Method for designing software online authorization system
By designing an online software authorization system, the existing authorization methods are inconvenient and insufficient security are solved, and convenient, safe and efficient authorization management is achieved, and diverse software distribution and use scenarios are adapted to.
Patent Information
- Application Number
- CN202411905187.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-23
- Publication Date
- 2025-05-30
AI Technical Summary
The existing software authorization methods have problems such as inconvenient authorization management, insufficient security, and inability to adapt to diverse software distribution and usage scenarios.
Design an online software authorization system, and manage users, customers, products and authorizations by building relationships between systems, designing front-end interfaces and back-end services, databases and security mechanisms, and realize authorization verification and version information collection.
It improves the convenience and security of the authorization process, reduces management costs, adapts to a diverse software distribution and use scenarios, supports a variety of authorization modes and device types, and enhances the flexibility and sustainability of software protection and management.
Smart Images

Figure CN120068024A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software authorization, and more specifically, to a method for designing an online software authorization system. Background Art
[0002] With the rapid development of the software industry, the value of software products has become increasingly prominent, and thus the need for software protection has become increasingly urgent. Traditional software protection methods, such as hardware-based dongles and serial number verification, although playing a protective role to a certain extent, have many limitations. For example, hardware dongles are easy to lose or damage, while serial number verification is easy to be cracked or shared. Therefore, a more efficient, convenient and secure software protection method is needed.
[0003] With the rapid development of Internet technology, software online authorization has become possible. Through Internet technology, software developers can establish a cloud authorization server to realize the online storage and management of authorization information. When users use software, they only need to communicate with the cloud server to verify the authorization information to obtain the usage rights of the software. This method not only improves the convenience of the authorization process, but also reduces the management cost and enhances the security of the authorization information.
[0004] With the popularization of technologies such as cloud computing and mobile Internet, software distribution and usage scenarios have become increasingly diverse. Traditional software authorization methods can no longer meet the diverse needs of modern software products. For example, in a cloud computing environment, software products are usually provided to users in the form of SaaS (Software as a Service), which requires an online authorization method that can adapt to the cloud computing environment. In addition, with the popularization of mobile devices, the authorization management of mobile application software has become increasingly important. Therefore, an online authorization system that can be applied to multiple distribution and usage scenarios is needed.
[0005] Limitations of Existing Authorization Schemes Inconvenient authorization management: Software developers need to manually manage users' authorization information, which increases the management cost and is more prone to errors.
[0006] Insufficient security: Traditional authorization methods are easy to be cracked or stolen, resulting in the infringement of the copyright of software products.
[0007] To solve these problems, an online software authorization system has emerged. It realizes software authorization and management through an online method, which can greatly improve the convenience and security of the authorization process, reduce the management cost, and at the same time adapt to diverse software distribution and usage scenarios.
[0008] In the design of an online software authorization system, there are already some implementation schemes similar to the present invention. These schemes mainly include the following: 1. Cloud-based software licensing solution: This solution stores licensing information on a cloud server, including license codes, expiration dates, usage scopes, etc. When users use the software, they need to communicate with the cloud server to verify the licensing information. It realizes real-time license management and monitoring and can quickly respond to changes in the license status. The client software contains a module for communicating with the cloud licensing server, which is responsible for sending license verification requests and receiving verification results. The licensing process is convenient, with low management costs and high security (because the licensing information is not stored locally), but it depends on the network connection and may have problems such as network latency or interruption, affecting the user experience.
[0009] 2. Hardware feature-based licensing solution: This solution generates a unique hardware identifier by collecting the hardware features of a computer (such as CPU serial number, hard disk serial number, MAC address, etc.). The licensing information is bound to this hardware identifier to ensure that only specific hardware devices can use the software. The client software collects the hardware features during installation or the first run and generates a hardware identifier. The hardware identifier and the licensing information are sent to the cloud server for verification together. After verification, the client software obtains the usage permission of the software. This method improves the security of licensing because hardware features are difficult to copy, but the process of obtaining and verifying hardware features may be relatively complex, and re-licensing may be required when the hardware is replaced or upgraded.
