Software authorization method, electronic equipment and computer readable storage medium
By generating public and private key strings in the robot and doubly encrypting the software pre-installed information, the problems of software stability and adaptability in the new environment are solved, and safe and efficient software authorization and use are achieved to adapt to the needs of different user environments.
Patent Information
- Application Number
- CN202511189202.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-10-10
AI Technical Summary
In existing technologies, customized software services are directly pre-installed into the robot body or control cabinet, resulting in the inability to guarantee the stability and adaptability of the software in the new environment, and putting the customer's usage rights and interests at risk.
Generate public and private key strings through the hosting server, encrypt the software pre-installation information containing software and hardware parameters twice, generate target encrypted pre-installation information, and use the target encrypted pre-installation information to generate the target key string. The user verifies the key string after unpacking to ensure that only software that matches the robot hardware is authorized for use.
It improves the security, flexibility and ease of use of the software authorization process, ensures that the software is used within the scope of legal authorization, prevents illegal copying and use, and adapts to the needs of different user environments, especially environments with limited network connectivity.
Smart Images

Figure CN120768670A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of robot application technology, and in particular to a software authorization method, an electronic device, and a computer-readable storage medium. Background Art
[0002] With the rapid development of robotics technology, customers' personalized demand for robotics software services is increasing. How to ensure the safe and stable operation of robots and their control systems, and ensure that the boundaries of software use are not illegally breached, and safeguard customers' usage rights and interests have become the key.
[0003] Currently, customized software services are typically pre-installed directly into the robot body or control cabinet to increase application breadth and operational efficiency. However, while this direct pre-installation approach meets customer customization needs to a certain extent, it has significant drawbacks. For example, when customized software services are repurposed, the software's stability and adaptability in the new environment cannot be guaranteed, putting the customer's rights and interests at risk. Therefore, it is crucial to ensure the safe and efficient use of software services while meeting customer customization needs. Summary of the Invention
[0004] The purpose of this application is to address the deficiencies in the above-mentioned prior art and provide a software authorization method, electronic device and computer-readable storage medium to solve the problem of how to ensure the safe and efficient use of software services while ensuring customer customization needs.
[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows: In a first aspect, an embodiment of the present application provides a software authorization method, the method comprising: Obtaining software pre-installation information of the target software in the robot, and generating a public-private key string based on the software pre-installation information using an asymmetric encryption algorithm, wherein the software pre-installation information includes at least software application boundaries, software usage permission information, and robot hardware parameters, and the public-private key string includes a public key and a private key, and the private key is stored in the system file of the robot; Performing secondary encryption on the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain target encrypted pre-installed information; generating a target key string according to the target encrypted preinstalled information and the public key, and providing the target key string to the user; Obtaining a key string to be verified input by a user, and obtaining the private key and the software pre-installation information stored in the system file of the robot; Decrypting the key string to be verified based on the private key to obtain the software information to be verified; The software information to be verified is compared with the software pre-installed information. If the comparison is successful, the user is allowed to use the target software.
[0006] As a possible implementation, the second encryption of the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain the target encrypted pre-installed information includes: Generating a symmetric session key using the symmetric encryption algorithm, encrypting usage scope data using the symmetric session key to obtain encrypted usage scope data, and storing the symmetric session key in a system file of the robot, wherein the usage scope data includes the software application boundary and the software usage permission information; The encrypted usage scope data is re-encrypted using the public key to obtain the target encrypted pre-installed information.
[0007] As a possible implementation manner, generating a target key string according to the target encrypted preinstalled information and the public key includes: The target encrypted preinstalled information and a preset character string are concatenated into the target key string.
[0008] As a possible implementation manner, decrypting the key string to be verified based on the private key to obtain the software information to be verified includes: Obtaining the preset character string and the symmetric session key; Eliminating the preset character string from the key string to be verified to obtain a character string to be decrypted; Decrypting the character string to be decrypted based on the private key to obtain a decrypted character string; The decrypted character string is decrypted based on the symmetric session key to obtain the software information to be verified.
[0009] As a possible implementation, removing the preset character string from the key string to be verified to obtain the character string to be decrypted includes: Determine the position and length of the preset character string in the key string to be verified according to the preset order during encryption; According to the position and length, the preset character string is removed from the key string to be verified to obtain the character string to be decrypted.
