Information security protection method and computing device

By sending the identity information of computing devices and hardware devices to the IAM and receiving the IAM digital signature results, the problem that the cloud tenant identity authentication protection cannot prevent the identity information of computing devices from being tampered with is solved, and the security protection of computing device information is realized.

CN114024702BActive Publication Date: 2025-06-06HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202010846754.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-07-17
Filing Date
2020-08-21
Publication Date
2025-06-06
Estimated Expiration
2040-08-21

AI Technical Summary

Technical Problem

Existing cloud tenant identity authentication protection cannot effectively prevent identity information on computing devices from being tampered with, especially if it is accidentally or maliciously changed by operation and maintenance personnel.

Method used

The computing device sends its first information and the identity information of the hardware device to the unified identity authentication IAM, and receives the public key and digital signature results of the IAM to ensure that the identity information of the hardware device is fixed and unchanged, thereby preventing the identity information from being tampered with.

Benefits of technology

It realizes security protection of information on computing devices to prevent attackers or operation and maintenance personnel from tampering with or replacing the identity information of computing devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114024702B_ABST
    Figure CN114024702B_ABST
Patent Text Reader

Abstract

The present application provides a method for information security protection and a computing device, wherein a hardware device is connected to the computing device, and the method comprises: the computing device sends first information on the computing device and identity information of the hardware device to a unified identity authentication system (IAM); the computing device receives the public key of the IAM and a first digital signature result sent by the IAM, wherein the first digital signature result is the result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM. The technical solution of the present application can prevent the information on the computing device from being tampered with.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information technology security technology, and more specifically, to an information security protection method and computing device. Background Art

[0002] The existing cloud tenant identity authentication protection usually uses unified identity authentication (identity and access management, IAM). The IAM management system is a basic service for permission management provided by many cloud service infrastructure providers, which can help tenants securely control the access rights of cloud services and resources purchased by tenants.

[0003] However, IAM cannot provide strong identity information protection for cloud service infrastructure, such as computing devices. In other words, the identity information on the computing device can be easily tampered with or replaced by others, or the operation and maintenance personnel provided by the cloud service infrastructure can intentionally or unintentionally change the identity information of the computing device.

[0004] Therefore, how to prevent the identity information on the computing device from being tampered with becomes an issue that needs to be solved urgently. Summary of the invention

[0005] The present application provides an information security protection method and a computing device, which can prevent information on the computing device from being tampered with.

[0006] In a first aspect, a method for information security protection is provided, including: a computing device sends first information on the computing device and identity information of a hardware device to a unified identity authentication IAM; the computing device receives the IAM's public key and a first digital signature result sent by the IAM, and the first digital signature result is a result of the IAM digitally signing the first information and the identity information of the hardware device based on the IAM's private key.

[0007] In the above technical solution, the hardware device will generate the identity information of the hardware device and burn it into the hardware device before leaving the factory, so the identity information of the hardware device is fixed. In this way, the first information of the computing device and the identity information of the hardware device are digitally signed by the private key of the IAM, the identity information of the hardware device is fixed, and the first information of the computing device is also fixed, thereby preventing the computing device from being tampered with or replaced by attackers after leaving the factory, or being changed by the operation and maintenance personnel provided by the cloud service infrastructure, thereby realizing the security protection of information on the computing device.

[0008] In a possible implementation manner, the method further includes: receiving, by the computing device, identity information of the hardware device sent by the hardware device.

[0009] In another possible implementation manner, the method further includes: the computing device sending the public key of the IAM and the first digital signature result to the hardware device.

[0010] In another possible implementation, the hardware device is a baseboard management controller BMC, and the identity information of the hardware device is an identification ID of the BMC.

[0011] In another possible implementation, the first information includes any one or more combinations of the following: the name of the computing device, the Internet Protocol IP address of the computing device, and the ID of the software running on the computing device.

[0012] In another possible implementation, the method further includes: the computing device and the hardware apparatus negotiating a communication key, where the communication key is used to encrypt data transmitted between the computing device and the hardware apparatus.

[0013] In the above technical solution, the computing device and the hardware device can encrypt the transmitted data through the negotiated communication key, thereby further realizing the security of information transmission between the computing device and the hardware device.

[0014] In another possible implementation, the computing device receives first key generation information sent by the hardware device, where the first key generation information is determined by the hardware device based on a first random number; the computing device determines a first key based on the first key generation information and second key generation information, where the second key generation information is determined by the computing device based on a second random number, and the first key is used by the computing device to encrypt data sent to the hardware device.

[0015] In another possible implementation, the method also includes: the computing device sends the second key generation information to the hardware device, so that the hardware device generates a second key based on the first key generation information and the second key generation information, and the second key is used by the hardware device to encrypt data sent to the computing device.

[0016] In another possible implementation, the method also includes: the computing device encrypting the data and the identity key based on the communication key; the computing device sending the encrypted data and the identity key to the hardware device; the computing device receiving a second digital signature result sent by the hardware device, the second digital signature result being the result of the hardware device digitally signing the data based on the identity key.

[0017] In a second aspect, a computing device is provided, wherein a hardware device is connected to the computing device, and the computing device comprises:

[0018] A sending module, configured to send the first information on the computing device and the identity information of the hardware device to a unified identity authentication IAM;

[0019] The receiving module is used to receive the public key of the IAM and the first digital signature result sent by the IAM, where the first digital signature result is the result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM.

[0020] In a possible implementation manner, the receiving module is further configured to: receive identity information of the hardware device sent by the hardware device.

[0021] In another possible implementation manner, the sending module is further used to: send the public key of the IAM and the first digital signature result to the hardware device.

