Method and system for verifying legality of equipment through software, and storage medium
A software-based validation method using encrypted permission codes in a trusted execution environment ensures legitimate device operation, enhancing security and reducing costs by eliminating the need for additional hardware encryption chips.
Patent Information
- Application Number
- CN202510387999.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-31
- Publication Date
- 2025-07-15
AI Technical Summary
The existing software verification device legality methods have problems such as low security or high hardware cost, especially the serial number protection mechanism is easy to be cracked, network verification requires a network environment, and hardware encryption costs are relatively high.
Controllable software is generated through the software source server. The device decrypts the encrypted licensed feature code in the trusted execution environment and compares it with the hardware feature code. If it is consistent, the software plaintext will be decrypted. Otherwise, the controllable software will be stopped and the trusted execution environment will be used to improve cracking difficulty and reduce hardware costs.
The license binding between software and device hardware is realized, effectively preventing illegal theft and overuse of rights, improving security and reducing hardware costs.
Smart Images

Figure CN120316754A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of encryption technology, and particularly to a method and system for verifying the legality of a device through software, and a storage medium. Background Art
[0002] For security or some special requirements, it is necessary to implement a solution in which software can verify the legality of a device so as to control the software operation permission. This solution supports that system software and application software can run normally on specified legal devices and cannot run normally on illegal devices. The system software and application software adopting this solution can prevent illegal theft and unauthorized use of software, such as preventing scenarios like hardware cloning.
[0003] Currently, the commonly used methods for software to verify the legality of a device include methods such as serial number protection mechanism, network verification, and hardware encryption. In these methods, the serial number protection mechanism is easily cracked and has low security. Network verification requires a network environment and the construction of a verification server. Hardware encryption involves an additional encryption chip in the software operation process, and the security is relatively well guaranteed, but the hardware cost is relatively high. Summary of the Invention
[0004] The present invention provides a method and system for verifying the legality of a device through software, and a storage medium, which can improve the effectiveness of preventing illegal theft and unauthorized use of software and reduce the hardware cost.
[0005] In one aspect of the present invention, a method for verifying the legality of a device through software is provided. The method includes: sending a controllable software from a software source server to the device, where the controllable software is generated based on the hardware feature code of the device and software encryption, and the controllable software includes an encrypted license feature code and encrypted software; decrypting the encrypted license feature code by the device in a trusted execution environment to obtain a license feature code; reading the hardware feature code from a secure one-time programmable area by the device and comparing the hardware feature code with the license feature code; if the result of the comparison is inconsistent, stopping processing the controllable software in the trusted execution environment; and if the result of the comparison is consistent, decrypting the encrypted software by the device in the trusted execution environment to obtain a software plaintext for running in the device.
[0006] In another aspect of the present invention, there is provided a system for verifying the legitimacy of a device through software. The system includes: a software source server configured to generate controllable software based on software encryption and the hardware signature of the device, the controllable software including an encrypted license signature and encrypted software; and a device coupled to the software source server and configured to: receive the controllable software from the software source server, decrypt the encrypted license signature in a trusted execution environment to obtain a license signature; read the hardware signature from a secure one-time programmable area, and compare the hardware signature with the license signature; if the result of the comparison is inconsistent, stop processing the controllable software in the trusted execution environment; and if the result of the comparison is consistent, decrypt the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device.
[0007] In yet another aspect of the present invention, there is provided a computer-readable medium. A computer program is stored on the medium, and the computer program is executed by a processor to implement the above method for verifying the legitimacy of a device through software.
[0008] According to the present invention, the software source server sends the controllable software to the device. The device decrypts the encrypted license signature in the trusted execution environment to obtain the license signature. The device reads the hardware signature from the secure one-time programmable area and compares the hardware signature with the license signature. If they are inconsistent, the processing of the controllable software is stopped. If they are consistent, the device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device, thereby realizing the license binding between the software and the device hardware. The trusted execution environment is added to the license verification process. The verification of the license signature and the decryption of the encrypted software are implemented in the trusted execution environment, effectively preventing the tampering of the verification result, increasing the cracking difficulty, and eliminating the need for an additional encryption chip, thereby improving the effectiveness of preventing the illegal appropriation and unauthorized use of software and reducing the hardware cost. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 It is a flowchart of a method for verifying the legitimacy of a device through software according to an embodiment of the present invention; Figure 2 It is a structure diagram of a hardware signature of a method for verifying the legitimacy of a device through software according to an embodiment of the present invention; Figure 3 It is a flowchart of generating controllable software of a method for verifying the legitimacy of a device through software according to an embodiment of the present invention; Figure 4 It is a flowchart of running controllable software of a method for verifying the legitimacy of a device through software according to an embodiment of the present invention; Figure 5Flowchart of a method for verifying device legality through software according to an embodiment of the present invention; Figure 6 Schematic structural diagram of a system for verifying device legality through software according to an embodiment of the present invention. Detailed implementation manner
[0010] To elaborate in detail on the technical content, achieved objectives and effects of the present invention, the following is described in conjunction with the implementation manners and accompanied by the drawings.
