Equipment authorization method and device, storage medium and computer equipment
By generating device authorization files and starting authorization licensing services, combining preset encryption policies and local caching technology, the problem of difficult to balance the security, convenience and flexibility of the device authorization method is solved, and efficient, secure and flexible authorization services are achieved.
Patent Information
- Application Number
- CN202510439922.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-06-13
AI Technical Summary
Existing equipment authorization methods are difficult to balance security, operational ease and deployment flexibility, and cannot meet the actual needs and business environment of the enterprise.
By generating a device authorization file and starting the authorization license service based on the file, the authorization file is encrypted by using a preset encryption policy and saved to the local cache to avoid complex peripheral authorization communications and realize the privatized deployment of the service.
While ensuring data security, it improves operational convenience and deployment flexibility, meets the enterprise's efficient and stable authorization service needs, and enhances the security of equipment.
Smart Images

Figure CN120145367A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of device authentication, and particularly to a device authorization method, apparatus, storage medium, and computer device. Background Art
[0002] In the current device management and authorization system, enterprises are facing the choice of device credit-granting methods. One method is to perform device credit-granting based on a dongle external device, which requires enterprises to configure a physical device as a server for managing and synchronizing tenant authorization information. Another method is to implement it through a credit-granting gateway service. The credit-granting gateway service needs to be connected to the external network, and the rest of the system services are kept privately deployed. The device registers its hardware information through the gateway service and dynamically obtains authorization information.
[0003] However, in the first method, the dongle peripheral device needs to go through a cumbersome and time-consuming security detection process. Once the server device fails, it will take time to redeploy and bind a new server device. For example, the average mean time to recover (MTTR) of the traditional dongle solution is 4 - 6 hours. If the dongle device is damaged, the average MTTR is 24 - 72 hours. Therefore, it cannot meet the requirements of business continuity. While the second method has high security at the enterprise service level, most enterprises prefer to run all services in the internal environment when choosing private deployment. Therefore, it cannot meet the actual production requirements. All in all, currently in the selection of device authorization methods, it is difficult to seek a balance among security, operation convenience, and deployment flexibility to meet the actual needs and business environment of enterprises themselves. Summary of the Invention
[0004] The purpose of this application is to at least solve one of the above technical defects, especially the technical defect that in the selection of device authorization methods in the prior art, it is difficult to seek a balance among security, operation convenience, and deployment flexibility to meet the actual needs and business environment of enterprises themselves.
[0005] This application provides a device authorization method, and the method includes:
[0006] Generating a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized, and starting an authorization license service based on the device authorization file;
[0007] Performing data grouping encryption on the device authorization file by using a preset encryption policy to obtain an encrypted file set, and saving the encrypted file set to the local cache of the authorization license service;
[0008] Starting a platform main service, and establishing a connection between the platform main service and the authorization license service based on the local cache, so that the target host device performs an authorization service;
[0009] Periodically verify the authorization information of the authorization license service, and when the authorization result is abnormal, exit the authorization service of the target host device.
[0010] Optionally, generating the device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized includes:
[0011] Determine the target host device and the client device to be authorized, and obtain the device information of the target host device and the authorization information of the client device;
[0012] Upload the device information and the authorization information to the platform service center for data binding, and generate a device authorization file according to the binding result.
[0013] Optionally, starting the authorization license service based on the device authorization file includes:
[0014] Store the device authorization file in the target host device, and parse the device authorization file through the target host device to obtain device information and authorization information;
[0015] When the device information is consistent with the device information built in the target host device, perform a security check on the authorization start time in the authorization information, and start the authorization license service when the security check of the authorization start time passes.
[0016] Optionally, performing a security check on the authorization start time in the authorization information includes:
[0017] Determine the difference between the authorization start time and the current time of the target host device, and determine whether the difference exceeds a preset error tolerance threshold;
[0018] If so, confirm that the security check of the authorization time fails;
[0019] If not, confirm that the security check of the authorization time passes.
[0020] Optionally, using a preset encryption policy to perform data grouping encryption on the device authorization file to obtain an encrypted file set includes:
[0021] Extract the authorization information from the device authorization file, and encrypt the authorization information using a national cryptography standard encryption algorithm to obtain encrypted data;
[0022] Split and confuse the encrypted data to obtain multiple grouped data, and perform encryption encoding on each grouped data to obtain multiple encrypted grouped files;
[0023] Encrypt and encode each group of encrypted packet files based on the key of the national cryptography standard encryption algorithm and the preset splicing order to obtain an encrypted spliced file;
[0024] Use a type discrimination algorithm to label the file types of each encrypted packet file and the encrypted spliced file, and form an encrypted file set according to the labeled encrypted packet files and encrypted spliced file.
[0025] Optionally, the timing of verifying the authorization information for the authorization license service includes:
[0026] Regularly read the authorization information corresponding to the authorization license service, and determine whether there is an authorization update time in the authorization information;
[0027] If so, determine the difference between the authorization update time and the current time of the target host device, and determine whether the difference exceeds a preset fault tolerance threshold;
[0028] When the difference does not exceed the preset fault tolerance threshold, confirm that the verification result is normal;
[0029] When the difference exceeds the preset fault tolerance threshold, or the current time exceeds the authorization end time in the authorization information, confirm that the verification result is abnormal.
