Authorization method applied to local area network and local area network authorization system

By setting up authorization servers and business servers in the LAN and distributing and verifying authorization files, the problem that enterprises find it difficult to protect software intellectual property rights when deploying software privately, and the legal verification of terminal device application software and effective protection of intellectual property rights is achieved.

CN120050080APending Publication Date: 2025-05-27BOE TECHNOLOGY GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510182393.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

When enterprises deploy software privately, it is difficult for enterprises to effectively protect software intellectual property rights, especially in LANs without public network environments.

Method used

By setting up an authorization server and a service server in the LAN, and using authorization services to distribute and verify authorization files, we ensure that the legality of the application software of the terminal device is verified. The specific steps include deploying authorization services, obtaining and distributing business authorization documents and terminal authorization documents, performing legal authorization verification on the business and server side, and generating and sending authorization information to the terminal device.

Benefits of technology

It realizes legal verification of terminal device application software in offline environments, ensures the protection of the intellectual property rights of the software, and prevents illegal copying and use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050080A_ABST
    Figure CN120050080A_ABST
Patent Text Reader

Abstract

The invention discloses an authorization method applied to a local area network and a local area network authorization system, and the authorization method in one embodiment comprises the steps: an authorization server deploys and starts an authorization service, and obtains a service authorization file and a terminal authorization file through a mobile storage device; distributing the service authorization file to a service server to perform legalization verification according to the service authorization file; importing a terminal authorization file, performing legalization verification according to the terminal authorization file, and storing each authorization code in the terminal authorization file into a corresponding database when verification succeeds; and based on the legality of the service end of the service server, in response to an authorization request of the to-be-authorized terminal equipment, generating first authorization information according to the authorization code in the database, and sending the first authorization information to the to-be-authorized terminal equipment, so that the terminal equipment performs terminal legalization authorization verification according to the first authorization information. According to the embodiment provided by the invention, legalization verification of the application software applied to the terminal equipment in an offline environment is realized, and the method has a practical application value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of display technology, and particularly to an authorization method applied to a local area network and a local area network authorization system. Background Art

[0002] With the development of society and economy, intellectual property rights are increasingly valued by various countries and enterprises. Enterprises have realized that intellectual property rights are very important intellectual capital for enterprises. In terms of software, protecting software from being illegally stolen and copied can protect the business models and technical assets of enterprises. The existing software protection methods are basically divided into two types: license or online verification. However, there are relatively few software authorization models for the situation without a public network environment within a local area network.

[0003] How to solve the protection of software intellectual property rights during the process of private deployment of software by enterprises has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention

[0004] To solve at least one of the above problems, a first embodiment of the present invention provides an authorization method for an authorization server applied to a local area network, including:

[0005] The authorization server deploys and starts an authorization service, and obtains a service authorization file and a terminal authorization file through a removable storage device;

[0006] Distribute the service authorization file to the corresponding service server, so that the service server performs service-side legalization authorization verification according to the service authorization file;

[0007] Import the terminal authorization file, perform server-side legalization authorization verification according to the terminal authorization file, and store each authorization code in the terminal authorization file in the database corresponding to the authorization service in response to successful verification;

[0008] In response to an authorization request from a terminal device to be authorized, generate first authorization information according to the authorization code in the database and send it to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information, where the authorization request is generated when the service side of the service server is legal.

[0009] For example, in the authorization method provided in some embodiments of the present application, before the deploying and starting the authorization service and obtaining the service authorization file and the terminal authorization file through a removable storage device, the authorization method further includes:

[0010] Encrypt service service information using the private key of an asymmetric encryption algorithm to generate the service authorization file, where the service service information includes a first identifier of the service server where the service application software is deployed;

[0011] The terminal authorization file includes an authorization code list data file and an authorization certificate data file.

[0012] Use the private key of the asymmetric encryption algorithm to encrypt the authorization service information to generate the authorization code list data file. The authorization service information includes the number of authorized devices, customer information, and authorization validity period.

[0013] Use the private key of the asymmetric encryption algorithm to encrypt the customer information to generate the authorization certificate data file. The customer information includes the second identifier of the authorization server.

[0014] For example, in the authorization method provided in some embodiments of the present application, the step of using the private key of the asymmetric encryption algorithm to encrypt the authorization service information to generate the authorization code list data file further includes:

[0015] Generate an authorization code list according to the number of authorized devices using a random algorithm.

[0016] Use the private key of the asymmetric encryption algorithm to encrypt according to the number of authorized devices, customer information, authorization validity period, and the authorization code list to generate the authorization code list data file.

[0017] For example, in the authorization method provided in some embodiments of the present application, the service server includes a deployed business application software and a business authorization software development kit. The business application software is the background software of the application software installed on the terminal device. The step of distributing the business authorization file to the corresponding service server so that the service server performs a business-side legalization authorization check according to the business authorization file further includes:

[0018] The business authorization software development kit uses the public key to decrypt the business authorization file and obtain the first identifier of the service server, obtains the device fingerprint of the service server, and compares it with the first identifier. If the comparison result is consistent, it is determined that the business application software of the service server is legal software.

