Software authorization management method and device, terminal and storage medium
By generating hardware fingerprints and transmitting them in encrypted form, and combining user level and behavior data for authorization management, the security and compatibility issues of traditional software authorization methods are solved, enabling intelligent cross-platform management and improved user experience.
Patent Information
- Application Number
- CN202511380037.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2026-02-17
AI Technical Summary
Traditional software licensing methods suffer from problems such as easy copying and sharing, poor cross-platform compatibility, high development and maintenance costs, poor user experience, and inability to achieve intelligent management.
By generating hardware fingerprints and transmitting them in encrypted form, and combining user level and behavior data for authorization management, cross-platform compatibility and intelligent management are achieved.
It improves the security and reliability of licensing, reduces development and maintenance costs, enhances user experience, and supports flexible management of modern business models.
Smart Images

Figure CN121543066A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of software authorization management, in particular to a software authorization management method and device, a terminal and a storage medium. BACKGROUND
[0002] With the vigorous development of the software industry, software authorization has become a key link to protect the rights and interests of software developers. Traditional authorization methods such as serial number (registration code) verification have been widely used. However, such methods have inherent defects: serial numbers are easily copied, shared or spread on the Internet by users, leading to illegal use of a license by multiple devices, affecting the healthy development of the software market and causing economic losses to software developers.
[0003] To address this problem, existing technologies have proposed a hardware binding solution, that is, a unique fingerprint is generated by collecting hardware information (such as CPU serial number, hard disk serial number, etc.) of a user's device, and the authorization is bound to the fingerprint. Although this method improves security to some extent, it still has significant limitations: first, the hardware information acquisition methods of different operating systems differ greatly, and there is a lack of unified and efficient cross-platform solutions, resulting in high development and maintenance costs; second, the authorization strategies of existing hardware binding solutions are mostly static and rigid, and once the authorization expires or the hardware changes, a "one-size-fits-all" approach is usually taken to directly deny access, resulting in poor user experience and potential harm to loyal users; finally, the authorization system cannot distinguish the value and loyalty of users, and lacks the ability to differentiate and intelligently manage based on user behavior, making it difficult to meet the needs of modern software service and continuous business model changes.
[0004] Therefore, there is an urgent need in the art for a comprehensive software authorization management solution that can ensure authorization security, have cross-platform compatibility, and intelligently and flexibly manage based on user behavior. SUMMARY
[0005] To solve the above problems, the present application provides a software authorization management method, device, terminal and storage medium.
[0006] In a first aspect, the present application provides a software authorization management method, which adopts the following technical means: A software authorization management method, comprising the following steps: validating the legality of an authorization login request containing hardware fingerprint information, and when the legality validation passes, determining whether there is a matching authorization record in a preset authorization database according to the hardware fingerprint information; If there is a matching authorization record, validating the effectiveness of authorization information corresponding to the authorization record; When the authorization information is valid, returning an authorization success prompt to the client. generating an exception handling instruction according to a pre-configured exception handling strategy when the authorization information is invalid, no matching authorization record exists, or the legitimacy check fails; The generation of the exception handling strategy is based on at least a user level associated with a user account of a sender of the authorized login request, and the user level is calculated and updated in real time by a pre-set credit system based on historical behavior data of the user. The exception handling instruction is returned to the client, and the client performs corresponding operations.
[0007] By using the above technical means, the fingerprint is generated based on hardware information and encrypted transmission, which fundamentally eliminates the risk of simple copying and sharing of authorization keys, and provides solid technical protection for software copyright. The user level is used as the core basis for generating the exception handling instruction, so that the authorization management can identify user value, reward loyal users, and flexibly manage abnormal states.
[0008] Preferably, the authorized login request is generated by the client based on local information, and the local information includes hardware data of a running device where the client is located. The data required for generating the authorized login request also includes software identification data of the current software and a user account as the sender of the authorized login request. The hardware data, the software identification data, and the user account are encrypted and packaged to obtain the hardware fingerprint information, and the authorized login request is obtained based on the hardware fingerprint information.
[0009] By using the above technical means, the hardware fingerprint is generated by integrating hardware data, software identification, and user account information, which constitutes a multi-dimensional unique identifier. Compared with the single hardware information dependent method, the reliability and tamper resistance of the fingerprint are significantly improved, and the problem of invalid legal authorization caused by single hardware change is avoided.