[0010] 3. Hybrid licensing solution: This solution combines the characteristics of the cloud-based software licensing solution and the hardware feature-based licensing solution. It takes into account both the convenience of the licensing process and management costs and the security of licensing. The client software interacts with both the cloud server and local hardware features simultaneously. The cloud server stores and manages the licensing information and conducts real-time license verification. Local hardware features are used to generate a unique hardware identifier for verification together with the licensing information. This method combines the advantages of the two solutions, being both convenient and secure, but the system may be relatively complex and requires handling the verification logics of both the cloud and local aspects simultaneously.
[0011] To solve the above problems, a technical solution is provided now. Summary of the Invention
[0012] To overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a method for designing a software online licensing system to solve the problems raised in the above background technology.
[0013] To achieve the above object, the present invention provides the following technical solution: A method for designing a software online licensing system, including the following steps: Step S1, establish the relationship between systems; Step S2, design the front-end interface, back-end service, database, and security mechanism; Step S3, manage users, customers, products, and authorizations, and generate reports; Step S4, conduct authorization verification and version information collection for core applications.
[0014] In a preferred embodiment, Step S1 specifically includes the following: Establish a connection mechanism between the platform's online authorization verification service and the enterprise-side products, verify the authorization status of the enterprise-side products in real time, and obtain the versions and operating statuses of the enterprise-side products through the information collection service; Design the interaction mode between the middle platform products and the authorization platform, and let the middle platform products obtain the authorization status by module and judge the authorization status when interacting with other applications; Set the mechanism for the platform to obtain customer information, logged-in operator information, and the association relationship between operators and customers from the company's CRM system; Connect the authorization approval process within the platform with the Aisino office system; Based on single sign-on, build a unified identity management system for the platform and the company's internal systems.
[0015] In a preferred embodiment, Step S2 specifically includes the following: Develop a front-end interface adapted to the PC and mobile terminals, design the back-end service based on the microservice architecture, and divide it into authorization verification service, authorization management service, and report statistics service; Select a relational database to store authorization data, customer information, and product information; The security mechanism selects integrated SSL encryption transmission, API interface key verification, permission control, and encrypted storage.
[0016] In a preferred embodiment, Step S3 specifically includes the following: For business personnel, the platform provides a single sign-on service. After logging in through the CRM system, they are redirected to this platform and use the logged-in personnel information of the CRM system. The CRM system provides a login verification service, and the platform logged-in personnel log in to this platform after verifying the login information through this service; For non-business dedicated users of the platform, build an independent user management and login verification mechanism; Preset the default business personnel roles within the platform and assign corresponding permissions. Users who log in through CRM single sign-on automatically apply the role permissions; The platform stores the basic customer information and obtains the detailed customer information by calling the customer details query interface of the CRM system and passing in the customer ID or other unique identifiers; Display all the authorization information of customers in a list form on the platform, call the customer list query interface of the CRM system, and verify the management authority of the logged-in user over the customers.
[0017] In a preferred embodiment, step S3 specifically further includes the following content: Authorized product administrators operate on product information on the platform, including adding, editing, and deleting product information; Set the authorization mode management function in the product information. According to product characteristics and business requirements, set authorization rules, including authorization period, authorization quantity, and authorized terminals, and the authorization rules correspond to the authorization verification methods; Classify and tag the products.
[0018] In a preferred embodiment, step S3 specifically further includes the following content: Select the product to be authorized from the product management list, and set the corresponding verification criteria according to the authorization mode of the selected product; In the time authorization mode, enter the start effective date and the authorization duration or end time; In the authorization quantity mode, enter the total available quantity; In the authorized terminal mode, collect the terminal environment to form a verification code for entry; Call the CRM system interface to obtain the user list managed by the logged-in person, select the customers who need to generate authorizations from it, and submit an authorization production application after completion; Open up the authorization application approval process with the Aviation Information Office system, automatically generate the approval process, and return the result to the platform after completing the approval according to the approval process; The platform sets approval role personnel to conduct in-platform approvals. After the approval is passed, generate the unique authorization code for this authorization record. The authorized authorizations are automatically exported to generate authorization files for offline authorization verification; Allow customers to apply for renewal or upgrade of authorizations. After the review is passed, perform the corresponding operations. The original authorization code remains unchanged, and a new authorization record is generated; For users or terminals with violations, execute the authorization cancellation operation and give a reminder when they apply for other authorized products; Manually adjust the generated authorization information, including extending the authorization period and increasing the authorization quantity. After the approval is passed, generate a new authorization code; Query authorization information according to conditions such as products, customers, terminals, and time, including authorized, unauthorized, expired, cancelled, etc. statuses, so as to adjust the authorization strategy in a timely manner.
