A method and apparatus for detecting software license usage based on blockchain evidence storage
By acquiring multi-dimensional behavioral data to generate behavioral fingerprints and comparing them on the blockchain, the problem of traditional software authorization detection being easily cracked and tampered with is solved, realizing secure, flexible and traceable authorization detection, and improving user experience and recognition accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING CHANGYANG TECH CO LTD
- Filing Date
- 2026-01-26
- Publication Date
- 2026-06-02
AI Technical Summary
Traditional software license detection methods are easily cracked, their features are easily tampered with, and changes in license status and historical records of behavioral characteristics are difficult to trace, thus failing to provide effective evidence.
By dynamically generating behavioral fingerprints from multidimensional behavioral data and binding them to the authorized ID on the blockchain, the current behavioral fingerprint is compared with the target behavioral fingerprint in real time. Blockchain is used to ensure that the detection results are tamper-proof and traceable.
It improves the security, flexibility, and traceability of authorized detection, enhances the user experience, and strengthens the accuracy of authorized user identification and anti-counterfeiting capabilities.
Smart Images

Figure CN122133116A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security and software license protection technology, and in particular to a method and apparatus for detecting software license usage based on blockchain evidence. Background Technology
[0002] With the rapid development of the software industry, software license protection has become a crucial aspect of safeguarding the rights and interests of software developers. Traditional software license detection methods mainly rely on static key verification, hardware binding (such as hard drive serial numbers and CPU identifiers), single behavioral characteristics (such as login IP and usage duration), digital signatures, license keys, or single behavioral characteristics (such as API call sequences). However, these methods all suffer from problems such as vulnerability to cracking, easy tampering of characteristics, and difficulty in tracing. In particular, static key verification and single behavioral characteristics are easily reverse engineered or simulated, leading to the failure of license detection; traditionally centralized storage of behavioral characteristic data is easily maliciously tampered with, making it impossible to guarantee data authenticity; and the historical records of license status changes and behavioral characteristics are difficult to trace completely, failing to provide effective evidence for infringement disputes.
[0003] Therefore, there is an urgent need for a software licensing and usage detection method and device based on blockchain-based evidence storage. Summary of the Invention
[0004] To address the aforementioned issues, this invention provides a software authorization usage detection method and apparatus based on blockchain evidence storage, which enables real-time verification of authorization status and anomaly warning, thereby improving the security, flexibility, traceability, and user experience of authorization detection.
[0005] In a first aspect, embodiments of the present invention provide a software licensing and usage detection method based on blockchain-based evidence storage, comprising: Acquire multidimensional behavioral data of the software under test during normal operation; A behavioral fingerprint is dynamically generated based on the multidimensional behavioral data, and then the behavioral fingerprint is bound to an authorization ID and uploaded to the blockchain; wherein, the authorization ID is used to represent the current usage behavior status; Dynamically generate the current behavior fingerprint based on real-time acquired current multidimensional behavior data; The corresponding target behavior fingerprint is obtained from the blockchain based on the authorized ID, and the current behavior fingerprint and the target behavior fingerprint are compared to obtain the detection result.
[0006] Secondly, embodiments of the present invention also provide a software licensing and usage detection device based on blockchain-based evidence storage, comprising: The acquisition module is used to acquire multidimensional behavioral data of the software under test during normal operation. The generation module is used to dynamically generate behavioral fingerprints based on the multidimensional behavioral data; The evidence storage module is used to bind the behavior fingerprint with the authorization ID and then upload it to the blockchain; wherein, the authorization ID is used to represent the current usage behavior status; The generation module is also used to dynamically generate the current behavior fingerprint based on the real-time acquired current multidimensional behavior data; The detection module is used to obtain the corresponding target behavior fingerprint from the blockchain based on the authorized ID, compare the current behavior fingerprint with the target behavior fingerprint, and obtain the detection result.
[0007] Thirdly, embodiments of the present invention also provide a computing device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the software authorization and use detection method based on blockchain evidence storage described above.
[0008] Fourthly, embodiments of the present invention also provide a computer-readable storage medium storing a computer program thereon, which, when executed in a computer, causes the computer to execute the software license usage detection method based on blockchain evidence as described above.