[0010] As a possible implementation manner, comparing the to-be-verified software information with the pre-installed software information and allowing the user to use the target software if the comparison is successful includes: Obtaining first software application boundary and first software usage permission information in the software information to be verified; Obtaining the second software application boundary and the second software usage permission information in the software preinstallation information; According to the first software application boundary, the first software usage permission information, the second software application boundary and the second software usage permission information, it is determined whether the comparison is successful. If the comparison is successful, the user is allowed to use the target software.
[0011] As a possible implementation, determining whether the comparison is successful based on the first software application boundary, the first software usage permission information, the second software application boundary, and the second software usage permission information, and if the comparison is successful, allowing the user to use the target software, includes: If the first software application boundary and the second software application boundary are the same, and the first software usage permission information and the second software usage permission information are the same, then it is determined that the comparison is successful, and the user is allowed to use the target software.
[0012] As a possible implementation manner, after comparing the to-be-verified software information with the pre-installed software information, the method further includes: If the comparison fails, a prompt message is output to the user, and the prompt message at least includes the reason for the comparison failure.
[0013] In a second aspect, an embodiment of the present application provides an electronic device, which is a robot or a server, and includes: a processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the storage medium communicate through the bus, and the processor executes the machine-readable instructions to perform the steps of the software authorization method as described in any one of the first aspects above.
[0014] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the software authorization method as described in any one of the first aspects above are executed.
[0015] According to the software authorization method, electronic device, and computer-readable storage medium of the embodiments of the present application, the robot is pre-installed with software selected by the user when it leaves the factory, and uses an asymmetric encryption algorithm to generate a public-private key string based on the software pre-installation information containing the software application boundary, usage permissions, and hardware parameters. The private key is stored in the system file, and the public key is used to double-encrypt the software pre-installation information encrypted by the symmetric encryption algorithm to form the target encrypted pre-installation information, and based on this, a target key string is generated and provided to the user. After unpacking, the user enters the key string to be verified and uses the private key stored inside the robot to decrypt the key string to obtain the software information to be verified. By comparing the decrypted software information to be verified with the pre-stored software pre-installation information, if the comparison is successful, the user is authorized to use the target software. According to the embodiments of the present application, the public-private key string is generated by the hosted server, and the software pre-installation information containing both software and hardware parameters is encrypted twice, ensuring the encryption security of the key string itself and the security of the software pre-installation information, thereby reducing the risk of key leakage. Even if the robot is physically obtained, it is difficult to decrypt the valid software pre-installation information. And because the software pre-installation information covers the software and hardware parameters, it not only improves the breadth of the encrypted content, but also through the encryption and verification process, it can ensure that only software that matches the robot hardware can be authorized for use, preventing instability or failures caused by software and hardware incompatibility. Moreover, the double confidentiality of the software pre-installation information and the target key string generated based on it provide an additional layer of protection barrier for software copyright, which helps to prevent illegal copying and use, and ensure that software use is within the scope of legal authorization. In addition, the present application supports differentiated use in offline and online scenarios to adapt to the needs of different user environments, and is also friendly to environments with limited network connections. Therefore, the software authorization method provided in the embodiment of the present application significantly improves the security, flexibility and ease of use of the software authorization process by introducing a hosting server, double-layer encryption technology and differentiated usage scenario support, better meets customer customization needs, and promotes the safe and efficient use of software services. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0017] Figure 1 A flowchart of a software authorization method provided in an embodiment of the present application is shown; Figure 2 A schematic diagram of a process for determining target encrypted pre-installed information provided by an embodiment of the present application is shown; Figure 3 A flow chart of a method for determining software information to be verified provided in an embodiment of the present application is shown; Figure 4 A flowchart of a software authorization method in an offline scenario provided by an embodiment of the present application is shown; Figure 5 A flowchart of a software authorization method in an online scenario provided by an embodiment of the present application is shown; Figure 6 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of illustration and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowcharts can be implemented out of sequence, and steps without logical context can be reversed or implemented simultaneously. In addition, those skilled in the art, under the guidance of the contents of this application, can add one or more other operations to the flowchart, or remove one or more operations from the flowchart.
[0019] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application generally described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application.
[0020] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.
