Work implementation method and apparatus for online OTP device
Patent Information
- Application Number
- CA3316666
- Authority / Receiving Office
- CA · CA
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-04-01
- Publication Date
- 2026-08-05
Abstract
Description
A WORK IMPLEMENTATION METHOD AND APPARATUS FOR AN ONLINE OTP DEVICE Technical Field
[0001] The present disclosure relates to the field of information security and particularly relates to a work implementation method and apparatus for an online OTP device. Background
[0002] An online OTP device is an electronic device provided with keys and needing to be connected to a host computer for work. In the existing technology, the online OTP device does not require any access permission, and any person can perform operations such as configuration and modification on the online OTP device, when the online OTP device is obtained by an unauthorized user, the unauthorized user can perform operations such as configuration and modification on the online OTP device, thus use the online OTP device to perform some illegal operations and exist significant security risks, therefore, a safe and reliable work implementation method for an online OTP device is urgently required. Invention Content
[0003] An objective of the present disclosure is to overcome deficiencies of the existing technology and provide a work implementation method and apparatus for an online OTP device.
[0004] In a first aspect, embodiments of the present disclosure provide a work implementation method for an online OTP device, the online OTP device being internally provided with a default storage area and a normal storage area, the default storage area storing a plurality of pieces of personalized data, the normal storage area storing one piece of personalized data, the method comprising: step S1, when an instruction sent by a host computer is received, determining a type of the instruction, when the instruction is an application selection instruction, executing step S2, when the instruction is a protection-code setting instruction, executing step S3, when the instruction is a personalized-data write instruction, executing step S5, and when the instruction is a personalized-data processing instruction, executing step S9; step S2, the online OTP device selects a corresponding OTP application according to an application identifier in the application selection instruction, acquires configured storage-area configuration, generates an application selection response according to the storage-area configuration and preset device data participating in calculation, and returns the application selection response to the host computer, the storage-area configuration comprising a storage- area identifier and a storage-area status code, and then returns to step S1; step S3, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S4 is executed, otherwise, an error is reported, and the process returns to step S1; step S4, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, an error is reported, and the process returns to step S1, otherwise, a protection code in the protection- code setting instruction is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, a successful setting response is returned to the host computer, and the process returns to step S1; step S5, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S6 is executed, otherwise, an error is reported, and the process returns to step S1; step S6, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step S7 is executed, otherwise, an error is reported, and the process returns to step S1; step S7, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, calculates fourth comparison data according to a fourth random number in the personalized-data write instruction and the protection code, determines whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, when the fourth comparison data is identical to the fourth intermediate data, step S8 is executed, otherwise, an error is reported, and the process returns to step S1; step S8, the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, personalized data in the personalized-data write instruction is stored in the default storage area, a successful write response is returned to the host computer, and the process returns to step S1, otherwise, personalized data stored in the storage area corresponding to the storage-area identifier is updated by using the personalized data in the personalized-data write instruction, a successful write response is returned to the host computer, and the process returns to step S1; step S9, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S10 is executed, otherwise, an error is reported, and the process returns to step S1; step S10, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step S11 is executed, otherwise, an error is reported, and the process returns to step S1; step S11, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data processing instruction, calculates first comparison data according to a first random number in the personalized-data processing instruction and the protection code, determines whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, when the first intermediate data is identical to the first comparison data, step S12 is executed, otherwise, an error is reported, and the process returns to step S1; and step S12, the online OTP device performs corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized- data processing instruction, returns a processing result to the host computer, and returns to step S1.
[0005] In a second aspect, embodiments of the present disclosure provide a work implementation apparatus for an online OTP device, the online OTP device being internally provided with a default storage area and a normal storage area, the default storage area storing a plurality of pieces of personalized data, the normal storage area storing one piece of personalized data, the apparatus comprising: a receiving-and-determining module, configured to receive an instruction issued by the host computer, determine a type of the instruction when the instruction is received, trigger a selection-calculating-and-returning module when the instruction is an application selection instruction, trigger a first determining module when the instruction is a protection-code setting instruction, trigger a second determining module when the instruction is a personalized-data write instruction, and trigger a fourth determining module when the instruction is a personalized-data processing instruction; the selection-calculating-and-returning module, configured to select a corresponding OTP application according to an application identifier in the application selection instruction, acquire configured storage-area configuration, generate an application selection response according to the storage-area configuration and preset device data participating in calculation, and return the application selection response to the host computer, the storage-area configuration comprising a storage-area identifier and a storage-area status code, and trigger the receiving-and- determining module; the first determining module, configured to determine whether an OTP application has been selected, trigger a determining-setting-and-returning module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the determining-setting-and-returning module, configured to determine whether the OTP application has been set with an access permission, report an error and trigger the receiving- and-determining module when the OTP application has been set with the access permission, and otherwise store a protection code in the protection-code setting instruction in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, return a successful setting response to the host computer, and trigger the receiving-and-determining module; the second determining module, configured to determine whether an OTP application has been selected, trigger a third determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the third determining module, configured to determine whether the OTP application has been set with an access permission, trigger a first acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module; the first acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, calculate fourth comparison data according to a fourth random number in the personalized-data write instruction and the protection code, determine whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, trigger a determining-and-writing module when the fourth comparison data is identical to the fourth intermediate data, and otherwise report an error and trigger the receiving- and-determining module; the determining-and-writing module, configured to determine, according to the storage-area identifier, whether a corresponding storage area is a default storage area, store personalized data in the personalized-data write instruction in the default storage area when the corresponding storage area is the default storage area, return a successful write response to the host computer, and return to step S1, and otherwise update personalized data stored in the storage area corresponding to the storage-area identifier by using the personalized data in the personalized-data write instruction, return the successful write response to the host computer, and trigger the receiving-and-determining module; the fourth determining module, configured to determine whether an OTP application has been selected, trigger a fifth determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the fifth determining module, configured to determine whether the OTP application has been set with an access permission, trigger a second acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module; the second acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized- data processing instruction, calculate first comparison data according to a first random number in the personalized-data processing instruction and the protection code, determine whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, trigger a processing-and-returning module when first intermediate data in the personalized-data processing instruction is identical to the first comparison data, and otherwise report an error and trigger the receiving-and-determining module; the processing-and-returning module, configured to perform corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, return a processing result to the host computer, and trigger the receiving-and-determining module.
[0006] In a third aspect, embodiments of the present disclosure provide an electronic device, comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, the at least one processor being configured to execute the instructions to implement the work implementation method for an online OTP device.
[0007] In a fourth aspect, embodiments of the present disclosure provide a computer-readable storage medium, wherein the computer-readable storage medium comprises a computer program, and when the computer program runs on an electronic device, the electronic device is caused to execute the work implementation method for an online OTP device.
[0008] In a fifth aspect, embodiments of the present disclosure provide a chip system, comprising a chip and a memory, the memory storing a computer program, the chip being configured to execute a computer program stored in the memory to execute the work implementation method for an online OTP device.
[0009] Compared with the existing technology, the present disclosure has the following advantages: in the technical solution of the present disclosure, the online OTP device is internally provided with a default storage area and a normal storage area, each storage area is provided with a respective protection code, the default storage area can store a plurality of pieces of personalized data, the normal storage area stores one piece of personalized data, and the storage areas are mutually independent and do not affect one another, thereby facilitating management and use; when a user uses the online OTP device, identity verification is first performed by using the protection code, thereby effectively ensuring that data (including personalized data and the protection code) in the storage areas is not maliciously modified, and ensuring safety of user information and property in situations such as loss of the online OTP device. Drawing Description
[0010] Figure 1 is a flow chart of a work implementation method for an online OTP device provided in Embodiment 1 of the present disclosure;
[0011] Figure 2 and Figure 3 are flow charts of a work implementation method for an online OTP device provided in Embodiment 2 of the present disclosure;
[0012] Figure 4 and Figure 5 are flow charts of a work implementation method for an online OTP device provided in Embodiment 3 of the present disclosure. Specific Embodiment Methods
[0013] The present application provides a work implementation method and apparatus for an online OTP device. Specific embodiments of the present application are described in detail below with reference to the accompanying drawings. Examples of the embodiments are shown in the accompanying drawings. The embodiments described below with reference to the accompanying drawings are exemplary and are only used for explaining the present application and cannot be construed as limiting the present application.
[0014] A person skilled in the art can understand that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as meaning generally understood by a person of ordinary skill in the art to which the present application pertains. It should also be understood that terms, such as terms defined in a general dictionary, should be understood as having a meaning consistent with meaning in the context of the existing technology, and, unless specifically defined as herein, should not be interpreted in an idealized or overly formal sense.
[0015] For clearer understanding of the objectives, technical solutions, and advantages of the present disclosure, the embodiments of the present disclosure are further described in detail below with reference to the accompanying drawings.
[0016] In the present embodiment, the online OTP device is internally provided with a default storage area and a normal storage area, one or more normal storage area can be provided, in the present embodiment, two normal storage areas are specifically taken as an example, the default storage area can store a plurality of pieces of personalized data, and the normal storage area stores one piece of personalized data.
[0017] Embodiment 1 Embodiment 1 of the present disclosure provides a work implementation method for an online OTP device. As shown in Figure 1, the method comprises:
[0018] Step S1, when an instruction sent by a host computer is received, determining a type of the instruction, when the instruction is an application selection instruction, executing step S2, when the instruction is a protection-code setting instruction, executing step S3, when the instruction is a personalized-data write instruction, executing step S5, and when the instruction is a personalized-data processing instruction, executing step S9;
[0019] Step S2, the online OTP device selects a corresponding OTP application according to an application identifier in the application selection instruction, acquires configured storage-area configuration, generates an application selection response according to the storage-area configuration and preset device data participating in calculation, and returns the application selection response to the host computer, the storage-area configuration comprising a storage-area identifier and a storage-area status code, and then returns to step S1;
[0020] Optionally, in the present embodiment, device data participating in calculation can be a challenge code or a device serial number;
[0021] Step S3, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S4 is executed, otherwise, an error is reported, and the process returns to step S1;
[0022] Step S4, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, an error is reported, and the process returns to step S1, otherwise, a protection code in the protection-code setting instruction is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, a successful setting response is returned to the host computer, and the process returns to step S1;
[0023] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction; when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0024] Step S5, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S6 is executed, otherwise, an error is reported, and the process returns to step S1;
[0025] Step S6, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step S7 is executed, otherwise, an error is reported, and the process returns to step S1;
[0026] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the personalized-data write instruction, when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0027] Step S7, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, calculates fourth comparison data according to a fourth random number in the personalized-data write instruction and the protection code, determines whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, when the fourth comparison data is identical to the fourth intermediate data, step S8 is executed, otherwise, an error is reported, and the process returns to step S1;
[0028] Specifically, in the present embodiment, calculating fourth comparison data according to a fourth random number in the personalized-data write instruction and a protection code comprises: calculating the fourth comparison data by using the protection code and the fourth random number in the personalized-data write instruction;
[0029] Step S8, the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, personalized data in the personalized-data write instruction is stored in the default storage area, a successful write response is returned to the host computer, and the process returns to step S1, otherwise, personalized data stored in the storage area corresponding to the storage-area identifier is updated by using the personalized data in the personalized-data write instruction, a successful write response is returned to the host computer, and the process returns to step S1;
[0030] Step S9, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S10 is executed, otherwise, an error is reported, and the process returns to step S1;
[0031] Step S10, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step S11 is executed, otherwise, an error is reported, and the process returns to step S1;
[0032] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the personalized-data processing instruction, when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0033] Step S11, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data processing instruction, calculates first comparison data according to a first random number in the personalized-data processing instruction and the protection code, determines whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, when the first intermediate data is identical to the first comparison data, step S12 is executed, otherwise, an error is reported, and the process returns to step S1; and
[0034] Step S12, the online OTP device performs corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, returns a processing result to the host computer, and returns to step S1.
