How to generate and validate a software license key?

Caveat: you can’t prevent users from pirating, but only make it easier for honest users to do the right thing.

Assuming you don’t want to do a special build for each user, then:

  • Generate yourself a secret key for the product
  • Take the user’s name
  • Concatentate the users name and the secret key and hash with (for example) SHA1
  • Unpack the SHA1 hash as an alphanumeric string. This is the individual user’s “Product Key”
  • Within the program, do the same hash, and compare with the product key. If equal, OK.

But, I repeat: this won’t prevent piracy


I have recently read that this approach is not cryptographically very sound. But this solution is already weak (as the software itself has to include the secret key somewhere), so I don’t think this discovery invalidates the solution as far as it goes.

Just thought I really ought to mention this, though; if you’re planning to derive something else from this, beware.

Leave a Comment