USB key-based identity verification method and device for software, and storage medium

Through the software identity verification method of the intelligent password key, the hash value and timestamp are used for dual authentication, which solves the problem of anti-piracy of commercial software, ensures that the software runs in a legal authorization environment, enhances security and protects the rights and interests of genuine software.

WO2025139169A1PCT designated stage expired Publication Date: 2025-07-03E SURFING IOT CO LTD

Patent Information

Application Number
PCT/CN2024/122865
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-09-30
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The existing commercial software lacks an effective anti-theft operation mechanism, which leads to the damage to the rights and interests of genuine software and cannot be run in a legally authorized environment.

Method used

The software identity verification is performed using the smart password key, and the hash value, timestamp and other information of the license and smart password key are obtained to ensure that the software runs in a legal authorized environment.

Benefits of technology

Enhance the security of software operation, ensure that the software only runs in an authorized environment, and protects the rights and interests of genuine software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122865_03072025_PF_FP_ABST
    Figure CN2024122865_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the technical field of network security, and provide a USB key-based identity verification method and device for software, and a storage medium. The method comprises: obtaining a license and a USB key, obtaining a first hash value, a license generation time, and a license expiration time on the basis of the license, and obtaining a second hash value on the basis of the USB key; if the first hash value is the same as the second hash value, calling a USB key executable file to obtain a third hash value, a one-time token, and a USB key time; if the USB key time does not exceed the license expiration time, integrating a USB key product code, a USB key user account, a USB key hardware code, a random number, and the one-time token to obtain a fourth hash value; and if the third hash value is the same as the fourth hash value, returning a Verification Passed result. Embodiments of the present application can enhance the software operation security, and ensure that software only runs in an authorized environment, thereby protecting the rights and interests of genuine software.
Need to check novelty before this filing date? Find Prior Art

Description

Software identity verification method, device and storage medium based on intelligent password key Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a software identity verification method, device and storage medium based on an intelligent password key. Background Art

[0002] With the rapid growth of the commercial software market, protecting commercial software from piracy and unauthorized copying is gaining increasing attention in the industry. Most commercial software must be deployed on client servers over private networks. Without effective anti-piracy mechanisms, commercial software can be deployed en masse to other server environments by copying the server's operating environment and the software itself. Without effective identity verification mechanisms, this can compromise the rights and interests of legitimate software owners.

[0003] Therefore, the above technical problems need to be solved urgently in the industry.

[0004] Summary of the Invention

[0005] The main purpose of the embodiments of the present application is to propose a software identity verification method, device and storage medium based on a smart password key to overcome the shortcomings of the existing technology.

[0006] The embodiments of this application disclose the following technical solutions:

[0007] In one aspect, an embodiment of the present application provides a software identity verification method based on a smart password key, the method comprising:

[0008] Obtaining a license and a smart password key, obtaining a first hash value, a license generation time, and a license expiration time according to the license, and obtaining a smart password key user password, a smart password key product code, a smart password key user account, a smart password key hardware code, and a random number according to the smart password key;

[0009] Integrate the smart key user password, the smart key product code, the smart key user account, the smart key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value;

[0010] If the first hash value and the second hash value are the same, calling the smart password key executable file to obtain a third hash value, a one-time token and a smart password key time;

[0011] If the smart key time does not exceed the license expiration time, integrating the smart key product code, the smart key user account, the smart key hardware code, the random number and the one-time token to obtain a fourth hash value;

[0012] If the third hash value is the same as the fourth hash value, a verification result of passing is returned.

[0013] In some embodiments, the method further comprises:

[0014] Detect whether the smart password key exists;

[0015] If the smart password key does not exist, prompt the user to insert the smart password key;

[0016] If the smart password key exists, check whether the license exists.

[0017] In some embodiments, the smart password key includes a smart password key user password, and the method further includes:

[0018] If the license does not exist, the smart password key product code, smart password key user account, smart password key hardware code and random number are obtained by querying the smart password key user password, the smart password key product code, smart password key user account, smart password key hardware code and random number are integrated to obtain a smart password key identification, and the license is obtained based on the smart password key identification.

[0019] In some embodiments, the method further includes initializing the smart password key, wherein initializing the smart password key includes:

[0020] Randomly generate a smart password key administrator password with read-write permissions, a smart password key user password with read-only permissions, a smart password key product code, a smart password key user account number, and a random number;

[0021] Create a smart password key data file and write a random number into it. The smart password key data file is written by the administrator and read by ordinary users.

[0022] Generate an asymmetric encryption algorithm key pair and create an asymmetric encryption algorithm private key file, wherein the asymmetric encryption algorithm private key file is accessible to ordinary users;

[0023] Import the Smart Password Key executable file.

[0024] In some embodiments, calling the smart password key executable file to obtain the third hash value, the one-time token, and the smart password key time includes:

[0025] Calling the smart password key executable file to obtain encrypted ciphertext, wherein the encrypted ciphertext is encrypted using an asymmetric encryption algorithm private key;

[0026] The encrypted ciphertext is decrypted by a public key of an asymmetric encryption algorithm to obtain the third hash value, the one-time token and the smart password key time.

[0027] In some embodiments, the step of calling the smart password key executable file to obtain the encrypted ciphertext includes:

[0028] Obtain the smart password key product code, smart password key user account and smart password key hardware code;

[0029] Read the smart password key data file to obtain the random number;

[0030] Get the smart password key time;

[0031] Read the asymmetric encryption algorithm private key file and obtain the asymmetric encryption algorithm private key;

[0032] Generate a one-time token;

[0033] The smart password key product code, the smart password key user account, the smart password key hardware code, the random number and the one-time token are integrated and calculated using a hash algorithm to obtain a third hash value;

[0034] The third hash value, the one-time token and the smart password key time are encrypted by the private key of the asymmetric encryption algorithm to obtain and return the encrypted ciphertext.