[0022] In another possible implementation, the hardware device is a baseboard management controller BMC, and the identity information of the hardware device is an identification ID of the BMC.

[0023] In another possible implementation, the first information includes any one or more combinations of the following: the name of the computing device, the Internet Protocol IP address of the computing device, and the ID of the software running on the computing device.

[0024] In another possible implementation, the computing device further includes:

[0025] The processing module is used to negotiate a communication key with the hardware device, and the communication key is used to encrypt data transmitted between the computing device and the hardware device.

[0026] In another possible implementation, the receiving module is further used to: receive first key generation information sent by the hardware device, where the first key generation information is determined by the hardware device according to a first random number;

[0027] The processing module is specifically used to determine a first key based on the first key generation information and the second key generation information, wherein the second key generation information is determined by the computing device based on a second random number, and the first key is used by the computing device to encrypt data sent to the hardware device.

[0028] In another possible implementation, the sending module is also used to: send the second key generation information to the hardware device, so that the hardware device generates a second key based on the first key generation information and the second key generation information, and the second key is used by the hardware device to encrypt data sent to the computing device.

[0029] In another possible implementation, the processing module is further used to: encrypt the data and the identity key based on the communication key;

[0030] The sending module is also used to: send the encrypted data and identity key to the hardware device;

[0031] The receiving module is further used to: receive a second digital signature result sent by the hardware device, where the second digital signature result is a result of the hardware device digitally signing the data based on the identity key.

[0032] The expansion, limitation, explanation, description and effect of the relevant contents in the above-mentioned first aspect also apply to the same contents in the second aspect.

[0033] In a third aspect, a computing device is provided, comprising: a processor and a memory, wherein the processor runs instructions in the memory so that the computing device executes the method steps executed in the above-mentioned first aspect or any possible implementation manner of the first aspect.

[0034] In a fourth aspect, a computer-readable storage medium is provided, comprising instructions; the instructions are used to implement the method steps performed in the first aspect or any possible implementation manner of the first aspect.

[0035] Optionally, as an implementation manner, the above-mentioned storage medium may specifically be a non-volatile storage medium.

[0036] In a fifth aspect, a chip is provided, which obtains instructions and executes the instructions to implement the method for information security protection in the above-mentioned first aspect and any implementation method of the first aspect.

[0037] Optionally, as an implementation method, the chip includes a processor and a data interface, and the processor reads instructions stored in the memory through the data interface to execute the information security protection method in the above-mentioned first aspect and any implementation method of the first aspect.

[0038] Optionally, as an implementation method, the chip may also include a memory, in which instructions are stored, and the processor is used to execute the instructions stored in the memory. When the instructions are executed, the processor is used to execute the information security protection method in the first aspect and any one of the implementation methods of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a schematic diagram of the architecture of a computing device 100 provided in an embodiment of the present application.

[0040] Figure 2 It is a schematic flowchart of a method for information security protection provided in an embodiment of the present application.

[0041] Figure 3 It is a schematic flowchart of another information security protection method provided in an embodiment of the present application.

[0042] Figure 4 It is a schematic flowchart of a method for determining a communication key between a BMC and a UIM on a computing device provided in an embodiment of the present application.

[0043] Figure 5 It is a schematic flowchart of a method for determining a communication key between a BMC and an IAM provided in an embodiment of the present application.

[0044] Figure 6 It is a schematic flowchart of a method for injecting an IAM identity key provided in an embodiment of the present application.

[0045] Figure 7 It is a schematic block diagram of a computing device 700 provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] The following will describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0047] In the various embodiments of the present application, “first”, “second”, “third”, “fourth”, etc. are only used to refer to different objects and do not mean any other limitations on the referred objects.

[0048] In the cloud (for example, public cloud), tenants’ identity authentication protection usually uses unified identity authentication (identity and access management, IAM). The IAM management system is a basic service for permission management provided by many cloud service infrastructure providers, which can help tenants securely control the access rights to the cloud services and resources purchased by tenants.

[0049] However, IAM cannot protect the identity information of cloud service infrastructure, such as computing devices. In other words, the identity information on the computing device can be easily tampered with or replaced by others, or the operation and maintenance personnel provided by the cloud service infrastructure can intentionally or unintentionally change the identity information of the computing device.

[0050] In view of this, the present application proposes a method for information security protection, which can perform security protection on the identity information of a computing device based on hardware, thereby preventing the identity information on the computing device from being tampered with.

[0051] The method for information security protection provided by the embodiment of the present application can be applied to a computing device, which can also be referred to as a computer system, including a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a processing unit, a memory and a memory control unit, and the function and structure of the hardware are described in detail later. The operating system is any one or more computer operating systems that implement business processing through a process, for example, a Linux operating system, a Unix operating system, an Android operating system, an iOS operating system, or a windows operating system. The application layer includes applications such as a browser, an address book, a word processing software, and an instant messaging software. In addition, optionally, the computer system is a handheld device such as a smart phone, or a terminal device such as a personal computer, and the present application is not particularly limited, as long as the method provided by the embodiment of the present application can be used. The execution subject of the method for information security protection provided by the embodiment of the present application can be a computer system, or a functional module in a computer system that can call a program and execute a program.

[0052] Combine the following Figure 1 , a computing device provided in an embodiment of the present application is described in detail.

[0053] Figure 1 1 is a schematic diagram of the architecture of a computing device 100 provided in an embodiment of the present application. The computing device 100 may be a server or a computer or other device with computing capabilities.

[0054] like Figure 1 As shown, a hardware device 130 is connected to the computing device 100. As an example, the hardware device 130 is deployed on the computing device 100 in the form of a bus and a peripheral component interface express (PCIe) slot.

