Device authentication system, method and terminal device

By establishing a mutual trust relationship between device A and the authentication server, and using the ESAM module for authentication and generating communication keys, the problem of low utilization of the ESAM module is solved, and secure communication and data transmission between devices is achieved.

CN114390478BActive Publication Date: 2025-09-16SHENZHEN CHENGGU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111593011.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-23
Publication Date
2025-09-16
Estimated Expiration
2041-12-23

AI Technical Summary

Technical Problem

In the prior art, the utilization rate of the ESAM module is low, especially when device A includes an ESAM module and device B does not include a PSAM module, effective authentication cannot be performed, resulting in communication security risks and waste of resources.

Method used

By establishing a mutual trust relationship between device A and the authentication server, using the ESAM module to authenticate the authentication server and generate a communication key, device B obtains the key from the authentication server for two-way authentication, ensuring secure communication between device A and device B.

Benefits of technology

The utilization rate of the ESAM module is improved, and the data security between devices is guaranteed. The key generated by the authentication server enables secure communication even if direct authentication between devices is not possible.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114390478B_ABST
    Figure CN114390478B_ABST
Patent Text Reader

Abstract

This application is applicable to the field of information security technology, and provides a device authentication system, method and terminal device. The device authentication system includes: a first device, an authentication server and a second device; the first device initiates a connection request message to the second device; if the second device detects that the first device has not been authenticated, it replies with a connection response message to the first device; the first device and the authentication server perform authentication based on the ESAM method; after the authentication server is successfully authenticated, the first device determines a communication key; the authentication server generates the communication key; the second device obtains the communication key from the authentication server; the second device and the first device perform two-way authentication based on the communication key. Through the above method, the utilization rate of ESAM can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security technology, and in particular relates to a device authentication system, method, terminal device, and computer-readable storage medium. Background Art

[0002] The PSAM-ESAM security mechanism is mainly used for security authentication between devices containing an Embedded Secure Access Module (ESAM) and devices containing a Point of Sale Secure Access Module (PSAM).

[0003] In the existing traffic system, if the road side unit (RSU) includes a PSAM card and the on-board unit (OBU) includes an ESAM module, the RSU and OBU first perform authentication based on the PSAM-ESAM security mechanism, and then transmit valid data after the authentication is passed. In other words, if only device A includes an ESAM module and device B does not include a PSAM module, then device A and device B will not be able to perform authentication based on the PSAM-ESAM security mechanism, thereby reducing the utilization rate of ESAM. Summary of the Invention

[0004] The embodiments of the present application provide a device authentication system, method, terminal device and computer-readable storage medium, which can solve the problem of low utilization rate of ESAM in existing methods.

[0005] In a first aspect, an embodiment of the present application provides a device authentication system, the device authentication system comprising a first device, an authentication server, and a second device, wherein the first device comprises an embedded secure access module (ESAM), the authentication server comprises a point-of-sale secure access module (PSAM), and the authentication server and the second device have established a mutual trust relationship;

[0006] Initiating, by the first device, a connection request message to the second device, wherein the connection request message carries a device identifier of the first device and an authentication method supported by the first device;

[0007] The second device detects, according to the device identifier of the first device, whether the first device has been authenticated;

[0008] If the second device detects that the first device has not been authenticated, the second device replies to the first device with a connection response message, where the connection response message includes information for instructing the first device to authenticate the authentication server based on the ESAM method;

[0009] After receiving the reply connection response message, the first device performs authentication with the authentication server based on the ESAM method;

[0010] After the authentication server is successfully authenticated, the first device determines a communication key;

[0011] The authentication server generates the communication key when a communication key generation condition is met, wherein the communication key generation condition includes that the first device is successfully authenticated;

[0012] The second device obtains the communication key from the authentication server;

[0013] The second device and the first device perform bidirectional authentication based on the communication key.

[0014] In a second aspect, an embodiment of the present application provides a device authentication method, which is applied to a first device, the first device including an ESAM, and the device authentication method includes:

[0015] Initiate a connection request message to the second device, wherein the connection request message carries the device identifier of the first device and the ESAM authentication method supported by the first device;

[0016] receiving a connection response message replied by the second device, the connection response message including information for instructing the first device to authenticate the authentication server based on the ESAM mode;

[0017] Performing authentication with the authentication server based on ESAM, wherein the authentication server and the second device have established a mutual trust relationship;

[0018] After the authentication server is successfully authenticated, determining a communication key;

[0019] Perform two-way authentication with the second device based on the communication key.

[0020] In a third aspect, an embodiment of the present application provides a terminal device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method described in the first aspect when executing the computer program.

[0021] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect is implemented.

[0022] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute the method described in the first aspect above.