[0035] Optionally, in the present embodiment, the personalized-data processing instruction comprises a dynamic-password generation instruction, a personalized-data deletion instruction, and a personalized-data reset instruction;
[0036] When the personalized-data processing instruction is specifically the dynamic-password generation instruction, the personalized data comprises a seed, and step S12 comprises: the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, acquires a corresponding seed stored in the default storage area according to a name of personalized data in the dynamic-password generation instruction, generates a dynamic password according to the seed, generates a successful processing response according to a processing-success status code, a storage-area status code, and the dynamic password, returns the successful processing response to the host computer, and returns to step S1, otherwise, the online OTP device prompts the user to perform key-press confirmation, when the key confirmation information of the user is received, generates a dynamic password according to a seed stored in a storage area corresponding to the storage- area identifier, generates a successful processing response according to the processing-success status code, the storage-area status code, and the dynamic password, returns the successful processing response to the host computer, and returns to step S1.
[0037] When the personalized-data processing instruction is specifically a personalized-data deletion instruction, step S12 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, deletes personalized data in the default storage area corresponding to a name of personalized data in the personalized-data deletion instruction, generates a successful processing response according to a deletion-success status code and a storage- area status code, returns the successful processing response to the host computer, and returns to step S1, otherwise, the online OTP device prompts the user to perform key-press confirmation, when the key confirmation information of the user is received, deletes personalized data stored in a storage area corresponding to the storage-area identifier, generates the successful processing response according to the deletion-success status code and the storage-area status code, returns the successful processing response to the host computer, and returns to step S1.
[0038] When the personalized-data processing instruction is specifically a personalized-data reset instruction, step S12 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, updates personalized data in the default storage area corresponding to a name of personalized data in the personalized-data reset instruction by using personalized data in the personalized-data reset instruction, generates a successful processing response according to a reset-success status code and a storage-area status code, returns the successful processing response to the host computer, and returns to step S1, otherwise, the online OTP device prompts the user to perform key-press confirmation, when the key confirmation information of the user is received, updates personalized data stored in a storage area corresponding to the storage-area identifier by using personalized data in the personalized-data reset instruction, generates the successful processing response according to the reset-success status code and the storage-area status code, returns the successful processing response to the host computer, and returns to step S1.
[0039] Optionally, in the present embodiment, when the type of the instruction is determined as a protection-code modification instruction in step S1, step H1 is executed;
[0040] Step H1, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step H2 is executed, otherwise, an error is reported, and the process returns to step S1;
[0041] Step H2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step H3 is performed, otherwise, an error is reported, and the process returns to step S1;
[0042] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the protection-code modification instruction, when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0043] Step H3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the protection-code modification instruction, generates second comparison data according to a second random number in the protection-code modification instruction and the acquired protection code, determines whether the second comparison data is identical to second intermediate data in the protection-code modification instruction, when the second comparison data is identical to the second intermediate data, step H4 is executed, otherwise, an error is reported, and the process returns to step S1;
[0044] Step H4, the online OTP device replaces the protection code stored in the storage area corresponding to the storage-area identifier with a new protection code in the protection-code modification instruction, returns a successful modification response to the host computer, and returns to step S1.
[0045] Optionally, in the present embodiment, when the type of the instruction is determined as a protection-code deletion instruction in step S1, step L1 is executed;
[0046] Step L1, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step L2 is executed, otherwise, an error is reported, and the process returns to step S1;
[0047] Step L2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step L3 is executed, otherwise, an error is reported, and the process returns to step S1;
[0048] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the protection-code deletion instruction; when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0049] Step L3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the protection-code deletion instruction, calculates third comparison data according to the protection code and a third random number in the protection-code deletion instruction, determines whether the third comparison data is identical to third intermediate data in the protection-code deletion instruction, when the third comparison data is identical to the third intermediate data, step L4 is executed, otherwise, an error is reported, and the process returns to step S1;
[0050] Step L4, the online OTP device deletes the protection code stored in the storage area corresponding to the storage-area identifier, returns a successful deletion response to the host computer, and returns to step S1.
[0051] Optionally, in the present embodiment, when the type of the instruction is determined as a personalized-data initialization instruction in step S1, step K1 is executed;
[0052] Step K1, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step K2 is executed, otherwise, an error is reported, and the process returns to step S1;
[0053] Step K2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step K3 is executed, otherwise, an error is reported, and the process returns to step S1;
[0054] Specifically, in the present embodiment, determining whether the OTP application has been set with an access permission by the online OTP device comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the personalized-data initialization instruction, when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission;
[0055] Step K3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data initialization instruction, calculates fifth comparison data according to a fifth random number in the personalized-data initialization instruction and the acquired protection code, determines whether the fifth comparison data is identical to fifth intermediate data in the personalized-data initialization instruction, when the fifth comparison data is identical to the fifth intermediate data, step K4 is executed, otherwise, an error is reported, and the process returns to step S1;
[0056] Step K4, the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, step K5 is executed, otherwise, an error is reported, and the process returns to step S1;
[0057] Step K5, the online OTP device deletes the protection code and personalized data stored in the default storage area, returns an initialization success response to the host computer, and returns to step S1.
[0058] Optionally, in the present embodiment, when the type of the instruction is determined as a personalized-data enumeration instruction in step S1, step P1 is executed;
[0059] Step P1, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step P2 is executed, otherwise, an error is reported, and the process returns to step S1;
[0060] Step P2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step P3 is executed, otherwise, an error is reported, and the process returns to step S1;
[0061] Step P3, the online OTP device acquires a protection code and all personalized data in a corresponding storage area according to the storage-area identifier in the personalized-data enumeration instruction, calculates sixth comparison data according to a sixth random number in the personalized- data enumeration instruction and the acquired protection code, determines whether the sixth comparison data is identical to sixth intermediate data in the personalized-data enumeration instruction, when the sixth comparison data is identical to the sixth intermediate data, step P4 is executed, otherwise, an error is reported, and the process returns to step S1;
[0062] Step P4, the online OTP device generates an enumeration success response according to the acquired personalized data and returns the enumeration success response to the host computer and returns to step S1.
[0063] The method of the present embodiment further comprises: after the host computer receives storage-area configuration and device data participating in calculation, the host computer displays corresponding storage areas according to the storage-area configuration for selection by a user, when the user selection information is received, the host computer prompts the user to input an access code of the selected storage area, and generates a protection code according to the received access code and the device data participating in calculation.
[0064] Specifically, when the device data participating in calculation is a challenge code, generating the protection code according to the received access code and the device data participating in calculation comprises: the host computer performs hash calculation on the access code and the challenge code to obtain a first hash value, and extracts data at a preset position in the first hash value as the protection code;
[0065] Alternatively, when the device data participating in calculation is a device serial number, generating the protection code according to the received access code and the device data participating in calculation comprises: the host computer takes the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key having a preset byte length, and takes the symmetric key as the protection code.
[0066] In the present embodiment, after the host computer generates the protection code, various operation instructions can be generated according to data such as the protection code and the storage- area identifier, for example:
[0067] After the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculate on the received access code and the challenge code, data at a preset position in the first hash value is extracted as the protection code, a protection-code setting instruction is generated according to the storage-area identifier and the protection code and is sent to the online OTP device, and the process returns to step S1;
[0068] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as the protection code, a fourth random number is generated, fourth intermediate data is obtained by calculating the fourth random number by using the protection code, a personalized-data write instruction is generated according to the storage-area identifier, the fourth random number, the fourth intermediate data, and personalized data, and is sent to the online OTP device, and the process returns to step S1;
[0069] Alternatively, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as the protection code, a sixth random number is generated, sixth intermediate data is obtained by calculating the sixth random number by using the protection code, a personalized-data enumeration instruction is generated according to the storage-area identifier, the sixth random number, and the sixth intermediate data, and is sent to the online OTP device, and step S1 is executed;
[0070] The host computer parses a received enumeration success response to obtain personalized data and displays the personalized data, when user selection information is received, a personalized-data processing instruction and a personalized-data initialization instruction can be generated according to a name of personalized data in the selection information;
[0071] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as a protection code, a first random number is generated, first intermediate data is obtained by calculating the first random number with the protection code, a personalized-data processing instruction is generated according to the storage-area identifier, the first random number, the first intermediate data, and the name of personalized data and sent to the online OTP device, and the process returns to step S1; the personalized-data processing instruction comprises a personalized-data reset instruction, a personalized-data deletion instruction, and a dynamic-password generation instruction;
[0072] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an old access code and a new access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received old access code and the challenge code, data at a preset position in the first hash value is extracted as an old protection code, a second hash value is obtained by hash calculation on the received new access code and the challenge code, data at a preset position in the second hash value is extracted as a new protection code, a second random number is generated, second intermediate data is obtained by calculating the second random number with the old protection code, a protection-code modification instruction is generated according to the storage-area identifier, the second random number, the second intermediate data, and the new protection code, and is sent to the online OTP device, and the process returns to step S1;
[0073] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as a protection code, a third random number is generated, third intermediate data is obtained by calculating the third random number with the protection code, a protection-code deletion instruction is generated according to the storage-area identifier, the third random number, and the third intermediate data, and is sent to the online OTP device, and the process returns to step S1;
[0074] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as a protection code, a fifth random number is generated, fifth intermediate data is obtained by calculating the fifth random number with the protection code, a personalized-data initialization instruction is generated according to the storage-area identifier, the fifth random number, the fifth intermediate data, and the name of personalized data, and is sent to the online OTP device, and the process returns to step S1;
[0075] Optionally, the method of the present embodiment further comprises: after the online OTP device is inserted into the host computer, when key confirmation information of the user is received, the online OTP device generates a dynamic password according to a seed in the normal storage area, and sends the dynamic password to the host computer for display.
[0076] Specifically, sending the dynamic password to the host computer for display comprises: sending the dynamic password to the host computer for display according to a keyboard protocol format.
[0077] In the present embodiment, the online OTP device is internally provided with a default storage area and a normal storage area, each storage area being provided with a respective protection code, the default storage area can store a plurality of pieces of personalized data, the normal storage area stores one piece of personalized data, and the storage areas are mutually independent and do not affect one another, thereby facilitating management and usage; when a user uses the online OTP device, identity verification is first performed by using the protection code, thereby effectively ensuring that data (including personalized data and the protection code) in the storage areas is not maliciously modified, and ensuring safety of user information and property in situations such as loss of the online OTP device.
