MBB Device Authentication Method, Device, MBB and Master Device, Medium
A dual authentication method for MBB devices during BIOS boot and OS environments ensures only authorized devices are enabled, addressing compatibility and security issues by enabling early defect detection and ensuring proper device operation.
Patent Information
- Application Number
- CN202111194307.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-10-13
AI Technical Summary
The lack of certification scheme between laptops and MBB equipment in the prior art has led to the inability to detect defective products during the boot stage, and the uniqueness and traceability of MBB equipment cannot be guaranteed, and compatibility and safety risks are posed.
By performing two-way authentication between the MBB device and the master device, including first authentication when the BIOS boot device is started and second authentication in the operating system environment, authentication is ensured by using preloader and encrypted information.
It realizes the identification of MBB devices during BIOS startup, early detection of defective products, and ensures the uniqueness and security of MBB devices in the operating system environment, improving the matching and security of laptops and MBB devices.
Smart Images

Figure CN113946814B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of electronic devices, and particularly to an MBB device authentication method, apparatus, MBB, host device, and medium. Background Art
[0002] With the continuous popularization of various portable devices and the continuous progress of communication technologies, various corresponding communication methods have emerged. Currently, in the process of people's daily use of portable devices, Mobile Broadband (MBB) devices are used.
[0003] Currently, there are many laptop (i.e., host device) manufacturers that support the design of MBB device interfaces (M.2) and their peripheral equipment (such as MBB device antennas), but there is a lack of an authentication scheme between laptops and MBB devices, which will cause the following problems:
[0004] 1. Due to the lack of signature authentication for specific manufacturer's MBB devices during the laptop startup process, the laptop production line cannot complete the inspection of defective products at the startup stage, such as whether the MBB device is inserted, whether the MBB device is unrecognizable, etc., resulting in a large time consumption for individual laptop defective product inspection during the mass production stage.
[0005] 2. Due to the lack of signature authentication for specific manufacturer's MBB devices during the laptop startup process, when installing an MBB device on a laptop or when a laptop customer later repairs the MBB device, the uniqueness and traceability of the MBB device cannot be guaranteed, which may lead to the installation of MBB devices from different manufacturers on the laptop, increasing the maintenance and repair work.
[0006] 3. Due to the lack of authentication of the MBB device for specific manufacturer's laptops in the operating system environment, the MBB device can be randomly installed and used in laptops of various manufacturers, burying potential compatibility hazards.
[0007] 4. Due to the lack of authentication of the MBB device for specific manufacturer's laptops in the operating system environment, the MBB device can be randomly installed and used in laptops of various manufacturers, and it may also lead to the snooping of some manufacturer-specific MBB device functions through laptops of other manufacturers.
[0008] It should be noted that the information disclosed in the above background art section is only used to enhance the understanding of the background of the present invention, and thus may include information that does not constitute the prior art known to those skilled in the art. Summary of the Invention
[0009] In view of this, the purpose of the embodiments of the present invention is to provide an MBB device authentication method, apparatus, MBB, host device, and medium to solve at least one problem arising from the lack of authentication between the host device and the MBB device in the prior art.
[0010] In order to solve the above technical problems, in a first aspect, an embodiment of the present invention provides an MBB device authentication method, which is applied to an MBB device. The MBB device is electrically connected to a master device. The method includes:
[0011] When the MBB device is powered on and receives the startup notification from the master device, it executes a preloading program to enable communication between the MBB device and the master device. Among them, the execution time of the preloading program is less than the startup time of the BIOS boot device of the master device;
[0012] Send the authentication information of the MBB device to the master device for the master device to perform a first authentication on the MBB device according to the authentication information of the MBB device during the startup process of the BIOS boot device. When the first authentication fails, the MBB device loses power;
[0013] When the first authentication is successful and the master device enters the operating system environment, obtain the authentication information of the master device, perform a second authentication on the MBB device according to the authentication information of the master device, and determine whether to unlock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication. Among them, the mobile broadband communication function of the MBB device is default configured to be in a disabled state.
[0014] In addition, determining whether to unlock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication includes:
[0015] If the second authentication is successful, enable the Modem function of the MBB device to restore the mobile broadband communication function of the MBB device. If the second authentication fails, keep the Modem function of the MBB device disabled.
[0016] In addition, the authentication information of the master device is the encrypted information of the BIOS feature information of the master device;
[0017] Correspondingly, performing a second authentication on the MBB device according to the authentication information of the master device includes:
[0018] The MBB device compares the encrypted information of the BIOS feature information of the master device with a preset list of legal BIOS ciphertext signatures to determine whether the MBB device passes the second authentication.