[0010] Preferably, the authorized login request containing the hardware fingerprint information is subjected to legitimacy check, and when the legitimacy check passes, it is determined whether a matching authorization record exists in a pre-set authorization database based on the authorized login request, specifically including the following steps: The authorized login request received from the client is subjected to legitimacy check, and the legitimacy check is used to determine whether the authorized login request is an illegal authorization; When the legitimacy check passes, a matching authorization record is searched in a pre-set authorization database based on the authorized login request, and it is determined whether an authorization record corresponding to the hardware data and the software identification data in the authorized login request exists in the pre-set authorization database.
[0011] By adopting the above technical means, the network attack means such as counterfeit authorization request, data packet stealing and tampering are effectively resisted through validity verification, and the overall security of the system is improved.
[0012] Preferably, if there is a matching authorization record, validity verification is performed on authorization information corresponding to the authorization record, specifically including the following steps: When the authorization database has the authorization record corresponding to the hardware data and the software identification data, validity verification is performed on authorization information corresponding to the authorization record to determine whether the authorization information is expired. If the authorization information is expired, the validity verification of the authorization information fails, and the authorization information is invalid. If the authorization information is not expired, the validity verification of the authorization information is passed, and the authorization information is valid. When the authorization information is valid, a prompt of authorization success is returned to the client, and the authorization information is returned, including the function permission of the user account.
[0013] By adopting the above technical means, not only whether the authorization exists is verified, but also the validity thereof is further verified, and fine management of the authorization life cycle is realized.
[0014] Preferably, the abnormal handling instruction is generated according to the preconfigured abnormal handling strategy, specifically including the following steps: When the authorization information is invalid, the level points of the user account are obtained, the level points are adjusted in real time according to pre-set behavior adding rules and behavior reducing rules in the point system, the user level of the user account is updated in real time according to the level points, and the user level includes ordinary users, important users and VIP users. An abnormal handling strategy configuration is accessed, the abnormal handling strategy configuration includes an expired handling strategy, an illegal authorization handling strategy and an authorization-free handling strategy. According to the user level, a corresponding expired handling rule is obtained from the expired handling strategy, and a first abnormal handling instruction is generated according to the expired handling rule. Different expired handling rules are configured for different user levels in the expired handling strategy, and the expired handling rule includes at least one of function limitation degree, buffer period length and renewal reminder mode. When there is no matching authorization record, a second abnormal handling instruction is generated according to a pre-set authorization-free handling strategy, and when the legality verification of the authorization login request fails, a third abnormal handling instruction is generated according to a pre-set illegal authorization handling strategy.
[0015] By adopting the above technical means, it is clear that the abnormal processing strategy can be differentially configured for different user levels, enabling software vendors to formulate extremely flexible business strategies and maximize profits; through differential processing strategies, unauthorized use is controlled while minimizing interference with legitimate users or high-value users, maintaining customer relationships.
[0016] Preferably, the first abnormal processing instruction is generated according to the expiration processing rule, specifically including the following steps: Obtain the historical behavior data corresponding to the user account, including the update frequency of the authorization record corresponding to the user account, the timeliness of the user account renewal, and the use frequency and duration of the user account; Assign a weight index to different types of historical behavior data, and calculate a comprehensive weight value of the current user account according to the weight index; Compare the comprehensive weight value with the weight threshold preset for the current user level, and if the current comprehensive weight value is higher than the corresponding weight threshold, generate the first abnormal processing instruction using the expiration processing rule corresponding to the user level.
[0017] By adopting the above technical means, a comparison mechanism of comprehensive weight value and weight threshold is introduced, so that system decision is no longer dependent on simple level labels, but based on multi-dimensional historical behavior data for more detailed and intelligent weighted calculation, realizing automatic intelligent decision of authorization management and reducing manual intervention cost.
[0018] Preferably, the point system monitors the behavior of the user account in real time, and adjusts the level points according to the behavior plus rule and the behavior minus rule, and the trigger conditions of the behavior plus rule and the behavior minus rule include at least one of the following: Whether the user account completes the renewal before the authorization expires; Whether the user account reaches a preset software use duration or frequency threshold; Whether the user account remains active within a preset period; Whether the user account has operation behaviors identified as invalid or abuse; If yes, it is determined that the trigger condition is triggered, and the point system increases or deducts the corresponding level points according to the behavior plus rule and the behavior minus rule.