[0021] Existing customized software services are pre-installed directly into the robot body or control cabinet. If the software services are re-used through other channels, their stability and environmental adaptability cannot be guaranteed. Therefore, it is crucial to ensure that customized software services can be used safely, efficiently and conveniently by customers under the premise of polymorphic applications, and to effectively control the software content when the robot body or control cabinet deviates from the predetermined software and hardware scenarios to protect the user's rights and interests.
[0022] In response to the above problems, an embodiment of the present application provides a software authorization method. After the robot is produced and shipped, the software is pre-installed according to the user's selection. For differentiated use in offline or online scenarios, a public and private key string is generated based on the software pre-installation information through a hosted server. While ensuring the encryption security of the key string itself, the software pre-installation information containing software and hardware parameters is encrypted twice to obtain the target encrypted pre-installation information, and the target encrypted pre-installation information is used to generate a target key string. After unpacking, the user can verify the key string, that is, decrypt the key string to be verified input by the user to obtain the software information to be verified, and compare the software information to be verified with the software pre-installation information stored in the system file of the robot, so as to determine whether the user is allowed to use the target software based on the comparison result. In other words, this application significantly improves the security, flexibility and ease of use of the software authorization process by introducing a hosted server, double-layer encryption technology and differentiated use scenario support, better meets customer customization needs, and promotes the safe and efficient use of software services.
[0023] Figure 1 The flowchart of a software authorization method provided by an embodiment of the present application is shown. The execution subject of the method is an electronic device, which can be a server or a robot. Figure 1 As shown, the method specifically includes the following steps: S101. Obtain software pre-installation information of the target software in the robot, and generate a public-private key string using an asymmetric encryption algorithm based on the software pre-installation information.
[0024] Optionally, after the robot leaves the factory, the target software selected by the customer is pre-installed. After the pre-installation is complete, the hosted server can obtain the software pre-installation information of the target software in the robot. The software pre-installation information includes at least software application boundaries, software usage permission information, and robot hardware parameters. Among them, the software application boundary refers to the installation location of the application in the robot system, its runtime behavior restrictions, and the interaction method with other components or services. The software usage permission information refers to the application's access rights to hardware resources and operating system functions. The robot hardware parameters refer to the physical properties of the robot, such as processor type, memory size, storage capacity, device address (Media Access Control Address, MAC), serial number or other unique identifiers.
[0025] Optionally, the asymmetric encryption algorithm may be, for example, the Rivest-Shamir-Adleman (RSA) asymmetric encryption algorithm. After obtaining the software pre-installation information of the target software in the robot, the server may use the RSA asymmetric encryption algorithm to generate a public-private key string based on the software pre-installation information. The public-private key string includes a public key and a private key. The private key may be stored in the robot's system files to ensure that only authorized processes can access it, while the public key can be securely distributed to other parties that need to communicate with the robot. Specifically, in the process of using the RSA asymmetric encryption algorithm to generate the public-private key string, the server may combine the collected software pre-installation information into a string or other form of data result, generate a unique identifier through a hash algorithm such as SHA-256, and select the RSA asymmetric encryption algorithm. The unique identifier generated above is used as an input parameter in the process of generating the public-private key string to generate a public key and a private key.
[0026] S102: re-encrypt the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain target encrypted pre-installed information.
[0027] Optionally, in this application, the software pre-installation information is initially encrypted using a symmetric encryption algorithm, and then the initially encrypted software pre-installation information is re-encrypted using a public key. This means that the software pre-installation information is hybrid encrypted using a combination of symmetric and asymmetric encryption algorithms. The symmetric encryption algorithm, for example, can be the Advanced Encryption Standard (AES) symmetric encryption algorithm. A symmetric session key is randomly generated based on the AES symmetric encryption algorithm. This symmetric session key can be used to encrypt and decrypt the software pre-installation information. Based on this, the generated symmetric session key and the selected symmetric encryption algorithm are used to encrypt the software pre-installation information twice to obtain the target encrypted pre-installation information.
[0028] Optionally, the target encrypted pre-installation information can be a simple concatenation of the symmetrically encrypted software pre-installation information and the public key encrypted symmetric session key, or a combination thereof in a specific format. In other words, the target encrypted pre-installation information contains both the encrypted software pre-installation information and the symmetric session key used to decrypt the software pre-installation information. However, the symmetric session key itself is also encrypted. Specifically, the generated symmetric session key is encrypted using the public key. This ensures that even if the target encrypted pre-installation information is intercepted, the symmetric session key cannot be decrypted without the corresponding private key, thereby protecting the original software pre-installation information.