[0019] For example, in the authorization method provided in some embodiments of the present application, the step of importing the terminal authorization file, performing a server-side legalization authorization check according to the terminal authorization file, and storing each authorization code in the terminal authorization file in the database corresponding to the authorization service in response to a successful check further includes:

[0020] Import the authorization code list data file and the authorization certificate data file respectively.

[0021] Use the public key to decrypt the authorization certificate data file and obtain the customer information.

[0022] Obtain the device fingerprint of the authorization server, and compare it with the device fingerprint of the authorization server based on the customer information. If the comparison result is consistent, determine that the authorization service is legal;

[0023] Use the public key to decrypt the authorization code list data file and obtain the authorization service information and the authorization code list, and store the authorization code list and the corresponding authorization validity period in the database corresponding to the authorization service.

[0024] For example, in the authorization method provided by some embodiments of the present application, the terminal device includes an installed application software and an application software authorization software development kit. Responding to the authorization request of the terminal device to be authorized, and generating first authorization information according to the authorization code in the database and sending it to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information further includes:

[0025] Receive the authorization request of the terminal device to be authorized, and the authorization request includes the third identifier of the terminal device to be authorized;

[0026] Obtain an available authorization code from the database, bind it with the device fingerprint of the terminal device to be authorized to generate first authorization information and send it to the terminal device to be authorized;

[0027] So that the application software authorization software development kit of the terminal device obtains the device fingerprint of the terminal device, obtains the third identifier according to the first authorization information and compares it with the device fingerprint of the terminal device. If the comparison result is consistent, determine that the application software installed on the terminal device is legal software.

[0028] For example, in the authorization method provided by some embodiments of the present application, in response to the application software installed on the terminal device being legal software, the authorization method further includes:

[0029] Receive the authorization validity request of the terminal device, and the authorization validity request includes the first authorization information;

[0030] Obtain the corresponding authorization validity period from the database according to the authorization code of the first authorization information;

[0031] Obtain the current time. In response to the current time being within the authorization validity period, determine that the application software of the terminal device is legal software. In response to the current time exceeding the authorization validity period, close the application software of the terminal device.

[0032] The second embodiment of the present invention provides an authorization method for a service server applied to a local area network, including:

[0033] Receive a service authorization file;

[0034] Perform service - side legalization authorization verification according to the service authorization file. The service server includes deployed service application software and a service authorization software development kit. The service application software is the background software of the application software installed on the terminal device, and further includes:

[0035] The service authorization software development kit decrypts the service authorization file using a public key and obtains the first identifier of the service server, obtains the device fingerprint of the service server and compares it with the first identifier. If the comparison result is consistent, it is determined that the service application software of the service server is legal software. The service authorization file is generated by encrypting service information using the private key of an asymmetric encryption algorithm. The service information includes the first identifier of the service server on which the service application software is deployed.

[0036] The third embodiment of the present invention provides an authorization method for a terminal device applied to a local area network, including:

[0037] Send an authorization request. The authorization request is generated when the service side of the service server in the local area network is legal and includes the third identifier of the terminal device to be authorized;

[0038] Receive the first authorization information sent by the authorization server. The first authorization information is generated by binding an available authorization code obtained by the authorization server from the database with the device fingerprint of the terminal device to be authorized;

[0039] Perform terminal legalization authorization verification according to the first authorization information. The terminal device includes installed application software and an application software authorization development kit, and further includes: The application software authorization development kit obtains the device fingerprint of the terminal device to which it belongs, obtains the third identifier according to the first authorization information and compares it with the device fingerprint of the terminal device. If the comparison result is consistent, it is determined that the application software installed on the terminal device is legal software.

[0040] For example, in the authorization method provided in some embodiments of the present application, send an authorization validity request. The authorization validity request includes the first authorization information, so that the authorization server obtains the corresponding authorization validity period from the database according to the authorization code of the first authorization information, obtains the current time and compares it with the authorization validity period:

[0041] Responding to the current time being within the authorization validity period, it is determined that the application software of the terminal device is legal software;

[0042] When the current time exceeds the authorized validity period, close the application software of the terminal device.

[0043] The fourth embodiment of the present invention provides a local area network authorization system, including an authorization server, at least one service server, and multiple terminal devices. Among them, the authorization server is configured to:

[0044] Deploy and start the authorization service, and obtain the service authorization file and the terminal authorization file through a removable storage device;

[0045] Distribute the service authorization file to the corresponding service server, so that the service server performs service-side legalization authorization verification according to the service authorization file;

[0046] Import the terminal authorization file, perform server-side legalization authorization verification according to the terminal authorization file, and store each authorization code in the terminal authorization file in the database corresponding to the authorization service in response to successful verification;

[0047] In response to the authorization request of the terminal device to be authorized, generate first authorization information according to the authorization code in the database and send it to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information. The authorization request is generated when the service side of the terminal device is legal based on the service server.

[0048] For example, in the authorization system provided by some embodiments of the present application, the service server and the authorization server are one server.

[0049] The fifth embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method described in any one of the first embodiment, the second embodiment, and the third embodiment.

