WO2019101170A1 - License管理 - Google Patents

License管理 Download PDF

Info

Publication number
WO2019101170A1
WO2019101170A1 PCT/CN2018/117232 CN2018117232W WO2019101170A1 WO 2019101170 A1 WO2019101170 A1 WO 2019101170A1 CN 2018117232 W CN2018117232 W CN 2018117232W WO 2019101170 A1 WO2019101170 A1 WO 2019101170A1
Authority
WO
WIPO (PCT)
Prior art keywords
license
transaction
processor
instruction
node
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2018/117232
Other languages
English (en)
French (fr)
Inventor
严德汗
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
New H3C Technologies Co Ltd
Original Assignee
New H3C Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by New H3C Technologies Co Ltd filed Critical New H3C Technologies Co Ltd
Publication of WO2019101170A1 publication Critical patent/WO2019101170A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q10/00Administration; Management
    • G06Q10/10Office automation; Time management
    • G06Q10/103Workflow collaboration or project management

Definitions

  • the enterprise After the enterprise produces the equipment and sells it to its customers, if the customer wants to use the purchased equipment or use certain functions of the equipment normally, they need to obtain the corresponding license, and the license generated by the enterprise is managed by the enterprise.
  • the user After the user purchases the authorization, the user obtains the authorization code, and then the user enters the relevant command on the purchased device to obtain the serial number and device ID (Identification) of the device, and then logs in to the website of the device manufacturing enterprise, and the product type of the device is passed through the device.
  • the authorization code, the serial number, and the device ID are used to apply for the activation file.
  • the activation file is downloaded to the purchased device, and the activation file is installed on the device.
  • the device obtains the license.
  • the device may need to be upgraded and migrated.
  • the license required for the device may also be transferred.
  • the device manufacturer needs to manage the license. Manually record the license management.
  • FIG. 1 is a schematic flowchart of a device authorization method according to an embodiment of the present disclosure
  • FIG. 2 is a schematic structural diagram of a block according to an embodiment of the present application.
  • FIG. 3 is a schematic diagram of a private blockchain according to an embodiment of the present application.
  • FIG. 4 is a schematic structural diagram of a transaction ticket according to an embodiment of the present application.
  • FIG. 5 is a schematic structural diagram of a device authorization apparatus according to an embodiment of the present disclosure.
  • FIG. 6 is a schematic structural diagram of an electronic device according to an embodiment of the present application.
  • the embodiment of the present application provides a license management method.
  • the license management method is applied to a primary node in a private blockchain, and the private blockchain further includes: a client node.
  • the above-mentioned master node may generate a block according to a preset rule and synchronize the generated block to each client node.
  • the master node detects that the predetermined rule is satisfied to generate a block and performs block synchronization.
  • the present application does not limit block generation and block synchronization and the execution order of S101-S107 described below. That is to say, the master node may detect that the preset rule is satisfied without performing any of the following steps S101-S107, thereby generating a block and synchronizing the block, and may also perform the following S101-S107. In the process of one step, it is detected that the preset rule is satisfied, thereby generating a block and synchronizing the block.
  • the above license management methods include:
  • the first license corresponding to the first device generated by the master node may be a temporary license or a formal license, which is not limited in this application.
  • the master node may obtain a third transaction order, where the third transaction ticket includes the content of the second license and the owner information of the second license, and the owner information of the second license is information of the master node, and the The third transaction ticket is stored in a block in which the primary node is active.
  • the license obtained after the upgrade of the second license is used as the first license.
  • the master node may receive an instruction to indicate that the second license is migrated from the second device to the first device; when the content of the second license includes the device identifier as the identifier of the second device, and the transaction type included is The license obtained after the migration of the second license is used as the first license.
  • the first transaction ticket includes the content of the first license and the owner information of the first license, and the owner information of the first license included in the first transaction ticket is information of the master node.
  • the device identifier included in the content of the first license is the identifier of the first device.
  • the first transaction ticket can be broadcast on the private blockchain.
  • the second transaction slip includes the content of the first license and the owner information of the first license, and the owner information of the first license included in the second transaction ticket is information of the first client node.
  • the primary node transmitting the second transaction ticket to the first client node can include broadcasting the second transaction ticket on the private blockchain such that the first transaction node can receive the second transaction ticket.
  • the master node may further obtain a fourth transaction slip, where the fourth transaction ticket includes the content of the third license and the owner information of the third license, and the owner information of the third license included in the fourth transaction ticket is Information about the second client node.
  • the fourth transaction ticket is stored in a block in which the master node is in an active state.
  • each of the above transaction orders further includes: a sequence number indicating a license transaction order and a signature of the license owner;
  • the signature of the license owner stored in a transaction ticket is: the information obtained by encrypting the first public key and the first sequence number by using the first private key as the encryption key, and the first private key is: the transaction key points The private key of the license owner recorded in the previous transaction.
  • the first public key is: the public key of the license owner recorded in the transaction order.
  • the first sequence number is: the previous transaction order pointed to by the transaction order. The sequence number of the store.
  • the above-mentioned master node can be understood as a node corresponding to the equipment manufacturing enterprise
  • the client node can be understood as a node corresponding to the customer who purchases the equipment produced by the enterprise.
  • the above first device can be understood as any device produced by the enterprise.
  • the master node has the right to generate a block. Since the master node generates the block, the generated block is synchronized to each client node. Therefore, the master node and the area in each client node can be considered. The blocks are consistent. As the number of blocks generated by the master node increases, there may be multiple blocks in the master node and each client node.
  • the master node when it generates a block according to a preset rule, it may generate a block every preset time interval, or may generate a block at a fixed time point.
  • the newly generated block may be referred to as a block in which the master node is in an active state.
  • the block in the active state of each client node can be understood as: the block that is newly synchronized by the master node to each client node.
  • Each of the above blocks is used to store a transaction order.
  • FIG. 2 a schematic structural diagram of a block is provided, in which the chain relationship between the blocks is shown by arrows, from left to right. The generated time of each block is getting shorter and shorter.
  • This chain relationship is formed by a total of 4 blocks of block 00, block 10, block 20 and block 30, wherein block 00 is the first generation.
  • the block can be called a creation block.
  • a front block hash can also be stored in each block, such as a front block hash 11 in block 10, a front block hash 21 in block 20, and a block 30.
  • the front block is hashed 31.
  • the hash of the previous block stored in a block is used to indicate the sequence number of the previous block of the block.
  • the sequence number of each block may be determined according to information such as the generation time of the block, and the like.
  • the order relationship between the blocks can be clearly understood according to the previous block hash stored in each block.
  • the creation block is the first block generated by the main node, there is no other block before it. Therefore, the pre-block hash may not be stored in the creation block.
  • TX represents the transaction order of the license
  • the transaction order stored in each block is: TX2000-TX2011.
  • Each transaction order stored in each of the above blocks corresponds to one license, and at least one of the following information is stored in one transaction list:
  • the transaction owner's information corresponding to the license is the transaction owner's information corresponding to the license.
  • the content of the foregoing license may include:
  • Device type authorization code
  • device serial number device ID
  • authorization method expiration date
  • transaction type device type, authorization code, device serial number, device ID, authorization method, expiration date, transaction type.
  • the device ID may be in the form of a string or a file, which is not limited in this application.
  • the above authorization method refers to the way to obtain authorization. You can install the activation file on the device to obtain authorization, or you can enter the activation code or authorization code to obtain authorization on the device.
  • the above validity period includes: permanent validity, absolute validity period and relative validity period.
  • the above transaction types can be time extension, function expansion, scale expansion, migration, customer change, and so on.
  • the transaction type is extended, the function is extended, and the capacity is expanded, you can upgrade the license. If the transaction type is extended, the function is extended, and the capacity is expanded, the license needs to be upgraded.
  • migration it can be understood as: the migration of the license between devices.
  • a customer change it can be understood as: the transfer of equipment between different customers.
  • the owner information of the foregoing license may be any information that can uniquely represent the owner of the license, for example, the address of the client node, the identity of the client node, the address of the master node, the identity of the master node, and the like.
  • the master node can assign a license to the device. Since the enterprise will have equipment transactions such as selling the equipment to the customer or transferring the equipment between the customers, and each device transaction will cause the content of the license to change, each change of the content of the license can be called a license transaction. .
  • the enterprise and the customer form a private blockchain, that is, the private blockchain formed by the above-mentioned master node and the client node, and the master node is the corresponding node of the enterprise to generate the first device corresponding The first license, and generating a first transaction slip, the first transaction slip includes the content of the first license, and the license owner information included in the first transaction ticket is information of the master node, determining the first device belongs to After the first client node, the second transaction order is generated, and the second transaction ticket also includes the content of the first license.
  • the license owner information included in the second transaction ticket is information of the first client node, and the master node is first.
