WO2012149717A1 - Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm - Google Patents

Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm Download PDF

Info

Publication number
WO2012149717A1
WO2012149717A1 PCT/CN2011/079141 CN2011079141W WO2012149717A1 WO 2012149717 A1 WO2012149717 A1 WO 2012149717A1 CN 2011079141 W CN2011079141 W CN 2011079141W WO 2012149717 A1 WO2012149717 A1 WO 2012149717A1
Authority
WO
WIPO (PCT)
Prior art keywords
license
data packet
function
public key
changed
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2011/079141
Other languages
English (en)
Chinese (zh)
Inventor
石峰
张羽
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN201180004976.0A priority Critical patent/CN102986162B/zh
Priority to PCT/CN2011/079141 priority patent/WO2012149717A1/fr
Publication of WO2012149717A1 publication Critical patent/WO2012149717A1/fr
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution
    • H04L2209/603Digital right managament [DRM]

Definitions

  • the present invention relates to the field of information technology, and in particular, to a TCM or TPM-based license dynamic management method, device and system.
  • License is the permission identifier of the customer to use the product. Different customers have different functional requirements for the product. Therefore, the product manufacturer will provide different licenses for customers to choose to purchase to meet the customer's needs, but the manufacturer prevents it in order to protect its own interests. The license is cracked or stolen, and the license needs to be securely managed.
  • the prior art provides a method for managing a license.
  • the specific operation of the method may be: the client requests the utility function A, the server generates a temporary enable message and sends the message to the client, and the client temporarily starts the function according to the temporary enable message.
  • the client sends a message to the server to purchase the feature A.
  • the server issues a start message, and the client permanently enables the feature A according to the start message.
  • the technical solution provided by the prior art does not consider the security of the intermediate transaction when the activation of the functional component A (including temporary or purchase), so the security of the prior art technical solution is low.
  • the dynamic management method of the license is designed to solve the problem of low security of the prior art.
  • the invention also provides a dynamic management support method for a license based on TCM or TPM.
  • the invention also provides a dynamic management device based on a TCM or TPM license.
  • the present invention also provides a support device for dynamic management of a license based on TCM or TPM.
  • the invention also provides a license management system.
  • the present invention provides a method for dynamically managing a license based on a TCM or a TPM, the method comprising:
  • the function list includes: a software and hardware function in the local device;
  • the key pair includes: a private key K S2 and a public key K P2 ;
  • the first data packet includes: a public key K P2 and a function to be changed ;
  • the second data packet encrypted by using the public key K P2 specifically includes: a license calculated for the local unique identifier and the function to be changed;
  • the encrypted second data packet is decrypted by using the private key K S2 to obtain a license, and the configuration of the function to be changed is completed according to the license.
  • the present invention provides a TCM based or TPM based A dynamic management support method for a license, characterized in that the method includes:
  • the first data packet includes: a public key K P2 and a function to be changed;
  • the present invention also provides a TCM based or TPM based Dynamic management device for the license, the device comprising:
  • a configuration unit configured to configure a public key K P1 in the local device
  • a receiving unit configured to receive a function to be changed selected by the customer according to the function list, where the function list includes: a software and hardware function in the local device;
  • a key generating unit configured to generate a key pair according to the local identification information, where the key pair includes: a private key K S2 and a public key K P2 ;
  • An encryption unit configured to generate a first data packet according to the public key K P2 and the function to be changed, and encrypt the first data packet by using the public key K P1 , where the first data packet includes: a public key K P2 And the function to be changed;
  • a sending unit configured to send the encrypted first data packet and the local unique identifier to the server, so that the server can obtain the private key K S1 according to the local unique identifier; and decrypt the first key according to the private key K S1 a public key K P2 obtained by a data packet and a function to be changed;
  • the receiving unit is further configured to receive a second data packet that is encrypted by using the public key K P2 , where the second data packet includes: a license that is calculated by a local unique identifier and a function to be changed;
  • the decryption configuration unit is configured to decrypt the encrypted second data packet by using the private key K S2 to obtain a license, and complete the configuration of the function to be changed according to the license; the private key K S1 and the public key K P1 are a key pair.
  • the invention further provides a TCM based or TPM A dynamic management support device for the license, the device comprising:
  • a configuration unit configured to configure a correspondence between the private key K S1 and the private key K S1 and the unique identifier of the client in the server;
  • a receiving unit configured to receive a unique identifier sent by the client and a first data packet encrypted by using a public key K P1 , where the first data packet includes: a public key K P2 and a function to be changed;
  • a decryption unit configured to decrypt, by using the private key K S1 , the encrypted first data packet to obtain a public key K P2 in the first data packet and a function to be changed;
  • Querying unit configured to query the corresponding relationship between the private key K S1 and uniquely identifies the client to the private key K S1 according to a unique identifier
  • the calculation sending unit is configured to calculate a license according to the unique identifier and the function to be changed, encrypt the license with the public key K P2 to obtain a second data packet, and send the second data packet to the client.