[0029] S103: Generate a target key string according to the target encrypted pre-installed information and the public key, and provide the target key string to the user.
[0030] Optionally, the target encrypted pre-installed information and the public key can be simply combined, or combined with a preset string or a preset combination format to generate the target key string. Furthermore, to ensure the security of the target key string during transmission and prevent it from being intercepted or tampered with by unauthorized users, a secure communication protocol, such as HTTPS, SSL / TLS, or other communication protocols, can be used to transmit the target key string to the user. Furthermore, before providing the target key string to the user, user identity verification can be performed to ensure that only legitimate users can obtain the target key string. Specifically, user identity verification can be achieved using methods such as username and password and biometrics.
[0031] S104: Obtain the key string to be verified input by the user, and obtain the private key and software pre-installation information stored in the system file of the robot.
[0032] Optionally, the key string to be verified is used to verify whether the user has the right to use the target software. The server can receive the key string to be verified input by the user based on an interface, such as an API interface, a command line, or an App graphical user interface, and read the private key from the robot's system files to ensure that only authorized processes can access sensitive files in the robot's system files. Similarly, the software pre-installation information is read from the robot's system files.
[0033] S105 : Decrypt the key string to be verified based on the private key to obtain the software information to be verified.
[0034] Optionally, the private key obtained from the robot system file is used to decrypt the key string to be verified. The decryption process will restore the encrypted information in the key string, including the decrypted symmetric key and the decrypted software pre-installed information, thereby obtaining the software information to be verified. Decrypting the symmetric key refers to decrypting the encrypted symmetric key using the private key, and decrypting the pre-installed information refers to decrypting the encrypted target encrypted pre-installed information using the decrypted symmetric session key.
[0035] S106: Compare the software information to be verified with the software pre-installed information. If the comparison is successful, allow the user to use the target software.
[0036] Optionally, the decrypted software information to be verified is compared with the pre-installed software information obtained from the robot's system files to determine whether the decrypted software information is consistent with the pre-installed software information stored in the system files. This comparison process may involve matching multiple fields, such as version numbers and function identifiers, to obtain a comparison result. Based on the comparison result, a decision is made as to whether the user is allowed to use the target software. Specifically, if the software information to be verified completely matches the pre-installed software information, the key string entered by the user is deemed valid. In this case, the user is allowed to use the target software, and the user's authorization status may be further updated or other related services may be provided.
[0037] It should be noted that the verification process corresponding to steps S104 to S106 can be performed by the robot or by the server, depending on whether the robot is online. In other words, if the robot is offline, the verification process is performed locally by the robot itself. If the robot is online, the server can be a cloud server and perform the verification process.
[0038] Based on this, according to the software authorization method provided in the embodiment of the present application, a public and private key string is generated through a hosted server, and the software pre-installation information containing both software and hardware parameters is encrypted twice, ensuring the encryption security of the key string itself and the security of the software pre-installation information, thereby reducing the risk of key leakage. Even if the robot is physically obtained, it is difficult to decrypt the valid software pre-installation information. And because the software pre-installation information covers the software and hardware parameters, it not only improves the breadth of the encrypted content, but also through the encryption and verification process, it can ensure that only software that matches the robot hardware can be authorized for use, preventing instability or failure caused by software and hardware incompatibility. Moreover, the double confidentiality of the software pre-installation information and the target key string generated based on it provide an additional layer of protection for software copyright, help prevent illegal copying and use, and ensure that software use is within the scope of legal authorization. In addition, the present application supports differentiated use in offline and online scenarios to adapt to the needs of different user environments, and is also friendly to environments with limited network connectivity. Therefore, the software authorization method provided in the embodiment of the present application significantly improves the security, flexibility and ease of use of the software authorization process by introducing a hosted server, double-layer encryption technology and differentiated usage scenario support, better meets customer customization needs, and promotes the safe and efficient use of software services.
