Dynamic plug-in based method and system for preventing copying of server code authorization running

CN122839360APending Publication Date: 2026-09-29BEIJING TITANIUM CORE INTERACTIVE INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611116377.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-27
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0002]当前服务端商业软件的知识产权保护与授权管控多采用静态授权文件、硬件加密锁或单一硬件指纹绑定方案,核心业务功能与主程序代码静态耦合编译,易通过反编译、内存转储等手段被窃取复制,授权文件也常被破解篡改后批量克隆使用,难以形成有效的代码防复制屏障

Benefits of technology

1、本发明通过构建多层级代码防复制防护体系,将核心业务功能抽离为独立加密动态插件,结合插件规范标识、授权证书与环境年轮链实现三重身份校验,通过内存安全区完成代码解密装载并即时擦除明文密钥,有效抵御静态反编译、内存转储与授权克隆破解行为。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122839360A_ABST
    Figure CN122839360A_ABST
Patent Text Reader

Abstract

The application discloses a server code anti-copy authorization running method and system based on a dynamic plug-in and relates to the technical field of data security.The application separates core business functions from a server main program and compiles the core business functions into a dynamic plug-in, and obtains an environment characteristic of a client main program to construct an environment ring chain.When a client requests to obtain the dynamic plug-in, the server performs ring backtracking verification according to a real-time environment ring chain, issues an authorization certificate according to a backtracking verification result, and verifies the legality of the authorization certificate and the continuity of the environment ring chain when the client main program loads the dynamic plug-in.According to a verification result, the dynamic plug-in is separated to obtain a dynamic plug-in main body and code segment decryption meta information, an authorization flow pool is set, and the environment ring chain obtains an authorization token from the authorization flow pool to complete dynamic plug-in installation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically to a method and system for preventing copying and authorizing the execution of server-side code based on dynamic plugins. Background Technology

[0002] Currently, intellectual property protection and licensing management for server-side commercial software mostly rely on static license files, hardware dongles, or single hardware fingerprint binding schemes. Core business functions are statically coupled with the main program code, making them vulnerable to theft and copying through decompilation, memory dumping, and other methods. License files are also frequently cracked, tampered with, and cloned in batches, making it difficult to form an effective code copy protection barrier. Furthermore, existing dynamic plug-in licensing schemes generally depend on single-point environment fingerprint verification, lacking a continuous lifecycle tracking mechanism for the client's operating environment. They cannot identify covert cracking methods such as time rollback, environment cloning, and license rollback. When the client's hardware or system environment experiences normal drift, license misjudgment and failure are likely to occur, resulting in insufficient environment adaptability.

[0003] In addition, traditional authorization mechanisms are mostly fixed node binding modes, which cannot flexibly transfer authorized resources and are difficult to adapt to application scenarios with distributed deployment and elastic scaling of instances. The granularity of concurrent authorization control is relatively coarse, and it is impossible to audit the authorization usage status and abnormal cloning behavior in real time. There are management vulnerabilities such as excessive use of authorization and unauthorized reuse. It cannot simultaneously meet the dual requirements of high-strength code copy prevention and flexible authorization control. To address this, a server-side code copy prevention authorization operation method and system based on dynamic plugins is provided. Summary of the Invention

[0004] The purpose of this invention is to provide a method and system for preventing copying and authorizing the execution of server-side code based on dynamic plugins, so as to solve the problems in the background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solution: The method for preventing copying and authorizing the execution of server-side code based on dynamic plugins includes the following steps: Step S1: Extract the core business functions from the server-side main program and compile them into dynamic plugins, and obtain the runtime environment characteristics of the client-side main program to construct the environment timeline. Step S2: When the client requests to obtain the dynamic plugin, the server performs a backtracking verification based on the real-time environment's annual ring chain and issues an authorization certificate based on the backtracking verification result. Step S3: When the client main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environment tree chain. Based on the verification results, it separates the dynamic plugin and obtains the dynamic plugin body and code segment decryption metadata. Step S4: Set up the authorized flow pool. The environment ring chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.

[0006] Furthermore, the process of extracting core business functions from the main server program and compiling them into dynamic plugins includes: The code segments involving core business functions in the server-side main program are extracted from the main program framework. The extracted core business function code covers all functional modules that require authorization control. The extracted core business function code is compiled independently to generate dynamic plugin files that conform to the target operating platform architecture. The dynamic plugin file format adopts the dynamic link library specification of the operating platform architecture, and the plugin is divided into three independent storage areas: code segment, data segment, and metadata segment. At the same time, a structured plugin specification identifier is generated based on all associated attributes of the dynamic plugin, which serves as the unique identity credential of the dynamic plugin.