[0019] By using the above technical means, the abstract user value is converted into quantifiable data by monitoring and analyzing the core behavior types such as authorized maintenance behavior and software use behavior, so that the system can automatically identify and reward high-value users and tap the potential value of users; the integral rules are highly summarized and classified, which not only ensures the definiteness of the rules, but also reserves sufficient flexibility for extending new specific behavior rules in the future, and the system is easy to maintain and upgrade.
[0020] In a second aspect, the application provides a software authorization management device, which adopts the following technical means: A software authorization management device comprises the following modules: A legality verification module is configured to verify the legality of an authorized login request containing hardware fingerprint information, and when the legality verification passes, determine whether there is a matching authorization record in a preset authorization database according to the hardware fingerprint information; An effectiveness verification module is configured to verify the effectiveness of authorization information corresponding to the authorization record if there is a matching authorization record; When the authorization information is effective, an authorized success prompt is returned to the client; An abnormality processing instruction generation module is configured to generate an abnormality processing instruction according to a pre-configured abnormality processing strategy when the authorization information is invalid, there is no matching authorization record, or the legality verification does not pass; The generation of the abnormality processing strategy is based on at least a user level associated with a user account of a sender of the authorized login request, and the user level is updated in real time by a pre-set integral system based on historical behavior data of the user; An execution response module is configured to return the authorized success prompt or the abnormality processing instruction to the client, and the client performs corresponding operations.
[0021] In a third aspect, the application provides an intelligent terminal, which adopts the following technical solution: An intelligent terminal comprises a memory and a processor, and the memory stores at least one instruction, at least one program, a code set or an instruction set, which is loaded and executed by the processor to realize the software authorization management method as described above.
[0022] In a fourth aspect, the application provides a computer-readable storage medium, which adopts the following technical solution: A computer-readable storage medium stores at least one instruction, at least one program, a code set or an instruction set, which is loaded and executed by a processor to realize the software authorization management method as described above.
[0023] To sum up, the present application at least includes the following beneficial effects: 1. The present application builds an authorized cornerstone which is difficult to copy and tamper by cross-platform hardware fingerprint generation and encryption verification process, fundamentally solves the technical problem that the traditional serial number method is easy to be rampant, and provides a solid guarantee for software intellectual property rights.
[0024] 2. The present application integrates user behavior analysis into the authorization verification process, realizes the leap from static control to intelligent differentiated management according to users through dynamic user level and configurable strategy, can flexibly handle abnormal state to improve user experience, and can provide core technical support for modern business models such as gradient pricing and loyalty programs.
[0025] 3. The present application adopts an abstract hardware information extraction architecture, unifies the technical implementation under different operating systems, greatly reduces the development and maintenance cost; at the same time, the modular design makes the system have high scalability, and can flexibly adapt to the diversified authorization needs of various software products. BRIEF DESCRIPTION OF DRAWINGS
[0026] Figure 1 is a method flowchart of an embodiment of the present application; Figure 2 is a verification flowchart of an authorization login request in the method of an embodiment of the present application; Figure 3 is a device structure diagram of an embodiment of the present application. DETAILED DESCRIPTION
[0027] The present application provides a software authorization management method, device, terminal and storage medium, in order to make the purpose, technical scheme and advantages of the present application more clear, the following will further detail the embodiments of the present application.
[0028] The following further describes an embodiment of a software authorization management method of the present application in combination with the drawings of the specification.
[0029] A software authorization management method of the present application, as shown in Figure 1 includes the following steps: S1, the authorization login request containing hardware fingerprint information is verified for legality, and when the legality verification is passed, it is judged whether there is a matching authorization record in the preset authorization database according to the hardware fingerprint information, which specifically includes the following steps.
[0030] S11, the client automatically triggers the authorization verification, first generates an authorization login request according to the local information, and then sends the authorization login request to the authorization server for verification.
[0031] The local information includes hardware data of a hardware device where the client is located, the hardware data being a unique serial number generated by encrypting specific combinations based on fixed content in the hardware device, the fixed content including a CPU serial number, a hard disk serial number, a network card address, and an operating system; Specifically, The type of the current operating system, such as Windows NT 10.0, Linux Kernel 5.4, etc., is obtained, and a corresponding hardware information extractor instance is dynamically loaded from a preset implementation class library according to the detected platform type.