[0035] In some embodiments, obtaining a license based on the smart password key identification includes:

[0036] Get the license generation time and license expiration time;

[0037] Performing a hash calculation on the smart password key identifier, the license generation time, and the license expiration time to obtain a first hash value;

[0038] The license generation time, the license expiration time and the first Hash value are encrypted with a private key using an asymmetric encryption algorithm to obtain a ciphertext as the license.

[0039] On the other hand, an embodiment of the present application provides a software identity verification device based on a smart password key, the device comprising:

[0040] a first hash value acquisition module, configured to acquire a license and a smart password key, acquire a first hash value, a license generation time, and a license expiration time based on the license, and acquire a smart password key user password, a smart password key product code, a smart password key user account, a smart password key hardware code, and a random number based on the smart password key, wherein the first hash value is generated when the license is initialized;

[0041] A second hash value acquisition module is configured to integrate the smart password key user password, the smart password key product code, the smart password key user account, the smart password key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value;

[0042] a third hash value acquisition module, configured to, if the first hash value and the second hash value are the same, call an executable file of the smart password key to obtain a third hash value, a one-time token, and a smart password key time, wherein the executable file of the smart password key is a file imported when the smart password key is initialized;

[0043] a fourth hash value acquisition module, configured to, if the smart password key time does not exceed the license expiration time, integrate the smart password key product code, the smart password key user account, the smart password key hardware code, the random number, and the one-time token to obtain a fourth hash value;

[0044] The result returning module is configured to return a verification result if the third hash value is the same as the fourth hash value.

[0045] On the other hand, an embodiment of the present application provides an electronic device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the above-mentioned software identity verification method based on the smart password key when executing the computer program.

[0046] On the other hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned software identity verification method based on the smart password key.

[0047] The present application proposes a software identity verification method, device, and storage medium based on a smart password key. The method obtains a license and a smart password key, obtains a first hash value, license generation time, and license expiration time from the license, and obtains a smart password key user password, smart password key product code, smart password key user account, smart password key hardware code, and a random number from the smart password key. The first hash value is generated when the license is initialized. The smart password key user password, smart password key product code, smart password key user account, smart password key hardware code, random number, license generation time, and license expiration time are integrated to obtain a second hash value. If the first hash value and the second hash value are the same, the license is verified to be valid. The smart password key executable file is called to obtain a third hash value, a one-time token, and the smart password key time. The smart password key executable file is a file imported during smart password key initialization. If the smart password key time does not exceed the license expiration time, the license is verified to be valid. The smart password key product code, smart password key user account, smart password key hardware code, random number, and one-time token are integrated to obtain a fourth hash value. If the third hash value and the fourth hash value are the same, the smart password key is verified to be valid and has passed dual authentication, and a verification result of passed is returned. The embodiment of the present application implements operation identity verification through double verification of the first hash value and the second hash value to prove the legitimacy of the license, and the third hash value and the fourth hash value to prove the legitimacy of the smart password key, ensuring that the software only runs in a legally authorized environment, enhancing the security of software operation, and ensuring that the software only runs in an authorized environment, thereby protecting the rights and interests of genuine software. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] FIG1 is a flow chart of a software identity verification method based on a smart password key provided in an embodiment of the present application;

[0049] FIG2 is a further flow chart of the software identity verification method based on the smart password key provided in an embodiment of the present application;

[0050] FIG3 is a flow chart of step S204 in FIG2 ;

[0051] FIG4 is a flow chart of step S103 in FIG1 ;

[0052] FIG5 is a flow chart of step S401 in FIG4 ;

[0053] FIG6 is a flow chart of step S206 in FIG2 ;

[0054] FIG7 is a timing diagram of a software identity verification method based on a smart password key provided in an embodiment of the present application;

[0055] FIG8 is a flowchart of a specific application embodiment of a software identity verification method based on a smart password key provided in an embodiment of the present application;

[0056] FIG9 is a schematic structural diagram of a software identity verification device based on a smart password key according to an embodiment of the present application;

[0057] FIG10 is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0059] It should be noted that although the device schematics illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the device or the sequence in the flowcharts. The terms "first," "second," and so on, in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.

[0060] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.

[0061] First, let’s analyze some of the terms used in this application:

[0062] A USB Key (UKey) is a small, reliable, and high-speed storage device that connects directly to a computer via a USB port and features password authentication. It serves as a secure hardware storage medium for digital certificates and private keys, and can perform cryptographic operations within the hardware. Combining the data encryption and digital signature capabilities of digital certificates, the UKey is widely used in industries such as CA centers, online banking, e-government, and e-commerce, enabling user identity authentication, data encryption protection, and information integrity protection.

[0063] License: This is the authorization document for using Ukey for online banking transactions, which uses identity authentication and encryption protection. It is a digital certificate issued by a bank or other financial institution to confirm the user's identity and authorize the use of Ukey for transactions.

[0064] Token: A security mechanism used for authentication and encryption protection. It is an identifier used in the interactive session between the commercial software server and Ukey, and is used to confirm user identity and authorize operations.

[0065] Hash value: A fixed-length value obtained by processing data with a specific algorithm.

[0066] MD5 (Message Digest Algorithm 5): is a widely used hash function that converts input data into a 128-bit hash value and is widely used to verify data integrity.

[0067] HMAC (Hash-based Message Authentication Code): HMAC is a key-based hash function that combines a hash function with a cryptographic key to verify data integrity and authentication. HMAC is widely used in network security.

[0068] SHA-256: is a cryptographic hash function that accepts data of any size and outputs a hash value of fixed length.

[0069] Asymmetric encryption is a cryptographic technique that uses a pair of different keys for encryption and decryption. This pair of keys includes a public key and a private key, where the public key is used for encryption and the private key is used for decryption.