[0019] Record the historical information of each authorization operation, covering the authorization code, authorization time, authorized object, and authorization mode; Generate a report showing the overall situation of authorization information, authorization status, and customer distribution, analyze the authorization situation, count the sales quantity, auxiliary sales amount, and profit of each product, and form a sales report.
[0020] In a preferred embodiment, step S4 specifically includes the following content: Business personnel complete the application and related approval operations of authorization information on the platform. When the authorized product is started or the authorization status needs to be verified at a specified time, the product generates an encrypted authorization verification request containing the authorization code, product information, customer name, customer tax number, and terminal verification code, and sends it to the authorization management platform through the network; Among them, the terminal verification code is generated by collecting and encrypting the hardware information of the enterprise-side product deployed, and is used for terminal verification of the authorization mode; For specific application scenarios, in the form of middleware product forwarding, the authorization of the middleware product itself is verified by the middleware sending a verification request to the authorization platform at regular intervals. Relying on the sales invoice management, purchase invoice management, and enterprise invoice pool of the middleware product application, the authorization verification situation can be requested from the middleware when the business is initiated. The middleware first verifies locally whether there is an authorization for this application. If not, it sends a verification request to the authorization platform, and there is no need to send an application authorization request to the authorization platform at regular intervals; After receiving the request, the authorization management platform parses each piece of information in it. First, it confirms whether the authorization record status is valid based on the authorization code, and then combines the product, authorization mode, and customer information to query the database or cache to verify whether its authorization is within the normal range; The authorization management platform returns the verification result to the authorized product, and the authorized product performs corresponding operations according to the result.
[0021] In a preferred embodiment, step S4 specifically further includes the following content: Integrate an authorization verification module in the authorized product, which is responsible for handling the communication and verification logic with the authorization management platform, can send verification requests, receive verification results, and perform reminders and disabling according to the results. The verification module enters the authorization code obtained after the authorization application is approved and builds in the product code for sending verification requests to the authorization management platform; The authorization management platform obtains the version information from the authorized product to comprehensively understand the promotion of the authorized product and the coverage of each version. The version information collection is synchronized with the authorization verification or collected separately according to the update frequency; Set a version parameter field in the authorization verification request, and the platform automatically updates the version information after receiving such a request; The platform stores the obtained version information to track the product version corresponding to each authorization.
[0022] The technical effects and advantages of the method for designing a software online authorization system of the present invention: 1. Adopt advanced encryption technologies and multi-level security protection measures to ensure the security of authorized information during transmission and storage, effectively prevent data leakage and illegal copying, have real-time monitoring and updating functions to ensure the accuracy and effectiveness of authorized information, promptly respond to changes in the authorization status, prevent the illegal use of software, and the application of automated management tools such as automated distribution, update, and monitoring of licenses reduces management costs and improves management efficiency. The modular design that is easy to expand facilitates subsequent function upgrades and expansions to meet the changing needs of software protection and management; 2. Design a simple and intuitive authorization process, which reduces the learning cost of users and improves their operation efficiency. Provide multiple authorization methods such as online authorization and offline authorization to adapt to the usage scenarios and needs of different users, enhance the user experience, and according to the usage situation and needs of users, expand to provide personalized authorization services such as pay-as-you-go and try-before-you-buy, which lower the threshold for users to use the software. Provide real-time license information such as expiration reminders and upgrade reminders to help users better manage and use the software; 3. Support multiple operating systems, browsers, and device types to ensure that users can seamlessly use the authorization function on different platforms. It is applicable to traditional software industries such as management and manufacturing, and also applicable to various business fields such as stock software, mass messaging software, game software, and online work software. It can be integrated with other management systems within