Equipment online authorization method and authorization verification method based on OpenHarmony
By establishing an online authorization system between the authorized cloud platform and the target device, and using the authentication and signature mechanism of the authorized cloud platform, the problem of poor validity and reliability of authorization management in the existing technology is solved, and more efficient and secure device authorization protection is achieved.
Patent Information
- Application Number
- CN202510114954.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-23
AI Technical Summary
The existing online licensing technology has security threats, such as flash transcription, license reuse, device flashing and license bypassing, resulting in poor device authorization protection effect.
By configuring the online authorization system of the target device and the authorized cloud platform, the target authorization request and the target request file are generated and sent to the authorized cloud platform for verification. After the authorized cloud platform passes verification, it generates and sends the target permission file and the target authorization file, and combines the pre-set cloud platform public key for online authorization. The target device performs integrity measurement and file detection through a trusted chip, extracts device attribute information for comparison, and uses a pre-stored service public key for signature verification to ensure the validity of authorization.
It improves the effectiveness and reliability of equipment authorization management, improves the authorization protection of equipment, and effectively prevents authorization-related security threats.
Smart Images

Figure CN120034365A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to an online authorization method, authorization verification method, device, equipment and medium for a device. Background Art
[0002] In today's era of rapid digital development, software and hardware products are increasingly used in various fields, from industrial production to daily life, from business operations to personal entertainment, and their importance is self-evident. For developers and owners of software and hardware products, effective authorization management is the key to ensure that their intellectual property rights are protected and commercial interests are realized.
[0003] As a modern authorization management method, online authorization service mainly relies on the powerful connection capability of the Internet to build an interactive channel between the license server and the client. In this process, the license verification process covers many links. For example, the license server conducts periodic verification operations through frequent communication with the client to ensure the continued validity of the authorization; at the same time, it can also update and revoke the license in a timely manner according to actual needs, so as to flexibly adapt to market changes and business adjustments. In addition, the outstanding advantage of online authorization service is that it can realize the dynamic management and efficient distribution of license information, making authorization management more accurate, convenient and efficient.
[0004] However, the existing online authorization technology still has many shortcomings. Generally speaking, the existing technology generally generates a unique authorization file by combining the unique characteristics of the software and hardware with the purchase information through the authorization service, and then encrypts and signs the authorization file, and performs corresponding management and server verification on the license server. However, this method faces a series of serious security threats in actual applications, such as the difficulty in effectively preventing flash copying, license reuse, device flashing, and license bypass. The existence of these security vulnerabilities greatly weakens the effectiveness and reliability of authorization management, resulting in poor authorization protection for software and hardware products. Summary of the invention
[0005] The present invention provides an online authorization method, authorization verification method, apparatus, device and medium for a device, which can solve the problem of poor authorization protection effect of the device caused by poor effectiveness and reliability of device authorization management in existing authorization methods and verification methods.
[0006] In a first aspect, an embodiment of the present invention provides an online authorization method for a device, which is performed by an online authorization system configured with a target device and an authorization cloud platform, and the method includes:
[0007] Based on the user's activation authorization operation on the target device, a target authorization request and a target request file are generated through the target device, and the target authorization request and the target request file are sent to the authorization cloud platform;
[0008] After receiving the target authorization request, the authorization cloud platform verifies the activation authorization operation of the target device according to the target authorization request and the target request file;
[0009] After the verification of the activation authorization operation is passed, the authorization cloud platform generates a target authority file and a target authorization file based on the target request file;
[0010] The target authority file, the target authorization file and the preset cloud platform public key are sent to the target device through the authorization cloud platform to perform online authorization operations on the target device.
[0011] In a second aspect, an embodiment of the present invention provides a method for verifying device authorization, which is performed by a target device equipped with a trusted chip, and the method includes:
[0012] In response to a power-on operation of the target device, performing integrity measurement on the target device through a trusted chip;
[0013] After the integrity measurement verification is passed, it is detected whether the target request file, the target permission file and the target authorization file exist in the preset location of the trusted chip;
[0014] When both the target permission file and the target authorization file exist, extract the device attribute information in the target request file and the target permission file, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent;
[0015] After determining that the device attribute information is consistent with the target attribute information of the target device, the target request file and the target permission file are decrypted and calculated using the pre-stored service public key to obtain the target request signature information and the target permission signature information;
[0016] Based on a preset signature verification algorithm, determine whether the target request signature information matches the target request file, and determine whether the target authority signature matches the target authority file, and determine that the authorization verification of the target device is successful after determining that both match.
[0017] In a third aspect, an embodiment of the present invention provides an online authorization device for a device, which is executed by an online authorization system configured with a target device and an authorization cloud platform, and the device includes:
[0018] A request generation module, configured to generate a target authorization request and a target request file through a target device based on an activation authorization operation of a user on a target device, and send the target authorization request and the target request file to an authorization cloud platform;
[0019] A request verification module, used for verifying the activation authorization operation of the target device according to the target authorization request and the target request file after the authorization cloud platform receives the target authorization request;
[0020] A file generation module, configured to generate a target authority file and a target authorization file based on the target request file after the activation authorization operation is verified through the authorization cloud platform;
[0021] The device activation module is used to send the target authority file, the target authorization file and the preset cloud platform public key to the target device through the authorization cloud platform to perform online authorization operations on the target device.