[0023] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0024] In an embodiment of the present application, since the first device includes an ESAM and the authentication server includes a PSAM, when the first device and the second device have not been authenticated, the first device can perform two-way authentication with the authentication server based on the ESAM method. At the same time, since the authentication server and the second device have established a mutual trust relationship in advance, the second device can obtain a trusted communication key that is the same as the one determined by the first device from the authentication server, and then use the communication key to perform two-way authentication with the first device. That is, through the above method, even if the first device and the second device cannot be directly authenticated based on the PSAM-ESAM security mechanism, a communication key can be obtained by using the ESAM of the first device, and then the first device and the second device can perform two-way authentication based on the communication key, thereby improving the utilization rate of the ESAM, and since the first device and the second device have undergone two-way authentication, the security of the data transmitted between the two devices can also be guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art.

[0026] Figure 1 This is a schematic diagram of the structure of a device authentication system provided by an embodiment of the present application;

[0027] Figure 2 This is a schematic diagram of the interaction between the first device, the authentication server, and the second device provided in one embodiment of the present application;

[0028] Figure 3 This is a schematic diagram of an application scenario provided by an embodiment of the present application;

[0029] Figure 4 This is a flow chart of a device authentication method provided by an embodiment of the present application;

[0030] Figure 5 This is a structural block diagram of a device authentication apparatus provided by another embodiment of the present application;

[0031] Figure 6 It is a structural diagram of the terminal device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0033] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.

[0034] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0035] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0036] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with the embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in yet other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized.

[0037] Example 1:

[0038] When equipment A comprises the ESAM module, and equipment B comprises the PSAM module, this equipment A and equipment B can be authenticated based on the PSAM-ESAM security mechanism.And in actual conditions, the equipment A that may exist to comprise the ESAM module needs to communicate with the equipment C that does not comprise the PSAM module (perhaps not comprising the subkey that ESAM disperses), and at this moment, equipment A and equipment C will not carry out two-way authentication based on the PSAM-ESAM security mechanism.If equipment A and equipment C do not carry out two-way authentication, the communication between this equipment A and the equipment C will be caused to have certain security risk, and if carry out two-way authentication, then need adopt alternative methods to carry out, such as, carry out two-way authentication by modes such as installing digital certificate, presetting shared keys.And do not need to use the ESAM module of equipment A when carrying out two-way authentication by modes such as installing digital certificate, presetting shared keys, that is, owing to not making full use of the ESAM module of equipment A, therefore, have wasted the resource of this ESAM module.

[0039] In order to improve the utilization rate of the ESAM module (hereinafter referred to as ESAM) and improve the communication security between device A and device C, an embodiment of the present application provides a device authentication system. The device authentication system includes a first device, a second device and an authentication server. The first device includes an ESAM, the authentication server includes a PSAM, and the second device and the authentication server have established a mutual trust relationship in advance, that is, they have performed two-way authentication in advance. When the first device and the second device need to communicate, if the first device has not performed two-way authentication with the second device, the first device needs to first perform mutual authentication with the authentication server. After the authentication is passed, the first device then performs two-way authentication with the second device.

[0040] The device authentication system provided in the embodiments of the present application is described below with reference to specific drawings.

[0041] Figure 1 The following is a schematic diagram showing the structure of a device authentication system provided by an embodiment of the present application. Figure 1 In the embodiment, the device authentication system 1 includes a first device 11, an authentication server 12 and a second device 13, wherein the first device 11 includes an embedded security access module ESAM, the authentication server 12 includes a point-of-sale terminal security access module PSAM, and the authentication server 12 and the second device 13 have established a mutual trust relationship.

[0042] It should be noted that the mutual trust relationship established between the authentication server 12 and the second device 13 can be established through a common security process. The established mutual trust relationship can be permanent or have a validity period. The common security process includes: a security process based on digital certificates, a security process based on a pre-set shared key, and other methods.

[0043] Figure 2 A schematic diagram of interaction among the first device 11, the authentication server 12 and the second device 13 is shown.

[0044] Step S21 : The first device 11 initiates a connection request message to the second device 13 , wherein the connection request message carries the device identifier of the first device 11 and an authentication method supported by the first device 11 .

[0045] The device identification of the first device 11 is used to uniquely identify the first device 11 , and may be a serial number of the first device 11 .

[0046] Specifically, since the first device 11 includes an ESAM, in order to make the second device aware that the first device 11 includes the ESAM and thereby improve the utilization rate of the ESAM, the authentication method supported by the first device 11 is set to include ESAM authentication.