[0019] In a second aspect, an embodiment of the present invention further provides an MBB device authentication method, which is applied to a master device. The master device is electrically connected to an MBB device. The method includes:
[0020] Power on the MBB device when the BIOS boot device of the master device starts up and notify the MBB device to power on.
[0021] If the authentication information of the MBB device is received during the startup process of the BIOS boot device, perform a first authentication on the MBB device according to the authentication information of the MBB device; if the first authentication fails, remove the power supply of the MBB device.
[0022] If the first authentication is successful and when the master device enters the operating system environment, send the authentication information of the master device to the MBB device for the MBB device to perform a second authentication according to the authentication information of the master device; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state, and when the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
[0023] In addition, the authentication information of the MBB device includes: the PID information of the MBB device and / or the VID information of the MBB device.
[0024] Performing a first authentication on the MBB device according to the authentication information of the MBB device includes:
[0025] If the authentication information of the MBB device exists in the preset legal MBB signature list in the master device, the first authentication is successful; if the authentication information of the MBB device does not exist, the first authentication fails.
[0026] In a third aspect, an embodiment of the present invention further provides an MBB device authentication apparatus configured in the MBB device, the MBB device being electrically connected to the master device, and the apparatus includes:
[0027] A preloading module for the MBB device to execute a preloading program to enable the MBB device to communicate with the master device when the MBB device is powered on and receives the power-on notification from the master device; wherein, the execution time of the preloading program is less than the startup time of the BIOS boot device of the master device.
[0028] A first authentication information sending module for sending the authentication information of the MBB device to the master device for the master device to perform a first authentication on the MBB device according to the authentication information of the MBB device during the startup process of the BIOS boot device; when the first authentication fails, the MBB device loses power.
[0029] A second authentication information obtaining module for obtaining the authentication information of the master device when the first authentication is successful and the master device enters the operating system environment.
[0030] A second authentication module, configured to perform a second authentication on the MBB device according to the authentication information of the master device.
[0031] An unlocking module, configured to determine whether to unlock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state.
[0032] In a fourth aspect, an embodiment of the present invention further provides an MBB device authentication apparatus, configured in a master device, the master device being electrically connected to the MBB device, the apparatus including:
[0033] A power-on notification module, configured to power on the MBB device and notify the MBB device to boot up when the BIOS boot device of the master device starts.
[0034] A first authentication module, configured to, if receiving the authentication information of the MBB device during the BIOS boot device startup process, perform a first authentication on the MBB device according to the authentication information of the MBB device; if the first authentication fails, remove the power supply of the MBB device.
[0035] A second authentication module, configured to, if the first authentication is successful and when the master device enters the operating system environment, send the authentication information of the master device to the MBB device for the MBB device to perform a second authentication according to the authentication information of the master device; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state, and when the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
[0036] In a fifth aspect, an embodiment of the present invention further provides an MBB device, electrically connected to a master device, the MBB device including: a memory and a processor, the memory storing a computer program, and the processor running the computer program to implement the MBB device authentication method as described above.
[0037] In a sixth aspect, an embodiment of the present invention further provides a master device, electrically connected to an MBB device, the master device including: a memory and a processor, the memory storing a computer program, and the processor running the computer program to implement the MBB device authentication method as described above.
[0038] In a seventh aspect, an embodiment of the present invention further provides a computer-readable storage medium, having a computer program stored thereon, and the program, when executed by a processor, implements the MBB device authentication method as described in any embodiment of the present invention.
