Service authorization method and device based on single device fingerprint, equipment and medium

By using a single-device fingerprint-based authorization method and public-key and private-key encryption/decryption technologies to generate authorization files, the problem of hardware dongle dependency is solved, enabling lightweight, flexible, and comprehensive authorization management for big data platforms.

CN121077784APending Publication Date: 2025-12-05HANGZHOU NETEASE ZHIQI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511323796.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

Existing hardware-based authorization methods rely on physical media, resulting in high costs, service interruptions when hardware is damaged or lost, incompatibility with cloud computing environments, and inability to adapt to the complex ecosystem of big data platforms.

Method used

A service authorization method based on single-device fingerprints is adopted. By obtaining single-device fingerprint information and multi-dimensional authorization information from the management server, an authorization file is generated, and encryption and decryption are performed using public and private keys to achieve refined authorization management of the big data platform.

Benefits of technology

It achieves lightweight licensing without hardware locks, supports cloud computing environments, and enables flexible control over the deployment and use of big data platforms, achieving comprehensive licensing management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121077784A_ABST
    Figure CN121077784A_ABST
Patent Text Reader

Abstract

The invention provides a service authorization method and device based on a single device fingerprint, equipment and a medium, and relates to the technical field of information security. The method comprises the following steps: acquiring single-device fingerprint information of a management server of a to-be-deployed big data platform; according to the single-device fingerprint information and multi-dimensional authorization information for the big data platform, a pre-generated private key is adopted for encryption, and an authorization file is generated; and sending an authorization file to a management server, decrypting the authorization file by using a public key corresponding to the private key by the management server, and performing authorization verification of the big data platform on the management server and a plurality of distributed servers of the management server according to the decrypted single-device fingerprint information and the decrypted multi-dimensional authorization information, and the plurality of distributed servers are used for deploying a plurality of service modules of the big data platform. According to the invention, refined authorization for the big data platform can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, in particular to a service authorization method and device based on single-device fingerprint, equipment and medium. BACKGROUND

[0002] The current mainstream software authorization technology mainly adopts an authorization mode based on a hardware encryption lock (dongle), and stores an encryption key and authorization information through a physical device. When the software runs, it needs to detect whether the dongle exists and is valid.

[0003] This authorization mode depends on the dongle and other physical media, needs to develop and produce physical products, has high cost, and in the case of damage or loss of the hardware medium, will immediately cause the service of the product to be interrupted, and also has repair cost; if a customer uses a cloud computing or virtualization environment, the insertion of the hardware encryption lock is not supported, which restricts the deployment of the big data platform in the cloud scenario; and the dongle authorization mode is mainly designed for a single commercial software product, and cannot effectively adapt to the complex ecology of the big data technology stack. SUMMARY

[0004] The present application aims at the deficiencies in the prior art, and provides a service authorization method and device based on single-device fingerprint, equipment and medium, so as to realize fine authorization for a big data platform.

[0005] To achieve the above purpose, the technical solutions adopted by the embodiments of the present application are as follows: In a first aspect, the embodiments of the present application provide a service authorization method based on single-device fingerprint, applied to an authorization management center of a big data platform management system, and the method comprises: Obtaining single-device fingerprint information of a management server of the big data platform to be deployed; According to the single-device fingerprint information and multi-dimensional authorization information for the big data platform, a pre-generated private key is used for encryption to generate an authorization file; Sending the authorization file to the management server, and the management server uses a public key corresponding to the private key to decrypt the authorization file, and according to the decrypted single-device fingerprint information and multi-dimensional authorization information, performs authorization verification on the management server and a plurality of distributed servers of the management server for the big data platform, wherein the plurality of distributed servers are used to deploy a plurality of service modules of the big data platform.

[0006] In a second aspect, the embodiments of the present application also provide a service authorization method based on single-device fingerprint, applied to a management server of a big data platform management system, and the method comprises: obtain an authorization file sent by an authorization management center of the big data platform management system, the authorization file being generated by the authorization management center according to single-device fingerprint information of the management server and multi-dimensional authorization information for the big data platform, and being encrypted by using a pre-generated private key; decrypt the authorization file by using a public key corresponding to the private key, and obtain the single-device fingerprint information and the multi-dimensional authorization information; perform authorization verification of the big data platform on the management server and a plurality of distributed servers of the management server according to the single-device fingerprint information and the multi-dimensional authorization information, wherein the plurality of distributed servers are configured to deploy a plurality of service modules of the big data platform.

[0007] In a third aspect, an embodiment of the present application further provides a service authorization device based on single-device fingerprint, applied to an authorization management center of a big data platform management system, and comprising: an information obtaining module configured to obtain single-device fingerprint information of a management server to be deployed with the big data platform; an authorization file generating module configured to generate an authorization file by encrypting the single-device fingerprint information and multi-dimensional authorization information for the big data platform by using a pre-generated private key; an authorization file sending module configured to send the authorization file to the management server, and the management server decrypts the authorization file by using a public key corresponding to the private key, and performs authorization verification of the big data platform on the management server and a plurality of distributed servers of the management server according to the decrypted single-device fingerprint information and multi-dimensional authorization information, wherein the plurality of distributed servers are configured to deploy a plurality of service modules of the big data platform.

[0008] In a fourth aspect, an embodiment of the present application further provides a service authorization device based on single-device fingerprint, applied to a management server of a big data platform management system, and comprising: an authorization file receiving module configured to obtain an authorization file sent by an authorization management center of the big data platform management system, the authorization file being generated by the authorization management center according to single-device fingerprint information of the management server and multi-dimensional authorization information for the big data platform, and being encrypted by using a pre-generated private key; an authorization file decrypting module configured to decrypt the authorization file by using a public key corresponding to the private key, and obtain the single-device fingerprint information and the multi-dimensional authorization information; An authorization verification module is configured to verify deployment and use of the big data platform on the management server and a plurality of distributed servers of the management server according to the single-device fingerprint information and the multi-dimensional authorization information, wherein the plurality of distributed servers are configured to deploy a plurality of service modules of the big data platform.

[0009] In a fifth aspect, an electronic device is provided, which comprises a processor, a storage medium and a bus. The storage medium stores program instructions executable by the processor. When the electronic device is running, the processor communicates with the storage medium through the bus. The processor executes the program instructions to perform the steps of the single-device fingerprint-based service authorization method according to any one of the first aspect or the second aspect.

[0010] In a sixth aspect, a computer-readable storage medium is provided, which stores a computer program. When the computer program is run by a processor, the steps of the single-device fingerprint-based service authorization method according to any one of the first aspect or the second aspect are performed.