[0047] Step S22, the second device 13 detects whether the first device 11 has been authenticated based on the device identification of the first device 11. If the second device 13 detects that the first device 11 has not been authenticated, it replies with a connection response message to the first device 11. The connection response message includes information for instructing the first device 11 to authenticate the authentication server 12 based on the ESAM method.

[0048] In this embodiment, to ensure security, different device identifiers typically correspond to different authentication-related information. Therefore, the second device 13 needs to search for the corresponding authentication-related information based on the device identifier to detect whether it has stored relevant information related to authentication with the first device 11. If no authentication-related information is found, it is assumed that mutual authentication with the first device 11 has not been completed. Otherwise, it is assumed that mutual authentication with the first device 11 has been completed, and the second device 13 can transmit data with the first device 11. After the second device 13 determines that mutual authentication with the first device 11 has not been completed, it will notify the first device 11 to authenticate with the authentication server 12 based on the ESAM method.

[0049] In some embodiments, the connection response message may further include the network address of the authentication server 12. In this way, after receiving the connection response message, the first device 11 can directly obtain the network address of the authentication server 12 from the connection response message. Of course, the first device 11 may also obtain the network address of the authentication server 12 in other ways, for example, the first device 11 may obtain the network address of the authentication server 12 from local configuration information.

[0050] Step S23: After receiving the reply connection response message, the first device 11 and the authentication server 12 perform authentication based on the ESAM method.

[0051] In this embodiment, since the authentication server 12 includes a PSAM and the first device 11 includes an ESAM, the first device 11 and the authentication server 12 can perform authentication based on the ESAM.

[0052] Step S24: After the authentication server 12 is successfully authenticated, the first device 11 determines a communication key.

[0053] Step S25: When the communication key generation condition is met, the authentication server 12 generates the communication key, and the communication key generation condition includes that the first device 11 is successfully authenticated.

[0054] In this embodiment, the authentication server 12 may generate the communication key after the first device 11 is successfully authenticated, so that when the second device 13 subsequently wishes to obtain the communication key, the communication key can be sent to the second device 13 as soon as possible.

[0055] The communication key may also be generated after the first device 11 is successfully authenticated and other conditions are met.

[0056] Step S26 : The second device 13 obtains the communication key from the authentication server 12 .

[0057] In step S27, the second device 13 and the first device 11 perform two-way authentication based on the communication key.

[0058] The communication key is a key, such as a character string.

[0059] In this embodiment, after the first device 11 and the authentication server 12 undergo bidirectional authentication, the first device 11 and the authentication server 12 determine a communication key, and the second device 13 then obtains the communication key from the authentication server 12. In this way, because the first device 11 and the second device 13 both have the same communication key, the first device 11 and the second device 13 can perform bidirectional authentication based on the communication key and then transmit corresponding data after successful bidirectional authentication.

[0060] In the embodiment of the present application, since the first device 11 includes an ESAM and the authentication server includes a PSAM, when the first device 11 and the second device 13 have not been authenticated, the first device 11 can perform two-way authentication with the authentication server 12 based on the ESAM method. At the same time, since the authentication server 12 and the second device 13 have already established a mutual trust relationship, the second device 13 can obtain a reliable communication key that is the same as the one determined by the first device 11 from the authentication server 12, and then use the communication key to perform two-way authentication with the first device 11. That is, through the above method, even if the first device 11 and the second device 13 cannot directly authenticate based on the PSAM-ESAM security mechanism, they can still use the ESAM of the first device 11 to obtain a communication key, thereby enabling the first device 11 and the second device 13 to perform two-way authentication based on the communication key, thereby improving the utilization rate of the ESAM. In addition, since the first device 11 and the second device 13 have undergone two-way authentication, the security of the data transmitted between the two devices can also be guaranteed.

[0061] In some embodiments, after the second device 13 obtains a communication key from the authentication server 12 that can be used for two-way authentication with the first device 11, the communication key is stored in correspondence with the device identifier of the first device 11. In this way, it is possible to subsequently determine whether the first device 11 has been authenticated by checking whether the communication key corresponding to the device identifier of the first device 11 is stored. That is, in step S22, the second device 13 detects whether the first device 11 has been authenticated based on the device identifier of the first device 11, including:

[0062] A1. The second device 13 searches to see whether a communication key corresponding to the device identification of the first device 11 has been stored, and obtains a search result.

[0063] A2. The second device 13 detects whether the first device 11 has been authenticated based on the search result.

[0064] The first device 11 and the second device 13 can use the communication key to perform bidirectional authentication, and can also use the communication key to encrypt or decrypt data transmitted between the first device 11 and the second device 13. Therefore, as long as the search result obtained by the second device 13 indicates that it stores the communication key corresponding to the first device 11, it indicates that the second device 13 and the first device 11 have previously performed bidirectional authentication. In other words, by searching for the stored communication key, it is possible to accurately determine whether the first device 11 has previously performed authentication.