[0070] With the rapid growth of the commercial software market, protecting commercial software from piracy and unauthorized copying is gaining increasing attention in the industry. Most commercial software must be deployed on user servers over private networks. Without effective anti-piracy mechanisms, commercial software can be deployed en masse to other server environments by copying the server's operating environment and the software itself. Without effective identity verification mechanisms, this can compromise the rights and interests of legitimate software owners.

[0071] Therefore, the above technical problems need to be solved urgently in the industry.

[0072] Based on this, the embodiments of the present application provide a software identity verification method, device and storage medium based on a smart password key, aiming to enhance the security of software operation, ensure that the software only runs in an authorized environment, and protect the rights and interests of genuine software.

[0073] The software identity verification method, device and storage medium based on the smart password key provided in the embodiments of the present application are specifically illustrated through the following embodiments. First, the software identity verification method based on the smart password key in the embodiments of the present application is described.

[0074] The software identity verification method based on the smart password key provided in the embodiment of the present application relates to the field of network security technology. The software identity verification method based on the smart password key provided in the embodiment of the present application can be applied in a terminal, can also be applied in a server side, and can also be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the software identity verification method based on the smart password key, etc., but is not limited to the above forms.

[0075] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0076] FIG1 is an optional flowchart of a software identity verification method based on a smart password key provided in an embodiment of the present application. The method in FIG1 may include but is not limited to steps S101 to S106 .

[0077] Step S101, obtaining a license and a smart password key, obtaining a first hash value, license generation time, and license expiration time based on the license, and obtaining a smart password key user password, a smart password key product code, a smart password key user account, a smart password key hardware code, and a random number based on the smart password key;

[0078] In some embodiments, the present application does not impose any specific restrictions on the first hash value, and it can be flexibly selected in combination with actual verification needs. For example, the first hash value generated when the license is initialized can be used, or a pre-stored first hash value can be used.

[0079] In some embodiments, this application does not make specific restrictions on random numbers, and can be flexibly selected in combination with actual verification needs. For example, a 128-bit random number can be used, or a 64-bit random number can be used. Different application scenarios and security requirements may require random numbers of different lengths. Generally speaking, the more bits a random number has, the stronger its randomness and unpredictability, thereby providing a higher level of security. Therefore, according to specific security needs and encryption algorithm requirements, the smart password key can flexibly generate random numbers of different bits to meet various security requirements.

[0080] Among them, ordinary users only have read permissions for the first hash value, license generation time, license expiration time, smart password key user password, smart password key product code, smart password key user account, smart password key hardware code and random number, ensuring data security and integrity.

[0081] Optionally, some smart key devices assign a fixed random number during initialization that remains unchanged throughout their lifecycle. This design ensures the uniqueness and immutability of the smart key, enhancing security and reliability. This fixed random number can be used to generate critical information such as encryption keys and authentication identifiers, ensuring security during communication and authentication.

[0082] In some embodiments, the license is decrypted using an asymmetric encryption algorithm public key to obtain the first hash value, the license generation time, and the license expiration time.

[0083] In this embodiment, a license and a smart password key are obtained, and the first hash value, the license generation time, and the license expiration time are obtained according to the license. In addition, the smart password key user password, the smart password key product code, the smart password key user account, the smart password key hardware code, and the random number are obtained according to the smart password key, thereby preparing for the subsequent verification of the validity and legality of the license.

[0084] Step S102, integrating the smart key user password, the smart key product code, the smart key user account, the smart key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value;

[0085] Specifically, the smart password key user password is the Ukey user password, the smart password key product code is the Ukey product ID, the smart password key user account is the Ukey user ID, and the smart password key hardware code is the Ukey hardware ID.

[0086] In some embodiments, the smart password key user password is hashed using a hash function (such as SHA-256) to obtain a first hash value.

[0087] In some embodiments, the smart password key product code, the smart password key user account, the smart password key hardware code and the random number are integrated together to form a character string.

[0088] In some embodiments, the obtained first hash value and the formed string are integrated together.

[0089] In some embodiments, a timestamp function is used to obtain the license generation time and the license expiration time. The two timestamps are converted into fixed-length character strings and integrated together.

[0090] In some embodiments, the obtained integration result and the obtained timestamp string are integrated together.

[0091] In some embodiments, the integrated result is hashed using a hash function (such as SHA-256) to obtain a final second hash value.

[0092] It should be noted that this application does not make any specific restrictions on the hash function, and it can be flexibly selected in combination with actual verification needs. For example, the SHA-256 hash function, the HMAC hash function, and the MD5 hash function can be used.

[0093] Optionally, the present application does not impose any specific restrictions on the integration method, and the integration method can be flexibly selected based on actual verification needs. For example, regular expression matching, string concatenation, or string replacement can be used.

[0094] In this embodiment, the smart password key user password, smart password key product code, smart password key user account, smart password key hardware code, random number, license generation time and license expiration time are integrated to obtain a second hash value. The obtained second hash value can be used to verify whether the license is legal, ensure the security and integrity of the data, and prevent illegal use of the software.

[0095] Step S103: If the first hash value and the second hash value are the same, calling the smart password key executable file to obtain a third hash value, a one-time token, and the smart password key time;

[0096] Specifically, the one-time token is the one-time Token, and the smart password key time is the Ukey time.

[0097] In some embodiments, the first hash value and the second hash value are compared, and if they are different, the user is prompted that the "license is illegal".

[0098] In some embodiments, calling the Ukey executable file returns the ciphertext encrypted by the private key of the asymmetric encryption algorithm, and decrypting it through the public key of the asymmetric encryption algorithm obtains a one-time Token, hash value C (generated by the Ukey executable file), and Ukey time.