[0009] Fifthly, embodiments of the present invention also provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the method described in any of the first aspects of this specification.
[0010] This invention provides a method and apparatus for detecting software authorization based on blockchain evidence. This method dynamically generates behavioral fingerprints using multi-dimensional behavioral data, overcoming the limitations of traditional single-hardware binding. By integrating multi-dimensional behavioral data, it significantly improves anti-forgery capabilities. Then, the behavioral fingerprint generated during normal operation is bound to a unique authorization ID and uploaded to the blockchain. Finally, the current dynamically generated behavioral fingerprint is compared with the corresponding target behavioral fingerprint obtained from the blockchain to obtain the detection result. Thus, this method improves the accuracy and security of authorized user identification, ensures the immutability of detection logs, and achieves security, flexibility, traceability, and improved user experience in authorization detection. Attached Figure Description
[0011] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0012] Figure 1 This is a flowchart of a software licensing and usage detection method based on blockchain evidence storage provided in an embodiment of the present invention; Figure 2 This is a hardware architecture diagram of a computing device provided in an embodiment of the present invention; Figure 3 This is a structural diagram of a software licensing and usage detection device based on blockchain evidence storage, provided in one embodiment of the present invention. Detailed Implementation
[0013] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0014] The following is the concept of the present invention, such as Figure 1 As shown, this embodiment of the invention provides a software licensing and usage detection method based on blockchain evidence storage, the method comprising: Step 100: Obtain multi-dimensional behavioral data of the software under test during normal operation; Step 102: Dynamically generate behavioral fingerprints based on multi-dimensional behavioral data, bind the behavioral fingerprints with the authorization ID, and upload them to the blockchain; whereby the authorization ID is used to represent the current usage behavior status; Step 104: Dynamically generate the current behavior fingerprint based on the real-time acquired current multidimensional behavior data; Step 106: Obtain the corresponding target behavior fingerprint from the blockchain based on the authorization ID, compare the current behavior fingerprint with the target behavior fingerprint, and obtain the detection result.
[0015] In this embodiment of the invention, behavioral fingerprints are dynamically generated using multi-dimensional behavioral data, overcoming the limitations of traditional single hardware binding. By integrating multi-dimensional behavioral data, the anti-counterfeiting capability is significantly improved. Then, the behavioral fingerprint generated during normal operation is bound to a unique authorization ID and uploaded to the blockchain. The current behavioral fingerprint, dynamically generated in real time, is then compared with the corresponding target behavioral fingerprint obtained from the blockchain to obtain the detection result. Thus, this method improves the accuracy and security of authorized user identification, ensures the immutability of detection logs, and achieves security, flexibility, traceability, and improved user experience in authorization detection.
[0016] The following description Figure 1 The execution method of each step is shown.
[0017] In step 100, during software runtime, the terminal's built-in acquisition module dynamically collects behavioral data across the following dimensions, including but not limited to device behavior data, software interaction behavior data, network interaction behavior data, and user operation behavior data. For example, device behavior data includes CPU resource usage fluctuations, memory access frequency, and network connection port characteristics. Software interaction behavior data includes functional module call sequences, file open / save time intervals, and plugin usage preferences. Network interaction behavior data includes the communication IP address, port, request type, data transmission volume, and time between the software and external servers. User operation behavior data includes click intervals, keyboard input rhythm, and mouse movement trajectory curvature. It should be noted that sensitive hardware identifiers (such as hard drive serial numbers) or user privacy data (such as account passwords) undergo hash-based anonymization during the data collection process to improve the user experience.
[0018] In step 102, behavioral fingerprints are dynamically generated based on multidimensional behavioral data, including: The multidimensional behavioral data sequence corresponding to the current usage behavior state is input into a pre-trained generative model to obtain a behavioral fingerprint. In the generative model, features are extracted from the multidimensional behavioral data to obtain key features. The key features are then dynamically weighted and fused to obtain a feature vector. Finally, the feature vector is signed using an encryption algorithm to obtain the behavioral fingerprint.