[0032] For example, if it is a Windows system, a WMI (Windows Management Instrumentation) interface is called to execute a query command to obtain a hard disk serial number and a CPU serial number.
[0033] If it is a Linux system, system files or specific commands are read to obtain hardware identification information. System files such as / sys / class / dmi / id / product_uuid.
[0034] If it is a macOS system, functions in the I / O Kit framework are used to obtain hardware data.
[0035] In addition to the hardware data, the data required to generate the authorized login request also includes software identification data of the current software and a user account as the sender of the authorized login request, the software identification data being a software name and a version number of the current software, to ensure the uniqueness of the request.
[0036] The client encrypts and packages the hardware data, the software identification data, and the user account through the HTTPS protocol to obtain unique hardware fingerprint information, generates an authorized login request according to the hardware fingerprint information, and sends it to a remote authorization server for verification.
[0037] S12, the authorization server performs legality verification on the authorized login request received from the client, and the legality verification is used to determine whether the authorized login request is illegal authorization.
[0038] If the legality verification fails, it is an illegal authorization, and in this embodiment, the illegal authorization includes tampering with the hardware fingerprint information.
[0039] Through the above steps, dynamic management and cross-platform compatibility of software authorization are achieved, and illegal copying and cracking are effectively prevented.
[0040] S13, as Figure 2As shown, when the legality verification passes, the matching authorization record is searched in the preset authorization database according to the authorization login request, and it is judged whether the authorization record corresponding to the hardware data and the software identification data in the authorization login request exists in the preset authorization database.
[0041] S2, when the matching authorization record exists, the validity of the authorization information corresponding to the authorization record is verified, and when the authorization information is valid, an authorization success prompt is returned to the client, specifically including the following steps: S21, when the authorization database exists the authorization record corresponding to the hardware data and the software identification data, the validity of the authorization information corresponding to the authorization record is verified, and it is judged whether the authorization information is expired.
[0042] S22, if the authorization information is expired, the validity verification of the authorization information is not passed, and the authorization information is invalid.
[0043] S23, if the authorization information is not expired, the validity verification of the authorization information is passed, and the authorization information is valid.
[0044] S24, when the authorization information is valid, an authorization success prompt is returned to the client, and the authorization information is returned, the authorization information includes the function permission of the user account.
[0045] In this embodiment, four authorization states are obtained after the validity of the authorization information is verified: A, valid authorization: when the authorization information is valid, the authorization state is valid authorization, and the processing strategy includes allowing the client software to normally access and use the protected resources, and recording the normal access log, etc.
[0046] B, invalid authorization: when the authorization information is invalid, the authorization state is invalid authorization, which means that the authorization information is expired.
[0047] C, illegal authorization: when the legality verification is not passed, the authorization state is illegal authorization, such as using tampered authorization code or stolen authorization information.
[0048] D, no authorization: when the matching authorization record is not found, the authorization state is no authorization.
[0049] S3, when the authorization information is invalid, the matching authorization record does not exist, or the legality verification is not passed, an exception handling instruction is generated according to the preconfigured exception handling strategy.
[0050] Among them, the generation of the exception handling strategy includes at least the user level associated with the user account as the sender of the authorization login request, and the user level is updated in real time by the pre-set credit system based on the historical behavior data of the user.
[0051] Specifically, it includes the following steps: S31, when the authorization information is invalid, obtaining the level points of the user account, the level points being adjusted in real time according to the preset behavior adding rule and the behavior reducing rule in the point system.
[0052] In the embodiment, the real-time adjustment manner of the level points is that the point system monitors the behavior of the user account in real time, and adjusts the level points according to the behavior adding rule and the behavior reducing rule.
[0053] In the embodiment, the trigger conditions of the behavior adding rule and the behavior reducing rule include at least one of the following: A, whether the user account completes the renewal before the authorization expiration; B, whether the user account reaches a preset software use time length or frequency threshold; C, whether the user account keeps the account active within a preset period; D, whether the user account has operation behaviors that are identified as invalid or abuse; If yes, it is determined that the trigger condition is triggered, and the point system adds or deducts the corresponding level points according to the behavior adding rule and the behavior reducing rule.
