Certificate verification method based on confusion encryption
By adopting a certificate verification method based on obfuscated encryption in software authorization management, combining RSA public and private keys, SM3 hash and AES encryption, the integrity and source authenticity of license data are guaranteed, and the security and user experience problems of authorization management in the prior art are solved.
Patent Information
- Application Number
- CN202510642481.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing software authorization management technology is facing the continuous evolution of cracking methods, declining user experience, difficulty in ensuring the integrity and authenticity of encrypted data, and authorization verification relies on a single encryption algorithm and local system time, which is easily bypassed.
The certificate verification method based on obfuscated encryption is adopted, and the encryption index and private key index are generated through the combination of RSA public key and private key, message filling and SM3 hashing operations are performed to generate the license plaintext, and the main wheel encryption is used to use the AES key, and the final license file is generated by combining digital signatures and multiple time verification.
Ensure the integrity and authenticity of the License data, protect the core verification logic, and enhance the security and reliability of authorization management through multiple time verification and hardware information binding.
Smart Images

Figure CN120165882A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of software license management, and particularly to a certificate verification method based on obfuscation encryption. Background Art
[0002] In the current era of rapid digital development, the wide application of software has made software license management a crucial technical field. As enterprises and individual users become more dependent on software products. This not only affects the revenue of software developers but also causes unfair competition in the market.
[0003] Existing software license management technologies mainly include license key generation, activation mechanisms, and user authentication, etc. However, with the progress of technology, these traditional methods face many challenges, such as the continuous evolution of cracking methods and the decline in user experience.
[0004] Existing technologies mostly rely on a single encryption algorithm (such as only RSA or AES) and do not combine digital signature technologies (such as SM3 hashing). The encrypted License data does not attach an integrity verification value, and attackers can tamper with the encrypted content and then re-encrypt it to bypass the verification.
[0005] Existing code obfuscation technologies (such as ProGuard) only simply replace class names and method names and do not encrypt bytecodes. Attackers can directly read the key verification logic through decompilation tools (such as JD-GUI).
[0006] Existing solutions only rely on the local system time to verify the authorization validity period, and users can bypass the restriction by modifying the system time or disabling network time synchronization (NTP). In the existing technology, the License plaintext is not bound to hardware features, resulting in the authorization being able to be copied and used across devices. Summary of the Invention
[0007] In view of the above situation, the main purpose of the present invention is to propose a certificate verification method and system based on obfuscation encryption to solve the above technical problems.
[0008] The present invention proposes a certificate verification method based on obfuscation encryption, and the method includes the following steps: Step 1, obtain two large prime numbers, and calculate an encryption exponent based on the obtained large prime numbers; Calculate a private key exponent based on the encryption exponent; Combine the encryption exponent, the private key exponent, and the modulus to obtain an RSA public key and an RSA private key; Step 2, perform message padding on the original binary data to obtain padded binary data, and generate a message word sequence using the padded binary data; Calculate the intermediate value through the message word sequence, and use the intermediate value to iterate the intermediate state vector of the SM3 compression function; After reaching the set number of iterations, output the final hash value, and generate the License plaintext through the final hash value; Step 3: Use the License plaintext and the AES key to perform the main round encryption on the padded binary data to obtain the ciphertext; Encrypt the AES key using the RSA public key to obtain the encrypted AES key; Step 4: Use the RSA private key and the License plaintext to generate a digital signature; Assemble the ciphertext, the encrypted AES key, and the digital signature to obtain the final License file; Step 5: Use the RSA public key and the original binary data to verify the final License file to obtain the verification result.
[0009] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. The present invention ensures the integrity and source authenticity of License data through a dual mechanism of "encryption + signature"; 2. The present invention protects the core verification logic by using bytecode obfuscation and dynamic decryption techniques; 3. The present invention performs multiple verifications by combining the server time and the local encrypted timestamp; 4. The present invention incorporates the hardware information into the License plaintext generation and verification processes.
[0010] The additional aspects and advantages of the present invention will be partially given in the following description, partially become apparent from the following description, or be understood through the embodiments of the present invention. Description of the Drawings
[0011] Figure 1 It is a flowchart of a certificate verification method based on obfuscated encryption proposed by the present invention. Detailed Embodiments
[0012] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention and should not be construed as limiting the present invention.
[0013] These and other aspects of the embodiments of the present invention will be apparent from the following description and the accompanying drawings. In these descriptions and drawings, specific embodiments of the embodiments of the present invention are specifically disclosed to represent some ways of implementing the principles of the embodiments of the present invention, but it should be understood that the scope of the embodiments of the present invention is not limited thereto.