[0078] Embodiment 2 Embodiment 2 of the present disclosure provides a work implementation method for an online OTP device, device data participating in calculation in the method being a challenge code, as shown in Figure 2 and Figure 3, the method of the present embodiment comprises:
[0079] Step 201, when the online OTP device receives an instruction issued by the host computer, the online OTP device determines a type of the instruction, when the instruction is an application selection instruction, step 202 is executed, when the instruction is a protection-code setting instruction, step 204 is executed, when the instruction is a personalized-data write instruction, step 207 is executed; when the instruction is a personalized-data processing instruction, step 214 is executed, when the instruction is a protection-code modification instruction, step 219 is executed, when the instruction is a protection- code deletion instruction, step 224 is executed, when the instruction is a personalized-data initialization instruction, step 229 is executed, when the instruction is a personalized-data enumeration instruction, step 235 is executed, and when the instruction is another instruction, a corresponding operation is executed;
[0080] In the present embodiment, an instruction issued by the host computer to the online OTP device is in an APDU format, specifically: CLA INS P1 P2 Lc Data Le, wherein CLA is an instruction class, INS is an instruction code, P1 and P2 are parameters, Lc is a length of Data, and Le is a length of response data;
[0081] Specifically, in the present embodiment, when the online OTP device receives the instruction issued by the host computer, the instruction is parsed, and a type of the instruction is determined according to an instruction header obtained through parsing;
[0082] Step 202, the online OTP device parses an application selection instruction, and selects a corresponding OTP application according to an application identifier in a parsing result;
[0083] For example, an instruction received by the online OTP device is 00A4040009 D15600013283260101, wherein data D15600013283260101 in a data field is the application identifier;
[0084] Step 203, the online OTP device acquires configured storage-area configuration, generates an application selection response according to the storage-area configuration and a preset challenge code, returns the application selection response to the host computer, and returns to step 201;
[0085] In the present embodiment, three storage areas are provided in the online OTP device, respectively a first storage area, a second storage area, and a default storage area;
[0086] Optionally, the challenge code is 8-byte data;
[0087] For example, in the present embodiment, the application selection response is 5903010002 5108AB61365B4024B533 7B0100 9000, wherein 5108AB61365B4024B533 is the challenge code, a last byte in 7B0100 indicates storage-area configuration, and 9000 indicates successful execution of the instruction;
[0088] Wherein the storage-area configuration comprises a storage-area status code, status code 00 indicates that no access code is configured for the three storage areas, status code 01 indicates that an access code is configured for the first storage area, status code 02 indicates that an access code is configured for the second storage area, status code 04 indicates that an access code is configured for the default storage area, status code 03 indicates that access codes are configured for the first storage area and the second storage area, status code 05 indicates that access codes are configured for the first storage area and the default storage area, status code 06 indicates that access codes are configured for the second storage area and the default storage area, and status code 07 indicates that access codes are configured for the first storage area, the second storage area, and the default storage area;
[0089] In the present embodiment, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, and the host computer can generate different instructions according to the challenge code, the access code, and the storage-area identifier of the selected storage area and send the instructions to the online OTP device for corresponding processing;
[0090] For example, when the storage-area configuration is 06, the host computer displays the second storage area and the default storage area for selection by a user;
[0091] Specifically, the host computer can generate different instructions according to the challenge code, the access code, and the storage-area identifier of the selected storage area and send the instructions to the online OTP device for corresponding processing, comprising:
[0092] The host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a protection-code setting instruction according to the storage-area identifier and the protection code, sends the protection-code setting instruction to the online OTP device, and executes step 201;
[0093] Alternatively, the host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a fourth random number, performs HMAC-SHA256 calculation on the fourth random number by using the protection code to obtain fourth intermediate data, generates a personalized-data write instruction according to the storage-area identifier, the fourth random number, the fourth intermediate data, and personalized data, sends the personalized-data write instruction to the online OTP device, and executes step 201;
[0094] Alternatively, the host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a sixth random number, performs HMAC-SHA256 calculation on the sixth random number by using the protection code to obtain sixth intermediate data, generates a personalized-data enumeration instruction according to the storage-area identifier, the sixth random number, and the sixth intermediate data, sends the personalized-data enumeration instruction to the online OTP device, and executes step 201;
[0095] The host computer parses a received enumeration success response to obtain personalized data and display the personalized data, when user selection information is received, can generate a personalized-data processing instruction and a personalized-data initialization instruction according to a name of personalized data in the selection information;
[0096] Alternatively, the host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a first random number, performs HMAC-SHA256 calculation on the first random number by using the protection code to obtain first intermediate data, generates a personalized-data processing instruction according to the storage-area identifier, the first random number, the first intermediate data, and the name of personalized data, sends the personalized-data processing instruction to the online OTP device, and executes step 201; the personalized-data processing instruction comprises a personalized-data reset instruction, a personalized-data deletion instruction, and a dynamic-password generation instruction;
[0097] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an old access code and a new access code of the selected storage area, a first hash value is obtained by performing SHA256 hash calculation on the received old access code and the challenge code, first 16- byte data in the first hash value is extracted as an old protection code, a second hash value is obtained by performing SHA256 hash calculation on the received new access code and the challenge code, first 16-byte data in the second hash value is extracted as a new protection code, a second random number is generated, second intermediate data is obtained by performing HMAC-SHA256 calculation on the second random number with the old protection code, a protection-code modification instruction is generated according to the storage-area identifier, the second random number, the second intermediate data, and the new protection code and sent to the online OTP device, and step 201 is executed;
[0098] Alternatively, the host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a third random number, performs HMAC-SHA256 calculation on the third random number with the protection code to obtain third intermediate data, generates a protection- code deletion instruction according to the storage-area identifier, the third random number, and the third intermediate data and sends the protection-code deletion instruction to the online OTP device, and step 201 is executed;
[0099] Alternatively, the host computer performs SHA256 hash calculation on the received access code and the challenge code to obtain a first hash value, extracts first 16-byte data in the first hash value as a protection code, generates a fifth random number, performs HMAC-SHA256 calculation on the fifth random number with the protection code to obtain fifth intermediate data, generates a personalized- data initialization instruction according to the storage-area identifier, the fifth random number, the fifth intermediate data, and the name of personalized data and sends the personalized-data initialization instruction to the online OTP device, and step 201 is executed;
[0100] In the present embodiment, a length of an access code corresponding to the first storage area is 6 bytes, a length of an access code corresponding to the second storage area is 6 bytes, and a length of an access code corresponding to the default storage area is variable; the protection code is 16-byte data, the first random number, the second random number, the third random number, the fourth random number, and the fifth random number are 16-byte data, and the first intermediate data, the second intermediate data, the third intermediate data, the fourth intermediate data, and the fifth intermediate data are 32-byte data;
[0101] Step 204, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 205 is executed; otherwise, an error is reported, and the process returns to step 201;
[0102] Specifically, in the present embodiment, hardware in the online OTP device determines whether an application has been selected and whether the selected application is an OTP application, when the application has been selected and the selected application is the OTP application, step 205 is executed, otherwise, an error is reported, and the process returns to step 201;
[0103] Step 205, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, an error is reported, and the process returns to step 201, otherwise, step 206 is executed;
[0104] Specifically, in the present embodiment, step 205 comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, when the protection code is stored, the access permission has been set, an error is reported, and the process returns to step 201, otherwise, the access permission has not been set, and step 206 is executed;
[0105] Optionally, in the present embodiment, the error reported in step 204 and step 205 specifically comprises: returning a setting failure response to the host computer;
[0106] Step 206, the online OTP device parses the protection-code setting instruction to obtain a protection code and a storage-area identifier, stores the protection code in a storage area corresponding to the storage-area identifier, returns a setting success response to the host computer, and returns to step 201;
[0107] For example, in the present embodiment, the setting instruction is 00A3020112 5310 E707BECF8E25D958803FC45A0A1B4740, wherein fourth-byte data 01 in the setting instruction is a storage-area identifier, and E707BECF8E25D958803FC45A0A1B4740 is a protection code;
[0108] In the present embodiment, after the online OTP device stores the protection code in a storage area of the OTP application, when the online OTP device subsequently receives another instruction, operation on the OTP application can be performed only after verification of the protection code succeeds;
[0109] Step 207, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 208 is executed; otherwise, an error is reported, and the process returns to step 201;
[0110] Step 208, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 209 is executed; otherwise, an error is reported, and the process returns to step 201;
[0111] Step 209, the online OTP device parses the personalized-data write instruction to obtain a storage-area identifier, a fourth random number, fourth intermediate data, and personalized data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and fourth comparison data is obtained by performing calculation on the fourth random number with the acquired protection code;
[0112] Step 210, the online OTP device determines whether the fourth comparison data is identical to the fourth intermediate data, when the fourth comparison data is identical to the fourth intermediate data, step 211 is executed, otherwise, an error is reported, and the process returns to step 201;
[0113] Optionally, in the present embodiment, the error reported in step 207, step 208, and step 210 can be: the online OTP device returns a write failure response to the host computer;
[0114] Step 211, the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, step 212 is executed, otherwise, step 213 is executed;
[0115] Step 212, the online OTP device stores personalized data in a storage area corresponding to the storage-area identifier, returns a write success response to the host computer, and returns to step 201;
[0116] In the present embodiment, the personalized data comprises information such as a name, a slot, a seed, an OTP type, a hash algorithm, and a length, and the online OTP device generates a 6-digit or 8-digit dynamic password according to the seed and the hash calculation;
[0117] Step 213, the online OTP device updates personalized data stored in a storage area corresponding to the storage-area identifier by using the personalized data, returns a write success response to the host computer, and returns to step 201;
[0118] Step 214, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 215 is executed, otherwise, an error is reported, and the process returns to step 201;
[0119] Step 215, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 216 is executed, otherwise, an error is reported, and the process returns to step 201;
[0120] Step 216, the online OTP device parses the personalized-data processing instruction to obtain a storage-area identifier, a first random number, first intermediate data, and a name of personalized data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and a first comparison data is obtained by performing calculation on the first random number with the acquired protection code;
[0121] Step 217, the online OTP device determines whether the first intermediate data is identical to the first comparison data, when the first intermediate data is identical to the first comparison data, step 218 is executed, otherwise, an error is reported, and the process returns to step 201;
[0122] Optionally, in the present embodiment, the error reported in step 214, step 215, and step 217 specifically comprises: the online OTP device generates an operation failure response according to a verification-failure status code and a storage-area status code and returns the operation failure response to the host computer;
[0123] Specifically, the online OTP device generates the operation failure response according to the verification-failure status code and the storage-area status code, comprising: the online OTP device generates the operation failure response according to the verification-failure status code and the storage- area status code;
[0124] Step 218, the online OTP device performs corresponding processing on personalized data corresponding to the name of personalized data in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, returns a processing result to the host computer, and returns to step 201;
[0125] Optionally, in the present embodiment, when the personalized-data processing instruction is specifically a dynamic-password generation instruction, the personalized data comprises a seed, and step 218 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, acquires a corresponding seed stored in the default storage area according to the name of personalized data in the dynamic-password generation instruction, generates a dynamic password according to the seed, generates a processing success response according to a processing-success status code, a storage-area status code, and the dynamic password, returns the processing success response to the host computer, and returns to step 201, otherwise, the online OTP device prompts the user to perform key-press confirmation, when key confirmation information of the user is received, generates a dynamic password according to a seed stored in a storage area corresponding to the storage-area identifier, generates a processing success response according to the processing-success status code, the storage-area status code, and the dynamic password, returns the processing success response to the host computer, and returns to step 201;
[0126] Specifically, in the present embodiment, generating the processing success response according to the processing-success status code, the storage-area status code, and the dynamic password, comprising: concatenating the dynamic password, the storage-area status code, and the verification- success status code in sequence to generate the processing success response;
[0127] In the present embodiment, the first storage area and the second storage area store one piece of personalized data, and the default storage area can store a plurality of pieces of personalized data, the personalized data comprises: a name of personalized data, a seed, an OTP type, a hash algorithm, a length, etc.;