  • the present invention provides a license management system, the system comprising: a client and a server; wherein the client stores a public key K P1 ; the server stores a private key K S1 and a private key K S1 Corresponding relationship with the unique identifier of the client; the private key K S1 and the public key K P1 are a key pair;
  • the client is configured to receive a function to be changed selected by the client according to the function list, and generate a key pair according to the local identification information, where the key pair includes: a private key K S2 and a public key K P2 ; according to the public key K P2 and the function to be changed generate a first data packet, and encrypt the first data packet with the public key K P1 , the first data packet includes: a public key K P2 and a function to be changed; the function
  • the list includes: hardware and software functions within the local device;
  • the client is further configured to send the encrypted first data packet and the local unique identifier to the server;
  • the server is configured to query the private key K S1 from the correspondence between the private key K S1 and the unique identifier of the client according to the unique identifier, and use the private key K S1 to decrypt the encrypted first data packet to obtain the first data packet.
  • the public key K P2 and the function to be changed calculate the license according to the unique identifier and the function to be changed, encrypt the license with the public key K P2 to obtain the second data packet, and send the second data packet to the client;
  • the client is further configured to decrypt the second data packet by using the private key K S2 to obtain a license, and complete the configuration of the function to be changed according to the license.
  • the present invention has the beneficial effects that the present invention applies the key pair to encrypt the message in the transaction process of the functional component, so the method provided by the present invention has the advantage of high security.
  • FIG. 1 is a flowchart of a method for dynamically managing a license based on a TCM or a TPM according to the present invention
  • FIG. 2 is a flowchart of a method for dynamically managing a license based on a TCM or a TPM according to the present invention
  • FIG. 3 is a flowchart of a method for dynamically managing a license based on a TCM or a TPM according to an embodiment of the present invention
  • FIG. 4 is a flowchart of a method for dynamically managing a license based on a TCM or a TPM according to another embodiment of the present invention
  • FIG. 5 is a structural diagram of a dynamic management apparatus for a license based on a TCM or a TPM according to the present invention
  • FIG. 6 is a structural diagram of a device for dynamically managing a license based on a TCM or a TPM according to the present invention.
  • the present invention provides a dynamic management method for a license based on TCM or TPM.
  • TCM Trusted Cryptography Module
  • TPM Trusted Platform Module
  • the method is shown in Figure 1. The method is completed by the client. Before performing the following method, the manufacturer needs to configure the public key K P1 in the local device. The method includes the following steps:
  • the local identification information includes: information that can identify the local device;
  • the foregoing first data packet may include: a public key K P2 and a function to be changed.
  • S14 Send the encrypted first data packet and the local unique identifier to the server, so that the server can obtain the private key K S1 according to the local unique identifier; and decrypt the first data packet according to the private key K S1 The obtained public key K P2 and the function to be changed;
  • the second data packet that is sent by the receiving server and encrypted by using the public key K P2 , where the second data packet includes: a license that is calculated for the local unique identifier and the function to be changed;
  • the license may be specifically: the server uses the K S1 decryption to obtain the to-be-changed function of the encrypted first data packet in the S14, and calculates the function and the unique identifier to be changed to obtain a license; in addition, the private key K S1 can uniquely identify from the query based on the corresponding relationship that uniquely identifies a private key K S1 and pre-configured to the private key K S1.
  • private key K S2 and the public key K P2 are key pairs; the private key K S1 and the public key K P1 are another key pair.
  • the private key K S1 and the private key K S2 belong to completely different private keys
  • the public key K P1 and the public key K P2 belong to completely different public keys
  • the first data packet and the second data packet It also belongs to completely different data.
  • the method provided by the present invention performs license management
  • all data interaction between the local (ie, the client) and the server is encrypted and decrypted by using a key pair, and all the data between them is not easy to be leaked and changed by others, all of which
  • the method has the advantages of improving the security of the license management.
  • since the number of functions to be changed of the method provided by the present invention can be flexibly set, it can improve the flexibility of license management.
  • the foregoing first data packet may further include: a pre-stored ciphertext, when the first data packet includes a pre-stored ciphertext, the server determines the hash value of the ciphertext and obtains according to the unique identifier. When the hash value is consistent, the second data packet with the license hash value of the private key K S1 signature encrypted by the public key K P2 is transmitted.
  • the encrypted second data packet in the foregoing S15 may further include: a license hash value obtained by using the private key K S2 and obtained by the private key K S2 , when the encrypted second data packet includes a license hash value,
  • the method specifically includes the following in S16:
  • the private data K S2 is used to decrypt the encrypted second data packet to obtain the license hash value of the license and the private key K S1 signature, and the license hash value signed by the private key K S1 is decrypted by the public key K P1 to obtain the license hash value, and the decryption value is decrypted.
  • the license hash value is the same as the license hash value calculated by hashing the license, the configuration of the function to be changed is completed according to the license, and the operation is ended.