[0039] Figure 2 The flowchart of a method for determining target encrypted pre-installed information provided by an embodiment of the present application is shown. Figure 2 As shown, the above step S102 performs secondary encryption on the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain the target encrypted pre-installed information, which specifically includes the following steps: S201. Generate a symmetric session key using a symmetric encryption algorithm, encrypt the usage scope data using the symmetric session key to obtain the encrypted usage scope data, and store the symmetric session key in the system file of the robot.
[0040] Optionally, the symmetric encryption algorithm requires a symmetric session key for encryption and decryption operations, which is randomly generated and can be different each time the encryption process is performed to ensure the security of the encrypted data. The scope of the data refers to the data in the software pre-installed information related to user authorization, software functions, etc., such as software application boundaries and software usage permission information, software application boundaries, i.e., the functional range or boundary of the software, and software usage permission information, such as whether the user has the right to perform certain operations.
[0041] For example, the symmetric session key is used to encrypt the scope of the data to obtain encrypted scope of the data, which ensures that even if the scope of the data is intercepted, it cannot be decrypted without the symmetric session key. In addition, since the symmetric session key is required in the subsequent decryption process, the symmetric session key also needs to be stored in the system file of the robot, and it should be noted that the storage location of the symmetric session key should also be protected to prevent unauthorized access.
[0042] S202, re-encrypt the encrypted scope of the data using the public key to obtain target encrypted pre-installed information.
[0043] For example, the public key is public, but the corresponding private key must be kept secret. The encrypted scope of the data is re-encrypted using the public key generated according to the asymmetric encryption algorithm, which further enhances the security of the data, i.e., even if other users obtain the encrypted scope of the data, they cannot decrypt it without the corresponding private key. That is, the target encrypted pre-installed information contains two layers of encryption of the scope of the data, one layer is symmetric encryption using the symmetric session key, and the other layer is asymmetric encryption using the public key.
[0044] Based on this, the present application processes a large amount of data through symmetric encryption, and protects the symmetric session key through asymmetric encryption, this double-layer encryption structure not only guarantees the encryption efficiency, but also ensures the security of the key exchange, because even if the target encrypted pre-installed information is intercepted, the symmetric session key cannot be decrypted without the corresponding private key, and then the original scope of the data cannot be accessed, thereby improving the security.
[0045] As a possible implementation, the above step S103 generates a target key string according to the target encrypted pre-installed information and the public key, including: concatenating the target encrypted pre-installed information and a preset string into the target key string.
[0046] For example, the preset string is a known string that can be any fixed or dynamically generated string, which is used to concatenate with the target encrypted pre-installed information. The preset string can be arbitrary, but a string with a certain length and complexity can be selected to increase the security and unpredictability of the key string.
[0047] Exemplarily, the target encrypted pre-installation information is spliced with the preset string in a preset splicing manner. The preset splicing manner can be simple string connection or combination according to a certain specific format or rule. For example, the preset string can be placed in front of or behind the target encrypted pre-installation information, or they are placed alternately, and the spliced result is the target key string, which contains all information of the target encrypted pre-installation information and the preset string.
[0048] In addition, in order to further enhance the security and uniqueness of the target key string, more elements such as time stamp, hash value or random number can be added in the splicing process. These elements can be used as additional verification points to help confirm the validity and integrity of the key string. This method is not only simple and easy to implement, but also can significantly improve the security and uniqueness of the key string, thereby better protecting sensitive information. The final target key string can be used in subsequent verification and authorization processes to ensure that only legitimate users can access and use the target software.
[0049] It should be noted that the splicing format should be consistent to ensure that the target encrypted pre-installation information and the preset string can be correctly parsed in the decryption or verification process, and the preset string should also be securely stored and transmitted to prevent unauthorized access or tampering.
[0050] Correspondingly, referring to FIG. 10, the step S105 decrypts the to-be-verified key string based on the private key to obtain the to-be-verified software information, which specifically includes the following steps. Figure 3 S301, obtaining the preset string and the symmetric session key.
[0051] Exemplarily, the preset string is obtained from the corresponding secure storage location in the system file of the robot, which is spliced with the target encrypted pre-installation information in the previous encryption process. Similarly, the symmetric session key stored previously is obtained from the system file of the robot or other secure storage location, which is used in the subsequent symmetric decryption process.
[0052] S302, removing the preset string from the to-be-verified key string to obtain a to-be-decrypted string.