the company to achieve data sharing. The architecture is scalable, and the functions are intelligent and automated, which enhances the enterprise's management level and competitiveness, facilitates the management of products and users, and reduces the costs of software protection, authorization, distribution, and maintenance; 4. Support multiple authorization modes such as time authorization, function authorization, device authorization, and quantity authorization, which provides software developers with a more flexible sales model. The real-time update function of authorization enables software developers to charge according to the usage situation of customers, realizing a pay-per-use sales model. The function of collecting usage data enables software developers to optimize products and adjust decisions according to the usage situation of customers. By analyzing user usage data, potential market opportunities and improvement points can be discovered, creating more profit models for software developers; 5. Has high flexibility and can be appropriately adjusted and optimized according to the actual situation. For example, the system supports multiple data interfaces and file formats, facilitating information interaction and sharing between the company and software users. At the same time, the system also supports flexible configuration and custom function development to meet the changing needs and technological development of enterprises, which helps enterprises achieve flexibility and sustainable development in the management of software products. Description of the Drawings
[0023] Figure 1 It is a schematic flowchart of a method for designing an online software authorization system according to the present invention. Detailed implementation manners
[0024] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Embodiment 1
[0025] Figure 1 A method for designing a software online authorization system of the present invention is given, which specifically includes the following steps: Step S1, establish the relationship between systems; Step S2, design the front-end interface, back-end service, database and security mechanism; Step S3, manage users, customers, products and authorizations, and generate reports; Step S4, perform authorization verification and version information collection on the core application.
[0026] Step S1 specifically includes the following content: Establish a connection mechanism between the platform online authorization verification service and the enterprise-side product, verify the authorization status of the enterprise-side product in real time, and obtain the version and running status of the enterprise-side product through the information collection service; Design the interaction mode between the middle-platform product and the authorization platform, and the middle-platform product obtains the authorization status by module and judges the authorization status when interacting with other applications; Set the mechanism for the platform to obtain customer information, login operator information and the association relationship between the operator and the customer from the company's CRM system; Docking of the authorization approval process within the platform with the Aisino office system; Based on single sign-on, build a unified identity management system for the platform and the company's internal systems.
[0027] It should be added that by verifying the authorization status of the enterprise-side product in real time, unauthorized product use can be effectively prevented. For software developers, this can protect their software copyright from infringement and reduce economic losses caused by piracy.
[0028] For example, a software company develops professional enterprise management software. Through this online authorization verification mechanism, it can be ensured that only enterprises that have purchased the authorization can use the software normally, avoiding unauthorized illegal copying and use within the enterprise.
[0029] Obtaining the version and running status information of enterprise-side products helps software developers promptly understand the usage of products in enterprises. When software failures occur or upgrades are needed, developers can more accurately locate problems and formulate upgrade strategies based on this information.
[0030] Step S2 specifically includes the following content: Develop a front-end interface that adapts to both the PC and mobile sides, design the back-end service based on the microservices architecture, and divide it into an authorization verification service, an authorization management service, and a report statistics service; Select a relational database to store authorization data, customer information, and product information; The security mechanism selects to integrate SSL encrypted transmission, API interface key verification, permission control, and encrypted storage.
[0031] It should be added that developing a front-end interface that adapts to both the PC and mobile sides can meet the needs of users to use the software on different devices. Whether it is a user who uses a PC for work in the office or a user who needs to handle business through a mobile device while on a business trip, they can conveniently access and operate the software.
[0032] Design the back-end service based on the microservices architecture, divide the system into modules such as an authorization verification service, an authorization management service, and a report statistics service, so that each service can be independently deployed, run, and extended. If one of the services fails, for example, the authorization verification service has a problem, it will not affect the normal operation of the authorization management service and the report statistics service, improving the availability of the entire system.