[0030] Optionally, the authorization license service is connected to multiple slave services; the method further includes:
[0031] After the authorization license service is started, synchronize the encrypted file set to the local caches of each slave service through the authorization license service for storage, so that after the authorization license service fails and exits the authorization service, select a slave service from each slave service as the new authorization license service and restart the authorization service.
[0032] This application also provides a device authorization device, including:
[0033] A service start module, configured to generate a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized, and start an authorization license service based on the device authorization file;
[0034] A file storage module, configured to perform data grouping encryption on the device authorization file by using a preset encryption policy to obtain an encrypted file set, and store the encrypted file set in the local cache of the authorization license service;
[0035] A service connection module, configured to start a platform main service, and establish a connection between the platform main service and the authorization license service based on the local cache, so that the target host device performs an authorization service;
[0036] An information verification module, which is used to regularly verify the authorization information of the authorization permission service, and exit the authorization service of the target host device when the authorization result is abnormal.
[0037] The present application also provides a storage medium, in which computer-readable instructions are stored. When the computer-readable instructions are executed by one or more processors, the one or more processors are caused to execute the steps of the device authorization method described in any one of the above embodiments.
[0038] The present application also provides a computer device, including: one or more processors, and a memory;
[0039] The memory stores computer-readable instructions. When the computer-readable instructions are executed by the one or more processors, the steps of the device authorization method described in any one of the above embodiments are executed.
[0040] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0041] The device authorization method, device, storage medium and computer device provided by the present application can generate a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized when authorizing the device, and start the authorization permission service based on the device authorization file to achieve a complete privatized deployment of the service through the device authorization file. Then, a preset encryption policy can be used to perform data grouping encryption on the device authorization file to obtain an encrypted file set, and the encrypted file set can be saved to the local cache of the authorization permission service, so that complex authorization communication work can be avoided through peripherals, while ensuring data security, improving the convenience of operation and the flexibility of deployment; then the platform main service can be started, and a connection can be established between the platform main service and the authorization permission service based on the local cache, so that the target host device can perform the authorization service, meeting the enterprise's demand for an efficient and stable authorization service; during the authorization service, the authorization information of the authorization permission service can also be regularly verified, and when the authorization result is abnormal, the authorization service of the target host device can be exited to avoid unauthorized access and use, further enhancing the security of the device. Description of the Drawings
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0043] Figure 1 Schematic flowchart of a device authorization method provided by an embodiment of the present application;
[0044] Figure 2 Schematic flowchart of a process for generating an encrypted file set provided by an embodiment of the present application;
[0045] Figure 3 Schematic diagram of the flow of a data encryption process provided by an embodiment of the present application;
[0046] Figure 4 Schematic structural diagram of a device authorization device provided by an embodiment of the present application;
[0047] Figure 5 Schematic internal structure diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0048] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0049] In the current device management and authorization system, enterprises are facing the choice of device credit-granting methods. One method is to perform device credit-granting based on a dongle external device, which requires an enterprise to configure a physical device as a server for managing and synchronizing tenant authorization information. Another method is to implement it through a credit-granting gateway service. The credit-granting gateway service needs to be connected to the external network, and the remaining system services are kept privately deployed. The device registers its hardware information through the gateway service and dynamically obtains authorization information.
[0050] However, in the first method, the dongle peripheral device needs to go through a cumbersome and time-consuming security detection process. Once the server device fails, it will take time to redeploy and bind a new server device; while the second method has high security at the service enterprise level, but most enterprises prefer to run all services in the internal environment when choosing private deployment, so it cannot meet the actual production requirements. All in all, currently in the selection of device authorization methods, it is difficult to seek a balance among security, operational convenience, and deployment flexibility to meet the actual needs and business environment of the enterprise itself.
[0051] Based on this, the present application proposes the following technical solutions. For details, please refer to the following:
[0052] In one embodiment, as Figure 1 shown, Figure 1 in, Figure 1Schematic flowchart of a device authorization method provided by an embodiment of this application; this application provides a device authorization method, which specifically includes the following:
[0053] S110: Generate a device authorization file based on the device information of the target host device and the authorization information of the client device to be authorized, and start the authorization license service based on the device authorization file.
[0054] In this step, when a user deploys a privatized service in a system cluster composed of multiple devices, the user can select one device as the target host device through a computer device, so that the computing device can obtain the device information of the target host device and the authorization information of the client device to be authorized, and generate a device authorization file. Furthermore, the authorization license service of the system cluster can be started based on this device authorization file, so that the full privatized deployment of the service can be achieved through the device authorization file.
[0055] Among them, the target host device refers to the core device selected in the system cluster for deploying and managing privatized services; the client device refers to the authorized user in the system cluster, which can request authorization from the target host device and use the privatized service.
[0056] Specifically, after determining the target host device, the computer device can obtain the device information of the target host device, including but not limited to hardware specifications, operating system version, network configuration, etc. At the same time, it can also obtain the authorization information of the client to be authorized, such as the authorization validity period, valid service interfaces, and traffic, etc. Furthermore, a device authorization file can be generated according to the obtained device information and authorization information. As a bridge connecting the target host device and the client device, it contains all the authorization information and verification rules required for the privatized deployment of the service. Therefore, through this device authorization file, the computer device can accurately identify and verify the identity and permissions of each client device, thereby ensuring that only authorized client devices can access and use the service.
[0057] It should be noted that through the deployment method of the device authorization file, this application can achieve the full privatized deployment of the service, ensuring the security, reliability, and controllability of the service. This deployment method not only improves the availability and scalability of the service, but also improves the convenience of operation and the flexibility of deployment.