[0128] The storage-area status code comprises: 00 indicating that no access code is configured for a storage area, 01 indicating that an access code is configured for the first storage area, 02 indicating that an access code is configured for the second storage area, 03 indicating that access codes are configured for the first storage area and the second storage area, 04 indicating that an access code is configured for the default storage area, 05 indicating that access codes are configured for the first storage area and the default storage area, 06 indicating that access codes are configured for the second storage area and the default storage area, and 07 indicating that access codes are configured for the first storage area, the second storage area, and the default storage area;
[0129] The verification-success status code is 9000, and the verification-failure status code is 0000;
[0130] For example, the generated processing success response 1S 5903010002510802241BBC2DFA1E2A7B0101 9000, wherein 5903010002510802241BBC2DFA1E2A is the dynamic password, last-byte data 01 in 7B0101 is the storage-area status code, and 9000 is the verification-success status code;
[0131] When the personalized-data processing instruction is specifically a personalized-data deletion instruction, step 218 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, deletes personalized data stored in the default storage area and corresponding to the name of personalized data in the personalized-data deletion instruction, generates a processing success response according to a deletion-success status code and a storage-area status code, returns the processing success response to the host computer, and returns to step 201, otherwise, the online OTP device prompts the user to perform key-press confirmation, when key confirmation information of the user is received, deletes personalized data stored in a storage area corresponding to the storage-area identifier, generates the processing success response according to the deletion-success status code and the storage-area status code, returns the processing success response to the host computer, and returns to step 201;
[0132] When the personalized-data processing instruction is specifically a personalized-data reset instruction, step 218 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, when key confirmation information of the user is received, updates personalized data stored in the default storage area and corresponding to the name of personalized data in the personalized-data reset instruction by using personalized data in the personalized-data reset instruction, generates a processing success response according to a reset-success status code and a storage-area status code, returns the processing success response to the host computer, and returns to step 201, otherwise, the online OTP device prompts the user to perform key-press confirmation, when key confirmation information of the user is received, updates personalized data stored in a storage area corresponding to the storage-area identifier by using personalized data in the personalized-data reset instruction, generates the processing success response according to the deletion-success status code and the storage-area status code, returns the processing success response to the host computer, and returns to step 201;
[0133] Step 219, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 220 is executed otherwise, an error is reported, and the process returns to step 201;
[0134] Step 220, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 221 is executed; otherwise, an error is reported, and the process returns to step 201;
[0135] Step 221, the online OTP device parses a protection-code modification instruction to obtain a storage-area identifier, second intermediate data, a second random number, and a new protection code, acquires a protection code in a corresponding storage area according to the storage-area identifier, and second comparison data is obtained by performing calculation on the second random number with the acquired protection code;
[0136] Step 222, the online OTP device determines whether the second comparison data is identical to the second intermediate data, when the second comparison data is identical to the second intermediate data, step 223 is executed, otherwise, an error is reported, and the process returns to step 201;
[0137] Optionally, in the present embodiment, the error reported in step 219, step 220, and step 222 is: the online OTP device returns a modification failure response to the host computer;
[0138] Step 223, the online OTP device replaces the protection code stored in the storage area corresponding to the storage-area identifier with the new protection code, returns a modification success response to the host computer, and returns to step 201;
[0139] Step 224, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 225 is executed, otherwise, an error is reported, and the process returns to step 201;
[0140] Step 225, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 226 is executed, otherwise, an error is reported, and the process returns to step 201;
[0141] Step 226, the online OTP device parses a protection-code deletion instruction to obtain a storage-area identifier, third intermediate data, and a third random number, acquires a protection code in a corresponding storage area according to the storage-area identifier, and third comparison data is obtained by performing calculation on the third random number with the acquired protection code;
[0142] Step 227, the online OTP device determines whether the third comparison data is identical to the third intermediate data, when the third comparison data is identical to the third intermediate data, step 228 is executed, otherwise, an error is reported, and the process returns to step 201;
[0143] Optionally, in the present embodiment, the error reported in step 224, step 225, and step 227 specifically is: the online OTP device returns a deletion failure response to the host computer;
[0144] Step 228, the online OTP device deletes the protection code stored in the storage area corresponding to the storage-area identifier, returns a deletion success response to the host computer, and returns to step 201;
[0145] Step 229, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 230 is executed, otherwise, an error is reported, and the process returns to step 201;
[0146] Step 230, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 231 is executed, otherwise, an error is reported, and the process returns to step 201;
[0147] Step 231, the online OTP device parses a personalized-data initialization instruction to obtain a storage-area identifier, a fifth random number, and fifth intermediate data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and fifth comparison data is obtained by performing calculation on the fifth random number with the acquired protection code;
[0148] Step 232, the online OTP device determines whether the fifth comparison data is identical to the fifth intermediate data, when the fifth comparison data is identical to the fifth intermediate data, step 233 is executed, otherwise, an error is reported, and the process returns to step 201;
[0149] Step 233, the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, step 234 is executed otherwise, an error is reported, and the process returns to step 201;
[0150] Optionally, in the present embodiment, the error reported in step 229, step 230, step 232, and step 233 specifically is: the online OTP device returns a reset failure response to the host computer;
[0151] Step 234, the online OTP device deletes personalized data and a protection code stored in the default storage area, returns an initialization success response to the host computer, and returns to step 201;
[0152] Step 235, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 236 is executed, otherwise, an error is reported, and the process returns to step 201;
[0153] Step 236, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 237 is executed, otherwise, an error is reported, and the process returns to step 201;
[0154] Step 237, the online OTP device parses a personalized-data enumeration instruction to obtain a storage-area identifier, a sixth random number, and sixth intermediate data, acquires a protection code and all personalized data in a corresponding storage area according to the storage-area identifier, and sixth comparison data is obtained by performing calculation on the sixth random number with the acquired protection code;
[0155] Step 238, the online OTP device determines whether the sixth comparison data is identical to the sixth intermediate data, when the sixth comparison data is identical to the sixth intermediate data, step 239 is executed, otherwise, an error is reported, and the process returns to step 201;
[0156] Optionally, in the present embodiment, the error reported in step 235, step 236, and step 238 specifically is: the online OTP device returns an enumeration failure response to the host computer;
[0157] Step 239, the online OTP device generates an enumeration success response according to the acquired personalized data, returns the enumeration success response to the host computer, and returns to step 201;
[0158] In the present embodiment, the host computer parses a received enumeration success response to obtain personalized data and display the personalized data, and when user selection information is received, generates a personalized-data processing instruction and a personalized-data initialization instruction according to a name of personalized data in the selection information.
[0159] In the present embodiment, a first storage area, a second storage area, and a default storage area are provided in the online OTP device, the first storage area and the second storage area are only allowed to store one piece of personalized data and support setting of a protection code, the host computer generates a protection code according to an access code input by a user and sends the protection code to the online OTP device for verification, modification, deletion, and other operations on personalized data and the protection code in the first storage area and / or the second storage area are allowed only after verification succeeds; the default storage area can store a plurality of pieces of personalized data without quantity limitation, and supports setting of a protection code, the host computer generates a protection code according to an access code input by the user and sends the protection code to the online OTP device for verification, modification, use, initialization, and other operations on personalized data and the access code in the default storage area are allowed only after verification succeeds, thereby facilitating management of the online OTP device and improving security of the online OTP device.
[0160] Embodiment 3 Embodiment 3 of the present disclosure provides a work implementation method for an online OTP device, device data participating in calculation in the method being a device serial number, as shown in Figure 4 and Figure 5, the method of the present embodiment comprises:
[0161] Step 301, when the online OTP device receives an instruction issued by the host computer, the online OTP device determines a type of the instruction, when the instruction is an application selection instruction, step 302 is executed, when the instruction is a protection-code setting instruction, step 304 is executed, when the instruction is a personalized-data write instruction, step 307 is executed; when the instruction is a personalized-data processing instruction, step 314 is executed, when the instruction is a protection-code modification instruction, step 319 is executed, when the instruction is a protection- code deletion instruction, step 324 is executed, when the instruction is a personalized-data initialization instruction, step 329 is executed, when the instruction is a personalized-data enumeration instruction, step 335 is executed, and when the instruction is another instruction, a corresponding operation is executed;
[0162] In the present embodiment, an instruction issued by the host computer to the online OTP device is in an APDU format, specifically is: CLA INS P1 P2 Lc Data Le, wherein CLA is an instruction class, INS is an instruction code, P1 and P2 are parameters, Lc is a length of Data, and Le is a length of response data;
[0163] Specifically, in the present embodiment, when the online OTP device receives the instruction issued by the host computer, the instruction is parsed, and a type of the instruction is determined according to an instruction header obtained through parsing;
[0164] Step 302, the online OTP device parses an application selection instruction, and selects a corresponding OTP application according to an application identifier in a parsing result;
[0165] For example, an instruction received by the online OTP device is 00A4040007A0000005272101, wherein data A0000005272101 in a data field is the application identifier;
[0166] Step 303, the online OTP device acquires configured storage-area configuration, generates an application selection response according to a device serial number of the online OTP device itself and the storage-area configuration, returns the application selection response to the host computer, and returns to step 301;
[0167] In the present embodiment, three storage areas are provided in the online OTP device and respectively are a first storage area, a second storage area, and a default storage area;
[0168] For example, in the present embodiment, the application selection response is 7903010004 7108E6029A6D1E7F85557B0102 9000, wherein 7108E6029A6D1E7F8555 indicates the device serial number, last-byte data in 7B0102 indicates storage-area configuration, and 9000 indicates successful execution of the instruction;
[0169] Wherein the storage-area configuration comprises: a storage-area status code, status code 00 indicating that no access code is configured for the three storage areas, status code 01 indicating that an access code is configured for the first storage area, status code 02 indicating that an access code is configured for the second storage area, status code 04 indicating that an access code is configured for the default storage area, status code 03 indicating that access codes are configured for the first storage area and the second storage area, status code 05 indicating that access codes are configured for the first storage area and the default storage area, status code 06 indicating that access codes are configured for the second storage area and the default storage area, and status code 07 indicating that access codes are configured for the first storage area, the second storage area, and the default storage area;
[0170] In the present embodiment, after the host computer receives the storage-area configuration and the device serial number, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, the host computer can generate different instructions according to the device serial number, the access code, and the storage-area identifier of the selected storage area and send the instructions to the online OTP device for corresponding processing;
[0171] Specifically, the host computer can generate different instructions according to the device serial number, the access code, and the storage-area identifier of the corresponding storage area and send the instructions to the online OTP device for corresponding processing, comprising:
[0172] The host computer takes the received access code and the device serial number as parameters, calls PBKDF2WithHmacSHA1 of Android system method SecretKeyFactory to construct a symmetric key having a length of 16 bytes, takes the symmetric key as a protection code, generates a protection- code setting instruction according to the storage-area identifier and the protection code, sends the protection-code setting instruction to the online OTP device, and executes step 301; furthermore, a system of the host computer is not limited to Android, and details are omitted herein;
[0173] Alternatively, the host device takes the received access code and device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as a protection code, the host device generates a fourth random number and performs an HMAC-SHA1 operation on the fourth random number by using the protection code to obtain a fourth intermediate value, the host device generates a personalized-data write instruction based on a storage area identifier, the fourth random number, the fourth intermediate value, and personalization data, and sends the instruction to an online OTP device to execute step 301.
[0174] Alternatively, the host device takes the received access code and device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as a protection code, the host device generates a sixth random number and performs an HMAC-SHA1 operation on the sixth random number by using the protection code to obtain a sixth intermediate value, the host device generates a personalized-data enumeration command based on a storage area identifier, the sixth random number, and the sixth intermediate value, and sends the instruction to an online OTP device to execute step 201.
[0175] The host device parses a received successful enumeration response to obtain personalized-data and displays the personalization data, when the user selection information is received, the host device generates a personalized-data processing instruction and a personalized-data initialization instruction according to selected personalized-data name.
[0176] Alternatively, the host device takes the received access code and device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as a protection code, the host device generates a first random number and performs an HMAC-SHA1 calculation on the first random number by using the protection code to obtain a first intermediate value, the host device generates a personalized-data processing instruction based on a storage area identifier, the first random number, the first intermediate value, and a name of personalization data, and sends the instruction to an online OTP device to execute step 301, the personalized-data processing instruction comprises a reset personalized-data instruction, a delete personalized-data instruction, and a dynamic password generation instruction.