[0033] Step S3 specifically includes the following content: For business personnel, the platform provides single sign-on service. After logging in through the CRM system, they are redirected to this platform and use the personnel information of the CRM system login. The CRM system provides a login verification service, and the platform login personnel log in to this platform after verifying the login information through this service; For non-business-specific users of the platform, build an independent user management and login verification mechanism; Preset the default business personnel role in the platform and assign corresponding permissions. Users who log in through CRM single sign-on automatically apply the role permissions; The platform stores the basic customer information and obtains the detailed customer information by calling the customer details query interface of the CRM system and passing in the customer ID or other unique identifier; Display all the authorization information of customers in a list form on the platform, call the customer list query interface of the CRM system, and verify the management permissions of the logged-in user for customers.
[0034] It should be added that the platform provides single sign-on service. After business personnel log in through the CRM system, they can directly jump to this platform without having to enter the account number and password again. This greatly simplifies the login process, saves the time of business personnel, and improves work efficiency.
[0035] For non-business-specific users of the platform (such as the Ministry of Commerce, approval, leadership inquiry, system management, etc.), an independent user management and login verification mechanism is constructed, which can perform customized permission settings and management according to the special needs of these users.
[0036] All authorized information of customers is displayed in a list form on the platform, and by calling the customer list query interface of the CRM system to verify the management permission of the logged-in user for the customer, it can ensure that only users with management permission can operate on customer authorization.
[0037] For example, when a business person wants to view or modify the software authorization information of a certain customer, the platform will first verify through the CRM system whether they have the management permission for this customer to prevent unauthorized users from misoperating on customer authorization.
[0038] Step S3 specifically further includes the following content: The authorized product administrator operates on product information on the platform, including adding, editing, and deleting product information; Set the authorization mode management function in the product information. According to product characteristics and business requirements, set authorization rules, including the authorization period, authorization quantity, and authorized terminals, and the authorization rules correspond to the authorization verification methods; Classify and tag the products.
[0039] It should be added that the authorized product administrator can directly add, edit, and delete product information on the platform, which makes the maintenance of product information efficient and convenient. For example, when a new software product is launched, the administrator can quickly add information such as the product name, version, code, description, and default authorization mode on the platform to ensure that the product can enter the authorization management process in a timely manner.
[0040] For the update of product information, such as modifying the product description after software version upgrade, the administrator can quickly complete it through the editing function to ensure the timeliness and accuracy of product information on the platform.
[0041] Step S3 specifically further includes the following content: Select the product to be authorized from the product management list and set the corresponding verification criteria according to the authorization mode of the selected product; In the time authorization mode, enter the start effective date and the authorization duration or end time; In the authorization quantity mode, enter the total available quantity; In the authorized terminal mode, the verification code is entered by collecting the terminal environment; Call the CRM system interface to obtain the user list managed by the logged-in personnel, select the customer for whom authorization needs to be generated, and submit the authorization production application after completion; Connect the authorization application approval process with the Air China office system, automatically generate the approval process, and return the results to the platform after the approval is completed according to the approval process; The platform sets up approval role personnel to conduct approval within the platform. After approval, a unique authorization code for the authorization record is generated. The approved authorization is automatically exported, and an authorization file is generated for offline authorization verification. Allow customers to apply for renewal or upgrade authorization. After approval, execute the corresponding operation. The original authorization code remains unchanged and a new authorization record is generated. For users or terminals that violate regulations, we will cancel their authorization and remind them when they apply for other authorized products. Manually adjust the generated authorization information, including extending the authorization period and increasing the authorization quantity, and generate a new authorization code after approval; Query authorization information by product, customer, terminal, time and other conditions, including authorized, unauthorized, expired, cancelled and other statuses, so as to adjust authorization policies in time.
[0042] Record the historical information of each authorization operation, including authorization code, authorization time, authorization object and authorization mode; Generate reports showing the overall authorization information, authorization status, and customer distribution, analyze the authorization status, and count the sales volume, auxiliary sales, and profits of each product to form sales reports.
[0043] It should be added that the corresponding verification standards can be set according to the authorization mode of different products, such as entering the effective date and duration in the time authorization mode, so that the authorization is closely matched with the product characteristics and customer needs. For example, for software products used seasonally, the authorization for a specific time period can be accurately set to avoid resource waste and authorization loopholes.
