Authorization authentication method, system, device, medium and program product

By using a secondary authorization authentication method combining hardware fingerprints and authorization codes, the problems of easy cracking of existing software authorization authentication and easy damage of hardware locks are solved, achieving higher security and reliability of authorization authentication and improving user experience.

CN121530684APending Publication Date: 2026-02-13CHINA MOBILE (XIONGAN) ICT CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511743749.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-25
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing software licensing and authentication methods have the problem that they can be cracked and reused an unlimited number of times, while hardware locks are costly, easily damaged, and affect user experience.

Method used

A two-stage authentication method using hardware fingerprints and authorization codes is adopted. A hardware fingerprint is generated by a fingerprint generator and an encrypted authorization code is generated by combining weight parameters. This two-stage authentication improves security and reliability.

Benefits of technology

It improves the security and reliability of authorization and authentication, prevents unauthorized copying and execution, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530684A_ABST
    Figure CN121530684A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an authorization authentication method, system and device, a medium and a program product. Comprising the steps that a fingerprint generator generates a hardware fingerprint based on a weight parameter requested and stored from an authorization center by an application server and a hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center for storage and registration; the authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, generates an encryption authorization code based on the obtained weight parameter and the dynamic encryption and decryption device after the first authorization authentication is passed, and sends the encryption authorization code to the application server; when the application server needs to be subjected to secondary authentication, the encrypted authorization code is sent to an authorization center; and the authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint. The security and reliability of authorization authentication are improved, and the user service experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security authentication, and particularly relates to an authorization authentication method, system, device, medium and program product. BACKGROUND

[0002] With the development of information technology, information service has become an indispensable tool in various industries. Especially in the fields of government and enterprise digitization, more and more service programs are deployed on the servers of customer systems. However, the problem of illegal use of software has been plaguing software developers.

[0003] In order to reduce the illegal use of software services, the current authorization sequence number, hardware lock or sequence number generated based on server hardware information (i.e. machine fingerprint) is often used. When the software starts, the user is allowed to use the software only when the sequence number or hardware lock matches.

[0004] However, whether it is a machine fingerprint sequence number generated based on hardware information or a separate authorization sequence number generated independently, no secondary encryption authentication is performed. Once cracked or leaked, it can be copied and used infinitely. Although the authorization protection based on hardware lock provides relatively high security, the hardware lock is high in cost and needs to be physically carried, and it is easy to be lost or damaged. Once the hardware lock is damaged, the device needs to be replaced, which will cause the user to be unable to use the software during the period, seriously affecting the user experience. SUMMARY

[0005] The embodiments of the present application provide an authorization authentication method, system, device, medium and program product, which combines more dimensions of server hardware information with only a single weight parameter provided to the server end, and performs secondary authorization authentication of the hardware fingerprint and the authorization code when the application server needs to be authorized to start, thereby improving the security and reliability of the authentication, preventing illegal copying and running of the provided service, and improving the user service experience.

[0006] In a first aspect, the embodiments of the present application provide an authorization authentication method applied to an authorization authentication system, the authorization authentication system including an application server, a fingerprint generator, an authorization center and a dynamic encryption and decryption device; the method includes:

[0007] The fingerprint generator generates a hardware fingerprint based on the weight parameter requested and stored by the application server to the authorization center and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center for storage and registration, respectively;

[0008] The authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, and generates and sends an encrypted authorization code to the application server based on the weight parameter obtained by the application server and the dynamic encryption and decryption device after the first authorization authentication is passed.

[0009] The encrypted authorization code is sent to the authorization center when the application server needs to perform secondary authentication.

[0010] The authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint.

[0011] In a second aspect, the embodiments of the present application also provide an authorization authentication system, comprising: an application server, a fingerprint generator, an authorization center and a dynamic encryption and decryption device.

[0012] The fingerprint generator generates a hardware fingerprint in response to the received weight parameter requested and stored by the application server to the authorization center and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center respectively.

[0013] The application server is configured to store the hardware fingerprint, and send the hardware fingerprint to the authorization center for first authorization authentication.

[0014] The authorization center is configured to register the hardware fingerprint, and perform first authorization authentication based on the hardware fingerprint sent by the application server and the registered hardware fingerprint, and generate and send an encrypted authorization code to the application server based on the weight parameter obtained by the application server and the dynamic encryption and decryption device after the first authorization authentication is passed.

[0015] The application server is further configured to send the encrypted authorization code to the authorization center when secondary authentication is needed.

[0016] The authorization center is further configured to decrypt the encrypted authorization code through the dynamic encryption and decryption device, and perform second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint.

[0017] In a third aspect, the embodiments of the present application also provide an authorization authentication device, comprising:

[0018] At least one processor; and a memory connected with the at least one processor in communication;

[0019] The memory stores a computer program which can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to implement the authorization authentication method of any embodiment of the present application.