  • the client node sends the second transaction order, so that the first client node can send the content of the first license to the first device according to the second transaction order.
  • the master node implements the license management by using the private blockchain formed by the client node, thereby eliminating the need for manually recording the license flow and reducing the equipment manufacturing enterprise. It is difficult to manage the license.
  • each customer's device can obtain the license content from the corresponding customer node, without requiring each device to obtain the license content from the production company's website, thereby further reducing the equipment manufacturing enterprise's license for the license. The difficulty of management.
  • the private blockchain shown in FIG. 3 is a master node 301 corresponding to the equipment manufacturing enterprise, a customer node 302 corresponding to the A customer who purchased the equipment produced by the enterprise, and a customer node 303 corresponding to the B customer who purchased the equipment produced by the enterprise. Composition.
  • the block generated by the master node 301 is as shown above the master node 301 in FIG. 3, and the master node synchronizes the generated block to each client node of the private blockchain after generating each block. Therefore, the case of the block in the client node 302 and the client node 303 is the same as in the master node 301, which is not shown in FIG.
  • TX3000-TX3011 mentioned in the following description is not shown in FIG. 3 in view of the limited space of FIG.
  • TX transaction order
  • client node 302 client node 302
  • client node 303 client node 303
  • the master node 301 currently generates a total of four blocks, in order of generation time from long to short: block 00, block 10, block 20 and block 30, that is, block 30 is the master node. 301 newly generated block, block 30 is a block in the active state of the master node 301.
  • the master node 301 allocates a temporary license0 to the device 401 and generates a TX3000.
  • the master node 301 stores the TX 3000 in the block 30 in which the master node 301 is in an active state.
  • the TX3000 includes: the content of the license0 and the owner information of the license0.
  • the device identifier included in the content of the license0 is: the identifier of the device 401.
  • the owner of the license 0 is also the master node 301. Therefore, the owner information of the license 0 included in the TX3000 is: information of the master node 301.
  • the master node 301 After the A customer purchases the device 401, in order to ensure that the A client can use the device 401 normally, so that the device 401 obtains the temporary license, the master node 301 generates the TX 3001 and stores the TX 3001 in the block 30 in which the master node 301 is in an active state.
  • the TX3001 includes: the content of License0 and the owner of License0.
  • the owner information of the license 0 included in the TX 3001 is the information of the client node 302, and the device identifier included in the content of the license 0 is the identifier of the device 401.
  • the TX 3001 is broadcast on the private blockchain, and the client node 302 obtains the TX 3001 and stores it in the block in which the client node 302 is in an active state.
  • the client node 302 determines that the owner information of the license0 in the TX3001 is the self-information and the device identifier included in the content of the license0 is the identifier of the device 401, the content of the license0 is sent to the device 401, and the device 401 downloads the license0 according to the content of the license0. And install License0 to get temporary authorization.
  • the master node 301 assigns the official license 1 to the device 401 and generates the TX 3002.
  • the master node 301 stores the TX 3002 in the block 30 in an active state.
  • the TX3002 includes: the content of the license1 and the owner information of the license1, wherein the owner information of the license1 included in the TX3002 is: information of the master node 301, and the device identifier included in the content of the license1 is: the identifier of the device 401.
  • the master node 301 Since the A client has purchased the official license for the device 401, in order to ensure that the device 401 obtains the official license, the master node 301 generates a TX 3003 and stores the TX 3003 in the block 30 in which the master node 301 is in an active state.
  • the TX3003 includes: the content of the license1 and the owner information of the license1.
  • the owner information of the license 1 included in the TX 3003 is the information of the client node 302, and the device identifier included in the content of the license 1 is the identifier of the device 401.
  • the client node 302 After the master node generates TX3003, the TX3003 is broadcasted on the private blockchain, the client node 302 obtains the TX3003, and the TX3003 is stored in the block where the client node 302 is in an active state.
  • the client node 302 determines that the owner information of the license 1 in the TX 3003 is the self information and the device identifier included in the content of the license 1 is the identifier of the device 401, the content of the license 1 recorded in the TX 3003 is sent to the device 401, and the device 401 is based on the license 1. Download License1 and install License1 to obtain formal authorization.
  • the A client discovers that the license 1 validity period of the device 401 is approaching.
  • the client node 302 generates the TX 3004, stores the TX 3004 in the block where the client node 302 is in an active state, and broadcasts on the private blockchain.
  • the TX3004 includes: the content of the license1 and the owner information of the license1, wherein the device identifier included in the content of the license1 is: the identifier of the device 401, and the transaction type included in the content of the license1 is: the extended validity period, the owner information of the license1 Is: information of the master node 301.
  • the master node 301 obtains the TX 3004 and stores the TX 3004 in the block 30 in which the master node 301 is in an active state.
  • the master node 301 determines that the owner information of the license 1 included in the TX 3004 is itself and the transaction type in the content of the license 1 is an extended validity period, the characterization indicates that the master node 301 needs to be upgraded for the license1, and the master node 301 records according to the content of the license 1 included in the TX 3004.
  • the information related to the validity period and the time limit for requesting extension, the license 401 is assigned to the device 401, and the TX 3005 is generated.
  • the master node 301 stores the TX 3005 in the block 30 in which the master node 301 is in an active state.
  • the TX3005 includes: the content of the license 2 and the owner information of the license 2, wherein the device identifier included in the content of the license 2 is: the identifier of the device 401, and the owner information of the license 2 is: information of the master node 301.
  • the master node 301 Since the A client has requested the device 401 to extend the license period, in order to ensure that the device 401 obtains the extended license, the master node 301 generates the TX 3006, and stores the TX 3006 in the block 30 in which the master node 301 is in an active state, wherein the TX 3006
  • the device includes: the content of the license 2 and the owner information of the license 2.
  • the device identifier included in the content of the license 2 is: the identifier of the device 401
  • the owner information of the license 2 included in the TX 3006 is: information of the client node 302.
  • the TX 3006 is broadcast on the private blockchain.
  • the client node 302 obtains the TX 3006, the TX 3006 is stored in the block where the client node 302 is in an active state, and the client node 302 determines the owner of the License 2 in the TX3006. If the information is the information of the device and the device ID included in the content of the license 2 is the identifier of the device 401, the content of the license 2 recorded in the TX3006 is sent to the device 401.
  • the device 401 downloads the license 2 according to the content of the license 2, and installs the license 2 to obtain the upgrade. Authorization.
  • the A customer finds that the device 401 is no longer suitable for the current work, and needs to complete the current work by the unauthorized device 402 instead of the device 401, wherein the device 402 is also the device produced by the above enterprise, in this case,
  • the license 2 needs to be migrated from the device 401 to the device 402.
  • the device 401 can voluntarily give up the license 2 and notify the client node 302 to migrate the license 2 to the device 402.
  • the client node 302 sends a notification to the master node 301 that the license 2 is migrated by the device 401.
  • the migration instruction to device 402, and generates TX 3007 stores TX 3007 in the block where client node 302 is active.
  • the TX3007 includes: the content of the license 2 and the owner information of the license 2, wherein the device identifier included in the content of the license 2 is: the identifier of the device 401, the transaction type in the content of the license 2 is: migration, and the owner information of the license 2 is: Information of node 301.
  • the TX 3007 is broadcasted on the private blockchain.
  • the master node 301 obtains the TX 3007, the TX 3007 is stored in the block 30 in which the master node 301 is in an active state.
  • the master node 301 determines the owner of the license 2 in the TX3007. The information is itself and the transaction type in the content of the license 2 is the migration.
  • the master node 301 allocates the license 3 to the device 402 according to the content of the license 2 included in the TX 3007 and the migration instruction, generates the TX 3008, and stores the TX 3008 in the active state of the master node 301.
  • the TX3008 includes: the content of the license 3 and the owner information of the license 3, wherein the device identifier included in the content of the license 3 is: the identifier of the device 402, and the owner information of the license 2 is: the master node 301 information.
  • the validity period of the license is expressed in the form of a relative validity period
  • the device 401 has used the license 2 for a total of 4 months, and the license 2 is valid for 12 months
  • the master node 301 As the A client has requested to migrate the license 2 from the device 401 to the device 402, in order to ensure that the device 402 is authorized, the master node 301 generates a TX 3009, and stores the TX 3009 in the block 30 in which the master node 301 is in an active state, where the TX 3009 includes: The content of the license 3 and the owner information of the license 3, wherein the device identifier included in the content of the license 3 is the identifier of the device 402, and the owner information of the license 3 is the information of the client node 302.
  • the TX3009 is broadcasted on the private blockchain.
  • the client node 302 obtains the TX3009, the TX3009 is stored in the block where the client node 302 is in an active state, and the client node 302 determines the owner of the license3 in the TX3009.
  • the information is its own information and the device identifier included in the content of the license 3 is the identifier of the device 402
  • the content of the license 3 recorded in the TX3009 is sent to the device 402.
  • the device 402 downloads the license 3 according to the content of the license 3, and installs the license 3 to obtain the upgrade.
  • Authorization is the information that the information is its own information and the device identifier included in the content of the license 3 is the identifier of the device 402
  • the A client finds that it no longer needs the device 402, and then transfers the device 402 to the B client.
  • the client node 302 In order for the B client to see the authorization of the device 402 owned by the client, the client node 302 generates the TX3010 and will The TX 3010 is stored in a block in which the client node 302 is active.
  • the TX3010 includes: the content of the license 3 and the owner information of the license 3.