[0058] S120: Use a preset encryption policy to perform data grouping encryption on the device authorization file to obtain an encrypted file set, and save the encrypted file set to the local cache of the authorization license service.
[0059] In this step, after starting the authorization service through step S110, the computer device can encrypt the device authorization file in data groups using a preset encryption policy to obtain an encrypted file set, and save the encrypted file set to the local cache of the authorization service, thereby avoiding complex authorization communication work with peripherals, improving the convenience of operation and the flexibility of deployment while ensuring data security.
[0060] Among them, the preset encryption policy refers to a set of rules and parameters for data encryption that have been set by the computer device before starting the authorization service; its main purpose is to ensure the security of the device authorization file during transmission and storage, preventing unauthorized access and tampering. In this application, the preset encryption policy can include multiple encryption algorithms, such as national cryptography standard encryption algorithms, block encryption algorithms, clustering algorithms, etc., which are not limited here.
[0061] Specifically, after the computer device successfully starts the authorization service, it needs to perform deep encryption processing on the device authorization file using the preset encryption policy, aiming to ensure the absolute security of the data during transmission and storage. During the encryption process, the computer device needs to split it into multiple data blocks of a fixed size, that is, perform data grouping, so as to efficiently utilize the encryption algorithm and ensure that each data block can be fully encrypted and protected. After the grouping is completed, each data block will be encrypted one by one according to the encryption algorithm and key specified in the preset encryption policy, thereby generating an encrypted file set containing multiple encrypted data blocks.
[0062] It can be understood that the encrypted file set contains all necessary authorization information and verification rules, and all exist in encrypted form, so the security of the data can be ensured. And once the encrypted file set is generated, the computer device can save it to the local cache of the authorization service. This local cache is an efficient and secure data storage area, so it can ensure that the encrypted file set can be quickly accessed and used when needed. Through this method of block encryption and local caching, the computer device can avoid the need to use peripherals for complex authorization communication work, which not only significantly improves the convenience of operation and the flexibility of deployment, but also does not need to wait for the transmission and verification of external authorization information when starting and accessing the authorization service.
[0063] S130: Start the platform main service, and establish a connection between the platform main service and the authorization service based on the local cache, so that the target host device can perform the authorization service.
[0064] In this step, after saving the encrypted file set to the local cache through step S120, the computer device can start the platform main service and establish a connection between the platform main service and the authorization license service based on the local cache, so that the target host device can perform the authorization service, thereby meeting the enterprise's demand for an efficient and stable authorization service.
[0065] Among them, the platform main service refers to the core service running in the system cluster, which is mainly responsible for managing and coordinating the operation of other services or components. In this application, the platform main service is mainly responsible for establishing a connection with the authorization license service based on the encrypted file set in the local cache, so that the target host device in the system cluster can perform the authorization service and meet the service access needs of other client devices.
[0066] It can be understood that the computer device can build a secure and stable communication channel between the platform main service and the authorization license service based on the encrypted file set in the local cache, so that the platform main service can directly access and utilize the authorization information in these encrypted file sets, enabling the target host device to perform the authorization service. Since the authorization service is an important mechanism to ensure the secure and orderly access to resources, through the access of the platform main service, the target host device can receive accurate and timely authorization instructions, thereby processing the legitimate access requests of client devices to specific resources or services, greatly simplifying the authorization process in the prior art and significantly improving the efficiency and stability of the authorization service.
[0067] S140: Regularly verify the authorization information of the authorization license service, and exit the authorization service of the target host device when the authorization result is abnormal.
[0068] In this step, after enabling the target host device to perform the authorization service through step S130, the computer device can also regularly verify the authorization information of the authorization license service, and exit the authorization service of the target host device when the authorization result is abnormal, avoiding unauthorized access and use of the service, and further enhancing the security of the device.
[0069] It can be understood that in order to ensure the continuous effectiveness and security of the authorization service, the computer device can set up a scheduled task to regularly verify the authorization information of the authorization license service. During the regular verification process, the computer device sends a verification request to the authorization license service using the communication protocol and receives the returned verification result. Once it detects that the authorization result obtained from the verification is abnormal, such as the authorization information is invalid, mismatched, or there are other security risks, the computing device can trigger an emergency response mechanism, that is, exit the authorization service of the target host device, effectively avoiding the occurrence of unauthorized access and use of the service.
[0070] In the above embodiments, when authorizing a device, a device authorization file may be generated according to the device information of the target host device and the authorization information of the client device to be authorized, and the authorization license service may be started based on the device authorization file to achieve a complete privatized deployment of the service through the device authorization file. Then, a preset encryption policy may be used to encrypt the data in the device authorization file in groups to obtain an encrypted file set, and the encrypted file set may be saved to the local cache of the authorization license service, so that complex authorization communication work can be avoided through the peripheral device, while ensuring data security, improving the convenience of operation and the flexibility of deployment. Then, the platform main service may be started, and a connection may be established between the platform main service and the authorization license service based on the local cache, so that the target host device can perform the authorization service to meet the enterprise's requirements for an efficient and stable authorization service. During the authorization service, the authorization information of the authorization license service may be periodically verified, and when an abnormal authorization result occurs, the authorization service of the target host device may be exited to avoid unauthorized access and use of the service, further enhancing the security of the device.