[0039] In an embodiment of the present invention, when the BIOS boot device starts, the master device powers on the MBB device and notifies the MBB device to boot up. When the MBB device is powered on and receives the boot notification from the master device, it executes a preloading program to enable communication between the MBB device and the master device, and sends the authentication information of the MBB device to the master device. During the startup process of the BIOS boot device, the master device performs a first authentication on the MBB device based on the authentication information of the MBB device. When the first authentication fails, the master device removes the power supply of the MBB device, so that the MBB device that fails the first authentication cannot be used on the master device. When the first authentication is successful and the master device enters the operating system environment, the MBB device obtains the authentication information of the master device and performs a second authentication on the MBB device based on the authentication information of the master device. The MBB device defaults its mobile broadband communication function to the disabled state and unlocks it when the second authentication is successful, otherwise it remains in the disabled state. Therefore, the MBB device can be authenticated during the startup process of the master device through the first authentication, and the MBB device can be authenticated in the operating system environment through the second authentication, realizing two-way authentication between the MBB device and the master device, and disabling the MBB device when the authentication fails respectively, thus greatly improving the matching and security of the use of the MBB device and the master device. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a schematic structural diagram of an authentication system for an MBB device authentication method provided by an embodiment of the present invention;
[0041] Figure 2 is a schematic flowchart of an MBB device authentication method provided by Embodiment 1 of the present invention;
[0042] Figure 3 is a schematic flowchart of the first authentication in the MBB device authentication method provided by an embodiment of the present invention;
[0043] Figure 4 is a schematic flowchart of the second authentication in the MBB device authentication method provided by an embodiment of the present invention;
[0044] Figure 5 is a schematic flowchart of an MBB device authentication method provided by Embodiment 2 of the present invention;
[0045] Figure 6 is a schematic block diagram of an MBB device authentication apparatus provided by Embodiment 3 of the present invention;
[0046] Figure 7 is a schematic block diagram of an MBB device authentication apparatus provided by Embodiment 4 of the present invention;
[0047] Figure 8 is a schematic structural diagram of an MBB device provided by Embodiment 5 of the present invention;
[0048] Figure 9 It is a schematic structural diagram of the master device provided in Embodiment 6 of the present invention. Detailed implementation manners
[0049] To make the objectives, technical solutions and advantages of the present invention clearer, the following will refer to the accompanying drawings in the embodiments of the present invention and clearly and completely describe the technical solutions of the present invention through implementation manners. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0050] Figure 1 It is a schematic structural diagram of an authentication system for the MBB device authentication method provided in an embodiment of the present invention. The authentication system includes a master device and an MBB device. The master device and the MBB device are electrically connected and can communicate through a PCIE / USB link and an MBIM protocol, etc. The master device can be a computing device such as a notebook computer or a PC that supports the MBB device interface. The master device performs a first authentication on the MBB device during the boot process. When the first authentication fails, the power supply of the MBB device can be removed to prevent an unmatched MBB device from being used on the master device. At the same time, after the master device enters the operating system environment, it also cooperates with the MBB device to perform a second authentication on it. And only when the second authentication is successful can the MBB device enable the mobile broadband communication function that is default disabled by it. The master device and the MBB device achieve two-way authentication between the master device and the MBB device through the first authentication during the boot process and the second authentication in the operating system environment, which can greatly improve the matching and security of the use of the MBB device and the master device.
[0051] First, the first authentication and the second authentication will be introduced in detail taking the MBB device as an example.
[0052] Figure 2 It is a flowchart of the MBB device authentication method provided in Embodiment 1 of the present invention. The technical solution of this embodiment is applicable to two-way identity authentication between an MBB device and a master device. This method can be executed by an MBB device authentication device provided in an embodiment of the present invention. The device can be implemented in a software and / or hardware manner and is configured in the MBB device application. As Figure 1 shown, this method specifically includes the following steps 201 to 204.
[0053] Step 201: When the MBB device is powered on and receives the boot notification from the master device, execute a preloading program to enable the MBB device to communicate with the master device.
[0054] Among them, the execution time of the preloading program is less than the BIOS boot device startup time of the master device.
[0055] Please refer to Figure 3 the first authentication process between the MBB device and the host device as shown. After the host device is powered on, it boots the device to enter the operating system through the BIOS (Basic Input Output System). After the host device is powered on, it powers on the MBB device inserted into its MBB device card slot and notifies the MBB device to power on. Specifically, when the power key of the host device is pressed, the BIOS turns on the power of the MBB device card slot (slot VCC), and the slot powers on the MBB device. After the power is stable (about 1 second after power on), along with pulling up the FUL_CARD_POWER_OFF (i.e., the Power_key power-on signal of the MBB device) GPIO (General Purpose Input Output) signal in the MBB device card slot, at this time, the FUL_CARD_POWER_OFF GPIO of the MBB device card slot is synchronously pulled to the power-on signal pin of the MBB device to notify the MBB device to power on. Since the BIOS boots the device in a short time, usually within a few seconds, it is required that the USB interface of the MBB device must be in place within 1 - 2 seconds after power on, that is, it can be recognized by the BIOS of the host device and does not affect the normal power-on process.
[0056] Currently, the complete loading process of the MBB device takes dozens of seconds, such as about 20 seconds. In this kind of loading process, the BIOS of the host device cannot recognize the MBB device during the power-on process, so the MBB device cannot provide its own authentication information to the host device during the BIOS startup process. In step 201, the MBB device is configured to immediately execute a preloading program after power on so that the MBB device can communicate with the host device and provide the feature information of the MBB device as authentication information.
[0057] The MBB device executes the SBL (Second Boot Loader) that can make the PCIE / USB in place as the preloading program. The execution time of this preloading program, that is, the time required for the MBB device to make the PCIE / USB in place from receiving the power-on notification is less than the BIOS boot time of the device. The MBB device executes the SBL after power on and can make the PCIE / USB interface in place after about 500ms, enabling the MBB device to provide information such as its PID / VID / interface type to the host device as the authentication information of the MBB device.