[0054] In a specific implementable manner, adding or deducting the corresponding level points according to the behavior adding rule and the behavior reducing rule specifically includes the following steps: S311, behavior adding: if the time of each authorization record update is before the authorization information expiration, the corresponding level points are added to the user account; If the time of the authorization record update is more than a preset period threshold from the authorization information expiration, additional level points are added to the user account; If any single use time length of the user account exceeds a preset time length threshold, the corresponding level points are added to the user account; If the renewal time of the user account is before the expiration of the payment function of the user account, the corresponding level points are added to the user account; S312, behavior reducing rule: if the user account is not updated after the authorization information expires, the corresponding level points are deducted according to a preset deduction period until the update; The behavior reducing rule further includes that if the user account does not renew after the authorization information expires, the corresponding level points are deducted; If the user account frequently performs invalid operations within the validity period of the authorization information, the corresponding level points are deducted.
[0055] If the user account does not log in within a preset active period, the corresponding level points are deducted.
[0056] More specifically, one embodiment is as follows: Behavior adding rule: Early renewal: the user renews the authorization more than 30 days before expiration, +100 points; renewing 15-30 days in advance, +50 points; Deep use: single-day software use time is more than 4 hours, +10 points / day; High activity: login days per week ≥5 days, +20 points / week; Behavior deduction rules: Expiration without renewal: -5 points / day after authorization expiration; Low activity: no login for 30 consecutive days, -50 points.
[0057] By updating the user level in real time, the user behavior can be accurately evaluated, the authorization management strategy can be optimized, and the user experience can be improved.
[0058] S32, updating the user level of the user account in real time according to the level points.
[0059] The user level of the embodiment includes ordinary users, important users, and VIP users.
[0060] In a specific implementation, the mapping of level points to user level is as follows: 0-100 points: ordinary user; 101-500 points: important user; 500 points: VIP user.
[0061] S33, access the pre-configured exception handling strategy configuration, which includes expiration handling strategy, illegal authorization handling strategy, and no authorization handling strategy.
[0062] The authorization server provides a configuration file containing user-defined exception handling strategy configuration, allowing software vendors to set handling strategies for different authorization exceptions (expired authorization, illegal authorization, and no authorization).
[0063] According to the matched exception handling strategy, the authorization server will construct corresponding exception instruction signals. These exception instruction signals include authorization status codes, handling suggestions, and other additional information; authorization status codes such as expiration status, illegal status, and no authorization status; handling suggestions such as limiting functions, prompting users to renew, and prohibiting access; additional information such as renewal links, error prompt information, etc.
[0064] S34, according to the invalid authorization information, access the expiration handling strategy in the exception handling strategy configuration, obtain the corresponding expiration handling rule from the expiration handling strategy according to the user level, and generate the first exception handling instruction according to the expiration handling rule.
[0065] The different user levels in the expiration processing strategy are configured with different expiration processing rules, and the expiration processing rules include at least one of a function restriction degree, a buffer period length, and a renewal reminder mode.
[0066] In a specific implementable manner, the expiration processing rule is specifically: The first expiration processing rule is that when the user account is a normal user, the rights of the user account for the paid function are limited, and a renewal reminder is sent. The second expiration processing rule is that when the user account is an important user, a preset buffer period is added to the user account, the user account is allowed to continue to use the paid function during the buffer period, and a renewal reminder and preferential information are sent. The third expiration processing rule is that when the user account is a VIP user, the user account is automatically renewed.
[0067] Specifically, the first exception processing instruction is generated according to the expiration processing rule, including the following steps: S341, obtaining historical behavior data corresponding to the current user account, specifically, the authorization server extracts the historical behavior data of the user from the user behavior log, and the historical behavior data is the update frequency of the authorization record corresponding to the user account, the renewal timeliness of the user account, and the use frequency and duration of the user account.
[0068] S342, assigning a weight index to different types of historical behavior data, and calculating a comprehensive weight value of the current user account according to the weight index.
[0069] The comprehensive weight value can reflect the importance and loyalty of the user account in the system, and also reflect the relative position and performance of the user in the current level.
[0070] S343, comparing the comprehensive weight value with a weight threshold preset for the current user level, if the current comprehensive weight value is higher than the corresponding weight threshold, the expiration processing rule corresponding to the user level is used to generate the first exception processing instruction.