[0071] In one embodiment, the process of generating a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized in step S110 may include:
[0072] S111: Determine the target host device and the client device to be authorized, and obtain the device information of the target host device and the authorization information of the client device.
[0073] S112: Upload the device information and the authorization information to the platform service center for data binding, and generate a device authorization file according to the binding result.
[0074] In this embodiment, the computer device may first determine the target host device and the client device to be authorized, obtain the device information of the target host device and the authorization information of the client device, then upload the device information and the authorization information to the platform service center for data binding, and generate a device authorization file according to the binding result.
[0075] Specifically, as the core node of the authorization license service, the target host device is mainly responsible for maintaining and distributing authorization data. Therefore, the computer device may first screen out a device that meets the requirements as the target host device and obtain its detailed device information, including the unique device identifier, hardware configuration information, operating system version, network environment information, and other information. At the same time, the computer device may also determine all the client devices to be authorized and collect their authorization information, such as the unique identifier of the device, device type, authorization mode, etc., to ensure that subsequent authorization management can cover all target devices.
[0076] Further, the computer device can upload the device information of the target host device and the authorization information of the client device to the platform service center, so that the platform service center can perform data binding. In this process, the platform service center can analyze and process the uploaded data, verify the legality of the device by comparing the device unique identifier, authorization policy, and authorization rules, and determine the binding relationship according to the authorization policy. In addition, the platform service center can also use security measures such as application digital signature, symmetric encryption, and hash algorithm to ensure the security and anti-tampering of the data during transmission and storage. Once the data binding is completed, the platform service center will generate a unique authorization credential and return the binding result, so that the computer device can generate a device authorization file according to the binding result.
[0077] It can be understood that the device authorization file of this application not only contains the authorization information of the target host device and the client device, but also is encrypted and signed to prevent tampering, and ensures that it can only take effect on the specified target host device, avoiding being copied or misused. Finally, the computer device can transmit the generated authorization file to the target host device and use it for the initialization of the authorization licensing service, so that the target host device can officially assume the function of authorization management and provide a secure and stable authorization verification mechanism for each device in the system cluster.
[0078] In one embodiment, the process of starting the authorization licensing service based on the device authorization file in step S110 may include:
[0079] S113: Store the device authorization file in the target host device, and parse the device authorization file through the target host device to obtain device information and authorization information.
[0080] S114: When the device information is consistent with the device information built in the target host device, perform a security check on the authorization start time in the authorization information, and start the authorization licensing service when the security check of the authorization start time passes.
[0081] In this embodiment, when starting the authorization licensing service, the computer device can store the device authorization file in the target host device, and parse the device authorization file through the target host device to obtain device information and authorization information. When the device information is consistent with the device information built in the target host device, perform a security check on the authorization start time in the authorization information, and start the authorization licensing service when the security check of the authorization start time passes.
[0082] Among them, the computer device stores the generated device authorization file in the target host device, which can ensure that the authorization data in the file can be securely managed and parsed locally, and extract the device information and authorization information for subsequent legality verification.
[0083] Specifically, the target host device can compare the extracted device information with its own built-in device information to ensure that the authorization file matches the currently running target host device, thereby preventing the authorization data from being illegally tampered with or used on unauthorized devices. After the device information verification passes, the target host device can also perform a security verification on the authorization start time in the authorization information, including methods such as timestamp verification, digital signature parsing, or encrypted data comparison, so as to further confirm the legality and effectiveness of the authorization. If the authorization start time verification passes, the target host device will officially start the authorization service, enabling it to enter the normal operating state and providing a stable authorization verification service for the client devices within the system cluster, thereby effectively preventing the occurrence of illegal authorization and ensuring the integrity and accuracy of the authorization data.
[0084] In one embodiment, the process of performing a security verification on the authorization start time in the authorization information in step S114 may include:
[0085] S1141: Determine the difference between the authorization start time and the current time of the target host device, and determine whether the difference exceeds a preset fault tolerance threshold.
[0086] S1142: If so, confirm that the security verification of the authorization time fails.
[0087] S1143: If not, confirm that the security verification of the authorization time passes.
[0088] In this embodiment, when performing a security verification on the authorization start time in the authorization information, the computer device can first determine the difference between the authorization start time and the current time of the target host device, and determine whether the difference exceeds a preset fault tolerance threshold; if so, confirm that the security verification of the authorization time fails; if not, confirm that the security verification of the authorization time passes.
[0089] Specifically, the computer device can first obtain the authorization start time recorded in the authorization information and synchronize the current time of the system in the target host device to ensure the accuracy and consistency of the time data. Subsequently, the computer device can calculate the time difference between the authorization start time and the current time of the target host device and compare it with the preset fault tolerance threshold to obtain the security verification result. Among them, the preset fault tolerance threshold can be set in advance by the system administrator or the authorization policy to define a reasonable time deviation range to prevent the authorization mechanism from failing due to time asynchronization or malicious tampering.
[0090] More specifically, if the calculated difference exceeds the preset fault tolerance threshold, it means that the security check of the authorization time has failed. At this time, the computer device can prevent the start of the authorization license service and issue a warning to the administrator or related system module to indicate that there may be security risks such as time tampering, system clock anomaly, or authorization data tampering. On the contrary, if the difference does not exceed the preset fault tolerance threshold, it means that the security check of the authorization time has passed. At this time, the computer device allows the authorization license service to start normally according to the authorization agreement, so that the target host device can continue to provide authorization management and verification services. Therefore, through this security verification mechanism, it can effectively prevent the authorization failure or illegal authorization caused by artificial modification of system time, network clock synchronization anomaly or other attack methods, and further improve the security and stability of the system.