[0022] In a fourth aspect, an embodiment of the present invention provides a device authorization verification apparatus, which is executed by a target device equipped with a trusted chip, and the apparatus includes:
[0023] An integrity measurement module, configured to perform integrity measurement on the target device through a trusted chip in response to a power-on operation of the target device;
[0024] A file detection module, used to detect whether a target request file, a target permission file, and a target authorization file exist in a preset location of the trusted chip after the integrity measurement verification is passed;
[0025] The attribute judgment module is used to extract the device attribute information in the target request file and the target authority file when both the target authority file and the target authorization file exist, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent;
[0026] The signature information acquisition module is used to, after determining that the device attribute information is consistent with the target attribute information of the target device, use the pre-stored service public key to decrypt the target request file and the target permission file to obtain the target request signature information and the target permission signature information;
[0027] The signature information confirmation module is used to determine whether the target request signature information matches the target request file based on a preset signature verification algorithm, and to determine whether the target permission signature matches the target permission file, and to determine that the authorization verification of the target device is successful after determining that both match.
[0028] In a fifth aspect, an embodiment of the present invention provides an electronic device, the electronic device comprising:
[0029] at least one processor; and
[0030] a memory communicatively connected to the at least one processor; wherein,
[0031] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute an online authorization method for a device and an authorization verification method for a device described in any embodiment of the present invention.
[0032] In a sixth aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement an online authorization method for a device and an authorization verification method for a device described in any embodiment of the present invention when executed.
[0033] The technical solution of the embodiment of the present invention first generates a target authorization request and a target request file through the target device based on the user's activation authorization operation on the target device, and sends the target authorization request and the target request file to the authorization cloud platform. After that, after the authorization cloud platform receives the target authorization request, it verifies the activation authorization operation of the target device according to the target authorization request and the target request file. After that, after the verification of the activation authorization operation is passed, the authorization cloud platform generates a target permission file and a target authorization file based on the target request file, and sends the target permission file, the target authorization file and the pre-set cloud platform public key to the target device through the authorization cloud platform to perform an online authorization operation on the target device. After that, the target device configured with a trusted chip responds to the power-on operation of the target device, performs integrity measurement on the target device through the trusted chip, and after the integrity measurement verification is passed, detects whether the target request file, the target permission file and the target authorization file are in the preset position of the trusted chip. The target authorization file is a target permission file. When both the target permission file and the target authorization file exist, the device attribute information in the target request file and the target permission file is extracted, and the device attribute information is compared with the target attribute information of the target device to determine whether they are consistent. After determining that the device attribute information is consistent with the target attribute information of the target device, the target request file and the target permission file are decrypted and calculated using the pre-stored service public key to obtain the target request signature information and the target permission signature information. Finally, based on the preset signature verification algorithm, it is determined whether the target request signature information matches the target request file, and whether the target permission signature matches the target permission file. After determining that they all match, it is determined that the authorization verification of the target device is successful. This solves the problem that the effectiveness and reliability of device authorization management in the existing authorization methods and verification methods are poor, resulting in poor device authorization protection effect, realizes online device authorization and authorization verification, improves the effectiveness and reliability of device authorization management, and improves device authorization protection.
[0034] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0036] Figure 1It is a flowchart of an online authorization method for a device provided in Embodiment 1 of the present invention;
[0037] Figure 2 It is a flowchart of an authorization verification method for a device provided in Embodiment 2 of the present invention;
[0038] Figure 3 It is a schematic structural diagram of an online authorization device for a device provided in Embodiment 3 of the present invention;
[0039] Figure 4 It is a schematic structural diagram of an authorization verification device for a device provided in Embodiment 4 of the present invention;
[0040] Figure 5 It is a schematic structural diagram of an electronic device for implementing an online authorization method for a device and an authorization verification method for a device according to an embodiment of the present invention. Detailed implementation manners
[0041] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0042] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" any deformation are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0043] Embodiment 1
[0044] Figure 1The following is a flowchart of an online authorization method for a device provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of online authorization for device hardware or device software. This method can be executed by an online authorization system configured with a target device and an authorization cloud platform. The device online authorization method device can be implemented in the form of hardware and / or software, and can be configured in an online authorization system with the online authorization function of the device.
[0045] As Figure 1 shown, the method includes:
[0046] S110. Based on the activation authorization operation of the user for the target device, generate a target authorization request and a target request file through the target device, and send the target authorization request and the target request file to the authorization cloud platform.