[0071] In a specific implementable manner, A. If the comprehensive weight value of the normal user is higher than the preset first weight threshold, the first exception processing instruction of the current normal user is updated according to the first expiration processing rule; B. If the comprehensive weight value of the important user is higher than the preset second weight threshold, the first exception processing instruction of the current important user is updated according to the second expiration processing rule; C. If the comprehensive weight value of the VIP user is higher than the preset third weight threshold, the first exception processing instruction of the current VIP user is updated according to the third expiration processing rule.
[0072] S35. When no matching authorization record exists, the authorization status is "unauthorized." The unauthorized handling policy in the access exception handling policy configuration is applied, and a second exception handling instruction is generated based on this policy. The handling policy includes prompting the user to perform an authorization operation, providing a trial function, or completely prohibiting access to protected resources.
[0073] S36. When the authorization login request fails the validity check, the authorization status is illegal authorization, i.e., using a tampered authorization code or stolen authorization information. In this case, the illegal authorization handling policy in the access exception handling policy configuration is applied, and a third exception handling instruction is generated based on the illegal authorization handling policy. The handling policy includes immediately prohibiting the client software from accessing the software, logging the illegal access, and notifying the software vendor or relevant security agency for further processing.
[0074] To ensure the security of the aforementioned command signals, the authorization server encrypts the exception handling commands and encapsulates them into a specific data packet format so that the client software can correctly parse and execute them.
[0075] S4. Return the exception handling instructions to the client, and the client will perform the corresponding operation, which includes the following steps: S41. Establish a communication connection between the authorization server and the client software through network protocols such as HTTP, HTTPS, and WebSocket.
[0076] S42. Through the established communication connection, the authorization server returns the encrypted and encapsulated first exception handling instruction, second exception handling instruction, or third exception handling instruction to the client software, and the client processes the exception according to the exception handling strategy corresponding to the instruction.
[0077] Based on the same inventive concept described above, this application also discloses a software license management device, such as... Figure 3 As shown, it includes the following modules: The legitimacy verification module is used to verify the legitimacy of authorized login requests containing hardware fingerprint information. When the legitimacy verification is successful, it determines whether there is a matching authorization record in the preset authorization database based on the hardware fingerprint information. The validity verification module is used to verify the validity of the authorization information corresponding to the authorization record if a matching authorization record exists. When the authorization information is valid, a success authorization message is returned to the client; The exception handling instruction generation module is used to generate exception handling instructions according to the pre-configured exception handling strategy when the authorization information is invalid, there is no matching authorization record, or the legality verification fails. The generation of the exception handling strategy comprises at least a user level associated with the user account as a sender of the authorized login request, and the user level is updated in real time based on historical behavior data of the user by a pre-set credit system. The execution response module is configured to return the authorized success prompt or the exception handling instruction to the client, and the client performs corresponding operations.
[0078] In a specific embodiment, the legality verification module comprises the following units: The first legality verification unit is configured to verify the legality of the authorized login request received from the client, and the legality verification is used to determine whether the authorized login request is illegal authorization. The second legality verification unit is configured to, when the legality verification is passed, find a matching authorized record in the pre-set authorized database according to the authorized login request, and determine whether there is an authorized record corresponding to the hardware data and the software identification data in the authorized database.
[0079] In a specific embodiment, the validity verification module comprises the following units: The first validity verification unit is configured to, when there is an authorized record corresponding to the hardware data and the software identification data in the authorized database, verify the validity of the authorized information corresponding to the authorized record, and determine whether the authorized information is expired. The second validity verification unit is configured to, if the authorized information is expired, the validity verification of the authorized information is not passed, and the authorized information is invalid, and if the authorized information is not expired, the validity verification of the authorized information is passed, and the authorized information is valid. The third validity verification unit is configured to, when the authorized information is valid, return an authorized success prompt to the client, and return the authorized information, which comprises the function permission of the user account.