[0091] In one embodiment, Figure 2 As shown, Figure 2 A schematic diagram of a process for generating an encrypted file set provided in an embodiment of the present application; Figure 2 In step S120, the process of using a preset encryption strategy to encrypt the device authorization file in data groups to obtain an encrypted file set may include:
[0092] S121: extract the authorization information in the device authorization file, and encrypt the authorization information using the national secret standard encryption algorithm to obtain encrypted data.
[0093] S122: Segment and confuse the encrypted data to obtain multiple groups of group data, and encrypt and encode each group data to obtain multiple encrypted group files.
[0094] S123: Encrypt and encode each group of encrypted group files based on the key of the national secret standard encryption algorithm and the preset splicing order to obtain an encrypted splicing file.
[0095] S124: using a type differentiation algorithm to mark the file type of each encrypted group file and encrypted spliced file, and forming an encrypted file set according to the marked encrypted group files and encrypted spliced files.
[0096] In this embodiment, the computer device may first extract the authorization information from the device authorization file, and use the encryption algorithm of the national cryptography standard to encrypt the authorization information to obtain encrypted data. Then, the encrypted data is segmented and confused to obtain multiple groups of grouped data, and each group of grouped data is encrypted and encoded respectively to obtain multiple encrypted grouped files. Next, the computer device may encrypt and encode each group of encrypted grouped files based on the key of the national cryptography standard encryption algorithm and the preset splicing order to obtain an encrypted spliced file. Finally, the computer device uses a type discrimination algorithm to label the file types of each encrypted grouped file and the encrypted spliced file, and forms an encrypted file set according to the labeled encrypted grouped files and encrypted spliced file.
[0097] Specifically, when processing the device authorization file, the computer device will first extract the authorization information to ensure that complete authorization data is obtained for subsequent encryption processing. After the extraction is completed, the computer device may use the encryption algorithm of the national cryptography standard, such as the SM9 encryption algorithm, to encrypt the authorization information, including the device fingerprint and expiration information, to generate a piece of encrypted data to ensure the confidentiality and security of the authorization information during storage and transmission.
[0098] After obtaining the encrypted data, the computer device may use a grouping algorithm to perform segmentation and confusion processing on it, dividing the encrypted data into multiple independent data blocks to improve the security and anti-cracking ability of the data. After the data segmentation is completed, the computer device may use the encryption algorithm of F-type files to encrypt and encode each group of grouped data respectively, thereby obtaining multiple encrypted grouped files, further enhancing the data security protection mechanism and preventing the risk of unauthorized tampering or detection failure of tampering.
[0099] Next, the computer device may use a clustering algorithm to perform secondary encryption and encoding on each group of encrypted grouped files based on the key of the national cryptography standard encryption algorithm and the preset splicing order to generate an encrypted spliced file. This can not only increase the integrity and security of the data, but also ensure that each group of grouped data can be recombined in the correct order during decryption and verification, improving the consistency and accuracy of the authorization data.
[0100] After all the encryption processing is completed, the computer device may use a type discrimination algorithm to label the file types of all the encrypted grouped files and the encrypted spliced file to ensure that the system can correctly identify and parse different types of encrypted files.
[0101] Finally, the computer device integrates the labeled encrypted grouped files and the encrypted spliced file to form a complete encrypted file set, providing a basic guarantee for subsequent authorization verification and system security management. Through these five encryption and data processing steps, the computer device can effectively protect the security of the authorization information, prevent unauthorized access or tampering, and at the same time improve the reliability and stability of the authorization service.
[0102] Schematically, as Figure 3 shown, Figure 3 is a flow diagram showing the transfer of a data encryption process provided by an embodiment of the present application; as can be seen from Figure 3 it, the present application can implement a complete data encryption process through five algorithms, namely the SM9 encryption algorithm, the grouping algorithm, the encryption algorithm for F - type files, the clustering algorithm, and the discrimination algorithm. The specific implementation process is as described above and Figure 3 will not be elaborated here.
[0103] It can be understood that Figure 3 in, the computer device can perform system initialization through the SMB (Server Message Block) protocol, generate a public master key and a master secret key, and then generate a private master key through a random ID and the public master key to ensure the uniqueness and security of the key. After generating the private master key, the computer device can also process authorization information and related system - derived information, and these information are encrypted into ciphertext through plaintext encryption to ensure the security of data during transmission. Then the computer device can determine the number of groups (GroupCount), which is determined by a random number between 3 and 12. It mainly calculates the average length of each group according to the length of the ciphertext and calculates a random length for each group to ensure that the data grouping process is random, thereby increasing security. Finally, the computer device can perform truncation processing on the ciphertext according to the calculation result to generate multiple groups (such as Group 1, Group 2, etc.), and each group corresponds to a string (such as String1, String2, etc.). The processing of these groups and strings can ensure the integrity and security of data during transmission and storage. Therefore, the present application can form the entire process based on five algorithms, and through encryption and grouping processing, ensure the security and reliability of system initialization.
[0104] In one embodiment, the process of periodically verifying authorization information for the authorization - permission service in step S140 may include:
[0105] S141: Periodically read the authorization information corresponding to the authorization - permission service, and determine whether there is an authorization update time in the authorization information.