[0065] In this embodiment, if the second device 13 stores the communication key corresponding to the first device 11, the obtained search result includes the communication key. If the second device 13 does not store the communication key corresponding to the first device 11, the obtained search result includes information indicating that the second device 13 does not store the communication key.

[0066] In some embodiments, in order to further improve the security of the transmitted data, a validity period may be set for the communication key. In this case, A2 includes:

[0067] A21. If the search result indicates that the second device 13 has stored a communication key corresponding to the device identification of the first device 11, determine whether the validity period of the communication key has expired, and when the validity period of the communication key has not expired, determine that the first device 11 has been authenticated; when the validity period of the communication key has expired, determine that the first device 11 has not been authenticated.

[0068] A22. If the search result indicates that the second device 13 does not store the communication key corresponding to the device identification of the first device 11, it is determined that the first device 11 is not authenticated.

[0069] In this embodiment, if the search result indicates that second device 13 stores the communication key corresponding to first device 11, the communication key is checked for validity. If so, the validity period is obtained and compared with the current date. If the current date is within the validity period, the communication key is determined to be valid, i.e., first device 11 is still within the authentication period. Otherwise, the communication key is no longer within the authentication period, i.e., first device 11 is not authenticated. Because the communication key has an validity period, using both the communication key and the corresponding validity period to determine whether first device 11 has been authenticated improves the accuracy of the resulting determination.

[0070] In some embodiments, step S23 includes:

[0071] B1. The first device 11 initiates an authentication request to the authentication server 12. The authentication request carries a device identifier of the first device 11 and a first value.

[0072] The first value may be a preset value or a value randomly generated according to a random function.

[0073] In this embodiment, the first device 11 may initiate an authentication request to the authentication server 12 according to the obtained network address.

[0074] B2. The authentication server 12 calculates a first access authentication key based on the primary authentication key of the PSAM, the device identifier of the first device 11, and the first value.

[0075] The PSAM includes a master authentication key (MasterAccessKey), and a value can be calculated based on the MasterAccessKey, the device identifier, and the first value. The calculated value is used as the first access authentication key.

[0076] B3. The authentication server 12 sends an authentication response message to the first device 11. The authentication response message carries the first access authentication key and the second value.

[0077] In this embodiment, the second value may be a value preset by the authentication server 12 or a value randomly generated according to a random function. Typically, the second value is not equal to the first value.

[0078] B4. The first device 11 calculates a second access authentication key based on the ESAM authentication key and the first value, and when it is determined that the second access authentication key is equal to the first access authentication key, determines that the authentication server 12 is a trusted device.

[0079] In this embodiment, the ESAM includes an authentication key (AccessKey). Assuming that the first value is RandA, the second access authentication key (tmpAccessCredentialsA) can be calculated according to the following formula:

[0080] tmpAccessCredentialsA=SM4(AccessKey,RandA).

[0081] SM4 is a block cipher algorithm. Of course, in actual situations, other encryption algorithms can also be selected to obtain the second access authentication key, which is not limited here.

[0082] In this embodiment, when the first device 11 determines that the authentication server 12 is a trustworthy device, it indicates that the authentication server 12 is successfully authenticated.

[0083] B5. The first device 11 calculates a first verification value based on the authentication key of the ESAM and the second value, and sends an authentication confirmation message to the authentication server 12. The authentication confirmation message carries the first verification value.

[0084] In this embodiment, the first verification value (accessCredentialsM) may be calculated according to the following method:

[0085] accessCredentialsM=SM4(AccessKey, RandM), where RandM is the second value and AccessKey is the authentication key.

[0086] B6. The authentication server 12 calculates a second verification value based on the second numerical value, and when it is determined that the first verification value is equal to the second verification value, determines that the first device 11 is a trustworthy device.

[0087] When the authentication server 12 determines that the first device 11 is a trustworthy device, it indicates that the first device 11 is successfully authenticated.

[0088] In B1-B6 above, since the first access authentication key is calculated by authentication server 12 based on its built-in algorithm, and the second access authentication key is calculated by first device 11 based on its built-in algorithm, that is, the first access authentication key and the second access authentication key are calculated independently by the two devices, when the first access authentication key and the second access authentication key are equal, it indicates that the algorithms built into authentication server 12 and first device 11 have not changed, that is, authentication server 12 is a trusted device of first device 11. Similarly, when the first check value and the second check value are equal, it indicates that first device 11 is a trusted device of authentication server 12. In other words, through the above method, mutual authentication between first device 11 and authentication server 12 can be accurately achieved.