[0177] Alternatively, after receiving storage area configuration and a device serial number, the host device displays storage areas for user selection according to the storage area configuration, when user selection information is received, the host device prompts a user to input an old access code and a new access code for a selected storage area, the host device uses the old access code and the device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as an old protection code. The host device uses the new access code and the device serial number as input parameters to derive a symmetric key having a length of 16 bytes as a new protection code. The host device generates a second random number and performs an HMAC-SHA1 calculation on the second random number by using the old protection code to obtain a second intermediate value. The host device generates a protection code modification instruction based on a storage area identifier, the second random number, the second intermediate value, and the new protection code, and sends the instruction to an online OTP device to execute step 301;
[0178] Alternatively, the host device takes the received access code and device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as a protection code, the host device generates a third random number and performs an HMAC-SHA1 calculation on the third random number by using the protection code to obtain a third intermediate value, the host device generates a protection code deletion instruction based on a storage area identifier, the third random number, and the third intermediate value, and sends the instruction to an online OTP device to execute step 301;
[0179] Alternatively, the host device takes the received access code and device serial number as input parameters to invoke the Android system method SecretKeyFactory with PBKDF2WithHmacSHA1 to derive a symmetric key having a length of 16 bytes as a protection code, the host device generates a fifth random number and performs an HMAC-SHA1 calculation on the fifth random number by using the protection code to obtain a fifth intermediate value, the host device generates a personalized-data write instruction based on a storage area identifier, the fifth random number, the fifth intermediate value, and a name of personalization data, and sends the instruction to an online OTP device to execute step 301.
[0180] In the present embodiment, an access code corresponding to a first storage area has a length of 6 bytes, an access code corresponding to a second storage area has a length of 6 bytes, the length of an access code corresponding to a default storage area is not fixed; the protection code has a length of 16 bytes, each of the first random number, the second random number, the third random number, the fourth random number, and the fifth random number has a length of 16 bytes, each of the first intermediate value, the second intermediate value, the third intermediate value, the fourth intermediate value, and the fifth intermediate value has a length of 32 bytes;
[0181] Step 304, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 305 is executed, otherwise, an error is reported, and the process returns to step 301;
[0182] Specifically, in the present embodiment, hardware in the online OTP device determines whether an application has been selected and whether the selected application is an OTP application, when the application has been selected and the selected application is the OTP application, step 305 is executed, otherwise, an error is reported, and the process returns to step 301;
[0183] Step 305, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, an error is reported, and the process returns to step 301, otherwise, step 306 is executed;
[0184] Specifically, in the present embodiment, step 305 comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, when the protection code is stored, the access permission has been set, an error is reported, and the process returns to step 301, otherwise, the access permission has not been set, and step 306 is executed;
[0185] Optionally, in the present embodiment, the error reported in step 304 and step 305 specifically is: a setting failure response is returned to the host computer;
[0186] Step 306, the online OTP device parses the protection-code setting instruction to obtain a protection code and a storage-area identifier, stores the protection code in a storage area corresponding to the storage-area identifier, returns a setting success response to the host computer, and returns to step 301;
[0187] In the present embodiment, after the online OTP device stores the protection code in a storage area of the OTP application, when the online OTP device subsequently receives another instruction, operation on the OTP application can be performed only after verification of the protection code succeeds;
[0188] Step 307, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 308 is executed, otherwise, an error is reported, and the process returns to step 301;
[0189] Step 308, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 309 is executed, otherwise, an error is reported, and the process returns to step 301;
[0190] Step 309, the online OTP device parses the personalized-data write instruction to obtain a storage-area identifier, a fourth random number, fourth intermediate data, and personalized data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and fourth comparison data is obtained by performing calculation on the fourth random number with the acquired protection code;
[0191] Step 310, the online OTP device determines whether the fourth comparison data is identical to the fourth intermediate data, when the fourth comparison data is identical to the fourth intermediate data, step 311 is executed, otherwise, an error is reported, and the process returns to step 301;
[0192] Optionally, in the present embodiment, the error reported in step 307, step 308, and step 310 can be: a write failure response is returned to the host computer;
[0193] Step 311, the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, step 312 is executed, otherwise, step 313 is executed;
[0194] Step 312, the online OTP device stores personalized data in a storage area corresponding to the storage-area identifier, returns a write success response to the host computer, and returns to step 301;
[0195] In the present embodiment, the personalized data comprises a name, a slot, a seed, an OTP type, a hash algorithm, a length, etc., and the online OTP device generates a 6-digit or 8-digit dynamic password according to the seed;
[0196] Step 313, the online OTP device updates personalized data stored in a storage area corresponding to the storage-area identifier by using the personalized data, returns a write success response to the host computer, and returns to step 301;
[0197] Step 314, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 315 is executed, otherwise, an error is reported, and the process returns to step 301;
[0198] Step 315, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 316 is executed, otherwise, an error is reported, and the process returns to step 301;
[0199] Step 316, the online OTP device parses the personalized-data processing instruction to obtain a storage-area identifier, a first random number, first intermediate data, and a name of personalized data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and first comparison data is obtained by performing calculation on the first random number with the acquired protection code;
[0200] Step 317, the online OTP device determines whether the first intermediate data is identical to the first comparison data, when the first intermediate data is identical to the first comparison data, step 318 is executed, otherwise, an error is reported, and the process returns to step 301;
[0201] Optionally, in the present embodiment, the error reported in step 314, step 315, and step 317 is: the online OTP device generates an operation failure response according to a verification-failure status code and a storage-area status code and returns the operation failure response to the host computer;
[0202] Specifically, generating the operation failure response according to the verification-failure status code and the storage-area status code comprises: the online OTP device concatenates the storage- area status code and the verification-failure status code in sequence to generate the operation failure response;
[0203] Step 318, the online OTP device performs corresponding processing on personalized data corresponding to the name of personalized data in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, returns a processing result to the host computer, and returns to step 301;
[0204] Optionally, in the present embodiment, when the personalized-data processing instruction is specifically a dynamic-password generation instruction, the personalized data comprises a seed, and step 318 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts the user to confirm by pressing a key, when key- confirmation information of the user is received, acquires a corresponding seed stored in the default storage area according to the name of personalized data in the dynamic-password generation instruction, generates a dynamic password according to the seed, generates a processing success response according to a processing-success status code, a storage-area status code, and the dynamic password, returns the processing success response to the host computer, and returns to step 301, otherwise, the online OTP device prompts the user to confirm by pressing a key, when key-confirmation information of the user is received, generates a dynamic password according to a seed stored in a storage area corresponding to the storage-area identifier, generates a processing success response according to the processing- success status code, the storage-area status code, and the dynamic password, returns the processing success response to the host computer, and returns to step 301;
[0205] Specifically, in the present embodiment, generating the processing success response according to the processing-success status code, the storage-area status code, and the dynamic password comprises: concatenating the dynamic password, the storage-area status code, and the verification- success status code in sequence to generate the processing success response;
[0206] In the present embodiment, the first storage area and the second storage area store one piece of personalized data, the default storage area can store a plurality of pieces of personalized data, and the personalized data comprises: a personalized-data name, a seed, an OTP type, a hash algorithm, a length, etc.;
[0207] The storage-area status code comprises: 00 indicating that no access code is configured for a storage area, 01 indicating that an access code is configured for the first storage area, 02 indicating that an access code is configured for the second storage area, 03 indicating that access codes are configured for the first storage area and the second storage area, 04 indicating that an access code is configured for the default storage area, 05 indicating that access codes are configured for the first storage area and the default storage area, 06 indicating that access codes are configured for the second storage area and the default storage area, and 07 indicating that access codes are configured for the first storage area, the second storage area, and the default storage area;
[0208] The verification-success status code is 9000, and the verification-failure status code is 0000;
[0209] For example, a generated processing success response is: 5903010002510802241BBC2DFA1E2A7B0101 9000, wherein 5903010002510802241BBC2DFA1E2A is the dynamic password, last-byte data 01 in 7B0101 is the storage-area status code, and 9000 is the verification-success status code;
[0210] When the personalized-data processing instruction is specifically a personalized-data deletion instruction, step 318 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts the user to confirm by pressing a key, when key-confirmation information of the user is received, deletes personalized data in the default storage area corresponding to the name of personalized data in the personalized-data deletion instruction, generates a processing success response according to a deletion-success status code and a storage-area status code, returns the processing success response to the host computer, and returns to step 301, otherwise, the online OTP device prompts the user to confirm by pressing a key, when key- confirmation information of the user is received, deletes personalized data stored in a storage area corresponding to the storage-area identifier, generates the processing success response according to the deletion-success status code and the storage-area status code, returns the processing success response to the host computer, and returns to step 301;
[0211] When the personalized-data processing instruction is specifically a personalized-data reset instruction, step 318 comprises: the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, the online OTP device prompts the user to confirm by pressing a key, when key-confirmation information of the user is received, updates personalized data in the default storage area corresponding to the name of personalized data in the personalized-data reset instruction by using personalized data in the personalized-data reset instruction, generates a processing success response according to a reset-success status code and a storage-area status code, returns the processing success response to the host computer, and returns to step 301, otherwise, the online OTP device prompts the user to confirm by pressing a key, when key-confirmation information of the user is received, updates personalized data stored in a storage area corresponding to the storage-area identifier by using personalized data in the personalized-data reset instruction, generates a processing success response according to a reset-success status code and a storage-area status code, returns the processing success response to the host computer, and returns to step 301;
[0212] Step 319, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 320 is executed, otherwise, an error is reported, and the process returns to step 301;
[0213] Step 320, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 321 is executed, otherwise, an error is reported, and the process returns to step 301;
[0214] Step 321, the online OTP device parses a protection-code modification instruction to obtain a storage-area identifier, second intermediate data, a second random number, and a new protection code, acquires a protection code in a corresponding storage area according to the storage-area identifier, and second comparison data is obtained by performing calculation on the second random number with the acquired protection code;
[0215] Specifically, in the present embodiment, the protection-code modification instruction received by the online OTP device comprises three TLV structures;
[0216] For example, the protection-code modification instruction in this step is: 0003000033 73112109FA07217854138DAF43B7FD2FEADC97 740819E052E744BA5AE4 75147C4D9A8947E14E9B92198883E92197371E2A7F94, wherein 73112109FA07217854138DAF43B7FD2FEADC97 is a first TLV, T=73, L=11, and V=2109FA07217854138DAF43B7FD2FEADC97 (the first byte 21 is an OTP type, and data starting from a second byte is a new protection code), 740819E052E744BA5AE4 is a second TLV, T=74, L=08, and V=19E052E744BA5AE4 (the second random number), and 75147C4D9A8947E14E9B92198883E92197371E2A7F94 is a third TLV, T=75, L=14, and V=7C4D9A8947E14E9B92198883E92197371E2A7F94 (the second intermediate data);
[0217] Step 322, the online OTP device determines whether the second comparison data is identical to the second intermediate data; when the second comparison data is identical to the second intermediate data, step 323 is executed, otherwise, an error is reported, and the process returns to step 301;
[0218] Optionally, in the present embodiment, the error reported in step 319, step 320, and step 322 is: the online OTP device returns a modification failure response to the host computer;
[0219] Step 323, the online OTP device replaces the protection code stored in the storage area corresponding to the storage-area identifier with the new protection code, returns a modification success response to the host computer, and returns to step 301;
[0220] Step 324, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 325 is executed, otherwise, an error is reported, and the process returns to step 301;
[0221] Step 325, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 326 is executed, otherwise, an error is reported, and the process returns to step 301;
[0222] Step 326, the online OTP device parses a protection-code deletion instruction to obtain a storage-area identifier, third intermediate data, and a third random number, acquires a protection code in a corresponding storage area according to the storage-area identifier, and third comparison data is obtained by performing calculation on the third random number with the acquired protection code;
[0223] Step 327, the online OTP device determines whether the third comparison data is identical to the third intermediate data; when the third comparison data is identical to the third intermediate data, step 328 is executed, otherwise, an error is reported, and the process returns to step 301;
[0224] Optionally, in the present embodiment, the error reported in step 324, step 325, and step 327 specifically is: the online OTP device returns a deletion failure response to the host computer;
[0225] Step 328, the online OTP device deletes the protection code stored in the storage area corresponding to the storage-area identifier, returns a deletion success response to the host computer, and returns to step 301;
[0226] Step 329, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step 330 is executed; otherwise, an error is reported, and the process returns to step 301;
[0227] Step 330, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step 331 is executed, otherwise, an error is reported, and the process returns to step 301;
[0228] Step 331, the online OTP device parses a personalized-data initialization instruction to obtain a storage-area identifier, a fifth random number, and fifth intermediate data, acquires a protection code in a corresponding storage area according to the storage-area identifier, and fifth comparison data is obtained by performing calculation on the fifth random number with the acquired protection code;
[0229] Step 332, the online OTP device determines whether the fifth comparison data is identical to the fifth intermediate data, when the fifth comparison data is identical to the fifth intermediate data, step 333 is executed; otherwise, an error is reported, and the process returns to step 301;
[0230] Step 333, the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, step 334 is executed, otherwise, an error is reported, and the process returns to step 301;
[0231] Optionally, in the present embodiment, the error reported in step 329, step 330, step 332, and step 333 specifically is: the online OTP device returns a reset failure response to the host computer;
[0232] Step 334, the online OTP device deletes personalized data and a protection code stored in the default storage area, returns an initialization success response to the host computer, and returns to step 301;
[0233] Step 335, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step 336 is executed, otherwise, an error is reported, and the process returns to step 301;
[0234] Step 336, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step 337 is executed, otherwise, an error is reported, and the process returns to step 301;
[0235] Step 337, the online OTP device parses a personalized-data enumeration instruction to obtain a storage-area identifier, a sixth random number, and sixth intermediate data, acquires a protection code and all personalized data in a corresponding storage area according to the storage-area identifier, and sixth comparison data is obtained by performing calculation on the sixth random number with the acquired protection code;
[0236] Step 338, the online OTP device determines whether the sixth comparison data is identical to the sixth intermediate data, when the sixth comparison data is identical to the sixth intermediate data, step 339 is executed, otherwise, an error is reported, and the process returns to step 301;
[0237] Optionally, in the present embodiment, the error reported in step 335, step 336, and step 338 specifically is: the online OTP device returns an enumeration failure response to the host computer;
[0238] Step 339, the online OTP device generates an enumeration success response according to the acquired personalized data, returns the enumeration success response to the host computer, and returns to step 301;
[0239] In the present embodiment, the host computer parses a received enumeration success response to obtain personalized data and display the personalized data, when user selection information is received, a personalized-data processing instruction and a personalized-data initialization instruction can be generated according to the name of personalized data in the selection information.