[0099] In some embodiments, the smart password key executable file is called to obtain the encrypted ciphertext, and the encrypted ciphertext is encrypted using a private key of an asymmetric encryption algorithm;

[0100] In some embodiments, the encrypted ciphertext is decrypted using an asymmetric encryption algorithm public key to obtain the third hash value, the one-time token, and the smart password key time.

[0101] In this embodiment, if the first hash value and the second hash value are the same, the smart password key executable file is called to obtain the third hash value, the one-time token and the smart password key time, and the validity of the license is verified, and preparations are made for the subsequent validity verification of the smart password key.

[0102] Step S104 , if the smart key time does not exceed the license expiration time, the smart key product code, the smart key user account, the smart key hardware code, the random number and the one-time token are integrated to obtain a fourth hash value;

[0103] In some embodiments, if the smart password key time exceeds the license expiration time, the user is prompted that "License has expired".

[0104] In some embodiments, the smart password key product code, the smart password key user account, the smart password key hardware code, the random number and the one-time token are concatenated to obtain a fourth hash value.

[0105] In this embodiment, if the smart password key time does not exceed the license expiration time, the smart password key product code, smart password key user account, smart password key hardware code, random number and one-time token are integrated to obtain a fourth hash value, perform license validity verification, and prepare for subsequent smart password key legitimacy verification.

[0106] Step S105: If the third hash value is the same as the fourth hash value, a verification result is returned.

[0107] In some embodiments, the third hash value is compared with the fourth hash value. If they are different, the user is prompted that "the smart password key is invalid." If they are the same, the software identity authentication detection program has passed the verification, and a verification result of passing is returned, prompting the user that "identity authentication verification passed."

[0108] In this embodiment, if the third Hash value is the same as the fourth Hash value, a verification result is returned, the legitimacy of the smart password key is verified, and a verification result is obtained.

[0109] In steps S101 to S106 of the embodiment of the present application, a license and a smart key are obtained, and a first hash value, a license generation time, and a license expiration time are obtained from the license. Furthermore, a smart key user password, a smart key product code, a smart key user account, a smart key hardware code, and a random number are obtained from the smart key. The first hash value is generated when the license is initialized. The smart key user password, the smart key product code, the smart key user account, the smart key hardware code, the random number, the license generation time, and the license expiration time are integrated to obtain a second hash value. If the first hash value and the second hash value are the same, the license is verified to be valid. The smart key executable file is called to obtain a third hash value, a one-time token, and the smart key time. The smart key executable file is a file imported during smart key initialization. If the smart key time does not exceed the license expiration time, the license is verified to be valid. The smart key product code, the smart key user account, the smart key hardware code, the random number, and the one-time token are integrated to obtain a fourth hash value. If the third hash value and the fourth hash value are the same, the smart key is verified to be valid and has passed dual authentication, and a verification result of passed is returned. The embodiment of the present application implements double verification of the running identity by proving the legitimacy of the license through the first hash value and the second hash value, and proving the legitimacy of the smart password key through the third hash value and the fourth hash value, thereby ensuring that the software runs only in a legally authorized environment, enhancing the security of the software anti-theft operation, and ensuring that the software runs only in an authorized environment, thereby protecting the rights and interests of genuine software.

[0110] Please refer to FIG. 2 . In some embodiments, the method of the present application may include but is not limited to steps S201 to S206 :

[0111] Step S201, detecting whether the smart password key exists, if yes, executing step S205, otherwise executing step S202;

[0112] In some embodiments, the smart password key is detected to be alive. If the smart password key is not detected to be alive, the user is prompted to insert the smart password key into the server where the software is located. If the smart password key is detected to be alive, the existence of the license is detected.

[0113] Step S202, prompting the user to insert the smart password key;

[0114] Specifically, if the smart password key is not detected to be alive, the user is prompted to insert the smart password key.

[0115] Step S203, insert the smart password key;

[0116] In some embodiments, the smart password key can be purchased from a legitimate software vendor.

[0117] Step S204, initializing the smart password key;

[0118] It should be noted that the present application is not limited to initializing the smart password key after insertion, and the user can also set the smart password key initialization time.

[0119] In some embodiments, a smart password key administrator password with read-write permissions, a smart password key user password with read-only permissions, a smart password key product code, a smart password key user account number, and a random number are randomly generated;

[0120] In some embodiments, a smart password key data file is created and a random number is written into the smart password key data file. The administrator has write permission to the smart password key data file, and ordinary users have read permission to the file.

[0121] In some embodiments, an asymmetric encryption algorithm key pair is generated, and an asymmetric encryption algorithm private key file is created. The asymmetric encryption algorithm private key file is accessible to ordinary users.

[0122] In some embodiments, a smart cryptographic key executable file is imported.

[0123] Step S205, check whether the license exists, if not, execute step S206;

[0124] Step S206: Generate a license.

[0125] In some embodiments, if a license does not exist, a license is generated.

[0126] Specifically, the smart password key product code, smart password key user account, smart password key hardware code and random number are obtained by querying the smart password key user password, the smart password key product code, smart password key user account, smart password key hardware code and random number are integrated to obtain the smart password key identification, and the license is obtained based on the smart password key identification.

[0127] Steps S201 to S206 shown in the embodiment of the present application detect whether the smart password key exists. If the smart password key does not exist, the user is prompted to insert the smart password key, and the smart password key is initialized. If the smart password key exists, the license is detected. If the license does not exist, the license is generated. The existence of the smart password key and the license is detected, the problem of the non-existence of the smart password key or the license is solved, and preparation is made for the subsequent use of the smart password key and the license for identity verification.