[0047] Among them, generating a target authorization request and a target request file through the target device based on the activation authorization operation of the user for the target device includes: obtaining device attribute information matching the target device through the target device, and generating a target authorization request based on the device attribute information; generating a device format file through the target device in response to the activation authorization operation of the user, and writing the device attribute information into the device format file to obtain an encrypted file to be encrypted that matches the target device; encrypting the encrypted file to be encrypted by the target device based on a preset ECDH key exchange algorithm, and signing the encrypted file with a pre-configured identity private key to obtain a target request file with device signature information.
[0048] Specifically, in the scenario of authorization management, when the user performs an activation authorization operation on the target device (such as an IPC device), the target device will play a key role, generate a target authorization request and a target request file, and transmit them to the authorization cloud platform to start the authorization process.
[0049] In a specific implementation scenario of this embodiment, based on the user's activation authorization operation for the target device, the process of generating a target authorization request and a target request file through the target device specifically includes the following steps: First, the target device will obtain device attribute information that matches itself, such as the device serial number (SN), whose value may be "123456781234", and the media access control address (MAC), such as "78:9A:BC:DE:F0:6A", etc. These device attribute information can uniquely identify the target device, and based on these acquired device attribute information, the target device generates a target authorization request. Then, the target device will generate a specific device format file in response to the user's activation authorization operation. For example, in an IPC device, an initial file will be generated under the rootfs partition, and then the acquired device attribute information (such as device SN, MAC, etc.) will be written into this device format file, thereby obtaining a file to be encrypted that matches the target device. Afterwards, the target device performs an encryption operation on the file to be encrypted based on a preset elliptic curve Diffie-Hellman (ECDH) key exchange algorithm. Specifically, the SM2 public key of the server and the private key of the target device are used to generate a symmetric key source through the ECDH algorithm, and then the SM4 symmetric key is generated to encrypt the file in SM4_CBC mode. For example, the protection key of the body domain of the target request file is generated in this way. Finally, the encrypted file is signed using the identity private key pre-configured in the target device (such as the identity SM2 private key in the secure and trusted chip SE) to obtain the target request file with device signature information. This signature can ensure the integrity of the file and the reliability of the source, and prevent the file from being tampered with or forged during transmission. At the same time, the data of the target request file consists of device attribute information, device signature information, device format file creation time, and generation time of the file to be encrypted. In actual applications, if the system detects a change in the file creation time, the target request file verification will fail, thereby preventing flash copying and repeated flashing of the same machine to reuse the target application file.
[0050] S120: After receiving the target authorization request, the authorization cloud platform verifies the activation authorization operation of the target device according to the target authorization request and the target request file.
[0051] Among them, the activation authorization operation of the target device is verified according to the target authorization request and the target request file, including: parsing the target authorization request through the authorization cloud platform to obtain device attribute information matching the target authorization request; decrypting the target request file through the authorization cloud platform using a pre-configured ECDH key exchange algorithm, and extracting the device attribute information from the decrypted file content, and comparing it with the device attribute information extracted from the target authorization request to determine whether they are consistent; if they are consistent, verifying the device signature information of the target request file through the authorization cloud platform using the pre-storage service public key; if the signature verification is successful, it is determined that the verification of the activation authorization operation has passed.
[0052] Exemplarily, the specific process of verifying the activation authorization operation of the target device according to the target authorization request and the target request file includes the following key steps: First, the authorization cloud platform will perform an in-depth analysis of the received target authorization request. The target authorization request here may be transmitted in a specific data format and protocol, such as a message in JSON format. Through analysis, the device attribute information that matches the target authorization request can be extracted, which may include key identifiers such as the serial number and media access control address of the target device. Next, the authorization cloud platform will use the pre-configured Elliptic Curve Diffie-Hellman (ECDH) key exchange algorithm to decrypt the target request file, which is an encryption algorithm commonly used to ensure secure data transmission and exchange. After the decryption is completed, the device attribute information is extracted from the decrypted file content, and it is carefully compared with the device attribute information extracted from the target authorization request to determine whether the two are completely consistent. If the two are consistent, the authorization cloud platform will further use the pre-stored service public key (such as the server's SM2 public key) to verify the device signature information of the target request file. This step is to confirm the authenticity and integrity of the signature to ensure that the file has not been tampered with and the source is credible. If the signature verification is successful, it means that the activation authorization operation of the target device has passed the strict verification of the authorization cloud platform and the subsequent authorization process can continue.
[0053] S130. After the activation authorization operation is verified, the authorization cloud platform generates a target authority file and a target authorization file based on the target request file.
[0054] Among them, after the verification of the activation authorization operation is passed, a target permission file and a target authorization file are generated based on the target request file, including: querying a pre-configured permission policy database based on the device attribute information in the target request file through the authorization cloud platform to obtain a permission policy template that matches the target device; generating a to-be-encrypted permission file that matches the target device based on the permission policy template and the device attribute information through the authorization cloud platform; encrypting the to-be-encrypted permission file based on a preset ECDH key exchange algorithm through the authorization cloud platform, and signing the encrypted file with a pre-configured server private key to obtain a target permission file with cloud platform signature information; calculating and generating a target authorization file through the authorization cloud platform according to the target request file and the generated target permission file in accordance with a preset authorization file generation algorithm.