[0007] Furthermore, the process of obtaining the runtime environment characteristics of the client's main program and constructing the environment timeline includes: When the client main program is launched for the first time, it automatically collects multi-dimensional operating environment characteristics of the client device to form a multi-dimensional environmental feature vector. Key events throughout the entire lifecycle of the client's main program are recorded sequentially as annual ring nodes, and then linked together in the form of a one-way hash chain to form an environment annual ring chain. The environment annual ring chain is used to completely record the changing trajectory of the client's environment. When the client main program is installed and started for the first time, it generates a root tree node and records the environment fingerprint digest at the time of the first start. After concatenating all the fields of the root tree node, the hash value is calculated to obtain the root hash of the environment tree chain. The root hash serves as the root of trust for the entire environment tree chain.

[0008] Furthermore, when a client requests a dynamic plugin, the server performs a backtracking verification process based on the real-time environment's annual ring chain, which includes: When the client main program needs to load core business functions, it sends a dynamic plugin acquisition request to the server. After receiving the request, the server verifies the format integrity and identity legality of the request message. After the verification is passed, the annual cycle backtracking verification process is started to perform multi-dimensional legality verification on the environmental annual cycle chain submitted by the client. The replay event sequence checks the unidirectional increment of timestamps, whether future events or time rollbacks occur, and identifies cloning behavior by comparing the global environment's annual ring chain to see if the same chain is reproduced on multiple terminals.

[0009] Furthermore, the process of issuing authorization certificates based on the backtracking verification results includes: After confirming the client environment is legitimate, the server locates the target dynamic plugin based on the target plugin function identifier in the request message, and packages and sends the authorization certificate and the decryption metadata of the encrypted dynamic plugin's code segment separately. The authorization certificate includes a plugin summary, plugin specification identifier, certificate validity and expiration time, verification mode, and hardware or runtime environment fingerprint required according to the mode; The server uses a symmetric encryption algorithm to encrypt the code segment of the target dynamic plugin, generating an encrypted dynamic plugin. At the same time, the key required for decrypting the code segment is encapsulated as code segment decryption metadata and stored separately from the encrypted dynamic plugin. Subsequently, the authorization certificate, the encrypted dynamic plugin, and the code segment decryption metadata are packaged separately and sent to the client through an encrypted transmission channel.

[0010] Furthermore, the process of verifying the validity of the authorization certificate and the continuity of the environment's timeline when the client main program loads the dynamic plugin includes: After the client main program receives the packaged file and completes local storage, it performs a full-dimensional legality verification of the authorization certificate before loading the dynamic plugin. This includes the plugin summary, plugin specification identifier, certificate validity and expiration time, verification mode, and the legality verification of the hardware or runtime environment fingerprint required by the mode. If any verification fails, the subsequent decoding process stops. After the authorization certificate passes the validity verification, the continuity and compliance of the local environment tree ring chain are verified. This includes checking the continuity of the local tree ring chain since the root hash, extracting the root hash value of the local environment tree ring chain, comparing it with the tree ring root hash embedded in the authorization certificate, and checking the hash association relationship of the local environment tree ring chain node by node starting from the root node.

[0011] Furthermore, the process of separating the dynamic plugin and obtaining the dynamic plugin body and code segment decryption metadata based on the verification results includes: Based on the verification results, the client program obtains the code segment decryption metadata from the dynamic plugin. The client program executes the decryption and loading operations of the dynamic plugin. The client program extracts the code segment decryption metadata from the plugin and parses the encrypted decryption key from the authorization certificate. It calls the client memory security area interface and passes the code segment decryption metadata and the key into the memory security area. Using the decryption key in the authorization certificate, the client program generates a one-time code decryption key and an initialization vector in the memory security area by combining the hash value of the current annual ring node. Within the memory-safe zone, the generated one-time code decryption key and initialization vector are used to complete the decryption, relocation, and dynamic loading of the code segment, resulting in the plaintext code segment. Subsequently, the absolute address references in the plaintext code segment are corrected according to the dynamic plugin, thus completing the memory relocation of the plaintext code segment.

[0012] Furthermore, the process of setting up an authorized flow pool includes: The server builds an authorization pool as a unified management and scheduling carrier for authorization tokens. The total number of authorization tokens in the pool corresponds to the maximum concurrent authorization purchased by the customer. Each authorization token in the authorization pool is bound to a plugin invocation identifier, and each authorization token in the pool is bound to a unique plugin invocation identifier; Each authorization token contains a unique token serial number, a bound plugin call identifier, a token status field, and an occupying terminal identifier. The token status is divided into idle, occupied, frozen, and revoked.

