoding is 3, the first two digits represent the year of the software authorization duration, and the last digit represents the month of the software authorization duration. For example, January is represented by a fixed English letter A, February is represented by a fixed English letter B, and so on, December is represented by a fixed English letter L. For example, an authorization of 30 years and 11 months is represented as "30K".
[0047] S34. Encode the functions and restrictions of the software. There is no limit on the length, but it should not be too long. 1 represents that a certain function of the software is authorized, and 0 represents that a certain function of the software is not authorized. Use fixed English letters to represent the restriction level of the software. For example, if the number of software processing per second is limited, 1000 can be represented by L, and 12000 can be represented by F. Among them, the number of digits after the software function and restriction encoding is M, 2 <M<7。
[0048] S35. The number of digits of the plain text activation code is equal to the sum of the number of digits after the software authorization date is encoded, the number of digits after the software authorization duration is encoded, the number of digits after the software function and restriction are encoded, and the N value.
[0049] S36. The software supplier encrypts the plaintext activation code by a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code, wherein the second symmetric encryption algorithm adopts the symmetric encryption algorithm AES-128-CBC. The number of bits of the plaintext activation code does not exceed 15 bits, and the number of bits of the fixed-length ciphertext activation code is 24 bits.
[0050] In the generation of the plaintext activation code, this embodiment proposes a permutation and combination method of MD5 operation, and combines the authorization date, authorization duration, and function and restriction information of the software to refine the complex authorization code content into a short and concise plaintext activation code. In addition, by limiting the length of the plaintext activation code and combining the second symmetric encryption algorithm, the length of the generated fixed-length ciphertext activation code is short, which further optimizes the input and convenience of the fixed-length ciphertext activation code. These improvements fully meet the requirements for short, secure, and easy-to-use fixed-length ciphertext activation codes in offline states.
[0051] like Figure 2 As shown, an embodiment of the present invention further provides a software offline authorization system, and the software offline authorization system includes: an authorization code generation module, which is used for the software to generate a registration code; an authorization code decryption module, which is used for the software supplier to decrypt the authorization code; an activation code generation module, which is used for the software supplier to generate an activation code; an activation code decryption module, which is used for the software to decrypt the activation code; and a verification module, which is used for the software to perform periodic verification. It should be noted that the software offline authorization system provided by the embodiment of the present invention is to implement the above method, and its specific functions can be referred to the above method embodiments, which will not be repeated here.
[0052] The embodiments described above are only preferred embodiments of the present invention and are only used to explain the present invention, not to limit the scope of implementation of the present invention. For those skilled in the art, other implementation methods can certainly be easily made by replacement or modification based on the technical contents disclosed in this specification. Therefore, all changes and improvements made to the principles and process conditions of the present invention should be included in the scope of the patent application of the present invention.
Claims
1. A software offline authorization method, characterized in that: The following steps are involved: S1. When the target host is running, the software obtains a characteristic value of the target host, and the software encrypts the characteristic value using a first symmetric encryption algorithm and generates an authorization code; S2. The user receives the authorization code and sends it to the software provider. The software provider decrypts the authorization code using the symmetric key of the first symmetric encryption algorithm. If the decryption fails, the authorization ends and the software provider refuses to provide the next service for the target host. If the decryption is successful, proceed to step S3; S3. The software vendor performs MD5 operation based on the successfully decrypted authorization code and extracts N bits, and at the same time encodes the authorization date, authorization duration, functions and restrictions of the software, and finally generates a plaintext activation code; the software vendor then encrypts the plaintext activation code through a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code; S4, the user receives the fixed-length ciphertext activation code and inputs it into the software, the software decrypts the fixed-length ciphertext activation code using the symmetric key of the second symmetric encryption algorithm, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host, if they are consistent, the verification is successful, and the process goes to step S5, otherwise the decryption fails, and the software refuses to activate; S5. The software is successfully activated and all or part of its functions are enabled within the specified time.
2. The software offline authorization method according to claim 1, characterized in that: The software offline authorization method also includes: Step S6: The fixed-length ciphertext activation code that successfully activates the software is encrypted by the software and cached in the target host. The software periodically decrypts the fixed-length ciphertext activation code, and then verifies whether the characteristic value obtained by decryption is consistent with the characteristic value of the target host. If they are consistent, the verification is successful and returns to step S5. Otherwise, the decryption fails and the software refuses to activate.
3. The software offline authorization method according to claim 1, characterized in that: The S1 specifically includes: when the software is running on the target host, it generates a characteristic value by reading the hardware information and operating system information of the target host; wherein the hardware information of the target host includes the motherboard serial number, CPU number and hard disk number of the target host; the operating system information of the target host includes the operating system version number and operating system installation time of the target host; the software finally encrypts the characteristic value through the first symmetric encryption algorithm and generates an authorization code.
4. The software offline authorization method according to claim 1, characterized in that: In S2, if the characteristic value is obtained by decryption, the decryption is successful.
5. The software offline authorization method according to claim 1, characterized in that: The S3 specifically includes: S31. The software supplier performs MD5 operation based on the authorization code after successful decryption and extracts N bits, and performs fixed permutations and combinations on the N bits of data; S32. The software supplier encodes the software authorization date. The current year when the software authorization starts is represented by a fixed English letter, and the current month when the software authorization starts is represented by a fixed English letter; S33. The software supplier encodes the software authorization duration, and the software authorization duration uses years and months as the time unit, where fixed numbers are used to represent years and fixed English letters are used to represent months; S34. The software vendor codes the functions and restrictions of the software. 1 represents that a certain function of the software is authorized, and 0 represents that a certain function of the software is not authorized. Fixed English letters are used to represent the restriction level of the software. S35. The number of digits of the plaintext activation code is equal to the sum of the number of digits after encoding the software's authorization date, the number of digits after encoding the software's authorization duration, the number of digits after encoding the software's functions and restrictions, and the value of N; S36. The software vendor encrypts the plaintext activation code through a second symmetric encryption algorithm and generates a fixed-length ciphertext activation code.
6. The software offline authorization method according to claim 5, characterized in that: In S31, 3 < N < 8; in S33, the number of digits after encoding the software's authorization duration is 3; in S34, the number of digits after encoding the software's functions and restrictions is M, where 2 < M < 7.
7. The software offline authorization method according to claim 5, characterized in that: In S3, the number of digits of the plaintext activation code does not exceed 15 digits, and the number of digits of the fixed-length ciphertext activation code is 24 digits.
8. A software offline authorization system, characterized in that: The software offline authorization system includes: An authorization code generation module for generating a registration code for the software; An authorization code decryption module for decrypting the authorization code by the software vendor; An activation code generation module for generating an activation code by the software vendor; An activation code decryption module for decrypting the activation code by the software; And a verification module for the software to perform timing verification.
Citation Information
Patent Citations
Offline software activation method and device, electronic equipment and storage medium
CN115659289A