[0020] In a fourth aspect, the embodiments of the present application further provide a storage medium containing computer executable instructions for executing the authorization authentication method of any of the embodiments of the present application when executed by a computer processor.

[0021] In a fifth aspect, the embodiments of the present application further provide a computer program product comprising a computer program for executing the authorization authentication method of any of the embodiments of the present application when executed by a processor.

[0022] The authorization authentication method, system, device, medium and program product provided by the embodiments of the present application are applied to an authorization authentication system, the authorization authentication system comprising an application server, a fingerprint generator, an authorization center and a dynamic encryption and decryption device; the method comprises: the fingerprint generator generates a hardware fingerprint based on the weight parameter requested and stored by the application server to the authorization center and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center for storage and registration respectively; the authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, and after the first authorization authentication passes, generates an encrypted authorization code based on the weight parameter obtained by the application server and the dynamic encryption and decryption device and sends the encrypted authorization code to the application server; when the application server needs to perform secondary authentication, the encrypted authorization code is sent to the authorization center; the authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint. By adopting the above technical solution, the weight parameter generated by the authorization center and only saved by the application server, and the server hardware information are introduced into the process of authorization authentication, first, the authorization authentication based on the weight parameter and the server hardware information is performed to generate a hardware fingerprint, and after the first authentication passes, the authorization code required for secondary authorization authentication is constructed based on the weight parameter and the hardware fingerprint, so that the application server can perform the corresponding secondary authorization authentication operation when needed. Since the server hardware information used in the process and the weight parameter saved by the application server only once are both information specific to the application server, they have higher security, and the way of dividing the authorization authentication into two stages can further improve the security and reliability of the authentication, prevent illegal copying and running of the provided service, and improve the user service experience.

[0023] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description only show some embodiments of the present application, and other drawings can be obtained by those of ordinary skill in the art without any creative effort based on these drawings.

[0025] Figure 1 A flow chart of an authorization authentication method provided for the first embodiment of the present application is shown in FIG. 2.

[0026] Figure 2 A flow chart of an authorization authentication method provided for the second embodiment of the present application is shown in FIG. 3.

[0027] Figure 3 A structural schematic diagram of an authorization authentication system provided for the third embodiment of the present application is shown in FIG. 4.

[0028] Figure 4 A structural schematic diagram of an authorization authentication device provided for the fourth embodiment of the present application is shown in FIG. 5. DETAILED DESCRIPTION

[0029] In order to make the person skilled in the art better understand the present application, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without any creative effort should be within the scope of protection of the present application.

[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0031] Embodiment one

[0032] Figure 1A flowchart of an authorization authentication method provided for the first embodiment of the present application, the embodiment of the present application can be applied to authorization authentication of a service program configured in a user server in an information service, so as to avoid illegal theft of software. The method can be executed by an authorization authentication system, the authorization authentication system includes an application server, a fingerprint generator, an authorization center and a dynamic encryption / decryption device, the authorization authentication system can be realized by software and / or hardware, and the authorization authentication system can be configured in an authorization authentication device. Optionally, the authorization authentication device can be a notebook computer, a desktop computer, a server and a server cluster, and the embodiment of the present application does not limit this.

[0033] In the embodiment, the authorization authentication system can be specifically understood as a system integrated in the authorization authentication device, which is used to provide authorization authentication for the service software configured in the authorization authentication device, so as to determine whether the software needing to provide services is in an abnormal state of being stolen, and to ensure that the service software is indeed in a service providing scene, and then to safely and effectively start the system.

[0034] In the embodiment, the application server can be specifically understood as a local server in the authorization authentication device for carrying the software needed to provide services. It can be understood that the application server can be a server owned by a user who purchases the software needed to start the service, or a server rented by a user who purchases the software needed to start the service, which is different from the geographical location of the user, and the embodiment of the present application does not limit this.

[0035] In the embodiment, the fingerprint generator can be specifically understood as a tool or algorithm integrated in the authorization authentication system, which is used to generate a unique identifier of the device or the user. It can generate a string with uniqueness based on the same input content for subsequent verification or identification.

[0036] In the embodiment, the authorization center can be specifically understood as a module integrated in the authorization authentication system, which is used to uniformly manage permission allocation, verify authorization legality and manage resource access rights.

[0037] In the embodiment, the dynamic encryption / decryption device can be specifically understood as a tool integrated in the authorization authentication system, which can adjust the encryption / decryption logic of the input data in real time according to the dynamic conditions. In the embodiment of the present application, the dynamic encryption / decryption device is mainly used for generating and decrypting the authorization code in the second authorization authentication process.

