Method, device and product for protecting intellectual property based on DBUS

By using the SM4 and SM2 encryption algorithms in DBUS communication and combining them with JSON formatted communication, the problems of unauthorized copying and communication efficiency in edge device intellectual property protection are solved, achieving secure and stable intellectual property protection and efficient communication.

CN120639459APending Publication Date: 2025-09-12GUANGXI PUBLIC INFORMATION IND CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510984190.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing DBUS applications have the risk of unauthorized copying and duplication in terms of intellectual property protection, and the security policy cannot meet customized authentication requirements and cannot encrypt data on demand, affecting communication efficiency.

Method used

It adopts SM4 symmetric encryption algorithm and SM2 asymmetric encryption algorithm, solidifies the key on the server and client, uses JSON data format for communication, and combines DBUS protocol for authentication and data encryption and decryption to ensure communication security and efficiency.

Benefits of technology

It achieves the security protection of edge device intellectual property rights, prevents unauthorized copying, meets customized authentication requirements, and improves communication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639459A_ABST
    Figure CN120639459A_ABST
Patent Text Reader

Abstract

The invention discloses a method, a device and a product for protecting intellectual property based on a DBUS. Comprising a server and a client. The server comprises a component registration module, an event monitoring module, an authentication module, a data decryption module and a request callback module; and the client comprises a ciphertext loading module, a data encryption module and a communication control module. The authentication module analyzes a token field of a JSON data structure of the communication request to extract encrypted authentication information, and if a piece of decrypted data of which the MAC address is matched with the MAC address of the current service equipment is extracted, it is proved that the communication request comes from a credit granted client, and data decryption operation continues; if the data are not matched, the authentication is not passed, error information is returned, and the communication request is interrupted. According to the invention, the DBUS is used as a service providing carrier, so that the service is safer and more stable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of communication data encryption protection, and specifically relates to a method, device and product for protecting intellectual property rights based on DBUS. Background Art

[0002] With the continuous development of artificial intelligence technology and the increasing complexity of enterprise applications, the number of applications on edge devices is experiencing explosive growth. These devices are located at the edge of the network, close to the source of data generation and use, rather than relying on the cloud or data center for data processing and analysis. This enables faster response times, greater data privacy protection, and more efficient resource utilization. Executable programs (carriers of intellectual property) within edge devices are at risk of unauthorized malicious copying and dissemination, potentially through copying the executable program or the entire storage chip data. Therefore, for manufacturers, effectively protecting the intellectual property within edge devices is of paramount importance.

[0003] In addition, existing DBUS applications are usually used for simple plaintext / ciphertext inter-process communication and are rarely used for intellectual property protection. At the same time, in existing DBUS applications, security policies rely on the local configuration of the daemon process, but cannot guarantee the risk of related configurations being copied or replicated after private deployment, and cannot meet customized authentication requirements. Data cannot be encrypted on demand, and if the amount of encrypted data is too large, it may affect communication efficiency. Summary of the Invention

[0004] The purpose of the present invention is to address the deficiencies in the prior art and to provide a method, device and product for protecting intellectual property rights based on DBUS.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions: A method for protecting intellectual property rights based on DBUS, comprising the following steps: (1) When the service is initialized and started on the server side, it first completes access to the "session bus", registers the service name, registers the service object path and registers the service interface according to the DBUS communication protocol. After that, the server side enters the message monitoring mode and receives and distributes the communication requests from the client in real time. (2) The server continuously receives various communication requests in a loop, and traverses and enumerates each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it starts authentication; if it does not match, it returns an error message and terminates the communication request; (3) The server parses the "token" field of the JSON data structure of the communication request and extracts the encrypted authentication information. If the decrypted MAC address extracted matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues with step (4). If the data does not match, the authentication fails, an error message is returned, and the request is terminated. (4) The server parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; (5) After the interface / method completes the business process, the original data output by the interface / method is encapsulated and serialized, and then returned to the client through callback.