[0055] Specifically, after the verification of the activation authorization operation is passed, the process of generating the target permission file and the target authorization file based on the target request file is as follows: First, the authorization cloud platform will query the pre-configured permission policy database based on the device attribute information contained in the target request file, such as the device serial number "123456781234". This database stores various permission policy rules. Through the query, the permission policy template that matches the target device is obtained. For example, for some devices, its permission policy may stipulate whether offline authorization is supported, whether cloud services are supported, whether configuration modification is supported, and the authorization time. Then, the authorization cloud platform will generate a permission file to be encrypted that matches the target device based on the obtained permission policy template and the device attribute information in the target request file. This file contains specific permission information customized for the target device. Then, the authorization cloud platform will encrypt the permission file to be encrypted based on the preset elliptic curve Diffie-Hellman (ECDH) key exchange algorithm; specifically, the SM2 public key of the client to be authorized and the private key of the server are used through the ECDH algorithm to generate a symmetric key source, and then the SM4 symmetric key is generated to encrypt the body area of the permission file in SM4_CBC mode. After the encryption is completed, the encrypted file is signed with the pre-configured server private key to obtain the target permission file with the cloud platform signature information. This can ensure the security and integrity of the permission file and prevent illegal tampering and forgery. Finally, the authorization cloud platform will calculate and generate the target authorization file according to the target request file and the generated target permission file according to the preset authorization file generation algorithm. Specifically, the device attribute information, the preset device authorization duration, the device permissions matching the target device, the device format file creation time and the generation time of the file to be encrypted are obtained, and these data are processed and calculated to generate the final target authorization file.
[0056] It should be noted that in this embodiment, since the method of using preset data to generate a target permission file and a target authorization file in a specific format is a mature existing technology, this embodiment does not elaborate on the specific generation process of each type of file.
[0057] S140. Send the target authority file, the target authorization file, and the preset cloud platform public key to the target device through the authorization cloud platform to perform online authorization operations on the target device.
[0058] In a specific implementation scenario of this embodiment, illustratively, assuming that the authorized cloud platform matched by the current target device is the Honghu cloud platform service, then specifically, after completing the verification step through the authorized cloud platform, the target permission file, the target authorization file and the pre-set cloud platform public key are sent to the target device, so that the specific process of implementing the online authorization operation on the target device can be: the target permission file contains detailed permission setting information such as whether the device supports offline authorization (for example, 0 for offline authorization, 1 for online authorization), whether it supports Honghu cloud platform services (such as cloud storage, cloud recording, etc., 0 for not supporting cloud services, 1 for supporting cloud services), whether it supports configuration modification (0 for not supporting configuration modification, 1 for supporting configuration modification) and authorization time (0 for permanent authorization, other numbers for authorization days, and the authorization time interval is calculated by issuing timestamps in conjunction with authorization time). Afterwards, the pre-set cloud platform public key, such as the SM2 public key of the server, is used by the target device to perform data encryption and decryption, signature verification and other operations in subsequent interactions to ensure the security of communication and the integrity of data. When these critical files and keys are sent to the target device, the target device can perform corresponding configurations and operations based on the received information, achieve effective online authorization, ensure that it operates normally within the prescribed scope of authority, and is protected by security mechanisms.
[0059] The technical solution of the embodiment of the present invention first generates a target authorization request and a target request file through the target device based on the user's activation authorization operation on the target device, and sends the target authorization request and the target request file to the authorization cloud platform. After that, after the authorization cloud platform receives the target authorization request, it verifies the activation authorization operation of the target device according to the target authorization request and the target request file. After that, after the verification of the activation authorization operation is passed, the authorization cloud platform generates a target authority file and a target authorization file based on the target request file. Finally, the authorization cloud platform sends the target authority file, the target authorization file and the pre-set cloud platform public key to the target device to perform online authorization operations on the target device, thereby realizing online authorization of the device, improving the effectiveness and reliability of device authorization management, and improving the authorization protection of the device.
[0060] Embodiment 2
[0061] Figure 2 A flowchart of a method for authorization verification of a device provided in Embodiment 2 of the present invention. This embodiment is applicable to situations where authorization verification of a device is performed. The method can be executed by a target device configured with a trusted chip. The authorization verification method device of the device can be implemented in the form of hardware and / or software. The authorization verification method device of the device can be configured in a hardware or software device with a device authorization verification function.
[0062] like Figure 2 As shown, the method includes:
[0063] S210 . In response to a power-on operation of a target device, perform integrity measurement on the target device through a trusted chip.
[0064] Among them, the integrity measurement refers to the process of detecting and evaluating the key components and system status of the target device to determine whether they have not been tampered with, damaged or modified without authorization. This includes hashing important parts of the device's operating system kernel, key drivers, system configuration files, etc., and comparing the calculated hash value with the pre-stored reference value. For example, the trusted chip will perform a hash operation on the operating system startup file of the target device to obtain a specific hash value. This hash value is then compared with the reference hash value of the file previously stored in a secure environment. If the two are consistent, it means that the integrity of the file has not been compromised; if they are inconsistent, it may mean that the device has experienced an abnormal situation before startup, such as tampering with malware, data corruption caused by hardware failure, etc. Through this integrity measurement method, potential security threats can be discovered in time at the early stage of device startup to ensure the normal operation of the device and the security of data.