[0058] Step 202: Send the authentication information of the MBB device to the host device for the host device to perform the first authentication on the MBB device according to the authentication information of the MBB device during the BIOS boot process of the device.
[0059] After the PCIE / USB interface of the MBB device is connected, it provides information such as the PID / VID / interface type of the MBB device to the host device as the authentication information of the MBB device. The authentication information of the MBB device can also be the PID or VID information of a separate MBB device or other information, which is not specifically restricted here. The host device can compare the received authentication information of the MBB device with the pre-stored MBB device signature list. If the comparison is successful, it means the first authentication is passed; otherwise, the first authentication is considered failed. When the first authentication fails, the MBB device loses power and the loading of the MBB device is prohibited. Generally, the host device BIOS can attempt to detect whether there is a PCIE / USB device in the MBB device card slot and attempt PCIE / USB enumeration 1 - 2 seconds after power-on. The MBB device and the host device can communicate through the MBIM (Mobile Broadband Interface Model, hereinafter referred to as MBIM) interface. The PCIE / USB communication bus is used under the MBIM interface. When the PCIE / USB bus successfully shakes hands with the BIOS, it means that the host device successfully enumerates the MBB device PCIE / USB. The host device further determines whether the PCIE / USB enumeration passes and whether the authentication information of the MBB device is legal. If the PCIE / USB enumeration fails or the authentication information of the MBB device is illegal, it is determined that the first authentication fails. At this time, the power supply of the MBB device card slot is cut off and the loading of the MBB device is prohibited; if the PCIE / USB enumeration passes and the authentication information of the MBB device is legal, it is determined that the first authentication passes, and then the BIOS boots into the OS.
[0060] Step 203: When the first authentication is successful and the host device enters the operating system environment, obtain the authentication information of the host device.
[0061] Step 204: Perform a second authentication on the MBB device according to the authentication information of the host device, and determine whether to lift the ban on the mobile broadband communication function of the MBB device according to the authentication result of the second authentication. Among them, the mobile broadband communication function of the MBB device is default configured to the disabled state.
[0062] Determining whether to unblock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication may include: if the second authentication succeeds, enabling the Modem function of the MBB device to restore the mobile broadband communication function of the MBB device; if the second authentication fails, keeping disabling the Modem function of the MBB device. Specifically, the Modem RF function of the MBB device is configured to be disabled by default. When the second authentication succeeds, the MBB device turns on the RF function of the Modem to restore the Modem to work; when the second authentication fails, the Modem RF function of the MBB device remains disabled, and the OS has no authority to turn on its RF function. Therefore, although the MBB device is visible in the OS of the master device, it cannot be used.
[0063] Combine the following Figure 4 The second authentication process between the MBB device and the master device is described in detail. The master device enters the OS after the first authentication succeeds, and the MBB device can also be started after the master device enters the OS. The RF function of the MBB device modem is configured to be off by default. The MBB device can request the master device to provide the authentication information of the master device. For example, the authentication information of the master device is the BIOS version information of the master device, which is not specifically limited here. The master device can collect its authentication information and return it to the MBB device. After receiving the authentication information of the master device, the MBB device verifies the legitimacy of the authentication information, that is, performs the second authentication. Specifically, the MBB device can compare the BIOS version information of the master device with the preset legal BIOS signature list. When the BIOS version information of the master device exists in the preset legal BIOS signature list, it is considered that the second authentication is passed. Otherwise, it is considered that the second authentication fails. The MBB device can notify the master device of the authentication result of the second authentication. At the same time, when the second authentication succeeds, the MBB device can release the RF function off state of the modem, that is, turn on the RF function of the modem, so that the modem can resume working and perform mobile broadband communication.
[0064] In some examples, the authentication information of the master device can be the encrypted information of the BIOS feature information of the master device. Correspondingly, performing a second authentication on the MBB device according to the authentication information of the master device can include: the MBB device comparing the encrypted information of the BIOS feature information of the master device with a preset list of legal BIOS ciphertext signatures to determine whether the MBB device passes the second authentication. Specifically, the master device can encrypt the BIOS feature information using a symmetric or asymmetric encryption algorithm, etc., to prevent the BIOS feature information from being illegally obtained. After receiving the encrypted BIOS feature information, the MBB device can directly compare it with the preset list of legal BIOS ciphertext signatures, that is, the preset list of legal BIOS ciphertext signatures stores the encrypted information of the legal BIOS feature information. If the comparison is successful, it is considered to pass the second authentication, otherwise, the second authentication is considered to fail.