[0019] It should be noted that step 104 also uses the above-described generation model to obtain the current behavior fingerprint. Specifically, step 104 involves inputting the current multi-dimensional behavior data into the generation model and outputting the current behavior fingerprint. In step 102, the encryption algorithm is preferably an asymmetric national cryptographic algorithm (such as SM2). This high-strength national cryptographic algorithm safeguards the product functionality for developers.
[0020] In a preferred embodiment, the current usage behavior status includes the remaining authorization time, with different remaining authorization times corresponding to different authorization IDs; wherein, the blockchain stores several authorization IDs of the software to be tested. It should be noted that if the multi-dimensional behavior data is the same for several consecutive days, it is possible for the behavior fingerprints to be the same, but the authorization IDs to be different.
[0021] Specifically, for the generative model, it employs LSTM time series analysis, statistical analysis, or CNN deep learning methods to extract key features from each behavioral data point. Then, a convolutional neural network with an attention mechanism is used to weightedly fuse these key features into a comprehensive feature vector. The weights are dynamically adjusted based on the importance of each behavioral data point to software authorization. Thus, by using multi-dimensional behavioral data sequences from the normal operation process as a training set, a pre-trained generative model is obtained. For example, a behavioral fingerprint is generated based on one day's worth of multi-dimensional behavioral data, bound to a unique authorization ID, and then uploaded to the blockchain for verification. In this case, different authorization IDs represent different remaining authorization days.
[0022] In a more preferred embodiment, the model is also updated periodically. For example, as described above, the latest (e.g., the last 7 days) multidimensional behavioral data of authorized users is collected every 30 days to fine-tune the model to adapt to normal changes in the behavior habits of authorized users. At the same time, a feature deviation threshold is set to trigger an anomaly warning when the deviation of the input behavioral data exceeds 20%.
[0023] In a preferred embodiment, key features are dynamically weighted and fused to obtain a feature vector, including: For each key feature, perform the following: Determine the weighting factors for this key feature; among which, the weighting factors include the behavioral time factor, the environmental risk coefficient, and the feature correlation factor; The weights are calculated based on the fundamental static weights and weight influence factors of this key feature. The feature vector is obtained by weighting and fusing the feature values and weights of each key feature.
[0024] It should be noted that the feature vector is obtained by weighted fusion of the feature values of each key feature and their corresponding weights. This process includes: standardizing the feature values of each key feature (including removing duplicate, invalid, or outlier data, normalization, Z-score standardization, etc.) to eliminate differences and obtain standardized feature values; concatenating the key features to obtain a preprocessed feature vector; and then weighted fusion of the standardized feature values of each key feature with their corresponding weights to generate the final feature vector. This fixed concatenation order increases the difficulty for attackers to forge a complete vector.
[0025] In this embodiment of the invention, since different key features are heterogeneous and their feature value types are different, the standardization preprocessing methods (including dimensionality reduction, summary extraction, numerical normalization, and semantic code preservation) for different types of feature values are also different. This invention does not specifically limit the standardization preprocessing methods. For example, feature value types include numerical data, trajectory data, categorical features, time series features, etc. For numerical data such as click interval, CPU usage, time interval, and memory call frequency, Min-Max normalization or Z-score standardization is used to map to the [0,1] interval. For trajectory data such as mouse movement trajectory curvature, after unifying the trajectory length through piecewise linear interpolation, Z-score standardization is applied to eliminate dimensional differences. For categorical features such as communication IP, port, and request type, one-hot encoding or hash encoding is used. For time series features, they are converted into vectors through sequence embedding (such as Word2Vec) and then Z-score standardization is performed. For example, key features include A1, A2, A3, and A4, and their corresponding weight values are respectively Their eigenvalues, after standardization preprocessing, are as follows: The preprocessed feature vector is obtained after receiving the data. The final feature vector is It should be noted that the sum of the weights corresponding to all key features here is not 1.
[0026] In one specific implementation, the weights are calculated based on the fundamental static weights and weight influence factors of this key feature, including: Based on the real-time data of this key feature within the corresponding sliding time window, the variance at the initial binding time and the variance at the current time are calculated. The behavior time factor is calculated based on the variance at the initial binding time, the variance at the current time, and the continuous runtime of the software to be tested. The environmental risk coefficient is determined based on the current network environment and the detection status of abnormal behavioral events. The correlation strength between the key feature and other key features is determined from the preset feature association library, and the feature association factor is determined based on the correlation strength and the weight of the corresponding correlation strength; The weights are calculated based on the basic static weights of the key feature, the behavioral time factor, the environmental risk coefficient, and the feature correlation factor.