  • the above method provided by the present invention uses the public key K P1 and the private key K S1 to determine whether the encrypted second data packet in S15 is sent by the server, because the public key K P1 and the private key K S1 are a key pair, such as encryption. After the second data packet is not sent by the server, the public key K P1 cannot decrypt the signed hash value of the signature at all, and the comparison and the confirmation cannot be performed. Therefore, the method further improves the security of the license management.
  • the present invention also provides a dynamic management support method for a license based on TCM or TPM, which is completed by a server.
  • the server is configured with a correspondence between the private key K S1 and the private key K S1 and the unique identifier of the client. Relationship; the method is shown in Figure 2 and includes:
  • the foregoing first data packet may further include: a pre-stored ciphertext.
  • the foregoing method may further include: configuring a ciphertext and a ciphertext hash value in the server before the S21
  • the steps in the foregoing method may further include:
  • the ciphertext hash value is queried from the correspondence between the ciphertext hash value and the client unique identifier, and the hash value of the received ciphertext is calculated to the calculated hash value; the hash value and calculation of the query are compared. If the hash value is consistent, execute S22-S26, otherwise the operation ends.
  • the foregoing S25 may further include: a license hash value obtained by performing a hash value calculation on the license, and the license hash value is encrypted by using a private key K S1 to obtain a license hash value of the private key K S1 signature, and the public key K is used.
  • P2 encrypts the license hash value and license of the private key K S1 to obtain the encrypted second data packet.
  • the license management support method provided by the present invention supports the implementation of the license management method.
  • the embodiment of the present invention provides an embodiment.
  • the method for managing a license is implemented between a client and a server.
  • the method is described by taking the function to be activated as an example.
  • the scenario is that the factory settings are made when the client leaves the factory.
  • the specific settings can be: through TCM/TPM, generate a key pair (such as private key K S1 , public key K P1 ), and the public key is stored in the client's TCM/TPM.
  • the private key is saved by the manufacturer himself.
  • the pair of keys is used for the signature of the manufacturer.
  • the key pair is only at the factory.
  • each factory client will save K P1 ;
  • the client is bound with a unique identifier (such as the client's MAC address, etc.), the identifier can be based on the client The identification of each hardware on the machine (in order to guarantee privacy, it can be its encrypted performance), or it can be a unique code defined by the manufacturer to the client.
  • the unique identifier only serves as a cable.
  • the function is convenient for the manufacturer to query the client for related information in its own database; the client is randomly bound with a ciphertext (the ciphertext can be a randomly generated ciphertext), which is stored in the client's TCM/TPM.
  • the hash value of the ciphertext is stored in the manufacturer server, and the ciphertext is another "identity card" of the client.
  • the manufacturer can determine that the relevant information is from the client.
  • the machine sends the relevant characteristics of the hash algorithm.
  • the hash value is saved, and the identity information can be verified.
  • the manufacturer can add a record containing the following fields to the database managed by the manufacturer through the above settings. Includes: unique identifier, ciphertext ("ID”) hash value, software feature status list, hardware status list, and e-wallet amount.
  • ID unique identifier
  • the method provided in this embodiment may specifically include:
  • the foregoing function list may specifically include, but not limited to, all software and hardware functions, and may also be a function activated or not activated by the client.
  • the display method of the activated or inactive function may be multiple. The method, for example, the activation function adopts a bright display, the inactive function is displayed in a dark color, and of course, the activation function is displayed in green, the inactive function is displayed in red, and the like; in addition, the function list may further include: function list.
  • the client determines a function (which may be software and/or hardware) selected by the user to be activated and how the function is applied (for example, permanent or temporary).
  • a function which may be software and/or hardware
  • the embodiment does not limit the number of functions, and the amount of data can be freely selected by the client, for example, 1, 2, 3 or 4, and the like.
  • the client generates another key pair (private key K S2 , public key K P2 ) according to the identification information on the client (for example, the unique identifier of the hardware).
  • identifier information may be the same as the unique identifier or unique code of the client, and may of course be different.
  • the client generates a first data packet according to the ciphertext, K P2, and the function to be activated, and encrypts the first data packet with K P1 ;
  • the foregoing first data packet may include: ciphertext, K P2, and a function to be activated.
  • the specific manifestation of the function to be activated may be: a list of software functions that the customer needs to use at the time, and a list of hardware that the customer needs to use at the time.
  • the client sends the encrypted first data packet and the unique identifier of the client to the server.
  • the server searches for the K S1 and the hash value corresponding to the unique identifier according to the unique identifier, and decrypts the encrypted first data packet by using the K S1 to obtain the ciphertext, the K P2, and the function to be activated in the first data packet. ;
  • the server performs a hash operation on the ciphertext in the first data packet to obtain a hash value of the ciphertext, and compares the calculated hash value with the hash value queried according to the unique identifier, and if the same, performs the following operations, otherwise Stop the operation.
  • the server calculates a license according to the unique identifier and the function to be activated, performs a hash operation on the license to obtain a hash value of the license, and signs the hash value of the license with K S1 , and signs the signature with K P2 .
  • the hash value of the license and the license are encrypted and sent to the client;
  • the client decrypts with K S2 to obtain the hash value and license of the signed license, and decrypts the hash value of the signed license with K P1 to obtain the license hash value, and compares the decrypted license hash value and the license.