[0055] There may be many types of hardware device 130 , which is not specifically limited in this application. As an example, the hardware device 130 is a baseboard management controller (BMC). BMC is usually an independent board installed on the computing device 100 .

[0056] Take the hardware device 130 as an example, which is a BMC. The boot chip (boot read only memory, bootROM) of the BMC will generate a random number (for example, a 256-bit random number) and burn it into an electronic fuse (eFuse) before leaving the factory.

[0057] It should be understood that an electronic fuse (eFuse) can also be called a one-time programmable memory. As a special read-only chip, it has electronic security features such as resistance to physical attacks and is used in various high-security scenarios.

[0058] It should also be understood that the boot ROM is a small piece of masked ROM or write-protected flash embedded inside the processor chip that contains the first code executed by the processor at power-up or reset. Depending on the configuration of certain strap pins or internal fuses, it can decide from where to load the next part of the code to be executed and how or whether to verify its correctness or validity. Sometimes it may contain other functions that may be used by user code during or after boot.

[0059] Figure 1 The computing device 100 shown includes at least one processor 110 and a memory 120 .

[0060] The processor 110 executes the instructions in the memory 120, so that the computing device 100 implements the information security protection method provided by the present application. Alternatively, the processor 110 executes the instructions in the memory 120, so that the computing device 200 implements the various functional modules provided by the present application.

[0061] Optionally, the computing device 100 further includes a system bus, wherein the processor 110 and the memory 120 are respectively connected to the system bus. The processor 110 can access the memory 120 through the system bus. For example, the processor 110 can read and write data or execute code in the memory 120 through the system bus. The system bus is a peripheral component interconnect express (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The system bus is divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 1Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0062] In a possible implementation, the function of the processor 110 is mainly to interpret the instructions (or codes) of the computer program and process the data in the computer software. The instructions of the computer program and the data in the computer software can be stored in the memory 120 or the cache 116.

[0063] Optionally, the processor 110 may be an integrated circuit chip with signal processing capabilities. As an example and not limitation, the processor 110 is a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component. Among them, the general-purpose processor is a microprocessor, etc. For example, the processor 110 is a central processing unit (CPU).

[0064] Optionally, each processor 110 includes at least one processing unit 112 and a memory control unit 114 .

[0065] Optionally, the processing unit 112 is also called a core or kernel, which is the most important component of the processor. The processing unit 112 is manufactured from single crystal silicon using a certain production process, and all calculations, command acceptance, command storage, and data processing of the processor are performed by the core. The processing units run program instructions independently and use the ability of parallel computing to speed up the running speed of the program. Various processing units have a fixed logical structure. For example, the processing unit includes logical units such as a first-level cache, a second-level cache, an execution unit, an instruction-level unit, and a bus interface.

[0066] In one implementation example, the memory control unit 114 is used to control data interaction between the memory 120 and the processing unit 112. Specifically, the memory control unit 114 receives a memory access request from the processing unit 112, and controls access to the memory based on the memory access request. As an example and not a limitation, the memory control unit is a device such as a memory management unit (MMU).

[0067] In one implementation example, each memory control unit 114 addresses the memory 120 via the system bus. An arbiter (not shown in the figure) is configured in the system bus, and the arbiter is responsible for processing and coordinating the contention access of multiple processing units 112 .

[0068] In an implementation example, the processing unit 112 and the memory control unit 114 are connected to each other through connection lines inside the chip, such as address lines, so as to achieve communication between the processing unit 112 and the memory control unit 114.

[0069] Optionally, each processor 110 further includes a cache 116, wherein the cache is a buffer for data exchange (called cache). When the processing unit 112 wants to read data, it will first search for the required data from the cache. If it is found, it will be executed directly. If it is not found, it will be searched from the memory. Since the operation speed of the cache is much faster than that of the memory, the role of the cache is to help the processing unit 112 run faster.

[0070] The memory 120 can provide a running space for the processes in the computing device 100. For example, the computer program (specifically, the program code) used to generate the process is stored in the memory 120. After the computer program is executed by the processor to generate the process, the processor allocates a corresponding storage space for the process in the memory 120. Furthermore, the above storage space further includes a text segment, an initialized data segment, a bit initialized data segment, a stack segment, a heap segment, etc. The memory 120 stores the data generated during the running of the process in the storage space corresponding to the above process, such as intermediate data, process data, etc.

[0071] Optionally, the memory is also called internal memory, which is used to temporarily store the calculation data in the processor 110 and the data exchanged with the external memory such as the hard disk. As long as the computer is running, the processor 110 will transfer the data to be calculated to the memory for calculation, and when the calculation is completed, the processing unit 112 will transmit the result.

[0072] As an example and not limitation, memory 120 is a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory is a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory is a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DRRAM). It should be noted that the memory 120 of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0073] The structure of the computing device 100 listed above is only an example, and the present application is not limited thereto. The computing device 100 of the embodiment of the present application includes various hardware in the computer system in the prior art. For example, the computing device 100 also includes other memories besides the memory 120, such as disk storage, etc. Those skilled in the art should understand that the computing device 100 may also include other devices necessary for normal operation. At the same time, according to specific needs, those skilled in the art should understand that the above-mentioned computing device 100 may also include hardware devices for implementing other additional functions. In addition, those skilled in the art should understand that the above-mentioned computing device 100 may also include only the devices necessary to implement the embodiment of the present application, and does not necessarily include Figure 1 All devices shown in .

[0074] Combine the following Figure 2 , the information security protection method provided by the embodiment of the present application is introduced in detail. The method can be Figure 1 The computing device 100 shown executes to implement the information security protection method provided by the present application.