[0240] In the present embodiment, after the online OTP device is inserted into the host computer, when short-press key-confirmation information or long-press key-confirmation information of a user is received, the online OTP device generates a dynamic password according to a seed in the first storage area or the second storage area and sends the dynamic password to the host computer for display;
[0241] Optionally, after the device generates the dynamic password, the dynamic password is sent to the host computer for display according to a keyboard protocol format.
[0242] Embodiment 4 Embodiment 4 of the present disclosure provides a work implementation apparatus for an online OTP device, wherein the online OTP device is internally provided with a default storage area and a normal storage area, the default storage area can store a plurality of pieces of personalized data, the normal storage area stores one piece of personalized data, and the apparatus of the present embodiment comprises:
[0243] A receiving-and-determining module, configured to receive an instruction issued by the host computer, determine a type of the instruction when the instruction is received, trigger a selection- calculating-and-returning module when the instruction is an application selection instruction, trigger a first determining module when the instruction is a protection-code setting instruction, trigger a second determining module when the instruction is a personalized-data write instruction, and trigger a fourth determining module when the instruction is a personalized-data processing instruction;
[0244] A selection-calculating-and-returning module, configured to select a corresponding OTP application according to an application identifier in the application selection instruction, acquire configured storage-area configuration, generate an application selection response according to the storage-area configuration and preset device data participating in calculation, return the application selection response to the host computer, the storage-area configuration comprising a storage-area identifier and a storage-area status code, and trigger the receiving-and-determining module; optionally, in the present embodiment, the device data participating in calculation can be a challenge code or a device serial number;
[0245] A first determining module, configured to determine whether an OTP application has been selected, trigger a determining-setting-and-returning module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0246] A determining-setting-and-returning module, configured to determine whether the OTP application has been set with an access permission, report an error and trigger the receiving-and- determining module when the OTP application has been set with the access permission, and otherwise store a protection code in the protection-code setting instruction in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, return a setting success response to the host computer, and trigger the receiving-and-determining module;
[0247] A second determining module, configured to determine whether an OTP application has been selected, trigger a third determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0248] A third determining module, configured to determine whether the OTP application has been set with an access permission, trigger a first acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0249] A first acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, obtain fourth comparison data by performing calculation on a fourth random number in the personalized-data write instruction with the protection code, determine whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, trigger a determining-and-writing module when the fourth comparison data is identical to the fourth intermediate data, and otherwise report an error and trigger the receiving-and-determining module;
[0250] In the present embodiment, the first acquiring-calculating-and-determining module is specifically configured to obtain the fourth comparison data by performing calculation on the fourth random number in the personalized-data write instruction with the protection code;
[0251] A determining-and-writing module, configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, store personalized data in the personalized-data write instruction in the default storage area when the corresponding storage area is the default storage area, return a write success response to the host computer, and trigger the receiving- and-determining module, and otherwise update personalized data stored in the storage area corresponding to the storage-area identifier by using the personalized data in the personalized-data write instruction, return the write success response to the host computer, and trigger the receiving-and- determining module;
[0252] A fourth determining module, configured to determine whether an OTP application has been selected, trigger a fifth determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0253] A fifth determining module, configured to determine whether the OTP application has been set with an access permission, trigger a second acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0254] A second acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data processing instruction, obtain first comparison data by performing calculation on a first random number in the personalized-data processing instruction with the protection code, determine whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, trigger a processing-and-returning module when the first intermediate data is identical to the first comparison data, and otherwise report an error and trigger the receiving-and-determining module;
[0255] A processing-and-returning module, configured to perform corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, return a processing result to the host computer, and trigger the receiving-and-determining module.
[0256] Optionally, in the present embodiment, the personalized-data processing instruction comprises a dynamic-password generation instruction, a personalized-data deletion instruction, and a personalized-data reset instruction;
[0257] When the personalized-data processing instruction is specifically a dynamic-password generation instruction and the personalized data comprises a seed, the processing-and-returning module is specifically configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, prompt the user to confirm by pressing a key when the corresponding storage area is the default storage area, when key-confirmation information of the user is received, acquire a corresponding seed stored in the default storage area according to a name of personalized data in the dynamic-password generation instruction, generate a dynamic password according to the seed, generate a processing success response according to a processing-success status code, a storage-area status code, and the dynamic password, return the processing success response to the host computer, and trigger the receiving-and-determining module, and otherwise prompt the user to confirm by pressing a key, when key-confirmation information of the user is received, generate a dynamic password according to a seed stored in a storage area corresponding to the storage-area identifier, generate a processing success response according to the processing-success status code, the storage-area status code, and the dynamic password, return the processing success response to the host computer, and trigger the receiving-and-determining module;
[0258] When the personalized-data processing instruction is specifically a personalized-data deletion instruction, the processing-and-returning module is specifically configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, prompt the user to confirm by pressing a key when the corresponding storage area is the default storage area, when key-confirmation information of the user is received, delete personalized data in the default storage area corresponding to the name of personalized data in the personalized-data deletion instruction, generate a processing success response according to a deletion-success status code and a storage-area status code, return the processing success response to the host computer, and trigger the receiving-and-determining module, and otherwise prompt the user to confirm by pressing a key, when key-confirmation information of the user is received, delete personalized data stored in a storage area corresponding to the storage-area identifier, generate the processing success response according to the deletion-success status code and the storage-area status code, return the processing success response to the host computer, and trigger the receiving-and-determining module;
[0259] When the personalized-data processing instruction is specifically a personalized-data reset instruction, the processing-and-returning module is specifically configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, prompt the user to confirm by pressing a key when the corresponding storage area is the default storage area, when key-confirmation information of the user is received, update personalized data in the default storage area corresponding to the name of personalized data in the personalized-data reset instruction by using personalized data in the personalized-data reset instruction, generate a processing success response according to a reset-success status code and a storage-area status code, return the processing success response to the host computer, and trigger the receiving-and-determining module, and otherwise prompt the user to confirm by pressing a key, when key-confirmation information of the user is received, update personalized data stored in a storage area corresponding to the storage-area identifier by using personalized data in the personalized-data reset instruction, generate the processing success response according to the reset-success status code and the storage-area status code, return the processing success response to the host computer, and trigger the receiving-and-determining module.
[0260] Optionally, the apparatus of the present embodiment further comprises:
[0261] A sixth determining module, configured to determine whether an OTP application has been selected when the receiving-and-determining module determines that the type of the instruction is a protection-code modification instruction, trigger a seventh determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0262] A seventh determining module, configured to determine whether the OTP application has been set with an access permission, trigger a third acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0263] A third acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the protection-code modification instruction, obtain second comparison data by performing calculation on a second random number in the protection-code modification instruction with the acquired protection code, determine whether the second comparison data is identical to second intermediate data in the protection-code modification instruction, trigger a replacement-and-returning module when the second comparison data is identical to the second intermediate data, and otherwise report an error and trigger the receiving-and- determining module;
[0264] A replacement-and-returning module, configured to replace the protection code stored in the storage area corresponding to the storage-area identifier with a new protection code in the protection- code modification instruction, return a modification success response to the host computer, and trigger the receiving-and-determining module.
[0265] Optionally, the apparatus of the present embodiment further comprises:
[0265] An eighth determining module, configured to determine whether an OTP application has been selected when the receiving-and-determining module determines that the type of the instruction is a protection-code deletion instruction, trigger a ninth determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0266] A ninth determining module, configured to determine whether the OTP application has been set with an access permission, trigger a fourth acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0267] A fourth acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the protection-code deletion instruction, obtain third comparison data by performing calculation on a third random number in the protection-code deletion instruction with the protection code, determine whether the third comparison data is identical to third intermediate data in the protection-code deletion instruction, trigger a first deleting-and-returning module when the third comparison data is identical to the third intermediate data, and otherwise report an error and trigger the receiving-and-determining module;
[0268] A first deleting-and-returning module, configured to delete the protection code stored in the storage area corresponding to the storage-area identifier, return a deletion success response to the host computer, and trigger the receiving-and-determining module.