[0080] In a specific embodiment, the exception handling instruction generation module comprises the following units: The first exception handling instruction generation unit is configured to, when the authorized information is invalid, obtain the level credit of the user account, the level credit is adjusted in real time according to pre-set behavior plus rules and behavior minus rules in the credit system, the user level of the user account is updated in real time according to the level credit, and the user level comprises a common user, an important user and a VIP user. The second exception handling instruction generation unit is configured to access a pre-configured exception handling strategy configuration, and the exception handling strategy configuration comprises an expired handling strategy, an illegal authorization handling strategy and an unauthorized handling strategy. The third exception processing instruction generation unit is configured to obtain a corresponding expiration processing rule from the expiration processing strategy according to the user level, and generate the first exception processing instruction according to the expiration processing rule. Different user levels in the expiration processing strategy are configured with different expiration processing rules, and the expiration processing rule includes at least one of a function restriction degree, a buffer period length, and a renewal reminder mode. The fourth exception processing instruction generation unit is configured to generate a second exception processing instruction according to a preset unauthorized processing strategy when there is no matching authorized record. The fifth exception processing instruction generation unit is configured to generate a third exception processing instruction according to a preset illegal authorization processing strategy when the legality verification of the authorized login request fails.
[0081] In a specific implementation, the first exception processing instruction generation unit includes the following sub-units: The first exception processing instruction generation sub-unit is configured to monitor the behavior of the user account in real time, and adjust the level points according to the behavior plus rule and the behavior minus rule. The trigger conditions of the behavior plus rule and the behavior minus rule include at least one of the following: Whether the user account completes the renewal before the authorization expires; Whether the user account reaches a preset software use time or frequency threshold; Whether the user account remains active within a preset period; Whether the user account has operation behaviors that are identified as invalid or abused; The second exception processing instruction generation sub-unit is configured to determine that the trigger condition is triggered if yes, and the points system increases or deducts the corresponding level points according to the behavior plus rule and the behavior minus rule.
[0082] In a specific implementation, the third exception processing instruction generation unit includes the following sub-units: The third exception processing instruction generation sub-unit is configured to obtain historical behavior data corresponding to the current user account, and the historical behavior data includes the update frequency of the authorized record corresponding to the user account, the renewal timeliness of the user account, and the use frequency and time length of the user account. The fourth exception processing instruction generation sub-unit is configured to assign a weight index to different types of historical behavior data, and calculate a comprehensive weight value of the current user account according to the weight index. The fifth exception processing instruction generation sub-unit is configured to compare the comprehensive weight value with a preset weight threshold corresponding to the current user level, and generate the first exception processing instruction using the expiration processing rule corresponding to the user level if the current comprehensive weight value is higher than the corresponding weight threshold.
[0083] Based on the same inventive concept, the application further discloses a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set can be loaded and executed by a processor to implement the software authorization management method provided by the above method embodiment.
[0084] Based on the same inventive concept, the application further discloses a computer readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set can be loaded and executed by a processor to implement the software authorization management method provided by the above method embodiment.
[0085] A person of ordinary skill in the art can understand that all or part of the steps of the above embodiments can be completed by hardware, or by a program instructing related hardware to complete, and the program can be stored in a computer readable storage medium, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media capable of storing program codes.
[0086] The above is only an optional embodiment of the application, and is not used to limit the application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the application shall be included in the protection scope of the application.
Claims
1. A software license management method, characterized in that, Includes the following steps: The authorization login request containing hardware fingerprint information is validated for legality. If the legality validation is successful, the system determines whether a matching authorization record exists in the preset authorization database based on the hardware fingerprint information. If a matching authorization record exists, the validity of the authorization information corresponding to the authorization record is verified; When the authorization information is valid, a success authorization message is returned to the client; When the authorization information is invalid, there is no matching authorization record, or the legality verification fails, an exception handling instruction is generated according to the pre-configured exception handling strategy. The generation basis of the exception handling strategy includes at least the user level associated with the user account that is the sender of the authorized login request. The user level is calculated and updated in real time by a pre-set points system based on the user's historical behavior data. The exception handling instruction is returned to the client, which then performs the corresponding operation.
2. The software license management method according to claim 1, characterized in that, The authorization login request is generated by the client based on local information, which includes the hardware data of the running device on which the client is located. The data required to generate the authorized login request also includes the software identification data of the current software and the user account that is the sender of the authorized login request. The hardware data, the software identification data and the user account are encrypted and packaged to obtain the hardware fingerprint information, and the authorized login request is obtained based on the hardware fingerprint information.
3. The software license management method according to claim 2, characterized in that, The process of verifying the legitimacy of the authorization login request containing hardware fingerprint information, and determining whether a matching authorization record exists in the preset authorization database based on the authorization login request, specifically includes the following steps: The authorization login request received from the client is validated for legality, and the validity validation is used to determine whether the authorization login request is an illegal authorization; When the legitimacy verification passes, a matching authorization record is searched in the preset authorization database based on the authorization login request. Then, it is determined whether there is an authorization record in the preset authorization database that corresponds to the hardware data and software identification data in the authorization login request.