  • the device identifier included in the content of the license 3 is: the identifier of the device 402, and the owner information of the license 3 included in the TX 3010 is the information of the client node 303.
  • the TX 3010 is broadcasted on the private blockchain, so that both the master node 301 and the client node 303 can receive the TX 3010.
  • the client node 303 stores the TX 3010 in the active state of the client node 303.
  • the B client can know the authorization status of the device 402 according to the information recorded in the TX3010.
  • the master node 301 stores the TX 3010 in the block 30 in which the master node 301 is in an active state.
  • the master node 301 checks that the transaction type in the content of the license 3 in the TX 3010 is changed by the client, so that the master node 301 can be based on the TX 3010.
  • the information recorded in the article understands that the A customer transferred the device 402 and the license 3 to the B customer.
  • the device 402 If the device 402 detects that the license 3 has expired during the operation, it sends a notification that the license 3 has expired to the client node 303. Upon receipt of the notification, the client node 303 generates a recycle transaction ticket, referred to herein as TX3011.
  • the TX3011 includes: the content of the license 3 and the owner information of the license 3.
  • the owner information of the license 3 is: information of the main section 301
  • the device identifier included in the content of the license 3 is: the identifier of the device 402, and the content of the license 3 includes
  • the transaction type is: Recycling.
  • Client node 303 broadcasts TX 3011 over the private blockchain. After receiving the TX 3011, the master node 301 stores the TX 3011 in the block 30 in which the master node 301 is in an active state. In this way, the master node 301 can learn that the license 3 on the device 402 has expired according to the content included in the TX 3011.
  • a transaction ticket in order to ensure that the device can accurately download the license according to the license content in the transaction ticket, a transaction ticket can also be used to store the sequence number indicating the transaction order of the license and the signature of the license owner.
  • the signature of the license owner stored in a transaction ticket is: the information obtained by encrypting the first public key and the first sequence number by using the first private key as the encryption key, wherein the first private key is: the transaction order The private key of the owner of the license recorded in the previous transaction order.
  • the first public key is: the public key of the owner of the license recorded in the transaction order.
  • the first sequence number is: the order pointed to by the transaction order. The sequence number stored in a trade order.
  • the above sequence number indicating the order of the license transaction can also be referred to as a hash value, so that a transaction list can be considered to store a hash value.
  • the previous transaction order pointed to by a transaction order can be understood as: the previous transaction order directly related to this transaction order.
  • TX3001 can be modified by the information of the owner 0 of the license 3000 in the TX3000.
  • the TX3001 is generated by modifying the information on the basis of the TX3000. Therefore, it can be considered that the previous transaction order pointed to by the TX3001 is TX3000.
  • the pointing relationship between the two transaction orders can be implemented in the form of a singly linked list or a doubly linked list. This application is only described by way of example, and does not limit the implementation form of the pointing relationship between the two transaction orders.
  • the device may first decrypt the device owner signature recorded in the transaction ticket by using the second public key as the decryption key. After the decryption result is obtained, it is checked whether the decryption result is the first public key and the first sequence number. If yes, the content of the transaction ticket has not been tampered with, and the license can be safely downloaded. If not, the content of the transaction ticket is indicated. It may have been tampered with and you can refuse to download the license.
  • the second public key is: the public key of the owner of the license recorded in the previous transaction order pointed to by the transaction slip.
  • FIG. 4 includes 10 transaction orders, TX3002-TX3011, wherein TX3002 is also referred to as a production transaction order, and the hash values of the 10 transaction orders are respectively recorded as: hash value 4001 - hash value 4010. among them,
  • the production transaction order is a transaction ticket including the content of the official license1 generated after the master node 301 assigns the official license1 to the device 401, since the transaction ticket can be regarded as the first officially generated by the master node 301 for the device 401.
  • the transaction ticket of the license, the master node 301 is the first owner of the official license, so the transaction ticket may not be signed by the license owner.
  • partial content refers to: part of the license in the current transaction order
  • Previous trading order means: the previous trading order pointed to by the current trading order
  • Previous owner means the owner of the license in the previous transaction
  • “Current Owner” means: the owner of Licnese in the current order
  • Previous sequence number means: the sequence number in the previous order
  • “Current sequence number” means: the sequence number in the current transaction order
  • the above current transaction order refers to the transaction order indicated in the first column of Table 1.
  • the license of the license owner is decrypted by the public key of the master node 301 to verify the signature of the device owner;
  • the license of the license owner is decrypted by the public key of the client node 302 to verify the signature of the device owner;
  • the license transaction process when a transaction order is generated, not only the previous transaction order pointed to by this transaction order is determined, but also the content of the license included in the transaction order is determined.
  • the direction of Licence can be known according to the pointing relationship between the various transaction orders generated in the license transaction process and the contents of the license included in the transaction ticket.
  • the pointing relationship between the above transaction orders and the contents of the license are determined during the process of generating the transaction order, so there is no need to manually record the transaction of the license, and no need to manually analyze the data to know the direction of the license.
  • the embodiment of the present application further provides a license management apparatus.
  • FIG. 5 is a schematic structural diagram of a license management apparatus according to an embodiment of the present disclosure, which is applied to a primary node in a private blockchain, where the private blockchain further includes: a client node; the device includes:
  • the block synchronization module 500 is configured to generate a block according to a preset rule, and synchronize the generated block to each client node;
  • the license generation module 501 is configured to generate a first license corresponding to the first device.
  • a first transaction form generating module 502 configured to generate a first transaction order, where the first transaction order includes content of the first license and owner information of the first license, where the first transaction order includes The owner information of the first license is the information of the primary node; the device identifier of the content of the first license is the identifier of the first device;
  • a first transaction order storage module 503, configured to store the first transaction order into a block in which the primary node is in an active state
  • a node determining module 504 configured to determine a first client node to which the first device belongs;
  • a second transaction order generating module 505 configured to generate a second transaction order, where the second transaction order includes content of the first license and owner information of the first license, where the second transaction order includes The owner information of the first license is information of the first client node;
  • a second transaction order storage module 506, configured to store the second transaction order into a block in which the primary node is in an active state
  • a transaction order sending module 507 configured to send the second transaction order to the first client node, so that the first client node stores the second transaction order to where the first client node is in an active state And sending the content of the first license to the first device.
  • the license management device may further include:
  • a broadcast module configured to broadcast the first transaction ticket on the private blockchain
  • the sending module is specifically configured to broadcast the second transaction ticket on the private blockchain.
  • the license generation module 501 includes:
  • a transaction order obtaining unit configured to acquire a third transaction order, where the third transaction order includes the content of the second license and the owner information of the second license, and the third transaction ticket includes the second license
  • the owner information is information of the master node
  • a transaction order storage unit configured to store the third transaction order into a block in which the primary node is in an active state
  • the first license determining unit is configured to: when the device identifier included in the content of the second license is the identifier of the first device, and the type of the transaction included is upgraded, the license obtained after the second license is upgraded As the first license.
  • the license generating module 501 further includes:
  • a receiving unit configured to receive an instruction for instructing the second license to be migrated from the second device to the first device
  • the second license determining unit is configured to: when the device identifier included in the content of the second license is the identifier of the second device, and the transaction type included in the migration is a migration, the license obtained after the second license is migrated As the first license.
  • the license management device further includes:
  • a transaction order obtaining module configured to acquire a fourth transaction form, where the fourth transaction order includes the content of the third license and the owner information of the third license, and the fourth transaction includes the third license
  • the owner information is information of the second client node
  • a third transaction order storage module configured to store, when the transaction type of the third license includes a customer change, the fourth transaction order to a block in which the primary node is in an active state.
  • a transaction order is also used to store the sequence number indicating the order of the license transaction and the signature of the license owner;
  • the signature of the license owner stored in a transaction ticket is: the information obtained by encrypting the first public key and the first sequence number by using the first private key as the encryption key, wherein the first private key is: the transaction The private key of the owner of the license recorded in the previous transaction note pointed to by the single, the first public key is: the public key of the owner of the license recorded in the transaction ticket, the first sequence number is: The sequence number stored in the previous order pointed to by the order.
  • the enterprise and the customer form a private blockchain, that is, the private blockchain formed by the above-mentioned master node and the client node, and the master node is the node corresponding to the enterprise to generate the first device.
  • the first transaction slip includes the content of the first license
  • the license owner information included in the first transaction slip is the information of the master node, determining that the first device belongs to After the first customer node, the second transaction order is generated, and the second transaction order also includes the content of the first license.