[0075] Figure 2 is a schematic flow chart of a method for information security protection provided by an embodiment of the present application. Figure 2 As shown, the method may include steps 210-220, and steps 210-220 are described in detail below.

[0076] Step 210: The computing device sends the first information on the computing device and the identity information of the hardware device to the unified identity authentication IAM.

[0077] The first information may include, but is not limited to, any one or more combinations of the following: a name of the computing device, an Internet protocol (IP) address of the computing device, and an identity (ID) of software running on the computing device.

[0078] Optionally, in some embodiments, before step 210, the computing device may also receive identity information of the hardware device sent by the hardware device.

[0079] As an example, the hardware device may be a BMC, and the identity information of the hardware device is the ID of the BMC.

[0080] Step 220: The computing device receives the public key of the IAM and the first digital signature result sent by the IAM.

[0081] The first digital signature result is the result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM.

[0082] It should be understood that the public key and private key are a key pair (i.e., a public key and a private key) obtained through an algorithm, and the key pair obtained through this algorithm can be guaranteed to be unique worldwide. One of them is open to the outside world and is called the public key, while the other is kept by oneself and is called the private key. The public key is usually used to encrypt session keys, verify digital signatures, or encrypt data that can be decrypted with the corresponding private key. When using this key pair, if one of the keys is used to encrypt a piece of data, the other key must be used to decrypt it. If the data is encrypted with the public key, it must be decrypted with the private key. If it is encrypted with the private key, it must also be decrypted with the public key, otherwise the decryption will not be successful.

[0083] There are many methods for determining a key pair (ie, a public key and a private key). As an example, the public-private key pair may be obtained according to an elliptic curve cryptography (ECC) algorithm.

[0084] Network security, mainly network information security, requires the adoption of corresponding security technical measures and the provision of appropriate security services. As one of the means to ensure network information security, the digital signature mechanism can solve the problems of forgery, denial, impersonation and tampering. One of the purposes of digital signature is to replace traditional manual signatures and seals in the network environment, which plays an important role.

[0085] A digital signature (also known as a public key digital signature) is a string of numbers that can only be generated by the sender of the information and cannot be forged by others. This string of numbers is also an effective proof of the authenticity of the information sent by the sender. It is a method for authenticating digital information, similar to an ordinary physical signature written on paper, but it is implemented using technology in the field of public key encryption.

[0086] It should be understood that digital signature is an encryption process, and digital signature verification is a decryption process.

[0087] Digital signatures have two functions: First, they can confirm that the message is indeed signed and sent by the sender, because no one can forge the sender's signature. Second, digital signatures can determine the integrity of the message. Because the characteristic of a digital signature is that it represents the characteristics of a file, if the file changes, the value of the digital summary will also change. Different files will get different digital summaries. A digital signature involves a hash function, the receiver's public key, and the sender's private key.

[0088] In one example, the IAM acts as the sender, and uses a hash function to generate a message digest from the text of the message (e.g., the first information and the identity information of the hardware device), and then encrypts the digest with the IAM's private key. The encrypted digest will be sent to the computing device acting as the receiver together with the message (e.g., the first information and the identity information of the hardware device) as the digital signature of the message (e.g., the first information and the identity information of the hardware device). The computing device uses the same hash function as the sender to calculate the message digest from the received original message, and then uses the IAM's public key sent by the IAM to decrypt the digital signature attached to the message. If the two digests are the same, the computing device acting as the receiver can confirm that the digital signature is from the sender.

[0089] In the above technical solution, the hardware device will generate the identity information of the hardware device and burn it into the hardware device before leaving the factory, so the identity information of the hardware device is fixed. In this way, the first information of the computing device and the identity information of the hardware device are digitally signed by the private key of the IAM, the identity information of the hardware device is fixed, and the first information of the computing device is also fixed, thereby preventing the computing device from being tampered with or replaced by attackers after leaving the factory, or being changed by the operation and maintenance personnel provided by the cloud service infrastructure, thereby realizing the security protection of information on the computing device.

[0090] Combine the following Figure 3 A specific implementation of the information security protection method is described with a specific example. It should be understood that Figure 3 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 3 Those skilled in the art can obviously make various equivalent modifications or changes based on the examples given, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0091] Figure 3 FIG. 1 is a schematic flow chart of another information security protection method provided by an embodiment of the present application. Figure 3 As shown, the method may include steps 310-380, and steps 310-380 are described in detail below.

[0092] Step 310: A user identification module (UIM) on a computing device sends a software ID to a baseboard management controller (BMC).

[0093] It should be understood that UIM can be used as a security application software on a computing device. As an example, the operation and maintenance personnel start the UIM as a security application software through a security code.

[0094] Step 320: The UIM on the computing device sends the identity information of the computing device to the IAM.

[0095] The computing device identity information sent by the UIM on the computing device to the IAM may include but is not limited to any one or more combinations of the following: the name of the computing device, the IP address of the computing device. The UIM sending the computing device identity information to the IAM may indicate that the computing device needs to be registered.

[0096] Step 330: The BMC generates a public key for a strong identity application.

[0097] After receiving the software ID sent by the UIM, the BMC can generate a public key for a strong identity application. The following is an example of a specific implementation process of generating a public key for a strong identity application.

[0098] 1. The BMC determines the UDI-A based on the unique device identification (UDI) of the strong identity application.

[0099] Strong identity applications have a separate private key UDI, which is a random number (for example, a 256-bit random number) generated during the device deployment phase and burned into the electronic fuse (eFuse). As a special read-only chip, eFuse has electronic security features such as resistance to physical attacks and is used in various high-security scenarios.

[0100] BMC is used as a security system to start the device. As a preset action before the startup phase, the boot chip (boot read only memory, boot ROM) of the BMC will generate a random number (for example, a 256-bit random number) and burn it into the eFuse before leaving the factory.