[0128] Please refer to FIG. 3 . In some embodiments, step S204 may include but is not limited to steps S301 to S304 :

[0129] Step S301, randomly generate a smart password key administrator password with read and write permissions, a smart password key user password with read-only permissions, a smart password key product code, a smart password key user account number and a random number;

[0130] In some embodiments, a smart password key administrator password (with read and write permissions), a smart password key user password (with read-only permissions), a smart password key product code, a smart password key user account number, and a random number are randomly generated;

[0131] Specifically, random numbers are typically generated by hardware during smart key initialization. These random numbers originate from physical random processes within the device, such as electronic noise, thermal noise, or other random events. This method of random number generation is more secure and reliable than software-generated pseudo-random numbers. Therefore, the random numbers generated during smart key initialization are based on true random numbers generated by hardware, rather than a simple pseudo-random number algorithm.

[0132] Among them, the product code is used to identify the smart password key, and the user account is used to identify different users.

[0133] Step S302: Create a smart password key data file and write a random number into it. The administrator has write permission to the smart password key data file, and ordinary users have read permission.

[0134] In some embodiments, the generated random number is written into a smart password key data file. The smart password key data file should have write permission for administrators to edit the contents, while ordinary users should have read permission to view the information in the file.

[0135] In this embodiment, a smart password key data file is created and a random number is written into the smart password key data file. The administrator has write permission to the smart password key data file, and ordinary users have read permission to the file, thereby ensuring the normal operation and security of the system.

[0136] Step S303: Generate an asymmetric encryption algorithm key pair and create an asymmetric encryption algorithm private key file. The asymmetric encryption algorithm private key file is accessible to ordinary users.

[0137] In some embodiments, an asymmetric encryption algorithm is used to generate a pair of keys, namely a private key and a public key. The private key is used for operations such as encryption, while the public key is used for operations such as decryption.

[0138] In some embodiments, an asymmetric encryption algorithm private key file is created to ensure that ordinary users have call permissions so that ordinary users can call the asymmetric encryption algorithm private key.

[0139] In some embodiments, an asymmetric encryption algorithm public key file is created to ensure that ordinary users have the right to call it, so that ordinary users can obtain the public key for calling the asymmetric encryption algorithm.

[0140] Step S304: import the smart password key executable file.

[0141] In this embodiment, the smart password key executable file is imported to prepare for the subsequent calling of the smart password key executable file to obtain the third hash value, the one-time token and the smart password key time.

[0142] Steps S301 to S304 shown in the embodiment of the present application randomly generate a smart password key administrator password with read-write permissions, a smart password key user password with read-only permissions, a smart password key product code, a smart password key user account and a random number, create a smart password key data file, write the random number, the smart password key data file has write permissions for the administrator and read permissions for ordinary users, generate an asymmetric encryption algorithm key pair, create an asymmetric encryption algorithm private key file, the asymmetric encryption algorithm private key file has call permissions for ordinary users, and import the smart password key executable file to protect the data stored in the smart password key from unauthorized access and modification, improve the security of the system, prepare for subsequent identity verification, and provide strong guarantees for the normal operation and data storage of the smart password key.

[0143] Referring to FIG. 4 , in some embodiments, step S103 may include but is not limited to steps S401 to S402 :

[0144] Step S401, calling the smart password key executable file to obtain encrypted ciphertext;

[0145] In some embodiments, relevant parameters are obtained, namely, the smart password key product code, the smart password key user account, the smart password key hardware code, the random number, the smart password key time, the asymmetric encryption algorithm private key, the one-time token and the third hash value.

[0146] In some embodiments, a pre-written function is called with relevant parameters to obtain a ciphertext encrypted with a private key of an asymmetric encryption algorithm.

[0147] Step S402: decrypt the encrypted ciphertext using the public key of the asymmetric encryption algorithm to obtain the third hash value, the one-time token, and the smart password key time.

[0148] In some embodiments, an asymmetric encryption algorithm public key is obtained, and the encrypted ciphertext is decrypted using the asymmetric encryption algorithm public key.

[0149] Optionally, this application does not specifically limit the method for obtaining the asymmetric encryption algorithm public key, and can be flexibly selected based on actual verification needs. For example, it can be obtained from the asymmetric encryption algorithm public key file, from a smart password key, or from a specific location.

[0150] In steps S401 to S402 shown in the embodiment of the present application, the smart password key executable file is called to obtain the encrypted ciphertext, and the encrypted ciphertext is decrypted by the public key of the asymmetric encryption algorithm to obtain the third hash value, the one-time token and the smart password key time, which prepares for the subsequent comparison of the third hash value and the fourth hash value and enhances the security of the operation.

[0151] Please refer to FIG. 5 . In some embodiments, step S401 may further include but is not limited to steps S501 to S507 :

[0152] Step S501, obtaining the smart password key product code, smart password key user account and hardware code;

[0153] In some embodiments, the smart password key executable file is called to obtain the smart password key product code, the smart password key user account and the hardware code from the smart password key.

[0154] Among them, the hardware code is the hardware identification of the smart password key and cannot be tampered with.

[0155] Step S502, read the smart password key data file to obtain a random number;

[0156] In some embodiments, the smart password key data file includes a 128-bit random number written when the smart password key is initialized.

[0157] Step S503, obtaining the smart password key time;

[0158] Specifically, the smart password key time is the real time, which is obtained from the clock chip contained in the smart password key.

[0159] Step S504: read the asymmetric encryption algorithm private key file to obtain the asymmetric encryption algorithm private key;

[0160] In some embodiments, the asymmetric encryption algorithm private key file in the smart password key is read to obtain the asymmetric encryption algorithm private key.

[0161] Step S505, generating a one-time token;

[0162] Specifically, a one-time token is a one-time token.

[0163] Optionally, this application does not make any specific restrictions on the one-time token, and it can be flexibly selected in combination with actual verification needs. For example, the one-time token can use a 128-bit random number, a 256-bit random number, or a 64-bit random number.

[0164] Step S506, integrating the smart password key product code, the smart password key user account, the smart password key hardware code, the random number and the one-time token to obtain a third hash value through a hash algorithm;

[0165] In some embodiments, relevant parameters (including the smart password key product code, the smart password key user account, the smart password key hardware code, the random number and the one-time token) are concatenated and then calculated using a hash algorithm to obtain a third hash value.