[0013] Furthermore, the process by which the Environmental Ring Chain obtains authorization tokens from the authorization pool to complete the dynamic plugin installation includes: When a tree ring node starts, it obtains an authorization token from the pool by borrowing. When the client's tree ring node starts the dynamic plugin loading process, it automatically sends a token borrowing request to the server's authorization flow pool. The token borrowing request carries the current tree ring node identifier, the corresponding plugin call identifier code, and the client's identity identifier. After the server verifies the legality of the token borrowing request, it selects an idle authorization token with the corresponding plugin call identifier from the authorization flow pool, marks the token status as occupied and binds it to the current tree ring node identifier, and at the same time sends the authorization token to the client. After obtaining the authorization token, the client generates an authorization borrowing ring event and reports it to the server. At the same time, the event is written to the local environment ring chain. When the ring node is released or scaled down, the client actively returns the authorization token and generates a cancellation ring event. When the dynamic plugin is uninstalled, the client node is scaled down, or the main program exits normally, the corresponding ring node actively returns the occupied authorization token to the server.

[0014] A server-side code copy protection authorization system based on dynamic plugins includes a dynamic plugin building module, an authorization verification module, and a plugin loading verification module. The dynamic plugin building module is used to extract core business functions from the server-side main program and compile them into dynamic plugins, and to obtain the runtime environment characteristics of the client-side main program to build an environment timeline. The verification and authorization module is used to perform backtracking verification based on the real-time environmental tree ring chain when the client requests to obtain the dynamic plugin, and issue an authorization certificate based on the backtracking verification result. When the client's main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environmental tree ring chain, and separates the dynamic plugin based on the verification result to obtain the dynamic plugin body and code segment decryption metadata. The plugin loading verification module is used to set up the authorized flow pool, and the environment chronology chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.

[0015] The technical effects and advantages provided by the present invention in the above technical solution are as follows: 1. This invention constructs a multi-level code anti-copying protection system, extracts core business functions into independent encrypted dynamic plugins, and achieves triple identity verification by combining plugin specification identifiers, authorization certificates and environment chronology chains. The code is decrypted and loaded through a memory security zone and the plaintext key is erased in real time, effectively resisting static decompilation, memory dumping and authorization cloning cracking behaviors.

[0016] 2. This invention enables the flexible borrowing and return of authorized tokens by relying on an authorized liquidity pool, adapting to the operational needs of distributed nodes for elastic scaling up and down, effectively improving the utilization rate of authorized resources. At the same time, combined with the annual cycle backtracking verification mechanism, it performs real-time auditing on all annual cycle nodes, effectively identifying violations such as time rollback, chain structure breakage, and abnormal branch cloning, triggering immediate revocation and global isolation, realizing full lifecycle management of authorization, and effectively avoiding the risks of excessive authorization usage and illegal reuse. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0018] Figure 1 This is a flowchart of the method of the present invention.

[0019] Figure 2 This is a system block diagram of the present invention. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Please see Figure 1 As shown, the server-side code copy protection authorization method based on dynamic plugins includes the following steps: Step S1: Extract the core business functions from the server-side main program and compile them into dynamic plugins, and obtain the runtime environment characteristics of the client-side main program to construct the environment timeline. Step S2: When the client requests to obtain the dynamic plugin, the server performs a backtracking verification based on the real-time environment's annual ring chain and issues an authorization certificate based on the backtracking verification result. Step S3: When the client main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environment tree chain. Based on the verification results, it separates the dynamic plugin and obtains the dynamic plugin body and code segment decryption metadata. Step S4: Set up the authorized flow pool. The environment ring chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.

[0022] Furthermore, step S1 is implemented through the following process: Step S101: Extract the core business functions from the server-side main program and compile them into dynamic plugins. The specific process includes: The code segments involving core business functions in the main server program are completely extracted from the main program framework. The extraction process follows the principle of interface standardization. A unified function call entry point, parameter passing specification and return value format are defined for the extracted code segments to ensure that the dynamic plugin and the main program only interact through standardized interfaces and there is no direct code dependency and memory address coupling. The extracted core business function code covers all functional modules that require authorization control. After the code is extracted, the main program is trimmed and compiled, all plain text code segments of core business functions are removed, and only the plugin loading engine, interface scheduling module and basic running framework are retained, so that the main program itself does not have complete business execution capabilities and must rely on dynamic plugins to complete the core function operation. The extracted core business function code is compiled independently to generate dynamic plugin files that conform to the target operating platform architecture. The dynamic plugin file format adopts the dynamic link library specification of the operating platform architecture, and the plugin is divided into three independent storage areas: code segment, data segment, and meta information segment. The code segment stores the encrypted core business instruction sequence, the data segment stores the constants and static variables required for the plugin to run, and the meta information segment stores the basic attribute information of the plugin and the auxiliary data required for decryption and verification. Simultaneously, a structured plugin specification identifier is generated based on the full set of associated attributes of the dynamic plugin. The plugin specification identifier serves as the unique identity credential of the dynamic plugin and accompanies the plugin's distribution, authorization, and loading process throughout. The plugin specification identifier includes associated attributes such as symbol table, instruction segment hash, and compilation timestamp.