[0101] As an example, the BootROM code may call the DICE engine (the hardware engine or the BootROM code itself) to calculate the UDI.

[0102] In order to prevent subjective and objective malicious behavior of delivery personnel in the Internet data center (IDC) room, UDI cannot be rewritten and can only be read once by the boot ROM after reset. If the read fails after reset, it cannot be read a second time and must be reset again. Operation and maintenance personnel can monitor the real-time reset status of the device and do post-audit work at the same time, forming a supervisory relationship with the delivery personnel.

[0103] In one possible implementation, the BootROM triggers hardware locking and the UDI cannot be accessed again until the next system reset and restart.

[0104] The boot ROM in the BMC can determine UDI-A based on the private key UDI of the strong identity application, a constant (const) and a hash function. It should be understood that const is a constant generated by the key security technique (KST) system in the BMC using the true random number of the security chip. As an example, the boot ROM can pass the private key UDI of the strong identity application and const into the hash message authentication code (HMAC) function to obtain UDI-A, and pass UDI-A to the strong identity application.

[0105] To prevent hacking or direct physical attack, the boot ROM can clear the UDI in the boot ROM after passing the UDI-A to the strong identity application.

[0106] 2. The strong identity application determines the public and private key pair of the strong identity application based on UDI-A.

[0107] After the strong identity application obtains UDI-A from the boot ROM, the public-private key pair of the strong identity application can be determined according to UDI-A. As an example, the strong identity application can use UDI-A as the private key SC_PRI and determine the public key SC_PUB corresponding to the private key SC_PRI according to UDI-A.

[0108] Step 340: The BMC sends the public key of the strong identity application and the chip device ID of the BMC to the UIM on the computing device.

[0109] In a secure environment, the strong identity application in the BMC can send the public key SC_PUB of the strong identity application and the chip device ID of the BMC to the UIM.

[0110] Step 350: The UIM on the computing device sends the public key of the BMC strong identity application, the chip device ID of the BMC, and the identity information of the computing device to the IAM.

[0111] The information sent by UIM to IAM may include, but is not limited to, any one or more combinations of the following: a public key of a strong identity application, a chip device ID of the BMC, a name of the computing device, an IP address of the computing device, and a software ID on the computing device.

[0112] Step 360: The IAM digitally signs the received information.

[0113] IAM can digitally sign the received information based on its own private key. The received information may include but is not limited to any one or more combinations of the following: the public key of the strong identity application, the chip device ID of the BMC, the name of the computing device, the IP address of the computing device, and the software ID on the computing device.

[0114] For the specific process of IAM digitally signing based on its own private key, please refer to the description above and will not be repeated here.

[0115] Step 370: The IAM sends the original information, the digital signature result of the original information, and the public key of the IAM to the UIM on the computing device.

[0116] The above original information may include but is not limited to any one or more combinations of the following: a public key of a strong identity application, a chip device ID of a BMC, a name of a computing device, an IP address of a computing device, and a software ID on a computing device.

[0117] Step 380: The UIM on the computing device sends the original information, the digital signature result of the original information, and the public key of the IAM to the BMC.

[0118] Optionally, in some embodiments, a communication key between the BMC and the UIM on the computing device may also be determined, and when data is transmitted between the BMC and the UIM on the computing device, encryption may be performed based on the communication key, thereby further improving the security of data transmission between the BMC and the UIM on the computing device.

[0119] Combine the following Figure 4 A specific example is given in which a specific implementation method for determining a communication key between a BMC and a UIM on a computing device is described. It should be understood that Figure 4 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 4 Those skilled in the art can obviously make various equivalent modifications or changes based on the examples given, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0120] Figure 4 1 is a schematic flow chart of a method for determining a communication key between a BMC and a UIM on a computing device provided by an embodiment of the present application. Figure 4 As shown, the method may include steps 410-450, and steps 410-450 are described in detail below.

[0121] Step 410: The UIM on the computing device initiates a communication key negotiation request to the BMC.

[0122] After the UIM on the computing device is started, a communication key negotiation request may be initiated to the strong identity application on the BMC. The request is used to request negotiation of a communication key KEY_M3_UIM between the strong identity application and the UIM.

[0123] Step 420: The strong identity application on the BMC generates key generation information 1 (q^a mod p) and a signature.

[0124] The strong identity application on the BMC can call the hardware to generate key generation information 1 (q^a mod p) and signature, and send it to the UIM.

[0125] As an example, the strong identity application calculates and generates a 2048-bit random number a, and calculates the key generation information 1 (q^a mod p), where q and p are public values. The strong identity application can also call the hash module to calculate the hash value of the key generation information 1 (q^a mod p), and use the previously generated private key SC_PRI to sign the key generation information 1 (q^a mod p) with a private key to prove the identity.

[0126] Step 425: The strong identity application on the BMC sends the key generation information 1 (q^a mod p) and the signature to the UIM.

[0127] Step 430: The UIM on the computing device generates a local communication key KEY_M3_UIM according to the key generation information 1 (q^a mod p) sent by the strong identity application.

[0128] After UIM receives the (q^a mod p, signature) sent by the strong identity application, it can verify the signature according to the public key SC_PUB of the strong identity application to prove that the key generation information 1 (q^a mod p) received by UIM is sent by the strong identity application.

[0129] UIM can also call hardware to generate key generation information 2 (q^b mod p) and send it to the strong identity application.

[0130] As an example, UIM can calculate and generate a 2048-bit random number b, and calculate key generation information 2 (q^b mod p), where q and p are public values. UIM can calculate (q^a mod p)^b mod p based on key generation information 1 (q^a mod p), thereby obtaining the communication key KEY_M3_UIM between UIM and the strong identity application.