[0027] In a more specific implementation, the weights are determined by the following formula: in, Key features i The weights; Key featuresi The basic static weights; Key features i The aforementioned behavioral time factor; Key features i Environmental risk coefficient; Key features i The aforementioned characteristic correlation factors; α , β , γ , δ These are the importance coefficients of the corresponding basic static weights, behavioral time factors, environmental risk coefficients, and feature correlation factors, respectively.
[0028] In this invention, the inherent importance of key features is represented by a basic static weight (values ranging from 0 to 1); current volatility is represented by a behavioral time factor (values ranging from 0 to 1); environmental threats are represented by an environmental risk coefficient (values ≥ 1), with higher values indicating amplified weights; and a feature correlation factor (values ranging from -1 to 1), with positive values indicating abnormal correlations and negative values indicating normal correlations. Thus, a weighted average ensures that the final weight of the key feature falls within a reasonable range. This weight reflects the score of each security dimension, and the higher the weight value, the greater the degree of change and instability of the corresponding key feature.
[0029] In a more specific implementation, the basic static weights are calculated using the following formula: in, These are the basic static weights; Key features i coefficient of variation; Key features i The security value coefficient; a higher value indicates greater security value for this key feature. i The more important it is for identifying malicious behavior; , These are the weighting coefficients for the coefficient of variation and the safety value coefficient, respectively. and The sum is 1.
[0030] It should be noted that the security value coefficients corresponding to each key feature were pre-set based on expert experience, and the key features and their corresponding coefficients of variation were pre-determined using historical software operation data. The security value coefficients and coefficients of variation for each key feature were then stored in the initial database, allowing for direct determination of these coefficients from the initial database to calculate the basic static weights. In this way, the basic static weights balance stability and security.
[0031] In a more specific implementation, the behavioral time factor is determined by the following formula: in, This is the attenuation sensitivity coefficient; Key features i exist t The variance of the values taken within a given time period; Key features i The variance at the initial running time. For example, the attenuation sensitivity coefficient is 0.5.
[0032] It should be noted that, for the initial weights during the initial runtime, t The time is 0, which is the initial running time. Regarding the current weights of the current key features, t The timeframe is the current moment. Specifically, this key feature is collected in... t The real-time sampled value sequence within the corresponding sliding time window (e.g., the past 5 minutes) is standardized and preprocessed to obtain real-time data composed of standardized feature values. The variance of this real-time data is then calculated. For volatile features, the greater the difference between the current variance and the initial variance, the more severe the weight decay. This reflects the stability changes of each key feature over time. By introducing a time-varying behavioral time factor, the behavioral fingerprint is strongly bound to time, making it effective only once. This prevents intercepted fingerprints from being replayed in attacks, improves anti-tampering capabilities and increases the difficulty of cracking, thereby ensuring the security of authorized detection.
[0033] In a more specific implementation, the environmental risk factor is determined by the following formula: in, This represents the basic risk level of the current network environment. for t Time of the first k Boolean indicator function for real-time behavioral anomaly events; For the corresponding number k Risk penalty value for each real-time behavioral anomaly event; N This represents the total number of real-time behavioral anomalies.
[0034] It should be noted that network interaction behavior data also includes the current network environment and the detection status of abnormal behavior events detected based on multi-dimensional behavior data. In this embodiment of the invention, a pre-generated network environment risk level library stores a one-to-one correspondence between network environments and basic risk levels. For example, the basic risk level of a company intranet is 1.0, the basic risk level of a home network is 1.2, and the basic risk level of public WiFi is 1.5, with risk being directly proportional to the basic risk level. The basic risk level of the current network environment can be determined from the network environment risk level library. The Boolean indicator function is 1 or 0; when the detection status of the k-th real-time abnormal behavior event is present, the Boolean indicator function is 1; otherwise, it is 0. The risk penalty value is, for example, 0.1. Thus, for the environmental risk coefficient, for each threat triggered, the total weight is amplified accordingly, making the system more sensitive to changes in all characteristics in a risky environment.