[0166] Step S507: encrypt the third Hash value, the one-time token, and the smart password key time using the private key of the asymmetric encryption algorithm to obtain and return the encrypted ciphertext.

[0167] Steps S501 to S507 shown in the embodiment of the present application obtain the smart password key product code, smart password key user account and hardware code, read the smart password key data file, obtain the random number, obtain the smart password key time, read the asymmetric encryption algorithm private key file, obtain the asymmetric encryption algorithm private key, generate a one-time token, integrate the smart password key product code, smart password key user account, smart password key hardware code, random number and one-time token, and then calculate a third hash value through a hash algorithm, encrypt the third hash value, the one-time token and the smart password key time through the asymmetric encryption algorithm private key, obtain and return the encrypted ciphertext, and obtain the encrypted ciphertext by calling the smart password key executable file, prepare for subsequent decryption, and enhance the security of operation.

[0168] Please refer to FIG. 6 . In some embodiments, step S206 includes but is not limited to steps S601 to S605 :

[0169] Step S601, obtaining the smart password key product code, smart password key user account, smart password key hardware code and random number by querying the smart password key user password;

[0170] In some embodiments, it is detected whether the license is imported into the software. If the license is not imported, the relevant information is queried through the smart password key user password to obtain the smart password key product code, smart password key user account, smart password key hardware code and 128-bit random number.

[0171] Step S602: Integrate the smart key product code, the smart key user account, the smart key hardware code, and the random number to obtain a smart key identifier;

[0172] Specifically, the smart password key identifier is the Ukey identifier ID.

[0173] In some embodiments, the smart password key product code, the smart password key user account, the smart password key hardware code and the random number are concatenated to obtain the smart password key identifier.

[0174] Step S603, obtaining the license generation time and license expiration time;

[0175] In some embodiments, the present application does not impose a specific limit on the license generation time, and can be flexibly selected in combination with actual verification needs. For example, the license generation time can be the application time, the approval time, or the first use time.

[0176] The application time is the time when the user submitted the license application after learning that the license was not imported. The approval time is the time when the license was approved, if it requires approval. The first use time is the time when the user first started using the service or function corresponding to the license.

[0177] Optionally, the present application does not impose any specific restrictions on the license expiration time, and can be flexibly selected in combination with actual verification needs. For example, the license expiration time can be a fixed date, a user-defined time, or a fixed number of uses.

[0178] Among them, the fixed date is a pre-set fixed date. The user-defined time is the expiration time defined by the user. The fixed number of uses means that it will expire after a specific number of uses.

[0179] Step S604: performing a hash calculation on the smart password key identifier, the license generation time, and the license expiration time to obtain a first hash value;

[0180] In some embodiments, the smart password key identifier, the license generation time, and the license expiration time are concatenated and hashed to obtain a first hash value.

[0181] The hash calculation includes hashing using a hash function (such as SHA-256).

[0182] Step S605: Encrypt the license generation time, license expiration time, and the first Hash value using a private key of an asymmetric encryption algorithm to obtain a ciphertext as the license.

[0183] In some embodiments, an asymmetric encryption algorithm private key file is read to obtain an asymmetric encryption algorithm private key.

[0184] In some embodiments, the obtained license is imported into the software.

[0185] In steps S601 to S605 illustrated in the embodiment of the present application, the smart password key product code, the smart password key user account, the smart password key hardware code, and the random number are obtained by querying the smart password key user password, the smart password key product code, the smart password key user account, the smart password key hardware code, and the random number are integrated to obtain the smart password key identifier, the license generation time, and the license expiration time are obtained, the smart password key identifier, the license generation time, and the license expiration time are integrated and hashed to obtain a first hash value, the license generation time, the license expiration time, and the first hash value are encrypted using a private key of an asymmetric encryption algorithm to obtain a ciphertext as the license, thereby preparing for subsequent verification of the legality and validity of the license.

[0186] Referring to FIG. 7 and FIG. 8 , in some embodiments, the method of the present application includes the following steps:

[0187] Before importing the license: Use a scheduled task to check whether the Ukey is alive every 5 seconds;

[0188] Among them, License is the license, Ukey is the smart password key, and detecting whether Ukey is alive is to detect whether the smart password key exists.

[0189] If it is detected that the Ukey is not alive, the user will be prompted to insert the Ukey through the Web;

[0190] The Web (World Wide Web) is the global wide area network, also known as the World Wide Web. It is a global, dynamically interactive, cross-platform distributed graphical information system based on hypertext and HTTP. Prompting the user to insert the Ukey through the Web means prompting the user to insert the Ukey through a visual page.

[0191] If the Ukey is valid, check whether the license is imported;

[0192] If the license is not imported, query the relevant information using the Ukey user password to obtain the Ukey product ID, user ID, hardware ID, and 128-bit random number, and then display the Ukey ID to the front end after splicing.

[0193] Among them, Ukey product ID is the smart password key product code, user ID is the smart password key user account, and hardware ID is the smart password key hardware code.

[0194] In some embodiments, based on the Ukey identification ID, the software vendor generates a license and gives it to the customer to import the software.

[0195] In some embodiments, the Ukey identification ID (Ukey user password + Ukey product ID + Ukey user ID + Ukey hardware ID + 128-bit random number), license generation time, and license expiration time obtained by the client are concatenated and hashed to obtain a hash value A; the license generation time, license expiration time, and hash value A are encrypted using the private key of an asymmetric encryption algorithm to obtain a ciphertext as the specific content of the license.

[0196] Import the license;

[0197] Use the RSA-2048 public key to decrypt the license to obtain the SM3 signature, license generation time, and license expiration time.