[0050] The sixth embodiment of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method described in any one of the first embodiment, the second embodiment, and the third embodiment.

[0051] The beneficial effects of the present invention are as follows:

[0052] In view of the existing problems at present, the present invention formulates an authorization method and an authorization system applied to a local area network. In the embodiments provided by the present invention, an authorization server and a service server are set up in an offline local area network, an authorization file is imported into the authorization service of the authorization server, and the authorization service is used to distribute the authorization file to the service server to implement the legalization verification of the service end. The authorization service is used to perform legalization verification on the service end according to the authorization file, generate authorization information in response to the authorization request of the terminal device to be authorized, and implement terminal legalization verification according to the authorization information, effectively realizing the legalization verification of the application software applied to the terminal device in an offline environment. In particular, an external online authorization service platform is used to generate a service authorization file and a terminal authorization file according to the information of the service server and the terminal device in the local area network, so as to ensure the security of the authorization source; that is, a low-cost secure authorization is realized based on the combination of online and offline methods, effectively realizing the secure authorization of enterprise software, thereby effectively preventing the software from being illegally copied and used, and having practical application value. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0054] Figure 1 The flowchart showing the authorization method according to an embodiment of the present invention;

[0055] Figure 2 The block diagram showing the structure of the authorization system according to an embodiment of the present invention;

[0056] Figure 3 The swimlane diagram showing the authorization method according to an embodiment of the present invention;

[0057] Figure 4 The schematic diagram showing the generation of the authorization code list data file according to an embodiment of the present invention;

[0058] Figure 5 The flowchart showing the legalization verification of the authorization service according to an embodiment of the present invention;

[0059] Figure 6 The flowchart showing the authorization method according to another embodiment of the present invention;

[0060] Figure 7 The flowchart showing the authorization method according to another embodiment of the present invention;

[0061] Figure 8Schematic structural diagram of a computer device according to another embodiment of the present invention. Detailed implementation manners

[0062] To more clearly illustrate the present invention, the present invention will be further described below in conjunction with preferred embodiments and the accompanying drawings. Similar components in the drawings are denoted by the same reference numerals. Those skilled in the art should understand that the content specifically described below is illustrative rather than restrictive, and should not be used to limit the protection scope of the present invention.

[0063] Regarding the problems existing in the related art, such as Figure 1 As shown, an authorization method for an authorization server applied to a local area network according to an embodiment of the present invention includes:

[0064] Deploy and start the authorization service, and obtain a service authorization file and a terminal authorization file through a removable storage device;

[0065] Distribute the service authorization file to the corresponding service server so that the service server performs service-side legalization authorization verification according to the service authorization file;

[0066] Import the terminal authorization file, perform server-side legalization authorization verification according to the terminal authorization file, and store each authorization code in the terminal authorization file in the database corresponding to the authorization service in response to successful verification;

[0067] Respond to the authorization request of the terminal device to be authorized, generate first authorization information according to the authorization code in the database, and send it to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information, and the authorization request is generated when the service side of the terminal device based on the service server is legal.

[0068] In this embodiment, in the case of not connecting to the Internet, by setting an authorization server and a service server in the local area network, importing the authorization file into the authorization service of the authorization server, using the authorization service to distribute the authorization file to the service server to implement service-side legalization verification, using the authorization service to perform server-side legalization verification according to the authorization file, and generating authorization information in response to the authorization request of the terminal device to be authorized to implement terminal legalization verification according to the authorization information, effectively realizing the legalization verification of the application software applied to the terminal device in an offline environment.

[0069] To further illustrate the specific implementation manners of the present application, in a specific example, the authorization of the service server and the terminal device in the local area network is taken as an example for illustration. As Figure 2As shown, the authorization system of the present invention that is not connected to the Internet and is applied to a local area network includes an authorization server, at least one service server, and multiple terminal devices. The authorization server is a local server set in the local area network, connected to each service server and each terminal device, and is used to receive the authorization file generated by an external online authorization service platform. The authorization file includes a service authorization file for verifying the legitimacy of the service application software installed on the service server in the local area network, and a terminal authorization file for verifying the legitimacy of the authorization service on the authorization server in the local area network and the legitimacy of the application software installed on the terminal device. The service server is a local server installed with service application software in the local area network. The service application software is the background software of the application software installed on the terminal device. The legitimacy of the service application software on the service server is a prerequisite for the startup of the service application software, and the startup of the service application software is a prerequisite for the startup of the application software on the terminal device. The terminal device is a carrier such as a smart phone, a tablet computer, or a notebook used by a user, which can install and run application software. The terminal device can be an Android system, a Windows system, or a Linux system.

[0070] It should be noted that the present application does not make specific limitations on the setting of the service server. According to the hardware requirements for the operation of the service application software, the service server can be the same server as the authorization server, or the service server can be a server independent of the authorization server. When there are multiple service application software and each service application software needs to be independently configured, the service server includes multiple service servers that respectively install each service application software. Those skilled in the art should set an appropriate service server according to actual application requirements.