[0065] Compared with the prior art, in the process of the master device booting up, by preloading the MBB device, the master device can recognize the MBB device during the BIOS startup process and authenticate the feature information of the MBB device, thereby implementing the first authentication. After the master device enters the OS, the MBB device performs a second authentication on the master device by obtaining the authentication information of the master device, and only opens the Modem function of the MBB device after the second authentication is successful, otherwise keeps the Modem function in the off state. Thus, through the first authentication and the second authentication, two-way authentication between the MBB device and the master device is achieved, so that only the MBB device that passes the two-way authentication can be used normally on the master device, ensuring the matching and security of the MBB device and the master device. If the MBB device fails to pass the first authentication, the failed MBB device can be detected at an earlier stage in the master device production line, and it is also beneficial to ensure that the MBB device is used on the master device of a specific manufacturer to solve the related problems mentioned in the background art.
[0066] Next, the first authentication and the second authentication will be introduced in detail taking the master device side as an example.
[0067] Figure 5 It is a flowchart of the MBB device authentication method provided in the second embodiment of the present invention. The technical solution of this embodiment can be applied to the two-way identity authentication between the MBB device and the master device. This method can be executed by an MBB device authentication device provided in the embodiments of the present invention. The device can be implemented in a software and / or hardware manner and is configured in the master device application. As Figure 5 shown, this method specifically includes the following steps 501 to step 504.
[0068] Step 501: Power on the MBB device and notify the MBB device to boot up when the BIOS boot device of the master device starts.
[0069] Step 502: If the authentication information of the MBB device is received during the BIOS boot device startup process, perform the first authentication on the MBB device according to the authentication information of the MBB device.
[0070] If the first authentication fails, remove the power supply of the MBB device.
[0071] Step 502: If the first authentication is successful and when the host device enters the operating system environment, send the authentication information of the host device to the MBB device for the MBB device to perform the second authentication according to the authentication information of the host device.
[0072] Among them, the mobile broadband communication function of the MBB device is default configured to the disabled state. When the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
[0073] Please continue to refer to Figure 3 , and first elaborate on the first authentication process between the host device and the MBB device in detail.
[0074] After the host device is powered on, it starts up through the BIOS boot device and enters the OS. After the host device is powered on, it powers on the MBB device inserted into its MBB device card slot and notifies the MBB device to power on. Specifically, when the power-on button of the host device is pressed, the BIOS turns on the power supply VCC of the MBB device card slot, and the card slot powers on the MBB device. After the power supply of the host device is stable about 1 second after power-on, along with pulling up the FUL_CARD_POWER_OFF GPIO signal in the MBB device card slot, at this time, the FUL_CARD_POWER_OFF GPIO of the MBB device card slot is synchronously pulled to the power-on signal pin of the MBB device to notify the MBB device to power on. Since the startup time of the BIOS boot device is short, usually within a few seconds, it is required that the PCIE / USB interface of the MBB device must be in place within 1 to 2 seconds after power-on, that is, it can be recognized by the BIOS of the host device and does not affect the normal startup process.
[0075] Currently, the complete loading process of the MBB device takes dozens of seconds, such as about 20 seconds. The BIOS of the host device cannot recognize the MBB device during the startup process with this kind of loading process. Therefore, the MBB device cannot provide its own authentication information to the host device during the BIOS startup process. The MBB device is configured to immediately execute a preloading program after power-on so that the MBB device can communicate with the host device and provide the feature information of the MBB device as authentication information.
[0076] The MBB device executes the SBL that can make the PCIE / USB in place as a pre-loader. The execution time of this pre-loader, that is, the time required for the MBB device to make the PCIE / USB in place from receiving the power-on notification is less than the BIOS boot device startup time. After power-on, the MBB device executes the SBL and can make the PCIE / USB interface in place after about 500 ms, enabling the MBB device to provide information such as its PID / VID / interface type to the host device as the authentication information of the MBB device.
[0077] After the PCIE / USB interface of the MBB device is accessed, it provides information such as the PID / VID / interface type of the MBB device to the host device as the authentication information of the MBB device. The authentication information of the MBB device can also be the PID or VID information of a separate MBB device or other information, which is not specifically restricted here. The host device can compare the received authentication information of the MBB device with the pre-stored MBB device signature list. If the comparison is successful, it means the first authentication is passed; otherwise, the first authentication is considered failed. When the first authentication fails, the host device removes the MBB power supply, powers off the MBB device, and prohibits the MBB device from loading. Generally, the host device BIOS can attempt to detect whether there is a PCIE / USB device in the MBB device card slot and attempt PCIE / USB enumeration about 1 - 2 seconds after power-on, and further determine whether the PCIE / USB enumeration passes and whether the authentication information of the MBB device is legal. If the PCIE / USB enumeration fails or the authentication information of the MBB device is illegal, it is determined that the first authentication fails, and at this time, the power supply of the MBB device card slot is cut off to prohibit the MBB device from loading; if the PCIE / USB enumeration passes and the authentication information of the MBB device is legal, it is determined that the first authentication is passed, and then the BIOS boots into the OS.