[0011] In the prior art, common methods for verifying device legality through software include serial number protection mechanisms, network verification, hardware encryption, etc. However, these methods have problems such as low security or high hardware costs.
[0012] To solve at least the above technical problems, the present disclosure provides a method for verifying device legality through software. According to the present disclosure, a controllable software is sent from a software source server to a device. The device decrypts an encrypted license feature code in a trusted execution environment to obtain a license feature code. The device reads a hardware feature code from a secure one-time programmable area and compares the hardware feature code with the license feature code. If they are inconsistent, the processing of the controllable software is stopped. If they are consistent, the device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device. In this way, the license binding of the software and the device hardware is achieved, and the trusted execution environment is added to the license verification process. The verification of the license feature code and the decryption of the encrypted software are implemented in the trusted execution environment, effectively preventing the tampering of the verification result, increasing the cracking difficulty, and at the same time eliminating the need for an additional encryption chip, thereby improving the effectiveness of preventing the illegal use and unauthorized use of software and reducing the hardware cost.
[0013] Hereinafter, the technical solutions according to the present disclosure will be described with reference to specific embodiments and in conjunction with the drawings.
[0014] Figure 1 It is a flowchart showing a method 100 for verifying device legality through software according to an embodiment of the present disclosure. Referring to Figure 1 , the method 100 includes the following steps 102 to 110.
[0015] In step 102, a controllable software is sent from a software source server to a device. The controllable software is generated based on the hardware feature code of the device and software encryption, and the controllable software includes an encrypted license feature code and encrypted software.
[0016] In some embodiments, the method 100 may further include: the hardware signature is burned in the secure one-time programming (OTP) area of the main control chip of the device, and the hardware signature includes a chip type signature, a chip subdivision signature, and a chip unique signature corresponding to different levels of controllable levels, wherein the encryption license signature is generated based on encrypting the license signature, and the license signature is generated based on the controllable level and the corresponding signature in the hardware signature.
[0017] In this way, the chip type signature represents a certain type of chip. If the chip type signature is specified for verification, the controllable software can only run properly on a specified type of chip. The chip subdivision signature represents a certain subdivision product type in a certain type of chip. If the chip subdivision signature is specified for verification, the controllable software can only run properly on the specified chip subdivision product type. The chip unique signature represents a certain chip in a certain subdivision product type of a certain type of chip. If the chip unique signature is specified for verification, the controllable software can only run properly on the specified single chip. The control range granularity of the signatures in the hardware signature is different, and different levels of software controllable levels can be achieved. Moreover, burning the hardware signature in the secure OTP of the device avoids leakage and improves the security of the device data.
[0018] In some embodiments, the method 100 may further include: generating a signature encryption key and a software encryption key using a message authentication code algorithm based on the hardware unique key (HUK) in the main control chip of the device; and burning the signature encryption key and the software encryption key into the secure one-time programming area.
[0019] In this way, the hardware unique key is unique. Generating the signature encryption key and the software encryption key based on the hardware unique key ensures that the keys in each chip are different.
[0020] In some embodiments, before step 102, the method 100 may further include: encrypting, by the device, the hardware signature, the signature encryption key, and the software encryption key using a public key, and sending the encrypted hardware signature, signature encryption key, and software encryption key to the software source server; decrypting, by the software source server, the encrypted hardware signature, signature encryption key, and software encryption key using a private key to obtain the hardware signature, signature encryption key, and software encryption key; determining, by the software source server, a controllable level, and extracting a target signature corresponding to the controllable level from the hardware signature; packaging, by the software source server, the target signature and the controllable level to generate a license signature, and encrypting the license signature using an encryption module based on the signature encryption key to obtain an encrypted license signature; and encrypting, by the software source server, the original software using the software encryption key to obtain the encrypted software, and generating a controllable software using a software obfuscation module according to the encrypted license signature, software encryption shell, and the encrypted software.
[0021] In this way, trusted communication is achieved between the device and the software source server through public and private keys. The device encrypts and transmits the hardware signature, signature encryption key, and software encryption key to the software source server, ensuring the security of data transmission. The software source server generates a controllable software based on the hardware signature, signature encryption key, and software encryption key, which can ensure that only legitimate devices can use the software.