[0198] In some embodiments, the first hash value, the license generation time, and the license expiration time are obtained according to the license.

[0199] Specifically, the SM3 signature, i.e., the first hash value, is obtained by decrypting the license using the RSA-2048 public key, which is an asymmetric encryption algorithm public key.

[0200] Get relevant information from Ukey every 5 minutes through a scheduled task;

[0201] Obtaining relevant information from Ukey includes obtaining the Ukey user password, Ukey product ID, Ukey user ID, Ukey hardware ID, and 128-bit random number from Ukey.

[0202] Generate SM3 signature;

[0203] Specifically, the SM3 signature (the second hash value) is generated using the method for obtaining relevant information from the Ukey. The SM3 signature includes the Ukey user password, Ukey product ID, Ukey user ID, Ukey hardware ID, a 128-bit random number, the license generation time, and the license expiration time. The license generation time and license expiration time are obtained by decrypting the license.

[0204] Compare the SM3 signature in the license (i.e., the first hash value) with the SM3 signature calculated by Gateway (i.e., the second hash value);

[0205] Web Gateway, that is, network gateway, is used to execute the method of this application.

[0206] If the SM3 signature comparison fails and the web prompt states that the license is invalid, please contact your account manager.

[0207] If the SM3 signature comparison passes, the Ukey executable file is called to return the RSA-2048 ciphertext;

[0208] Decrypt the Token, SM3 hash, and Ukey time using the RSA-2048 public key (i.e., the asymmetric encryption algorithm private key);

[0209] Verify the license validity period:

[0210] Compare the time in the Ukey with the expiration time in the license;

[0211] If the license expires, a message will appear on the web indicating that the license has expired. Please contact your account manager.

[0212] If the license is not expired, obtain the Ukey product ID + user ID + hardware ID + 128-bit random number in the license, calculate SM3 (the fourth hash value), and compare it with the SM3 hash value (the third hash value) returned by Ukey;

[0213] Among them, the fourth hash value includes Ukey product ID, user ID, hardware ID, 128-bit random number and Token.

[0214] Compare the calculated SM3 (i.e., the fourth hash value) with the SM3 hash value (i.e., the third hash value) returned by Ukey;

[0215] If the verification passes, the scheduled task will end and wait for the next execution;

[0216] If the verification fails: The web prompts that the Ukey is invalid. Please contact your account manager.

[0217] Referring to FIG. 9 , an embodiment of the present application further provides a software identity verification device based on a smart password key, which can implement the above-mentioned software identity verification method based on a smart password key. The device includes:

[0218] A first hash value acquisition module 901 is configured to acquire a license and a smart password key, obtain a first hash value, license generation time, and license expiration time based on the license, and obtain a smart password key user password, smart password key product code, smart password key user account, smart password key hardware code, and a random number based on the smart password key. The first hash value is generated when the license is initialized;

[0219] A second hash value acquisition module 902 is configured to integrate the smart key user password, the smart key product code, the smart key user account, the smart key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value;

[0220] A third hash value acquisition module 903 is configured to, if the first hash value and the second hash value are the same, call the smart password key executable file to obtain the third hash value, the one-time token, and the smart password key time. The smart password key executable file is a file imported when the smart password key is initialized.

[0221] A fourth hash value acquisition module 904 is configured to integrate the smart key product code, the smart key user account, the smart key hardware code, the random number, and the one-time token to obtain a fourth hash value if the smart key time does not exceed the license expiration time;

[0222] The result returning module 905 is configured to return a verification pass result if the third hash value is the same as the fourth hash value.

[0223] The specific implementation of the software identity verification device based on the smart password key is basically the same as the specific embodiment of the software identity verification method based on the smart password key, and will not be repeated here.

[0224] The contents of the method embodiments of this application are all applicable to the device embodiments. The functions specifically implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method.

[0225] The present application also provides an electronic device comprising a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned software identity verification method based on a smart password key. The electronic device can be any smart terminal, including a tablet computer and an in-vehicle computer.

[0226] The contents of the method embodiments of this application are all applicable to the electronic device embodiments. The functions specifically implemented by the electronic device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.

[0227] Please refer to FIG10 , which illustrates a hardware structure of an electronic device according to another embodiment. The electronic device includes:

[0228] The processor 1001 can be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.

[0229] The memory 1002 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1002 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1002, and the processor 1001 calls and executes the software identity verification method based on the smart password key in the embodiments of this application;

[0230] Input / output interface 1003, used to implement information input and output;

[0231] Communication interface 1004, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);

[0232] Bus 1005 , which transmits information between various components of the device (e.g., processor 1001 , memory 1002 , input / output interface 1003 , and communication interface 1004 );

[0233] The processor 1001 , the memory 1002 , the input / output interface 1003 and the communication interface 1004 are connected to each other in communication within the device via a bus 1005 .

[0234] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned software identity verification method based on the smart password key.

[0235] The contents of the method embodiments of this application are all applicable to the storage medium embodiments. The functions specifically implemented by the storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method.

[0236] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0237] The software identity verification method, device and storage medium based on the smart password key provided in the embodiment of the present application obtain a license and a smart password key, obtain a first hash value, license generation time and license expiration time according to the license, and obtain a smart password key user password, smart password key product code, smart password key user account, smart password key hardware code and random number according to the smart password key. The first hash value is generated when the license is initialized; the smart password key user password, smart password key product code, smart password key user account, smart password key hardware code, random number, license generation time and license expiration time are integrated. Get the second hash value; if the first hash value and the second hash value are the same, it proves that the license is legal, and calls the smart password key executable file to obtain the third hash value, the one-time token and the smart password key time. The smart password key executable file is the file imported when the smart password key is initialized; if the smart password key time does not exceed the license expiration time, it proves that the license is valid, and the smart password key product code, the smart password key user account, the smart password key hardware code, the random number and the one-time token are integrated to obtain the fourth hash value; if the third hash value is the same as the fourth hash value, it proves that the smart password key is legal and has passed the dual authentication, and returns the result of the verification pass. The embodiment of the present application implements the operation identity verification through the dual verification of the first hash value and the second hash value to prove the legality of the license and the third hash value and the fourth hash value to prove the legality of the smart password key, ensuring that the software only runs in a legally authorized environment, enhancing the security of the software operation, and ensuring that the software only runs in an authorized environment, thereby protecting the rights and interests of genuine software.