[0053] Optionally, to obtain the to-be-decrypted string from the to-be-verified key string, the position and length of the preset string need to be determined, so that the preset string is removed from the to-be-verified key string. Specifically, the to-be-verified key string can be parsed to determine the format of the to-be-verified key string, and the to-be-decrypted string is separated from the preset string by simple string operation according to the position and length of the preset string in the to-be-verified key string and the preset order during encryption.
[0054] Optionally, the position and length of the preset character string in the key string to be verified are determined according to a preset order during encryption; and the preset character string is removed from the key string to be verified according to the position and length to obtain the character string to be decrypted.
[0055] For example, the position and length of a preset string in the key string to be verified are determined based on a preset order or rule used during encryption. The position includes a starting position and an ending position. During this process, the position and length of the preset string can be more accurately determined based on additional information, such as the specific format or tags used during encryption, or contextual information. Furthermore, based on the determined position and length, the preset string is removed from the key string to be verified. The remaining portion is the string to be decrypted, which should contain the asymmetrically encrypted symmetric session key and / or the symmetrically encrypted usage scope data.
[0056] S303: Decrypt the character string to be decrypted based on the private key to obtain a decrypted character string.
[0057] Exemplarily, the string to be decrypted is asymmetrically encrypted, specifically using a public key in a public-private key string generated by an asymmetric encryption algorithm. The private key corresponding to the public key can be used to decrypt the string to be decrypted to obtain a decrypted string. The decrypted string can be the symmetric session key itself, or a string containing the symmetric session key and other information.
[0058] S304: Decrypt the decrypted character string based on the symmetric session key to obtain the software information to be verified.
[0059] For example, the symmetric session key is obtained during the process of decrypting the string to be decrypted using the private key to obtain the decrypted string. This symmetric session key can be used for the next symmetric decryption step. Specifically, the string to be decrypted is decrypted using a symmetric encryption algorithm (the same symmetric encryption algorithm used for encryption) and the symmetric session key. The decrypted result is the software information to be verified. If the transmission process is secure, the software information to be verified should normally match the original pre-installed software information, particularly the usage scope data in the pre-installed software information.
[0060] Based on this, the private key is used to decrypt the keystring to be verified, ultimately obtaining the software information to be verified, which is then used in subsequent verification or authorization processes. This decryption process not only ensures data security but also provides a strict verification mechanism to ensure that only legally generated keystrings can be correctly decrypted and verified, helping to protect sensitive information and prevent unauthorized access and tampering.
[0061] As a possible implementation, step S106 compares the software information to be verified with the software pre-installed information. If the comparison is successful, the user is allowed to use the target software, including: Obtain the first software application boundary and the first software usage permission information in the software information to be verified, and obtain the second software application boundary and the second software usage permission information in the software pre-installed information; determine whether the comparison is successful based on the first software application boundary, the first software usage permission information, the second software application boundary and the second software usage permission information, and if the comparison is successful, allow the user to use the target software.
[0062] Optionally, the boundaries and permission information in the software information to be verified and the software pre-installed information are obtained. Specifically, the first software application boundary and the first software usage permission information are extracted from the decrypted character string, and the second software application boundary and the second software usage permission information are read from the robot's system file, and the application boundaries and usage permission information in the two information sets, the software information to be verified and the software pre-installed information, are compared respectively. Specifically, it is checked whether the application boundary in the software information to be verified is the same as that in the pre-installed information, and whether the usage permission information in the software information to be verified is completely consistent with that in the pre-installed information, so as to obtain a comparison result, and decide whether to allow the user to use the target software based on the comparison result.
[0063] Optionally, if the first software application boundary and the second software application boundary are the same, and the first software usage permission information and the second software usage permission information are the same, then the comparison is determined to be successful and the user is allowed to use the target software. If the comparison fails, a prompt message is output to the user, the prompt message at least including the reason for the comparison failure.
[0064] For example, comparing the first software application boundary with the second software application boundary typically involves checking whether the two define the same software functional scope or operational boundary, while comparing the first software usage permission information with the second software usage permission information typically involves verifying whether the user has permission to perform specific operations or access specific resources. If the comparison is successful, the user is allowed to use the target software, which may involve unlocking specific software functions, granting user access rights, or performing other necessary operations. Conversely, if the comparison fails, the user is denied access to the target software, and additional security measures may need to be taken, such as logging, notifying an administrator, or displaying an error message.