[0131] In a possible implementation, the elliptic curve digital signature algorithm (ECDSA) can be used to determine the communication key KEY_M3_UIM between UIM and the strong identity application. Specifically, the base point G(x,y) on the elliptic curve can be agreed upon, and G(x,y) is the base point of an elliptic curve algorithm recognized worldwide.

[0132] Step 435: UIM sends key generation information 2 (q^b mod p) to the strong identity application.

[0133] Step 440: The strong identity application generates a local communication key KEY_M3_UIM according to the key generation information 2 (q^b mod p) sent by UIM.

[0134] As an example, after receiving the key generation information 2 (q^b mod p), the strong identity application calculates (q^b mod p)^a mod p according to the key generation information 2 (q^b mod p), thereby obtaining the communication key KEY_M3_UIM between the UIM and the strong identity application.

[0135] Step 450: The strong identity application sends a message to the UIM to notify the UIM that the key negotiation is successful.

[0136] Optionally, in some embodiments, a communication key between the BMC and the IAM may be determined, and when data is transmitted between the BMC and the IAM, encryption may be performed based on the communication key, thereby further improving the security of data transmission between the BMC and the IAM.

[0137] Combine the following Figure 5 A specific example is given in which a specific implementation method for determining the communication key between the BMC and the IAM is described. It should be understood that Figure 5 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 5 Those skilled in the art can obviously make various equivalent modifications or changes based on the examples given, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0138] Figure 5 is a schematic flow chart of a method for determining a communication key between a BMC and an IAM provided in an embodiment of the present application. Figure 5 As shown, the method may include steps 510-580, and steps 510-580 are described in detail below.

[0139] Step 510: The UIM on the computing device initiates a communication key negotiation request to the BMC.

[0140] It should be understood that UIM is a bridge for communication between the strong identity application and IAM. In the process of negotiating the communication key KEY_M3_IAM between the strong identity application and IAM, UIM can perform indirect transmission.

[0141] After the UIM on the computing device is started, it can initiate a communication key negotiation request to the strong identity application on the BMC. The request is used to request negotiation of the communication key KEY_M3_IAM between the strong identity application and the IAM.

[0142] Step 520: The strong identity application on the BMC generates key generation information 1 (q^a mod p) and a signature, and sends it to the UIM.

[0143] The strong identity application on the BMC can call the hardware to generate key generation information 1 (q^a mod p) and signature.

[0144] As an example, the strong identity application calculates and generates a 2048-bit random number a, and calculates the key generation information 1 (q^a mod p), where q and p are public values. The strong identity application can also call the hash module to calculate the hash value of the key generation information 1 (q^a mod p), and use the previously generated private key SC_PRI to sign the key generation information 1 (q^a mod p) with a private key to prove the identity.

[0145] Step 525: The strong identity application on the BMC sends the key generation information 1 (q^a mod p) and the signature to the UIM.

[0146] Step 530: The UIM on the computing device initiates a communication key negotiation request to the IAM.

[0147] After receiving the key generation information 1(q^a modp) and signature sent by the strong identity application on the BMC, the UIM on the computing device can initiate a communication key negotiation request to the IAM. The request includes the key generation information 1(q^a mod p) and the signature, and the request is used to negotiate the communication key KEY_M3_IAM between the strong identity application and the IAM.

[0148] Step 540: IAM generates a local communication key KEY_M3_IAM according to the key generation information 1 (q^a mod p) sent by the strong identity application.

[0149] Similar to step 430, please refer to the description in step 430 for details, which will not be repeated here.

[0150] Step 545: IAM sends the additionally generated key generation information 2 (q^b mod p) to UIM.

[0151] Step 550: UIM sends key generation information 2 (q^b mod p) to the strong identity application on the BMC

[0152] Step 560: The strong identity application generates a local communication key KEY_M3_IAM according to the key generation information 2 (q^b mod p) sent by UIM.

[0153] As an example, after receiving the key generation information 2 (q^b mod p), the strong identity application calculates (q^b mod p)^a mod p according to the key generation information 2 (q^b mod p), thereby obtaining the communication key KEY_M3_UIM between the UIM and the strong identity application.

[0154] Step 570: The strong identity application sends information to the UIM to notify that the key negotiation between the strong identity application and the IAM is successful.

[0155] Step 580: UIM sends information to IAM to notify that the key negotiation between UIM and IAM is successful.

[0156] Figure 5 In the embodiment shown, the BMC and the IAM negotiate a communication key KEY_M3_IAM. Figure 5 The communication key KEY_M3_IAM negotiated between BMC and IAM is used to encrypt the injected IAM identity key.

[0157] Combine the following Figure 6 A specific example of a specific implementation of the injected IAM identity key is described. It should be understood that Figure 6 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 6 Those skilled in the art can obviously make various equivalent modifications or changes based on the examples given, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0158] Figure 6 1 is a schematic flow chart of a method for injecting an IAM identity key provided in an embodiment of the present application. Figure 6 As shown, the method may include steps 610-695, and steps 610-695 are described in detail below.

[0159] Step 610: The UIM on the computing device initiates a request to the IAM to inject the identity key of the IAM.

[0160] Step 620: IAM obtains the corresponding identity key SKEY, and encrypts the identity key SKEY based on the communication key KEY_M3_IAM.

[0161] After the communication key KEY_M3_IAM is negotiated between UIM and IAM, IAM can encrypt the identity key SKEY based on the communication key KEY_M3_IAM and send it to UIM.

[0162] Step 630: The IAM sends the encrypted SKEY to the UIM.

[0163] Step 640: The UIM forwards the encrypted SKEY to the strong identity application on the BMC.