[0022] In step 104, the device decrypts the encrypted license signature in a trusted execution environment to obtain the license signature.
[0023] In some embodiments, when running the controllable software, the device uses a shell program to send the encrypted license signature to the trusted execution environment (TEE) to decrypt the encrypted license signature using a trusted program in the trusted execution environment to obtain the license signature.
[0024] In this way, when the device runs the controllable software, it needs to decrypt the encrypted license signature in the trusted execution environment using a trusted program to obtain the license signature, avoiding the leakage of the license signature for subsequent device verification using the license signature.
[0025] In step 106, the device reads the hardware signature from the secure one-time programming area and compares the hardware signature with the license signature.
[0026] In some embodiments, a feature code to be compared is determined from the hardware feature code according to the controllable level in the permitted feature code, and the feature code to be compared is compared with the target feature code in the permitted feature code.
[0027] In this way, the feature code to be compared is determined according to the controllable level, and the feature code to be compared is compared with the target feature code in the permitted feature code, so that the legitimacy of the device can be effectively verified.
[0028] In step 108, if the comparison result is inconsistent, the processing of the controllable software in the trusted execution environment is stopped.
[0029] In this way, when the comparison result is inconsistent, it means that the device is an illegal device. At this time, the controllable software is stopped, which improves the effectiveness of preventing illegal theft of software and unauthorized use of software.
[0030] In step 110, if the comparison result is consistent, the device decrypts the encrypted software in the trusted execution environment to obtain a software plain text for running in the device.
[0031] In some embodiments, the device uses a shell program to send the encrypted software to the trusted execution environment, and the device uses the software encryption key in the trusted execution environment through a trusted program to decrypt the encrypted software to obtain software plaintext, and returns the software plaintext to the shell program.
[0032] In some embodiments, the method 100 may further include: the device using the shell program to run the software plain text.
[0033] In this way, when the device passes the verification, the device is allowed to run the software, ensuring the security of the software.
[0034] In some embodiments, the method 100 may further include: if the result of the comparison is inconsistent, determining the device as an illegal device; and if the result of the comparison is consistent, determining the device as a legal device.
[0035] Hereinafter, application scenarios of the method and system for verifying the legitimacy of a device through software and a storage medium according to an embodiment of the present invention will be described by way of examples.
[0036] Figure 2 is a diagram showing a hardware feature code structure of a method for verifying the legitimacy of a device through software according to an embodiment of the present invention. Figure 3 The invention is a flow chart showing the controllable software generation method of verifying the legitimacy of a device through software according to an embodiment of the present invention. Figure 4It is a controllable software operation flowchart showing a method for verifying device legality through software according to an embodiment of the present invention. Figure 5 It is a flowchart showing a method for verifying device legality through software according to an embodiment of the present invention. Refer to Figure 5 and this method includes the following steps 201 to step 213.
[0037] In step 201, a feature code encryption key and a software encryption key are generated using a message authentication code algorithm based on a hardware unique key in the main control chip of the device.
[0038] In some embodiments, a feature code encryption key and a software encryption key are generated using a message authentication code algorithm based on the hardware unique key in the main control chip of the device and different factors respectively.
[0039] In some embodiments, the different factors can be different string data or different numbers, etc. The message authentication code algorithm can be the HMAC-SHA256 algorithm.
[0040] In step 202, a hardware feature code, a feature code encryption key, and a software encryption key are burned into the secure OTP of the main control chip of the device. In this embodiment, refer to Figure 2 and the hardware feature code includes a chip type feature code, a chip subdivision feature code, and a chip unique feature code corresponding to different levels of controllable levels. The secure OTP can only be accessed in a trusted execution environment.
[0041] In step 203, a public key and a private key are generated using an asymmetric encryption algorithm, the public key is stored in the device, and the private key is stored in the software source server.
[0042] In step 204, the device encrypts the hardware feature code, the feature code encryption key, and the software encryption key using the public key and sends the encrypted hardware feature code, feature code encryption key, and software encryption key to the software source server.
[0043] In step 205, the software source server decrypts the encrypted hardware feature code, feature code encryption key, and software encryption key using the private key to obtain the hardware feature code, feature code encryption key, and software encryption key.
[0044] In step 206, the software source server determines the controllable level and extracts the target feature code corresponding to the controllable level from the hardware feature code.
[0045] For example, the controllable levels corresponding to the chip type feature code, the chip subdivision feature code, and the chip unique feature code are level one, level two, and level three respectively. Assume that the software source server determines the controllable level to be level one, then the chip type feature code is selected from the hardware feature code as the target feature code.