[0071] As Figure 3 shown, authorizing the service server and the terminal device in the local area network specifically includes the following steps:

[0072] Preparation step: Use an external online authorization service platform to generate an authorization file inside the local area network.

[0073] In this embodiment, through the online authorization service platform, for example, the cloud authorization service platform uses the private key of the asymmetric encryption algorithm to encrypt the service information to generate the service authorization file, and encrypts the authorization service information to generate the terminal authorization file.

[0074] Specifically, the business service information includes the first identifier of the business server on which the business application software is deployed, and may also include the authorization time and the identifier of the business application software. The first identifier is a unique identifier capable of characterizing the business server, such as the device fingerprint of the business server. The authorization time is the authorization period of the business application software, and the identifier of the business application software is an identifier characterizing the business application software, such as the name of the business application software. The external online authorization service platform generates a business authorization file, such as a license, based on the business service information, so that the business server can decrypt the business authorization file according to the public key and obtain the business service information.

[0075] Further, the terminal authorization file includes an authorization code list data file and an authorization certificate data file. Among them, the authorization code list data file is generated by encrypting the authorization service information using the private key of the asymmetric encryption algorithm by the external online authorization service platform. The authorization service information includes the number of authorized devices, customer information, and authorization validity period. The authorization certificate is generated by encrypting the customer information using the private key of the asymmetric encryption algorithm by the external online authorization service platform. The customer information includes the second identifier of the authorization server. The second identifier is a unique identifier characterizing the authorization server, such as the device fingerprint of the authorization server. That is, only when the customer information matches can the legitimacy of the authorization server be indicated.

[0076] Specifically, as Figure 4 shown, an authorization code list is generated using a random algorithm according to the number of authorized devices; according to the number of authorized devices, customer information, authorization validity period, and the authorization code list, the authorization code list data file is generated by encrypting using the private key of the asymmetric encryption algorithm. Among them, the authorization code list data file includes multiple authorization code data files, such as 8-bit short codes, and is saved in the file in ciphertext form.

[0077] In this embodiment, the external online authorization service platform uses the private key of the asymmetric encryption algorithm to generate ciphertext based on the device fingerprints of the business server and the authorization server in the local area network, that is, the business authorization file and the terminal authorization file including the authorization code list data file and the authorization certificate data file, so as to ensure the unified issuance of the authorization file and ensure the security of the authorization source.

[0078] The first step is that the authorization server deploys and starts the authorization service.

[0079] In this embodiment, within the local area network, an authorization service is deployed on the authorization server. The authorization service is developed using the Java language, providing an integrated front-end and back-end web service. To ensure a lightweight service, a lightweight database is also integrated, which occupies less resources. The lightweight authorization service provides a web page where authorization credentials and authorization code lists are imported through the page. Server-side legitimacy verification is performed based on the decrypted authorization credentials, and the authorization code list is decrypted and stored in the lightweight database.

[0080] In the second step, the authorization server receives the authorization file.

[0081] In this embodiment, since the local area network is not connected to the Internet, the business authorization file and the terminal authorization file generated by the external online authorization service platform are transmitted to the authorization server through a removable storage device, such as a USB flash drive or a portable hard drive.

[0082] In the third step, the authorization service distributes the business authorization file to the business server.

[0083] In this embodiment, the authorization service sends the business authorization file to the business server. For example, the authorization service decrypts the business authorization file using the public key. Especially when there are multiple services, the corresponding business server is determined according to the name of the business software.

[0084] In the fourth step, the business server performs business-side legalization authorization verification based on the received business authorization file.

[0085] In this embodiment, the service server includes deployed business application software and a business authorization software development kit. The business application software is the background software of the application software installed on the terminal device. The business authorization software development kit decrypts the business authorization file using the public key and obtains the first identifier of the service server, obtains the device fingerprint of the service server, and compares it with the first identifier. If the comparison result is consistent, it is determined that the business application software of the service server is legal software. In this embodiment, the authorization server in the local area network distributes the business authorization file to the service server, and the business authorization software development kit of the service server realizes the legality verification of the service end. If the comparison result is inconsistent, it indicates that the business application software is illegal software, and the business application software cannot be started, which is manifested as the business application software being closed. Further, the application software installed on the terminal device in this local area network cannot be started either, which is manifested as the application software being closed. That is, only when the legalization authorization verification of the business application software is legal, the application software installed on the terminal device can be started, and the subsequent legalization authorization verification of the application software on the terminal device is carried out; otherwise, the terminal device cannot start the application software, and there is no legalization authorization verification of the application software. This embodiment further improves the protection of the intellectual property rights of software applied to the local area network by performing legalization authorization verification on the business application software in the local area network.

[0086] Step 5: The authorization service imports the terminal authorization file.

[0087] Step 6: The authorization service performs server-side legalization authorization verification according to the terminal authorization file.

[0088] Step 7: The authorization service stores each authorization code in the authorization code list of the terminal authorization file into the corresponding database.

[0089] In this embodiment, as Figure 5 shown, it specifically includes the following steps:

[0090] First, the terminal authorization file includes an authorization code list data file and an authorization credential data file, and the two files are imported separately through the web page of the authorization service.