[0006] The JSON data structure is as follows:

[0007] The present invention further illustrates that in step (5), encapsulating the original data output by the interface / method is specifically as follows: first, the "encrypt_output" field of the JSON data structure of the communication request is parsed; if the field is "true", the original data is SM4 encrypted and then encapsulated; otherwise, the original data is used for encapsulation.

[0008] The present invention further illustrates that during the communication process between the client and the server, data encryption and decryption use SM4 symmetric encryption, and the encryption and decryption keys are solidified in the applications of the server and the client and do not change with changes in the application scenario.

[0009] The present invention further illustrates that the method for protecting intellectual property rights based on DBUS further includes: (11) When the client is initialized, it must first load the ciphertext to provide a basis for subsequent communication authentication between the client and the server; after the client loads the ciphertext, it uses the SM2 public key solidified in the client to complete the ciphertext decryption and ciphertext loading and initialization; (12) When a user calls a service exposed by a service, the data is automatically encrypted according to the parameters input by the user. That is, the original ciphertext is first decrypted to obtain the MAC address, and the authentication key is generated using SM4 encryption. If the user needs to encrypt the input data, the encryption process will also be completed using the SM4 algorithm. (13) According to the user interface call request, the JSON data formatting process is automatically completed, including the filling of the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

[0010] The present invention further illustrates that in step (11), the ciphertext is a one-machine-one-code generated by the SM2 asymmetric encryption algorithm using the MAC address of the server and the private key of SM2 when the product delivery is completed.

[0011] The present invention also provides a device for protecting intellectual property rights based on DBUS, comprising a server and a client; the server comprises a component registration module, an event monitoring module, an authentication module, a data decryption module, and a request callback module; The component registration module is used to complete access to the "session bus", register the service name, register the service object path and register the service interface according to the DBUS communication protocol; The event monitoring module is used to continuously receive various communication requests in a loop, traverse and enumerate each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it will be transferred to the authentication module for authentication; if it does not match, it will return an error message and terminate the communication request; The authentication module is used to parse the "token" field of the JSON data structure of the communication request and extract the encrypted authentication information. If a decrypted MAC address is found that matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues the data decryption operation. If the data does not match, the authentication fails, an error message is returned, and the communication request is terminated. The data decryption module parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; The request callback module is used to encapsulate and serialize the original data output by the interface / method, and return it to the client through callback.

[0012] The DBUS bus is divided into a "system bus" and a "session bus". The "system bus" is controlled by the operating system and mainly performs communication at the operating system level, strictly controlling access rights. The use of the "session bus" in this invention has met basic usage requirements.

[0013] The service name ensures that no other service with the same name exists on the same bus. Other applications can also use the name to find and connect to the service. This is the basis for providing services externally and for client access, for example, com.gxxc.ai.service.

[0014] The service object is uniquely identified by the object path, which serves as an abstract carrier of the internal functional unit of the service and is used to specify the specific object, such as / com / gxxc / ai / service.

[0015] The service interface defines the specific methods and signals provided by the service, declares the operations supported by the service, and ensures consistent interaction between the client and the server. For example, under com.gxxc.ai.service.face, this interface may contain methods such as recog and detect, which are bound to specific service functions.

[0016] The present invention further illustrates that the client includes a ciphertext loading module, a data encryption module, and a communication control module; The ciphertext loading module is used to load ciphertext and use the SM2 public key solidified in the client to complete ciphertext decryption and ciphertext loading and initialization; The data encryption module is used to automatically encrypt data based on the parameters entered by the user when the user calls the service exposed by the service. That is, it first decrypts the original ciphertext to obtain the MAC address and uses SM4 encryption to generate the authentication key. If the user needs to encrypt the input data, it will also be encrypted using the SM4 algorithm. The communication control module is used to automatically complete the formatting of JSON data according to the user interface call request, including the filling of the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

[0017] The JSON data structure is as follows:

[0018] The communication control module is also bound to the callback interface called by each interface, which is used to receive the processing results returned by the server and process the response data in an asynchronous manner to improve communication efficiency.