[0038] As shown in FIG. 1, Figure 1 The authorization authentication method provided by the embodiment of the present application specifically includes the following steps:

[0039] S101, the fingerprint generator generates a hardware fingerprint based on the weight parameter requested and stored by the application server to the authorization center and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center respectively for storage and registration.

[0040] In the embodiment, the weight parameter can be specifically understood as a parameter combination randomly generated by the authorization center in response to the request of the application server and sent to the application server. It can be understood that the weight parameter generated by the authorization center each time is different and will not be saved, so the weight parameter obtained by the application server has uniqueness in the whole authorization authentication process.

[0041] In the embodiment, the hardware parameter can be specifically understood as a parameter information that can be used to assist in identifying the identity of the application server based on the hardware characteristics of the application server. For example, the hardware parameter can include the mainboard serial number, the hard disk serial number, the central processing unit (CPU) serial number, the media access control (MAC) address, etc., which is not limited in the embodiment of the application.

[0042] In the embodiment, the hardware fingerprint can be specifically understood as a unique string of characters generated based on the unique characteristics of the hardware device to uniquely identify the hardware identity, which can be understood in the embodiment of the application as information generated based on the uniquely determined weight parameter and the hardware parameter of the application server to uniquely represent the identity of the application server.

[0043] Specifically, when the application server needs to authorize and authenticate the service therein to start, it will first request a randomly generated weight parameter from the authorization center. After receiving the weight parameter, the application server will save the weight parameter for subsequent use, and will send the weight parameter and the hardware parameter of the hardware of the application server to the fingerprint generator at the same time, and the fingerprint generator will generate a hardware fingerprint based on the weight parameter and the hardware parameter uniquely determined by the fingerprint generation algorithm. The fingerprint generator sends the hardware fingerprint to the application server for storage for subsequent authorization authentication, and sends the hardware fingerprint to the authorization center for registration, so that the authorization center can clearly identify the information of the application server that can be authorized, and support subsequent authorization authentication based on the hardware fingerprint.

[0044] S102, the authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, and after the first authorization authentication passes, generates an encrypted authorization code based on the weight parameter obtained by the application server and the dynamic encryption and decryption device and sends it to the application server.

[0045] In the embodiment, the first authorization authentication can be understood as an authorization authentication based on whether the hardware fingerprint provided by the application server matches the registered hardware fingerprint in the authorization center. The encrypted authorization code can be understood as an authorization credential for verifying the legal use right of the user or the device to the software, service or resource, which is obtained by encrypting the key information related to the authorization.

[0046] Specifically, the authorization center performs the first authorization authentication based on the hardware fingerprint sent by the application server and the registered hardware fingerprint stored by the authorization center. When the first authorization authentication is passed, it can be preliminarily considered that the application server at least belongs to the device registered to the authorization center at the hardware level, and the subsequent authorization authentication operation can be continued. At this time, the authorization center can obtain the weight parameter used to uniquely generate the hardware fingerprint of the application server from the application server, and obtain the encrypted authorization code by encrypting the weight parameter and other key information related to the authorization by the dynamic encryption and decryption device, and send the encrypted authorization code back to the application server for use by the application server when the second authorization authentication is needed.

[0047] In the embodiment of the application, since the hardware fingerprint of the application server is generated based on the unique weight parameter and the hardware parameter, the weight parameter is included in the encrypted authorization code for the second authorization authentication, so that when the service set in the application server is stolen, the service cannot be reproduced due to the inability to determine the weight parameter used to generate the encrypted authorization code, and the service cannot pass the subsequent second authorization authentication, thereby improving the security and reliability of the authentication.

[0048] S103, when the application server needs to perform secondary authentication, the encrypted authorization code is sent to the authorization center.

[0049] In the embodiment, the timing of the secondary authentication of the application server can be understood as the timing of the authorization authentication that the application server needs to start or maintain the normal operation of the service started in the application server and needs to perform again to the authorization center. Optionally, the timing of the secondary authentication includes at least one of the following: when the application server is started for the first time; when the application server is started and reaches a preset time period.

[0050] Specifically, after receiving the encrypted authorization code, the application server will save the encrypted authorization code, and when it is determined that the service to be started needs to be authenticated twice, the application server will send the encrypted authorization code to the authorization center to initiate the second authorization authentication. The timing of the application server initiating the second authentication can be when the service is started for the first time, and the service can be normally started only after completing the two authorization authentications. After the service has been normally started, in order to ensure the continuous security of the service, the service can be periodically authenticated for the second time, that is, when the application server is started and reaches a preset time period, it is considered that the timing of the second authentication is reached, and the application server initiates the second authorization authentication to the authorization center.

[0051] In S104, the authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs the second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint.