[0089] In some embodiments, step B2 includes:

[0090] B21. The authentication server generates a temporary authentication key based on the master authentication key of the PSAM and the device identification of the first device.

[0091] B22. Use the temporary authentication key to encrypt the first value to obtain the first access authentication key.

[0092] In the above steps B21 and B22, assuming that the device identifier of the first device is ID_A, the master authentication key is MasterAccessKey, and the first value is RandA, the temporary authentication key (tmpAccessKey) can be decentralized according to the following formula:

[0093] tmpAccessKey=SM4(MasterAccessKey, ID_A), or it can be calculated using the following algorithm: tmpAccessKey=SM4(MasterAccessKey, ID_A|0x00).

[0094] The authentication server 12 then uses the tmpAccessKey to encrypt RandA to generate a first access authentication key (accessCredentialsA). Specifically, the following encryption algorithm may be used:

[0095] accessCredentialsA=SM4(tmpAccessKey,RandA).

[0096] Correspondingly, in step B6, the authentication server 12 calculates a second verification value based on the second value, including:

[0097] The authentication server 12 calculates the second verification value based on the temporary authentication key and the second value.

[0098] In this embodiment, the authentication server 12 may use the following encryption algorithm to calculate the second verification value (tmpAccessCredentialsM):

[0099] tmpAccessCredentialsM=SM4(tmpAccessKey,RandM).

[0100] In some embodiments, the above step S24 includes:

[0101] After the authentication server is successfully authenticated, the first device determines the communication key based on the authentication key of the ESAM, the first value, and the second value.

[0102] In this embodiment, if the authentication server 12 has been verified as a trustworthy device, the first device 11 creates a communication key Ks. Specifically, the following encryption algorithm may be used:

[0103] Ks=SM4(AccessKey,RandA|RandM).

[0104] Here, “|” represents concatenation. For example, 0x1234|0x5678 = 0x12345678.

[0105] If the communication key generation condition further includes that the first device is successfully authenticated and receives a security context request initiated by the second device, and the security context request carries the device identifier of the first device, then step S25 includes:

[0106] After the first device is successfully authenticated and receives the security context request initiated by the second device, the authentication server determines the communication key according to the temporary authentication key, the first value, and the second value.

[0107] In this embodiment, after authenticating the first device 11 as a trusted device, the authentication server 12 does not immediately generate a normal key. Instead, it generates the communication key after receiving a security context request from the second device 13. Since the communication key is generated only when the second device 13 needs it, the communication key is prevented from prematurely occupying resources.

[0108] In some embodiments, considering that the second device 13 has a PSAM, the first device 11 can directly perform mutual authentication with the second device 13. Therefore, before step S21, the following steps are included:

[0109] The first device 11 determines whether it can directly authenticate with the second device 13 based on the PSAM-ESAM security mechanism.

[0110] Correspondingly, step S21 includes:

[0111] If the first device 11 cannot directly authenticate with the second device 13 based on the PSAM-ESAM security mechanism, a connection request message is initiated to the second device 13 .

[0112] Among them, when the second device 13 does not include PSAM and does not include the dispersed sub-key dispersed from ESAM (a new key calculated by a dispersion algorithm (such as SM4) of an original key is called a dispersed sub-key), the second device 13 cannot directly authenticate with the first device 11 based on the PSAM-ESAM security mechanism.

[0113] In this embodiment, since step S21 is executed only after the first device 11 determines that it cannot directly authenticate with the second device 13 based on the PSAM-ESAM security mechanism, it is avoided that the first device 11 can directly authenticate with the second device 13 based on the PSAM-ESAM security mechanism and also needs to authenticate through the authentication server 12, thereby ensuring the authentication efficiency of the first device 11 and the utilization rate of the ESAM of the first device.

[0114] In order to more clearly describe the device authentication system provided in the embodiment of the present application, a description is given below in conjunction with specific application scenarios.

[0115] refer to Figure 3 Schematic diagram of the application scenario, Figure 3 In the embodiment, the roadside sensor is a device including ESAM, the service platform is a device not including PSAM and not including the dispersed subkey dispersed from ESAM, the authentication server includes PSAM, and the service platform and the authentication server are pre-authenticated.

[0116] When a roadside sensor initiates a connection request message to the service platform, if the service platform determines that the roadside sensor has not been authenticated, it will reply with a connection response message to the roadside sensor. The connection response message includes information for instructing the roadside sensor to authenticate the authentication server based on the ESAM method.

[0117] The roadside sensor will perform two-way authentication with the authentication server. After successful authentication, the roadside sensor generates a communication key and initiates a new connection request message to the service platform. The new connection request message carries an indication that the roadside sensor has completed two-way authentication with the authentication server. For example, the new connection request message carries a special field, and the parameters of the special field are used to indicate that the roadside sensor has completed two-way authentication with the authentication server.