[0065] S220: After the integrity measurement verification is passed, detect whether a target request file, a target authority file, and a target authorization file exist in a preset location of the trusted chip.
[0066] The preset location is a specific storage space that is pre-set in the trusted chip for storing these important files.
[0067] For example, during the detection, the system will search for the existence and integrity of these files in the specific storage area of the trusted chip according to the preset rules and paths. If the complete and accurate target request file, target permission file and target authorization file are successfully found in the preset location, the target device can operate normally according to the established permissions and rules; if they are not found or the files are incomplete, it may mean that there is an abnormal situation and corresponding measures need to be taken to deal with it, such as prompting authorization failure to exit the authorization detection operation or issuing a security alarm.
[0068] S230. When both the target permission file and the target authorization file exist, extract device attribute information from the target request file and the target permission file, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent.
[0069] Specifically, when it is determined that both the target permission file and the target authorization file exist in the preset position of the trusted chip, the system will start a key comparison process. This process aims to extract the device attribute information in the target request file and the target permission file, and compare it with the target attribute information of the target device itself to determine whether they are completely consistent. The target request file mentioned here usually contains attribute information that can accurately identify the identity of the device, such as the unique serial number of the target device and the media access control address. The target permission file records in detail the specific permission settings related to the target device, such as whether it has the permission for offline authorization (0 means no, 1 means yes), whether it supports cloud services (0 means no, 1 means yes), whether it is allowed to modify the configuration (0 means no, 1 means yes), etc., and may also contain some basic attribute information of the device. The target attribute information of the target device refers to the real and accurate device characteristic data obtained through the hardware or software identification of the device itself, such as the serial number read from the BIOS of the device, or the MAC address obtained through the network interface. When performing the comparison, the system will compare each field of these device attribute information one by one, such as each digit of the serial number, each character of the MAC address, etc. Only when the device attribute information extracted from the target request file and the target permission file completely matches the actual target attribute information of the target device in all key fields can it be judged as consistent; if there is any difference, even a slight difference, it may indicate an abnormal situation, which may be a file error, device tampering, or other security risks.
[0070] S240. After determining that the device attribute information is consistent with the target attribute information of the target device, use the pre-stored service public key to decrypt the target request file and the target authority file to obtain the target request signature information and the target authority signature information.
[0071] S250. Determine whether the target request signature information matches the target request file based on a preset signature verification algorithm, and determine whether the target authority signature matches the target authority file, and determine that the authorization verification of the target device is successful after determining that both match.
[0072] Among them, the preset signature verification algorithm is a program logic specially designed to verify the consistency of digital signatures and file contents. It will compare the target request signature information with each key element of the target request file in detail to ensure that the signature can accurately reflect the content of the file and has not been tampered with, such as the ECDSA signature verification algorithm or the SM2 signature verification algorithm. At the same time, the target authority signature and the target authority file will also be subjected to the same strict matching judgment. Only when the judgment result shows that the target request signature information completely matches the target request file, and the target authority signature completely matches the target authority file, can the authorization verification of the target device be finally determined to be successful, which means that the target device is confirmed to be within the legal authorization scope and can use the corresponding functions and services normally.
[0073] Optionally, in this embodiment, the authorization verification method of the device also includes: in response to the power-on operation of the target device, detecting whether the network time protocol time synchronization of the target device is in an on state; after detecting that the network time protocol time synchronization is turned on, obtaining the current system time, and parsing the target request file to obtain device attribute information matching the target device; based on the authorization time limit information contained in the device attribute information, determining whether the current system time is within the authorization time limit; if so, determining that the authorization verification of the target device is successful; if not, determining that the authorization verification of the target device has failed.
[0074] In this embodiment, the authorization verification method of the device further includes the following important steps: When the target device (such as a specific computer terminal, mobile device, etc.) performs a power-on operation, that is, when it is powered on and ready to start running, it will first detect whether the Network Time Protocol (NTP) time calibration function of the target device is enabled. Network Time Protocol time calibration is a mechanism for synchronizing device time through the network, which can ensure that the system time of the device is highly accurate and consistent with the standard time. For example, in an enterprise network environment, all computers synchronize time by connecting to a specified NTP server to ensure time accuracy. After detecting that the Network Time Protocol time calibration is enabled, it will obtain the current system time. Then, it will perform a parsing operation on the target request file. By parsing this file, device attribute information that exactly matches the target device can be extracted. Based on the authorization time limit information obtained from the device attribute information, it will be determined whether the currently obtained system time is within the authorization time limit. The authorization time limit information here may specify the start time and end time of device authorization, or the effective duration of authorization (such as 30 days, one year, etc.). If the current system time is exactly within the authorization time limit, then it is determined that the authorization verification of the target device is successful, and the target device can normally use its authorized functions and services. For example, if a software authorization starts on January 1, 2023, with a validity period of one year, when the current system time is July 1, 2023, it is determined that the authorization verification is successful. Conversely, if the current system time is not within the authorization time limit, then it is determined that the authorization verification of the target device fails, and the target device may be restricted from using related functions, or corresponding alarms and processing mechanisms may be triggered.