[0014] Please refer to Figure 1 , an embodiment of the present invention provides a certificate verification method based on obfuscation encryption, and the method includes the following steps: Step 1: Obtain two large prime numbers, and calculate an encryption exponent based on the obtained large prime numbers; Calculate a private key exponent based on the encryption exponent; Combine the encryption exponent, the private key exponent, and the modulus to obtain an RSA public key and an RSA private key; In step 1, to obtain two large prime numbers and calculate an encryption exponent based on the obtained large prime numbers, the specific steps are as follows: Obtain a modulus through the large prime numbers, and the relational expression existing in the corresponding process is: ; Among them, represents the modulus, and both represent large prime numbers; Obtain an Euler's totient function through the modulus and the large prime numbers, and the relational expression existing in the corresponding process is: ; Among them, represents the Euler's totient function; Obtain an encryption exponent based on the Euler's totient function, and the relational expression existing in the corresponding process is: ; Among them, represents the encryption exponent, represents that the encryption exponent and the Euler's totient function are relatively prime; Calculate a private key exponent based on the encryption exponent, and the relational expression existing in the corresponding process is: ; Among them, represents the private key exponent, represents the modulo operation.
[0015] Furthermore, in this step, by combining the Miller-Rabin primality test and the random number perturbation mechanism, it is ensured that the generated prime numbers have higher randomness and anti-cracking properties. In specific implementation, the system will dynamically adjust the number of bits of the prime numbers (such as expanding from 2048 bits to 3072 bits) to cope with the improvement of future computing power.
[0016] Meanwhile, after the private key exponent is generated, it will be sharded and stored in different security modules, and needs to be recombined through a security protocol during use to prevent the leakage of the private key.
[0017] Furthermore, when calculating the Euler's totient function, the fast exponentiation algorithm is adopted to optimize the performance and reduce the large number operation time. The selection of the encryption exponent accelerates the relatively prime judgment through pre-computing the prime number table to improve the key generation efficiency.
[0018] Step 2: Perform message padding on the original binary data to obtain the padded binary data, and generate a message word sequence using the padded binary data. Calculate the intermediate value through the message word sequence, and use the intermediate value to iterate the intermediate state vector of the SM3 compression function. After reaching the set number of iterations, output the final hash value, and generate the License plaintext through the final hash value. In Step 2, performing message padding on the original binary data to obtain the padded binary data, and generating a message word sequence using the padded binary data, the specific steps are as follows: Perform message padding on the original binary data to obtain the padded binary data. Perform grouping processing on the padded binary data. The relational expression existing in the corresponding process is: ; Among them, both represent 512-bit information blocks, represents the number of groups, represents the padded binary data; Apply the expansion function to each message group to generate a message word sequence. The relational expression existing in the corresponding process is: ; Among them, represents the sequence of the th message word, represents the th message word, represents the th message word; Calculate the intermediate value through the message word sequence. The relational expression existing in the corresponding process is: ; Among them, and both represent being processed by the non-linear Boolean function in the th round, and both represent the output values, represents being used for calculation Intermediate variable, indicating the intermediate variable used for calculation Intermediate variable, indicating rotating each position of the binary number to the left, indicating the constant of the round, both indicating the index of the current vector item count; Iterate the intermediate state vector of the SM3 compression function using the intermediate value, and the relational expression existing in the corresponding process is: ; where, indicating the intermediate vector before the group processing, indicating the intermediate vector before the group processing, indicating being processed by the permutation function, indicating a 32-bit integer; After reaching the set number of iterations, output the final hash value, and the relational expression existing in the corresponding process is: ; where, indicating the final hash value, indicating being processed by the SM3 compression function.
[0019] Furthermore, the License certificate is first entered into the authorization system by the operation and maintenance personnel, filling in the relevant information of the client server obtained by the shell script and other information, and generating the corresponding license certificate through a specific encryption method. The business system loads the license certificate through the import method, and at the same time integrates the certificate verification SDK and the custom classloader class encryption and decryption SDK.
[0020] Based on the asm bytecode code obfuscation maven plugin, it will perform bytecode-level code obfuscation and encryption on the certificate verification SDK and other specified classes. The business system will directly reference the obfuscated and encrypted certificate verification SDK, and decrypt and obfuscate and run it by the class loader of the business system at runtime.
[0021] The certificate verification SDK will be started regularly to check whether the MAC address of the business system is consistent and whether the system time is within the valid period.
[0022] Furthermore, in the message padding stage, a random salt value based on yin characteristics is introduced, and the relational expression existing in the corresponding process is: ; where, Indicates that after padding processing, Indicates a randomly generated 16-byte value, Indicates the original binary data.