[0065] For example, when the comparison between the software information to be verified and the pre-installed software information fails, a prompt message is output to the user, which includes at least the reason for the comparison failure, guiding the user to take appropriate action. Alternatively, the prompt message may be an error message, such as "An error occurred while comparing the software information; your usage permissions could not be verified," and include the specific reason for the failure, such as "Your software application boundaries do not match the definition in the pre-installed software information" or "Your software usage permission information is inconsistent with the record in the pre-installed software information."
[0066] Furthermore, the prompt information can also include suggested actions, such as "Please check whether the key string you entered is correct", "Make sure your network connection is stable and retry the verification process", "If the problem persists, please contact our technical support team for help", etc. In addition, when outputting prompt information, it is necessary to pay attention to the prompt information being displayed in a location that users can easily see, such as a prominent area on the software interface or a pop-up window, and using appropriate formatting and layout to highlight key information. For example, bold fonts, color coding or icons can be used to emphasize the cause of the error and the suggested action. In this way, by constructing and outputting clear, specific and user-friendly prompt information, users can better understand the reasons for the comparison failure and guide them to take appropriate actions to solve the problem.
[0067] Based on this, this application provides a simple but effective method to protect software from unauthorized modification, while ensuring that only versions that meet the expected configuration can run. In this process, by comparing and verifying whether the software information to be verified matches the pre-installed software information, the legitimacy and integrity of the software are ensured, preventing unauthorized modification or replacement.
[0068] Figure 4 The following is a flow chart of a software authorization method in an offline scenario provided by an embodiment of the present application. Figure 4As shown in the figure, in an offline scenario, when the robot is powered on or receives a startup command, its operating system begins running and initializes the necessary hardware and software components. Through its built-in sensors or network interfaces, the robot collects and reads its own hardware information, such as CPU model, memory size, and storage space, as well as software configuration information, such as the operating system version and the list of installed software. Furthermore, it reads the keychain used for subsequent encryption and decryption operations from the robot's system files. Based on the installed software list and the user's authorization information, the robot generates or retrieves software usage permission information. This software usage permission information defines which software can be executed and the required permission level. The robot also checks whether its hardware parameters meet the software's operating requirements. After the user enters the keychain to be verified, the robot decrypts the generated software information to be verified and compares it with the pre-installed software information. If the comparison is successful, the robot will allow the user to install or run the software and may update its pre-installed software information to reflect the change. Otherwise, if the comparison fails, the robot may refuse to install or run the software and display an error message to the user.
[0069] Figure 5 The following is a flow chart of a software authorization method in an online scenario provided by an embodiment of the present application. Figure 5 As shown, Figure 5 The software authorization process in the online scenario shown is the same as Figure 4 The software authorization process for the offline scenario is similar, differing in that the verification process in the online scenario is performed by a cloud server, while in the offline scenario, it is performed by the robot itself. Furthermore, in the online scenario, on-site user information can be obtained in real time, such as the reset and upgrade plan, software version, the software environment after the reset, and the robot's initial position information. Initial position information, such as user coordinates, can be used to perform upgrade operations based on this on-site usage information.
[0070] In addition, for online scenarios, a dynamically generated key string can be obtained from the cloud key library corresponding to the robot. The key string can be customized and dynamically generated based on the robot's factory serial number, time, software, etc. After the robot decrypts the key string, it can be used for upgrades, etc.
[0071] Based on this, this application pre-installs software according to the user's selection, which can better match the customer's actual needs. This flexibility is not limited to the one-time configuration at the factory, but can also achieve subsequent software upgrades or function expansions by updating the key string, thereby supporting continuous customized services. In addition, the software authorization method provided by this application takes into account the encryption security of the key string itself, the managed isolation of the public and private key string generation services, the breadth of encrypted content, and the differentiated usability in offline / online scenarios. It significantly improves the security, flexibility and ease of use of the software authorization process, better meets customer customization needs, and promotes the safe and efficient use of software services.