[0035] It should be noted that abnormal behavior events refer to signals that may indicate security risks or abnormal states, obtained through local detection or simple interaction with the authorization server during software operation. Examples of abnormal behavior events include whether the software is running in a virtualized or containerized environment, whether the process has been attached to by a debugger, whether critical memory areas have been modified, whether the login IP's geographical location differs from its usual location, and whether multiple verification requests are made within a very short period.
[0036] In a more specific implementation, the feature association factor is determined by the following formula: in, Key features i With key features j The expected correlation strength between them, ∈[0,1]; for t Key features of a moment i With key features j The actual strength of the correlation between them; For feature pairs ( i , j Importance weight of relevance ,and .
[0037] It should be noted that, tanhThe hyperbolic tangent function is used to compress the output, preventing a single anomalous association from having an excessive impact on the weights and enhancing system robustness. The expected association strength is statistically derived from historical normal data obtained during the normal operation of the detection software, for example, by using covariance normalization or collinearity probability calculation, and stored in the association database to directly obtain the association strength between feature pairs from the association data. Specifically, for key features with numerical eigenvalues, the Pearson correlation coefficient is used as the expected association strength in historical normal data; for key features with non-numerical eigenvalues, the co-occurrence probability is used as the expected association strength, i.e., the Jaccard similarity coefficient is used as the expected association strength. Similarly, based on the current dataset obtained within the sliding time window corresponding to the current moment, the Pearson correlation coefficient is calculated as the real-time association strength of numerical key features, and the Jaccard similarity coefficient is calculated as the real-time association strength of non-numerical key features. The importance weight is assigned based on the importance of the feature pair to the security of software licensing. For example, a feature pair consisting of GPU model and operating system version is stable and difficult to forge, so it should be given a high importance weight; a feature pair consisting of the current connected WiFi SSID and the location of the public IP address, although unstable, has a reasonable geographical logical relationship between the two and can be given a medium importance weight.
[0038] In this embodiment of the invention, global prior knowledge is provided by historical normal data, and real-time evidence is provided based on the current behavior dataset. The difference between the two is then used as a signal for security risk control. When the correlation at the current moment deviates significantly from the global prior knowledge, the correlation factor of the feature increases, which in turn leads to an increase in weight. The corresponding current feature vector deviates from the feature vector under the same usage behavior state, resulting in an increase in the difference between the current behavior fingerprint and the target behavior fingerprint, so that users can detect abnormal situations in a timely manner.
[0039] In this embodiment of the invention, the three influencing factors of time, environment, and relevance are decoupled, making the weight calculation model easier to understand, debug, and optimize. Simultaneously, the weights of each key feature are no longer fixed but are adjusted in real time based on the key feature's own performance, environmental risk, and relevance to other key features, achieving dynamic weighting and improving anti-tampering capabilities and authorization verification security. Furthermore, by setting an environmental risk coefficient, the entire authorization system possesses basic risk perception capabilities.
[0040] In step 106, the corresponding target behavior fingerprint is obtained from the blockchain based on the authorization ID. The current behavior fingerprint and the target behavior fingerprint are compared to obtain the detection result, including: Based on the moment when the current multidimensional behavior data is acquired, the remaining authorization duration is determined to identify the current authorization ID and the previous authorization IDs before that moment. Retrieve several target behavior fingerprints from the blockchain based on the current authorized ID and past authorized IDs; Determine if there are any key bits in the target behavior fingerprint that are the same as the key bits in the current behavior fingerprint; If the judgment result is yes, calculate the similarity between the current behavior fingerprint and each target behavior fingerprint; Determine whether there is a similarity greater than a first preset threshold; If the judgment result is yes, the detection result is normal operation, and the detection result is stored on the blockchain for evidence, and the transaction hash in the process of storing on the blockchain is associated with the current authorized ID.
[0041] For example, following the previous example, based on the moment when the current multidimensional behavior data is obtained, the remaining authorization duration is determined to be 30 days, so as to determine the current authorization ID and the past authorization IDs of the past 6 days before this moment; and obtain a total of 7 target behavior fingerprints from the blockchain based on the current authorization ID and the past authorization IDs.