[0052] Specifically, the authorization center decrypts the received encrypted authorization code through the dynamic encryption and decryption device to obtain the decrypted encrypted authorization code. Since the hardware parameters of the application server are already included in the fingerprint generator, the hardware fingerprint can be generated according to the weight parameters included in the decrypted encrypted authorization code and the hardware parameters of the hardware fingerprint generator, and then the generated hardware fingerprint is compared with the registered hardware fingerprint, and the second authorization authentication is completed together with other parameters in the decrypted encrypted authorization code.

[0053] The technical scheme of the embodiment is applied to an authorization authentication system, and the authorization authentication system comprises an application server, a fingerprint generator, an authorization center and a dynamic encryption and decryption device. The method comprises the following steps: the fingerprint generator generates a hardware fingerprint based on weight parameters requested and stored by the application server from the authorization center and hardware parameters of the application server, and sends the hardware fingerprint to the application server and the authorization center for storage and registration; the authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, and generates an encrypted authorization code based on the weight parameters obtained by the application server and the dynamic encryption and decryption device and sends the encrypted authorization code to the application server after the first authorization authentication is passed; when the application server needs to perform secondary authentication, the encrypted authorization code is sent to the authorization center; the authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint. By adopting the above technical scheme, the weight parameters generated by the authorization center and only saved by the application server and the server hardware information are introduced into the authorization authentication process, first, the authorization authentication based on the weight parameters and the server hardware information is performed to generate the hardware fingerprint, and after the first authentication is passed, the authorization code required for the secondary authorization authentication is constructed based on the weight parameters and the hardware fingerprint, so that the application server can perform the corresponding secondary authorization authentication operation when needed. Since the server hardware information used in the process and the weight parameters saved by the application server are only issued once, the information is specific to the application server, has higher security, and the two-stage authorization authentication mode can further improve the security and reliability of the authentication, prevent illegal copying and running of the provided service, and improve the user service experience.

[0054] Embodiment two

[0055] Figure 2 The flowchart of the authorization authentication method provided by the second embodiment of the application is based on the above optional technical schemes, and further optimized. After the generation and registration of the hardware fingerprint are completed, the authorization center compares the hardware fingerprint sent by the application server with the registered hardware fingerprint to realize first authorization authentication. In the case where the first authorization authentication is passed, more parameter information capable of indicating the identity information of the application server, a random code for improving the randomness of the generation of the authorization code, and an expiration time for increasing the time validity of the authorization code are introduced in the secondary authentication process to generate an encrypted authorization code through dynamic encryption, and the subsequent second authorization authentication is completed based on the encrypted authorization code. This process not only strengthens the identity verification of the application server, but also further improves the security and reliability of the authorization authentication due to the dynamic nature of the encrypted authorization code and the unique and non-reproducible characteristics of the weight parameters in the entire system.

[0056] AsFigure 2 As shown, the authorization authentication method provided by the second embodiment of the present application specifically comprises the following steps:

[0057] S201, the fingerprint generator generates a hardware fingerprint based on the weight parameter requested and stored by the application server and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center for storage and registration respectively.

[0058] S202, the authorization center compares the hardware fingerprint sent by the application server with the registered hardware fingerprint.

[0059] Specifically, since the hardware fingerprint is usually a serial number or other string representation with uniqueness, and has been registered to the authorization center by the fingerprint generator after generation, when the authorization center receives the hardware fingerprint sent by the application server, it can be considered that the application server requests to perform the first authorization authentication, at this time the authorization center will compare the hardware fingerprint sent by the application server with the registered hardware fingerprint, if there is a consistent hardware fingerprint in the registered hardware fingerprint, the comparison result can be considered as comparison success, otherwise as comparison failure.

[0060] S203, it is judged whether the comparison result is comparison success, if yes, S204 is executed; otherwise, S213 is executed.

[0061] Specifically, the authorization center judges whether the comparison result is comparison success, if yes, it can be considered that the first authorization authentication of the application server is passed, and has the condition to perform the subsequent second authorization authentication, at this time S204 is executed; otherwise, it can be considered that the first authorization authentication of the application server is not passed, and there may be illegal misuse of the service, at this time S213 is executed.

[0062] S204, it is determined that the first authorization authentication is passed, the authorization center generates a random code and an expiration time, and sends the random code, the expiration time, the weight parameter obtained by the application server and the registered hardware fingerprint to the dynamic encryption and decryption device as authorization plaintext.

[0063] In this embodiment, the expiration time can be understood as the authorization validity period of the application server set in advance according to the actual situation.

[0064] Specifically, the authorization center will prepare for the second authorization authentication of the application server after determining that the first authorization authentication is passed. At this time, the authorization center will request the unique weight parameter stored in the application server as part of the content for generating the authorization code, and the authorization center will also generate a random code for generating the authorization code and generate an expiration time of the authorized time assigned to the authorization code in order to improve the security of the authorization code for the second authorization authentication. Then the generated random code, expiration time, obtained weight parameter and registered hardware fingerprint corresponding to the application server in the authorization center are sent to the dynamic encryption and decryption device as the authorization plaintext that needs to be encrypted.