[0075] The technical solution of the embodiment of the present invention first performs integrity measurement on the target device. After the integrity measurement verification passes, it detects whether there are a target request file, a target permission file, and a target authorization file in the preset positions of the trusted chip. When both the target permission file and the target authorization file exist, it extracts the device attribute information in the target request file and the target permission file, and compares the device attribute information with the target attribute information of the target device to determine whether they are consistent. After determining that the device attribute information is consistent with the target attribute information of the target device, it uses the pre-stored service public key to perform decryption calculations on the target request file and the target permission file to obtain the target request signature information and the target permission signature information. Finally, based on the preset signature verification algorithm, it determines whether the target request signature information matches the target request file, and whether the target permission signature matches the target permission file. After determining that both match, it determines that the authorization verification of the target device is successful, realizing the authorization verification of the device, improving the effectiveness and reliability of device authorization management, and perfecting the authorization protection of the device.
[0076] Embodiment 3
[0077] Figure 3 A schematic diagram of the structure of an online authorization device of a device provided in Embodiment 3 of the present invention.
[0078] like Figure 3 As shown, the device comprises:
[0079] A request generation module 310, for generating a target authorization request and a target request file through a target device based on an activation authorization operation of a user on a target device, and sending the target authorization request and the target request file to an authorization cloud platform;
[0080] A request verification module 320, configured to verify the activation authorization operation of the target device according to the target authorization request and the target request file after the authorization cloud platform receives the target authorization request;
[0081] A file generation module 330, configured to generate a target authority file and a target authorization file based on the target request file after the activation authorization operation is verified through the authorization cloud platform;
[0082] The device activation module 340 is used to send the target authority file, the target authorization file and the preset cloud platform public key to the target device through the authorization cloud platform to perform online authorization operations on the target device.
[0083] The technical solution of the embodiment of the present invention first generates a target authorization request and a target request file through the target device based on the user's activation authorization operation on the target device, and sends the target authorization request and the target request file to the authorization cloud platform. After that, after the authorization cloud platform receives the target authorization request, it verifies the activation authorization operation of the target device according to the target authorization request and the target request file. After that, after the verification of the activation authorization operation is passed, the authorization cloud platform generates a target permission file and a target authorization file based on the target request file. Finally, the authorization cloud platform sends the target permission file, the target authorization file and the pre-set cloud platform public key to the target device to perform online authorization operations on the target device, thereby realizing online authorization of the device, improving the effectiveness and reliability of device authorization management, and improving the authorization protection of the device.
[0084] Based on the above embodiment, the request generation module 310 includes:
[0085] An authorization request generating unit, configured to obtain device attribute information matching the target device through the target device, and generate a target authorization request based on the device attribute information;
[0086] a file to be encrypted generating unit, configured to generate a device format file through the target device in response to the user's activation authorization operation, and write the device attribute information into the device format file to obtain a file to be encrypted that matches the target device;
[0087] The device signature unit is used to perform an encryption operation on the file to be encrypted through the target device based on a preset ECDH key exchange algorithm, and use a pre-configured identity private key to sign the encrypted file to obtain a target request file with device signature information.
[0088] Based on the above embodiment, the request verification module 320 includes:
[0089] An attribute information parsing unit, used to parse the target authorization request through the authorization cloud platform to obtain device attribute information matching the target authorization request;
[0090] A request file decryption unit, used to decrypt the target request file using a pre-configured ECDH key exchange algorithm through the authorization cloud platform, and extract device attribute information from the decrypted file content, and compare it with the device attribute information extracted from the target authorization request to determine whether they are consistent;
[0091] A device signature verification unit, used to verify the device signature information of the target request file by using the pre-storage service public key through the authorized cloud platform if they are consistent;
[0092] The verification passing unit is used to determine whether the verification of the activation authorization operation is passed if the signature verification is successful.
[0093] Based on the above embodiment, the file generation module 330 includes:
[0094] A template acquisition unit, configured to query a pre-configured authority policy database based on the device attribute information in the target request file through the authorization cloud platform to acquire an authority policy template matching the target device;
[0095] A to-be-encrypted rights file generating unit, configured to generate, through the authorization cloud platform, a to-be-encrypted rights file matching a target device based on the rights policy template and the device attribute information;
[0096] The cloud platform signature unit is used to perform an encryption operation on the to-be-encrypted permission file through the authorized cloud platform based on a preset ECDH key exchange algorithm, and use a pre-configured server private key to sign the encrypted file to obtain a target permission file with cloud platform signature information;
[0097] The authorization file generation unit is used to calculate and generate the target authorization file according to the target request file and the generated target authority file through the authorization cloud platform according to a preset authorization file generation algorithm.