[0042] In this embodiment of the invention, by setting key bits in the behavioral fingerprint and prioritizing comparison of whether the key bits in the current behavioral fingerprint are the same as those in the target behavioral fingerprint, anomalies are quickly determined. If the key bit is different from any key bit in the target behavioral fingerprint, an anomaly is directly determined to exist at the current moment. If at least one key bit in the target behavioral fingerprint is the same as a key bit in the current behavioral fingerprint, subsequent determinations are performed to further determine whether the software under test is running normally based on the similarity between the current and target behavioral fingerprints. Thus, by combining user behavior patterns during software operation with behavioral fingerprints, the false alarm rate is reduced, real-time detection of the software under test is successfully achieved, significantly improving the security of software operation. Furthermore, efficient and secure detection can be achieved without requiring user privacy information, enhancing the user experience.
[0043] In this invention, the blockchain network adopts a consortium blockchain architecture. Nodes include software developer servers, third-party evidence storage institution nodes, third-party auditing institutions, and authorized user terminals (optional). Nodes in the blockchain network verify and confirm the process through a consensus mechanism. Once consensus is reached, the node is packaged into a new block and appended to the end of the blockchain. Both the target behavior fingerprint and the current behavior fingerprint are stored on the blockchain. Simultaneously, each detection result generates a blockchain transaction, which is uploaded to the consortium blockchain for storage. The transaction hash is associated with the current authorized ID, ensuring the immutability and traceability of the detection log.
[0044] Following step 106, if the detection result indicates an abnormality, the following steps are also included: A1. Determine whether the similarity between the current behavior fingerprint and the target behavior fingerprint is not less than the second preset threshold; if the determination result is yes, then execute A2; otherwise, execute A3. A2. Determine the anomaly level of this abnormal situation as low, and generate an adjustment strategy to enable the authorized use of the software under test through this adjustment strategy; A3. Determine whether the similarity is not less than the third preset threshold; where the second preset threshold is greater than the third preset threshold; if the determination result is yes, then execute A4; otherwise, execute A5; A4. Determine the anomaly level of this abnormal situation as medium, and generate an adjustment strategy to shorten the detection and verification cycle and restrict the authorized functions that can be used. A5. Determine the anomaly level of this abnormal situation as high, and generate an adjustment strategy to stop the authorized use of the software to be detected.
[0045] It should be noted that the first preset threshold is greater than the second preset threshold.
[0046] In this embodiment of the invention, the abnormal situation database stores adjustment strategies corresponding to each abnormal situation, enabling adaptive adjustments based on the current abnormal situation. This ensures the secure operation of the software while maximizing user satisfaction and protecting the rights of the software developer. For example, if the current abnormal situation involves a user changing their network environment due to business trips (e.g., IP address change but other behavioral data remain the same), the abnormality level is determined to be low. The adjustment strategy is to generate a temporary behavioral fingerprint based on a historically trusted environment to allow short-term use. If the abnormality level is medium, the detection and verification cycle needs to be shortened and the authorized functions that can be used restricted. If the abnormality level is high, the authorized use of the software under test needs to be stopped, the authorization ID frozen, and the user needs to submit identity verification materials to the developer to unlock it. It should be noted that when an authorized user changes devices, after identity verification, the original authorized behavioral fingerprint is associated with the de-identified hardware identifier of the new device, and the device association record is updated on the blockchain to achieve a legitimate transfer of authorization.