[0023] Step S102: Obtain the runtime environment characteristics of the client's main program and construct the environment chronology chain. The specific process includes: When the client main program is launched for the first time, it automatically collects multi-dimensional operating environment characteristics of the client device to form a multi-dimensional environmental feature vector. The feature dimensions cover four levels: hardware layer, system layer, software layer and operating status layer. Each level contains no less than 5 subdivided feature indicators. Hardware layer features include CPU model and serial number, motherboard chipset identifier, hard drive unique identifier, network card MAC address, memory capacity and timing parameters, and trusted execution environment hardware identifier; system layer features include operating system version and kernel version, system installation time, system unique identifier, and system security configuration status; software layer features include installed core runtime library version, main program installation path and version number, and critical system service running status; runtime status layer features include current system runtime, CPU core utilization, memory utilization ratio, and network connection status. After normalization, all environmental features form a fixed-dimensional multi-dimensional environmental feature vector, which serves as the base data for the environmental fingerprint. Key events throughout the entire lifecycle of the client's main program are recorded sequentially as tree ring nodes, and then linked together in a one-way hash chain to form an environment tree ring chain. This environment tree ring chain is used to completely record the changing trajectory of the client's environment. The construction process of the environment tree ring chain is as follows: Key events such as client startup, configuration changes, time jump detection, plugin loading, plugin uninstallation, authorization changes, system hardware changes, and system software upgrades are defined as year-ring node trigger events. When each type of event occurs, year-ring node generation is automatically triggered. Each year-ring node contains the hash of the previous year-ring node, event type, event timestamp, and environment fingerprint digest, forming a unidirectional and irreversible hash chain. The hash of the previous year-ring node is the overall hash value of the previous year-ring node, which is used to build the chain association and ensure the irreversibility of the chain. When the client program is first installed and launched, a root tree node is generated, and the environment fingerprint digest at the time of the first launch is recorded. After concatenating all fields of the root tree node, the hash value is calculated to obtain the root hash of the environment tree chain. The root hash serves as the root of trust for the entire environment tree chain and cannot be modified throughout the process. Each time a critical event is triggered, a new tree node is generated according to the standard structure. The hash field of the previous tree node of the new tree node is filled into the hash value of the current end node of the chain. After calculating the hash value of all fields of the new tree node, the tree node is appended to the end of the environment tree chain to complete the chain update. All tree nodes are arranged in the order of their generation, forming a unidirectional and irreversible chain. It should be noted that the event type is the standardized code of the event corresponding to the current node; the event timestamp is the system time when the event is triggered; and the environmental fingerprint summary is the summary value generated by hashing the multi-dimensional feature vector of the environment collected when the event is triggered, which is used to record the environmental state at the time of generation of the annual ring node.

[0024] Furthermore, step S2 is implemented through the following process: Step S201: When the client requests to obtain the dynamic plugin, the server performs a backtracking verification based on the real-time environment's annual ring chain. The specific process includes: When the client main program needs to load core business functions, it sends a dynamic plugin acquisition request to the server. The request message carries the client identity identifier, the complete node sequence of the current environment's annual ring chain, the function identifier of the target plugin, and the current main program version number. After receiving the request, the server first verifies the format integrity and identity validity of the request message. If the verification is successful, the annual ring backtracking verification process is initiated to perform multi-dimensional legality verification on the environmental annual ring chain submitted by the client. The replay event sequence checks the unidirectional increment of timestamps, whether future events or time rollbacks occur, and identifies cloning behavior by comparing the global environment's annual ring chain to see if the same chain is reproduced on multiple terminals. The process includes: The server replays all event sequences of the environmental tree chain submitted by the client in the order of generation, verifying the unidirectional increment of the timestamp of each tree node. The verification rule is: the event timestamp of the subsequent tree node must be strictly greater than the event timestamp of the preceding tree node; timestamps that are equal or decreasing are not allowed. At the same time, the timestamp of each tree node is compared with the server's global standard time. If a node's timestamp is later than the server's current standard time, it is determined that a future event has occurred; if a subsequent tree node's timestamp is earlier than the preceding tree node, it is determined that a time rollback has occurred. If either a future event or a time rollback occurs, the timing verification is deemed to have failed, and the request message is directly rejected. Starting from the root ring node of the environmental ring chain, verify in sequence whether the hash field of the previous year's ring node is completely consistent with the calculated hash value of the previous year's ring node to ensure that there are no breaks, tamperings, or node insertions in the entire chain; if the hash association of any ring node does not match, it is determined that the continuity of the environmental ring chain is broken and the verification fails. The server stores a global environment tree chain database of all legitimate clients. It compares the submitted tree chain with all historical environment tree chains in the global environment tree chain database node by node to determine if the same environment tree chain is reproduced in multiple reports from different clients. If the root hash and intermediate node sequence of the environment tree chain are associated with two or more different client identities, it is determined that there is an environment cloning behavior, that is, the client attempts to bypass authorization restrictions by copying environment data and forging the environment tree chain. After identifying the cloning behavior, the server directly marks the corresponding client as a risk terminal, rejects the request, and updates the list of risk terminals simultaneously.