[0011] The present application has the following beneficial effects: The single-device fingerprint-based service authorization method, device, equipment and medium provided by the present application generate an authorization file based on single-device fingerprint information and multi-dimensional authorization information of a management server of a to-be-deployed big data platform, so that the management server verifies deployment and use of the big data platform in a plurality of distributed servers based on the authorization file. The present application can realize targeted authorization for the management server and independently and flexibly control fine-grained authorization of the big data platform, and realize all-round authorization management of the whole set of products of the big data platform through single-device fingerprint. Compared with the existing authorization scheme of a hardware lock such as a dongle, the authorization mode of the present application does not need to manufacture a hardware lock, and is more lightweight. BRIEF DESCRIPTION OF DRAWINGS

[0012] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiments. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be considered as limiting the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.

[0013] Figure 1 An existing hardware dongle authorization schematic diagram; Figure 2 An architecture diagram of a big data platform management system provided by the embodiments of the present application; Figure 3 A flowchart of the single-device fingerprint-based service authorization method provided by the embodiments of the present applicationFigure 1 Figure 4 A single-device fingerprint information acquisition schematic diagram provided for an embodiment of the present application; Figure 5 A service authorization method based on single-device fingerprint provided for an embodiment of the present application Figure 2 Figure 6 A service authorization method based on single-device fingerprint provided for an embodiment of the present application Figure 3 Figure 7 A service authorization method based on single-device fingerprint provided for an embodiment of the present application Figure 4 Figure 8 A service authorization device based on single-device fingerprint provided for an embodiment of the present application Figure 1 Figure 9 A service authorization device based on single-device fingerprint provided for an embodiment of the present application Figure 2 Figure 10 An electronic device provided for an embodiment of the present application. DETAILED DESCRIPTION

[0014] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some but not all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative effort shall fall within the scope of the present application.

[0015] Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative effort shall fall within the scope of the present application.

[0016] ​​​​​​Moreover, the terms "first", "second", and the like, in the description and in the claims of the present application and the above figures are used for distinguishing between similar objects and not necessarily for describing a specific sequential or chronological order. It is to be understood that the use of data "first", "second", etc., significantly implies the presence of data "third", "fourth" or more, although these can not be explicitly mentioned in the application. It is to be understood that even though the terms "first" and "second" etc. can be used herein to describe various objects, these objects should not be limited by these terms, and these terms are only used to distinguish one object from another. The data used with these terms can potentially be interchangeable, unless otherwise understood from the context. Furthermore, the terms "comprising", "having", "including", and the like, as well as any variations thereof, are intended to cover a non-exclusive inclusion such that a process, method, system, product, or apparatus that comprises, has, includes or includes elements or steps do not include only those elements or steps but can include other elements or steps not expressly listed or inherent to such process, method, system, product, or apparatus.

[0017] It should be noted that the features in the embodiments of the present application can be combined with each other without conflict.

[0018] Figure 1 For the authorization principle diagram of the existing hardware dongle, as shown in Figure 1 The dongle is usually inserted in the form of a USB interface on the server, and the dongle carries authorization information. The dongle software development kit (SDK) is a dependent library provided by the dongle supplier to call the dongle interface, which is integrated in the software and hardware products that need to control authorization.

[0019] This authorization method depends on physical media such as dongles, and needs to develop and produce physical products, which is relatively high in cost. In the case of damage or loss of hardware media, the product service will be immediately interrupted, and there is also a repair cost. If the customer uses a cloud computing or virtualization environment, the insertion of a hardware dongle is not supported, which restricts the deployment of a big data platform in a cloud scenario. Moreover, this dongle authorization method is mainly designed for a single commercial software product, and cannot effectively adapt to the complex ecology of the big data technology stack.

[0020] Based on the problems existing in the prior art, the present application provides a service authorization method, device, equipment and medium based on single device fingerprint, which generates an authorization file based on single device fingerprint information and multi-dimensional authorization information of a management server of a to-be-deployed big data platform, so that the management server verifies the deployment and use of the big data platform in multiple distributed servers based on the authorization file. It can realize targeted authorization for the management server, and independently and flexibly control the fine-grained authorization of the big data platform, and realize the all-round authorization management of the whole set of products of the big data platform through the single device fingerprint.

[0021] Before introducing the service authorization method based on single device fingerprint provided by the present application, the big data platform management system applied by the present application is introduced.

[0022] Figure 2 The architecture diagram of the big data platform management system provided by the embodiment of the present application is shown in Figure 2 The big data platform management system includes a license management center License-Center, a management server Easyops-manager, a fingerprint acquisition component machine_id-getter, and a plurality of distributed servers.

[0023] The license management center License-Center is a management center for the provider of the big data platform to authorize the user to use the big data platform. The management server Easyops-manager is a server for the user to manage the deployed big data platform. The plurality of distributed servers are servers for deploying a plurality of service modules of the big data platform. The management server Easyops-manager serves as a management node of the plurality of distributed servers. The plurality of distributed servers constitute a cluster. Each distributed server serves as a cluster node in the cluster.

[0024] The fingerprint acquisition component machine_id-getter can be deployed alone or together with the license management center License-Center. The fingerprint acquisition component machine_id-getter is used to collect the single-device fingerprint of the management server Easyops-manager from the management server Easyops-manager and send the single-device fingerprint of the management server Easyops-manager to the license management center License-Center. The license management center License-Center can generate an authorization file according to the single-device fingerprint of the management server Easyops-manager and the use requirement of the user for the big data platform, so that the management server Easyops-manager performs authorization verification according to the authorization file, deploys and runs the big data platform.

[0025] The following describes the specific implementation of the single-device fingerprint-based service authorization method applied to the license management center provided by the present application in combination with the embodiments.

[0026] Figure 3 The flowchart of the single-device fingerprint-based service authorization method provided by the embodiment of the present application is shown in Figure 1 As shown in Figure 3 The method can include the following steps. S101, acquiring the single-device fingerprint information of the management server of the big data platform to be deployed.

[0027] In the embodiment, when deploying the big data platform to the management server Easyops-manager, the management server Easyops-manager needs to be authorized by the provider of the big data platform to have the qualification of deploying and using the big data platform.

[0028] The fingerprint obtaining component machine_id-getter sends a device fingerprint information obtaining request to the management server Easyops-manager to collect the single-device fingerprint information of the management server Easyops-manager, and sends the single-device fingerprint information of the management server Easyops-manager to the license management center License-Center.

[0029] In some embodiments, Figure 4 A single-device fingerprint information obtaining schematic diagram provided by the embodiment is shown in FIG. 1. Figure 4 As shown in FIG. 1, the fingerprint obtaining component machine_id-getter sends a device fingerprint information obtaining command dmidecode to the management server Easyops-manager, and the management server Easyops-manager returns the single-device fingerprint information to the fingerprint obtaining component machine_id-getter.