  • the license owner information included in the second transaction order is information of the first client node, and the master node A client node sends a second transaction order, so that the first client node can send the content of the first license to the first device according to the second transaction order.
  • the master node implements the license management by using the private blockchain formed by the client node, thereby eliminating the need for manually recording the license flow and reducing the equipment manufacturing enterprise. It is difficult to manage the license.
  • each customer's device can obtain the license content from the corresponding customer node, and each device does not need to obtain the license content from the production company's website, thereby further reducing the equipment manufacturing enterprise's license. The difficulty of managing.
  • the embodiment of the present application further provides an electronic device.
  • FIG. 6 is a schematic structural diagram of an electronic device according to an embodiment of the present disclosure, where the electronic device is a master node in a private blockchain, the private blockchain further includes: a client node; and the electronic device includes: a processor 61.
  • the machine executable instructions executed by the processor 61, the machine executable instructions include: a synchronization instruction 621, a generation instruction 622, a storage instruction 623, a determination instruction 624, and a transmission instruction 625;
  • the processor is caused by the synchronization instruction 621 to implement the steps of: generating a block according to a preset rule, and synchronizing the generated block to each client node;
  • the processor is caused by the generating instruction 622 to implement the step of: generating a first license corresponding to the first device;
  • the processor is caused by the generating instruction 622 to implement the step of: generating a first transaction slip, the first transaction ticket including content of the first license and owner information of the first license, the first transaction
  • the owner information of the first license is the information of the primary node, and the device identifier of the content of the first license is the identifier of the first device.
  • the processor is caused by the storage instruction 623 to implement the step of: storing the first transaction order into a block in which the primary node is in an active state;
  • the processor is caused by the determining instruction 624 to cause an implementation step of: determining a first client node to which the first device belongs;
  • the processor is caused by the generating instruction 622 to implement the step of: generating a second transaction slip, the second transaction ticket including the content of the first license and the owner information of the first license, the second transaction
  • the owner information of the first license included in the single is the information of the first client node;
  • the processor is caused by the store instruction 623 to implement the step of: storing the second transaction ticket into a block that is in an active state of the master node;
  • the processor is caused by the sending instruction 625 to implement the step of: transmitting the second transaction slip to the first client node to cause the first client node to store the second transaction ticket to the first
  • the client node is in the active state, and the content of the first license is delivered to the first device.
  • the machine executable instructions further include: a broadcast instruction
  • the processor 61 is caused by the broadcast instruction to implement the step of: broadcasting the first transaction order on the private blockchain;
  • the processor 61 is prompted by the send command 625 to implement a specific implementation step of broadcasting the second transaction ticket over the private blockchain.
  • the processor 61 is caused by the generating instruction 622 to perform a specific implementation step of acquiring a third transaction order, where the third transaction order includes the content of the second license and the owner information of the second license.
  • the owner information of the second license included in the third transaction order is information of the master node; storing the third transaction ticket in a block in which the master node is in an active state;
  • the device identifier of the license includes the identifier of the first device and the type of the transaction included is upgraded, the license obtained by upgrading the second license is used as the first license.
  • the processor 61 is caused by the generating instruction 622 to further implement the steps of: receiving an instruction to instruct the second license to be migrated from the second device to the first device; when the second license is When the device identifier is the identifier of the second device and the transaction type is the migration, the license obtained after the migration of the second license is used as the first license.
  • the machine executable instructions further comprise: obtaining an instruction
  • the processor 61 is caused by the obtaining instruction to implement the step of: acquiring a fourth transaction slip, the fourth transaction slip including the content of the third license and the owner information of the third license, where the fourth transaction order includes The owner information of the third license is information of the second client node;
  • the processor 61 is caused by the storage instruction 623 to further implement the step of: when the transaction type of the third license includes a customer change, storing the fourth transaction order to the active node of the active node. In the block.
  • a transaction order is also used to store the sequence number indicating the order of the license transaction and the signature of the license owner;
  • the signature of the license owner stored in a transaction ticket is: the information obtained by encrypting the first public key and the first sequence number by using the first private key as the encryption key, wherein the first private key is: the transaction The private key of the owner of the license recorded in the previous transaction note pointed to by the single, the first public key is: the public key of the owner of the license recorded in the transaction ticket, the first sequence number is: The sequence number stored in the previous order pointed to by the order.
  • the enterprise and the customer form a private blockchain, that is, the private blockchain formed by the above-mentioned master node and the client node, and the master node is the corresponding node of the enterprise to generate the first device corresponding The first license, and generating a first transaction slip, the first transaction slip includes the content of the first license, and the license owner information included in the first transaction ticket is information of the master node, determining the first device belongs to After the first client node, the second transaction order is generated, and the second transaction ticket also includes the content of the first license.
  • the license owner information included in the second transaction ticket is information of the first client node, and the master node is first.
  • the client node sends the second transaction order, so that the first client node can send the content of the first license to the first device according to the second transaction order.
  • the master node implements the license management by using the private blockchain formed by the client node, thereby eliminating the need for manually recording the license flow and reducing the equipment manufacturing enterprise. It is difficult to manage the license.
  • each customer's device can obtain the license content from the corresponding customer node, without requiring each device to obtain the license content from the production company's website, thereby further reducing the equipment manufacturing enterprise's license for the license. The difficulty of management.
  • the embodiment of the present application further provides a machine readable storage medium, which is a storage medium of a master node in a private blockchain, the private
  • the blockchain also includes: a client node;
  • the machine readable storage medium stores machine executable instructions including: a synchronization instruction, a generation instruction, a storage instruction, a determination instruction, and a transmission instruction;
  • the allocation instruction when invoked and executed by the processor, causes the processor to implement the steps of: generating a block according to a preset rule, and synchronizing the generated block to each client node;
  • the generating instruction when being called and executed by the processor, causes the processor to implement the step of: generating a first license corresponding to the first device;
  • the generating instruction when invoked and executed by the processor, causes the processor to implement the step of: generating a first transaction slip, the first transaction ticket including content of the first license and the first
  • the owner information of the license, the owner information of the first license included in the first transaction ticket is information of the master node, and the device identifier included in the content of the first license is an identifier of the first device ;
  • the storage instruction when invoked and executed by the processor, causes the processor to implement the step of: storing the first transaction order into a block in which the primary node is in an active state;
  • the determining instruction when invoked and executed by the processor, causes the processor to implement the step of: determining a first client node to which the first device belongs;
  • the generating instruction when invoked and executed by the processor, causes the processor to implement the step of: generating a second transaction slip, the second transaction ticket including the content of the first license and the first Owner information of the license, the owner information of the first license included in the second transaction order is information of the first client node;
  • the storage instruction when invoked and executed by the processor, causes the processor to implement the step of: storing the second transaction order into a block in which the primary node is in an active state;
  • the sending instruction when invoked and executed by the processor, causes the processor to implement the step of: transmitting the second transaction order to the first client node, such that the first client node
  • the second transaction ticket is stored in the block in which the first client node is in an active state, and the content of the first license is delivered to the first device.
  • the enterprise and the customer form a private blockchain, that is, the private blockchain formed by the above-mentioned master node and the client node, and the master node is the corresponding node of the enterprise to generate the first device corresponding The first license, and generating a first transaction slip, the first transaction slip includes the content of the first license, and the license owner information included in the first transaction ticket is information of the master node, determining the first device belongs to After the first client node, the second transaction order is generated, and the second transaction ticket also includes the content of the first license.
  • the license owner information included in the second transaction ticket is information of the first client node, and the master node is first.
  • the client node sends the second transaction order, so that the first client node can send the content of the first license to the first device according to the second transaction order.
  • the master node implements the license management by using the private blockchain formed by the client node, thereby eliminating the need for manually recording the license flow and reducing the equipment manufacturing enterprise. It is difficult to manage the license.
  • each customer's device can obtain the license content from the corresponding customer node, without requiring each device to obtain the license content from the production company's website, thereby further reducing the equipment manufacturing enterprise's license for the license. The difficulty of management.