[0118] After receiving a new connection request message initiated by the roadside sensor, the service platform initiates a security context request to the authentication server. The security context request is used to request a communication key from the authentication server.

[0119] The authentication server generates a communication key and sends a security context response to the service platform, which carries the generated communication key. Of course, if the communication key has an expiration date, the security context response also carries the expiration date corresponding to the communication key.

[0120] The business platform and roadside sensors then perform two-way authentication and encrypt the transmitted data based on the communication key.

[0121] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0122] Example 2:

[0123] Corresponding to the device authentication system of the first embodiment above, Figure 4 A flow chart of a device authentication method provided in an embodiment of the present application is shown, where the device authentication method is applied to a first device.

[0124] Step S41: Initiate a connection request message to the second device, wherein the connection request message carries the device identification of the first device and the ESAM authentication method supported by the first device.

[0125] Step S42: Receive a connection response message replied by the second device, where the connection response message includes information for instructing the first device to authenticate the authentication server based on the ESAM method.

[0126] In some embodiments, the connection response message may also include the network address of the authentication server.

[0127] Step S43: Authentication is performed with the authentication server based on the ESAM method. The authentication server and the second device have established a mutual trust relationship.

[0128] Step S44: After the authentication server is successfully authenticated, a communication key is determined.

[0129] Step S45: Perform two-way authentication with the second device based on the communication key.

[0130] By adopting the solution provided in the embodiment of the present application, even if the first device and the second device cannot be directly authenticated based on the PSAM-ESAM security mechanism, a communication key can be obtained by using the ESAM of the first device, so that the first device and the second device can perform two-way authentication based on the communication key, thereby improving the utilization rate of the ESAM. Moreover, since the first device and the second device have undergone two-way authentication, the security of the data transmitted between the two devices can also be guaranteed.

[0131] In some embodiments, step S43 includes:

[0132] C1. Initiate an authentication request to an authentication server, where the authentication request carries the device identifier of the first device and a first value.

[0133] The first value may be a preset value or a value randomly generated according to a random function.

[0134] C2. Receive an authentication response message sent by the authentication server, where the authentication response message carries a first access authentication key and a second value. The first access authentication key is calculated by the authentication server based on the master authentication key of the PSAM, the device identifier of the first device, and the first value.

[0135] The process of calculating the first access authentication key is the same as that in the first embodiment and will not be repeated here.

[0136] C3. Calculate a second access authentication key based on the ESAM authentication key and the first value, and when it is determined that the second access authentication key is equal to the first access authentication key, determine that the authentication server is a trusted device.

[0137] The process of calculating the second access authentication key is the same as that in the first embodiment and will not be repeated here.

[0138] C4. Calculate a first check value based on the authentication key of the ESAM and the second value, and send an authentication confirmation message to the authentication server, the authentication confirmation message carrying the first check value. The authentication server subsequently calculates a second check value based on the second value, and if the first check value and the second check value are equal, determines that the first device is a trusted device.

[0139] The process of calculating the first check value and the second check value is the same as that of the first embodiment and will not be repeated here.

[0140] In some embodiments, step S44 includes:

[0141] After the authentication server is successfully authenticated, the communication key is determined based on the authentication key of the ESAM, the first value, and the second value.

[0142] The calculation process of the communication key is the same as that of the first embodiment and will not be repeated here.

[0143] In some embodiments, before step S41, the following steps are included:

[0144] Determine whether it is possible to directly authenticate with the second device based on the PSAM-ESAM security mechanism.

[0145] Correspondingly, step S41 includes:

[0146] If it is not possible to directly authenticate with the second device based on the PSAM-ESAM security mechanism, a connection request message is initiated to the second device.

[0147] Example 3:

[0148] Corresponding to the device authentication method in the second embodiment above, Figure 5 A structural block diagram of a device authentication apparatus provided in an embodiment of the present application is shown. For ease of explanation, only the parts related to the embodiment of the present application are shown.

[0149] Reference Figure 5 The device authentication device 5 is applied to the first device and includes: a connection request message initiating module 51, a connection response message receiving module 52, a first authentication module 53, a communication key determination module 54, and a second authentication module 55, wherein:

[0150] The connection request message initiating module 51 is used to initiate a connection request message to the second device, wherein the connection request message carries the device identification of the first device and the ESAM authentication method supported by the first device.

[0151] The connection response message receiving module 52 is used to receive a connection response message replied by the second device, where the connection response message includes information for instructing the first device to authenticate the authentication server based on the ESAM method.