[0238] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0239] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0240] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0241] It should be understood that in this application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0242] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.

Claims

1. A software identity verification method based on an intelligent cryptographic key, characterized in that, The method includes: Obtain a license and a smart password key, obtain a first hash value, a license generation time, and a license expiration time according to the license, and obtain a smart password key user password, a smart password key product code, a smart password key user account, a smart password key hardware code, and a random number according to the smart password key; Integrate the smart password key user password, the smart password key product code, the smart password key user account, the smart password key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value; If the first hash value is the same as the second hash value, call the smart password key executable file to obtain a third hash value, a one-time token, and a smart password key time; If the smart password key time does not exceed the license expiration time, integrate the smart password key product code, the smart password key user account, the smart password key hardware code, the random number, and the one-time token to obtain a fourth hash value; If the third hash value is the same as the fourth hash value, return a result indicating that the verification has passed.

2. The method according to claim 1, wherein The method further includes: Detect whether the smart password key exists; If the smart password key does not exist, prompt the user to insert the smart password key; If the smart password key exists, detect whether the license exists.

3. The method according to claim 2, wherein The smart password key includes a smart password key user password, and the method further includes: If the license does not exist, query the smart password key product code, the smart password key user account, the smart password key hardware code, and the random number through the smart password key user password, integrate the smart password key product code, the smart password key user account, the smart password key hardware code, and the random number to obtain a smart password key identifier, and obtain a license based on the smart password key identifier.

4. The method according to claim 1, characterized in that, The method further includes initializing the smart password key, and the initializing the smart password key includes: Randomly generate a smart password key administrator password with read-write permissions, a smart password user password with read-only permissions, a smart password key product code, a smart password key user account, and a random number; Create a smart password key data file, write the random number into it, and the smart password key data file has write permissions for the administrator and read permissions for ordinary users; Generate an asymmetric encryption algorithm key pair, create an asymmetric encryption algorithm private key file, and the asymmetric encryption algorithm private key file has call permissions for ordinary users; Import the smart password key executable file.

5. The method according to claim 1, characterized in that, The calling the smart password key executable file to obtain a third hash value, a one-time token, and a smart password key time includes: Call the smart password key executable file to obtain an encrypted ciphertext, and the encrypted ciphertext is encrypted with the asymmetric encryption algorithm private key; Decrypt the encrypted ciphertext with the asymmetric encryption algorithm public key to obtain the third hash value, the one-time token, and the smart password key time.

6. The method according to claim 5, characterized in that, The calling the smart password key executable file to obtain an encrypted ciphertext includes: Obtain the smart password key product code, the smart password key user account, and the smart password key hardware code; Read the data file of the intelligent password key to obtain the random number; Obtain the time of the intelligent password key; Read the private key file of the asymmetric encryption algorithm to obtain the private key of the asymmetric encryption algorithm; Generate a one-time token; Integrate the intelligent password key product code, intelligent password key user account, intelligent password key hardware code, the random number, and the one-time token, and calculate the third hash value through the hash algorithm; Encrypt the third hash value, the one-time token, and the intelligent password key time through the private key of the asymmetric encryption algorithm, and obtain and return the encrypted ciphertext.

7. The method according to claim 3, characterized in that, The obtaining the license based on the intelligent password key identifier includes: Obtain the license generation time and the license expiration time; Integrate the intelligent password key identifier, the license generation time, and the license expiration time, and perform a hash calculation to obtain the first hash value; Use the ciphertext obtained by encrypting the license generation time, the license expiration time, and the first hash value through the private key of the asymmetric encryption algorithm as the license.

8. A software identity verification device based on an intelligent cryptographic key, characterized in that, The device includes: A first hash value obtaining module, configured to obtain a license and an intelligent password key, obtain a first hash value, a license generation time, and a license expiration time according to the license, and obtain an intelligent password key user password, an intelligent password key product code, an intelligent password key user account, an intelligent password key hardware code, and a random number according to the intelligent password key, where the first hash value is generated during the initialization of the license; A second hash value obtaining module, configured to integrate the intelligent password key user password, the intelligent password key product code, the intelligent password key user account, the intelligent password key hardware code, the random number, the license generation time, and the license expiration time to obtain a second hash value; A third hash value obtaining module, configured to, if the first hash value is the same as the second hash value, call the intelligent password key executable file to obtain a third hash value, a one-time token, and the intelligent password key time, where the intelligent password key executable file is a file imported during the initialization of the intelligent password key; A fourth hash value obtaining module, configured to, if the intelligent password key time does not exceed the license expiration time, integrate the intelligent password key product code, the intelligent password key user account, the intelligent password key hardware code, the random number, and the one-time token to obtain a fourth hash value; A result returning module, configured to, if the third hash value is the same as the fourth hash value, return a result indicating that the verification is passed.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the software identity verification method based on an intelligent password key according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the software identity verification method based on an intelligent password key according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Verifying method and system for intelligent secret key

    CN103634114A

  • Checking method and system for cryptographic module firmware

    CN115296800A

  • Software identity verification method and device based on intelligent password key and storage medium

    CN117978399A

  • Blockchain-based user authentication method and terminal device

    WO2020073513A1

Cited By

  • Software authorization method and system, computer equipment, quantum cryptographic key and medium

    CN121098491A