Landscapes

  • Business, Economics & Management (AREA)
  • Human Resources & Organizations (AREA)
  • Strategic Management (AREA)
  • Engineering & Computer Science (AREA)
  • Entrepreneurship & Innovation (AREA)
  • Operations Research (AREA)
  • Economics (AREA)
  • Marketing (AREA)
  • Data Mining & Analysis (AREA)
  • Quality & Reliability (AREA)
  • Tourism & Hospitality (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

一种授权许可License管理方法及装置,涉及通信技术领域,包括:按照预设规则生成区块,将生成的区块同步至各个客户节点;生成第一设备对应的第一License(S101);生成第一交易单(S102);将所述第一交易单存储至所述主节点(301)处于活跃状态的区块中(S103);确定所述第一设备所属的第一客户节点(S104);生成第二交易单(S105);将所述第二交易单存储至处于所述主节点处于活跃状态的区块中(S106);向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备(S107)。应用本方法降低了管理难度。

Description

License管理
本申请要求于2017年11月27日提交中国专利局、申请号为201711202672.0发明名称为“一种授权许可License管理方法及装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
背景技术
企业生产设备并销售给其客户后,这些客户若想正常使用所购买的设备或者正常使用设备的某些功能,需要获得相应的License(授权许可),而企业生成的License均由企业管理。
下面以通过激活文件授权为例,对现有技术中设备生产企业对License的管理方法进行说明:
用户购买授权书后获得授权码,然后用户通过在所购买设备上输入相关命令获取设备的序列号和设备ID(Identification,标识),再登录设备生产企业的网站,在该网站中通过设备的产品类型、授权码、序列号和设备ID申请激活文件,将激活文件下载至所购买设备上,再在设备上安装上述激活文件,设备获得License。
设备除了需要获得Licesne外,还可能需要对License进行升级、迁移等操作,也就是设备所需要的License还有可能发生流转,设备生产企业为了解License的流转情况,需要对License进行管理,一般通过人工记录的方式实现License管理。
附图简要说明
为了更清楚地说明本申请实施例和现有技术的技术方案,下面对实施例和现有技术中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例提供的一种设备授权方法的流程示意图;
图2为本申请实施例提供的一种区块的结构示意图;
图3为本申请实施例提供的一种私有区块链的示意图;
图4为本申请实施例提供的一种交易单的结构示意图;
图5为本申请实施例提供的一种设备授权装置的结构示意图;
图6为本申请实施例提供的一种电子设备的结构示意图。
具体实施方式
为使本申请的目的、技术方案、及优点更加清楚明白,以下参照附图并举实施例,对本申请进一步详细说明。显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
随着企业所生产设备增多,现有技术中设备生产企业对License进行管理时,需要人工记录的信息越来越多,使得设备生产企业管理License的难度越来越大,为解决这一技术问题,本申请实施例提供了一种License管理方法。
参见图1,提供了一种License管理方法的流程示意图,该License管理方法应用于私有区块链中的主节点,上述私有区块链还包括:客户节点。
上述主节点可以按照预设规则生成区块,并将所生成的区块同步至各个客户节点。
在一个例子中,主节点检测到满足预设规则即可生成区块并进行区块同步,本申请并不限定区块生成以及区块同步与下述S101-S107的执行顺序。也就是说,主节点可能会在未执行下述S101-S107任一步骤的情况下,检测到满足预设规则,进而生成区块,并同步区块,也可能在执行下述S101-S107任一步骤的过程中,检测到满足预设规则,进而生成区块,并同步区块。
上述License管理方法包括:
S101、生成第一设备对应的第一License。
在一个例子中,主节点生成的第一设备对应的第一License可以是临时License,也可以是正式License,本申请并不对此进行限定。
在一个例子中,主节点可以获取第三交易单,该第三交易单包括第二License的内容及第二License的所有者信息,该第二License的所有者信息为主节点的信息,将该第三交易单存储至主节点处于活跃状态的区块中。
当该第二License的内容包括的设备标识为第一设备的标识且包括的交易类型为升级时,将对第二License进行升级后得到的License作为第一License。
在另一个例子中,主节点可以接收用于指示第二License由第二设备迁移至第一设备的指令;当第二License的内容包括的设备标识为第二设备的标识且包括的交易类型为迁移时,将对第二License进行迁移后得到的License作为第一License。
S102、生成第一交易单。
该第一交易单包括第一License的内容及第一License的所有者信息,该第一交易单包括的第一License的所有者信息为主节点的信息。
其中,第一License的内容包括的设备标识为上述第一设备的标识。
S103、将第一交易单存储至主节点处于活跃状态的区块中。
在一个例子中,主节点生成第一交易单之后,可以在私有区块链上广播该第一交易单。
S104、确定第一设备所属的第一客户节点。
S105、生成第二交易单。
该第二交易单包括第一License的内容及第一License的所有者信息,该第二交易单包括的第一License的所有者信息为第一客户节点的信息。
S106、将第二交易单存储至处于主节点处于活跃状态的区块中。
S107、向第一客户节点发送第二交易单,以使得第一客户节点将第二交易单存储至第一客户节点处于活跃状态的区块中,并将第一License的内容下发给第一设备。
在一个例子中,主节点向第一客户节点发送第二交易单可以包括:在私有区块链上广播第二交易单,这样第一客户节点便可以接收到该第二交易单。
在一个例子中,主节点还可以获取第四交易单,该第四交易单包括第三License的内容及第三License的所有者信息,该第四交易单包括的第三License的所有者信息为第二客户节点的信息。当第三License的内容包括的交易类型为客户变更时,将该第四交易单存储至主节点处于活跃状态的区块中。
在一个例子中,上述各交易单中还包括:表示License交易顺序的顺序号和License所有者签名;
其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,第一私钥为:该交易单所指向的 上一交易单中记录的License所有者的私钥,第一公钥为:该交易单中记录的License所有者的公钥,第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
一个例子中,上述主节点可以理解为设备生产企业对应的节点,客户节点可以理解为购买该企业所生产设备的客户对应的节点。上述第一设备可以理解为企业生产的任意一台设备。
在上述私有区块链中主节点具有生成区块的权限,由于主节点生成区块后,会将所生成的区块同步至各个客户节点,因此,可以认为主节点和各个客户节点中的区块是一致的。随着主节点生成区块数量的增多,主节点和各个客户节点中可能会存在多个区块。
一个例子中,主节点按照预设规则生成区块时,可以是每间隔预设时长生成一个区块,可以是在固定的时间点生成一个区块等等。
在主节点生成的区块中,最新生成的区块可以称之为主节点处于活跃状态的区块。与此相对应,各个客户节点中处于活跃状态的区块可以理解为:由主节点最新同步至各个客户节点的区块。
上述各个区块用于存储交易单,一个例子中,参见图2,提供了一种区块的结构示意图,该图中以箭头示出了各个区块之间的链式关系,从左至右各个区块的已生成时间越来越短,这一链式关系由区块00、区块10、区块20和区块30共计4个区块形成,其中,区块00是第一个生成的区块,可以称为创世区块。
从图2中可以看出,每一区块中还可以存储有前块散列,如,区块10中的前块散列11、区块20中的前块散列21、区块30中的前块散列31。
一个区块中存储的前块散列用于表示这一区块的前一区块的序号,具体的,每一区块的序号可以是根据区块的生成时间等信息确定的,这样区块中存储有前块散列的情况下,根据每一区块中存储的前块散列可以清楚的了解到各个区块之间的顺序关系。
另外,由于创世区块为主节点生成的第一个区块,所以在其之前没有其他区块,因此,创世区块中可以不存储前块散列。
图2中TX表示License的交易单,各个区块所存储的交易单为: TX2000-TX2011。
上述各个区块中存储的每一交易单对应于一个License,一个交易单中至少存储有以下信息:
该交易单所对应License的内容;
该交易单所对应License的所有者信息。
一个例子中,上述License的内容可以包括:
设备类型、授权码、设备序列号、设备ID、授权方式、有效期、交易类型。
其中,上述设备ID可以是字符串形式的,也可以是文件形式的,本申请并不对此进行限定。
上述授权方式是指获得授权的方式,可以是在设备上安装激活文件获得授权,还可以是在设备上输入激活码或授权码获得授权。
上述有效期包括:永久有效、绝对有效期和相对有效期。
上述交易类型可以是时限延长、功能扩展、规模扩容、迁移、客户变更等等。
其中,上述交易类型为时限延长、功能扩展、规模扩容时,可以理解为需要对License进行升级,也就是交易类型为时限延长、功能扩展、规模扩容时,表征需要对License进行升级。上述交易类型为迁移时,可以理解为:License在设备间的迁移。上述交易类型为客户变更时,可以理解为:设备在不同客户之间的转让。
前述License的所有者信息可以为能够唯一表示License所有者的任一信息,例如,客户节点的地址、客户节点的标识、主节点的地址、主节点的标识等等。
在上述私有区块链中主节点能够为设备分配License。由于企业生产设备后会存在将设备出售给客户或者客户之间转让设备等等设备交易,而每一次设备交易均会引起License的内容变化,License的内容的每一次变化可以称之为一次License交易。
由以上可见,上述实施例提供的方案中,企业和客户形成私有区块链,也就是上述的主节点和客户节点形成的私有区块链,主节点也就是企业对应 的节点生成第一设备对应的第一License,并生成第一交易单,第一交易单中包含第一License的内容,另外,第一交易单所包含的License所有者信息为主节点的信息,在确定第一设备所属的第一客户节点后,生成第二交易单,第二交易单也包含第一License的内容,另外,第二交易单所包含的License所有者信息为第一客户节点的信息,主节点向第一客户节点发送第二交易单,这样第一客户节点获得第二交易单后,可以依据上述第二交易单将第一License的内容下发给第一设备。与现有技术中相比,上述实施例提供的License管理方案中,主节点借助与客户节点形成的私有区块链实现License的管理,从而无需人工记录License的流转情况,降低了设备生产企业对License进行管理的难度,另外,各个客户的设备从各自对应的客户节点即可获得License的内容,而无需每一设备从生产企业的网站获得License内容,从而更进一步降低了设备生产企业对License进行管理的难度。
下面结合图3所示的私有区块链,对本申请实施例提供的License管理方法再进行详细的介绍。
图3所示的私有区块链由设备生产企业对应的主节点301、购买了该企业所生产设备的A客户对应的客户节点302以及购买了该企业所生产设备的B客户对应的客户节点303构成。
随着时间的推移,主节点301所生成的区块如图3中主节点301上方所示,主节点在生成各个区块后会将所生成的区块同步到私有区块链的各个客户节点中,因此,客户节点302和客户节点303中区块的情况与主节点301中相同,图3中未示出。
另外,图3中主节点301上方示出的各个区块的情况与图2中示出的各个区块的情况相同,这里不再赘述。
需要说明的是,考虑到图3空间有限,以下描述中提及的TX3000-TX3011未在图3中示出。
下面对主节点301生成交易单(TX)、客户节点302以及客户节点303获得交易单的过程详细描述如下:
假设,主节点301当前共生成了4个区块,按照生成时间由长到短的顺 序依次为:区块00、区块10、区块20和区块30,也就是区块30为主节点301最新生成的区块,区块30为主节点301中处于活跃状态的区块。
企业生产出设备401后,主节点301为设备401分配临时License0,并生成TX3000。主节点301将TX3000存储于主节点301处于活跃状态的区块30中。该TX3000中包括:License0的内容和License0的所有者信息。其中,License0的内容中包括的设备标识为:设备401的标识。此时设备401还未出售,设备401还属于企业,相应的,License0的所有者也为主节点301,因此TX3000中包括的License0的所有者信息为:主节点301的信息。