[0047] like Figure 2 , Figure 3 As shown, this embodiment of the invention provides a software licensing and usage detection device based on blockchain evidence storage. The device embodiment can be implemented through software, hardware, or a combination of both. From a hardware perspective, such as... Figure 2 The diagram shown is a hardware architecture diagram of a computing device housing a software licensing and usage detection device based on blockchain evidence storage, as provided in an embodiment of the present invention. (Except for...) Figure 2In addition to the processor, memory, network interface, and non-volatile memory shown, the computing device in the embodiment may also include other hardware, such as a forwarding chip responsible for processing packets. Taking software implementation as an example, such as... Figure 3 As shown, a device in a logical sense is formed by the CPU of its computing device reading the corresponding computer program from non-volatile memory into memory for execution. This embodiment provides a software licensing and usage detection device based on blockchain evidence storage, comprising: The acquisition module 300 is used to acquire multi-dimensional behavioral data of the software under test during normal operation. Generation module 302 is used to dynamically generate behavioral fingerprints based on the multidimensional behavioral data; The evidence storage module 304 is used to bind the behavior fingerprint with the authorization ID and then upload it to the blockchain; wherein, the authorization ID is used to represent the current usage behavior status; The generation module 302 is also used to dynamically generate the current behavior fingerprint based on the real-time acquired current multidimensional behavior data; The detection module 306 is used to obtain the corresponding target behavior fingerprint from the blockchain according to the authorization ID, compare the current behavior fingerprint and the target behavior fingerprint, and obtain the detection result.
[0048] In some specific implementations, the acquisition module 300 can be used to perform the above step 100, the generation module 302 and the evidence storage module 304 can be used to perform the above step 102, the generation module 302 is used to perform the above step 104, and the detection module 306 can be used to perform the above step 106.
[0049] Since the contents of the above-described apparatus are based on the same concept as the method embodiments of the present invention, the specific contents can be found in the descriptions in the method embodiments of the present invention, and will not be repeated here.
[0050] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on a software licensing and usage detection device based on blockchain evidence storage. In other embodiments of the present invention, a software licensing and usage detection device based on blockchain evidence storage may include more or fewer components than illustrated, or combine some components, or split some components, or arrange different components. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0051] The information interaction and execution process between the modules in the above-mentioned device are based on the same concept as the method embodiment of the present invention, and the specific details can be found in the description of the method embodiment of the present invention, and will not be repeated here.
[0052] This invention also provides a computing device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements a software licensing and usage detection method based on blockchain evidence storage according to any embodiment of this invention.
[0053] This invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform a software licensing and usage detection method based on blockchain evidence storage according to any embodiment of this invention.
[0054] Embodiments of this application also provide a computer program product, which includes a computer program. A processor of a computer device reads the computer program from a computer-readable storage medium and executes the computer program, causing the computer device to perform a software license usage detection method based on blockchain evidence storage as described in any of the above embodiments.
[0055] Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the embodiments described above is stored, and the computer (or CPU or MPU) of the system or apparatus may read and execute the program code stored in the storage medium.
[0056] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute part of the present invention.
[0057] Storage media embodiments for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.
[0058] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit programs for use by or in conjunction with an instruction execution system, system, or device.
[0059] The program code contained on a computer-readable medium may be transmitted using any suitable medium, including, but not limited to, wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0060] Computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0061] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.
[0062] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion module connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion module execute some and all of the actual operations, thereby realizing the function of any of the above embodiments.
[0063] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0064] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.
[0065] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for detecting software licensing based on blockchain evidence storage, characterized in that, include: Acquire multidimensional behavioral data of the software under test during normal operation; A behavioral fingerprint is dynamically generated based on the multidimensional behavioral data, and then the behavioral fingerprint is bound to an authorization ID and uploaded to the blockchain; wherein, the authorization ID is used to represent the current usage behavior status; Dynamically generate the current behavior fingerprint based on real-time acquired current multidimensional behavior data; The corresponding target behavior fingerprint is obtained from the blockchain based on the authorized ID, and the current behavior fingerprint and the target behavior fingerprint are compared to obtain the detection result.
2. The method according to claim 1, characterized in that, The multidimensional behavioral data includes device behavioral data, software interaction behavioral data, network interaction behavioral data, and user operation behavioral data; The dynamic generation of behavioral fingerprints based on the multidimensional behavioral data includes: The multidimensional behavior data sequence corresponding to the current usage behavior state is input into a pre-trained generative model to obtain a behavior fingerprint. In the generative model, features are extracted from the multidimensional behavior data to obtain key features. The key features are then dynamically weighted and fused to obtain a feature vector. Finally, the feature vector is signed using an encryption algorithm to obtain the behavior fingerprint.
