Tamper-proof offline software authorization implementation method
By generating an authorization file on the target computer and checking the authorization information, and combining a randomly generated authorization application code with the target computer's characteristic values, an activation code is dynamically generated. This solves the security problem of offline software authorization, prevents the authorization file from being tampered with and the system time from being spoofed, and improves the security of software authorization on offline computers.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA
- Filing Date
- 2025-12-08
- Publication Date
- 2026-04-28
AI Technical Summary
In existing offline software licensing methods, licensing information is easily stolen and tampered with, and the determination of the licensing period depends on the local system time, resulting in low security.
The system generates and manages license files on the target computer, and prevents tampering by checking the license information. It uses a randomly generated license application code bound to the target computer's feature value to dynamically generate an activation code. Combined with the licensed software ID and version information, it performs efficient license management.
It achieves tamper-proof protection of license files, improves the security and reliability of offline computer software licensing, and prevents tampering of license information and deception of system time.
Smart Images

Figure CN121935896A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of computer software, and particularly relates to a tamper-proof offline software licensing implementation method. Background Technology
[0002] Currently, there are three types of activation code authorization mechanisms based on verification: online authorization, offline authorization, and hybrid authorization. While online and hybrid authorization mechanisms offer high security, they restrict internet access. For software that needs to run in an offline environment (such as a company LAN computer or a classified computer), offline authorization is usually the only option. Current offline authorization methods typically generate authorization request numbers based on the target computer's characteristics, resulting in a fixed authorization request number for the same computer. Furthermore, authorization information is stored locally, making it vulnerable to theft and tampering. The authorization period depends on the local system time, rendering time verification ineffective. These shortcomings of offline software authorization methods pose risks to the security and reliability of software authorization, resulting in low security.
[0003] In view of this, the present invention is hereby proposed. Summary of the Invention
[0004] The tamper-proof offline software licensing method provided by this invention solves the technical problem of low security in traditional licensing methods. The technical solution of this invention has many beneficial effects, as described below: A tamper-proof offline software licensing implementation method is provided, applicable to providing security for offline software licensing. The offline software licensing method includes: S101: Generate and manage license files on the target computer, and prevent tampering of the license files by checking the license information in the license files; S102: The target computer generates an authorization application code dynamically using the target computer's feature values according to a random generation method; The authorization management computer uses the authorization application code, authorized software ID information, authorization level, authorization duration, and authorization version information to generate an activation code, and the target computer completes software activation based on the authorization application code and activation code.
[0005] Compared with the prior art, the technical solution provided by the present invention has the following beneficial effects: This method addresses the security issues inherent in traditional offline activation code authorization processes. These issues include the authorization request code being entirely generated from the target computer's characteristic values, authorization information being stored locally, authorization periods depending on the local system time, and susceptibility to tampering. This invention maintains an authorization file on the target offline computer and prevents tampering by checking local software authorization information. The method employs a random authorization request code generation process, binding the authorization request code to the target computer's characteristic values for dynamic generation. It incorporates the authorized software ID and version information into the activation code generation and verification processes, providing an efficient algorithm for managing authorizations of different versions of different software, and comprehensively meeting the tamper-proof and security requirements of offline computer software authorization. Attached Figure Description
[0006] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0007] Figure 1 This is a flowchart illustrating the software licensing information inspection and management process of the present invention; Figure 2 This is a flowchart illustrating the offline software licensing system of the present invention. Detailed Implementation
[0008] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0009] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this invention, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.
[0010] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. The drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0011] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that aspects can be practiced without these specific details. To enable those skilled in the art to better understand the invention, the invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, features defined as "first" and "second" may explicitly or implicitly include one or more of that feature. In the description of the invention, unless otherwise stated, "a plurality of" means two or more.
[0012] The overall approach is to maintain an authorization file on the target offline computer and prevent tampering of the authorization file through a process of checking local software authorization information. A random authorization request code generation process was designed, binding the authorization request code to the target computer's characteristic values for dynamic generation. The authorized software ID and authorization version information are incorporated into the activation code generation and verification processes, providing an efficient algorithm for managing authorizations of different versions of different software. This comprehensively meets the anti-tampering and security requirements of software authorization on offline computers. For details, see [reference needed]. Figures 1 to 2 The tamper-proof offline software licensing implementation method shown is applicable to providing security for offline software licensing. The offline software licensing method includes: S101: The target computer generates and manages the license file, and checks the license information in the license file to prevent tampering of the license file. The generation and management of the license file by the target computer includes recording all the license information required during the process of checking the license information in the license file, and checking the license information in the license file. Multiple checking methods are used to prevent external tampering of the license file and to prevent tampering of the target computer system time.