[0106] S142: If so, determine the difference between the authorization update time and the current time of the target host device, and determine whether the difference exceeds a preset fault - tolerance threshold.
[0107] S143: When the difference does not exceed the preset fault - tolerance threshold, confirm that the verification result is normal.
[0108] S144: When the difference exceeds the preset fault - tolerance threshold, or the current time exceeds the authorization end time in the authorization information, confirm that the verification result is abnormal.
[0109] In this embodiment, the computer device can periodically read the authorization information corresponding to the authorization license service and determine whether there is an authorization update time in the authorization information. If so, it determines the difference between the authorization update time and the current time of the target host device, and determines whether the difference exceeds a preset fault tolerance threshold. When the difference does not exceed the preset fault tolerance threshold, the computer device can confirm that the verification result is normal; when the difference exceeds the preset fault tolerance threshold, or the current time exceeds the authorization end time in the authorization information, the computer device can confirm that the verification result is abnormal.
[0110] It can be understood that the computer device can periodically read the authorization information corresponding to the authorization license service at preset time intervals to ensure that the authorization status of the system remains valid and controlled. After reading the authorization information, the computer device can check whether the authorization information contains an authorization update time, that is, the last update timestamp of the authorization data, to judge the timeliness and integrity of the authorization information.
[0111] Specifically, if there is an authorization update time in the authorization information, the computer device can synchronize the current time of the target host device, calculate the time difference between the authorization update time and the current time, and compare this difference with the preset fault tolerance threshold set by the system. When the calculated difference does not exceed the preset fault tolerance threshold, it means that the authorization information is still within the safe range, and the authorization license service can continue to run stably. At this time, the computer device can determine that the verification result is normal; when the difference exceeds the preset fault tolerance threshold, it means that the authorization data has not been updated for a long time, and there is a risk of clock drift, data synchronization anomaly, or authorization mechanism failure. At this time, the computer device can determine that the verification result is abnormal.
[0112] In addition, the computer device can further check whether the current time has exceeded the authorization end time recorded in the authorization information. If the current time has exceeded the authorization end time, it means that the authorization has expired. At this time, the computer device can also determine that the verification result is abnormal and perform corresponding authorization restriction or termination operations according to the security policy, such as preventing the authorization license service from continuing to run, notifying the administrator to update the authorization, or triggering the system security protection mechanism to avoid unauthorized access and use.
[0113] Therefore, through this periodic verification mechanism, the computer device can ensure the effectiveness and security of the authorization information, prevent authorization failures or illegal use problems caused by expired authorizations, time tampering, or data synchronization anomalies, thereby enhancing the stability and security of the system, and at the same time providing an efficient and reliable authorization management guarantee for the enterprise's private authorization deployment.
[0114] In one embodiment, the authorization license service is connected to multiple slave services; the method may further include:
[0115] S150: After the authorization service is started, the encrypted file set is synchronized to the local caches of each slave service through the authorization service for storage, so that after the authorization service fails and exits the authorization service, a slave service is elected from each slave service as the new authorization service and the authorization service is restarted.
[0116] In this embodiment, the authorization service is connected to multiple slave services. After the authorization service is started, the computer device can synchronize the encrypted file set to the local caches of each slave service through the authorization service for storage, so that after the authorization service fails and exits the authorization service, a slave service is elected from each slave service as the new authorization service and the authorization service is restarted.
[0117] Specifically, after the authorization service is successfully started, the computer device can synchronize the generated encrypted file set to the local caches of multiple slave services and ensure that each slave service can accurately receive and store these encrypted files, so as to have high availability and disaster tolerance capabilities during the operation of the authorization service.
[0118] For example, when the authorization service is interrupted due to system failure, abnormal exit or other unforeseen circumstances, the computer device can automatically trigger the slave service election mechanism, elect a suitable slave service from multiple slave services, make it assume the new authorization service role, and restart the authorization service to maintain the stable operation of the system. During the election process, the computer device can comprehensively evaluate the availability of each slave service according to the preset election strategy, such as the health status, response speed, operation log records, load conditions and connection status with other system modules of the slave service, and finally select the most suitable slave service as the new authorization service.
[0119] Furthermore, after the new authorization service is determined, the selected slave service will read the encrypted file set from the local cache, decrypt and parse the authorization information therein to ensure the continuity and integrity of the authorization status. Once the authorization information verification passes, the slave service will officially take over the authorization service function and provide authorization verification and management services for the system again. At the same time, the computer device can also send notifications to other slave services to update the current authorization service node information to ensure the correct identification and access of the entire system to the new authorization service.
[0120] It can be understood that through this master-slave backup and dynamic switching mechanism, even if the authorization service exits unexpectedly, the system can still seamlessly resume the authorization service, ensure the high availability and business continuity of authorization management, avoid service interruption or business damage caused by the failure of the authorization mechanism, and at the same time improve the system robustness and operation stability of the enterprise in the private deployment environment.
[0121] The device authorization apparatus provided by the embodiments of the present application will be described below. The device authorization apparatus described below can be correspondingly referred to the device authorization method described above.
[0122] In one embodiment, as Figure 4 shown, Figure 4 is a schematic structural diagram of a device authorization apparatus provided by an embodiment of the present application; the present application also provides a device authorization apparatus, including a service startup module 210, a file storage module 220, a service connection module 230, and an information verification module 240, specifically including the following:
[0123] The service startup module 210 is configured to generate a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized, and start an authorization permission service based on the device authorization file.