[0065] S205, the dynamic encryption and decryption device encrypts the authorization plaintext and sends the generated encrypted authorization code to the authorization center.

[0066] Specifically, the dynamic encryption and decryption device encrypts the authorization plaintext based on the dynamically generated key pair to obtain the encrypted authorization code, and feeds back the encrypted authorization code to the authorization center. It can be understood that the dynamic encryption and decryption device can perform one or more encryptions when encrypting the authorization plaintext. The number of generated key pairs is consistent with the number of encryptions, and the generated key pairs will be put into the key pool for subsequent decryption.

[0067] Optionally, in order to further improve the security of the system, the dynamic encryption and decryption device can adopt twice encryption when encrypting the authorization plaintext, that is, after the first encryption, a different key or algorithm is applied for secondary encryption to further enhance the security level of the encrypted authorization code and improve the difficulty of unauthorized decryption. Taking twice encryption as an example, the dynamic encryption and decryption device encrypts the authorization plaintext, including:

[0068] The dynamic encryption and decryption device generates a first key pair and encrypts the authorization plaintext by using the first private key in the first key pair to determine a first ciphertext;

[0069] The dynamic encryption and decryption device generates a second key pair, assembles the first ciphertext and the first public key in the first key pair into a new plaintext, encrypts the new plaintext by using the second private key in the second key pair to determine the encrypted authorization code;

[0070] Among them, the algorithm parameters of the first key pair and the second key pair, and the second public key in the second key pair will be registered in the key pool after being generated.

[0071] Specifically, since the dynamic encryption and decryption device is composed of an encryptor, a decryptor and a key pool, in the encryption process, in the case that two encryption operations are required, a random key pair containing a public key and a private key is generated in each encryption, that is, corresponding to the first key pair and the second key pair, and the key pool is responsible for storing these generated key pairs for subsequent use. In the encryption process, the authorization plaintext received by the authorization center based on the first private key in the generated first key pair is first encrypted to obtain the first ciphertext. Further, the first ciphertext and the first public key in the first key pair which can be used to decrypt the first ciphertext are assembled into a new plaintext, and the new plaintext is encrypted by the second private key in the second key pair, and the ciphertext obtained by the encryption is determined as the encrypted authorization code.

[0072] It can be understood that since the algorithm parameters of the first key pair and the second key pair, and the second public key in the second key pair are all registered in the key pool after generation, the authorization center can directly decrypt the received encrypted authorization code through the dynamic encryption and decryption device in the subsequent second authorization authentication process, and if the received encrypted authorization code cannot be decrypted through the dynamic encryption and decryption device, it itself reflects that the encrypted authorization code sent by the application server is abnormal, that is, the application server may be mismatched, at this time, it can be directly determined that the second authorization authentication is not passed.

[0073] S206, the authorization center sends the encrypted authorization code to the application server.

[0074] Specifically, the authorization center sends the encrypted authorization code to the application server, so that the application server has the ability to perform the second authorization authentication, and can initiate the second authorization authentication to the authorization center according to the received encrypted authorization code when secondary authentication is required.

[0075] S207, when the application server requires secondary authentication, the encrypted authorization code is sent to the authorization center.

[0076] S208, the authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device to determine the decrypted encrypted authorization code.

[0077] Specifically, the authorization center sends the encrypted authorization code received in the second authorization authentication process to the dynamic encryption and decryption device, and the dynamic encryption and decryption device performs the decryption operation opposite to the above S205 based on the key pool therein to obtain the decrypted encrypted authorization code.

[0078] S209, determining the to-be-verified weight parameter, the to-be-verified random code, the registered hardware fingerprint and the expiration time based on the decrypted encrypted authorization code.

[0079] Specifically, since the encrypted authorization code contains the random code, the expiration time, the weight parameter and the registered hardware fingerprint in the authorization plaintext when being constructed, the contents contained in the decrypted encrypted authorization code should also be consistent with the authorization plaintext after being decrypted. At this time, the weight parameter obtained by decryption can be used as the to-be-verified weight parameter, the random code obtained by decryption can be used as the to-be-verified random code, and the registered hardware fingerprint and the expiration time contained therein can be directly obtained.

[0080] S210, sending the to-be-verified weight parameter to the fingerprint generator and receiving the to-be-verified fingerprint returned by the fingerprint generator.