[0030] For example, the single-device fingerprint information can be the motherboard serial number serial-number of the management server Easyops-manager, which is injected by the device manufacturer when producing the server and has uniqueness.

[0031] S102, according to the single-device fingerprint information and the multi-dimensional authorization information for the big data platform, a pre-generated private key is used for encryption to generate an authorization file.

[0032] In the embodiment, according to the use requirement of the user for the big data platform, the multi-dimensional authorization information for the big data platform is input to the license management center License-Center, and the multi-dimensional authorization information includes the use requirement of the user for the big data platform in multiple dimensions, such as use period, use function, use scale, etc., which is not limited in the embodiment.

[0033] A preset encryption algorithm is used to generate a public key and a private key, wherein the private key is saved by the license management center License-Center, and the public key is packaged and sent to the management server Easyops-manager together with the big data platform.

[0034] In some embodiments, the preset encryption algorithm can be an RSA asymmetric encryption algorithm, and specifically can be a GPG (GNUPrivacy Guard) encryption algorithm.

[0035] The License-Center encrypts the single-device fingerprint information and the multi-dimensional authorization information for the big data platform according to the private key, and generates an authorization file License.

[0036] In S103, the authorization file is sent to the management server, the management server decrypts the authorization file by using a public key corresponding to the private key, and performs authorization verification on the management server and multiple distributed servers of the management server according to the decrypted single-device fingerprint information and multi-dimensional authorization information, wherein the multiple distributed servers are used to deploy multiple service modules of the big data platform.

[0037] In this embodiment, the authorization file is sent to the management server Easyops-manager, the management server Easyops-manager imports the authorization file, and decrypts the authorization file by using the previously received public key, and judges whether the management server Easyops-manager is authorized to deploy and use the big data platform and the authorization range according to the decrypted single-device fingerprint information and multi-dimensional authorization information.

[0038] If the management server Easyops-manager is authorized to deploy and use the big data platform, the corresponding service modules of the big data platform are deployed in the multiple distributed servers according to the authorization range.

[0039] If the management server Easyops-manager is authorized to deploy and use the big data platform, the management service needs to be deployed in the management server Easyops-manager, the management server Easyops-manager manages the service modules deployed on the multiple distributed servers based on the management service, and according to the access request of the user to the big data platform, the corresponding distributed server is called to provide the function of the corresponding service module.

[0040] The service authorization method based on single-device fingerprint provided in the above embodiments generates an authorization file based on the single-device fingerprint information and multi-dimensional authorization information of the management server of the big data platform to be deployed, so that the management server verifies the deployment and use of the big data platform in the multiple distributed servers based on the authorization file, which can realize targeted authorization for the management server, and independently and flexibly control the fine-grained authorization of the big data platform, and realize the all-round authorization management of the whole set of products of the big data platform through the single-device fingerprint. Compared with the existing authorization scheme of the hardware lock such as the dongle, the authorization mode of the present scheme does not need to manufacture and carry the hardware lock, and is more lightweight.

[0041] In a possible implementation manner, Figure 5 A flowchart of a service authorization method based on single-device fingerprint provided by an embodiment of the present application Figure 2 As shown in Figure 5 The process of generating the authorization file by using the pre-generated private key to encrypt according to the single-device fingerprint information and the multi-dimensional authorization information for the big data platform in S102 can include the following steps. S201, generating an original license file according to the single-device fingerprint information and the multi-dimensional authorization information.

[0042] In this embodiment, according to the contract formed between the user and the provider of the big data platform for the big data platform, the multi-dimensional authorization information about the authorization range of the big data platform is determined from the contract, and the single-device fingerprint information and the multi-dimensional authorization information are written in the original license file in plaintext.

[0043] For example, part of the content in the original license file is as follows: { "expiryDate": "2025-12-31", "nodeSize": "10", "serviceList": ["HDFS", "YARN”, "SPARK"], "machineId": "00:1A:2B:3C:4D" } S202, signing the original license file by using the private key to generate a first signature value.

[0044] In this embodiment, the private key is used to sign the original license file by using a preset hash algorithm to generate a first signature value.

[0045] For example, the preset hash algorithm can be SHA256withRSA, and the signature mode is as follows: Signature signer = Signature.getInstance("SHA256withRSA"); signer.initSign(privateKey); signer.update(licenseData.getBytes()); byte[] signature = signer.sign(); S203, encode according to a preset encoding mode based on the original license file and the first signature value, to generate an authorization file.

[0046] In the embodiment, the original license file and the first signature value are encoded respectively by using the preset encoding mode, and the encoded license file and the encoded first signature value are merged to generate the authorization file.

[0047] In some embodiments, the preset encoding mode can be Base64 format, and the way of generating the authorization file can be BASE64 (original data) + "|" + BASE64 (signature).

[0048] The service authorization method based on single device fingerprint provided in the above embodiments uses a private key to sign an original license file, and generates an authorization file based on the original license file and a first signature value, which can ensure the security of the authorization file in the transmission process. If the authorization file is tampered with in the transmission process, it can be identified, and it is ensured that the user can only use the big data platform within the authorization range of the authorization file.

[0049] The following describes the specific implementation of the service authorization method based on single device fingerprint applied to the management server provided by the present application in combination with embodiments.

[0050] Figure 6 The flowchart of the service authorization method based on single device fingerprint provided in the embodiments of the present application Figure 3 As shown in Figure 6 , the method can include: S301, obtaining an authorization file sent by an authorization management center of a big data platform management system, the authorization file being generated by the authorization management center based on single device fingerprint information of the management server and multi-dimensional authorization information for the big data platform by using a pre-generated private key for encryption.

[0051] In the embodiment, the authorization management center License-Center generates the authorization file by using the method of S101-S103 as described above, and sends it to the management server Easyops-manager, which will not be described in detail here.

[0052] S302, decrypting the authorization file by using a public key corresponding to the private key to obtain the single device fingerprint information and the multi-dimensional authorization information.

[0053] In the embodiment, the license management center License-Center sends the big data platform and the public key to the management server Easyops-manager, and the management server Easyops-manager decrypts the license file by using the public key after receiving the license file, and determines the single-device fingerprint information and the multi-dimensional authorization information in the license file.

[0054] S303, according to the single-device fingerprint information and the multi-dimensional authorization information, performing authorization verification of the management server and a plurality of distributed servers of the management server on the big data platform, wherein the plurality of distributed servers are used to deploy a plurality of service modules of the big data platform.

[0055] In the embodiment, the management server Easyops-manager determines whether the management server Easyops-manager is authorized to deploy and use the big data platform and the authorization range according to the decrypted single-device fingerprint information and the multi-dimensional authorization information.