[0078] Please continue to refer to Figure 4 , and then a detailed description of the second authentication process between the host device and the MBB device will be given.
[0079] The master device enters the OS after the first authentication succeeds, and the MBB device can also be started after the master device enters the OS. The RF function of the MBB device Modem is configured to be off by default. The MBB device may request the master device to provide the authentication information of the master device. For example, the authentication information of the master device is the BIOS version information of the master device, which is not specifically limited here. The master device may collect its authentication information and return it to the MBB device. After receiving the authentication information of the master device, the MBB device verifies its legitimacy, that is, performs the second authentication. Specifically, the MBB device may compare the BIOS version information of the master device with the preset legal BIOS signature list. When the BIOS version information of the master device exists in the preset legal BIOS signature list, it is considered that the second authentication is passed. Otherwise, it is considered that the second authentication fails. The MBB device may notify the master device of the authentication result of the second authentication. At the same time, when the second authentication succeeds, the MBB device may release the RF function off state of the Modem, that is, turn on the RF function of the Modem, so that the Modem can resume working and perform mobile broadband communication.
[0080] It should be noted that both the authentication information of the MBB device and the authentication information of the master device may be encrypted using an encryption algorithm to further improve the security of authentication, and no specific limitation is made here.
[0081] Compared with the prior art, in the present embodiment, during the booting process of the main device, the MBB device is preloaded so that the main device can identify the MBB device during the BIOS startup process, and authenticate the characteristic information of the MBB device, thereby implementing the first authentication. After the main device enters the OS, the MBB device performs the second authentication on the main device by obtaining the authentication information of the main device, and only turns on the modem function of the MBB device after the second authentication succeeds, otherwise the modem function remains in the off state. Thus, the two-way authentication between the MBB device and the main device is implemented through the first authentication and the second authentication, so that only the MBB device that passes the two-way authentication can be used normally on the main device, ensuring the matching and security of the MBB device and the main device. If the MBB device fails to pass the first authentication, the failed MBB device can be detected at an early stage of the main device production line, which is conducive to ensuring that the MBB device is used on the main device of a specific manufacturer, so as to solve the related problems mentioned in the background technology.
[0082] Figure 6It is a structural block diagram of an MBB device authentication apparatus provided in the third embodiment. The embodiment of the present invention also provides an MBB device authentication apparatus 600, configured at the MBB device side. The MBB device is electrically connected to the master device, and the MBB device is used to execute the MBB device authentication method provided in the first embodiment above. The MBB device authentication apparatus 600 includes: a preloading module 601, a first authentication information sending module 602, a second authentication information obtaining module 603, a second authentication module 604, and an unlocking module 605.
[0083] Among them, the preloading module 601 is used for the MBB device to execute a preloading program when powered on and receiving a startup notification from the master device, so that the MBB device can communicate with the master device; wherein, the execution time of the preloading program is less than the BIOS boot device startup time of the master device.
[0084] The first authentication information sending module 602 is used to send the authentication information of the MBB device to the master device for the master device to perform a first authentication on the MBB device according to the authentication information of the MBB device during the BIOS boot device startup process; when the first authentication fails, the MBB device loses power.
[0085] The second authentication information obtaining module 603 is used to obtain the authentication information of the master device when the first authentication is successful and the master device enters the operating system environment.
[0086] The second authentication module 604 is used to perform a second authentication on the MBB device according to the authentication information of the master device.
[0087] The unlocking module 605 is used to determine whether to unlock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state.
[0088] Optionally, the unlocking module 605 is used to enable the Modem function of the MBB device to restore the mobile broadband communication function of the MBB device if the second authentication is successful, and to keep the Modem function of the MBB device disabled if the second authentication fails.
[0089] Optionally, the authentication information of the master device is the encrypted information of the BIOS feature information of the master device. Correspondingly, the second authentication module 604 is used for the MBB device to compare the encrypted information of the BIOS feature information of the master device with a preset legal BIOS ciphertext signature list to determine whether the MBB device passes the second authentication.
[0090] The authentication device of this embodiment realizes mutual authentication between the MBB device and the master device through the first authentication and the second authentication, so that only the MBB device that passes the mutual authentication can be used normally on the master device, ensuring the compatibility and security of the MBB device and the master device.
[0091] Figure 7 It is the structural block diagram of an MBB device authentication device provided in the fourth embodiment. The embodiment of the present invention also provides an MBB device authentication device 700, which is configured at the master device end. The MBB device is electrically connected to the master device, and the master device is used to execute the MBB device authentication method provided in the second embodiment above. The MBB device authentication device 700 includes: a boot notification module 701, a first authentication module 702, and a second authentication module 703.