[0025] Step S202: Issue an authorization certificate based on the backtracking verification results. The specific process includes: After confirming the client environment is legitimate, the server locates the target dynamic plugin based on the target plugin function identifier in the request message, embeds the encrypted environment commitment value, tree root hash and access policy into the authorization certificate, and then separates and packages them with the decryption metadata of the encrypted dynamic plugin's code segment and sends them out. The environment commitment value is the data encrypted by the server's private key after the client's environment fingerprint digest is used for local environment matching and verification on the client; the tree root hash is the tree root hash of the environment that passed the verification this time, which is used for chain root consistency verification when the client loads dynamic plugins in the future; the access policy includes four types of control rules: allowed runtime of the plugin, maximum number of concurrent instances, allowed scope of functional permissions, and verification mode requirements, which are used to limit the usage boundaries of the plugin. The authorization certificate includes a plugin summary (derived from the plugin file content), a plugin specification identifier, certificate validity and expiration times, verification mode (online full verification / offline verification / online skip hardware signature), and the hardware or runtime environment fingerprint required according to the mode; The server uses a symmetric encryption algorithm to encrypt the code segment of the target dynamic plugin, generating an encrypted dynamic plugin. At the same time, the key required for decrypting the code segment is encapsulated as code segment decryption metadata and stored separately from the encrypted dynamic plugin. Subsequently, the authorization certificate, the encrypted dynamic plugin, and the code segment decryption metadata are packaged separately and sent to the client through an encrypted transmission channel.

[0026] Furthermore, step S3 is implemented through the following process: Step S301: When the client main program loads the dynamic plugin, it verifies the validity of the authorization certificate and the continuity of the environment's timeline. The specific process includes: After the client program receives the packaged file and completes local storage, it performs a full-dimensional legality check on the authorization certificate before loading the dynamic plugin. If any check fails, the subsequent decoding process stops. Obtain the hash digest of the entire encrypted dynamic plugin file stored locally and compare it with the plugin digest recorded in the authorization certificate. If the two hash digests are completely consistent, the plugin file is determined to be complete and has not been tampered with; if they are inconsistent, it means that the plugin file may have been replaced, tampered with, or corrupted during transmission, and the verification fails. Obtain the current system time and compare it with the certificate's effective and expiration times in the authorization certificate; if the current time is between the effective and expiration times, the authorization certificate is considered valid; if the current time is earlier than the effective time or later than the expiration time, the authorization certificate is considered expired and the verification fails. Extract the plugin specification identifier from the encrypted dynamic plugin metadata segment and compare it item by item with the plugin specification identifier attached to the authorization certificate, including three dimensions: symbol table structure, instruction segment hash value, and compilation timestamp. If all three dimensions match, the authorization certificate is determined to correspond to the current plugin. If any dimension does not match, the authorization certificate is determined to be unsuitable for the current plugin, and there is a risk of certificate theft, and the verification fails. Read the plugin loading method of the current client, distinguish between remote real-time loading and local cache loading, and match it with the verification mode recorded in the authorization certificate; remote loading corresponds to the online class verification mode, and local loading corresponds to the offline verification mode; if the loading method does not match the certificate verification mode, the verification fails. In the online full verification mode that requires hardware verification, the local hardware is called to collect the real-time environmental characteristics of the current device to generate a real-time environmental fingerprint summary, which is then matched with the runtime environment fingerprint recorded in the authorization certificate. If the difference between the real-time fingerprint and the certificate fingerprint is within the preset environment drift threshold, the environment fingerprint is determined to match. If the difference exceeds the threshold, it indicates that the runtime environment has undergone a major change and there is a risk of authorization migration and theft, and the verification fails. After the authorization certificate passes the validity verification, the continuity and compliance of the local environmental tree chain on the client are further verified. The continuity of the environmental tree chain is checked by verifying the continuity of the local tree chain since the root hash and confirming that there are no breaks or rollbacks. Extract the root hash value of the local environment's tree ring chain and compare it with the tree ring root hash embedded in the authorization certificate. If the two are completely consistent, it is determined that the current environment's tree ring chain and the chain at the time of authorization issuance originate from the same trust root, and the operating environment has not been completely replaced. If they are inconsistent, it is determined that the environment's tree ring chain has been replaced or reset, and the verification fails. Starting from the root node, check the hash association of the local environment's annual ring chain node by node to confirm that the hash of the previous node of each node corresponds one-to-one with the hash value of the preceding node. The entire local environment's annual ring chain does not have any broken, missing, or rolled-back annual ring nodes. If a broken node is detected, it is determined that the runtime environment state has been maliciously rolled back to a historical version, which poses a risk of bypassing the authorization time limit, and the verification fails.

