Method for controlling authorized use of software on Windows equipment
By using AES encryption, initialization vector (IV) and binary cyclic offset technology in software authorization, combined with the device's motherboard ID and preset expiration time, the problem that existing software authorization methods are easily cracked is solved, the legality and security of the software are realized, and the risks of piracy and illegal use are reduced.
Patent Information
- Application Number
- CN202510113171.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-06-13
AI Technical Summary
Existing software authorization methods are prone to cracking and tampering, resulting in serious problems in software piracy and illegal use.
By combining the motherboard ID of the device and the preset expiration time into a string, encrypted using the AES encryption algorithm and the initialization vector (IV), and then cyclically offset by binary data, it is stored as a certificate using Base64 encoding. Decode and decrypt it on the software side, verify the motherboard ID and expiration time to determine whether the software is running normally.
Effectively prevent unauthorized use, ensure that the software can only run on authorized devices and within an effective time frame, provide a high degree of security, and reduce the risks of software piracy and illegal use.
Smart Images

Figure CN120145340A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software license control, and particularly to a method for controlling the licensed use of software on Windows devices. Background Art
[0002] With the rapid development of the software industry, the problems of software piracy and illegal use are becoming increasingly serious. Traditional software licensing methods usually rely on simple serial numbers or activation codes, which are easily cracked and tampered with. Therefore, a more secure and reliable software license control method is needed to prevent the illegal use and piracy of software. Summary of the Invention
[0003] To solve the above technical problems, the present invention provides a method for controlling the licensed use of software on Windows devices.
[0004] The technical solution of the present invention is as follows:
[0005] A method for controlling the licensed use of software on Windows devices. First, combine the motherboard ID of the device and a preset expiration time into a string, and perform AES encryption on it using a specific key and a randomly generated initialization vector (IV). The encrypted data is concatenated with the random IV, and after binary data cyclic offset, it is stored as a certificate using Base64 encoding. On the software side, obtain the encrypted data by Base64 decoding the certificate, restore the offset of the binary data, extract the IV, and decrypt the data using the preset key to obtain the motherboard ID and the expiration time. Then, the software obtains the actual motherboard ID of the device and verifies whether it matches the decrypted motherboard ID. Finally, obtain the current time through the Network Time Protocol (NTP), and check whether the expiration time is greater than the current time to determine whether the software runs normally. This verification process needs to be triggered when the software starts and executes key functions to ensure the legal use and security of the software.
[0006] Further, it specifically includes the following steps:
[0007] k) Obtain the motherboard ID of the device and a preset expiration time, and combine them into a string;
[0008] l) Use the AES encryption algorithm, in combination with a preset key and a randomly generated initialization vector IV, to encrypt the string;
[0009] m) Concatenate the encrypted data with the randomly generated initialization vector IV to generate encrypted information;
[0010] n) Perform binary data offset processing on the encrypted information, and store it as a certificate using Base64 encoding;
[0011] o) On the software side, read the certificate and restore the binary data through Base64 decoding;
[0012] p) Perform offset restoration on the restored binary data to extract the initialization vector IV and the encrypted data;
[0013] q) Use the preset key and the extracted initialization vector IV to decrypt the encrypted data to obtain the motherboard ID and the expiration time;
[0014] r) Obtain the actual motherboard ID of the device and verify whether it matches the motherboard ID obtained by decryption;
[0015] s) Obtain the current time through the Network Time Protocol, and compare the current time with the expiration time obtained by decryption. If the expiration time is greater than the current time, it is determined that the software is authorized for normal use;
[0016] t) Trigger the above verification process when the software starts and executes the specified function.
[0017] Furthermore,
[0018] The AES encryption algorithm adopts the AES-256 standard and randomly generates the initialization vector IV.
[0019] The rule for binary data offset is to offset by a fixed number of N bits. The part exceeding the binary on the left is supplemented to the right for circular offset, thus confusing the encrypted information.
[0020] Using the motherboard ID as the basis for authorization control ensures that the authorization is strictly for a specific device and prevents unauthorized devices from using the software.
[0021] The certificate stored in Base64 encoding can be stored in the local file system, registry or transmitted through a secure communication protocol.
[0022] The Network Time Protocol NTP is used to obtain a trusted current time to ensure the accuracy and anti-tampering of time verification.
[0023] The matching results of the motherboard ID and the expiration time during the verification process can trigger different operating modes of the software, including normal operation, restricted operation or stop operation.
[0024] The beneficial effects of the present invention are
[0025] This method can effectively prevent unauthorized use and ensure that the software can only run on authorized devices within a valid time range. By combining the unique hardware identifier of the device (motherboard ID) and the preset authorization expiration time, and adopting the AES encryption, initialization vector (IV), and binary cyclic shift method, the present invention can provide a high level of security, preventing the software from being cracked, tampered with, or forged authorization certificates. In addition, this method can verify the authorization time through the Network Time Protocol (NTP) to ensure the legality of the software, reduce the risk of software piracy and illegal use, and protect the copyright and economic interests of software developers. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 is a schematic diagram of the workflow of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0028] The present invention provides a method for controlling the authorized use of software on Windows devices, including the following steps:
[0029] I. Generate a certificate
[0030] 1. Obtain the motherboard ID of the device and the preset expiration time, and combine them into a string;
[0031] a) Obtain the motherboard ID of the device
[0032] string GetDeviceID()
[0033]
[0034] b) Combine the motherboard ID and the expiration time
[0035] CAAA2A65-9D87-4E28-A6EC-07FEF8D17CAC+2025-12-31:23:59:59
[0036] 2. Use the AES encryption algorithm, in combination with a preset key and a randomly generated initialization vector (IV), to encrypt the string, where the preset key Key is 256 bits (32 bytes) with the highest encryption strength, and the randomly generated initialization vector (IV) can increase the randomness of encryption.