[0091] Second, the authorization service decrypts the authorization credential data file using the public key and obtains the customer information.

[0092] Third, the authorization service obtains the device fingerprint of the authorization server, and compares it with the device fingerprint of the authorization server according to the customer information. If the comparison result is consistent, it is determined that the authorization service is legal.

[0093] Finally, the authorization service decrypts the authorization code list data file using the public key, obtains the authorization service information and the authorization code list, and stores the authorization code list and the corresponding authorization validity period in the database corresponding to the authorization service.

[0094] In this embodiment, the authorization service is legally verified through the authorization certificate. After obtaining the legality, the obtained authorization code list, such as multiple authorization codes and the corresponding authorization validity period, is stored in the corresponding lightweight database. If the comparison result is inconsistent, it indicates that the authorization service is illegal, manifested as the authorization service being closed, and the subsequent legal authorization verification of the application software of the terminal device will no longer be performed.

[0095] Step 8: The terminal device sends an authorization request to the authorization server.

[0096] Step 9: The authorization service generates the first authorization information according to the authorization request and the authorization code in the database.

[0097] Step 10: The authorization service sends the first authorization information to the terminal device.

[0098] In this embodiment, in response to the installation of the application software on the terminal device to be authorized, when the business application software is legal, an authorization request is sent to the authorization server when the application software is started. The authorization request includes the third identifier of the terminal device to be authorized, and the third identifier is a unique identifier representing the terminal device, such as the device fingerprint of the terminal device. An available authorization code is obtained from the database, bound to the device fingerprint of the terminal device to be authorized to generate the first authorization information, and sent to the terminal device to be authorized. The terminal device includes an application software and an application software authorization software development kit, and the application software authorization software development kit performs a legality check on the terminal device according to the obtained first authorization information.

[0099] Specifically, it includes the following steps:

[0100] First, the address of the lightweight authorization service (local area network address, such as: http: / / 10.10.130.51:8090) is configured on the application software of the terminal device.

[0101] Second, the application software uses an http request, such as using the okhttp package, to call the access interface of the authorization service to obtain the interface access token token.

[0102] Third, the current device fingerprint is obtained through the application software authorization software development kit.

[0103] Next, the terminal application calls the regist interface to apply for a license based on the device fingerprint, so that the authorization service generates the first authorization information, that is, the license, according to the device fingerprint and an authorization code obtained from the database, and transmits it to the terminal device.

[0104] Finally, the application software authorization software development kit of the terminal device performs terminal legalization authorization verification according to the first authorization information. The terminal device includes the installed application software and the application software authorization software development kit. Specifically, the application software authorization software development kit obtains the device fingerprint of the terminal device to which it belongs, obtains the third identifier according to the first authorization information, and compares it with the device fingerprint of the terminal device. If the comparison result is consistent, it is determined that the application software installed on the terminal device is legal software. If the comparison result is inconsistent, it indicates that the terminal device is an illegal device and the application software is illegal software, which is manifested as the application software being closed.

[0105] So far, the authorization of the business server and the terminal device in the local area network is completed. In this embodiment, by setting an authorization server and a business server in an offline local area network, importing the authorization file into the authorization service of the authorization server, using the authorization service to distribute the authorization file to the business server to implement the legalization verification of the service end, using the authorization service to perform the legalization verification of the service end according to the authorization file, and generating authorization information in response to the authorization request of the terminal device to be authorized to implement the legalization verification of the terminal according to the authorization information, the legalization verification of the application software applied to the terminal device in the offline environment is effectively realized. In particular, using an external online authorization service platform to generate a business authorization file and a terminal authorization file according to the information of the business server and the terminal device in the local area network, thereby ensuring the security of the authorization source; that is, realizing low-cost secure authorization based on the combination of online and offline methods, effectively realizing the secure authorization of enterprise software, and thus effectively preventing the software from being illegally copied and used, which has practical application value.

[0106] Considering that the application software of the terminal device has an authorization validity period, in an optional embodiment, in response to the application software installed on the terminal device being legal software, the authorization method further includes:

[0107] Receiving an authorization validity request from the terminal device, where the authorization validity request includes the first authorization information;

[0108] Obtaining the corresponding authorization validity period from the database according to the authorization code of the first authorization information;

[0109] Obtaining the current time, and in response to the current time being within the authorization validity period, determining that the application software of the terminal device is legal software, and in response to the current time exceeding the authorization validity period, closing the application software of the terminal device.

[0110] In this embodiment, at set time intervals, the application software of the terminal device sends an authorization validity check to the authorization service. The authorization service obtains the corresponding authorization validity period from the database based on the authorization code of the first authorization information obtained by the terminal device during the legality check, and compares the authorization validity period with the current time to determine the authorization validity of the application software of the terminal device. When the current time is within the authorization validity period, it indicates that the application software is legal software and continues to run; otherwise, it is illegal software and the application software is closed. This embodiment ensures the protection of the enterprise's intellectual property rights and intellectual property benefits from infringement by performing an authorization validity check on the application software of the terminal device.