[0098] An online authorization device for a device provided in an embodiment of the present invention can execute an online authorization method for a device provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0099] Embodiment 4
[0100] Figure 4 A schematic diagram of the structure of an authorization verification device of a device provided in Embodiment 4 of the present invention.
[0101] like Figure 4 As shown, the device comprises:
[0102] The integrity measurement module 410 is used to perform integrity measurement on the target device through the trusted chip in response to the power-on operation of the target device;
[0103] The file detection module 420 is used to detect whether the target request file, the target permission file and the target authorization file exist in the preset location of the trusted chip after the integrity measurement verification is passed;
[0104] The attribute determination module 430 is used to extract the device attribute information in the target request file and the target authority file if both the target authority file and the target authorization file exist, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent;
[0105] The signature information acquisition module 440 is used to use the pre-stored service public key to decrypt the target request file and the target permission file if they are consistent, and obtain the target request signature information matching the target request file and the target permission signature information matching the target permission file;
[0106] The signature information confirmation module 450 is used to determine whether the target request signature information matches the target request file based on a preset signature verification algorithm, and to determine whether the target authority signature matches the target authority file, and to determine that the authorization verification of the target device is successful after determining that both match.
[0107] The technical solution of the embodiment of the present invention first performs integrity measurement on the target device, and after the integrity measurement verification is passed, detects whether there is a target request file, a target permission file and a target authorization file in the preset position of the trusted chip. When the target permission file and the target authorization file both exist, extracts the device attribute information in the target request file and the target permission file, and compares the device attribute information with the target attribute information of the target device to determine whether they are consistent. After determining that the device attribute information is consistent with the target attribute information of the target device, uses a pre-stored service public key to decrypt and calculate the target request file and the target permission file to obtain target request signature information and target permission signature information. Finally, based on a preset signature verification algorithm, determines whether the target request signature information matches the target request file, and determines whether the target permission signature matches the target permission file. After determining that they all match, it is determined that the authorization verification of the target device is successful, thereby realizing device authorization verification, improving the effectiveness and reliability of device authorization management, and improving device authorization protection.
[0108] On the basis of the above embodiment, the authorization verification device of the device also includes: a time limit verification module, which is used to detect whether the network time protocol time synchronization of the target device is in an on state in response to the power-on operation of the target device; after detecting that the network time protocol time synchronization is turned on, obtaining the current system time, and parsing the target request file to obtain device attribute information matching the target device; based on the authorization time limit information contained in the device attribute information, judging whether the current system time is within the authorization time limit; if so, determining that the authorization verification of the target device is successful; if not, determining that the authorization verification of the target device has failed.
[0109] An authorization verification device for a device provided in an embodiment of the present invention can execute an authorization verification method for a device provided in any embodiment of the present invention, and has functional modules and beneficial effects corresponding to the execution method.
[0110] Embodiment 5
[0111] Figure 5 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.
[0112] like Figure 5 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, ROM 12 and RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0113] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0114] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processor 11 executes the various methods and processes described above, such as an online authorization method for a device and an authorization verification method for a device.
[0115] Accordingly, an online authorization method for a device includes:
[0116] Based on the user's activation authorization operation on the target device, a target authorization request and a target request file are generated through the target device, and the target authorization request and the target request file are sent to the authorization cloud platform;
[0117] After receiving the target authorization request, the authorization cloud platform verifies the activation authorization operation of the target device according to the target authorization request and the target request file;
[0118] After the verification of the activation authorization operation is passed, the authorization cloud platform generates a target authority file and a target authorization file based on the target request file;
[0119] The target authority file, the target authorization file and the preset cloud platform public key are sent to the target device through the authorization cloud platform to perform online authorization operations on the target device.
[0120] In some embodiments, an online authorization method for a device and an authorization verification method for a device may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the online authorization method for a device and the authorization verification method for a device described above may be executed. Alternatively, in other embodiments, the processor 11 may be configured to execute an online authorization method for a device and an authorization verification method for a device in any other appropriate manner (e.g., by means of firmware).
[0121] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0122] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0123] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0124] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).
[0125] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0126] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.
[0127] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.
Claims
1. A method for online authorization of a device, executed by an online authorization system configured with a target device and an authorization cloud platform, characterized in that: include: Based on the user's activation authorization operation on the target device, a target authorization request and a target request file are generated through the target device, and the target authorization request and the target request file are sent to the authorization cloud platform; After receiving the target authorization request, the authorization cloud platform verifies the activation authorization operation of the target device according to the target authorization request and the target request file; After the verification of the activation authorization operation is passed, the authorization cloud platform generates a target authority file and a target authorization file based on the target request file; The target authority file, the target authorization file and the preset cloud platform public key are sent to the target device through the authorization cloud platform to perform online authorization operations on the target device.