[0044] The detailed setting of the authorized quantity and terminal mode can effectively control the scope and scale of software use, protect the rights and interests of software providers and the reasonable distribution of products, and prevent excessive use or illegal terminal access.
[0045] Supports customer authorization renewal and upgrade applications, and the original authorization code remains unchanged, only a new record is generated to ensure the continuity and stability of customer use. For long-term cooperative customers or business expansion needs, the authorization level can be easily adjusted to enhance customer satisfaction and loyalty.
[0046] The function of manually adjusting authorization information (such as extending the term and increasing the quantity) can handle special situations or temporary business adjustments, making authorization management more flexible and elastic to meet the needs of diverse business scenarios.
[0047] Step S4 specifically includes the following content: Business personnel complete the application and relevant approval operations of authorization information on the platform. When the authorized product is started or the authorization status needs to be verified at a specified time, the product generates an encrypted authorization verification request containing the authorization code, product information, customer name, customer tax number, and terminal verification code, and sends it to the authorization management platform through the network. Among them, the terminal verification code is generated by collecting and summarizing the hardware information of the enterprise-side product and encrypting it, and is used for terminal verification of the authorization mode. For specific application scenarios, in the form of middleware product forwarding, the authorization of the middleware product itself is verified by the middleware sending a verification request to the authorization platform at regular intervals. Relying on the sales invoice management, purchase invoice management, and enterprise invoice pool of the middleware product application, the authorization verification situation can be requested from the middleware when the business is initiated. The middleware first verifies locally whether there is an authorization for this application. If not, it sends a verification request to the authorization platform, and there is no need to send an application authorization request to the authorization platform at regular intervals. After receiving the request, the authorization management platform parses each piece of information in it. First, it confirms whether the authorization record status is valid based on the authorization code, and then combines the product, authorization mode, and customer information to query the database or cache to verify whether its authorization is within the normal range. The authorization management platform returns the verification result to the authorized product, and the authorized product performs corresponding operations according to the result.
[0048] It should be added that business personnel centrally apply for and approve authorization information on the platform, realizing the standardization and regularization of the process. This helps to reduce human errors and the uncertainty of the approval process, and improve the accuracy and efficiency of authorization management. For example, through preset approval processes and permission settings, it can be ensured that only eligible applications can be approved, avoiding the occurrence of random authorizations.
[0049] The authorized product automatically generates an encrypted authorization verification request according to the regulations and sends it to the authorization management platform, realizing the automatic triggering of the verification process. Whether it is when the product is started or verified at a specified time, the authorization status can be checked in a timely and accurate manner without manual intervention, greatly saving time and labor costs, and at the same time reducing the risk of authorization loopholes caused by human negligence.
[0050] For specific application scenarios, adopting the form of middleware product forwarding, the authorization timing verification mechanism of the middleware itself can reasonably allocate resources and avoid frequently sending a large number of unnecessary verification requests to the authorization platform. For example, the middleware can set an appropriate timing verification interval according to the busyness of its own business and the usage rules of the application, reducing network bandwidth occupancy and consumption of the authorization platform's computing resources while ensuring the effectiveness of authorization.
[0051] When an application relying on the middleware initiates a business and requests authorization verification, the middleware first locally verifies whether there is authorization for this application. If not, it sends a request to the authorization platform. This hierarchical verification mechanism greatly improves the efficiency of authorization verification and reduces the delay of verification requests. Because in many cases, the authorization status of the application can be quickly confirmed locally in the middleware without being transmitted over the network to the authorization platform for verification, thus shortening the response time of business processing and enhancing the user experience.
[0052] Step S4 specifically further includes the following content: Integrate an authorization verification module in the authorized product, which is responsible for handling the communication and verification logic with the authorization management platform, capable of sending verification requests, receiving verification results, and executing reminders and disabling according to the results. The verification module enters the authorization code obtained after the authorization application is approved and embeds the product code for sending verification requests to the authorization management platform; The authorization management platform obtains the version information from the authorized product to comprehensively understand the promotion of the authorized product and the coverage of each version. The collection of version information is carried out synchronously with authorization verification or collected separately according to the update frequency; Set a version parameter field in the authorization verification request, and the platform automatically updates the version information after receiving such a request; The platform stores the obtained version information to track the product version corresponding to each authorization.