[0124] The file storage module 220 is configured to perform data grouping encryption parsing on the device authorization file by using a preset encryption policy, obtain an encrypted file set, and save the encrypted file set to the local cache of the authorization permission service.
[0125] The service connection module 230 is configured to start a platform main service, and establish a connection between the platform main service and the authorization permission service based on the local cache, so that the target host device performs an authorization service.
[0126] The information verification module 240 is configured to periodically verify the authorization information of the authorization permission service, and exit the authorization service of the target host device when an abnormal authorization result occurs.
[0127] In the above embodiment, when authorizing a device, a device authorization file can be generated according to the device information of the target host device and the authorization information of the client device to be authorized, and an authorization permission service can be started based on the device authorization file to implement a complete privatized deployment of the service through the device authorization file. Then, a preset encryption policy can be used to perform data grouping encryption on the device authorization file to obtain an encrypted file set, and the encrypted file set can be saved to the local cache of the authorization permission service, so that complex authorization communication work can be avoided through peripheral devices, while ensuring data security, improving the convenience of operation and the flexibility of deployment; then, the platform main service can be started, and a connection can be established between the platform main service and the authorization permission service based on the local cache, so that the target host device performs an authorization service to meet the enterprise's demand for an efficient and stable authorization service; during the authorization service, the authorization information of the authorization permission service can also be periodically verified, and when an abnormal authorization result occurs, the authorization service of the target host device can be exited to avoid unauthorized access and use, further enhancing the security of the device.
[0128] In one embodiment, the service startup module 210 may include:
[0129] An information acquisition sub-module, configured to determine a target host device and a client device to be authorized, and acquire device information of the target host device and authorization information of the client device.
[0130] A data binding sub-module, configured to upload the device information and the authorization information to a platform service center for data binding, and generate a device authorization file according to the binding result.
[0131] In one embodiment, the service startup module 210 may further include:
[0132] A file parsing sub-module, configured to store the device authorization file in the target host device, and parse the device authorization file through the target host device to obtain device information and authorization information.
[0133] A security verification sub-module, configured to perform a security verification on the authorization start time in the authorization information when the device information is consistent with the device information built in the target host device, and start an authorization permission service when the security verification of the authorization start time passes.
[0134] In one embodiment, the security verification sub-module may include:
[0135] A first difference judgment unit, configured to determine a difference between the authorization start time and the current time of the target host device, and judge whether the difference exceeds a preset fault tolerance threshold.
[0136] A first confirmation unit, configured to confirm that the security verification of the authorization time fails when the difference exceeds the preset fault tolerance threshold.
[0137] A second confirmation unit, configured to confirm that the security verification of the authorization time passes when the difference does not exceed the preset fault tolerance threshold.
[0138] In one embodiment, the file saving module 220 may include:
[0139] A data encryption sub-module, configured to extract the authorization information from the device authorization file, and encrypt the authorization information by using a national cryptography standard encryption algorithm to obtain encrypted data.
[0140] A data segmentation sub-module, configured to segment and confuse the encrypted data to obtain multiple groups of segmented data, and respectively perform encryption coding on each group of segmented data to obtain multiple encrypted segmented files.
[0141] A data splicing sub-module, configured to perform encryption coding on each group of encrypted segmented files based on a key of the national cryptography standard encryption algorithm and a preset splicing order to obtain an encrypted spliced file.
[0142] A type discrimination sub-module is used to label the file types of each encrypted packet file and encrypted splicing file by using a type discrimination algorithm, and form an encrypted file set according to the labeled encrypted packet files and encrypted splicing files.
[0143] In one embodiment, the information verification module 240 may include:
[0144] An authorization information reading sub-module is used to regularly read the authorization information corresponding to the authorization permission service, and determine whether there is an authorization update time in the authorization information.
[0145] A second difference judgment sub-module is used to, when there is an authorization update time in the authorization information, determine the difference between the authorization update time and the current time of the target host device, and judge whether the difference exceeds a preset fault tolerance threshold.
[0146] A third confirmation sub-module is used to confirm that the verification result is normal when the difference does not exceed the preset fault tolerance threshold.
[0147] A fourth confirmation sub-module is used to confirm that the verification result is abnormal when the difference exceeds the preset fault tolerance threshold, or the current time exceeds the authorization end time in the authorization information.
[0148] In one embodiment, there are multiple slave services connected to the authorization permission service in the device; the device may further include:
[0149] A service competition module is used to, after the authorization permission service is started, synchronize the encrypted file set to the local caches of each slave service through the authorization permission service for storage, so that after the authorization permission service fails and exits the authorization service, a slave service is selected from each slave service as the new authorization permission service and the authorization service is restarted.
[0150] In one embodiment, the present application further provides a storage medium, in which computer-readable instructions are stored. When the computer-readable instructions are executed by one or more processors, one or more processors are caused to execute the steps of the device authorization method as described in any one of the above embodiments.
[0151] In one embodiment, the present application further provides a computer device, in which computer-readable instructions are stored. When the computer-readable instructions are executed by one or more processors, one or more processors are caused to execute the steps of the device authorization method as described in any one of the above embodiments.