[0019] The present invention also provides a product for protecting intellectual property rights based on DBUS, including an edge device equipped with the above-mentioned device for protecting intellectual property rights based on DBUS.

[0020] DBUS: An inter-process communication (IPC) mechanism for Linux and Unix systems. Its core goal is to achieve efficient interaction between different processes, services, and even the kernel and user space through a bus architecture.

[0021] MAC: Ethernet address, hardware address, physical address, an address used to identify the location of a network device. A MAC address uniquely identifies a network card on a network. If a device has one or more network cards, each card requires and has a unique MAC address.

[0022] SM4: Released by the China National Cryptography Administration in 2012, it is the core symmetric encryption standard in my country's commercial cryptographic system. It is a block-symmetric encryption algorithm that uses the same key for encryption and decryption. The key length and block length are both 128 bits, making it suitable for protecting data confidentiality.

[0023] SM2: It is an asymmetric encryption algorithm standard independently developed by China. It is a core component of the national secret algorithm system. It adopts the architecture of public key encryption, private key decryption, or private key signature, public key verification, and uses a specific 256-bit prime field elliptic curve equation. The key length is short but the security is high.

[0024] JSON: JSON (JavaScript Object Notation) is a lightweight data exchange format. Based on a subset of ECMAScript (the European Computer Manufacturers Association's JS specification), it uses a text format that is completely independent of programming languages ​​to store and represent data. Its simplicity and clear hierarchical structure make JSON an ideal data exchange language. It is easy for humans to read and write, as well as for machines to parse and generate data, significantly improving network transmission efficiency.

[0025] Advantages of the present invention: 1. The present invention uses DBUS as a service provider, which makes the service more secure and stable.

[0026] 2. The present invention uses a formatted data format, avoids the use of a binary protocol, and facilitates subsequent function expansion.

[0027] 3. The client of the present invention is provided in the form of a dynamic library, hiding the encryption and decryption details.

[0028] 4. Intellectual Property Protection: A one-machine, one-code mechanism is adopted to prevent the use of multiple machines with a single machine being authorized. Communication Efficiency: User input / output data is encrypted on demand to improve communication efficiency. Confidentiality: Keys are embedded in the program binary to reduce the risk of key leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 It is the overall interaction sequence diagram of the method of the present invention; Figure 2 This is the client flow chart of the present invention; Figure 3 This is the service-side flow chart of the present invention; Figure 4 Schematic diagram of the system framework of the device of the present invention. DETAILED DESCRIPTION

[0030] The present invention will be further described below with reference to the accompanying drawings.

[0031] Example: A method for protecting intellectual property rights based on DBUS, such as Figure 1 and Figure 3 As shown, the following steps are included: (1) When the service is initialized and started on the server side, it first completes access to the "session bus", registers the service name, registers the service object path and registers the service interface according to the DBUS communication protocol. After that, the server side enters the message monitoring mode and receives and distributes the communication requests from the client in real time. (2) The server continuously receives various communication requests in a loop, and traverses and enumerates each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it starts authentication; if it does not match, it returns an error message and terminates the communication request; (3) The server parses the "token" field of the JSON data structure of the communication request and extracts the encrypted authentication information. If the decrypted MAC address extracted matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues with step (4). If the data does not match, the authentication fails, an error message is returned, and the request is terminated. (4) The server parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; (5) After the interface / method completes the business process, the original data output by the interface / method is encapsulated and serialized, and then returned to the client through callback.

[0032] In step (5), the original data output by the interface / method is encapsulated as follows: first parse the "encrypt_output" field of the JSON data structure of the communication request. If the field is "true", the original data is SM4 encrypted and then encapsulated. Otherwise, the original data is used for encapsulation.