[0013] S102: The target computer (usually a client) dynamically generates an authorization request code using its characteristic values according to a random generation method. Specifically, the dynamic generation of the authorization request code using the target computer's characteristic values includes... The feature value generates a dynamic authorization request code bound to the target computer using a random generation method, and configures a lifecycle for the authorization request code. The authorization request code for the target computer is obtained by the customer through human-computer interaction and then sent to the authorization management computer. The authorization request code is input into the authorization management computer through human-computer interaction. (Because the target computer is in an offline operating environment and cannot communicate with the authorization management computer, the operator of the target computer needs to manually record the authorization request code and pass it to the operator of the authorization management computer, who then inputs the authorization request code into the authorization management computer through human-computer interaction.) The authorization management computer uses the authorization request code, authorization level, authorization duration, authorized software ID information, and software version information to generate an activation code. The activation code is input into the target computer through human-computer interaction, and the target computer activates the software on the target computer based on the authorization request code and the activation code.
[0014] The authorization management computer (usually a server) uses the authorization application code, authorized software ID information, authorization level, authorization duration, and authorization version information to generate an activation code. The target computer then activates the software based on the authorization application code and the activation code.
[0015] In one embodiment, preventing external tampering with the authorization file through multiple checks includes, (1) Verify the authorization file according to the check code in the authorization file to prevent the authorization file from being tampered with externally; (2) Compare the creation time and authorization start time of the authorization file (the time interval is qualified or the same if it is within the threshold range) to prevent the authorization file from being tampered with externally; (3) Obtain the modification time of the authorization file and compare it with the maintenance time of the authorization information (the time interval is qualified or the same if it is within the threshold range) to prevent the authorization file from being tampered with externally.
[0016] The purpose is to detect whether the user is copying, restoring, or modifying the license file, compared to the traditional offline license information maintenance method. When the user copies, restores, or modifies the license file, it is considered that the user is trying to tamper with the software license, and the license information is set to invalid.
[0017] In one embodiment, preventing tampering with the target computer system time through multiple inspection methods includes: (1) Compare the system time and the authorization information maintenance time to prevent tampering with the target computer's system time; (2) Compare the computer boot time, authorization information maintenance time, and computer boot time when the software was last run to prevent tampering with the target computer system time; (3) Obtain the modification time of the license file and compare it with the license information maintenance time to prevent tampering with the target computer's system time. Compared with the traditional offline license information maintenance method, this process can detect whether the user is trying to deceive the software's license information check by modifying the target computer's system time. Therefore, if it is detected that the user has modified the target computer's system time, the license information will be set to invalid.
[0018] In one embodiment, the feature value is generated using a random generation method to create a dynamic license request code that is bound to the target computer, and the lifecycle of the license request code is set, including: (1) In the process of generating the authorization application number, in addition to collecting the target computer feature values, an extra set of random data is generated to generate the authorization application number; (2) Set a lifecycle for the authorization application number and limit the usage time of the authorization application number.
[0019] This method generates and manages license files on the target offline computer, and prevents tampering of the license files through a local software license information check process. A random license application code generation process is designed, binding the license application code to the target computer's characteristic values for dynamic generation. The licensed software ID and licensed version information are incorporated into the activation code generation and verification processes, providing an efficient algorithm for license management of different versions of different software, and fully meeting the anti-tampering and security requirements of software licenses on offline computers. To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with an embodiment of the present invention.
[0020] In embodiments of the present invention, different encryption algorithms and message digest algorithms are used in multiple places for data encryption or data verification. The different encryption algorithms and message digest algorithms used in the process are distinguished by number. The software license information inspection and management process described in the embodiments is as follows: (1) The software maintains an authorization file to manage software permissions. The authorization file is a binary file encrypted using encryption algorithm 1. After decryption, its internal structure is as follows: a. A 12-byte authorization request number; b. The number of times the 1-byte authorization request number is valid, which is 5 by default in this example; c. The 8-byte software license level uses 64 bits to represent the license status of up to 64 different functions. A bit of 1 indicates that the function is authorized, and when all bits are 0, it indicates the lowest level of privilege, and the software is only allowed to use basic functions. d.8 bytes of authorization start time, using FILETIM format timing, represented by a 64-bit unsigned integer; e.8 bytes of the license expiration time, using the FILETIM format for timing, represented by a 64-bit unsigned integer. When the license expiration time is 0xFFFFFFFFFFFFFFFF, it indicates that the license has no expiration period. f.8 bytes of authorization information maintenance time, using FILETIM format timing method, with time represented by a 64-bit unsigned integer; g.8 bytes of the last time the computer was powered on, represented as a 64-bit unsigned integer with a precision of seconds; h.32 bytes of the license file checksum, generated based on all content in the license file except for the license file checksum field.