[0081] Specifically, since the weight parameter is only generated when the application server requests the authorization center for the first time and is only stored in the application server, it has high specificity. At the same time, when the fingerprint generator generates the hardware fingerprint, it will also be based on the hardware parameters and the weight parameter of the application server. When the weight parameter is different, the same hardware fingerprint as the application server registered in the authorization center for the first time cannot be generated. Therefore, when the application server is authorized and authenticated for the second time according to the to-be-verified weight parameter, the to-be-verified weight parameter can be sent to the fingerprint generator, so that the fingerprint generator can generate the hardware fingerprint based on the hardware parameters of the application server and the to-be-verified weight parameter, and send the generated hardware fingerprint to the authorization center as the to-be-verified fingerprint.

[0082] S211, comparing the to-be-verified fingerprint with the registered hardware fingerprint, the to-be-verified random code with the random code pool, and the expiration time with the verification time, and determining that the second authorization authentication is passed when the comparison is successful, and performing S212; otherwise, performing S213.

[0083] In this embodiment, the random code pool can be specifically understood as a number pool composed of the generated random codes in the authorization center.

[0084] In this embodiment, the verification time can be specifically understood as the time when the second authorization authentication occurs. If the verification time is earlier than the expiration time, it can be considered that the encrypted authorization code sent by the application server is still valid at the time of the second authorization authentication.

[0085] Specifically, the authorization center compares the to-be-verified fingerprint with the registered hardware fingerprint, and if they are consistent, it is considered that the application server is indeed the application server initially registered with the authorization center; the to-be-verified random code is compared with the random code pool, and if the to-be-verified random code exists in the random code pool, it is considered that the encrypted authorization code is indeed the encrypted authorization code generated and sent by the authorization center to the application server; the expiration time in the decrypted encrypted authorization code is compared with the verification time at the present, and if the verification time does not exceed the expiration time, it is considered that the comparison is successful, that is, it is still within the authorized validity period. When all the above comparisons are successful, it is considered that the second authorization authentication is passed, and S212 is performed; when any of the above comparisons is not successful, it is considered that the second authorization authentication is not passed, and S213 is performed.

[0086] S212, starting the service in the application server or keeping the service in the application server started.

[0087] Specifically, when the service in the application server is started for the first time, the starting of the service is completed after the second authorization authentication is passed; when the service in the application server has been started, only when the periodic authentication is performed, the starting of the service in the application server is kept after the second authorization authentication is passed.

[0088] S213, determining that the authorization authentication is not passed, and not starting the service in the application server or terminating the service running in the application server.

[0089] Specifically, in the case that any authorization authentication is not passed, the service in the application server should be terminated, that is, when the service in the application server needs to be started for the first time, the starting operation is not performed; and when the service in the application server has been started, only when the periodic authentication is performed, the service running in the application server should be terminated to ensure the safety of the service running.

[0090] The technical scheme of the embodiment, after the generation and registration of the hardware fingerprint are completed, the authorization center compares the hardware fingerprint sent by the application server with the registered hardware fingerprint, to realize the first authorization authentication. In the case that the first authorization authentication is passed, to improve the security of the authorization authentication, more parameter information capable of single indicating the identity information of the application server, a random code for improving the randomness of the authorization code, and an expiration time for adding time validity to the authorization code are introduced in the secondary authentication process, an encrypted authorization code is generated through dynamic encryption, and the subsequent second authorization authentication is completed based on the encrypted authorization code. This process not only strengthens the identity verification of the application server, but also further improves the security and reliability of the authorization authentication due to the dynamic nature of the encrypted authorization code and the unique and non-reproducible characteristics of the weight parameters contained in the encrypted authorization code in the entire system.

[0091] Embodiment Three

[0092] Figure 3 A structural schematic diagram of an authorization authentication system provided for Embodiment Three of the present application is shown in the figure, which includes an application server 31, a fingerprint generator 32, an authorization center 33 and a dynamic encryption and decryption device 34. Figure 3

[0093] The fingerprint generator 32 generates a hardware fingerprint in response to the received weight parameter requested and stored by the application server 31 to the authorization center 33 and the hardware parameter of the application server 31, and sends the hardware fingerprint to the application server 31 and the authorization center 33 respectively; the application server 31 is configured to store the hardware fingerprint and send the hardware fingerprint to the authorization center 33 for first authorization authentication; the authorization center 33 is configured to register the hardware fingerprint and perform first authorization authentication based on the hardware fingerprint sent by the application server 31 and the registered hardware fingerprint, and after the first authorization authentication passes, generate an encrypted authorization code based on the weight parameter obtained by the application server 31 and the dynamic encryption and decryption device 34 and send the encrypted authorization code to the application server 31; the application server 31 is further configured to send the encrypted authorization code to the authorization center 33 when secondary authentication is required; and the authorization center 33 is further configured to decrypt the encrypted authorization code through the dynamic encryption and decryption device 34, and perform second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint.