[0092] Among them, the boot notification module 701 is used to power on the MBB device and notify the MBB device to boot when the BIOS boot device of the master device starts.
[0093] The first authentication module 702 is used to, if the authentication information of the MBB device is received during the startup process of the BIOS boot device, perform the first authentication on the MBB device according to the authentication information of the MBB device; if the first authentication fails, remove the power supply of the MBB device.
[0094] The second authentication module 703 is used to, if the first authentication is successful and when the master device enters the operating system environment, send the authentication information of the master device to the MBB device for the MBB device to perform the second authentication according to the authentication information of the master device; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state, and when the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
[0095] Optionally, the authentication information of the MBB device includes: the PID information of the MBB device and / or the VID information of the MBB device. The first authentication module 702 is used to, if the authentication information of the MBB device exists in the preset legal MBB signature list in the master device, the first authentication is successful; if the authentication information of the MBB device does not exist, the first authentication fails.
[0096] The second authentication module 703 can adopt a similar manner to that in the third embodiment, which will not be elaborated here.
[0097] The authentication device of this embodiment realizes mutual authentication between the MBB device and the master device through the first authentication and the second authentication, so that only the MBB device that passes the mutual authentication can be used normally on the master device, ensuring the compatibility and security of the MBB device and the master device.
[0098] Embodiment 5 of the present invention further provides an MBB device, and the MBB device is electrically connected to the master device. As Figure 8 shown, the MBB device includes: a memory 802 and a processor 801;
[0099] Wherein, the memory 802 stores instructions executable by the at least one processor 801, and the instructions are executed by the at least one processor 801 to implement the MBB device authentication method described in the foregoing embodiments.
[0100] The MBB device includes one or more processors 801 and a memory 802. Figure 8 Taking one processor 801 as an example. The processor 801 and the memory 802 can be connected by a bus or other means. Figure 8 Taking connection by bus as an example. The memory 802, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The processor 801 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions, and modules stored in the memory 802, that is, to implement the above-mentioned MBB device authentication method.
[0101] The memory 802 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function. In addition, the memory 802 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices.
[0102] One or more modules are stored in the memory 802, and when executed by one or more processors 801, they execute the MBB device authentication method in Embodiment 1 above.
[0103] The above device can execute the method provided by the embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method. For technical details not described in detail in this embodiment, reference can be made to the method provided by the embodiment of the present invention.
[0104] The MBB device of this embodiment realizes two-way authentication between the MBB device and the master device through the first authentication and the second authentication, so that only the MBB device that has passed the two-way authentication can be used normally on the master device, ensuring the matching and security of the MBB device and the master device.
[0105] Embodiment 6 of the present invention further provides a master device, and the master device is electrically connected to the MBB device. As Figure 9 shown, the master device includes: a memory 902 and a processor 901;
[0106] Among them, the memory 902 stores instructions executable by the at least one processor 901, and the instructions are executed by the at least one processor 901 to implement the MBB device authentication method described in the foregoing embodiments.
[0107] The master device includes one or more processors 901 and a memory 902. Figure 9 Here, one processor 901 is taken as an example. The processor 901 and the memory 902 can be connected through a bus or other means. Figure 9 Here, taking the connection through a bus as an example. The memory 902, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The processor 901 executes various functional applications and data processing of the device by running the non-volatile software programs, instructions, and modules stored in the memory 902, that is, implements the above MBB device authentication method.
[0108] The memory 902 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function. In addition, the memory 902 may include a high-speed random access memory, and may also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices.
[0109] One or more modules are stored in the memory 902, and when executed by one or more processors 901, implement the MBB device authentication method in the first embodiment above.
[0110] The master device of this embodiment realizes two-way authentication between the MBB device and the master device through the first authentication and the second authentication, so that only the MBB device that passes the two-way authentication can be used normally on the master device, ensuring the matching and security of the MBB device and the master device.
[0111] Embodiment 7 of the present invention also relates to a non-volatile storage medium for storing a computer-readable program, and the computer-readable program is used for a computer to execute the above partial or all method embodiments.
[0112] That is, those skilled in the art can understand that all or part of the steps in the methods of the above embodiments can be completed by instructing relevant hardware through a program. The program is stored in a storage medium, including several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.
[0113] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present invention, and in practical applications, various changes can be made to them in form and details without departing from the spirit and scope of the present invention.