[0037]
[0038]
[0039] 3. Concatenate the encrypted data with a randomly generated initialization vector (IV) to generate encrypted information;
[0040] byte[] result = new byte[aes.IV.Length + encryptedData.Length];
[0041] Array.Copy(aes.IV, 0, result, 0, aes.IV.Length);
[0042] Array.Copy(encryptedData, 0, result, aes.IV.Length, encryptedData.Length);
[0043] 4. Perform a circular shift of the binary data of the encrypted information, fixed shift N bits to the left, and supplement the left side that exceeds the binary to the right side for circular shift, so as to confuse the encrypted information.
[0044]
[0045] 5. Store it as a certificate using Base64 encoding.
[0046] II. Using the certificate
[0047] Trigger the above verification process when the software starts and executes key functions to ensure the legitimacy and security of software authorization.
[0048] 1. On the software side, read the certificate and restore the binary data through Base64 decoding;
[0049] 2. Perform offset restoration on the binary data of the data, fixed shift N bits to the right, and supplement the right side that exceeds the binary to the left side for circular shift
[0050] 3. Extract the initialization vector (IV) and encrypted data;
[0051] Use the preset key and the extracted initialization vector (IV) to decrypt the encrypted data to obtain the motherboard ID and expiration time; the preset key can be stored in the software code.
[0052]
[0053] 4. Obtain the actual motherboard ID of the device and verify whether it matches the motherboard ID obtained by decryption;
[0054] 5. Obtain the current time through the Network Time Protocol (NTP), and compare the current time with the decrypted expiration time. If the expiration time is greater than the current time, it is determined that the software is authorized for normal use;
[0055]
[0056]
[0057] The above are only the preferred embodiments of the present invention, which are only used to illustrate the technical solutions of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.
Claims
1. A method for controlling software authorization use on a Windows device, characterized in that: First, the device's motherboard ID and the preset expiration time are combined into a string and encrypted using AES with a key and a randomly generated initialization vector IV. The encrypted data is concatenated with the randomly generated initialization vector IV, and after binary data cyclic shifting, it is encoded in Base64 and stored as a certificate. On the software side, the encrypted data is obtained by decoding the certificate with Base64, and the offset of the binary data is recovered to extract the initialization vector IV, and the data is decrypted using the preset key to obtain the motherboard ID and expiration time; Next, the software obtains the actual motherboard ID of the device and verifies whether it matches the decrypted motherboard ID. Finally, the current time is obtained through the network time protocol and the expiration time is checked to see if it is greater than the current time to determine whether the software is running properly.
2. The method according to claim 1, characterized in that The above verification process is triggered when the software is started and the specified function is executed.
3. The method according to claim 2, characterized in that The specific steps include: a) Get the device's motherboard ID and the preset expiration time and combine them into a string; b) using the AES encryption algorithm, combined with a preset key and a randomly generated initialization vector IV, to encrypt the string; c) concatenate the encrypted data with the randomly generated initialization vector IV to generate encrypted information; d) performing binary data offset processing on the encrypted information and storing it as a certificate using Base64 encoding; e) On the software side, read the certificate and recover the binary data by Base64 decoding; f) performing offset restoration on the recovered binary data to extract the initialization vector IV and encrypted data; g) Use the preset key and the extracted initialization vector IV to decrypt the encrypted data and obtain the motherboard ID and expiration time; h) Obtain the actual motherboard ID of the device and verify whether it matches the decrypted motherboard ID; i) obtaining the current time through the network time protocol, and comparing the current time with the decrypted expiration time. If the expiration time is greater than the current time, it is determined that the software is authorized for normal use; j) The above verification process is triggered when the software is started and executes the specified function.
4. The method according to claim 3, characterized in that The AES encryption algorithm adopts the AES-256 standard and randomly generates an initialization vector IV.
5. The method according to claim 3, characterized in that: The rule of binary data offset is to have a fixed offset of N bits, and the binary data exceeding the left side is supplemented to the right side for cyclic offset, thereby obfuscating the encrypted information.
6. The method according to claim 3, characterized in that The use of the motherboard ID as the basis for authorization control ensures that the authorization is strictly targeted at a specific device, preventing unauthorized devices from using the software.
7. The method according to claim 3, characterized in that The Base64-encoded stored certificate may be stored in a local file system, a registry, or transmitted via a secure communication protocol.
8. The method according to claim 3, characterized in that The Network Time Protocol (NTP) is used to obtain a reliable current time and ensure the accuracy and tamper-proofness of time verification.
9. The method according to claim 3, characterized in that: The matching result of the motherboard ID and the expiration time during the verification process can trigger different operation modes of the software, including normal operation, restricted operation or stopped operation.