[0053] It should be added that integrating an authorization verification module in the authorized product realizes close communication and efficient verification logic processing with the authorization management platform. It can automatically and timely send verification requests and receive results without manual intervention, greatly improving the efficiency and timeliness of authorization verification. For example, when the product starts up each time or regularly conducts authorization checks according to the set time, the verification module can quickly complete the request sending and result receiving, ensuring that the product always runs in a legally authorized state and reducing the risk of business interruption caused by authorization issues.
[0054] Performing reminder and disabling functions based on the verification results provides an effective authorization management means for software providers. When the authorization is about to expire, the verification module can pop up a reminder message to the user, prompting the user to handle the authorization renewal in a timely manner and avoid affecting the normal operation of the business due to expired authorization. If the verification fails, such as detecting illegal copying or authorization abuse, the verification module can immediately disable the product function to protect software intellectual property rights and prevent illegal use and economic losses.
[0055] The verification module enters the authorization code and the built-in product code, ensuring the accuracy and uniqueness of the verification request. As the core identifier of authorization, the authorization code, combined with the product code, can accurately convey the authorization information of the product to the authorization management platform, enabling the authorization management platform to quickly and accurately perform authorization verification and status judgment, and improving the operation accuracy and reliability of the entire authorization system.
[0056] The authorization management platform obtains version information from the authorized products, which helps to comprehensively understand the promotion situation of the authorized products in the market and the coverage of each version. By analyzing the usage ratio and feedback information of different versions among different regions and different customer groups, software providers can formulate targeted product promotion strategies and optimize market resource allocation. For example, if it is found that the promotion of a certain new version is slow among customers in a specific industry, the reasons can be analyzed in depth and the marketing strategy can be adjusted, increasing the promotion efforts or improving the product functions to meet the needs of that industry.
[0057] The above are only the specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.
[0058] Finally: The above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A method for designing a software online authorization system, characterized in that: The steps include: Step S1, building relationships between systems; Step S2, design the front-end interface, back-end services, database and security mechanism; Step S3, manage users, customers, products and authorizations, and generate reports; Step S4: perform authorization verification and version information collection on the core application.
2. The method for designing a software online authorization system according to claim 1, characterized in that: Step S1 specifically includes the following contents: Establish a connection mechanism between the platform's online authorization verification service and enterprise-side products, verify the authorization status of enterprise-side products in real time, and obtain the version and operating status of enterprise-side products through information collection services; Design the interaction mode between the middle-end products and the authorization platform, so that the middle-end products can obtain authorization status by module and judge the authorization status when interacting with other applications; Set up a mechanism for the platform to obtain customer information, login operator information, and operator-customer relationship from the company's CRM system; The authorization and approval process within the platform is connected with the Air China office system; Based on single sign-on, a unified identity management system is built for the platform and the company's internal systems.
3. The method for designing a software online authorization system according to claim 2, characterized in that: Step S2 specifically includes the following contents: Develop front-end interfaces that are compatible with PC and mobile terminals, design back-end services based on microservice architecture, and divide them into authorization verification services, authorization management services, and report statistics services; Choose a relational database to store authorization data, customer information, and product information; The security mechanism integrates SSL encrypted transmission, API interface key verification, permission control and encrypted storage.
4. The method for designing a software online authorization system according to claim 3, characterized in that: Step S3 specifically includes the following contents: For business personnel, the platform provides a single sign-on service. After logging in through the CRM system, they will be redirected to the platform and use the CRM system login personnel information. The CRM system provides a login verification service. The platform login personnel will log in to the platform after verifying the login information through the service. For non-business-specific users of the platform, an independent user management and login verification mechanism is established; Preset default business personnel roles in the platform and assign corresponding permissions. Users who log in through CRM single sign-on will automatically apply the role permissions. The platform stores basic customer information and obtains detailed customer information by calling the customer detail query interface of the CRM system and passing in the customer ID or other unique identifier; Display all customer authorization information in a list on the platform, call the customer list query interface of the CRM system, and verify the logged-in user's management authority over the customer.