[0094] The technical scheme of the embodiment of the present application introduces the weight parameter generated by the authorization center and only saved by the application server and the server hardware information into the authorization authentication process, first performs authorization authentication based on the weight parameter and the server hardware information to generate a hardware fingerprint, and after the first authentication passes, constructs an authorization code required for secondary authorization authentication based on the weight parameter and the hardware fingerprint, so that the application server can perform corresponding secondary authorization authentication operation when required. Since the server hardware information used in the process and the weight parameter saved by the application server are only issued once, both of which are specific information of the application server, they have higher security, and the two-stage authorization authentication mode can further improve the security and reliability of the authentication, prevent illegal copying and running of the provided service, and improve the user service experience.

[0095] Optionally, the authorization center 33 is specifically configured to: compare the hardware fingerprint sent by the application server 31 with the registered hardware fingerprint; if the comparison result is a comparison success, it is determined that the first authorization authentication passes; otherwise, it is determined that the first authorization authentication fails.

[0096] ​Optionally, the authorization center 33 is further configured to: generate the random code and the expiration time, send the random code, the expiration time, the weight parameter obtained by the application server 31 and the registered hardware fingerprint as the authorization plaintext to the dynamic encryption and decryption device 34, and send the encrypted authorization code received by the dynamic encryption and decryption device 34 to the application server 31.

[0097] Optionally, the dynamic encryption and decryption device 34 is configured to: encrypt the authorization plaintext, and send the generated encrypted authorization code to the authorization center 33.

[0098] Optionally, the encryption of the authorization plaintext comprises:

[0099] generating a first key pair, encrypting the authorization plaintext by a first private key in the first key pair to determine a first ciphertext;

[0100] generating a second key pair, assembling the first ciphertext and a first public key in the first key pair as a new plaintext, encrypting the new plaintext by a second private key in the second key pair to determine the encrypted authorization code;

[0101] wherein algorithm parameters of the first key pair and the second key pair, and a second public key in the second key pair are registered in a key pool after being generated.

[0102] Optionally, the authorization center 33 is configured to:

[0103] determining the weight parameter to be verified, the random code to be verified, the registered hardware fingerprint and the expiration time based on the decrypted encrypted authorization code;

[0104] sending the weight parameter to be verified to the fingerprint generator, and receiving the fingerprint to be verified returned by the fingerprint generator 32;

[0105] comparing the fingerprint to be verified with the registered hardware fingerprint, the random code to be verified with the random code pool, and the expiration time with the verification time, and determining that the second authorization authentication is passed when the comparison is all successful.

[0106] Optionally, after the second authorization authentication is passed, the method further comprises:

[0107] starting the service in the application server 31 or keeping the service in the application server 31 started;

[0108] wherein the timing of the secondary authentication comprises at least one of:

[0109] when the application server 31 is started for the first time;

[0110] when the application server 31 is started and reaches a preset time period.

[0111] The authorization authentication system provided by the embodiments of the present application can execute the authorization authentication method provided by any of the embodiments of the present application, and has the function modules and beneficial effects corresponding to the execution method.

[0112] Embodiment Four

[0113] Figure 4 A structural schematic diagram of an authorization authentication device provided by Embodiment Four of the present application. The authorization authentication device 40 can be intended to represent various forms of digital computers, such as laptops, desktops, workstations, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The authorization authentication device 40 can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices (such as headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.

[0114] As shown in Figure 4 The authorization authentication device 40 includes at least one processor 41, and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41, wherein the memory stores a computer program executable by the at least one processor. The processor 41 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or loaded from the storage unit 48 into the random access memory (RAM) 43. In the RAM 43, various programs and data required for the operation of the authorization authentication device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other through a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0115] A plurality of components in the authorization authentication device 40 are connected to the I / O interface 45, including: an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the authorization authentication device 40 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunications networks.

[0116] The processor 41 can be various general and / or special purpose processing components having processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 performs various methods and processes described above, such as the authorization authentication method.

[0117] In some embodiments, the authorization authentication method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed onto the authorization authentication device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded onto the RAM 43 and executed by the processor 41, one or more steps of the authorization authentication method described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to perform the authorization authentication method by any other appropriate means, such as by means of firmware.

[0118] Optionally, the embodiments of the present application also provide a computer program product comprising a computer program which, when executed by a processor, implements the authorization authentication method provided by any of the embodiments of the present application.

[0119] The various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0120] Computer programs for implementing the methods of the present application can be written in any combination of one or more programming languages. These computer programs can be implemented on general purpose computers, special purpose computers, or other programmable data processing apparatus to produce the functions / acts specified in the flow diagrams and / or block diagrams. Computer programs can be applied to input data to perform the functions of the present application and to generate output information. The output information can be applied to one or more output devices such as a display screen, printer, storage, etc. These functions / acts performed by the computer programs are referred to as being computer-executed. Computer programs, also referred to as programs, software, software applications, applications, components, or code, can be written in any form of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program can be deployed to be executed by a host machine, a server, a client, or other computing device.