[0021] (2) Each time the software generates a new license file, it regenerates a license application number and resets the information within the license file, specifically as follows: a. When generating the authorization application number, obtain the target computer's characteristic values, including the target computer's MAC address, motherboard serial number, CPU serial number, hard disk serial number, and operating system serial number, and generate a random code. Encrypt the target computer's characteristic values and the random code using a message digest algorithm to generate a fixed 12-byte plaintext authorization application number. b. Set the number of valid authorization request numbers to 5; c. When setting the authorization start time and authorization information maintenance time, the current system time is obtained in FILETIME format, stored as an 8-byte unsigned integer, and assigned to the authorization start time and authorization information maintenance time. d. Set the authorization expiration time to 0xFFFFFFFFFFFFFFFF; e. Set the computer boot time last run, obtain the current system time and the system startup time, round down to the nearest second, and subtract the system startup time from the current time to get the computer boot time last run; f. Set the software license level to 0x0, indicating the lowest possible privileges; g. Encrypt all content in the authorization file except for the authorization file checksum field using Message Digest Algorithm 1 to generate a fixed 32-byte data as the authorization file checksum; (3) When the software starts, it reads and parses the license file. If the license file does not exist or the license file fails to be parsed, a new license file is generated and the permission level is determined to be the lowest permission. (4) After parsing the license file, check whether the license file has been tampered with. If it has been tampered with, determine that the permissions are the lowest possible. Specifically: a. Based on all the contents of the authorization file except for the authorization file check code, use Message Digest Algorithm 1 to encrypt and generate a data with a fixed length of 32. If the data matches the authorization file check code, the verification passes; otherwise, the authorization file is considered to have been tampered with, a new authorization file is generated, and the permission level is determined to be the lowest permission level. b. Obtain the creation time of the license file and compare it with the license start time. If the creation time and the license start time are inconsistent, it is determined that the license file has been tampered with, a new license file is generated, and the permission level is determined to be the lowest permission. Consider the software running time when the license file is created. If the difference between the creation time and the license start time exceeds 1 millisecond, it is considered that the creation time and the license start time are inconsistent. c. Obtain the modification time of the license file and compare it with the license information maintenance time. If the modification time of the license file and the license information maintenance time are inconsistent, the license file has been tampered with. A new license file is generated, and the permission level is determined to be the lowest permission. Taking into account the software running time when updating the license file, if the modification time of the license file and the license information maintenance time deviate by more than 1 millisecond, it is considered that the modification time of the license file and the license information maintenance time are inconsistent. (5) After parsing the authorization file, check if the system time has been modified. If it has been tampered with, determine that the permissions are the lowest possible. Specifically: a. Obtain the system time. If the system time is earlier than the authorization information maintenance time, the system time has been tampered with, a new authorization file is generated, and the permission level is determined to be the lowest level. b. Obtain the computer boot time. If the computer boot time is earlier than the license information maintenance time and is inconsistent with the computer boot time when the software was last run, the system time has been tampered with. A new license file is generated, and the permission level is determined to be the lowest permission. Taking into account the software running time when updating the license file, if the modification time of the license file and the license information maintenance time deviate by more than 1 second, it is considered that the computer boot time is inconsistent with the computer boot time when the software was last run. (6) After parsing the authorization file, check the authorization validity period. If the system time is later than the authorization expiration time, the authorization expires, a new authorization file is generated, and the permission level is determined to be the lowest permission. (7) If the checks mentioned in steps 3), 4), and 5) are passed, the permission level is determined to be the parsed authorization level, and the software selects the functions to be opened to the user according to the permission level; (8) The software obtains the system time every 30 minutes during operation and updates the license information maintenance time in the license file to ensure that the software running time is correctly recorded.
[0022] Secondly, the software activation code authorization process of the embodiment is described, and the specific process is as follows: (1) When a user applies for permission, the software decrypts the authorization file using an encryption algorithm to obtain the current authorization application number and sends it to the software vendor; (2) After receiving the authorization application number, the software vendor generates an activation code based on the authorization application number, authorization level, authorization duration, authorized software ID, and software version information, specifically: a. The software vendor enters the license application number into the software licensing system; b. The software vendor selects the functional items to be authorized and generates permission levels based on the selected functional items; c. Software vendor's choice of license duration; d. The software vendor selects the software to be licensed and the software version; e. The software licensing system encrypts the license application number, license level, license duration, licensed software ID, and software version information using Message Digest Algorithm 2 to generate an license verification code field, which, together with the license application number, license level, license duration, licensed software ID, and software version information, forms the activation code plaintext. f. Use encryption algorithm two to encrypt the plaintext activation code and use it as the activation code; (3) After obtaining the activation code from the software vendor, the user enters it into the software. The software verifies the validity of the activation code, specifically as follows: a. Use the decryption algorithm corresponding to encryption algorithm two to decrypt the activation code and obtain the plaintext activation code. If decryption fails, activation fails. b. Obtain the authorization application number, authorization level, authorization duration, authorized software ID, software version information, and authorization verification code from the activation code (in plain text); c. Using the authorization application number, authorization level, authorization duration, authorized software ID, and software version information, calculate an authorization verification code using Message Digest Algorithm 2, compare it with the authorization verification code in the plaintext of the activation code, and at the same time obtain the current software information, compare the authorized software ID and software version information. If the comparison matches, the activation is successful; otherwise, the activation fails. (4) After successful activation, the software checks the bit in the authorization level. If the bit value is 1, the corresponding function is enabled to the user. At the same time, a new authorization file is generated and the authorization file information is updated, specifically: a. Update the authorization level in the authorization file according to the authorization level; b. Update the license expiration time in the license file based on the current time and the license duration; c. Update the verification code of the authorization file using the information encryption algorithm.