[0152] The first authentication module 53 is used to perform authentication with the authentication server based on the ESAM method. The authentication server and the second device have established a mutual trust relationship.

[0153] The communication key determination module 54 is configured to determine a communication key after the authentication server is successfully authenticated.

[0154] The second authentication module 55 is configured to perform bidirectional authentication with the second device based on the communication key.

[0155] In an embodiment of the present application, even if the first device and the second device cannot be directly authenticated based on the PSAM-ESAM security mechanism, a communication key can be obtained by using the ESAM of the first device, so that the first device and the second device can perform two-way authentication based on the communication key, thereby improving the utilization rate of the ESAM. Moreover, since the first device and the second device have undergone two-way authentication, the security of the data transmitted between the two devices can also be guaranteed.

[0156] In some embodiments, the first authentication module 53 is specifically configured to:

[0157] An authentication request is initiated to an authentication server, where the authentication request carries the device identifier of the first device and a first value.

[0158] An authentication response message sent by the authentication server is received, where the authentication response message carries a first access authentication key and a second value, where the first access authentication key is calculated by the authentication server based on a master authentication key of the PSAM, a device identifier of the first device, and the first value.

[0159] A second access authentication key is calculated based on the authentication key of the ESAM and the first value, and when it is determined that the second access authentication key is equal to the first access authentication key, the authentication server is determined to be a trusted device.

[0160] A first verification value is calculated based on the authentication key of the ESAM and the second numerical value, and an authentication confirmation message is sent to the authentication server, where the authentication confirmation message carries the first verification value.

[0161] In some embodiments, the communication key determination module 54 is specifically configured to:

[0162] After the authentication server is successfully authenticated, the communication key is determined based on the authentication key of the ESAM, the first value, and the second value.

[0163] In some embodiments, the device authentication apparatus 5 further includes:

[0164] The module for determining whether direct authentication is possible is used to determine whether direct authentication with the second device can be performed based on the PSAM-ESAM security mechanism.

[0165] Correspondingly, the connection request message initiating module 51 is specifically configured to:

[0166] If it is not possible to directly authenticate with the second device based on the PSAM-ESAM security mechanism, a connection request message is initiated to the second device.

[0167] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of this application. Their specific functions and technical effects can be found in the method embodiment section and will not be repeated here.

[0168] Example 4:

[0169] Figure 6 This is a schematic diagram of the structure of a terminal device provided in one embodiment of the present application. Figure 6 As shown, the terminal device 6 of this embodiment includes: at least one processor 60 ( Figure 6 Only one processor is shown in the figure), a memory 61, and a computer program 62 stored in the memory 61 and executable on the at least one processor 60, wherein the processor 60 implements the steps of any of the above-mentioned method embodiments when executing the computer program 62.

[0170] The terminal device 6 may be a computing device such as a roadside unit. The terminal device may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will understand that Figure 6 It is only an example of the terminal device 6 and does not constitute a limitation on the terminal device 6. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, it may also include input and output devices, network access devices, etc.

[0171] The processor 60 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.

[0172] In some embodiments, the memory 61 may be an internal storage unit of the terminal device 6, such as a hard disk or memory of the terminal device 6. In other embodiments, the memory 61 may also be an external storage device of the terminal device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the terminal device 6. Furthermore, the memory 61 may also include both an internal storage unit of the terminal device 6 and an external storage device. The memory 61 is used to store an operating system, application programs, a boot loader (BootLoader), data, and other programs, such as the program code of the computer program. The memory 61 may also be used to temporarily store data that has been output or is about to be output.

[0173] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0174] An embodiment of the present application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor implements the steps of any of the above-mentioned method embodiments when executing the computer program.

[0175] An embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above-mentioned various method embodiments can be implemented.

[0176] An embodiment of the present application provides a computer program product. When the computer program product is run on a terminal device, the terminal device can implement the steps in the above-mentioned method embodiments when executing the computer program product.

[0177] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process of the above-mentioned method embodiment by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can at least include: any entity or device capable of carrying computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, mobile hard drive, magnetic disk, or optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.