A客户购买设备401后,为保证A客户能够正常使用设备401,使得设备401获得临时License,主节点301生成TX3001,并将TX3001存储在主节点301处于活跃状态的区块30中。该TX3001中包括:License0的内容和License0的所有者。其中,TX3001中包括的License0的所有者信息为:客户节点302的信息,License0的内容中包括的设备标识为:设备401的标识。
主节点生成TX3001后,在私有区块链上广播TX3001,客户节点302获得TX3001,并存储在客户节点302处于活跃状态的区块中。客户节点302在确定TX3001中的License0的所有者信息为自身信息且License0的内容中包括的设备标识为设备401的标识时,将License0的内容下发给设备401,设备401根据License0的内容下载License0,并安装License0,获得临时授权。
当A客户为设备401购买正式License后,主节点301为设备401分配正式License1,并生成TX3002。主节点301将TX3002存储于处于活跃状态的区块30中。该TX3002中包括:License1的内容和License1的所有者信息,其中,该TX3002包括的License1的所有者信息为:主节点301的信息,License1的内容中包括的设备标识为:设备401的标识。
由于A客户已为设备401购买正式License,为保证设备401获得正式License,主节点301生成TX3003,并将TX3003存储在主节点301处于活跃状态的区块30中。该TX3003中包括:License1的内容和License1的所有者信息。其中,该TX3003中包括的License1的所有者信息为:客户节点302的信息,License1的内容中包括的设备标识为:设备401的标识。
主节点生成TX3003后,在私有区块链上广播上述TX3003,客户节点302获得TX3003,将TX3003存储在客户节点302处于活跃状态的区块中。客户节点302在确定TX3003中的License1的所有者信息为自身信息且License1的内容中包括的设备标识为设备401的标识时,将TX3003中记录的License1的内容下发给设备401,设备401根据License1的内容下载License1,并安装License1,获得正式授权。
在工作过程中,A客户发现设备401的License1有效期临近,想延长License1的有效期,客户节点302生成TX3004,将TX3004存储在客户节点302处于活跃状态的区块中,并在私有区块链上广播TX3004。其中,TX3004包括:License1的内容和License1的所有者信息,其中,License1的内容中包括的设备标识为:设备401的标识,License1的内容中包括的交易类型为:延长有效期,License1的所有者信息为:主节点301的信息。
主节点301获得TX3004,将TX3004存储在主节点301处于活跃状态的区块30中。主节点301确定TX3004中包括的License1的所有者信息为自身且License1的内容中交易类型为延长有效期时,表征需要主节点301为License1进行升级,则主节点301按照TX3004中包括的License1的内容记录的与有效期相关的信息以及请求延长的期限,为设备401分配License2,生成TX3005。主节点301将TX3005存储于主节点301处于活跃状态的区块30中。TX3005中包括:License2的内容和License2的所有者信息,其中,License2的内容中包括的设备标识为:设备401的标识,License2的所有者信息为:主节点301的信息。
由于A客户已为设备401请求延长License的期限,为保证设备401获得期限延长后的License,主节点301生成TX3006,并将TX3006存储在主节点301处于活跃状态的区块30中,其中,TX3006中包括:License2的内容和License2的所有者信息,License2的内容中包括的设备标识为:设备401的标识,TX3006中包括的License2的所有者信息为:客户节点302的信息。
主节点301生成TX3006后,在私有区块链上广播TX3006,客户节点302获得TX3006后,将TX3006存储在客户节点302处于活跃状态的区块中,客 户节点302在确定TX3006中的License2的所有者信息为自身信息且License2的内容中包括的设备标识为设备401的标识时,将TX3006中记录的License2的内容下发给设备401,设备401根据License2的内容下载License2,并安装License2,获得升级后的授权。
随着工作的进行,A客户发现设备401不再适合当前的工作,需要由未获得授权的设备402代替设备401完成当前工作,其中,设备402也是上述企业所生产的设备,这种情况下,需要将上述License2从设备401迁移至设备402,这时设备401可以主动放弃License2并通知客户节点302要将License2迁移至设备402,为此,客户节点302向主节点301发送指示License2由设备401迁移至设备402的迁移指令,并生成TX3007,将TX3007存储在客户节点302处于活跃状态的区块中。该TX3007中包括:License2的内容和License2的所有者信息,其中,License2的内容中包括的设备标识为:设备401的标识,License2的内容中交易类型为:迁移,License2的所有者信息为:主节点301的信息。
客户节点302生成TX3007后,在私有区块链上广播TX3007,主节点301获得该TX3007后,将TX3007存储在主节点301处于活跃状态的区块30中,主节点301确定TX3007中License2的所有者信息为自身且License2的内容中交易类型为迁移,则主节点301根据TX3007中包括的License2的内容以及上述迁移指令,为设备402分配License3,生成TX3008,并将TX3008存储于主节点301处于活跃状态的区块30中,其中,TX3008中包括:License3的内容和License3的所有者信息,其中,License3的内容中包括的设备标识为:设备402的标识,License2的所有者信息为:主节点301的信息。
另外,假设,License的有效期以相对有效期的形式表示时,设备401已使用License2共计4个月,而License2的有效期为12个月,则License3的有效期为12个月-4个月=8个月,也就是上述TX3008中License3的内容中包括的有效期为:8个月。
由于A客户已请求将License2由设备401迁移至设备402,为保证设备402获得授权,主节点301生成TX3009,将TX3009存储在主节点301处于 活跃状态的区块30中,其中,TX3009中包括:License3的内容和License3的所有者信息,其中,License3的内容中包括的设备标识为:设备402的标识,License3的所有者信息为:客户节点302的信息。
主节点生成TX3009后,在私有区块链上广播TX3009,客户节点302获得该TX3009后,将TX3009存储在客户节点302处于活跃状态的区块中,客户节点302在确定TX3009中的License3的所有者信息为自身信息且License3的内容中包括的设备标识为设备402的标识时,将TX3009中记录的License3的内容下发至设备402,设备402根据License3的内容下载License3,并安装License3,获得升级后的授权。
在工作过程中,A客户发现其不再需要设备402,进而将设备402转让给B客户,A客户为了让B客户能够看到其所拥有设备402的授权情况,客户节点302生成TX3010,并将TX3010存储在客户节点302处于活跃状态的区块中。该TX3010中包括:License3的内容和License3的所有者信息,其中,License3的内容中包括的设备标识为:设备402的标识,TX3010中包括的License3的所有者信息为:客户节点303的信息。
客户节点302生成上述TX3010后,在私有区块链上广播TX3010,这样主节点301和客户节点303均可以接收到TX3010,客户节点303接收到TX3010后,将TX3010存储在客户节点303处于活跃状态的区块中,这样B客户可以依据TX3010中记录的信息了解到设备402的授权情况。主节点301接收到上TX3010后,将TX3010存储在主节点301处于活跃状态的区块30中,主节点301经检查发现TX3010中License3的内容中交易类型为客户变更,这样主节点301可以依据TX3010中记录的信息了解到A客户将设备402及License3转让给了B客户。
若设备402在运行过程中检测到License3已到期,则向客户节点303发送License3已到期的通知。客户节点303在收到该通知后,生成回收交易单,这里称之为TX3011。该TX3011中包括:License3的内容、License3的所有者信息,其中,License3的所有者信息为:主节301的信息,License3的内容 中包括的设备标识为:设备402的标识,License3的内容中包括的交易类型为:回收。
客户节点303在私有区块链上广播TX3011。主节点301接收到TX3011后,将TX3011存储在主节点301处于活跃状态的区块30中。这样,主节点301可以根据TX3011中包括的内容获知设备402上的License3已到期。
一种实现方式中,为了保证设备能够准确的根据交易单中的License内容进行License下载,一个交易单还可以用于存储表示License交易顺序的顺序号和License所有者签名。
其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,其中,第一私钥为:该交易单所指向的上一交易单中记录的License的所有者的私钥,第一公钥为:该交易单中记录的License的所有者的公钥,第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
上述表示License交易顺序的顺序号也可以称之为散列值,这样的话,可以认为一个交易单存储一个散列值。
一个交易单所指向的上一交易单可以理解为:与这一交易单具有直接关联关系的前一交易单,例如,TX3001可以是通过将TX3000中License0的所有者信息由主节点301的信息修改为客户节点302的信息得到,则认为TX3000与TX3001之间具有直接关联关系,而TX3001是在TX3000的基础上通过修改信息生成的,所以可以认为TX3001所指向的上一交易单为TX3000。
另外,两个交易单之间的指向关系可以通过单向链表或者双向链表的形式实现,本申请仅仅以此为例进行说明,并不对两个交易单之间的指向关系的实现形式进行限定。
一个交易单中存储了上述信息后,当设备根据该交易单中包含的License的内容下载License时,可以先以第二公钥为解密秘钥对该交易单中记录的设备所有者签名进行解密,得到解密结果后,检查解密结果是否为上述第一公钥和第一顺序号,若是,则说明交易单的内容没有被篡改,可以安全的进行 License下载,若不是,则说明交易单的内容可能被篡改了,可以拒绝进行License下载。其中,上述第二公钥为:该交易单所指向的上一交易单中记录的License的所有者的公钥。
下面结合图4所示的实例以及前述图3所示实例部分提及的TX3002-TX3011对上述License的交易单进行详细说明。
图4中包含10个交易单,TX3002-TX3011,其中,TX3002也称之为生产交易单,这10个交易单的散列值分别记为:散列值4001-散列值4010。其中,
TX3002,也就是生产交易单为:主节点301为设备401分配正式License1后生成的包含该正式License1的内容的交易单,由于该交易单可以认为是主节点301为设备401生成的第一个正式License的交易单,主节点301是这一正式License的第一个所有者,所以该交易单可以不存在License所有者签名。
基于图3所示实施例部分的描述,TX3002-TX3011中License所有者签名如下表1所示:
其中,表1中,“部分内容”是指:当前交易单中License的部分内容;
“上一交易单”是指:当前交易单所指向的上一交易单;
“上一所有者”是指:上一交易单中License所有者;
“当前所有者”是指:当前交易单中的Licnese所有者;
“上一顺序号”是指:上一交易单中的顺序号;
“当前顺序号”是指:当前交易单中的顺序号;
上述当前交易单是指:表1第一列中所指示的交易单。
表1
Figure PCTCN2018117232-appb-000001
Figure PCTCN2018117232-appb-000002
Figure PCTCN2018117232-appb-000003
当设备根据TX3003中的License的内容下载License时,以主节点301的公钥对License所有者签名进行解密验证设备所有者签名;
当设备根据TX3004中的License的内容下载License时,以客户节点302的公钥对License所有者签名进行解密验证设备所有者签名;
设备根据TX3005-TX3011中的License的内容下载License时,情况与上述描述相似,区别仅在于所使用的解密公钥不同,这里不再一一赘述。
从表1可以看出,在License交易过程中,生成一个交易单时,不仅确定了这一交易单所指向的前一交易单,还确定了这一交易单所包括的License的内容,因此,可以根据License交易过程中生成的各个交易单之间的指向关系以及交易单中包括的License的内容,获知Licence的走向。另外,上述交易单之间的指向关系以及License的内容均是在生成交易单过程中确定的,因此也无需人工记录License的交易情况,更不需要人工进行数据分析获知License的走向。