[0164] Optionally, when UIM forwards the encrypted SKEY to the strong identity application on the BMC, UIM may also encrypt the above result (encrypted identity key SKEY) based on the communication key KEY_M3_UIM negotiated between the UIM and the strong identity application, and then forward it to the strong identity application.

[0165] Step 650: The strong identity application on the BMC decrypts to obtain the identity key SKEY.

[0166] After the strong identity application receives the identity key SKEY encrypted by the communication key KEY_M3_IAM, it decrypts it using the communication key KEY_M3_IAM to obtain the identity key SKEY.

[0167] Optionally, if UIM encrypts the above result (encrypted identity key SKEY) based on the communication key KEY_M3_UIM negotiated between the strong identity application before forwarding the identity key SKEY encrypted by the communication key KEY_M3_IAM to the strong identity application, then the strong identity application first needs to decrypt the above result according to the communication key KEY_M3_UIM to obtain the encrypted identity key SKEY, and then decrypt it through the communication key KEY_M3_IAM to obtain the identity key SKEY.

[0168] Step 660: The strong identity application on the BMC sends the identity key SKEY to the UIM.

[0169] As an example, the strong identity application can also generate a 256-bit random number R, and encrypt (R, SKEY) with the private key SC_PRI of the strong identity application to obtain the encrypted (R, SKEY). The encrypted (R, SKEY) can also be called Encrypt (R, SKEY). The strong identity application encrypts the above result (Encrypt (R, SKEY)) using the communication key KEY_M3_UIM negotiated with the UIM and sends it to the UIM.

[0170] After the strong identity application sends Encrypt(R, SKEY) to UIM, the identity key SKEY will not be saved. Every time UIM asks the strong identity application to sign data using the identity key SKEY, UIM sends the data and Encrypt(R, SKEY) to the strong identity application. The strong identity application decrypts the data using the private key SC_PRI to obtain the identity key SKEY, and then uses the identity key SKEY to sign the data.

[0171] Step 670: UIM manages and saves Encrypt(R, SKEY).

[0172] Step 680: UIM sends the data to be signed and Encrypt(R, SKEY) to the strong identity application.

[0173] As an example, the UIM may encrypt the data and Encrypt(R, SKEY) based on the communication key KEY_M3_UIM negotiated with the strong identity application, and then send the encrypted data to the strong identity application.

[0174] Step 690: The strong identity application signs the service request data based on the identity key SKEY.

[0175] The strong identity application first decrypts the data and Encrypt(R, SKEY) based on the communication key KEY_M3_UIM negotiated with UIM to obtain Encrypt(R, SKEY). Then, the strong identity application decrypts Encrypt(R, SKEY) using the private key SC_PRI of the strong identity application to obtain the identity key SKEY.

[0176] Step 695: The strong identity application feeds back the signature result to the UIM.

[0177] After the strong identity application obtains the identity key SKEY, it can sign the data of the service request based on the identity key SKEY and return the signature result to UIM.

[0178] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0179] Combination of the above Figures 1 to 6 , describes in detail a method for information security protection. Figure 7 , describe in detail the device embodiments of the present application.

[0180] Figure 7 It is a schematic block diagram of a computing device 700 provided in an embodiment of the present application.

[0181] The computing device 700 is capable of executing Figures 2 to 3 The steps of the information security protection method shown in FIG. 7 are not described in detail here to avoid repetition. The computing device 700 includes: a sending module 710, a receiving module 720,

[0182] A sending module 710, configured to send the first information on the computing device and the identity information of the hardware device to a unified identity authentication IAM;

[0183] The receiving module 720 is used to receive the public key of the IAM and the first digital signature result sent by the IAM, where the first digital signature result is the result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM.

[0184] Optionally, the receiving module 720 is further used to: receive identity information of the hardware device sent by the hardware device.

[0185] Optionally, the sending module 710 is further used to: send the public key of the IAM and the first digital signature result to the hardware device.

[0186] Optionally, the hardware device is a baseboard management controller BMC, and the identity information of the hardware device is an identification ID of the BMC.

[0187] Optionally, the first information includes any one or more combinations of the following: the name of the computing device, the Internet Protocol IP address of the computing device, and the ID of the software running on the computing device.

[0188] Optionally, the computing device 700 further includes:

[0189] The processing module 730 is used to negotiate a communication key with the hardware device, where the communication key is used to encrypt data transmitted between the computing device and the hardware device.

[0190] Optionally, the receiving module 720 is further used to: receive first key generation information sent by the hardware device, where the first key generation information is determined by the hardware device according to a first random number;

[0191] The processing module 730 is specifically used to determine a first key based on the first key generation information and the second key generation information, wherein the second key generation information is determined by the computing device based on a second random number, and the first key is used by the computing device to encrypt data sent to the hardware device.

[0192] Optionally, the sending module 710 is also used to: send the second key generation information to the hardware device, so that the hardware device generates a second key based on the first key generation information and the second key generation information, and the second key is used by the hardware device to encrypt data sent to the computing device.

[0193] Optionally, the processing module 730 is further used to: encrypt data and identity key based on the communication key;

[0194] The sending module 710 is also used to: send the encrypted data and identity key to the hardware device;

[0195] The receiving module 720 is further used to: receive a second digital signature result sent by the hardware device, where the second digital signature result is a result of the hardware device digitally signing the data based on the identity key.

[0196] The computing device 700 here can be embodied in the form of a functional module. The term "module" here can be implemented in the form of software and / or hardware, and is not specifically limited to this.

[0197] For example, a "module" may be a software program, a hardware circuit, or a combination of the two that implements the above functions. The hardware circuit may include an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor, or a group processor, etc.) and a memory for executing one or more software or firmware programs, a combined logic circuit, and / or other suitable components that support the described functions.