  • the obtained license hash value is the same, and the loading and configuration of the to-be activated function is performed according to the license.
  • the method for loading and configuring the to-be-activated function according to the license may be: storing the license in the TCM/TPM of the client; after the client restarts, from the trusted metric root (Core) Root of Trust Measurement , CTRM) began to build a trusted platform, and finally in the trusted platform to configure the software and hardware functions (to be activated) according to the license.
  • CTRM trusted metric root
  • each message needs to be encrypted and decrypted by a key pair during function configuration and loading, so that it has the advantage of improving the security of the license management.
  • the client when performing encryption, The client is re-authenticated by using the hash value of the random ciphertext, which further improves the security, so that it has the advantage of higher security.
  • the method provided by the embodiment can flexibly configure the to-be activated according to the needs of the client. The function is more in line with the customer's needs, so it has the advantage that the customer can flexibly choose the client configuration.
  • the embodiment of the present invention further provides another embodiment.
  • the present embodiment provides a license management method, which is described by taking the unsubscribe function as an example.
  • the method is the same as the technical scenario of an embodiment, and the specific operation of the method is The process is shown in Figure 4 and includes:
  • the client When the client triggers unsubscription on the client, the client displays a function list.
  • the client determines a function (which may be software and/or hardware) selected by the user to be unsubscribed.
  • the embodiment does not limit the number of functions, and the amount of data can be freely selected by the client, for example, 1, 2, 3 or 4, etc., in addition, in principle, permanent functions and basic functions (ie, no such Features that the feature client cannot run) cannot be unsubscribed.
  • the client generates another key pair (private key K S3 , public key K P3 ) according to the identification information on the client (for example, the unique identifier of the hardware).
  • identifier information may be the same as the unique identifier or unique code of the client, and may of course be different.
  • the client generates a first data packet according to the ciphertext, K P3, and the function to be unsubscribed, and encrypts the first data packet by using the public key K P1 .
  • the foregoing first data packet may include: a ciphertext, a private key K P3, and a function to be unsubscribed.
  • the specific manifestation of the function to be unsubscribed may be: a list of software functions that the customer needs to unsubscribe at the moment, and a list of hardware that the customer needs to unsubscribe at the moment.
  • the client sends the encrypted data and the unique identifier of the client to the server.
  • the server searches for the private key K S1 and the hash value corresponding to the unique identifier according to the unique identifier, and decrypts the encrypted first data packet with the private key K S1 to obtain the ciphertext and the private key K in the first data packet.
  • S46 The server performs a hash operation on the ciphertext in the first data packet to obtain a hash value of the ciphertext, and compares the calculated hash value with the hash value queried according to the unique identifier, and if the same, performs the following operations, otherwise Stop the operation.
  • the server calculates a license according to the unique identifier and the function to be unsubscribed, performs a hash operation on the license to obtain a hash value of the license, and uses the private key K S1 to sign the hash value of the license, and then signs the signature with the public key K P3 .
  • the hash value of the subsequent license is encrypted and sent to the client;
  • the client decrypts with K S3 to obtain the hash value and license of the signed license, and decrypts the hash value of the signed license with K P1 to obtain the license hash value, and compares the decrypted license hash value and the license. If the obtained license hash value is the same, the unsubscribe function is unsubscribed according to the license, and after the unsubscribe is successful, an unsubscribe success message is generated to the server;
  • the server calculates a residual value of the unsubscribe function, and returns the remaining value to the client.
  • the method for unsubscribing the function to be unsubscribed according to the license may be: storing the license in the TCM/TPM of the client; after the client restarts, establishing a trusted platform from the CTRM, and finally The configuration of the software and hardware functions (to be unsubscribed) according to the license in the trusted platform.
  • the method provided in this embodiment provides a function unsubscribe mechanism, which expands the function of the license.
  • the method needs to perform strict encryption and decryption operations when performing function unsubscription, so it also has high security. advantage.
  • a specific embodiment of the present invention also provides a TCM based or TPM
  • the dynamic management device of the license includes:
  • the configuration unit 56 is configured to configure the public key K P1 in the local device
  • the receiving unit 51 is configured to receive a function to be changed selected by the customer according to the function list, where the function list includes: all software and hardware functions in the local device;
  • the key generating unit 52 is configured to generate a key pair according to the local identification information, where the key pair includes: a private key K S2 and a public key K P2 , wherein the identification information is: information that can identify the local device;
  • the encryption unit 53 is configured to generate a first data packet according to the public key K P2 and the function to be changed, and encrypt the first data packet with the public key K P1 ; the first data packet includes: a public key K P2 and the function to be changed;
  • the sending unit 54 is configured to send the encrypted first data packet and the local unique identifier to the server, so that the server can obtain the private key K S1 according to the local unique identifier, and decrypt the public key K S1 according to the private key K S1
  • the public key K P2 obtained by the first data packet and the function to be changed;