与上述License管理方法相对应,本申请实施例还提供了一种License管理装置。
图5为本申请实施例提供的一种License管理装置的结构示意图,应用于私有区块链中的主节点,所述私有区块链还包括:客户节点;所述装置包括:
区块同步模块500,用于按照预设规则生成区块,并将生成的区块同步至各个客户节点;
License生成模块501,用于生成第一设备对应的第一License;
第一交易单生成模块502,用于生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
第一交易单存储模块503,用于将所述第一交易单存储至所述主节点处于活跃状态的区块中;
节点确定模块504,用于确定所述第一设备所属的第一客户节点;
第二交易单生成模块505,用于生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包 括的所述第一License的所有者信息为所述第一客户节点的信息;
第二交易单存储模块506,用于将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
交易单发送模块507,用于向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
在一个例子中,上述License管理装置还可以包括:
广播模块,用于在所述私有区块链上广播所述第一交易单;
所述发送模块,具体用于在所述私有区块链上广播所述第二交易单。
在一个例子中,所述License生成模块501,包括:
交易单获取单元,用于获取第三交易单,所述第三交易单包括第二License的内容及所述第二License的所有者信息,所述第三交易单包括的所述第二License的所有者信息为所述主节点的信息;
交易单存储单元,用于将所述第三交易单存储至所述主节点处于活跃状态的区块中;
第一License确定单元,用于当所述第二License的内容包括的设备标识为所述第一设备的标识且包括的交易类型表征升级时,将对所述第二License进行升级后得到的License作为第一License。
在一个例子中,所述License生成模块501,还包括:
接收单元,用于接收用于指示所述第二License由第二设备迁移至所述第一设备的指令;
第二License确定单元,用于当所述第二License的内容包括的设备标识为所述第二设备的标识且包括的交易类型为迁移时,将对所述第二License进行迁移后得到的License作为第一License。
在一个例子中,上述License管理装置还包括:
交易单获取模块,用于获取第四交易单,所述第四交易单包括第三License的内容及所述第三License的所有者信息,所述第四交易单包括的所述第三License的所有者信息为第二客户节点的信息;
第三交易单存储模块,用于当所述第三License的内容包括的交易类型为 客户变更时,将所述第四交易单存储至所述主节点处于活跃状态的区块中。
在一个例子中,一个交易单还用于存储表示License交易顺序的顺序号和License所有者签名;
其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,其中,所述第一私钥为:该交易单所指向的上一交易单中记录的License的所有者的私钥,所述第一公钥为:该交易单中记录的License的所有者的公钥,所述第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
由以上可见,上述各个实施例提供的方案中,企业和客户形成私有区块链,也就是上述的主节点和客户节点形成的私有区块链,主节点也就是企业对应的节点生成第一设备对应的第一License,并生成第一交易单,第一交易单中包含第一License的内容,另外,第一交易单所包含的License所有者信息为主节点的信息,在确定第一设备所属的第一客户节点后,生成第二交易单,第二交易单也包含第一License的内容,另外,第二交易单所包含的License所有者信息为第一客户节点的信息,主节点向第一客户节点发送第二交易单,这样第一客户节点获得第二交易单后,可以依据上述第二交易单将第一License的内容下发给第一设备。与现有技术中相比,上述各个实施例提供的License管理方案中,主节点借助与客户节点形成的私有区块链实现License的管理,从而无需人工记录License的流转情况,降低了设备生产企业对License进行管理的难度,另外,各个客户的设备从各自对应的客户节点即可获得License的内容,而无需每一设备从生产企业的网站获得License内容,从而更进一步降低了设备生产企业对License进行管理的难度。
与上述License管理方法和License管理装置相对应,本申请实施例还提供了一种电子设备。
图6为本申请实施例提供的一种电子设备的结构示意图,该电子设备为私有区块链中的主节点,所述私有区块链还包括:客户节点;所述电子设备包括:处理器61、机器可读存储介质62和系统总线63,所述处理器61和机器可读存储介质62通过所述系统总线63完成相互间的通信,所述机器可读 存储介质存储62有能够被所述处理器61执行的机器可执行指令,所述机器可执行指令包括:同步指令621、生成指令622、存储指令623、确定指令624和发送指令625;
所述处理器被所述同步指令621促使实现步骤:按照预设规则生成区块,并将生成的区块同步至各个客户节点;
所述处理器被所述生成指令622促使实现步骤:生成第一设备对应的第一License;
所述处理器被所述生成指令622促使实现步骤:生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
所述处理器被所述存储指令623促使实现步骤:将所述第一交易单存储至所述主节点处于活跃状态的区块中;
所述处理器被所述确定指令624促使实现步骤:确定所述第一设备所属的第一客户节点;
所述处理器被所述生成指令622促使实现步骤:生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包括的所述第一License的所有者信息为所述第一客户节点的信息;
所述处理器被所述存储指令623促使实现步骤:将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
所述处理器被所述发送指令625促使实现步骤:向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
一个例子中,所述机器可执行指令还包括:广播指令;
所述处理器61被所述广播指令促使实现步骤:在所述私有区块链上广播所述第一交易单;
所述处理器61被所述发送指令625促使具体实现步骤:在所述私有区块 链上广播所述第二交易单。
一个例子中,所述处理器61被所述生成指令622促使具体实现步骤:获取第三交易单,所述第三交易单包括第二License的内容及所述第二License的所有者信息,所述第三交易单包括的所述第二License的所有者信息为所述主节点的信息;将所述第三交易单存储至所述主节点处于活跃状态的区块中;当所述第二License的内容包括的设备标识为所述第一设备的标识且包括的交易类型表征升级时,将对所述第二License进行升级后得到的License作为第一License。
一个例子中,所述处理器61被所述生成指令622促使还实现步骤:接收用于指示所述第二License由第二设备迁移至所述第一设备的指令;当所述第二License的内容包括的设备标识为所述第二设备的标识且包括的交易类型为迁移时,将对所述第二License进行迁移后得到的License作为第一License。
一个例子中,所述机器可执行指令还包括:获取指令;
所述处理器61被所述获取指令促使实现步骤:获取第四交易单,所述第四交易单包括第三License的内容及所述第三License的所有者信息,所述第四交易单包括的所述第三License的所有者信息为第二客户节点的信息;
所述处理器61被所述存储指令623促使还实现步骤:当所述第三License的内容包括的交易类型为客户变更时,将所述第四交易单存储至所述主节点处于活跃状态的区块中。
一个例子中,一个交易单还用于存储表示License交易顺序的顺序号和License所有者签名;
其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,其中,所述第一私钥为:该交易单所指向的上一交易单中记录的License的所有者的私钥,所述第一公钥为:该交易单中记录的License的所有者的公钥,所述第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
由以上可见,上述实施例提供的方案中,企业和客户形成私有区块链,也就是上述的主节点和客户节点形成的私有区块链,主节点也就是企业对应的节点生成第一设备对应的第一License,并生成第一交易单,第一交易单中 包含第一License的内容,另外,第一交易单所包含的License所有者信息为主节点的信息,在确定第一设备所属的第一客户节点后,生成第二交易单,第二交易单也包含第一License的内容,另外,第二交易单所包含的License所有者信息为第一客户节点的信息,主节点向第一客户节点发送第二交易单,这样第一客户节点获得第二交易单后,可以依据上述第二交易单将第一License的内容下发给第一设备。与现有技术中相比,上述实施例提供的License管理方案中,主节点借助与客户节点形成的私有区块链实现License的管理,从而无需人工记录License的流转情况,降低了设备生产企业对License进行管理的难度,另外,各个客户的设备从各自对应的客户节点即可获得License的内容,而无需每一设备从生产企业的网站获得License内容,从而更进一步降低了设备生产企业对License进行管理的难度。
与上述设备授权方法和设备授权装置相对应,本申请实施例还提供了一种机器可读存储介质,所述机器可读存储介质为私有区块链中的主节点的存储介质,所述私有区块链还包括:客户节点;
所述机器可读存储介质存储有机器可执行指令,所述机器可执行指令包括:同步指令、生成指令、存储指令、确定指令和发送指令;
所述分配指令在被处理器调用和执行时,所述分配指令促使所述处理器实现步骤:按照预设规则生成区块,并将生成的区块同步至各个客户节点;
所述生成指令在被处理器调用和执行时,所述分配指令促使所述处理器实现步骤:生成第一设备对应的第一License;
所述生成指令在被处理器调用和执行时,所述生成指令促使所述处理器实现步骤:生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
所述存储指令在被处理器调用和执行时,所述存储指令促使所述处理器实现步骤:将所述第一交易单存储至所述主节点处于活跃状态的区块中;
所述确定指令在被处理器调用和执行时,所述确定指令促使所述处理器实现步骤:确定所述第一设备所属的第一客户节点;
所述生成指令在被处理器调用和执行时,所述生成指令促使所述处理器实现步骤:生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包括的所述第一License的所有者信息为所述第一客户节点的信息;
所述存储指令在被处理器调用和执行时,所述存储指令促使所述处理器实现步骤:将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
所述发送指令在被处理器调用和执行时,所述发送指令促使所述处理器实现步骤:向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
需要说明的是,机器可读存储介质的其他实施例中,机器可执行指令包括的各个执行执行的步骤,与前述电子设备实施例中相同,这里不再赘述。
由以上可见,上述实施例提供的方案中,企业和客户形成私有区块链,也就是上述的主节点和客户节点形成的私有区块链,主节点也就是企业对应的节点生成第一设备对应的第一License,并生成第一交易单,第一交易单中包含第一License的内容,另外,第一交易单所包含的License所有者信息为主节点的信息,在确定第一设备所属的第一客户节点后,生成第二交易单,第二交易单也包含第一License的内容,另外,第二交易单所包含的License所有者信息为第一客户节点的信息,主节点向第一客户节点发送第二交易单,这样第一客户节点获得第二交易单后,可以依据上述第二交易单将第一License的内容下发给第一设备。与现有技术中相比,上述实施例提供的License管理方案中,主节点借助与客户节点形成的私有区块链实现License的管理,从而无需人工记录License的流转情况,降低了设备生产企业对License进行管理的难度,另外,各个客户的设备从各自对应的客户节点即可获得License的内容,而无需每一设备从生产企业的网站获得License内容,从而更进一步降低了设备生产企业对License进行管理的难度。
需要说明的是,在本文中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、 “包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。
本说明书中的各个实施例均采用相关的方式描述,各个实施例之间相同相似的部分互相参见即可,每个实施例重点说明的都是与其他实施例的不同之处。尤其,对于装置、电子设备、机器可读存储介质实施例而言,由于其基本相似于方法实施,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
以上所述仅为本申请的较佳实施例而已,并非用于限定本申请的保护范围。凡在本申请的精神和原则之内所作的任何修改、等同替换、改进等,均包含在本申请的保护范围内。