[0027] Step S302: Based on the verification results, separate the dynamic plugin to obtain the main body and code segment decryption metadata of the dynamic plugin. The specific process includes: Based on the verification results, the code segment decryption metadata is obtained from the dynamic plugin. After both rounds of verification pass, the client main program executes the decryption and loading operation of the dynamic plugin. The entire process is completed within the memory safe area, ensuring that the plaintext of the core code will not be leaked to the ordinary memory area. The client main program extracts code segment decryption metadata from the plugin and parses the encrypted decryption key from the authorization certificate. It then calls the client memory security area interface to pass the code segment decryption metadata and the key into the memory security area. The ordinary memory space does not retain any plaintext data related to the key. Using the decryption key in the authorization certificate, a one-time code decryption key and an initialization vector are generated in the memory security area in combination with the hash value of the current annual ring node. The one-time code decryption key is only valid for the current load and becomes invalid immediately after the plugin is uninstalled. The key never leaves the memory security area and cannot be read by external processes. Within the memory-safe zone, the generated one-time code decryption key and initialization vector are used to complete the decryption, relocation, and dynamic loading of the code segment, resulting in a plaintext code segment. Subsequently, the absolute address references in the plaintext code segment are corrected according to the dynamic plugin, completing the memory relocation of the plaintext code segment and ensuring that the dynamic plugin can run normally in the current process address space. After the relocation is completed, the plaintext code segment is mapped to the protected execution memory page of the main program process. The protected execution memory page is in an executable-only, non-readable-write state to prevent code from being stolen by memory reading tools, and all plaintext code segment associated data is erased after loading is complete.

[0028] Furthermore, step S4 is implemented through the following process: Step S401: Set up the authorized flow pool. The specific process includes: The server builds an authorization pool as a unified management and scheduling carrier for authorization tokens. The total number of authorization tokens in the pool corresponds to the maximum concurrent authorization purchased by the customer, realizing quantitative control and elastic scheduling of authorization quotas. Each authorization token in the authorization pool is bound to a plugin call identifier. The authorization pool adopts a centralized pool management model. Each authorization token in the pool is bound to a unique plugin call identifier. The plugin call identifier is the smallest authorization unit for dynamic plugin functions. Different dynamic plugins with different functions correspond to different plugin call identifier codes. Each authorization token contains a unique token serial number, a bound plugin call identifier, a token status field, and an occupying terminal identifier. The token status is divided into four types: idle, occupied, frozen, and revoked. Idle tokens can be borrowed by the main program, occupied tokens are bound to the corresponding annual ring node, frozen tokens are temporarily unavailable, and revoked tokens are permanently invalid.

[0029] Step S402: The environmental chronology chain obtains an authorization token from the authorized flow pool to complete the dynamic plugin installation. The specific process includes: The authorization token adopts a dynamic management model of borrowing and returning, and is deeply bound to the lifecycle of the client's annual ring node. The application and release of the authorization token will generate annual ring events and report them to the server in a synchronous manner. When a tree ring node starts, it obtains an authorization token from the pool by borrowing. When the client's tree ring node starts the dynamic plugin loading process, it automatically sends a token borrowing request to the server's authorization flow pool. The token borrowing request carries the current tree ring node identifier, the corresponding plugin call identifier code, and the client's identity identifier. After the server verifies the legality of the token borrowing request, it selects an idle authorization token with the corresponding plugin call identifier from the authorization flow pool, marks the token status as occupied and binds it to the current tree ring node identifier, and at the same time sends the authorization token to the client. After obtaining the authorization token, the client generates an authorization borrowing ring event and reports it to the server. At the same time, the event is written to the local environment ring chain. When the ring node is released or scaled down, the client actively returns the authorization token and generates a cancellation ring event. When the dynamic plugin is uninstalled, the client node is scaled down, or the main program exits normally, the corresponding ring node actively returns the occupied authorization token to the server. After receiving the return request, the server removes the binding relationship between the authorization token and the annual ring node, resets the token status to idle and puts it back into the liquidity pool. At the same time, the client generates an annual ring cancellation event and reports it to the server, synchronously writing it into the local environment's annual ring chain, completing the closed loop of the entire life cycle of the authorization token. The server performs real-time auditing of the annual cycle to ensure that the number of concurrent active tokens does not exceed the authorization limit. It also performs real-time auditing of annual cycle events reported by all terminals, counts the total number of authorized tokens currently in use, and ensures that the number of concurrent active tokens does not exceed the authorization limit of the authorized liquidity pool. When an abnormal annual cycle branch or excessive token usage is detected, the relevant authorization can be revoked immediately and global isolation can be triggered.