  • the receiving unit 51 is further configured to receive the second data packet encrypted by using the public key K P2 , where the second data packet specifically includes: a license obtained by decrypting and calculating the encrypted data by using the private key K S1 ;
  • the decryption configuration unit 55 is configured to decrypt the encrypted second data packet by using the private key K S2 to obtain a license, and complete the configuration of the function to be changed according to the license;
  • the private key K S1 and the public key K P1 are a key pair.
  • the functions to be changed include:
  • the encrypted second data packet may further comprise: a public key K P2 license signature hash value, when the license includes a public key hash value K P2 signature, decryption unit 55 is further arranged for using a private key K S2 decrypts the encrypted second data packet to obtain the license hash value of the license and the private key K S1 signature, and uses the public key K P1 to decrypt the license hash value signed by the private key K S1 to obtain the license hash value, and compares the decrypted license hash.
  • the value is the same as the license hash value calculated for the license, and the configuration of the function to be changed is completed according to the license.
  • the device provided by the present invention performs license management, all data interaction between the local (ie, the license management device, specifically the client) and the server is encrypted and decrypted by using a key pair, and the data between them is not easy. Leaked and changed by others, all of the devices have the advantage of improving license management security.
  • Embodiments of the present invention also provide a TCM based or TPM
  • the dynamic management support device of the license as shown in FIG. 6, includes:
  • the configuration unit 66 is configured to configure a correspondence between the private key K S1 and the private key K S1 and the unique identifier of the client in the server;
  • the receiving unit 61 is configured to receive the unique identifier sent by the client and the first data packet encrypted by using the public key K P1 , where the first data packet includes: a public key K P2 and a function to be changed;
  • the query unit 62 is configured to query the private key K S1 from the pre-configured private key K S1 and the uniquely identified correspondence according to the unique identifier;
  • the decrypting unit 63 is configured to decrypt the data sent by the client by using the private key K S1 to obtain the public key K P2 and the function to be changed;
  • the calculation sending unit 64 is configured to calculate a license according to the unique identifier and the function to be changed, encrypt the license with the public key K P2 to obtain a second data packet, and send the second data packet to the client.
  • the foregoing first data packet further includes: a ciphertext
  • the configuration unit 66 is further configured to configure a correspondence between the ciphertext and the ciphertext hash value and the unique identifier of the client
  • the apparatus further includes:
  • the hash value verification unit 65 is configured to query the key hash value from the correspondence between the ciphertext hash value and the client unique identifier according to the unique identifier, and compare the queryed hash value with the received ciphertext hash value, such as
  • the trigger inquiry unit 62, the decryption unit 63, and the calculation transmission unit 64 perform operations.
  • the calculating sending unit 64 specifically includes:
  • the calculation module 641 is configured to calculate a license according to the unique identifier and the function to be changed, and perform a hash value of the license value calculated by the hash value of the license;
  • the signature module 642 is configured to encrypt the license hash value by using a private key K S1 to obtain a license hash value of the private key K S1 signature.
  • Transmitting encryption module 643, license for using encrypted hash value and the license of the private key of the public key K P2 K S1 signature is encrypted second data packet, sends the packet to the second client.
  • the support device for license management provided by the present invention supports the implementation of the management method of the above license.
  • a specific embodiment of the present invention further provides a management system for a license, the system comprising: a client and a server; wherein the client stores a public key K P1 ; the server stores a private key K S1 and a private key K a correspondence between S1 and a unique identifier of the client; the private key K S1 and the public key K P1 are a key pair;
  • a client configured to receive a function to be changed selected by the client according to the function list, and generate a key pair according to the local identification information, the key pair includes: a private key K S2 and a public key K P2 ; according to the public key K P2 and The function to be changed generates a first data packet, and encrypts the first data packet with a public key K P1 ; the first data packet includes: a public key K P2 and a function to be changed; the function list includes: local Software and hardware functions within the device;
  • the client is further configured to send the encrypted first data packet and the local unique identifier to the server;
  • a server configured to query the private key K S1 from the correspondence between the private key K S1 and the client unique identifier according to the unique identifier, and use the private key K S1 to decrypt the encrypted first data packet to obtain the public information in the first data packet.
  • Key K P2 and the function to be changed ; calculate the license according to the unique identifier and the function to be changed, encrypt the license with the public key K P2 to obtain the second data packet, and send the second data packet to the client;
  • the client is further configured to decrypt the second data packet by using the private key K S2 to obtain a license, and complete the configuration of the function to be changed according to the license.
  • the client and the server in the system provided by the present invention use the encryption and decryption method to exchange information when interacting, so it has the advantage of improving the security of the intermediate data.
  • the technical solution provided by the invention has the advantage of high safety.
  • each module or unit included is only divided according to functional logic, but is not limited to the above division, as long as the corresponding function can be implemented; in addition, the specific name of each functional module is also They are only used to facilitate mutual differentiation and are not intended to limit the scope of the present invention.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