Claims (13)

  1. 一种授权许可License管理方法,应用于私有区块链中的主节点,所述私有区块链还包括:客户节点;所述方法包括:
    按照预设规则生成区块,并将生成的区块同步至各个客户节点;
    生成第一设备对应的第一License;
    生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
    将所述第一交易单存储至所述主节点处于活跃状态的区块中;
    确定所述第一设备所属的第一客户节点;
    生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包括的所述第一License的所有者信息为所述第一客户节点的信息;
    将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
    向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
  2. 根据权利要求1所述的方法,所述方法还包括:
    在所述私有区块链上广播所述第一交易单;
    所述向所述第一客户节点发送所述第二交易单,包括:
    在所述私有区块链上广播所述第二交易单。
  3. 根据权利要求1或2所述的方法,所述生成所述第一设备对应的第一License,包括:
    获取第三交易单,所述第三交易单包括第二License的内容及所述第二License的所有者信息,所述第三交易单包括的所述第二License的所有者信息为所述主节点的信息;
    将所述第三交易单存储至所述主节点处于活跃状态的区块中;
    当所述第二License的内容包括的设备标识为所述第一设备的标识且包括 的交易类型表征升级时,将对所述第二License进行升级后得到的License作为第一License。
  4. 根据权利要求3所述的方法,所述方法还包括:
    接收用于指示所述第二License由第二设备迁移至所述第一设备的指令;
    当所述第二License的内容包括的设备标识为所述第二设备的标识且包括的交易类型为迁移时,将对所述第二License进行迁移后得到的License作为第一License。
  5. 根据权利要求1或2所述的方法,所述方法还包括:
    获取第四交易单,所述第四交易单包括第三License的内容及所述第三License的所有者信息,所述第四交易单包括的所述第三License的所有者信息为第二客户节点的信息;
    当所述第三License的内容包括的交易类型为客户变更时,将所述第四交易单存储至所述主节点处于活跃状态的区块中。
  6. 根据权利要求1或2所述的方法,一个交易单还用于存储表示License交易顺序的顺序号和License所有者签名;
    其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,其中,所述第一私钥为:该交易单所指向的上一交易单中记录的License的所有者的私钥,所述第一公钥为:该交易单中记录的License的所有者的公钥,所述第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
  7. 一种电子设备,所述电子设备为私有区块链中的主节点,所述私有区块链还包括:客户节点;所述电子设备包括:处理器、机器可读存储介质和系统总线,所述处理器和机器可读存储介质通过所述系统总线完成相互间的通信,所述机器可读存储介质存储有能够被所述处理器执行的机器可执行指令,所述机器可执行指令包括:同步指令、生成指令、存储指令、确定指令和发送指令;
    所述处理器被所述同步指令促使实现步骤:按照预设规则生成区块,并将生成的区块同步至各个客户节点;
    所述处理器被所述生成指令促使实现步骤:生成第一设备对应的第一 License;
    所述处理器被所述生成指令促使实现步骤:生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
    所述处理器被所述存储指令促使实现步骤:将所述第一交易单存储至所述主节点处于活跃状态的区块中;
    所述处理器被所述确定指令促使实现步骤:确定所述第一设备所属的第一客户节点;
    所述处理器被所述生成指令促使实现步骤:生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包括的所述第一License的所有者信息为所述第一客户节点的信息;
    所述处理器被所述存储指令促使实现步骤:将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
    所述处理器被所述发送指令促使实现步骤:向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
  8. 根据权利要求7所述的电子设备,所述机器可执行指令还包括:广播指令;
    所述处理器被所述广播指令促使实现步骤:在所述私有区块链上广播所述第一交易单;
    所述处理器被所述发送指令促使具体实现步骤:在所述私有区块链上广播所述第二交易单。
  9. 根据权利要求7或8所述的电子设备,所述处理器被所述生成指令促使具体实现步骤:
    获取第三交易单,所述第三交易单包括第二License的内容及所述第二License的所有者信息,所述第三交易单包括的所述第二License的所有者信息为所述主节点的信息;
    将所述第三交易单存储至所述主节点处于活跃状态的区块中;
    当所述第二License的内容包括的设备标识为所述第一设备的标识且包括的交易类型表征升级时,将对所述第二License进行升级后得到的License作为第一License。
  10. 根据权利要求9所述的电子设备,所述处理器被所述生成指令促使还实现步骤:
    接收用于指示所述第二License由第二设备迁移至所述第一设备的指令;
    当所述第二License的内容包括的设备标识为所述第二设备的标识且包括的交易类型为迁移时,将对所述第二License进行迁移后得到的License作为第一License。
  11. 根据权利要求7或8所述的电子设备,所述机器可执行指令还包括:获取指令;
    所述处理器被所述获取指令促使实现步骤:获取第四交易单,所述第四交易单包括第三License的内容及所述第三License的所有者信息,所述第四交易单包括的所述第三License的所有者信息为第二客户节点的信息;
    所述处理器被所述存储指令促使还实现步骤:当所述第三License的内容包括的交易类型为客户变更时,将所述第四交易单存储至所述主节点处于活跃状态的区块中。
  12. 根据权利要求7或8所述的电子设备,一个交易单还用于存储表示License交易顺序的顺序号和License所有者签名;
    其中,一个交易单存储的License所有者签名为:以第一私钥为加密秘钥,对第一公钥和第一顺序号加密得到的信息,其中,所述第一私钥为:该交易单所指向的上一交易单中记录的License的所有者的私钥,所述第一公钥为:该交易单中记录的License的所有者的公钥,所述第一顺序号为:该交易单所指向的上一交易单所存储的顺序号。
  13. 一种机器可读存储介质,所述机器可读存储介质为私有区块链中的主节点的存储介质,所述私有区块链还包括:客户节点;
    所述机器可读存储介质存储有机器可执行指令,所述机器可执行指令包括:同步指令、生成指令、存储指令、确定指令和发送指令;
    所述分配指令在被处理器调用和执行时,所述分配指令促使所述处理器实现步骤:按照预设规则生成区块,并将生成的区块同步至各个客户节点;
    所述生成指令在被处理器调用和执行时,所述分配指令促使所述处理器实现步骤:生成第一设备对应的第一License;
    所述生成指令在被处理器调用和执行时,所述生成指令促使所述处理器实现步骤:生成第一交易单,所述第一交易单包括所述第一License的内容及所述第一License的所有者信息,所述第一交易单包括的所述第一License的所有者信息为所述主节点的信息;所述第一License的内容包括的设备标识为所述第一设备的标识;
    所述存储指令在被处理器调用和执行时,所述存储指令促使所述处理器实现步骤:将所述第一交易单存储至所述主节点处于活跃状态的区块中;
    所述确定指令在被处理器调用和执行时,所述确定指令促使所述处理器实现步骤:确定所述第一设备所属的第一客户节点;
    所述生成指令在被处理器调用和执行时,所述生成指令促使所述处理器实现步骤:生成第二交易单,所述第二交易单包括所述第一License的内容及所述第一License的所有者信息,所述第二交易单包括的所述第一License的所有者信息为所述第一客户节点的信息;
    所述存储指令在被处理器调用和执行时,所述存储指令促使所述处理器实现步骤:将所述第二交易单存储至处于所述主节点处于活跃状态的区块中;
    所述发送指令在被处理器调用和执行时,所述发送指令促使所述处理器实现步骤:向所述第一客户节点发送所述第二交易单,以使得所述第一客户节点将所述第二交易单存储至所述第一客户节点处于活跃状态的区块中,并将所述第一License的内容下发给所述第一设备。
PCT/CN2018/117232 2017-11-27 2018-11-23 License管理 Ceased WO2019101170A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201711202672.0 2017-11-27
CN201711202672.0A CN109146392B (zh) 2017-11-27 2017-11-27 一种授权许可License管理方法及装置

Publications (1)

Publication Number Publication Date
WO2019101170A1 true WO2019101170A1 (zh) 2019-05-31

Family

ID=64803794

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2018/117232 Ceased WO2019101170A1 (zh) 2017-11-27 2018-11-23 License管理

Country Status (2)

Country Link
CN (1) CN109146392B (zh)
WO (1) WO2019101170A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB201913990D0 (en) * 2019-09-27 2019-11-13 Nchain Holdings Ltd Time-locked blockchain transactions and related blockchain technology
CN111641695B (zh) * 2020-05-19 2022-10-28 全链通有限公司 基于区块链的应用程序授权使用方法、设备及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160275461A1 (en) * 2015-03-20 2016-09-22 Rivetz Corp. Automated attestation of device integrity using the block chain
CN106301794A (zh) * 2016-10-17 2017-01-04 特斯联(北京)科技有限公司 使用区块链进行授权认证的方法及系统
CN107018432A (zh) * 2017-03-28 2017-08-04 华为技术有限公司 媒体内容的许可方法以及设备
CN107079036A (zh) * 2016-12-23 2017-08-18 深圳前海达闼云端智能科技有限公司 注册及授权方法、装置及系统
CN107145605A (zh) * 2017-06-07 2017-09-08 北京天德科技有限公司 一种基于区块链统一接口(obcc)的许可链应用系统

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10129032B2 (en) * 2016-02-16 2018-11-13 Xerox Corporation Secure revisioning auditing system for electronic document files
CN106453435B (zh) * 2016-12-21 2020-04-03 中国人民解放军31401部队150分队 一种基于区块链的数据共享授权方法

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160275461A1 (en) * 2015-03-20 2016-09-22 Rivetz Corp. Automated attestation of device integrity using the block chain
CN106301794A (zh) * 2016-10-17 2017-01-04 特斯联(北京)科技有限公司 使用区块链进行授权认证的方法及系统
CN107079036A (zh) * 2016-12-23 2017-08-18 深圳前海达闼云端智能科技有限公司 注册及授权方法、装置及系统
CN107018432A (zh) * 2017-03-28 2017-08-04 华为技术有限公司 媒体内容的许可方法以及设备
CN107145605A (zh) * 2017-06-07 2017-09-08 北京天德科技有限公司 一种基于区块链统一接口(obcc)的许可链应用系统

Also Published As

Publication number Publication date
CN109146392B (zh) 2021-02-12
CN109146392A (zh) 2019-01-04

Similar Documents

Publication Publication Date Title
US10439804B2 (en) Data encrypting system with encryption service module and supporting infrastructure for transparently providing encryption services to encryption service consumer processes across encryption service state changes
JP4976492B2 (ja) ライセンスをバックアップおよび復元するための方法とシステム
JP4856169B2 (ja) ユーザ及びデバイス基盤のドメインシステムを示すドメインコンテキスト及びその管理方法
US20190207813A1 (en) Device provisioning system
CN113326533B (zh) 基于区块链及分布式文件存储的电子证照服务系统及方法
JP2018528691A (ja) マルチユーザクラスタアイデンティティ認証のための方法および装置
CN114282193B (zh) 一种应用授权方法、装置、设备及存储介质
CN105225072A (zh) 一种多应用系统的访问管理方法及系统
CN105099697A (zh) 可重用的许可证激活密钥
CN112596740A (zh) 一种程序部署方法及装置
US20140157368A1 (en) Software authentication
WO2010003328A1 (zh) 许可的处理方法及装置
WO2009093572A1 (ja) ライセンス認証システム及び認証方法
CN110276170A (zh) 基于区块链进行作品保护的方法、设备和介质
CN110324283B (zh) 基于非对称加密的许可方法、装置及系统
US20200349291A1 (en) Data bundle generation and deployment
WO2016165215A1 (zh) 应用程序加载代码签名的方法和装置
CN113642239A (zh) 一种联邦学习建模方法及系统
WO2019101170A1 (zh) License管理
CN100492386C (zh) 复制受保护数据的方法与系统
CN114372242A (zh) 密文数据的处理方法、权限管理服务器和解密服务器
JP2009251977A (ja) ソフトウェアインストールシステム
JP2020092289A (ja) 機器統合システム及び更新管理システム
CN115396209B (zh) 访问授权方法、装置、电子设备及可读存储介质
CN111737747A (zh) 数据库保密方法、装置、设备及计算机存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18880878

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18880878

Country of ref document: EP

Kind code of ref document: A1