[0111] Based on the authorization method of the above embodiment, as Figure 6 shown, an authorization method for a business server applied to a local area network includes:

[0112] Receive a business authorization file;

[0113] Perform a business - end legalization authorization check according to the business authorization file. The business server includes deployed business application software and a business authorization software development kit. The business application software is the background software of the application software installed on the terminal device. Further included is that the business authorization software development kit decrypts the business authorization file using a public key and obtains the first identifier of the business server, obtains the device fingerprint of the business server and compares it with the first identifier. If the comparison result is consistent, it is determined that the business application software of the business server is legal software. The business authorization file is generated by encrypting business service information using the private key of an asymmetric encryption algorithm. The business service information includes the first identifier of the business server on which the business application software is deployed.

[0114] In this embodiment, by setting an authorization server and a business server in an offline local area network, importing the authorization file into the authorization service of the authorization server, using the authorization service to distribute the authorization file to the business server to achieve business - end legalization verification, using the authorization service to perform server - end legalization verification according to the authorization file, and generating authorization information in response to the authorization request of the terminal device to be authorized to achieve terminal legalization verification according to the authorization information, it effectively realizes the legalization verification of the application software applied to the terminal device in an offline environment.

[0115] Based on the authorization method of the above embodiment, as Figure 7 shown, an authorization method for a terminal device applied to a local area network includes:

[0116] Send an authorization request. The authorization request is generated when the business end of the business server in the local area network is legal and includes the third identifier of the terminal device to be authorized;

[0117] Receive the first authorization information sent by the authorization server, where the first authorization information is generated by the authorization server by obtaining an available authorization code from the database and binding it to the device fingerprint of the terminal device to be authorized;

[0118] Perform terminal legalization authorization verification according to the first authorization information. The terminal device includes the installed application software and the application software authorization software development kit, and further includes: the application software authorization software development kit obtains the device fingerprint of the terminal device to which it belongs, obtains the third identifier according to the first authorization information, and compares it with the device fingerprint of the terminal device. If the comparison result is consistent, it is determined that the application software installed on the terminal device is legal software.

[0119] In this embodiment, an authorization server and a service server are set up in an offline local area network. The authorization file is imported into the authorization service of the authorization server, and the authorization service distributes the authorization file to the service server to implement service-side legalization verification. The authorization service performs service-side legalization verification according to the authorization file, generates authorization information in response to the authorization request of the terminal device to be authorized, and implements terminal legalization verification according to the authorization information, effectively realizing the legalization verification of the application software applied to the terminal device in an offline environment.

[0120] In an optional embodiment, the authorization method further includes:

[0121] Send an authorization validity request, where the authorization validity request includes the first authorization information, so that the authorization server obtains the corresponding authorization validity period from the database according to the authorization code of the first authorization information, obtains the current time, and compares it with the authorization validity period:

[0122] If the current time is within the authorization validity period, it is determined that the application software of the terminal device is legal software; or, if the current time exceeds the authorization validity period, the application software of the terminal device is closed.

[0123] In this embodiment, at the set time interval, the application software of the terminal device sends an authorization validity check to the authorization service. The authorization service obtains the corresponding authorization validity period from the database according to the authorization code of the first authorization information obtained by the terminal device during the legality check, and compares the authorization validity period with the current time to judge the authorization validity of the application software of the terminal device. When the current time is within the authorization validity period, it indicates that the application software is legal software and continues to run; otherwise, if it is illegal software, the application software is closed. This embodiment ensures the protection of the enterprise's intellectual property rights and intellectual property benefits from infringement by performing authorization validity verification on the application software of the terminal device.

[0124] Based on the authorization method of the above embodiments, as Figure 2 shown, an embodiment of the present invention provides a local area network authorization system, including an authorization server, at least one service server, and a plurality of terminal devices, wherein the authorization server is configured to:

[0125] Deploy and start an authorization service, and obtain a service authorization file and a terminal authorization file through a removable storage device;

[0126] Distribute the service authorization file to the corresponding service server, so that the service server performs service - end legalization authorization verification according to the service authorization file;

[0127] Import the terminal authorization file, perform server - end legalization authorization verification according to the terminal authorization file, and store each authorization code in the terminal authorization file in the database corresponding to the authorization service in response to successful verification;

[0128] Respond to an authorization request of a terminal device to be authorized, generate first authorization information according to the authorization code in the database, and send it to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information, and the authorization request is generated when the service - end of the terminal device is legal based on the service server.

[0129] The local area network authorization system of this embodiment sets an authorization server and a service server in an offline local area network, imports the authorization file into the authorization service of the authorization server, uses the authorization service to distribute the authorization file to the service server to achieve service - end legalization verification, uses the authorization service to perform server - end legalization verification according to the authorization file, and responds to the authorization request of the terminal device to be authorized to generate authorization information to achieve terminal legalization verification according to the authorization information, effectively realizing the legalization verification of application software applied to terminal devices in an offline environment.

[0130] In an optional embodiment, the service server and the authorization server are one server.