L'invention a trait au domaine des technologies de l'information, et concerne en particuler un procédé, un dispositif et un système de gestion dynamique de licence basés sur une TCM ou une TPM. Le procédé comprend les étapes suivantes: recevoir une fonction à changer sélectionnée par un client, selon une liste de fonctions; produire une paire de clés selon des données d'identification locale, la paire de clés comprenant une clé privée KS2 et une clé publique KP2; produire un premier paquet de données et chiffrer celui-ci au moyen d'une clé publique KP1, le premier paquet de données comprenant la clé publique KP2 et la fonction à changer; envoyer à un serveur les données chiffrées et l'identification locale unique; recevoir un deuxième paquet de données, chiffré au moyen de la clé publique KP2 et qui est envoyé par le serveur, le deuxième paquet de données comprenant en particulier une licence, obtenue par le déchiffrement et le calcul des données chiffrées au moyen d'une clé privée KS1; et obtenir la licence en déchiffrant le deuxième paquet de données chiffrées au moyen de la clé privée KS2, et configurer la fonction à changer selon la licence. La solution technique de l'invention présente l'avantage d'offrir une sécurité élevée.
PCT/CN2011/079141 2011-08-31 2011-08-31 Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm Ceased WO2012149717A1 (fr)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN201180004976.0A CN102986162B (zh) 2011-08-31 2011-08-31 基于TCM或TPM的license动态管理方法、装置及系统
PCT/CN2011/079141 WO2012149717A1 (fr) 2011-08-31 2011-08-31 Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/079141 WO2012149717A1 (fr) 2011-08-31 2011-08-31 Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm

Publications (1)

Publication Number Publication Date
WO2012149717A1 true WO2012149717A1 (fr) 2012-11-08

Family

ID=47107752

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/079141 Ceased WO2012149717A1 (fr) 2011-08-31 2011-08-31 Procédé, dispositif et système de gestion dynamique de licence basés sur une tcm ou une tpm

Country Status (2)

Country Link
CN (1) CN102986162B (fr)
WO (1) WO2012149717A1 (fr)

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112235107A (zh) * 2020-10-27 2021-01-15 南方电网科学研究院有限责任公司 一种数据传输方法、装置、设备和存储介质
CN112597551A (zh) * 2020-12-22 2021-04-02 南京道熵信息技术有限公司 一种使用License可实时更新的磁盘加密方法与系统
CN114499891A (zh) * 2022-03-21 2022-05-13 宁夏凯信特信息科技有限公司 一种签名服务器系统以及签名验证方法
WO2022174748A1 (fr) * 2021-02-20 2022-08-25 普源精电科技股份有限公司 Dispositif de test électronique et procédé de configuration de fonction facultative
CN116155633A (zh) * 2023-04-23 2023-05-23 农数源(成都)科技有限公司 一种传感器外置数据安全保护与双向鉴别方法、系统、装置
US20230289478A1 (en) * 2020-08-28 2023-09-14 Hewlett-Packard Development Company, L.P. Generating signed measurements

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103916390B (zh) * 2014-03-20 2017-10-31 汉柏科技有限公司 云计算系统中license的控制方法和装置
CN112398818B (zh) * 2020-11-02 2023-03-07 深圳数联天下智能科技有限公司 一种软件激活方法及其相关装置
CN113422683B (zh) * 2021-03-04 2023-05-26 上海数道信息科技有限公司 一种边云协同数据传输方法、系统、存储介质及终端

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1372055A2 (fr) * 2002-06-12 2003-12-17 Microsoft Corporation Publication de contenu utilisant une architecture de gestion de droits d'accès
CN1539107A (zh) * 2001-06-07 2004-10-20 ��̹�е¿عɹɷ����޹�˾ 用于订阅数字权利管理的方法和系统
CN101610148A (zh) * 2009-07-08 2009-12-23 李伟 一种对等互联网络数字版权保护方法
CN102077213A (zh) * 2008-06-26 2011-05-25 微软公司 用于确保通信的认证和完整性的技术

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101631305B (zh) * 2009-07-28 2011-12-07 交通银行股份有限公司 一种加密方法及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1539107A (zh) * 2001-06-07 2004-10-20 ��̹�е¿عɹɷ����޹�˾ 用于订阅数字权利管理的方法和系统
EP1372055A2 (fr) * 2002-06-12 2003-12-17 Microsoft Corporation Publication de contenu utilisant une architecture de gestion de droits d'accès
CN102077213A (zh) * 2008-06-26 2011-05-25 微软公司 用于确保通信的认证和完整性的技术
CN101610148A (zh) * 2009-07-08 2009-12-23 李伟 一种对等互联网络数字版权保护方法

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
CHEN, JUAN ET AL.: "Research on CPK Authentication of Information Security Based on TPM", MODERN ELECTRONIC TECHNIQUE, vol. 323, no. 12, June 2010 (2010-06-01), pages 137 - 140 AND 146 *