[0023] (5) After the activation code verification fails more than the predetermined number of times, update the authorization application number in the software authorization file.
[0024] To address the security issues inherent in traditional offline activation code licensing, such as authorization request codes being entirely generated from the target computer's signature values, local storage of authorization information, authorization periods dependent on local system time, and susceptibility to tampering, this paper proposes maintaining an authorization file on the target offline computer and implementing tamper-proofing through a local software authorization information check process. A random authorization request code generation process is designed, binding the authorization request code to the target computer's signature values for dynamic generation. The authorized software ID and version information are incorporated into the activation code generation and verification processes, providing an efficient algorithm for managing licenses of different versions of different software, and comprehensively meeting the tamper-proofing and security requirements of offline computer software licensing.
[0025] The product provided by this invention has been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this invention. The descriptions of the embodiments above are merely for the purpose of helping to understand the core ideas of this invention. It should be noted that those skilled in the art can make various improvements and modifications to the invention without departing from the principles of the invention, and these improvements and modifications also fall within the protection scope of the invention claims.
Claims
1. A tamper-proof offline software licensing implementation method, applicable to providing security for offline software licensing, characterized in that, The offline software licensing method includes, S101: Generate and manage license files on the target computer, and prevent tampering of the license files by checking the license information in the license files; S102: The target computer generates an authorization application code dynamically using the target computer's feature values according to a random generation method; The authorization management computer uses the authorization application code, authorized software ID information, authorization level, authorization duration, and authorization version information to generate an activation code, and the target computer completes software activation based on the authorization application code and activation code.
2. The offline software licensing method according to claim 1, characterized in that, The target computer generates and manages the license file. The generation and management of the license file by the target computer in step S101 includes... During the process of checking the authorization information in the authorization file, all necessary authorization information is recorded, and the authorization information in the authorization file is checked. Multiple checking methods are used to prevent external tampering with the authorization file and to prevent tampering with the target computer system time.
3. The offline software licensing method according to claim 2, characterized in that, S102 includes dynamically generating the license application code using the target computer's feature values, including: The feature value is used to generate a dynamic authorization request code that is bound to the target computer through a random generation method, and a lifecycle is configured for the authorization request code; The authorization application code for the target computer is obtained by the customer through human-computer interaction and then sent to the authorization management computer; The authorization application code is input to the authorization management computer via human-computer interaction. The authorization management computer uses the authorization application code, authorization level, authorization duration, authorized software ID information, and software version information to generate an activation code. The activation code is input to the target computer via human-computer interaction. The target computer activates the software on the target computer based on the authorization application code and the activation code.
4. The offline software licensing method according to claim 2, characterized in that, The method of preventing external tampering with the authorization file through multiple checks includes, The authorization file is verified using the checksum in the authorization file to prevent it from being tampered with externally. The creation time and start time of the license file are compared to prevent the license file from being tampered with externally. Obtain the modification time of the license file and compare it with the license information maintenance time to prevent the license file from being tampered with externally.
5. The offline software licensing method according to claim 2, characterized in that, Preventing tampering with the target computer system's time through multiple inspection methods includes: The system time and authorization information maintenance time are compared to prevent tampering with the target computer's system time; The computer's boot time, authorization information maintenance time, and the computer's boot time during the last software run are compared to prevent tampering with the target computer's system time. The modification time of the license file is compared with the maintenance time of the license information to prevent tampering with the target computer system's time.
6. The offline software licensing method according to claim 3, characterized in that, The feature value is used to generate a dynamic authorization request code that is bound to the target computer through a random generation method, and the lifecycle of the authorization request code is set as follows: In the process of generating the authorization application number, in addition to collecting the target computer's characteristic values, an extra set of random data is generated to generate the authorization application number; Set a lifecycle for the authorization application number to limit the time during which the authorization application number can be used.