4. The software license management method according to claim 2, characterized in that, If a matching authorization record exists, the validity of the authorization information corresponding to the authorization record is verified, specifically including the following steps: When the authorization database contains an authorization record corresponding to the hardware data and the software identification data, the validity of the authorization information corresponding to the authorization record is verified to determine whether the authorization information has expired. If the authorization information has expired, the validity verification of the authorization information fails and the authorization information is invalid; if the authorization information has not expired, the validity verification of the authorization information passes and the authorization information is valid. When the authorization information is valid, a successful authorization message is returned to the client, along with the authorization information, which includes the user account's functional permissions.
5. The software license management method according to claim 2, characterized in that, The step of generating exception handling instructions according to a pre-configured exception handling strategy specifically includes the following steps: When the authorization information is invalid, the user account's level points are obtained. The level points are adjusted in real time according to the preset behavior bonus and behavior deduction rules in the points system. The user account's user level is updated in real time based on the level points. The user level includes ordinary user, important user, and VIP user. Access the pre-configured exception handling policy settings, which include expiration handling policy, unauthorized authorization handling policy, and no-authorization handling policy; The system retrieves the corresponding expiration handling rules from the expiration handling strategy based on the user level, and generates a first exception handling instruction based on the expiration handling rules; wherein, different user levels in the expiration handling strategy are configured with different expiration handling rules, and the expiration handling rules include at least one of the following: degree of function restriction, buffer period duration, and renewal reminder method; When no matching authorization record exists, a second exception handling instruction is generated according to a preset unauthorized handling strategy. When the validity verification of the authorized login request fails, a third exception handling instruction is generated according to a preset illegal authorization handling strategy.
6. The software license management method according to claim 5, characterized in that, The step of generating the first exception handling instruction based on the expiration handling rules specifically includes the following steps: Obtain historical behavior data corresponding to the current user account, including the update frequency of the authorization record corresponding to the user account, the timeliness of the user account renewal, and the usage frequency and duration of the user account; Assign weight indicators to different types of historical behavior data, and calculate the comprehensive weight value of the current user account based on the weight indicators; The comprehensive weight value is compared with the weight threshold preset for the current user level. If the current comprehensive weight value is higher than the corresponding weight threshold, the first exception handling instruction is generated using the expiration handling rule corresponding to the user level.
7. The software license management method according to claim 5, characterized in that, The points system monitors the user account's behavior in real time and adjusts the level points according to the behavior-based point-addition rules and behavior-based point-deduction rules. The triggering conditions for the behavior-based point-addition rules and behavior-based point-deduction rules include at least one of the following: Whether the user account has been renewed before the authorization expires; Whether the user account has reached the preset software usage time or frequency threshold; Whether the user account remains active within a preset period; Does the user account have any operations that have been deemed invalid or abused? If so, the triggering condition is determined to be triggered, and the points system increases or decreases the corresponding level points according to the behavior bonus rules and the behavior deduction rules.
8. A software license management device, characterized in that, Includes the following modules: The legitimacy verification module is used to verify the legitimacy of authorized login requests containing hardware fingerprint information. When the legitimacy verification is passed, it determines whether there is a matching authorization record in the preset authorization database based on the hardware fingerprint information. The validity verification module is used to verify the validity of the authorization information corresponding to the authorization record if a matching authorization record exists. When the authorization information is valid, a success authorization message is returned to the client; An exception handling instruction generation module is used to generate an exception handling instruction according to a pre-configured exception handling strategy when the authorization information is invalid, there is no matching authorization record, or the legality verification fails. The generation basis of the exception handling strategy includes at least the user level associated with the user account that is the sender of the authorized login request. The user level is calculated and updated in real time by a pre-set points system based on the user's historical behavior data. The execution response module is used to return the authorization success message or the exception handling instruction to the client, so that the client can perform the corresponding operation.
9. A smart terminal, characterized in that, The system includes a memory and a processor, wherein the memory stores at least one instruction, at least one program, code set, or instruction set, and the at least one instruction, at least one program, code set, or instruction set is loaded and executed by the processor to implement the software license management method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The readable storage medium stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement the software license management method as described in any one of claims 1 to 7.