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230289478A1 (en) * 2020-08-28 2023-09-14 Hewlett-Packard Development Company, L.P. Generating signed measurements
CN112235107A (zh) * 2020-10-27 2021-01-15 南方电网科学研究院有限责任公司 一种数据传输方法、装置、设备和存储介质
CN112235107B (zh) * 2020-10-27 2023-03-03 南方电网科学研究院有限责任公司 一种数据传输方法、装置、设备和存储介质
CN112597551A (zh) * 2020-12-22 2021-04-02 南京道熵信息技术有限公司 一种使用License可实时更新的磁盘加密方法与系统
CN112597551B (zh) * 2020-12-22 2023-08-18 南京道熵信息技术有限公司 一种使用License可实时更新的磁盘加密方法与系统
WO2022174748A1 (fr) * 2021-02-20 2022-08-25 普源精电科技股份有限公司 Dispositif de test électronique et procédé de configuration de fonction facultative
US12323508B2 (en) 2021-02-20 2025-06-03 Rigol Technologies Co., Ltd. Electronic test equipment and optional function configuring method
CN114499891A (zh) * 2022-03-21 2022-05-13 宁夏凯信特信息科技有限公司 一种签名服务器系统以及签名验证方法
CN114499891B (zh) * 2022-03-21 2024-05-31 宁夏凯信特信息科技有限公司 一种签名服务器系统以及签名验证方法
CN116155633A (zh) * 2023-04-23 2023-05-23 农数源(成都)科技有限公司 一种传感器外置数据安全保护与双向鉴别方法、系统、装置
CN116155633B (zh) * 2023-04-23 2023-06-27 农数源(成都)科技有限公司 一种传感器外置数据安全保护与双向鉴别方法、系统、装置

Also Published As

Publication number Publication date
CN102986162A (zh) 2013-03-20
CN102986162B (zh) 2015-08-05

Similar Documents

Publication Publication Date Title
WO2020147383A1 (fr) Procédé, dispositif et système d'examen et d'approbation de processus utilisant un système de chaîne de blocs, et support de stockage non volatil
CN101019369B (zh) 利用在线服务向装置传递直接证明私有密钥的方法
WO2014069783A1 (fr) Procédé d'authentification par mot de passe et appareil pour l'exécuter
WO2016206530A1 (fr) Procédé, appareil et système de paiement mobile hautement sécurisé
WO2020186775A1 (fr) Procédé, appareil et dispositif de fourniture de données de service, et support de stockage lisible par ordinateur
WO2019132272A1 (fr) Identifiant en tant que service basé sur une chaîne de blocs
WO2014175538A1 (fr) Appareil permettant d'utiliser un otp matériel basé sur puf et procédé permettant une authentification à 2 facteurs l'utilisant
JP7586355B2 (ja) 暗号通信システム、セキュアエレメント、デバイス及び暗号通信方法
WO2014008858A1 (fr) Procédé de mise en œuvre de saut inter-domaine, navigateur et serveur de nom de domaine
WO2020050424A1 (fr) SYSTÈME ET PROCÉDÉ BASÉS SUR UNE CHAÎNE DE BLOCS POUR UNE AUTHENTIFICATION DE SÉCURITÉ MULTIPLE ENTRE UN TERMINAL MOBILE ET UN DISPOSITIF D'IdO
WO2016123926A1 (fr) Procédé et système de gestion de terminal à carte de module d'identité d'abonné par télécommande
WO2014063455A1 (fr) Procédé et système de messagerie instantanée
WO2014139343A1 (fr) Procédé de téléchargement de clé, procédé de gestion, procédé de gestion de téléchargement, appareil et système
WO2012093900A2 (fr) Procédé et dispositif pour authentifier une entité de réseau personnel
WO2020022700A1 (fr) Élément de sécurité de traitement et d'authentification de clé numérique et procédé de fonctionnement associé
WO2018072261A1 (fr) Procédé et dispositif de chiffrement d'informations, procédé et dispositif de déchiffrement d'informations, et terminal
WO2016176967A1 (fr) Système de paiement mobile et procédé de paiement mobile associé
CA2713787A1 (fr) Protocole de protection des donnees de protection de contenus
WO2020235733A1 (fr) Dispositif et procédé permettant d'authentifier un utilisateur et d'obtenir une signature d'utilisateur grâce à la biométrie de l'utilisateur
WO2012099330A2 (fr) Système et procédé de délivrance d'une clé d'authentification pour authentifier un utilisateur dans un environnement cpns
WO2018090481A1 (fr) Procédé et système de vérification de certificat numérique d'application de terminal mobile
WO2018098886A1 (fr) Procédé d'ouverture de portière de véhicule, terminal mobile, terminal monté sur véhicule et système
WO2025005456A1 (fr) Procédé et dispositif de lecture multimédia pour système virtuel
WO2020253120A1 (fr) Procédé, système et dispositif d'enregistrement de page web, et support de stockage informatique
WO2017166884A1 (fr) Procédé et appareil de traitement de fichiers employant un dispositif externe

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201180004976.0

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11864687

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 11864687

Country of ref document: EP

Kind code of ref document: A1