[0131] In this embodiment, according to the hardware requirements for running the service application software, the service server and the authorization server can be the same server. The local area network authorization system includes a server deployed with an authorization service and a service application software, and a plurality of terminal devices.

[0132] Another embodiment of the present invention provides a computer - readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements an authorization method applied to a local area network.

[0133] In practical applications, the computer-readable storage medium may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0134] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0135] The program code contained on the computer-readable medium may be transmitted by any appropriate medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.

[0136] The computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by connecting through an Internet service provider via the Internet).

[0137] As Figure 8As shown, a schematic structural diagram of a computer device provided by another embodiment of the present invention. Figure 8 The computer device T12 shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.

[0138] As Figure 8 shown, the computer device T12 is presented in the form of a general-purpose computing device. The components of the computer device T12 may include, but are not limited to: one or more processors or processing units T16, a system memory T28, and a bus T18 connecting different system components (including the system memory T28 and the processing unit T16).

[0139] The bus T18 represents one or more of several types of bus architectures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus architectures. For example, these architectures include, but are not limited to, Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.

[0140] The computer device T12 typically includes a variety of computer system-readable media. These media can be any available media accessible by the computer device T12, including volatile and non-volatile media, removable and non-removable media.

[0141] The system memory T28 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) T30 and / or cache memory T32. The computer device T12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system T34 can be used to read and write non-removable, non-volatile magnetic media ( Figure 8 not shown, commonly referred to as a "hard disk drive"). Although Figure 8 not shown in the figure, a disk drive for reading and writing removable non-volatile disks (such as "floppy disks") and an optical disk drive for reading and writing removable non-volatile optical disks (such as CD-ROM, DVD-ROM, or other optical media) can be provided. In these cases, each drive can be connected to the bus T18 through one or more data media interfaces. The memory T28 may include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0142] A program / utility T40 having a set (at least one) of program modules T42 can be stored, for example, in a memory T28. Such program modules T42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules T42 generally execute the functions and / or methods in the embodiments described in the present invention.

[0143] The computer device T12 can also communicate with one or more external devices T14 (such as a keyboard, a pointing device, a display T24, etc.), and can also communicate with one or more devices that enable a user to interact with the computer device T12, and / or communicate with any device that enables the computer device T12 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface T22. Moreover, the computer device T12 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter T20. As Figure 8 shown, the network adapter T20 communicates with other modules of the computer device T12 through a bus T18. It should be understood that although Figure 8 not shown in the figure, other hardware and / or software modules can be used in conjunction with the computer device T12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0144] The processor unit T16 executes various functional applications and data processing by running programs stored in the system memory T28, such as implementing an authorization method applied to a local area network provided by the embodiments of the present invention.

[0145] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limitations on the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or modifications can be made based on the above description. It is impossible to list all the implementation manners here. Any obvious changes or modifications derived from the technical solutions of the present invention still fall within the protection scope of the present invention.

Claims

1. An authorization method applied to a local area network, characterized in that: Applicable to the authorization server, including: Deploy and start the authorization service, and obtain the business authorization file and terminal authorization file through the mobile storage device; Distribute the service authorization file to the corresponding service server, so that the service server performs service end legalization authorization verification according to the service authorization file; Importing the terminal authorization file, performing a server-side legalization authorization verification according to the terminal authorization file, and storing each authorization code in the terminal authorization file into a database corresponding to the authorization service in response to successful verification; In response to an authorization request from a terminal device to be authorized, first authorization information is generated based on the authorization code in the database and sent to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification based on the first authorization information. The authorization request is generated by the terminal device when the business end of the business server is legal.

2. The authorization method according to claim 1, characterized in that: Before the authorization service is deployed and started, and the service authorization file and the terminal authorization file are obtained through the mobile storage device, the authorization method further includes: The business authorization file is generated by encrypting the business service information using a private key of an asymmetric encryption algorithm, wherein the business service information includes a first identifier of a business server where the business application software is deployed; The terminal authorization file includes an authorization code list data file and an authorization credential data file, The authorization service information is encrypted using a private key of an asymmetric encryption algorithm to generate the authorization code list data file, wherein the authorization service information includes the number of authorized devices, customer information, and authorization validity period. The client information is encrypted using a private key of an asymmetric encryption algorithm to generate the authorization credential data file, wherein the client information includes the second identifier of the authorization server.

3. The authorization method according to claim 2, characterized in that: The step of using a private key of an asymmetric encryption algorithm to encrypt the authorization service information to generate the authorization code list data file further includes: Generate an authorization code list using a random algorithm according to the number of authorized devices; The authorization code list data file is generated by encrypting using a private key of an asymmetric encryption algorithm according to the number of authorized devices, customer information, authorization validity period, and authorization code list.

4. The authorization method according to claim 2, characterized in that: The business server includes deployed business application software and a business authorization software development kit, wherein the business application software is the background software of the application software installed on the terminal device, and the business authorization file is distributed to the corresponding business server so that the business server performs business end legalization authorization verification according to the business authorization file further includes: The business authorization software development toolkit uses the public key to decrypt the business authorization file and obtain the first identifier of the business server, obtains the device fingerprint of the business server and compares it with the first identifier. If the comparison results are consistent, it is determined that the business application software of the business server is legal software.