[0030] Please see Figure 2 As shown, the server-side code anti-copying authorization system based on dynamic plugins includes a dynamic plugin building module, a verification and authorization module, and a plugin loading verification module. The dynamic plugin building module is used to extract core business functions from the server-side main program and compile them into dynamic plugins, and to obtain the runtime environment characteristics of the client-side main program to build an environment timeline. The verification and authorization module is used to perform backtracking verification based on the real-time environmental tree ring chain when the client requests to obtain the dynamic plugin, and issue an authorization certificate based on the backtracking verification result. When the client's main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environmental tree ring chain, and separates the dynamic plugin based on the verification result to obtain the dynamic plugin body and code segment decryption metadata. The plugin loading verification module is used to set up the authorized flow pool, and the environment chronology chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.

[0031] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for preventing copying and authorizing the execution of server-side code based on dynamic plugins, characterized in that, Includes the following steps: Step S1: Extract the core business functions from the server-side main program and compile them into dynamic plugins, and obtain the runtime environment characteristics of the client-side main program to construct the environment timeline. Step S2: When the client requests to obtain the dynamic plugin, the server performs a backtracking verification based on the real-time environment's annual ring chain and issues an authorization certificate based on the backtracking verification result. Step S3: When the client main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environment tree chain. Based on the verification results, it separates the dynamic plugin and obtains the dynamic plugin body and code segment decryption metadata. Step S4: Set up the authorized flow pool. The environment ring chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.

2. The server-side code anti-copying authorization execution method based on dynamic plugins according to claim 1, characterized in that, The process of extracting core business functions from the main server program and compiling them into dynamic plugins includes: Extract the core business function code segments from the main program framework of the server-side main program. The extracted core business function code covers all functional modules that require authorization control. The extracted core business function code is compiled independently to generate dynamic plugin files that conform to the target operating platform architecture. The dynamic plugin file format adopts the dynamic link library specification of the operating platform architecture, and the plugin is divided into three independent storage areas: code segment, data segment, and metadata segment. At the same time, a plugin specification identifier is generated based on the full association attributes of the dynamic plugin, and the plugin specification identifier serves as the unique identity credential of the dynamic plugin.

3. The server-side code anti-copying authorization execution method based on dynamic plugins according to claim 2, characterized in that, The process of obtaining the runtime environment characteristics of the client's main program and constructing the environment chronology includes: When the client main program is launched for the first time, it automatically collects multi-dimensional operating environment characteristics of the client device to form a multi-dimensional environmental feature vector. Key events throughout the entire lifecycle of the client's main program are recorded sequentially as annual ring nodes, and then linked together in the form of a one-way hash chain to form an environment annual ring chain. The environment annual ring chain is used to completely record the changing trajectory of the client's environment. When the client main program is installed and started for the first time, a root tree node is generated, and the environment fingerprint digest at the time of the first start is recorded. After concatenating all fields of the root tree node, the hash value is calculated to obtain the root hash of the environment tree chain. The root hash serves as the root of trust for the entire environment tree chain. The environmental fingerprint summary is a summary value generated by hashing the multi-dimensional feature vector of the environment collected when the event is triggered, and is used to record the environmental state at the time of generation of the annual ring node.

4. The server-side code copy protection and authorized execution method based on dynamic plugins according to claim 3, characterized in that, When a client requests a dynamic plugin, the server performs a backtracking verification process based on the real-time environment's annual ring chain, which includes: When the client main program needs to load core business functions, it sends a dynamic plugin acquisition request to the server. After receiving the request, the server verifies the format integrity and identity legality of the request message. After the verification is passed, the annual cycle backtracking verification process is started to perform multi-dimensional legality verification on the environmental annual cycle chain submitted by the client. The replay event sequence checks the unidirectional increment of timestamps, whether future events or time rollbacks occur, and identifies cloning behavior by comparing the global environment's annual ring chain to see if the same chain is reproduced on multiple terminals.

5. The server-side code copy protection and authorized execution method based on dynamic plugins according to claim 4, characterized in that, The process of issuing an authorization certificate based on the backtracking verification results includes: After confirming the client environment is legitimate, the server locates the target dynamic plugin based on the target plugin function identifier in the request message, and packages and sends the authorization certificate and the decryption metadata of the encrypted dynamic plugin's code segment separately. The authorization certificate includes a plugin summary, plugin specification identifier, certificate validity and expiration time, verification mode, and hardware or runtime environment fingerprint required according to the mode; The server uses a symmetric encryption algorithm to encrypt the code segment of the target dynamic plugin, generating an encrypted dynamic plugin. At the same time, the key required for decrypting the code segment is encapsulated as code segment decryption metadata and stored separately from the encrypted dynamic plugin. Subsequently, the authorization certificate, the encrypted dynamic plugin, and the code segment decryption metadata are packaged separately and sent to the client.