[0269] Optionally, the apparatus of the present embodiment further comprises:
[0270] A tenth determining module, configured to determine whether an OTP application has been selected when the receiving-and-determining module determines that the type of the instruction is a personalized-data initialization instruction, trigger an eleventh determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0271] An eleventh determining module, configured to determine whether the OTP application has been set with an access permission, trigger a fifth acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0272] A fifth acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data initialization instruction, obtain fifth comparison data by performing calculation on a fifth random number in the personalized-data initialization instruction with the acquired protection code, determine whether the fifth comparison data is identical to fifth intermediate data in the personalized-data initialization instruction, trigger a twelfth determining module when the fifth comparison data is identical to the fifth intermediate data, and otherwise report an error and trigger the receiving-and- determining module;
[0273] A twelfth determining module, configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, trigger a second deleting-and-returning module when the corresponding storage area is the default storage area, and otherwise report an error and trigger the receiving-and-determining module;
[0274] A second deleting-and-returning module, configured to delete a protection code and personalized data stored in the default storage area, return an initialization success response to the host computer, and trigger the receiving-and-determining module.
[0275] Optionally, the apparatus of the present embodiment further comprises:
[0276] A thirteenth determining module, configured to determine whether an OTP application has been selected when the receiving-and-determining module determines that the type of the instruction is a personalized-data enumeration instruction, trigger a fourteenth determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module;
[0277] A fourteenth determining module, configured to determine whether the OTP application has been set with an access permission, trigger a sixth acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module;
[0278] A sixth acquiring-calculating-and-determining module, configured to acquire a protection code and all personalized data in a corresponding storage area according to the storage-area identifier in the personalized-data enumeration instruction, obtain sixth comparison data by performing calculation on a sixth random number in the personalized-data enumeration instruction with the acquired protection code, determine whether the sixth comparison data is identical to sixth intermediate data in the personalized-data enumeration instruction, trigger a generating-and-returning module when the sixth comparison data is identical to the sixth intermediate data, and otherwise report an error and trigger the receiving-and-determining module;
[0279] The thirteenth determining module is further configured to determine whether a corresponding storage area is a default storage area according to the storage-area identifier, trigger the generating-and- returning module when the corresponding storage area is the default storage area, and otherwise report an error and trigger the receiving-and-determining module;
[0280] The generating-and-returning module is configured to generate an enumeration success response according to the acquired personalized data, return the enumeration success response to the host computer, and trigger the receiving-and-determining module.
[0281] Optionally, the apparatus of the present embodiment further comprises:
[0282] A receiving-generating-and-sending module, configured to, after the online OTP device is inserted into the host computer, generate a dynamic password according to a seed in the normal storage area when key-confirmation information of the user is received, and send the dynamic password to the host computer for display.
[0283] The receiving-generating-and-sending module, configured to send the dynamic password to the host computer for display, specifically comprises: sending the dynamic password to the host computer for display according to a keyboard protocol format.
[0284] In the present embodiment, after the host computer receives storage-area configuration and device data participating in calculation, corresponding storage areas are displayed according to the storage-area configuration for selection by a user; when the user selection information is received, the user is prompted to input an access code of the selected storage area, and a protection code is generated according to the received access code and the device data participating in calculation.
[0285] Specifically, when the device data participating in calculation is a challenge code, generating the protection code according to the received access code and the device data participating in calculation comprises: the host computer performs hash calculation on the access code and the challenge code to obtain a first hash value, and extracts data at a preset position in the first hash value as the protection code;
[0286] Alternatively, when the device data participating in calculation is a device serial number, generating the protection code according to the received access code and the device data participating in calculation comprises: the host computer uses the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key having a preset byte length, and uses the symmetric key as the protection code.
[0287] Preferably, the preset byte length is 16 bytes.
[0288] In the present embodiment, after the host computer generates the protection code, various operation instructions can be generated according to data such as the protection code and the storage- area identifier, for example:
[0289] After the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as the protection code, a protection-code setting instruction is generated according to the storage-area identifier and the protection code, and is sent to the online OTP device, and the process returns to step S1;
[0290] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, a first hash value is obtained by performing hash calculation on the received access code and the challenge code, data at a preset position in the first hash value is extracted as the protection code, a fourth random number is generated, fourth intermediate data is obtained by calculating the fourth random number with the protection code, a personalized-data write instruction is generated according to the storage-area identifier, the fourth random number, the fourth intermediate data, and personalized data and is sent to the online OTP device, and the process returns to step S1;
[0291] Alternatively, the host computer performs hash calculation on the received access code and the challenge code to obtain a first hash value, extracts data at a preset position in the first hash value as a protection code, generates a sixth random number, obtains sixth intermediate data by performing calculation on the sixth random number with the protection code, generates a personalized-data enumeration instruction according to the storage-area identifier, the sixth random number, and the sixth intermediate data, sends the personalized-data enumeration instruction to the online OTP device, and returns to step S1;
[0292] The host computer parses a received enumeration success response to obtain personalized data and display the personalized data, and when user selection information is received, can generate a personalized-data processing instruction and a personalized-data initialization instruction according to the name of personalized data in the selection information;
[0293] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, the host computer performs hash calculation on the received access code and the challenge code to obtain a first hash value, extracts data at a preset position in the first hash value as a protection code, generates a first random number, obtains first intermediate data by performing calculation on the first random number with the protection code, generates a personalized- data processing instruction according to the storage-area identifier, the first random number, the first intermediate data, and the name of personalized data, sends the personalized-data processing instruction to the online OTP device, and returns to step S1; the personalized-data processing instruction comprises a personalized-data reset instruction, a personalized-data deletion instruction, and a dynamic-password generation instruction;
[0294] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an old access code and a new access code of the selected storage area, the host computer performs hash calculation on the received old access code and the challenge code to obtain a first hash value, extracts data at a preset position in the first hash value as an old protection code, performs hash calculation on the received new access code and the challenge code to obtain a second hash value, extracts data at a preset position in the second hash value as a new protection code, generates a second random number, obtains second intermediate data by performing calculation on the second random number with the old protection code, generates a protection-code modification instruction according to the storage-area identifier, the second random number, the second intermediate data, and the new protection code, sends the protection-code modification instruction to the online OTP device, and returns to step S1;
[0295] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, the host computer performs hash calculation on the received access code and the challenge code to obtain a first hash value, extracts data at a preset position in the first hash value as a protection code, generates a third random number, obtains third intermediate data by performing calculation on the third random number with the protection code, generates a protection- code deletion instruction according to the storage-area identifier, the third random number, and the third intermediate data, sends the protection-code deletion instruction to the online OTP device, and returns to step S1;
[0296] Alternatively, after the host computer receives the storage-area configuration and the challenge code, corresponding storage areas are displayed according to the storage-area configuration for selection by a user, when the user selection information is received, the user is prompted to input an access code of the selected storage area, the host computer performs hash calculation on the received access code and the challenge code to obtain a first hash value, extracts data at a preset position in the first hash value as a protection code, generates a fifth random number, obtains fifth intermediate data by performing calculation on the fifth random number with the protection code, generates a personalized-data initialization instruction according to the storage-area identifier, the fifth random number, the fifth intermediate data, and the name of personalized data, sends the personalized-data initialization instruction to the online OTP device, and returns to step S1;
[0297] Optionally, embodiments of the present application further provide an electronic device, the electronic device comprises at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, and the at least one processor executes the instructions to implement the work implementation method for an online OTP device described in any one of the foregoing embodiments, the electronic device can be a chip system, the chip system can be formed by a chip, and can further comprise the chip and other discrete devices, no specific limitation is imposed in embodiments of the present application; the chip is coupled to the memory and is configured to execute a computer program stored in the memory to implement the work implementation method for an online OTP device disclosed in the foregoing embodiments.
[0298] In the foregoing embodiments, implementation can be entirely or partially achieved by software, hardware, firmware, or any combination thereof. When implementation is achieved by using a software program, implementation can be entirely or partially achieved in a form of a computer program product. The computer program product comprises one or more computer programs. When the computer programs are loaded and executed on the electronic device, flows or functions described in embodiments of the present application are entirely or partially generated. The computer programs can be stored in a computer-readable storage medium or can be transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one base station, electronic device, server, or data center to another base station, electronic device, server, or data center through a wired manner (such as a coaxial cable, an optical fiber, or a digital subscriber line (DSL)), or through a wireless manner (such as infrared, wireless, or microwave). The computer-readable storage medium can be any available medium accessible by the electronic device, or can be a data storage device, such as a server or a data center, comprising one or more available media integrated thereinto. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, or a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)). In embodiments of the present application, the electronic device can comprise the foregoing apparatus.
[0299] Although embodiments have been described herein with reference to embodiments of the present application, during implementation of the present application to be protected, a person skilled in the art can understand and implement other changes to the disclosed embodiments by referring to the drawings, the disclosed content, and the appended claims. In the claims, the term "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plural number. A single processor or another unit can implement a plurality of functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not indicate inability of combination of the measures to produce a good effect.
[0300] Although the present application has been described with reference to specific features and embodiments, apparently, various modifications and combinations can be made thereto without departing from the spirit and scope of the present application. Accordingly, the specification and the drawings are merely illustrative description of the present application defined by the appended claims, and are deemed to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Apparently, a person skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Accordingly, when the changes and modifications fall within the scope of the claims of the present application and equivalent technologies thereof, the present application is also intended to cover the changes and modifications.
Claims
1. A work implementation method for an online One-Time Password (OTP) device, the online OTP device being an electronic device provided with keys and requiring connection to a host computer for operation, the online OTP device being provided with a default storage area and a normal storage area, the default storage area storing a plurality of pieces of personalized data, the normal storage area storing one piece of personalized data, the method comprising: step S1, when an instruction sent by a host computer is received, determining a type of the instruction, when the instruction is an application selection instruction, executing step S2, when the instruction is a protection-code setting instruction, executing step S3, when the instruction is a personalized-data write instruction, executing step S5, and when the instruction is a personalized-data processing instruction, executing step S9; step S2, the online OTP device selects a corresponding OTP application according to an application identifier in the application selection instruction, acquires configured storage-area configuration, generates an application selection response according to the storage-area configuration and preset device data participating in calculation, and returns the application selection response to the host computer, the storage-area configuration comprising a storage- area identifier and a storage-area status code, and then returns to step S1; step S3, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step S4 is executed, otherwise, an error is reported, and the process returns to step S1; step S4, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, an error is reported, and the process returns to step S1, otherwise, a protection code in the protection- code setting instruction is stored in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, a successful setting response is returned to the host computer, and the process returns to step S1; step S5, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S6 is executed, otherwise, an error is reported, and the process returns to step S1; step S6, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step S7 is executed, otherwise, an error is reported, and the process returns to step S1; step S7, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, calculates fourth comparison data according to a fourth random number in the personalized-data write instruction and the protection code, determines whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, when the fourth comparison data is identical to the fourth intermediate data, step S8 is executed, otherwise, an error is reported, and the process returns to step S1; step S8, the online OTP device determines whether a corresponding storage area is a default storage area according to the storage-area identifier, when the corresponding storage area is the default storage area, personalized data in the personalized-data write instruction is stored in the default storage area, a successful write response is returned to the host computer, and the process returns to step S1, otherwise, personalized data stored in the storage area corresponding to the storage-area identifier is updated by using the personalized data in the personalized-data write instruction, a successful write response is returned to the host computer, and the process returns to step S1; step S9, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step S10 is executed, otherwise, an error is reported, and the process returns to step S1; step S10, the online OTP device determines whether the OTP application has been set with an access permission, when the OTP application has been set with the access permission, step S11 is executed, otherwise, an error is reported, and the process returns to step S1; step S11, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data processing instruction, calculates first comparison data according to a first random number in the personalized-data processing instruction and the protection code, determines whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, when the first intermediate data is identical to the first comparison data, step S12 is executed, otherwise, an error is reported, and the process returns to step S1; and step S12, the online OTP device performs corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized- data processing instruction, returns a processing result to the host computer, and returns to step S1.