[0023] Specifically, the iteration of the SM3 compression function adopts multi-threaded block processing. Each group of message word sequences independently calculates the intermediate value and then merges them to improve the throughput.
[0024] Step 3: Use the License plaintext and the AES key to perform the main round encryption on the padded binary data to obtain the ciphertext; Use the RSA public key to encrypt the AES key to obtain the encrypted AES key; In Step 3, use the License plaintext and the AES key to perform the main round encryption on the padded binary data to obtain the ciphertext. The specific steps are as follows: Initialize the state matrix with the License plaintext. The relationship existing in the corresponding process is: ; Wherein, Indicates the License plaintext, Indicates the initial state matrix, Indicates the key of the 0th round; Use the state matrix and the AES key to perform the main round encryption on the padded binary data to obtain the ciphertext. The relationship existing in the corresponding process is: ; Wherein, Indicates the ciphertext, Indicates that after processing through a predefined lookup table, Indicates using the predefined lookup table to replace each byte with another byte, Indicates the number of rows, Indicates the number of columns, Indicates a state matrix with Rows Columns, Indicates that each column is multiplied by For column confusion, Indicates the current round key, Indicates the round number, Indicates the current state matrix, Indicates the state matrix of the 10th round; Use the RSA public key to encrypt the AES key to obtain the encrypted AES key. The relationship existing in the corresponding process: ; Wherein, Indicates the encrypted AES key, Represents the AES key; Specifically, during the process of using the AES key for main-round encryption, the round key is derived in real time through SM3 hashing. The relational expression existing in the corresponding process is: ; Moreover, the encrypted AES key is appended with a timeliness tag and will automatically become invalid after timeout, and re-authorization is required.
[0025] Step 4: Generate a digital signature using the RSA private key and the License plaintext; Assemble the ciphertext, the encrypted AES key, and the digital signature to obtain the final License file; In Step 4, when generating a digital signature using the RSA private key and the License plaintext, the relational expression existing in the corresponding process is: ; Wherein, represents the hash value of the License plaintext, represents the digital signature.
[0026] Furthermore, through Steps 1 to 4, a triple protection chain of AES data encryption, SA key encryption, and SM3 signature is formed to solve the problem that a single algorithm is easily cracked.
[0027] Step 5: Use the RSA public key and the original binary data to verify the final License file to obtain a verification result.
[0028] Furthermore, in this step, the RSA public key is used to decrypt the final License file to obtain decrypted data, and then the SM3 algorithm is used in combination with the binary data to calculate the hash value of the decrypted data. Compare this hash value with the hash value in the signature to verify the integrity of the data.
[0029] Specifically, in this step, a timestamp service module is set up. The timestamp service module uses blockchain technology to store encrypted timestamps, and the signature on the blockchain needs to be verified during local verification; at the same time, the timestamp service module will regularly obtain encrypted timestamps from the authorization server and compare them with the local time; The present invention sets up time reverse detection. By recording the most recent legal timestamp, a warning is triggered when time rollback is detected; Combining the server time and the local encrypted timestamp to prevent local time tampering.
[0030] Before verifying the final License file, the binary data is verified using a composite hash based on the CPU serial number and the hard disk ID. The relational expression existing in the corresponding process is: ; Among them, represents the verification hash value, represents the MAC address, represents the CPU serial number, represents the hard disk ID; The binary data is verified by comparing the verification hash value with the final hash value.
[0031] Furthermore, in deployment and operation, dynamic obfuscation loading is adopted. The ASM obfuscation plugin of the certificate verification SDK decrypts class bytecodes as needed during runtime. The decryption key is dynamically issued by the server and updated every time it starts.
[0032] For low-performance devices, a "quick verification" option is provided to only verify critical hash values and timestamps to balance security and performance.
[0033] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one of the following techniques known in the art or a combination thereof can be used: discrete logic circuits with logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits with appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0034] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0035] The above-described embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but should not be construed as limiting the scope of the present invention's patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention's patent should be subject to the appended claims.
Claims
1. A certificate verification method based on obfuscation encryption, characterized in that: The method comprises the following steps: Step 1, obtain two large prime numbers, and calculate the encryption exponent based on the obtained large prime numbers; The private key index is calculated based on the encryption index; Combine the encryption exponent, private key exponent and modulus to obtain the RSA public key and RSA private key; Step 2: Fill the original binary data with a message to obtain filled binary data, and generate a message word sequence using the filled binary data; The intermediate value is calculated through the message word sequence, and the intermediate state vector of the SM3 compression function is iterated using the intermediate value; After reaching the set number of iterations, the final hash value is output and the License plain text is generated through the final hash value; Step 3: Use the License plaintext and the AES key to perform a main round encryption on the filled binary data to obtain the ciphertext; Encrypt the AES key using the RSA public key to obtain the encrypted AES key; Step 4: Generate a digital signature using the RSA private key and the License plain text. Assemble the ciphertext, encrypted AES key, and digital signature to obtain the final license file; Step 5: Use the RSA public key and original binary data to verify the final license file and obtain the verification result.