[0121] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal form, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0122] To provide for interaction with a user, the systems and techniques described here can be implemented on an authorization authentication device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the authorization authentication device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0123] The systems and techniques described herein can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described herein, or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0124] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.

[0125] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in different orders, as long as the desired results of the technical solutions of the present disclosure can be achieved, and the present disclosure is not limited herein.

[0126] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. An authorization authentication method characterized by, The application is applied to an authorization authentication system, the authorization authentication system comprises an application server, a fingerprint generator, an authorization center and a dynamic encryption and decryption device; the method comprises: The fingerprint generator generates a hardware fingerprint based on the weight parameters requested and stored by the application server to the authorization center and the hardware parameters of the application server, and sends the hardware fingerprint to the application server and the authorization center respectively for storage and registration; The authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, and after the first authorization authentication passes, generates an encrypted authorization code based on the weight parameters obtained by the application server and the dynamic encryption and decryption device and sends the encrypted authorization code to the application server; When the application server needs to perform secondary authentication, the encrypted authorization code is sent to the authorization center; The authorization center decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint.

2. The method of claim 1, wherein, The authorization center performs first authorization authentication based on the hardware fingerprint sent by the application server, comprising: The authorization center compares the hardware fingerprint sent by the application server with the registered hardware fingerprint; If the comparison result is a successful comparison, it is determined that the first authorization authentication passes; otherwise, it is determined that the first authorization authentication fails.

3. The method of claim 1, wherein, The authorization center generates a random code and an expiration time, sends the random code, the expiration time, the weight parameters obtained by the application server and the registered hardware fingerprint to the dynamic encryption and decryption device as authorization plaintext; The dynamic encryption and decryption device encrypts the authorization plaintext and sends the generated encrypted authorization code to the authorization center; The authorization center sends the encrypted authorization code to the application server. The dynamic encryption and decryption device encrypts the authorization plaintext, comprising:

4. The method of claim 3, wherein, The dynamic encryption and decryption device generates a first key pair, and encrypts the authorization plaintext through the first private key in the first key pair to determine a first ciphertext; The dynamic encryption and decryption device generates a second key pair, assembles the first ciphertext and the first public key in the first key pair into a new plaintext, encrypts the new plaintext through the second private key in the second key pair to determine an encrypted authorization code; Wherein, the algorithm parameters of the first key pair and the second key pair, and the second public key in the second key pair are registered in a key pool after being generated. The second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator and the registered hardware fingerprint, comprising:

5. The method of claim 1, wherein, Determine the to-be-verified weight parameters, the to-be-verified random code, the registered hardware fingerprint and the expiration time based on the decrypted encrypted authorization code; Send the to-be-verified weight parameters to the fingerprint generator, and receive the to-be-verified fingerprint returned by the fingerprint generator; ​ The to-be-verified fingerprint is compared with the registered hardware fingerprint, the to-be-verified random code is compared with the random code pool, the expiration time is compared with the verification time, and when the comparisons are all successful, it is determined that the second authorization authentication is passed.

6. The method of claim 1-5, wherein, After the second authorization authentication is passed, further comprising: starting a service in the application server or keeping the service in the application server started; The timing of the secondary authentication includes at least one of: When the application server is started for the first time; When the application server is started and reaches a preset time period.

7. An authorization authentication system characterized by comprising: Comprising: an application server, a fingerprint generator, an authorization center, and a dynamic encryption and decryption device; The fingerprint generator generates a hardware fingerprint in response to the weight parameter received by the application server from the authorization center and the hardware parameter of the application server, and sends the hardware fingerprint to the application server and the authorization center, respectively; The application server stores the hardware fingerprint and sends the hardware fingerprint to the authorization center for first authorization authentication; The authorization center registers the hardware fingerprint and performs first authorization authentication based on the hardware fingerprint sent by the application server and the registered hardware fingerprint, and after the first authorization authentication is passed, generates an encrypted authorization code based on the weight parameter obtained by the application server and the dynamic encryption and decryption device and sends it to the application server; The application server further sends the encrypted authorization code to the authorization center when secondary authentication is required; The authorization center further decrypts the encrypted authorization code through the dynamic encryption and decryption device, and performs second authorization authentication based on the decrypted encrypted authorization code, the fingerprint generator, and the registered hardware fingerprint.

8. An authorization authentication device, characterized by, Comprising: at least one processor; and a memory connected in communication with the at least one processor; The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the authorization authentication method of any one of claims 1-6.

9. A storage medium containing computer-executable instructions, wherein: The computer executable instructions, when executed by a computer processor, are used to execute the authorization authentication method of any one of claims 1-6.

10. A computer program product, characterised in that, The computer program, when executed by a processor, implements the authorization authentication method of any one of claims 1-6.