3. The method according to claim 2, characterized in that, The dynamic weighted fusion of the key features to obtain the feature vector includes: For each of the aforementioned key features, the following is performed: Determine the weighting factors for this key feature; wherein, the weighting factors include behavioral time factors, environmental risk coefficients, and feature correlation factors; The weights are calculated based on the fundamental static weights of this key feature and the weight influence factors. The feature vector is obtained by weighting and fusing the feature values of each key feature with the weights.
4. The method according to claim 3, characterized in that, Also includes: Based on the real-time data of this key feature within the corresponding sliding time window, the variance at the initial running time and the variance at the current time are calculated. The behavior time factor is calculated based on the variance of the initial running time, the variance of the current time, and the continuous running time of the software to be tested. The environmental risk coefficient is determined based on the current network environment and the detection status of abnormal behavioral events. The correlation strength between the key feature and other key features is determined from a preset feature association library, and the feature association factor is determined based on the correlation strength and the weight corresponding to the correlation strength; The weight is calculated based on the basic static weight of the key feature, the behavioral time factor, the environmental risk coefficient, and the feature correlation factor; preferably, the weight is determined by the following formula: in, Key features i The weights; These are the basic static weights; The time factor of the behavior; The environmental risk coefficient is mentioned above; The feature correlation factor; α , β , γ , δ These are the corresponding importance coefficients.
5. The method according to claim 1, characterized in that, The current usage behavior status includes the remaining authorization time, and different remaining authorization times correspond to different authorization IDs; wherein, the blockchain stores several authorization IDs of the software to be tested; The step of obtaining the corresponding target behavior fingerprint from the blockchain based on the authorized ID, comparing the current behavior fingerprint with the target behavior fingerprint, and obtaining the detection result includes: Based on the moment when the current multidimensional behavior data is acquired, the remaining authorization duration is determined to determine the current authorization ID and the previous authorization IDs before that moment; Based on the current authorized ID and the previous authorized ID, obtain several target behavior fingerprints from the blockchain; Determine whether there are any key bits in the target behavior fingerprint that are the same as the key bits in the current behavior fingerprint; When the judgment result is yes, calculate the similarity between the current behavior fingerprint and each of the target behavior fingerprints; Determine whether there is a similarity greater than a first preset threshold; If the judgment result is yes, then the detection result is normal operation, and the detection result is stored on the blockchain for evidence, and the transaction hash in the process of storing on the blockchain is associated with the current authorized ID.
6. The method according to any one of claims 1 to 5, characterized in that, When the detection result indicates an abnormality, the following is also included: A1. Determine whether the similarity between the current behavior fingerprint and the target behavior fingerprint is not less than a second preset threshold; if the determination result is yes, then execute A2; otherwise, execute A3. A2. Determine the anomaly level of this abnormal situation as low, and generate an adjustment strategy to enable the authorized use of the software under test through this adjustment strategy; A3. Determine whether the similarity is not less than a third preset threshold; wherein the second preset threshold is greater than the third preset threshold; if the determination result is yes, then execute A4; otherwise execute A5; A4. Determine the anomaly level of this abnormal situation as medium, and generate an adjustment strategy to shorten the detection and verification cycle and restrict the authorized functions that can be used. A5. Determine the anomaly level of this abnormal situation as high, and generate an adjustment policy to stop the authorized use of the software to be detected through this adjustment policy.
7. A software licensing and usage detection device based on blockchain-based evidence storage, characterized in that, include: The acquisition module is used to acquire multidimensional behavioral data of the software under test during normal operation. The generation module is used to dynamically generate behavioral fingerprints based on the multidimensional behavioral data; The evidence storage module is used to bind the behavior fingerprint with the authorization ID and then upload it to the blockchain; wherein, the authorization ID is used to represent the current usage behavior status; The generation module is also used to dynamically generate the current behavior fingerprint based on the real-time acquired current multidimensional behavior data; The detection module is used to obtain the corresponding target behavior fingerprint from the blockchain based on the authorized ID, compare the current behavior fingerprint with the target behavior fingerprint, and obtain the detection result.
8. A computing device comprising a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program, implements the method as described in any one of claims 1-6.
9. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method of any one of claims 1-6.
10. A computer program product, characterized in that, Includes computer instructions that, when executed by a processor, implement the steps of the method as described in any one of claims 1-6.