[0046] In step 207, the software source server packages the target feature code and the controllable level to generate a license feature code, and uses an encryption module to encrypt the license feature code based on the feature code encryption key to obtain an encrypted license feature code.
[0047] In step 208, the software source server encrypts the original software using the software encryption key to obtain encrypted software, and uses a software shelling module to generate controllable software based on the encrypted license feature code, the software encryption shell, and the encrypted software, refer to Figure 3 。
[0048] In some embodiments, the original software refers to the software that needs to be license-bound to the device, which can be a running program or a code library, etc.
[0049] In step 209, the software source server sends the controllable software to the device.
[0050] In step 210, when the device runs the controllable software, it decrypts the encrypted license feature code in the trusted execution environment to obtain the license feature code, refer to Figure 4 。
[0051] In some embodiments, when the device runs the controllable software, it uses a shell program to send the encrypted license feature code to the trusted execution environment, so as to use a trusted program to decrypt the encrypted license feature code in the trusted execution environment to obtain the license feature code.
[0052] In step 211, the device reads the hardware feature code from the secure OTP and compares the read hardware feature code with the license feature code.
[0053] In some embodiments, refer to Figure 4 According to the controllable level in the license feature code, the to-be-compared feature code is determined from the read hardware feature code, and the to-be-compared feature code is compared with the target feature code in the license feature code.
[0054] In step 212, if the comparison result is inconsistent, the device is determined to be an illegal device, and the processing of the controllable software is stopped in the trusted execution environment, refer to Figure 4 。
[0055] In step 213, if the comparison result is consistent, the device is determined to be a legal device. The device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device, and the device uses a shell program to run the software plaintext.
[0056] In some embodiments, refer to Figure 4, the device uses the shell program to send the encrypted software to the trusted execution environment. The device decrypts the encrypted software with the software encryption key in the trusted execution environment to obtain the software plaintext, returns the software plaintext to the shell program, and the device uses the shell program to run the software plaintext.
[0057] According to another aspect of the present invention, Figure 6 is a block diagram showing a system 300 for verifying the legitimacy of a device through software according to an embodiment of the present invention. Refer to Figure 6 , the system 300 for verifying the legitimacy of a device through software includes a software source server 302 and a device 304.
[0058] The software source server 302 is configured to generate a controllable software based on software encryption and the hardware signature of the device. The controllable software includes an encryption license signature and encrypted software.
[0059] The device 304 is coupled to the software source server 302. The device 304 is configured to receive the controllable software from the software source server and decrypt the encryption license signature in the trusted execution environment to obtain the license signature. The device 304 is configured to read the hardware signature from the secure one-time programmable area and compare the hardware signature with the license signature. The device 304 is configured to stop processing the controllable software in the trusted execution environment if the result of the comparison is inconsistent; and decrypt the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device if the result of the comparison is consistent.
[0060] It should be understood that the software source server 302 and the device 304 can be further configured to execute the respective corresponding steps or actions in the method described above, which will not be elaborated here.
[0061] According to still another aspect of the present invention, a computer-readable medium is provided. A computer program is stored on the computer-readable medium, and the computer program is executed by a processor to implement the method for verifying the legitimacy of a device through software as described above.
[0062] In summary, for the method, system, and storage medium for verifying the legality of a device through software provided by the present invention, a controllable software is sent from a software source server to the device. The device decrypts an encrypted license feature code in a trusted execution environment to obtain a license feature code, reads a hardware feature code from a secure one-time programmable area, and compares the hardware feature code with the license feature code. If they are inconsistent, the processing of the controllable software is stopped; if they are consistent, the device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device, thereby realizing the license binding between the software and the device hardware. In addition, the trusted execution environment is added to the license verification process, and the verification of the license feature code and the decryption of the encrypted software are implemented in the trusted execution environment, effectively preventing the tampering of the verification result, increasing the cracking difficulty, and at the same time eliminating the need for an additional encryption chip, thereby improving the effectiveness of preventing the illegal appropriation and unauthorized use of software and reducing the hardware cost. Moreover, the chip type feature code represents a certain type of chip. If the chip type feature code is specified for verification, the controllable software can only run properly on a specified type of chip. The chip sub-type feature code represents a certain sub-type product in a certain type of chip. If the chip sub-type feature code is specified for verification, the controllable software can only run properly on the specified chip sub-type product. The chip unique feature code represents a certain chip in a certain sub-type product in a certain type of chip. If the chip unique feature code is specified for verification, the controllable software can only run properly on the specified single chip. The control range granularity of the feature codes in the hardware feature code is different, enabling different levels of software controllability. Furthermore, the hardware feature code, the feature code encryption key, and the software encryption key are written in the secure OTP of the device to avoid leakage and improve the security of the device data.