Claims
1. A method for authenticating an MBB device, characterized in that, Applied to an MBB device, the MBB device is electrically connected to a master device, and the method includes: When the MBB device is powered on and receives the boot notification from the master device, execute a preloading program to enable communication between the MBB device and the master device; wherein, the execution time of the preloading program is less than the BIOS boot device startup time of the master device; Send the authentication information of the MBB device to the master device for the master device to perform a first authentication on the MBB device according to the authentication information of the MBB device during the BIOS boot device startup process; when the first authentication fails, the MBB device loses power; When the first authentication is successful and the master device enters the operating system environment, obtain the authentication information of the master device, perform a second authentication on the MBB device according to the authentication information of the master device, and determine whether to lift the ban on the mobile broadband communication function of the MBB device according to the authentication result of the second authentication; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state.
2. The MBB device authentication method according to claim 1, wherein Determining whether to lift the ban on the mobile broadband communication function of the MBB device according to the authentication result of the second authentication includes: If the second authentication is successful, enable the Modem function of the MBB device to restore the mobile broadband communication function of the MBB device; if the second authentication fails, keep the Modem function of the MBB device disabled.
3. The MBB device authentication method according to claim 1, wherein The authentication information of the master device is the encrypted information of the BIOS feature information of the master device; Accordingly, performing a second authentication on the MBB device according to the authentication information of the master device includes: The MBB device compares the encrypted information of the BIOS feature information of the master device with a preset list of legal BIOS ciphertext signatures to determine whether the MBB device passes the second authentication.
4. A method for authenticating an MBB device, characterized in that, Applied to a master device, the master device is electrically connected to an MBB device, and the method includes: Power on the MBB device and notify the MBB device to boot when the BIOS boot device of the master device starts; If the authentication information of the MBB device is received during the BIOS boot device startup process, perform a first authentication on the MBB device according to the authentication information of the MBB device; if the first authentication fails, remove the power supply of the MBB device; If the first authentication is successful and when the master device enters the operating system environment, send the authentication information of the master device to the MBB device for the MBB device to perform a second authentication according to the authentication information of the master device; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state, and when the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
5. The MBB device authentication method according to claim 4, wherein The authentication information of the MBB device includes: the PID information of the MBB device and / or the VID information of the MBB device; Performing a first authentication on the MBB device according to the authentication information of the MBB device includes: If the authentication information of the MBB device exists in the preset legal MBB signature list in the master device, the first authentication is successful; if the authentication information of the MBB device does not exist, the first authentication fails.
6. An MBB device authentication apparatus, configured in an MBB device, the MBB device being electrically connected to a master device, characterized in that, The device includes: A preloading module, configured to execute a preloading program when the MBB device is powered on and receives a boot notification from the master device, so that the MBB device can communicate with the master device; wherein, the execution time of the preloading program is less than the startup time of the BIOS boot device of the master device; A first authentication information sending module, configured to send the authentication information of the MBB device to the master device for the master device to perform a first authentication on the MBB device according to the authentication information of the MBB device during the startup process of the BIOS boot device; when the first authentication fails, the MBB device loses power; A second authentication information obtaining module, configured to obtain the authentication information of the master device when the first authentication is successful and the master device enters the operating system environment; A second authentication module, configured to perform a second authentication on the MBB device according to the authentication information of the master device, An unlocking module, configured to determine whether to unlock the mobile broadband communication function of the MBB device according to the authentication result of the second authentication; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state.
7. An MBB device authentication apparatus, configured in a master device, the master device being electrically connected to the MBB device, characterized in that, The device includes: A boot notification module, configured to power on the MBB device and notify the MBB device to boot when the BIOS boot device of the master device starts up; A first authentication module, configured to perform a first authentication on the MBB device according to the authentication information of the MBB device if the authentication information of the MBB device is received during the startup process of the BIOS boot device; if the first authentication fails, remove the power supply of the MBB device; A second authentication module, configured to send the authentication information of the master device to the MBB device for the MBB device to perform a second authentication according to the authentication information of the master device if the first authentication is successful and when the master device enters the operating system environment; wherein, the mobile broadband communication function of the MBB device is default configured to be in a disabled state, and when the second authentication fails, the MBB device keeps the mobile broadband communication function of the MBB device disabled.
8. An MBB device, electrically connected to the master device, characterized in that, The MBB device includes: a memory and a processor, the memory stores a computer program, and the processor runs the computer program to implement the MBB device authentication method according to any one of claims 1 to 3.
9. A master device, electrically connected to an MBB device, characterized in that The master device includes: a memory and a processor, the memory stores a computer program, and the processor runs the computer program to implement the MBB device authentication method according to claim 4 or 5.
10. A computer-readable storage medium, characterized in that, For storing a computer-readable program, the computer-readable program is used for a computer to execute the MBB device authentication method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Information protection system and method based on mobile data safety
CN101795261A
Data processing method during starting of intelligent device and intelligent device
CN104102695A