[0152] Schematically, as Figure 5 shown, Figure 5 is an internal structural schematic diagram of a computer device provided by an embodiment of the present application. The computer device 300 may be provided as a server. Referring toFigure 5 The computer device 300 includes a processing component 302, which further includes one or more processors, and memory resources represented by a memory 301 for storing instructions executable by the processing component 302, such as application programs. The application programs stored in the memory 301 may include one or more modules each corresponding to a set of instructions. In addition, the processing component 302 is configured to execute instructions to perform the device authorization method of any of the above embodiments.
[0153] The computer device 300 may further include a power component 303 configured to perform power management of the computer device 300, a wired or wireless network interface 304 configured to connect the computer device 300 to a network, and an input / output (I / O) interface 305. The computer device 300 may operate based on an operating system stored in the memory 301, such as Windows Server TM, Mac OS XTM, Unix TM, Linux TM, Free BSDTM, or the like.
[0154] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. A specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different component layout.
[0155] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0156] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referred to each other.
[0157] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A device authorization method, characterized in that: The method comprises: Generate a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized, and start the authorization licensing service based on the device authorization file; Encrypting the device authorization file in data packets using a preset encryption strategy to obtain an encrypted file set, and saving the encrypted file set to a local cache of the authorization licensing service; Starting the platform main service, and establishing a connection between the platform main service and the authorization and licensing service based on the local cache, so that the target host device performs authorization services; The authorization information of the authorization license service is verified regularly, and when the authorization result is abnormal, the authorization service of the target host device is exited.
2. The device authorization method according to claim 1, characterized in that: The generating of the device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized includes: Determine a target host device and a client device to be authorized, and obtain device information of the target host device and authorization information of the client device; The device information and the authorization information are uploaded to the platform service center for data binding, and a device authorization file is generated according to the binding result.
3. The device authorization method according to claim 1, characterized in that: The starting the authorization licensing service based on the device authorization file includes: The device authorization file is stored in the target host device, and the device authorization file is parsed by the target host device to obtain device information and authorization information; When the device information is consistent with the device information built into the target host device, a security check is performed on the authorization start time in the authorization information, and when the security check of the authorization start time passes, the authorization licensing service is started.
4. The device authorization method according to claim 3, characterized in that: The performing security verification on the authorization start time in the authorization information includes: Determine the difference between the authorization start time and the current time of the target host device, and determine whether the difference exceeds a preset fault tolerance threshold; If yes, confirm that the security check of the authorization time fails; If not, confirm that the security check of the authorization time has passed.
5. The device authorization method according to claim 1, characterized in that: The method of using a preset encryption strategy to encrypt the device authorization file in data groups to obtain an encrypted file set includes: Extracting the authorization information from the device authorization file, and encrypting the authorization information using a national secret standard encryption algorithm to obtain encrypted data; The encrypted data is divided and obfuscated to obtain multiple groups of group data, and each group data is encrypted and encoded to obtain multiple encrypted group files; Encrypting and encoding each group of encrypted group files based on the key of the national secret standard encryption algorithm and the preset splicing order to obtain an encrypted splicing file; A type differentiation algorithm is used to mark the file types of each encrypted group file and the encrypted spliced file, and an encrypted file set is formed according to the marked encrypted group files and encrypted spliced files.
6. The device authorization method according to claim 1, characterized in that: The periodically verifying the authorization information of the authorization and licensing service includes: Read the authorization information corresponding to the authorization license service at regular intervals, and determine whether there is an authorization update time in the authorization information; If so, determining the difference between the authorized update time and the current time of the target host device, and determining whether the difference exceeds a preset fault tolerance threshold; When the difference does not exceed the preset fault tolerance threshold, confirming that the verification result is normal; When the difference exceeds the preset fault tolerance threshold, or the current time exceeds the authorization end time in the authorization information, it is confirmed that the verification result is abnormal.
7. The device authorization method according to claim 1, characterized in that: The authorization and licensing service is connected to a plurality of slave services; the method further comprises: When the authorization and licensing service is started, the encrypted file set is synchronized to the local cache of each slave service through the authorization and licensing service for storage, so that after the authorization and licensing service fails and exits the authorization service, a slave service is elected from each slave service as a new authorization and licensing service and the authorization service is restarted.
8. A device authorization apparatus, characterized in that: include: A service startup module, used to generate a device authorization file according to the device information of the target host device and the authorization information of the client device to be authorized, and to start the authorization license service based on the device authorization file; A file saving module, used to encrypt the device authorization file in data packets using a preset encryption strategy to obtain an encrypted file set, and save the encrypted file set to a local cache of the authorization and licensing service; A service connection module, used for starting the platform main service and establishing a connection between the platform main service and the authorization and licensing service based on the local cache, so that the target host device performs the authorization service; The information verification module is used to verify the authorization information of the authorization license service at regular intervals, and to exit the authorization service of the target host device when an abnormality occurs in the authorization result.
9. A storage medium, characterized in that: The storage medium stores computer-readable instructions, and when the computer-readable instructions are executed by one or more processors, the one or more processors execute the steps of the device authorization method as described in any one of claims 1 to 7.
10. A computer device, characterized in that: include: one or more processors, and memory; The memory stores computer-readable instructions, and when the computer-readable instructions are executed by the one or more processors, the steps of the device authorization method according to any one of claims 1 to 7 are performed.
Citation Information
Cited By
Software authorization code generation method and device, software authorization code analysis method and device, equipment, storage medium and product
CN121009529A
Software license code generation method, analysis method, device, equipment, storage medium and product
CN121009529B