[0033] During the communication between the client and the server, data is encrypted and decrypted using SM4 symmetric encryption, and the encryption and decryption keys are solidified in the applications of the server and the client and do not change with changes in the application scenario.

[0034] The method for protecting intellectual property rights based on DBUS is as follows: Figure 2 As shown, it also includes: (11) When the client is initialized, it must first load the ciphertext to provide a basis for subsequent communication authentication between the client and the server; after the client loads the ciphertext, it uses the SM2 public key solidified in the client to complete the ciphertext decryption and ciphertext loading and initialization; (12) When a user calls a service exposed by a service, the data is automatically encrypted according to the parameters input by the user. That is, the original ciphertext is first decrypted to obtain the MAC address, and the authentication key is generated using SM4 encryption. If the user needs to encrypt the input data, the encryption process will also be completed using the SM4 algorithm. (13) According to the user interface call request, the JSON data formatting process is automatically completed, including the filling of the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

[0035] In step (11), the ciphertext is a one-machine-one-code generated by the SM2 asymmetric encryption algorithm using the server's MAC address and SM2's private key when the product is delivered.

[0036] A device for protecting intellectual property rights based on DBUS is used to implement the above method, such as Figure 4 As shown, it includes a server and a client; the server includes a component registration module, an event monitoring module, an authentication module, a data decryption module, and a request callback module; The component registration module is used to complete access to the "session bus", register the service name, register the service object path and register the service interface according to the DBUS communication protocol; The event monitoring module is used to continuously receive various communication requests in a loop, traverse and enumerate each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it will be transferred to the authentication module for authentication; if it does not match, it will return an error message and terminate the communication request; The authentication module is used to parse the "token" field of the JSON data structure of the communication request and extract the encrypted authentication information. If a decrypted MAC address is found that matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues the data decryption operation. If the data does not match, the authentication fails, an error message is returned, and the communication request is terminated. The data decryption module parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; The request callback module is used to encapsulate and serialize the original data output by the interface / method, and return it to the client through callback.

[0037] The client includes a ciphertext loading module, a data encryption module, and a communication control module; The ciphertext loading module is used to load ciphertext and use the SM2 public key solidified in the client to complete ciphertext decryption and ciphertext loading and initialization; The data encryption module is used to automatically encrypt data based on the parameters entered by the user when the user calls the service exposed by the service. That is, it first decrypts the original ciphertext to obtain the MAC address and uses SM4 encryption to generate the authentication key. If the user needs to encrypt the input data, it will also be encrypted using the SM4 algorithm. The communication control module is used to automatically complete the formatting of JSON data according to the user interface call request, including the filling of the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

[0038] A product for protecting intellectual property rights based on DBUS includes an edge device equipped with the above-mentioned device.

[0039] Obviously, the above embodiments are merely examples for the purpose of clearly illustrating the present invention and are not intended to limit the implementation of the present invention. Those skilled in the art will readily appreciate that other variations or modifications may be made based on the above description. It is not necessary and impossible to enumerate all possible implementations here. Obvious variations or modifications derived therefrom remain within the scope of protection of the present invention.

Claims

1. A method for protecting intellectual property rights based on DBUS, characterized in that The following steps are involved: (1) When the service is initialized and started on the server side, it first completes the access to the "session bus", registers the service name, registers the service object path and registers the service interface according to the DBUS communication protocol. After that, the server enters the message monitoring mode and receives and distributes the communication requests from the client in real time; (2) The server continuously receives various communication requests in a loop, and traverses and enumerates each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it starts authentication; if it does not match, it returns an error message and terminates the communication request; (3) The server parses the "token" field of the JSON data structure of the communication request and extracts the encrypted authentication information. If the decrypted MAC address extracted matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues with step (4). If the data does not match, the authentication fails, an error message is returned, and the request is terminated. (4) The server parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; (5) After the interface / method completes the business process, the original data output by the interface / method is encapsulated and serialized, and then returned to the client through callback.