[0056] If the management server Easyops-manager is authorized to deploy and use the big data platform, the corresponding service modules of the big data platform are deployed in the plurality of distributed servers according to the authorization range.

[0057] If the management server Easyops-manager is authorized to deploy and use the big data platform, the management service needs to be deployed in the management server Easyops-manager, and the management server Easyops-manager manages the service modules deployed on the plurality of distributed servers based on the management service, and according to the access request of the user to the big data platform, the corresponding distributed server is called to provide the function of the corresponding service module.

[0058] In some embodiments, the management server Easyops-manager determines whether it is authorized to deploy and use the big data platform according to the single-device fingerprint information, and if it is authorized to deploy and use the big data platform, determines the authorization range according to the multi-dimensional authorization information.

[0059] The single-device fingerprint-based service authorization method provided in the above embodiments determines whether the management server is authorized to run the big data platform and the authorization range based on the license file provided by the license management center, realizes targeted authorization for the management server, and independently and flexibly controls the fine-grained authorization of the big data platform, and realizes the all-round authorization management of the whole set of products of the big data platform through the single-device fingerprint. Compared with the existing hardware lock such as the dongle, the authorization method of the present scheme does not need to manufacture and carry the hardware lock, and is more lightweight.

[0060] In a possible implementation, the authorization file includes: the original license file encoded by using a preset encoding mode and a first signature value, Figure 7 A flowchart of a service authorization method based on a single-device fingerprint provided by an embodiment of the present application Figure 4 As shown in Figure 7 The process of decrypting the authorization file by using the public key corresponding to the private key to obtain the single-device fingerprint information and the multi-dimensional authorization information in S302 can include: S401, decode the authorization file by using a preset decoding mode.

[0061] S402, sign the decoded original license file by using the public key to obtain a second signature value.

[0062] S403, determine whether the first signature value and the second signature value match.

[0063] S404, if the first signature value and the second signature value match, obtain the single-device fingerprint information and the multi-dimensional authorization information from the original license file.

[0064] In the embodiment, the process of generating the authorization file in S201-S203, the management server Easyops-manager first decodes the authorization file by using a preset decoding mode corresponding to the preset encoding mode to obtain the decoded original license file and the first signature value.

[0065] Then, the validity of the decoded original license file needs to be determined to avoid the original license file being tampered, and the specific determination mode is: signing the decoded original license file by using the public key to generate a second signature value.

[0066] The authorization management center License-Center compares whether the first signature value and the second signature value match, and if the first signature value and the second signature value match, it is determined that the original license file is not tampered in the transmission process.

[0067] For example, the mode of determining the validity of the decoded original license file can be: Signature verifier = Signature.getInstance("SHA256withRSA"); verifier.initVerify(publicKey); verifier.update(licenseData.getBytes()); boolean isValid = verifier.verify(signature). In a case where the first signature value matches the second signature value, the single-device fingerprint information and the multi-dimensional authorization information are obtained from the decoded original license file.

[0068] In an example, the manner of obtaining the single-device fingerprint information and the multi-dimensional authorization information from the decoded original license file can be as follows: if (license.isVerified()) { license.getFeature("expireDate"); license.getFeature("nodeSize"); license.getFeature("serviceList"); license.getFeature("machineIds");}. The service authorization method based on the single-device fingerprint provided in the above embodiment adopts a public key to sign the decoded original license file, and the second signature value is compared with the first signature value in the authorization file, so that the validity of the original license file can be verified, and the original license file can be prevented from being tampered with.

[0069] In a possible implementation, the process of performing authorization verification on the management server in S303 can include: It is determined whether the single-device fingerprint information is consistent with single-device fingerprint information of the management server. If the single-device fingerprint information is consistent with the single-device fingerprint information of the management server, it is determined that the management server is authorized to use the big data platform. If the single-device fingerprint information is not consistent with the single-device fingerprint information of the management server, it is determined that the management server cannot use the big data platform.

[0070] In this embodiment, before the big data platform is deployed, it is necessary to ensure that the management server Easyops-manager that manages the big data platform is a legal server, that is, the management server Easyops-manager is authorized in the authorization management center License-Center.

[0071] The fingerprint acquisition component machine_id-getter is also deployed in the management server Easyops-manager, and acquires the single-device fingerprint of the management server Easyops-manager. The management server Easyops-manager compares the single-device fingerprint acquired by the fingerprint acquisition component machine_id-getter with the single-device fingerprint decoded from the original license file, and determines whether the two are consistent.

[0072] If the single-device fingerprint acquired by the fingerprint acquisition component machine_id-getter is consistent with the single-device fingerprint decoded from the original license file, it is determined that the license License is a valid file, and the current management server Easyops-manager is the management server Easyops-manager authorized in the authorized management center License-Center. The current management server Easyops-manager is a legal server, and can run the deployment and big data platform.

[0073] If the single-device fingerprint acquired by the fingerprint acquisition component machine_id-getter is inconsistent with the single-device fingerprint decoded from the original license file, it is determined that the license License is an invalid file, or the license License is the license of another management server. It is determined that the current management server Easyops-manager is not authorized in the authorized management center License-Center, and the current management server Easyops-manager is an illegal server, and cannot run the deployment and big data platform.

[0074] The single-device fingerprint-based service authorization method provided by the above embodiment determines whether the management server is authorized to run the big data platform based on the single-device fingerprint information of the management server, and can realize the license authorization of enterprise production-level products without using a hardware lock, and realizes the targeted authorization for the management server.

[0075] In a possible implementation, the multi-dimensional authorization information includes a valid period, and the process of authorizing and verifying the management server in S303 can include: determining whether the current system time meets the valid period; and if the current system time does not meet the valid period, shutting down the entry service of the big data platform.

[0076] In the embodiment, the valid period is the period in which the user can use the big data platform. The valid period can be a preset date or a running time length of the big data platform. The management server Easyops-manager needs to determine whether the valid period is met during deployment of the big data platform, each start of the big data platform, and running of the big data platform.

[0077] In some embodiments, if the valid period is a preset date, it is determined whether the current system time of the management server Easyops-manager exceeds the preset date, that is, it is determined whether the preset date is future time or past time relative to the current system time. If the preset date is future time relative to the current system time, it is determined that the current system time of the management server Easyops-manager does not exceed the preset date, the big data platform is still in the valid period, and the management server can continue to run the big data platform.

[0078] If the preset date is past time relative to the current system time, it is determined that the current system time of the management server Easyops-manager has exceeded the preset date, the big data platform exceeds the valid period, and the management server cannot continue to run the big data platform.