2. According to the certificate verification method based on obfuscated encryption according to claim 1, it is characterized in that: In step 1, two large prime numbers are obtained, and an encryption index is calculated based on the obtained large prime numbers. The specific steps are as follows: The modulus is obtained by a large prime number, and the corresponding process has the following relationship: ; in, represents the modulus, and Both represent large prime numbers; The Euler function is obtained by modulus and large prime numbers, and the corresponding process has the following relationship: ; in, represents the Euler function; Based on the Euler function, the encryption index is obtained, and the corresponding process has the following relationship: ; in, represents the encryption index, Indicates that the encrypted exponent and the Euler function are coprime.
3. A certificate verification method based on obfuscated encryption according to claim 2, characterized in that: In step 1, the private key index is calculated based on the encryption index, and the corresponding process has the following relationship: ; in, represents the private key exponent, Represents the modulo operation.
4. A certificate verification method based on obfuscated encryption according to claim 3, characterized in that: In step 2, the original binary data is message filled to obtain filled binary data, and the message word sequence is generated using the filled binary data. The specific steps are as follows: Perform message padding on the original binary data to obtain the filled binary data; The binary data after filling is grouped and processed, and the relationship between the corresponding process is: ; in, Both represent 512-bit information blocks. Indicates the number of groups. Represents the binary data after padding; Apply the expansion function to each message group to generate a message word sequence. The corresponding process relationship is: ; in, Indicates A sequence of message words, Indicates Message word, Indicates A message word.
5. A certificate verification method based on obfuscated encryption according to claim 4, characterized in that: In step 2, the intermediate value is calculated by the message word sequence, and the relationship between the corresponding process is: ; in, and All indicated that after Nonlinear Boolean function processing of the wheel, and All represent output values. Indicates the calculation The intermediate variable Indicates the calculation The intermediate variable It means to rotate each position of the binary number to the left. Indicates The constant of the wheel, represents the number of iterations, Both represent the index of the current vector item number.
6. A certificate verification method based on obfuscated encryption according to claim 5, characterized in that: In step 2, the intermediate state vector of the SM3 compression function is iterated using the intermediate value, and the relationship between the corresponding process is: ; in, Indicates The intermediate vector before group processing, Indicates The intermediate vector before group processing, Indicates that it is processed by the permutation function. Represents a 32-bit integer.
7. A certificate verification method based on obfuscated encryption according to claim 6, characterized in that: In step 2, after reaching the set number of iterations, the final hash value is output, and the relationship between the corresponding process is: ; in, Represents the final hash value, Indicates that the data has been processed by the SM3 compression function.
8. A certificate verification method based on obfuscated encryption according to claim 7, characterized in that: In step 3, the filled binary data is encrypted using the License plaintext and the AES key to obtain the ciphertext. The specific steps are as follows: Use the License plain text to initialize the state matrix. The corresponding process has the following relationship: ; in, Indicates the license plain text. represents the initial state matrix, Indicates the key of round 0; The filled binary data is encrypted using the state matrix and the AES key to obtain the ciphertext. The corresponding process has the following relationship: ; in, Represents ciphertext, Indicates that it has been processed by a predefined lookup table. means to replace each byte with another byte using a predefined lookup table. Indicates the number of rows, Indicates the number of columns, Indicates a person who has OK The state matrix of the columns, Indicates that each column and Multiplication is done to confuse the columns, represents the current round key, Indicates the number of rounds, represents the current state matrix, Represents the state matrix of the 10th round.
9. A certificate verification method based on obfuscated encryption according to claim 8, characterized in that: In step 3, the AES key is encrypted using the RSA public key to obtain the encrypted AES key. The corresponding process has the following relationship: ; in, Represents the encrypted AES key. Indicates an AES key.
10. A certificate verification method based on obfuscated encryption according to claim 9, characterized in that: In step 4, a digital signature is generated using the RSA private key and the License plain text. The corresponding relationship in the process is: ; in, Indicates the hash value of the License plain text. Indicates a digital signature.
Citation Information
Patent Citations
License generation method and system
CN116881865A
Cited By
Power communication resource data encryption method, system and equipment based on multi-algorithm fusion
CN121012627A