5. The authorization method according to claim 4, characterized in that: The step of importing the terminal authorization file, performing a server-side legalization authorization verification according to the terminal authorization file, and storing each authorization code in the terminal authorization file in a database corresponding to the authorization service in response to successful verification further includes: Import the authorization code list data file and the authorization credential data file respectively; Decrypt the authorization credential data file using the public key and obtain the customer information; Obtain the device fingerprint of the authorization server, and compare the device fingerprint of the authorization server with the customer information, and if the comparison results are consistent, determine that the authorization service is legal; The authorization code list data file is decrypted using a public key to obtain the authorization service information and the authorization code list, and the authorization code list and the corresponding authorization validity period are stored in a database corresponding to the authorization service.

6. The authorization method according to claim 5, characterized in that: The terminal device includes installed application software and an application software authorization software development kit, and the method of responding to an authorization request of the terminal device to be authorized and generating first authorization information according to the authorization code in the database and sending the first authorization information to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification according to the first authorization information, further includes: receiving an authorization request from the terminal device to be authorized, wherein the authorization request includes a third identifier of the terminal device to be authorized; Obtaining an available authorization code from the database, binding the code with the device fingerprint of the terminal device to be authorized to generate first authorization information, and sending the first authorization information to the terminal device to be authorized; So that the application software authorization software development tool kit of the terminal device obtains the device fingerprint of the terminal device, obtains the third identifier according to the first authorization information and compares it with the device fingerprint of the terminal device, and if the comparison results are consistent, it is determined that the application software installed on the terminal device is legal software.

7. The authorization method according to claim 6, characterized in that: In response to the application software installed on the terminal device being legal software, the authorization method further includes: receiving an authorization validity request of the terminal device, wherein the authorization validity request includes the first authorization information; Acquire the corresponding authorization validity period from the database according to the authorization code of the first authorization information; The current time is obtained, and in response to the current time being within the authorization validity period, the application software of the terminal device is determined to be legal software; in response to the current time exceeding the authorization validity period, the application software of the terminal device is closed.

8. An authorization method applied to a local area network, characterized in that: Applied to business servers, including: Receive business authorization documents; The business end legalization authorization verification is performed according to the business authorization file, and the business server includes deployed business application software and a business authorization software development kit, and the business application software is the background software of the application software installed on the terminal device, and further includes: The business authorization software development toolkit uses the public key to decrypt the business authorization file and obtain the first identifier of the business server, obtains the device fingerprint of the business server and compares it with the first identifier. If the comparison results are consistent, it is determined that the business application software of the business server is legal software. The business authorization file is generated by encrypting the business service information using the private key of an asymmetric encryption algorithm. The business service information includes the first identifier of the business server on which the business application software is deployed.

9. An authorization method applied to a local area network, characterized in that: Applied to terminal equipment, including: Sending an authorization request, wherein the authorization request is generated by the terminal device when the service end of the service server in the local area network is legitimate and includes a third identifier of the terminal device to be authorized; Receive first authorization information sent by an authorization server, where the first authorization information is generated by binding an available authorization code obtained by the authorization server from a database and a device fingerprint of the terminal device to be authorized; The terminal legalization authorization verification is performed according to the first authorization information. The terminal device includes installed application software and an application software authorization software development kit, further including: the application software authorization software development kit obtains the device fingerprint of the terminal device to which it belongs, obtains the third identifier according to the first authorization information and compares it with the device fingerprint of the terminal device, and if the comparison results are consistent, it is determined that the application software installed on the terminal device is legal software.

10. The authorization method according to claim 9, characterized in that: The authorization method further includes: Sending an authorization validity request, the authorization validity request including the first authorization information, so that the authorization server obtains the corresponding authorization validity period from the database according to the authorization code of the first authorization information, obtains the current time and compares it with the authorization validity period: In response to the current time being within the authorization validity period, determining that the application software of the terminal device is legal software; In response to the current time exceeding the authorization validity period, the application software of the terminal device is closed.

11. A local area network authorization system, characterized in that: The system comprises an authorization server, at least one service server, and a plurality of terminal devices, wherein the authorization server is configured as follows: Deploy and start the authorization service, and obtain the business authorization file and terminal authorization file through the mobile storage device; Distribute the service authorization file to the corresponding service server, so that the service server performs service end legalization authorization verification according to the service authorization file; Importing the terminal authorization file, performing a server-side legalization authorization verification according to the terminal authorization file, and storing each authorization code in the terminal authorization file into a database corresponding to the authorization service in response to successful verification; In response to an authorization request from a terminal device to be authorized, first authorization information is generated based on the authorization code in the database and sent to the terminal device to be authorized, so that the terminal device performs terminal legalization authorization verification based on the first authorization information. The authorization request is generated by the terminal device when the business end of the business server is legal.

12. The local area network authorization system according to claim 11, characterized in that: The business server and the authorization server are one server.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.

14. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 10 is implemented.