[0079] In other embodiments, if the valid period is a running time length, the running time length is continuously updated according to the running time of the big data platform after the big data platform is deployed on the management server and starts to run. If the running time length is greater than 0, it is determined that the big data platform is still in the valid period, and the management server can continue to run the big data platform. If the running time length is less than or equal to 0, it is determined that the big data platform exceeds the valid period, and the management server cannot continue to run the big data platform.

[0080] When it is determined that the running of the big data platform deployed in the management server Easyops-manager exceeds the valid period, the management server stops the entry web service of the big data platform, that is, closes the web access entry of the big data platform, to avoid that the user continues to use the big data platform through the web access entry.

[0081] In some embodiments, an expired prompt can be displayed on the management server Easyops-manager and the user client to indicate that the service provided by the big data platform has expired and needs to be renewed to be used.

[0082] Further, in addition to closing the entry web service of the big data platform, some services of the back end of the big data platform can also be closed according to the rules determined in advance.

[0083] The method for authorizing services based on single-device fingerprints provided by the above embodiments determines whether the validity period of the big data platform is expired according to the validity period authorized for the big data platform, and closes the entry service of the big data platform in the case of expiration, and intercepts user entry access, thereby realizing precise partial degradation of the big data platform services.

[0084] In a possible implementation, the multi-dimensional authorization information further includes at least one authorized service module of the big data platform, and the process of authorizing and verifying the plurality of distributed servers of the management server in S303 can include: At least one authorized service module is deployed in the plurality of distributed servers.

[0085] In this embodiment, the big data platform provides a plurality of service modules available for subscription for the user, and according to the service module subscribed by the user from the plurality of service modules, the information of the service module subscribed by the user is carried in the multi-dimensional authorization information to authorize the service module subscribed by the user.

[0086] After the management server Easyops-manager determines at least one authorized service module authorized by the authorization management center License-Center from the original license file, at least one authorized service module is deployed in the plurality of distributed servers managed by the management server, so as to run the authorized service module by the distributed server and provide the function of the authorized service module.

[0087] In some embodiments, the management server Easyops-manager can deploy each authorized service module in at least one distributed server, wherein the number of distributed servers in which the authorized service module is deployed can be determined according to the usage rate of the authorized service module.

[0088] For the service module that is not authorized, the service module cannot be deployed in the distributed server, and the user cannot access the service module that is not authorized from the front-end client of the big data platform.

[0089] In some embodiments, the method can further include: According to all service modules of the big data platform and the at least one authorized service module, an authorized service view is generated, and the authorized service view is used to indicate the service module available for the user in the big data platform.

[0090] In the embodiment, the management server Easyops-manager filters at least one authorized service module from all service modules according to information of at least one authorized service module in all service modules and multi-dimensional authorization information, generates an authorized service view about the at least one authorized service module, so that a user can determine the authorized available service module from the authorized service view, and the authorized service view can be displayed in a client provided by the big data platform for the user.

[0091] The service authorization method based on single-device fingerprint provided in the above embodiment performs service authorization according to a service module subscribed by a user, so as to realize fine authorization of service functions of the big data platform and realize authorization control of service functions of the big data platform based on single-device fingerprint.

[0092] In a possible implementation, the multi-dimensional authorization information further includes an authorized cluster size, and the process of S303 of performing authorization verification on the plurality of distributed servers of the management server can further include: If the addition request sent by the new distributed server is received, it is determined whether the cluster size meets the authorized cluster size; if the cluster size does not meet the authorized cluster size, the new distributed server is rejected.

[0093] In the embodiment, the provider and the user of the big data platform agree on the maximum number of nodes of the service module of the big data platform in a contract, when the user needs to increase the distributed server because the access amount of the authorized service module is too large, so as to deploy the authorized service module in more distributed servers to improve service efficiency, the management server Easyops-manager needs to determine whether the cluster size exceeds the authorized cluster size.

[0094] Specifically, when the management server Easyops-manager receives the addition request sent by the new distributed server, it is determined whether the sum of the existing distributed server and the new distributed server exceeds the number of the authorized cluster size, if the sum of the existing distributed server and the new distributed server does not exceed the number of the authorized cluster size, the new distributed server is added, if the sum of the existing distributed server and the new distributed server exceeds the number of the authorized cluster size, the new distributed server is rejected.

[0095] It should be noted that for adding a distributed server, only the distributed server used for deploying the service module of the big data platform is determined, if the added distributed server is not used for deploying the service module of the big data platform, it is not necessary to determine whether the authorized cluster size is met.

[0096] In some embodiments, when the management server Easyops-manager deploys a service module to a new distributed server, it can be determined whether the distributed server deploying the service module exceeds the number of authorized cluster size. If not, the new distributed server is allowed to deploy the service module. If yes, the new distributed server is refused to deploy the service module.

[0097] For example, the core control logic is as follows: int addHostCount=req.getHostList().size(); int limitHostCount= AuthService.getTokenLicenses().getNodeSize(); int currentHostCount=hostRepository.findAll().size(); if (currentHostCount+addHostCount>limitHostCount){ Throw new BusinessException(ResultCode.HOST_COUNT_EXCEED_LIMIT); }. The service authorization method based on single device fingerprint provided by the above embodiments can achieve fine-grained authorization of the scale of the service module deployed in the big data platform, and achieve cluster size authorization control of the big data platform based on single device fingerprint.

[0098] In some embodiments, the multi-dimensional authorization information can also include the number of cores. The number of cores of the distributed server can be used to determine whether the distributed server can deploy the service module.

[0099] Based on the service authorization method based on single device fingerprint provided by the above embodiments, the embodiment of the application further provides a service authorization device based on single device fingerprint, which is applied to the authorization management center of the big data platform management system. Figure 8 The structure of the service authorization device based on single device fingerprint provided by the embodiment of the application is shown in Figure 1 As shown in Figure 8 The device can include: An information acquisition module 501 is configured to acquire single device fingerprint information of a management server of a big data platform to be deployed; An authorization file generation module 502 is configured to encrypt the single device fingerprint information and multi-dimensional authorization information for the big data platform by using a pre-generated private key to generate an authorization file. The authorization file sending module 503 is configured to send the authorization file to the management server, and the management server decrypts the authorization file by using a public key corresponding to the private key and performs authorization verification on the management server and multiple distributed servers of the management server according to the single-device fingerprint information and the multi-dimensional authorization information after decryption, where the multiple distributed servers are configured to deploy multiple service modules of the big data platform.

[0100] The single-device fingerprint-based service authorization apparatus provided in the above embodiments generates an authorization file based on the single-device fingerprint information and the multi-dimensional authorization information of the management server of the big data platform to be deployed, so that the management server verifies the deployment and use of the big data platform in the multiple distributed servers based on the authorization file, the targeted authorization of the management server can be implemented, the fine-grained authorization of the big data platform can be flexibly controlled, and the all-round authorization management of the complete set of products of the big data platform can be completed through the single-device fingerprint. Compared with the existing authorization scheme of the hardware lock such as the dongle, the authorization manner of the present scheme does not need to manufacture and carry the hardware lock, and is more lightweight.