[0063] The above are only embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent transformation made using the content of the specification and drawings of the present invention, or directly or indirectly applied in related technical fields, shall be similarly included in the patent protection scope of the present invention.
Claims
1. A method for verifying the legality of a device through software, characterized in that, Including: The software source server sends the controllable software to the device. The controllable software is generated based on the hardware fingerprint code and software encryption of the device, and the controllable software includes an encrypted license fingerprint code and encrypted software; The device decrypts the encrypted license fingerprint code in the trusted execution environment to obtain the license fingerprint code; The device reads the hardware fingerprint code from the secure one-time programming area and compares the hardware fingerprint code with the license fingerprint code; If the comparison result is inconsistent, the processing of the controllable software is stopped in the trusted execution environment; And If the comparison result is consistent, the device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device.
2. The method according to claim 1, wherein It also includes: The hardware fingerprint code is programmed in the secure one-time programming area of the main control chip of the device. The hardware fingerprint code includes a chip type fingerprint code, a chip detailed fingerprint code, and a chip unique fingerprint code corresponding to different levels of controllable levels, wherein the encrypted license fingerprint code is generated by encrypting the license fingerprint code, and the license fingerprint code is generated based on the controllable level and the corresponding fingerprint code in the hardware fingerprint code.
3. The method according to claim 2, wherein It also includes: Generating a fingerprint code encryption key and a software encryption key based on the hardware unique key in the main control chip of the device using a message authentication code algorithm; And Programming the fingerprint code encryption key and the software encryption key into the secure one-time programming area.
4. The method according to claim 3, wherein Before the software source server sends the controllable software to the device, it also includes: The device encrypts the hardware fingerprint code, the fingerprint code encryption key, and the software encryption key using the public key and sends the encrypted hardware fingerprint code, fingerprint code encryption key, and software encryption key to the software source server; The software source server decrypts the encrypted hardware fingerprint code, fingerprint code encryption key, and software encryption key using the private key to obtain the hardware fingerprint code, fingerprint code encryption key, and software encryption key; The software source server determines the controllable level and extracts the target fingerprint code corresponding to the controllable level from the hardware fingerprint code; The software source server packages the target fingerprint code and the controllable level to generate a license fingerprint code, and encrypts the license fingerprint code using an encryption module based on the fingerprint code encryption key to obtain an encrypted license fingerprint code; and The software source server encrypts the original software using the software encryption key to obtain the encrypted software, and uses a software obfuscation module to generate the controllable software according to the encrypted license fingerprint code, software encryption shell, and the encrypted software.
5. The method according to claim 1, characterized in that, The device decrypting the encrypted license fingerprint code in the trusted execution environment to obtain the license fingerprint code includes: When running the controllable software, the device uses a shell program to send the encrypted license fingerprint code to the trusted execution environment, so as to decrypt the encrypted license fingerprint code using a trusted program in the trusted execution environment to obtain the license fingerprint code.
6. The method according to claim 4, wherein Comparing the hardware feature code with the license feature code includes: Determining a feature code to be compared from the hardware feature code according to the controllable level in the license feature code, and comparing the feature code to be compared with the target feature code in the license feature code.
7. The method according to claim 2, wherein The device decrypts the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device, including: The device uses a shell program to send the encrypted software to the trusted execution environment; and The device decrypts the encrypted software with the software encryption key through a trusted program in the trusted execution environment to obtain the software plaintext, and returns the software plaintext to the shell program.
8. The method according to claim 7, wherein It further includes: The device uses the shell program to run the software plaintext.
9. The method according to claim 1, characterized in that, It further includes: If the result of the comparison is inconsistent, the device is determined to be an illegal device; and If the result of the comparison is consistent, the device is determined to be a legal device.
10. A system for verifying the legality of a device through software, characterized in that, It includes: A software source server configured to generate a controllable software based on software encryption and the hardware feature code of the device, the controllable software including an encrypted license feature code and encrypted software; and A device coupled to the software source server and configured to: Receive the controllable software from the software source server and decrypt the encrypted license feature code in the trusted execution environment to obtain the license feature code; Read the hardware feature code from the secure one-time programming area and compare the hardware feature code with the license feature code; If the result of the comparison is inconsistent, stop processing the controllable software in the trusted execution environment; and If the result of the comparison is consistent, decrypt the encrypted software in the trusted execution environment to obtain the software plaintext for running on the device.
11. A computer-readable medium having a computer program stored thereon, characterized in that, The computer program is executed to implement the method according to any one of claims 1 to 9.