The invention relates to a
digital signature-based
software package installation and operation control method and
system. The method comprises the following steps: S100, obtaining a
unique identifier of a target
machine for
software package installation and operation; s200, submitting a
software package use application by a terminal user; s300, the
server side audits the application information, after the application information passes the auditing, signature
processing is carried out on the
software package and the program file in the
software package, and a signed
software package is obtained and issued to the terminal user; s400, the terminal user installs the signed software package and executes an installation
verification process, and if the installation
verification process passes, installation is allowed; and S500, when the installed program runs, executing the running
verification process, and if the running verification process passes, allowing the running verification process to be executed. The main purpose of the invention is to bind a software package
digital signature with a target
machine, set a signature validity period, verify a software signature and the signature validity period when the software package is installed and operated, and only the software package which is within the binding range of the target
machine and within the signature validity period and passes the signature verification can be installed and operated.