[0178] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0179] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0180] In the embodiments provided in this application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0181] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0182] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

Claims

1. A device authentication system, characterized in that: The device authentication system includes a first device, an authentication server, and a second device, wherein the second device does not include a point-of-sale secure access module (PSAM) or a subkey dispersed from an embedded secure access module (ESAM), the first device includes the ESAM, the authentication server includes the PSAM, and a mutual trust relationship has been established between the authentication server and the second device; Initiating, by the first device, a connection request message to the second device, wherein the connection request message carries a device identifier of the first device and an authentication method supported by the first device; The second device detects, according to the device identifier of the first device, whether the first device has been authenticated; If the second device detects that the first device has not been authenticated, the second device replies to the first device with a connection response message, where the connection response message includes information for instructing the first device to authenticate the authentication server based on the ESAM method; After receiving the reply connection response message, the first device performs authentication with the authentication server based on the ESAM method; After the authentication server is successfully authenticated, the first device determines a communication key; The authentication server generates the communication key when a communication key generation condition is met, wherein the communication key generation condition includes that the first device is successfully authenticated; The second device obtains the communication key from the authentication server; The second device and the first device perform bidirectional authentication based on the communication key.

2. The device authentication system according to claim 1, wherein: The second device detecting, according to the device identifier of the first device, whether the first device has been authenticated, includes: The second device searches to see whether a communication key corresponding to the device identifier of the first device has been stored, and obtains a search result; The second device detects whether the first device has been authenticated based on the search result.

3. The device authentication system according to claim 2, wherein: Detecting, by the second device, whether the first device has been authenticated based on the search result, includes: If the search result indicates that the second device has stored a communication key corresponding to the device identifier of the first device, determining whether the validity period of the communication key has expired, and if the validity period of the communication key has not expired, determining that the first device has been authenticated; if the validity period of the communication key has expired, determining that the first device has not been authenticated; If the search result indicates that the second device does not store the communication key corresponding to the device identification of the first device, it is determined that the first device has not been authenticated.

4. The device authentication system according to claim 1, wherein: The first device and the authentication server perform authentication based on the ESAM method, including: The first device initiates an authentication request to the authentication server, where the authentication request carries a device identifier of the first device and a first value; The authentication server calculates a first access authentication key based on the primary authentication key of the PSAM, the device identifier of the first device, and the first value; The authentication server sends an authentication response message to the first device, where the authentication response message carries the first access authentication key and a second value; The first device calculates a second access authentication key based on the ESAM authentication key and the first value, and determines that the authentication server is a trusted device when it is determined that the second access authentication key is equal to the first access authentication key; The first device calculates a first check value based on the authentication key of the ESAM and the second value, and sends an authentication confirmation message to the authentication server, where the authentication confirmation message carries the first check value; The authentication server calculates a second verification value based on the second numerical value, and determines that the first device is a trustworthy device when it is determined that the first verification value and the second verification value are equal.

5. The device authentication system according to claim 4, wherein: The authentication server calculates a first access authentication key based on a primary authentication key of the PSAM, a device identifier of the first device, and the first value, including: The authentication server disperses a temporary authentication key based on the primary authentication key of the PSAM and the device identification of the first device; Encrypting the first value using the temporary authentication key to obtain the first access authentication key; Correspondingly, the authentication server calculates a second verification value based on the second value, including: The authentication server calculates the second verification value based on the temporary authentication key and the second value.

6. The device authentication system according to claim 5, wherein: After the authentication server is successfully authenticated, the first device determines a communication key, including: After the authentication server is successfully authenticated, the first device determines the communication key based on the authentication key of the ESAM, the first value, and the second value; If the communication key generation condition further includes that the first device is successfully authenticated and receives a security context request initiated by the second device, and the security context request carries the device identifier of the first device, then when the communication key generation condition is met, the authentication server generates the communication key, including: After the first device is successfully authenticated and receives a security context request initiated by the second device, the authentication server determines the communication key according to the temporary authentication key, the first value, and the second value.

7. The device authentication system according to any one of claims 1 to 6, wherein: Before the first device sends a connection request message to the second device, the method includes: The first device determines whether it can directly authenticate with the second device based on the PSAM-ESAM security mechanism; Correspondingly, the first device initiates a connection request message to the second device, including: If the first device cannot directly authenticate with the second device based on the PSAM-ESAM security mechanism, a connection request message is initiated to the second device.

8. A device authentication method, characterized in that: Applied to a first device, the first device including an ESAM, the device authentication method includes: Initiating a connection request message to a second device, wherein the connection request message carries the device identifier of the first device and an ESAM authentication method supported by the first device, wherein the second device does not include a point-of-sale secure access module (PSAM) or a subkey dispersed from the ESAM; receiving a connection response message replied by the second device, the connection response message including information for instructing the first device to authenticate the authentication server based on the ESAM mode; Performing authentication with the authentication server based on the ESAM method, the authentication server and the second device have established a mutual trust relationship, and the authentication server includes the PSAM; After the authentication server is successfully authenticated, determining a communication key; Perform two-way authentication with the second device based on the communication key.

9. A terminal device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to claim 8 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to claim 8 is implemented.

Citation Information

Patent Citations

  • ETC system and ETC service authentication method

    CN107016741A