5. The method for designing a software online authorization system according to claim 4, characterized in that: Step S3 specifically also includes the following contents: Authorize product administrators to operate product information on the platform, including adding, editing and deleting product information; Set up the authorization mode management function in the product information, and set the authorization rules according to the product characteristics and business requirements, including the authorization period, authorization quantity and authorized terminals, and the authorization rules and authorization verification methods correspond to each other; Categorize and label products.
6. The method for designing a software online authorization system according to claim 5, characterized in that: Step S3 specifically also includes the following contents: Select the product to be authorized from the product management list and set the corresponding verification standard according to the authorization mode of the selected product; In the time authorization mode, enter the effective start date and authorization duration or end time; In the authorized quantity mode, enter the total amount that can be used; In the authorized terminal mode, the verification code is entered by collecting the terminal environment; Call the CRM system interface to obtain the user list managed by the logged-in personnel, select the customer for whom authorization needs to be generated, and submit the authorization production application after completion; Connect the authorization application approval process with the Air China office system, automatically generate the approval process, and return the results to the platform after the approval is completed according to the approval process; The platform sets up approval role personnel to conduct approval within the platform. After approval, a unique authorization code for the authorization record is generated. The approved authorization is automatically exported, and an authorization file is generated for offline authorization verification; Allow customers to apply for renewal or upgrade authorization. After approval, execute the corresponding operation. The original authorization code remains unchanged and a new authorization record is generated. For users or terminals that violate regulations, we will cancel their authorization and remind them when they apply for other authorized products. Manually adjust the generated authorization information, including extending the authorization period and increasing the authorization quantity, and generate a new authorization code after approval; Query authorization information by product, customer, terminal, time and other conditions, including authorized, unauthorized, expired, cancelled and other statuses, so as to adjust authorization policies in a timely manner; Record the historical information of each authorization operation, including authorization code, authorization time, authorization object and authorization mode; Generate reports showing the overall authorization information, authorization status, and customer distribution, analyze the authorization status, and count the sales volume, auxiliary sales, and profits of each product to form sales reports.
7. The method for designing a software online authorization system according to claim 6, characterized in that: Step S4 specifically includes the following contents: Business personnel complete the application for authorization information and related approval operations on the platform. When the authorized product is started or the authorization status needs to be verified at the specified time, the product generates an encrypted authorization verification request containing the authorization code, product information, customer name, customer tax number and terminal verification code, and sends it to the authorization management platform through the network; The terminal verification code is generated by collecting, summarizing and encrypting the hardware information of enterprise-side products, and is used for terminal verification authorization mode; For specific application scenarios, the middle platform product forwarding form is adopted. The authorization of the middle platform product itself is verified by the middle platform sending verification requests to the authorization platform regularly. Relying on the sales invoice management, input invoice management and enterprise ticket pool of the middle platform product application, the authorization verification status can be requested from the middle platform when the business is initiated. The middle platform first verifies whether there is authorization for the application locally. If not, it sends a verification request to the authorization platform. There is no need to send application authorization requests to the authorization platform regularly. After receiving the request, the authorization management platform parses the information therein. First, it confirms whether the authorization record status is valid based on the authorization code. Then, it queries the database or cache to verify whether the authorization is within the normal range based on the product, authorization mode and customer information. The authorization management platform returns the verification results to the authorized product, and the authorized product performs corresponding operations based on the results.
8. The method for designing a software online authorization system according to claim 7, characterized in that: Step S4 specifically also includes the following contents: An authorization verification module is integrated into the authorized product, which is responsible for handling the communication and verification logic with the authorization management platform. It can send verification requests, receive verification results, and perform reminders and disablements based on the results. The verification module enters the authorization code obtained after the authorization application is approved, and has a built-in product code for sending verification requests to the authorization management platform; The authorization management platform obtains version information from the authorized product to fully understand the promotion of the authorized product and the coverage of each version. Version information collection and authorization verification are carried out simultaneously or separately according to the update frequency; Set the version parameter field in the authorization verification request. The platform will automatically update the version information after receiving such a request. The platform stores the obtained version information and tracks the product version corresponding to each authorization.