6. The server-side code anti-copying authorization execution method based on dynamic plugins according to claim 5, characterized in that, The process of verifying the validity of the authorization certificate and the continuity of the environment's timeline when the client's main program loads dynamic plugins includes: After the client main program receives the packaged file and completes local storage, it performs a full-dimensional legality verification of the authorization certificate before loading the dynamic plugin. This includes the plugin summary, plugin specification identifier, certificate validity and expiration time, verification mode, and the legality verification of the hardware or runtime environment fingerprint required by the mode. If any verification fails, the subsequent decoding process stops. After the authorization certificate passes the validity verification, the continuity and compliance of the local environment tree ring chain are verified. This includes checking the continuity of the local tree ring chain since the root hash, extracting the root hash value of the local environment tree ring chain, comparing it with the tree ring root hash embedded in the authorization certificate, and checking the hash association relationship of the local environment tree ring chain node by node starting from the root node.

7. The server-side code copy protection and authorized execution method based on dynamic plugins according to claim 6, characterized in that, The process of separating dynamic plugins based on verification results to obtain the main body and decrypted metadata of the code segment includes: Based on the verification results, the client program obtains the code segment decryption metadata from the dynamic plugin. The client program executes the decryption and loading operations of the dynamic plugin. The client program extracts the code segment decryption metadata from the plugin and parses the encrypted decryption key from the authorization certificate. It calls the client memory security area interface and passes the code segment decryption metadata and the key into the memory security area. Using the decryption key in the authorization certificate, the client program generates a one-time code decryption key and an initialization vector in the memory security area by combining the hash value of the current annual ring node. Within the memory-safe zone, the generated one-time code decryption key and initialization vector are used to complete the decryption, relocation, and dynamic loading of the code segment, resulting in the plaintext code segment. Subsequently, the absolute address references in the plaintext code segment are corrected according to the dynamic plugin, thus completing the memory relocation of the plaintext code segment.

8. The server-side code anti-copying authorization execution method based on dynamic plugins according to claim 7, characterized in that, The process of setting up an authorized flow pool includes: Each authorization token in the authorization pool is bound to a plugin invocation identifier, and each authorization token in the pool is bound to a unique plugin invocation identifier; Each authorization token contains a unique token serial number, a bound plugin call identifier, a token status field, and an occupying terminal identifier. The token status is divided into idle, occupied, frozen, and revoked.

9. The server-side code copy protection and authorized execution method based on dynamic plugins according to claim 8, characterized in that, The process by which the Environment Tree Chain obtains authorization tokens from the authorization pool to complete the dynamic plugin installation includes: When the client's ring node initiates the dynamic plugin loading process, it sends a token borrowing request to the server's authorization pool. The token borrowing request carries the current ring node identifier, the corresponding plugin call identifier code, and the client's identity identifier. After the server verifies the legality of the token borrowing request, it selects an idle authorization token with the corresponding plugin call identifier from the authorization pool, marks the token status as occupied and binds it to the current ring node identifier, and simultaneously sends the authorization token to the client. After obtaining the authorization token, the client writes the event to the local environment's annual ring chain. When the annual ring node is released or scaled down, the client actively returns the authorization token. When the dynamic plugin is uninstalled, the client node is scaled down, or the main program exits normally, the corresponding annual ring node actively returns the occupied authorization token to the server.

10. A server-side code copy protection authorization system based on dynamic plugins, used to implement the server-side code copy protection authorization method based on dynamic plugins as described in any one of claims 1-9, characterized in that, This includes a dynamic plugin building module, a verification and authorization module, and a plugin loading verification module; The dynamic plugin building module is used to extract core business functions from the server-side main program and compile them into dynamic plugins, and to obtain the runtime environment characteristics of the client-side main program to build an environment timeline. The verification and authorization module is used to perform backtracking verification based on the real-time environmental tree ring chain when the client requests to obtain the dynamic plugin, and issue an authorization certificate based on the backtracking verification result. When the client's main program loads the dynamic plugin, it verifies the legality of the authorization certificate and the continuity of the environmental tree ring chain, and separates the dynamic plugin based on the verification result to obtain the dynamic plugin body and code segment decryption metadata. The plugin loading verification module is used to set up the authorized flow pool, and the environment chronology chain obtains the authorization token from the authorized flow pool to complete the dynamic plugin installation.