[0101] Optionally, the authorization file generating module 502 is specifically configured to generate an original license file according to the single-device fingerprint information and the multi-dimensional authorization information, sign the original license file by using the private key to generate a first signature value, and encode the original license file and the first signature value by using a preset encoding manner to generate the authorization file.

[0102] The single-device fingerprint-based service authorization apparatus provided in the above embodiments is applied to a management server of a big data platform management system. Figure 9 The single-device fingerprint-based service authorization apparatus provided in the above embodiments is applied to a management server of a big data platform management system. Figure 2 As shown in Figure 9 The apparatus can include: The authorization file receiving module 601 is configured to obtain an authorization file sent by an authorization management center of the big data platform management system, where the authorization file is generated by the authorization management center by encrypting the single-device fingerprint information of the management server and the multi-dimensional authorization information of the big data platform by using a pre-generated private key. The authorization file decryption module 602 is configured to decrypt the authorization file by using a public key corresponding to the private key to obtain the single-device fingerprint information and the multi-dimensional authorization information. The authorization verification module 603 is configured to perform deployment and use verification on the management server and multiple distributed servers of the management server according to the single-device fingerprint information and the multi-dimensional authorization information, where the multiple distributed servers are configured to deploy multiple service modules of the big data platform.

[0103] The authorization file includes: an original license file encoded by using a preset encoding mode and a first signature value, the authorization file decryption module 602 is specifically used for decoding the authorization file by using a preset decoding mode; signing the decoded original license file by using a public key to obtain a second signature value; judging whether the first signature value and the second signature value match; if the first signature value and the second signature value match, obtaining single-device fingerprint information and multi-dimensional authorization information from the original license file.

[0104] Optionally, the authorization verification module 603 is specifically used for judging whether the single-device fingerprint information is consistent with single-device fingerprint information of the management server; if the single-device fingerprint information is consistent with the single-device fingerprint information of the management server, it is determined that the management server is authorized to use the big data platform; if the single-device fingerprint information is not consistent with the single-device fingerprint information of the management server, it is determined that the management server cannot use the big data platform.

[0105] Optionally, the multi-dimensional authorization information includes: a validity period, and the authorization verification module 603 is further used for judging whether a current system time meets the validity period; if the current system time does not meet the validity period, the entry service of the big data platform is closed.

[0106] Optionally, the multi-dimensional authorization information further includes: at least one authorized service module of the big data platform, and the authorization verification module 603 is further used for deploying the at least one authorized service module in the plurality of distributed servers.

[0107] Optionally, the authorization verification module 603 is further used for generating an authorized service view according to all service modules of the big data platform and the at least one authorized service module, and the authorized service view is used for indicating service modules that can be used by a user in the big data platform.

[0108] Optionally, the multi-dimensional authorization information further includes: an authorized cluster size, and the authorization verification module 603 is further used for, if an adding request sent by a new distributed server is received, judging whether the cluster size meets the authorized cluster size; if the cluster size does not meet the authorized cluster size, the new distributed server is rejected.

[0109] The service authorization device based on single-device fingerprint provided by the above embodiment determines whether the management server is authorized to run the big data platform and the authorization range based on the authorization file provided by the authorization management center, realizes the targeted authorization for the management server, and independently and flexibly controls the fine authorization of the big data platform, so that the all-round authorization management of the whole set of products of the big data platform is completed through the single-device fingerprint. Compared with the existing dongle and other hardware lock authorization schemes, the authorization mode of the present scheme does not need to manufacture and carry hardware locks, and is more lightweight.

[0110] The above-described device is used to execute the method provided in the foregoing embodiments, and its implementation principle and technical effect are similar, so they will not be described again here.

[0111] These modules can be one or more integrated circuits configured to implement the above methods, such as one or more Application Specific Integrated Circuits (ASICs), one or more microprocessors, or one or more Field Programmable Gate Arrays (FPGAs). Alternatively, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a Central Processing Unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together as a system-on-a-chip (SOC).

[0112] Figure 10 A schematic diagram of the electronic device provided in the embodiments of this application, such as... Figure 10 As shown, the electronic device 700 may include a processor 701, a storage medium 702, and a bus. The storage medium 702 stores program instructions that can be executed by the processor 701. When the electronic device 700 is running, the processor 701 communicates with the storage medium 702 through the bus, and the processor 701 executes the program instructions to perform the above-described method embodiments.

[0113] Specifically, the steps of the processor executing the above-described service authorization method based on single-device fingerprints applied to the authorization management center may include: Obtain the single-device fingerprint information of the management server of the big data platform to be deployed; based on the single-device fingerprint information and the multi-dimensional authorization information for the big data platform, encrypt it using a pre-generated private key to generate an authorization file; send the authorization file to the management server, and the management server decrypts the authorization file using the public key corresponding to the private key; based on the decrypted single-device fingerprint information and multi-dimensional authorization information, perform authorization verification for the management server and multiple distributed servers of the management server for the big data platform, wherein the multiple distributed servers are used to deploy multiple service modules of the big data platform.

[0114] Optionally, the processor's steps of generating an authorization file by encrypting the single-device fingerprint information and multi-dimensional authorization information for the big data platform using a pre-generated private key may include: The single-device fingerprint-based service authorization method executed by the processor comprises the following steps: generating an original license file based on single-device fingerprint information and multi-dimensional authorization information of a management server of a big data platform to be deployed; signing the original license file by using a private key to generate a first signature value; and encoding the original license file and the first signature value by using a preset encoding mode to generate an authorization file.

[0115] The single-device fingerprint-based service authorization method executed by the processor comprises the following steps: generating an original license file based on single-device fingerprint information and multi-dimensional authorization information of a management server of a big data platform to be deployed; signing the original license file by using a private key to generate a first signature value; and encoding the original license file and the first signature value by using a preset encoding mode to generate an authorization file.

[0116] Specifically, the processor executes the steps of the single-device fingerprint-based service authorization method applied to the management server, which can comprise the following steps: obtaining an authorization file sent by an authorization management center of a big data platform management system, the authorization file being generated by the authorization management center by encrypting based on single-device fingerprint information of the management server and multi-dimensional authorization information of the big data platform by using a private key generated in advance; decrypting the authorization file by using a public key corresponding to the private key to obtain the single-device fingerprint information and the multi-dimensional authorization information; and performing authorization verification of the management server and a plurality of distributed servers of the management server for the big data platform based on the single-device fingerprint information and the multi-dimensional authorization information, wherein the plurality of distributed servers are used to deploy a plurality of service modules of the big data platform.