2. The method according to claim 1, characterized in that Based on the user's activation authorization operation on the target device, a target authorization request and a target request file are generated through the target device, including: Acquire device attribute information matching the target device through the target device, and generate a target authorization request based on the device attribute information; Generate a device format file by the target device in response to the user's activation authorization operation, and write the device attribute information into the device format file to obtain a file to be encrypted that matches the target device; The target device performs an encryption operation on the file to be encrypted based on a preset ECDH key exchange algorithm, and uses a pre-configured identity private key to sign the encrypted file to obtain a target request file with device signature information.
3. The method according to claim 1, characterized in that Verifying the activation authorization operation of the target device according to the target authorization request and the target request file includes: Parsing the target authorization request through the authorization cloud platform to obtain device attribute information matching the target authorization request; Decrypt the target request file using a pre-configured ECDH key exchange algorithm through the authorization cloud platform, extract device attribute information from the decrypted file content, and compare it with the device attribute information extracted from the target authorization request to determine whether they are consistent; If they are consistent, the device signature information of the target request file is verified by the authorized cloud platform using the pre-storage service public key; If the signature verification is successful, it is determined that the verification of the activation authorization operation is successful.
4. The method according to claim 1, characterized in that: After the verification of the activation authorization operation is passed, a target authority file and a target authorization file are generated based on the target request file, including: The authorization cloud platform queries a pre-configured authority policy database based on the device attribute information in the target request file to obtain an authority policy template that matches the target device; Generate, by the authorization cloud platform, a permissions file to be encrypted that matches the target device based on the permissions policy template and the device attribute information; The authorization cloud platform performs an encryption operation on the to-be-encrypted authority file based on a preset ECDH key exchange algorithm, and signs the encrypted file using a pre-configured server private key to obtain a target authority file with cloud platform signature information; The authorization cloud platform calculates and generates the target authorization file according to the target request file and the generated target authority file and in accordance with a preset authorization file generation algorithm.
5. A device authorization verification method, executed by a target device equipped with a trusted chip, characterized in that: include: In response to a power-on operation of the target device, performing integrity measurement on the target device through a trusted chip; After the integrity measurement verification is passed, it is detected whether the target request file, the target permission file and the target authorization file exist in the preset location of the trusted chip; When both the target permission file and the target authorization file exist, extract the device attribute information in the target request file and the target permission file, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent; After determining that the device attribute information is consistent with the target attribute information of the target device, the target request file and the target permission file are decrypted and calculated using the pre-stored service public key to obtain the target request signature information and the target permission signature information; Based on a preset signature verification algorithm, determine whether the target request signature information matches the target request file, and determine whether the target authority signature matches the target authority file, and determine that the authorization verification of the target device is successful after determining that both match.
6. The method according to claim 5, characterized in that The authorization verification method of the device also includes: In response to a power-on operation of the target device, detecting whether a network time protocol time synchronization of the target device is in an on state; After detecting that the network time protocol is turned on, obtaining the current system time, and parsing the target request file to obtain device attribute information matching the target device; Based on the authorization time limit information included in the device attribute information, determining whether the current system time is within the authorization time limit; If yes, then it is determined that the authorization verification of the target device is successful; If not, it is determined that the authorization verification of the target device fails.
7. An online authorization device for a device, executed by an online authorization system configured with a target device and an authorization cloud platform, characterized in that: include: A request generation module, configured to generate a target authorization request and a target request file through a target device based on an activation authorization operation of a user on a target device, and send the target authorization request and the target request file to an authorization cloud platform; A request verification module, used for verifying the activation authorization operation of the target device according to the target authorization request and the target request file after the authorization cloud platform receives the target authorization request; A file generation module, configured to generate a target authority file and a target authorization file based on the target request file after the activation authorization operation is verified through the authorization cloud platform; The device activation module is used to send the target authority file, the target authorization file and the preset cloud platform public key to the target device through the authorization cloud platform to perform online authorization operations on the target device.
8. A device authorization verification device, executed by a target device equipped with a trusted chip, characterized in that: include: An integrity measurement module, configured to perform integrity measurement on the target device through a trusted chip in response to a power-on operation of the target device; A file detection module, used to detect whether a target request file, a target permission file, and a target authorization file exist in a preset location of the trusted chip after the integrity measurement verification is passed; The attribute judgment module is used to extract the device attribute information in the target request file and the target authority file when both the target authority file and the target authorization file exist, and compare the device attribute information with the target attribute information of the target device to determine whether they are consistent; The signature information acquisition module is used to, after determining that the device attribute information is consistent with the target attribute information of the target device, use the pre-stored service public key to decrypt the target request file and the target permission file to obtain the target request signature information and the target permission signature information; The signature information confirmation module is used to determine whether the target request signature information matches the target request file based on a preset signature verification algorithm, and to determine whether the target permission signature matches the target permission file, and to determine that the authorization verification of the target device is successful after determining that both match.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute an online authorization method for a device and an authorization verification method for a device as described in any one of claims 1-6.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement an online authorization method for a device and an authorization verification method for a device according to any one of claims 1 to 6 when executed.
Citation Information
Cited By
License verification method and electronic equipment
CN121644088A