2. The method according to claim 1, wherein the personalized-data processing instruction is a dynamic- password generation instruction, the personalized data comprises a seed; the step S12 comprising: when a corresponding storage area is the default storage area, prompting a user to perform key-press confirmation, acquiring from the default storage area a seed corresponding to a personalized-data name in the dynamic-password generation instruction after key confirmation information is received, generating a dynamic password according to the seed, generating a successful processing response according to a processing- success status code, a storage-area status code, and the dynamic password, and returning the successful processing response to the host computer; and when the corresponding storage area is not the default storage area, generating a dynamic password according to a seed stored in a storage area corresponding to the storage-area identifier, generating the successful processing response, and returning the successful processing response to the host computer.
3. The method according to claim 1, wherein the personalized-data processing instruction is specifically a personalized-data deletion instruction, and step S12 comprises: the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, deletes, when key confirmation information of the user is received, personalized data stored in the default storage area and corresponding to a name of personalized data in the personalized-data deletion instruction, generates a successful processing response according to a deletion-success status code and a storage-area status code, returns the successful processing response to the host computer, and returns to step S1, otherwise, the online OTP device prompts the user to perform key-press confirmation, deletes, when the key confirmation information of the user is received, personalized data stored in a storage area corresponding to the storage-area identifier, generates the successful processing response according to the deletion-success status code and the storage-area status code, returns the successful processing response to the host computer, and returns to step S1.
4. The method according to claim 1, wherein the personalized-data processing instruction is specifically a personalized-data reset instruction, and step S12 comprises: the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, the online OTP device prompts a user to perform key-press confirmation, updates, when key confirmation information of the user is received, personalized data stored in the default storage area and corresponding to a name of personalized data in the personalized-data reset instruction by using personalized data in the personalized-data reset instruction, generates a successful processing response according to a reset-success status code and a storage-area status code, returns the successful processing response to the host computer, and returns to step S1, otherwise, the online OTP device prompts the user to perform key-press confirmation, updates, when the key confirmation information of the user is received, personalized data stored in a storage area corresponding to the storage-area identifier by using personalized data in the personalized-data reset instruction, generates the successful processing response according to the reset-success status code and the storage-area status code, returns the successful processing response to the host computer, and returns to step S1.
5. The method according to claim 1, wherein, when the type of the instruction is determined as a protection-code modification instruction in step S1, step H1 is executed; step H1, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step H2 is executed, otherwise, an error is reported, and the process returns to step S1; step H2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step H3 is performed, otherwise, an error is reported, and the process returns to step S1; step H3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the protection-code modification instruction, generates second comparison data according to a second random number in the protection-code modification instruction and the acquired protection code, determines whether the second comparison data is identical to second intermediate data in the protection-code modification instruction, when the second comparison data is identical to the second intermediate data, step H4 is executed, otherwise, an error is reported, and the process returns to step S1; and step H4, the online OTP device replaces the protection code stored in the storage area corresponding to the storage-area identifier with a new protection code in the protection-code modification instruction, returns a successful modification response to the host computer, and returns to step S1.
6. The method according to claim 1, wherein, when the type of the instruction is determined as a protection-code deletion instruction in step S1, step L1 is executed; step L1, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step L2 is executed, otherwise, an error is reported, and the process returns to step S1; step L2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step L3 is executed, otherwise, an error is reported, and the process returns to step S1; step L3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the protection-code deletion instruction, calculates third comparison data according to the protection code and a third random number in the protection-code deletion instruction, determines whether the third comparison data is identical to third intermediate data in the protection-code deletion instruction, when the third comparison data is identical to the third intermediate data, step L4 is executed, otherwise, an error is reported, and the process returns to step S1; and step L4, the online OTP device deletes the protection code stored in the storage area corresponding to the storage-area identifier, returns a successful deletion response to the host computer, and returns to step S1.
7. The method according to claim 1, wherein, when the type of the instruction is determined as a personalized-data initialization instruction in step S1, step K1 is executed; step K1, the online OTP device determines whether an OTP application has been selected; when the OTP application has been selected, step K2 is executed, otherwise, an error is reported, and the process returns to step S1; step K2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step K3 is executed, otherwise, an error is reported, and the process returns to step S1; step K3, the online OTP device acquires a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data initialization instruction, calculates fifth comparison data according to a fifth random number in the personalized-data initialization instruction and the acquired protection code, determines whether the fifth comparison data is identical to fifth intermediate data in the personalized-data initialization instruction, when the fifth comparison data is identical to the fifth intermediate data, step K4 is executed, otherwise, an error is reported, and the process returns to step S1; step K4, the online OTP device determines, according to the storage-area identifier, whether a corresponding storage area is a default storage area; when the corresponding storage area is the default storage area, step K5 is executed, otherwise, an error is reported, and the process returns to step S1; and step K5, the online OTP device deletes the protection code and personalized data stored in the default storage area, returns an initialization success response to the host computer, and returns to step S1.
8. The method according to claim 1, wherein, when the type of the instruction is determined as a personalized-data enumeration instruction in step S1, step P1 is executed; step P1, the online OTP device determines whether an OTP application has been selected, when the OTP application has been selected, step P2 is executed, otherwise, an error is reported, and the process returns to step S1; step P2, the online OTP device determines whether the OTP application has been set with an access permission; when the OTP application has been set with the access permission, step P3 is executed, otherwise, an error is reported, and the process returns to step S1; step P3, the online OTP device acquires a protection code and all personalized data in a corresponding storage area according to the storage-area identifier in the personalized-data enumeration instruction, calculates sixth comparison data according to a sixth random number in the personalized-data enumeration instruction and the acquired protection code, determines whether the sixth comparison data is identical to sixth intermediate data in the personalized- data enumeration instruction, when the sixth comparison data is identical to the sixth intermediate data, step P4 is executed, otherwise, an error is reported, and the process returns to step S1; and step P4, the online OTP device generates an enumeration success response according to the acquired personalized data and returns the enumeration success response to the host computer and returns to step S1.
9. The method according to claim 1, further comprising: after receiving storage-area configuration and device data participating in calculation, the host computer displays the storage-area configuration for selection by a user, when the user selection information is received, the host computer prompts the user to input an access code corresponding to the selected storage-area identifier, and a protection code is generated according to the received access code and the device data participating in calculation.
10. The method according to claim 9, wherein the device data participating in calculation is a challenge code, and generating the protection code according to the received access code and the device data participating in calculation specifically comprises: the host computer performs hash calculation on the access code and the challenge code to obtain a first hash value, and extracts data at a preset position in the first hash value as the protection code; Alternatively, the device data participating in calculation is a device serial number, and generating the protection code according to the received access code and the device data participating in calculation specifically comprises: the host computer uses the access code and the device serial number as parameters, calls a preset algorithm to construct a symmetric key having a preset byte length, and uses the symmetric key as the protection code.
11. The method according to claim 1, wherein determining, by the online OTP device, whether the OTP application has been set with an access permission comprises: the online OTP device determines whether a protection code is stored in a storage area corresponding to the storage-area identifier in the received instruction; when the protection code is stored, the OTP application is determined to have been set with the access permission, otherwise, the OTP application is determined not to have been set with the access permission.
12. The method according to claim 1, further comprising: after the online OTP device is connected to the host computer, when key confirmation information of the user is received, the online OTP device generates a dynamic password according to a seed in a normal storage area, and sends the dynamic password to the host computer for display.
13. The method according to claim 12, wherein sending the dynamic password to the host computer for display comprises: sending the dynamic password to the host computer for display according to a keyboard protocol format.
14. A work implementation apparatus for an online OTP device, the online OTP device being an electronic device provided with keys and needing to be connected to a host computer for work, the online OTP device being internally provided with a default storage area and a normal storage area, the default storage area storing a plurality of pieces of personalized data, the normal storage area storing one piece of personalized data, the apparatus comprising: a receiving-and-determining module, configured to receive an instruction issued by the host computer, determine a type of the instruction when the instruction is received, trigger a selection-calculating-and-returning module when the instruction is an application selection instruction, trigger a first determining module when the instruction is a protection-code setting instruction, trigger a second determining module when the instruction is a personalized-data write instruction, and trigger a fourth determining module when the instruction is a personalized-data processing instruction; the selection-calculating-and-returning module, configured to select a corresponding OTP application according to an application identifier in the application selection instruction, acquire configured storage-area configuration, generate an application selection response according to the storage-area configuration and preset device data participating in calculation, and return the application selection response to the host computer, the storage-area configuration comprising a storage-area identifier and a storage-area status code, and trigger the receiving-and- determining module; the first determining module, configured to determine whether an OTP application has been selected, trigger a determining-setting-and-returning module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the determining-setting-and-returning module, configured to determine whether the OTP application has been set with an access permission, report an error and trigger the receiving- and-determining module when the OTP application has been set with the access permission, and otherwise store a protection code in the protection-code setting instruction in a storage area corresponding to the storage-area identifier in the protection-code setting instruction, return a successful setting response to the host computer, and trigger the receiving-and-determining module; the second determining module, configured to determine whether an OTP application has been selected, trigger a third determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the third determining module, configured to determine whether the OTP application has been set with an access permission, trigger a first acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module; the first acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized-data write instruction, calculate fourth comparison data according to a fourth random number in the personalized-data write instruction and the protection code, determine whether the fourth comparison data is identical to fourth intermediate data in the personalized-data write instruction, trigger a determining-and-writing module when the fourth comparison data is identical to the fourth intermediate data, and otherwise report an error and trigger the receiving- and-determining module; the determining-and-writing module, configured to determine, according to the storage-area identifier, whether a corresponding storage area is a default storage area, store personalized data in the personalized-data write instruction in the default storage area when the corresponding storage area is the default storage area, return a successful write response to the host computer, and return to step S1, and otherwise update personalized data stored in the storage area corresponding to the storage-area identifier by using the personalized data in the personalized-data write instruction, return the successful write response to the host computer, and trigger the receiving-and-determining module; the fourth determining module, configured to determine whether an OTP application has been selected, trigger a fifth determining module when the OTP application has been selected, and otherwise report an error and trigger the receiving-and-determining module; the fifth determining module, configured to determine whether the OTP application has been set with an access permission, trigger a second acquiring-calculating-and-determining module when the OTP application has been set with the access permission, and otherwise report an error and trigger the receiving-and-determining module; the second acquiring-calculating-and-determining module, configured to acquire a protection code in a corresponding storage area according to the storage-area identifier in the personalized- data processing instruction, calculate first comparison data according to a first random number in the personalized-data processing instruction and the protection code, determine whether first intermediate data in the personalized-data processing instruction is identical to the first comparison data, trigger a processing-and-returning module when first intermediate data in the personalized-data processing instruction is identical to the first comparison data, and otherwise report an error and trigger the receiving-and-determining module; the processing-and-returning module, configured to perform corresponding processing on personalized data stored in the storage area corresponding to the storage-area identifier according to the personalized-data processing instruction, return a processing result to the host computer, and trigger the receiving-and-determining module.
15. An electronic device, comprising at least one processor, a memory, and instructions stored in the memory and executable by the at least one processor, the at least one processor being configured to execute the instructions to implement the work implementation method for an online OTP device according to any one of claims 1 to 13.
16. A computer-readable storage medium, wherein the computer-readable storage medium comprises a computer program, and when the computer program runs on an electronic device, the electronic device is caused to execute the work implementation method for an online OTP device according to any one of claims 1 to 13.
17. A chip system, comprising a chip and a memory, the memory storing a computer program, the chip being configured to execute a computer program stored in the memory to execute the work implementation method for an online OTP device according to any one of claims 1 to 13.