[0117] Optionally, the authorization file comprises an original license file and a first signature value, which are encoded by using a preset encoding mode, and the processor executes the process of decrypting the authorization file by using the public key corresponding to the private key to obtain the single-device fingerprint information and the multi-dimensional authorization information, which can comprise the following steps: decoding the authorization file by using a preset decoding mode; signing the decoded original license file by using the public key to obtain a second signature value; determining whether the first signature value and the second signature value match; and if the first signature value and the second signature value match, obtaining the single-device fingerprint information and the multi-dimensional authorization information from the original license file.

[0118] Optionally, the processor executes the step of performing authorization verification of the management server, which can comprise the following steps: determining whether the single-device fingerprint information of the management server is consistent with the single-device fingerprint information of the single device; if the single-device fingerprint information of the management server is consistent with the single-device fingerprint information of the single device, determining that the management server is authorized to use the big data platform; and if the single-device fingerprint information of the management server is not consistent with the single-device fingerprint information of the single device, determining that the management server cannot use the big data platform.

[0119] Optionally, the multi-dimensional authorization information includes a validity period, and the processor performing the step of authorizing and verifying the management server can include: determining whether the current system time meets the validity period; and if the current system time does not meet the validity period, shutting down the entry service of the big data platform.

[0120] Optionally, the multi-dimensional authorization information further includes at least one authorized service module of the big data platform, and the processor performing the step of authorizing and verifying the multiple distributed servers of the management server can include: deploying at least one authorized service module in the multiple distributed servers.

[0121] Optionally, the processor performing the step of the service authorization method based on the single-device fingerprint can further include: generating an authorized service view according to all service modules of the big data platform and the at least one authorized service module, the authorized service view being used to indicate service modules available to the user in the big data platform.

[0122] Optionally, the multi-dimensional authorization information further includes an authorized cluster size, and the processor performing the step of authorizing and verifying the multiple distributed servers of the management server can include: if an addition request sent by a new distributed server is received, determining whether the cluster size meets the authorized cluster size; and if the cluster size does not meet the authorized cluster size, rejecting the addition of the new distributed server.

[0123] The processor performing the service authorization method based on the single-device fingerprint determines whether the management server is authorized to run the big data platform and the authorization range based on the authorization file provided by the authorization management center, realizes targeted authorization for the management server, and independently and flexibly controls the fine-grained authorization of the big data platform, and realizes the all-around authorization management of the complete set of products of the big data platform through the single-device fingerprint. Compared with the existing authorization scheme of the hardware lock such as the dongle, the authorization mode of the present scheme does not need to manufacture and carry the hardware lock, and is more lightweight.

[0124] Optionally, the present application further provides a computer readable storage medium, and the storage medium stores a computer program, and the computer program is run by the processor to execute the method embodiment.

[0125] Specifically, the processor performing the steps of the single-device-fingerprint-based service authorization method applied to the authorization management center can include: Obtaining single-device-fingerprint information of a management server of a big data platform to be deployed; encrypting the single-device-fingerprint information and multi-dimensional authorization information for the big data platform using a pre-generated private key to generate an authorization file; and sending the authorization file to the management server, wherein the management server decrypts the authorization file using a public key corresponding to the private key, and performs authorization verification of the management server and multiple distributed servers of the management server for the big data platform based on the decrypted single-device-fingerprint information and multi-dimensional authorization information, wherein the multiple distributed servers are used to deploy multiple service modules of the big data platform.

[0126] Optionally, the processor performing the step of encrypting the single-device-fingerprint information and multi-dimensional authorization information for the big data platform using a pre-generated private key to generate an authorization file can include: Generating an original license file based on the single-device-fingerprint information and the multi-dimensional authorization information; signing the original license file using the private key to generate a first signature value; and encoding the original license file and the first signature value using a preset encoding method to generate the authorization file.

[0127] The single-device-fingerprint-based service authorization method performed by the processor generates an authorization file based on single-device-fingerprint information of a management server of a big data platform to be deployed and multi-dimensional authorization information, so that the management server verifies deployment and use of the big data platform in multiple distributed servers based on the authorization file, which can realize targeted authorization for the management server and autonomous and flexible control of fine-grained authorization of the big data platform, and achieve all-round authorization management of the entire set of products of the big data platform through single-device fingerprints. Compared with existing hardware lock authorization schemes such as dongles, the authorization method of the present scheme does not need to manufacture and carry hardware locks, and is more lightweight.

[0128] Specifically, the processor performing the steps of the single-device-fingerprint-based service authorization method applied to the management server can include: Obtaining an authorization file sent by an authorization management center of a big data platform management system, wherein the authorization file is generated by the authorization management center based on single-device-fingerprint information of the management server and multi-dimensional authorization information for the big data platform using a pre-generated private key; decrypting the authorization file using a public key corresponding to the private key to obtain the single-device-fingerprint information and the multi-dimensional authorization information; and performing authorization verification of the management server and multiple distributed servers of the management server for the big data platform based on the single-device-fingerprint information and the multi-dimensional authorization information, wherein the multiple distributed servers are used to deploy multiple service modules of the big data platform.

[0129] Optionally, the authorization file comprises: the original license file and the first signature value encoded by using a preset encoding mode, and the processor performs the process of decrypting the authorization file by using a public key corresponding to the private key to obtain the single-device fingerprint information and the multi-dimensional authorization information, which can comprise: decoding the authorization file by using a preset decoding mode; signing the decoded original license file by using the public key to obtain a second signature value; determining whether the first signature value and the second signature value match; and if the first signature value and the second signature value match, obtaining the single-device fingerprint information and the multi-dimensional authorization information from the original license file.

[0130] Optionally, the processor performs the step of authorizing and verifying the management server, which can comprise: determining whether the single-device fingerprint information is consistent with single-device fingerprint information of the management server; if the single-device fingerprint information is consistent with the single-device fingerprint information of the management server, determining that the management server is authorized to use the big data platform; and if the single-device fingerprint information is not consistent with the single-device fingerprint information of the management server, determining that the management server cannot use the big data platform.

[0131] Optionally, the multi-dimensional authorization information comprises: a validity period, and the processor performs the step of authorizing and verifying the management server, which can comprise: determining whether a current system time meets the validity period; and if the current system time does not meet the validity period, closing an entry service of the big data platform.

[0132] Optionally, the multi-dimensional authorization information further comprises: at least one authorized service module of the big data platform, and the processor performs the step of authorizing and verifying the multiple distributed servers of the management server, which can comprise: deploying at least one authorized service module in the multiple distributed servers.