[0198] Therefore, the units of each example described in the embodiments of the present application can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present application.

[0199] An embodiment of the present application also provides a chip, which obtains instructions and executes the instructions to implement the above-mentioned information security protection method.

[0200] Optionally, as an implementation method, the chip includes a processor and a data interface, and the processor reads instructions stored in the memory through the data interface to execute the above-mentioned information security protection method.

[0201] Optionally, as an implementation method, the chip may also include a memory, in which instructions are stored, and the processor is used to execute the instructions stored in the memory. When the instructions are executed, the processor is used to execute the above-mentioned information security protection method.

[0202] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions, and the instructions are used in the method for information security protection in the above method embodiment.

[0203] An embodiment of the present application also provides a computer program product including instructions, wherein the instructions are used to implement the information security protection method in the above method embodiment.

[0204] In one implementation example, the processor may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0205] In one implementation example, the memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0206] The term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding.

[0207] In this application, "multiple" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0208] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0209] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0210] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computing device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0211] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for information security protection, It is characterized in that A hardware device is connected to the computing device, and the method includes: The computing device sends the first information on the computing device and the identity information of the hardware device to the unified identity authentication IAM, the hardware device is a baseboard management controller BMC, and the identity information of the hardware device is an identification ID of the BMC; The computing device receives the public key of the IAM and a first digital signature result sent by the IAM, where the first digital signature result is a result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM; The computing device and the hardware device negotiate a communication key, where the communication key is used to encrypt data transmitted between the computing device and the hardware device.

2. The method according to claim 1, It is characterized in that The method further comprises: The computing device receives the identity information of the hardware device sent by the hardware device.

3. The method according to claim 1 or 2, It is characterized in that The method further comprises: The computing device sends the public key of the IAM and the first digital signature result to the hardware device.

4. The method according to claim 1 or 2, It is characterized in that The first information includes any one or more combinations of the following: the name of the computing device, the Internet Protocol IP address of the computing device, and the ID of the software running on the computing device.

5. The method according to claim 1 or 2, It is characterized in that The computing device and the hardware device negotiate a communication key, including: The computing device receives first key generation information sent by the hardware device, where the first key generation information is determined by the hardware device according to a first random number; The computing device determines a first key based on the first key generation information and the second key generation information, wherein the second key generation information is determined by the computing device based on a second random number, and the first key is used by the computing device to encrypt data sent to the hardware device.

6. The method according to claim 5, It is characterized in that The method further comprises: The computing device sends the second key generation information to the hardware device, so that the hardware device generates a second key according to the first key generation information and the second key generation information, and the second key is used by the hardware device to encrypt data sent to the computing device.

7. The method according to claim 6, It is characterized in that The method further comprises: The computing device encrypts data and an identity key based on the communication key; The computing device sends the encrypted data and the identity key to the hardware device; The computing device receives a second digital signature result sent by the hardware device, where the second digital signature result is a result of the hardware device digitally signing the data based on the identity key.

8. A computing device, It is characterized in that The computing device is connected to a hardware device, and the computing device includes: A sending module, used for sending the first information on the computing device and the identity information of the hardware device to the unified identity authentication IAM, wherein the hardware device is a baseboard management controller BMC, and the identity information of the hardware device is an identification ID of the BMC; A receiving module, configured to receive the public key of the IAM and a first digital signature result sent by the IAM, where the first digital signature result is a result of the IAM digitally signing the first information and the identity information of the hardware device based on the private key of the IAM; The processing module is used to negotiate a communication key with the hardware device, and the communication key is used to encrypt data transmitted between the computing device and the hardware device.

9. The computing device according to claim 8, It is characterized in that The receiving module is also used for: Receive the identity information of the hardware device sent by the hardware device.

10. A computing device according to claim 8 or 9, It is characterized in that The sending module is also used for: The public key of the IAM and the first digital signature result are sent to the hardware device.

11. A computing device according to claim 8 or 9, It is characterized in that The first information includes any one or more combinations of the following: the name of the computing device, the Internet Protocol IP address of the computing device, and the ID of the software running on the computing device.

12. The computing device according to claim 8 or 9, It is characterized in that The receiving module is also used for: Receiving first key generation information sent by the hardware device, where the first key generation information is determined by the hardware device according to a first random number; The processing module is specifically used to determine a first key based on the first key generation information and the second key generation information, wherein the second key generation information is determined by the computing device based on a second random number, and the first key is used by the computing device to encrypt data sent to the hardware device.

13. The computing device according to claim 12, It is characterized in that The sending module is also used for: The second key generation information is sent to the hardware device so that the hardware device generates a second key according to the first key generation information and the second key generation information, wherein the second key is used by the hardware device to encrypt data sent to the computing device.

14. The computing device according to claim 13, It is characterized in that The processing module is also used for: encrypting data and identity keys based on the communication key; The sending module is also used to: send the encrypted data and identity key to the hardware device; The receiving module is further used to: receive a second digital signature result sent by the hardware device, where the second digital signature result is a result of the hardware device digitally signing the data based on the identity key.

15. A computing device, It is characterized in that The device comprises a processor and a memory; the processor executes instructions in the memory, so that the computing device executes the method according to any one of claims 1 to 7.

16. A computer-readable storage medium, It is characterized in that The method comprises instructions for implementing the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Protecting method and protecting system for authentication server software copyright

    CN102780699A

  • Two-way authentication method and system

    CN108366069A

  • Method, apparatus, apparatus and computer readable storage medium for preventing data tampering

    CN109063514A

  • Security management for rack server system

    US20170109531A1