[0072] The embodiment of the present application further provides an electronic device 600, such as Figure 6 FIG. 6 is a schematic diagram of the structure of an electronic device 600 provided in an embodiment of the present application. The electronic device is a robot or a server, and includes a processor 601, a memory 602, and optionally, a bus 603. The memory 602 stores machine-readable instructions executable by the processor 601. When the electronic device 600 is running, the processor 601 communicates with the memory 602 via the bus 603. When the machine-readable instructions are executed by the processor 601, the method steps of any of the above software authorization methods are performed.
[0073] An embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method steps in any one of the above software authorization methods are executed.
[0074] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0075] In addition, the functional units in the various embodiments of the present application can be integrated into a single processing unit, each unit can exist physically separately, or two or more units can be integrated into a single unit. If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present invention. The aforementioned storage medium includes various media that can store program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0076] The above is only a specific implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with this technical field can easily think of changes or replacements within the technical scope disclosed in this application, which should be covered by the protection scope of the present application.
Claims
1. A software authorization method, characterized in that: include: Obtaining software pre-installation information of the target software in the robot, and generating a public-private key string based on the software pre-installation information using an asymmetric encryption algorithm, wherein the software pre-installation information includes at least software application boundaries, software usage permission information, and robot hardware parameters, and the public-private key string includes a public key and a private key, and the private key is stored in the system file of the robot; Performing secondary encryption on the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain target encrypted pre-installed information; generating a target key string according to the target encrypted preinstalled information and the public key, and providing the target key string to the user; Obtaining a key string to be verified input by a user, and obtaining the private key and the software pre-installation information stored in the system file of the robot; Decrypting the key string to be verified based on the private key to obtain the software information to be verified; The software information to be verified is compared with the software pre-installed information. If the comparison is successful, the user is allowed to use the target software.
2. The method according to claim 1, characterized in that The second encryption of the software pre-installed information encrypted by the symmetric encryption algorithm based on the public key to obtain the target encrypted pre-installed information includes: Generating a symmetric session key using the symmetric encryption algorithm, encrypting usage scope data using the symmetric session key to obtain encrypted usage scope data, and storing the symmetric session key in a system file of the robot, wherein the usage scope data includes the software application boundary and the software usage permission information; The encrypted usage scope data is re-encrypted using the public key to obtain the target encrypted pre-installed information.
3. The method according to claim 2, characterized in that The generating a target key string according to the target encrypted preinstalled information and the public key includes: The target encrypted preinstalled information and a preset character string are concatenated into the target key string.
4. The method according to claim 3, characterized in that The decrypting the key string to be verified based on the private key to obtain the software information to be verified includes: Obtaining the preset character string and the symmetric session key; Eliminating the preset character string from the key string to be verified to obtain a character string to be decrypted; Decrypting the character string to be decrypted based on the private key to obtain a decrypted character string; The decrypted character string is decrypted based on the symmetric session key to obtain the software information to be verified.
5. The method according to claim 4, characterized in that The step of removing the preset character string from the key string to be verified to obtain the character string to be decrypted includes: Determine the position and length of the preset character string in the key string to be verified according to the preset order during encryption; According to the position and length, the preset character string is removed from the key string to be verified to obtain the character string to be decrypted.
6. The method according to claim 4, characterized in that The comparing the software information to be verified with the software pre-installed information, and if the comparison is successful, allowing the user to use the target software, includes: Obtaining first software application boundary and first software usage permission information in the software information to be verified; Obtaining the second software application boundary and the second software usage permission information in the software preinstallation information; According to the first software application boundary, the first software usage permission information, the second software application boundary and the second software usage permission information, it is determined whether the comparison is successful. If the comparison is successful, the user is allowed to use the target software.
7. The method according to claim 6, characterized in that The determining whether the comparison is successful based on the first software application boundary, the first software usage permission information, the second software application boundary, and the second software usage permission information, and if the comparison is successful, allowing the user to use the target software includes: If the first software application boundary and the second software application boundary are the same, and the first software usage permission information and the second software usage permission information are the same, then it is determined that the comparison is successful, and the user is allowed to use the target software.
8. The method according to claim 1, characterized in that After comparing the software information to be verified with the software pre-installed information, the method further includes: If the comparison fails, a prompt message is output to the user, and the prompt message at least includes the reason for the comparison failure.
9. An electronic device, characterized in that: The electronic device is a robot or a server, and includes: a processor and a memory, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor executes the machine-readable instructions to perform the steps of the software authorization method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the software authorization method according to any one of claims 1 to 8.