2. The method for protecting intellectual property rights based on DBUS according to claim 1, characterized in that: In step (5), the original data output by the interface / method is encapsulated as follows: first parse the "encrypt_output" field of the JSON data structure of the communication request. If the field is "true", the original data is SM4 encrypted and then encapsulated. Otherwise, the original data is used for encapsulation.

3. The method for protecting intellectual property rights based on DBUS according to claim 1, characterized in that: During the communication between the client and the server, data is encrypted and decrypted using SM4 symmetric encryption, and the encryption and decryption keys are solidified in the applications of the server and the client and do not change with changes in the application scenario.

4. The method for protecting intellectual property rights based on DBUS according to claim 1, characterized in that: Also includes: (11) When the client is initialized, it must first load the ciphertext to provide a basis for subsequent communication authentication between the client and the server; After the client loads the ciphertext, it uses the SM2 public key stored in the client to decrypt the ciphertext and load and initialize the ciphertext. (12) When a user calls a service exposed by a service, the data is automatically encrypted according to the parameters input by the user. That is, the original ciphertext is first decrypted to obtain the MAC address, and the authentication key is generated using SM4 encryption. If the user needs to encrypt the input data, the encryption process will also be completed using the SM4 algorithm. (13) According to the user interface call request, the JSON data formatting process is automatically completed, including the filling of the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

5. The method for protecting intellectual property rights based on DBUS according to claim 4, characterized in that: In step (11), the ciphertext is a one-machine-one-code generated by the SM2 asymmetric encryption algorithm using the server's MAC address and SM2's private key when the product is delivered.

6. A device for protecting intellectual property rights based on DBUS, comprising a server and a client; characterized in that: The server includes a component registration module, an event monitoring module, an authentication module, a data decryption module, and a request callback module; The component registration module is used to complete the access to the "session bus", register the service name, register the service object path and register the service interface according to the DBUS communication protocol; The event monitoring module is used to continuously receive various communication requests in a loop, traverse and enumerate each communication request to see if it matches the interface / method exported by the current service registration. If it matches, it will be transferred to the authentication module for authentication; if it does not match, it will return an error message and terminate the communication request; The authentication module is used to parse the "token" field of the JSON data structure of the communication request and extract the encrypted authentication information. If the decrypted MAC address extracted matches the MAC address of the current service device, it proves that the communication request comes from a trusted client and continues the data decryption operation; if the data does not match, the authentication fails, an error message is returned, and the communication request is terminated; The data decryption module parses the "encrypt_input" field of the JSON data structure of the communication request. If the field is "true", the data in the "user_data" field of the JSON data structure is decrypted by SM4. Otherwise, the "user_data" field is extracted as input data to complete the subsequent specified interface / method business process call; The request callback module is used to encapsulate and serialize the original data output by the interface / method, and return it to the client through callback.

7. The device for protecting intellectual property rights based on DBUS according to claim 6, characterized in that: The client includes a ciphertext loading module, a data encryption module, and a communication control module; The ciphertext loading module is used to load ciphertext and use the SM2 public key solidified in the client to complete ciphertext decryption and ciphertext loading and initialization; The data encryption module is used to automatically encrypt data based on the parameters entered by the user when the user calls the service exposed by the service. That is, it first decrypts the original ciphertext to obtain the MAC address and uses SM4 encryption to generate the authentication key. If the user needs to encrypt the input data, it will also be encrypted using the SM4 algorithm. The communication control module is used to automatically complete the formatting of JSON data according to the user interface call request, including filling in the "service name", "service object path", "service interface" and "method" parameters in the DBUS interactive communication interface.

8. A product based on DBUS to protect intellectual property rights, characterized by: The invention comprises an edge device equipped with the apparatus according to claim 2.