[0133] Optionally, the processor performs the step of the service authorization method based on the single-device fingerprint, which can further comprise: generating an authorized service view according to all service modules of the big data platform and the at least one authorized service module, the authorized service view being used to indicate service modules available to a user in the big data platform.

[0134] Optionally, the multi-dimensional authorization information further comprises: an authorized cluster size, and the processor performs the step of authorizing and verifying the multiple distributed servers of the management server, which can comprise: if an addition request sent by a new distributed server is received, determining whether a cluster size meets the authorized cluster size; and if the cluster size does not meet the authorized cluster size, rejecting the addition of the new distributed server.

[0135] The single-device-fingerprint-based service authorization method executed by the processor determines whether the management server is authorized to run the big data platform and the authorization range based on the authorization file provided by the authorization management center, realizes targeted authorization for the management server, and independently and flexibly controls the fine authorization of the big data platform, and realizes the all-round authorization management of the whole set of products of the big data platform through the single-device fingerprint. Compared with the existing dongle and other hardware lock authorization scheme, the authorization mode of the present scheme does not need to manufacture a hardware lock, and is more lightweight.

[0136] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. For example, the above-described apparatus embodiments are merely schematic. Taking the division of the units as an example, the division can be a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.

[0137] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.

[0138] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware, or in the form of hardware plus software function unit.

[0139] The integrated unit realized in the form of software function unit can be stored in a computer readable storage medium. The software function unit stored in a storage medium includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute part of the steps of the method described in each embodiment of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (English: Read-Only Memory, abbreviated as: ROM), a random access memory (English: Random Access Memory, abbreviated as: RAM), a magnetic disk or an optical disk, and various program code storage media.

[0140] The above merely provides the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of the changes or replacements within the technical scope disclosed by the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A single device fingerprint based service authorization method, characterized by, The application discloses an authorization management center applied to a big data platform management system, and a method thereof. Obtaining single-device fingerprint information of a management server of the big data platform to be deployed; According to the single-device fingerprint information and multi-dimensional authorization information of the big data platform, a pre-generated private key is used for encryption to generate an authorization file; The authorization file is sent to the management server, and the management server uses a public key corresponding to the private key to decrypt the authorization file, and according to the decrypted single-device fingerprint information and multi-dimensional authorization information, the management server and multiple distributed servers of the management server are authorized and verified for the big data platform, wherein the multiple distributed servers are used for deploying multiple service modules of the big data platform.

2. The method of claim 1, wherein, According to the single-device fingerprint information and multi-dimensional authorization information of the big data platform, a pre-generated private key is used for encryption to generate an authorization file, including: Generating an original license file according to the single-device fingerprint information and the multi-dimensional authorization information; Using the private key to sign the original license file to generate a first signature value; According to the original license file and the first signature value, a preset encoding mode is used for encoding to generate the authorization file.

3. A single device fingerprint based service authorization method, characterized by, The application discloses a management server applied to a big data platform management system, and a method thereof. Obtaining an authorization file sent by an authorization management center of the big data platform management system, wherein the authorization file is generated by the authorization management center according to single-device fingerprint information of the management server and multi-dimensional authorization information of the big data platform, and using a pre-generated private key for encryption; Using a public key corresponding to the private key to decrypt the authorization file to obtain the single-device fingerprint information and the multi-dimensional authorization information; According to the single-device fingerprint information and the multi-dimensional authorization information, the management server and multiple distributed servers of the management server are authorized and verified for the big data platform, wherein the multiple distributed servers are used for deploying multiple service modules of the big data platform.

4. The method of claim 3, wherein, The authorization file includes an original license file encoded by a preset encoding mode and a first signature value, and using the public key corresponding to the private key to decrypt the authorization file to obtain the single-device fingerprint information and the multi-dimensional authorization information includes: Using a preset decoding mode to decode the authorization file; Using the public key to sign the decoded original license file to obtain a second signature value; Determining whether the first signature value and the second signature value match; If the first signature value and the second signature value match, the single-device fingerprint information and the multi-dimensional authorization information are obtained from the original license file.

5. The method of claim 3, wherein, The authorization verification on the management server includes: Determining whether the single-device fingerprint information is consistent with single-device fingerprint information of the management server; If the single-device fingerprint information is consistent with the single-device fingerprint information of the management server, it is determined that the management server is authorized to use the big data platform. If the single-device fingerprint information is inconsistent with the single-device fingerprint information of the management server, it is determined that the management server cannot use the big data platform.

6. The method of claim 3, wherein, The multi-dimensional authorization information further includes an authorized cluster size, and the authorization verification on the multiple distributed servers of the management server includes: If an addition request sent by a new distributed server is received, it is determined whether the cluster size meets the authorized cluster size; If the cluster size does not meet the authorized cluster size, the new distributed server is rejected.

7. A single device fingerprint based service authorization apparatus, characterized by, An authorization management center applied to a big data platform management system, the device includes: An information acquisition module configured to acquire single-device fingerprint information of a management server to be deployed with the big data platform; An authorization file generation module configured to generate an authorization file by encrypting the single-device fingerprint information and multi-dimensional authorization information for the big data platform using a pre-generated private key; An authorization file sending module configured to send the authorization file to the management server, and the management server decrypts the authorization file using a public key corresponding to the private key, and performs authorization verification on the management server and multiple distributed servers of the management server for deployment and use of the big data platform according to the decrypted single-device fingerprint information and multi-dimensional authorization information, wherein the multiple distributed servers are configured to deploy multiple service modules of the big data platform.

8. A single device fingerprint based service authorization apparatus, characterized by, A management server applied to a big data platform management system, the device includes: An authorization file receiving module configured to acquire an authorization file sent by an authorization management center of the big data platform management system, the authorization file being generated by the authorization management center by encrypting single-device fingerprint information of the management server and multi-dimensional authorization information for the big data platform using a pre-generated private key; An authorization file decryption module configured to decrypt the authorization file using a public key corresponding to the private key to acquire the single-device fingerprint information and the multi-dimensional authorization information; An authorization verification module configured to perform authorization verification on the management server and multiple distributed servers of the management server for deployment and use of the big data platform according to the single-device fingerprint information and the multi-dimensional authorization information, wherein the multiple distributed servers are configured to deploy multiple service modules of the big data platform.

9. An electronic device, comprising: includes: A processor, a storage medium, and a bus, the storage medium storing program instructions executable by the processor, when the electronic device is running, the processor and the storage medium communicate through the bus, and the processor executes the program instructions to perform the steps of the single-device fingerprint-based service authorization method according to any one of claims 1 to 6.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to perform the steps of the single-device fingerprint-based service authorization method according to any one of claims 1 to 6.